Fortinet has released security updates addressing critical remote code execution vulnerabilities in FortiSandbox and FortiAuthenticator that could allow attackers to execute arbitrary commands on affected systems.
The vendor disclosed two critical vulnerabilities requiring immediate patching. Both flaws enable remote code execution, presenting severe risk to organizations relying on these security tools.
FortiSandbox Vulnerability
The vulnerability in FortiSandbox allows attackers to execute commands remotely without authentication. FortiSandbox, used for analyzing suspicious files and malware detection, processes untrusted content regularly, making it an attractive target for exploitation.
FortiAuthenticator Vulnerability
FortiAuthenticator, which handles authentication and single sign-on services, contains a separate critical flaw enabling code execution. Compromising authentication infrastructure could grant attackers access to multiple connected systems.
Impact and Response
Both products are widely deployed across enterprise networks. The criticality rating reflects the ease of exploitation and potential blast radius. Fortinet has released patches and recommends immediate deployment.
Organizations using either product should prioritize updating to patched versions. Security teams should verify patch application and monitor logs for signs of exploitation attempts.
Mitigation Steps
Until patches are applied, administrators should:
- Restrict network access to affected systems
- Monitor for unusual command execution or authentication activity
- Review recent logs for compromise indicators
- Coordinate with Fortinet support for deployment guidance
No evidence of active exploitation has been publicly reported, though the critical nature of these flaws makes rapid patching essential to prevent attacks.
This disclosure underscores the importance of maintaining security tools with current patches, as these products often have privileged positions in network infrastructure.
Visa is enabling expired payment cards to continue processing contactless transactions through a new feature. The move allows cardholders to keep using their old cards for tap-to-pay purchases even after expiration.
A Texas-based student discovered and reported an unauthorized AI system being used for cyberattacks. The disclosure prompted immediate investigation and security responses from affected organizations.
Iranian cyber actors shut down a small UK power generation facility for four days, according to sources cited by The Telegraph. The incident coincides with a broader wave of attacks targeting US water utilities attributed to Iran-affiliated groups.
A supply-chain attack is exploiting legitimate device-update apps to infect Android-based car head units with malware. The compromised devices are being enlisted into proxy botnets or used for ad fraud schemes.