A new malware variant, identified as TerminalFix, has been discovered by Microsoft. This malicious software tricks users into executing harmful commands through Windows Terminal or PowerShell by presenting fake Cloudflare CAPTCHAs. Unlike previous versions that targeted the Run dialog, this variant's use of the command line interface may increase its success rate.

A newly identified malware variant, dubbed TerminalFix by Microsoft, has been observed leveraging deceptive Cloudflare CAPTCHAs to trick users into executing malicious commands. This particular variant is notable for its method of operation, which involves manipulating users into running harmful instructions through Windows Terminal or PowerShell.
The core mechanism of TerminalFix relies on social engineering, specifically by presenting what appears to be a legitimate Cloudflare CAPTCHA challenge. Users are prompted to interact with this fake CAPTCHA, and in doing so, are inadvertently guided to input or execute commands within their command-line interface. This technique aims to bypass typical user caution by masquerading as a common security verification step.
Once the user is deceived into executing the malicious commands, the malware proceeds to deploy a backdoor onto the compromised system. This backdoor provides persistent access to the attacker, enabling further malicious activities such as data exfiltration, remote control, or the deployment of additional payloads. The specific functionalities of the backdoor were not detailed, but backdoors commonly allow for remote code execution, file manipulation, and system reconnaissance.
Microsoft's identification of TerminalFix highlights a shift in attack vectors. Previous iterations of similar malware, or other social engineering campaigns, have often targeted user interaction with the Windows Run dialog. The transition to exploiting Windows Terminal or PowerShell for command execution represents an adaptation that could potentially increase the success rate of such attacks, as users might be less suspicious of command-line prompts in certain contexts or might perceive them as part of a legitimate technical process.
Products in the Windows ecosystem are primarily affected, given the reliance on Windows Terminal and PowerShell. Users of Windows operating systems are advised to exercise extreme caution when encountering CAPTCHA challenges, especially those that prompt for command-line interaction or unusual steps. General mitigation strategies for this class of threat include user education on recognizing phishing and social engineering tactics, the implementation of endpoint detection and response (EDR) solutions, and maintaining up-to-date antivirus software.
To mitigate the risk posed by TerminalFix and similar threats, organizations and individual users should prioritize security awareness training. Emphasizing the importance of verifying the legitimacy of prompts, especially those requesting command-line input, is crucial. Additionally, employing robust security solutions that can detect and prevent the execution of malicious scripts, along with regularly patching operating systems and applications, forms a critical defense against evolving malware tactics.
This discovery underscores the continuous evolution of malware tactics, with attackers adapting their methods to exploit user trust and common interface elements. The move from targeting simpler dialog boxes to more technical command-line interfaces suggests a calculated effort to bypass established user security heuristics and potentially target users who may have a higher comfort level with command-line environments.

A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). [...]

Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the security of the company's hardware wallets

A critical arbitrary file upload vulnerability in the Elementor Pro WordPress plugin, tracked as CVE-2026-32475, is being actively exploited to compromise websites. The flaw exists in the plugin's form submission handling function, allowing attackers to upload malicious files.

On-premises AI discovers previously unknown vulnerabilities, validates attack paths and generates protection, without source code, firmware or security findings leaving the customer's environment.

OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model "misalignment" rather than a security breach. [...]

Plus: Tens of millions of US and Canadian drivers’ licenses go up for sale on the dark web, the US military finally tries to tackle the risk online ad data poses to troops, and more.