Ghost CMS flaw abused to push ClickFix attacks on hundreds of sites
2026-05-25T20:51:43Z•fe9669add64a7b32041cad8a42d193bf7190a21b34a1f4f6578dbd51bda04431
Anthropic Project GlasswingCISA KEVCVE-2026-26980CVE-2026-9082ClickFixDrupalGhost CMSOnlyFans data aggregationStark IndustriesWhatsAppaccount takeoverdata leakhosting takedowniOS 16malware campaignnpm compromisepatchingserver seizuresupply chainvulnerability discoveryzero-click
What happened
Multiple active and high-impact incidents: attackers are exploiting a patched Ghost CMS flaw (CVE-2026-26980) to push ClickFix malware across >700 unpatched sites (including universities), and a highly critical Drupal SQL injection (CVE-2026-9082, CVSS ~9.8) is under active attack and was added to CISA’s KEV. Other notable items include a 340M-record OnlyFans-linked dataset compiled from prior leaks (not a direct breach), a zero-click WhatsApp account takeover affecting iOS 16 users, Dutch authorities seizing ~800 servers tied to a hosting provider linked to cyberattacks/disinformation, the_k/
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityaffairs
- Record identifier
- fe9669add64a7b32041cad8a42d193bf7190a21b34a1f4f6578dbd51bda04431
- Enrichment time
- 2026-05-25T20:51:43Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.