Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

2026-08-06T01:23:59Z40f1d21d55e9331af575b32ccfff6cc75d9e3cd77f086855a102e1e0e8f0b396
CVE-2026-18556CVE-2026-18577CVE-2026-58048CVE-2026-59774CVE-2026-64531CVE-2026-9198AI securityCISA KEVClickFixGiteaLangflowLinux kernelMFA bypassN-able N-centralRATSonicWallactive exploitationcredential theftcritical vulnerabilitiesdata exfiltrationdeveloper toolingdevice code phishingmalicious npm packagesmalwarephishingprivilege escalationransomwareremote code executionsoftware supply chain

What happened

The collection highlights active exploitation, critical vulnerabilities, phishing and malware campaigns, and software supply-chain compromises reported in August 2026. Notable risks include unauthenticated Gitea file disclosure (CVE-2026-59774), actively exploited Langflow, Tomcat, and N-able N-central flaws, Linux kernel local privilege escalation (CVE-2026-64531), malicious npm packages and extensions, ClickFix campaigns, device-code phishing, exposed credentials, and ransomware activity. Organizations should prioritize CISA KEV remediation, patch critical internet-facing software, rotate or

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
40f1d21d55e9331af575b32ccfff6cc75d9e3cd77f086855a102e1e0e8f0b396
Enrichment time
2026-08-06T01:23:59Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.