惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
Martin Fowler
Martin Fowler
Last Week in AI
Last Week in AI
罗磊的独立博客
阮一峰的网络日志
阮一峰的网络日志
博客园 - 【当耐特】
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
博客园 - 三生石上(FineUI控件)
S
SegmentFault 最新的问题
V
Visual Studio Blog
Hugging Face - Blog
Hugging Face - Blog
雷峰网
雷峰网
博客园_首页
人人都是产品经理
人人都是产品经理
量子位
美团技术团队
The Cloudflare Blog
小众软件
小众软件
WordPress大学
WordPress大学
有赞技术团队
有赞技术团队
M
MIT News - Artificial intelligence
Microsoft Security Blog
Microsoft Security Blog
D
DataBreaches.Net
博客园 - Franky

9to5Mac

Apple permanently closing three US stores, here’s when [Updated] Apple Arcade just added 4 new ad-free games with these titles now available At least for now, Liquid Glass in Pixelmator Pro remains a Creator Studio exclusive Apple @ Work: How to add an existing Mac to Apple Business Manager without wiping it Hands-on: SkyDex turns your daily weather check into a Pokémon adventure App Store fight continues as Apple and Epic clash over court-ordered stay OpenAI says to update Mac apps including ChatGPT and Codex as security precaution Apple TV in-person ‘experience’ coming later this month in LA New iPhone Fold leaks cover ‘Ultra’ name, launch timing, more Report: Apple tops global smartphone market for first time in Q1 as overall shipments drop Car Keys in Apple Wallet coming soon to major new vehicle brand Apple previews AI, accessibility, and AirPods Pro 3 research for CHI 2026 April 10, 2026 – Apple Store closures, more VSCO report explores how photographers perceive, adopt, and actually use AI XChat, X’s standalone messaging app, launching soon with these features Apple TV has three shows with finales this week, here’s what’s ending iOS 26.4 adds setting to let you change new Liquid Glass effect Hands-on: Satechi’s 3-in-1 Qi2 charger brings 25W of power with a clean Apple aesthetic [Video] iOS 27 adding new ‘Siri’ app to Home Screen: Here are the rumored features Deals: All 15-inch M5 MacBook Air models $150 off, Series 11 $99 off, Nomad leather iPhone 17 cases, more Amazon launches ‘Prime Video Ultra’ with new features, higher price How the Mac changed the way I clear mental clutter YouTube Premium is getting a US price hike of up to $4/month Tribit StormBox Micro 3: My favorite travel speaker just got better and cheaper FBI used iPhone notification data to retrieve deleted Signal messages Adobe’s low-processing camera app expands support to select iPads and the iPhone 17e New Apple TV movie starring Keanu Reeves now available to stream Apple collector showcases 50 years of Mac startup sounds [Video] WhatsApp is bringing Status updates to the top of the Chats tab iOS 26’s Messages app got a big upgrade for an essential feature
Security Bite: ClickFix malware authors already bypassing...
Arin Waichul · 2026-04-19 · via 9to5Mac

9to5Mac Security Bite is exclusively brought to you by Mosyle, the only Apple Unified Platform. Making Apple devices work-ready and enterprise-safe is all we do. Our unique integrated approach to management and security combines state-of-the-art Apple-specific security solutions for fully automated Hardening & Compliance, Next Generation EDR, AI-powered Zero Trust, and exclusive Privilege Management with the most powerful and modern Apple MDM on the market. The result is a totally automated Apple Unified Platform currently trusted by over 45,000 organizations to make millions of Apple devices work-ready with no effort and at an affordable cost. Request your EXTENDED TRIAL today and understand why Mosyle is everything you need to work with Apple.


As you may know, a couple weeks ago on Security Bite I was raving about Apple’s new warning prompt in Terminal that appears when a user pastes potentially malicious commands. The security feature was bundled into the public release of macOS Tahoe 26.4 to further disrupt ClickFix attacks, which are now the leading delivery mechanism for malware on Mac.

However, it now appears malware authors are already deploying workarounds.

While the payload it drops is almost always an infostealer or trojan like Atomic Stealer, ClickFix itself isn’t a malware family but a delivery technique that largely relies on social engineering. It typically works by tricking an unsuspecting user into pasting malicious code into Terminal and running it.

Its soaring popularity came in 2025 after Apple released macOS Sequoia, which took a proactive step to help keep Joe Shmoes from executing malware on their Macs. Users on Sequoia could no longer right-click to override Gatekeeper and open software that isn’t signed or notarized by Apple. They now had to go into Settings, then Privacy, and “review security information” before being able to run it. The additional steps and hassle are a far cry from the ease malware authors were used to.

Fake DMG installers took a big hit after that, but ClickFix since emerged because it’s cheap, fast, and still bypasses Gatekeeper without needing to obtain a signing certificate.

Now in a recent blog post from Jamf Threat Labs, its security researchers detail a new ClickFix variant that sidesteps Terminal with Apple’s new protections entirely.

Instead of pushing users to paste a command into Terminal, one example from Jamf includes a fake Apple-themed webpage (spoofed as a “Reclaim disk space on your Mac” page) that features an “Execute” button. Clicking it fires an applescript:// URL scheme in the browser, which prompts the user to open Script Editor with a pre-filled script already loaded. One more click and it runs.

Fake Apple webpage with “Execute” button to launch  Script Editor. Image via Jamf.
Prompt to open Script Editor. Image via Jamf.

Because the command never touches Terminal, the new paste warning in macOS Tahoe 26.4 never gets a chance to fire. On 26.4, Script Editor does throw its own “unidentified developer” prompt before saving the script, but if the user clicks through it, the script executes, pulls down an obfuscated curl command, and drops the latest variant of something like Atomic Stealer onto the Mac.

And so goes the never-ending tug-of-war between Apple and malware authors…

Follow Arin Waichulis: LinkedIn, Threads, X


Subscribe to the 9to5Mac Security Bite Podcast for biweekly deep dives and interviews with leading Apple security researchers and experts:

Add 9to5Mac as a preferred source on Google Add 9to5Mac as a preferred source on Google

FTC: We use income earning auto affiliate links. More.