The appliance that inspects your malware is the way in

The news: CISA flagged two FortiSandbox command-injection flaws as actively exploited on July 16, both rated 9.1. Attackers run unauthenticated code on the box through crafted HTTP requests, and the federal deadline was Sunday.

Why it matters: FortiSandbox sits inside your trust chain, receiving files to detonate and touching firewalls, mail, and endpoints. A foothold there is a quiet, trusted vantage point most detection assumes is safe. It is the lesson of every edge-appliance breach this year: the security box is the target.

What to do: Confirm it runs 4.4.9 or 5.0.6 this morning, and treat anything behind as exposed.

A Chinese open-weights model just narrowed the gap to two points

Moonshot released Kimi K3 on July 16, an open-weights model with a million-token context window. On the Artificial Analysis index it scores 57.1, near GPT-5.6's 58.9 and Fable 5's 59.9. That is the smallest gap yet between a self-hostable model and the closed frontier. Full weights drop July 27, so your team can benchmark it on a real task first. If data residency or per-token cost drives your model choice, price the tradeoff this week.

The attacker inside Hugging Face was an AI agent

Hugging Face disclosed on July 16 that an intruder reached production systems through a malicious dataset. What is new: an AI agent ran the intrusion itself, logging 17,000 actions as it stole credentials and spread. Impact stayed limited to internal datasets and a few service credentials. The story is the new shape of the threat, not the blast radius. If you load untrusted datasets with code-execution rights, sandbox the loaders and alert on action bursts.

Watch This

China's AI-agent rules took effect July 15, the first anywhere written for autonomous agents as a category. They require a tiered authorization structure: an agent's power scales with the stakes of its action. Western equivalents will follow within a year. The audit starts with one question: which agents act without a human, and who approved it?

This week, DoGood network members are writing down which AI agents in their stack can act without a human, and who owns the sign-off. If you run IT or security at a $100M+ company, that inventory is the conversation your peers are already having.

Know a CIO who needs this? Forward it and they can subscribe here.

Enterprise IT leader at a $100M+ company? Apply to join DoGood.

Keep Reading