Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
2026-05-24T19:23:33Z•1599e30ead538463646d2ea7c2f5034eef7caaf4728007c3311ac43470270397
CVE-2026-26980Chromium RCE leakCisco Secure WorkloadClickFixDrupalGhost CMSJFMBackdoorKimWolf botnetLaravel LangSQL injectionShowboatTrend MicroUbiquiti UniFi OScredential stealercrypto drainermalwarepiracy/CINEMAGOALsupply chaintelco espionagezero-day
What happened
This collection of stories describes multiple high-impact active threats and supply-chain incidents: a large-scale campaign exploiting a critical Ghost CMS SQL injection (CVE-2026-26980) to inject JavaScript and drive ClickFix attack flows; a Laravel Lang package supply-chain compromise distributing credential-stealing malware via abused GitHub tags/Composer; Trend Micro warning of an Apex One zero-day used in Windows attacks; and reports of Drupal SQLi, Ubiquiti UniFi OS, and Cisco Secure Workload maximum-severity flaws being patched or actively targeted. Other notable items include law-enfor
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 1599e30ead538463646d2ea7c2f5034eef7caaf4728007c3311ac43470270397
- Enrichment time
- 2026-05-24T19:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.