DriveSurge Hijacks Thousands of Sites for ClickFix, FakeUpdate Attacks

2026-06-02T20:51:39Zd878587b3caf113dc41c4bb1e1d26b6fe08d88b28cf835ba0604c7a3b0df818c
API-keys-exposure','SharePoint-patch','ransomware','Silent-Rans0APTAzureveilBTMOBChinaClickFixDriveSurgeFakeUpdateGitHub-compromiseGlobalProtectMaaSMegalodonOT-robot-OSPAN-OSRATTDSTeamPCPUnderminractive-exploitcommand-injectioncredential-theftdomain-frontingmalvertisingsupply-chain-compromisetraffic-distribution-system

What happened

This DarkReading digest describes multiple active and large-scale threats: a malicious traffic distribution system (DriveSurge) hijacking thousands of trusted sites to redirect users to ClickFix/FakeUpdate malware pages; active exploits targeting Palo Alto PAN-OS GlobalProtect (auth-bypass) and a critical unauthenticated command‑injection flaw in an OT robot OS; widespread supply-chain and repository compromises (Megalodon malicious commits to 5,500+ GitHub repos; TeamPCP-linked GitHub breach); proliferating MaaS and RAT activity in Latin America (BTMOB); and continued advanced persistent‑then

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
darkreading
Record identifier
d878587b3caf113dc41c4bb1e1d26b6fe08d88b28cf835ba0604c7a3b0df818c
Enrichment time
2026-06-02T20:51:39Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.