<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Sandbox on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/sandbox/</link><description>Recent content in Sandbox on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Tue, 16 Jun 2026 18:27:12 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/sandbox/index.xml" rel="self" type="application/rss+xml"/><item><title>Critical Fortinet FortiSandbox Bugs Actively Exploited</title><link>https://zxcloudsecurity.co.uk/posts/fortinet-fortisandbox-critical-vulnerabilities-actively-exploited/</link><pubDate>Tue, 16 Jun 2026 18:27:12 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/fortinet-fortisandbox-critical-vulnerabilities-actively-exploited/</guid><description>Three critical Fortinet FortiSandbox vulnerabilities are being actively exploited. Patches are available — upgrade immediately to protect your environment.</description><content:encoded><![CDATA[<p>🔴 <strong>Critical</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/security/2026/06/16/three-critical-fortinet-sandbox-bugs-splattered-by-unknown-attackers/5256461">The Register — Security</a></p>
<hr>
<p>Three critical vulnerabilities in Fortinet&rsquo;s FortiSandbox product have been actively exploited by unknown attackers in the wild. Patches are available for all three flaws, making urgent remediation essential for any organisation running FortiSandbox. The active exploitation status significantly raises the risk, as attackers are already leveraging these weaknesses before many organisations have had a chance to respond.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> If FortiSandbox is deployed anywhere in your environment — on-premises or integrated with cloud workloads — prioritise patching immediately and review logs for indicators of compromise prior to the patch window. Isolate affected appliances from the network if an immediate upgrade is not possible.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/security/2026/06/16/three-critical-fortinet-sandbox-bugs-splattered-by-unknown-attackers/5256461">Three critical Fortinet sandbox bugs splattered by unknown attackers</a></p>
]]></content:encoded></item><item><title>Homebrew 6.0: New Security Sandbox &amp; Supply Chain Fixes</title><link>https://zxcloudsecurity.co.uk/posts/homebrew-6-0-security-sandbox-supply-chain-improvements/</link><pubDate>Wed, 17 Jun 2026 13:31:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/homebrew-6-0-security-sandbox-supply-chain-improvements/</guid><description>Homebrew 6.0 introduces a Linux sandbox and new security mechanisms to reduce supply chain risk in one of the most widely used developer package managers.</description><content:encoded><![CDATA[<p>🟡 <strong>Medium</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/devops/2026/06/17/homebrew-60-released-with-new-security-mechanism-linux-sandbox-and-more/5257570">The Register — Security</a></p>
<hr>
<p>Homebrew 6.0 has been released with a new security mechanism and a Linux sandbox, addressing longstanding concerns about the package manager&rsquo;s vulnerability to supply chain attacks. The project lead noted that Homebrew has historically been more exposed than npm, making these improvements significant for developer environments. The update represents a meaningful step forward in hardening a widely used tool in macOS and Linux development workflows.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review your organisation&rsquo;s use of Homebrew in developer or CI/CD environments and plan an upgrade to 6.0 to take advantage of the new sandbox and security controls. Assess whether Homebrew installations on engineering endpoints or build pipelines are governed by policy, as package managers remain a high-value supply chain attack vector.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/devops/2026/06/17/homebrew-60-released-with-new-security-mechanism-linux-sandbox-and-more/5257570">Homebrew 6.0 released with new security mechanism, Linux sandbox and more</a></p>
]]></content:encoded></item></channel></rss>