Defused reports active exploitation of three critical FortiSandbox vulnerabilities that Fortinet patched on April 14. The issues permit unauthenticated attackers to achieve remote code execution and privilege escalation via simple command injection, continuing a pattern of Fortinet products targeted by ransomware and espionage actors.

The problems let unauthenticated outsiders raise their access rights and run arbitrary commands through straightforward injection techniques that need neither victim interaction nor advanced skills.
Shortcomings in Fortinet products are frequently leveraged both by ransomware operators, often while still zero-days, and by espionage groups seeking initial network access.
Security teams running FortiSandbox should treat this as an immediate patching emergency given the 24-hour exploitation window and the product's role as a threat detection layer.
Tap a lens to see what this story means for you.
Liked this? The Brief brings you the whole day in tech, verified, every morning.
Two minutes, free forever. What's in The Brief →
See what’s happening right now
The Feed runs all day — short, verified briefs the moment they break.
Open the FeedFollow @thecircuitry_
Every story we publish, as it happens. No noise between.
Reader-supported
The Circuitry is a passion project I've always wanted to build, and I love the work behind it.
Running it costs real money. APIs, hosting, time. To keep improving the site and growing this into something useful for everyone, those costs have to be covered.
Any contribution is appreciated. If not, no pressure. Thanks for reading.
Mathspace disclosed that attackers stole personal data belonging to 1,079,819 students, staff, and parents or guardians in Australia and New Zealand after breaching its Metabase system. The incident is the latest in a campaign exploiting a Metabase zero-day vulnerability used by multiple companies.
OpenAI announced that its Astra model is the first to reach the company’s critical cyber threshold by independently locating and exploiting unknown vulnerabilities in live software. A public version is slated for release soon, but advanced capabilities will initially be available only to Daybreak Blue partners while new guardrails and a misalignment monitor are deployed.
The FBI is investigating the dark web sale of scans from more than 153 million US and Canadian drivers licenses obtained via an ongoing breach at a Louisiana identity verification company. The incident underscores the lasting danger of stolen physical identity documents that cannot be reset like passwords and the growing scale of cyber-enabled identity theft.
ShinyHunters published data from 12.9 million genuine Carhartt accounts after the apparel company refused a $3.3 million ransom. The breach, which also exposed records for more than 15,000 employees, originated from Carhartt's Databricks analytics platform.
Sakura Internet disclosed that hackers accessed its sales management system on August 9, potentially compromising data from up to 1.36 million accounts. The breach, discovered during a separate Rental Server investigation, exposes personal and contract details but no confirmed exfiltration or credit card data.