Vulnerabilities & CVEsIntermediate

12-Year-Old PostgreSQL Vulnerability Enables Database, Server Takeover

A long-dormant database replication vulnerability can be chained to achieve permanent administrative compromise and persistent backdoor access to PostgreSQL systems.

Why this matters

A long-dormant database replication vulnerability can be chained to achieve permanent administrative compromise and persistent backdoor access to PostgreSQL systems.

Check the original work

This explanation is Korpalis’s guide to the material, not a replacement for it. Read the publisher’s page for the full method, evidence and limitations.

Read the original source

Related research

Advanced

39 New Methods That Compromise Passkey Authentication

Researchers documented dozens of attack methods against passkey systems that do not require breaking the underlying FIDO2 cryptography but instead exploit trust boundaries in enrollment, recovery, and credential handling, showing that the cryptographic strength alone does not guarantee authentication security.

Read summary →
Intermediate

Google warns of new Chrome zero-day flaw exploited in attacks

Google released a Chrome update fixing an actively exploited zero-day in the V8 JavaScript engine along with 11 other vulnerabilities. The V8 flaw poses immediate risk to browser users and developers using V8-based tools.

Read summary →
Beginner

Over 3 Million WordPress Sites Affected by Migration Plugin Vulnerability

A SQL injection vulnerability in a widely-deployed WordPress migration plugin could allow attackers to execute arbitrary code on millions of affected websites. The high severity and unauthenticated attack vector make patching critical for site operators.

Read summary →