AI's RAG platform let attackers run arbitrary queries as PostgreSQL superuser - and the default config has auth turned off.
Attackers who exploited a zero-day vulnerability in BeyondTrust Privileged Remote Access and Remote Support products in December likely also exploited a previously unknown SQL injection flaw in ...
Hackers have been exploiting a critical-severity vulnerability (CVE-2026-9586) in the enterprise VoIP telephony management solution Sangoma Switchvox.
A new tool is making the rounds on the criminal underground. Called Katyusha Scanner, this is a hybrid between a classic SQL injection (SQLi) vulnerability scanner and Anarchi Scanner, an open-source ...
Security researchers have developed a generic technique for SQL injection that bypasses multiple web application firewalls (WAFs). At the core of the issue was WAF vendors failing to add support for ...