Now, even Russia's most elite hackers are using Clickfix to infect devices

2026-07-18T08:51:45Zbf5de001e2b931eb6619a7aeb582dc796e18037cdf7c21c763cf9070290fcce7
ai-abusebotnetsclickfixcredential-breachguest-vm-escapemacos-infostealermemory-encryptionpost-quantum-cryptoprompt-injectionrouter-compromisesecure-boot-bypasssocial-engineeringvm-escapewindows-0daywindows-defender

What happened

Multiple recent Ars Technica reports highlight an escalation in both sophisticated state‑actor tradecraft and widely exploitable vulnerabilities. Russian actors are adopting the Clickfix social‑engineering technique and targeting home routers; Microsoft Secure Boot has long‑standing shim-related bypasses while a string of Windows 0‑days (including a Defender issue and HiveLegacy primitive) and record patching activity were disclosed. Other notable issues: high‑value Google‑rewarded Linux guest VM escapes, a new macOS infostealer (PamStealer), USB‑spreading crypto clippers, large credential exf

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
arstechnica_security
Record identifier
bf5de001e2b931eb6619a7aeb582dc796e18037cdf7c21c763cf9070290fcce7
Enrichment time
2026-07-18T08:51:45Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.