Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain

2026-09-05T19:23:21Ze3954dda125a6085c7f68ce20852cdca60b2f30099db1e6c0b7b4e31669490b3
CVE-2026-19490ArubaOS-CXCitrix NetScalerClickFixCrowdStrike FalconGoogle ChromeTerraform modulesV8active exploitationauthenticationblockchain malwarecloud outagecompromised websitescredential theftdata breachpasskeysprivilege escalationremote code executionsupply-chain compromisezero-day

What happened

BleepingComputer security feed covering active exploitation of critical vulnerabilities, zero-days, supply-chain compromises, ClickFix malware delivery through compromised websites and blockchain-stored payloads, authentication threats, and major data breaches. The most urgent items include an actively exploited Citrix NetScaler authentication bypass (CVE-2026-19490), a Chrome V8 zero-day, a CrowdStrike Falcon privilege-escalation zero-day, and a critical ArubaOS-CX remote-code-execution flaw.

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
bleepingcomputer
Record identifier
e3954dda125a6085c7f68ce20852cdca60b2f30099db1e6c0b7b4e31669490b3
Enrichment time
2026-09-05T19:23:21Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.