ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure

2026-09-21T13:24:00Z•a94b2ad49b3bb9f73d33a47800a7f5543379974a2b7dc20172e6646b61c57c19
CVE-2025-39682CVE-2026-28326CVE-2026-58138CVE-2026-77179CVE-2026-81642CVE-2026-85889AI-securityCISA-KEVClickFixDNSSECDockerIranLinux-kernelNorth KoreaPakistanRATWordPressactive-exploitationcloud-securitycritical-vulnerabilitiesidentity-securityinformation-stealernation-statenpm-malwarephishingremote-code-executionsupply-chain-attack

What happened

The feed reports active exploitation and disclosure of multiple critical vulnerabilities, malware campaigns, supply-chain compromises, and nation-state operations. Notable items include pre-authenticated remote code execution in Orkes Conductor, Unbound DNS, Docker Sandboxes, Check Point management servers, and SolarWinds ARM; Linux kernel flaws added to CISA KEV; malicious npm packages delivering stealers; ClickFix phishing deploying ChainScript RAT; and activity attributed to Jade Sleet, Transparent Tribe, and Handala Hack.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
the_hacker_news
Record identifier
a94b2ad49b3bb9f73d33a47800a7f5543379974a2b7dc20172e6646b61c57c19
Enrichment time
2026-09-21T13:24:00Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure · Baitaphish