discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.
Featured

Hackers exploit FortiClient EMS flaw to push infostealer malware

Hackers are abusing a FortiClient EMS auth bypass to run scripts that install EKZ, a credential-stealing malware, on endpoints.

By Bill Toulas·May 28·bleepingcomputer.com·2 min read

Intelligence analysis by GPT-5.4 Mini

Hackers exploit FortiClient EMS flaw to push infostealer malware
Image: bleepingcomputer.com

Attackers are using CVE-2026-35616 in FortiClient EMS to make managed endpoints run malicious update scripts. Arctic Wolf says the campaign drops EKZ, an infostealer that steals browser data and sends it to attacker infrastructure.

Why it matters

This is an actively exploited flaw in a widely used enterprise product, so exposed EMS systems can become a direct launch point for malware. It also shows how attackers are turning trusted management workflows into an execution path for credential theft.

A company’s security tool was supposed to help computers stay safe. Hackers found a weak spot and used it like a fake key to make the tool run their own code.

That code quietly installed a thief program called EKZ. It looked for saved passwords, cookies, and other private details in web browsers, then sent the stolen data to the hackers.

It is like a burglar sneaking in by wearing a delivery uniform and convincing the front desk to open the door. Security teams now need to watch for strange log messages and sudden changes in the tool’s settings.

Analysis

What happened

Hackers are exploiting CVE-2026-35616 in FortiClient Enterprise Management Server, an authentication bypass and access-control flaw that lets unauthenticated attackers execute commands through crafted requests. Fortinet said in early April that the bug was being exploited and released emergency hotfixes for versions 7.4.5 and 7.4.6.

How the attack works

According to Arctic Wolf, the attack starts by abusing endpoint APIs to perform administrative actions without logging in. The attacker then changes EMS configuration and VPN policies so that FortiClient-managed workflows launch malicious scripts. After endpoints establish an IPsec tunnel to a FortiGate firewall, the legitimate fortitray.exe process starts batch files through Command Prompt. Those scripts run base64-encoded PowerShell that downloads malware disguised as a Fortinet patch, executes it quietly, and sends stolen data to an attacker-controlled VPS over HTTP.

What EKZ does

The payload, tracked as EKZ Infostealer, is a credential stealer with standard browser-theft features. Arctic Wolf says it targets Chromium-based browsers and Firefox, extracts stored data into text files, and bypasses encrypted password protections. It steals credentials, credit card details, addresses, phone numbers, and cookies that can be used to access accounts protected by multi-factor authentication.

What defenders should look for

Arctic Wolf says one clue is the log line “Certificate not found in request header.” In testing, that was followed seconds later by a certificate update message. The researchers recommend watching for certificate-authentication anomalies, unexpected changes to Remote Access Profile settings, new accounts, unfamiliar login origins such as Tor or VPS IPs, and other suspicious administrative changes.

Key points

  • Hackers are exploiting CVE-2026-35616 in FortiClient EMS to run commands without authentication.
  • Arctic Wolf says the attack chain uses FortiClient-managed VPN scripting to launch malicious PowerShell.
  • The payload is EKZ Infostealer, which steals browser data, credentials, cookies, and payment details.
  • Fortinet issued emergency hotfixes in April for versions 7.4.5 and 7.4.6 after confirming exploitation.
  • Defenders are told to watch for certificate-authentication errors, remote profile changes, and suspicious admin activity.

Originally reported at

bleepingcomputer.com

Discernion covers the story. Read the full piece at the source.

Tagssecuritymalwarevulnerabilityfortinetinfostealerenterprise-security

Author

Bill Toulas

Intelligence analysis by

GPT-5.4 Mini

Published

May 28, 2026

Source

bleepingcomputer.com

Share

Topics

securitymalwarevulnerabilityfortinetinfostealerenterprise-security

Related

More from this desk

Jul 29·thehackernews.com

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

A maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, allows unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726, impacts all versions of the project before version 3.16.3.

Jul 29·thehackernews.com

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom patched three critical VMware vulnerabilities including two CVSS 9.8 flaws in vCenter for auth bypass and arbitrary code execution, plus a VMXNET3 flaw enabling VM escape.

Jul 29·bleepingcomputer.com

Hackers target over 30 Minnesota water utilities in coordinated OT attack

Hackers targeted over 30 Minnesota water utilities in a coordinated cyberattack, disrupting operational technology systems. The Minnesota IT Services agency is working with federal and state partners to investigate and fortify the security of the state's critical infrastr…

Jul 29·bleepingcomputer.com

Your AI Agents Are Guessing at Scale: Permissions Decide the Damage

AI agents are designed to improvise, but this can lead to security risks when paired with broad access. Teams struggle to apply least privilege to agents, and traditional security models break down. Token Security offers a solution to discover and map risky access, and au…