Collected every two hours from specialised publications — each link leads to the original article.
MyDumper is a MySQL Logical Backup Tool. The MySQL C client library (libmysqlclient) allows authenticated remote actors to read arbitrary files from client sys…
PgBouncer is a lightweight connection pooler for PostgreSQL. CVE-2021-3539
SQL injection in the PostgreSQL driver has been fixed in the ADOdb database access library for PHP. For Debian 11 bullseye, this problem has been fixed in vers…
Keeping WordPress secure can be challenging, especially when considering Linux security concerns in a typical LAMP stack setup. Most WordPress security issues …
Multiple vulnerabilities have been fixed in the PostgreSQL JDBC Driver. CVE-2022-31197
Two vulnerabilities were discovered in pgpool2, a connection pool server and replication proxy for PostgreSQL. CVE-2023-22332
A new stable version was released for galera-4, a synchronous multimaster replication engine for MySQL and MariaDB. This fixes several issues detailed at:
pymongo a python interface to the MongoDB document-oriented database was vulnerable. An out-of-bounds read in the 'bson' module allowed deserialization of
The peer-to-peer malware botnet known as P2PInfect has been found targeting misconfigured Redis servers with ransomware and cryptocurrency miners.The developme…
MariaDB 10.5.25 & Galera 26.4.18 Release notes: https://mariadb.com/kb/en/mariadb-10-5-25-release-notes/
MariaDB 10.11.8 & Galera 26.4.18 Release notes: https://mariadb.com/kb/en/mariadb-10-11-7-release-notes/ https://mariadb.com/kb/en/mariadb-10-11-8-release-note…
A possible SQL injection vulnerability was found in libpgjava, the PostgreSQL JDBC Driver. It allows an attacker to inject SQL if using PreferQueryMode=SIMPLE …
The malicious code inserted into the open-source library XZ Utils, a widely used package present in major Linux distributions, is also capable of facilitating …
A set of fake npm packages discovered on the Node.js repository has been found to share ties with North Korean state-sponsored actors, new findings from Phylum…
Four security vulnerabilities in the ScrutisWeb ATM fleet monitoring software made by Iagona could be exploited to remotely break into ATMs, upload arbitrary f…
According to recent reports, there have been instances of threat actors using malware called ''SkidMap'' to exploit vulnerable Redis systems.
As many as 196 hosts have been infected as part of an aggressive cloud campaign mounted by the TeamTNT group calledSilentbob."The botnet run by TeamTNT has set…
A new Golang-based malware dubbedGoBruteforcerhas been found targeting web servers running phpMyAdmin, MySQL, FTP, and Postgres to corral the devices into a bo…
An update for ovirt-ansible-collection, ovirt-engine, and postgresql-jdbc is now available for Red Hat Virtualization 4 Tools for Red Hat Enterprise Linux 8, R…
In yet another campaign targeting the Python Package Index (PyPI) repository, six malicious packages have been found deploying information stealers on develope…
pgjdbc is an open source postgresql JDBC Driver. In affected versions a prepared statement using either `PreparedStatement.setText(int, InputStream)` or `Prepa…
**MariaDB 10.5.18 & Galera 26.4.13** Release notes: https://mariadb.com/kb/en/mdb-10-5-18-rn/
An update for puppet-mysql is now available for Red Hat OpenStack Platform 13.0 (Queens), 16.1 (Train), 16.2 (Train) and 17.0 (Wallaby). Red Hat Product Securi…
It was discovered that there was a potential SQL injection vulnerability in libpgjava, a Java library for connecting to PostgreSQL databases.