- Critical pre-authentication API access bypass in FortiClient EMS 7.4.5 and 7.4.6, actively exploited in the wild
- Related critical FortiClient EMS vulnerability reported last week, also actively exploited
ThreatNoir Morning Brief — April 6
Morning Review in IT Security — April 6, 2026
The cybersecurity landscape continues to evolve with critical vulnerabilities being actively exploited, supply chain threats targeting popular development tools, and malicious software being openly sold on underground forums. Today's review covers urgent patching requirements, automated credential theft campaigns, and compromised infrastructure affecting developers worldwide.
New FortiClient EMS Flaw Exploited in Attacks, Emergency Patch Released
Fortinet has released an emergency weekend security update addressing a critical vulnerability in FortiClient Enterprise Management Server (EMS) that is currently being exploited in active attacks. The vulnerability, tracked as CVE-2026-35616, requires immediate patching to prevent unauthorized access and potential compromise of managed endpoints. Additionally, CVE-2026-21643 has been identified as a related concern requiring attention from affected organizations. Source: New FortiClient EMS flaw exploited in attacks, emergency patch released
Hackers Exploit React2Shell in Automated Credential Theft Campaign
Threat actors are conducting a large-scale automated campaign exploiting the React2Shell vulnerability (CVE-2025-55182) to steal credentials from vulnerable Next.js applications. The campaign leverages the NEXUS Listener malware to harvest credentials at scale, targeting organizations that have not yet patched their Next.js deployments. This supply chain attack demonstrates the critical importance of maintaining current security patches across development frameworks and dependencies. Source: Hackers exploit React2Shell in automated credential theft campaign
ILSpy WordPress Domain Compromised to Deliver Malware
The ILSpy WordPress domain was compromised approximately two hours ago at 01:22 EST to deliver malware to unsuspecting users. The compromised domain (ilspy.wordpress.com) was redirecting download attempts away from the legitimate GitHub repository toward malicious payloads before returning a 502 error. This incident highlights the vulnerability of legitimate development tool distribution channels to compromise and underscores the need for developers to verify download sources and validate integrity checksums. Source: ILSpy WordPress domain compromise
Threat Actor JINKUSU Selling EvilNote Source Code
Threat actor JINKUSU is actively selling the complete source code for EvilNote, a bulk email sending tool, for $500 on underground markets. The EvilNote tool enables users to conduct mass email campaigns using their own SMTP servers with features including recipient list management, email templates, and message personalization. The availability of this malicious tool's source code for sale significantly increases the threat landscape for phishing and spam campaigns targeting organizations globally. Source: Threat actor JINKUSU selling EvilNote source code
Organizations should prioritize patching the critical Fortinet and React2Shell vulnerabilities while maintaining heightened vigilance regarding software download sources and email security controls. The combination of actively exploited vulnerabilities, compromised development infrastructure, and readily available malicious tools creates an elevated threat environment requiring immediate defensive action.
Sources & IOCs
Source articles and extracted indicators (defanged where appropriate).
- React2Shell vulnerability exploited in Next.js applications for credential theft
- NEXUS ListenerC2 framework used to exfiltrate harvested credentials and secrets via HTTP port 8080
ilspy.wordpress.comILSpy WordPress domain compromised to deliver malware
- EvilNoteBulk email sending tool with SMTP spoofing capabilities, source code being sold by JINKUSU
evilnote.suEvilNote malware domain associated with bulk email tool