• About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us
TechTrendFeed
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT
No Result
View All Result
TechTrendFeed
No Result
View All Result

Ghost CMS Vulnerability Exploited to Hack Over 700 Web sites

Admin by Admin
May 25, 2026
Home Cybersecurity
Share on FacebookShare on Twitter


A vulnerability patched a number of months in the past within the Ghost content material administration system (CMS) has been exploited to hack tons of of internet sites, together with ones belonging to main organizations, in response to Chinese language cybersecurity firm Qianxin.

The exploited vulnerability is tracked as CVE-2026-26980 and its existence got here to gentle in February when it was patched.

Ghost is a extensively used open supply CMS designed particularly for running a blog, newsletters, and publishing, providing built-in instruments for memberships, subscriptions, and viewers monetization. Based on its developer, Ghost is actively utilized by over 100,000 web sites. 

When CVE-2026-26980 was disclosed, SentinelOne warned that the vulnerability, an SQL injection flaw, might be exploited by unauthenticated attackers to extract delicate knowledge from the Ghost database. The safety agency famous that an attacker may get hold of authentication tokens, person credentials, and web site content material. 

Qianxin reported final week that CVE-2026-26980 has been exploited in mass assaults in opposition to unpatched Ghost situations. 

Menace actors leveraged the flaw to acquire the focused websites’ Admin API Key after which used the API to change articles posted on Ghost-powered websites. Particularly, the attackers injected malicious JavaScript loaders designed for ClickFix assaults. 

Commercial. Scroll to proceed studying.

The compilation timestamp of a DLL file used within the assault is February 16, the day a patch was introduced for CVE-2026-26980. Qianxin began seeing compromised web sites in early Might.

The safety agency has recognized greater than 700 web sites compromised within the marketing campaign, together with ones belonging to main organizations comparable to DuckDuckGo, Harvard College, and Oxford College.

An evaluation confirmed that just about half of the hacked web sites are private blogs and unbiased websites, however dozens belong to software program improvement and tech blogs, AI, cryptocurrency, and varied different kinds of entities. 

Qianxin has alerted most of the victims, however mentioned a overwhelming majority didn’t reply to its notifications. 

“No less than two teams are at present actively conducting such poisoning operations, and a few websites have even grow to be the goal of competitors between the 2 events, with completely different malicious code being implanted one after one other inside a single day,” Qianxin mentioned.

Associated: Drupal Vulnerability in Hacker Crosshairs Shortly After Disclosure

Associated: Exploitation of Crucial NGINX Vulnerability Begins

Associated: Hackers Focused PraisonAI Vulnerability Hours After Disclosure

Tags: CMSExploitedGhostHackVulnerabilitywebsites
Admin

Admin

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Trending.

Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

Safety Amplified: Audio’s Affect Speaks Volumes About Preventive Safety

May 18, 2025
Reconeyez Launches New Web site | SDM Journal

Reconeyez Launches New Web site | SDM Journal

May 15, 2025
Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

Discover Vibrant Spring 2025 Kitchen Decor Colours and Equipment – Chefio

May 17, 2025
Flip Your Toilet Right into a Good Oasis

Flip Your Toilet Right into a Good Oasis

May 15, 2025
Apollo joins the Works With House Assistant Program

Apollo joins the Works With House Assistant Program

May 17, 2025

TechTrendFeed

Welcome to TechTrendFeed, your go-to source for the latest news and insights from the world of technology. Our mission is to bring you the most relevant and up-to-date information on everything tech-related, from machine learning and artificial intelligence to cybersecurity, gaming, and the exciting world of smart home technology and IoT.

Categories

  • Cybersecurity
  • Gaming
  • Machine Learning
  • Smart Home & IoT
  • Software
  • Tech News

Recent News

Ghost CMS Vulnerability Exploited to Hack Over 700 Web sites

Ghost CMS Vulnerability Exploited to Hack Over 700 Web sites

May 25, 2026
Trump Cell Cellphone Assessment: My Lengthy Weekend With The Golden T1

Trump Cell Cellphone Assessment: My Lengthy Weekend With The Golden T1

May 25, 2026
  • About Us
  • Privacy Policy
  • Disclaimer
  • Contact Us

© 2025 https://techtrendfeed.com/ - All Rights Reserved

No Result
View All Result
  • Home
  • Tech News
  • Cybersecurity
  • Software
  • Gaming
  • Machine Learning
  • Smart Home & IoT

© 2025 https://techtrendfeed.com/ - All Rights Reserved