Australia warns of global campaign targeting vulnerable CMS platforms

2026-07-11T19:23:28Z1285cbd03b862bf2be9bdbc8b7d5aca576c2e1f200b6000e52f1a03535f8ff74
ACSCAI agentsCMS exploitationDocker imageGhostcommitGiteaHelix groupInjective SDKMFA abuse','Odido breach','insider sabotage','OpenMandriva','AI-ShareFileStorage Zone ControllerU-BootZimbraactive exploitationauthentication bypassbootloader vulnerabilitiescross-site scriptingcryptocurrency theftfirmware attacksimage-based attacknpm supply chainprogress softwareprompt injectionvishingwallet stealer

What happened

Multiple high-impact security developments: the Australian Cyber Security Centre warns of a global campaign exploiting vulnerable CMS platforms and plugins; researchers demonstrate 'Ghostcommit' — image-based prompt injection that can exfiltrate repo secrets via AI coding agents; six U-Boot bootloader vulnerabilities could enable stealthy firmware compromise; attackers are actively exploiting a critical authentication-bypass in the official Gitea Docker image to impersonate any user; Progress urges ShareFile Storage Zone Controller customers to shut down servers over a “credible” external risk

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
1285cbd03b862bf2be9bdbc8b7d5aca576c2e1f200b6000e52f1a03535f8ff74
Enrichment time
2026-07-11T19:23:28Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Australia warns of global campaign targeting vulnerable CMS platforms · Baitaphish