ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser’s cache.

“Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file,” the Microsoft Threat Intelligence team said in a post on X.

Source: The Hacker News

Leave a Reply

Your email address will not be published. Required fields are marked *

Explore More

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoning

OpenAI, Anthropic, Google API Flaw Let Weaker AI Models Decode Stronger Models’ Reasoning A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API

AI Tutoring with Khanmigo in a Two-Year School Experiment

AI Tutoring with Khanmigo in a Two-Year School Experiment Source: Hacker News

An algorithmic failure beneath the secret ballot

An algorithmic failure beneath the secret ballot Source: Hacker News