Thousands of hacked sites trick you into installing malware

Security researchers have identified over 5,400 compromised small-business websites being used to distribute malware via fake CAPTCHA prompts. Users are tricked into running malicious commands on their computers, posing a significant cybersecurity risk.
Why it matters
This highlights the vulnerability of small business web infrastructure and the sophisticated social engineering tactics used to bypass standard security awareness.
You land on the real website of a local business and a CAPTCHA appears. It looks routine until the page tells you to open Windows Run and paste a command. That should stop you cold. Security researchers say thousands of legitimate small-business websites have been compromised to spread this malware trap. Here's what to know before a familiar website catches you off guard. NEW! Join our upcoming CyberGuy LIVE class: Get Better Health Care With AI In this free live online class, Kurt "CyberGuy" Knutsson will show you five practical ways AI can help you take a more active role in your health care. You’ll learn how to organize your health history, remember important appointment details, understand complicated medical information, research prescriptions and prepare questions for your next doctor’s visit. No technical experience is needed.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in