FortiClient EMS Exploited via CVE-2026-35616 to Deliver EKZ Infostealer Disguised as a Fortinet Patch

In May 2026, threat actors exploited CVE-2026-35616, an improper access control vulnerability in FortiClient Endpoint Management Server (EMS), to bypass API authentication and execute privileged requests without credentials. Attackers leveraged trusted endpoint management infrastructure to push malicious PowerShell scripts disguised as legitimate Fortinet patches across managed endpoints. The campaign deployed EKZ Infostealer, a credential-stealing tool targeting Chrome, Firefox, and other browser credentials. The stealer extracts passwords, cookies, and autofill data, staging results locally before exfiltration via HTTP to threat-actor-controlled infrastructure. Threat actors accessed systems through Tor exit nodes, modified VPN configurations to enable script execution, and used FortiClient's own management pathways to distribute payloads fleet-wide without requiring individual endpoint compromises.

Pulse ID: 6a185cd579d639bcc6ece4ac
Pulse Link: https://otx.alienvault.com/pulse/6a185cd579d639bcc6ece4ac
Pulse Author: AlienVault
Created: 2026-05-28 15:18:45

Be advised, this data is unverified and should be considered preliminary. Always do further verification.

#Browser #Chrome #Cookies #CyberSecurity #Endpoint #FireFox #HTTP #InfoSec #InfoStealer #OTX #OpenThreatExchange #Password #Passwords #PowerShell #RAT #Rust #ScriptExecution #Troll #VPN #Vulnerability #Word #bot #AlienVault

LevelBlue - Open Threat Exchange

Learn about the latest cyber threats. Research, collaborate, and share threat intelligence in real time. Protect yourself and the community against today's emerging threats.

LevelBlue Open Threat Exchange
@mariejulien parce qu'ils adorent décider de nous priver de notre pouvoir et autonomie de décision pour se les garder et n'en rien faire ? #troll
Oh, look! #AMD decided to #troll #Linux users with #Vivado licensing changes, proving once again that open-source enthusiasts are merely pawns in their corporate chess game. 🎯🤦‍♂️ Meanwhile, AMD's PR department must be working overtime crafting excuses that no one will read. 📉
https://itsfoss.com/news/amd-vivado-bait-and-switch-on-linux-users/ #OpenSource #CorporateChess #HackerNews #ngated
AMD Pulls a Bait-and-Switch on Linux Users with Vivado Licensing Changes

Tells Linux users to either pay up or get stuck on an aging, unsupported version forever.

It's FOSS
@TechCrunch

Paid plans might make sense for
organizations (but then, aren't they already paying to have adverts inserted??), but makes little sense for "regular" users. I mean, unless I'm looking to be a more-amplified #troll (like the blue-checkmarks on #Twitter all seem to be), why would I pay to use any of those services?? It's not like my paying will stop them from productizing my information, so "why bother?"

#Meta
#MetaOne
#FaceBook
#WhatsApp
I celebrate #God and #Infinity, #faith and #science, with y'all and I don't care how you do it or don't do it. If you're a #FlatEarther, I know you're here just to #troll me so I don't worry about it LOL. #Guru #Himself says that there is no origin. But for this box no origin that can be explained.

Tonight's movie is Troll 2 (2025). It's streaming on Netflix.

I enjoyed the first one, Troll (2022), and this is a sequel. It was filmed in Norwegian and it's overdubbed into English.

Stars Ine Marie Wilmann, Kim Falck, Mads Sjøgård Pettersen, & Dennis Storhøi.

Written and directed by Roar Uthaug, who also directed Tomb Raider and The Wave.

Music by Johannes Ringen, who composed the music for over 40 Norwegian movies and shows.

https://www.netflix.com/title/81667085

#movies 🎬 #NowWatching #troll

Watch Troll 2 | Netflix Official Site

When a dangerous new troll unleashes devastation across their homeland, Nora, Andreas and Major Kris embark on their most perilous mission yet.

@masnick.com

I don't post on Twitter any more, read-only

But just as a *lot* of people cannot bring themselves to admit that #Trump is *not* some sort of god-tier strategist who is playing twelve-dimensional geopolitical chess in a way that is too subtle for the human mind to comprehend,

so a *lot* of peeple cannot bring themselves to admit that #Musk is just a petty little twenty-something 4Chan /pol shitposting edgelord most of the time

He's not an adult, people, he's a troll who just loves how many people Musk has hanging on his every word, searching for wisdom

Musk is a fucking #Troll, people

Catch a clue, laugh at him, and move on