Build1 distinct publisher3 min readPublished
Forcepoint's X-Labs found short-lived ClickFix domains carrying white-on-white characters and zero-width spaces, which puts the trust boundary for any agent you point at the open web inside your own extraction code.
The Engineer · Build desk

Compiled by The EngineerSomething wrong?How this is made
Invisibility is a property of the renderer, not of the bytes. A summarize-this-URL path normally goes fetch, strip tags, feed text to the model. Nothing in that sequence evaluates the rule that paints a character white on a white ground, and nothing weighs a zero-width space at zero. The hidden string lands in the context window with the same standing as the `<h1>`. Your extractor is more thorough than your users, which is the whole exploit.
Forcepoint's account of the CSS-based variant is that the model reads those embedded strings as part of its instructions and returns a summary carrying encoded links or fragments of executable text [8]. The post's own one-line version is blunter: "if an AI can read everything, it can also be deceived by anything" [15].
One page, two readers. On the Booking.com impersonation X-Labs walks through, hidden JavaScript collected data and staged an obfuscated downloader and credential stealer once the victim finished the on-screen steps [12], while Forcepoint reads the invisible layer of such pages as aimed at summarizers or automated scanners reviewing the same content [13]. Earlier ClickFix, including the Odyssey Stealer macOS work X-Labs published, needed a person to paste [14]; the CSS variant adds a reader that executes nothing and still shapes what the person is told.
Two claims in the post carry different weight. Three distinct payload families turn up in the early samples [16], which suggests the invisible-prompt trick is circulating between operators rather than sitting in one crew's toolkit. The geography is softer. Forcepoint reads bursts in North America, Western Europe and Southeast Asia as tracking the regions with highest enterprise AI adoption [6]. For that to transfer to your own risk model, sensor coverage would have to be roughly even across those regions and across the ones that stayed dark. Vendor telemetry maps the install base before it maps the adversary.
Adoption cost. Render first and then extract, and you get visibility-aware text at the price of a headless browser per fetch, which is real latency and real CPU on every page an agent reads. Normalizing text at ingest is far cheaper, but put the strip behind a flag and log what you removed, so the day someone's non-Latin content loses characters you can find out why rather than guess. The part I would not trade is authority. Text that arrived over a fetch is data, a summary of that text is also data, and nothing in either should become a tool call, a click target or a clipboard write without a human in between.
In my context that puts the trust boundary at the fetch. The config line that proves you meant it is the one that records what your extractor threw away.
Ranked by verification strength, evidence, and original report placement.
The activity involved a series of short-lived domains, many active for less than a day, appearing and disappearing across networks.
Over a 90-day period, ClickFix-related domains appeared in short bursts before disappearing within hours.
Late last year, Forcepoint X-Labs researchers began noticing a pattern in telemetry from recent ClickFix detections.
Inspection of the pages' HTML uncovered strings of white-on-white characters and zero-width spaces; this hidden text was invisible to users but fully readable to large language models.
Forcepoint characterises the activity as an attack still in its testing phase, with attackers testing how summarizers process malicious text and which prompts can evade detection.
In a Booking.com impersonation campaign hosted at hxxps://booking.com-reactivate[.]de/uri.html, the page displayed a CAPTCHA claiming to verify the user's session, then guided victims through steps such as copying commands to the clipboard and confirming browser troubleshooting, socially engineered to open PowerShell on Windows, Terminal on macOS or shell on Linux and paste preloaded strings that executed the malicious payload.
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 30, 2026
Follow any of these and your For You feed starts watching them — no settings page required.
security
A year of Sophos AI cases: 30 of 38 were fake installers, not autonomous attackers1 distinct publisher
security
Sophos: Fake AI Installers Drove 30 of 38 AI-Linked MDR Cases, With Claude the Favourite Costume1 distinct publisher
product
Incogni ranks 13 AI assistants by privacy risk: bigger is worse, except ChatGPT1 distinct publisher
security
PavinLoader: the lures keep changing, the MSBuild stage does not1 distinct publisher
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
One firm's telemetry, one checkable artifact
Forcepoint is both the discoverer and the only publisher, and a reader can independently examine precisely one thing: the booking.com-reactivate[.]de page. No hashes, no domain counts, no date range on the 90 days, and the simulation that supposedly turned one page into two different summaries names neither model nor version. The technical observation at the base of it all — invisible characters in HTML reach a model intact — is the part least in need of corroboration; everything built on top of it needs it most.
Live infrastructure, no scale
The technique exists in the wild — short-lived domains and one named impersonation page prove that much. What the reporting never does is count anything: no victims, no sessions, no tally of poisoned pages, and Forcepoint itself calls the pattern reconnaissance rather than a campaign. Domains that die within hours are cheap to stand up and tell you nothing about reach.
The opening outruns the fine print
'ClickFix was no longer trying to trick people' is the sentence the story turns on, and four sections later the same post admits the observed attacks still require a user to click a prompt and paste a command. The hidden-prompt layer is real and worth knowing about; the promotion of the summarizer from bystander to victim is a framing the published evidence has not yet earned, and the commodity-stealer names lend it borrowed weight.
A forecast series with a product behind it
The post announces itself in its first line as entry one of Forcepoint's 2026 Future Insights series and threads through links to the firm's own Lumma, Rhadamanthys and Odyssey research. Naming an emerging attack class you are positioned to detect is ordinary vendor practice rather than misconduct — but here the party doing the framing, the party holding the unshared telemetry and the party selling the remedy are the same one, with no outside reader in between.
Solid on the artifact, thin on the trend
That a page hid white-on-white text and zero-width spaces is the sort of finding a researcher reads straight off the source and is hard to get wrong. That this marks attackers pivoting to summarizers rests on aggregate telemetry nobody else has seen, in-house simulations described but not shown, and a single live URL. Confidence should follow that split rather than the headline.