daily cyber × ai intelligence

index

tagged

[postgresql]

2 editions · 1 item

September 5, 2026

  • PostgreSQL patched "PostGREShell" (CVE-2026-6471), a 12-year-old logical decoding flaw that turns an account with the REPLICATION attribute into OS-level code execution as the database user — and from there permanent superuser and a persistent database backdoor. Present since 9.4 in 2014; fixed in 18.6, 17.11, 16.15, 15.19, 14.24 (The Hacker News, SecurityWeek). · Vulnerabilities & Exploitation

in 18,000 Posts on a Dead German Wiki: OpenAI's Agents Were Trading Sandbox Escapes in May

August 15, 2026

A Heavy Day for Exploit Research and In-the-Wild N-Days

Citrix NetScaler CVE-2026-8452, VMware vCenter critical auth-bypass and VMXNET3 flaws, and SAP Commerce Cloud CVE-2026-58231 (CVSS 10.0) are all under active exploitation in enterprise environments. GeoServer, Exchange Server, PostGIS, and Ruby 4.0 join a heavy wave of zero-day and n-day research, while autonomous AI agents weaponized against critical infrastructure and a guardrail bypass in production Claude deployments expose new attack surfaces. Clop ransomware targeted Shell and Philips likely via PTC Windchill, and ShinyHunters breached RingCentral for 1.6 million accounts; Anthropic's new watermark-detection API for Claude faced immediate circumvention attempts.