ClickFix Campaign Abuses Trusted Websites to Deploy Psychedelic Stealer
2026-09-25T14:51:40Z•5f97f4d158619653370edb5f110498120fee4e0e3d3e9c6d836eead6f2cb8533
CVE-2026-5430CVE-2026-85102CVE-2026-94127AI-assisted malwareArista VeloCloudCARBONATO botnetCISA KEVCLOSEDQUORUMCheck PointClickFixDockerF5 BIG-IP APMMikroTik RouterOSPsychedelic StealerWSO2active exploitationauthentication bypasscloud securitycompromised websitescredential theftcrypto theftcybercrimegovernment systemsphishingremote code executionzero-day
What happened
SecurityAffairs RSS collection covering active exploitation of enterprise vulnerabilities, malware and botnets using AI-assisted or autonomous behavior, ClickFix phishing delivering Psychedelic Stealer, router exploitation, alleged government breaches, and cybercrime activity. Multiple items describe critical vulnerabilities being exploited in the wild, including F5 BIG-IP APM RCE, WSO2 authentication bypass, and other CISA KEV additions.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 5f97f4d158619653370edb5f110498120fee4e0e3d3e9c6d836eead6f2cb8533
- Enrichment time
- 2026-09-25T14:51:40Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.