Source |
The Hacker News |
Identifiant |
8648448 |
Date de publication |
2025-02-14 10:33:00 (vue: 2025-02-14 06:07:59) |
Titre |
PostgreSQL Vulnerability Exploited Alongside BeyondTrust Zero-Day in Targeted Attacks |
Texte |
Threat actors who were behind the exploitation of a zero-day vulnerability in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products in December 2024 likely also exploited a previously unknown SQL injection flaw in PostgreSQL, according to findings from Rapid7.
The vulnerability, tracked as CVE-2025-1094 (CVSS score: 8.1), affects the PostgreSQL interactive tool psql.
"An
Threat actors who were behind the exploitation of a zero-day vulnerability in BeyondTrust Privileged Remote Access (PRA) and Remote Support (RS) products in December 2024 likely also exploited a previously unknown SQL injection flaw in PostgreSQL, according to findings from Rapid7.
The vulnerability, tracked as CVE-2025-1094 (CVSS score: 8.1), affects the PostgreSQL interactive tool psql.
"An |
Notes |
★★★
|
Envoyé |
Oui |
Condensat |
1094 2024 2025 access according actors affects alongside also attacks behind beyondtrust cve cvss day december exploitation exploited findings flaw from injection interactive likely postgresql pra previously privileged products psql rapid7 remote score: sql support targeted threat tool tracked unknown vulnerability who zero |
Tags |
Tool
Vulnerability
Threat
|
Stories |
|
Move |
|