logo

黑客利用 CVE-2026-26980 攻陷 Ghost CMS,大量站点沦为 ClickFix 攻击帮凶

ID: 175efab6-fe4e-5142-b937-00d30df6fae3

STIX ID: report--175efab6-fe4e-5142-b937-00d30df6fae3

Feed Name: QiAnXin XLab

Threat Score
78/100

Date Published: 2026-05-21

Date Updated: 2026-05-25

Author: Alex.Turing

...
...

**XLab identified a large-scale mass‑poisoning campaign exploiting Ghost CMS CVE-2026-26980 to steal Admin API keys and inject JavaScript loaders that redirect users to FakeCaptcha/ClickFix pages, resulting in silent download and execution of malware (installer.dll, UtilifySetup.exe); over 700 domains across multiple sectors were impacted and two distinct attacker groups were observed — immediate patching, credential rotation, and cleanup are strongly recommended.**

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.