ClickFix Attacks Still Using the Finger

Introduction Since as early as November 2025, the finger protocol has been used in ClickFix social engineering attacks. BleepingComputer posted a report of this activity on November 15th, and Didier Stevens posted a short follow-up in an ISC diary the next day. I often investigate two campaigns that employ ClickFix attacks: KongTuke and SmartApeSG. When…

Read More

Why are sperm donors having hundreds of children?

James Gallagher,Health and science correspondentand Catherine Snowdon,Health reporter Getty Some men are having vast numbers of children through sperm donation. This week the BBC reported on a man whose sperm contained a genetic mutation that dramatically raises the risk of cancer for some of his offspring. One of the most striking aspects of the investigation…

Read More

Metasploit Wrap-Up

React2shell Module As you may have heard, on December 3, 2025, the React team announced a critical Remote Code Execution (RCE) vulnerability in servers using the React Server Components (RSC) Flight protocol. The vulnerability, tracked as CVE-2025-55182, carries a CVSS score of 10.0 and is informally known as “React2Shell”. It allows attackers to achieve prototype pollution…

Read More