Technology
Fake Windows update pushes malware in new ClickFix attack
NEWYou can now listen to Fox News articles!
Cybercriminals keep getting better at blending into the software you use every day.
Over the past few years, we’ve seen phishing pages that copy banking portals, fake browser alerts that claim your device is infected and “human verification” screens that push you to run commands you should never touch. The latest twist comes from the ongoing ClickFix campaign.
Instead of asking you to prove you are human, attackers now disguise themselves as a Windows update. It looks convincing enough that you might follow the instructions without thinking, which is exactly what they want.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
NEW SCAM SENDS FAKE MICROSOFT 365 LOGIN PAGES
The malware hides inside seemingly normal image files, using steganography to slip past traditional security tools. (Microsoft)
How the fake update works
Researchers noticed that ClickFix has upgraded its old trick. The campaign used to rely on human verification pages, but now you get a full-screen Windows update screen that looks almost identical to the real thing. Joe Security showed how the page displays fake progress bars, familiar update messages and a prompt that tells you to complete a critical security update.
If you are on Windows, the site tells you to open the Run box, copy something from your clipboard and paste it in. That “something” is a command that silently downloads a malware dropper. The final payload is usually an infostealer, which steals passwords, cookies and other data from your machine.
NEW EMAIL SCAM USES HIDDEN CHARACTERS TO SLIP PAST FILTERS
Fake update screens are getting harder to spot as attackers mimic Windows with near-perfect precision. (Joe Security)
The moment you paste the command, the infection chain begins. First, a file called mshta.exe reaches out to a remote server and grabs a script. To avoid detection, these URLs often use hex encoding for parts of the address and rotate their paths. The script then runs obfuscated PowerShell code filled with junk instructions to throw researchers off. Once PowerShell does its work, it decrypts a hidden .NET assembly that functions as the loader.
Why is this attack so hard to detect?
The loader hides its next stage inside what looks like a regular PNG file. ClickFix uses custom steganography, which is a technique that hides secret data inside normal-looking content. In this case, the malware sits inside the image’s pixel data. The attackers tweak color values in certain pixels, especially in the red channel, to embed pieces of shellcode. When you view the image, everything appears normal.
The script knows exactly where the hidden data sits. It extracts the pixel values, decrypts them and rebuilds the malware directly in memory. That means nothing obvious is written to disk. Security tools that rely on file scanning miss it, since the shellcode never appears as a standalone file.
Once rebuilt, the shellcode is injected into a trusted Windows process like explorer.exe. The attack uses familiar in-memory techniques such as VirtualAllocEx, WriteProcessMemory and CreateRemoteThread. Recent ClickFix activity has delivered infostealers like LummaC2 and updated versions of Rhadamanthys. These tools are built to harvest credentials and send them back to the attacker with very little noise.
Once the hidden code loads into a trusted Windows process, infostealers quietly begin harvesting your data. (Kurt “CyberGuy” Knutsson)
7 steps you can take to protect yourself from the ClickFix campaign
The best way to stay protected is to slow down for a moment and follow a few steps that cut off these attacks before they start.
1) Never run commands you didn’t ask for
If any site tells you to paste a command into Run, PowerShell or Terminal, treat it as an immediate warning sign. Real operating system updates never require you to run commands from a webpage. When you run that command, you hand full control to the attacker. If something feels off, close the page and don’t interact further.
2) Keep Windows updates inside Windows
Updates should only come from the Windows Settings app or through official system notifications. A browser tab or pop-up pretending to be a Windows update is always fake. If you see anything outside the normal update flow asking for your action, ignore it and check the real Windows Update page yourself.
3) Use a reputable antivirus
Choose a security suite that can detect both file-based and in-memory threats. Stealthy attacks like ClickFix avoid leaving obvious files for scanners to pick up. Tools with behavioral detection, sandboxing and script monitoring give you a much better chance of spotting unusual activity early.
The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.
Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.
4) Use a password manager
Password managers create strong, unique passwords for every account you use. They also autofill only on legitimate websites, which helps you catch fake login pages. If a manager refuses to fill out your credentials, take a second look at the URL before entering anything manually.
Next, see if your email has been exposed in past breaches. Our No. 1 password manager pick includes a built-in breach scanner that checks whether your email address or passwords have appeared in known leaks. If you discover a match, immediately change any reused passwords and secure those accounts with new, unique credentials.
Check out the best expert-reviewed password managers of 2025 at Cyberguy.com.
5) Use a personal data removal service
Many attacks start by targeting emails and personal details already exposed online. Data removal services help shrink your digital footprint by requesting takedowns from data broker sites that collect and sell your information. They can’t erase everything, but reducing your exposure means fewer attackers have easy access to your details.
While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.
Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.
6) Check URLs before trusting anything
A convincing layout doesn’t mean it is legitimate. Always look at the domain name first. If it doesn’t match the official site or uses odd spelling or extra characters, close it. Attackers rely on the fact that people recognize a page’s design but ignore the address bar.
7) Close suspicious full-screen pages
Fake update pages often run in full-screen mode to hide the browser interface and make the page look like part of your computer. If a site suddenly goes full screen without your permission, exit with Esc or Alt+Tab. Once you’re out, scan your system and don’t return to that page.
Kurt’s key takeaway
ClickFix works because it leans on user interaction. Nothing happens unless you follow the instructions on the screen. That makes the fake Windows update page especially dangerous, because it taps into something most people trust. If you are used to Windows updates freezing your screen, you may not question a prompt that appears during the process. Cybercriminals know this. They copy trusted interfaces to lower your guard and then rely on you to run the final command. The technical tricks that follow are complex, but the starting point is simple. They need you to help them.
Do you ever copy commands from a website without thinking twice about what they do? Let us know by writing to us at Cyberguy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
The latest iPad Air is $400 for the first time and arrives by Christmas
If you have $400 and want an iPad, your options are usually kind of limited to either just the base iPad, or better yet, the latest iPad Mini — if it happens to be on sale when you’re shopping (it is now, but that’s not always the case). But right now, you should consider getting the 128GB version of Apple’s 11-inch iPad Air with the capable M3 processor. At Target, multiple colors of this model are $399.99, beating the previous low of $449.99 we’ve seen during large-scale deal events. Currently, no other retailer is matching this price. This sale ends Saturday night.
$400 is a sweet price for this model, as it debuted in early 2025 for $600. In terms of how it stacks up to other iPad models, Verge editor-at-large David Pierce said in his impressions that the M3 Air is “exactly what you think it is. Which is fine.” I know, that sounds like a back-handed compliment, but it’s been a while since iPads peaked in terms of utility, design, and fast performance. This one carries the torch in Apple’s tablet dominance, and its M3 processor means it’ll be a fantastic tablet for longer than any other iPad at the $400 price point. Read our in-depth impressions.
Other Verge-approved deals
Technology
Facebook settlement scam emails to avoid now
NEWYou can now listen to Fox News articles!
Millions of Facebook users filed claims in a recent privacy settlement after the platform was accused of mishandling user data. The approved payouts have been rolling out, which means people are watching their inboxes for updates. Scammers know this and are sending look-alike emails that push you to click a “Redeem Virtual Card” button. Arlene B emailed us to share what landed in her inbox.
“I received an email stating that it was from (Facebook User Privacy Settlement Administrator) and that I needed to click on the button below to “Redeem Virtual Card.” Do you know if this is a scam or not?”
Her question shows how convincing these fake messages appear. A real settlement did happen, and people have been getting payments. Still, criminals are now piggybacking on the rollout with messages that look official but lead to dangerous sites that steal your information. Let’s walk through how to tell real emails from fake ones.
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
NEW SCAM SENDS FAKE MICROSOFT 365 LOGIN PAGES
Scammers send fake settlement emails that mimic the real payout notices to trick you into clicking. (Kurt “CyberGuy” Knutsson)
How to check if your Facebook settlement email is legitimate
Scammers rely on confusion and urgency. These steps help you confirm the message before you click anything.
Confirm the sender’s address
Real settlement emails come from facebookuserprivacysettlement@notifications.kroll.com. Kroll is the official administrator.
Look for your claimant ID
Real notices include your unique claimant ID and reference the claim you filed last year. Fake emails skip this personalized detail.
Check where the link leads
Real payout links go to DigitalPay / Veritas or domains tied to krollsettlementadministration. If the link points to a strange or shortened URL, it is likely unsafe.
Watch for common red flags
Pressure to act right away. Clumsy wording or spelling mistakes. A button that goes to a suspicious URL. You never filed a claim in the first place. Any sender address that is not the official Kroll domain.
Remember that you are not required to click anything
If your claim was approved, you have already received a legitimate notice. Emails that say you must “redeem” again or “confirm” payment are signs of a scam.
GEEK SQUAD SCAM EMAIL: HOW TO SPOT AND STOP IT
A quick hover over the “Redeem Virtual Card” button often reveals a suspicious link that gives the scam away. (Kurt “CyberGuy” Knutsson)
Why scammers target large settlements
Whenever a major payout occurs, criminals blend in with legitimate messages because people expect money and may open emails quickly. When fake notices look similar to real ones, it only takes one careless click for scammers to grab your data.
DON’T FALL FOR FAKE SETTLEMENT SITES THAT STEAL YOUR DATA
A person logging onto Facebook (Kurt “CyberGuy” Knutsson)
Ways to stay safe from settlement scams
Use these simple habits to protect yourself from Facebook settlement scams and any future payout scam.
1) Verify the sender every time
Look at the full address. Scammers often change one character in hopes you will not notice.
2) Hover over links before tapping
Check the destination without clicking. A strange URL is your warning sign.
3) Never share sensitive information through email
Real administrators do not ask for banking info or logins.
4) Use a data removal service
Data brokers often collect your email address, phone number and other personal details that scammers use to target victims. A data removal service can pull you out of those databases, which reduces the amount of scam email that reaches you in the first place.
While no service can guarantee the complete removal of your data from the internet, a data removal service is really a smart choice. They aren’t cheap, and neither is your privacy. These services do all the work for you by actively monitoring and systematically erasing your personal information from hundreds of websites. It’s what gives me peace of mind and has proven to be the most effective way to erase your personal data from the internet. By limiting the information available, you reduce the risk of scammers cross-referencing data from breaches with information they might find on the dark web, making it harder for them to target you.
Check out my top picks for data removal services and get a free scan to find out if your personal information is already out on the web by visiting Cyberguy.com.
Get a free scan to find out if your personal information is already out on the web: Cyberguy.com.
5) Go directly to the official settlement site
Type in the address yourself instead of using a link from an email.
6) Use strong antivirus software
Good security software blocks dangerous links and pages. The best way to safeguard yourself from malicious links that install malware, potentially accessing your private information, is to have strong antivirus software installed on all your devices. This protection can also alert you to phishing emails and ransomware scams, keeping your personal information and digital assets safe.
Get my picks for the best 2025 antivirus protection winners for your Windows, Mac, Android and iOS devices at Cyberguy.com.
7) Delete emails that push urgency
Scammers want fast reactions. Slow down and confirm details.
Kurt’s key takeaways
The Facebook settlement payout created the perfect moment for scammers to slip fake messages into inboxes. Once you know the signs, it becomes much easier to separate real notices from dangerous ones. Stay alert, trust your instincts and verify before you click.
Would you open a payout email if you were not expecting money in the first place? Let us know by writing to us at Cyberguy.com.
CLICK HERE TO DOWNLOAD THE FOX NEWS APP
Sign up for my FREE CyberGuy Report
Get my best tech tips, urgent security alerts and exclusive deals delivered straight to your inbox. Plus, you’ll get instant access to my Ultimate Scam Survival Guide — free when you join my CYBERGUY.COM newsletter.
Copyright 2025 CyberGuy.com. All rights reserved.
Technology
The first Dolby FlexConnect soundbar is coming from LG
Dolby Atmos FlexConnect technology debuted this year with the TCL Z100 speakers, and now we’re getting our first FlexConnect soundbar thanks to LG. The new H7 soundbar — which runs on the same Alpha 11 Gen 3 chip as LG’s OLEDs and new Micro RGB LED — is a part of the LG Sound Suite, a modular home audio system the company will debut at CES 2026. In addition to the soundbar, the Sound Suite will include the M5 and M7 surround speakers and the W7 subwoofer. All of the speakers feature Peerless Audio components.
The two main drawbacks of TCL’s Dolby FlexConnect implementation were the limitation of only allowing four connected speakers, including a sub, and the need for a 2025 QM series TCL TV. So you needed to pick between better sound coverage with a fourth speaker or more bass performance with a sub. LG’s Sound Suite, on the other hand, will allow you to connect the soundbar with up to four surround speakers and a subwoofer for a potential 13.1.7-channel system.
And while the speakers can be used with a compatible LG TV (including the 2026 premium LG TV lineup and 2025’s C5 and G5 OLEDs), it isn’t required. It’s possible to use the H7 soundbar with any TV — or without — and have it act as what’s called the lead device to connect the surround speakers and sub. LG says there are 27 different speaker configurations possible, from using two speakers as a stereo pair up to the full system with soundbar, surrounds, and sub.
In my experience with the TCL Z100, calibrating FlexConnect speakers to your space is also fast. Once they’re in place and plugged in, a short musical clip is played for a few seconds and then setup is complete. The system is able to know where the speakers are placed and how to optimize the surround and Atmos sound for your room. With other room correction software, the process can take much longer, requiring taking sound readings from multiple locations in the room.
LG is using ultra-wideband technology to adjust the sweet spot based on your listening position that it’s calling Sound Follow. What will be interesting to see with the LG Sound Suite’s Dolby FlexConnect implementation is how customizable it is after setup (for instance, adjusting subwoofer levels).
I’ll be hearing the system at CES and plan on reviewing the system when it’s available to see how well the technology translates into a home.
-
Iowa4 days agoAddy Brown motivated to step up in Audi Crooks’ absence vs. UNI
-
Washington1 week agoLIVE UPDATES: Mudslide, road closures across Western Washington
-
Iowa5 days agoHow much snow did Iowa get? See Iowa’s latest snowfall totals
-
Maine2 days agoElementary-aged student killed in school bus crash in southern Maine
-
Maryland4 days agoFrigid temperatures to start the week in Maryland
-
Technology1 week agoThe Game Awards are losing their luster
-
South Dakota4 days agoNature: Snow in South Dakota
-
Nebraska1 week agoNebraska lands commitment from DL Jayden Travers adding to early Top 5 recruiting class