North Korea Uses ClickFix to Target macOS Users' Data

2026-04-16T20:51:42Za3436ff172af80187047af184090926d2cace5d243c077bc24380ef6aadd6ef5
ai-vulnerabilitiesaptbyovdclickfixcloud-credentialsedr-killermacos-malwarenginxot-icspatch-managementransomwaresecure-bootsupply-chainzero-day

What happened

This Dark Reading roundup highlights a surge in active exploitation, state-backed APT operations, and AI-related risks. Notable items include North Korea-linked Sapphire Sleet using ClickFix campaigns to steal macOS credentials, multiple actively exploited zero-days (Adobe, Windows 'BlueHammer' PoC), a critical nginx-ui/MCP integration flaw, and APT41/APT28/Fancy Bear campaigns targeting cloud and router infrastructure. Themes include AI-safety and prompt-injection/agent data-leak issues (Anthropic Mythos, Microsoft/Salesforce, Grafana), expansion of EDR-killer/BYOVD techniques, high-velocity

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
a3436ff172af80187047af184090926d2cace5d243c077bc24380ef6aadd6ef5
Enrichment time
2026-04-16T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.