Cylake Raises $45 Million to Secure Organizations Barred From Cloud
2026-03-10T07:24:09Z•5c8709fe88b8b5d1d2d109b48d2cbc9f7e9542494d03a967029e0c828fc34380
.arpaAnthropicBoryptGrabCVE-2026-20127Cisco CatalystClickFixCloudflareCylakeFBIGitHubInstallFixM&APentagonSD-WANUS cyber strategyWindows Terminalcloned sitesdata sovereigntyexploitationmalware distributionphishingsensitive systemssocial engineeringstealer
What happened
Collection of SecurityWeek reports: a recently disclosed Cisco Catalyst SD‑WAN flaw (CVE-2026-20127) is now being widely exploited. Multiple active malware/phishing campaigns described — ClickFix social‑engineering pages trick victims into pasting malicious commands into Windows Terminal, cloned AI tool sites (InstallFix) swap legitimate install commands for malicious ones, and over 100 GitHub repositories are distributing the BoryptGrab stealer targeting browsers and crypto wallets. Threat actors also abused the infrastructure TLD .arpa and Cloudflare DNS controls to hide phishing content. On
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- 5c8709fe88b8b5d1d2d109b48d2cbc9f7e9542494d03a967029e0c828fc34380
- Enrichment time
- 2026-03-10T07:24:09Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.