Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing ...
Metabase SQL injection vulnerability gave unauthenticated attackers full admin access and downstream database credentials, breaching five companies. CISA added CVSS 10.0 CVE-2026-72898 and Cisco ASA ...
Attackers chained SQL injection with Oracle’s embedded Java capabilities to hide a custom post-exploitation toolkit inside ...
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft ...
A zero-day SQL-injection vulnerability in Metabase Cloud is under exploitation in the wild, and it could spell trouble for many downstream organizations. Metabase, which provides AI-driven business ...
The critical zero-day can provide direct SQL access to Metabase’s underlying database, potentially exposing credentials, API keys, and other sensitive data.
Hackers exploited a SQL injection vulnerability to install a post-exploitation toolkit directly inside an Oracle database ...
For the third year in a row, prompt injection tops the OWASP GenAI / LLM Top Ten list issued today as being the most ...
A critical-severity SQL injection vulnerability in Metabase has been exploited as a zero-day to gain administrative privileges.
By chaining an SQL injection and an API vulnerability, attackers can inject code. WordPress has released an update, the finders a hotfix.
Security researchers tracked and eavesdropped on a WIRED reporter using vulnerabilities in a pink plastic smartwatch. It’s ...