Back Mezha Hackers Hijack HBO Max Reddit Account to Spread ClickFix Malware
Prince Harry and Meghan Move Their Children to a New School Over Security Concerns
Zelenskyy urges parliament to secure budget funding and dismiss Prosecutor General Ruslan Kravchenko
Ukrainian People’s Artist Halyna Yablonska Dies After Serious Illness
Prosecutor General’s Office denies suspicion notice for NABU director
Ukraine’s Padel Team Reaches World Championship Main Draw After Beating Hong Kong
Zelenskyy Urges Parliament to Criminalize Fraudulent Call Centers and Dismiss Prosecutor General
Evening Digest: Ukraine and the World — September 14, 2026
Zelenskyy urges Ukraine’s parliament to dismiss Prosecutor General Ruslan Kravchenko
Russian Missile Strike on Izium Injures Four, Including Three Children
Zelensky Urges Ukraine’s Parliament and Government to Secure Budget Funding and Social Payments
Russian Drone Strike Sets Market Pavilions Ablaze in Kharkiv Region
Ukraine’s Government Ends Lesia Karnaukh’s Tenure as Acting Tax Chief
UK Man Admits Drugging and Raping His Wife for More Than 20 Years
Hackers Hijack HBO Max Account to Spread ClickFix Malware
Amazon Prime Video Adds Short News Clips to Compete With TikTok
Kyiv fertility clinic director Ihor Ilyin dies after shooting
Russian Drones Set Agricultural Enterprise Ablaze in Ukraine’s Kharkiv Region
Ninth Ukraine Support Summit Brings American Advocates to Washington
Zelenskyy appoints military surgeon Kostyantyn Humenyuk to lead Ukraine’s Medical Forces
Zelenskyy Awards 278 Ukrainian Defenders, 134 Posthumously
Trump rejects calls to slow AI development, says US has enough controls
Joe Manchin Backs Two Republicans in Senate Races That Could Shape Control of the Chamber
Oil Prices Surge Above $108 as Middle East Disruptions Threaten a Prolonged Energy Shock
xAI Asks US Appeals Court to Block Minnesota AI Image Law
London Tribunal Upholds Crispin Odey’s Financial Industry Ban but Cuts His Fine
Poland Begins Repairs at Shehyni–Medyka Crossing, Rerouting Buses Until 2027
Ukraine Reports Strikes, Prosecutor Vote and New International Support
US Senate Negotiators Weigh AI Safety Bill as Oversight Powers Remain Unclear
Fuel Price Hikes Trigger Syria’s Largest Protests Since Assad’s Fall
iOS 27 Makes Siri More Useful With Smarter Tools and Automations
Volkswagen unveils Mission Efficiency electric prototype with 323 mpg equivalent
Russian Hacker Group Claims DDoS Attack on Norway’s Parliament Website
Ukraine Risks Losing $29.5 Billion in Aid Without Urgent Parliamentary Votes
Ukraine and Costa Rica Black Sea Security and Air Defense
Russia Bans Sulfuric Acid Exports, Citing Domestic Supply Concerns
Shakhtar Beats Chornomorets 2-0 to Join Polissia atop Ukrainian Premier League
British Expert Says Stronger Pressure Could Force the Kremlin to Rethink Its War Strategy
Summer 2026 Becomes the Hottest on Record in the United States
LZ Detector Records Possible Dark Matter Signal, but Scientists Seek Proof
A familiar streaming brand became the cover for a campaign that asked users to perform an unusually risky “security” step. The consequences could reach far beyond one social platform.
As stated by Techcrunch
ClickFix has become one of the most prominent cyberthreats of 2026. The scheme was initially disguised as a tool for solving technical problems, but it later evolved into a widespread method of infecting devices in countries around the world.
How the ClickFix scheme works
The attack begins when a user visits a fake or compromised legitimate website. A window appears on the page imitating a CAPTCHA or an “I’m not a robot” check. The user is then asked to complete a supposedly additional security step: copy the provided text and paste it into the Windows Command Prompt or macOS Terminal.
If the person presses Enter, the command executes malicious code. It can steal passwords, account credentials, active authentication sessions, and information from cryptocurrency wallets. Running the commands through a system terminal also helps some attacks bypass standard antivirus protections.
Malicious HBO Max ads on
confirmed that it had detected the compromise of the HBO Max account. It was used to distribute ads containing malicious links. After the incident was discovered, the account was blocked and the ads were removed.
The exact number of people who clicked the dangerous ads, as well as the number of potentially infected devices, remains unknown. Warner Bros. Discovery, the company that owns HBO, did not on the incident.
Why ClickFix is dangerous for users
For most people, running commands through the Command Prompt, PowerShell on Windows, or Terminal on macOS is not a routine action. That is why a request to paste unknown text into a system tool should be treated as a serious warning sign.
Researcher Kevin Beaumont noted that organizations can centrally restrict access to such tools on Windows work computers. Mac users can use BlockBlock, a tool that helps detect attempts to change system settings.
ClickFix’s key feature is its use of social engineering. Instead of automatically exploiting a vulnerability, attackers persuade the victim to execute a dangerous command, turning them into an unwitting participant in the infection.
Other topics you might like:
Jaguar Land Rover plans to cut 4,000 jobs over two years as Chinese competition, US trade restrictions, electric vehicle demand and a cyberattack pressure its finances.
AI is accelerating cyberattacks through faster phishing, malware creation and social engineering, but experts say people remain the greatest cybersecurity risk.
Scammers are promoting fake GTA 6 demos that install malware and steal browser passwords, cookies, active sessions, and account access.
The full story
This article is one source in a clustered incident — the cluster page carries the summary, timeline and every other outlet covering it.
