ClickFix is a sophisticated social engineering technique that exploits trust in CAPTCHA systems to execute malicious commands. It guides users through harmless keystrokes to install malware like infostealers and Qakbot. By relying on user interaction and obfuscation, this method complicates detection by security solutions, making it a challenging threat for defenses. Efforts are ongoing to disrupt its infrastructure.

Ivanti VPN customers targeted via unrecognized RCE vulnerability (CVE-2025-22457)
A suspected Chinese advanced persistent threat (APT) group exploited CVE-2025-22457, a previously unexploitable buffer overflow bug, to compromise devices running Ivanti Connect Secure (ICS) and