Skip to main content

Tag: sql injection

25 articles

Laptop on a neutral desk in a blurred office setting.

ServiceNow Flaws Expose Code, SQL to Unauthenticated Attackers

Critical vulnerabilities in ServiceNow's Now Platform could allow unauthenticated attackers to execute arbitrary code or SQL, putting sensitive data at risk. Three flaws, earning the maximum CVSS score of 10.0, were recently disclosed, highlighting an urgent need for patching to prevent devastating attacks.

Analyst 207
Laptop on cluttered desk with blurred login screen, surrounded by papers and coffee cups in modern office.

Metabase Zero-Day Exploited to Breach Framework Customer Data

A zero-day exploit in analytics provider Metabase has led to a data breach at laptop maker Framework, exposing personal customer information, and prompting a review of its data storage methods with external vendors. Metabase has since patched the bug, blocked attack endpoints, and deployed a fix across its cloud service to prevent further exploitation.

Analyst 207
Rows of computer servers and networking equipment in a brightly-lit server room with a single, unoccupied workstation in…

Metabase Zero-Day Exploits Grant Admin Access

A critical zero-day vulnerability in Metabase allows hackers to gain admin access and wreak havoc on your data, with a perfect 10.0 CVSS score highlighting the severity of this threat. Attackers can inject malicious SQL, steal sensitive credentials, and export data, making immediate patching a top priority.

Analyst 207
Laptop screen on a plain desk in a blurred office setting with a faint shadow.

Metabase Zero-Day Exploited in Data-Theft Attacks

Metabase Cloud was recently hit by a data-theft attack, exploiting a previously unknown security vulnerability in versions 1.58 and above, which the company has since patched and confirmed had a maximum severity rating. If you're a self-hosted customer, you'll need to update manually to protect yourself.

Analyst 207
Rows of servers in a brightly-lit data center with one server in focus and others blurred.

Oracle Database Exploited to Hide Post-Exploitation Toolkit

Stay one step ahead of hackers by ensuring your online forms are secure and not vulnerable to injection - a crucial defense against SQL injection attacks that can lead to devastating breaches.

Analyst 207
Rows of computer servers in a brightly-lit data center with a single unoccupied workstation in the foreground.

Oracle Exploited: Attackers Turn SQL Injection into Windows SYSTEM Access

Attackers have successfully exploited a SQL injection vulnerability to gain unprecedented access to Oracle databases, converting it into a Windows SYSTEM-level access with alarming ease. This rare and sophisticated technique has allowed hackers to deploy a custom toolkit, dubbed khunt, that turns database-stored Java into a powerful post-exploitation tool.

Analyst 207
Server room interior with rows of equipment and a blurred database server in the foreground.

Hackers Embed khunt Toolkit in Oracle Database via SQL Injection

Security researchers have uncovered a rare and stealthy attack where hackers embedded the Khunt toolkit in an Oracle database using a SQL injection technique, highlighting a seldom-documented threat in the wild. The attack started with a simple vulnerability in an autocomplete search feature that allowed malicious input to slip through.

Analyst 207
Rows of rack-mounted servers and storage systems in a brightly-lit data center with a single workstation in the foreground.

cPanel Flaw Exposes Database Vulnerability to Authenticated Users

A critical cPanel flaw, CVE-2026-58048, with a near-perfect CVSS score of 9.4, allows authenticated users to execute SQL commands with root-level access, putting databases at risk. This vulnerability lets users with basic cPanel access escalate privileges and take control of the server's administrative database.

Analyst 207
Server room with IT staff in background, focus on single server with open panel showing circuit boards and cables.

Attackers Exploit, Then Manipulate: The Post-Breach Playbook

Attackers often find an open door in our defenses, exploiting weaknesses like SQL injection vulnerabilities to gain a foothold - and then manipulate systems to wreak havoc. A recent incident revealed how an unvalidated input field on a webpage led to a full-blown breach of a Microsoft SQL Server host.

Analyst 207
WordPress dashboard on a laptop screen in a modern office setting with a blurred cityscape background.

WordPress Exploits Spread as Attackers Chain Critical Vulnerabilities

Within hours of public disclosure, hackers leveraged AI models to exploit two critical WordPress vulnerabilities, CVE-2026-60137 and CVE-2026-63030, that when combined enable unauthenticated remote code execution. This potent pairing allows attackers to wreak havoc on websites, highlighting the urgent need for updates.

Analyst 207
Blurred laptop screen displays abstract website backend with faint code.

Vulnerabilities Exposed in AI-Assisted Cyber Attacks

Beware: a potent pair of WordPress Core vulnerabilities, CVE-2026-63030 and CVE-2026-60137, can be chained together to allow anonymous remote code execution - and attackers are already exploiting them in the wild. Patch immediately to avoid devastating consequences.

Analyst 207
Vulnerable WordPress site setup with laptop, router, and modem on a minimalist desk.

WordPress Sites Targeted as Public Exploits Emerge for wp2shell Flaws

A critical vulnerability in WordPress Core, dubbed "wp2shell," has been discovered, allowing hackers to remotely execute code on affected sites - putting your online presence at risk if you haven't updated yet. Immediate action is urged for site operators to protect against this high-severity threat.

Analyst 207
Laptop on a minimalist desk with a potted plant and stack of paper in soft natural light.

WordPress Discloses Core Flaw Enabling Unauthenticated Code Execution

WordPress has patched a critical flaw that allowed hackers to execute code remotely without authentication, releasing versions 6.9.5 and 7.0.2 to fix the vulnerability. The update addresses a REST API batch-route confusion and SQL injection issue that could be triggered by a simple HTTP request.

Analyst 207
A clutter-free workstation with a blank laptop screen in a brightly-lit research facility.

LangGraph Flaw Chain Enables Remote Code Execution in Self-Hosted AI Agents

A critical flaw in LangGraph's system could let attackers take control of your self-hosted AI agents with just a single exploit, allowing for remote code execution. Thankfully, the vulnerability has been patched after being discovered by cybersecurity researchers Check Point and Yarden Porat.

Analyst 207
Large, empty government building interior with podium and blurred seal on wall.

CISA Mandates Patching of Exploited Drupal Vulnerability

The US Cybersecurity and Infrastructure Security Agency has issued a directive requiring federal agencies to patch a critical Drupal vulnerability, known as CVE-2026-9082, by May 27 to prevent devastating SQL injection attacks. This highly critical flaw allows hackers to exploit PostgreSQL-powered Drupal sites and gain unauthorized access to sensitive information.

Analyst 207
Laptop screen displays a blurred CMS interface with a cityscape background.

Ghost CMS Flaw Exploited to Hijack Over 700 Sites in ClickFix Attacks

Over 700 websites were hijacked in a massive campaign that exploited a critical Ghost CMS vulnerability, turning legitimate pages into gateways for Windows malware. This alarming attack was made possible by CVE-2026-26980, an SQL injection flaw with a near-perfect CVSS score of 9.4.

Analyst 207
Laptop screen displays website homepage amidst papers and coffee cups in a busy workspace.

Ghost CMS SQL flaw fuels large-scale ClickFix attacks

Over 700 domains were hit in a massive cyberattack that exploited a critical vulnerability in Ghost CMS, putting sensitive data at risk. The flaw, tracked as CVE-2026-26980, allowed hackers to tap into site databases and steal admin API keys.

Analyst 207
A Drupal website's backend system on a minimalist desk with code on a laptop screen.

Drupal Core SQL Injection Flaw Actively Exploited

Drupal has confirmed that exploit attempts for a critical SQL injection flaw, CVE-2026-9082, are being actively detected in the wild, posing a significant risk of privilege escalation and remote code execution. This vulnerability affects all supported Drupal Core versions and can lead to full site compromise if not addressed promptly.

Analyst 207
Rows of computer servers and networking equipment in a server room or network operations center.

Drupal Sites Targeted in SQL Injection Attacks

Drupal sites are under attack as SQL injection exploits are now being detected in the wild, taking advantage of a vulnerability that can be triggered without authentication. This critical flaw, CVE-2026-9082, allows attackers to execute arbitrary SQL and potentially run remote code, putting sites that use PostgreSQL at risk.

Analyst 207
Rows of computer servers and storage devices in a brightly-lit server room with a single terminal in the foreground.

Drupal Flaw Exposes PostgreSQL Sites to Remote Code Execution Attacks

A vulnerability in Drupal Core's database abstraction API leaves PostgreSQL sites open to devastating SQL injection attacks, allowing hackers to send malicious requests and wreak havoc. This highly critical flaw, tracked as CVE-2026-9082, has been patched with urgent security updates.

Analyst 207
Web development workspace with laptop and coding materials on desk.

Avada Builder Flaws Expose WordPress Sites to Credential Theft

A critical vulnerability in the Avada Builder WordPress plugin, used by an estimated one million active installations, leaves sites exposed to credential theft and data breaches. Two flaws, CVE-2026-4782 and CVE-2026-4798, allow attackers to read sensitive files and extract database information, putting your site at risk.

Analyst 207
Technicians work in a database server room with rows of computer racks and cables.

Security Flaws Exposed in Popular Database Projects' MCP Servers

Critical security flaws have been uncovered in MCP servers used by popular analytics databases, leaving them vulnerable to risks like SQL injection and full database takeover due to faulty validation and authentication processes. These defects, discovered by Akamai security analyst Tomer Peled, highlight a pressing need for enhanced security measures to protect sensitive data.

Analyst 207
Rows of computer servers and networking equipment with a single laptop screen in the foreground.

LiteLLM SQL Flaw Exploited 36 Hours After Disclosure

A critical SQL injection flaw, CVE-2026-42208, was exploited just 36 hours after its disclosure, putting vulnerable LiteLLM versions at risk of unauthorized database access. The bug, with a CVSS score of 9.3, allows unauthenticated callers to reach a vulnerable database query through the proxy's error-handling path.

Analyst 207
Server room with equipment racks and a workstation terminal displaying a blurred interface.

Hackers Exploit LiteLLM SQL Flaw for Sensitive Data Access

Within just 36 hours of being publicly disclosed, a critical SQL injection flaw in LiteLLM, known as CVE-2026-42208, was actively exploited by hackers, allowing them to access sensitive data without authentication. This alarming vulnerability highlights the importance of swift patching, with LiteLLM version 1.83.7 now available to fix the issue.

Analyst 207