North Korea Uses ClickFix to Target macOS Users' Data
2026-04-16T20:51:42Z•a3436ff172af80187047af184090926d2cace5d243c077bc24380ef6aadd6ef5
ai-vulnerabilitiesaptbyovdclickfixcloud-credentialsedr-killermacos-malwarenginxot-icspatch-managementransomwaresecure-bootsupply-chainzero-day
What happened
This Dark Reading roundup highlights a surge in active exploitation, state-backed APT operations, and AI-related risks. Notable items include North Korea-linked Sapphire Sleet using ClickFix campaigns to steal macOS credentials, multiple actively exploited zero-days (Adobe, Windows 'BlueHammer' PoC), a critical nginx-ui/MCP integration flaw, and APT41/APT28/Fancy Bear campaigns targeting cloud and router infrastructure. Themes include AI-safety and prompt-injection/agent data-leak issues (Anthropic Mythos, Microsoft/Salesforce, Grafana), expansion of EDR-killer/BYOVD techniques, high-velocity
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- darkreading
- Record identifier
- a3436ff172af80187047af184090926d2cace5d243c077bc24380ef6aadd6ef5
- Enrichment time
- 2026-04-16T20:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.