Cloudflare-Themed ClickFix Attack Drops Infiniti Stealer on Macs

2026-03-28T13:24:06Za599d0af928d1b5b6522ab145356da9ab69cf8681473162018eece1f81698b0a
BINDBash scriptCISACVE-2026-4681Coruna','Operation Triangulation'DNS resolverHightowerInfiniti stealerNuitkaPII exposurePTC WindchillPython infostealerRCETP-Linkaccount compromiseauthentication bypassdata breachfake CAPTCHAiOS exploit kitmacOS malwarememory leakout-of-memoryphishingpro-Iranian threat actorrouter vulnerabilities

What happened

Multiple high-impact cyber stories: A Cloudflare-themed ‘ClickFix’ phishing chain targets macOS users and installs a Python-based Infiniti infostealer via a fake CAPTCHA, Bash staging script and a Nuitka loader. A pro‑Iranian hacking group claims to have breached FBI Director Kash Patel’s personal account and leaked emails. CISA and German police flagged a critical PTC Windchill vulnerability (CVE-2026-4681) that prompted emergency warnings. TP-Link and BIND released patches for high‑severity vulnerabilities (authentication bypass, remote command execution, and DNS resolver OOM/memory-leak/den

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityweek
Record identifier
a599d0af928d1b5b6522ab145356da9ab69cf8681473162018eece1f81698b0a
Enrichment time
2026-03-28T13:24:06Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.