Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
2026-09-06T07:23:22Z•0ac53c101f1e42819b5fb0ec6921b946fba791c544b9a6880a1c1e2831437af8
CVE-2026-19490AI securityArubaOS-CXCitrix NetScalerClickFixCrowdStrike FalconGoogle ChromeTerraformV8active exploitationauthentication bypassavailability outageblockchaincredential theftdata breachmalware deliverypasskeysphishingprivilege escalationremote code executionsupply-chain compromiseweb compromisezero-day
What happened
BleepingComputer reports a broad set of September 2026 cybersecurity developments, including a large ClickFix campaign using more than 5,400 compromised websites and blockchain-hosted payloads, exploitation of a critical Citrix NetScaler authentication bypass (CVE-2026-19490), an actively exploited Chrome zero-day, a CrowdStrike Falcon privilege-escalation zero-day, a supply-chain compromise delivering malicious Terraform modules, and critical ArubaOS-CX remote-code-execution remediation. The feed also covers alleged major data breaches, passkey attack research, AI incidents, and service or IT
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 0ac53c101f1e42819b5fb0ec6921b946fba791c544b9a6880a1c1e2831437af8
- Enrichment time
- 2026-09-06T07:23:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.