Evil evolution: ClickFix and macOS infostealers

2026-03-12T20:51:39Z20913b62b0be98050c648ad86712ae410e5bc3d5e440dc313ec98cb2313ae7dd
Cisco SD‑WANIranIsraelMacSyncOperation Epic FurySophos CTUactive-adversaryclickfixexploit-in-the-wildfirewall-v22geopolitical-cyber-riskhacktivisminfostealermacOSproduct-releasesocial‑engineeringvulnerabilityworkspace-protection

What happened

Sophos published multiple security updates and research items describing: (1) campaigns using ClickFix social‑engineering lures to deliver macOS infostealers (MacSync and variants), (2) increased regional hacktivist activity tied to U.S.–Iran–Israel tensions (Operation Epic Fury) with guidance from Sophos CTU, and (3) active exploitation of Cisco SD‑WAN vulnerabilities (CVE‑2026‑20127 and CVE‑2022‑20775). The feed also includes product announcements (Sophos Workspace Protection, Firewall v22) and the 2026 Active Adversary report with defensive recommendations. Overall, the collection warns of:

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
20913b62b0be98050c648ad86712ae410e5bc3d5e440dc313ec98cb2313ae7dd
Enrichment time
2026-03-12T20:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Evil evolution: ClickFix and macOS infostealers · Baitaphish