#sqlinjection

13 posts· Last used 18d

Active exploitation attempts are targeting CVE-2026-9586, a critical unauthenticated SQL injection in Sangoma Switchvox SMB Edition. A single crafted request enables arbitrary SQL execution on PostgreSQL and leads to remote code execution via reverse shell. Immediate patching and exposure review are critical. #Switchvox #SqlInjection #ThreatIntel https://cyberworldops.eu/en/switchvox-under-attack-critical-sql-injection-installs-reverse-shell
0
0
0
0
🚨 CRITICAL: WordPress Core "wp2shell" RCE A single anonymous HTTP request can lead to Remote Code Execution on vulnerable WordPress Core installations. ⚠️ No plugins. ⚠️ No themes. ⚠️ No authentication required. Tracked as: 🔴 CVE-2026-63030 (REST API Batch Route Confusion → RCE) 🔴 CVE-2026-60137 (Facilitated SQL Injection) Affected versions • WordPress 6.9.0–6.9.4 • WordPress 7.0.0–7.0.1 ✅ Update immediately to WordPress 6.9.5 or 7.0.2. Due to the severity, WordPress has enabled forced automatic security updates for affected installations. 🔗 Full technical analysis: https://thecybersecguru.com/news/wordpress-core-rce-wp2shell/ #WordPress #WordPressSecurity #wp2shell #CVE202663030 #CVE202660137 #RCE #RemoteCodeExecution #SQLInjection #RESTAPI #CyberSecurity #InfoSec #WebSecurity #WebsiteSecurity #PatchNow #ThreatIntelligence #BlueTeam #SOC #Linux #PHP #ZeroDay #SecurityResearch #SysAdmin #DevSecOps
35
4
57
0
If you're looking at the #Wordpress PoC for https://github.com/WordPress/wordpress-develop/security/advisories/GHSA-ff9f-jf42-662q at https://github.com/attackercan/wp2shell-poc2 , please be aware that the "check" and "read" PoC do not always work. I assume it was created on an empty Wordpress install (with 0 posts). But if it's populated, the OR SLEEP(3) is short circuited away. Trust your version.php instead. (wp2shell-poc does not have an issue tracker enabled to report this to.) #sqlinjection #vulnerability #cve #infosec
1
0
1
0
https://codewall.ai/blog/how-we-hacked-mckinseys-ai-platform "The agent mapped the attack surface and found the API documentation publicly exposed — over 200 endpoints, fully documented. Most required authentication. Twenty-two didn't. One of those unprotected endpoints wrote user search queries to the database. The values were safely parameterised, but the JSON keys — the field names — were concatenated directly into SQL." Read and write access to everything. #mckinsey #security #ai #sqlinjection
4
2
11
1
You've seen all posts