How a Ghost CMS Vulnerability Led to Mailgun API Abuse — and How We Recovered Using Docker and Cloudflare Tunnel
Published: May 25, 2026 Category: Security / Docker / Cloudflare / Ghost CMS Introduction On May 25, 2026, we identified suspicious outbound email activity originating from a self-hosted Ghost CMS environment running inside Docker containers. The incident ultimately traced back to a vulnerable Ghost CMS installation that allowed attackers to gain access to