Skip to main content
Security

Researchers link 5,400 hacked sites to blockchain-hosted ClickFix campaign

Researchers link 5,400 hacked sites to blockchain-hosted ClickFix campaign Image: Primary
Researchers identified more than 5,400 compromised websites, mostly built on WordPress and PrestaShop, that deliver ClickFix lures using payloads stored in BNB Smart Chain testnet smart contracts. Netskope said injected scripts show fake CAPTCHAs that direct visitors to run a PowerShell command, which downloads and executes a final payload. The operator later replaced the ClickFix payload with a WebRTC data-channel stager that receives and executes code in browser memory. Netskope said the operation uses more than 300 infected sites each day.
Sources
Published by Tech & Business, a media brand covering technology and business. This story was sourced from BleepingComputer and reviewed by the T&B editorial agent team.
Back to Newswire
Keep reading
Full wire
Robotics
Robotics

Atoms develops robotaxi technology after Pronto acquisition

Atoms, the company founded by Travis Kalanick, is developing robotaxi technology, hired Anthony Levandowski after acquiring his company Pronto, and has received a $100 million investment from Uber, according to sources cited by th...

Security Policy
Security Policy

Berlin reviews ransomware data release after rejecting ransom

Berlin's state government said it is reviewing a 5.79TB trove of stolen data published by the Rhysida ransomware group after the state refused to pay a ransom. Reuters reported that the released files reportedly include national-d...

Security Infrastructure
Security Infrastructure

JetBrains tells Cadence users to rotate credentials after TeamCity breach

JetBrains is telling Cadence users to revoke or rotate credentials and secrets after attackers exploited a critical TeamCity vulnerability to breach a Cadence environment. The company said the attackers accessed a 2024 server back...

Security
Security

PaperCut flaws exploited in credential-theft attacks on schools

Attackers are exploiting two newly disclosed PaperCut flaws in attacks on vulnerable education-sector servers in the U.S. and Europe, according to Arctic Wolf. The security firm described the flaws as an authentication-bypass and ...

Security
Security

Brave releases patch for reported exploited V8 flaw

Brave released desktop version 1.94.121 with a fix for CVE-2026-85046, a Chromium V8 JavaScript-engine vulnerability the company said had been exploited in the wild. The browser maker urged users to install the update and relaunch...