Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

2026-09-06T07:23:22Z0ac53c101f1e42819b5fb0ec6921b946fba791c544b9a6880a1c1e2831437af8
CVE-2026-19490AI securityArubaOS-CXCitrix NetScalerClickFixCrowdStrike FalconGoogle ChromeTerraformV8active exploitationauthentication bypassavailability outageblockchaincredential theftdata breachmalware deliverypasskeysphishingprivilege escalationremote code executionsupply-chain compromiseweb compromisezero-day

What happened

BleepingComputer reports a broad set of September 2026 cybersecurity developments, including a large ClickFix campaign using more than 5,400 compromised websites and blockchain-hosted payloads, exploitation of a critical Citrix NetScaler authentication bypass (CVE-2026-19490), an actively exploited Chrome zero-day, a CrowdStrike Falcon privilege-escalation zero-day, a supply-chain compromise delivering malicious Terraform modules, and critical ArubaOS-CX remote-code-execution remediation. The feed also covers alleged major data breaches, passkey attack research, AI incidents, and service or IT

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
0ac53c101f1e42819b5fb0ec6921b946fba791c544b9a6880a1c1e2831437af8
Enrichment time
2026-09-06T07:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.