watchTowr logged hundreds of exploitation probes against an unpatched GeoServer SQLi bug within hours of its disclosure.
Attackers used an unknown Metabase flaw to grab admin access and customer data before a patch shipped.
Huntress found attackers using Oracle's own Java engine to compile malware directly inside a database.
Adobe patches a CVSS 10 Campaign Classic flaw that allows code execution with no user interaction.
A trio of patched vulnerabilities in LangGraph's checkpoint system can be chained through SQL injection and unsafe deserialization to execute…
The Avada Builder plugin flaws allow low level users to read server files and unauthenticated attackers to steal database credentials.