Home / Oct 07, 2026 / Story
0
#8 The Hacker News general October 06, 2026 at 05:22 UTC

ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits

By [email protected] (The Hacker News)

AI Summary

Microsoft Threat Intelligence documented a new ClickFix variant that pre-fetches malicious JavaScript payloads into the browser cache disguised as PNG files on compromised websites, bypassing Windows execution warnings that typically appear when running remotely-fetched scripts. A related campaign tracked by CERT-UA compromised over 100 Ukrainian websites to deliver the Lunex infostealer via fake Cloudflare verification pages using this technique.

Relevance score: 84.0/100

# More from October 07