Close Menu
Tech Nova Mindset – Empower Innovation and Forward Thinking

    Subscribe to Updates

    Get the latest creative news from FooBar about art, design and business.

    What's Hot

    Why I designed Charlotte Tilbury Beauty as a technology company

    June 15, 2026

    Nintendo’s Switch 2 price is increasing to AU$769.95 come Sep 1 — which makes this AU$629 deal for EOFY all the more tempting

    June 15, 2026

    Here's what Jeff Bezos' new startup Prometheus will do

    June 15, 2026
    Facebook X (Twitter) Instagram
    Trending
    • Why I designed Charlotte Tilbury Beauty as a technology company
    • Nintendo’s Switch 2 price is increasing to AU$769.95 come Sep 1 — which makes this AU$629 deal for EOFY all the more tempting
    • Here's what Jeff Bezos' new startup Prometheus will do
    • Berlin’s Qorelo raises €3 million five months after launch to tackle SAP’s 2027 transformation crunch
    • Chinese Drivers Are Using Tiny Plastic Heads to Fool Tesla’s Autopilot Safeguards
    • 5 new Netflix movies and shows you need to stream this week (June 15-21)
    • Scientists Investigate Strange Rumbling Beneath Utah
    • What superstar founders Kirsten Tibballs, Shaun Wilson and Carla Oates do differently
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    • Home
    • Gadgets
    • Reviews
    • Tech News
    • Future Tech
    • AI & Robotics
    • How-To Guides
    • More
      • Cybersecurity
      • Startups & Innovation
    Tech Nova Mindset – Empower Innovation and Forward Thinking
    Home»Cybersecurity»New infostealer reaches enterprise devices through FortiClient EMS vulnerability
    Cybersecurity

    New infostealer reaches enterprise devices through FortiClient EMS vulnerability

    kirklandc008@gmail.comBy kirklandc008@gmail.comMay 29, 2026No Comments3 Mins Read
    Facebook Twitter Pinterest LinkedIn Tumblr Email
    New infostealer reaches enterprise devices through FortiClient EMS vulnerability
    Share
    Facebook Twitter LinkedIn Pinterest Email

    Attackers are delivering a broad-spectrum infostealer to enterprise computers by exploiting a known vulnerability (CVE-2026-35616) in FortiClient Enterprise Management Server (EMS).

    “The [malicious] payload was presented as a Fortinet endpoint update and executed through FortiClient-managed VPN scripting workflows,” Arctic Wold researchers noted.

    About CVE-2026-35616

    CVE-2026-35616 is an improper access control vulnerability vulnerability in FortiClient EMS, a centralized management platform through which IT admins deploy, configure, and monitor FortiClient endpoint security software across all devices in an organization’s network.

    The vulnerability was publicly disclosed in early April by Fortinet, after Defused Cyber spotted it being exploited as a zero-day. Details about the attacks were unavailable at the time.

    The attacks observed by Arctic Wolf happened in May 2026.

    The attack campaign

    CVE-2026-35616 allows attackers to bypass API authentication and authorization.

    “When specially crafted HTTP requests are sent to certain FortiClient EMS endpoints without valid credentials, the requests are processed as if they were legitimate administrative actions. From that point onward, threat actors can interact with EMS functionality that would normally require administrative access,” Arctic Wolf researchers explained.

    “Several follow-on actions were performed by the threat actor, such as updating the remind_upgrade_after configuration to defer firmware upgrade reminders, as well as editing the Remote Access Profile configuration and endpoint policy to insert a malicious script for execution on endpoint devices.

    The malicious payload (FortiEndpoint_Patch.exe) delivered to target endpoints is a MinGW-compiled Windows credential stealer the researchers dubbed EKZ Infostealer.

    The malware is capable of harvesting session cookies, credentials and autofill data stored by browsers and software using the Chromium and Gecko engines: Google Chrome, Microsoft Edge, Opera, Brave, Vivaldi, Mozilla’s Firefox (and its Thunderbird email client), the Tor Browser, LibreWolf, Pale Moon, and others.

    “While not directly observed in this infection chain, several other malicious samples were recovered from the threat-actor-controlled HTTP server,” the researchers noted. Those samples had file names like FortiEndpoint_Patch.2.4.9.zip, Microsoftr Windowsr Operating System-Installer.exe, and fil_api_ms_win_crt_apibase_l1_1_0.dll.

    Investigation and remediation

    Arctic Wolf shared known indicators of compromised tied to this attack campaign and has urged organizations using FortiClient EMS to check its log for specific headers showing certificate errors, new accounts, suspicious/unfamiliar logins, and execution-enabling configuration changes.

    The researchers also warned that the stolen cookies and credentials may be used by attackers for “follow-on access to cloud services, internal applications, and other authenticated resources”.

    If evidence of compromise is found, a thorough remediation process must include changing affected passwords and revoking active sessions across all potentially affected services. Depending on the autofill data saved by the browsers, further action may be needed (e.g., cancelling and reissuing payment cards whose details were stored).

    Subscribe to our breaking news e-mail alert to never miss out on the latest breaches, vulnerabilities and cybersecurity threats. Subscribe here!

    devices EMS enterprise FortiClient infostealer reaches vulnerability
    Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
    kirklandc008@gmail.com
    • Website

    Related Posts

    Proving what a military AI model will do is the real problem

    June 15, 2026

    Phone battery draining fast? Malware is one of 8 possible factors – how to tell for sure

    June 15, 2026

    NASA’s X-59 Reaches Speed And Altitude Milestones Ahead Of First Quiet Supersonic Flights

    June 14, 2026
    Leave A Reply Cancel Reply

    Top Posts

    Google DeepMind Plans to Track AGI Progress With These 10 Traits of General Intelligence

    March 21, 20263 Views

    The AirPods 4 and Lego’s brick-ified Grogu are our favorite deals this week

    October 12, 20253 Views

    Anthropic’s Mythos AI Uncovered Serious Security Holes in Every Major OS and Browser

    April 10, 20262 Views
    Stay In Touch
    • Facebook
    • YouTube
    • TikTok
    • WhatsApp
    • Twitter
    • Instagram
    Latest Reviews

    Subscribe to Updates

    Get the latest tech news from FooBar about tech, design and biz.

    Recent Posts
    • Why I designed Charlotte Tilbury Beauty as a technology company
    • Nintendo’s Switch 2 price is increasing to AU$769.95 come Sep 1 — which makes this AU$629 deal for EOFY all the more tempting
    • Here's what Jeff Bezos' new startup Prometheus will do
    • Berlin’s Qorelo raises €3 million five months after launch to tackle SAP’s 2027 transformation crunch
    • Chinese Drivers Are Using Tiny Plastic Heads to Fool Tesla’s Autopilot Safeguards

    Why I designed Charlotte Tilbury Beauty as a technology company

    June 15, 2026

    Nintendo’s Switch 2 price is increasing to AU$769.95 come Sep 1 — which makes this AU$629 deal for EOFY all the more tempting

    June 15, 2026

    Here's what Jeff Bezos' new startup Prometheus will do

    June 15, 2026

    Berlin’s Qorelo raises €3 million five months after launch to tackle SAP’s 2027 transformation crunch

    June 15, 2026
    Facebook X (Twitter) Instagram Pinterest
    • About Us
    • Contact Us
    • Privacy Policy
    • Terms and Conditions
    • Disclaimer
    © 2026 TechNovaMindset. Designed by By Pro.

    Type above and press Enter to search. Press Esc to cancel.