澳大利亚信号局本周发布警告,指出诈骗分子正利用虚假CAPTCHA对澳大利亚用户实施欺诈,案件数量"现已以百万计"1。这类诈骗通过诱导用户在终端粘贴恶意脚本1,绕过反恶意软件保护系统1。黑客可获得对受害者设备和浏览器会话信息的访问权限1。
UNSW计算机科学学院高级讲师Hammond Pearce指出,AI代理使用数量的增加导致了CAPTCHA验证使用的激增1。专家建议用户对要求输入内容或离开窗口的CAPTCHA保持警惕1。
Australian authorities have raised alarm over a rapidly proliferating fraud scheme exploiting fake CAPTCHA verification systems to compromise users' devices. The Signal Bureau issued a warning this week alerting the public to the threat, which now affects millions of Australians 1.
The scam operates by deceiving users into pasting malicious scripts into their terminal or command line, a tactic that circumvents standard antimalware protections 1. Once users comply, attackers gain access to sensitive device and browser session information 1. According to Hammond Pearce, a senior lecturer in computer science at UNSW, the proliferation of such scams is linked to the surge in CAPTCHA usage driven by increased deployment of AI agents 1.
Security experts warn users to exercise immediate caution if a CAPTCHA prompts them to enter text or directs them to leave the browser window 1. These anomalous requests represent a critical red flag for potential fraud 1.
评论
还没有评论,欢迎留下第一条。