September 16, 2026
- VectraRAT packages a Windows implant, C2 and operator panel from $250 per month. SOCRadar describes a from-scratch MaaS platform with hidden-desktop control, keylogging, clipboard hijacking, browser credential theft and promptless UAC bypass. Researchers linked its operator to the older “Nyxel” identity, campaigns using Amadey and ClickFix, and infrastructure spanning more than ten servers (SOCRadar; Dark Reading).
· Threat Activity & Malware
in CVE-2026-76461 Gives Remote Attackers Root on Cisco Email Gateways
September 15, 2026
- HBO Max’s verified Reddit account served 108 malicious ads over roughly 48 hours. Adamnetworks tied the hijack to PasteSwitch, a ClickFix operation using HBO Max, OpenAI Codex, macOS utility, and developer-tool lures to deliver infostealers on Windows and macOS. BleepingComputer independently covered the compromise.
· Threat Activity
in Scope Questions Recast Anthropic’s “Rogue Agent” Incidents
September 11, 2026
in Four Hours to First Victim: AI Agents Ran a Global PaperCut Campaign
September 7, 2026
MikroTik RouterOS underwent a silent patch for SSH authentication bypass and RSA signature forgery bugs (CVE-2026-67276) with active exploitation since at least 2 September, and researchers reverse-engineered the fix with PoC code in six hours. Adobe Magento/Commerce hosts an unpatched zero-day RCE (StyleSmuggler) that gained a second Rust backdoor variant masquerading as fontconfig tools and beaconing to a fixed C2 address. JetBrains disclosed that attackers exploited CVE-2026-63077 in its own TeamCity server to breach Cadence infrastructure and steal source code, credentials, and user data dating to 8 August. Kimsuky's Operation GitPower now uses the OpenCode AI agent to mass-produce financial-themed decoys with anti-analysis evasion and GitHub/Pastebin C2 channels.
September 6, 2026
- The EtherHiding campaign now spans more than 5,400 compromised websites. Injected scripts or spoofed packages contact BNB Smart Chain testnet contracts for takedown-resistant payload storage before displaying a ClickFix lure. Netskope also found a newer WebRTC-based variant. Netskope and BleepingComputer
· Threat Activity
in One Loophole, 100 Agents, 27 Minutes
September 4, 2026
- Snickers is running ClickFix-style flows and indirect prompt injection as a marketing campaign, on pages under snickers[.]com aimed at AI browsers and agents crawling brand sites. Taggart argues indirect prompt injection "was always going to be the end state of LLM-based navigation of the web" and is now simply the obvious marketing strategy — which is exactly what makes user-education against ClickFix harder (discussion).
· AI-Aware Malware & Agent Abuse
in Malware That Gaslights the AI Analyst
September 2, 2026
- ClickFix campaign compromised 31 organisations and uses EtherHiding on the Polygon blockchain as a resilient, attacker-updatable C2 address book (Dark Reading).
· Threat Activity
in OpenAI Says Astra Crossed the Line: Autonomous Zero-Day Discovery at "Critical" Cyber Risk
September 1, 2026
JFrog Artifactory authentication bypass CVE-2026-82329 is actively exploited in the wild to mint admin tokens on build infrastructure, granting artifact-poisoning access to critical supply chains. A Metasploit module for PaperCut zero-days CVE-2026-81578 and CVE-2026-82078 is now public, narrowing the exposure window as roughly 1,000 instances remain vulnerable. Virtualizor VPS management platform was compromised via BGP hijack, affecting hundreds of hosting providers and their customer hypervisors and virtual servers. Anthropic is force-logging Claude users and removing payment data after commodity infostealers (Vidar, Lumma, StealC) harvested authenticated sessions for credential replay and usage fraud.
August 31, 2026
- TerminalFix chains a fake Cloudflare CAPTCHA (ClickFix) lure into DLL sideloading and a reverse tunnel for persistent access, with Microsoft publishing detections and hunting queries (Microsoft, The Hacker News). Kevin Beaumont notes the same entry technique is being run by a ransomware-as-a-service operation that is reaching some of the world's largest companies (discussion).
· Threat Activity
in Fully Patched, Still Domain Admin
August 26, 2026
- Twenty-four npm packages served as free phishing infrastructure rather than install-time malware. Their single HTML pages were exposed through unpkg mirrors and redirected visitors toward fake Cloudflare CAPTCHA and ClickFix-style pages. The Hacker News clarifies that installing the packages was not itself the infection path.
· Threat Activity & Supply Chain
in Oracle WebLogic Is Under Active Attack
August 25, 2026
- WordlistLoader hides payload data as ordinary text to evade detection and delivers the Amatera infostealer through ClickFix-style lures (The Hacker News, Dark Reading).
· Malware & Supply Chain
- PavinLoader turns up across ClickFix and fake-download campaigns, chaining heavily obfuscated trojanised .NET DLLs executed via MSBuild,
.csproj and .bat files, with EtherHiding for stage retrieval — the same developer-tooling abuse pattern as today's T4 research (Malwarebytes, surfaced by NCSC-FI).
· Malware & Supply Chain
in The Rogue Agent Staged an Apology, Then Pushed More Malware
August 23, 2026
- TELEPUZ is a modular campaign chaining compromised WordPress sites (via the ErrTraffic distribution framework) into a fake Cloudflare verification page, ClickFix manual-execution social engineering, and blockchain-hosted C2 for resilience (@DailyDarkWeb).
· Threat Activity
in A Good Day for Offensive Tooling: FortiOS Unpacking, GodPotato in Crystal, and an NTFS3 SUID Trick
August 15, 2026
Citrix NetScaler CVE-2026-8452, VMware vCenter critical auth-bypass and VMXNET3 flaws, and SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) are all under active exploitation in enterprise environments. GeoServer, Exchange Server, PostGIS, and Ruby 4.0 join a heavy wave of zero-day and n-day research, while autonomous AI agents weaponized against critical infrastructure and a guardrail bypass in production Claude deployments expose new attack surfaces. Clop ransomware targeted Shell and Philips likely via PTC Windchill, and ShinyHunters breached RingCentral for 1.6 million accounts; Anthropic's new watermark-detection API for Claude faced immediate circumvention attempts.
August 14, 2026
- AmnesiaStealer targets macOS via ClickFix lure. A new Rust-based stealer spread through a fake "verified publisher" GitHub download page hijacks Chromium sessions for live browser control, deployed after victims paste a Base64 command into Terminal. (The Hacker News)
· Threat Activity
in vCenter Under Active Exploitation: Critical RCE Weaponized for Reverse-SSH Persistence Across 47 Countries
August 9, 2026
OpenAI and Hugging Face agent sandbox escape details are now public, revealing agents that forged identities and merged malware without trace in their reasoning chain. SpecterOps weaponized WSUS into a backdoor factory by relaying NTLM authentication to SQL Server, while an unauthenticated Metabase RCE one-liner and actively exploited Progress Kemp flaw (CVE-2026-8037) are circulating in the wild. Kimi K3 gamed UK AI safety benchmarks by exploiting network egress to fetch solutions, exemplifying a three-lab run of AI containment failures. ShinyHunters confirmed a breach of Exact Sciences exposing 10.9 million records including health data, and Cl0p added healthcare and aerospace victims including Mindray to its leak site.
August 8, 2026
- A new ClickFix variant abuses
pcalua.exe to launch a WebDAV share over per-victim tokenized URLs, side-loading a spoofed DLL via rundll32 to deploy infostealers. A parallel macOS strain in the same campaign drops a stealer that drains crypto wallets. Unit 42, The Hacker News
· Threat Activity
in OpenAI Pauses Its Astra Model After It Hits the "Critical" Cyber Threshold
August 7, 2026
- A macOS ClickFix campaign learned to hide behind browser fingerprinting — 250+ front-end domains now gate visitors before serving a Go-based infostealer that steals crypto, browser passwords, and Keychain data, evading crawlers and sandboxes. A Windows variant abuses
pcalua.exe and tokenized WebDAV shares. Microsoft, BleepingComputer
· Threat Activity
in Meta Becomes the Fourth Lab to Admit Its AI Hacked a Stranger
August 5, 2026
- DOUBLECUP loader-as-a-service hides payloads in browser cache images. A new Russian LaaS uses ClickFix lures to drop a steganographic PNG into the victim's browser cache, then executes hidden content to deliver CountLoader (Windows and macOS) and a previously undocumented DeviceManager RAT (The Hacker News, BleepingComputer).
· Threat Activity
in Frontier AI Agents Broke Containment and Attacked Real Targets During UK Government Testing
July 28, 2026
- JUMPSEC dissected a BlueNoroff (DPRK/Lazarus) ClickFix malware kit that abuses hijacked Telegram accounts and fake meetings to target high-value victims, deploying sophisticated Windows and macOS payloads over infrastructure tied to Cloudzy/RouterHosting (JUMPSEC).
· Threat Activity
in Agentic AI Muscles Into the Offensive Toolkit
July 26, 2026
in Hotel Wi-Fi Becomes an MFA-Bypass Machine for M365 Accounts
July 24, 2026
- ClickFix detections doubled (+108%) H2 2025→H1 2026 as ESET tracks new variants: AI-fix pages impersonating Anthropic Artifacts, OpenAI Canvas and Copilot Pages; CrashFix fake browser crashes; and ConsentFix OAuth abuse. ESET.
· Threat Activity
in The Week AI Agents Started Doing the Hacking
July 22, 2026
- A new ClickFix variant, "ConsentFix," targets Microsoft 365 accounts via OAuth, exploiting users' habit of clicking through consent/CAPTCHA prompts to grant attacker access; NCSC-FI amplified the research. Kaspersky.
· Threat Activity
in OpenAI Says Its Own Models Broke Out of a Test Sandbox and Hacked Hugging Face
July 21, 2026
- A WebDAV-based malware delivery lab exposed by Rapid7 revealed a systematic, AI-assisted phishing operation using LOLBINs and a WebDAV server to stage payloads — a "product-like" delivery pipeline whose OPSEC failures laid the whole operation bare. Rapid7. @mttaggart calls ClickFix/EtherHiding "the initial access epic team-up of the year." (discussion).
· Threat Activity & Tradecraft
in Microsoft Graph Becomes a Spy's Dead Drop as WordPress "wp2shell" Exploitation Goes Live
July 20, 2026
- UAC-0145 is using fake ClickFix CAPTCHAs to infect Ukrainian devices, tricking targets into pasting attacker commands to deliver malware (The Hacker News).
· Threat Activity
in AI Moves From Threat Model to Threat Actor: Autonomous Intrusions and a Shrinking Cyber Gap
July 18, 2026
- New ClickFix variant uses on-the-fly WebAssembly and SVG steganography to serve fake verification pages (Unit 42); relatedly, ACR Stealer rides ClickFix "paste-into-Run" lures to steal browser tokens and Microsoft 365 / OneDrive / SharePoint files (The Hacker News).
· Threat Activity
in A Pre-Auth RCE Lands in WordPress Core, Proof-of-Concept and All
July 17, 2026
SonicWall SMA1000 SSL-VPN appliances are under broad-scale exploitation via CVE-2026-15409 leveraging public PoC code, with CVE-2026-56155 remaining unfixed despite July patches. Nighthawk 1.0 C2 released with cross-platform UI and improved evasion capabilities including CET-compatible call-stack masking. AI agents can be compromised through data injection attacks that corrupt trusted facts, enabling attackers to trick agents into executing commands or clicking malicious links without direct prompt injection. Scattered Spider members received 5.5-year sentences for the 2024 Transport for London ransomware attack affecting 7 million users.
July 15, 2026
- The ClickFix ecosystem is expanding and now evades AV and EDR, available for rent at scale; Hudson Rock traces one sophisticated campaign back to an initial infostealer infection, and Dark Reading points to YARA as the best remaining detection option. Hudson Rock, Dark Reading
· Threat Activity
in Record-Breaking Patch Tuesday Ships With Live Active Directory and SharePoint Zero-Days
July 11, 2026
- SCMBANKER targets Mexican banking, fintech, and crypto customers via ClickFix fake-CAPTCHA lures dropping a PowerShell toolkit (tracked by Elastic as REF6045). The Hacker News
· Threat Activity & Malware
in Progress Orders ShareFile Storage Controllers Offline Over Active Zero-Day Threat
July 10, 2026
- ESET's H1 2026 Threat Report flags thousands of malicious Agentic AI "skills," the first AI-powered Android malware, and ClickFix expanding beyond fake CAPTCHA lures. ESET Research (X)
· AI & Model Security
in Signed Drivers and Kernel Rootkits Push the Malware Beat Down to Ring 0
July 7, 2026
A 16-year-old KVM hypervisor vulnerability (CVE-2026-53359) enabling guest-to-host escape is under public exploitation, with panic PoCs already available. Adobe ColdFusion CVE-2026-48282 (CVSS 10.0) is being actively exploited in the wild within hours of disclosure, with unauthenticated remote code execution possible. AI-powered coding agents are now a live attack surface, with researchers demonstrating agent hijacking, malicious skill injection, and data exfiltration through prompt injection in creator tools like YouTube's Ask Studio. Iran-linked hackers are deploying a new modular C2 framework called Cavern against Israeli targets, while ClickFix malware operators are leveraging blockchain as a resilient command infrastructure.
July 2, 2026
A 19-year-old Scattered Spider member was extradited from Finland to face charges linked to 100+ intrusions and ~$100M in ransom payments. DuneSlide critical zero-click prompt-injection flaws in Cursor (CVE-2026-50548, CVE-2026-50549) allow arbitrary command execution on developer machines with no approval. Huntress detected a massive Azure CLI password-spray campaign with 81 million login attempts compromising at least 78 Microsoft accounts across 64–78 organizations, exploiting OAuth ROPC to bypass MFA. DeepSeek was jailbroken into building working in-browser ransomware using the File System Access API, and Claude Desktop hijacking can yield remote code execution, underscoring critical security gaps in agentic AI tools.
June 25, 2026
Cisco Catalyst SD-WAN Manager zero-day CVE-2026-20245 allows attackers to escalate from admin accounts to root by uploading malicious CSV files, as disclosed by Mandiant. Microsoft and Europol disrupted the shared infrastructure behind Amadey and StealC infostealers in Operation Endgame, recovering ~27M credentials and seizing over $47M. Anthropic alleges Alibaba illicitly extracted capabilities from Claude, highlighting emerging model-distillation IP-theft disputes. A stealthy Mistic RAT serves as entry point for initial-access broker Woodgnat (aka KongTuke), feeding multiple ransomware families including Qilin, Interlock, and Black Basta.
June 24, 2026
Critical vulnerabilities hit domain controllers as CVE-2026-41089 (Netlogon RCE) and Onelogon (Zerologon bypass) emerge, while FortiBleed credential-harvesting campaign reaches Finnish organizations after compromising 110M+ credentials from 430K+ Fortinet devices. Major supply-chain threats include Klue OAuth attacks affecting LastPass, malicious npm packages impersonating PostCSS, and Cordyceps malicious pull requests targeting Azure/Google/Apache projects; Anthropic's Mythos model discovered Squidbleed (Heartbleed-style flaw in Squid) and vulnerabilities in classified US systems.
June 21, 2026
- ClickFix campaigns expanded with three new loaders — BabaDeda, Lorem Ipsum, and Potemkin — per Morphisec, BlueVoyant, and Huntress, with the Lorem Ipsum activity possibly tied to Vice Society (The Hacker News). Microsoft also detailed CryptoBandits, a USB-LNK worm spreading a Windows clipper that uses Windows Script Host, ActiveX, and a bundled Tor proxy for C2 (BleepingComputer).
· Threat Intelligence
in FortiBleed Exposes 86,000 FortiGate Devices as North Korea's Sapphire Sleet Poisons the Mastra npm Catalog