Free practical cybersecurity guidance for organisations without a security team.
hello@actionsoncyber.com

Daily SMB Cyber Intelligence Brief

Today’s SME lookout: fake “Cloudflare CAPTCHA” pages telling staff to run a command

What small and medium-sized businesses should look out for today.

High Sunday 30 August 2026, 13:52 UK time
Today’s look-out: Phishing and fake verification prompts leading to device takeover

What to look out for today

Watch for fake “Cloudflare CAPTCHA” or “verify you’re human” pages that instruct staff to copy and paste something into Windows Terminal or PowerShell. This is a social engineering trick (a ClickFix-style variant) designed to get a user to run a malicious command themselves.

Why this matters to smaller businesses

SMEs rely on staff getting on with work quickly. A convincing “verification” page can appear during normal browsing, when accessing supplier portals, or after clicking a link in an email/chat. If a staff member runs a command, attackers may gain remote access, leading to stolen passwords, email account takeover, invoice fraud, and potentially ransomware disruption.

Warning signs

  • A web page (especially branded like Cloudflare) that says you must open Windows Terminal/PowerShell to continue.
  • Instructions to copy/paste text into a terminal “to verify” or “to fix a security check”.
  • Unexpected prompts appearing after clicking a link from an email, social media, or a chat message.
  • Staff reporting “a security check is blocking me” and asking for urgent help to bypass it.

How attackers may exploit the situation

  • They lure staff to a malicious page (via email, ads, search results, or compromised websites) and get them to run a command that installs or enables remote access.
  • Once on a device, they may move quickly to steal saved browser passwords, access email, or pivot to shared drives and cloud services.
  • They can use that foothold to request payment changes, send internal phishing from a real mailbox, or disrupt operations.

What to do today

  • Send a short staff alert: “Never paste commands into Terminal/PowerShell because a website tells you to.”
  • Update your helpdesk script: if someone reports a CAPTCHA telling them to run commands, treat it as a suspected compromise and escalate.
  • Review who has local admin rights and reduce where possible (these attacks are more damaging with elevated permissions).
  • Make sure MFA is enabled on email and key SaaS tools to reduce impact if credentials are stolen.

Ask your IT provider

  • Do we have monitoring that flags unusual PowerShell/Terminal activity on user PCs?
  • Can we block or warn on “paste-and-run” style attacks (web filtering, endpoint controls, application control)?
  • If a user ran a command from a web page, what’s our first-hour response (isolation, log review, password resets)?

Patch watch - only one short paragraph, and only if relevant

Separately, PaperCut has issued another emergency update after initial fixes were bypassed. If your organisation uses PaperCut for print management (common in schools and offices), confirm with your IT provider that you’re on the latest emergency release and that any internet exposure is reviewed.

One action today

Message staff today: “If a website tells you to open Terminal/PowerShell and paste a command to ‘verify’, stop and report it to IT immediately.”

Related Actions On Cyber resource

Actions On Cyber: Phishing & suspicious link reporting checklist (staff quick guide)

Sources

This brief is for general awareness and does not replace advice from your IT provider, legal adviser, insurer or incident response specialist.