<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/"><channel><title>Cms-Compromise on ZX Cloud Security</title><link>https://zxcloudsecurity.co.uk/tags/cms-compromise/</link><description>Recent content in Cms-Compromise on ZX Cloud Security</description><generator>Hugo</generator><language>en-GB</language><lastBuildDate>Sun, 22 Jun 2025 09:56:00 +0000</lastBuildDate><atom:link href="https://zxcloudsecurity.co.uk/tags/cms-compromise/index.xml" rel="self" type="application/rss+xml"/><item><title>Gizmodo ClickFix Attack: Windows Users Hit by Trojan</title><link>https://zxcloudsecurity.co.uk/posts/gizmodo-clickfix-malware-account-compromise-windows-trojan/</link><pubDate>Mon, 22 Jun 2026 09:56:00 +0000</pubDate><guid>https://zxcloudsecurity.co.uk/posts/gizmodo-clickfix-malware-account-compromise-windows-trojan/</guid><description>Gizmodo was compromised to serve ClickFix malware prompts targeting Windows users with trojan malware. Here&amp;#39;s what security teams need to know.</description><content:encoded><![CDATA[<p>🟠 <strong>High</strong>  |  <strong>Source:</strong> <a href="https://www.theregister.com/security/2026/06/22/gizmodo-readers-hit-with-clickfix-malware-prompts-after-account-compromise/5259226">The Register — Security</a></p>
<hr>
<p>Gizmodo&rsquo;s website was compromised and used to serve ClickFix social engineering prompts, tricking Windows users into running malicious commands that could install trojan malware. Mac users were largely unaffected. The incident highlights how trusted media brands can become vectors for malware distribution following an account or CMS compromise.</p>
<blockquote>
<p><strong>Security Architect&rsquo;s Take:</strong> Review your organisation&rsquo;s acceptable use and endpoint protection policies to ensure that browser-based social engineering attacks like ClickFix — which instruct users to paste commands into PowerShell or Run dialogs — are mitigated through application control and PowerShell constrained language mode. Consider alerting your security awareness programme to this specific technique, as it bypasses many traditional content filters.</p>
</blockquote>
<p><strong>Original advisory:</strong> <a href="https://www.theregister.com/security/2026/06/22/gizmodo-readers-hit-with-clickfix-malware-prompts-after-account-compromise/5259226">Gizmodo readers hit with ClickFix malware prompts after account compromise</a></p>
]]></content:encoded></item></channel></rss>