Feed aggregator
Criminals turn placeholder domain into ClickFix trap
A domain that has long appeared in software documentation, code examples, and developer test material is now being used to push a ClickFix attack against Windows users.
A placeholder domain stands in for a website in an example. The best-known is probably example.com. Another, third-party[.]com, has often been used in documentation to represent an external website, API, or service.
However, there is a very important difference between the two: example.com is reserved for documentation, while third-party[.]com is an ordinary domain. Anyone could register it, and someone did. Every document, test, and skill that hardcoded it now points readers and users to the attacker’s infrastructure.
Researchers at Manifold Security found that third-party[.]com was serving a fake Cloudflare-style verification page to Windows visitors. The page tries to persuade them to open the Windows Run box and paste a command it has copied to their clipboard.This command is designed to download and execute a PowerShell script. At the time of writing the domain hosting the script is not resolving.
ClickFix is a social-engineering technique that turns the victim into the malware installer.
Instead of relying on a malicious attachment or an obvious executable download, the attacker convinces someone to run a command themselves. Common lures include:
- A fake CAPTCHA or Cloudflare Turnstile check.
- A browser error that claims it needs a “manual fix.”
- A bogus video-player, document-viewer, or popular software download.
- A support scam page that tells the visitor to paste a command into Run, Command Prompt, Terminal, or PowerShell.
ClickFix works because the command often uses legitimate Windows or Mac tools to download and execute the next stage. It also runs with the permissions of the person who has been convinced to enter it.
The consequences can range from information theft to more serious compromise of a company network. In a recent campaign called TerminalFix, a fake Cloudflare CAPTCHA led victims to paste a PowerShell command into Windows Terminal or PowerShell.
How to stay safeWith ClickFix running rampant—and it doesn’t look like it’s going away anytime soon—it’s important to be aware, careful, and protected.
- Slow down. Be wary of a webpage that urges you to run commands on your device, especially if it uses a countdown or other pressure tactic.
- Don’t run commands or scripts from untrusted sources. Never run code or commands copied from websites, emails, or messages unless you trust the source and understand the action’s purpose. Verify instructions independently. If a website tells you to execute a command or perform a technical action, check through official documentation or contact support before proceeding.
- Check what you’re pasting. A website may copy a command to your clipboard without showing you the full text. Don’t paste it into a command window.
- Secure your device. Use an up-to-date, real-time anti-malware solution with a web protection component.
- Educate yourself on evolving attack techniques. Understanding that attacks may come from unexpected vectors and evolve helps maintain vigilance. Keep reading our blog!
Pro tip: The free Malwarebytes Browser Guard extension warns you when a website tries to copy something to your clipboard.
Stop threats before they can do any harm.
Malwarebytes Browser Guard blocks phishing pages and malicious sites automatically. Free, one click to install. Add it to your browser →
Ormaos: What happened inside your Python execution?
Article URL: https://ormaos.com/
Comments URL: https://news.ycombinator.com/item?id=49843825
Points: 1
# Comments: 0
ChatGPT composed a BEAUTIFUL, original piano solo with code. Is this AGI?
Article URL: https://twitter.com/AdamHincu/status/2103462960463311100
Comments URL: https://news.ycombinator.com/item?id=49843819
Points: 1
# Comments: 0
Agent communication should be designed as Byzantine
Article URL: https://www.noetive.io/blog/byzantine-agents
Comments URL: https://news.ycombinator.com/item?id=49843814
Points: 1
# Comments: 1
Ali Alkhatib: Weeds tend not to grow where they can't take root
Article URL: https://ali-alkhatib.com/blog/weeding-out-ai
Comments URL: https://news.ycombinator.com/item?id=49843811
Points: 1
# Comments: 0
CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks
Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July.
The post CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks appeared first on SecurityWeek.
Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services.
The post Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court appeared first on SecurityWeek.
Famous actors arriving in the vertical drama no longer just bring romance
Article URL: https://www.duanju.news/en/post/famous-actors-duanju-romance
Comments URL: https://news.ycombinator.com/item?id=49843361
Points: 1
# Comments: 0
The Cryptopals Crypto Challenges
Article URL: https://cryptopals.com/
Comments URL: https://news.ycombinator.com/item?id=49843334
Points: 1
# Comments: 0
Clankers Made Me Build a Second Brain
Article URL: https://jadarma.github.io/blog/posts/2026/09/clankers-made-me-build-a-second-brain/
Comments URL: https://news.ycombinator.com/item?id=49843333
Points: 1
# Comments: 0
Silicon Valley 'sex assault list' with 'over 100' names circulated
Midden, a JVM heap dump analyser in a single static binary
Article URL: https://github.com/NullByte3/midden/
Comments URL: https://news.ycombinator.com/item?id=49843312
Points: 1
# Comments: 1
Reimagining research papers as interactive and reliable AI agents
Article URL: https://www.nature.com/articles/s41586-026-11044-y
Comments URL: https://news.ycombinator.com/item?id=49843293
Points: 1
# Comments: 0
I got Opus 5.5 to make a whimsical video ad for my side hustle
Article URL: https://www.reddit.com/r/ClaudeAI/comments/1wptwrk/got_opus_55_to_build_an_advert_for_my_side_hustle/
Comments URL: https://news.ycombinator.com/item?id=49843290
Points: 2
# Comments: 0
Causal questions and the jobs program data
Article URL: https://stochastic.blog/causal-questions-and-the-jobs-program-data/
Comments URL: https://news.ycombinator.com/item?id=49843272
Points: 1
# Comments: 0
Platform-Independent SIMD in Go
Article URL: https://go.dev/blog/simd-experiment
Comments URL: https://news.ycombinator.com/item?id=49843269
Points: 1
# Comments: 0
The Biggest Risk of AI Wearables Is Not Personal Privacy – It's Human Agency
Article URL: https://papers.ssrn.com/sol3/papers.cfm?abstract_id=7498938
Comments URL: https://news.ycombinator.com/item?id=49843266
Points: 3
# Comments: 0
Kilo for JetBrains is now a multi-agent control room
Article URL: https://blog.kilo.ai/p/kilo-for-jetbrains-a-multi-agent-control-room
Comments URL: https://news.ycombinator.com/item?id=49843261
Points: 1
# Comments: 0
Hardlist: Index of ambitious European hardware startups
Article URL: https://www.hardli.st/
Comments URL: https://news.ycombinator.com/item?id=49843259
Points: 1
# Comments: 0
Double-entry accounting for compute time
Article URL: https://sfcompute.com/news/abel-ledger
Comments URL: https://news.ycombinator.com/item?id=49843241
Points: 1
# Comments: 0
