Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
2026-09-06T01:23:22Z•c24c656086457e7a48d9687603d9575ded4156461e48033440db8dbaaf7aae86
CVE-2026-19490BNB Smart ChainCitrix NetScalerClickFixCrowdStrike FalconGoogle ChromeMicrosoft Exchange OnlineTerraformV8active exploitationblockchaincompromised websitescredential theftcybersecurity newsdata breachhealthcareidentity datapasskeysprivilege escalationsupply-chain compromisezero-day
What happened
BleepingComputer security feed covering active exploitation of a critical Citrix NetScaler authentication bypass (CVE-2026-19490), an actively exploited Chrome V8 zero-day, a CrowdStrike Falcon privilege-escalation zero-day, blockchain-hosted ClickFix campaigns distributed through more than 5,400 compromised websites, supply-chain compromise of Coder registry infrastructure, and other major data breaches, vulnerabilities, and service outages.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- c24c656086457e7a48d9687603d9575ded4156461e48033440db8dbaaf7aae86
- Enrichment time
- 2026-09-06T01:23:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.