Find notable cyber news and cases, enriched with sources, timelines, and signals.

Push Security launches browser-based malicious copy-and-paste detection for ClickFix attacks

Security Tool/Service
First reported
Last updated
Happening score
H score 17
1 unique sources, 1 articles

Summary

Hide ▲

Push Security introduced malicious copy and paste detection, adding browser-based detection and blocking for ClickFix-style attacks that try to push users into running malicious commands locally. The update matters because it stops the attack at the browser layer, before users can hand off execution to the endpoint. It is positioned as a front-line control that works across lure delivery channels and page styles.

Related Happenings

Venom Stealer MaaS continuous credential theft and exfiltration

Malware Activity
H score29 First: 01.04.2026 16:30 Last: 01.04.2026 16:30 Sources 1

About this happening: The Venom Stealer malware-as-a-service platform has been identified as a credential-theft threat that keeps exfiltrating data after infection, extending the window for...

Torg Grabber browser-extension theft activity

Malware Activity
H score36 First: 25.03.2026 20:32 Last: 25.03.2026 20:32 Sources 1

About this happening: The Torg Grabber infostealer is actively stealing data from 850 browser extensions, including 728 cryptocurrency wallet extensions, which raises the risk of account ta...

InstallFix Claude Code malvertising campaign

Campaign
H score32 First: 06.03.2026 17:00 Last: 06.03.2026 17:00 Sources 1

About this happening: InstallFix is being used in an active malvertising operation that pushes cloned Claude Code install pages and malicious CLI instructions, putting users who search for...

Google Groups and Google-hosted URL malware campaign targeting global organizations

Campaign
H score66 First: 15.02.2026 18:30 Last: 15.02.2026 18:30 Sources 1

About this happening: An active Google Groups malware campaign is abusing Google-hosted URLs to target global organizations and increase trust-based delivery success. Attackers seed legitim...

Lumma Stealer and trojanized Ninja Browser malware activity

Malware Activity
H score49 First: 15.02.2026 18:30 Last: 15.02.2026 18:30 Sources 1

About this happening: A Lumma Stealer and Ninja Browser malware activity was identified in February 2026, creating a cross-platform risk to Windows and Linux browser sessions. The W...

Timeline

  1. 20.10.2025 14:55 2 articles · 8mo ago

    Push Security launches browser-based malicious copy-and-paste detection

    Mitigation Patch Update

    Push Security introduced malicious copy and paste detection for its browser-based security platform, adding browser-based detection and blocking for ClickFix-style attacks that trick users into copying malicious code from a web page and running it locally. The control is designed to stop the browser-layer abuse without disabling copy and paste altogether.

    Show sources