FBI director Kash Patel’s brand website taken offline after malware reports
2026-05-25T08:51:43Z•e6691acf3ea12e55d93ede6a00fa29792a331ff8f731459fdb70ca642c278f31
Anthropic GlasswingCISA KEVCVE-2025-34291CVE-2026-9082ClickFixDrupalGitHub Actions compromiseKimwolfbotnet arrestclickjackingfake-Cloudflareghostwritermalwarenpm compromisepatching gapphishingransomware extortionsupply-chain compromisevulnerability managementwebsite compromise
What happened
Security Affairs roundup: a merchandise site for FBI director Kash Patel was taken offline after attackers used a fake Cloudflare page and a ClickFix technique to push malware. Drupal disclosed a highly critical SQL injection (CVE-2026-9082, CVSS 9.8) that is under active exploitation and was added to CISA’s KEV; CISA also added other high-profile flaws (including CVE-2025-34291). Anthropic’s Project Glasswing flagged 10,000+ high/critical vulnerabilities in one month, highlighting major patching gaps. Additional coverage details supply‑chain and npm compromises, a return of the Ghostwriter A
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- e6691acf3ea12e55d93ede6a00fa29792a331ff8f731459fdb70ca642c278f31
- Enrichment time
- 2026-05-25T08:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.