Find a story
Search Spins
Search titles, summaries, and missing voices across published articles — press releases, announcements, and media coverage.
0 results for “SQL injection”
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
Active exploitation of a critical unauthenticated SQL injection vulnerability (CVE-2026-9586) in Sangoma Switchvox VoIP systems enables remote code execution and reverse shell deployment by attackers.
Sep 3, 2026
WordPress backup plugin flaw exposes millions of sites to takeover attacks
A critical SQL injection flaw in the All-in-One WP Migration and Backup plugin enables unauthenticated remote code execution, placing millions of WordPress sites at risk of full compromise.
Sep 3, 2026
ServiceNow warns of three max severity security vulnerabilities
ServiceNow disclosed and patched three critical-severity vulnerabilities in its AI Platform that enable code injection, SQL injection, and privilege escalation — representing a material security risk to customers using the platform.
Aug 30, 2026
GeoServer Zero-Day Targeted in Active Exploitation Attempts, Can Lead to RCE
A zero-day SQL injection vulnerability in the open-source GeoServer platform is under active exploitation, enabling remote code execution, with no patch yet available and no assigned CVE identifier.
Published Aug 13, 2026 · Analyzed Aug 17, 2026
Metabase SQLi zero-day exploited in customer data-theft attacks
A critical, unpatched SQL injection vulnerability in Metabase was actively exploited in zero-day attacks to steal customer data from at least two organizations—Framework and Tally—exposing real-world compromise before public disclosure or remediation.
Aug 8, 2026
datasette 1.0a38
Datasette 1.0a38 patches a SQL injection vulnerability enabling unauthorized read access to private tables when public and private tables coexist in the same database under Datasette’s permissions system.
Aug 7, 2026
datasette 0.65.3
Datasette 0.65.3 was released with a back-ported SQL injection security fix originally introduced in version 1.0a38.
Aug 7, 2026
Hackers run khunt post-exploitation toolkit from Oracle database
Attackers leveraged a SQL injection flaw to deploy the Khunt post-exploitation toolkit inside an Oracle database, enabling lateral movement and persistence within a corporate network.
Aug 6, 2026