Toggle light / dark theme

Get the latest international news and world events from around the world.

Log in for authorized contributors

Threat Actors Exploit Critical FortiClient EMS Flaw to Deploy Credential Stealer

Threat actors are continuing to exploit a critical, now-patched security flaw impacting FortiClient Endpoint Management Server (EMS) deployments to deliver credential-stealing malware.

“The campaign abused trusted endpoint management infrastructure to deliver malware across managed endpoints,” Arctic Wolf said. “Threat actors disguised the credential stealer payload as a Fortinet endpoint update, silently executing the malicious executable through PowerShell.”

The activity, observed by the cybersecurity company in May 2026, involves the exploitation of CVE-2026–35616 (CVSS score: 9.1), a critical pre-authentication API access bypass leading to privilege escalation. The issue was addressed by Fortinet in FortiClient EMS 7.4.7 and later.

GreyVibe hackers use ChatGPT, Gemini to power cyberattacks

A likely Russian threat group tracked as GreyVibe has been using AI-generated lures and a rich set of custom malware tools to target entities in the military, government, civilian, and business sectors.

The cyberespionage campaign has been active since at least August 2025 and appears to align with Russian state interests, although researchers cannot confidently classify it as a nation-state operation.

Cybersecurity company WithSecure discovered the activity in January this year and determined that its focus is on Ukrainian or Ukraine-related organizations.

BTMOB Android malware service generates custom phishing payloads

An Android remote access trojan named BTMOB is offered to cybercriminals with a builder interface for generating malware payloads tailored to phishing lures.

The malware provides a wide set of features that includes stealing specific data, intercepting financial transactions, capturing screenshots, and remote control capabilities.

Cybersecurity company ESET says that BTMOB is openly advertised on the clearweb and operates as a malware-as-a-service (MaaS) platform. The APK builder included in the offer provides easy customization of the payload without any need to code.

NASA draws on industry for Mars telecommunications network

On Thursday, NASA issued a Request for Proposal (RFP), seeking industry collaboration for the Mars Telecommunications Network.

Reliable, high bandwidth communications are necessary to relay science data, high-definition imagery, and critical information during Mars missions. The network will use high-performance Mars telecommunications orbiters at the red planet to support future surface, orbital, and human exploration.

This RFP builds on a draft released April 2, as well as insights gathered during the accompanying industry day at NASA’s Goddard Space Flight Center in Greenbelt, Maryland, where commercial partners provided feedback on agency objectives for the Mars Telecommunications Network.

Blind ambition: AI agents can turn tasks into digital disasters

Computer scientists at UC Riverside have identified troubling flaws in a new generation of artificial intelligence (AI) agents designed to take over routine computer chores while users are away—sorting emails, organizing files, analyzing data, and handling other everyday digital tasks that might otherwise consume hours.

The researchers found that the automated agents can become dangerously fixated on completing assignments without recognizing when their actions are harmful, contradictory, or simply irrational.

The team compared these behaviors to those of Mr. Magoo, the famously near-sighted cartoon character popular in the 1960s, who stumbled through hazardous situations while insisting everything was under control.

/* */