This day 02:07 06:07 10:08 14:08 18:08 22:09
Info  2026-08-30 10:08Z · last 4h · 11 findings · glm-5.2:cloud

Threat Brief — 2026-08-30 — Fake CAPTCHAs, Real Backdoors

Executive summary. A new ClickFix attack variant dubbed "TerminalFix" tricks users into running malicious commands in Windows Terminal or PowerShell under the guise of fake Cloudflare CAPTCHA challenges, ultimately deploying a reverse-tunnel backdoor. The rest of today's feed is dominated by general science and hardware news with no direct security-intelligence value.

Top items

Themes

ClickFix evolution. The TerminalFix variant shows the ClickFix attack pattern continuing to diversify its delivery vectors. Where earlier iterations relied on the Windows Run dialog, this version targets Windows Terminal and PowerShell — suggesting attackers are adapting to environments where users may be more technically inclined or where Run-dialog execution is restricted. The fake-CAPTCHA pretext remains the constant anchor across variants, exploiting user familiarity with browser verification prompts.


Public exploits · latest from the exploit feed

[remote] Ecava_ntegraXor IGX_16.0.701.10 - RCE 2026-10-01 15:15Z · RSS:exploit-db [webapps] Food-Ordering 1.0 - LFI 2026-10-01 15:15Z · RSS:exploit-db [webapps] WordPress 7.0.2 - Path Travesal 2026-10-01 15:15Z · RSS:exploit-db [webapps] TigerGraph_Community_Edition 4.2.4 - arbitrary file write 2026-10-01 15:15Z · RSS:exploit-db [remote] Teltonika_RutOS 00.07.06.21 - command injection 2026-10-01 15:15Z · RSS:exploit-db [webapps] POMS oretnom23v1.0 - SQLi vulnerabilities 2026-10-01 14:15Z · RSS:exploit-db [webapps] InvoicePlane 1.7.1 - RCE 2026-10-01 14:15Z · RSS:exploit-db [webapps] SuiteCRM 8.10.1 - Authenticated SSRF 2026-10-01 14:15Z · RSS:exploit-db [webapps] Krayin CRM 2.2.4 - IDOR 2026-10-01 14:15Z · RSS:exploit-db [remote] MikroTrick, 7.24, 7.24.2, 7.0.0, 7.23.4, 6.0.0, 6.49.21 - RCE 2026-09-30 15:11Z · RSS:exploit-db