Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flaw

2026-05-31T08:51:45Zadf7e6b8f2a258c710bea4c1b22a846332fbb1650187ba2a09a35f78345dc319
17 million devicesAdobe A/B testing abuseAnthropicCPS securityCVE-2026-35616ClarotyFROSTFortiClient EMSHumanixLinkedIn-themed phishingNetskopeSSD fingerprintingTrend Micro Apex One (exploited)VPN scriptingbotnet takedowndata localizationendpoint compromiseenterprise securityinfostealerlaw enforcementphishing

What happened

Weekly security roundup: Active exploitation of a FortiClient Enterprise Management Server (EMS) improper access-control bug (CVE-2026-35616) is being used to deliver a broad infostealer to enterprise endpoints via forged Fortinet endpoint updates and FortiClient-managed VPN scripting workflows. Dutch law enforcement and the NCSC disrupted a massive botnet (≈17 million infected devices) by taking down ~200 C2 servers. Researchers disclosed FROST, an SSD-timing website fingerprinting technique, and attackers abused Adobe’s A/B testing platform to deliver LinkedIn-themed phishing. Additional non

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
helpnetsecurity
Record identifier
adf7e6b8f2a258c710bea4c1b22a846332fbb1650187ba2a09a35f78345dc319
Enrichment time
2026-05-31T08:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.