Tor-Based Clipper Malware Targets Wallet Seed Phrases

2026-06-19T02:51:43Z98732445aaacee26f806ee8d676df08b0e0330e2dcb3339a559be87d626aad8e
Android-banking-trojanCISA-KEVCiscoF5FortinetJoomlaMicrosoftclipboard-clippercredential-exposurecrypto-theftdata-breachinfostealermalwarepatchingransomwarevulnerabilityzero-day

What happened

Multiple high‑impact security events reported: a Tor-based clipboard clipper malware campaign is targeting cryptocurrency users (stealing seed phrases, replacing wallet addresses, capturing screenshots); Microsoft confirmed a RoguePlanet zero-day in Defender (CVE-2026-50656) allowing local privilege escalation; F5 issued emergency patches for critical NGINX flaws enabling unauthenticated code execution (CVE-2026-42530, CVE-2026-42055); Cisco patched a critical ISE command‑execution/root escalation vulnerability (CVE-2026-20181); CISA added the Widget Factory Joomla Content Editor flaw (CVE-202

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
98732445aaacee26f806ee8d676df08b0e0330e2dcb3339a559be87d626aad8e
Enrichment time
2026-06-19T02:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.