AUTO-UPDATED

Week in review: Infostealer dropped via FortiClient EMS flaw, exploited Trend Micro Apex One flaw

Recent cybersecurity reports highlight critical vulnerabilities in FortiClient EMS and Trend Micro Apex One, alongside a surge in AI-driven threats and data breaches impacting major global organizations.

Key Points

  • Attackers are exploiting a FortiClient EMS vulnerability (CVE-2026-35616) to deploy infostealers on enterprise networks.
  • Trend Micro confirmed active zero-day exploitation of a directory path traversal flaw (CVE-2026-34926) in its Apex One security platform.
  • Microsoft issued a patch for a high-severity remote code execution vulnerability (CVE-2026-45659) affecting multiple SharePoint Server editions.
  • Data breaches at 7-Eleven and Carnival Corporation exposed the personal information of approximately 185,000 and 6 million customers, respectively.
  • Research from Cisco indicates that current safety benchmarks fail to account for multi-turn AI attacks that reframe prompts to bypass model restrictions.

Why it Matters

The rapid integration of AI agents into enterprise workflows has created a new, often unmanaged layer of privileged access that attackers are increasingly targeting. As threat actors leverage AI to accelerate vulnerability discovery, organizations must shift toward risk-based management and stricter governance of both human and machine identities.
Help Net Security Published by Help Net Security
Read original