Evil evolution: ClickFix and macOS infostealers

2026-03-11T20:51:42Z55e364c7e5349562404f1f533b5402c57ed1c1d6e9dbe0eda9dd2063f8b44f81
active adversaryactive exploitationadvisoryciscoclickfixfirewallhacktivismidentity securityinfostealeriranisraelitdrmacosmacsyncmdrnetworkoperation epic furysd-wansecure by designsocial engineeringsophos ctuv22vulnerabilityworkspacexdr

What happened

Feed of Sophos blog posts (Feb–Mar 2026) highlighting multiple threat and product developments: evolving ClickFix campaigns delivering macOS infostealers (including MacSync and social‑engineering lures); increased hacktivist activity tied to US–Iran–Israel tensions (Operation Epic Fury) with limited observed impact; disclosure that Cisco SD‑WAN vulnerabilities (CVE-2026-20127 and CVE-2022-20775) are being actively exploited; publication of the 2026 Active Adversary Report; and product announcements (Sophos Workspace Protection, Firewall v22).

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
sophos_news
Record identifier
55e364c7e5349562404f1f533b5402c57ed1c1d6e9dbe0eda9dd2063f8b44f81
Enrichment time
2026-03-11T20:51:42Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.