Browser attacks without downloads. [Research Saturday]

Browser attacks without downloads. [Research Saturday]

0 Ratings
0
Episode
3400 of 3425
Duration
22min
Language
English
Format
Category
Non-fiction

Today we are joined by Nati Tal, Head of Guardio Labs, discussing their work “CAPTCHAgeddon” or unmasking the viral evolution of the ClickFix browser-based threat. CAPTCHAgeddon — Shaked Chen’s deep dive into the ClickFix fake-captcha wave — reveals how a red-team trick morphed into a dominant, download-free browser threat that tricks users into pasting clipboard PowerShell/shell commands and leverages trusted infrastructure, including Google Scripts. Guardio’s DBSCAN-based payload clustering exposes distinct attacker toolkits and distribution paths — from malvertising and compromised WordPress to social posts and Git repos — and argues defenders need behavioral, intelligence-driven protections, not just signatures.

The research can be found here:

“CAPTCHAgeddon” Unmasking the Viral Evolution of the ClickFix Browser-Based Threat

Learn more about your ad choices. Visit megaphone.fm/adchoices


Listen and read

Step into an infinite world of stories

  • Read and listen as much as you want
  • Over 1 million titles
  • Exclusive titles + Storytel Originals
  • 7 days free trial, then €9.99/month
  • Easy to cancel anytime
Try for free
Details page - Device banner - 894x1036
Cover for Browser attacks without downloads. [Research Saturday]

Other podcasts you might like ...