Field notes from the edge.
What our engineers learned this week. Hands-on technical deep-dives, postmortems, and strategy frameworks.
AIAttackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week
Threat intelligence firm Defused Cyber reports active exploitation of three security vulnerabilities in Fortinet's FortiSandbox product, including CVE-2026-39813 (CVSS 9.1), a critical path traversal flaw in the JRPC API. The exploitation activity has been observed within the past 24 hours, with one vulnerability reportedly patched just last week, indicating attackers are moving quickly to exploit
AIThreat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer
Threat actors are actively exploiting a critical, patched vulnerability in FortiClient Endpoint Management Server (EMS) to deploy credential-stealing malware across enterprise networks. The attackers leveraged trusted endpoint management infrastructure to distribute malicious payloads disguised as legitimate Fortinet endpoint components, allowing them to compromise managed endpoints at scale.
