Sober Thoughts. Drunk Posts.

Another Friday of Security News: AI SQLi, FortiMail Chaos, and the Same Old Human Denial

Another Friday of Security News: AI SQLi, FortiMail Chaos, and the Same Old Human Denial

Another zero-day patched just in time for no one to notice. And yes, I get it. You are busy. You are understaffed. Your vulnerability backlog is “strategic.” Your CISO is “sponsoring transformation.” Meanwhile, attackers are having a nice quiet week, poking at the soft parts of the internet like they are rifling through the last open bottle at the office party.

Today’s fun comes from a handful of top-tier horrors in that daily security roundup. If you want one story to clutch your pearls over, pick the FortiMail zero-day actively exploited (CVE-2026-104286). The gist: a critical-severity path traversal issue that can allow unauthenticated attackers to write arbitrary files on the underlying system. Unauthenticated. Arbitrary file writes. Critical. That is not “urgent action” territory. That is “wake up the on-call engineer, cancel the meeting, and start reading the emergency runbook” territory.

Path traversal: because filters are just vibes now

Path traversal has been a reliable criminal lifestyle choice for years, which means the real surprise is not the bug. The surprise is how frequently organizations treat exploited vulnerabilities like optional accessories. You know the routine: “We’ll validate exposure.” “We’re waiting on vendor guidance.” “We need approval.” Sure. And I’m waiting on my retirement plan to mature from “hope” into “actual budget.”

File write vulnerabilities are particularly nasty because they turn a remote flaw into something closer to hands-on control. Once an attacker can drop files where they shouldn’t, the rest is just picking the easiest next step. Persistence. Webshells. Lateral movement. The kind of chain-of-events that makes investigators pull ten tabs, four spreadsheets, and one bottle of scotch out of the same drawer.

AI agents firing SQLi at government targets – what could possibly go wrong

While FortiMail screams from the corner, the roundup also includes AI agents aimed at SQL injection against US and Canadian government sites. Yes, AI is involved. No, that does not make it magic. It just means the automation is more scalable, more adaptable, and less polite about finding the easiest injection point in your “customer portal” from 2019.

SQLi is still winning because so many apps still treat input like it is a suggestion. Attackers do not need novel exploitation. They need opportunity, volume, and weak validation. Welcome to modern security: the era where “secure coding” is a slide deck, not a practice.

What vendors and CISOs say versus what reality does

Vendors will publish advisories. CISOs will schedule risk reviews. Someone will ask if “the threat is confirmed.” Confirmed by what, exactly? By the attackers showing up to your environment and politely filling out an incident ticket?

If you are reading this and thinking, “We should patch,” congratulations, you are ahead of the curve. Now do the part that actually matters: verify exposure, apply the fix, hunt for exploitation indicators, and document ownership so the backlog stops breeding in the dark.

Pour yourself something. Not because you deserve it, but because you are going to need focus. And attackers? They do not take weekends off. Neither should your patching.

Tags :
Sober Thoughts. Drunk Posts.
Share This :