AUTO-UPDATED

Apple @ Work: Why the ClickFix campaign means it is time to kill the 90 day update deferral

A new macOS social engineering campaign called ClickFix highlights the urgent need for IT departments to shorten software update deferral windows to better protect against evolving security threats.

Key Points

  • The ClickFix campaign tricks users into pasting malicious scripts into Terminal via fake CAPTCHA or browser update alerts.
  • Attackers use these scripts to steal macOS Keychain databases and browser session cookies, effectively bypassing multi-factor authentication.
  • Apple introduced a native Terminal security warning in macOS Sequoia and macOS Tahoe 26.4 to disrupt these specific paste-based attacks.
  • Industry experts recommend reducing the standard 90-day software update deferral window to 30 or 45 days to ensure critical security patches are applied.

Why it Matters

Maintaining a 90-day update deferral window leaves corporate devices vulnerable to modern social engineering tactics that exploit known system weaknesses. Shortening this window is essential for IT teams to balance application compatibility testing with the immediate need to deploy critical OS-level security mitigations.
9to5Mac Published by Bradley C
Read original