๐Ÿ“ฃ

Advertisement

Google Ad - 970ร—90 Leaderboard ย TOP_LEADERBOARD_4

๐Ÿ“ฃ

Advertisement

Google Ad - 970ร—90 Leaderboard ย TOP_LEADERBOARD_4

The Thread

Four stories logged in two days describe the same shift from different angles. Attackers are no longer primarily breaking software; they are persuading people to break it for them, as TechCrunch reported in its account of ClickFix attacks tricking Mac and Windows users into hacking themselves. Meanwhile, the industry's response is increasingly procedural and human-facing rather than purely technical - Microsoft is issuing a code of conduct for its AI models and a patch that quietly breaks Excel copy and paste. The common thread is that the human operator has become both the primary attack vector and the primary point of failure.

Attackers Have Stopped Picking Locks

ClickFix is the clearest expression of the trend. According to TechCrunch, users who clicked a fake HBO Max ad on Reddit in the past week may have fallen victim to the technique, which does not exploit a software vulnerability in the traditional sense. Instead, it walks a user through running malicious instructions themselves. BleepingComputer reported that hackers compromised HBO Max's official Reddit account to push those malicious ads, launching ClickFix attacks that infected Windows and macOS devices with information-stealing malware.

The detail worth dwelling on is that the delivery mechanism was a trusted brand account on a mainstream platform. There was no zero-day, no exotic exploit chain, no malicious attachment that a mail gateway might quarantine. The attacker borrowed a recognizable name and asked the user to participate. That is a cheaper and more scalable business model than vulnerability research, and it works across operating systems, which is why the same campaign reached both Mac and Windows users.

Trusted Platforms Are the Distribution Channel

The choice of Reddit is not incidental. Social platforms have spent years building verification systems, brand accounts, and advertising infrastructure designed to signal legitimacy. Those signals are exactly what makes a compromised brand account valuable. A user scrolling past an ad from an official entertainment account has no practical way to distinguish a legitimate promotion from a hijacked one at the moment of the click.

For US technology companies, this inverts a long-standing assumption. Platform operators have generally treated account compromise as a reputational and content problem. This week's reporting suggests it is a malware distribution problem with real consumer harm. The entities absorbing the cost are not only the affected brand but the platform whose trust signals were weaponized. American consumers, meanwhile, are being asked to exercise skepticism toward exactly the cues - verified accounts, familiar logos, official-looking promotions - that platforms have trained them to rely on.

The Patch That Breaks the Office

Against that backdrop, Microsoft's confirmation of the KB5002914 Excel update is a reminder that the mundane failure modes still matter. As BleepingComputer reported, Microsoft confirmed that copy and paste may silently fail for some Excel users after installing the September 2026 security update.

Advertisement

๐Ÿ“ฃ

728x90

MID_CONTENT_2

The word to emphasize is silently. A security update that visibly crashes a spreadsheet generates a support ticket and a rollback. One that quietly fails to paste data generates corrupted work, missed figures, and hours of confusion before anyone identifies the cause. For US businesses that run financial models, inventories, and reporting pipelines through Excel, a silent data-integrity failure in a security patch is its own category of risk. The security fix and the productivity harm arrive in the same package, and the user has no way to opt out of one while keeping the other.

Governing the Machine That Talks to People

Microsoft's new AI code of conduct, reported by TechCrunch, is the fourth piece of the pattern. The code lays out general principles Microsoft AI models should uphold - supporting humans rather than replacing them, and accelerating human flourishing - alongside specific safety constraints, including instructions not to hack systems or trick humans.

Read against the other three stories, the inclusion of tricking humans is telling. The threat model the code addresses is not a model that autonomously compromises infrastructure. It is a model that persuades a person to do something they should not. That is the same mechanism ClickFix relies on, and it is the same mechanism a phishing email relies on. Microsoft is effectively writing down a rule for its AI systems that its human users are currently failing to follow themselves. The code of conduct is a governance document, but it is also an admission that conversational interfaces introduce a persuasion surface that traditional security controls do not cover.

What This Means for the US Market

The practical consequence for American technology companies is that security spending increasingly has to target human decision points rather than only technical perimeters. Brand account protection, ad verification, and platform integrity are now security functions, not just trust-and-safety functions. For consumers, the burden of verification keeps rising while the signals available for verification keep getting spoofed.

There is also a compliance dimension. A code of conduct for AI models is voluntary and self-described as principles, but it establishes an expectation that vendors will constrain how their systems communicate with users. Once one major vendor publishes such a document, enterprise buyers have a reference point to demand comparable commitments from others. That dynamic tends to move faster in the US market than formal regulation would.

What to Watch

The material points to three concrete things. First, whether platform operators change how brand and advertising accounts are secured in response to the HBO Max Reddit compromise that BleepingComputer described. Second, whether Microsoft expands or revises KB5002914 given the confirmed silent copy-and-paste failures, and how it communicates that to Excel users. Third, whether the principles in Microsoft's AI code of conduct, as TechCrunch reported them, are accompanied by any measurable enforcement or reporting. Each of those is a test of whether the industry treats the human at the keyboard as a security boundary or merely as the place where things go wrong.

More on this beat: Cybersecurity on TechManNews.

Advertisement

๐Ÿ“ฃ

728x90

IN_ARTICLE_5

#cybersecurity#ClickFix#social engineering#Microsoft#AI governance#platform trust

Newsletter

Get Tech News in Your Inbox

The latest AI, gadgets, software and startup stories from TechManNews, delivered every morning - free.