Zero-Day Drama: Hackers Exploit PostgreSQL Flaw for Remote Code Shenanigans
Rapid7 has uncovered a new SQL injection flaw in PostgreSQL, CVE-2025-1094, linked to BeyondTrust software exploits. This vulnerability, affecting the psql tool, allows attackers to execute arbitrary code. PostgreSQL has issued updates to patch this flaw, ensuring your software doesn’t get more holes than a donut factory on overtime.

Hot Take:
Looks like the cybercriminals are leveling up their game faster than a teenager on a Red Bull-fueled Fortnite binge. With these new vulnerabilities popping up like weeds in a garden, it’s clear the hackers are working overtime—and not even overtime pay would make this worth it!
Key Points:
- Threat actors exploited a zero-day vulnerability in BeyondTrust’s PRA and RS products and also an SQL injection flaw in PostgreSQL.
- The PostgreSQL vulnerability, CVE-2025-1094, has a CVSS score of 8.1 and affects the interactive tool psql.
- Successful exploitation of CVE-2024-12356 required exploiting CVE-2025-1094.
- PostgreSQL versions have been updated to patch the flaw.
- CISA added another remote support software flaw to its KEV catalog, requiring federal agencies to fix it by March 2025.
Already a member? Log in here