<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Fortinet on CuraSec</title><link>https://curasec.metacog.co.kr/tags/fortinet/</link><description>Recent content in Fortinet on CuraSec</description><generator>Hugo</generator><language>en-us</language><lastBuildDate>Tue, 11 Aug 2026 11:54:43 +0000</lastBuildDate><atom:link href="https://curasec.metacog.co.kr/tags/fortinet/index.xml" rel="self" type="application/rss+xml"/><item><title>Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws</title><link>https://curasec.metacog.co.kr/insights/2026-08-11-gunra-ransomware-exploits-fortinet-and-schneider-electric-fl/</link><pubDate>Tue, 11 Aug 2026 11:54:43 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-08-11-gunra-ransomware-exploits-fortinet-and-schneider-electric-fl/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> Fortinet and Schneider Electric products are named as actively exploited entry points in a joint US/South Korea advisory; audit Fortinet appliances and OT-facing Schneider devices for unpatched vulnerabilities and apply vendor patches immediately.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Joint government advisory signals published TTPs and IOCs are available; run a Gunra hunt across network and endpoint telemetry now, prioritizing environments in healthcare, financial services, or government sectors given the stated targeting pattern.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> A US/South Korea joint advisory naming specific critical-infrastructure sectors—healthcare, financial, government—warrants same-week action: confirm whether Fortinet or Schneider Electric products are in your estate and brief leadership before this appears in industry news.&lt;/li>
&lt;/ul></description></item><item><title>CVE-2026-25089: FortiSandbox unauthenticated RCE added to CISA KEV</title><link>https://curasec.metacog.co.kr/insights/2026-07-21-cve-2026-25089-fortisandbox-unauthenticated-command-injectio/</link><pubDate>Tue, 21 Jul 2026 12:43:35 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-21-cve-2026-25089-fortisandbox-unauthenticated-command-injectio/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> FortiSandbox is actively exploited per CISA KEV listing with a public PoC on GitHub; patch to the fixed version immediately and check for signs of compromise on any internet-facing FortiSandbox appliances.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> KEV listing plus public PoC means exploitation is likely underway; hunt for anomalous outbound connections or new processes spawned from FortiSandbox hosts since the PoC publication date, and check edge appliance logs for unauthenticated command-injection attempts.&lt;/li>
&lt;li>&lt;strong>Leader — Plan:&lt;/strong> KEV-listed Fortinet RCE warrants confirming whether FortiSandbox is in the environment and requesting patch status from the infrastructure team; brief on remediation timeline if deployed, given the active exploitation signal.&lt;/li>
&lt;li>&lt;strong>Signals:&lt;/strong> CVE-2026-25089 — CISA KEV: listed, EPSS 0.36, public PoC on GitHub&lt;/li>
&lt;/ul></description></item><item><title>CISA orders immediate patching of exploited Fortinet FortiSandbox flaws</title><link>https://curasec.metacog.co.kr/insights/2026-07-17-cisa-urges-immediate-action-on-actively-exploited-fortinet-f/</link><pubDate>Fri, 17 Jul 2026 12:06:10 +0000</pubDate><guid>https://curasec.metacog.co.kr/insights/2026-07-17-cisa-urges-immediate-action-on-actively-exploited-fortinet-f/</guid><description>&lt;ul>
&lt;li>&lt;strong>Engineer — Act:&lt;/strong> CISA KEV listing with active exploitation means patch FortiSandbox to the vendor-fixed version immediately — treat this as a critical-priority change with a days-level window, not weeks.&lt;/li>
&lt;li>&lt;strong>SOC/IR — Act:&lt;/strong> Active exploitation of FortiSandbox warrants an assume-breach sweep on any FortiSandbox instances in the estate; hunt for anomalous outbound connections or config changes on those appliances since the vulnerability window opened.&lt;/li>
&lt;li>&lt;strong>Leader — Act:&lt;/strong> Confirm whether FortiSandbox is deployed anywhere in your environment, verify the patching timeline with your engineering team, and be prepared to brief leadership if you are a federal agency facing CISA&amp;rsquo;s Sunday deadline.&lt;/li>
&lt;/ul></description></item></channel></rss>