Hackers Exploit FortiClient EMS Flaw to Push Infostealer Malware
6 Articles
6 Articles
Hackers exploit FortiClient EMS flaw to push infostealer malware
Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ.
The failure in FortiClient EMS rekindled the alert among system administrators and security teams after confirming that cybercriminals are actively exploring the vulnerability CVE-2026-35616 to distribute specialized malware in the theft of credentials. The case draws attention to a worrying reason: the corporate infrastructure itself created to protect devices is being used as a platform to compromise users and entire networks. The discovery, r…
Hackers exploit FortiClient EMS vulnerability to push messages and steal malware.
Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer
Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver credential-stealing malware. "The campaign abused trusted endpoint management infrastructure to deliver malware across managed endpoints," Arctic Wolf said. "Threat actors disguised the credential stealer payload as a Fortinet endpoint
Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks
Fortinet rolled out hotfixes for the security defect in April, warning that it had been exploited in the wild as a zero-day and urging immediate patching. The post Critical FortiClient EMS Vulnerability Exploited in Fresh Attacks appeared first on SecurityWeek.
Coverage Details
Bias Distribution
- 100% of the sources are Center
Factuality
To view factuality data please Upgrade to Premium

