The Daily Cyber

Archives
Log in
Subscribe
May 25, 2026

Ghost CMS ClickFix Poisoning Hits 700+ Sites

Ghost CMS ClickFix Poisoning Hits 700+ Sites

Ghost CMS ClickFix Poisoning Hits 700+ Sites

Attackers exploited Ghost CMS CVE-2026-26980 to steal admin API keys and inject ClickFix scripts into 700+ sites. Ghost operators should update, rotate credentials, clean pages, and audit logs.

Read on dailycyber.net →

Don't miss what's next. Subscribe to The Daily Cyber:
← Newer SharePoint RCE Patch Closes Site Member Risk Older → Megalodon CI/CD attack hits thousands of GitHub repos
Powered by Buttondown, the easiest way to start and grow your newsletter.