logo

FortiClient EMS, GitHub secrets, CISA breach: critical exploitation ongoing

ID: e762713f-f52d-5ed5-986d-bbcc5cf28ff4

STIX ID: report--e762713f-f52d-5ed5-986d-bbcc5cf28ff4

Feed Name: defend.network – Daily Threat Briefings

Threat Score
85/100

Date Published: 2026-05-29

Date Updated: 2026-05-29

...
...

This briefing highlights multiple high-priority threats: an actively exploited FortiClient EMS authentication bypass (CVE-2026-35616) used to deliver the EKZ credential stealer; a CISA contractor's public GitHub repository that exposed privileged AWS GovCloud keys and internal secrets; the BTMOB Android RAT spreading via phishing with a malware-builder service; over 4,300 fraudulent FIFA domains targeting 2026 World Cup buyers; and a critical authenticated RCE in Gogs — recommended actions include immediate patching, credential rotation, forensic audits, endpoint and mobile threat scanning, and blocking known malicious domains and IOCs.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.