Hackers exploit FortiClient EMS flaw to push infostealer malware | HappeningNow.news

Cybersecurity · 46 views

Hackers exploit FortiClient EMS flaw to push infostealer malware

Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ.

Source AI Summary Published May 28, 2026 Brief Under 1 min brief
Story intelligence
Coverage Single outlet Single-outlet story
Views 46 Community interest
Brief read Under 1 min brief 74 words

AI Summary

Hackers are using an authentication bypass flaw (CVE‑2026‑35616) in FortiClient Enterprise Management Server to push a credential‑stealing malware called EKZ. The attackers disguise the malware as a legitimate Fortinet endpoint update. They deliver it through VPN scripting workflows that are managed by FortiClient. The vulnerability allows the malware to run without proper authentication, enabling the theft of user credentials. The attack demonstrates how a single server flaw can be leveraged to compromise endpoint security.

AI summaries can be wrong sometimes—always verify important details using the source article.

How AI & Automation are used
Read original at BleepingComputer

Coverage Context

Part of Forticlient coverage 3 tracked stories

More from Cybersecurity

Continue reading recent Cybersecurity coverage

Support HappeningNow

Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.

Support HappeningNow

Report an issue with this page