Vulnerability Overview
Exploitation Activity
Exploitation Intelligence
A critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS is being actively exploited in a large-scale cyberattack affecting over 700 websites, including those of Harvard University, Oxford University, Auburn University, and DuckDuckGo. The vulnerability allows unauthenticated attackers t...
CVE-2026-26980 is a SQL Injection vulnerability affecting Ghost, a Node.js content management system, allowing unauthenticated attackers to perform arbitrary database reads. The flaw exists in the Content API's slug filter ordering functionality, impacting versions 3.24.0 through 6.19.0. Attackers c...
NightSpire ransomware, identified in early 2025, has rapidly become a significant threat, employing double-extortion tactics. It targets various sectors, including hospitals and government offices, by exploiting Remote Desktop Protocol (RDP) vulnerabilities and remote admin tools. Victims face data...
In 2026, the rise of agentic AI is transforming how businesses operate, particularly in the financial services sector. This new technology allows for autonomous decision-making, which increases the potential impact of errors and security breaches. IT leaders are actively addressing these challenges...