#SQLi
Cloudflare leaked 10% of bot traffic to my homelab. Installed SafeLine WAF via Docker in 5 minutes. Free, self-hosted, blocks SQLi, XSS, DDoS. Guide: https://www.valtersit.com/guides/security/safeline-waf-docker-homelab-api-protection/ #homelab #docker #security
September 27, 2026 at 7:30 AM
Roundcube SQLi & WordPress RCE actively exploited. OpenAI agent accessed Oz health data. Iran-linked ops hit US water. Geopolitical: US/Iran talks, Ukraine ceasefire, US-China-Russia arms talks. #Cybersecurity #Anonymous #News
AnonNews_irc
We Are Anonymous We Do Not Forget Expect us
anon-news-irc.wuaze.com
September 26, 2026 at 7:27 PM
Meta's Muse agent just got a major upgrade, but the real story is AI safety: rogue agents caught attempting XSS, SQLi, and reward-hacking in the wild. https://latent.space/p/ainews-meta-connect-2026-muse-glasses
September 26, 2026 at 6:04 AM
Unauthenticated SQLi (CVE-2026-48842) in Roundcube's virtuser_query plugin lets attackers steal mail data. Patches were out in May '26. That it's still actively exploited makes me intrigued and worried about patching ...
Roundcube Webmail Vulnerability in Attackers' Crosshairs
Threat actors are actively exploiting a high-severity SQL injection vulnerability (CVE-2026-48842) in Roundcube, a widely used open-source webmail client. The flaw, found in the virtuser_query plugin,
www.securityweek.com
September 25, 2026 at 5:04 PM
ServiceNow AI flaws: unauth SQLi = arbitrary SQL on the instance DB. Two 9.3 criticals. Patch self-hosted now. https://intel.threadlinqs.com/threat/TL-2026-2653 #ThreatIntel #CVE_2026_13016 #CVE_2026_86857 #ServiceNow
September 25, 2026 at 12:55 PM
September 25, 2026 at 12:23 PM
September 25, 2026 at 11:57 AM
【セキュリティ ニュース】「ServiceNow AI Platform」にSQLiなど複数脆弱性 - 修正版を提供(1ページ目 / 全2ページ):Security NEXT https://www.security-next.com/190682
September 25, 2026 at 8:15 AM
CVE-2026-84105 IBM Guardium Data Protection 12.2 SQLi lets a remote authenticated attacker pull sensitive data. CVSS 7.7, patch status unknown. Restrict access and update immediately. https://www.valtersit.com/cve/CVE-2026-84105/ #CVE #infosec #IBM
CVE-2026-84105 Vulnerability in IBM
www.valtersit.com
September 25, 2026 at 4:00 AM
FunnelKit: 23 CVEs, max CVSS 9.8, 100% unpatched, trust score D. SQLi and XSS dominate. Patch discipline is failing. https://www.valtersit.com/vendors/funnelkit/ #cybersecurity #infosec #WordPress
Funnelkit
www.valtersit.com
September 25, 2026 at 3:00 AM
「ServiceNow AI Platform」にSQLiなど複数脆弱性 - 修正版を提供

ServiceNow AI Platformに5件の脆弱性が発見され、SQLインジェクションを含むクリティカル脆弱性が複数あります。ServiceNowは利用者にアップデートを推奨しています。

#脆弱性 #情報セキュリティ
「ServiceNow AI Platform」にSQLiなど複数脆弱性 - 修正版を提供
ServiceNow AI Platformに5件の脆弱性が発見され、SQLインジェクションを含むクリティカル脆弱性が複数あります。ServiceNowは利用者にアップデートを推奨しています。
www.security-next.com
September 25, 2026 at 1:01 AM
🤖 CVE-2026-48842: pre-auth SQLi in Roundcube Webmail (virtuser_query), patched in May, now actively exploited. Attackers can bypass auth and steal DB data.
https://www.bleepingcomputer.com/news/security/critical-roundcube-flaw-now-actively-exploited-in-code-injection-attacks/
September 24, 2026 at 1:45 PM
Adobe Connect & AEM Forms face CRITICAL vulnerabilities, including SQLi, XSS, SSRF. Patch within 30 days to prevent code execution & privilege escalation. No active exploits. https://radar.offseq.com/threat/adobe-patches-critical-flaws-in-connect-aem-forms-c099ebdbecb92098 #OffSeq #Adobe #Security
Adobe Patches Critical Flaws in Connect, AEM Forms
Adobe patched nine critical security defects in Adobe Connect, including SQL injection, cross-site scripting (XSS), and improper input validation flaws that could lead to arbitrary code execution and privilege escalation. Six vulnerabilitie
radar.offseq.com
September 23, 2026 at 12:00 PM
18,000 security teams self-host SafeLine WAF to stop SQLi, XSS and RCE before they hit the server. Your box, your logs. 5% off via link.
https://www.valtersit.com/deals/safeline/
#WAF #Infosec #OpenSource
September 23, 2026 at 11:00 AM
Ultimate Member WordPress plugin holds a Trust Score D with 100% of its 20 CVEs unpatched. Max CVSS 9.8, top flaws XSS and SQLi. Patch your sites now. https://www.valtersit.com/vendors/ultimate-member/ #cybersecurity #WordPress #infosec
Ultimate member
www.valtersit.com
September 23, 2026 at 5:00 AM
Master Cybersecurity: The Ultimate 5-in-1 Ethical Hacking Complete Course (2026 Masterclass)
galaxyonknowledge.substack.com/p/master-cyb...
Master Cybersecurity: The Ultimate 5-in-1 Ethical Hacking Complete Course (2026 Masterclass)
Master cyber defense with our free 5-in-1 Ethical Hacking Complete Course. Learn Linux admin, SQLi, WiFi hacking, and social engineering in 4 hours!
galaxyonknowledge.substack.com
September 22, 2026 at 6:13 AM
401-line SQLi tester that replaces FUZZ markers with payloads from a wordlist. For pentesters and security researchers. Advanced. https://www.valtersit.com/python/sql-injection-parameter-tester/ #security #python #infosec
September 21, 2026 at 10:20 AM
Security doesn't always have to start inside the application.

SEOSiri Cloud Defense puts a zero-code edge WAF between attackers and your origin — with SQLi/XSS filtering, BOLA/IDOR enforcement, rate limiting, mobile API protection, and continuous monitoring.
September 20, 2026 at 4:12 PM
🔐 Secure PHP from server to XSS

At #IntPHPcon Munich, part of Agentic Web Week, Marcus Bointon shows you:
🛡️ SSH, TLS & firewalls
💉 SQLi, validation & XSS
🧪 security testing tools

📅 Friday, October 30, 2026 | 🕘 09:00 - 16:30 | IPC | 📍 Munich

🔗 https://tinyurl.com/57d8kdf3

#PHP #WebSecurity
September 18, 2026 at 9:02 AM
( '-`)oO( SQLiでDB全削除って、よっぽどマズい作りしてたとしか…)
September 17, 2026 at 11:08 PM
GitHub - SnailSploit/Claude-Red: claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface
GitHub - SnailSploit/Claude-Red: claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a s...
github.com
September 17, 2026 at 4:30 PM
Laravel Firewall helps you protect your apps from different types of attacks – XSS, SQLi, RFI & more 🔐 - madewithlaravel.com/laravel-fire...
September 17, 2026 at 2:30 PM
🎉 Celebrating! 🎉 (500+ new stars)

📦 SnailSploit / Claude-Red
⭐ 5,572 (+699)
🗒 Python

claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a spe...
GitHub - SnailSploit/Claude-Red: claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a specific attack surface — from SQLi to shellcode, EDR evasion to exploit development.
claude-red is a curated library of offensive security skills designed for the Claude skills system. Each skill is a structured SKILL.md file that primes Claude with expert-level methodology for a s...
github.com
September 17, 2026 at 3:17 AM
7.110 fixed a second-order SQLi that can turn a restore into RCE. The changelog buried it.

Update. Turn off unused trackbacks. Check mu-plugins.

www.bleepingcomputer.com/news/securit...
September 16, 2026 at 10:17 AM
🇫🇷 CERT-FR : Apple (RCE, élév. de privilèges) et Cisco (RCE, SQLi, CVE-2026-76461 exploitée).
https://www.cert.ssi.gouv.fr/avis/CERTFR-2026-AVI-1172/
September 16, 2026 at 5:59 AM