ClickFix attacks, which use fake CAPTCHA overlays on compromised websites to trick users into running malicious terminal commands, have become mainstream and are infecting both PC and Mac users at scale. The technique's effectiveness stems from widespread internet fatigue, as casual users have grown desensitized to complex instructions and suspicious-seeming security prompts. Even Kremlin-backed hacking groups have adopted the method.
The US National Security Agency, CISA, and FBI accused six Chinese AI firms—DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI—of systematically stealing capabilities from American frontier AI models since late 2024 through API exploitation and prompt injection attacks. The agencies alleged the firms likely acted with Chinese government awareness and recommended coordinated defenses to protect US AI leadership.