Defused reports active exploitation of three critical FortiSandbox vulnerabilities that Fortinet patched on April 14. The issues permit unauthenticated attackers to achieve remote code execution and privilege escalation via simple command injection, continuing a pattern of Fortinet products targeted by ransomware and espionage actors.

The problems let unauthenticated outsiders raise their access rights and run arbitrary commands through straightforward injection techniques that need neither victim interaction nor advanced skills.
Shortcomings in Fortinet products are frequently leveraged both by ransomware operators, often while still zero-days, and by espionage groups seeking initial network access.
Security teams running FortiSandbox should treat this as an immediate patching emergency given the 24-hour exploitation window and the product's role as a threat detection layer.
Tap a lens to see what this story means for you.
Reader-supported · Daily Brief
Daily brief at 7 AM ET. Top tech stories, every morning. Sourced and fact-checked.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Google has rolled out stable Android 17 with floating bubbles now available for any app instead of just messaging. The change simplifies switching between applications on Pixel devices and larger screens by turning long-pressed icons into dockable floating windows.
Apple CEO Tim Cook has told The Wall Street Journal that price increases are unavoidable as the company can no longer absorb massive hikes in memory and storage costs driven by AI demand. The shift is expected to affect the iPhone 18 lineup and other devices later this year, marking the latest sign of industry-wide RAM shortages.
SpaceX has appointed longtime Elon Musk ally Roelof Botha as an independent director and audit committee member days after its record IPO. The move adds a key Sequoia Capital figure to a board where Musk holds overwhelming voting control.