Zero-Day Drama: Hackers Exploit PostgreSQL Flaw for Remote Code Shenanigans

Rapid7 has uncovered a new SQL injection flaw in PostgreSQL, CVE-2025-1094, linked to BeyondTrust software exploits. This vulnerability, affecting the psql tool, allows attackers to execute arbitrary code. PostgreSQL has issued updates to patch this flaw, ensuring your software doesn’t get more holes than a donut factory on overtime.

Pro Dashboard

Hot Take:

Looks like the cybercriminals are leveling up their game faster than a teenager on a Red Bull-fueled Fortnite binge. With these new vulnerabilities popping up like weeds in a garden, it’s clear the hackers are working overtime—and not even overtime pay would make this worth it!

Key Points:

  • Threat actors exploited a zero-day vulnerability in BeyondTrust’s PRA and RS products and also an SQL injection flaw in PostgreSQL.
  • The PostgreSQL vulnerability, CVE-2025-1094, has a CVSS score of 8.1 and affects the interactive tool psql.
  • Successful exploitation of CVE-2024-12356 required exploiting CVE-2025-1094.
  • PostgreSQL versions have been updated to patch the flaw.
  • CISA added another remote support software flaw to its KEV catalog, requiring federal agencies to fix it by March 2025.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here
The Nimble Nerd
Confessional Booth of Our Digital Sins

Okay, deep breath, let's get this over with. In the grand act of digital self-sabotage, we've littered this site with cookies. Yep, we did that. Why? So your highness can have a 'premium' experience or whatever. These traitorous cookies hide in your browser, eagerly waiting to welcome you back like a guilty dog that's just chewed your favorite shoe. And, if that's not enough, they also tattle on which parts of our sad little corner of the web you obsess over. Feels dirty, doesn't it?