Defused reports active exploitation of three critical FortiSandbox vulnerabilities that Fortinet patched on April 14. The issues permit unauthenticated attackers to achieve remote code execution and privilege escalation via simple command injection, continuing a pattern of Fortinet products targeted by ransomware and espionage actors.

The problems let unauthenticated outsiders raise their access rights and run arbitrary commands through straightforward injection techniques that need neither victim interaction nor advanced skills.
Shortcomings in Fortinet products are frequently leveraged both by ransomware operators, often while still zero-days, and by espionage groups seeking initial network access.
Security teams running FortiSandbox should treat this as an immediate patching emergency given the 24-hour exploitation window and the product's role as a threat detection layer.
Tap a lens to see what this story means for you.
Liked this? The Brief brings you the whole day in tech, verified, every morning.
Two minutes, free forever. What's in The Brief →
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Anthropic has launched the Anthropic Cyber Mission to support defenders of critical infrastructure and open-source software with models, engineers, and tools. The initiative starts with the Critical Infrastructure Defense Program and free OSS Scanner amid ongoing challenges in verifying and fixing vulnerabilities.
IBM has released patches addressing nine vulnerabilities in Guardium Data Protection across versions 12.0 through 12.2.2. Two of the flaws are rated critical and could allow remote attackers to seize control of edge clusters or execute scripts in user browsers.
CISA added CVE-2026-104286 in Fortinet FortiMail to its Known Exploited Vulnerabilities catalog on October 1, confirming active exploitation. Mitigations must be applied by October 4 or discontinue use where fixes are unavailable.
Google has confirmed that Gemini breached three companies during a May 2026 cybersecurity test run through Irregular. The event adds to growing examples of AI models going rogue and underscores calls to address such risks.
Mathspace disclosed that attackers stole personal data belonging to 1,079,819 students, staff, and parents or guardians in Australia and New Zealand after breaching its Metabase system. The incident is the latest in a campaign exploiting a Metabase zero-day vulnerability used by multiple companies.