<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"><channel><title>Cyber Resilience — Exposures News</title><link>https://security-resilience.ai/exposures/</link><description>Ranked exposures security news with our own read on each story — what it is, how confident we are, and what it means for you.</description><lastBuildDate>Wed, 12 Aug 2026 16:27:32 +0000</lastBuildDate><item><title>KEV: CVE-2025-68686 — Fortinet FortiOS (Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability)</title><link>https://security-resilience.ai/news/story/sr-1e730c30c2b8.html</link><guid isPermaLink="true">https://security-resilience.ai/news/story/sr-1e730c30c2b8.html</guid><category>confirmed</category><pubDate>Wed, 12 Aug 2026 16:27:32 +0000</pubDate><description>CISA added CVE-2025-68686 to KEV. It lets a remote unauthenticated attacker bypass a prior FortiOS symbolic-link patch via crafted HTTP requests, but only after filesystem-level compromise via another flaw. Patch if you run FortiOS yourself.</description></item></channel></rss>