Now, even Russia's most elite hackers are using Clickfix to infect devices

2026-07-19T08:51:43Z22e370b9b4b0543a11af4582d259b5213836d77373ee1b4ba95719f68d5f5d96
AI threatsCISAClickfixCrypto ClipperHalluSquattingHiveLegacyLinux kernelPamStealerRussiaSecure BootSecure Boot keysWindows 0-dayWindows Defenderbotnetscredentialscryptocurrency theftguest VM escapemacOSmass breachpost-quantum-cryptoprompt-injectionrouter compromiseshim vulnerabilitiesstate-sponsored

What happened

Roundup of July 2026 security reporting: Russian state and financially motivated attackers are adopting a social‑engineering technique called “Clickfix” and increasingly targeting home routers and messaging apps; multiple high‑impact Windows vulnerabilities and 0‑days (including the reported “HiveLegacy” primitive and a Windows Defender bug) surfaced alongside a paid Linux guest‑VM escape; researchers disclosed long‑standing Secure Boot weaknesses caused by unrevoked shims and warned about expiring Secure Boot keys; new macOS infostealers (PamStealer) and self‑propagating crypto‑stealers (Cryp

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
22e370b9b4b0543a11af4582d259b5213836d77373ee1b4ba95719f68d5f5d96
Enrichment time
2026-07-19T08:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.