New malware campaign exploits FortiClient EMS flaw to steal browser credentials
A new malware campaign is exploiting a critical flaw in Fortinet's endpoint manager. Arctic Wolf says attackers are pushing fake Fortinet updates onto company devices. The payload runs silently through PowerShell and steals passwords from Chrome and Firefox. The fix is in FortiCl
A new malware campaign is exploiting a known critical flaw in Fortinet's endpoint manager. Security firm Arctic Wolf says attackers are using the vulnerability to bypass authentication and inject malicious scripts onto company devices. The payload disguises itself as an official Fortinet endpoint update. It runs silently through PowerShell, then steals saved passwords from Chrome and Firefox, including a technique that breaks Chrome's encrypted vault. The stolen credentials are sent back to attacker servers over plain web traffic. The vulnerability carries a critical severity rating of nine point one. It affects FortiClient EMS versions seven point four point five and seven point four point six. A patch is in version seven point four point seven. The flaw was first spotted being exploited back in March. CISA added it to its known exploited vulnerabilities catalog in April.