Microsoft is telling enterprises to migrate away from Slmgr.vbs, the VBScript-based tool used to manage Windows product activation, because VBScript itself is being phased out of Windows. The company recommends switching to PowerShell equivalents before VBScript is removed entirely in a future Windows release.
techspot.com
· 2026-09-12
Microsoft has identified a malware campaign named TerminalFix that mimics Cloudflare and other trusted verification pages to trick Windows users into pasting commands into PowerShell or Command Prompt. Unlike earlier ClickFix attacks that used the Run dialog for simpler commands, TerminalFix's terminal-based approach lets attackers run longer, multi-stage scripts that establish persistent proxy access into a victim's machine and network.
techspot.com
· 2026-09-03
Microsoft has identified a new ClickFix-style social engineering campaign called TerminalFix, which uses fake Cloudflare CAPTCHA prompts to trick users into pasting malicious commands into Windows Terminal or PowerShell. Once executed, the command triggers a multi-stage attack chain designed to give attackers a persistent foothold inside enterprise systems.
darkreading.com
· 2026-08-31
Microsoft has identified a new ClickFix-style attack called TerminalFix that uses fake Cloudflare CAPTCHA pages on compromised websites to trick users into pasting and running malicious PowerShell commands in Windows Terminal. Rather than deploying simple infostealers, the campaign runs a multi-stage chain that hides payloads inside PNG images via steganography, establishes persistence through scheduled tasks and registry keys, and ultimately installs a custom Python-based reverse tunnel into the victim's internal network.
bleepingcomputer.com
· 2026-08-31