logo

FortiClient EMS, Gogs RCE actively exploited; CISA GitHub leak exposes AWS keys

ID: 949c0439-ee6a-5791-8833-ed10f11478db

STIX ID: report--949c0439-ee6a-5791-8833-ed10f11478db

Feed Name: defend.network – Daily Threat Briefings

Threat Score
88/100

Date Published: 2026-05-28

Date Updated: 2026-05-29

...
...

This briefing reports multiple concurrent high-risk incidents: active exploitation of FortiClient EMS (CVE-2026-35616) to deploy the EKZ credential stealer, an unpatched Gogs RCE zero-day, public exposure of CISA-related AWS GovCloud credentials via a contractor's GitHub repo, a 4,300+ domain FIFA fraud campaign targeting World Cup attendees, and a Carnival data breach affecting ~6 million customers; recommended immediate actions include patching/isolation, credential rotation, log audits, and customer fraud/credit monitoring.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.