

We are introducing a temporary risk to respond to the FortiBleed incident. FortiBleed is a credential-exposure campaign affecting internet-facing Fortinet devices, where we believe attackers gained access through a mix of unpatched vulnerabilities and credential-stuffing techniques, then extracted device configuration data and used hashcracking techniques to break credentials into plaintext. Because this can indicate real compromise risk on affected infrastructure, we are adding a short-term detection signal that will remain active until 29 July 2026.
This change adds a new risk that can raise in both products: in Breach Risk, it raises when a customer’s own asset is on the impacted list; in Vendor Risk, it raises when a monitored vendor has an asset on that list. The signal is intended for fast visibility and triage so teams can prioritize validation and remediation on potentially impacted systems.






