Cisco has issued a patch for a security flaw in its ClamAV anti-malware scanner that created serious risk for its Secure Web Appliance and Secure Endpoint products. The vulnerability, discovered by a Google engineer, allowed potential attackers to inject malicious code into endpoints or vulnerable Secure Web Appliances. The flaw was not under active attack but patching is recommended. ClamAV, acquired by Cisco a decade ago, is primarily used on mail servers.

ClickFix Captcha – A Creative Technique That Allow Attackers Deliver Malware and Ransomware on Windows
The ClickFix Captcha technique exploits user trust to distribute malware, including Quakbot. Users visiting malicious sites encounter a fake captcha directing them to perform actions