Feed aggregator
Data center foes win big in Tuesday's primaries
Article URL: https://www.politico.com/news/2026/08/05/data-center-foes-win-big-in-tuesdays-primaries-01025481
Comments URL: https://news.ycombinator.com/item?id=49186000
Points: 2
# Comments: 1
DHS Is Hiring Bounty Hunters to Find and Photograph Deported People’s Homes Abroad
Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP)
As organizations adopt AI, they must secure both cloud and AI environments through a unified security control plane as their attack surface expands. Because modern applications and AI workloads are built and run in the cloud, security teams must understand which exposures matter most, prioritize what can truly be exploited, and reduce risk across cloud infrastructure, applications, identities, data, and AI systems in one place.
Modern IT estates now span multiple clouds and on-premises systems, with architectures built on containers, Kubernetes, serverless functions, microservices, APIs, and AI-powered workloads. This increases both the volume and the interconnectedness of security signals. The challenge is no longer identifying individual risks, but determining how misconfigurations, identities, and data exposures combine to create real attack paths, and which of these are most critical to fix at the source.
KuppingerCole’s Leadership Compass: Cloud Native Application Protection Platforms (CNAPP) reflects this shift. The report describes how CNAPP is evolving from a consolidation of cloud security tools into the security foundation for AI-native enterprises, combining cloud security, AI security posture management, runtime protection, attack path analysis, cloud detection and response, and agentic AI operations into unified platforms.
Read the full reportWithin this evolving market, KuppingerCole names Microsoft a Leader across all four of its Leadership categories: Overall, Product, Innovation, and Market. In the report’s words:
“Microsoft earns its Overall Leadership with its Defender for Cloud that is redefining the CNAPP market by extending cloud security beyond infrastructure protection and into a unified security platform for cloud, data, identity, AI, and security operations, supported by one of the industry’s most advanced agentic AI ecosystems.”
That recognition reflects where the category is heading: toward platforms that unify cloud and AI security into one operational view of risk.
Why CNAPP is being redefinedKuppingerCole makes a clear point: CNAPP is no longer about posture or visibility alone. It is becoming the operational foundation for securing AI-powered applications, services, and business processes, across the full software lifecycle from cloud infrastructure to the AI systems running on top of it.
Modern environments introduce complexity across:
- Multicloud and hybrid infrastructure.
- Rapid development and continuous deployment.
- Containers, serverless, microservices, and APIs.
- AI models, agents, pipelines, and machine identities.
This complexity exposes the limits of traditional, siloed tools, where cloud posture, workload protection, AI security, and the security operations center (SOC) each live in their own console. Organizations now need platforms that can:
- Correlate posture, runtime, identity, data, application, and AI signals.
- Prioritize risk based on exploitability, not severity alone.
- Integrate security across development, cloud operations, and the SOC.
- Bring AI systems into the same risk model as the rest of the cloud.
Runtime intelligence is now central to this shift. Across the platforms KuppingerCole evaluated, 94% detect active exploitation of the complex attack paths they surface, moving teams from long lists of findings to the exposures threat actors can actually use.
What distinguishes leading platformsKuppingerCole evaluates providers on product strength, innovation, and market presence, and, more importantly, on how effectively they help organizations manage real risk across cloud and AI. Several themes define the next generation of platforms:
- AI security posture management that governs models, pipelines, and AI-specific attack paths.
- Agentic AI that investigates, validates exposures, and helps remediate, not just detect.
- Runtime-driven risk prioritization focused on what is exploitable in production.
- Security graphs and attack path analysis across identity, data, network, workload, and AI.
- Convergence of CNAPP with cloud detection and response, integrated with the SOC.
Taken together, these capabilities represent a move from fragmented visibility to connected, contextual risk management that spans cloud and AI in a single fabric.
How Microsoft helps organizations manage real risk 1. Connect cross-domain signals to prioritize real attack pathsMost security tools surface large volumes of findings, but isolated findings do not reflect how cyberattacks actually happen. Microsoft Defender for Cloud uses the Cloud Security Graph and risk-based, multicloud attack path analysis to correlate posture, identity (human and non-human), data, network, and workload signals and identify which risks are truly exploitable. A misconfigured storage resource may look low priority on its own. Exposed to the internet, combined with excessive permissions, and connected to sensitive data, it becomes part of a clear attack path.
What this means: Security teams can prioritize real attack paths instead of individual findings, helping reduce alert fatigue and improve remediation speed and precision.
Get started with Microsoft Defender for Cloud 2. Secure AI as part of cloud risk, and use AI to run securityDefender for Cloud brings AI security posture management into the same model as the rest of the cloud, helping organizations validate AI deployment configurations, access controls, model provenance, approved model usage, and identify potential shadow AI risks within supported environments. Through Microsoft Security Copilot and a growing set of specialized security agents, the platform also helps teams investigate, prioritize, guide remediation, and automate workflows.
What this means: Organizations can govern AI as part of cloud risk rather than in a separate silo, and shift AI from flagging risk to actively helping resolve it.
3. Reduce complexity from code to cloud to SOCAs environments scale, fragmented tools make it difficult to understand how risks connect and where to focus first. Defender for Cloud connects code and infrastructure definitions, assesses cloud configurations, protect workloads at runtime, monitor applications and APIs, govern identities, correlate threats across the broader digital estate, and use AI to accelerate investigation and remediation across multicloud and hybrid environments.
What this means: Security teams can investigate faster, prioritize more consistently, and respond more quickly across fragmented cloud and application environments.
What this signals for security leadersThe Leadership Compass offers a signal for where cloud security is headed: toward platforms that connect context across cloud, application, and AI environments so teams can prioritize the risks most likely to be exploited and reduce exposure faster. Security leaders should now ask:
- Can the platform correlate signals across identity, endpoints, data, cloud, runtime, and applications?
- Does it see AI models, agents, and pipelines as part of cloud risk, or is AI a separate tool?
- Can it prioritize risk based on exploitability, not just severity?
- Does AI help the team investigate and remediate, or only detect?
- Can it scale across multicloud and AI environments and reach into the SOC?
These are the capabilities that define the next generation of cloud-native application protection.
Bottom lineKuppingerCole’s 2026 CNAPP Leadership Compass reinforces a clear shift: CNAPP is becoming the control plane for managing risk across cloud, identity, data, applications, and AI. Microsoft’s recognition as a Leader across all four Leadership categories reflects this shift, bringing posture, runtime, identity, data, application, and AI signals into a connected platform that helps organizations prioritize and reduce risk continuously.
Get the full report Learn more- Read KuppingerCole’s Leadership Compass: Cloud Native Application Protection Platforms (CNAPP) to see how leading vendors are evaluated and how the category is shifting toward securing the AI-native enterprise.
- Explore Microsoft cloud security solutions to see how unified posture management, risk prioritization, and protection across cloud and AI can help reduce risk.
To learn more about Microsoft Security solutions, visit our website. Bookmark the Security blog to keep up with our expert coverage on security matters. Also, follow us on LinkedIn (Microsoft Security) and X (@MSFTSecurity) for the latest news and updates on cybersecurity.
The post Microsoft named a Leader in the KuppingerCole Leadership Compass for Cloud Native Application Protection Platforms (CNAPP) appeared first on Microsoft Security Blog.
Meta Ran Ads That Contained AI-Generated Child Sexual Abuse Imagery
From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide
- Activity overview
- How ClickFix works
- Campaign overview
- ClickFix moved from open pages to fingerprinting gates
- The fingerprinting gate
- Mitigation and protection guidance
- Indicators of compromise (IOC)
- References
- Learn more
Microsoft Threat Intelligence observed a macOS ClickFix campaign distributing infostealers, including MacSync and Atomic Stealer (AMOS), through a large cluster of look-alike domains. The campaign evolved from broadly serving ClickFix lures to using a server-side browser-fingerprinting gate that shows the lure primarily to visitors whose environment appears consistent with a genuine macOS browser. This cloaking limits visibility for crawlers, sandboxes, and some automated analysis workflows. The blog details the domain pattern, fingerprinting checks, infection chain, detection coverage, and hunting pivots that defenders can use to identify related activity.
Activity overviewMicrosoft Threat Intelligence has been tracking a macOS ClickFix operation that distributes information-stealing malware through a large family of algorithmically named domains. Over several weeks of monitoring, Microsoft observed a notable shift in tradecraft: the same infrastructure moved from openly serving the malicious command in the served page’s HTML source to concealing the lure behind a server-side fingerprinting gate that reveals the payload only to visitors the server assesses as a genuine macOS target. The chain ultimately delivers information stealers such as MacSync or Atomic Stealer (AMOS).
This activity is consistent with the broader shift in macOS ClickFix tradecraft that Microsoft Threat Intelligence previously documented, in which threat actors instruct users to run Terminal commands that retrieve remotely hosted content rather than the traditional approach of delivering a disk image for manual installation. The cluster described here is notable for two reasons: its domains are mass-produced by a recognizable name generator, and it adopted server-side cloaking on existing infrastructure, giving defenders a clear before-and-after view of the same operation.
In this blog, we describe the campaign’s domain-generation pattern, the two delivery phases we observed, the fingerprinting gate that now fronts the infrastructure, and the end-to-end infection chain. We also provide hunting guidance, mitigation recommendations, and defanged indicators of compromise.
How ClickFix worksClickFix is a social-engineering technique where attackers persuade users to copy and run a command in Terminal instead of downloading a traditional macOS application. The lure usually appears as a fake verification step, software update, download error, or CAPTCHA, with the command disguised as something required to complete the action. Because execution starts from a user-run Terminal command rather than a downloaded app bundle, the flow can avoid parts of the normal macOS application trust path, including quarantine handling, code-signing evaluation, and notarization checks typically applied to downloaded applications.
In this campaign, ClickFix remains the delivery mechanism, but the important change is that the lure is no longer shown to every visitor. The page first profiles the visitor through a browser-fingerprinting gate and primarily requests consistent with a genuine macOS browser environment receive the fake “Download for macOS” page and copied Terminal command.
Figure 1a – The counterfeit “Download for macOS” page served to a qualifying visitor by a cloaked gate (apricotfilepoint[.]com). The page displays a forged “Verified Publisher” badge and offers a one-click Copy of an obfuscated curl one-liner.Delivery is conditional. During analysis, the same URLs returned different content to different requests. In some case the macOS ClickFix lure, and in others an apparently benign decoy page.
In our testing, a request presenting a Windows browser received a decoy page such as a fake browser-extension or VPN landing page (Figure 1b) or a page impersonating an unrelated business such as a logistics and freight-forwarding company rather than the ClickFix lure. Because this decision is made server-side on a per-request basis, a given scan or visit may receive benign or decoy content and still be interacting with malicious infrastructure, so an apparently benign or look-alike response does not mean the domain is safe. We examine how the gate evaluates each request later in this post.
Figure 1b – A decoy page (a fake “Urban VPN Proxy” browser extension landing page) returned to non qualifying requests on the same domain (apricotfilepoint[.]com). Campaign overviewThe key change in this campaign is not the ClickFix lure itself, but the new layer placed in front of it. Microsoft Threat Intelligence confirmed more than 250 ClickFix front-end domains during the tracking window, and many followed a repeated naming pattern using the token “file” with dictionary-style words, such as filecopperbasket, filevelvettractor, fileoceanhammer, and filemarblegarden.
Some related domains place “file” token in the middle or at the end, such as applefilevault, bananafastfile, and orangesmartfile, while others omit it completely, such as cloudsendhub and syncdatavault. Defenders should treat the naming pattern as a hunting pivot, not a complete signature. The stronger signal is the combination of dictionary-style domains, shared infrastructure behaviour, and the fingerprinting gate that controls who sees the ClickFix lure. This naming pattern is useful for clustering and hunting, but it is not the main story. The more important behaviour is that these domains now serve a browser-fingerprinting gate before showing any malicious content.
ClickFix moved from open pages to fingerprinting gatesIn its earlier phase, the campaign’s domains served the lure directly. Retrieving one returned a “complete your download in Terminal” page with the malicious command present in the HTML. A scanner that does not execute JavaScript could recover the entire attack from the page source, including: the macOS paste-to-Terminal instructions, clipboard-write logic, obfuscated shell command, and encoded staging URL. Because the command was embedded in the served page, the domains were readily identifiable from passive data and static content matching.
The same infrastructure that previously exposed its ClickFix lure directly to visitors has evolved to employ a server-side fingerprinting gate. Rather than immediately presenting the malicious content, affected domains now return a minimal page containing only a lightweight JavaScript profiling routine(~2.5 KB size). To both casual visitors and automated scanners, the site may appear blank, inactive, or apparently benign. In reality, the page serves as an evaluation layer that determines whether a visitor should be shown the ClickFix lure.
Across Microsoft Threat Intelligence’s investigation of this domain cluster, the outcomes were consistent. Simple crawlers received an empty, parked-looking page. JS-capable crawlers and sandbox environments that failed fingerprinting checks were served apparently benign decoy page, and requests presenting a genuine macOS browser fingerprint were shown the ClickFix lure.
Figure 2 – Earlier open-lure delivery compared with the current fingerprinting-gated delivery flow. The fingerprinting gateThe gate profiles each visitor using a combination of browser, hardware, and runtime attributes, which are submitted to the server for evaluation. The following sections break down the categories of signals collected.
Browser profiling and environment collectionThe first stage builds a browser fingerprint by collecting browser and page details from six objects exposed to the page: navigator, screen, window, document, location, and console. From navigator, it captures values such as platform, for example, “MacIntel”, user agent, language, vendor, and plugins, which establish the visitor’s claimed device and browser identity.
Display values from screen and window, including screen size, color depth, window dimensions, and pixel ratio, provide consistency signals for whether that identity is consistent with a real, non‑virtualized Mac environment. Page context from document and location, including title, referrer, character set, URL, and host, helps tie the fingerprint to the delivery context. The console object is also enumerated as part of the runtime surface and later helps identify developer tools or automated log-capturing environments. These values are merged into a single fingerprint object tagged with mode: “php” and later submitted back to the server for evaluation.
Figure 3a – The gate collects browser, system, and environment characteristics from multiple browser objects to build a visitor fingerprint. Hardware validationThe gate then performs additional validation to determine whether the visitor resembles a genuine macOS user. One notable check uses WebGL, a browser graphics API normally used to render 2D and 3D content, to retrieve graphics-processing details from the visitor’s device. In this campaign, those WebGL-derived GPU signals help distinguish real Apple hardware from virtualized, emulated, software-rendered, or sandboxed environments before the server decides whether to return the ClickFix lure.
Figure 3b – WebGL-derived GPU signals can help distinguish likely Apple hardware from virtualized, emulated, software-rendered, or sandboxed environments. Environment and behavioral checksAdditional probes evaluate characteristics such as timezone configuration, touch-input support, and whether the page is running inside an embedded frame. These signals help identify uncommon execution contexts that may indicate automated analysis or monitoring infrastructure.
The script records three signals:
- timezoneOffset reads the system’s local timezone offset. Unusual or inconsistent values can contribute to identifying hosted infrastructure, sandbox environments, or otherwise atypical execution context.
- frame checks whether the page is running inside an iframe. While common in legitimate scenarios, embedded execution contexts can also be associated with crawlers, analysis tools, and other automated environments, making this a useful qualification signal.
- touchEvent checks for touch-input support. On desktop macOS systems, touch support is generally uncommon; unexpected touch capabilities can contribute to identifying an emulated, spoofed, or otherwise atypical environment.
Together, these checks help the gate distinguish a normal macOS desktop browser session from framed, headless, mobile, sandboxed, or automated environments before the server decides what content to return.
Figure 3c – Additional checks evaluate environmental attributes that can help differentiate legitimate users from automated systems. Anti-analysis techniquesThe gate also incorporates checks designed to detect browser instrumentation, automation frameworks, and modified browser behavior. Rather than simply determining whether a visitor is a bot, these probes appear intended to identify environments commonly used by researchers, crawlers, and security-analysis platforms. The implementation details described here are intended to help defenders recognize and detect gate behavior in malicious traffic-distribution infrastructure.
Figure 3d – The gate performs checks intended to identify browser instrumentation and automated analysis environments.Two checks stand out. The first is a toString() counter. The script creates a temporary function whose toString() method increases a counter, then writes that function to the console. In a normal browser, this counter usually remains unchanged. However, if the developer console is open, or if a headless or log-capturing tool serializes console output, the function may be converted to a string, causing the counter to increase.
The second is a prototype-tamper probe built around a normal browser capability check. The gate calls canPlayType(“video/mp4”), which normally checks whether the browser supports MP4 playback. Here, that check is repurposed as a tripwire. A genuine browser handles the codec check natively and silently, but some automated or stealth browsers fake codec support in JavaScript. If that JavaScript path calls the hooked Array.prototype.includes, the gate sets the proto:true signal and flags the environment as potentially instrumented or automated.
Fingerprint submissionOnce profiling is complete, the collected attributes are packaged and silently submitted back to the same server for evaluation. This process occurs without any user interaction or visible page content.
Figure 3e – Collected fingerprint data is submitted to the server, which determines whether the visitor qualifies to receive the ClickFix lure.The following is the sample fingerprint the client sends to the server (values are representative and defanged):
Server-side victim selectionWith the fingerprinting logic in place, the malicious content is no longer present in the initial page shown to the visitor. Instead, the server withholds the ClickFix lure until it receives and evaluates the submitted fingerprint, then returns one of two responses:
- A bot, crawler, sandbox, virtual machine, unexpected geography, or unexpected browser receives a blank page, a benign decoy, or no content.
- A genuine Mac and browser in an expected context receive the ClickFix lure: the counterfeit “Verified Publisher / Download for macOS” page and its poisoned one-liner. The targeting is primarily environment-based: genuine macOS users in an expected browser and request context receive the ClickFix lure.
This is a Traffic Distribution System (TDS) gate. We call it a TDS because the payload is delivered by server-side, on demand, only to visitors the operator selects security crawlers, researchers, and sandboxes are served no malicious content. This gating can make automated detection and analysis more difficult because those tools may see only an apparently benign response even though the infrastructure can deliver the ClickFix lure to selected macOS visitors.
Figure 4 – Server-side fingerprint evaluation and possible responses for selected and non-selected visitors. Inside the infection chain: from gated lure to AMOSThe individual techniques used by the gate are not inherently malicious or novel. Browser fingerprinting, hardware validation checks, and Traffic Distribution System (TDS)-style visitor filtering are common in anti-abuse systems and have previously appeared in exploit-kit and malvertising ecosystems. What distinguishes this activity is how these techniques are integrated into a ClickFix campaign. Rather than immediately presenting a malicious command, the actor performs server-side victim qualification before revealing the lure, reducing visibility to researchers and automated security systems while maintaining access to intended macOS targets.
Using a qualified macOS target, we analyzed the complete infection chain. The activity began on a file<word><word>[.]com domain hosting the fingerprinting gate, which returned the counterfeit Download for macOS page (Figure 1a). A non-qualifying request received little or no visible content. The page uses GitHub-themed branding to mimic a legitimate software download experience; the branding is spoofed and does not indicate any compromise of GitHub.
When the victim runs the Terminal command, the campaign retrieves and executes a remote script from a /curl/<id> URL. The chain then progresses through multiple script stages before ultimately downloading and launching Atomic Stealer (AMOS), an information stealer that harvests credentials, browser and cryptocurrency wallet data, authentication stores, and other sensitive files before exfiltrating them. We detailed AMOS delivery across multiple macOS ClickFix lures in earlier research.
Because delivery is restricted to qualified visitors, the fingerprinting gate is often a more reliable hunting target than the downstream malware. Systems that inspect page content without executing client-side JavaScript can observe the gate logic directly, while environments that fail qualification are redirected to apparently benign or no content. Because these characteristics also appear in legitimate anti-bot implementations, evaluate combinations rather than single indicators. Useful signals include self-submitting fingerprinting forms, hidden fingerprint data fields, artifacts such as the mode:”php” parameter, and domains following the observed file naming convention; correlating several of these improves confidence and reduces false positives.
Mitigation and protection guidanceOrganizations can apply the following recommendations to reduce exposure to this and similar macOS ClickFix campaigns:
- Educate users. Reinforce that no legitimate download, CAPTCHA, or verification step requires pasting a command into Terminal.
- Monitor Terminal usage. Alert on Terminal or shell sessions that spawn curl, base64, gunzip, or osascript, particularly when initiated shortly after web browsing.
- Detect native-tool abuse. Flag unusual sequences of macOS utilities such as curl piped to zsh, base64 -d, and xattr -c immediately preceding chmod +x.
- Inspect outbound downloads. Monitor curl activity that retrieves encoded or compressed payloads from newly registered or low-reputation domains, including /curl/<hex-id> request paths.
- Protect credential stores. Detect unauthorized access to keychain items, browser credential databases, SSH keys, and cryptocurrency wallet data.
- Monitor data staging. Alert on the creation of archives of sensitive artifacts followed by HTTP POST exfiltration.
- Block on infrastructure, not just front-end domains. Where validated, prioritize blocking known shared back end and staging hosts (for example, malware-c2 and the /curl/<id> staging hosts) over individual disposable front-end domains.
- Hunt the generation pattern. Where feasible, alert the file<word><word> domain pattern rather than maintaining a list of individual domains.
On macOS 26.4 and later, Apple introduced a mitigation that displays a warning when a user attempts to paste a potentially malicious command into Terminal, directly addressing the ClickFix delivery mechanism.
When a user attempts to paste a potentially malicious command into Terminal, they will now see the following prompt:
Possible malware, Paste blocked
Your Mac has not been harmed. Scammers often encourage pasting text into Terminal to try and harm your Mac or compromise your privacy. These instructions are commonly offered via websites, chat agents, apps, files, or a phone call.
Microsoft Defender XDR detections Tactic Observed activity Microsoft Defender coverage Initial Access Malicious webpage Microsoft Defender for SmartScreenSmartScreen Detection Blocks webpage (Figure 5) Execution User copies, pastes, and runs encoded instructions. The instructions are decoded, executable files are created from remote attacker infrastructure, and the malware implant is executed.Microsoft Defender for Endpoint
– Behavior:MacOS/SuspAmosExecution
– Malicious file execution
– Behavior:MacOS/SuspOsascriptExec
– Malicious osascript execution
– Behavior:MacOS/SuspDownloadFileExec
– Behavior:MacOS/SuspInfoExfil
– Behavior:MacOS/SuspiciousActiviyGen.AE
– Suspicious file download and executionCredential access Keychain extraction Behavior:MacOS/SuspKeyChainCopy.ABCollection & Exfiltration Browser data, crypto wallets, keys etc. – Behavior:MacOS/SuspInfostealExec
– Behavior:MacOS/SuspCredCopy
– Behavior:MacOS/SuspPassSteal
Microsoft Defender SmartScreen displays a warning message to Microsoft Edge users when they visit a ClickFix landing page:
Figure 5. Microsoft Defender SmartScreen flagging a ClickFix webpage. Microsoft Security CopilotSecurity Copilot customers can use the standalone experience to create their own prompts or run the following prebuilt promptbooks to automate incident response or investigation tasks related to this threat:
- Incident investigation
- Microsoft User analysis
- Threat actor profile
- Threat Intelligence 360 report based on MDTI article
- Vulnerability impact assessment
Note that some promptbooks require access to plugins for Microsoft products such as Microsoft Defender XDR or Microsoft Sentinel.
Advanced huntingThe following query is an illustrative starting point. Validate table/column names and adjust the time range and indicators for your environment before running.
Known-IOC network sweep (mirrors a standard IOC hunt; populate from the IOC table and refresh as domains rotate)
let lookback = 30d; let SuspiciousDomains = dynamic(["lemonfilewave.com","limefilescope.com","mangocloudfile.com"]); DeviceNetworkEvents | where Timestamp >ago(lookback) | where RemoteUrl has_any (SuspiciousDomains) Indicators of compromise (IOC) Indicator Type Description applefilevault[.]comDomainClickFix Webpageapricotfilepoint[.]comDomainClickFix Webpage bananafastfile[.]comDomainClickFix Webpagecloudfilebridge[.]comDomainClickFix Webpagefilecedarwallet[.]online.DomainClickFix Webpagefilecopperbasket[.]sbsDomainClickFix Webpagefilecrimsonsignal[.]onlineDomainClickFix Webpagefilemarblegarden[.]sbsDomainClickFix Webpagefileoceanhammer[.]sbsDomainClickFix Webpagefilerubyfolder[.]sbsDomainClickFix Webpagefilevelvettractor[.]sbsDomainClickFix Webpagelemonfilewave[.]comDomainClickFix Webpagelimefilescope[.]comDomainClickFix Webpagemangocloudfile[.]comDomainClickFix Webpageorangesmartfile[.]comDomainClickFix Webpagesyncdatavault[.]comDomainClickFix Webpagecloudsendhub[.]comDomainClickFix Webpage References- ClickFix campaign uses fake macOS utilities lures to deliver infostealers | Microsoft Security Blog
- Think before you Click(Fix): Analyzing the ClickFix social engineering technique | Microsoft Security Blog
- macOS ClickFix Lures Deploy AppleScript Stealer & Persistent RAT | The Lens blog – netskope – June 17, 2026
- Clickfix Github Themed macOS Infostealer Deliver Campaign IOCs | GitHub gist – brkalbyrk – May 16, 2026
- Atomic macOS Stealer (AMOS): Reading the C2 Protocol from a PCAP | Pcap AI blog – June 23, 2026
- Evil evolution: ClickFix and macOS infostealers | Sophos Blog – March 11, 2026
For the latest security research from the Microsoft Threat Intelligence community, check out the Microsoft Threat Intelligence Blog.
To get notified about new publications and to join discussions on social media, follow us on LinkedIn, X (formerly Twitter), and Bluesky.
To hear stories and insights from the Microsoft Threat Intelligence community about the ever-evolving threat landscape, listen to the Microsoft Threat Intelligence podcast.
Review our documentation to learn more about our real-time protection capabilities and see how to enable them within your organization.
- Microsoft 365 Copilot AI security documentation
- How Microsoft discovers and mitigates evolving attacks against AI guardrails
- Learn more about securing Copilot Studio agents with Microsoft Defender
- Evaluate your AI readiness with our latest Zero Trust for AI workshop.
The post From open lures to cloaked gates: How a macOS ClickFix campaign learned to hide appeared first on Microsoft Security Blog.
Ledgerful – I built a local tool to catch when AI invents stuff in my code
Article URL: https://www.ledgerful.dev
Comments URL: https://news.ycombinator.com/item?id=49184441
Points: 2
# Comments: 1
Stateless MCP is cheaper to scale
Article URL: https://jeffauriemma.leaflet.pub/3msdu742fik24
Comments URL: https://news.ycombinator.com/item?id=49184433
Points: 1
# Comments: 0
Google is killing Google Assistant next month
Article URL: https://www.neowin.net/news/another-one-bites-the-dust-google-is-finally-killing-google-assistant-next-month/
Comments URL: https://news.ycombinator.com/item?id=49184407
Points: 1
# Comments: 0
Offensive Internet Posture
Article URL: https://bruceediger.com/posts/offensive-machine/
Comments URL: https://news.ycombinator.com/item?id=49184398
Points: 2
# Comments: 1
Batteries are getting cheaper while gas gets pricier. Here's why
Article URL: https://theconversation.com/batteries-are-getting-cheaper-while-gas-gets-pricier-heres-why-287956
Comments URL: https://news.ycombinator.com/item?id=49184396
Points: 2
# Comments: 0
Wikipedia: AI or Not Quiz
Article URL: https://en.wikipedia.org/wiki/Wikipedia:AI_or_not_quiz
Comments URL: https://news.ycombinator.com/item?id=49184395
Points: 1
# Comments: 0
Show HN: HUD, an open-source minimal terminal UI for ClaudeCode, Codex, OpenCode
Article URL: https://github.com/adrida/hud-mode
Comments URL: https://news.ycombinator.com/item?id=49184388
Points: 2
# Comments: 1
Jellyware
Article URL: https://twitter.com/thorstenball/status/2085017920782877041
Comments URL: https://news.ycombinator.com/item?id=49184384
Points: 1
# Comments: 0
Desktop Touch ID sensor for $20 [video]
Article URL: https://www.youtube.com/watch?v=tB3lk-PNA6I
Comments URL: https://news.ycombinator.com/item?id=49184373
Points: 1
# Comments: 1
What went wrong with data lakes? A 15-year reality check
Article URL: https://arxiv.org/abs/2606.08266
Comments URL: https://news.ycombinator.com/item?id=49184370
Points: 2
# Comments: 0
Ghosthub: Tmux/SSH-native macOS terminal based on libghostty
Article URL: https://ghosthub.ai/
Comments URL: https://news.ycombinator.com/item?id=49184357
Points: 1
# Comments: 0
See the Sun like never before with most detailed images yet
Article URL: https://www.bbc.com/news/articles/c36d4376nd2o
Comments URL: https://news.ycombinator.com/item?id=49184355
Points: 2
# Comments: 0
She Believed Big Tech Could Change the World. Just Not for the Worse.
Article URL: https://www.nytimes.com/2026/08/04/books/review/dont-be-evil-claire-stapleton.html
Comments URL: https://news.ycombinator.com/item?id=49184350
Points: 1
# Comments: 1
AI agents can't yet do open-ended AI research
Article URL: https://www.normaltech.ai/p/ai-agents-cant-yet-do-open-ended
Comments URL: https://news.ycombinator.com/item?id=49184336
Points: 1
# Comments: 0
