惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

The GitHub Blog
The GitHub Blog
Martin Fowler
Martin Fowler
Vercel News
Vercel News
U
Unit 42
Engineering at Meta
Engineering at Meta
aimingoo的专栏
aimingoo的专栏
MyScale Blog
MyScale Blog
Y
Y Combinator Blog
阮一峰的网络日志
阮一峰的网络日志
爱范儿
爱范儿
Apple Machine Learning Research
Apple Machine Learning Research
博客园_首页
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
B
Blog RSS Feed
N
Netflix TechBlog - Medium
GbyAI
GbyAI
F
Fortinet All Blogs
MongoDB | Blog
MongoDB | Blog
大猫的无限游戏
大猫的无限游戏
C
Check Point Blog
M
MIT News - Artificial intelligence
D
Docker
IT之家
IT之家
Stack Overflow Blog
Stack Overflow Blog

Cyber Security News

AIRecon: AI-Powered Penetration Testing Tool with Kali Linux Sandbox Critical Chrome Vulnerabilities Allow Attackers to Execute Arbitrary Code - Update Now! Hackers Use Rokarolla Android Malware to Disable Google Play Protect and Control Devices UNC3753 Uses Screen-Sharing Sessions and RMM Tools to Exfiltrate Sensitive Legal Data New OnionDrop Loader Campaign Uses gainmsg C2 to Deliver LegionLoader Payloads ClickFix Campaign Uses EtherHiding and GULoader to Infect Windows Users via Fake CAPTCHA Ghostwriter Hackers Abuse Gmail Admin-Themed Emails to Steal Credentials and 2FA Codes The Half-Life of Threat Intelligence: When Does an IOC Stop Being Useful? Aembit Extends IAM for Agentic AI to Microsoft Copilot Studio India Temporarily Bans Telegram Messenger Over Medical Exam Fraud Microsoft 365 Device Code Phishing Campaign Bypasses Password Theft With Legitimate Login Flow AppViewX Launches Agent Identity Security to Govern Agents for the AI and Quantum Era Hackers Weaponize Microsoft Teams Relay to Hide Ransomware Traffic Developer laptops are the credential store attackers are picking through in 2026, GitGuardian announces Endpoint Protection Interlock and Rhysida Ransomware Operations Share Supper Backdoor and Malware Codebase Novo Nordisk Confirms Cyber Attack — Hackers Accessed Patient Medical Data and Internal AI Assets Russian and Chinese Influence Actors Use AI to Evade Bot Detection and Mimic Human Behavior Microsoft Teams Analyze the Wi-Fi Hotspot Data Connected to an Employee’s Device PRC-Nexus Hackers Exploit REDCap Servers to Spy on US Medical Research Institutions Infinite Campus Data Breach Exposes 137,000 Users Personal Details OptinMonster Plugin Hack Exposes 1.2 Million Wordpress Sites to Cyberattack Ransomware Ecosystem Consolidates Around LockBit Alumni, Qilin, Hyflock, and The Gentlemen Hackers Abuse Legitimate RMM Tools in The Quarry IRS and SSA Phishing Campaigns LiteSpeed cPanel Plugin 0-Day Vulnerability Actively Exploited in the Wild Cisco SD-WAN vManage Vulnerability Exploited in Zero-Day Attacks Nearly 14,000 SimpleHelp Servers Exposed Amid Critical Authentication Bypass Disclosure Microsoft Site Showing Warning Following Certificate Expiry DPAPISnoop Tool Extracts CREDHIST Hashes for Offline Windows Credential Recovery SHADOWBYT3$ Allegedly Claim Breach of Nintendo, Stealing Sensitive Data Anthropic Updated Privacy Policy to Include Identity Verification for Claude Users
Critical Fortinet FortiSandbox Vulnerabilities Actively E...
Guru Baran · 2026-06-17 · via Cyber Security News

Threat actors are actively exploiting multiple critical vulnerabilities in Fortinet’s FortiSandbox platform, with live attack telemetry confirming exploitation attempts over the past 24 hours.

Defused has flagged three CVEs under active targeting — including one, CVE-2026-39813, with no previously recorded exploitation history.

Honeypot sensors and deception infrastructure disguised as Fortinet FortiSandbox instances have captured exploitation attempts across three vulnerabilities, all triggered over port 443 via crafted POST requests to the /jsonrpc/ API endpoint.

CVE-2026-39813 : A path traversal vulnerability (CWE-24) in the FortiSandbox JRPC API that allows an unauthenticated remote attacker to bypass authentication via specially crafted HTTP requests.

By injecting traversal sequences such as session: "../../tmp/" into the API, attackers can access sensitive system data — including configuration backups, serial numbers, and version details — without any credentials. This CVE has no prior recorded exploitation in the wild, making this cluster of observed attacks a first-of-its-kind event.

CVE-2026-39808: An OS command injection flaw (CWE-78) in a FortiSandbox API endpoint that allows unauthenticated attackers to execute arbitrary commands as root.

A public proof-of-concept exploit has been available since April 2026, weaponizing the jid GET parameter via pipe-chained Unix commands. Attack payloads consistent with this PoC have now been observed in live exploitation attempts.

CVE-2026-25089 : A second OS command injection vulnerability (CWE-78) affecting the FortiSandbox Web UI across versions 5.0.0–5.0.5, 4.4.0–4.4.8, 4.2 all versions, and FortiSandbox Cloud/PaaS deployments. Notably, no functional public exploit has been disclosed for this CVE.

Observed exploitation attempts appear to be “vibecoded” — i.e., likely AI-assisted or heuristically generated exploits with faulty logic — suggesting opportunistic actors are probing without a validated working payload.

Affected Versions

CVEAffected VersionsFixed Version
CVE-2026-39813FortiSandbox 4.4.0–4.4.8, 5.0.0–5.0.54.4.9, 5.0.6+
CVE-2026-39808FortiSandbox 4.4.0–4.4.84.4.9+
CVE-2026-25089FortiSandbox 4.2 all versions, 4.4.0–4.4.8, 5.0.0–5.0.5; Cloud/PaaS 5.0.4–5.0.54.4.9, 5.0.6+

All three CVEs can be triggered without authentication through a single HTTP request, meaning exposed FortiSandbox management interfaces require zero pre-existing access to exploit.

Fortinet FortiSandbox Flaws (Source: X)
Fortinet FortiSandbox Flaws (Source: Defused)

A compromised FortiSandbox can be weaponized to approve malicious files as clean to dependent Fortinet products or serve as a lateral movement pivot within enterprise networks.

The attacker’s IP was observed in active exploitation 141.11.43[.]175 is attributed to AS136510 Streamline Servers Pty Ltd (Singapore) and carries a high-interest threat score.

Indicators of Compromise (IOCs)

TypeValueContext
Attacker IP141.11.43.175Observed exploit source
ASNAS136510Streamline Servers Pty Ltd, SG
Target Port443HTTPS/JRPC API
Target Endpoint/jsonrpc/FortiSandbox API path
User-AgentMozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/149.0.0.0 Safari/537.36Observed in live requests

Follow us on Google NewsLinkedIn, and X to Get More Instant Updates.

Guru Baran

Guru Baranhttps://cybersecuritynews.com

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.