SIGNALInfrastructure Software·May 28, 2026, 5:25 PMSignal75Short term

Hackers exploit FortiClient EMS flaw to push infostealer malware

Source: BleepingComputer

Share
Hackers exploit FortiClient EMS flaw to push infostealer malware

Hackers are exploiting an authentication bypass vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS) to deliver an undocumented credential stealer called EKZ. [...]

Why this matters
Why now

The continuous discovery and exploitation of critical vulnerabilities in widely used enterprise software highlight an ongoing struggle between security providers and sophisticated threat actors.

Why it’s important

This incident underscores the persistent and evolving threat of supply chain attacks targeting critical infrastructure and data, impacting enterprise security and data integrity.

What changes

Enterprises using FortiClient EMS are now at heightened risk, requiring immediate patching and increased scrutiny of their network perimeters and endpoint security.

Winners
  • · Cybersecurity intelligence firms
  • · Security consultants
  • · Endpoint Detection and Response (EDR) providers
Losers
  • · Fortinet (vendor)
  • · Organizations using vulnerable FortiClient EMS
  • · End-users whose credentials are stolen
Second-order effects
Direct

Immediate patching and increased cybersecurity spending among affected organizations.

Second

Heightened scrutiny and calls for improved security-by-design from vendors of critical enterprise software.

Third

Potential for new regulations or industry standards for software supply chain security and vulnerability disclosure.

Editorial confidence: 90 / 100 · Structural impact: 55 / 100
Original report

This signal links to a primary source. Continuum Brief monitors and indexes it as part of the live intelligence stream — we do not republish source content.

Read at BleepingComputer
Tracked by The Continuum Brief · live intelligence network
Share
The Brief · Weekly Dispatch

Stay ahead of the systems reshaping markets.

By subscribing, you agree to receive updates from THE CONTINUUM BRIEF. You can unsubscribe at any time.