Brevo disclosed that hackers obtained a hardcoded, full-permission Cloudflare API key and used it to deploy a rogue Cloudflare Worker that rewrote content at the CDN edge for roughly 5.5 hours on September 14. The tampered scripts, including Brevo's forms widget, Conversations tool and SDK loader embedded on customer sites, were altered to serve ClickFix malware while stripping security headers to evade detection.
bleepingcomputer.com
· 2026-09-17
Security researchers say attackers compromised HBO Max's official Reddit account and used it to post hundreds of fake ads linking to a lookalike site that runs a ClickFix scam. The scheme tricks visitors into copying and pasting a malicious command into their Terminal or Command Prompt, which silently installs info-stealing malware. Warner Bros. Discovery has not responded to requests for comment, and it's unclear how many users were affected.
techcrunch.com
· 2026-09-14
Homebrew, the widely used macOS package manager, has shipped version 7.0.0 with a fully released BrewUI graphical interface for macOS 26 'Tahoe' and later, letting users browse packages and dependencies visually instead of via command line. The update also introduces a new 'brew vulns' command backed by a Homebrew-specific advisory database, which cross-references installed formulae against OSV.dev vulnerability records.
bleepingcomputer.com
· 2026-09-14
Attackers took over HBO Max's official, verified Reddit account and used it to post 108 malicious ads over roughly two days, tricking Windows and macOS users into installing information-stealing malware. The ads used the ClickFix technique, luring victims into pasting attacker-supplied commands into Run, PowerShell, or Terminal under the guise of fixing errors or verifying CAPTCHAs, with some posts impersonating a fake HBO Max app and others posing as AI tools or developer utilities.
bleepingcomputer.com
· 2026-09-14
Security researchers report that ClickFix-style attacks, which trick users into copying and running malicious commands via fake CAPTCHA pop-ups, are proliferating across both Windows and Mac systems. Researcher Kevin Beaumont notes victims are flooding Reddit for help, and attackers are now compromising legitimate websites to embed these prompts, making the scam harder to spot.
techspot.com
· 2026-09-14
Security researchers report that ClickFix, a malware technique relying on fake CAPTCHA prompts and terminal commands, has exploded in popularity among attackers, including state-backed hacking groups. The attack tricks victims into copying and pasting a malicious command into Windows Run, PowerShell, or macOS Terminal after clicking through a fraudulent verification screen on a compromised website.
arstechnica.com
· 2026-09-11
Cisco Talos researchers identified two separate ClickFix-style social engineering campaigns that trick victims into executing malicious code themselves, one aimed at stealing cryptocurrency and another designed to gain persistent enterprise network access. One campaign uses a publicly shared Google Sheet to distribute malicious browser code that hijacks Chrome transaction interfaces, while both operations abuse legitimate cloud services and trusted software to disguise malicious activity as normal user behavior.
darkreading.com
· 2026-09-08
Netskope researchers found over 5,400 compromised small-business websites, mostly running WordPress and PrestaShop, injected with scripts that fetch malicious payloads from smart contracts on the BNB Smart Chain Testnet. Visitors are shown a fake CAPTCHA that tricks them into pasting a PowerShell command via the Windows Run dialog, which downloads and runs the attacker's final payload. Later in the campaign, attackers swapped the ClickFix payload for a stealthier WebRTC data-channel stager that opens a covert encrypted connection without a genuine handshake.
bleepingcomputer.com
· 2026-09-05
Microsoft has identified a malware campaign named TerminalFix that mimics Cloudflare and other trusted verification pages to trick Windows users into pasting commands into PowerShell or Command Prompt. Unlike earlier ClickFix attacks that used the Run dialog for simpler commands, TerminalFix's terminal-based approach lets attackers run longer, multi-stage scripts that establish persistent proxy access into a victim's machine and network.
techspot.com
· 2026-09-03
GuidePoint Security's research team found that attackers have breached at least 31 organizations—spanning e-commerce, professional services, and retail logistics—using a ClickFix campaign that leverages the Polygon blockchain to conceal command-and-control infrastructure. The technique, dubbed EtherHiding, lets attackers dynamically update C2 server locations via blockchain transactions instead of relying on a single fixed address.
darkreading.com
· 2026-09-01
Microsoft has identified a new ClickFix-style social engineering campaign called TerminalFix, which uses fake Cloudflare CAPTCHA prompts to trick users into pasting malicious commands into Windows Terminal or PowerShell. Once executed, the command triggers a multi-stage attack chain designed to give attackers a persistent foothold inside enterprise systems.
darkreading.com
· 2026-08-31
Microsoft has identified a new ClickFix-style attack called TerminalFix that uses fake Cloudflare CAPTCHA pages on compromised websites to trick users into pasting and running malicious PowerShell commands in Windows Terminal. Rather than deploying simple infostealers, the campaign runs a multi-stage chain that hides payloads inside PNG images via steganography, establishes persistence through scheduled tasks and registry keys, and ultimately installs a custom Python-based reverse tunnel into the victim's internal network.
bleepingcomputer.com
· 2026-08-31