DuckDuckGo A.I CyberSecurity Scoring
DuckDuckGo
Company Information
Website:https://duckduckgo.com/
Employees number:453
Number of followers:135,383
NAICS:5112
Industry Type:Software Development
Homepage:duckduckgo.com
DuckDuckGo Risk Score (AI oriented)
Between 700 and 749
DuckDuckGoSoftware Development
Updated:
26/05/2026
26/05/2026
736/1000
Moderate
Ba
DuckDuckGo Global Score (TPRM)
xxxx
DuckDuckGoSoftware Development
Score locked

DuckDuckGoModerate
Current Score
736Ba (MODERATE)
01000
2 incidents
-11 avg impact
Incident timeline with MITRE ATT&CK tactics, techniques, and mitigations.
JUNE 2026
737
MAY 2026
756
Cyber Attack
07 May 2026 • DuckDuckGo
DuckDuckGo, Harvard University and Ghost: Critical Ghost CMS Vulnerability Exploited to Hack 700+ Websites
Critical Ghost CMS Vulnerability Exploited in Large-Scale Malware Campaign
736
CRITICAL-20
DUCHARGHO1779798590
Critical Ghost CMS Vulnerability Exploited in Large-Scale Malware Campaign
A severe SQL injection flaw in the Ghost content management system (CMS), tracked as CVE-2026-26980, has been exploited in a widespread cyberattack compromising over 700 websites, including platforms linked to Harvard University, the University of Oxford, and DuckDuckGo. The campaign, uncovered by Chinese cybersecurity firm QiAnXin’s XLab team, leverages unpatched Ghost installations to inject malicious JavaScript, enabling ClickFix malware attacks.
The vulnerability, disclosed and patched in February 2026 (Ghost version 6.19.1), carries a CVSS score of 9.4, reflecting its critical severity. It allows unauthenticated attackers to extract sensitive data including Admin API keys, user credentials, and authentication tokens via Ghost’s Content API. Once obtained, the Admin API key grants attackers the ability to modify published articles and embed malicious code without authorization.
Exploitation began almost immediately after the patch’s release, with a DLL file linked to the campaign compiled on February 16, 2026, the same day the fix was announced. The first malicious activity was detected on May 7, 2026, with hundreds of Ghost-powered sites compromised by early May. Victims span AI, blockchain, cybersecurity, fintech, media, SaaS, and higher education, though nearly half were personal blogs or independent sites.
Attackers injected two-stage JavaScript loaders into website articles, directing visitors to an external domain (clo4shara[.]xyz/11z77u3.php) to fetch additional payloads. The infrastructure used Adspect, a commercial cloaking service, to fingerprint visitors and selectively deliver malware, evading detection by automated scanners. QiAnXin noted that at least two threat groups are actively competing in these "poisoning operations," with some sites receiving multiple malicious code injections in a single day.
Despite notifications, most compromised sites failed to respond, leaving the campaign ongoing. The attack highlights the risks of delayed patching in widely used CMS platforms.
INCIDENT DETAILS -
TYPE
MOTIVATION
IMPACT
DATA BREACH
REFERENCES
APRIL 2026
756
MARCH 2026
758
Vulnerability
02 Mar 2026 • DuckDuckGo
DuckDuckGo: UXSS Vulnerability in DuckDuckGo Browser’s AutoConsent JS Bridge Allows Cross-Origin Attacks
DuckDuckGo Android Browser Patched for Critical UXSS Vulnerability
756
CRITICAL-2
DUC1772461435
DuckDuckGo Android Browser Patched for Critical UXSS Vulnerability
A high-severity vulnerability in the DuckDuckGo browser for Android was recently disclosed, exposing users to Universal Cross-Site Scripting (UXSS) attacks. The flaw, discovered in the browser’s AutoConsent JS bridge, allowed malicious code from untrusted sources to execute on trusted webpages, bypassing the Same-Origin Policy (SOP).
Security researcher Dhiraj Mishra reported the issue via HackerOne, revealing that the AutoconsentAndroid Java bridge designed to automate cookie consent pop-ups failed to validate message origins. The bridge accepted commands from any iframe, including cross-origin ones, without authentication, enabling attackers to inject arbitrary JavaScript into the main webpage.
A proof-of-concept (PoC) demonstrated the exploit: a hidden malicious iframe could alter the content of a victim page, confirming the SOP bypass. The vulnerability, assigned a CVSS score of 8.6 (High), could have been exploited to steal cookies, hijack sessions, or manipulate website content all without user interaction.
DuckDuckGo has since patched the flaw in recent updates to the com.duckduckgo.mobile.android app. The fix ensures the AutoConsent bridge now properly verifies message origins, preventing unauthorized script execution. Users were advised to update to the latest version to mitigate risks.
INCIDENT DETAILS -
TYPE
IMPACT
DATA BREACH
REFERENCES
FEBRUARY 2026
758
JANUARY 2026
758
DECEMBER 2025
758
NOVEMBER 2025
758
OCTOBER 2025
758
SEPTEMBER 2025
758
AUGUST 2025
758
JULY 2025
758
Frequently Asked Questions
?
What is the current A.I Rankiteo Cyber Score for DuckDuckGo ??
What was DuckDuckGo's A.I Rankiteo Cyber Score in May 2026 ??
What was DuckDuckGo's A.I Rankiteo Cyber Score in April 2026 ??
What was DuckDuckGo's A.I Rankiteo Cyber Score in March 2026 ??
What was DuckDuckGo's A.I Rankiteo Cyber Score in February 2026 ??
What was DuckDuckGo's A.I Rankiteo Cyber Score in January 2026 ??
What was DuckDuckGo's A.I Rankiteo Cyber Score in December 2025 ??
What was DuckDuckGo's A.I Rankiteo Cyber Score in November 2025 ??
What was DuckDuckGo's A.I Rankiteo Cyber Score in October 2025 ??
What was DuckDuckGo's A.I Rankiteo Cyber Score in September 2025 ??
What was DuckDuckGo's A.I Rankiteo Cyber Score in August 2025 ??
What was DuckDuckGo's A.I Rankiteo Cyber Score in July 2025 ??
What is the average per-incident point impact on DuckDuckGo's A.I Rankiteo Cyber Score over the past 12 months ??
Where can I access detailed records of all cyber incidents associated with DuckDuckGo ??
Where can I find a summary of the A.I Rankiteo Risk Scoring methodology ??
Where can I view DuckDuckGo's profile page on Rankiteo ??
How accurate is the A.I Rankiteo Risk Scoring methodology ?