Browser attacks without downloads. [Research Saturday]

Browser attacks without downloads. [Research Saturday]

0 Calificaciones
0
Episodio
3400 of 3425
Duración
22min
Idioma
Inglés
Formato
Categoría
No ficción

Today we are joined by Nati Tal, Head of Guardio Labs, discussing their work “CAPTCHAgeddon” or unmasking the viral evolution of the ClickFix browser-based threat. CAPTCHAgeddon — Shaked Chen’s deep dive into the ClickFix fake-captcha wave — reveals how a red-team trick morphed into a dominant, download-free browser threat that tricks users into pasting clipboard PowerShell/shell commands and leverages trusted infrastructure, including Google Scripts. Guardio’s DBSCAN-based payload clustering exposes distinct attacker toolkits and distribution paths — from malvertising and compromised WordPress to social posts and Git repos — and argues defenders need behavioral, intelligence-driven protections, not just signatures.

The research can be found here:

“CAPTCHAgeddon” Unmasking the Viral Evolution of the ClickFix Browser-Based Threat

Learn more about your ad choices. Visit megaphone.fm/adchoices


Escucha y lee

Descubre un mundo infinito de historias

  • Lee y escucha todo lo que quieras
  • Más de 900,000 títulos
  • Títulos exclusivos + Storytel Originals
  • 7 días de prueba gratis, luego $169 MXN al mes
  • Cancela cuando quieras
Suscríbete ahora
Copy of Device Banner Block 894x1036 3
Cover for Browser attacks without downloads. [Research Saturday]

Otros podcasts que te pueden gustar...