Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
2026-06-02T01:23:29Z•0ee339b499f04b24b8fed15ea9478bb5139257ba536b2ed156f4185bcac58d67
C2CIFSwitchCVE-2026-0257ClickFixDashlaneDriveSurgeFakeUpdateGlobalProtectLinux LPEMFA-outageMiasmaMicrosoft outage','doxing','data-leak'NetlogonPaloAltoRedHatShai-HuludSteam CommunityWP Maps ProWindows RCEWordPressbrute-forcecredential-stealermalware-distributionnpmsupply-chain
What happened
Multiple active campaigns and exploited vulnerabilities were reported: a threat actor called DriveSurge is hijacking thousands of sites to deliver ClickFix and FakeUpdate malware; over 30 Red Hat npm packages were backdoored to deliver a new Shai‑Hulud credential stealer variant dubbed “Miasma”; WordPress sites (including via WP Maps Pro) and ~2,000 sites were abused to hide malware/C2 (Steam profile comments); ChatGPT share links were abused to host fake outage pages delivering malware; and a critical Windows Netlogon RCE is being exploited in the wild. Security incidents, outages, and auth/M
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 0ee339b499f04b24b8fed15ea9478bb5139257ba536b2ed156f4185bcac58d67
- Enrichment time
- 2026-06-02T01:23:29Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.