The FortiBleed credential theft campaign, which compromised more than 73,000 Fortinet devices, is now directly linked to the INC and Lynx ransomware-as-a-service groups. SOCRadar's Threat Research Unit discovers the connection after identifying a Windows server used as part of the FortiBleed infrastructure that contains access to ransomware