DAILY BRIEFING
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Today's briefing covers a new TerminalFix social engineering campaign, critical WordPress vulnerabilities, a major healthcare data breach, and updates to Brave and Claude Code.
5 stories2 min read

Today's security landscape highlights social engineering threats targeting administrative command-line environments alongside persistent web application vulnerabilities and supply chain risk. Attackers are increasingly leveraging user execution vectors such as fake CAPTCHA prompts to run malicious code directly in Windows Terminal and PowerShell.
System administrators, web site operators, and security operations centers should prioritize reviewing system command execution policies and auditing third-party WordPress extensions. Web-facing infrastructures remain prime targets for unauthorized access and remote code execution.
Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE
Multiple critical vulnerabilities were disclosed across WordPress components, including CVE-2026-76581 (CVSS 9.8), an authentication bypass in WPMU DEV Dashboard up to 5.0.1, and CVE-2026-18431 (CVSS 9.8), an arbitrary file write flaw in the Avada theme, alongside flaws in TranslatePress, Pods, and GiveWP.
- Why it matters
- Unauthenticated attackers can bypass authentication to gain full administrator access or execute arbitrary code, leading to total site compromise.
- What to do
- Update WPMU DEV Dashboard past version 5.0.1, patch the Avada theme, and update affected TranslatePress, Pods, and GiveWP plugins immediately.
McKesson discloses breach after ShinyHunters claims patient data theft
Healthcare giant McKesson disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft. The ShinyHunters threat group claimed responsibility, asserting it stole 284 million patient data records.
- What to do
- Review third-party integration access logs and audit external vendor data-sharing permissions.
TerminalFix Uses Fake Cloudflare CAPTCHAs to Deploy Reverse-Tunnel Backdoor
Microsoft disclosed details of TerminalFix, a ClickFix variant using compromised websites and fake Cloudflare CAPTCHAs to trick users into running malicious PowerShell commands in Windows Terminal or PowerShell. The attack uses DLL sideloading and steganographic payload extraction to deploy a reverse tunnel.
- Why it matters
- Attackers are pivoting from the Windows Run dialog to terminal environments, increasing the execution success of complex multi-line scripts across corporate networks.
Anthropic is cutting Claude Code's current weekly limits by 17%
Anthropic announced changes to Claude Code weekly usage limits for users on Pro, Max, Team, and seat-based Enterprise plans.
- Why it matters
- Organizations relying on Claude Code for automated software development or security scripting must monitor developer usage shifts and plan allocations.
Brave browser adds email aliases to help users evade tracking
Brave browser version 1.94 has added an 'Email Aliases' feature, allowing users to automatically generate disposable email addresses when registering for new online services.
Key takeaways
- TerminalFix tricks users into running malicious PowerShell scripts via fake Cloudflare CAPTCHAs.
- Five critical vulnerabilities in WordPress plugins and themes enable site takeover and remote code execution.
- CVE-2026-76581 allows unauthenticated admin bypass on vulnerable WPMU DEV Dashboard installations up to version 5.0.1.
- Healthcare distribution giant McKesson disclosed a breach involving unauthorized third-party application access.
- Brave browser version 1.94 added built-in support for generating disposable email aliases.