惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

F
Full Disclosure
Recorded Future
Recorded Future
T
Tenable Blog
S
Securelist
C
CERT Recently Published Vulnerability Notes
T
Threatpost
S
Schneier on Security
A
Arctic Wolf
The Hacker News
The Hacker News
C
CXSECURITY Database RSS Feed - CXSecurity.com
Know Your Adversary
Know Your Adversary
P
Privacy International News Feed
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
The Register - Security
The Register - Security
Cisco Talos Blog
Cisco Talos Blog
AWS News Blog
AWS News Blog
K
Kaspersky official blog
T
True Tiger Recordings
T
Threat Research - Cisco Blogs
V
Vulnerabilities – Threatpost
P
Palo Alto Networks Blog
T
The Exploit Database - CXSecurity.com
小众软件
小众软件
B
Blog
Cyber Security Advisories - MS-ISAC
Cyber Security Advisories - MS-ISAC
Microsoft Azure Blog
Microsoft Azure Blog
Cyberwarzone
Cyberwarzone
C
Cybersecurity and Infrastructure Security Agency CISA
T
Tor Project blog
Spread Privacy
Spread Privacy
Malwarebytes
Malwarebytes
P
Proofpoint News Feed
F
Fox-IT International blog
F
Fortinet All Blogs
P
Privacy & Cybersecurity Law Blog
G
GRAHAM CLULEY
量子位
Latest news
Latest news
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
Project Zero
Project Zero
T
Tailwind CSS Blog
N
Netflix TechBlog - Medium
Martin Fowler
Martin Fowler
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
IntelliJ IDEA : IntelliJ IDEA – the Leading IDE for Professional Development in Java and Kotlin | The JetBrains Blog
I
Intezer
博客园_首页
腾讯CDC
H
Hackread – Cybersecurity News, Data Breaches, AI and More
D
Darknet – Hacking Tools, Hacker News & Cyber Security

Latest from TechRadar

What is the release date for Hacks season 5 episode 10 on HBO Max? Apple’s Fitbit Air-rivaling AI health coach is delayed, new report claims, and that’s bad news for fitness… ‘Social media should be treated like tobacco’: health experts say the internet is just as bad as smoking for under-16s as UK government edges closer to introducing ban ‘Spotify Connect destroys Apple Music at this specific thing’: Apple Music fans still can’t believe the platform is behind on continuity features — but that’s not the only thing that’s getting under their skin Absolute Anonymity: This VPN allows cash payments and costs the same every month, forever Custom drone makers hit 453mph to (unofficially) break the record for fastest drone on earth — and hand-made sawtooth carbon fiber propellors made all the difference Diablo 4: Lord of Hatred is one of the best expansions I've ever played — here's why Warhorse promises that Middle-earth RPG is a 'passion project' that 'will be a living world' with a… 'Technology is never neutral': the Pope says the quiet part out loud, and it's time we accept that AI and tech's failures — and dangers — are human-made 'I'm delighted to ⁠be wrong': Sam Altman says AI won't lead to a 'jobs apocalypse' - but admits he was 'pretty wrong' on the social and economic implications it is having I spent a long weekend with the GoPro Mission 1 Pro — it survived heat, sea, sand and a couple of drops, but you need to respect its limits The UK's online safety consultation ends today — here's what it could mean for VPNs Leaked Samsung Galaxy S26 FE case images point to the most minor design change — and Samsung fans aren't… Surfshark launches new ‘Antiscam Hub’ for iOS users, rolling 5 security features into a single in-app… The Currys bank holiday sale isn't over yet — save up to 40% with 21 best deals on TVs, appliances, laptops,… Trump Mobile probing second major data leak — additional breach allegedly exposes personal info of 27,000… Fans mourn what would have been GTA 6's launch today — 'My girl surprised me with $100 today and thought… What to look for in an enterprise-grade smart dash cam The latest MacBook Air has just got a surprise new record-low price at Amazon — our favorite laptop now rivals the… NordVPN wins crucial legal battle in Spain over La Liga piracy fines Marketing doesn’t have a data problem: it has an action problem 9 portable air conditioners that are still in stock after this weekend's sweat-fest — plus our top tips on how to choose and use one Reported ransomware incidents are just the tip of the iceberg Dutton Ranch fans are already hoping one unhinged character 'doesn't survive' first season of Taylor Sheridan's Yellowstone spinoff series — but for the 'dumbest reason' 'You can really tell how long a game has been in development' — 007 First Light features a cameo of an internet star who went viral years ago Could AI-powered dash cams save businesses millions in legal fees? Observability was built for humans. AI agents need something different The Pope just warned AI could create ‘new forms of dehumanization’ — and his message feels aimed straight at Big Tech Ghost CMS flaw hijacked to target hundreds of websites with ClickFix attacks — here's how to stay safe 'It's something we've never done before': Logitech's newest flagship mouse and keyboard comes… What is the release date for The Four Seasons season 2 on Netflix? 007 First Light is the closest I’ll ever come to feeling like I'm in a Bond movie — it’s a blockbuster game that’s equal parts spy film and action shooter I tested the Geekom A9 Max 2026 Edition — and discovered a powerful AI mini PC with workstation-level performance Adorama's Memorial Day sale is ending soon — don't miss these record-low prices on the Nikon Z6 III, Sony a7CR, Canon R5 Mark II, and much more Arkane devs say the studio almost made Thief 4 and a Blade Runner game before it made Dishonored — 'We were both so excited. Blade Runner and Thief, two of our favourite things of all time' 'Somehow worse than I could ever have imagined': the new Ferrari Luce EV is getting a brutal reception, but legendary Apple designer Jony Ive has defended his choices — and there's one key decision most people agree with AI-generated threats are hitting businesses harder than ever - do you know what to look out for? The best Nintendo Switch 2 controllers: the handheld hybrids top gamepads, all tested and reviewed by us Microsoft promised it would scale back on AI visibility, but Copilot is now back to its original and invasive sidebar design Apple is introducing useful accessibility features in tvOS 27 for Apple TV 4K that will appeal to everyone, including larger text and auto-generated subtitles — but some major streaming apps don't use Apple's own app tech that enables them Is this the Honey scandal all over again? Motorola phones caught adding affiliate codes to Amazon orders Next boss says 'dramatic' fall in entry-level roles could cause job market chaos — Lord Wolfson says fall highlights 'the crisis is in youth unemployment at the moment' Why health AI needs a new approach, not just smarter algorithms Sennheiser finally launches the successor to its ultra-popular 5-star Momentum wireless headphones, and adds in great new features including Dolby Atmos — Sony and Bose have some hot competition here How .BRANDs improve domain security and user trust – even in an AI world 'ChatGPT kind of sucked' — Former Assassin's Creed director says he used AI to help him learn to… Are cyber pros fooling themselves with skills development? What is the release date for Rivals season 2 episode 5 on Hulu and Disney+? I gamed with MSI's new 4K QD-OLED monitor and it was the eye-popping HDR experience I've been waiting for 'Downtime is inevitable; prolonged disruption is not': Unplanned downtime is now costing businesses billions…
Kash Patel的'BasedApparel'网站显然在托管ClickFix恶意软件
Sead Fadilpa · 2026-05-27 · via Latest from TechRadar
Based Apparel
(图片来源:Future)

  • 研究人员发现一个名为 Based Apparel 的网站正在传播伪装成 Cloudflare 验证的 macOS ClickFix 信息窃取器
  • 受害者被诱骗在终端中粘贴恶意 Applescript 命令,VirusTotal 将该恶意软件标记为通用木马/信息窃取器
  • 该网站基于WordPress/WooCommerce和Ghost CMS构建,在披露后被下线,将此次事件与正在进行的ClickFix活动中对Ghost CMS的广泛利用联系起来

美国在线服装公司Based Apparel,销售爱国主义、保守和自由言论主题的商品,似乎被入侵并用于通过ClickFix技术提供恶意软件——但仅针对macOS用户。

一位使用别名“debbie”的研究人员向公众透露了她的发现。PC Mag(PC杂志),在分享视频证据到X之前,她表示在网上读到Based Apparel是由FBI局长卡什·帕特尔共同创立的,因此决定仔细看看。

“点击修复攻击在我浏览时突然出现了,”黛比在邮件中说。“我快速查看了一下,它就是一个经典的窃信者,用base64(二进制到文本编码)包装了两次。虽然它用Applescript编写,但这很有趣。”

受害者被要求在一个看似来自 Cloudflare 的验证码页面上验证他们是人类。这个冒充 Cloudflare 的网站会告诉受害者检测到“异常网络流量”,并要求受害者通过打开终端并粘贴页面上共享的命令来确认他们是人类。

将信息窃取器在 VirusTotal 上运行,PC Mag 被发现被 27 个杀毒引擎标记为木马和情报窃取器,这意味着它是一种通用的 恶意软件,而不是针对特定攻击的自定义解决方案.

Based Apparel 尚未评论,但该网站目前离线。在新闻发布时,该网站显示一条“我们很快就会回来”的消息,称公司正在进行“改进”。

该网站似乎使用两个内容管理系统构建——WordPress(配合WooCommerce实现商店功能),以及Ghost CMS(用于独立的新闻子域名)。

订阅TechRadar Pro新闻简报,获取您的企业成功所需的所有顶级新闻、观点、功能和指导!

今天早些时候,我们报道了Ghost CMS中的一个严重漏洞 于2026年2月被修补,也被用于针对700多个域名发起ClickFix攻击.


Best antivirus software header

Google logo on a black background next to text reading 'Click to follow TechRadar'

关注TechRadar在Google新闻上 将我们添加为首选信息源 以便在您的信息流中获取我们的专家新闻、评测和观点。


Sead 是一位驻在波斯尼亚和黑塞哥维那萨拉热窝的资深自由记者。他撰写关于 IT(云、物联网、5G、VPN)和网络安全(勒索软件、数据泄露、法律法规)的内容。在他的职业生涯中,超过十年,他为众多媒体撰写文章,包括 Al Jazeera Balkans。他还为 Represent Communications 担任过几个内容写作模块。