← All issues
cybersecurityCyberBubblephishing

ClickFix Is Now the #1 Way Hackers Break In — Here's the Simple Trick to Stop It

🌐  World Intel
Ukraine: Hackers hijack legitimate business websites to spread "Psychedelic" malware

Criminals have broken into real Ukrainian business websites — a hair clinic, a bookshop, a scale-model maker — and replaced what visitors see with a fake Cloudflare verification page. If you follow the instructions on that page, you end up installing a new piece of spyware called Psychedelic that hoovers up your browser passwords, account tokens, and any cryptocurrency wallet data it can find. The sites look completely normal from the outside, which is exactly what makes this scary.

↗ The Hacker News
Global: A placeholder web address used by thousands of developers now points to malware

Developers have used "third-party.com" as a dummy stand-in address in code examples and documentation for years — think of it like "example.com." But unlike example.com, nobody had ever officially reserved it. Someone bought it, and now it serves a malicious fake browser alert to Windows users who click on it. Over 1,700 code repositories link to this address, meaning a lot of developers and readers of technical docs could stumble onto it without realizing the danger. Google's Safe Browsing and VirusTotal have both flagged it as malicious.

↗ The Hacker News
USA: ShinyHunters claims it hacked the FBI using a software flaw in PeopleSoft

The ShinyHunters group is claiming it broke into FBI systems by exploiting a zero-day vulnerability in Oracle PeopleSoft, enterprise software used widely across government agencies. The group says it stole data during the breach. The FBI has not publicly confirmed or denied the claim. If true, it would be a significant embarrassment and a reminder that even law-enforcement agencies run software with unpatched holes.

↗ BleepingComputer
⚔️  Active Attacks
ClickFix is everywhere — and it's targeting you, not your software

ClickFix has gone from an obscure trick to the most common way attackers break into computers right now. Here's how it works: you visit a website — sometimes a legitimate one that's been hacked — and you see a message saying your browser can't load the page, or you need to verify you're human. The page quietly copies a dangerous command to your clipboard, then tells you to open a Windows dialog box and paste it in. You run the command thinking you're fixing a problem. You're actually handing attackers control of your machine. A new report tracking 17,000 malicious URLs shows this technique is now being sold as a subscription service to other criminals, and even state-sponsored hacking groups are using it.

🛡 What to do: If any website ever tells you to press Windows+R, open PowerShell, or paste something into a command box to "fix" a browser issue — stop immediately and close the tab. No legitimate website will ever ask you to do this.
AI agents used to steal 600,000 credit cards from online shops

A financially motivated criminal group is using open-source AI agent frameworks to attack hundreds of online retailers at the same time. The AI tools probe sites for weaknesses, then plant hidden web skimmers on checkout pages to silently record shoppers' payment card details as they type them. More than 600,000 credit card records have been stolen this way, and over 100 sites have been compromised. This is the first major case of AI being used at scale to automate the entire attack chain against e-commerce sites.

🛡 What to do: When shopping online, prefer paying with a virtual card number (most major banks offer these) or via PayPal/Apple Pay — that way your real card number never touches the retailer's site.
🔓  New Vulnerabilities
CVE-2026-85102 Check Point Security Gateway (VPN) CRITICAL

Check Point's Security Gateway — a firewall and VPN product used by many businesses — has a severe flaw in the way it handles VPN connections. An attacker doesn't need a password or account to exploit it: they can send a specially crafted request and gain full remote control of the device. Attackers are already actively using this in the wild.

Status: Patch available — Check Point has released a fix. If your company uses a Check Point gateway, flag this to your IT team today.

CVE-2026-87902 WordPress (popular website platform) CRITICAL

A serious flaw in WordPress is now being actively exploited after attackers moved past just scanning for it. The bug lets outsiders write files to a vulnerable website's server and then run commands on it — essentially giving them a back door into the whole site. WordPress powers roughly 40% of all websites on the internet, so the potential reach here is enormous.

Status: Patch available. If you own or manage a WordPress site, log into your dashboard and update immediately. If you use a host like WordPress.com, check whether updates were applied automatically.

CVE-2026-TEAMCITY JetBrains TeamCity (software build tool) HIGH

JetBrains TeamCity is a tool developers use to automatically build and test software — it's the engine room of many companies' software development. CISA warned federal agencies this week that ransomware gangs are now actively using a critical flaw in TeamCity that was patched back in July. If your development team hasn't updated yet, attackers could use this to take over your build systems and potentially inject malicious code into your software releases.

Status: Patch available since July — update to the latest version of TeamCity immediately.

CVE-2026-ROUNDCUBE Roundcube Webmail HIGH

Roundcube is open-source webmail software used by universities, governments, and small businesses around the world. A high-severity flaw patched back in May is now being actively exploited in code injection attacks, according to Canada's national cybersecurity centre. If your organization runs its own Roundcube server and hasn't updated since May, attackers may already be targeting it.

Status: Patch available since May 2026 — check with your email admin or hosting provider to confirm you're on the latest version.

🛠  New Tech
EvilTokens PhaaS platform taken down after 12,000 Microsoft accounts compromised

Law enforcement and security researchers disrupted EvilTokens, a Phishing-as-a-Service platform that made it easy for even unskilled criminals to run large-scale phishing operations. EvilTokens specialized in stealing session tokens to bypass two-factor authentication, and managed to compromise 12,000 Microsoft accounts before it was shut down. The takedown is a reminder that the criminal ecosystem around phishing has become industrialized — and that two-factor authentication, while still valuable, isn't a silver bullet if attackers can steal your session after you've already logged in. Using hardware security keys remains the strongest protection against this class of attack.

💡  Deep Dive
The People-Search Company That Kept Dodging Justice — Until a Judge Finally Seized Its Domain

Imagine a website that publishes your home address, phone number, relatives' names, and daily routines — and simply ignores every request to take it down. That's what Radaris, one of the internet's largest data broker sites, has been doing for years. Now, after a long legal fight, a judge has finally ordered the radaris.com domain itself handed over to the plaintiffs suing the company.

The case was brought under New Jersey's Daniels Law, which gives law enforcement officers, judges, and government officials the right to have their personal information wiped from data brokers. Atlas Data Privacy Corp sued Radaris in early 2024 after the site repeatedly ignored removal requests. What followed was a master class in corporate evasion: the company's owners — Russian-born brothers Igor and Dmitry Lubarsky, living in Massachusetts — shuffled ownership through a series of shell companies registered in places like the Marshall Islands, the British Virgin Islands, and the Seychelles. They even invented a fake CEO named "Gary Norden," complete with press releases, to obscure who was really running things. At one point, investigators hired in the Marshall Islands discovered that a newly named managing entity didn't even legally exist yet.

This matters beyond one shady website. There are hundreds of Radaris-style data brokers online, and most ordinary people have no idea their home address, family connections, and financial details are being sold to anyone who pays. For police officers, judges, and domestic violence survivors, that information exposure can be genuinely life-threatening. The legal tools to fight back — like Daniels Law — exist in only a handful of US states, and even when they do exist, companies like Radaris have shown they'll burn years of court time playing procedural games to outlast the plaintiffs.

The domain seizure is a notable win because it hits where it hurts most: the website address itself. Without radaris.com, the whole operation loses its primary audience. Watch for whether the Lubarsky brothers simply re-emerge under a new domain — because based on their track record, that's exactly the kind of move their playbook suggests. In the meantime, if you want to see what data brokers have on you and start requesting removals, services like DeleteMe or Mozilla Monitor Plus can help automate the process across dozens of sites at once.

🛡️

Stay sharp. It's free.

Join thousands of readers who get daily cybersecurity news in plain English.

Subscribe Free →