Here's the trap with the Ghost CMS bug everyone's about to patch today: closing the SQL injection shuts the door, but the attacker already copied the keys to the building.