ClickFix social engineering attacks are spreading widely, delivering malware to Windows and macOS users by tricking them into running malicious terminal commands that bypass Gatekeeper.
BlueVoyant reports the Lorem Ipsum malware operation pivoted to ClickFix in late May 2026, dropping code-signing infrastructure and broadening its victim pool from Microsoft Teams searchers to anyone browsing a compromised website. Jamf and independent researchers documented macOS ClickFix variants that bypass Gatekeeper protections. Cisco Talos observed attackers abusing published Google Sheets for control traffic, while Netskope counted 5,400 sites beaconing to one campaign; Sandworm has separately hosted control infrastructure in blockchain smart contracts.
Cisco Talos's Threat Source newsletter critiques 'burnout' terminology, describing four occupational injuries, and flags a UAT-10820 WebDAV stealer campaign at a Ukrainian government organization.
Cisco Talos's Threat Source newsletter argues that 'burnout' is the wrong word for most cybersecurity occupational harm, distinguishing exhaustion, secondary traumatic stress, vicarious trauma, and moral injury based on clinical literature from trauma-exposed professions. The featured disclosure describes a complex WebDAV infection chain found at a Ukrainian government organization, attributed with moderate confidence to the Russian-tracked actor UAT-10820 and assessed as an opportunistic cryptocurrency and credential-stealing operation. The campaign delivers the Amatera stealer alongside ZigCryptoStealer and NetSupport Manager, abusing BNB Smart Chain bulletproof hosting, fake CAPTCHA prompts, a vulnerable driver to kill EDR, and rundll32.exe execution of disguised DLLs with ordinal calls. Weekly headlines also cover a Microsoft Defender 'ShieldCrash' zero-day exploit released after September 2026 Patch Tuesday, a North Korean Linux espionage toolkit backdooring HAProxy, and a multi-hop Google-domain redirect phishing campaign.
Cisco Talos reports in-the-wild exploitation of critical FMC flaw CVE-2026-20079 by three clusters including a Sandworm-linked APT and Qilin ransomware affiliates.
Cisco Talos is tracking active exploitation of CVE-2026-20079 (CVSS 10.0), an authentication bypass in Cisco Secure Firewall Management Center that lets unauthenticated remote attackers execute scripts and obtain root access, and CVE-2026-20316 (CVSS 5.3), which permits low-privileged logins and can be chained for privilege escalation. Talos identified three post-compromise clusters: UAT-12197 deploying JSP web shells and a JAR command executor for credential theft; UAT-11823, an APT overlapping with Sandworm, deploying a Netcat reverse shell and Cyclops Blink malware; and UAT-11988, assessed as a ransomware operator with TTPs consistent with Qilin affiliates. Hotfixes are available, with a comprehensive hardening release due the week of September 14, 2026.
Cisco Talos details ClearFake's fake-CAPTCHA chain deploying ZigCryptoStealer with a BYOVD attack that kills EDR processes, observed at a Ukrainian government organization in April 2026.
ClearFake compromises websites, injects JavaScript via a malicious Cloudflare Worker, retrieves instructions from BNB Smart Chain contracts (EtherHiding), and presents a fake Google CAPTCHA that tricks Windows users into pasting a command that loads a remote library over WebDAV via rundll32. The crypto-stealer branch uses DLL side-loading with a signed Chrome component to launch ZigCryptoStealer, which hijacks clipboard cryptocurrency addresses, alongside a signed but vulnerable Windows driver used in a BYOVD attack to terminate EDR processes. A parallel branch delivers Amatera secondary payloads that install a hidden remote-access client providing operator desktop control, with Cisco Talos tracking the remote-loader activity as UAT-10820. Talos observed unusual remote library execution at a Ukrainian government organization in April 2026 and assesses the attacks are part of a broader theft operation rather than a single targeted campaign.
Cisco Talos details ClickFix campaigns abusing fake Google CAPTCHA prompts, WebDAV and BNB Smart Chain to deploy the Amatera infostealer.
Cisco Talos identified a multi-stage campaign, first observed in April 2026 when a Ukrainian government organization executed a disguised DLL named verification.google from a WebDAV path. The chain combines ClearFake JavaScript injected via malicious Cloudflare Workers, EtherHiding payloads stored in BNB Smart Chain contracts, ClickFix social engineering, and WebDAV-hosted DLL loaders to deliver the Amatera (ACR Stealer) infostealer. The Amatera configuration contained over 400 collection entries targeting browsers, messengers, crypto wallets, password managers, FTP and VPN tools, hunting for .kdbx, .p12, .pfx and .pem files. The pf.ch branch deploys ZigCryptoStealer, an EDR-terminating vulnerable driver and Go-based reverse TCP proxies, while the verification.google branch installs NetSupport Manager, supporting moderate-confidence attribution of the UAT-10820 activity to a Russian actor.
Cisco Talos details a crypto-theft ClickFix campaign abusing Google Sheets to swap wallet addresses, with about $10,000 in observed Bitcoin losses.
Cisco Talos tracks a ClickFix-style campaign that tricks cryptocurrency traders into pasting JavaScript into Chrome's address bar or a Tampermonkey extension, promising fake bonuses on SwapZone and SimpleSwap. The loader pulls obfuscated JavaScript from cells in a public Google Sheet via the Visualization API, then behaves like a web skimmer, rewriting deposit addresses on screen, in web responses, and in the clipboard. Researchers counted 49 attacker-controlled Bitcoin addresses, with 24 receiving a combined 0.159 BTC, roughly $10,000, by early August 2026. A Tampermonkey variant re-injects the payload on every return visit, giving the attackers persistence despite takedown efforts.
Microsoft's September 2026 Patch Tuesday fixes 973 vulnerabilities, including 113 critical, with two Windows privilege-escalation bugs (CVE-2026-81963, CVE-2026-85880) exploited in the wild.
Microsoft's September 2026 security update addresses 973 vulnerabilities across its product lineup, 113 rated critical, of which 82 are remote code execution flaws. Two vulnerabilities are confirmed exploited in the wild: CVE-2026-81963, an elevation-of-privilege flaw in the Windows Update Stack (CVSS 7.8), and CVE-2026-85880, a heap-based buffer overflow in Windows Advanced Local Procedure Call (CVSS 7.8). Microsoft flags several bugs as more likely to be exploited, including a 9.8 RCE in Windows DNS Server (CVE-2026-69730), an 8.8 RCE in Windows Kerberos (CVE-2026-69676), and a 9.0 EoP in Spring Cloud Azure (CVE-2026-69854). Cisco Talos published accompanying Snort rules to detect exploitation attempts against the prominent flaws.
Cisco Talos details ClearFake WebDAV chains delivering Amatera stealer to a Ukrainian government organization, with cryptocurrency and credential theft payloads.
Cisco Talos investigated DLL executions named 'verification.google' via WebDAV UNC paths at a Ukrainian government organization, tracking the actor as UAT-10820 and assessing with moderate confidence the activity is Russian and opportunistic rather than targeted. The infection chain uses ClearFake JavaScript injected via a Cloudflare Worker, EtherHiding storage on BNB Smart Chain contracts, and a ClickFix fake Google CAPTCHA prompt to deliver Amatera stealer. Secondary payloads differ by C2: one loader deploys ZigCryptoStealer with a Go reverse TCP proxy and a vulnerable driver that kills EDR, while the other installs an unauthorized NetSupport Manager with a Russia-based C2. Similar Amatera chains were separately documented by Malwarebytes and Blackpoint Cyber, but with no shared infrastructure.
Talos tracks a crypto-theft campaign abusing the Google Visualization API for C2, using browser-based ClickFix lures to inject web-skimmer JavaScript.
Criminal actors convinced targets to paste JavaScript into Chrome's address bar or install it in the Tampermonkey extension, injecting a web skimmer into sessions on two cryptocurrency trading websites; Tampermonkey also provides persistence. Since March 2026 the campaign retrieved obfuscated scripts via the Google Visualization API from public Google Sheets documents, hooking the fetch API and replacing cryptocurrency deposit addresses in responses and the clipboard. Lures pose as leaked reports of a nonexistent API flaw at cryptocurrency swap services and spread via Telegram, DarkForums, and paste sites since early October 2025. Talos warns the legitimate-service-abuse techniques could enable wider supply-chain attacks on e-commerce and customer-facing systems.
Cisco Talos newsletter features adversary-engagement podcast, flags AI guardrail 'safety penalty' slowing defenders, and recaps McKesson breach and PaperCut patching headlines.
The Threat Source newsletter spotlights the Beers with Talos podcast, in which researcher Azim Khodjibaev describes maintaining eight dark-web personas to identify prolific cybercriminals and support disruption efforts. Talos also argues frontier AI guardrails impose an AI 'safety penalty', citing a July 2026 incident where Hugging Face's primary cloud LLM refused to analyze forensic breach data and delayed response. Recapped headlines include ShinyHunters claiming theft of 284 million patient records from McKesson via vishing and Okta account takeover, Anthropic warning Claude users about infostealer malware, and PaperCut issuing emergency patches for chained vulnerabilities.
Weekly ThreatsDay bulletin details a ShinyHunters-style social engineering hit on ReliaQuest, the 296,000-device Dysphoria IoT botnet, and several new malware families.
ReliaQuest confirmed a social engineering attack on August 22, 2026, in which an attacker used a fake SSO page and MFA push approval to gain brief view-only access to an identity dashboard, with tactics matching ShinyHunters, which has since listed the firm on its leak portal. The Shadowserver Foundation reported the Dysphoria botnet has compromised nearly 296,000 IoT devices for DDoS attacks and recently added residential proxy capability. Cisco Talos documented JWR, an operator-driven phishing-as-a-service framework linked to The Outsider that harvests credentials, identity documents, and 2FA codes over an encrypted WebSocket. New malware coverage includes the Octagon Android fraud bot ($1,400/month), the C2Looper Rust backdoor delivered via ClickFix, and the Aeternum loader that moved C2 to the Polygon blockchain.
Cisco Talos exposes UAT-10147, a Chinese-speaking group using AI tools to automate intrusions, deploy SPECTRE, BadIIS, and rootkits against web servers worldwide.
Cisco Talos detailed UAT-10147, a Chinese-speaking cybercrime group conducting SEO fraud and data theft against Windows and Linux web servers in education, media, technology, and gaming sectors, with most victims in Brazil, Bolivia, China, Canada, and Vietnam. The actor exploits publicly disclosed vulnerabilities for initial access, including Zimbra (CVE-2022-27925) and Alibaba Nacos (CVE-2021-29441), and abuses Linux LPE flaws like CVE-2022-0847 and CVE-2021-3156 for root. Its toolset includes AI-assisted frameworks DeepAudit and PentestGPT, plus implants such as SPECTRE, BadIIS, Quasar RAT, Gh0stCringe, and Noodle RAT. An exposed directory contained a target list of roughly 170,000 URLs, with the US, India, UK, Germany, and Netherlands as top destinations.
Cisco Talos's David Bianco argues AI guardrail customization requires operational sovereignty so defenders retain the advantage over attackers.
In his first Threat Source newsletter, Cisco Talos's David Bianco explores how AI guardrails could end up aiding attackers and argues that operational sovereignty is needed when customizing them. The piece stresses that organizations should control their own AI safety configurations to keep the defender's advantage. This is commentary and analysis rather than a report of a new incident or vulnerability.
Cisco Talos explains JavaScript obfuscation techniques used by phishing kits and the approaches researchers use to reverse them.
Cisco Talos published an educational walkthrough of JavaScript obfuscation as used in modern phishing kits. The piece covers why analysts deobfuscate malicious scripts and outlines several practical approaches to reversing obfuscated code. The techniques help defenders unpack phishing kit payloads during investigations.
Cisco Talos argues restrictive frontier AI models impose a 'safety penalty' on security teams, urging operational sovereignty for defensive AI in incident response.
Cisco Talos published commentary arguing that increasingly restrictive frontier AI models create a 'safety penalty' that slows real-time incident response. It recommends organizations pursue operational sovereignty so defensive AI can keep pace with unconstrained adversaries.
Cisco Talos analyzes the White House memorandum on private-sector participation in government-authorized offensive cyber operations.
A new White House memorandum addresses private sector participation in government-authorized offensive cyber operations. Cisco Talos's newsletter, introduced by new author Mick Baccio, explores the operational and security implications of this policy for the cybersecurity industry.
Cisco Talos identifies UAT-10147 deploying the SPECTRE implant with cross-platform C2, credential theft, and kernel-level EDR bypass.
Cisco Talos reports that the tracked threat actor UAT-10147 is deploying a newly identified implant named SPECTRE. SPECTRE supports cross-platform command-and-control, process injection, credential theft, and anti-analysis protections. It also includes a Linux rootkit and BYOVD (bring your own vulnerable driver) capability enabling kernel-level EDR bypass, marking an evolution in commodity intrusion tooling.
Cisco Talos tracks UAT-10147, a Chinese-speaking cybercrime group exploiting vulnerable web servers and using agentic AI in post-compromise operations.
Cisco Talos identified a Chinese-speaking cybercrime group tracked as UAT-10147 that targets a wide range of vulnerable web servers. The report maps affected countries and analyzes the impact of BadIIS infections on compromised servers. It also documents the attack chain and emerging use of agentic AI during post-compromise activities.
Cisco Talos researcher Martin explains how crime script analysis describes attacks in everyday language, aiding communication and identifying disruption points.
Cisco Talos published a methodology piece on applying crime script analysis to cybersecurity incidents. The approach describes each stage of an attack in everyday language, making technical incidents accessible to non-technical audiences. It also helps defenders identify points in the attack chain where the crime can be disrupted.
Rig exploit kit activity dropped roughly 75% after the pseudo-Darkleech and EITest campaigns stopped using EKs, reflecting an overall decline in exploit kit activity.
Rig EK activity fell sharply in 2017: the pseudo-Darkleech campaign disappeared at the end of March, cutting Rig traffic about 50%, and the EITest campaign switched to tech support scams in late April, cutting another 50% in May. Broader causes include a shrinking browser target base, no major EK zero-day in over a year, and community takedowns of domain shadowing infrastructure. Criminals are shifting to malspam, social engineering schemes like fake HoeflerText notifications, and tech support scams.
Cisco Talos' Threat Source newsletter reflects on the 'Make Hazel a Hacker' segment and how cybersecurity questions can have multiple correct answers.
In this edition of the Threat Source newsletter, William reflects on the 'Make Hazel a Hacker' segment from the Beers with Talos podcast. The piece discusses how cybersecurity is a field where questions can lead to multiple correct answers. It is commentary and career discussion rather than threat intelligence or research.
Cisco Talos uncovered an undocumented phishing framework branded JWR that impersonates checkout and login pages of major payment and shopping platforms.
Cisco Talos researchers identified an undocumented phishing framework internally branded JWR by its developer. The framework is built to convincingly impersonate checkout and login pages across major payment and shopping platforms, likely to harvest credentials and payment details. Talos's analysis details the framework's infrastructure and impersonation capabilities, giving defenders indicators to detect campaigns using it.
Out-of-Bounds Write in Linux Kernel watch_queue Enables Local Privilege Escalation
CVE-2022-0995 is an out-of-bounds (OOB) memory write in the Linux kernel's watch_queue event notification subsystem (CWE-787) that can overwrite parts of kernel state. A local user can trigger it through the watch_queue interface, for example by supplying a crafted event filter definition, causing the kernel to write beyond allocated memory when event notifications are processed. Successful exploitation may allow the local user to gain privileged (kernel/root) access or crash the system, yielding high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8, local attack vector). Affected systems include mainstream Linux kernels (Fedora is explicitly listed) and NetApp HCI appliance firmware products that ship the affected kernel. The flaw is confirmed exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2026-08-26, two public proof-of-concepts are available, and EPSS puts 30-day exploitation probability at 9.5% (95th percentile), though ransomware use is unconfirmed.
· Linux kernel Kernels shipping the watch_queue event notification subsystem prior to patched/upstream fixes (see distribution advisories for exact affected and fixed versions · Fedora Project Fedora Fedora releases with affected kernel packages prior to the issued kernel updates (see Fedora/Red Hat advisories) KEV PoC ×2mass
Hard-Coded Password Vulnerability in Cisco Secure Firewall Management Center
Cisco Secure Firewall Management Center (FMC), formerly Firepower Management Center, contains a use of hard-coded password vulnerability (CWE-259) that allows an unauthenticated, remote attacker to log in to an affected system. By authenticating with the built-in hard-coded credentials for a low-privileged account, the attacker can gain access to sensitive data within the impacted systems. Any organization running an affected Cisco FMC deployment is exposed, particularly where the management interface is reachable from untrusted networks. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2026-07-29, indicating active exploitation in the wild, and related reporting describes active exploitation of FMC vulnerabilities. No CVSS score or public proof-of-concept is yet available, but EPSS assigns a 9.8% probability of exploitation within 30 days (95th percentile).
· Cisco Secure Firewall Management Center (FMC) KEV ransomwarelarge
Critical unauthenticated file-path RCE in Microsoft Skype for Business
CVE-2026-66302 is a critical (CVSS 9.8) vulnerability in Microsoft Skype for Business in which an external attacker controls the file name or path used by the software (CWE-73, external control of file name or path). The flaw is exploitable over a network with no authentication, no privileges, and no user interaction, so a remote unauthenticated attacker who can reach the affected Skype for Business service can trigger it. Successful exploitation yields remote code execution on the target, with high impact on confidentiality, integrity, and availability. Any organization running the affected Skype for Business deployment, presumably the on-premises Skype for Business server product, is affected; the available data does not specify the exact affected version ranges. No public proof-of-concept is known, the CVE is not in CISA's KEV catalog, and EPSS assigns roughly a 0.5% probability of exploitation in the next 30 days, so no exploitation is currently known.
Unauthenticated Heap Overflow RCE in Microsoft Windows DHCP Server
CVE-2026-69845 is a heap-based buffer overflow caused by improper input validation (CWE-20/CWE-122) in the Windows DHCP Server service, letting an unauthorized remote attacker execute arbitrary code with no privileges or user interaction required. An attacker triggers it by sending specially crafted DHCP network traffic to a machine running the DHCP Server role, and successful exploitation gives full compromise of the affected host (confidentiality, integrity, and availability all rated high per the 9.8 CVSS score). Affected products span Windows 10 1607 and 1807/1809-era releases through Windows Server 2012, 2016, 2019, 2022, and 2025, meaning both legacy out-of-support and current server builds are exposed. Microsoft addressed the flaw in the September 2026 Patch Tuesday release. No public proof-of-concept or in-the-wild exploitation is known, and EPSS currently puts 30-day exploitation probability at about 1%.
· microsoft windows 10 1607 1607 (all editions/branches in this build line as listed by Microsoft) · microsoft windows 10 1809 1809 (LTSC/Server-equivalent branch as listed by Microsoft)mass
Kerberos Capture-Replay Authentication Bypass in Microsoft Windows (RCE)
CVE-2026-69676 is a capture-replay authentication bypass (CWE-294) in the Windows Kerberos implementation, disclosed by Microsoft as part of the September 2026 Patch Tuesday. An attacker who is already authorized (low-privilege credentials) can replay captured authentication material over the network to bypass authentication checks. Successful exploitation results in remote code execution, with high impact on confidentiality, integrity, and availability (CVSS 3.1 score of 8.8). Any organization running Windows in an Active Directory environment is potentially affected, since Kerberos is the default authentication protocol for Windows domains. As of this analysis there is no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a ~1.2% chance of exploitation within 30 days, though it shipped in a record-sized Patch Tuesday release alongside two actively exploited zero-days.
· Microsoft Windows (Kerberos authentication implementation)mass
Heap Overflow in Microsoft Windows Secure Kernel Mode Allows Local Privilege Escalation
CVE-2026-69906 is a heap-based buffer overflow (CWE-122) in Windows Secure Kernel Mode, the isolated, higher-trust kernel component that underpins Microsoft's Virtualization-Based Security (VBS). It is triggered locally by an already-authorized attacker who holds high privileges on the machine (CVSS PR:H), with no user interaction required. Successful exploitation allows the attacker to elevate privileges into the secure kernel's trust scope (CVSS scope-changed, S:C), with high impact to confidentiality, integrity, and availability, and potential undermining of VBS-protected assets such as credential isolation. Affected systems are Microsoft Windows releases that ship the Secure Kernel Mode component; the source data does not enumerate specific affected version ranges, and fixes shipped in Microsoft's September 2026 Patch Tuesday, whose coverage also highlighted related Snort detection rules. As of publication there is no known public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation within 30 days (25th percentile).
· Microsoft Windows (Secure Kernel Mode component / Virtualization-Based Security)mass
Integer Overflow in Windows Secure Kernel Mode Enables Local Privilege Escalation
CVE-2026-69846 is an integer overflow or wraparound flaw (CWE-190) in the Windows Secure Kernel Mode, the isolated kernel component that underpins Virtualization-Based Security features such as Credential Guard. It is triggered locally by an authorized attacker who already holds high privileges on the machine (per the CVSS PR:H vector), by causing a size or count computation to wrap around and corrupt secure kernel memory. Successful exploitation lets the attacker elevate privileges across a security boundary (CVSS Scope: Changed), potentially gaining code execution at a higher trust level and undermining VBS-based protections. All Windows builds listed for this CVE in Microsoft's September 2026 Patch Tuesday advisory are affected; the available data does not enumerate specific versions, so administrators should consult the advisory for exact ranges. There is currently no public proof-of-concept, no entry in CISA's KEV catalog, and only a modest 0.3% EPSS probability of exploitation within 30 days, so no in-the-wild exploitation is known.
Untrusted Pointer Dereference LPE in Windows Secure Kernel Mode
CVE-2026-83939 is an untrusted pointer dereference (CWE-822) in the Windows Secure Kernel Mode, the high-privilege virtualization-based security component of Windows. A local attacker who is already authorized and holds high privileges on the system can trigger the flaw by causing the Secure Kernel to dereference an attacker-influenced pointer, gaining local elevation of privileges. Because the CVSS scope is 'changed' (S:C), the flaw lets an attacker cross a security boundary beyond the process they started in, with high impact on confidentiality, integrity and availability. Any Windows installation whose Secure Kernel component is affected is at risk, per Microsoft's September 2026 Patch Tuesday advisory; exact version ranges are listed in Microsoft's bulletin. There is no known in-the-wild exploitation, no public proof-of-concept, and a low 0.3% EPSS probability of exploitation in the next 30 days, but a fix shipped as part of the 974-vulnerability September 2026 release.
· Microsoft Windows (Secure Kernel Mode component)mass
Heap-Based Buffer Overflow in Windows Deployment Services Allows Local Code Execution
CVE-2026-72957 is a heap-based buffer overflow (CWE-122) in Microsoft's Windows Deployment Services (WDS), the optional Windows Server role used for network-based operating system deployment such as PXE boot and imaging. The flaw is triggered locally: an authorized, low-privileged attacker sends crafted input to the WDS service, overflowing a heap buffer with no user interaction required. Successful exploitation allows the attacker to execute code locally on the affected server, and the high confidentiality, integrity, and availability ratings combined with the low privilege requirement are consistent with a local elevation-of-privilege outcome. Any organization running the WDS server role on Windows Server is affected; the provided data does not specify which Windows Server versions are impacted. As of the available data the flaw is not known to be exploited: it is absent from CISA KEV, has no public proof-of-concept, carries a low 0.3% EPSS score, and was addressed in Microsoft's September 2026 Patch Tuesday.
· Microsoft Windows Deployment Services (Windows Server role)large
Out-of-Bounds Read in Windows Virtualization-Based Security (VBS) Enclave
An out-of-bounds read (CWE-125) in the Windows Virtualization-Based Security (VBS) Enclave allows a locally authenticated, low-privilege attacker to read memory beyond the enclave's intended boundary. It is triggered by code running locally under an authorized account that interacts with the enclave, with no user interaction required. The result is information disclosure only - potentially leaking data the enclave was meant to isolate, such as secrets or protected content - with no impact on integrity or availability. Any Windows system with VBS Enclave support is affected; Microsoft patched the issue in its September 2026 Patch Tuesday release, which fixed 974 vulnerabilities. No public proof-of-concept exists, the flaw is not in CISA's KEV catalog, and EPSS assigns roughly a 0.3 percent 30-day exploitation probability, so no exploitation is currently known.
· Microsoft Windows Virtualization-Based Security (VBS) Enclavemass
Entities are extracted by the model from each article. Watching an entity keeps it in this browser only (no account); the watchlist page and dashboard alerts use it.