importantSYS.SOURCE: The Hacker News• 2026-10-06T10:52:55+05:30
ClickFix Attack Bypasses Windows Run Limits via Browser Cache Exploitation
A new ClickFix attack bypasses Windows Run's 260-character limit by smuggling malicious VBScript payloads into browser caches, enabling credential theft and malware deployment. The technique leverages browser cache smuggling and AI-driven prompt injection to evade detection and exploit trusted system tools.
A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache.
"Instead of downloading and executing remote payloads like the typical attack pattern, in this attack, the websites pre-fetch a script payload into the browser cache disguised as a PNG file," the Microsoft Threat Intelligence team said in a post on X.
*** END OF TRANSMISSION ***