Published: May 25, 2026
Category: Security / Docker / Cloudflare / Ghost CMS
Introduction
On May 25, 2026, we identified suspicious outbound email activity originating from a self-hosted Ghost CMS environment running inside Docker containers.
The incident ultimately traced back to a vulnerable Ghost CMS installation that allowed attackers to gain access to