Attackers chained SQL injection with Oracle’s embedded Java capabilities to hide a custom post-exploitation toolkit inside ...
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database ...
James Bennett of Liquibase walks through a live demo of targeted rollback, undoing one bad database change without a full restore or risky fix forward.
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft ...
Metabase SQL injection vulnerability gave unauthenticated attackers full admin access and downstream database credentials, breaching five companies. CISA added CVSS 10.0 CVE-2026-72898 and Cisco ASA ...
Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing ...
Attackers compile khunt inside Oracle after a web SQL injection, reach Windows SYSTEM, and stage credential data and registry ...
A post-exploitation toolkit has been found compiled and stored inside an Oracle database as schema objects, giving attackers ...
The critical zero-day can provide direct SQL access to Metabase’s underlying database, potentially exposing credentials, API keys, and other sensitive data.
Customers run the same Base Database Service available in OCI on a compact engineered system called Data Infrastructure Cloud@Customer X11. The 8U system is installed at a customer’s facility, and ...
Microsoft and Apple released patches for multiple vulnerabilities across their products, including critical-severity issues.
Legal AI solutions provider LexisNexis shut down Diligence, Newsdesk, and Metabase API data services following a cyber attack ...