Tor-Based Clipper Malware Targets Wallet Seed Phrases

2026-06-18T20:51:51Z08165d9738a50a06c365c8242023bf96e0aead3e3c5b678de3f5d82d3b38d0cb
Android banking trojanC2 tunnelingCISA KEVCVE-2026-20181CVE-2026-42055CVE-2026-42530CVE-2026-48907CVE-2026-50656Cisco ISEDragonForceF5FortiBleedFortinet credential leakJoomla JCEMicrosoft DefenderMicrosoft Teams abuseNGINXRoguePlanetRokarollaTorUSB .lnkclipboard hijackclipper malwarecryptocurrency theftdata breach','ransomware','FulcrumSec','Novo Nordisk'

What happened

Multiple high-impact security incidents and vulnerabilities reported: Microsoft is tracking a Tor-based clipper malware campaign that hijacks clipboards, replaces wallet addresses, steals seed phrases and screenshots; Cisco patched a critical ISE command-execution flaw (CVE-2026-20181) that allows authenticated admins to gain root; F5 released emergency fixes for critical NGINX vulnerabilities (CVE-2026-42530, CVE-2026-42055) enabling unauthenticated code execution; Microsoft confirmed the RoguePlanet zero-day in Defender (CVE-2026-50656) enabling privilege escalation and is developing a patch

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
08165d9738a50a06c365c8242023bf96e0aead3e3c5b678de3f5d82d3b38d0cb
Enrichment time
2026-06-18T20:51:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.