Evil evolution: ClickFix and macOS infostealers
2026-03-11T20:51:42Z•55e364c7e5349562404f1f533b5402c57ed1c1d6e9dbe0eda9dd2063f8b44f81
active adversaryactive exploitationadvisoryciscoclickfixfirewallhacktivismidentity securityinfostealeriranisraelitdrmacosmacsyncmdrnetworkoperation epic furysd-wansecure by designsocial engineeringsophos ctuv22vulnerabilityworkspacexdr
What happened
Feed of Sophos blog posts (Feb–Mar 2026) highlighting multiple threat and product developments: evolving ClickFix campaigns delivering macOS infostealers (including MacSync and social‑engineering lures); increased hacktivist activity tied to US–Iran–Israel tensions (Operation Epic Fury) with limited observed impact; disclosure that Cisco SD‑WAN vulnerabilities (CVE-2026-20127 and CVE-2022-20775) are being actively exploited; publication of the 2026 Active Adversary Report; and product announcements (Sophos Workspace Protection, Firewall v22).
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- sophos_news
- Record identifier
- 55e364c7e5349562404f1f533b5402c57ed1c1d6e9dbe0eda9dd2063f8b44f81
- Enrichment time
- 2026-03-11T20:51:42Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.