黑客利用 CVE-2026-26980 攻陷 Ghost CMS,大量站点沦为 ClickFix 攻击帮凶
ID: 175efab6-fe4e-5142-b937-00d30df6fae3
STIX ID: report--175efab6-fe4e-5142-b937-00d30df6fae3
Feed Name: QiAnXin XLab
Threat Score
**XLab identified a large-scale mass‑poisoning campaign exploiting Ghost CMS CVE-2026-26980 to steal Admin API keys and inject JavaScript loaders that redirect users to FakeCaptcha/ClickFix pages, resulting in silent download and execution of malware (installer.dll, UtilifySetup.exe); over 700 domains across multiple sectors were impacted and two distinct attacker groups were observed — immediate patching, credential rotation, and cleanup are strongly recommended.**
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
