Skip to main content

Share story

Security

ClickFix attackers hide executable scripts in browser cache

ClickFix attackers hide executable scripts in browser cache Image: Primary
Microsoft Threat Intelligence has identified a ClickFix attack that stages a malicious script in a browser's cache disguised as a PNG image. Compromised websites then persuade users to run a command that executes the cached content, concealing the script and bypassing the Windows Run dialog's approximately 260-character input limit. The observed chain locates a cache file by its byte length, copies it with a Visual Basic Script extension and executes it. Subsequent stages load code into memory and inject it into a legitimate Windows process to target browser and device credentials. The attack still depends on a user pasting and executing the malicious command.
Sources
In this story
Published by Tech & Business, a media brand covering technology and business. This story was sourced from The Hacker News and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Security
Security

Dell urges System Update patch for flaw enabling root access

Dell urged customers to update its System Update tool after identifying a critical vulnerability that could let an unauthenticated remote attacker execute code with root privileges on vulnerable PowerEdge servers. SecurityAffairs ...

AI Policy
AI Policy

Pentagon says it has ended use of Anthropic products

The Pentagon has completed its phase-out of Anthropic products, the BBC reported, citing the US Department of Defense. The removal followed a dispute over Anthropic's insistence on contractual restrictions against mass surveillanc...

Security Products
Security Products

Texas disclosure puts Oracle healthcare breach at nearly 20 million people

Information released by the Texas attorney general puts the scope of last year's cybersecurity breach at Oracle's healthcare unit at nearly 20 million people, Bloomberg reported. The breach compromised personal information belongi...

Policy Security
Policy Security

OpenAI and Anthropic support mandatory AI breach reporting in Australia

OpenAI and Anthropic told an Australian parliamentary inquiry they would support laws requiring AI developers to disclose breaches involving their systems, EconoTimes reported. The comments follow criticism of OpenAI for waiting t...