Sep 9, 2026 · 27 min · 8 segments
Ah, the crisp fall air, brand-new books and backpacks, and the quiet irony of cybercriminals turning on each other to steal a few extra bucks. Security Engineer Sean Gallagher joins Amy to break down…
Sean GallagherGuest
Amy CiminnisiHost
Welcome to the Talos Takes podcast, where we discuss Talos' latest research and security news.

We've all heard about the click fix social engineering scheme, where users are tricked into running malicious commands on their machines so that actors can gain their initial access.

But the threat actors behind a new scheme have moved the playing field entirely.

Instead of targeting the operating system, they're going straight for the browser session.

They're using a mix of social engineering and some really creative abuse of the Google visualization API to turn a user's own browser against them.

So to help us understand exactly how this works, why it could be so hard to catch in the future, and what security practitioners need to do to stay ahead of it, I am joined today by security engineer Sean Gallagher, who has been leading the research on this campaign.

Can you start by explaining how this click fix variation differs from the traditional malware delivery that most people are used to, and why this focus has shifted?
Read the full transcript.
Create an account to read the whole episode, search across every transcript, and follow the shows you care about.