Threat actors are employing a new variation of the ClickFix social engineering technique called InstallFix to convince users ...
Fake OpenClaw installers hosted in GitHub repositories and promoted by Microsoft Bing's AI-enhanced search feature instructed users to run commands that deployed information stealers and proxy malware ...
OAuth redirection is being repurposed as a phishing delivery path. Trusted authentication flows are weaponized to move users ...
Dubbed InstallFix by Push Security, the scheme inserts instructions to download malware during the Claude Code install ...