fromArs Technica
5 days agoClickFix may be the biggest security threat your family has never heard of
Another campaign, documented by Sekoia, targeted Windows users. The attackers behind it first compromise a hotel's account for Booking.com or another online travel service. Using the information stored in the compromised accounts, the attackers contact people with pending reservations, an ability that builds immediate trust with many targets, who are eager to comply with instructions, lest their stay be canceled. The site eventually presents a fake CAPTCHA notification that bears an almost identical look and feel to those required by content delivery network Cloudflare.
Information security