Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs
2026-03-28T13:24:06Z•a599d0af928d1b5b6522ab145356da9ab69cf8681473162018eece1f81698b0a
BINDBash scriptCISACVE-2026-4681Coruna','Operation Triangulation'DNS resolverHightowerInfiniti stealerNuitkaPII exposurePTC WindchillPython infostealerRCETP-Linkaccount compromiseauthentication bypassdata breachfake CAPTCHAiOS exploit kitmacOS malwarememory leakout-of-memoryphishingpro-Iranian threat actorrouter vulnerabilities
What happened
Multiple high-impact cyber stories: A Cloudflare-themed ‘ClickFix’ phishing chain targets macOS users and installs a Python-based Infiniti infostealer via a fake CAPTCHA, Bash staging script and a Nuitka loader. A pro‑Iranian hacking group claims to have breached FBI Director Kash Patel’s personal account and leaked emails. CISA and German police flagged a critical PTC Windchill vulnerability (CVE-2026-4681) that prompted emergency warnings. TP-Link and BIND released patches for high‑severity vulnerabilities (authentication bypass, remote command execution, and DNS resolver OOM/memory-leak/den
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- a599d0af928d1b5b6522ab145356da9ab69cf8681473162018eece1f81698b0a
- Enrichment time
- 2026-03-28T13:24:06Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.