<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Fortinet on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/fortinet/</link><description>Recent content in Fortinet on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Wed, 17 Jun 2026 17:27:40 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/fortinet/index.xml" rel="self" type="application/rss+xml"/><item><title>Fortinet Firewall Attack Steals Passwords on 75k Devices</title><link>https://zxcloudsecurity.co.uk/posts/fortinet-firewall-mass-password-theft-75k-devices/</link><pubDate>Wed, 17 Jun 2026 17:27:40 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/fortinet-firewall-mass-password-theft-75k-devices/</guid><description>A mass credential-theft attack has hit 75,000 Fortinet firewalls. Learn what cloud security architects should do now to protect their environments.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/cyber-crime/2026/06/17/massive-password-stealing-attack-hits-75k-fortinet-firewalls/5257877">The Register — Security</a></p>
<hr>
<p>A large-scale credential-theft campaign has compromised approximately 75,000 Fortinet firewall devices, exfiltrating stored passwords. The attack exploits exposed management interfaces or known vulnerabilities to harvest credentials at scale. This poses a significant risk to organisations using FortiGate appliances, particularly those with internet-facing management planes.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Immediately rotate all credentials associated with affected Fortinet devices, including VPN accounts, local admin accounts, and any downstream systems that share those credentials. Audit your FortiGate estate for internet-exposed management interfaces and restrict access to trusted IP ranges via firewall policy or a jump host.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/cyber-crime/2026/06/17/massive-password-stealing-attack-hits-75k-fortinet-firewalls/5257877">Massive password-stealing attack hits 75k Fortinet firewalls</a></p>
]]></content:encoded></item><item><title>Critical Fortinet FortiSandbox Bugs Actively Exploited</title><link>https://zxcloudsecurity.co.uk/posts/fortinet-fortisandbox-critical-vulnerabilities-actively-exploited/</link><pubDate>Tue, 16 Jun 2026 18:27:12 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/fortinet-fortisandbox-critical-vulnerabilities-actively-exploited/</guid><description>Three critical Fortinet FortiSandbox vulnerabilities are being actively exploited. Patches are available — upgrade immediately to protect your environment.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/security/2026/06/16/three-critical-fortinet-sandbox-bugs-splattered-by-unknown-attackers/5256461">The Register — Security</a></p>
<hr>
<p>Three critical vulnerabilities in Fortinet&rsquo;s FortiSandbox product have been actively exploited by unknown attackers in the wild. Patches are available for all three flaws, making urgent remediation essential for any organisation running FortiSandbox. The active exploitation status significantly raises the risk, as attackers are already leveraging these weaknesses before many organisations have had a chance to respond.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> If FortiSandbox is deployed anywhere in your environment — on-premises or integrated with cloud workloads — prioritise patching immediately and review logs for indicators of compromise prior to the patch window. Isolate affected appliances from the network if an immediate upgrade is not possible.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/security/2026/06/16/three-critical-fortinet-sandbox-bugs-splattered-by-unknown-attackers/5256461">Three critical Fortinet sandbox bugs splattered by unknown attackers</a></p>
]]></content:encoded></item><item><title>Fortinet FortiSandbox CVE-2026-39813 Exploited in Wild</title><link>https://zxcloudsecurity.co.uk/posts/fortinet-fortisandbox-cve-2026-39813-cve-2026-39808-cve-2026-25089-exploited/</link><pubDate>Tue, 16 Jun 2026 10:30:41 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/fortinet-fortisandbox-cve-2026-39813-cve-2026-39808-cve-2026-25089-exploited/</guid><description>Attackers are actively exploiting three Fortinet FortiSandbox flaws, including critical CVE-2026-39813 (CVSS 9.1). Patch immediately and restrict JRPC API</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://thehackernews.com/2026/06/attackers-exploit-three-fortinet.html">The Hacker News</a></p>
<hr>
<p>Attackers are actively exploiting three vulnerabilities in Fortinet FortiSandbox, a network security sandboxing product, including a critical path traversal flaw (CVE-2026-39813, CVSS 9.1) in its JRPC API. Two additional CVEs — CVE-2026-39808 and CVE-2026-25089 — are also being abused in the wild, with at least one patched only last week. Active exploitation makes this an urgent patching priority for any organisation running FortiSandbox.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Immediately apply the latest Fortinet patches for FortiSandbox and audit internet-facing exposure of the JRPC API — if it does not need to be externally accessible, restrict it at the network perimeter. Check threat intelligence feeds and FortiSandbox logs for indicators of compromise consistent with path traversal attempts.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://thehackernews.com/2026/06/attackers-exploit-three-fortinet.html">Attackers Exploit Three Fortinet FortiSandbox Flaws, One Patched Last Week</a></p>
]]></content:encoded></item></channel></rss>