Hackers exploit FortiClient EMS flaw to push infostealer malware
ID: aefd8edf-bab1-59f0-acae-6a117803b9d1
STIX ID: report--aefd8edf-bab1-59f0-acae-6a117803b9d1
Feed Name: Bleeping Computer
Attackers are actively exploiting CVE-2026-35616 in FortiClient EMS to push an EKZ infostealer by abusing unauthenticated endpoint APIs and VPN scripting workflows; the payload runs via fortitray/Command Prompt and PowerShell, harvests browser-stored credentials, cards, and cookies, and exfiltrates data to an attacker-controlled VPS. Fortinet released emergency hotfixes, CISA ordered federal mitigations, and observers reported thousands of exposed EMS instances, with detection guidance noting log strings like "Certificate not found in request header."
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
