Tag

Ghost Cms

All articles tagged with #ghost cms

Ghost CMS flaw spawns 700-site ClickFix loader campaign
technology3 months ago

Ghost CMS flaw spawns 700-site ClickFix loader campaign

Threat actors exploited Ghost CMS CVE-2026-26980, a critical Content API SQL injection, to steal Admin API keys and inject malicious JavaScript across 700+ sites, enabling two-stage payload delivery for ClickFix-style fake CAPTCHA attacks; a patch (Ghost 6.19.1) was released in February 2026, and victims span universities, blockchain, SaaS, media, and finance. Remediation: upgrade, rotate credentials, audit access logs, and alert users who visited affected sites.

Global Ghost CMS flaw exploited to steal admin keys and push ClickFix scam
security3 months ago

Global Ghost CMS flaw exploited to steal admin keys and push ClickFix scam

A widespread campaign abused a critical Ghost CMS SQL injection (CVE-2026-26980) affecting versions 3.24.0–6.19.0 to read database data and steal admin API keys, then injects malicious JavaScript into articles. The loader fetches a second-stage payload that triggers a fake Cloudflare prompt and a ClickFix lure, leading victims to a Windows command prompt instruction and subsequent malware downloads. High-profile targets (Harvard, Oxford, Auburn, DuckDuckGo) were affected. Ghost released fix 6.19.1 on Feb 19, but many sites have not updated. Action items: upgrade to 6.19.1+, rotate all exposed keys, and review up to 30 days of admin API call logs to identify IoCs and remove injected scripts.