Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Indicators Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks

download-file.today

TLP:CLEAR
Active

Domain

Description

Attackers exploited CVE-2026-26980, a critical SQL injection vulnerability in Ghost CMS, to obtain Admin API Keys without authorization and conduct mass website poisoning campaigns. Over 700 domains across multiple industries including universities, blockchain, AI, security research, and media were compromised. The attack chain involves CMS takeover, page poisoning with malicious JavaScript loaders, two-stage cloaking scripts, and FakeCaptcha social engineering to trick users into executing malicious commands. Two distinct threat groups are actively exploiting unpatched Ghost CMS installations, delivering information stealers and remote access tools. Compromised sites include Harvard University, Oxford University, and Auburn University. The attacks leverage users' trust in legitimate websites to increase success rates of ClickFix-type attacks, with payloads being dynamically distributed through Cloudflare-proxied domains.

Sightings (0)

No sightings recorded yet

Details

Name / Label
Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks
Pattern Type
STIX
Confidence
75%
Valid From
May 26, 2026 02:41
Total Sightings
0
Added
May 26, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.

Record Sighting

Record an observation of download-file.today

Sighting Type
Source
Comment
Leaving Threaticon

This link opens an external site that isn't part of the platform.