Now, even Russia's most elite hackers are using Clickfix to infect devices
2026-07-18T20:51:46Z•790bf2bec48cc5b20ccd54e58468594185aef6c341bdd0229b61b2bf62454a10
HiveLegacyNightmareEclipseai_botnets_UX_abuse?ai_securitycisaclickfixcrypto_clipperdata_breachguest_vm_escapehalluSquattingincident_responselinux_vm_escapemacos_malwaremass_breachpamstealerpatchingprompt_injectionrouter_hacksrussiasecure_bootsocial_engineeringstate_sponsoredvulnerability_disclosurewindows_0daywindows_defender
What happened
A cluster of high-impact security stories from Ars Technica in June–July 2026: nation-state and crimeware groups are adopting new social-engineering methods (notably “Clickfix”) and targeting residential devices (CISA warns on router compromise). Multiple high-risk flaws and active zero-days were reported — including a Windows 0‑day (HiveLegacy-related), a Windows Defender 0‑day tied to the NightmareEclipse feud, and a Linux guest‑VM escape for which Google paid a $250K bounty. Researchers also disclosed systemic Secure Boot weaknesses caused by unrevoked shims and urged users to update Secure
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- 790bf2bec48cc5b20ccd54e58468594185aef6c341bdd0229b61b2bf62454a10
- Enrichment time
- 2026-07-18T20:51:46Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.