Reading view

Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root

A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the exploit code is now public, and any machine still running an older kernel should be updated. The flaws

  •  

Researchers used Claude to hack OpenAI employees' ChatGPT accounts

Talk about your competitor getting through the door. Security researchers used Anthropic's Claude to help hack into OpenAI employees’ ChatGPT accounts. A trio of bug hunters researching frontier AI labs’ security weaknesses chained two vulnerabilities to take over multiple OpenAI employees’ ChatGPT accounts, then used that access to demonstrate they could reach an internal OpenAI repository by opening a harmless pull request. The entire timeline, from initial discovery to accessing OpenAI’s repo, took less than 72 hours and earned the researchers a $6,500 reward from OpenAI’s bug bounty program on Bugcrowd. “Until two months ago, any user or OpenAI employee logging into OpenAI’s own help forum (community.openai.com) could have had their ChatGPT and Codex accounts taken over,” Hacktron researchers Harsh Jaiswal, Mohan Pedhapati, and Rahul Maini said in a writeup about their research. “Since people can connect various services to Codex and ChatGPT, the scope of what we could theoretically access was huge, including GitHub, Slack and emails.” And, in a poetic twist, they used rival AI giant Anthropic’s Claude models to develop the exploit. Claude has shown a propensity to hack organizations without human guidance, as have OpenAI's models. The team gained initial entry on July 25 via OpenAI’s community forum. The forum runs on Discourse, which typically uses FastImage to perform image checks. However, since FastImage didn’t support HEIF files in the affected setup, HEIF images uploaded to Discourse passed through ImageMagick, which used libheif to process them before converting them to another image format. “That exposed the underlying libheif parser directly to attacker-controlled files,” the researchers wrote. Using Claude Opus 4.8, the trio found a heap buffer overflow flaw in the libheif library and attempted to use that model to develop a remote code execution (RCE) attack, but this didn’t work on Discourse’s default configuration. But then, Anthropic released Claude Opus 5. The bug hunters used the newer model to generate an exploit script, and achieved RCE on OpenAI’s instance. The trio “immediately” reported the vulnerability to OpenAI. “We then took over an OpenAI employee’s account, whose Codex was connected to OpenAI’s Github organization,” they wrote. “To demonstrate impact without actually accessing any internal code, we sent a prompt to this employee’s Codex account to open a PR for us in OpenAI’s internal monorepo. Then we stopped any further testing.” Neither OpenAI nor Anthropic responded to The Register’s requests for comment. OpenAI fixed the flaw within about 14 hours of the report’s submission, marked the issue as resolved, and paid the Hacktron team a $6,500 bounty. “To clarify the scope of that award: testing against the Discourse-hosted community.openai.com was explicitly excluded from our bug bounty program,” OpenAI said in a comment shared by Hacktron. “The award recognizes the OpenAI-side finding, not the actions against Discourse.” Discourse also issued a fix that added image-processing sandboxing, and published a security advisory GHSA-vhm9-85gw-x335 with patching and rebuild guidance. The entire hack took a few days for an AI agent and a few hours of human work. “Work that once required a well-resourced team and months of effort can now be compressed into days,” the researchers said. “Security assumptions must catch up with attacker capabilities.” ®

  •  

New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution

WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install. The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only

  •  

North Korea's fake job interviews infected 30,000 devices

North Korea's employment scams work both ways. As well as placing fraudulent IT workers inside Western companies, regime-backed cybercriminals have posed as recruiters to infect more than 30,000 devices and steal over $10 million, according to an international advisory. Law enforcement and cybersecurity agencies from Australia, Germany, Japan, and the US issued an update on the campaign on Thursday. They said the attackers had compromised more than 7,000 cryptocurrency wallets and stolen funds that ultimately supported the North Korean regime. The agencies track the activity collectively as WaterPlum. Its operators target web designers, engineers, and cryptocurrency and Web3 specialists with bogus recruitment approaches. During the supposed interview process, victims are instructed to download files presented as coding assignments or other recruitment tests. Opening them backdoors the applicants' computers and installs malware. Once inside, the attackers deploy remote access trojans (RATs) and information stealers, giving them persistent access to credentials and other sensitive data long after the fake interview ends. In some cases, the compromised machines may later provide a route into corporate systems when the jobseekers secure legitimate employment. WaterPlum operators use that access to steal intellectual property, credentials, clipboard contents, keystrokes, cryptocurrency wallet data, and identity documents that can support further impersonation. "Stolen IDs can be used by North Korean IT workers to impersonate victims and generate foreign currency," the advisory [PDF] said. "Stolen credentials may be leveraged to exfiltrate crypto assets, personal data, trade secrets, etc., from victims' employers, clients, or contracting parties. The actors can also use stolen sensitive information for extortion." The agencies attributed at least $10.71 million in thefts to these tactics, with the proceeds funneled to Pyongyang. The recruiter campaign complements North Korea's better-known tactic of placing its own IT workers in technology roles at Western and allied companies. The scheme has been extensively documented and has generated revenue for North Korea for years. Researchers estimate that roughly 100,000 North Korean IT workers are employed or seeking work worldwide. Some are supported by accomplices operating laptop farms, which make remote workers appear to be based in the country where they were hired. The workers collect salaries from companies in countries that impose heavy sanctions on North Korea, with much of the money surrendered to the state. The sprawling IT worker fraud is thought to net Kim Jong Un's regime upwards of $500 million a year. The scale of the operation means some applicants inevitably succeed, although employers are becoming more familiar with signs of fraudulent North Korean candidates. Applicants often submit impressive resumes claiming prestigious educational backgrounds, extensive work experience, and language skills that may not withstand scrutiny during an interview. Other warning signs include repeated refusals to meet in person, suspicious interruptions to video feeds, voices in the background, and requests for payment in cryptocurrency. Fraudulent workers may also use AI face-swapping software, which can produce visual artifacts during video calls and prompt them to disable their cameras shortly after an interview or meeting begins. The agencies recommend that any organization suspecting it has engaged a fraudulent North Korean IT worker launch a full forensic investigation and assume that credentials and other sensitive data have been compromised. ®

  •  

FBI: Fake cop and government impersonation scams cost victims $1.6B

Scammers impersonating law enforcement or government officials have cost victims more than $1.6 billion since January 2025, the FBI reports. The FBI’s Internet Crime Complaint Center (IC3) received close to 61,000 complaints of this type between January 2025 and July 2026, putting the average per-complaint loss at more than $26,000. The most common type of scam is one involving criminals convincing targets to pay a sum of money to remove charges the fraudsters claim were filed against them. Typically contacting targets via unsolicited phone calls, the scammers usually claim that the target has committed or is connected to a crime, and threaten consequences such as arrest and prison time if a payment is not made. Accounting for roughly 11 percent of the complaints is a different type of scam, which involves alleging victims did not fulfill their assigned jury duty or missed a court date, then threatening them with a fine or arrest unless they pay. Of these 6,833 complaints, scammers caused losses amounting to nearly $36 million. A more profitable variant involves a more targeted approach. Scammers will complete some due diligence on a target, such as ascertaining their profession, and tailor the scam to their job. The IC3 has seen cases in which scammers contact medical practitioners, for example, claiming their medical license is expiring or that it was used in the commission of a crime. Payment is then demanded either under the guise of renewing the license or as part of an extortion attempt to "protect their professional reputation." Victims reported 3,322 instances of this kind of targeted scam, with total losses exceeding $37 million. A far less common tactic, deployed in 496 of the total complaints, saw scammers claim that documents such as driver's licenses or passports had expired and demand payment to renew them. Despite accounting for a minority of cases, criminals still netted $348,000 using this method. Finally, and arguably the most elaborate tactic the IC3 outlined, was the targeting of Americans from different ethnic communities, foreign nationals, and international students in the US. The nature of the targeting was not the aspect the criminals invested the most effort in. The general procedure was also similar to the other examples: Scammers impersonate foreign law enforcement or US-based foreign diplomatic officials, threatening to cancel the victim’s home-country passport or have them extradited. However, these scams sometimes involve video calls. The criminals are known to don a country’s law enforcement uniform, or in some cases even take the calls in movie-style sets they create to mimic real government facilities. The IC3 said that it received 1,809 complaints of this kind of targeted scam during the 19-month reporting period, with total losses exceeding $140 million. It means nearly 10 percent of the overall losses stemmed from one scam that accounted for less than 3 percent of the total complaints. Law enforcement impersonation scams are common across the world, although they may take different shapes from country to country. In the Netherlands, for example, police received more than 7,200 reports of fake police officer scams in the first half of 2026 alone, although the criminals behind them don’t hide behind a phone or keyboard. Scams in the Netherlands see fraudsters approach victims at their homes, usually targeting the elderly population, offering to safeguard their valuables while posing as a trusted authority. In reality, the criminals simply steal the jewelry, money, bank cards, and other valuables they are entrusted to protect. Cases like these have surged across the country in recent years, and aspiring crooks as young as 14 have tried to cash in on the trend. Police have invested more in public awareness campaigns as a result. The FBI reminded the public that neither it nor any other law enforcement agency will call an individual and demand payment or request personal or sensitive information. Citizens should remember to ask for credentials and make attempts to independently verify the identity of the caller, such as calling the relevant office using publicly available details and asking for the caller by name. The IC3 recently reported its most damaging year for internet scams. It released 2025’s data in April, covering all types of cybercrime, pegging total losses at $20.87 billion – the first time it has reported annual losses exceeding the $20 billion threshold. ®

  •  

Transparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2

The Pakistan-aligned threat group tracked as Transparent Tribe (aka APT36 and Earth Karkaddan) has been attributed to a fresh set of cyber attacks targeting government and defense entities in India and Afghanistan. The attacks, per Zscaler ThreatLabz, involve the use of previously undocumented tools called RUSTYSHADE, RUSTYMOVE, PSNATCH, and BASHNATCH. The activity has been codenamed Operation

  •  

Fake HBO Max Ads Spread ClickFix Malware on Reddit: This Week in Scams

If a website asks you to open Terminal, PowerShell, Command Prompt, or the Windows Run box and paste something in, stop.

That simple rule can protect you from a type of attack McAfee has been tracking for years. Known as ClickFix, the scam turns an ordinary-looking online instruction into a way for criminals to install malware on your device. The lure might look like a CAPTCHA, a software fix, a download, or a quick tutorial. The trick is getting you to run the attack yourself.

ClickFix is back in the headlines this week after attackers reportedly compromised HBO Max’s verified Reddit advertising account and used it to distribute malicious ads. But while the brands, websites, and platforms keep changing, the underlying trick is one McAfee researchers have been following since at least 2024.

What is a ClickFix Attack?

A ClickFix attack is a social engineering scam that convinces someone to copy, paste, or run a malicious command on their own computer.

This week’s example shows why the tactic can be so convincing. According to TechCrunch, attackers compromised an HBO Max account authorized to run ads on Reddit. The account was then used to publish malicious advertisements that could direct people to fake sites, including pages made to look like they were associated with HBO Max.

Researchers investigating the campaign reported finding 108 malicious ads posted over roughly 48 hours. Some promoted what appeared to be a Mac version of HBO Max, while others used software and AI-related lures.

Instead of providing a normal download, the sites instructed visitors to open tools such as Terminal on a Mac or PowerShell or the Run dialog on Windows, paste in a command, and execute it. That last step is the important one.

The website is not really helping you fix or install something. It is convincing you to give your computer malicious instructions.

Depending on the campaign and device, those instructions can lead to information-stealing malware designed to collect things such as saved passwords, browser information, account data, or cryptocurrency wallet information.

Reddit told TechCrunch that it learned an HBO Max account authorized to run advertisements had been compromised and used for malicious links. The company said it locked the account and removed the ads. The number of people who clicked the ads or were ultimately compromised remains unclear.

Clickfix isn’t New, and Mcafee Has Been Tracking It For Years

What makes this week’s story notable isn’t that ClickFix suddenly appeared. It’s how far the tactic has traveled.

McAfee Labs documented ClickFix attacks in July 2024 after researchers discovered compromised websites displaying fake error messages that instructed people to paste scripts into PowerShell. Researchers observed the technique being used to deliver malware including DarkGate and Lumma Stealer.

Just a few months later, McAfee Labs documented another variation built around something nearly everyone recognizes: the CAPTCHA.

Victims encountered fake “Verify you are a human” or “I’m not a robot” pages. Clicking the button could copy a malicious command to the clipboard. The page would then walk the person through opening the Windows Run box and pasting it in. McAfee researchers observed those fake CAPTCHA attacks connected to phishing emails and searches for cracked games.

By 2025, the same basic idea was appearing in yet another familiar place: social media tutorials. McAfee reported on ClickFix-style scams circulating through TikTok videos that promised free software upgrades or premium versions of popular apps. Instead of solving a problem, the instructions could lead people to install information-stealing malware.

Now the lure has changed again. This time, attackers allegedly used advertising from a compromised, verified corporate account.

That evolution matters because ClickFix isn’t one particular fake website or pop-up you can memorize. It’s a reusable scam technique.

Why ClickFix scams can be so convincing

Most online scams ask you to click something. ClickFix adds another layer by asking you to do something.

That action may feel technical enough to be legitimate. A page tells you there’s an error. It gives you several steps to fix it. Maybe you’re asked to press a few keys, open a utility you’ve seen on your computer before, paste something, and hit Enter.

Following instructions can feel safer than downloading an unfamiliar file. But in a ClickFix attack, following the instructions is effectively the download.

Attackers also keep placing these instructions inside familiar online experiences. McAfee researchers have seen fake error messages and CAPTCHA checks. Other campaigns have appeared in social media tutorials, software downloads, phishing messages, and now online advertising.

Even a familiar brand or verified account shouldn’t override an unusual request from a website.

Key Takeaways

ClickFix is a social engineering technique, not one specific scam. The lure can change while the basic attack stays the same.

McAfee researchers have tracked ClickFix campaigns since 2024, including fake error messages and CAPTCHA pages designed to deliver malware.

Mac users aren’t automatically outside the target zone. This week’s campaign reportedly included separate techniques targeting both macOS and Windows.

The biggest warning sign is an unusual instruction. A website should not need you to paste an unexplained command into Terminal, PowerShell, Command Prompt, or Run to prove you’re human or download ordinary consumer software.

How McAfee Helps

You deserve multiple layers of cybersecurity protection to prevent and stop threats like ClickFix at every potential point of malware entry. That’s what McAfee’s built to do.

Web Protection can help prevent access to known malicious websites, including sites used as part of malware campaigns. That matters when an otherwise convincing ad or message sends you somewhere dangerous.

Device Security adds another layer by scanning for and helping block malware that attackers attempt to install. McAfee Labs has previously documented McAfee protections blocking stages of ClickFix infection chains, including malicious URLs and suspicious behavior.

And because information stealers often target passwords and account information, Identity Monitoring can help alert you when monitored personal information is found in a breach so you can respond sooner.

Technology can help, but ClickFix also has a human checkpoint built into the attack. If a webpage suddenly asks you to become your own system administrator and run a command you don’t understand, don’t.

Other Scam and Security News This Week

Spain’s privacy regulator receives report of an alleged AI-powered breach. Spain’s data protection agency said it was notified of an incident in which an AI agent was allegedly used to find vulnerabilities, access systems, probe applications, and ultimately access or modify data. The regulator has not yet investigated and verified the reported incident, an important distinction as security researchers continue examining how AI agents could be misused in cyberattacks.
Source: BleepingComputer

Revolut says its core systems weren’t hacked in customer data incident. Reuters reported that sensitive information involving about 680 customers was disclosed after fraudulent requests were sent from a legitimate government agency email domain, according to a source familiar with the matter. Revolut said it had received no direct demand from the group claiming responsibility, while the group reportedly threatened to sell customer records unless it received a $3 million ransom.
Source: Reuters

More details emerge about the malicious HBO Max Reddit ads. Additional reporting on the ClickFix campaign said the compromised account was used to run 108 malicious ads over about 48 hours, with lures ranging from HBO Max downloads to AI and software tools. The findings reinforce the main lesson from this week’s story: a verified account or recognizable brand doesn’t make unusual download instructions safe.
Source: Malwarebytes

This Week’s Safety Tips

Some practical safety tips in light of this week’s news:

Don’t paste commands from websites into system tools. Treat the request itself as a warning sign.

Skip software downloads promoted through ads. Navigate to the company’s official website or trusted app store yourself.

Use multifactor authentication on important accounts. It can provide another barrier if a password is stolen.

Keep security protection and your devices updated. Current protection gives you more opportunities to catch malicious sites and malware before they can do damage.

ClickFix may keep changing its disguise, but you don’t need to learn every version. Remember the underlying trick: a website that asks you to copy, paste, and run unfamiliar commands is asking for far more trust than you should give it.

And we’ll be back next week with more cybersecurity news and scam alerts.

The post Fake HBO Max Ads Spread ClickFix Malware on Reddit: This Week in Scams appeared first on McAfee Blog.

  •  

Microsoft Teams Help Desk Impersonation: When IT Support Messages You First

Attackers are opening Microsoft Teams chats from tenants they control, using a display name like IT Service Desk, and talking people into either installing a file or handing over a remote session. Teams allows chat from any external domain by default, and the attacker only needs the target to say yes once. In the case Expel documented, the yes was an MSI hosted on a Microsoft Azure storage endpoint; the payoff was a fake Windows lock screen that captured the user’s password in the clear. Two settings in the Teams admin center and one sentence said out loud to your staff close most of this.

submitted by /u/scamdrill
[link] [comments]
  •  

Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation

Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. "Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,"

  •  

An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.

In July 2025, someone registered a domain that used to belong to a content delivery network.  The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositories, and documentation pages still carry hard-coded references to hostnames beneath it.  The new owner holds

  •  

Plugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding Agents

A flaw in four widely used AI coding agents lets someone who controls a plugin's code repository swap the plugin an agent installs for a malicious one, even when the agent locked that plugin to a specific reviewed version, security firm Air Security said on Thursday. The firm said Anthropic has patched the flaw in Claude Code 2.1.179 and OpenAI in Codex 0.146.0, that GitHub Copilot has no

  •  

WeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension Storage

Cybersecurity researchers have discovered a cluster of 13 npm packages that have been found to deliver a previously undocumented JavaScript stealer codenamed WeaselBiscuit. The new malware family, per OpenSourceMalware, exhibits functional overlaps with two malware strains associated with the Democratic People's Republic of Korea's (DPRK) Contagious Interview campaign: BeaverTail and

  •  
❌