Skip to content
tag — clickfix

grep -rl "clickfix" ./articles

#clickfix

7 articles

Microsoft's own figures put weaponisation under a day and remediation at up to sixty, and the most-detected flaw is from 2020

2026-10-03Security

The 2026 Digital Defense Report, covering July 2025 to June 2026, says attackers are collecting the benefits of AI first. Underneath that headline are three numbers that do not need AI to explain them: nearly 40,000 CVEs in six months, a weaponisation median well below 24 hours against 30 to 60 days to remediate, and a 2020 vulnerability still responsible for most detections among the top five.

The payloads sit on a blockchain testnet, which is free

2026-09-08Security

Netskope found over 5,400 compromised WordPress and PrestaShop sites pulling their next stage from smart contracts on the BNB Smart Chain testnet. EtherHiding is not new. Putting it on the testnet is, because the testnet costs nothing, behaves like the real chain, and has no abuse desk to write to.

The rogue ScreenConnect clients infect the hosts that connect to them

2026-09-08Security

Huntress found ScreenConnect clients that write a four-stage VBScript chain onto machines as they connect, profile each host, and then request a different payload depending on how much RAM it has and which EDR is installed. There is no code execution vulnerability to patch — it abuses file transfer, and ConnectWise says the fix is to turn the permission off.

The only thing they changed was telling you to open Terminal instead of Run

2026-08-31Security

TerminalFix is ClickFix with one substitution. A fake Cloudflare CAPTCHA asks you to paste a command, and instead of the Run dialog it sends you to Windows Terminal or PowerShell — where long multi-line scripts actually work. The end of the chain is a Python reverse tunnel that lets the operator reach anything your machine can see.