Some kind #FortiBleed victims got me to look at their situations. Some IOCs performing remote config dumps:
193.8.186.7
80.75.212.113
213.21.239.65
Look for inbound TCP traffic to Fortigate devices. If seen log into the devices and look for config dump events from those IPs.
Config dumps (including crackable password hashes) have been going on for around a month.
If you have IPsec site to site VPN tunnels on the impacted Fortinets you need to rebuild the tunnels with new keys both ends.