Metabase SQL injection vulnerability gave unauthenticated attackers full admin access and downstream database credentials, breaching five companies. CISA added CVSS 10.0 CVE-2026-72898 and Cisco ASA ...
A zero-day SQL-injection vulnerability in Metabase Cloud is under exploitation in the wild, and it could spell trouble for many downstream organizations. Metabase, which provides AI-driven business ...
A critical Metabase SQL injection vulnerability was exploited in zero-day attacks to breach customer instances in data theft ...
Huntress spotted a white whale - a malicious toolkit stored as a database object.
Attackers chained SQL injection with Oracle’s embedded Java capabilities to hide a custom post-exploitation toolkit inside ...
Google has fixed the issues, which exploited a trust boundary between two AI agents with different privileges to potentially ...
Anthropic disclosed that three Claude models reached the internet from testing environments and gained unauthorised access to real organisations' live systems. One uploaded a malicious PyPI package ...
Filters don't stop prompt injection; architecture does. A field guide to the lethal trifecta, the rule of two, Dual-LLM and ...
A two-person Brisbane company reckons the answer is a smaller box, used properly. On a modest 8-core CPU VM, a machine most ...
Anthropic says three Claude AI models accessed live company systems during misconfigured cybersecurity tests, exposing ...
Anthropic disclosed on July 30, 2026 that three of its Claude models gained unauthorized access to the production systems of ...
A figurine in front of the logo of the AI assistant "Claude" built by the US artificial intelligence safety and research company Anthropic during a photo session in Paris on February 13, 2026. Joel ...