Metabase SQL injection vulnerability gave unauthenticated attackers full admin access and downstream database credentials, breaching five companies. CISA added CVSS 10.0 CVE-2026-72898 and Cisco ASA ...
Attackers chained SQL injection with Oracle’s embedded Java capabilities to hide a custom post-exploitation toolkit inside ...
Devart has earned recognition across five DBTA categories, highlighting strengths in administration, performance, ...
Attackers compile khunt inside Oracle after a web SQL injection, reach Windows SYSTEM, and stage credential data and registry ...
Devart today launched Devart SQL Formatter Online, a browser-based SQL Server code formatter that provides immediate ...
A post-exploitation toolkit has been found compiled and stored inside an Oracle database as schema objects, giving attackers ...
A critical-severity SQL injection vulnerability in Metabase has been exploited as a zero-day to gain administrative privileges.
See how ControlCom Connect uses TimescaleDB to monitor thousands of industrial assets, process 300M+ data points monthly, and uncover costly anomalies.
The critical zero-day can provide direct SQL access to Metabase’s underlying database, potentially exposing credentials, API keys, and other sensitive data.
Huntress spotted a white whale - a malicious toolkit stored as a database object.