<?xml version="1.0" encoding="UTF-8"?>
<!-- generator="wordpress.com" -->
<urlset xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
	xsi:schemaLocation="http://www.sitemaps.org/schemas/sitemap/0.9 http://www.sitemaps.org/schemas/sitemap/0.9/sitemap.xsd"
	xmlns="http://www.sitemaps.org/schemas/sitemap/0.9"
	xmlns:news="http://www.google.com/schemas/sitemap-news/0.9"
	xmlns:image="http://www.google.com/schemas/sitemap-image/1.1"
	>
<url><loc>https://socdfir.com/2026/05/26/cyber-pulse-technical-threat-deep-dives-on-active-cves-ghost-cms-sql-injection-weaponized-for-clickfix-poisoning/</loc><news:news><news:publication><news:name>Ramblings of a CyberSecurity Nerd</news:name><news:language>en</news:language></news:publication><news:publication_date>2026-05-26T15:21:54+00:00</news:publication_date><news:title>Cyber Pulse: Technical Threat Deep Dives on Active CVEs — Ghost CMS SQL Injection Weaponized for ClickFix Poisoning</news:title><news:keywords>security, cybersecurity, technology, dfir, threat-intelligence, soc, splunk, artificial-intelligence, yara, sigma, suricata, api-abuse, threat intelligence, admin api, sql injection, github advisory, clickfix, web application security, ghost cms, t1190, website compromise, ghost, malware delivery, waf, content api, qianxin, cms security, securityweek, javascript injection, snyk, nvd, cve-2026-26980, api abuse</news:keywords></news:news></url></urlset>
