Hot take: S/pn isn’t about two brothers fighting monsters. It’s about two bros fighting American myth & folklore. Which means they fight wendigos & werewolves, but it also means they fight the greatest American myth of all - that success for everyone looks like the American dream
DO NOT touch that keyboard. This is one of the most dangerous attacks circulating right now.
This is called a ClickFix attack. It is not a CAPTCHA. It is not a verification step. It is a social engineering attack designed to make you execute malicious code on your own machine while believing you are proving you are human.
Here is exactly what happens if you follow those steps.
The fake page has already silently copied a malicious PowerShell command to your clipboard without you knowing. It happened the moment the page loaded. You did not click anything. You did not consent to anything. The clipboard was written to in the background by JavaScript running on the page.
When you press Win + R you open the Windows Run dialog. When you press Ctrl + V you paste that malicious command directly into it. When you press Run you execute it with your own permissions on your own machine. No exploit needed. No vulnerability needed. You did it yourself. Willingly. While thinking you were completing a CAPTCHA.
The payload varies. Researchers have documented ClickFix delivering infostealers, remote access trojans, and credential harvesters. The malware executes instantly and silently. By the time the Run dialog closes the damage is done.
The reason this attack works so well is threefold. The fake CAPTCHA looks visually identical to a real one. The instructions sound technical and therefore trustworthy. And critically, you are the one executing the command so endpoint security tools see a legitimate user action rather than an automated attack.
Real CAPTCHAs never ask you to open Run dialogs. Real CAPTCHAs never ask you to paste anything. Real CAPTCHAs never give you keyboard shortcuts.
If a webpage ever asks you to press Win + R for any reason, close the tab immediately.
i’ve written whole essays about how queer people and women specifically use fanfiction as a tool for exploring their identity, gender, sexual desires etc. that’s always been part of why fanfic exists and people with no idea about fandom history are now trying to police what people can write. it’s infuriating. DONT LIKE, DONT READ.
We’re so excited to announce that The Road So Far… The Road Ahead Tour is heading to Kansas City June 11-13, 2027!
Gold weekend packages along with photo ops, autographs, and special event tickets will be available tomorrow at 1 PM EST/10 AM PST!
Stay tuned!
Guillermo del Toro says AI is a form of "natural stupidity"
“We are on the verge of image illiteracy. We are on the verge of cinema illiteracy... The pact between man and image is sacred, but we are in a time when that is in danger... We are told images can be generated by artificial means. The existence of an image is not just to be there. It is to connect us, to make us feel beauty,” he said.
https://t.co/h1bAYmAQKa
É OFICIAL!
A Amazon submeteu oficialmente Jensen Ackles à categoria de Melhor Ator Coadjuvante em Série Dramática no Emmy por sua atuação como Soldier Boy na quinta temporada de The Boys! 💚
I’m actually a child online safety expert and was one of the pioneers in this space with Club Penguin and so I feel uniquely positioned to critique this.
The groomer problem is real but it’s also vastly overstated. The far larger issue we saw at Penguin was suicidality or reports of sexual abuse in the home.
There is no solution for lazy/bad parenting. You can implement all the ID laws you want but if parents are going to just hand kids their phones unlocked, those kids will have access to all the same things the parents have unfettered.
What I found is that these draconian safety laws actually make it harder to be an honest operator of kids apps because on one hand it’s so much legal risk and so much user friction that it simply becomes uninvestible as a business.
Parents will just lie to let their kids use the unfettered internet. For example, I have a friend who works in mobile gaming who has two kids, one above and one below the age limit but separated by just 2 yrs, and the two wanted to play and chat together on Roblox - which is reasonable. To do this, he just verified that his younger kid is old enough for the chat feature when he’s not.
This happens all the time and will happen with these laws to. How far do we want to go with this? Scan the face of the user in real-time to make sure it’s not a kid using the device? We could do that but it feels like a massive unwanted intrusion of privacy.
That’s how you know this law isn’t about kids. COPPA and GDPR-K and so forth already make it illegal to allow chat and other grooming vectors to kids.
What’s really being done here is trying to eliminate online anonymity. And this is a far bigger issue that goes to core speech rights because if you cannot criticize the govt anonymously and if wrong speech is a crime then it becomes easy to identify all the detractors of the govt in power, and ban, fine or jail them for speech crimes.
Starmer has already been doing this and he wants to do it at a much bigger scale. Starmer won’t even acknowledge the problem of actual grooming gangs in Britain’s neighborhoods but he’s worried about online grooming?
No he’s not, and this hypocrisy gives away the game. What he wants is to kill online anonymity so he can enforce censorship of his unpopular policies. No politician should have this power.