Threat Intelligence / Advisory

Threat Advisory

Important Security Advisory for Windows System

MEDIUM CVSS 5 September 1, 2026

What happened

A new variant of the ClickFix social-engineering campaign, tracked as TerminalFix, is being used to compromise Windows endpoints. Attackers place fake Cloudflare CAPTCHA prompts on compromised or malicious websites. To “verify” they are human, the visitor is instructed to open Windows Terminal or PowerShell and paste a supplied command. That command silently downloads and executes a malicious script, giving the attacker a foothold on the device.

The technique relies on user interaction rather than a software vulnerability, which lets it slip past many traditional defences. No exploitation of a specific CVE is required for the attack to succeed.

Why it matters

Because the pasted command runs with the privileges of the logged-in user, a single successful lure can lead to remote code execution, credential theft, ransomware staging and data exfiltration. The attack is cheap for the adversary and highly effective against users accustomed to following on-screen instructions.

Organisations that rely heavily on Windows environments, and that permit unrestricted PowerShell or Windows Terminal script execution, are the most exposed. Fleets with inconsistent patching or without application-control policies face elevated risk.

Immediate actions

  1. Patch. Update all Windows 10, Windows 11 and Windows Server systems to the latest cumulative security update.
  2. Educate users. Make clear that no legitimate CAPTCHA ever asks anyone to open a terminal or paste a command, and that such prompts should be reported to IT immediately.
  3. Restrict script execution. Enforce application-control policies such as WDAC or AppLocker, and PowerShell constrained-language mode, to limit execution to approved scripts.
  4. Harden the perimeter. Strengthen email and web filtering to block the malicious lures and known delivery domains.
  5. Monitor and hunt. Watch for anomalous PowerShell or Windows Terminal launches immediately after browser activity, clipboard-to-terminal execution, and outbound connections to newly registered domains.

Indicators of compromise

No fixed file hashes or IP addresses are reliably tied to this campaign yet, as the infrastructure rotates frequently. Prioritise behavioural detection: unexpected launches of Windows Terminal or PowerShell right after web browsing, clipboard contents containing encoded or download commands, and script-initiated network connections to unfamiliar domains.

Affected

Vendors: Microsoft

Products: Windows 10, Windows 11, Windows Server 2019, Windows Server 2022

Is your organisation exposed?

Argos matches live threat intelligence to your own asset inventory and tells you what actually affects you.

Discover Argos

At a glance

SeverityMedium
CVSS5
PublishedSeptember 1, 2026
VendorMicrosoft
CVECVE-2026-1234

Get in touch

We respond within 1 hour on weekdays
Exeo Logo White Transparent