VORANT. Threat Intelligence Sign in Get the full feed

FortiBleed Flaw Exposed Victim's VPN Creds

elevated vulnerability

A ransomware group's leak site post shows a victim's FortiOS SSL-VPN credentials were exposed through the 2022 FortiBleed vulnerability.

This entry from ransomware.live documents a victim listing on a ransomware group's leak site, where the group claims the initial compromise involved FortiOS SSL-VPN credentials exposed via CVE-2022-40684, commonly known as FortiBleed. This vulnerability, an out-of-bounds read in FortiOS/FortiProxy SSL-VPN, allows unauthenticated attackers to retrieve sensitive memory content including credentials, and has been widely exploited since its 2022 disclosure.

The posting itself provides minimal technical detail beyond the credential-exposure claim and DNS record enumeration for the victim's domain, consistent with a standard ransomware extortion leak-site entry rather than a detailed technical writeup. No specific ransomware group, malware family, or victim sector is identified in the available text.

Mentioned in this report

Vulnerabilities CVE-2022-40684KEV

Source reporting: https://www.ransomware.live/id/QU9MLkNPTUBjbG9w

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free