Threat actors started exploiting an unpatched zero-day vulnerability in GeoServer hours after it was publicly disclosed, attack surface management firm WatchTowr says. The security defect, described ...
Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing ...
The Hacker News is the top cybersecurity news platform, delivering real-time updates, threat intelligence, data breach ...
Admins responsible for Windows fleets are advised to take action to protect their systems against this actively exploited vulnerability. Here's what you need to do to stay secure.
Metabase SQL injection vulnerability gave unauthenticated attackers full admin access and downstream database credentials, breaching five companies. CISA added CVSS 10.0 CVE-2026-72898 and Cisco ASA ...
The critical zero-day can provide direct SQL access to Metabase’s underlying database, potentially exposing credentials, API keys, and other sensitive data.
Semgrep, a leading code security company, today announced a deepened partnership with Replit to bring automated, real-time security analysis directly into the AI-native development workflow.
Nation-state grade iOS exploit chains Coruna and DarkSword are proliferating among cybercriminals, with 17,000 domains hosting variants.
A critical-severity SQL injection vulnerability in Metabase has been exploited as a zero-day to gain administrative privileges.
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft ...
OpenAI and Anthropic's models have been attacking companies around the world.
Attackers chained SQL injection with Oracle’s embedded Java capabilities to hide a custom post-exploitation toolkit inside ...