← Back to the feed

~/article/clickfix-smuggles-payloads-through-browser-cache-to-bypass-windows-run-l-s5huea
infoSource: The Hacker News

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X.

Read at the source

Summary written for cymesh.dev. The full article lives at The Hacker News.

Topics

~/cymesh.net

Certificates expire quietly

cymesh.net watches your TLS and SSL certificates and warns you before one lapses.

monitorsTLS/SSL expiry, chain and hostnamealertsemail, ahead of the expiry datescopenon-intrusive, read-only checks

Related

~/related/clickfix-smuggles-payloads-through-browser-cache-to-bypass-windows-run-l-s5huea