Attackers exploited this critical FortiClient EMS bug as a 0-day
2026-04-06T19:24:03Z•452609740bbf2725ae632b3b9a203acbb9d60596803a72c90673a54bbca8c07a
0-dayaxioschatgptcisacitrix-netscalerdns-exfiltrationemergency-patchemsforticlientfortinetghostosocksin-the-wildkevlitellmmsi-malwarenpmopenaipassword-sprayingpypisource-code-leaksupply-chaintrivytrojanvidarwhatsapp
What happened
The feed highlights a wave of active, high-impact incidents: a critical FortiClient Enterprise Management Server (EMS) vulnerability was confirmed as a 0-day and reportedly exploited in the wild, prompting an emergency Fortinet patch and CISA KEV listing. Supply-chain attacks remain prolific — attackers trojanized popular packages and repos (notable incidents include a backdoored axios npm release, PyPI/Telnyx poisoning tied to the Trivy breach, and the LiteLLM/Trivy fallout), and the leaked “Claude Code” downloads were trojanized with credential stealers (Vidar) and GhostSocks. Other majors:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- 452609740bbf2725ae632b3b9a203acbb9d60596803a72c90673a54bbca8c07a
- Enrichment time
- 2026-04-06T19:24:03Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.