Placeholder domain used in dev docs now serves ClickFix attacks

2026-09-24T01:23:22Z•dd048f80f5e5d014349615f95f4784d5c655ccaf0233e3b6a1e26a60051fd480
CVE-2026-85102CVE-2026-87902Android malwareCheck Point Security GatewayClickFixF5 BIG-IPGoogle CloudKubernetesPeopleSoftPowerShellVPNVeloCloud OrchestratorWordPressZyxelactive exploitationbanking trojancloud privilege escalationcredential theftdata breachransomwareremote code executionsupply chainweb skimmingzero-day

What happened

BleepingComputer security headlines report active exploitation of multiple critical and zero-day vulnerabilities, including Check Point Security Gateway VPN RCE (CVE-2026-85102), a critical WordPress code-execution flaw (CVE-2026-87902), Arista VeloCloud Orchestrator and F5 BIG-IP APM zero-days, and attacks against Zyxel and WordPress systems. Other coverage includes ClickFix PowerShell malware delivery, RemControl Android banking malware, AI-assisted payment-card skimming affecting more than 600,000 cards, cloud privilege escalation through Kubernetes Config Connector, ransomware, credential盗

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
dd048f80f5e5d014349615f95f4784d5c655ccaf0233e3b6a1e26a60051fd480
Enrichment time
2026-09-24T01:23:22Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.