Vulnerabilità ed exploit · Attacco ad app web
La SQLi di Ghost trasforma i siti in trusted malware launchpads Ghost CMS qui non sta solo perdendo dati. Una vulnerabilità di SQL injection può consegnare agli attacker chiavi API admin, e questo trasforma un singolo bug di web app in controllo persistente su articoli, theme e contenuti delle pagine. La pulizia del solo percorso SQLi può lasciare il sito ancora in grado di distribuire JavaScript malevolo da pagine trusted.
3 fonti · 25 mag
CVE-2026-26980 NVD KEV
CVSS 9.4 CRITICAL: ghost is a Node.js content management system. EPSS 5% (92º percentile).
Cronologia Fonti 25 mag The Hacker News
Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
Ghost CMS flaw CVE-2026-26980 enabled attacks on 700+ sites, injecting ClickFix malware through fake CAPTCHA pages.
originale 25 mag SecurityWeek
Ghost CMS Vulnerability Exploited to Hack Over 700 Websites
Sites belonging to major universities such as Harvard and Oxford, as well as DuckDuckGo, have been compromised in the attack.
originale 24 mag BleepingComputer
Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows.
originale Part of the PlainSec briefing for 2026-05-25
Every edition of this story: La SQLi di Ghost trasforma i siti in trusted malware launchpads
Altro da oggi
Vulnerabilità ed exploit · Attacco ad app web
La SQLi di Ghost trasforma i siti in trusted malware launchpads Ghost CMS qui non sta solo perdendo dati. Una vulnerabilità di SQL injection può consegnare agli attacker chiavi API admin, e questo trasforma un singolo bug di web app in controllo persistente su articoli, theme e contenuti delle pagine. La pulizia del solo percorso SQLi può lasciare il sito ancora in grado di distribuire JavaScript malevolo da pagine trusted.
3 fonti · 25 mag
CVE-2026-26980 NVD KEV
CVSS 9.4 CRITICAL: ghost is a Node.js content management system. EPSS 5% (92º percentile).
Cronologia Fonti 25 mag The Hacker News
Ghost CMS CVE-2026-26980 Exploited to Hijack 700+ Sites for ClickFix Attacks
Ghost CMS flaw CVE-2026-26980 enabled attacks on 700+ sites, injecting ClickFix malware through fake CAPTCHA pages.
originale 25 mag SecurityWeek
Ghost CMS Vulnerability Exploited to Hack Over 700 Websites
Sites belonging to major universities such as Harvard and Oxford, as well as DuckDuckGo, have been compromised in the attack.
originale 24 mag BleepingComputer
Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign
A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows.
originale Part of the PlainSec briefing for 2026-05-25
Every edition of this story: La SQLi di Ghost trasforma i siti in trusted malware launchpads
Altro da oggi