A ClickFix campaign has been observed hiding a VBScript payload in the browser cache, disguised as an image, so the script was already on the device when the victim was tricked into running a command ...
ClickFix attacks fake CAPTCHA pages to trick users into running malicious commands, delivering malware through compromised websites.
Microsoft observed ClickFix attacks using browser cache smuggling to execute cached VBScript and launch a credential-targeting malware chain.
That old Java icon had a much bigger résumé than I gave it credit for.
Microsoft Threat Intelligence has uncovered a ClickFix campaign in which compromised websites abuse browser cache storage to ...
Ukraine’s Computer Emergency Response Team, discovered more than 100 compromised websites in September 2026 distributing LUNEXSTEALER ...
CERT-UA found 100+ compromised sites using ClickFix lures to distribute LunexStealer to Windows search visitors.
Over 100 hacked Ukrainian websites used fake Cloudflare checks to install Lunex Stealer and steal browser passwords, tokens ...
BragJack, a proof-of-concept attack from Forever Security's Gal Weizman, hijacks the AI assistants in Chrome, Edge, Opera Neon, Perplexity Comet, and Claude in Chrome using one malicious extension.
When writing sample code or configuration examples, I'm sure you've used 'your-domain.com' or 'yoursite.com' for the URL part ...
This is the visibility gap in modern phishing detection. Knowing where a link leads is only the starting point, as analysts also need to understand what unfolds after the page loads. The challenge is ...