53
Hackers use Fake Cloudflare Verification Screen to Trick Users into Executing Malware
(cybersecuritynews.com)
c/cybersecurity is a community centered on the cybersecurity and information security profession. You can come here to discuss news, post something interesting, or just chat with others.
THE RULES
Instance Rules
Community Rules
If you ask someone to hack your "friends" socials you're just going to get banned so don't do that.
Learn about hacking
Other security-related communities !databreaches@lemmy.zip !netsec@lemmy.world !securitynews@infosec.pub !cybersecurity@infosec.pub !pulse_of_truth@infosec.pub
Notable mention to !cybersecuritymemes@lemmy.world
This article doesn't at all explain what actually happens. There's a hand wavey description including PowerShell scripts and the clipboard, but it doesn't indicate how the code gets executed.
The article talks about a complex and sophisticated attack, but I don't see any evidence of that assertion.
Also, given that it's talking about PowerShell, I'm going to guess that this affects Windows only.
Finally, there's no source links, no CVE allocation, no indication what the URL looks like.
I'm going with deep scepticism about this report unless more information comes to hand.
It's so called ClickFix and FileFix atracks. They give malicious instructions on how to perform a certain task, like download a file or solve a CAPTCHA. Some swap the clipboard contents in the last moment, so the victim doesn't even know what's in it: https://www.mobile-hacker.com/2025/06/24/introducing-filefix-a-new-alternative-to-clickfix-attacks/