ClickFix Campaigns Expand Malware Delivery With New Loaders and Fake Update Lures

2026-06-16T19:24:08Z5590fa59570e2027bf698a39fed13e6ba61dd1c04290b629111968650a4c5f83
adwareai-abuseandroid-banking-trojanbackdoorcredential-theftexploitationmalwarepatch-managementphishingprivilege-escalationrcerootkitsupply-chainthreat-actorsvulnerability

What happened

This feed reports a wave of high-impact vulnerabilities, active exploitations, and diverse malware campaigns. Key vulnerabilities include a critical Splunk RCE (CVE-2026-20253, CVSS 9.8), multiple FortiSandbox flaws under exploitation (CVE-2026-39813, CVE-2026-39808, CVE-2026-25089), a Cisco Catalyst SD‑WAN Manager web UI flaw (CVE-2026-20262), a Palo Alto PAN‑OS GlobalProtect auth bypass (CVE-2026-0257), and a LiteSpeed cPanel Plugin privilege escalation added to CISA KEV (CVE-2026-54420). Active malware and campaign activity includes ClickFix campaigns delivering loaders (BabaDeda, Lorem Ips

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
5590fa59570e2027bf698a39fed13e6ba61dd1c04290b629111968650a4c5f83
Enrichment time
2026-06-16T19:24:08Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.