BTC $71,807
2026 Bull Run Is Building Start trading with 5% OFF all fees
Sign Up Now
BTC $71,807
Bull Run 2026 | 5% Off Fees Open your Binance account today
Sign Up

Ghost CMS Flaw Fuels Widespread ClickFix Malware

Ghost CMS flaw hijacks articles, fueling ClickFix malware via hijacked legitimate websites.

  • A critical SQL injection flaw (CVE-2026-26980) in Ghost CMS is being actively exploited to hijack website articles.
  • Attackers have compromised over 700 legitimate websites across sectors including blockchain, AI, and fintech to fuel ClickFix malware campaigns.
  • The attacks inject a two-stage JavaScript loader that deploys a cloaking script and a fake CAPTCHA page to trick victims into running malicious commands.
  • The end goal is to install a modified version of the open-source Grape desktop client for persistent remote control.

Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks, according to a report from QiAnXin XLab. The campaign, first detected on May 7, 2026, has resulted in the large-scale poisoning of legitimate websites.

- Advertisement -

The vulnerability, CVE-2026-26980, is an SQL injection flaw in Ghost’s Content API with a CVSS score of 9.4. This flaw allows unauthenticated attackers to read arbitrary data and obtain a site’s admin API key without authorization. Consequently, attackers can tamper with articles in bulk by injecting malicious code.

More than 700 websites across universities, blockchain, artificial intelligence, and financial technology sectors have been compromised. XLab said the use of legitimate sites increases the success rate of the subsequent attacks.

The injected code functions as a two-stage loader that retrieves a main payload from an external domain. This payload is a traffic distribution script powered by the commercial cloaking service Adspect, which collects browser fingerprints and serves malicious content only to intended victims. Visitors deemed as targets are shown a fake CAPTCHA verification page within an iframe.

This fake page triggers a ClickFix attack, instructing users to paste a Base64-encoded command into the Windows Run dialog. The command acts as a dropper, ultimately delivering a modified version of the open-source Grape desktop client. This application achieves persistence and polls a remote server every 30 seconds to execute attacker commands.

- Advertisement -

Ghost CMS users are urged to upgrade to version 6.19.1 or later, rotate all credentials, and audit access logs for suspicious activity. Meanwhile, they should notify users who visited during the contamination period of potential compromise.

✅ Follow BITNEWSBOT on Telegram, Facebook, LinkedIn, X.com, and Google News for instant updates.

Previous Articles:

- Advertisement -
Ad
Altseason Is Loading. Don't watch from the sidelines.
SOL $90.51
DOGE $0.0963
LINK $9.02
SUI $1.00
5% off fees when you sign up
Start Trading
Ad
Pay Less on Every Trade. For Life.
$10K/mo volume Save $60/yr
$50K/mo volume Save $300/yr
$100K/mo volume Save $600/yr
5% off all trading fees when you sign up
Claim Your Discount

Latest News

Gates Foundation Sells $3.2B MSFT Stake as Ackman Buys In

The Bill & Melinda Gates Foundation Trust has sold its remaining 7.7 million shares...

Mining Mogul Chun Wang Purchases SpaceX Mars Mission

Chun Wang, founder of the Bitcoin mining pool F2Pool, has purchased and will join...

TrapDoor Malware Targets npm, PyPI, Crates.io in Supply Chain Attack

A coordinated supply chain attack, codenamed TrapDoor, has deployed malware across three major developer...

$1,000 in SHIB Could’ve Become $99.1 Million

A $1,000 investment in Shiba Inu on its all-time low day in November 2020...

BitMEX Analyst: Bond Yield Surge Fuels Bitcoin Supercycle

A Bitmex analyst argues surging sovereign bond yields will force a "structural" shift, creating...

Must Read

7 Best Audiobooks on Cybersecurity

Cybersecurity has become an essential topic in our increasingly digital world. As technology evolves and becomes more integrated into our daily lives, the importance...
Ad
Altseason Is Loading. These 4 coins are trending right now.
SOL $92.12
DOGE $0.0950
LINK $9.02
SUI $1.02
5% off spot fees when you sign up
Start Trading