---
title: "FortiBleed: 74,000 Fortinet Firewall Credentials | Firevault"
description: "Researchers say a Russian-speaking crew cracked nearly half the internet's Fortinet firewalls, exposing plaintext logins for Oracle, Chevron, Lenovo, FedEx, a…"
lang: en-GB
json-ld: |
  [
    {
      "@context": "https://schema.org",
      "@type": "Organization",
      "@id": "https://fire-vault.com/#organization",
      "name": "Firevault",
      "legalName": "Firevault Limited",
      "url": "https://fire-vault.com",
      "logo": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/logo.png",
        "width": 200,
        "height": 60
      },
      "foundingDate": "2025-03",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "address": {
        "@type": "PostalAddress",
        "addressCountry": "GB",
        "addressLocality": "United Kingdom"
      },
      "contactPoint": [
        {
          "@type": "ContactPoint",
          "contactType": "customer service",
          "email": "hello@fire-vault.com",
          "availableLanguage": "English",
          "areaServed": [
            "GB",
            "EU",
            "US",
            "AE"
          ]
        }
      ],
      "sameAs": [
        "https://www.linkedin.com/company/firevault",
        "https://x.com/firevaultuk"
      ],
      "slogan": "Disconnect to Protect",
      "knowsAbout": [
        "Offline Secure Storage",
        "Physical Air Gap Data Protection",
        "Ransomware Protection",
        "Data Sovereignty",
        "GDPR Compliance",
        "NIS2 Compliance"
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "WebSite",
      "@id": "https://fire-vault.com/#website",
      "name": "Firevault",
      "alternateName": [
        "Firevault",
        "Firevault UK",
        "Firevault Limited"
      ],
      "url": "https://fire-vault.com",
      "publisher": {
        "@id": "https://fire-vault.com/#organization"
      },
      "inLanguage": "en-GB",
      "description": "Protect what matters with Offline Secure Storage and control what moves with Control by Firevault. Physically disconnected, always reachable by you.",
      "potentialAction": {
        "@type": "SearchAction",
        "target": {
          "@type": "EntryPoint",
          "urlTemplate": "https://fire-vault.com/learn?q={search_term_string}"
        },
        "query-input": "required name=search_term_string"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "WebPage",
      "@id": "https://fire-vault.com/news/fortibleed-74000-fortinet-firewalls-credentials-exposed#webpage",
      "url": "https://fire-vault.com/news/fortibleed-74000-fortinet-firewalls-credentials-exposed",
      "name": "FortiBleed: 74,000 Fortinet Firewall Credentials",
      "description": "Researchers say a Russian-speaking crew cracked nearly half the internet's Fortinet firewalls, exposing plaintext logins for Oracle, Chevron, Lenovo, FedEx, a…",
      "isPartOf": {
        "@id": "https://fire-vault.com/#website"
      },
      "about": {
        "@id": "https://fire-vault.com/#organization"
      },
      "primaryImageOfPage": {
        "@type": "ImageObject",
        "url": "https://fire-vault.com/__l5e/assets-v1/4b28b391-6cbf-4fc1-abad-5910c154bba8/news-fortibleed-fortinet-firewalls-hero-2x.jpg"
      },
      "inLanguage": "en-GB",
      "breadcrumb": {
        "@id": "https://fire-vault.com/news/fortibleed-74000-fortinet-firewalls-credentials-exposed#breadcrumb"
      }
    },
    {
      "@context": "https://schema.org",
      "@type": "BreadcrumbList",
      "@id": "https://fire-vault.com/news/fortibleed-74000-fortinet-firewalls-credentials-exposed#breadcrumb",
      "itemListElement": [
        {
          "@type": "ListItem",
          "position": 1,
          "name": "Home",
          "item": "https://fire-vault.com"
        },
        {
          "@type": "ListItem",
          "position": 2,
          "name": "Learn",
          "item": "https://fire-vault.com/learn"
        },
        {
          "@type": "ListItem",
          "position": 3,
          "name": "Knowledge Vault",
          "item": "https://fire-vault.com/learn/knowledge"
        },
        {
          "@type": "ListItem",
          "position": 4,
          "name": "FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials",
          "item": "https://fire-vault.com/news/fortibleed-74000-fortinet-firewalls-credentials-exposed"
        }
      ]
    },
    {
      "@context": "https://schema.org",
      "@type": "NewsArticle",
      "headline": "FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials",
      "description": "Researchers say a Russian-speaking crew cracked nearly half the internet's Fortinet firewalls, exposing plaintext logins for Oracle, Chevron, Lenovo, FedEx, a NATO defence contractor and Fortinet itself.",
      "url": "https://fire-vault.com/news/fortibleed-74000-fortinet-firewalls-credentials-exposed",
      "image": [
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/4b28b391-6cbf-4fc1-abad-5910c154bba8/news-fortibleed-fortinet-firewalls-hero-2x.jpg",
          "width": 1200,
          "height": 1200
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/4b28b391-6cbf-4fc1-abad-5910c154bba8/news-fortibleed-fortinet-firewalls-hero-2x.jpg",
          "width": 1200,
          "height": 900
        },
        {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/__l5e/assets-v1/4b28b391-6cbf-4fc1-abad-5910c154bba8/news-fortibleed-fortinet-firewalls-hero-2x.jpg",
          "width": 1200,
          "height": 675
        }
      ],
      "thumbnailUrl": "https://fire-vault.com/__l5e/assets-v1/4b28b391-6cbf-4fc1-abad-5910c154bba8/news-fortibleed-fortinet-firewalls-hero-2x.jpg",
      "author": {
        "@type": "Person",
        "name": "Mark Fermor",
        "jobTitle": "Director & Co-Founder",
        "worksFor": {
          "@id": "https://fire-vault.com/#organization"
        },
        "url": "https://fire-vault.com/why-oss/about"
      },
      "publisher": {
        "@type": "NewsMediaOrganization",
        "name": "Firevault",
        "url": "https://fire-vault.com",
        "logo": {
          "@type": "ImageObject",
          "url": "https://fire-vault.com/logo.png",
          "width": 600,
          "height": 60
        }
      },
      "datePublished": "2026-06-18T09:03:31.659279+00:00",
      "dateModified": "2026-08-28T08:03:22.256672+00:00",
      "mainEntityOfPage": {
        "@type": "WebPage",
        "@id": "https://fire-vault.com/news/fortibleed-74000-fortinet-firewalls-credentials-exposed"
      },
      "inLanguage": "en-GB",
      "articleSection": "Threat Analysis",
      "wordCount": 760,
      "keywords": "FortiBleed:, Threat Analysis, data breach, cyber security, offline secure storage, data protection, physical air gap",
      "articleBody": "Researchers have uncovered a mass compromise of Fortinet firewalls that has handed a Russian-speaking criminal crew near-unrestricted access to some of the world''s largest organisations, including Oracle, Chevron, Lenovo, Federal Express, a NATO defence contractor and Fortinet itself. According to Bob Diachenko of SecurityDiscovery.com, nearly 74,000 Fortinet devices across more than 21,000 IP ad",
      "dateline": "United Kingdom",
      "speakable": {
        "@type": "SpeakableSpecification",
        "cssSelector": [
          "h1",
          ".article-summary",
          "h2"
        ]
      },
      "isAccessibleForFree": true,
      "copyrightHolder": {
        "@id": "https://fire-vault.com/#organization"
      },
      "copyrightYear": 2026
    },
    {
      "@context": "https://schema.org",
      "@type": "FAQPage",
      "mainEntity": [
        {
          "@type": "Question",
          "name": "What is FortiBleed?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "FortiBleed is the informal name given to a mass compromise of roughly 74,000 internet-facing Fortinet firewalls, in which attackers harvested and cracked SSL VPN credentials and posted the plaintext logins online."
          }
        },
        {
          "@type": "Question",
          "name": "How do I know if my organisation is affected?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Hudson Rock has published a lookup tool at hudsonrock.com/fortinet that lets you check whether your domain appears in the leaked data. Treat every Fortinet admin, VPN, Radius and Active Directory credential as suspect until rotated."
          }
        },
        {
          "@type": "Question",
          "name": "How does offline secure storage help?",
          "acceptedAnswer": {
            "@type": "Answer",
            "text": "Crown-jewel secrets such as recovery keys, root credentials and succession material should not sit behind an internet-facing firewall at all. Holding them inside a physically air-gapped Firevault module means a cracked VPN hash cannot reach them, no matter how the perimeter fails."
          }
        }
      ]
    }
  ]
---

Recent Breaches 

Breaches 

[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)[2026 PowerSchool 62.4M records ](/learn/breaches)[2026 DISA Global Solutions 3.3M records ](/learn/breaches)[2026 Globe Life 850K records ](/learn/breaches)[2026 Lidl GB Customer contact data ](/learn/breaches)[2026 Asahi Group Production systems disrupted ](/learn/breaches)[2026 Kido International 8K records ](/learn/breaches)[2026 Collins Aerospace (RTX) Check-in and boarding disruptio... ](/learn/breaches)[2026 Jaguar Land Rover Production and IT systems disru... ](/learn/breaches)[2026 Peter Green Chilled Order and logistics data ](/learn/breaches)[2026 Adidas UK Customer contact details ](/learn/breaches)

[View All →](/learn/breaches)

[![Firevault - offline secure storage, physically disconnected from the internet](/assets/logo-color-DBVl0KCg.png)](/)

Products

Solutions

[Why OSS](/why-oss)

More

[Help](/help)[Get started](/get-started)

Overview

What happenedWho is affectedWhy this mattersThe Firevault viewWhat to do nowSourcesMore Resources

[Knowledge Vault](/learn/knowledge)/ [News](/learn/knowledge?filter=news)

News · Threat Analysis · 18 June 2026 

# FortiBleed: 74,000 Fortinet firewalls leak plaintext credentials

Researchers say a Russian-speaking crew cracked nearly half the internet's Fortinet firewalls, exposing plaintext logins for Oracle, Chevron, Lenovo, FedEx, a NATO defence contractor and Fortinet itself.

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

Mark Fermor Director & Co-Founder, Firevault 

4 min read 

Share 

[](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ffortibleed-74000-fortinet-firewalls-credentials-exposed)[](https://twitter.com/intent/tweet?url=https%3A%2F%2Ffire-vault.com%2Fnews%2Ffortibleed-74000-fortinet-firewalls-credentials-exposed&text=FortiBleed%3A%2074%2C000%20Fortinet%20firewalls%20leak%20plaintext%20credentials%0A%0AResearchers%20say%20a%20Russian-speaking%20crew%20cracked%20nearly%20half%20the%20internet's%20Fortinet%20firewalls%2C%20exposing%20plaintext%20logins%20for%20Oracle%2C%20Chevron%2C%20Lenovo%2C%20FedEx%2C%20a%20NATO%20defence%20contractor%20and%20Fortinet%20itself.)[](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Ffire-vault.com%2Fnews%2Ffortibleed-74000-fortinet-firewalls-credentials-exposed)[](mailto:?subject=FortiBleed%3A%2074%2C000%20Fortinet%20firewalls%20leak%20plaintext%20credentials&body=Researchers%20say%20a%20Russian-speaking%20crew%20cracked%20nearly%20half%20the%20internet's%20Fortinet%20firewalls%2C%20exposing%20plaintext%20logins%20for%20Oracle%2C%20Chevron%2C%20Lenovo%2C%20FedEx%2C%20a%20NATO%20defence%20contractor%20and%20Fortinet%20itself.%0A%0Ahttps%3A%2F%2Ffire-vault.com%2Fnews%2Ffortibleed-74000-fortinet-firewalls-credentials-exposed)

![Glowing padlocks and binary code leaking from a dark Fortinet-style firewall appliance in a server rack](/__l5e/assets-v1/4b28b391-6cbf-4fc1-abad-5910c154bba8/news-fortibleed-fortinet-firewalls-hero-2x.jpg)

Glowing padlocks and binary code leaking from a dark Fortinet-style firewall appliance in a server rack

Why it matters

## What this means for organisations holding critical data

Researchers say a Russian-speaking crew cracked nearly half the internet's Fortinet firewalls, exposing plaintext logins for Oracle, Chevron, Lenovo, FedEx, a NATO defence contractor and Fortinet itself.

In this analysis

1.  01 [What happened](#section-0)
2.  02 [Who is affected](#section-1)
3.  03 [Why this matters](#section-2)
4.  04 [The Firevault view](#section-3)
5.  05 [What to do now](#section-4)

**On this page**[What happened](#section-0)[Who is affected](#section-1)[Why this matters](#section-2)[The Firevault view](#section-3)[What to do now](#section-4)

Researchers have uncovered a mass compromise of Fortinet firewalls that has handed a Russian-speaking criminal crew near-unrestricted access to some of the world''s largest organisations, including Oracle, Chevron, Lenovo, Federal Express, a NATO defence contractor and Fortinet itself.

According to Bob Diachenko of SecurityDiscovery.com, nearly 74,000 Fortinet devices across more than 21,000 IP addresses in 194 countries have been compromised, with their plaintext credentials exposed online. Independent researcher Kevin Beaumont confirms that "almost all" of the affected devices remained online as of this week, and that the credentials are real and current. By Shodan''s count, that is roughly half of every internet-facing Fortinet firewall on the planet.

## What happened

The attackers mass-scanned the public internet for FortiGate remote login endpoints, then sprayed them with thousands of username and password combinations using a custom 25,000-thread binary. Each success gave them, in Diachenko''s words, "a network tap inside the organisation".

From there, Hudson Rock reports, the crew intercepted SSL VPN authentication hashes and fed them to a 45-GPU Hashtopolis cluster running a 12-level recursive cracking pipeline. Successful guesses were looped back as seeds for the next round, so the attack got faster and smarter the more it succeeded. Once cracked, those passwords were used to move laterally into Active Directory, Radius and other centralised authentication systems.

"The scale is the sophistication," Diachenko told Ars Technica.

## Who is affected

The exposed database also lists the industry, revenue and employee count for each compromised organisation. Named victims include Oracle, Chevron, Lenovo, Federal Express, Foxconn, Samsung, Comcast, Siemens, PwC, Accenture and Fortinet itself, alongside what Hudson Rock describes as "thousands of others, including major government agencies and [critical infrastructure](/control-for-critical-infrastructure) providers".

The most serious confirmed case is a Turkish NATO defence contractor, from which the group is said to have successfully exfiltrated classified defence documents. Diachenko''s investigation confirmed full network compromises at organisations across Japan, Taiwan, Vietnam, Iraq and Turkey. The top affected sectors are IT services, construction materials, telecommunications, construction and engineering, industrial equipment and financial services.

## Why this matters

Firewalls have always been an attractive entry point. They sit on the perimeter, accept connections from the open internet, and broker access to the most valuable resources inside the network. When a single product line is this widely deployed, a working credential database becomes a master key to half the economy.

What is striking about FortiBleed is not a novel zero-day but the brute, industrial scale of the operation. Tens of thousands of passwords cracked at scale, fed back into a self-improving pipeline, then quietly used to pivot into Active Directory. The perimeter held the door; the attackers simply made enough keys.

## The Firevault view

This is the failure mode Firevault was built to remove. If your recovery keys, root credentials, succession material or long-term audit secrets sit on a system that an internet-facing firewall can reach, then a cracked VPN hash, somewhere in the world, can reach them too.

An [offline secure storage](/offline-secure-storage) module is not a replacement for a firewall. It is a physically separate place to hold the material that must survive a perimeter compromise, including the credentials you would need to recover from one. A Firebreak deployment keeps that material in a tamper-evident enclosure, with no network path that a Hashtopolis cluster can ever reach. The question we keep putting to security leaders is simple: if your perimeter was in the FortiBleed dataset tomorrow, what would you wish had never been online?

## What to do now

-   Check your domains against Hudson Rock''s lookup at [hudsonrock.com/fortinet](https://www.hudsonrock.com/fortinet).
-   Force rotate Fortinet admin, SSL VPN, Radius and Active Directory credentials, then audit for lateral movement that pre-dates the rotation.
-   Review logs on FortiGate appliances for high-volume authentication attempts and anomalous successful logins from unfamiliar geographies.
-   Move long-life secrets, recovery keys and succession material into an offline, physically air-gapped store. Talk to us about [gold-copy backups](/solutions/oss/use-cases/gold-copy-backups) and [Firebreak deployments](/firebreak).

## Sources

-   Dan Goodin, Ars Technica, ["Massive breach spills credentials for thousands of sensitive networks"](https://arstechnica.com/security/2026/06/massive-breach-spills-credentials-for-thousands-of-sensitive-networks/).
-   Kevin Beaumont, DoublePulsar, ["FortiBleed: 75k Fortinet firewalls have admin passwords cracked"](https://doublepulsar.com/fortibleed-75k-fortinet-firewalls-have-admin-passwords-cracked-60299faa65f8).
-   Hudson Rock, [FortiBleed analysis and victim lookup](https://www.infostealers.com/article/fortibleed-75000-fortinet-firewalls-compromised-global-enterprises-exposed-claim-your-ethical-disclosure/).

_Analysis by Mark Fermor, Firevault._

**How Firevault helps**

-   **[Offline Secure Storage](/offline-secure-storage)** keeps gold-copy data physically disconnected from the network, so a ransomware or exfiltration event cannot reach it.
-   **[Control](/control)** gives boards and operators a single view of what is online, what is isolated, and what is recoverable across the estate.
-   **[Firebreak](/firebreak)** delivers hardware-enforced disconnection at Layer 1, so exposed credentials or compromised network paths cannot become a route into the vault.

_Talk to Firevault about [Disconnect to Protect®](/about) for your organisation._

Sources

## Where this reporting comes from

01 

**Original report**Primary coverage referenced in this analysis [View original article](https://arstechnica.com/security/2026/06/massive-breach-spills-credentials-for-thousands-of-sensitive-networks/)

About the author

![Mark Fermor](/assets/mark-fermor-aWtKNSv7.jpg)

### Mark Fermor

[](https://www.linkedin.com/in/mfermor)

Director & Co-Founder

Co-founder of Firevault, focused on offline secure storage and protecting individuals and businesses from fraud, fines, loss and damage. Speaker, owner and advisor.

The Firevault view**Offline Secure Storage® keeps a clean copy beyond the reach of an attacker.**[Why #OSS →](/why-oss)

Control systems and access**Cut the physical paths attackers and third parties depend on.**[Explore Control →](/solutions/control)

Get started**Get started, or talk to a member of the team.**[Get started →](/get-started)

How Firevault would handle this

## A recovery copy an attacker cannot reach

Offline Secure Storage® keeps a clean copy of your data on hardware that is physically disconnected, so backup and recovery do not depend on systems an intruder can touch.

[Get started](/get-started)[Talk to the team](/demo)

**Hardware**Your copy sits on dedicated encrypted hardware 

**Disconnect**Offline by default, connected only when you say so 

**Recovery**A known-clean copy to rebuild from, on your timetable 

**Location**Held in a secure Firevault Bunker 

Related Reading

## You may also find these useful

[

![Scattered Spider Guilty Pleas: What the TfL Hack Confirms About Offline Recovery](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fscattered-spider-tfl-guilty-plea.jpg)

Threat Analysis 

### Scattered Spider Guilty Pleas: What the TfL Hack Confirms About Offline Recovery

Two Scattered Spider members have admitted the £39m TfL hack. Mark Fermor on identity blast radius and why offline recovery is the deciding layer.

22 Jun 2026 4 min 







](/news/scattered-spider-tfl-guilty-plea-offline-recovery)[

![UK critical infrastructure hit by 200 cyber incidents in a year, NCSC warns](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2Fncsc-uk-cni-incidents-hero.jpg)

Threat Analysis 

### UK critical infrastructure hit by 200 cyber incidents in a year, NCSC warns

NCSC chief Richard Horne says the UK faced more than 200 nationally significant cyber incidents against critical infrastructure in a year, with about three-quarters tied to state actors.

20 Jun 2026 5 min 







](/news/ncsc-uk-critical-infrastructure-incidents-double)[

![24 billion credentials exposed in record infostealer leak](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/news%2F24bn-credentials-infostealer-hero.jpg)

Threat Analysis 

### 24 billion credentials exposed in record infostealer leak

Cybernews researchers found an 8.3 TB Elasticsearch cluster holding 24 billion records, including plaintext passwords and login URLs harvested from infostealer logs.

19 Jun 2026 4 min 







](/news/24-billion-credentials-infostealer-leak)[

![Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/manchester-airports-group-data-breach-2026.jpg)

Insight 

### Airport WiFi sign-ups turn into a national data problem as 8.7 million customer records are accessed

Manchester Airports Group has confirmed that criminal hackers accessed the data of about 8.7 million customers across Manchester, East Midlands and London Stansted. Most of it came from free terminal WiFi sign-ups and from car parking, lounge and fast-track bookings.

27 Aug 2026 5 min 







](/news/manchester-airports-group-data-breach-87-million-customers-2026)[

![Premier League moves the goalposts as cyber rulebook introduces 22 security control areas](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/premier-league-cyber-rulebook-2026.jpg)

Regulation 

### Premier League moves the goalposts as cyber rulebook introduces 22 security control areas

Rule J.9 and Appendix 11 put cyber security into the Premier League rulebook, with phased deadlines, annual evidence and 22 control areas spanning club, stadium and supplier operations.

27 Aug 2026 14 min 







](/news/premier-league-cyber-rulebook-appendix-11-2026)[

![T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.](https://zomvctmqpgirvjnvawlz.supabase.co/storage/v1/object/public/article-images/tmobile-power-pull-salt-typhoon-2026.jpg)

Insight 

### T-Mobile pulled the plug on Salt Typhoon. It took a car journey to get there.

T-Mobile's security chief ended months of failed software remediation by driving to the data centre, clearing ID, finding the cabinet and physically pulling the power supply from the compromised hardware. Disconnection was the right control. Firevault Control is designed to take the same action in under six milliseconds.

27 Aug 2026 7 min 







](/news/tmobile-severs-network-cable-salt-typhoon-hackers-2026)

## Suggested Reading

-   [What is Offline Secure Storage The foundation of physical disconnection ](/how-it-works/offline-secure-storage)
-   [Why Offline Secure Storage The case for physical control ](/why-oss)
-   [Ransomware Defence Hold gold copies offline ](/oss-for-ransomware-recovery)
-   [Control Physical path control for IT and OT ](/solutions/control)
-   [Knowledge Vault All articles, guides and whitepapers ](/learn/knowledge)
-   [Book a Demo See Firevault in action ](/demo)

[Back to Knowledge Vault](/learn/knowledge)