Lyrie
← Active Exploitation
1 sources verifiedΒ·1 min read
By Lyrie Threat IntelligenceΒ·5/25/2026

0day Intel: 🚨 Hackers breached 700+ Ghost CMS websites to serve ClickFix malware attacks.

Source: X search for CVE-2026 critical

Posted: 2026-05-25T12:09:26.000Z

Likes: 49

Full Tweet

🚨 Hackers breached 700+ Ghost CMS websites to serve ClickFix malware attacks.

Read πŸ ’ https://t.co/BUYGls2Eq6

The attackers exploited critical flaw CVE-2026-26980 to steal admin API keys and inject malicious JavaScript into legitimate sites, including university, AI, https://t.co/v7BdvmIstW

Source Link

https://x.com/i/status/2058883135002366116

Lyrie Verdict

Lyrie's autonomous defense layer flags this class of exposure the moment it surfaces β€” no signature update required.

Validated sources

  1. [1]@209811713 on X