home.social

#captcha — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #captcha, aggregated by home.social.

fetched live
  1. A few additional samples and domains just for the sake of posterity:

    hxxps://trycap[.]dev -> paste.opensuse.org/pastes/15b4
    hxxps://inject.estrogen[.]delivery referenced multiple times from the js chain, accepts POST requests

    tl,dr; domains are in https://tiago[.]zip/cdn/widget.js redirects to https://tiago[.]zip/assets/widget.js and the pastebinned sample is in the previous reply.

    Seems sketch to me?

    #InfoSec #Privacy #Captcha

  2. Inside Multi-Stage Phishing Redirection Chains

    Recent investigations have uncovered sophisticated phishing campaigns employing multi-stage redirection chains that abuse trusted cloud infrastructure and newly registered domains. One campaign exploits Framer, a no-code web platform, combined with Cloudflare Workers to host deceptive landing pages. These pages utilize HTML redirection smuggling via the Blob API, Web Crypto API for decryption, and anti-debugging techniques to evade detection. Another campaign involves device code phishing targeting OneDrive credentials through three-stage redirections using newly registered domains with randomized alphanumeric strings. Both campaigns employ brand impersonation, custom CAPTCHA challenges, and anti-analysis measures including keyboard shortcut blocking. The threat actors leverage a hybrid infrastructure combining legitimate cloud services with short-lived domains to bypass traditional detection methods.

    Pulse ID: 6a7ce26b7815e336e5eee192
    Pulse Link: otx.alienvault.com/pulse/6a7ce
    Pulse Author: AlienVault
    Created: 2026-08-12 21:15:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #Cloud #CyberSecurity #EDR #HTML #InfoSec #OTX #OpenThreatExchange #Phishing #Rust #bot #AlienVault

  3. Inside Multi-Stage Phishing Redirection Chains

    Recent investigations have uncovered sophisticated phishing campaigns employing multi-stage redirection chains that abuse trusted cloud infrastructure and newly registered domains. One campaign exploits Framer, a no-code web platform, combined with Cloudflare Workers to host deceptive landing pages. These pages utilize HTML redirection smuggling via the Blob API, Web Crypto API for decryption, and anti-debugging techniques to evade detection. Another campaign involves device code phishing targeting OneDrive credentials through three-stage redirections using newly registered domains with randomized alphanumeric strings. Both campaigns employ brand impersonation, custom CAPTCHA challenges, and anti-analysis measures including keyboard shortcut blocking. The threat actors leverage a hybrid infrastructure combining legitimate cloud services with short-lived domains to bypass traditional detection methods.

    Pulse ID: 6a7ce26b7815e336e5eee192
    Pulse Link: otx.alienvault.com/pulse/6a7ce
    Pulse Author: AlienVault
    Created: 2026-08-12 21:15:23

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #Cloud #CyberSecurity #EDR #HTML #InfoSec #OTX #OpenThreatExchange #Phishing #Rust #bot #AlienVault

  4. Just spent five minutes logging in to a service because #CAPTCHA really wanted me to "select all squares with a vehicle". Apparently vehicles are alien to me. Just let me click on fire hydrants until there are none left.

  5. 🚔🔫 Oh, the joys of modern technology! One minute you're minding your own business, the next you're a #fugitive on the run from a rogue camera with a vendetta. Meanwhile, you're stuck in a #CAPTCHA loop from hell, wondering if you're a human or a bot. 🤖💫
    guessingheadlights.com/yall-fa #moderntechnology #roguecamera #loopfromhell #HackerNews #ngated

  6. 🚔🔫 Oh, the joys of modern technology! One minute you're minding your own business, the next you're a #fugitive on the run from a rogue camera with a vendetta. Meanwhile, you're stuck in a #CAPTCHA loop from hell, wondering if you're a human or a bot. 🤖💫
    guessingheadlights.com/yall-fa #moderntechnology #roguecamera #loopfromhell #HackerNews #ngated

  7. FYI: PatronView blocks Amazon's AI crawler after 117,000 daily page reads: Anthropic's crawler hit a 35,000 to 1 crawl ratio, and CAPTCHA solve rates measured just 0.24%. The findings show why small operators are locking down servers. ppc.land/patronview-blocks-ama #AI #WebSecurity #DataPrivacy #Crawling #CAPTCHA

  8. FYI: PatronView blocks Amazon's AI crawler after 117,000 daily page reads: Anthropic's crawler hit a 35,000 to 1 crawl ratio, and CAPTCHA solve rates measured just 0.24%. The findings show why small operators are locking down servers. ppc.land/patronview-blocks-ama #AI #WebSecurity #DataPrivacy #Crawling #CAPTCHA

  9. I fucking hate the enshitified #Tellows site because of the #CAPTCHA test I have to pass before I eat the "send" button.
    What the #zark is this?
    I want to report a number, why should I click all squares containing motorcycles?

    #enshitification

  10. I fucking hate the enshitified site because of the test I have to pass before I eat the "send" button.
    What the is this?
    I want to report a number, why should I click all squares containing motorcycles?

  11. Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam

    Pulse ID: 6a7951aad7b05814243eb26a
    Pulse Link: otx.alienvault.com/pulse/6a795
    Pulse Author: Tr1sa111
    Created: 2026-08-10 04:20:58

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #CyberSecurity #InfoSec #Mac #Malware #OTX #OpenThreatExchange #bot #Tr1sa111

  12. Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam

    Pulse ID: 6a7951aad7b05814243eb26a
    Pulse Link: otx.alienvault.com/pulse/6a795
    Pulse Author: Tr1sa111
    Created: 2026-08-10 04:20:58

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #CyberSecurity #InfoSec #Mac #Malware #OTX #OpenThreatExchange #bot #Tr1sa111

  13. eeEhello #python users of #pypi, or rather, devs!
    i have a question.
    could someone help me with the captcha?
    i'm trying to upload a project, github.com/averlice/mclient to the directory.
    problem is, when i go to register, it wants a stupid #captcha using #hcaptcha and i need help!
    if anyone could do this, that would be great!

  14. eeEhello #python users of #pypi, or rather, devs!
    i have a question.
    could someone help me with the captcha?
    i'm trying to upload a project, github.com/averlice/mclient to the directory.
    problem is, when i go to register, it wants a stupid #captcha using #hcaptcha and i need help!
    if anyone could do this, that would be great!

  15. ICYMI: PatronView blocks Amazon's AI crawler after 117,000 daily page reads: Anthropic's crawler hit a 35,000 to 1 crawl ratio, and CAPTCHA solve rates measured just 0.24%. The findings show why small operators are locking down servers. ppc.land/patronview-blocks-ama #AI #Crawler #WebSecurity #CAPTCHA #DataPrivacy

  16. ICYMI: PatronView blocks Amazon's AI crawler after 117,000 daily page reads: Anthropic's crawler hit a 35,000 to 1 crawl ratio, and CAPTCHA solve rates measured just 0.24%. The findings show why small operators are locking down servers. ppc.land/patronview-blocks-ama #AI #Crawler #WebSecurity #CAPTCHA #DataPrivacy

  17. 🚀🤖 Oh, look! Bloomberg's #CAPTCHA is more concerned with verifying #humanity than addressing a tragic issue in cyber command. Meanwhile, soldiers grapple with real crises while Bloomberg grapples with keeping its digital gates secure. 🤦‍♂️🔒
    bloomberg.com/news/articles/20 #CyberSecurity #DigitalGates #MilitaryCrisis #HackerNews #ngated

  18. 🚀🤖 Oh, look! Bloomberg's #CAPTCHA is more concerned with verifying #humanity than addressing a tragic issue in cyber command. Meanwhile, soldiers grapple with real crises while Bloomberg grapples with keeping its digital gates secure. 🤦‍♂️🔒
    bloomberg.com/news/articles/20 #CyberSecurity #DigitalGates #MilitaryCrisis #HackerNews #ngated

  19. RE: mstdn.social/@emkingma/1170585

    This.

    . . . and the #accessibility #cookie. It's apparently too difficult to make a #CAPTCHA with #audio, so can we give you a special cookie so we (and lots of other #websites) stop asking you to try to see.

  20. I went looking for Terminator memes for a different purpose but had to post this.
    #Terminator #Captcha

  21. I went looking for Terminator memes for a different purpose but had to post this.
    #Terminator #Captcha

  22. Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam

    A sophisticated macOS malware campaign leverages ClickFix social engineering to infect victims. The attack begins with a fake CAPTCHA prompt delivered via email links, tricking users into executing malicious commands in Terminal. This downloads a profiling script that collects system information and deploys architecture-specific Go-based Mach-O payloads. The stealer targets browser passwords, Apple Keychain credentials, and cryptocurrency wallets. Its most notable feature is a DRAIN function that gradually siphons cryptocurrency from victims' wallets by redirecting portions to attacker-controlled accounts. The malware supports Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. Infrastructure analysis reveals hosting through Aeza Group, a sanctioned Russian bulletproof hosting provider. The malware achieves persistence through macOS Background Task Management and uses various evasion techniques including Gatekeeper bypass and credential harvesting via fake system prompts.

    Pulse ID: 6a74c5ff523b6fcb70f5711d
    Pulse Link: otx.alienvault.com/pulse/6a74c
    Pulse Author: AlienVault
    Created: 2026-08-06 17:35:59

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BitCoin #Browser #CAPTCHA #CredentialHarvesting #CyberSecurity #Email #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #Password #Passwords #Russia #SocialEngineering #Troll #Word #bot #cryptocurrency #AlienVault

  23. Mac Malware Drains Crypto Wallets Via Fake CAPTCHA Scam

    A sophisticated macOS malware campaign leverages ClickFix social engineering to infect victims. The attack begins with a fake CAPTCHA prompt delivered via email links, tricking users into executing malicious commands in Terminal. This downloads a profiling script that collects system information and deploys architecture-specific Go-based Mach-O payloads. The stealer targets browser passwords, Apple Keychain credentials, and cryptocurrency wallets. Its most notable feature is a DRAIN function that gradually siphons cryptocurrency from victims' wallets by redirecting portions to attacker-controlled accounts. The malware supports Bitcoin, Litecoin, Dogecoin, Monero, Ethereum, and XRP. Infrastructure analysis reveals hosting through Aeza Group, a sanctioned Russian bulletproof hosting provider. The malware achieves persistence through macOS Background Task Management and uses various evasion techniques including Gatekeeper bypass and credential harvesting via fake system prompts.

    Pulse ID: 6a74c5ff523b6fcb70f5711d
    Pulse Link: otx.alienvault.com/pulse/6a74c
    Pulse Author: AlienVault
    Created: 2026-08-06 17:35:59

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #BitCoin #Browser #CAPTCHA #CredentialHarvesting #CyberSecurity #Email #InfoSec #Mac #MacOS #Malware #OTX #OpenThreatExchange #Password #Passwords #Russia #SocialEngineering #Troll #Word #bot #cryptocurrency #AlienVault

  24. Fake CAPTCHA, Real Business: Traffic Distribution for Hire

    A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines.

    Pulse ID: 6a734a570822e0edf4d1fdb5
    Pulse Link: otx.alienvault.com/pulse/6a734
    Pulse Author: AlienVault
    Created: 2026-08-05 14:36:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #CDN #CyberSecurity #Endpoint #Google #InfoSec #OTX #OpenThreatExchange #PDF #RAT #SMS #bot #AlienVault

  25. Fake CAPTCHA, Real Business: Traffic Distribution for Hire

    A sophisticated traffic distribution system has been operating for over 14 months, using more than 12,700 structurally similar fake CAPTCHA PDFs hosted on Webflow's CDN. The operation begins with search engine optimization, where victims searching for legitimate content encounter malicious PDFs through Google searches. These documents contain fake CAPTCHA panels that route users through a custom Elixir/Phoenix traffic distribution system employing IP filtering, bot detection, and geographic targeting. The infrastructure sorts visitors and redirects qualifying traffic to three distinct endpoints: Legion Loader distribution, a TDS reseller gate, and premium-SMS subscription scams targeting Spanish-speaking users. Non-qualifying traffic is monetized through search-arbitrage advertising. The operation primarily targets English-speaking countries and has recently been surfaced by AI assistants including Google Gemini and Claude, expanding its reach beyond traditional search engines.

    Pulse ID: 6a734a570822e0edf4d1fdb5
    Pulse Link: otx.alienvault.com/pulse/6a734
    Pulse Author: AlienVault
    Created: 2026-08-05 14:36:07

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #CAPTCHA #CDN #CyberSecurity #Endpoint #Google #InfoSec #OTX #OpenThreatExchange #PDF #RAT #SMS #bot #AlienVault

  26. 🚨 #AI BREAKING NEWS! 🚨 In an astonishing turn of events, the digital gatekeepers at #OpenReview have decided that even computers must verify their existence before accessing the sacred halls of Open Peer Review. 🤖🔒 Because, clearly, nothing screams "cutting-edge research" like #CAPTCHA tests for #LLMs. 😂🔍
    openreview.net/challenge?redir #News #PeerReview #HackerNews #ngated

  27. 🚨 #AI BREAKING NEWS! 🚨 In an astonishing turn of events, the digital gatekeepers at #OpenReview have decided that even computers must verify their existence before accessing the sacred halls of Open Peer Review. 🤖🔒 Because, clearly, nothing screams "cutting-edge research" like #CAPTCHA tests for #LLMs. 😂🔍
    openreview.net/challenge?redir #News #PeerReview #HackerNews #ngated

  28. 🚫🤖 Ah, the wonders of modern technology! Learn all about the pneumatic genius of Hero of Alexandria—if you can bypass the digital bouncer that thinks you're a cyber-villain for daring to click a link. 🕵️‍♂️🔍 Just another day on the internet, where the only hero is the #CAPTCHA. 🛡️💻
    thehopkinthomasproject.com/The #moderntechnology #pneumaticgenius #HeroofAlexandria #internetsecurity #HackerNews #ngated

  29. 🚫🤖 Ah, the wonders of modern technology! Learn all about the pneumatic genius of Hero of Alexandria—if you can bypass the digital bouncer that thinks you're a cyber-villain for daring to click a link. 🕵️‍♂️🔍 Just another day on the internet, where the only hero is the #CAPTCHA. 🛡️💻
    thehopkinthomasproject.com/The #moderntechnology #pneumaticgenius #HeroofAlexandria #internetsecurity #HackerNews #ngated

  30. Get your shit together CloudFlare!! It's been broken on Firefox for like 3 weeks now. I can't log in to any sites using CloudFlare captcha.

    It forces me to switch to Chromium every time I hit this wall. To have such a crucial piece of the web broken for this long on a major browser is insanity to me as a developer.

    The general drop in software quality over the last 3 years is unacceptable. Hire more QA people and quit relying exclusively on automation you fools!

    #cloudflare #web #www #captcha

  31. RT @rustybrick: TRANSLASATION: Google Search testet, ob Suchende sich anmelden müssen, um zu verifizieren, dass sie Menschen sind, und um mehr Suchergebnisse zu sehen (nicht nur ein Captcha). seroundtable.com/google-search via @iKamleshShukla

    mehr auf Arint.info

    #Captcha #DigitalMarketing #GoogleSearch #HumanVerification #SearchEngine #SEO #arint_info

    https://x.com/rustybrick/status/2084238097089224777#m

  32. RT @rustybrick: TRANSLASATION: Google Search testet, ob Suchende sich anmelden müssen, um zu verifizieren, dass sie Menschen sind, und um mehr Suchergebnisse zu sehen (nicht nur ein Captcha). seroundtable.com/google-search via @iKamleshShukla

    mehr auf Arint.info

    #Captcha #DigitalMarketing #GoogleSearch #HumanVerification #SearchEngine #SEO #arint_info

    https://x.com/rustybrick/status/2084238097089224777#m

  33. Как мы делали доступными 37 госсайтов: грабли, скринридеры и никакой горизонтальной прокрутки

    Уже более 10 лет мы сопровождаем Единый официальный сайт органов власти Ханты-Мансийского автономного округа — Югры ( admhmao.ru , далее – сайт), в структуру которого входят ещё 36 сайтов органов власти округа. За это время требования к доступности государственных сайтов несколько раз менялись. В этой статье мы рассказываем, как выполняли требования законодательства о доступности сайта для инвалидов по зрению, хотя между собой называем это просто «доступностью»: читать мелкий серый текст на белом фоне не любит никто. Покажем на реальном госпроекте, какие грабли ждут команду, когда большой legacy-сайт приводят к современным требованиям доступности. Большинство рекомендаций пригодятся при разработке любого сайта, не только государственного.

    habr.com/ru/articles/1066092/

    #Accessibility #госсайт #доступность #слабовидящие #скринридер #ITФорум #ARIA #HTML #тестирование #CAPTCHA

  34. 🎉Bravo, Bloomberg! You've ingeniously transformed a tech marvel into a #CAPTCHA challenge.🤖 Who needs details on a 20k Nvidia chip cluster when you can provide riveting insights into browser settings and cookie policies instead? 🍪✨
    bloomberg.com/news/articles/20 #Bloomberg #Innovation #TechChallenge #BrowserSettings #CookiePolicy #HackerNews #ngated

  35. 🎉Bravo, Bloomberg! You've ingeniously transformed a tech marvel into a #CAPTCHA challenge.🤖 Who needs details on a 20k Nvidia chip cluster when you can provide riveting insights into browser settings and cookie policies instead? 🍪✨
    bloomberg.com/news/articles/20 #Bloomberg #Innovation #TechChallenge #BrowserSettings #CookiePolicy #HackerNews #ngated

  36. Mercredi confession : dans un moment de désarroi, j’ai tenté de mettre à jour mon moyen de paiement #Spotify. Sans succès : sur la page de connexion à mon compte, impossible de passer le Google #Captcha (deux tentatives d’une vingtaine [!] de puzzles, soldées par une erreur serveur).

    Ayé, j’ai suffisamment la gniarre pour passer à #BandCamp + #Qobuz.

    Les caquètements du Grand Palmipède sont parfois mystérieux, mais toujours pertinents.

  37. Mercredi confession : dans un moment de désarroi, j’ai tenté de mettre à jour mon moyen de paiement #Spotify. Sans succès : sur la page de connexion à mon compte, impossible de passer le Google #Captcha (deux tentatives d’une vingtaine [!] de puzzles, soldées par une erreur serveur).

    Ayé, j’ai suffisamment la gniarre pour passer à #BandCamp + #Qobuz.

    Les caquètements du Grand Palmipède sont parfois mystérieux, mais toujours pertinents.

  38. C'est curieux, ces derniers temps je tombe toujours sur le même CAPTCHA audio, l'extrait "je fais, tu", alors que jusque là je pouvais tomber sur des extraits en n'importe quelle langue. Les deux situations me semblent absurdes, mais bon j'ai entendu que de nos jours les CAPTCHA analysaient plutôt le comportement que la réponse. #captcha #audio #a11y

  39. C'est curieux, ces derniers temps je tombe toujours sur le même CAPTCHA audio, l'extrait "je fais, tu", alors que jusque là je pouvais tomber sur des extraits en n'importe quelle langue. Les deux situations me semblent absurdes, mais bon j'ai entendu que de nos jours les CAPTCHA analysaient plutôt le comportement que la réponse. #captcha #audio #a11y

  40. Email threat landscape: Q2 2026 trends and insights

    During Q2 2026, Microsoft detected approximately 7.6 billion email-based phishing threats, with monthly volumes declining from 2.7 billion in April to 2.4 billion in June. The quarter was significantly shaped by the downstream effects of Microsoft's Digital Crimes Unit disruption of the Tycoon2FA phishing-as-a-service platform in March, resulting in a 92% decline in associated phishing volume. QR code phishing attacks peaked at 18.7 monthly attacks in March before declining 48% by June, while CAPTCHA-gated phishing fell 81% from its March high. Credential phishing remained the dominant objective, accounting for 94-96% of all payload-based attacks. Business email compromise activity returned to historical norms after an anomalous April surge. Microsoft Teams-based threats grew substantially, with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by quarter end.

    Pulse ID: 6a6241aa79fc3235d84045f9
    Pulse Link: otx.alienvault.com/pulse/6a624
    Pulse Author: AlienVault
    Created: 2026-07-23 16:30:34

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #2FA #CAPTCHA #CyberSecurity #Email #InfoSec #Microsoft #MicrosoftTeams #OTX #OpenThreatExchange #Phishing #bot #AlienVault

  41. En fin. Se habla de los #captcha y como han sido utilizados para entrenar a algoritmos para estas inteligencias fingidas que necesitan ingentes cantidades de repeticiones humanas para "detectar" el patrón humano al identificar, por ejemplo, una bicicleta.

    Estas corpos hacen y deshacen a su antojo. Nos usan como quieren. Son unos ladrones.

  42. Inside a Global Procurement-Themed AiTM Phishing Campaign

    A sophisticated adversary-in-the-middle phishing campaign is targeting universities, enterprises, and multinational institutions including EU and UN agencies. Active since May 2026, the operation leverages compromised organizational email accounts to distribute procurement-themed lures that mimic requests for information, bid invitations, and project documentation. Victims are redirected through fake document portals, CAPTCHA verification stages, and cloned authentication pages impersonating Microsoft, OpenGov, and financial institutions. The attacker rotates between multiple AiTM phishing kits including EvilProxy, FlowerStorm, and Kali365 to intercept MFA-protected sessions in real time, capturing session tokens and cookies to establish authenticated access. Rather than using newly registered domains, the actor compromises aged domains that have been dormant for years, injecting PHP files to host phishing infrastructure and evade detection through domain reputation systems.

    Pulse ID: 6a6015d87a94549d768bc929
    Pulse Link: otx.alienvault.com/pulse/6a601
    Pulse Author: AlienVault
    Created: 2026-07-22 00:59:04

    Be advised, this data is unverified and should be considered preliminary. Always do further verification.

    #AdversaryInTheMiddle #AitM #CAPTCHA #Cookies #CyberSecurity #EU #Email #InfoSec #MFA #Microsoft #Mimic #OTX #OpenThreatExchange #PHP #Phishing #Proxy #RAT #RCE #bot #AlienVault