:

FBI DIRECTOR'S APPAREL SITE HOSTS MALWARE ATTACK

SECURITY DESK1 MIN READ
SAT, MAY 23, 2026

■ AI-SUMMARIZED FROM 1 SOURCE ▸ TIMELINE

The Based Apparel website linked to FBI Director Kash Patel has been identified hosting a ClickFix malware attack, attempting to trick visitors into installing malicious software.

Security researchers discovered the attack vector on the e-commerce site, which uses social engineering tactics common to ClickFix campaigns. These attacks typically display fake system warnings or update prompts, deceiving users into downloading malware. ClickFix attacks have become increasingly prevalent in 2024, targeting Windows users through compromised websites and malicious ads. The malware often leads to ransomware infections or credential theft. The discovery raises questions about website security practices and third-party vulnerabilities. It's unclear whether the attack represents a compromise of the site's infrastructure or a supply chain issue. Based Apparel sells merchandise featuring political messaging. The incident highlights how high-profile websites remain attractive targets for attackers seeking to distribute malware at scale. No statement has been issued regarding the attack or remediation efforts.

■ SOURCES

Hacker News

■ SUMMARY WRITTEN BY AI FROM THE LINKS ABOVE

■ MORE FROM THE SECURITY DESK

Cybercriminals have transformed DDoS attacks into a polished, commercialized service complete with pricing tiers, customer support, and reseller programs. The DDoS-as-a-Service market has evolved from basic tools into sophisticated attack platforms.

9H AGOIndustry Desk

Microsoft faced backlash after threatening a security researcher with criminal investigation, reigniting debate over software vulnerability disclosure practices and corporate responsibility.

9H AGOSecurity Desk

Google is deploying Device Bound Session Credentials (DBSC) to all Chrome users, a security feature designed to prevent account takeovers by protecting session cookies from theft.

9H AGOIndustry Desk

Dutch authorities have dismantled a major botnet comprising 17 million infected devices and seized over 200 servers hosting the operation at a local provider.

9H AGOSecurity Desk

■ SUBSCRIBE TO THE DAILY BRIEF

ONE EMAIL, 5 STORIES, 06:00 UTC. UNSUBSCRIBE ANYTIME.