Cylake Raises $45 Million to Secure Organizations Barred From Cloud

2026-03-10T07:24:09Z5c8709fe88b8b5d1d2d109b48d2cbc9f7e9542494d03a967029e0c828fc34380
.arpaAnthropicBoryptGrabCVE-2026-20127Cisco CatalystClickFixCloudflareCylakeFBIGitHubInstallFixM&APentagonSD-WANUS cyber strategyWindows Terminalcloned sitesdata sovereigntyexploitationmalware distributionphishingsensitive systemssocial engineeringstealer

What happened

Collection of SecurityWeek reports: a recently disclosed Cisco Catalyst SD‑WAN flaw (CVE-2026-20127) is now being widely exploited. Multiple active malware/phishing campaigns described — ClickFix social‑engineering pages trick victims into pasting malicious commands into Windows Terminal, cloned AI tool sites (InstallFix) swap legitimate install commands for malicious ones, and over 100 GitHub repositories are distributing the BoryptGrab stealer targeting browsers and crypto wallets. Threat actors also abused the infrastructure TLD .arpa and Cloudflare DNS controls to hide phishing content. On

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
5c8709fe88b8b5d1d2d109b48d2cbc9f7e9542494d03a967029e0c828fc34380
Enrichment time
2026-03-10T07:24:09Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.