⤷ Title: The Code Was Fine. The Access Model Was Not.
════════════════════════
𐀪 Author: Shiki65536@TechRoamer
════════════════════════
ⴵ Time: Sun, 19 Jul 2026 09:05:37 GMT
════════════════════════
⌗ Tags: #application_security #postgresql #database_security #backend_development #supabase
════════════════════════
𐀪 Author: Shiki65536@TechRoamer
════════════════════════
ⴵ Time: Sun, 19 Jul 2026 09:05:37 GMT
════════════════════════
⌗ Tags: #application_security #postgresql #database_security #backend_development #supabase
Medium
The Code Was Fine. The Access Model Was Not.
This week, Supabase flagged several backend tables with: RLS Disabled in Public.
⤷ Title: Critical Apache Doris Flaw (CVE-2026-58319) Exposes Admin APIs to Unauthenticated Attackers
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 13:30:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Doris #CVE_2026_58319 #database security #improper authentication #Vulnerability
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Mon, 20 Jul 2026 13:30:28 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #Apache Doris #CVE_2026_58319 #database security #improper authentication #Vulnerability
Daily CyberSecurity
Critical Apache Doris Flaw (CVE-2026-58319) Exposes Admin APIs to Unauthenticated Attackers
TL;DR The Apache Doris project has patched a critical Apache Doris vulnerability, tracked as CVE-2026-58319. Some Frontend (FE) HTTP REST admin APIs were reachable without authentication. As a res…
⤷ Title: Database developments DON’Ts
════════════════════════
𐀪 Author: Zahir Mohideen
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 15:46:51 GMT
════════════════════════
⌗ Tags: #explain_plan #sql #best_practices #sql_injection #database_development
════════════════════════
𐀪 Author: Zahir Mohideen
════════════════════════
ⴵ Time: Mon, 27 Jul 2026 15:46:51 GMT
════════════════════════
⌗ Tags: #explain_plan #sql #best_practices #sql_injection #database_development
Medium
Database developments DON’Ts
This is my first blog. Based on your feedback , I will be updating this blog , post new blogs .Thanks for looking into this .
⤷ Title: MongoDB Patches 27 Vulnerabilities, Including Memory Corruption, RBAC Bypass, and a Compass Command Injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 14:10:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_11933 #CVE_2026_13059 #CVE_2026_13072 #database security #Denial of Service #memory corruption #mongodb #MongoDB Compass
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 14:10:33 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CVE_2026_11933 #CVE_2026_13059 #CVE_2026_13072 #database security #Denial of Service #memory corruption #mongodb #MongoDB Compass
Daily CyberSecurity
MongoDB Patches 27 Vulnerabilities, Including Memory Corruption, RBAC Bypass, and a Compass Command Injection
TL;DR MongoDB disclosed 27 vulnerabilities across MongoDB Server and the Compass GUI client. Most are denial-of-service bugs, but several allow access-control bypass, information disclosure, or me…
⤷ Title: Microsoft Fixes CosmosEscape Flaw That Could Allow Any Cosmos DB Takeover
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 15:17:42 +0000
════════════════════════
⌗ Tags: #Security #Azure #Azure Cosmos DB #Cosmos DB #CosmosEscape #Cybersecurity #database #Microsoft #Vulnerability
════════════════════════
𐀪 Author: Waqas
════════════════════════
ⴵ Time: Thu, 30 Jul 2026 15:17:42 +0000
════════════════════════
⌗ Tags: #Security #Azure #Azure Cosmos DB #Cosmos DB #CosmosEscape #Cybersecurity #database #Microsoft #Vulnerability
Hackread
Microsoft Fixes CosmosEscape Flaw That Could Allow Any Cosmos DB Takeover
Wiz found CosmosEscape in Azure's Gremlin API, exposing a master key that could access any Cosmos DB account. Microsoft fixed it, with no customer impact found.
⤷ Title: SQL Injection Attacks: Understanding the Threat, Impacts, and Essential Defenses
════════════════════════
𐀪 Author: BlackHat
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 13:30:50 GMT
════════════════════════
⌗ Tags: #business #database #cybersecurity #hacking #artificial_intelligence
════════════════════════
𐀪 Author: BlackHat
════════════════════════
ⴵ Time: Sat, 01 Aug 2026 13:30:50 GMT
════════════════════════
⌗ Tags: #business #database #cybersecurity #hacking #artificial_intelligence
Medium
SQL Injection Attacks: Understanding the Threat, Impacts, and Essential Defenses
SQL Injection Attacks: Understanding the Threat, Impacts, and Essential Defenses SQL injection remains one of the most persistent and damaging web application vulnerabilities. Despite decades of …
⤷ Title: Dynamic Sort
════════════════════════
𐀪 Author: Zahir Mohideen
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 19:44:50 GMT
════════════════════════
⌗ Tags: #sorting #oracle_database #database_security #database_development #sql_injection
════════════════════════
𐀪 Author: Zahir Mohideen
════════════════════════
ⴵ Time: Mon, 03 Aug 2026 19:44:50 GMT
════════════════════════
⌗ Tags: #sorting #oracle_database #database_security #database_development #sql_injection
Medium
Dynamic Sort
Let us say we have a requirement to sort the result set based on the given input parameter . In most of the system , the developers…
⤷ Title: CVE-2026-58048: cPanel Root SQL Execution Flaw Patched
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 01:01:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CPanel #CVE_2026_58047 #CVE_2026_58048 #database security #http_request_smuggling #privilege escalation #Web Hosting Security #WHM
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Tue, 04 Aug 2026 01:01:20 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #CPanel #CVE_2026_58047 #CVE_2026_58048 #database security #http_request_smuggling #privilege escalation #Web Hosting Security #WHM
Daily CyberSecurity
CVE-2026-58048: cPanel Root SQL Execution Flaw Patched
TL;DR: cPanel patched a cPanel root SQL execution flaw tracked as CVE-2026-58048, rated CVSS 9.4. A second, lower-severity bug, CVE-2026-58047, allows HTTP request smuggling under limited conditio…
⤷ Title: pgAdmin 4 RCE Flaw Leads Three Critical Fixes in Version 9.17
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 01:02:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Assistant Security #Credential Theft #CVE_2026_17566 #Database Tools #pgAdmin #PostgreSQL #Remote Code Execution #sql injection
════════════════════════
𐀪 Author: Do Son
════════════════════════
ⴵ Time: Wed, 05 Aug 2026 01:02:51 +0000
════════════════════════
⌗ Tags: #Vulnerability Report #AI Assistant Security #Credential Theft #CVE_2026_17566 #Database Tools #pgAdmin #PostgreSQL #Remote Code Execution #sql injection
Daily CyberSecurity
pgAdmin 4 RCE Flaw Leads Three Critical Fixes in Version 9.17
TL;DR: The pgAdmin Development Team patched a pgAdmin 4 RCE flaw tracked as CVE-2026-17566, rated CVSS 9.4. Version 9.17 also fixes a credential-cloning bug and an AI Assistant bypass, alongside f…
⤷ Title: When the Database Becomes the Attacker: The khunt Oracle SQL Injection Incident
════════════════════════
𐀪 Author: GraySentinel- Cyber Defence Lab
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 06:14:56 GMT
════════════════════════
⌗ Tags: #oracle #database #cybersecurity #threat_intelligence #sql_injection
════════════════════════
𐀪 Author: GraySentinel- Cyber Defence Lab
════════════════════════
ⴵ Time: Fri, 07 Aug 2026 06:14:56 GMT
════════════════════════
⌗ Tags: #oracle #database #cybersecurity #threat_intelligence #sql_injection
Medium
When the Database Becomes the Attacker: The khunt Oracle SQL Injection Incident
How a classic SQL injection flaw led to SYSTEM-level compromise through Oracles Java engine