Iranian spies hit Windows machines with Chosen Brick data-stealing malware
2026-09-15T19:23:51Z•f90aa0a3bdf14de27556d045dde4604edfc372025b6cbfa882b86995da18ac4a
AI-securityChosen-BrickCiscoClickFixContiGitLabIranian-threat-actorJFrog-ArtifactoryLockergogaMegaCortexMicrosoft-365NefilimRubyGemsWindows-malwareactive-exploitationcredential-theftcritical-vulnerabilitiesdata-breachdata-thefthealthcaremalvertisingphishingransomwaresupply-chain-securityzero-day
What happened
The feed is a cybersecurity news roundup covering active exploitation of critical vulnerabilities, malware and phishing campaigns, ransomware activity, major data breaches, supply-chain and AI-agent abuse, hardware attacks, and cybersecurity policy. Notable items include active exploitation of a critical Cisco email-security appliance flaw, GitLab and JFrog Artifactory vulnerabilities, a Windows data-stealing campaign attributed to Iranian spies, ClickFix malvertising, large-scale credential theft, and attacks affecting healthcare and software ecosystems. Multiple articles reference severe or
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- theregister_security
- Record identifier
- f90aa0a3bdf14de27556d045dde4604edfc372025b6cbfa882b86995da18ac4a
- Enrichment time
- 2026-09-15T19:23:51Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.