Australia warns of global campaign targeting vulnerable CMS platforms
2026-07-11T19:23:28Z•1285cbd03b862bf2be9bdbc8b7d5aca576c2e1f200b6000e52f1a03535f8ff74
ACSCAI agentsCMS exploitationDocker imageGhostcommitGiteaHelix groupInjective SDKMFA abuse','Odido breach','insider sabotage','OpenMandriva','AI-ShareFileStorage Zone ControllerU-BootZimbraactive exploitationauthentication bypassbootloader vulnerabilitiescross-site scriptingcryptocurrency theftfirmware attacksimage-based attacknpm supply chainprogress softwareprompt injectionvishingwallet stealer
What happened
Multiple high-impact security developments: the Australian Cyber Security Centre warns of a global campaign exploiting vulnerable CMS platforms and plugins; researchers demonstrate 'Ghostcommit' — image-based prompt injection that can exfiltrate repo secrets via AI coding agents; six U-Boot bootloader vulnerabilities could enable stealthy firmware compromise; attackers are actively exploiting a critical authentication-bypass in the official Gitea Docker image to impersonate any user; Progress urges ShareFile Storage Zone Controller customers to shut down servers over a “credible” external risk
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 1285cbd03b862bf2be9bdbc8b7d5aca576c2e1f200b6000e52f1a03535f8ff74
- Enrichment time
- 2026-07-11T19:23:28Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.