##SQLInjection
Roundcube Webmail is affected by CVE-2026-48842, a high-severity unauthenticated SQL injection in virtuser_query. Exploitation can expose messages, address books, and user identities. #Roundcube #SQLInjection #CVE202648842
Roundcube Webmail Vulnerability In Attackers’ Crosshairs
Threat actors are exploiting a high-severity Roundcube flaw, tracked as CVE-2026-48842, which enables unauthenticated SQL injection through the virtuser_query plugin. Successful attacks can expose messages, address books, user identities, and other sensitive database content, prompting Roundcube to release fixes in versions 1.6.16 and 1.7.1. #Roundcube #CVE-2026-48842 #virtuser_query...
www.hendryadrian.com
September 25, 2026 at 9:00 AM
#KRITIS Sektor #Transport und #Verkehr

#Flughafen-#Sicherheitskontrollen in den USA über #SQLInjection umgangen

"Schwachstelle in der Online-Plattform des #FlyCASS-#Kontrollsystem's auszunutzen, um damit Zugänge zu #Sicherheitsbereichen zu erlangen..."
www.heise.de/news/TSA-Air...
Flughafen-Sicherheitskontrollen in den USA über SQL-Injection umgangen
Sicherheitsforschern in den USA ist es gelungen, über SQL-Injection das FlyCASS-Sicherheitssystem zu täuschen und damit Zugangssperren zu umgehen.
www.heise.de
August 31, 2024 at 3:40 PM
Wir schrieben das Jahr 2024. #SQLInjection ist immer noch ein heisses Thema.

Bypassing airport security via SQL injection https://ian.sh/tsa
August 29, 2024 at 6:57 PM
Alpha game testing with nerds be like:
#gamedev #xkcd #sqlinjection
August 27, 2025 at 9:07 AM
September 25, 2026 at 12:23 PM
September 24, 2026 at 8:32 AM
This was one of our favorite talks from #defon32. This is a really clever approach to getting SQL injection at the protocol level.
#appsec #sqlinjection #hacking #applicationsecurity

www.youtube.com/watch?v=Tfg1...
DEF CON 32 - SQL Injection Isn't Dead Smuggling Queries at the Protocol Level - Paul Gerste
YouTube video by DEFCONConference
www.youtube.com
December 2, 2024 at 2:50 PM
SQL Injections: The only time typing ' OR 1=1-- makes me feel like a Digital Witch 🧙‍♀️

Protection against them:
- Sanitize your inputs
- Use prepared statements
- Lock your databases up

#cybersecurity #sqlinjection
January 11, 2025 at 1:29 AM
A new data leak shows the dangers of secret, silent #stalkerware. An app known as #Catwatchful appears to be just as insecure as all the others.

The Catwatchful app’s user login database was vulnerable to a simple #SQLinjection attack. In #SBBlogwatch, we call for Little Bobby Tables.
Yet More Stalkerware Leaks Secret Data: ‘Catwatchful’ is Latest Nasty App
Content warning: Domestic abuse, stalking, controlling behavior, Schadenfreude, irony.
securityboulevard.com
July 4, 2025 at 4:20 PM
#IT At #38C3 #CCC showed massive #security gaps in #ePA, where medical data for 10s of millions Germans will be stored from 2025 on. The Federal Data Protection Supervisor who warned that this will happen was kicked. One attack vector is #SQLinjection. I do not believe this. Fucking #Database Noobs!
December 28, 2024 at 3:46 PM
Want to keep your financial data secure? You'll need to learn about SQL injection and how it can use malicious code to get to your private information:

#cybersecurity #itsecurityoperations #itsecurity #socservices #SQL #SQLinjection #cyberchallenges #cybercrime #cyberattack
October 3, 2025 at 10:00 AM
December 10, 2023 at 8:25 PM
CRITICAL: Unauthenticated SQL Injection in impleCode eCommerce Product Catalog <=3.5.5. Sensitive data at risk. Patch status unknown — implement input validation & monitor vendor. https://radar.offseq.com/threat/cve-2026-52693-cwe-89-improper-neutralization-of-s-53fcc5a2 #OffSeq #SQLInjection #ec...
CVE-2026-52693: CWE-89 Improper Neutralization of Special Elements used in an SQ
This vulnerability (CVE-2026-52693) involves improper neutralization of special elements used in SQL commands (CWE-89) in impleCode's eCommerce Product Catalog. It affects all versions up to and including 3.5.5. The flaw allows unauthentica
radar.offseq.com
June 16, 2026 at 6:00 AM
I just completed module SQL Injection Fundamentals in HTB Academy!

My first HTBA module of medium difficulty 🚀

The best one so far 👍

academy.hackthebox.com/achievement/...

#hackthebox #htbacademy #cybersecurity #BugBounty #sqli #sqlinjection
Completed SQL Injection Fundamentals
Databases are an important part of web application infrastructure and SQL (Structured Query Language) to store, retrieve, and manipulate information stored in them. SQL injection is a code injection t...
academy.hackthebox.com
January 20, 2025 at 8:06 PM
🚨 SuiteCRM ≤ 7.14.6 suffers inbound-email SQL injection AND PHP unserialize() RCE (CVSS 8.8)—full DB takeover + remote code execution. 😱

🔗👉 basefortify.eu/cve_reports/...

#SuiteCRM #SQLInjection #RCE #CyberSecurity
August 7, 2025 at 7:48 AM
😱 Despite being alerted since Feb 2022, SicommNet STILL hasn’t fixed this vulnerability! ⚠️ Repeated messages via email, LinkedIn, and even CISA have been ignored, leaving systems wide open to attack. Time is running out—every second counts! ⏰💣 #SQLInjection #DataBreach
April 14, 2025 at 12:39 PM
Just saw a company lose $8.7M from a SQL injection attack that could've been prevented with parameterized queries

ncse.info/these-5-sql-...

#SQLInjection #CyberSecurity #TechInnovation #DecentralizedWeb #Queries #DataProtection #TechLeadership #BlueskyCommunity #WebSecurity #DevSecOps
These 5 SQL Injection Attacks Are Targeting Your Code
SQL injection attacks cost companies millions. Practical prevention guide with secure code examples for developers.
ncse.info
July 1, 2025 at 12:06 PM
Researchers say a bug let them add fake pilots to rosters used for TSA checks
www.theverge.com/202... #cybersecurity #US #TSA #flightcrews #pilots #SQLinjection
Researchers say a bug let them add fake pilots to rosters used for TSA checks
Becoming a pilot through SQL expertise.
www.theverge.com
September 9, 2024 at 2:00 PM