<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>RuntimeRebel — #FortiGate</title><description>Cybersecurity articles tagged #FortiGate on RuntimeRebel.</description><link>https://runtimerebel.com</link><item><title>Private APN Misconfiguration Led to Polish Energy Plant OT Compromise</title><link>https://runtimerebel.com/blog/private-apn-misconfiguration-led-to-polish-energy-plant-ot-compromise</link><guid isPermaLink="true">https://runtimerebel.com/blog/private-apn-misconfiguration-led-to-polish-energy-plant-ot-compromise</guid><description>Hackers compromised a Polish energy plant&apos;s OT network by exploiting a private APN misconfiguration, shutting down a steam turbine and water treatment system.</description><pubDate>Tue, 11 Aug 2026 00:59:03 GMT</pubDate><category>OT Security</category><category>Critical Infrastructure</category><category>FortiGate</category><category>Private APN</category><category>WAGO PLC</category></item><item><title>FortiBleed: Credential Theft Fuels INC &amp; Lynx Ransomware Intrusions</title><link>https://runtimerebel.com/blog/fortibleed-credential-theft-fuels-inc-lynx-ransomware-intrusions</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortibleed-credential-theft-fuels-inc-lynx-ransomware-intrusions</guid><description>Analysis of the FortiBleed campaign, linking mass FortiGate credential theft to INC and Lynx ransomware operations for follow-on intrusions.</description><pubDate>Thu, 02 Jul 2026 10:44:52 GMT</pubDate><category>FortiBleed</category><category>INC Ransomware</category><category>Lynx Ransomware</category><category>FortiGate</category><category>Credential Theft</category><category>Ransomware</category></item><item><title>FortiBleed: 110 Million Credentials Harvested via FortiGate Firewalls</title><link>https://runtimerebel.com/blog/fortibleed-110-million-credentials-harvested-via-fortigate-firewalls</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortibleed-110-million-credentials-harvested-via-fortigate-firewalls</guid><description>Russian-speaking threat actors harvest 110 million credentials from 430,000 FortiGate firewalls globally. Learn to detect and mitigate FortiBleed tactics.</description><pubDate>Tue, 23 Jun 2026 20:49:19 GMT</pubDate><category>FortiBleed</category><category>FortiGate</category><category>Credential Harvesting</category><category>Initial Access Broker</category><category>Firewall Security</category></item><item><title>FortiBleed: FortiGate Firewalls Used as Credential Stealers</title><link>https://runtimerebel.com/blog/fortibleed-fortigate-firewalls-used-as-credential-stealers</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortibleed-fortigate-firewalls-used-as-credential-stealers</guid><description>Threat actors deploy Golang sniffers in the FortiBleed campaign, compromising 430,000 FortiGate firewalls to steal 110 million credentials globally.</description><pubDate>Tue, 23 Jun 2026 13:14:16 GMT</pubDate><category>FortiBleed</category><category>FortiGate</category><category>Credential Theft</category><category>Golang</category><category>Firewall Security</category></item><item><title>FortiBleed: 73,932 FortiGate Systems Exposed – Credential Leak Analysis</title><link>https://runtimerebel.com/blog/fortibleed-73932-fortigate-systems-exposed-credential-leak-analysis</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortibleed-73932-fortigate-systems-exposed-credential-leak-analysis</guid><description>Analysis of the FortiBleed campaign, detailing the exposure of administrative and VPN credentials for over 73,000 Fortinet FortiGate firewalls and critical mitigation…</description><pubDate>Sat, 20 Jun 2026 05:36:54 GMT</pubDate><category>FortiBleed</category><category>FortiGate</category><category>Fortinet</category><category>Credential Exposure</category><category>Firewall Security</category><category>Network Security</category></item><item><title>FortiBleed Data Leak: Securing Fortinet VPNs Against Exposure</title><link>https://runtimerebel.com/blog/fortibleed-data-leak-securing-fortinet-vpns-against-exposure</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortibleed-data-leak-securing-fortinet-vpns-against-exposure</guid><description>CISA warns organizations after 74,000 Fortinet VPN credentials were leaked online. Learn how to mitigate the FortiBleed threat and secure your network.</description><pubDate>Fri, 19 Jun 2026 09:44:30 GMT</pubDate><category>Fortinet</category><category>FortiGate</category><category>VPN</category><category>CVE-2018-13379</category><category>CISA</category><category>Credential Leak</category></item><item><title>FortiBleed: 73,000 Fortinet VPN Credentials Exposed</title><link>https://runtimerebel.com/blog/fortibleed-73000-fortinet-vpn-credentials-exposed</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortibleed-73000-fortinet-vpn-credentials-exposed</guid><description>FortiBleed leak compromises Fortinet and FortiGate VPN credentials for over 73,000 firewall URLs globally, posing significant access risks.</description><pubDate>Thu, 18 Jun 2026 01:08:29 GMT</pubDate><category>FortiBleed</category><category>Fortinet</category><category>FortiGate</category><category>VPN</category><category>Credentials</category><category>Data Leak</category></item><item><title>FortiGate RaaS and Citrix Exploits: Defensive Analysis of New TTPs</title><link>https://runtimerebel.com/blog/fortigate-raas-and-citrix-exploits-defensive-analysis-of-new-ttps</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortigate-raas-and-citrix-exploits-defensive-analysis-of-new-ttps</guid><description>An analysis of the latest ThreatsDay bulletin covering FortiGate RaaS, Citrix exploits, and LiveChat phishing lures targeting perimeter security.</description><pubDate>Thu, 19 Mar 2026 16:24:11 GMT</pubDate><category>FortiGate</category><category>Citrix</category><category>RaaS</category><category>Livechat Phishing</category><category>Mcp Abuse</category></item><item><title>FortiGate NGFW Exploitation Leads to Service Account Credential Theft</title><link>https://runtimerebel.com/blog/fortigate-ngfw-exploitation-leads-to-service-account-credential-theft</link><guid isPermaLink="true">https://runtimerebel.com/blog/fortigate-ngfw-exploitation-leads-to-service-account-credential-theft</guid><description>Threat actors are exploiting FortiGate devices to extract configuration files and steal service account credentials, facilitating lateral movement in networks.</description><pubDate>Tue, 10 Mar 2026 20:12:12 GMT</pubDate><category>Fortinet</category><category>FortiGate</category><category>Ngfw</category><category>Credential Theft</category><category>Fortios</category></item><item><title>CyberStrikeAI Leveraged in AI-Driven FortiGate Attacks Across 55 Countries</title><link>https://runtimerebel.com/blog/cyberstrikeai-leveraged-in-ai-driven-fortigate-attacks-across-55-countries</link><guid isPermaLink="true">https://runtimerebel.com/blog/cyberstrikeai-leveraged-in-ai-driven-fortigate-attacks-across-55-countries</guid><description>An open-source AI platform, CyberStrikeAI, is deployed in sophisticated, AI-driven attacks targeting Fortinet FortiGate appliances globally.</description><pubDate>Tue, 03 Mar 2026 16:22:24 GMT</pubDate><category>CyberStrikeAI</category><category>FortiGate</category><category>AI Driven Attacks</category><category>Team Cymru</category><category>Threat Actor</category><category>Open Source</category></item><item><title>Automated AI-Driven Exploitation of FortiGate Management Interfaces in AWS Environments</title><link>https://runtimerebel.com/blog/automated-ai-driven-exploitation-of-fortigate-management-interfaces-in-aws-environments</link><guid isPermaLink="true">https://runtimerebel.com/blog/automated-ai-driven-exploitation-of-fortigate-management-interfaces-in-aws-environments</guid><description>Threat actors are utilizing artificial intelligence to automate credential stuffing and exploit exposed administrative ports on Fortinet devices within AWS…</description><pubDate>Mon, 23 Feb 2026 12:21:29 GMT</pubDate><category>FortiGate</category><category>AWS</category><category>Credential Stuffing</category><category>AI</category><category>Network Security</category></item><item><title>AI-Automated Campaign Targets Global FortiGate Edge Infrastructure</title><link>https://runtimerebel.com/blog/ai-automated-campaign-targets-global-fortigate-edge-infrastructure</link><guid isPermaLink="true">https://runtimerebel.com/blog/ai-automated-campaign-targets-global-fortigate-edge-infrastructure</guid><description>A Russian-speaking threat actor leveraged generative AI to automate the compromise of over 600 FortiGate devices across 55 countries between January and February 2026.</description><pubDate>Mon, 23 Feb 2026 04:05:57 GMT</pubDate><category>FortiGate</category><category>GenAI</category><category>Credential Stuffing</category><category>Threat Intelligence</category><category>Network Security</category></item></channel></rss>