Attackers exploited this critical FortiClient EMS bug as a 0-day

2026-04-06T19:24:03Z452609740bbf2725ae632b3b9a203acbb9d60596803a72c90673a54bbca8c07a
0-dayaxioschatgptcisacitrix-netscalerdns-exfiltrationemergency-patchemsforticlientfortinetghostosocksin-the-wildkevlitellmmsi-malwarenpmopenaipassword-sprayingpypisource-code-leaksupply-chaintrivytrojanvidarwhatsapp

What happened

The feed highlights a wave of active, high-impact incidents: a critical FortiClient Enterprise Management Server (EMS) vulnerability was confirmed as a 0-day and reportedly exploited in the wild, prompting an emergency Fortinet patch and CISA KEV listing. Supply-chain attacks remain prolific — attackers trojanized popular packages and repos (notable incidents include a backdoored axios npm release, PyPI/Telnyx poisoning tied to the Trivy breach, and the LiteLLM/Trivy fallout), and the leaked “Claude Code” downloads were trojanized with credential stealers (Vidar) and GhostSocks. Other majors:

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
452609740bbf2725ae632b3b9a203acbb9d60596803a72c90673a54bbca8c07a
Enrichment time
2026-04-06T19:24:03Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.