Placeholder domain used in dev docs now serves ClickFix attacks
2026-09-24T01:23:22Z•dd048f80f5e5d014349615f95f4784d5c655ccaf0233e3b6a1e26a60051fd480
CVE-2026-85102CVE-2026-87902Android malwareCheck Point Security GatewayClickFixF5 BIG-IPGoogle CloudKubernetesPeopleSoftPowerShellVPNVeloCloud OrchestratorWordPressZyxelactive exploitationbanking trojancloud privilege escalationcredential theftdata breachransomwareremote code executionsupply chainweb skimmingzero-day
What happened
BleepingComputer security headlines report active exploitation of multiple critical and zero-day vulnerabilities, including Check Point Security Gateway VPN RCE (CVE-2026-85102), a critical WordPress code-execution flaw (CVE-2026-87902), Arista VeloCloud Orchestrator and F5 BIG-IP APM zero-days, and attacks against Zyxel and WordPress systems. Other coverage includes ClickFix PowerShell malware delivery, RemControl Android banking malware, AI-assisted payment-card skimming affecting more than 600,000 cards, cloud privilege escalation through Kubernetes Config Connector, ransomware, credential盗
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- dd048f80f5e5d014349615f95f4784d5c655ccaf0233e3b6a1e26a60051fd480
- Enrichment time
- 2026-09-24T01:23:22Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.