Huntress found legitimate remote management software abused in 45% of the endpoint incidents it logged in the first quarter of 2026. A rogue copy can behave like IT's approved one, so defenders have to know which tools are sanctioned and how each install arrived.
Reality
- Evidence45
- Adoption55
- Hype gap+5
- Incentives
- Insufficient
- Confidence55
Microsoft says Star Blizzard has sent fake event invitations to more than 100 organizations since January, many from hacked WordPress and cPanel sites. The group, long known for stealing email passwords, now uses the messages to install a Windows backdoor.
Perspective Coverage
8 publishers
- Builder
- Builder 28%
- Operator
- Operator 62%
- Investor
- Investor 10%
Reality
- Evidence66
- Adoption35
- Hype gap+18
- Incentives35
- Confidence70
Microsoft says Russia's FSB-linked Star Blizzard sent fake event invitations to more than 100 organizations since January 2026. The lures pose as Chatham House and Atlantic Council events and carry a new Python backdoor, CosmicPulse, aimed at people working on Ukraine.
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+20
- Incentives
- Insufficient
- Confidence62
Sophos linked ClickFix lures that open Windows Terminal, not the Run dialog, to STAC4924, a campaign it has tracked since at least March. The intrusions plant Lorem Ipsum Loader and a Python reverse-tunnel implant that relays attacker traffic through the victim host.
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap−5
- Incentives
- Insufficient
- Confidence58
Microsoft Defender Experts tied 30+ domains to a macOS stealer by matching execution, staging and upload behaviour. The count is incidental; the method is the part worth copying.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 67%
- Investor
- Investor 5%
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+10
- Incentives45
- Confidence70
Disclosures doubled year over year while actually-exploited vulnerabilities rose 8%. The arithmetic retires patch-everything SLAs and leaves exploitability triage as the defensible option.
Perspective Coverage
3 publishers
- Builder
- Builder 12%
- Operator
- Operator 76%
- Investor
- Investor 12%
Reality
- Evidence62
- Adoption
- Insufficient
- Hype gap+30
- Incentives70
- Confidence60
Check Point Research says exposed directories revealed the logs, source code and management tooling behind StopAndProtect, a campaign it links to more than 5,000 infected machines.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 63%
- Investor
- Investor 7%
Reality
- Evidence62
- Adoption30
- Hype gap+10
- Incentives55
- Confidence65
Socket found 19 Chrome and Edge extensions carrying crypto-draining code, five of them bought from their original owners. The malware landed in updates after each listing had earned real installs, which is exactly what a one-time vetting pass never re-checks.
Reality
- Evidence60
- Adoption35
- Hype gap+10
- Incentives
- Insufficient
- Confidence60
Microsoft's TerminalFix writeup shows the same fake CAPTCHA lure now feeding multi-line PowerShell into Windows Terminal, where it sideloads a signed binary, pulls payloads out of PNG files and leaves a reverse tunnel behind.
Perspective Coverage
4 publishers
- Builder
- Builder 20%
- Operator
- Operator 75%
- Investor
- Investor 5%
Reality
- Evidence65
- Adoption
- Insufficient
- Hype gap+20
- Incentives30
- Confidence65
The domain expired after the CDN was wound down, someone re-registered it in July 2025, and nobody told the pages calling those hostnames. Every hostname beneath it now resolves to that owner's infrastructure.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+35
- Incentives85
- Confidence40
Patrick Wardle published working code that sends Muse's dictated audio to a server of the attacker's choosing. Because the assistant holds file, microphone, camera, calendar and paired-iPhone access, whoever redirects it inherits all of it.
Perspective Coverage
3 publishers
- Builder
- Builder 33%
- Operator
- Operator 54%
- Investor
- Investor 13%
Reality
- Evidence70
- Adoption
- Insufficient
- Hype gap+20
- Incentives45
- Confidence65
Manifold Security found third-party.com, a placeholder in more than 1,700 public repositories, serving a ClickFix clipboard lure to Windows browsers since at least June 2026. Static scans of the same files come back clean, because the server chooses what to send.
Reality
- Evidence58
- Adoption62
- Hype gap+12
- Incentives62
- Confidence60
Patrick Wardle showed that one undocumented key, endo_voyager_dictation_endpoint, let unprivileged local code reroute Muse's dictation audio and account token. Meta stripped the key from production builds and requested no CVE.
Reality
- Evidence58
- Adoption30
- Hype gap+20
- Incentives72
- Confidence55
ENISA counted 8,257 EU incidents in 2025 and found that denial of service against public-facing services supplies most of the volume, while its warning about compromised technology suppliers rests on one named Swedish case.
Reality
- Evidence60
- Adoption55
- Hype gap+25
- Incentives55
- Confidence58
AvisLoader statically links the reference Tox client, so its operator keeps the same identity after moving to a new server. The ClickFix page and Cloudflare tunnel that deliver it are still ordinary takedown targets.
Publishers:varonis.com
Reality
- Evidence66
- Adoption20
- Hype gap+18
- Incentives62
- Confidence57
Meta's bug bounty puts $130,000 on a prompt injection against Muse out of a $300,000 top payout. A researcher has now demonstrated a working hijack of the agent Meta sells as safe enough to complete purchases.
Reality
- Evidence30
- Adoption
- Insufficient
- Hype gap+38
- Incentives68
- Confidence34
Brevo says a long-lived Cloudflare key with full account permissions sat in its application source code, and the Worker built with it stripped Content-Security-Policy headers from scripts that Sansec estimates reach 100,000 sites.
Perspective Coverage
3 publishers
- Builder
- Builder 34%
- Operator
- Operator 48%
- Investor
- Investor 18%
Reality
- Evidence78
- Adoption60
- Hype gap+20
- Incentives58
- Confidence72
SOCRadar's teardown of the $250-a-month service puts the elevation step behind an administrator account and permissive UAC settings, so on a fleet of standard users the rental buys remote access and credential theft and stops there.
Reality
- Evidence58
- Adoption28
- Hype gap+30
- Incentives52
- Confidence55
Unit 42 followed the copy-paste instructions on Aug. 5, 2026, and watched one Zsh command install AMOS twice over and package a lab Mac's wallet folders and cloud credentials into a single zip.
Reality
- Evidence70
- Adoption30
- Hype gap−10
- Incentives40
- Confidence62
The Windows implant, its Linux control server, the protocol between them and the licensing all came from one author, sold at $250 a month. SOCRadar puts the operator's undetected run at nearly four years.
Reality
- Evidence58
- Adoption60
- Hype gap+22
- Incentives65
- Confidence57
Earlier coverage
- Replayed session cookies bypassed the conditional access that blocked stolen passwords
Security · September 10, 2026 · 1 publisher
- Talos found ClickFix operators moving their skimmer into a Tampermonkey userscript
Product · September 8, 2026 · 1 publisher
- A loader on 5,400 hacked sites borrows the page's own CSP nonce to execute
Build · September 5, 2026 · 1 publisher
- Recorded Future's half-year data shows adversaries continuing to favor abusing legitimate tools and trusted platforms already inside the enterprise
Security · September 3, 2026 · 1 publisher
- Symantec finds attackers installing the signed Node.js runtime to run their payloads
Security · September 3, 2026 · 1 publisher
- Attackers ran ClickFix into 47% of the initial access Microsoft logged last year
Security · September 1, 2026 · 1 publisher
- A tampered Exodus installer hides a modular RAT behind a genuine wallet install
Security · September 1, 2026 · 1 publisher
- CRPx0 climbed to 46 claimed victims in July on countdowns that fired in near unison
Security · August 31, 2026 · 1 publisher
- ClickFix lures now paste an msiexec command that installs legitimate software to sideload a DLL
Security · August 31, 2026 · 1 publisher
- Fake macOS troubleshooting posts route infostealers past Gatekeeper
Leadership · August 31, 2026 · 1 publisher
- TerminalFix sends the fake CAPTCHA command to PowerShell so multi-line payloads survive
Leadership · August 31, 2026 · 1 publisher
- ClickFix scales by asking employees to paste the command themselves
Leadership · August 31, 2026 · 1 publisher
- Click-Exfil turns one pasted command into Claude Code account takeover
Security · August 31, 2026 · 1 publisher
- Attackers bought five working browser extensions and shipped malware through auto-update
Security · August 30, 2026 · 1 publisher
- Quishing moves the login off the managed laptop and onto an unfiltered personal phone
Product · August 30, 2026 · 1 publisher
- Superior ships its wallet drainer as a routine auto-update to extensions users already trusted
Build · August 30, 2026 · 1 publisher
- ClickFix operators moved the payload into text only the summarizer can see
Build · August 30, 2026 · 1 publisher
- FTP welcome banners are the new dead drop, and that suits whoever reads netflow
Security · August 25, 2026 · 1 publisher
- PavinLoader: the lures keep changing, the MSBuild stage does not
Security · August 24, 2026 · 1 publisher
- Fake Codex installer outranks OpenAI in Google ads, then asks for a paste
Product · August 24, 2026 · 1 publisher
- FTP greeting banners are now a C2 channel, and they are carrying two new RATs
Security · August 21, 2026 · 2 publishers
- Check Point finds 2,000 hacked WordPress sites doing the hosting for a crypto-stealing toolkit
Invest · August 21, 2026 · 2 publishers
- Sophos: Fake AI Installers Drove 30 of 38 AI-Linked MDR Cases, With Claude the Favourite Costume
Security · August 21, 2026 · 1 publisher
- ClickFix in the sidebar: Def Con follow-up phishing turns a real Google Doc into the payload
Security · August 20, 2026 · 2 publishers
- A year of Sophos AI cases: 30 of 38 were fake installers, not autonomous attackers
Security · August 19, 2026 · 1 publisher
- C2Looper puts its C2 inside GitHub, and domain-reputation stacks will not care
Security · August 18, 2026 · 1 publisher
- ClickFix operators install the signed Deno runtime to run their remote JavaScript
Security · August 14, 2026 · 1 publisher
- Bring Your Own Runtime: Sophos MDR maps a repeatable Deno-based intrusion chain
Security · August 14, 2026 · 1 publisher