惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Latest news
Latest news
Cisco Talos Blog
Cisco Talos Blog
Simon Willison's Weblog
Simon Willison's Weblog
N
News and Events Feed by Topic
Recent Commits to openclaw:main
Recent Commits to openclaw:main
S
Security Affairs
PCI Perspectives
PCI Perspectives
I
Intezer
V2EX - 技术
V2EX - 技术
S
Securelist
O
OpenAI News
S
Secure Thoughts
aimingoo的专栏
aimingoo的专栏
V
Visual Studio Blog
P
Proofpoint News Feed
月光博客
月光博客
博客园 - 叶小钗
Hacker News: Ask HN
Hacker News: Ask HN
有赞技术团队
有赞技术团队
酷 壳 – CoolShell
酷 壳 – CoolShell
Stack Overflow Blog
Stack Overflow Blog
宝玉的分享
宝玉的分享
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
Google DeepMind News
Google DeepMind News
C
Cybersecurity and Infrastructure Security Agency CISA
H
Hackread – Cybersecurity News, Data Breaches, AI and More
cs.CL updates on arXiv.org
cs.CL updates on arXiv.org
Schneier on Security
Schneier on Security
N
News | PayPal Newsroom
S
Schneier on Security
T
Threatpost
G
Google Developers Blog
P
Palo Alto Networks Blog
P
Privacy & Cybersecurity Law Blog
Microsoft Azure Blog
Microsoft Azure Blog
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
C
Cyber Attacks, Cyber Crime and Cyber Security
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
P
Privacy International News Feed
博客园 - 三生石上(FineUI控件)
Help Net Security
Help Net Security
Google Online Security Blog
Google Online Security Blog
C
CXSECURITY Database RSS Feed - CXSecurity.com
D
DataBreaches.Net
Cyberwarzone
Cyberwarzone
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Webroot Blog
Webroot Blog
K
Kaspersky official blog
Security Latest
Security Latest
www.infosecurity-magazine.com
www.infosecurity-magazine.com

Consumer Insights

The ransomware negotiator who was working for the other side After years on the run, alleged Ryuk ransomware operator pleads guilty INTERPOL crackdown shows scammers shifting to social media Meta lets strangers remix your public Instagram photos with AI—here’s how to opt out Invited to a "job interview" with Netflix or OpenAI? Beware! Your Google password could be at risk Two arrested over credit card phishing - as the Netherlands is named Europe's worst for payment fraud India pauses WhatsApp username feature over security concerns Alleged teen ransomware hustler faces US charges after arrest in Finland WhatsApp usernames explained: how to reserve yours and stay safe Scammers race to cash in on Venezuelan earthquake disaster USB drives carrying China-linked malware infected Japanese military networks for nearly a year WhatsApp tests new safety prompt before you chat with strangers Social media is worth celebrating. It's also worth protecting. Polish police dismantle SIM-swap gang accused of crypto theft Operation Endgame deals fresh blow to StealC and Amadey malware networks Hacker hijacks Brazil's national alert system, sending "misanthropy" to millions of phones Cybercrime now rivals traditional crime across parts of Asia Apple's Hide My Email tweak leaves privacy fans fuming Americans lost $3.5 billion to imposter scams last year — and the scams are getting harder to spot Scammers have killed the physical Steam Gift cards Crypto investment scam sends couriers to collect victims' cash, FBI warns Maine forced to take down data breach portal after fake notices filed with authorities Privacy own-goal: World Cup blunder leaks Lionel Messi's passport details Why schools remain one of cybercriminals' favourite targets WhatsApp detects new spyware activity from Israel’s NSO Group despite court order Got a LinkedIn message from a recruiter? It might be Chinese intelligence, warn FBI and MI5 Europol cracks down on illegal streaming globally Hackers didn't hack Instagram; they just asked Meta AI FBI Warns Fans About FIFA Scams Ahead of 2026 World Cup Virtual knife, real lawsuit: Counter-Strike skin dispute ends in court As Deepfakes Spread, YouTube Makes AI Labels Harder to Miss Carnival breach exposes data of nearly 6 million people Police arrest man following hack of Ajax football club MyPillow listed on ransomware gang's leak site, but denies it has been breached FBI warns criminals impersonating IT support to breach law firms FBI warns of Kali365 phishing kit that breaks into Microsoft 365 accounts — no password required Telecom Executives Plead Guilty to Tech Support Fraud 7-Eleven data breach exposes data of 185,000 people ASIC Warns Australians About Crypto Trading Scams Google Search AI Mode brings a major overhaul Deleted Google API keys may remain active for 23 minutes Ukrainian police identify perp in $721k infostealer scheme Steam removes horror game after malware steals player data FBI: Crypto ATM Scams Keep Growing as Americans Lose Millions FBI warns students and staff that ShinyHunters may come knocking after Canvas breach Scam Centers Under Pressure as INTERPOL Makes More Arrests FBI Warns Older Adults Lost Billions to Scammers Burst Statistics WordPress flaw under attack Android 17 Will Let Users Verify Whether Their OS Is Legit Suspected Dream Market kingpin arrested after gold bars sent to his home address BitLocker zero-day exposes Windows drives as PoC goes public Apple Fixes ‘Persistent Notifications’ Flaw on Older iPhones Football Ticket Scams Are Rising Fast, Lloyds Bank Warns When ransomware gets physical: cybercriminals turn to threats of violence iPhone-to-Android Texts Are Now Encrypted (RCS Messaging) UK Water Supplier Fined Nearly £1 Million After Hackers Roamed Networks for Almost 2 Years Instagram Drops Encrypted DMs — What This Means for You New fear: Man films woman with smart glasses, seeks money to take video down ClickFix Campaign Uses Compromised WordPress Sites to Spread Vidar Stealer in Australia Inside Department 4: Russia's secret school for hackers Ubuntu’s new AI dreams attracted a very old-fashioned crypto scam on X Chrome 4GB AI model: What weights.bin does Sri Lanka makes 37 arrests as it raids another scam centre DAEMON Tools Lite breach prompts urgent update after malware-laced installer Brits Lost £102 Million to Romance Scams Last Year The Online Safety Act Is Changing the Internet for Kids World Password Day 2026 How Hackers Stole and Sold Roblox Accounts for $250,000 Before Getting Caught Four Years in Prison for Cybersecurity Pros Turned Ransomware Attackers Teenager alleged to be Scattered Spider hacker arrested in Finland, faces US extradition 276 Arrested in Crypto Scam Crackdown Popular WordPress redirect plugin found with years-old backdoor Iran-linked Handala hackers leak US Marines data, send chilling WhatsApp threats Alleged Silk Typhoon hacker extradited to the United States to face charges FTC: Social Media Scams Cost Americans $2.1 Billion in 2025 French police arrest 21-year-old "HexDex" hacker over 100 alleged data breaches iOS Flaw Exposed ‘Deleted’ Signal Messages Sony Starts Enforcing PlayStation Age Verification; UK and Ireland Are First Ransomware ‘Negotiator’ Faces 20 Years in Prison for Allegedly Betraying His Employers You’ve Got Mail and It’s Tracking Your Warship Crypto Investment Scam Costs Woman in Hong Kong Nearly $1 Million Operation PowerOFF warns 75,000 DDoS users Singer loses life savings to fake wallet downloaded from the Apple App Store AgingFly malware targets Ukraine government, hospitals 108 malicious Chrome extensions caught stealing Google and Telegram data from 20,000 users Rockstar Games confirms breach after ShinyHunters leaks stolen analytics data FBI: Cybercrime Losses Hit $21 Billion in 2025, Fueled by AI Life imprisonment for Cambodian scam compound operators - but will it make a difference? Fake Claude Code leak on GitHub spreads Vidar malware Apple Expands ‘DarkSword’ Patch to More iPhones and iPads Nigerian romance scammer jailed after being caught out by fellow fraudster Fake WhatsApp Clone Used in Spyware Campaign, Meta Warns Fake CERT-UA emails spread AGEWHEEZE in ukraine Alleged RedLine malware developer extradited to United States Iranian hackers breach FBI director's personal email, and post his CV and photos online Don't Ignore This Security Alert Apple Sent to iPhone Lock Screens Meta and YouTube Designed Addictive Platforms, Jury Finds TikTok Business phishing campaign targets advertisers Lapsus$ claims AstraZeneca breach exposes code and credentials How one man used 10,000 bots to steal $8,000,000 from music artists
The Scam That Tricks You Into Infecting Your Own Mac
Filip TRUȚĂ · 2026-03-31 · via Consumer Insights

Update to macOS Tahoe 26.4 today!

Apple’s latest macOS update came with no flashy headlines — but it did introduce a small security feature that tackles a very real and fast-growing threat.

With macOS 26.4, Apple is now warning users before they paste potentially dangerous commands into the Terminal app. On the surface, it’s a minor tweak. In practice, it directly targets one of today’s most effective social engineering techniques: ClickFix attacks.

Key takeaways:

  • Attackers are increasingly targeting macOS with social engineering tricks

  • macOS 26.4 introduces a critical layer of friction at the right moment — your Mac can now warn you before you paste dangerous commands

  • The feature targets ClickFix-style attacks that trick users into infecting their own devices

Let’s break down what’s happening — and why it matters more than it seems.

When you become the attack vector

Terminal in macOS is a command-line interface that provides text-based access to the operating system, allowing users to execute commands, run scripts, and automate tasks. It has always been a powerful tool, giving users deep control over their system. But that power comes with risk.

Unlike traditional malware infections, some modern attacks don’t simply exploit software vulnerabilities. Instead, they trick users into running malicious commands themselves.

This is where ClickFix attacks come in.

ClickFix is a growing social engineering technique that tricks you into manually executing malicious commands on your own computer through “pastejacking” – where you’re duped into copying and running a malicious script to solve a fake technical error.

These scams typically:

  • Pose as verification steps, CAPTCHA checks, or tech support fixes
  • Instruct users to copy and paste commands into Terminal
  • Deliver malware or grant attackers access — without triggering traditional defenses

Because the user willingly executes the command, many built-in protections are bypassed. And this technique is gaining traction on macOS.

Security researchers have already observed macOS-focused malware campaigns — like the Infiniti Stealer — leveraging ClickFix-style tactics to steal credentials and sensitive data.

‘Possible malware. Paste blocked’

macOS 26.4 introduces a simple but effective countermeasure: a warning prompt when users paste suspicious commands into Terminal.

When triggered, users see a message like:

Possible malware, paste blocked. Scammers often encourage pasting text into Terminal to try and harm your Mac or compromise your privacy. These instructions are commonly offered via websites, chat agents, apps, files, or a phone call.

Source: Mr. Macintosh (via MacRumors)

The system:

  • Pauses execution before the command runs
  • Alerts the user to risk
  • Allows users to cancel — or proceed if they understand the command

This measure is designed to break the attacker’s flow. ClickFix attacks rely on speed and automation — copy, paste, execute. Apple’s new prompt inserts a moment of friction, giving people a chance to reconsider before damage is done.

The warning was spotted by Redditors and X users over the past week, as reported by MacRrumors.

Hackers make you execute the threat yourself

As we note in our 2023 macOS Threat Landscape Report, threats designed to infect Macs typically require the victim to manually run an executable.

Apple's new approach might seem like a niche feature aimed at developers at first glance, but it’s not.

1. It protects non-techies

Terminal used to be a tool only advanced users touched. That’s no longer true. Today, people are frequently told to “just paste this command” in:

  • Forums
  • AI-generated responses
  • YouTube tutorials
  • Fake support chats

Many don’t fully understand what they’re running — and attackers exploit that.

2. It’s social engineering (not just malware)

Traditional security focuses on blocking malicious files. But ClickFix attacks don’t need files—they weaponize instructions. Apple’s approach reflects a broader shift in cybersecurity: protecting users from manipulation, not just malicious code.

3. It acknowledges a changing threat landscape

For years, macOS had a reputation as a safer platform. That perception is eroding. Attackers are adapting:

  • Porting techniques from Windows to macOS
  • Designing platform-specific phishing flows
  • Automating command injection via clipboard tricks

Apple’s update is a clear signal: macOS users are now squarely in the crosshairs.

The new security prompt added in macOS Tahoe 26.4 is a solid step towards protecting Mac users from malware — but it’s not a silver bullet.

  • It likely doesn’t block all malicious commands
  • Users can still click “Paste Anyway”
  • It may not appear in every scenario

In other words, user awareness still matters.

What you should do

This new protection is important. So, the first thing you want to do is update to macOS Tahoe 26.4 so you’re equipped with this new layer of security. That’s a given. Next:

1. Never paste commands you don’t understand

If you can’t explain what a command does, don’t run it.

2. Be skeptical of ‘verification’ steps

No legitimate website or service will ask you to paste commands into Terminal to prove you’re human.

3. Treat urgency as a red flag

ClickFix attacks often use countdown timers or warnings to pressure users into acting quickly.

4. Stick to trusted sources

Only follow instructions from reputable documentation—not random forums or pop-ups.

5. Always run an independent security solution on your Mac

Bitdefender Antivirus for Mac offers real-time protection against threats targeting macOS. If you accidentally end up downloading malware on your Mac, we’ll block it for you.

You may also want to read:

Apple Sends Urgent Security Alert to iPhone Lock Screens — Here’s Why You Shouldn’t Ignore It

Windows and macOS Malware Spreads via Fake “Claude Code” Google Ads

Hijacked Google Ads Push Fake 7-Zip, Notepad++ and Office Downloads to Mac Users via Evernote Pages, Bitdefender Labs Warns