A critical alert has been issued regarding seven active exploits detected today, including vulnerabilities in BerriAI LiteLLM and Kludex Starlette among others. The primary focus is on an identified TerminalFix campaign, which employs fake Cloudflare CAPTCHA prompts to trick users into executing malicious commands in Windows Terminal, creating a multi-stage attack.
This infiltration technique allows attackers to establish a reverse tunnel into enterprise networks, enabling extensive system reconnaissance and potential privilege escalation. Mitigation strategies recommend monitoring for unauthorized PowerShell usage and restricting script execution permissions.