Now, even Russia's most elite hackers are using Clickfix to infect devices
2026-07-18T08:51:45Z•bf5de001e2b931eb6619a7aeb582dc796e18037cdf7c21c763cf9070290fcce7
ai-abusebotnetsclickfixcredential-breachguest-vm-escapemacos-infostealermemory-encryptionpost-quantum-cryptoprompt-injectionrouter-compromisesecure-boot-bypasssocial-engineeringvm-escapewindows-0daywindows-defender
What happened
Multiple recent Ars Technica reports highlight an escalation in both sophisticated state‑actor tradecraft and widely exploitable vulnerabilities. Russian actors are adopting the Clickfix social‑engineering technique and targeting home routers; Microsoft Secure Boot has long‑standing shim-related bypasses while a string of Windows 0‑days (including a Defender issue and HiveLegacy primitive) and record patching activity were disclosed. Other notable issues: high‑value Google‑rewarded Linux guest VM escapes, a new macOS infostealer (PamStealer), USB‑spreading crypto clippers, large credential exf
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- arstechnica_security
- Record identifier
- bf5de001e2b931eb6619a7aeb582dc796e18037cdf7c21c763cf9070290fcce7
- Enrichment time
- 2026-07-18T08:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.