“Reddit is becoming post after post after post of people getting their computer infected via ClickFix,” independent researcher Kevin Beaumont observed Thursday. “Legit websites everywhere [are] ...
The browser says something broke. A CAPTCHA wants proof you’re human. The fix looks easy: open Windows Run, paste a command, press Enter. Convenient. Also deeply suspicious. That sequence is the heart ...
If you clicked on a fake HBO Max ad on Reddit in the past week, you might have fallen victim to a rising "ClickFix" security threat.
ClickFix accounted for 47% of Microsoft Defender Experts initial-access cases in 2025, while a Polygon contract rotated lure hosts.
Remember over a year ago when we reported on the ClickFix malware that uses fake CAPTCHA mechanisms to dupe unwitting victims into pwning their own machines? Well, apparently not enough people shared ...
The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake ...
Research by security firm Arctic Wolf Labs has confirmed a cyberattack campaign in which legitimate small and medium-sized ...
Why ClickFix still drives an estimated 20+ incidents a day at Huntress even after law enforcement disrupted major infostealer ...
A hack at Brevo, an online marketing vendor, created a pathway to place a ClickFix-style attack across numerous websites on ...
Following instructions can lead to bad things, as this increasingly common attack method can bypass Windows protections.
Varonis Threat Labs discovered AvisLoader, a Windows malware loader that uses the Tox peer-to-peer network for C2 and arrives ...
Brevo confirmed that attackers stole a Cloudflare API key and used it to inject malicious ClickFix scripts into its websites ...