Now, even Russia's most elite hackers are using Clickfix to infect devices
2026-07-19T08:51:43Z•22e370b9b4b0543a11af4582d259b5213836d77373ee1b4ba95719f68d5f5d96
AI threatsCISAClickfixCrypto ClipperHalluSquattingHiveLegacyLinux kernelPamStealerRussiaSecure BootSecure Boot keysWindows 0-dayWindows Defenderbotnetscredentialscryptocurrency theftguest VM escapemacOSmass breachpost-quantum-cryptoprompt-injectionrouter compromiseshim vulnerabilitiesstate-sponsored
What happened
Roundup of July 2026 security reporting: Russian state and financially motivated attackers are adopting a social‑engineering technique called “Clickfix” and increasingly targeting home routers and messaging apps; multiple high‑impact Windows vulnerabilities and 0‑days (including the reported “HiveLegacy” primitive and a Windows Defender bug) surfaced alongside a paid Linux guest‑VM escape; researchers disclosed long‑standing Secure Boot weaknesses caused by unrevoked shims and warned about expiring Secure Boot keys; new macOS infostealers (PamStealer) and self‑propagating crypto‑stealers (Cryp
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 22e370b9b4b0543a11af4582d259b5213836d77373ee1b4ba95719f68d5f5d96
- Enrichment time
- 2026-07-19T08:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.