Curated Cyber Threat Intelligence
Threat Feed
Daily intelligence on vulnerabilities, threat actors and geopolitical context — distilled from primary sources.
scheduleUpdated 2026-07-21 · 02:09 UTC
articleTotal: 606 reports
Filtered Reports
2 / 2 results
criticalbug_reportVulnerabilitybug_reportVulnerability
Ghost CMS SQL injection (CVE-2026-26980) exploited in ClickFix campaign
Ghost CMS Content API, all versions prior to patch. Over 700 sites confirmed compromised. Unauthenticated attackers can exploit the SQL injection vulnerability remotely.
CVE-2026-2698010:02 UTC
criticalperson_alertThreat Actorperson_alertThreat Actor
ClickFix Campaign Exploits Ghost CMS SQLi to Inject Malicious JavaScript
The threat actor behind this campaign remains unattributed. Motivation appears to be financially driven, leveraging ClickFix social engineering tactics to deliver malware or steal credentials.
CVE-2026-2698012:12 UTC