Meet Meraj: the expert-level analyst AI for your business

Today's edition, unpackedAI & Frontier Tech

ClickFix attacks trick Mac and Windows users into running their own malware

Habib Ferdous·Edition #85·September 15, 2026·21 minSummarize:
Bottom line

ClickFix attacks are tricking Mac and Windows users into pasting attacker commands into their own terminal, and the fix is a company-wide rule against pasting anything from a pop-up dialog. The pattern is simple: a fake "browser fix" or CAPTCHA prompt tells the user to open a run box and paste a line of text, which executes malware with that user's permissions.

For operators, this is a [security hygiene problem]( /blog/ai-for-operators) that lands on whoever holds admin rights, not a technical exploit that requires a patch. Push the alert Monday: no pasting commands from any dialog, ever.

This story is part of our running guide to AI for operators.

The Read

The ClickFix social-engineering campaign, now running through hijacked brand accounts like HBO Max Reddit, is the week's sharpest operational exposure: it requires no technical sophistication, just one employee who pastes a fake browser fix. The Cass freight index closes a chapter simultaneously: the longest freight downturn on record ended in August, with truckload rates up 11% and shipments turning positive, a real inflection for operators repricing logistics contracts. Brent crude near $108 on Houthi-Saudi escalation adds a second cost vector hitting transport and manufacturing at the same time. On capital, prominent economists are flagging a potential Fed policy mistake with the 10-year at 4.96%, floating-rate borrowers should stress-test covenant headroom rather than wait for clarity.

Cyber threats down 75% this week Markets, broadly down 69% this week AI tools & vendors down 47% this week Tariffs & trade up 80% this week 10-Yr up 4.0% this week

The lead story, in full

What is a ClickFix attack and how does it work?

ClickFix attacks are tricking Mac and Windows users into hacking their own machines, per TechCrunch. The entry point is a fake browser-fix prompt: a page tells the user something is broken, then hands them a command to paste into a terminal or Run dialog. The user executes it. The malware runs with the user's own privileges, under the user's own name.

TechCrunch traces one live lure to a fake HBO Max ad on Reddit, clicked within the past week. The ad is the delivery vehicle, not the payload. The payload is the instruction the user types in themselves.

The paste is the infection

Nothing in the chain requires a software vulnerability. The attacker supplies a sentence. The user supplies the execution. That is the whole attack.

Who gets hit first by ClickFix inside a company?

Your endpoint protection sees a legitimate process, launched by a legitimate user, running a command the user typed. There is no exploit to signature, no malicious binary to quarantine on arrival. The command is the malware, and it arrives as text.

The help desk is the first responder

A compromised machine does not announce itself. The first signal is usually an odd login, a mailbox rule nobody wrote, or a session token reused from an unfamiliar address. By then the attacker has been inside for days, reading mail and watching which systems the user can reach.

For a 20-to-200 person company, the blast radius is set by what that one user can touch: the finance inbox, the shared drive, the shipping portal, the carrier login. A warehouse supervisor and a controller carry very different access. The attacker does not need to know which. They take what the seat already has.

The cost lands on the operator, not the vendor

Recovery is billed in hours, not licenses. Password resets across the directory, mailbox rule audits, session revocation, a forensics retainer, and the two days your team spends not shipping. If the seat held payment credentials, add the bank's fraud review and the wire recall window.

The alert is the control

The fix is a behavior change, not a purchase. No legitimate browser, OS, or software vendor asks a user to paste a command into a terminal to fix a page. That single rule covers the whole family of these lures, including the variants that have not shipped yet.

Who gets hit, and how hard

Business modelSeverityFirst symptom
law firmHIGH

A browser tab freezes, then a dialog claims the page needs a quick fix and offers a one-line command to copy.

accounting firmHIGH

A staffer reports a pop-up that told them to paste a command to 'verify' the browser.

healthcare practiceHIGH

A reception terminal slows or a browser extension the practice never installed appears in the toolbar.

financial advisor/RIAHIGH

A custodian portal logs the advisor out mid-session and asks for credentials again.

agency (marketing/creative)HIGH

A designer says a Reddit ad asked them to copy a command to fix a video player.

SaaS (B2B)HIGH

A support agent reports a browser dialog instructing them to paste a command to continue.

e-commerce brand (DTC)WATCH

An admin notices a new login from an unfamiliar location on the store dashboard.

importer/distributorWATCH

A rep reports a pop-up asking them to paste a command to view a tracking page.

staffing & recruiting firmWATCH

A recruiter says a job-board page told them to run a command to fix a loading error.

FILTERED · JUSTFILTERED.COM

Which one are you? Tap your row.

What should I tell my team about pasting commands from pop-ups?

Open questions

  • Which platforms and browsers the fake prompts currently impersonate

    Why it matters: The impersonated brand tells you which of your teams is most exposed right now.

    What resolves it: Follow-on reporting or vendor advisories naming the specific lures in circulation.

  • Whether the Reddit ad campaign is one operator or a template others are copying

    Why it matters: A single campaign burns out; a template keeps coming back under new brands.

    What resolves it: Ad platform takedown data or a second outlet confirming the same lure pattern.

The playbook

This week

Send a one-paragraph alert to every employee: never paste a command from a pop-up dialog, close the tab, reopen the site. Ask each person whether they clicked a fake ad in the past week and treat any yes as a compromised machine. Rotate the credentials that machine can reach, starting with email and the shared drive.

This month

Add the paste rule to onboarding and to the annual security training, with the fake HBO Max ad as the worked example. Turn on a browser policy that blocks copy-paste into terminal windows where your tools allow it. Test the alert with one simulated fake-fix prompt and see who reports it.

This quarter

Move the accounts that reset everything (email, banking, payroll) behind hardware keys so a stolen session cannot cascade. Review which machines hold credentials they do not need. Re-run the simulated prompt and compare the report rate to the first test.

What to watch: Watch whether a second confirmed lure appears beyond the fake HBO Max ad on Reddit, per TechCrunch. A second vector means the campaign is broadening and your alert needs the new example. Watch whether your own simulated prompt gets reported within the hour. A slow report rate means the rule is not landing. Watch whether endpoint alerts start flagging user-initiated command execution. If they do, your tooling is catching the pattern and the paste rule is buying time.

Business Pulse

Freight demand just turned, and fuel is repricing underneath it, so the contracts you sign this month set your cost floor for the next one.

Cass: TL rates up 11% in August as freight shipments finally turn positive

RATES

Truckload linehaul rates rose 11% year over year in August, per Cass data reported by FreightWaves, and freight shipments turned positive after 42 months of decline. The longest downturn on record just ended.

The mechanism is a floor resetting under you. Carriers spent three and a half years bidding against each other with too much capacity. When volume inflects, that capacity stops being a discount and starts being leverage, and linehaul rates move before anyone renegotiates a contract.

Who gets hit first

The freight broker re-quoting Gulf lanes Monday eats this first, then passes it to the shipper. If your carrier agreement has a rate review window, the number you agree to now is the number you live with after spot rates absorb the new floor.

Re-quote carrier contracts before the next bid cycle closes.

BOTTOM LINEThe downturn is over. Lock linehaul before spot rates set your new floor.
THE MOVERe-quote carrier contracts before the next bid cycle closes.

Brent crude nears $108 after Houthi strikes on Saudi Arabia

FUEL

Brent crude pushed toward $108 after fresh Houthi strikes on Saudi Arabia and attacks by Iran on ships in the Gulf, per CNBC. WTI, the U.S. benchmark, stood at $97.26 on the same date. Brent trades at a premium to WTI because it prices seaborne supply risk more directly. Oil extended gains on both reports.

Fuel is the fastest line item to move through your P&L. A carrier fuel surcharge recalculates on a published index, usually weekly, and it lands on your invoice before any contract renegotiation happens. The surcharge is not a negotiation. It is a formula.

The chain from the Gulf to your invoice

Strikes on Saudi infrastructure and attacks on shipping in the Gulf raise the crude price, the index follows, the carrier surcharge follows, and your landed cost follows. Each step takes days, not quarters.

Model your freight spend at the current Brent level before you sign anything with a surcharge pass-through clause.

BOTTOM LINESurcharges recalculate weekly. Your invoice moves before your contract does.
THE MOVEModel freight spend at current Brent before signing surcharge pass-through terms.

Ocean peak season defies early-end forecasts, extending freight pressure

OCEAN

Ocean peak season is still running, contrary to forecasts that it would fade by now, per the National Retail Federation and Hackett Associates via Supply Chain Dive. Shipments may crest in September instead.

The mechanism is capacity timing. Carriers plan blank sailings and equipment repositioning around an expected peak end. When the peak does not end, that capacity stays committed, space tightens, and spot ocean rates hold higher for longer than the forward curve assumed.

What it does to your inbound plan

If you booked ocean freight assuming a post-peak rate drop, that assumption is now costing you. The same delay pushes container availability and drayage scheduling, which is where the real demurrage charges accumulate.

Confirm space allocations for the next inbound cycle before assuming the peak has passed.

BOTTOM LINEPeak season did not end on schedule. Space and rates stay tight into fall.
THE MOVEConfirm ocean space allocations before assuming the peak has passed.
AI & Frontier Tech

Both items are the same trade: AI capex and AI-driven attack surface get funded first, and the people and accounts underneath absorb the bill.

HBO Max Reddit account hijacked to serve ClickFix attacks to followers

SECURITY

A brand's own social account became the delivery vehicle. Attackers took over HBO Max's Reddit account and used it to push ClickFix attacks at its followers, part of what The Register describes as a massive 48-hour malvertising blitz aimed at both macOS and Windows machines.

The mechanism is the part that reaches you. ClickFix does not exploit a software flaw. It tells the visitor to paste a command into their own terminal or Run dialog, and the visitor does it because the instruction appears to come from a trusted account they already follow. Brand trust is the payload carrier.

Your followers are the attack surface

For an operator, the exposure is not the media company. It is every account your team posts from, and every follower who treats those posts as safe. A hijacked brand account converts your audience into a distribution list you cannot recall.

Audit who holds credentials to your social accounts, whether two-factor is enforced on each one, and whether a compromised post can be pulled without waiting on the platform.

BOTTOM LINEA trusted account is the delivery mechanism. Lock the logins your audience already believes.
THE MOVEAudit social account credentials and enforce two-factor on every posting login this week.

Oracle cuts staff again to fund AI spending after a banner quarter

VENDORS

Oracle posted a strong quarter and cut staff anyway, with the savings routed toward its AI cloud buildout. The Register frames it as congratulations on helping Larry Ellison's AI cloud boom, followed by a request to pack your bags.

The chain runs past Oracle. When a company with a banner quarter still funds AI by cutting headcount, the message to every operator is that AI spend is being treated as non-discretionary, and payroll is the flexible line. Your own board reads the same headlines.

The budget line that moves

Expect the same trade inside your vendors. Support contracts, implementation teams, and account coverage are the first places an AI-funded cost cut shows up, and those are the people who answer when your system breaks.

Before you renew, ask each critical vendor what changed in their support staffing over the last two quarters.

BOTTOM LINEAI spend is being funded from payroll, including at vendors you depend on.
THE MOVERenew vendor contracts only after asking what changed in their support staffing.
Growth & GTM

Both items are about where ad dollars are actually working: retail media is compounding profit while search anxiety is being used to justify bigger budgets elsewhere.

Marketers use AI search anxiety to argue for bigger media budgets

MEDIA

Brands with long consideration journeys, insurance and cars among them, are citing shifting search behavior to argue for larger media budgets, per Digiday. The concern is real. The budget request built on it is a separate question.

The mechanism is a reallocation with no measurement attached. When AI search changes how buyers find you, the honest response is to test where the traffic went. The easier response is to raise the top-of-funnel number and call it adaptation.

Ask for the channel math

If your agency is citing AI search risk to justify more spend, the ask is channel-by-channel attribution: what each channel returned before the shift, and what it returns now. A budget increase without that comparison is a hedge, not a plan.

Demand channel-level attribution before approving any increase tied to AI search.

BOTTOM LINEAI search anxiety is a real risk and a convenient argument. Ask for the channel math.
THE MOVEDemand channel-by-channel attribution before approving an AI-search budget increase.

Kroger's ad business posts its strongest profit growth since 2021

RETAIL

Kroger Precision Marketing grew profit 24% in the second quarter, per Kroger's earnings release reported by Digiday, its strongest profit growth since 2021. Retail media is now a profit center, not a side experiment.

The mechanism is first-party purchase data. Kroger knows what a household bought, so an ad can be tied to a sale in a way a search or social placement cannot. That closes the attribution loop your agency keeps asking you to trust on faith.

Where your next dollar goes

Retail media networks sell closed-loop measurement, and they are pricing it accordingly. If you sell through grocery or retail channels, that is where your competitor's budget is moving, and it is the one channel where the receipt is the proof.

Test a retail media placement with a measurable sales lift before shifting budget on search anxiety alone.

BOTTOM LINERetail media closes the attribution loop. That is why the profit is compounding.
THE MOVETest a retail media placement with measurable sales lift before shifting budget.
Leadership & Ops

Three moves that reset the ground under hiring and location: a profitable giant cutting staff to fund AI, a federal agency opening a charge intake against employers, and a cross-border business that chose relocation over a tariff.

Oracle announces layoffs to offset AI spending costs

HEADCOUNT

Oracle cut staff this week and told the affected workers by email, framing the reduction as a way to offset what it is spending on AI infrastructure. Business Insider reported last month that the company was looking to reduce payroll after borrowing to build data centers and buy chips.

The comp ceiling resets

A profitable company funding AI by cutting headcount is the signal that matters. When a name that size moves first, peers follow, and the reset lands on salary bands rather than on a single payroll. Your open offers sit in that current.

Where it reaches you

Recruiters at competitors will point at the same budget line. Candidates who were holding out for a number will take the number they have. The window to close an accepted offer is short, and it closes from the top down.

BOTTOM LINEA profitable giant cut staff to fund AI. Your comp bands move next.
THE MOVELock open role offers before peers reset salary bands downward.

EEOC opens intake for anti-American bias charges against employers

LIABILITY

The EEOC has opened intake for charges alleging bias against workers for being, or sounding, too American. The agency's chair asked workers in a video whether they had been harassed at work for speaking English.

The intake is the mechanism

An intake channel converts anecdotes into filed charges. Once a charge is filed, the employer carries the response cost: counsel, records, interviews, and a written position. The agency does not need a pattern to open the door; one worker with a story does.

What your managers said

Your exposure is not the policy manual. It is the meeting where a manager told someone to speak English, or the group chat nobody archived. Those are the exhibits.

The cheap move

Pull your harassment reporting channel and confirm it reaches someone outside the reporting line. Then brief managers on what a language comment costs.

BOTTOM LINEA new charge intake turns watercooler comments into filed complaints.
THE MOVEAudit your harassment intake and manager language guidance this week.

Canadian brewery relocates to Maine rather than absorb a 50% US tariff

TARIFFS

Mother Mushroom Brewery sources supplies and serves customers from both sides of the border, and it says a 50 percent levy has made its current Canadian location unsustainable. The company is moving to Maine instead of absorbing the tariff.

Why relocation beat absorption

A tariff at that level is not a margin problem you price through. It is a permanent cost on every unit that crosses, and it compounds with freight and currency. Moving the production footprint removes the crossing entirely.

The copyable math

Any operator whose product crosses that border runs the same equation: eat the levy, pass it to customers, or move the plant. The brewery picked the third option, which means it decided the tariff outlasts the move.

What it signals

When a small producer relocates rather than reprice, the tariff is being read as durable. Suppliers and landlords on the US side of that border should expect more of these calls.

BOTTOM LINEA 50% levy made the Canadian site unsustainable. The brewery moved instead.
THE MOVEModel relocation against absorption for any product that crosses that border.
Capital & Markets

Rate direction is the shared wire here: economists warning the Fed off a hike, the 10-year holding near five, and a coffeehouse chain that could not carry its cost structure into Chapter 11.

Prominent economists warn the Fed may be on the verge of a serious mistake

RATES

Economists are calling on the central bank to wait before raising rates, warning the economy may be weaker underneath than the headline data shows. The argument is about sequencing: a hike into a soft spot does damage that shows up later.

Why the warning matters to a borrower

A policy error is not priced until it is. If the Fed moves and the economy buckles, the correction arrives after your floating-rate debt has already repriced. Covenant headroom is tested on the way up, not on the way down.

The stress test to run

Take your current debt service and hold it at today's rate for four quarters without assuming a cut. If the covenant trips in that scenario, the fix is a conversation with your lender now, not after the meeting.

The asymmetry

Waiting costs the Fed nothing it cannot recover. A hike you did not need costs you a refinancing window.

BOTTOM LINEIf a policy error is coming, your floating-rate debt reprices first.
THE MOVEStress-test covenant headroom against a sustained high-rate scenario now.

10-year Treasury holds at 4.96% as rate uncertainty persists

YIELDS

The 10-year Treasury closed at 4.96% on 2026-09-11, up from 4.95% the prior day, per FRED. A single basis point is not a move. The level is.

The level is the story

The 10-year is the reference rate under commercial paper, equipment financing, and the spread your lender adds on top. Holding near five keeps the floor under your cost of capital where it has been, which means no relief arrives from the bond market this quarter.

What it does to a deal

An acquisition or a capex project underwritten at a lower rate now clears a higher bar. The spread between the project return and the financing cost is thinner than the model assumed.

The practical read

Do not wait for the 10-year to fall before you finance. Price the deal at this level and let a decline be upside.

BOTTOM LINEThe 10-year held at 4.96%. Your cost of capital did not move.
THE MOVEReprice your capex model at this 10-year level before you commit.

Coffeehouse chain files Chapter 11 as costs and prices squeeze margins

MARGINS

Another coffeehouse chain has filed Chapter 11, squeezed between rising input costs and customers who will not pay more for a cup. The filing is the end of a margin compression that ran for several quarters.

The squeeze has two sides

Green coffee, labor, rent, and dairy all moved up. The price on the board could not follow without losing traffic. When both sides of the margin move against you at once, the only lever left is the balance sheet.

What a filing does to the street

Landlords with that chain in the portfolio now renegotiate or lose the rent. Suppliers holding receivables take a haircut. Competitors pick up the leases at lower rates, which resets the rent comp for everyone nearby.

The read for operators

If your margin has been compressing for three quarters and you have not repriced, the filing is the reminder that the balance sheet is not a strategy.

BOTTOM LINECosts rose, prices could not follow, and the balance sheet ran out.
THE MOVEReprice your menu or your contracts before the margin compression compounds.

The Pulse, broken down

WTI Oil

$97.26 +3.2%

$97.26. Fuel surcharges on your freight quotes jump before the next rate sheet.

10-Yr Treasury

4.96% +0.01%

4.96%. Equipment loans and lines of credit reprice higher; your next truck loan costs more.

Fed Funds Rate

3.63% 0.00%

3.63%. Holding steady, so no relief on floating-rate debt this week.

CPI (YoY)

3.4% +0.0%

3.4%. Input costs stay sticky; your supplier price increases stick with them.

Unemployment

4.1% 0.0%

4.1%. Hiring stays tight; wage pressure on your crew holds.

USD Index

118.2 +0.1%

118.2. A stronger dollar makes your imports cheaper, but your exports cost more abroad.

Bitcoin

$76.9K -1.58%

$76.9K. Down 1.58%; if you hold crypto on the balance sheet, collateral value slips.

Oil and the 10-year both climbed while the Fed stood still, so fuel and financing costs rise together. A stronger dollar softens import bills but squeezes export margins.

THE ONE TO WATCHWTI OilFreight surcharges follow oil with a lag; watch next week's quotes.
Watch your back

Japan VPN flaw exposed 246,000 records

if you run remote-access VPNs for staff, this bites

THE MOVEPatch VPN appliances now and audit access logs.

Homebrew 7.0.0 adds GUI and security controls

if your devs install packages via Homebrew, this bites

THE MOVEUpdate Homebrew and review new security settings.

Apple released updates across its products

if your team uses Apple devices, this bites

THE MOVEPush Apple updates to all company devices.

Pro-Ukraine group deploys new malware

if you operate in or with Russian markets, this bites

THE MOVECheck for indicators and isolate affected systems.

Fake government websites target Central Asia

if you or your partners transact in Central Asia, this bites

THE MOVEVerify government domains before entering credentials.

Frequently asked questions

What is a ClickFix attack and how does it work?

ClickFix is a social-engineering technique that convinces a user to run malicious code themselves. A fake browser-fix or CAPTCHA page instructs the victim to open a run dialog or terminal and paste a command. That command downloads and executes malware with the user's own permissions, which is why it bypasses tools that only scan downloads.

Why does ClickFix matter to a small or mid-size business?

It turns an ordinary employee into the delivery mechanism for malware, so endpoint tools that watch for suspicious files may see nothing unusual. The user's own hands run the command. That means the control that stops it is a written rule and training, not a patch, and the cost of missing it is a compromised machine with that user's access.

Who gets hit first inside a company?

Whoever holds local admin rights or works in a browser all day: IT, finance, and anyone who clicks a "your browser is out of date" prompt. The first machine compromised is usually the one with the most access, because that is the account the attacker inherits. Push the alert to those teams first.

What does a ClickFix compromise actually cost?

Not enough public reporting yet to say what a typical ClickFix incident costs a mid-size operator. What is known: the malware runs with the user's permissions, so the blast radius is whatever that account can reach, including shared drives, email, and any saved credentials. Treat the cost as the scope of that one account.

What should I do this week about ClickFix?

Send a company-wide alert that no one pastes commands from a pop-up dialog, browser fix prompt, or CAPTCHA page, ever. Add it to onboarding and to your phishing training. Then check who in the company has local admin rights and remove it where the role does not need it.

Is there a contract or vendor angle to this?

Yes, if you outsource IT or security. Ask your managed service provider whether their endpoint tooling blocks run-dialog and terminal paste execution, and get the answer in writing. If your contract only promises antivirus and patching, ClickFix sits outside what you bought, and you should say so before an incident.

How long has ClickFix been active and is it still spreading?

ClickFix has been an active technique and continues to appear in campaigns targeting both Mac and Windows users. The exact duration and current volume are not established in the reporting here. What is known: the technique keeps working because it relies on the user, not a software flaw, so it does not get patched away.

What is the second-order risk after a ClickFix infection?

The attacker inherits the user's session, so the next move is usually credential theft and lateral movement, not just the one machine. Saved browser passwords, email, and shared drives are all reachable. Rotate credentials for the affected account and check what that account touched before assuming the incident is contained.

What would change the picture on ClickFix?

A browser or OS change that blocks paste-and-run from dialogs by default would blunt the technique at the source. Until then, the control is behavioral. If your endpoint vendor ships a specific ClickFix detection, that changes your response time, but the rule against pasting commands still stands.

19 sources cited · view
Summarize:

Forward this to an operator who needs it.

Related in AI & Frontier Tech

The guide: AI for Operators · This post elaborates edition #85

Summarize this article

Opens with the article ready to summarize.