Close Menu
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
What's Hot

Threat actors exploit critical flaw in FortiClient EMS to deploy credential stealer

A sneak peek at the new Siri app reveals Apple’s plans to tackle ChatGPT and more

RSI is the new AGI, but it’s just as difficult to identify

Facebook X (Twitter) Instagram
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
Facebook X (Twitter) Instagram
Fyself News
  • Home
  • Identity
  • Inventions
  • Future
  • Science
  • Startups
  • Spanish
Fyself News
Home » Threat actors exploit critical flaw in FortiClient EMS to deploy credential stealer
Identity

Threat actors exploit critical flaw in FortiClient EMS to deploy credential stealer

By May 28, 2026No Comments2 Mins Read
Share Facebook Twitter Pinterest Telegram LinkedIn Tumblr Email Copy Link
Follow Us
Google News Flipboard
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link

Rabi LakshmananMay 28, 2026Vulnerabilities / Endpoint Security

Attackers continue to exploit patched critical security flaws affecting FortiClient Endpoint Management Server (EMS) deployments to distribute credential-stealing malware.

“This campaign exploited trusted endpoint management infrastructure to distribute malware across managed endpoints,” Arctic Wolf said. “Threat actors disguised the credential-stealing payload as a Fortinet endpoint update and silently executed the malicious executable through PowerShell.”

This activity, observed by a cybersecurity firm in May 2026, involved exploitation of CVE-2026-35616 (CVSS score: 9.1), a critical pre-authentication API access bypass leading to privilege escalation. This issue has been resolved by FortiNet in FortiClient EMS 7.4.7 and later.

A successful compromise allows the attacker to modify configurations to defer firmware upgrade notifications, or modify remote access profile configurations and endpoint policies to inject malicious scripts to run on endpoint devices.

“The observed execution patterns suggest that the attacker was using FortiClient’s own management channels to push malicious PowerShell commands to managed endpoints in a manner that resembles legitimate management operations,” said Arctic Wolf.

“Once the attacker gained a route to modify the EMS management configuration, all managed endpoints became potential execution targets without requiring a separate compromise path to each device.”

Additionally, this attack was found to exploit a legitimate executable file associated with FortiClient, ‘fortitray.exe’, and use ‘cmd.exe’ to launch a .cmd script file. .cmd scripts are designed to call Base64-encoded PowerShell scripts. This script downloads a malicious payload, executes it, and extracts the result to “83.138.53”.[.]110″ via HTTP POST request.

The executable named “FortiEndpoint_Patch.exe” disguises itself as an update, but is actually a previously unreported Windows information stealer that can collect sensitive data from Chromium and Gecko-based browsers, including passwords, cookies, credit card information, and autofill details such as addresses and phone numbers.

The data is written to a log file and saved in the ProgramData directory. It is worth noting that the stealer does not have network-based stealing capabilities. It is a PowerShell script that sends the captured data to attacker-controlled infrastructure.

“Bypassing API authentication and interacting with EMS functionality in a privileged context, attackers were able to modify management configurations and execute malicious scripts on managed endpoints,” said Arctic Wolf.

“Session cookies and stored browser credentials can provide an attacker with subsequent access to cloud services, internal applications, and other authenticated resources, including when session reuse bypasses MFA prompts.”


Source link

#BlockchainIdentity #Cybersecurity #DataProtection #DigitalEthics #DigitalIdentity #Privacy
Follow on Google News Follow on Flipboard
Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Previous ArticleA sneak peek at the new Siri app reveals Apple’s plans to tackle ChatGPT and more

Related Posts

Microsoft condemns zero-day release while GitHub Researcher account deletion

May 28, 2026

Claude Security Plugin, Azure Priv-Esc, Kali365 MFA Bypass, FIFA Scams +15 More

May 28, 2026

Enterprise AI risks are concentrated in a small group of AI “power users”

May 28, 2026
Add A Comment
Leave A Reply Cancel Reply

Latest Posts

Threat actors exploit critical flaw in FortiClient EMS to deploy credential stealer

A sneak peek at the new Siri app reveals Apple’s plans to tackle ChatGPT and more

RSI is the new AGI, but it’s just as difficult to identify

Microsoft condemns zero-day release while GitHub Researcher account deletion

Trending Posts

Subscribe to News

Subscribe to our newsletter and never miss our latest news

Please enable JavaScript in your browser to complete this form.
Loading

Welcome to Fyself News, your go-to platform for the latest in tech, startups, inventions, sustainability, and fintech! We are a passionate team of enthusiasts committed to bringing you timely, insightful, and accurate information on the most pressing developments across these industries. Whether you’re an entrepreneur, investor, or just someone curious about the future of technology and innovation, Fyself News has something for you.

Castilla-La Mancha Ignites Innovation: fiveclmsummit Redefines Tech Future

Local Power, Health Innovation: Alcolea de Calatrava Boosts FiveCLM PoC with Community Engagement

The Future of Digital Twins in Healthcare: From Virtual Replicas to Personalized Medical Models

Human Digital Twins: The Next Tech Frontier Set to Transform Healthcare and Beyond

Facebook X (Twitter) Instagram Pinterest YouTube
  • Home
  • About Us
  • Advertise with Us
  • Contact Us
  • DMCA
  • Privacy Policy
  • Terms & Conditions
  • User-Submitted Posts
© 2026 news.fyself. Designed by by fyself.

Type above and press Enter to search. Press Esc to cancel.