Summary
Microsoft warns of a new malicious campaign called "TerminalFix" that uses compromised websites and fake Cloudflare CAPTCHAs to trick users into running malicious PowerShell commands. This campaign deploys a Python implant that creates encrypted reverse tunnels, giving attackers SOCKS5-style proxy access to internal networks for potential lateral movement.