Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain
2026-09-05T19:23:21Z•e3954dda125a6085c7f68ce20852cdca60b2f30099db1e6c0b7b4e31669490b3
CVE-2026-19490ArubaOS-CXCitrix NetScalerClickFixCrowdStrike FalconGoogle ChromeTerraform modulesV8active exploitationauthenticationblockchain malwarecloud outagecompromised websitescredential theftdata breachpasskeysprivilege escalationremote code executionsupply-chain compromisezero-day
What happened
BleepingComputer security feed covering active exploitation of critical vulnerabilities, zero-days, supply-chain compromises, ClickFix malware delivery through compromised websites and blockchain-stored payloads, authentication threats, and major data breaches. The most urgent items include an actively exploited Citrix NetScaler authentication bypass (CVE-2026-19490), a Chrome V8 zero-day, a CrowdStrike Falcon privilege-escalation zero-day, and a critical ArubaOS-CX remote-code-execution flaw.
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- e3954dda125a6085c7f68ce20852cdca60b2f30099db1e6c0b7b4e31669490b3
- Enrichment time
- 2026-09-05T19:23:21Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.