Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flaw
2026-05-31T08:51:45Z•adf7e6b8f2a258c710bea4c1b22a846332fbb1650187ba2a09a35f78345dc319
17 million devicesAdobe A/B testing abuseAnthropicCPS securityCVE-2026-35616ClarotyFROSTFortiClient EMSHumanixLinkedIn-themed phishingNetskopeSSD fingerprintingTrend Micro Apex One (exploited)VPN scriptingbotnet takedowndata localizationendpoint compromiseenterprise securityinfostealerlaw enforcementphishing
What happened
Weekly security roundup: Active exploitation of a FortiClient Enterprise Management Server (EMS) improper access-control bug (CVE-2026-35616) is being used to deliver a broad infostealer to enterprise endpoints via forged Fortinet endpoint updates and FortiClient-managed VPN scripting workflows. Dutch law enforcement and the NCSC disrupted a massive botnet (≈17 million infected devices) by taking down ~200 C2 servers. Researchers disclosed FROST, an SSD-timing website fingerprinting technique, and attackers abused Adobe’s A/B testing platform to deliver LinkedIn-themed phishing. Additional non
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- helpnetsecurity
- Record identifier
- adf7e6b8f2a258c710bea4c1b22a846332fbb1650187ba2a09a35f78345dc319
- Enrichment time
- 2026-05-31T08:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.