Live data from Hacker News

Good Careers at Bad Companies

sharedphysics.com

11–14 of 14 posts

Re: Good Careers at Bad Companies

#12
OP/author here! Apologies about the malware and captcha. It looks like my site was exploited by CVE-2026-26980 affecting all Ghost sites pre v6.19 [1][2] An API key was hijacked to inject malicious JS into every page that looks like a cloudflare captcha; it seems that the JS only targeted windows users, so I didn't catch it before I shared the post widely.

The site has been upgraded to 6.44 to close the vulnerability, I rotated every API key and account credential, and both manually and programmatically scrubbed every instance I could find of the code injection across the database. I think we're clear now!

Sorry to anyone caught by this and thank you to folks for flagging it (and thanks to the HN team for letting me follow up on this after comments were closed). I'm seriously mortified. X_X

[1] https://github.com/TryGhost/Ghost/security/advisories/GHSA-w... [2] https://www.securityweek.com/ghost-cms-vulnerability-exploit...

Re: Good Careers at Bad Companies

#13
Thanks for fixing the site, OP.

The post is fantastically helpful for keeping perspective and navigating orgs regardless of whether or not they’re a “bad company”. Because there’s parts of every company that are dysfunctional.

Re: Good Careers at Bad Companies

#14

I am highly disrespected by your misleading and scummy CAPTcha, which is very very unethical. Copying a command to my clipboard and asking me to run it in terminal? You should be banned for this. Here is the analysis of what you were asking readers to do: It's a multi-stage malware loader. The decoded PowerShell does this: Forces TLS 1.2 and creates a randomly-named folder in %TEMP%. Downloads a copy of 7z.exe (the l…

Looks like the site got hit by the CVE-2026-26980 exploit right shortly before I posted this. This was helpful in identifying the malicious code that was added to the footer of every page, thank you!
Post reply on HN