ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures
2026-06-16T19:24:08Z•5590fa59570e2027bf698a39fed13e6ba61dd1c04290b629111968650a4c5f83
adwareai-abuseandroid-banking-trojanbackdoorcredential-theftexploitationmalwarepatch-managementphishingprivilege-escalationrcerootkitsupply-chainthreat-actorsvulnerability
What happened
This feed reports a wave of high-impact vulnerabilities, active exploitations, and diverse malware campaigns. Key vulnerabilities include a critical Splunk RCE (CVE-2026-20253, CVSS 9.8), multiple FortiSandbox flaws under exploitation (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089), a Cisco Catalyst SD‑WAN Manager web UI flaw (CVE-2026-20262), a Palo Alto PAN‑OS GlobalProtect auth bypass (CVE-2026-0257), and a LiteSpeed cPanel Plugin privilege escalation added to CISA KEV (CVE-2026-54420). Active malware and campaign activity includes ClickFix campaigns delivering loaders (BabaDeda, Lorem Ips
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- the_hacker_news
- Record identifier
- 5590fa59570e2027bf698a39fed13e6ba61dd1c04290b629111968650a4c5f83
- Enrichment time
- 2026-06-16T19:24:08Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.