A fake CAPTCHA triggered a multi-stage credential theft attempt ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­    ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏  ͏ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­ ­  
Zero Trust Weekly

This week in Zero Trust

When something gets through, what happens next matters

Estimated reading time: 6–7 minutes

 

In this issue:

  • How ThreatLocker MDR intercepted a ClickFix attack before compromise
  • A passenger created a fake WiFi network mid-flight
  • How excessive agency expands the blast radius of AI
  • Threats you need to know: 2,000+ hacked WordPress sites & an exploited Windows flaw
View in browser

Manage preferences

From the CEO

How to make your team more effective

 

"We regularly see security teams responsible for thousands of endpoints with only a handful of staff. That forces them into a reactive mode where they’re constantly responding to incidents instead of reducing risk. If you implement deny-by-default controls, every cybersecurity professional on your team becomes more effective because they’re spending less time responding to preventable incidents and more time focused on genuine threats." - Danny Jenkins

From the ThreatLocker blog

 

See how ThreatLocker MDR stopped ClickFix attack

Default-deny controls give analysts the time they need

  • What's happening: The ThreatLocker MDR team intercepted a ClickFix attack inside a customer environment after detecting suspicious PowerShell activity downloading an image payload. The attack began with a fake CAPTCHA on a compromised legitimate website that instructed the user to run a malicious command, which was blocked by Allowlisting. From there, a heavily obfuscated, multi-stage infection chain attempted to deploy ACR Stealer, malware capable of stealing browser credentials, cryptocurrency wallets, files, screenshots, and other sensitive data.
  • Why it matters: A simple social engineering lure can lead to a highly sophisticated compromise. In this instance, the malware hid code inside a legitimate MP3, extracted another payload from an image, executed components in memory, and ultimately attempted to deploy ACR Stealer and a secondary tool designed to steal Google credentials and relay MFA.

  • The big picture: Detection tools and MDR teams are most effective when they have time to respond to an alert. In this instance, default-deny controls gave the ThreatLocker MDR team that time. Allowlisting prevented the execution of the malicious script and alerted the MDR team to the suspicious activity so it could be investigated before a compromise occurred. 

Delta passenger creates fake WiFi mid-flight

Attackers can impersonate trusted networks without touching your device

  • What's happening: On Aug. 10, 2026, an unidentified passenger created a fake WiFi network aboard a Delta flight from Las Vegas to Atlanta, just days after Black Hat USA and DEF CON wrapped up in Las Vegas. Delta said passenger safety was never at risk, and no aircraft operating systems were affected. The incident highlights a broader attack technique in which malicious WiFi networks impersonate legitimate or previously trusted networks, potentially allowing attackers to intercept traffic or direct users to fake login pages designed to steal credentials.
  • Why it matters: Many users are aware of the dangers of public WiFi, but when there is no other option, they will likely be more trusting. This is exactly what attackers are counting on. They impersonate familiar networks, creating opportunities to intercept unencrypted data or steal credentials without compromising the device first.
  • The big picture: Security should follow your devices wherever they go, not just your users. Device-level firewall policies can help protect users who unknowingly connect to malicious or unmanaged networks, preventing that connection from becoming an entry point into your environment. 

Excessive agency expands the blast radius of AI mistakes

Why you need to deploy least privilege and least agency together

  • What's happening: When an AI agent has capabilities that exceed what the agent's job requires, a bad model decision, compromised workflow, or prompt injection can have much greater consequences. The Open Worldwide Application Security Project (OWASP) defines this as excessive agency and breaks the problem into three root causes: excessive functionality, permissions, and autonomy. Least agency helps address the problem by limiting how freely an agent can act with the access it legitimately holds.
  • Why it matters: The ability to act autonomously is what makes AI agents useful, but it also determines their blast radius when they're manipulated, compromised, or simply wrong. An email assistant designed to summarize messages, for example, shouldn't also be able to send email or access unrelated data. If an attacker manipulates the agent, those unnecessary capabilities can be turned against the organization.
  • The big picture: AI security can't rely predominantly on determining intent and detecting every malicious input. Instead, limit the blast radius before something goes wrong. Least privilege restricts what an agent can reach, while least agency restricts what it can do with that access and how freely it can act. Together, they prevent a bad AI decision from becoming an action your environment never intended to allow.
ThreatLocker Webinars

September webinars from ThreatLocker

 

What makes you a target? Lessons from the cybercrime economy

Sept. 1 | 11 a.m. EDT

 

Why do attackers choose one organization over another? We'll break it down and let you know what controls send attackers running. 

Learn how attackers choose their targets

 

Debunking the cybersecurity myths that leave you exposed

Sept. 29 | 11 a.m. EDT

 

Does MFA stop credential theft? Can you trust a signed application? We'll draw from real attack scenarios to examine the security assumptions too many believe to be true.

Put your security assumptions to the test

Threats you need to know

 

CISA adds Windows IKE RCE flaw to KEV catalog 

CVE-2026-33824 affects Microsoft Internet Key Exchange Service Extensions

  • What's happening: CISA added CVE-2026-33824 to its KEV catalog warning that the flaw could allow unauthenticated remote code execution. The vulnerability is a double-free weakness, meaning the software attempts to release the same memory allocation more than once. IKE is used to establish secure IPsec VPN connections, potentially putting internet-facing VPN gateways and remote-access servers at risk. CISA has not confirmed whether or not the vulnerability has been used in ransomware campaigns. 

  • Why it matters: This exploit does not necessarily require a stolen password or successful phishing attempt. If an attacker can reach a vulnerable IKE service, they may be able to compromise the system before authentication.
  • The big picture: Vulnerabilities that enable remote code execution can be the foothold for a broad range of attacks. Organizations should apply the patch for CVE-2026-33824, validate the deployment, and limit IKE traffic to only networks and peers where it is required.

Nearly 2,000 hacked WordPress sites fuel malware operations

ClickFix spreads through compromised websites

  • What's happening: Researchers uncovered a global operation dubbed StopAndProtect that has been abusing hacked WordPress sites as infrastructure for malware delivery, command and control, and stolen data storage. The chain begins with a ClickFix social engineering attack, which leads to the execution of a PowerShell command. The resulting infection can deploy credential stealers, ransomware, screen-locking malware, and tools capable of spreading across networks and removable drives. More than 6,000 unique IP addresses had been compromised as of July 24, 2026. 

  • Why it matters: Compromising a single website or company for the data it contains is no longer the only objective. In this case, attackers repurposed the legitimate infrastructure to attack entirely different users, turning vulnerable websites into distributed infrastructure for malware delivery, surveillance, and data theft. 
  • The big picture: Most of the websites were found to be running outdated versions of WordPress and installed plugins, making them easier targets for attackers. Patching is a critical part of an organization's security, while default-deny controls can prevent the execution of malicious commands and payloads delivered through ClickFix attacks, even when a user falls for the lure. 
Zero Trust World 2027

Zero Trust World returns to Orlando

February 17–19, 2027

Loews Universal Orlando

 

Explore how to proactively defend against new and existing threats, engage with industry peers about the latest security trends, and learn the tactics cybercriminals don't want you to know.  

Register now

ThreatLocker events

Meet the Cyber Hero Team in person at these upcoming events

  • Arizona Tech Summit | Aug. 25
    Scottsdale, AZ
  • Secure Carolinas | Aug. 26–27
    Greenville, SC
  • ISACA Silicon Valley | Aug. 27–28
    Santa Clara, CA
  • Gartner IT Symposium | Sept. 14–16
    Broadbeach, AU
  • CTRL+ALT+DELight | Sept. 15
    Brisbane, AU
  • CTRL+ALT+DELight | Sept. 17
    Sydney, AU
See more upcoming events
ThreatLocker: Zero Trust Platform | Zero Trust Weekly

ThreatLocker, 1901 Summit Tower Blvd, Orlando, Florida 32810, United States

Manage preferences

Connect with us

                             

©2026 ThreatLocker Inc., All Rights Reserved