CRITICALAdvisorySep 26, 2026
Action required
Hunt for suspicious clipboard activity and script execution from PowerShell/cmd.exe following user interactions with web browsers. Monitor for process creation from these shells with command-line arguments containing encoded payloads, Base64 strings, or suspicious download commands. Check endpoint logs for paste operations into system consoles within 5 minutes of browser activity.
Affected products
CloudflareWordPressTelegramSteamMicrosoft Defender
Linked articles