Tag: Databases
-
CBP Workers Allegedly Used Government Databases to Spy on Exes, Crushes, and Colleagues
Records obtained by WIRED detail hundreds of allegations of Customs and Border Protection workers misusing internal tools to look up …
-
TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign
A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as far back as 2020, …
-
Hooking into ActiveRecord’s Connection Pool: A Clean Way to Enable PostgreSQL Row-Level Security
August 6, 2026 Most Rails applications that implement multi-tenancy eventually face the same question: Where should the PostgreSQL tenant …
-
Brazil Health Surveillance Database Exposed 79GB of Sensitive Records
Over 102,000 private records belonging to Brazil’s health surveillance system were left online without passwords or basic encryption. …
-
UK’s Police National Legal Database Reveals Data Breach
A major database containing the work details of British police officers and criminal justice professionals has been compromised, it has …
-
Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database
A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service’s Gremlin query sandbox and obtain full read …
-
1Password launches Privileged Access to cut standing access for AI agents
Identity security company 1Password today launched 1Password Privileged Access, a product that gives engineers and AI agents a single …
-
Critical Splunk Enterprise Flaw Lets Attackers Run Code Without Authentication
Splunk has released security updates to address a critical security flaw in Splunk Enterprise that could be exploited to conduct …
-
Lone attacker published 14 malicious npm packages mimicking popular OpenSearch, Elasticsearch libraries
A single npm user on Thursday published 14 malicious packages within a four-hour window, all mimicking popular OpenSearch, Elasticsearch, …
-
Attackers Use LLM Agent for Post-Exploitation After Marimo CVE-2026-39987 Exploit
An unknown threat actor has been observed using a large language model (LLM) agent to conduct post-compromise actions after obtaining …
-
Company Database Deleted by AI Agent: What Security Leaders Need to Know
Nine seconds — that’s how long it took for an AI agent to delete a company’s production database and volume-level backups. In a …
-
Finance company stores DB credentials in helpfully labeled spreadsheet
Welcome, once again, to PWNED, the weekly column where we recount the adventures of IT explorers who found their own pile of quicksand and …
●●●
