logo

ClickFix Attack Tricks AI Summaries Into Pushing Malware

ID: ae4910bf-8a0c-5153-a3dc-150e530bceda

STIX ID: report--ae4910bf-8a0c-5153-a3dc-150e530bceda

Feed Name: Dark Reading

Threat Score
40/100

Date Published: 2025-08-25

Date Updated: 2026-05-05

Author: Alexander Culafi

...
...

CloudSEK demonstrated a proof-of-concept ClickFix attack that uses hidden HTML/CSS tricks and repeated payloads to manipulate AI-generated summaries into displaying malicious Windows Run/PowerShell commands that could lead to ransomware infections; defenders are advised to normalize/sanitize content before summarization, implement payload detection, and enforce enterprise AI policies.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.