Huntress details four ways attackers who already hold administrator rights add Microsoft Defender exclusions to keep malicious files out of every scan. A registry value can also hide those exclusions from any admin who checks for them.
Reality
- Evidence58
- Adoption
- Insufficient
- Hype gap+8
- Incentives62
- Confidence60
Huntress traced at least two of more than 40 ClickFix malware incidents to fake custom GPTs on OpenAI's chatgpt.com. On that route every hop before the PowerShell command sat on a Google or OpenAI address, so staff taught to trust familiar domains would click through each one.
Reality
- Evidence45
- Adoption20
- Hype gap+20
- Incentives
- Insufficient
- Confidence50
One developer's secrets scanner printed PASS before every release for two months while matching zero files, according to a dev.to post. The fix gives a scan of nothing its own failing exit code, so a broken check stops looking clean.
Reality
- Evidence45
- Adoption
- Insufficient
- Hype gap+10
- Incentives40
- Confidence55
Microsoft has removed the legacy WMIC binary rather than deprecating it again. WMI itself stays, so admin scripts and detection content keyed to wmic.exe both need rework this cycle.
Publishers:bleepingcomputer.com · scworld.com · windowslatest.com Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 67%
- Investor
- Investor 5%
Reality
- Evidence72
- Adoption65
- Hype gap+15
- Incentives
- Insufficient
- Confidence74
Check Point Research says exposed directories revealed the logs, source code and management tooling behind StopAndProtect, a campaign it links to more than 5,000 infected machines.
Perspective Coverage
3 publishers
- Builder
- Builder 30%
- Operator
- Operator 63%
- Investor
- Investor 7%
Reality
- Evidence62
- Adoption30
- Hype gap+10
- Incentives55
- Confidence65
Microsoft's TerminalFix writeup shows the same fake CAPTCHA lure now feeding multi-line PowerShell into Windows Terminal, where it sideloads a signed binary, pulls payloads out of PNG files and leaves a reverse tunnel behind.
Perspective Coverage
4 publishers
- Builder
- Builder 20%
- Operator
- Operator 75%
- Investor
- Investor 5%
Reality
- Evidence65
- Adoption
- Insufficient
- Hype gap+20
- Incentives30
- Confidence65
third-party.com is an ordinary registered domain that developer documentation has used as a stand-in for years. It currently answers with a fake Cloudflare check that tells Windows users to paste a PowerShell command into the Run box.
Reality
- Evidence68
- Adoption
- Insufficient
- Hype gap+15
- Incentives45
- Confidence70
Securonix pulled four scheduled tasks and a Startup folder copy out of one infected machine, and the two PowerShell modules restart each other. Delete the desktop script and the backdoor keeps collecting documents.
Perspective Coverage
3 publishers
- Builder
- Builder 28%
- Operator
- Operator 66%
- Investor
- Investor 6%
Reality
- Evidence60
- Adoption
- Insufficient
- Hype gap+8
- Incentives
- Insufficient
- Confidence62
Extending a PowerShell endpoint suite with roles, sessions and think time exposed authentication, contract, cleanup and rate-limit defects first. The nine journey sessions still share three accounts, one per role.
Reality
- Evidence55
- Adoption
- Insufficient
- Hype gap−18
- Incentives20
- Confidence52
Blackpoint's SOC worked an incident where a fake captcha on the victim company's own WordPress site ran a hidden PowerShell downloader, and the campaign's later stage sits in a blockchain contract no provider can pull.
Publishers:blackpointcyber.com
Reality
- Evidence60
- Adoption30
- Hype gap+15
- Incentives65
- Confidence55
Zscaler ThreatLabz says the Pakistan-aligned group worked government and defense targets in India and Afghanistan with four undocumented tools, one of them a Rust backdoor that takes its orders from files in a private repo.
Reality
- Evidence40
- Adoption25
- Hype gap+18
- Incentives65
- Confidence45
SQS standard queues and Lambda event source mappings both deliver at least once, and that guarantee is about the envelope. A lab in us-east-1 sent the same 150-real order four times and logged four charges.
Reality
- Evidence56
- Adoption
- Insufficient
- Hype gap−8
- Incentives22
- Confidence62
A fresh terminal resolves ffmpeg while the IDE on the same machine says the tool is missing. The difference is the environment block each process got when it was created, and Windows sends no update to a process already running.
Reality
- Evidence76
- Adoption
- Insufficient
- Hype gap−12
- Incentives18
- Confidence70
A quantised 27B on one 16GB GPU audited a home Splunk and Sysmon install with nothing leaving the host. Its first repair attempt ran the 128K context window dry. A halt rule in the system prompt got it under control.
Reality
- Evidence38
- Adoption9
- Hype gap+22
- Incentives32
- Confidence44
A dev.to writeup pins silent copy/paste failures in Excel 2016 through 2024 on KB5002914, and says MSI machines can drop the patch while volume Click-to-Run installs have to be moved back a whole build.
Reality
- Evidence30
- Adoption20
- Hype gap+30
- Incentives40
- Confidence45
Microsoft's guidance on illicit consent grants says password resets and MFA do not touch the access, and it sends admins to the Purview audit log, where the entry can take up to 24 hours to appear.
Publishers:learn.microsoft.com
Reality
- Evidence64
- Adoption
- Insufficient
- Hype gap−12
- Incentives58
- Confidence66
Seven Claude Code subagents produced 382 commits, 24 board meetings and 16 articles in 21 days, and no revenue. The reusable part of the writeup is the runner that treated exit code 0 as proof the work happened.
Reality
- Evidence45
- Adoption18
- Hype gap−20
- Incentives55
- Confidence42
A parity script, an xUnit mirror of it, two Claude Code hooks and a skill file all went in before any hardcoded string moved, and a JSON baseline of per-file literal counts is what let a half-finished extraction still pass.
Reality
- Evidence58
- Adoption15
- Hype gap−5
- Incentives30
- Confidence55
A Windows box running about thirty unattended jobs reported success through three months of failures, because each exit code had to survive a VBScript launcher and a .cmd shim before the scheduler ever saw it.
Reality
- Evidence45
- Adoption12
- Hype gap+10
- Incentives20
- Confidence55
Compromised WordPress and PrestaShop pages fetch their next stage with a JSON-RPC eth_call to BNB Smart Chain Testnet, so the artefact sitting on the site is a request, not a file you can quarantine.
Reality
- Evidence40
- Adoption45
- Hype gap+8
- Incentives55
- Confidence45
Earlier coverage
- 5,400 hacked WordPress and PrestaShop sites pull their ClickFix payload from a BNB testnet contract
Security · September 5, 2026 · 1 publisher
- TerminalFix delivers its first stage through the clipboard of the person it targets
Build · August 31, 2026 · 1 publisher
- ClickFix lures now paste an msiexec command that installs legitimate software to sideload a DLL
Security · August 31, 2026 · 1 publisher
- TerminalFix sends the fake CAPTCHA command to PowerShell so multi-line payloads survive
Leadership · August 31, 2026 · 1 publisher
- Given one full stop as input, a coding agent mined the shared run record for work
Build · August 28, 2026 · 1 publisher
- Three items, one tier: Keycloak's reset bug, an N-able password leak, a Grok data-theft trick
Security · August 26, 2026 · 1 publisher
- wmic is gone, and Node's process trees on Windows 11 now come back empty
Build · August 23, 2026 · 1 publisher
- Parallel coding agents on Windows break at the home directory, not the launcher
Build · August 23, 2026 · 1 publisher
- Before you restart that Windows service, find out whether StartType survived the update
Build · August 23, 2026 · 1 publisher
- The malware asks a question and reads its orders off the doormat: PowerShell in FTP banners
Build · August 21, 2026 · 1 publisher
- SynkLoader: the Teams help-desk lure now ships with a reverse proxy attached
Build · August 21, 2026 · 1 publisher
- Check Point finds 2,000 hacked WordPress sites doing the hosting for a crypto-stealing toolkit
Invest · August 21, 2026 · 2 publishers
- Sophos: Fake AI Installers Drove 30 of 38 AI-Linked MDR Cases, With Claude the Favourite Costume
Security · August 21, 2026 · 1 publisher
- The extortion call now comes from your help desk, and the fix is a procedure you own
Leadership · August 19, 2026 · 1 publisher
- Cursor's undocumented 'desktop' command turns local AI agents into a scriptable control channel
Build · August 18, 2026 · 1 publisher
- Your shell exports never reach the Claude Code panel, and your gateway logs know it
Build · August 15, 2026 · 1 publisher
- ClickFix operators install the signed Deno runtime to run their remote JavaScript
Security · August 14, 2026 · 1 publisher
- Bring Your Own Runtime: Sophos MDR maps a repeatable Deno-based intrusion chain
Security · August 14, 2026 · 1 publisher