A new macOS social engineering campaign called ClickFix highlights the urgent need for IT departments to shorten software update deferral windows to better protect against evolving security threats.
Key Points
- The ClickFix campaign tricks users into pasting malicious scripts into Terminal via fake CAPTCHA or browser update alerts.
- Attackers use these scripts to steal macOS Keychain databases and browser session cookies, effectively bypassing multi-factor authentication.
- Apple introduced a native Terminal security warning in macOS Sequoia and macOS Tahoe 26.4 to disrupt these specific paste-based attacks.
- Industry experts recommend reducing the standard 90-day software update deferral window to 30 or 45 days to ensure critical security patches are applied.