Evil evolution: ClickFix and macOS infostealers
2026-03-12T20:51:39Z•20913b62b0be98050c648ad86712ae410e5bc3d5e440dc313ec98cb2313ae7dd
Cisco SD‑WANIranIsraelMacSyncOperation Epic FurySophos CTUactive-adversaryclickfixexploit-in-the-wildfirewall-v22geopolitical-cyber-riskhacktivisminfostealermacOSproduct-releasesocial‑engineeringvulnerabilityworkspace-protection
What happened
Sophos published multiple security updates and research items describing: (1) campaigns using ClickFix social‑engineering lures to deliver macOS infostealers (MacSync and variants), (2) increased regional hacktivist activity tied to U.S.–Iran–Israel tensions (Operation Epic Fury) with guidance from Sophos CTU, and (3) active exploitation of Cisco SD‑WAN vulnerabilities (CVE‑2026‑20127 and CVE‑2022‑20775). The feed also includes product announcements (Sophos Workspace Protection, Firewall v22) and the 2026 Active Adversary report with defensive recommendations. Overall, the collection warns of:
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 20913b62b0be98050c648ad86712ae410e5bc3d5e440dc313ec98cb2313ae7dd
- Enrichment time
- 2026-03-12T20:51:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.