A critique published in Nature Wednesday calls the basic technology behind Microsoft’s “breakthrough” quantum computing chip the Majorana 1 into question. Microsoft unveiled the chip in February 2025 and said it featured a brand-new technology known as a topological qubit. Topological qubits, they said, would be the “building blocks” for their future quantum computer. Microsoft announced the next generation chip Majorana 2 at Build earlier this month.
Technology
Fake Windows update pushes malware in new ClickFix attack
NEWYou can now listen to Fox News articles!
Cybercriminals keep getting better at blending into the software you use every day.
Over the past few years, we’ve seen phishing pages that copy banking portals, fake browser alerts that claim your device is infected and “human verification” screens that push you to run commands you should never touch. The latest twist comes from the ongoing ClickFix campaign.
Instead of asking you to prove you are human, attackers now disguise themselves as a Windows update. It looks convincing enough that you might follow the instructions without thinking, which is exactly what they want.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
NEW SCAM SENDS FAKE MICROSOFT 365 LOGIN PAGES
The malware hides inside seemingly normal image files, using steganography to slip past traditional security tools. (Microsoft)
How the fake update works
Researchers noticed that ClickFix has upgraded its old trick. The campaign used to rely on human verification pages, but now you get a full-screen Windows update screen that looks almost identical to the real thing. Joe Security showed how the page displays fake progress bars, familiar update messages and a prompt that tells you to complete a critical security update.
If you are on Windows, the site tells you to open the Run box, copy something from your clipboard and paste it in. That “something” is a command that silently downloads a malware dropper. The final payload is usually an infostealer, which steals passwords, cookies and other data from your machine.
NEW EMAIL SCAM USES HIDDEN CHARACTERS TO SLIP PAST FILTERS
Fake update screens are getting harder to spot as attackers mimic Windows with near-perfect precision. (Joe Security)
The moment you paste the command, the infection chain begins. First, a file called mshta.exe reaches out to a remote server and grabs a script. To avoid detection, these URLs often use hex encoding for parts of the address and rotate their paths. The script then runs obfuscated PowerShell code filled with junk instructions to throw researchers off. Once PowerShell does its work, it decrypts a hidden .NET assembly that functions as the loader.
Why is this attack so hard to detect?
The loader hides its next stage inside what looks like a regular PNG file. ClickFix uses custom steganography, which is a technique that hides secret data inside normal-looking content. In this case, the malware sits inside the image’s pixel data. The attackers tweak color values in certain pixels, especially in the red channel, to embed pieces of shellcode. When you view the image, everything appears normal.
The script knows exactly where the hidden data sits. It extracts the pixel values, decrypts them and rebuilds the malware directly in memory. That means nothing obvious is written to disk. Security tools that rely on file scanning miss it, since the shellcode never appears as a standalone file.
Once rebuilt, the shellcode is injected into a trusted Windows process like explorer.exe. The attack uses familiar in-memory techniques such as VirtualAllocEx, WriteProcessMemory and CreateRemoteThread. Recent ClickFix activity has delivered infostealers like LummaC2 and updated versions of Rhadamanthys. These tools are built to harvest credentials and send them back to the attacker with very little noise.
Once the hidden code loads into a trusted Windows process, infostealers quietly begin harvesting your data. (Kurt “CyberGuy” Knutsson)
7 steps you can take to protect yourself from the ClickFix campaign
The best way to stay protected is to slow down for a moment and follow a few steps that cut off these attacks before they start.
1) Never run commands you didn’t ask for
If any site tells you to paste a command into Run, PowerShell or Terminal, treat it as an immediate warning sign. Real operating system updates never require you to run commands from a webpage. When you run that command, you hand full control to the attacker. If something feels off, close the page and don’t interact further.
2) Keep Windows updates inside Windows
Updates should only come from the Windows Settings app or through official system notifications. A browser tab or pop-up pretending to be a Windows update is always fake. If you see anything outside the normal update flow asking for your action, ignore it and check the real Windows Update page yourself.
3) Use a reputable antivirus
Choose a security suite that can detect both file-based and in-memory threats. Stealthy attacks like ClickFix avoid leaving obvious files for scanners to pick up. Tools with behavioral detection, sandboxing and script monitoring give you a much better chance of spotting unusual activity early.
The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.
Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.
4) Use a password manager
Password managers create strong, unique passwords for every account you use. They also autofill only on legitimate websites, which helps you catch fake login pages. If a manager refuses to fill out your credentials, take a second look at the URL before entering anything manually.
Next, see if your email has been exposed in past breaches. Our No. 1 password manager pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.
Check out the best expert-reviewed password managers of 2025 at Cyberguy.com.
5) Use a personal data removal service
Many attacks start by targeting emails and personal details already exposed online. Data removal services help shrink your digital footprint by requesting takedowns from data broker sites that collect and sell your information. They can’t erase everything, but reducing your exposure means fewer attackers have easy access to your details.
While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.
Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.
6) Check URLs before trusting anything
A convincing layout doesn’t mean it is legitimate. Always look at the domain name first. If it doesn’t match the official site or uses odd spelling or extra characters, close it. Attackers rely on the fact that people recognize a page’s design but ignore the address bar.
7) Close suspicious full-screen pages
Fake update pages often run in full-screen mode to hide the browser interface and make the page look like part of your computer. If a site suddenly goes full screen without your permission, exit with Esc or Alt+Tab. Once you’re out, scan your system and don’t return to that page.
Kurt’s key takeaway
ClickFix works because it leans on user interaction. Nothing happens unless you follow the instructions on the screen. That makes the fake Windows update page especially dangerous, because it taps into something most people trust. If you are used to Windows updates freezing your screen, you may not question a prompt that appears during the process. Cybercriminals know this. They copy trusted interfaces to lower your guard and then rely on you to run the final command. The technical tricks that follow are complex, but the starting point is simple. They need you to help them.
Do you ever copy commands from a website without thinking twice about what they do? Let us know by writing to us at Cyberguy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
The best Apple deals you can get during Prime Day
Amazon’s Prime Day is now in its second day, and whether you’re looking for a new pair of wireless earbuds or a smartwatch, there’s a good chance you’ll find a discount. The Apple Watch Series 11 has already dropped to a new low price, while the AirPods Pro 3 are discounted to $179. With Tim Cook warning that price hikes are coming, now may be the moment if you’ve been eyeing one of the company’s devices.
Below are the best Apple deals currently available. Some are exclusive to Prime Day, while others are simply great discounts we think are worth highlighting. We’ll continue updating this guide throughout Prime Day, highlighting more deals as they become available.
Earbud and headphone deals
Update, June 24th: Adjusted prices and availability, and added deals for Apple’s MagSafe Charger as well as the Apple Magic Keyboard.
Technology
A new paper argues Microsoft exaggerated its quantum claims a year ago
But in a peer-reviewed article, Henry Legg, a physicist at the University of St Andrews, reanalyzed Microsoft’s data on their device and argued that the company’s researchers did not conclusively demonstrate a working topological qubit in the first place.
Theory predicts that the electrons in this wire behave in a collective pattern known as a Majorana particle, for which the chip is named.
Proponents of quantum computing predict that the technology’s computational abilities will advance new medicine discovery, encryption, and machine learning. Companies like Google and IBM have already demonstrated more advanced machines than Majorana 1 or 2, although presently, no one has conclusively gotten any quantum computer to perform anything useful. But Microsoft claimed that Majorana 1, and subsequently Majorana 2, paved their path toward a practical quantum computer.
Microsoft’s design, unique among quantum computing companies, involves a tiny wire, thinner than a human hair, made of the semiconductor indium arsenide stuck to a superconductor. Theory predicts that the electrons in this wire behave in a collective pattern known as a Majorana particle, for which the chip is named. Microsoft wants to encode information in the properties of the Majorana particle. (A topological qubit is to a Majorana particle as a transistor is to silicon.)
Proponents of the Majorana particle think it is promising qubit material because theory predicts that when formed into topological qubits, the Majorana should compute with fewer errors than competing materials, such as superconducting circuits pursued by IBM. This suggests that ultimately, fewer topological qubits are needed to scale up to a useful quantum computer.
That is, if Microsoft has actually made a Majorana particle. “They haven’t convincingly shown that they have Majoranas,” Legg told The Verge. “You can’t make a qubit if you don’t have the Majoranas.”
In Legg’s critique, he writes that what Microsoft claims as a signature of the Majorana particle could actually be from the formation of quantum dots, which are electron-containing structures, in the device. Quantum dots would not be useful for building the quantum computer. He also writes that Microsoft cherry-picked their data.
“You can’t make a qubit if you don’t have the Majoranas.”
Microsoft’s team published a rebuttal in Nature disputing Legg’s interpretation of their data. Legg’s critique “does not constitute a substantial scientific challenge to our findings,” the Microsoft team wrote. Legg has not “proposed an alternative model that fits all of our data,” Chetan Nayak, a physicist leading Microsoft’s quantum team, told The Verge.
Legg first posted his critique on the online physics repository arXiv on February 26, 2025, within a week of Microsoft’s Majorana 1 announcement. It took a year for Nature to conduct a peer review and publish his article.
Meanwhile, on June 2, Microsoft announced a new chip, the Majorana 2, featuring what they claimed was the next generation of their topological qubits. The company says they can build a “scalable quantum computer” by 2029. “We 100% stand behind our results,” Nayak told The Verge. “We stand by our roadmap. We stand behind our long-standing commitment to scientific rigor and dialogue.”
Legg says the company’s characterization of Majorana 2, which Microsoft wrote in a non-peer reviewed manuscript, suffers from similar problems he pointed out a year ago. “Nothing in this [manuscript] resolves the fundamental issues that so many scientists have with this company’s previous claims,” Legg told The Verge.
Technology
FCC phone ID plan could end burner phones
NEWYou can now listen to Fox News articles!
Buying a phone without tying it directly to your identity could get much harder. The Federal Communications Commission (FCC) is considering tougher “know your customer” rules for voice providers.
The proposal would push phone companies to collect and keep more personal information before giving many new or renewing customers access to service. That could include your name, physical address, government-issued identification number and an alternate phone number.
The FCC says the goal is to make life harder for scammers, robocallers and criminals who abuse phone networks. That sounds reasonable at first. Nobody wants more fake bank calls, Medicare scam texts or urgent messages from crooks pretending to be family members. Yet this proposal raises a much bigger question. How much personal privacy should we give up to fight scam calls?
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
GOOGLE SEARCH LED TO A COSTLY SCAM CALL
The FCC is considering tougher phone identity checks that could require more personal information before service begins. (Kurt “CyberGuy” Knutsson)
What the FCC phone ID proposal would require
The FCC phone ID proposal focuses on identity checks for originating voice providers. Those are the companies that allow calls to enter the phone network. Right now, the FCC already expects providers to take steps to know their customers and stop illegal calls. The new proposal would make those duties more specific. The FCC is asking whether providers should be required to obtain and retain certain customer information before granting service. At a minimum, that could include:
- Name
- Physical address
- Government-issued identification number
- Alternate telephone number
The FCC is also asking how these rules should apply to “new and renewing” customers. That phrase is important. A narrow version could focus on people opening new accounts. A broader version could reach people who switch plans or renew service with a current provider. For high-volume customers, including some business and foreign customers, the FCC is also asking whether providers should collect more information. That could include the intended use of the service and the IP address used to place calls, when applicable.
The FCC is also asking whether providers should retain KYC records for four years after the customer relationship ends, tied to the statute of limitations for certain illegal calling violations.
Why the FCC wants stronger phone identity checks
The FCC says scammers hide behind phone calls and texts to rip people off, then disappear before anyone can track them down. Anyone with a phone knows this problem has gotten out of hand. Most of us now look at an unknown number and assume trouble before we even answer.
The agency believes tougher identity checks could make it harder for bad actors to get onto phone networks in the first place. It also says better customer records could help investigators connect the dots after a scam call or text causes harm.
Here is where the proposal gets bigger. The FCC also asks whether stronger records could help law enforcement investigate crimes that go beyond scam calls, including national security threats and abuse in text messaging networks. So while robocalls are the headline, this proposal reaches much further. It could move phone service closer to an identity-check model that goes well beyond robocalls.
Why burner phones could become harder to buy
The FCC proposal does not specifically say it will ban burner phones. Still, the practical impact could be significant. A burner phone usually refers to a prepaid phone or phone line with no clear identity link at the point of purchase. TV shows often connect burner phones with criminals. Real life is more complicated.
People use prepaid or private phone lines for plenty of lawful reasons. A domestic abuse survivor may need a safe phone that an abuser cannot easily trace through shared accounts. A journalist may need to protect a source. A whistleblower may need to call without exposing a personal number. Someone without a stable address may rely on prepaid service because it is easier to obtain.
If phone companies must collect a government ID number and physical address before service begins, anonymous or lightly identified prepaid service could become far harder to access. That is why privacy advocates see this as more than a robocall rule. They see it as a potential shift in how Americans get basic phone service.
HOW SCAMMERS BUILD A PROFILE ON YOU USING DATA BROKERS
Prepaid phones could face closer scrutiny if the FCC moves ahead with stricter “know your customer” rules. (Photographer: Brent Lewin/Bloomberg via Getty Images)
The FCC proposal could affect prepaid phone plans
Prepaid phones are a big part of this story. Some people use them to save money. Others use them because they want more control over what they spend or because a traditional phone plan creates hurdles they would rather avoid.
The FCC is now asking whether prepaid and postpaid customers should face different identity checks. That question is important because prepaid service has long been one of the easiest ways to get a working phone without a lengthy signup process.
A strict final rule could make prepaid service feel a lot more like opening a bank account. For some people, that may only mean another form to fill out. For others, especially someone trying to stay safe or keep a phone line private, it could be a much bigger deal.
The privacy risk behind a phone ID database
The most obvious concern is privacy. The quieter concern is cybersecurity. Phone companies already hold sensitive customer information. Adding government ID numbers, physical addresses and alternate phone numbers would make those records even more valuable to hackers.
If a telecom database gets breached, criminals may use stolen customer data for phishing, identity theft, SIM-swap attacks or stalking. A rule meant to stop scammers could create a richer target for scammers to steal. That to me is scary.
The FCC does ask how providers should protect customer information and how long records should be retained. Those are important questions. Still, better security rules would need real teeth. Sensitive data becomes a liability the moment it gets collected.
What “physical address” could mean for phone customers
The FCC is also asking whether P.O. boxes, shared office locations and similar addresses should count as a customer’s physical address. That detail could create real problems.
Some people do not have a traditional home address. Others may avoid sharing one because of safety concerns. A domestic abuse survivor may use a mailing address that keeps a home location private. A small business owner may use a shared office or mail service. If the final rule limits what counts as a valid address, some people could face a harder path to phone service. That may sound like a compliance detail. For someone trying to stay safe, it could matter a lot.
TOP 10 ROBOCALL HOT SPOTS IN AMERICA
Privacy advocates warn that stronger identity checks could make private phone access harder for people with legitimate safety concerns. (Kurt “CyberGuy” Knutsson)
What happens next with the FCC phone ID proposal
The FCC is taking public comments on the proposal through June 25, 2026. Reply comments are due July 27, 2026. After that, the agency can review feedback from phone companies, law enforcement, privacy groups, consumer advocates and the public.
The final rule could change. The FCC could narrow the requirements, add privacy safeguards, create exceptions or revise major parts of the proposal. For now, this is one to watch closely.
We reached out to the FCC for comment, but did not hear back before our deadline.
How to reduce scam calls and texts now
You do not need to wait for a new FCC rule to protect yourself.
1) Let unknown calls go to voicemail
Do not feel pressured to answer every unknown number. A real caller can leave a message. A scammer wants you on the line fast, before you have a chance to slow down and think.
2) Turn on phone spam protections
On iPhone, go to Settings, tap Apps, scroll down and tap Phone, then go to the unknown caller settings. Choose Silence to send calls from unsaved numbers to voicemail, or choose Ask Reason for Calling if you want unsaved callers to provide more information before your iPhone rings. You can also look under Call Filtering and toggle on Unknown Callers and Spam.
On many Samsung phones, open the Phone app, tap the three dots, tap Settings, tap Caller ID and spam protection and turn it on. Then, scroll down and make sure Block all spam and scam calls is toggled on. Settings may vary depending on your phone model.
3) Avoid links in unexpected texts
Go directly to the company’s app or website instead. That habit can help stop fake toll texts, bank scams and delivery alerts.
4) Reduce the personal info scammers can use against you
Scammers often sound convincing because they already know something about you. That information can come from people-search sites, data brokers, old breaches or public records. Consider using a data removal service to reduce how much of your personal information is floating around online. Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com
5) Block and report suspicious messages
Do not just delete scam texts. On iPhone, open Messages. If you have not opened the message, swipe left on it, tap the Delete button, then tap Delete and Report Spam. If you have already opened it, tap Report Spam at the bottom of the message, then tap Delete and Report Spam. To block the sender, open the conversation, tap the sender’s icon at the top, tap Info, scroll down and tap Block Contact. Apple says reporting spam does not block the sender. Settings and carrier support may vary.
On many Samsung Galaxy phones using Google Messages, open the message, tap the three dots and choose Block and report spam, if requested confirm your decision by tapping Yes. If you use Samsung Messages, touch and hold the conversation, tap More, then tap Block. Settings may vary depending on your phone model and messaging app.
6) Use antivirus software and a password manager
Strong antivirus software can help block phishing links and malicious websites before they cause damage. A password manager can also help you avoid reusing passwords if a scammer tricks you into entering login details on a fake page. Get my picks for the best 2026 antivirus protection winners for your Windows, Mac, Android & iOS devices at Cyberguy.com
7) Turn on account alerts
Turn on bank, credit card and phone carrier alerts so you know quickly if someone tries to make a charge, move money or change your account. Fast alerts can help you stop damage before it spreads.
Watch the CyberGuy Live replay: Lock Down Your Phone in 30 Minutes
Your phone holds your email, passwords, photos, banking apps and personal data. In this free CyberGuy Live replay, Kurt the CyberGuy walks you step by step through simple phone security fixes you can do at your own pace. You’ll learn how to improve your privacy settings, spot the latest phone scams, use trusted security tools and walk away with a simple checklist to stay protected. Watch the replay and get our checklist here: CyberGuyLive.com
Kurt’s key takeaways
The FCC wants to stop scammers before they ever get onto the phone network. I get that. Scam calls and texts are out of control, and they have cost too many people real money. At the same time, the way the FCC is looking at this raises a real privacy concern. Asking phone companies to collect a government ID number, physical address and alternate phone number could change what it takes to get basic phone service in America. The FCC believes stronger customer records could help investigators track scammers after illegal calls happen. The question is whether scammers would still find ways around the rules while people with legitimate privacy needs face new hurdles. A domestic abuse survivor, journalist, whistleblower or person without a stable address may have a much harder time getting a private phone line. That is why any scam-fighting plan needs strong privacy safeguards. Before asking phone customers to hand over more personal information, the FCC should show how this data would reduce scams and how it would be protected.
Would you give your phone carrier a government ID number and physical address if it meant fewer scam calls, or does that go too far? Let us know by writing to us at CyberGuy.com.Cyberguy.com
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
- Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox.
- For simple, real-world ways to spot scams early and stay protected, visit CyberGuy.com – trusted by millions who watch CyberGuy on TV daily.
- Plus, you’ll get instant access to my Ultimate Scam Survival Guide free when you join.
Copyright 2026 CyberGuy.com. All rights reserved.
-
News19 minutes ago
Federal judge halts Trump’s election executive order seeking to create a federal voter list
-
Los Angeles, Ca2 hours agoBoyle Heights warehouse cleanup begins as crews face 85 million pounds of spoiled food
-
Detroit, MI2 hours agoWould Detroit Lions Salary Cap Be Wrecked If Terrion Arnold Gets Cut?
-
San Francisco, CA2 hours agoTwo more Presidio Heights homes reach $10M range as luxury supply dwindles
-
Dallas, TX2 hours agoOne Dallas Cowboys Contract That Will Age Poorly in 2026
-
Miami, FL2 hours agoLive updates: Today’s South Florida News
-
Boston, MA2 hours agoA federal judge in Boston has blocked parts of Trump’s order to limit voting by mail
-
Denver, CO2 hours ago
Denver Transplant Games sets Guinness World Record for most living donors, recipients in one place at one time