I'm not a security pro, but the claim about "spun clickbait" doesn't hold for me. I thought it was new to me, and an attack possibility that I hadn't considered before reading. I do think I "validate" sites pretty well before doing any serious things there (logins, transactions, etc).
You're correct that it's not clickbait. This author is a known security researcher who specializes in this type of thing. It's just another type of attack that they've writing about.