Minacce · 172 giorni fa
Le difese di macOS che avvertono gli utenti riguardo a comandi sospetti nel Terminal possono essere bypassate abusando di Script Editor, un'app preinstallata e affidabile, per eseguire comandi dannosi senza interazione esplicita con il Terminal. Questo infrange l'assunzione che gli avvisi basati sul Terminal coprano tutte le vie di attacco ClickFix e significa che i metodi standard di rilevamento non individuano questo vettore di consegna.
5 fonti che coprono questa storia
ClickFix campaign delivers Mac malware via fake Apple page - Help Net Security
A new ClickFix-style attack targeted Mac users via a fake Apple-themed webpage offering instructions on how to "reclaim disk space."
Atomic Stealer MacOS ClickFix Attack Bypasses Apple Security Warnings
macOS 26.4 update introduced security warnings into Terminal to prevent ClickFix attacks, so attackers have shifted to Script Editor instead
New ClickFix variant bypasses Apple safeguards with one‑click script execution
Jamf finds a ClickFix variant that swaps copy-paste Terminal lures for Script Editor execution, tightening delivery of Atomic Stealer.
New macOS stealer campaign uses Script Editor in ClickFix attack
A new campaign delivering the Atomic Stealer malware to macOS users abuses the Script Editor in a variation of the ClickFix attack that tricked users into executing commands in Terminal.
Risky Bulletin: Apple adds ClickFix warning to macOS terminal
Apple adds a ClickFix warning to macOS, Handala hacks Kash Patel's personal email, Balancer crypto platform shuts down after last year’s h [Read More
Part of the PlainSec briefing for 2026-04-11