logo

Global Ghost CMS Poisoning Campaign Exploits Enterprise Blogs

ID: 87e96f2d-dd94-5dfe-b545-397f83d9bb6c

STIX ID: report--87e96f2d-dd94-5dfe-b545-397f83d9bb6c

Feed Name: securityonline.info

Threat Score
80/100

Date Published: 2026-05-27

Date Updated: 2026-05-27

Author: Ddos

...
...

Security researchers uncovered a widespread Ghost CMS poisoning campaign exploiting CVE-2026-26980 (SQL injection) to obtain Admin API keys, append malicious JavaScript to posts, and redirect visitors to a convincing FakeCaptcha flow. The attack chain uses browser fingerprinting and traffic distribution to cloak real victims, delivers a background compressed installer that executes a multi-stage Rust binary (installer.dll) and ultimately installs a trojan (UtilifySetup.exe); over 700 domains — including high-profile institutions — were reported affected. Immediate mitigation recommended includes patching Ghost instances, rotating Admin API keys, and scanning for injected scripts and unauthorized backend changes.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.