New macOS stealer campaign uses Script Editor in ClickFix attack
2026-04-08T19:23:36Z•337e02c49a9b1d33be0c748342078bf387ceb1619159facd5c4cbd337364d64b
Allen-BradleyApache ActiveMQAtomic StealerCISACVE-2025-59528ClickFixDNS hijackFlowiseFrostArmadaIranian threat actorIvanti EPMMMikroTikNinja FormsPLCsRCERockwellSaaS integrator breachScript EditorSnowflakeTP-Link','GPUBreach','Rowhammer','GPU exploit','BlueHammer','WinWordPressdata theftexploited vulnerabilitymacOSunauthenticated file upload
What happened
Feed of April 6–8, 2026 Bleeping Computer headlines: multiple actively exploited and high-impact vulnerabilities (including Flowise RCE CVE-2025-59528 and a CISA-ordered, actively exploited Ivanti EPMM flaw) plus a newly observed macOS Atomic Stealer campaign abusing Script Editor/ClickFix, a 13-year-old RCE in Apache ActiveMQ Classic, and an exploited critical Ninja Forms File Uploads plugin that can lead to unauthenticated arbitrary file upload and RCE. Other notable items: Snowflake customers hit after a SaaS integrator breach, Iranian-linked targeting of Rockwell/Allen‑Bradley PLCs, law‑en
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 337e02c49a9b1d33be0c748342078bf387ceb1619159facd5c4cbd337364d64b
- Enrichment time
- 2026-04-08T19:23:36Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.