New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands
2026-07-16T13:24:16Z•4ff375f41df0d75528c050a132f6b6608feaa763e54ba761551bf978cad5a139
@asyncapiCVE-2026-15409CVE-2026-15718CVE-2026-15719CVE-2026-44747CVE-2026-53412ClickFixClickLockCursorDaxin`,`Stupig`,`UEFI`,`secure-boot`,`Shark-vacuum`,`IoT`,`LabubFirefoxIoT botnetOkoBotSAPSonicWallTELEPUZTuxBotZoombotnetmacOS stealermalwarenpm compromiserepository-executionseed-phrase phishingsupply-chain
What happened
A broad set of high-impact security stories: new modular TELEPUZ malware spreading via ClickFix-infected sites and multiple infostealers (ClickLock for macOS, OkoBot targeting hardware-wallet seed phrases) plus supply-chain and repo abuse (compromised @asyncapi npm packages, Cursor executing git.exe). Serious infrastructure and device issues include SonicWall SMA 1000 zero-days (one allowing arbitrary command execution), a critical Zoom Windows flaw enabling account takeover, Firefox WebAssembly/DOM bugs with public exploit code, and an SAP NetWeaver ABAP out‑of‑bounds flaw. Other notable risk
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 4ff375f41df0d75528c050a132f6b6608feaa763e54ba761551bf978cad5a139
- Enrichment time
- 2026-07-16T13:24:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.