Ghost CMS Vulnerability Exploited to Hack Over 700 Websites
2026-05-25T19:24:05Z•b0ccc5e177fe267ff87da1fc23618b7b9a53100d838d0d27e5d3c3bef87070b2
Anthropic MythosCI secretsCMSCVE-2026-9082DNS filtering bypassDocketWiseDrupalGhostGhost CMSGitHub ActionsLaravel‑LangMegalodonRadiology Associates of RichmondTriZettoUnderminrcommand-and-controlhealthcare breachopen source vulnerabilitiespackage poisoningsupply chainthird-party breachwebsite compromise
What happened
Multiple high-impact security events reported: a Ghost CMS vulnerability was exploited to compromise over 700 websites (including major universities and DuckDuckGo); a third‑party data breach affected an oncology institute (possible TriZetto) and healthcare breaches at Radiology Associates of Richmond (266,000 impacted) and DocketWise (143,000). Large-scale supply‑chain attacks were observed — over 5,500 GitHub repositories infected in the “Megalodon” campaign and malicious tags/commits poisoned Laravel‑Lang packages to exfiltrate CI secrets. Anthropic’s Mythos scan flagged ~23,000 potential (
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- securityweek
- Record identifier
- b0ccc5e177fe267ff87da1fc23618b7b9a53100d838d0d27e5d3c3bef87070b2
- Enrichment time
- 2026-05-25T19:24:05Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.