‹ BackHN Continuity

Thread

Meta’s Muse has a serious 0-day

122 points · 49 comments · pavel_lishin

  1. gavinray · · focus · HN ↗
    The "zero day" is something they call a "ClickFix Attack"

    Upon Googling "ClickFix":

      > "A ClickFix attack is a social engineering technique... It typically compromises devices by manipulating victims into copying and pasting malicious commands directly into system-level tools"
    
    I'm sorry, that's not a zero-day, that's idiocy that's as old as time.
    1. bachittle · · focus · HN ↗
      The exploit is a local zero day exploit, meaning the machine needs to already be compromised. For it to be a remote zero day exploit you need to do the ClickFix attack. The idea is that it lets you access much more machines and resources if the one machine with Muse is compromised. More info here: <a href="https:&#x2F;&#x2F;x.com&#x2F;dps&#x2F;status&#x2F;2102248329111634067" rel="nofollow">https:&#x2F;&#x2F;x.com&#x2F;dps&#x2F;status&#x2F;2102248329111634067
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.