Threat actors are actively exploiting three security vulnerabilities in Fortinet FortiSandbox, according to threat intelligence firm Defused Cyber. The flaws include CVE-2026-39813…
Active DirectoryAI-generated exploitcommand injectioncredential harvesting
A path traversal vulnerability in FortiSandbox JRPC API that could allow an unauthenticated attacker to bypass authentication via specially crafted HTTP requests.…
A critical flaw in Fortinet FortiClient EMS (CVE-2026-35616, CVSS score: 9.1) exploited by threat actors to deploy EKZ Stealer for credential harvesting…
A separate bucket-squatting vulnerability in Google Vertex AI Experiments that allowed cross-tenant code execution, model theft, and poisoning. Patched by Google in…
bucket squattingCross-TenantCVE-2026-2473Google Vertex AI
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a maximum-severity vulnerability affecting the Widget Factory Joomla Content Editor (JCE) to…
CVE-2019-0708 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…
Microsoft has formally disclosed a zero-day vulnerability in Microsoft Defender, codenamed RoguePlanet, and confirmed that a patch is in development. The flaw,…
CVE-2026-50656 was identified as a relevant cybersecurity entity in recently ingested reporting. This profile is generated so related cyber news, CVEs, malware,…