Microsoft reported that ClickFix operators have shifted tactics to better evade detection while continuing to use phishing and social engineering to trick users into executing malicious actions that lead to malware delivery and follow-on compromise. Separate reporting also describes Microsoft warning of phishing campaigns designed to establish persistent backdoors on victim endpoints, indicating continued investment by multiple actors in email-led initial access and long-lived footholds.
Other items in the set are not about ClickFix and instead cover unrelated security news and commentary, including EU automotive cybersecurity compliance requirements under Euro 7, an alleged compromise of an FBI wiretap-related system, general governance commentary about limited board time spent on cyber risk, a newsletter-style link roundup, a “News March 2026” aggregation page mixing multiple unrelated stories (Cisco SD-WAN exploitation, a new stealer, Iranian camera targeting, and more), and a security podcast discussing disparate topics (trade-secret theft/zero-day brokering and information manipulation risks).

Get the infrastructure and lures behind it.
2 events from the most recent confirmed update back to the earliest known activity.
A separate report stated that hackers had accessed or tapped an FBI wiretap system. The item indicates a newly disclosed intrusion affecting a U.S. law enforcement surveillance-related system.
Microsoft said attackers behind ClickFix were using a new tactic to evade detection. The report marks a technical development in the ongoing activity by revealing an updated attacker method.
Get the infrastructure, lures, and IOCs behind this campaign, ready to push into your email and identity stack.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.