LIVE · cybersecurity feed
Live wire
CVE-2026-86360 · Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root AccessCVE-2026-21589 · Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 ProductsCVE-2026-88779 · Citrix NetScaler Hit by Third Actively Exploited Zero-DayClingSTUN Malware Turns IoT Devices Into Proxy NodesCVE-2026-61500 · Rejetto HFS servers now actively scanned for critical RCE flawCVE-2026-88779 · Citrix NetScaler Flaw Exploited Before CVE PublicationCVE-2026-88779 · NetScaler CVE-2026-88779 Exploited Before PublicationCVE-2022-28368 · dompdf_project dompdf XSS flaw added to VulnCheck KEVCVE-2026-88771 · Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploitedWarlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure
patch

ClickFix Attack Hides VBScript Payload in Browser Cache

A new "ClickFix" social engineering campaign has been identified that leverages browser caches to conceal malicious VBScript payloads. The technique, detailed by Microsoft Threat Intelligence on October 3, involves compromised websites pre-fetching a script disguised as an image into a visitor's browser cache. This allows the payload to be present on the victim's device before they are tricked…

ZeroDay News ·

Source: Infosecurity Magazine

A new "ClickFix" social engineering campaign has been identified that leverages browser caches to conceal malicious VBScript payloads. The technique, detailed by Microsoft Threat Intelligence on October 3, involves compromised websites pre-fetching a script disguised as an image into a visitor's browser cache. This allows the payload to be present on the victim's device before they are tricked into executing it.

The attack begins with a fake CAPTCHA pop-up instructing users to open the Windows Run dialog, paste a command from their clipboard, and press Enter. By pre-loading the VBScript into the cache, the attackers circumvent the Run dialog's character limit, as the pasted command only needs to locate and launch an existing file.

The command executed by the victim runs `cmd.exe`, which then searches the browser profile folder for cached files starting with "f_". Unlike previous iterations that might have searched for specific content markers, this campaign identifies the malicious file by comparing its size against an expected value. Once located, the file is copied to a temporary folder, renamed with a `.vbs` extension, and executed using `wscript.exe`.

The VBScript then proceeds to gather host details via Windows Management Instrumentation (WMI). It subsequently fetches and executes a PowerShell script, bypassing the system's execution policy. Later stages of the attack involve compiling and loading additional code in memory, which is then injected into the legitimate `timeout.exe` process. This injected code is designed for credential theft, targeting browsers and other device information.

For persistence, the malware connects to attacker-controlled servers and unpacks a Python interpreter using the built-in `tar.exe` utility. It then establishes a scheduled task that runs a Python payload through `pythonw.exe`, ensuring the attackers maintain a foothold on the compromised system even after a reboot.

Microsoft Defender Antivirus identifies and blocks malicious command execution related to this campaign as `Trojan:Win32/ClickFix` and `Trojan:Win32/TermFix`. Microsoft recommends several protective measures, including enabling cloud-delivered protection, network protection, application control, and PowerShell script-block logging. For threat hunting, the company advises looking beyond typical download events to analyze browser activity, unusual `WScript`, PowerShell, and scheduled task activity, and the `RunMRU` registry key, which logs commands entered into the Run dialog. Microsoft also emphasized that legitimate CAPTCHA challenges should never prompt users to execute code.

patch
ShareXLinkedInWhatsAppFacebook

More News

view all →
CVE-2026-86360critical

Dell Urges Customers to Patch Critical DSU Flaw That Can Give Attackers Root Access

Dell has issued an urgent advisory to customers, recommending they patch a critical vulnerability in its System Update (DSU) tool that could allow attackers to gain root access on affected PowerEdge servers. The flaw, identified as CVE-2026-86360, carries a CVSS score of 9.6, indicating its severe potential impact.

breach

FBI Removes Accenture Contractor After Patch Failure Led to ShinyHunters Breach

The U.S. Federal Bureau of Investigation (FBI) has reportedly removed an Accenture contractor following an alleged security failure that contributed to a data breach attributed to the ShinyHunters threat group. This incident is said to have resulted in the theft of personal details belonging to thousands of FBI employees. The reported cause of the breach was a patch failure.

malware

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

Fortinet's FortiGuard Labs has detailed a new Linux backdoor, dubbed ClingSTUN, which leverages legitimate public Session Traversal Utilities for NAT (STUN) infrastructure to mask its command and control (C2) communications. The malware primarily targets unpatched Internet of Things (IoT) devices, functioning as a back-connect proxy that turns compromised systems into remotely controlled nodes.

security

Microsoft extends the Outlook naughty step with two more file types

Microsoft is implementing new security measures for Outlook, adding two file types, .msix and .msixbundle, to its default block list for attachments. These file types are associated with Windows application packages and bundles. The change is set to affect users of the New Outlook for Windows client and Outlook on the Web within Exchange Online.

ai

Mitigate Risks of AI-Generated Apps by Citizen Coders

The increasing use of AI tools by non-technical employees, often referred to as "citizen coders," to develop workplace applications presents significant security and data risks for organizations. While these AI-generated applications can boost productivity and streamline workflows, their rapid creation without proper oversight can lead to "shadow AI" assets with critical vulnerabilities,…

CVE-2026-21589critical

Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

A critical vulnerability has been reported in eight Atlassian Data Center products, enabling unauthenticated attackers to read known files within the web application root directory. The flaw, identified as CVE-2026-21589, was disclosed by Atlassian on October 5th and carries a CVSS rating of 9.3 out of 10, indicating its severe impact and ease of exploitation.