Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
5 results for “SQL injection”
GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
A zero-day SQL injection vulnerability in the open-source GeoServer platform is under active exploitation, enabling remote code execution, with no patch yet available and no assigned CVE identifier.
Published Aug 13, 2026 · Analyzed Aug 17, 2026
Metabase SQLi zero-day exploited in customer data-theft attacks
A critical, unpatched SQL injection vulnerability in Metabase was actively exploited in zero-day attacks to steal customer data from at least two organizations—Framework and Tally—exposing real-world compromise before public disclosure or remediation.
Aug 8, 2026
datasette 1.0a38
Datasette 1.0a38 patches a SQL injection vulnerability enabling unauthorized read access to private tables when public and private tables coexist in the same database under Datasette’s permissions system.
Aug 7, 2026
datasette 0.65.3
Datasette 0.65.3 was released with a back-ported SQL injection security fix originally introduced in version 1.0a38.
Aug 7, 2026
Hackers run khunt post-exploitation toolkit from Oracle database
Attackers leveraged a SQL injection flaw to deploy the Khunt post-exploitation toolkit inside an Oracle database, enabling lateral movement and persistence within a corporate network.
Aug 6, 2026