Tech article

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits - The Hacker News

Publisher description: Microsoft observed ClickFix attacks using browser cache smuggling to execute cached VBScript and launch a credential-targeting malware chain.

NewsAPI | Oct 6, 2026 | The Hacker News

Automated excerpt

A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. ClickFix is effective because it persuades users to run attacker-supplied commands under the pretext of CAPTCHA verifications, browser updates, or unexpected errors -- situations users routinely encounter. It's suspected that the ClickFix lures were delivered via compromised Ukrainian websites.

Selected automatically from source text; not independently written or fact-checked. Read the original for full context.

Read the original article

Read next

AI briefing: recent picks

More tech news