Iranian spies hit Windows machines with Chosen Brick data-stealing malware

2026-09-15T19:23:51Z•f90aa0a3bdf14de27556d045dde4604edfc372025b6cbfa882b86995da18ac4a
AI-securityChosen-BrickCiscoClickFixContiGitLabIranian-threat-actorJFrog-ArtifactoryLockergogaMegaCortexMicrosoft-365NefilimRubyGemsWindows-malwareactive-exploitationcredential-theftcritical-vulnerabilitiesdata-breachdata-thefthealthcaremalvertisingphishingransomwaresupply-chain-securityzero-day

What happened

The feed is a cybersecurity news roundup covering active exploitation of critical vulnerabilities, malware and phishing campaigns, ransomware activity, major data breaches, supply-chain and AI-agent abuse, hardware attacks, and cybersecurity policy. Notable items include active exploitation of a critical Cisco email-security appliance flaw, GitLab and JFrog Artifactory vulnerabilities, a Windows data-stealing campaign attributed to Iranian spies, ClickFix malvertising, large-scale credential theft, and attacks affecting healthcare and software ecosystems. Multiple articles reference severe or

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
theregister_security
Record identifier
f90aa0a3bdf14de27556d045dde4604edfc372025b6cbfa882b86995da18ac4a
Enrichment time
2026-09-15T19:23:51Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Iranian spies hit Windows machines with Chosen Brick data-stealing malware · Baitaphish