Tor-Based Clipper Malware Targets Wallet Seed Phrases
2026-06-19T02:51:43Z•98732445aaacee26f806ee8d676df08b0e0330e2dcb3339a559be87d626aad8e
Android-banking-trojanCISA-KEVCiscoF5FortinetJoomlaMicrosoftclipboard-clippercredential-exposurecrypto-theftdata-breachinfostealermalwarepatchingransomwarevulnerabilityzero-day
What happened
Multiple high‑impact security events reported: a Tor-based clipboard clipper malware campaign is targeting cryptocurrency users (stealing seed phrases, replacing wallet addresses, capturing screenshots); Microsoft confirmed a RoguePlanet zero-day in Defender (CVE-2026-50656) allowing local privilege escalation; F5 issued emergency patches for critical NGINX flaws enabling unauthenticated code execution (CVE-2026-42530, CVE-2026-42055); Cisco patched a critical ISE command‑execution/root escalation vulnerability (CVE-2026-20181); CISA added the Widget Factory Joomla Content Editor flaw (CVE-202
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- 98732445aaacee26f806ee8d676df08b0e0330e2dcb3339a559be87d626aad8e
- Enrichment time
- 2026-06-19T02:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.