ClickFix malware turns one of the internet’s most familiar security checks into a trap. Instead of simply asking you to prove that you are human, a fake CAPTCHA may instruct you to open Windows Run, PowerShell, Windows Terminal, or the macOS Terminal and paste a command. If you follow those instructions, you may actually installContinue reading “That CAPTCHA Could Be Malware: How ClickFix Tricks Employees Into Infecting Their Own Computers”
Tag Archives: phishing
Before You Trust That File: How Metadata Can Reveal Scams, Fake Images, and Suspicious Documents
A photograph can contain GPS coordinates. A PDF can contain the name of the person or computer that created it. A Word document may reveal its author, editing software, company name, and creation history. Even a video can contain information about the device, software, date, and encoding process used to create it. All of thisContinue reading “Before You Trust That File: How Metadata Can Reveal Scams, Fake Images, and Suspicious Documents”
Business Email Compromise: When the Email Is Real but the Person Behind It Isn’t
A phishing email is dangerous when it looks real. Business email compromise can be even more dangerous because sometimes the email is real. The criminal may be communicating from the actual account of your employee, vendor, executive, or business partner. That changes the problem completely. There may be no misspelled domain to spot. No suspicious-lookingContinue reading “Business Email Compromise: When the Email Is Real but the Person Behind It Isn’t”