logo

Ghost CMS Mass Compromised via CVE-2026-26980, Now Fueling ClickFix Attacks

ID: 3d4bc7c4-e509-55e9-9fd8-c241880fb10f

STIX ID: report--3d4bc7c4-e509-55e9-9fd8-c241880fb10f

Feed Name: QiAnXin XLab

Threat Score
80/100

Date Published: 2026-05-21

Date Updated: 2026-05-25

Author: Alex.Turing

...
...

XLab detected a large-scale Ghost CMS poisoning campaign exploiting CVE-2026-26980 to extract Admin API keys and inject JavaScript loaders across 700+ domains; attackers used cloaking services and FakeCaptcha social engineering to distribute multi-stage payloads (including a stealer trojan and persistent Electron backdoor), multiple attack groups are active, and the report includes IoCs, sample analyses, detection checks, and remediation steps.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.