SECURITYBLEEPING COMPUTER
Hackers exploit FortiClient EMS flaw to push infostealer malware
Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ.
Mentioned
Related Signal
Adjacent reporting
- cPanel’s authentication bypass bug is being exploited in the wild, CISA warns
- SHub macOS infostealer variant spoofs Apple security updates
- The Internet Is Falling Down- CPanel/WHM Authentication Bypass CVE-2026-41940
- Fortinet Issues Emergency Patch for FortiClient Zero-Day
- Yet Another Way to Bypass Google Chrome's Encryption Protection
- Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer