Cybersecurity · 46 views
Hackers exploit FortiClient EMS flaw to push infostealer malware
Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ.
AI Summary
Hackers are using an authentication bypass flaw (CVE‑2026‑35616) in FortiClient Enterprise Management Server to push a credential‑stealing malware called EKZ. The attackers disguise the malware as a legitimate Fortinet endpoint update. They deliver it through VPN scripting workflows that are managed by FortiClient. The vulnerability allows the malware to run without proper authentication, enabling the theft of user credentials. The attack demonstrates how a single server flaw can be leveraged to compromise endpoint security.
AI summaries can be wrong sometimes—always verify important details using the source article.
How AI & Automation are usedCoverage Context
More from Cybersecurity
Continue reading recent Cybersecurity coverage
- Cyber exec arrested in case allegedly tied to ShinyHunters hackersContinue reading
- ARTEX AI, Claude agents used in cyberattacks on South Korean banksContinue reading
- Criminal IP Introduces AITEM as the Next Evolution of Attack Surface ManagementContinue reading
- The Third-Party Agent Problem: Why Security Built for AI You Chose Misses the Agents You Didn'tContinue reading
Support HappeningNow
Independent AI-powered news analysis is reader-supported. Your contribution helps cover infrastructure, summaries, and continued platform development.
Support HappeningNow