Metabase SQLi zero-day exploited in customer data-theft attacks
…The SQLi vulnerability has been fixed in patched versions for all affected branches from 0.58 through 0.63, with the minimum safe releases being 0.58.24, 0.59.21, 0…
…The SQLi vulnerability has been fixed in patched versions for all affected branches from 0.58 through 0.63, with the minimum safe releases being 0.58.24, 0.59.21, 0…
…updates released in March, April, or later months," Microsoft said in a service alert first spotted by Microsoft MVP Susan Bradley. "This issue results from recent changes in download timeout requirements when…
…The researchers linked the initial server to additional attacker-controlled infrastructure by shared TLS certificates used during the same time period. "In addition to the common name, all these certificates share a…
…On the first day , Orange Tsai earned another $175,000 for a Microsoft Edge sandbox escape chaining 4 logic bugs, Windows 11 was hacked 3 times, and Valentina Palmiotti (chompie) of IBM…
…Google notified the software developer about the significant threat and timely action to disrupt the attack. “For the first time, GTIG has identified a threat actor using a zero-day exploit that…
…The Mechanics of "Slopsquatting" and Machine Ingestion Large language models (LLMs) recommend software libraries based on statistical probability and historical code patterns, not real-time package registry verification. When a model suggests…
…Because it is a deterministic logic bug that does not depend on a timing window, no race condition is required, the kernel does not panic when the exploit fails, and the success…
…Offer the finding on the underground markets. "Hercules" even suggests that an actor could approach the victim and sell the information elsewhere at the same time. Exploit the vulnerability and detect what…
…What began as a textbook engineering discipline governed by documentation and sequential milestones has transformed into an increasingly dynamic process where ideas can become functioning applications in real time. The journey from…
…Series firewalls. "We are aware of only limited exploitation of CVE-2026-0300 at this time. Unit 42 is tracking CL-STA-1132, a cluster of likely state-sponsored threat activity exploiting…