A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows.
Fortinet’s FortiClient endpoint management software, meant to harden corporate and government machines, instead exposed them ...