Hackers hijack thousands of sites for ClickFix and FakeUpdate attacks
2026-06-02T07:23:33Z•a9665b19525ae2a2797d8674d3450b751d0d034cbab03e1842215d5109811421
CVE-2026-0257brute-forcechatgpt-abusecifswitchclickfixcredential-stealerdashlanefakeupdatesincident-responselinux-local-privilege-escalationmiasmamicrosoft-outagenetlogon-rcenpm-supply-chainpackage-tamperingpalo-alto-globalprotectphishingshai-huludsite-hijackingsteam-c2wordpresswp-maps-pro
What happened
Multiple active and diverse threats observed across the Internet: a threat actor (DriveSurge) is hijacking thousands of sites to deliver ClickFix and FakeUpdate campaigns; 30+ npm packages in the @redhat-cloud-services namespace were poisoned to distribute a new Shai-Hulud variant ("Miasma") that steals developer credentials; WordPress sites are being exploited (WP Maps Pro bug creating admin accounts and a campaign hiding C2 payloads in Steam profiles); widespread exploitation reported for a critical Windows Netlogon RCE and a Palo Alto GlobalProtect authentication-bypass (CVE-2026-0257); a新C
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- a9665b19525ae2a2797d8674d3450b751d0d034cbab03e1842215d5109811421
- Enrichment time
- 2026-06-02T07:23:33Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.