AI security · Blog

FortiBleed had around twenty people. JadePuffer had an agent. The way in was identical.

A coverage audit of my own Sentinel detections.

The thesis I had to throw out

Two intrusions dominated the last month, and the coverage of both led with AI.

  • FortiBleed: an initial-access operation running on around twenty people with a defined division of labour.

  • JadePuffer: an agent that reached a production database with nobody at the keyboard.

The AI is real in both. I know because I set out to argue the opposite: that it was mostly narrative, and the reporting had gone looking for a machine where there were people. A week of verification killed that thesis. SOCRadar's second FortiBleed whitepaper documents AI integrated into the crew's own workflow: penetration testing, vulnerability research, attack automation, and ransomware development [1]. That's tooling in the operational workflow – not hype applied afterwards by reporters.

What replaced my thesis is narrower and more useful. AI is an operational multiplier for people who are already skilled, and it did not lower the floor for FortiBleed. That operation is closer to a small software company than a gang [2]. And the way to gain initial access never changed: valid credentials, exposed interfaces, and unpatched internet-facing services.

JadePuffer sits at the other end of every axis you'd normally use to rank an adversary in a graph: one agent, pointed at an exposed Langflow instance, issuing extortion demands on its own [3].

Around twenty skilled operators at one end. One agent at the other. Both walked through the same neglected door.

I write Sentinel detections and publish them; there are eight in my lab, documented, including the ones that went wrong. Later in this post I run every detection I own against both of these.


Twenty people and a diagnostic command

FortiBleed is not a Fortinet product-vulnerability story, and reading it as one is the first place a defender's attention is misdirected.

The operation, as attributed by SOCRadar to Lynx and INC, Russian-speaking and active since at least February 2026, built a custom Golang tool called 'FortigateSniffer' around the native FortiOS diagnose sniffer packet command, capturing authentication traffic across roughly two dozen protocols [2], [4]. Not an exploit. A supported administrative feature, driven with valid credentials, on devices the operators were already authenticated to. A FortiCloud SSO SAML bypass, CVE-2026-24858, disclosed in January, has been discussed as a possible contributor to initial access in a subset of cases and remains under investigation [4].

Around 430,000 FortiGate firewalls were targeted across 659 documented harvest cycles that exposed over 110 million credentials — RADIUS, NTLM and Kerberos material among them [10]. Administrative access was achieved on 409 of them, and on 354 the full chain was completed: VPN compromise, domain controller, and domain admin [2]. Where credentials weren't already in hand, they came from cracking harvested hashes offline, which is why "we rotated the passwords" is a weaker sentence than it sounds and why the checklist at the end has something specific to say about it.

The part that reads like a company rather than a crew came out of a recovered internal tracking document: around twenty people with a clear division of labour, a small core of lead operators driving the high-impact intrusions, backed by specialists and support staff [2]. Target inventories. Automation scripts. Operational artefacts.

None of that requires a firewall zero-day. It requires organisation, division of labour, and infrastructure – the same things any product team needs.The AI sits inside that operation as leverage, not as a substitute for the people running it.

FortiBleed chain: harvest auth traffic, crack hashes offline, authenticate with credentials that already work, capture in transit, hand off to Lynx


One agent and thirty-one seconds

JadePuffer, documented by Sysdig in early July, started at an internet-facing Langflow instance and CVE-2025-3248 — a vulnerability with a patch available and an exploit that requires no particular artistry [3].

From there it pivoted to an internet-facing production server running MySQL and Alibaba Nacos, authenticating with root MySQL credentials that did not come from the victim environment [3]. That detail is worth sitting with: somewhere upstream, a human compromise supplied those credentials. It exploited known Nacos authentication weaknesses dating back to 2021 and inserted a backdoor admin account.

The moment that got the coverage: a login failed, the agent read the error, worked out what it had got wrong, and regained access in thirty-one seconds with nobody assisting it. Over the course of the intrusion it generated more than 600 distinct, purposeful payloads, narrating its own reasoning in plain language as it went [3].

The clock is the difference. FortiBleed ran for months with a roster. JadePuffer ran a recovery cycle in under a minute with no one watching. Same year, same class of exposed service, opposite ends of every axis you'd normally use to rank an adversary.

And the ransom itself is where the machine shows its seams. Sysdig cannot say whether the Bitcoin address it produced is a real wallet or a string recalled from documentation it was trained on [3]. An operation that can self-correct in thirty-one seconds may not have been able to get paid.

JadePuffer chain: exposed Langflow, CVE-2025-3248, root MySQL login, backdoor in Nacos, login fails, back in within 31 seconds


Capability went up. AI sophistication didn't.

The tempting reading of those two sections is a ladder: crude attackers are at the bottom, organised crews are above them, autonomous agents are at the top, and AI is how you climb. The evidence doesn't support a ladder. It supports a spectrum, and AI is distributed across it unevenly.

LAMEHUG is the hinge. A state-sponsored actor embedded LLM prompting directly into malware, the most advanced adversary category we track, doing the most novel-sounding thing available and got no meaningful gain in effectiveness or sophistication for it [5]. Meanwhile, CrowdStrike's assessment across 2025 is that AI primarily enhances established tradecraft rather than creating original attack vectors and that adversaries who use it successfully generally need enough technical proficiency to catch the model's errors [5]. Capability and AI sophistication are two different axes, and they do not track each other.

ACTORAI in PlayWHAT IT BOUGHT THEM
JadePufferThe agent is the operator.31 seconds to self-correct
FortiBleedTooling inside workflow.Leverage on skilled people
LAMEHUGLLM embedded in malwareNo measurable gain
All three started at an exposed internet-facing service
Capability rises down the table. What the AI contributes falls.

What all eight of my detections would have seen

A threat narrative is a targeting instruction for defender attention. That's the whole claim, and it isn't a claim about journalists. It's about what happens in your head between reading a headline and opening a query window.

"Autonomous AI ransomware" sends you hunting AI: agentic processes, model API egress, and curiosity about something new on the box. "Around twenty people and a native sniffer command" sends you somewhere else entirely – credential reuse, accounts authenticating from places they shouldn't, and administrative features being used exactly as designed by someone who shouldn't have them. Same fortnight, same reader, opposite queries. Only one of those two framings was ever going to be written up as interesting.

SCATTERED SPIDER is the external version of this. Domain credentials were reached in around three hours; one managed endpoint was touched, and a help desk was talked into the access [5]. No AI anywhere in the chain. It is the least unprecedented intrusion imaginable in write-up terms and one of the most effective in terms of outcome, and it maps onto exactly the telemetry most teams already collect and aren't querying because attention is somewhere more exciting, for instance, zero-days.

WHAT YOU READ ABOUTWHAT THEY ACTUALLY USED
An autonomous AI agentAn exposed Langflow instance
AI-written ransomwareRoot credentials that already worked
An AI-enabled criminal crewA built-in command and cracked hashes
A sophisticated adversaryA phone call to a help desk

Which is a comfortable argument to make about other people. So I ran it against my own lab.

Repo: github.com/Kajal-Dhanjal/sentinel-detection-lab

Eight documented rules. Two real intrusions. One table. To be exact about the method: I did not replay either intrusion's telemetry through Sentinel — I audited each rule against the log sources it reads and the events these two intrusions would have produced.

#RuleReadsFortiBleedJadePufferWhy
1Brute forceWindows Security 4625MissMissHashes were cracked offline; the login that followed was valid
2PowerShell flagsWindows SecurityMissMissWindows signature, neither platform
3Registry persistenceSysmon EID 13MissMissNo Windows registry in either intrusion
4Recon burstWindows process namesMissMissWindows process names only
5MFA registration from an untrusted IPEntra sign-in logsClosestMissWrong platform, right logic
6Shadow-AI executionSysmon EID 1, .exe listMissMissWindows endpoint telemetry
7AI egressSysmon EID 3MissMissJadePuffer ran on Linux
8Agentic process lineageSysmon EID 1MissMissNo cmd.exe on a Langflow box

All three of my AI-track detections — shadow-AI execution, AI egress, and agentic process lineage — miss both intrusions. Every one.

The honest reason isn't that they're badly written. It's telemetry scope. Every AI rule I own reads Windows endpoint telemetry: Sysmon Event IDs 1 and 3, and a process name list, an .exe. JadePuffer ran on Linux — Langflow, MySQL, Nacos, no cmd.exe anywhere near it. FortiBleed ran on FortiOS with credentials that were valid. A rule keyed to a Windows process starting cannot see either of those, no matter how good the logic inside it is. A detection is only as good as your understanding of what its data source can see, which I wrote about in Part 7 [6], about a gap in my own Sysmon baseline, and did not expect to be quoting back at myself this soon.

The row that mattered is Part 5.

Part 5 correlates a sign-in from an untrusted IP with a security-info registration inside a thirty-minute window [7]. I built it as Variant B, a downgraded, free-tier version because Entra P2 wouldn't activate and I couldn't have the signal I actually wanted. I wrote it before the AI track existed, when I wasn't thinking about AI at all.

Strip the platform off it, and that is FortiBleed's exact shape: a legitimate account, arriving from somewhere it shouldn't, doing something that matters.

let TrustedIPs = dynamic(["<office/home IP 1>", "<office/home IP 2>"]);
let UntrustedSignIns = SigninLogs
| where IPAddress !in (TrustedIPs)
| where ResultType == 0
| project SignInTime = TimeGenerated, UserPrincipalName, IPAddress, Location;
let MFARegistrations = AuditLogs
| where ActivityDisplayName == "User started security info registration"
| extend UserPrincipalName = tostring(InitiatedBy.user.userPrincipalName)
| project RegTime = TimeGenerated, UserPrincipalName;
UntrustedSignIns
| join kind=inner MFARegistrations on UserPrincipalName
| where RegTime between (SignInTime .. (SignInTime + 30m))
| summarize arg_min(SignInTime, *) by UserPrincipalName, IPAddress
| project SignInTime, RegTime, UserPrincipalName, IPAddress, Location

Wrong log source. Right detection logic. It generalises because it keys on a behaviour, which doesn't age, rather than a technology, which does.

Part 8 does have a real-world match; it just isn't either of these. It's the Nx npm compromise: malicious packages driving victims' own local AI command-line tools into generating credential-theft commands; more than 90 customers were affected [5]. My agentic-lineage rule [8] fires on that shape. It got almost no coverage.


What changes Monday

I don't manage FortiGates for anyone's clients. What follows is what CISA's guidance [9], SOCRadar's documentation and my own coverage audit add up to for the people who do - sourced on each item, so you can check them rather than take my word for it. Here's the checklist:

1. Rotation isn't recovery. Cracked hashes mean the old password was already usable. Rotation closes one door, not the intrusion.

2. Confirm the PBKDF2 rehash per device — following CISA's alert, not me. PBKDF2 replaced SHA-256-with-salt in FortiOS 7.2.11, 7.4.8 and 7.6.1, but a stored password stays on the old scheme until that admin logs in again, and a hidden old-password setting can retain the previous hash. On 7.2.x and 7.4.x, login-lockout-upon-weaker-encryption purges the residue. Verify device by device; assume nothing from the version number alone.

3. Log process lineage on local AI binaries. Not the model traffic — the parent/child chain. The Nx case is a developer's own CLI tool being driven, and lineage is what shows it.

4. Put valid-account abuse ahead of malware signatures. Most detections now are malware-free, and valid accounts dominate cloud intrusions. Neither of these two intrusions would have tripped a signature.

5. Audit your detection backlog for narrative bias. Sort by what you built after reading something alarming, then check which log sources those rules can actually reach.

Both of these intrusions came through a service that was exposed, reachable and authenticated. What was on the other end, twenty people or one agent, changed nothing about the door.

Still open

Whether JadePuffer's Bitcoin address is a real wallet or a string recalled from training data — Sysdig can't distinguish the two.

CVE-2026-24858's role in FortiBleed initial access — under investigation.


References

[1]

“FortiBleed Unmasked: Inside the Lynx and INC Ransomware Operation - SOCRadar,” SOCRadar® Cyber Intelligence Inc., July 09, 2026. https://socradar.io/resources/whitepapers/fortibleed-unmasked-inside-the-lynx-and-inc-ransomware-operation/ (accessed July 21, 2026).

[2]

Ameer Owda, “SOCRadar Links FortiBleed Campaign to INC and Lynx Ransomware Operations,” SOCRadar® Cyber Intelligence Inc., July 2026. https://socradar.io/blog/fortibleed-inc-lynx-ransomware-link/ (accessed July 21, 2026).

[3]

M. Clark, “Jadepuffer: Agentic Ransomware for Automated Database Extortion,” Sysdig.com, July 2026. https://sysdig.com/blog/jadepuffer-agentic-ransomware-for-automated-database-extortion (accessed July 21, 2026).

[4]

Ameer Owda, “FortiBleed: The Campaign That Cracked 86,644 Firewalls,” SOCRadar® Cyber Intelligence Inc., June 16, 2026. https://socradar.io/blog/fortibleed-fortinet-firewalls-compromised (accessed July 21, 2026).

[5]

“CrowdStrike 2026 Global Threat Report,” 2026. Accessed: July 21, 2026. [Online]. Available: https://www.crowdstrike.com/explore/2026-global-threat-report?utm_medium=dir

[6]

K. Dhanjal, “Building a Sentinel Detection Lab, Part 7: The Detection That Taught Me My Own Telemetry’S Blind Spot,” Kajal’S Security Notes, June 30, 2026. https://knowngood.au/writing/building-a-sentinel-detection-lab-part-7-the-detection-that-taught-me-my-own-telemetry-s-blind-spot (accessed July 21, 2026).

[7]

K. Dhanjal, “Building a Sentinel Detection Lab, Part 5: MFA Registration, a Missing License, and the First Detection That Talks Back,” Kajal’S Security Notes, June 21, 2026. https://knowngood.au/writing/building-a-sentinel-detection-lab-part-5-mfa-registration-a-missing-license-and-the-first-detection-that-talks-back (accessed July 21, 2026).

[8]

K. Dhanjal, “Building a Sentinel Detection Lab, Part 8: Watching for Agents, Not Just Attackers,” Kajal’S Security Notes, June 30, 2026. https://knowngood.au/writing/building-a-sentinel-detection-lab-part-8-watching-for-agents-not-just-attackers (accessed July 21, 2026).

[9]

“CISA Urges Hardening Fortinet Devices After Reports of Credential Exposure | CISA,” Cybersecurity and Infrastructure Security Agency CISA, June 22, 2026. https://www.cisa.gov/news-events/alerts/2026/06/18/cisa-urges-hardening-fortinet-devices-after-reports-credential-exposure (accessed July 21, 2026).

[10]

“Dismantling FortiBleed: Inside a Russian Fortinet Compromise Operation - SOCRadar,” SOCRadar® Cyber Intelligence Inc., June 22, 2026. https://socradar.io/resources/whitepapers/dismantling-fortibleed-inside-a-russian-fortinet-compromise-operation/ (accessed July 21, 2026).

Consulted, not cited

Risky Business Features, "FortiBleed: the bleeding edge of AI cybercrime," podcast episode with E. Seker.
https://open.spotify.com/episode/4WNNxX0RVyLoQHU5fDo5LsDo5Ls

Kajal Dhanjal

Kajal Dhanjal

I build detections in my own Microsoft Sentinel lab and write up what holds and what doesn’t. About