PostgreSQL Zero-Day Chaos: BeyondTrust Breached and Treasury Tangled!
The Rapid7 team discovered a PostgreSQL zero-day vulnerability that helped attackers breach BeyondTrust. This PostgreSQL zero-day exploit, CVE-2025-1094, facilitates SQL injections, playing a crucial role in the BeyondTrust breach. Rapid7 highlighted that the patch for CVE-2024-12356 inadvertently prevents CVE-2025-1094 exploitation, showcasing accidental cybersecurity brilliance.

Hot Take:
Well, folks, if you thought your database was safe and sound, think again! The hackers are at it again, and this time they’ve got a new toy to play with – a zero-day vulnerability in PostgreSQL. Just when you thought it was safe to go back in the database waters, here comes the cyber equivalent of Jaws. Looks like it’s time to batten down the hatches and patch those systems before your precious data becomes hacker sushi!
Key Points:
- Attackers exploited a PostgreSQL zero-day to breach BeyondTrust in December.
- Two zero-day bugs and a stolen API key were involved in the breach.
- The U.S. Treasury was also compromised, linked to Chinese hackers “Silk Typhoon.”
- CVE-2024-12356 and CVE-2024-12686 were pivotal vulnerabilities.
- Rapid7 discovered another PostgreSQL zero-day, CVE-2025-1094.