logo

700+ education and tech websites hijacked in huge ClickFix malware campaign

ID: b070788b-1365-5132-8000-e72d6df95dcc

STIX ID: report--b070788b-1365-5132-8000-e72d6df95dcc

Feed Name: Security Boulevard

Threat Score
75/100

Date Published: 2026-05-26

Date Updated: 2026-05-26

Author: Malwarebytes

...
...

Malwarebytes reports a large ClickFix campaign exploiting a critical Ghost CMS SQL injection (CVE-2026-26980) affecting Ghost versions 3.24.0–6.19.0; attackers compromised 700+ sites, stole Admin API keys, injected malicious JavaScript that shows fake Cloudflare/CAPTCHA dialogs, and tricks visitors into copy‑pasting and running Windows commands which install malware. Site operators should patch Ghost immediately and users should avoid running commands from web pages.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.