FBI director Kash Patel’s brand website taken offline after malware reports

2026-05-25T08:51:43Ze6691acf3ea12e55d93ede6a00fa29792a331ff8f731459fdb70ca642c278f31
Anthropic GlasswingCISA KEVCVE-2025-34291CVE-2026-9082ClickFixDrupalGitHub Actions compromiseKimwolfbotnet arrestclickjackingfake-Cloudflareghostwritermalwarenpm compromisepatching gapphishingransomware extortionsupply-chain compromisevulnerability managementwebsite compromise

What happened

Security Affairs roundup: a merchandise site for FBI director Kash Patel was taken offline after attackers used a fake Cloudflare page and a ClickFix technique to push malware. Drupal disclosed a highly critical SQL injection (CVE-2026-9082, CVSS 9.8) that is under active exploitation and was added to CISA’s KEV; CISA also added other high-profile flaws (including CVE-2025-34291). Anthropic’s Project Glasswing flagged 10,000+ high/critical vulnerabilities in one month, highlighting major patching gaps. Additional coverage details supply‑chain and npm compromises, a return of the Ghostwriter A­

Why it matters

A reviewed impact interpretation has not been published for this record.

Evidence and limitations

Source ID
securityaffairs
Record identifier
e6691acf3ea12e55d93ede6a00fa29792a331ff8f731459fdb70ca642c278f31
Enrichment time
2026-05-25T08:51:43Z
AI-assisted enrichment
Yes

This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.

Record · FBI director Kash Patel’s brand website taken offline after malware reports · Baitaphish