Critical

ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain

darkreading
Actively Exploited

Overview

A recent cyber campaign known as ClickFix has compromised 31 organizations by utilizing a technique called EtherHiding. This method allows attackers to dynamically update their command-and-control server while exploiting the Polygon blockchain as a form of an address book under their control. The campaign's use of blockchain technology for malicious purposes raises significant concerns about the security of decentralized systems. As these incidents become more common, organizations need to be vigilant about their security practices and the potential for blockchain to be used in cyberattacks. The implications of such tactics could lead to more sophisticated phishing attacks and data breaches.

Key Takeaways

  • Active Exploitation: This vulnerability is being actively exploited by attackers. Immediate action is recommended.
  • Affected Systems: 31 organizations affected
  • Action Required: Organizations should enhance their security protocols, monitor blockchain transactions, and educate staff on recognizing phishing attempts.
  • Timeline: Newly disclosed

Original Article Summary

The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.

Impact

31 organizations affected

Exploitation Status

This vulnerability is confirmed to be actively exploited by attackers in real-world attacks. Organizations should prioritize patching or implementing workarounds immediately.

Timeline

Newly disclosed

Remediation

Organizations should enhance their security protocols, monitor blockchain transactions, and educate staff on recognizing phishing attempts.

Additional Information

This threat intelligence is aggregated from trusted cybersecurity sources. For the most up-to-date information, technical details, and official vendor guidance, please refer to the original article linked below.

Related Topics: This incident relates to Phishing, Update.

Related Coverage

FBI Probes Service Selling 153M+ Drivers Licenses

Krebs on Security

A new service on the dark web is offering digital scans of over 153 million drivers licenses from individuals in the U.S. and Canada. This data appears to have been obtained from a well-known identity verification company based in Louisiana. The FBI's New Orleans field office has initiated an investigation to trace the source of these images. This incident raises significant concerns about identity theft, as the availability of such personal information can lead to fraudulent activities. Individuals whose licenses are compromised may face risks to their financial and personal security, highlighting the need for enhanced security measures in data handling by verification companies.

Sep 1, 2026

Hackers abuse Faronics Deploy admin tool to install ScreenConnect

BleepingComputer

Phishing attackers are exploiting the Faronics Deploy endpoint-management tool to gain unauthorized access to victims' computers. By abusing this legitimate software, they can install ScreenConnect, a remote support application, allowing them to control the affected systems remotely. This tactic poses a significant risk to organizations that rely on Faronics Deploy for managing their IT infrastructure, as it can lead to data breaches and unauthorized access to sensitive information. Companies using this software should be vigilant and monitor for any unusual activities. Protecting against such abuses is crucial to maintaining the integrity and security of their networks.

Sep 1, 2026

Aesto Health says data breach affects over 9.5 million patients

BleepingComputer

Aesto LLC, known as Aesto Health, has reported a significant data breach that impacts over 9.5 million patients. The breach was discovered recently, and while specific details about how the breach occurred remain unclear, it raises serious concerns about the security of patient information in the healthcare sector. Aesto Health provides various health-related services, and the exposure of such a large number of personal records can lead to identity theft and other malicious activities. This incident emphasizes the need for healthcare providers to enhance their cybersecurity measures to protect sensitive patient data from unauthorized access. The full implications of this breach are still unfolding, but affected individuals should be vigilant about potential phishing attempts and other fraud schemes that may arise as a result.

Sep 1, 2026

Coast Guard Establishes Office of Maritime Cybersecurity Policy

SecurityWeek

The U.S. Coast Guard has established a new Office of Maritime Cybersecurity Policy to oversee cybersecurity measures for U.S. ports, vessels, and maritime facilities. This office will be responsible for creating and implementing policies aimed at enhancing the security of maritime operations against cyber threats. The move comes amid growing concerns over the vulnerability of critical infrastructure in the maritime sector, which has seen increased cyberattacks in recent years. By centralizing cybersecurity policy, the Coast Guard aims to better coordinate efforts to protect these vital assets. This initiative is crucial for ensuring the safety and security of maritime trade and transportation, which play a significant role in the U.S. economy.

Sep 1, 2026

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

The Hacker News

A serious vulnerability in JFrog Artifactory, identified as CVE-2026-82329, has been actively exploited by attackers just days after it was publicly disclosed. This flaw, which has a CVSS score of 9.8, allows for authentication bypass, potentially granting unauthorized administrative access to users. Organizations using JFrog Artifactory are at risk, as attackers can mint admin tokens and gain control over the system. The urgency of addressing this vulnerability is underscored by its exploitation in the wild, prompting immediate action from affected users to secure their installations and prevent unauthorized access.

Sep 1, 2026

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

The Hacker News

Breeze Comet, a financially motivated cybercriminal group, has been targeting Brazilian financial services, retail, and e-commerce sectors since 2024. This group, previously known as UNC5669, has been manipulating payment systems and banking software to carry out hundreds of fraudulent transactions. Researchers from Google Threat Intelligence Group and Mandiant have identified the group's methods, which involve exploiting vulnerabilities in Brazilian payment systems. The impact of these attacks is significant, as they undermine trust in online transactions and can result in substantial financial losses for businesses and consumers alike. Companies in Brazil need to bolster their security measures to protect against these sophisticated forms of fraud.

Sep 1, 2026