HBO Max Reddit Ads Led to the PasteSwitch Malware Operation
A hijacked HBO Max Reddit account ran 108 malicious ads. Researchers followed…
SimpleSwap Bonus Script Scam: Remove Malicious Userscripts
Remove a fake SimpleSwap bonus userscript, check browser persistence, and respond safely…
StopAndProtect Turns Hacked WordPress Sites Into Malware Traps
StopAndProtect uses hacked WordPress sites, fake CAPTCHA prompts, and PowerShell. Follow the…
TerminalFix Turns Fake CAPTCHA Into a Network Tunnel
Microsoft says TerminalFix uses a fake CAPTCHA, PowerShell, DLL sideloading, and a…
PavinLoader Spreads Through ClickFix and Fake Downloads
PavinLoader links fake CAPTCHA, software, and game lures to a multi-stage Windows…
AmnesiaStealer Hijacks Mac Browser Sessions After ClickFix
AmnesiaStealer spreads through a counterfeit GitHub page, steals Mac passwords and browser…
Steam Forum ClickFix Installs XMRig Miner via PowerShell
Fake Steam forum fixes are installing an XMRig miner through PowerShell. Check…
UAC-0145 Uses Fake CAPTCHA and Security Apps Against Ukraine
CERT-UA says UAC-0145 is using ClickFix pages, fake security tools, Signal lures,…
ACR Stealer ClickFix Attacks: What to Check After Running the Command
Microsoft tracked ACR Stealer ClickFix chains using WebDAV, MSHTA and PowerShell. Check…
Potemkin Loader Turns ClickFix Into 11-Host Intrusion
A ClickFix command dropped Potemkin Loader, RMMProject and EtherRAT across 11+ hosts.…
Trojan:JS/Obfuse.NF!MTB: PowerShell Alert Keeps Coming Back
What Trojan:JS/Obfuse.NF!MTB means when Defender keeps catching hidden PowerShell, and how to…
Ghost CMS Exploit Poisons 700 Sites for ClickFix Malware
Attackers are exploiting Ghost CMS CVE-2026-26980 to inject ClickFix loaders into trusted…
