Go back

There’s No Patch for a Stolen Password: What FortiBleed Teaches Us About the Limits of Detection

Brad LaPorte | New York
Brad LaPorte | New York
02 Sep 2026
4 min read
Advanced Threat Defense

A credential-based attack is an intrusion in which the attacker authenticates with a legitimate, stolen username and password rather than exploiting a software flaw β€” which means there is no malware signature, no exploit, and no vulnerability to patch at the point of entry. To every identity, network, and endpoint tool watching the login, the attacker looks like an authorized user.

The FortiBleed leak made the scale of this problem impossible to ignore. 

Researchers discovered an exposed server holding valid Fortinet SSL-VPN credentials β€” usernames, emails, and passwords β€” for 73,932 FortiGate firewalls across 194 countries, one of the largest VPN-credential exposures on record. Fortinet's investigation indicates the credentials were assembled from previous incidents and brute-force activity, not a new vulnerability. In other words: there is nothing to patch.

That is the whole point. The perimeter held. The credentials didn't. And once a valid login walks through the VPN, the attacker's next moves β€” lateral movement into Active Directory, then ransomware β€” are the part that actually causes damage. The future of cybersecurity is stopping that payload deterministically, because you cannot detect a legitimate credential.

Why Can't You Detect a Stolen Credential?

Because a stolen credential is a real credential. When an attacker signs in with a valid username and password, the authentication succeeds exactly as designed. There is no exploit to flag, no malware to fingerprint, and no anomaly in the login itself β€” the session is, by every technical measure, legitimate. Signature- and anomaly-based detection have nothing to fire on at the moment of entry.

FortiBleed shows how industrial this has become. This was not one phished password; it was a harvested trove of nearly 74,000 firewall credentials, assembled from prior breaches and brute-force campaigns and offered up at scale. Recovered credentials were then used for lateral movement into internal Active Directory β€” the standard pre-ransomware staging ground. The intrusion never needed a vulnerability, so 'patch and move on' was never an available response.

The Front Door Moved β€” and Detection Didn't Follow

For years, defensive spending assumed the attacker would break in. Increasingly, the attacker logs in. That shift quietly invalidates a lot of the detection stack at the point of entry.

  • No exploit, no signature. Credential-based access leaves nothing for signature engines to match.
  • Authorized-looking behavior. The session mirrors a real employee's, defeating anomaly models.
  • Rotation helps, but can't be complete. Reset passwords and enforce MFA β€” but assume some valid credentials will always get through.
  • The damage is downstream. The real harm is the lateral movement and ransomware that follow the login, not the login itself.

A Better Model: Prevention Before Execution

If you cannot reliably stop the attacker from getting in with a valid credential, you change where you stop them: at execution. A prevention-first security model assumes the perimeter and identity layers will sometimes be bypassed and focuses on the one thing every ransomware attack must still do β€” run code.

Automated Moving Target Defense (AMTD) morphs the runtime memory environment so that when the ransomware payload finally tries to execute, it cannot find its targets and is blocked deterministically, before encryption begins.

This is why a stolen credential stops being a crisis. AMTD does not need to decide whether a login is legitimate β€” it neutralizes the malicious payload that login was meant to deliver. Combined with credential hygiene, MFA, and exposure management, it covers the gap that detection structurally can't: the moment an authorized-looking session turns into ransomware execution. It augments NGAV, EDR, and XDR rather than replacing them.

Prevention Beats Detection Every Time

Rotate the passwords. Enforce MFA. Harden the VPN. Do all of it β€” and then assume some credentials will still get through, because FortiBleed proves they will. 

There is no patch for a stolen password, but there is a way to make it worthless: stop the payload it was meant to carry before it ever runs. When the front door is a valid login, prevention at execution is the lock that still works.

When the credential is real, make the ransomware payload fail. Book a Morphisec demo

New call-to-action

About the author

Brad LaPorte headshot

Brad LaPorte | New York

Chief Marketing Officer

Brad LaPorte is a seasoned cybersecurity expert and former military officer specializing in cybersecurity and military intelligence for the United States military and allied forces. With a distinguished career at Gartner as a top-rated research analyst, Brad was instrumental in establishing key industry categories such as Attack Surface Management (ASM), Extended Detection & Response (XDR), Digital Risk Protection (DRP), and the foundational elements of Continuous Threat Exposure Management (CTEM). His forward-thinking approach led to the inception of Secureworks’ MDR service and the EDR product Red Cloakβ€”industry firsts. At IBM, he spearheaded the creation of the Endpoint Security Portfolio, as well as MDR, Vulnerability Management, Threat Intelligence, and Managed SIEM offerings, further solidifying his reputation as a visionary in cybersecurity solutions years ahead of its time. He is based in Morphisec’s New York office at 122 Grand St, New York, NY.

Stay up-to-date

Get the latest resources, news, and threat research delivered to your inbox.

Morphisec Launches AI Usage Control Governing AI on the Endpoint