Firewall integrations

Fortinet

Elevate the power of your Fortinet Fortigate Firewall using by adding our Intelligence.

Palo Alto

Palo Alto Firewalls can be hardened with our threat intelligence as well.

Sophos XGS

Enhance the Sophos XGS Firewall with our threat intelligence.

OPNsense

Enhance your OPNsense Firewall with our threat intelligence using the native plugin.

SIEM integrations

Splunk

Splunk is a great platform, but without the right Threat Intelligence it's just a log server. Try our threat intelligence today. 

Microsoft Sentinel

One of the most used SIEM solutions should be enriched with the right Intelligence. At Q-Feeds you're at the right place!

Other

Luckily there are many other SIEM vendors whom support 3rd party threat intelligence.

Threat Intelligence Portal

Darkweb Monitoring

Darkweb monitoring is one of our services, not only for threat intelligence but also for you most important assets.

Threat Lookup

With Threat Lookup you get full insights in our IOC database, including full MITRE ATT&K mapping.

External Attack Surface Management

A toolset to check your external facing assets exposed on the internet

Vulnerability Scanner

A comprehensive vulnerability scanner which can scan your infrastructure and web applications

Brand Protection

Protect your brand for look-a-likes and potential phishing attempts

Services

TAXII Feeds & Server Software

TAXII/STIX2.1 standard. Both in form of feeds and server software available

Implementation

Need help with implementations? No worries, we have a strong network of partners who are able to help you.

Solutions

Enrich my SIEM

Elevate the power of your SIEM solution using by adding our Intelligence.

Enrich my Firewall

Firewalls can be hardened with our threat intelligence as well.

Prevent phishing

Enhance your protection against phishing

Achieve compliancy

Achieve compliancy by correlating the best threat intelligence to your logs

Futuristic eye design with circuits and geometric shapes.

Company

About

Read here all about Q-Feeds

News and Updates

Cybersecurity news and updates about us

Publications

All of our media coverage in one place

Become a reseller

Strengthen your portfolio with our comprehensive reseller program

Partner locator

Find our certified partners here

Contact

For all your questions or inquiries

Neural network representation of a human brain

Support

My Account

Access your account and manage your licenses

Downloads & Manuals

On this page you find white papers and manuals

Knowledge base

Our knowledge base full of implementation instructions

Start for free

Start your cyber security intelligence journey here

Abstract geometric wireframe human head

Understanding the landscape: Strategies to combat large-scale credential attacks

Jun 21, 2026 | Threat Intelligence Research

Large Scale Credential Theft Campaign Targets Fortinet Devices

Credential theft through large-scale password spraying against Fortinet and other devices has been reported by Unit 42 of Palo Alto Networks. The campaign, known as “FortiBleed,” also appears to involve attempts targeting MSSQL and Sophos devices.

Threat actors are utilizing a curated password list developed from previous data breaches. The password spraying method involves scanning internet-exposed services and attempting credential guesses. Successful access grants the attackers a pathway to escalate privileges and extract device configurations containing sensitive information. This process is iterative; stolen credentials are used to expand the password list, thus perpetuating the cycle of compromise.

The initial access broker allegedly responsible for this campaign has posted on a Russian-language cybercrime forum, promoting the sale of the stolen credentials alongside referencing an unspecified CVE. This highlights how credential theft can serve as a lucrative business for cybercriminals, further complicating defensive strategies.

Defensive Context

Organizations with devices such as Fortinet, MSSQL, or Sophos should take special note of this activity. Those with exposed services, especially remote access interfaces, are particularly vulnerable. However, entities that do not utilize these specific technologies or maintain strict access controls may be less concerned about the immediate risks presented by this campaign.

Why This Matters

This campaign underscores the risks associated with improper security hygiene, particularly for devices exposed to the internet. Enterprises using affected technologies must recognize that attackers are actively searching for weak points in their defenses, emphasizing the need for robust security practices.

Defender Considerations

Administrators are advised to closely monitor remote access logs for unusual login patterns, particularly successful logins that follow many failed password attempts. Credential hardening measures, such as implementing multi-factor authentication and disabling unused accounts, are critical countermeasures. Continuous vigilance around configurations and the use of complex passwords is also crucial for reducing potential attack vectors.

Environment Exposure

This threat is particularly relevant when Fortinet, MSSQL, and Sophos devices are improperly secured or exposed to public networks. Environments lacking recent updates or that have known vulnerabilities may especially attract attackers using this methodology. Conversely, organizations with strong access controls and comprehensive monitoring practices may find themselves less at risk from such campaigns.

Indicators of Compromise (IOCs)

While specific IP addresses or hashes were not detailed, the campaign’s association with Russian-language forums and credential sales presents a potential IOCs landscape for monitoring in threat intelligence efforts.

Click here for the full article

Try our Intelligence today!

Streamline your security operations with a free Q-Feeds trial and see the difference.

Other articles