Topic: malicious javascript
-
Ghost CMS SQL injection exploited in widespread ClickFix attacks
A critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980) is being actively exploited, allowing attackers to inject malicious JavaScript that initiates a ClickFix attack chain to compromise visitors and steal sensitive data. The attack tricks users with a fake "click to fix" prompt tha...
Read More » -
Adform ad script hacked to steal cryptocurrency
Adform, a major European adtech provider, suffered a supply-chain attack that injected crypto-stealing code into its tracking script, which swapped copied or displayed cryptocurrency wallet addresses on websites using its platform to redirect funds to attackers. Security researcher Kevin Beaumont...
Read More » -
AppsFlyer SDK Hijacked to Steal Crypto in New Attack
A widely used marketing analytics tool, AppsFlyer, was compromised in a supply-chain attack where its Web SDK delivered malicious code to intercept and replace cryptocurrency wallet addresses on websites, diverting funds to attackers. Security researchers confirmed the breach, which involved obfu...
Read More »