Urgent.News

600+ sources. One page. See who else covered it.

Editions

Tech

GeoServer jsonArrayContains SQL Injection Zero-Day: Mass Probes Hours After Disclosure, RCE Possible Depending on Configuration

GeoServer jsonArrayContains SQL Injection Zero-Day: Mass Probes Hours After Disclosure, RCE Possible Depending on Configuration 1. Basic Information Severity: Critical Article Title: Hackers Exploiting Unpatched GeoServer Zero-Day Publisher: SecurityWeek Publication Date: 2026-08-14 Update Date: None Original Article: Original Article Related Sources: None Malware: None Groups: None CVEs:…

A critical SQL injection vulnerability was discovered in GeoServer's jsonArrayContains filter. Within hours of its public disclosure, hundreds of unauthorized attempts were made to exploit this flaw. The GeoServer jsonArrayContains function improperly includes user-provided arguments in database queries, allowing attackers to manipulate data and potentially execute arbitrary code depending on the server's configuration.

While no confirmed remote code execution (RCE) cases have been reported, the vulnerability is particularly dangerous for systems running GeoServer with PostGIS, Oracle, or H2 data stores and without proper security measures. Organizations should immediately apply patches, limit exposure, and monitor for abnormal filter queries, SQL errors, and child processes indicating potential attacks.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

AmnesiaStealer: macOS Infostealer that Hijacks In-Browser Sessions via ClickFix

AmnesiaStealer: macOS Infostealer that Hijacks In-Browser Sessions via ClickFix 1. Basic Information Severity: High Article Title: AmnesiaStealer: a multi-stage Rust-based macOS infostealer that…

  • AmnesiaStealer is macOS-specific infostealer targeting Chromium browsers
  • Distributed via fake GitHub ClickFix page tricking users into executing shell script
  • Steals login passwords, Keychain data, documents, browser info using CDP control

SAP Commerce Cloud CVE-2026-58231: Active Exploit Attempts for Unauthenticated RCE

SAP Commerce Cloud CVE-2026-58231: Active Exploit Attempts for Unauthenticated RCE 1. Basic Information Severity: Critical Article Title: Max severity SAP Commerce Cloud flaw now targeted in attacks…

  • Critical flaw CVE-2026-58231 allows unauthenticated RCE in SAP Commerce Cloud.
  • Active exploit attempts confirmed three days after security patch release.
  • Potential risk of compromised systems due to numerous associated IP addresses.

Day 14: AWS Compute — Managed & Serverless

We started the compute layer on Day 13 with EC2, ELB, and Auto Scaling — where you launch and manage everything yourself.

  • AWS Elastic Beanstalk simplifies deployment by managing EC2 instances and load balancing.
  • Amazon Lightsail offers pre-configured virtual servers with fixed pricing for common applications.

macOS Screen Sharing CVE-2026-65400: Authentication Bypass Leads to Root Access and Monero Miner Installation

macOS Screen Sharing CVE-2026-65400: Authentication Bypass Leads to Root Access and Monero Miner Installation 1. Basic Information Severity: Critical Title: Hackers exploit macOS Screen Sharing flaw…

  • Authentication bypass vulnerability in macOS Screen Sharing exploited
  • Hackers gain root access and install Monero miner
  • Update macOS, disable Screen Sharing to mitigate risk

More from Saturday 15 August →