• Forging Trust
  • Posts
  • The Value of Compliance + ClickFix Dominates Malware Delivery

The Value of Compliance + ClickFix Dominates Malware Delivery

IT channel and business news with a focus on regulatory compliance.

🚨 ClickFix Is Winning Right Now. MSPs Need to Treat It Like a Tier-1 Delivery Threat.

ClickFix has become one of the most common malware delivery methods in 2026 because it bypasses the normal technical choke points MSPs rely on and instead turns end users into the execution mechanism. Recent reporting indicates the technique dominated malware delivery in the March-May 2026 period and should no longer be treated as an emerging tactic or edge-case curiosity…

🎙️ Podcast: Security questionnaires are not the finish line…

…they are the opening move in a negotiation, and saying “yes” to everything can create a bigger problem than admitting what is still in progress.

In this episode of Get NIST-y, the cybersecurity and compliance podcast from Blacksmith InfoSec, Jared and Michael talk about turning evidence collection into a recurring habit instead of a Friday afternoon panic spiral.

đź’˛Turning Red Tape into Client Value

Most MSPs talk about security as a way to “keep you safe.” That’s fine, but it misses the reason your clients are suddenly paying attention to compliance: their ability to win business, keep contracts, and stay insurable now depends on being able to prove they’re safe to work with. Compliance frameworks are not just about surviving audits — they’re tools for making trust visible and repeatable.…

⚠️ Threat Updates

đź”´ Veil#Drop Fileless Blogspot Chain Deploys PureLog Infostealer In Memory (07/01/26)

Threat researchers have detailed a new campaign dubbed Veil#Drop that abuses compromised websites, Windows Script Host, and Google’s Blogspot platform to deliver the PureLog Stealer entirely in memory, leaving few artifacts on disk for traditional antivirus to catch. The attack begins when a victim opens what looks like a PDF but is actually a script; that script launches PowerShell with security checks disabled, then pulls multiple XOR‑encoded stages from attacker‑controlled Blogspot pages and reconstructs .NET assemblies directly in memory. MSPs should treat any unexpected “document” that triggers script execution as suspicious, monitor for PowerShell reaching out to Blogspot and spawning LOLBINs, tighten controls around Windows Script Host, and implement strong credential hygiene and token revocation workflows to reduce the blast radius when infostealers like PureLog land. » More Info

đź”´ InfernoGrabber AI-Built Browser Ransomware Abuses Chromium File System Access API (07/01/26)

Check Point researchers have analyzed a Python Flask application, InfernoGrabber v9.0, generated by the DeepSeek LLM that turns a fake “Discord avatar AI upscaler” website into a combined infostealer and browser‑native ransomware toolkit, running entirely inside Chromium‑based browsers on Windows and Android. Organizations and MSPs should respond by hardening the delivery layer (especially Chromium‑based browsers), treating every file‑access prompt as a security decision, limiting which devices and users can grant browser file system access, and monitoring for suspicious use of the File System Access API alongside aggressive credential and token hygiene to blunt the impact of any AI‑generated infostealer components. » More Info

🗨️ Parting Words

"I choose a lazy person to do a hard job, because a lazy person will find an easy way to do it." — Bill Gates

Find the Blacksmith Team…

…on demand with 
Get NIST-y on Spotify!

Are you a vCISO or MSP looking to operationalize security programs? Let’s discuss how Blacksmith Infosec proves that compliance is an opportunity, not a struggle that has to be packaged in FUD!