Australia warns of global campaign targeting vulnerable CMS platforms

2026-07-12T07:23:25Z4afe95b563e9dac0ba6d735f807097d3b011af0026660626c0bdb43c4038acab
AI agent securityCMS exploitationDockerGhostcommitGiteaHelixInjective SDKMFA abuseProgress SoftwareRyukShareFileStorage Zone ControllerU-BootXSSZimbraactive exploitationauthentication bypasscryptocurrency wallet stealerfirmware compromisenpm malwareplugin vulnerabilitiesprompt injectionransomwaresupply-chain riskvishing

What happened

Multiple high-impact incidents and vulnerability disclosures were reported: the Australian Cyber Security Centre warns of a global campaign exploiting vulnerable CMS platforms and plugins; a novel prompt‑injection technique dubbed “Ghostcommit” hides instructions in PNG images to trick AI/code‑review agents and exfiltrate secrets; six U‑Boot bootloader vulnerabilities could enable stealthy, persistent firmware attacks; and attackers are actively exploiting a critical authentication bypass in the official Gitea Docker image to impersonate any user. Other notable items include Progress urging on

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
4afe95b563e9dac0ba6d735f807097d3b011af0026660626c0bdb43c4038acab
Enrichment time
2026-07-12T07:23:25Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · Australia warns of global campaign targeting vulnerable CMS platforms · Baitaphish