All issues
Tech & Security Intelligence Issue 016 · 7 Sep 2026

The Weekly
Brief

A fake CAPTCHA that asks you to run the malware yourself. An emergency Chrome patch you only get if you restart. A Teams message from “Help Desk” that ends at your domain controller. And a Microsoft password deadline that just moved to November.

Paul, Director of Node-Red
Curated by Paul
Editor · Node-Red

4 stories · 7 min read

In this issue

01 Threat Alert

The fake CAPTCHA that asks you to run the malware yourself

On 2 September New Zealand’s National Cyber Security Centre issued an alert about a technique called ClickFix. A legitimate website gets compromised, and visitors are shown what looks like an ordinary CAPTCHA or Cloudflare Turnstile check — the same “verify you are human” box everyone clicks through a dozen times a week. Instead of a tick box, the page gives instructions: press a key combination, paste this line, press Enter. Do that and you have just run the attacker’s command on your own machine, typically installing an infostealer that empties saved browser passwords, session cookies and crypto wallets.

What makes it work is that nothing is exploited. There is no dodgy download, no macro warning, no certificate error — the victim performs the install by hand, so most of the controls people rely on never get a chance to fire. The NCSC’s advice is pointed squarely at website owners, because the delivery vehicle is somebody else’s hacked site and WordPress is the usual one: keep WordPress and every plugin updated, remove extensions you no longer use, put MFA and least privilege on admin logins, run file integrity monitoring and central logging, and — the step almost nobody takes — test your own site from different browsers, IP addresses and devices, because injected pages are commonly cloaked so the owner and the office never see them. If you find your site is serving these pages, take it offline, reset credentials, and get it remediated properly rather than just deleting the file.

02 Patch Now

Chrome shipped an emergency fix on Friday — check the number, not the tick

On 4 September Google released an out-of-band Chrome update for CVE-2026-85046, a type confusion flaw in V8 — the JavaScript engine at the heart of the browser. A crafted web page can use it to run code, and Google has confirmed that an exploit for it exists in the wild, which is the wording that means real attacks on real targets rather than a researcher’s proof of concept. The bug was reported on 4 August by researcher Salvatore Gulizia. The fixed builds are 152.0.7977.82/.83 on Windows and macOS and 152.0.7977.82 on Linux. The US cyber agency CISA added it to its Known Exploited Vulnerabilities catalogue the same day, giving federal agencies until 18 September to patch — a useful borrowed deadline if you want one.

The catch is how Chrome updates. It downloads the fix quietly in the background and then applies it on the next restart of the browser — and a great many people never restart Chrome. They close the laptop lid, open it in the morning, and the same session with forty tabs is still there, still running the vulnerable build, sometimes for weeks. Google also staggers the rollout, so “Chrome is up to date” on one machine does not mean the whole office is. And remember the rest of the family: Edge, Brave, Opera and Vivaldi are all built on Chromium and inherit V8, so each needs its own update from its own vendor. Edge in particular is the one that matters in most New Zealand offices, because it is the browser nobody chose and everybody uses.

03 Microsoft 365

“Hi, this is IT” — the Teams chat that ends at your domain controller

On 31 August Palo Alto Networks’ Unit 42 published research into a campaign it calls Spring Ring. Between January and April 2026 the attackers used external Microsoft Teams accounts, run from throwaway onmicrosoft.com tenants, to open chats with more than 150 employees across at least 10 organisations. They used 26 distinct identities with display names chosen to look like the internal service desk — “Help Desk”, “IT Assistance”, “Support Staff”. The chat is only the doorway. What follows quickly is a voice call inside Teams, which is why this is classed as vishing rather than phishing.

On the call the “technician” talks the employee through launching Quick Assist — a remote-control tool that ships with Windows — or downloading a legitimate, commercially licensed remote monitoring and management product. From the user’s side it looks exactly like being helped. From the network’s side it is an authorised remote session that no antivirus is going to object to, since the software is genuine. Some victims were also given a PowerShell-based remote access trojan. In the most serious variant Unit 42 followed, the attackers went further, attempting a PetitPotam coercion to make the domain controller authenticate to a machine they controlled, and relaying that authentication back — an NTLM relay aimed at domain-level privileges. Start to finish, no vulnerability was exploited and no password was stolen. It needed one employee to accept a chat from outside the organisation and stay on the call.

04 Microsoft

Microsoft moved the password-reset deadline. The work didn’t move with it.

A change to self-service password reset in Microsoft Entra ID — message centre item MC1325414 — was due to start biting this week. It has been pushed back roughly two months. Today, if a staff member’s mobile number or alternate email address happens to be sitting in their directory profile, self-service password reset can sometimes use it to verify them, even though the user never registered it as an authentication method. Microsoft is ending that. From the enforcement date, only methods the user has explicitly registered will count, and directory fields such as mobile phone, business phone and alternate email will no longer be accepted on their own.

The new dates: the registration campaign — which prompts users to register a method when they sign in — begins 5 October 2026, enforcement starts 7 November, and the act-by date is 9 November. Microsoft’s own figure is that roughly 86% of password reset verifications already use properly registered methods, so most tenants will notice nothing at all. It is the remaining slice that hurts, because of when those users find out: locked out of their account, in a hurry, trying to reset — and the mobile number their employer typed into their profile years ago quietly stops being accepted. The fix is unglamorous and takes an afternoon: audit registration coverage under Authentication methods in the Entra admin centre, turn the registration campaign on rather than waiting for it, and make sure whoever answers the phone has a verified way to identify a caller and reset them by hand.

Tip of the week

Decide who is allowed to message your staff on Teams — because right now the answer is “anyone”

Most Microsoft 365 tenants ship with external access wide open: any person with a Microsoft 365 account, in any organisation on earth, can start a Teams chat with any of your staff. Nobody chose that — it is simply the default, and it is the doorway the campaign in story three walked through. To change it: go to the Teams admin centre (admin.teams.microsoft.com) → UsersExternal access (on older tenants it sits under Org-wide settings → External access). Switch from allowing all external domains to allow only specific external domains, and list the ones you actually deal with — your accountant, your main suppliers, your biggest clients, your IT provider. Save, and allow a few hours for it to take effect. What this does not break: chats between your own staff, guests you have already invited into your Teams, ordinary email, or anyone you later add to the allow list. It is one of the rare security changes that is close to invisible to the people who work for you and closes a real door. Then do the half that no setting can do for you. Tell the whole team, in plain words, that nobody from IT — not us, not a supplier, not “Microsoft” — will ever ring or message out of the blue and ask them to start Quick Assist, install remote-access software, or read out a code. Agree what happens instead: hang up, and ring the number you already have, from your own contacts, never a number supplied during the call. Say explicitly that nobody will ever be in trouble for hanging up on a real technician. That single sentence is what makes people willing to do it — and it is the whole defence, because the attack in story three needed no software flaw at all, just one polite person who didn’t want to be rude.

Node-Red

Want all of this handled for you?

We keep an eye on the threats, the updates and the fine print so you don't have to. Book a free, no-obligation IT checkup.

Book your free IT checkup