> InfoSec News Nuggets – 10/08/2026
[AUTHOR: Mary]
[DATE: 08/10/2026 10:37]
[LANGUAGE: EN]
FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
The FBI is warning that the FortiBleed campaign against internet-exposed Fortinet FortiGate firewalls and SSL VPN gateways is still active, months after a massive credential leak was first discovered in June. Attackers break in using previously leaked logins, infostealer data, credential stuffing and password spraying, then pull additional authentication data from compromised devices and crack the stolen hashes offline on a distributed GPU cluster running Hashcat and Hashtopolis. In some incidents the intruders create their own administrator accounts and delete or reset legitimate ones, locking victims out before establishing persistence and moving laterally, and the FBI says the attack chain has served as an initial entry point for ransomware affiliates including INC/Lynx and Payload. The bureau cautions that patching and password resets alone may not be enough, recommending restricted external access, termination of all active VPN sessions, enforced MFA, log reviews for unauthorized changes, and PBKDF2 for administrator password storage instead of legacy SHA-256 hashes.
Hackers hijack three country-code domain registries, obtain HTTPS certificates for Google domains
Google has disclosed that attackers compromised the third-party operators of the .gh (Ghana), .sl (Sierra Leone) and .as (American Samoa) country-code top-level domains, altered authoritative DNS records, and used that control to obtain HTTPS certificates for several Google domains as well as domains belonging to other large brands and online services. Google stressed that its own systems were not breached and that it has no reason to believe the issuing certificate authorities did anything wrong, but it has not said how the registries were compromised, who is responsible, or when the attacks began. The company blocked the rogue certificates in Chrome via CRLSets, worked with the CAs to revoke them, and used Certificate Transparency logs to identify and notify other affected organizations. Google warned that it cannot guarantee every affected domain was found and that Chrome-side blocking does not protect users of other browsers, adding that it will keep pushing ecosystem changes such as shorter certificate validity and reduced domain-validation reuse.
Arizona courts say hackers stole info on more than 1.3 million people
Arizona court officials now say a cyberattack that began in late September gave hackers access to sensitive information on more than 1.3 million people, after federal and state investigators confirmed the intruders accessed and copied backup court files. The attackers breached the statewide Fines/Fees and Restitution Enforcement (FARE) Program, exposing names, Social Security numbers and case numbers dating back 30 years, and also reached more than 150,000 Foster Care Review Board reports going back to 2010, including records tied to 8,000 children currently in foster care, along with records on active and inactive protective orders. Investigators believe the intrusion started when a court employee clicked a malicious link in a phishing email. Officials say the incident did not involve ransomware, no group has claimed responsibility, and victims of the FARE breach will be notified by text message and are being urged to place holds on their credit.
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
Denmark’s digitalization ministry says unauthorized parties obtained the names, addresses and CPR personal identification numbers of roughly 8.8 million people, living and dead, from the country’s Central Person Register by abusing a small private company’s lawful lookup access. The data protection authority Datatilsynet says a very large number of automated lookups were made to identify valid CPR numbers, and the minister responsible said the access ran for about 10 days in September before a register employee spotted the unusual activity on October 2. The register has cut off the company’s access, police are investigating, and the minister has ordered a full security review while acknowledging that safeguards were not solid enough. Records of people with name-and-address protection were not exposed, but officials have not explained how the attackers got into the company’s systems, who they are, or whether the data has been used, and residents are being urged to watch for targeted scams and consider setting a credit warning.
Atlassian warns of critical file access flaw in its datacenter products
Atlassian is urging customers running self-hosted Data Center editions of Bitbucket, Confluence, Jira Service Management, Jira Software, Bamboo, Crowd, Crucible and Fisheye to patch CVE-2026-21589, a 9.3-rated arbitrary file access vulnerability that lets an unauthenticated attacker read specific files within the web application root directory. The company warns that some configurations may contain sensitive files that raise the risk, although exploitation requires knowing the exact file name and path and the bug does not allow directory listing. Fixed versions are available, and Atlassian advises that internet-facing instances, including those behind user authentication, be cut off from external network access until they can be upgraded, while cloud customers need take no action because the SaaS platform has already been fixed.
The post InfoSec News Nuggets – 10/08/2026 appeared first on AboutDFIR - The Definitive Compendium Project.