Placeholder domain used in dev docs now serves ClickFix attacks

2026-09-24T07:23:21Z•00760edb5351750b4b5ea5ba491876392e633389ffd3242026b97d4df33068b2
CVE-2026-85102CVE-2026-87902Android-malwareClickFixGoogle-CloudKubernetesMFAPowerShellVPNWordPressactive-exploitationbanking-trojancredential-theftcredit-card-theftcritical-infrastructuredata-breachmalvertisingnetwork-appliancephishingprivilege-escalationransomwareremote-code-executionthreat-actorsweb-skimmingzero-day

What happened

A BleepingComputer security-news feed covering active exploitation of enterprise and internet-facing vulnerabilities, ClickFix phishing, Android banking malware, web skimming, cloud and Kubernetes privilege escalation, ransomware, data breaches, and threat-actor claims. Multiple reports describe zero-days or critical flaws under active exploitation, including Check Point Security Gateway, WordPress, VeloCloud Orchestrator, F5 BIG-IP APM, Zyxel devices, and an alleged Oracle PeopleSoft vulnerability.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
00760edb5351750b4b5ea5ba491876392e633389ffd3242026b97d4df33068b2
Enrichment time
2026-09-24T07:23:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.