Placeholder domain used in dev docs now serves ClickFix attacks
2026-09-24T07:23:21Z•00760edb5351750b4b5ea5ba491876392e633389ffd3242026b97d4df33068b2
CVE-2026-85102CVE-2026-87902Android-malwareClickFixGoogle-CloudKubernetesMFAPowerShellVPNWordPressactive-exploitationbanking-trojancredential-theftcredit-card-theftcritical-infrastructuredata-breachmalvertisingnetwork-appliancephishingprivilege-escalationransomwareremote-code-executionthreat-actorsweb-skimmingzero-day
What happened
A BleepingComputer security-news feed covering active exploitation of enterprise and internet-facing vulnerabilities, ClickFix phishing, Android banking malware, web skimming, cloud and Kubernetes privilege escalation, ransomware, data breaches, and threat-actor claims. Multiple reports describe zero-days or critical flaws under active exploitation, including Check Point Security Gateway, WordPress, VeloCloud Orchestrator, F5 BIG-IP APM, Zyxel devices, and an alleged Oracle PeopleSoft vulnerability.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 00760edb5351750b4b5ea5ba491876392e633389ffd3242026b97d4df33068b2
- Enrichment time
- 2026-09-24T07:23:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.