New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands

2026-07-16T13:24:16Z4ff375f41df0d75528c050a132f6b6608feaa763e54ba761551bf978cad5a139
@asyncapiCVE-2026-15409CVE-2026-15718CVE-2026-15719CVE-2026-44747CVE-2026-53412ClickFixClickLockCursorDaxin`,`Stupig`,`UEFI`,`secure-boot`,`Shark-vacuum`,`IoT`,`LabubFirefoxIoT botnetOkoBotSAPSonicWallTELEPUZTuxBotZoombotnetmacOS stealermalwarenpm compromiserepository-executionseed-phrase phishingsupply-chain

What happened

A broad set of high-impact security stories: new modular TELEPUZ malware spreading via ClickFix-infected sites and multiple infostealers (ClickLock for macOS, OkoBot targeting hardware-wallet seed phrases) plus supply-chain and repo abuse (compromised @asyncapi npm packages, Cursor executing git.exe). Serious infrastructure and device issues include SonicWall SMA 1000 zero-days (one allowing arbitrary command execution), a critical Zoom Windows flaw enabling account takeover, Firefox WebAssembly/DOM bugs with public exploit code, and an SAP NetWeaver ABAP out‑of‑bounds flaw. Other notable risk

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
4ff375f41df0d75528c050a132f6b6608feaa763e54ba761551bf978cad5a139
Enrichment time
2026-07-16T13:24:16Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands · Baitaphish