Topic: exploit
-
Ghost CMS SQL injection exploited in widespread ClickFix attacks
A critical SQL injection vulnerability in Ghost CMS (CVE-2026-26980) is being actively exploited, allowing attackers to inject malicious JavaScript that initiates a ClickFix attack chain to compromise visitors and steal sensitive data. The attack tricks users with a fake "click to fix" prompt tha...
Read More »