MySQL is a technology platform tracked across 32 threat clusters and 49 intelligence report mentions on ThreatCluster. First observed October 29, 2025; most recent activity July 19, 2026.
MySQL is a widely used open-source relational database management system (RDBMS) for storing and querying structured data. The provided articles do not discuss MySQL directly, but the incidents highlight risks to data platforms and compute clusters that commonly host database workloads, underscoring the importance of securing database deployments and data access in cybersecurity.
Recent updates to RoundcubeMail for Fedora 43 and 44 revealed critical vulnerabilities, including SQL injection and cross-site scripting (XSS) issues. CVE-2026-48842 details a pre-auth SQL injection in the…
On April 21, 2026, Oracle released its Critical Patch Update (CPU) for April 2026, which includes 481 security patches addressing 241 unique CVEs across 28 product families. Among these, 34 patches are classified as…
Two critical denial of service vulnerabilities were discovered in MySQL affecting Ubuntu 20.04 LTS. The vulnerabilities, identified as CVE-2026-46862 and CVE-2026-46863, allow unauthenticated remote attackers to crash…
A cyber campaign attributed to the threat actor INJ3CTOR3 is targeting FreePBX systems, deploying a new PHP webshell named JOMANGY. This operation utilizes a six-layer persistence mechanism to maintain control over…
Tenable Research disclosed 'LeakyLooker', a set of nine cross-tenant vulnerabilities in Google Looker Studio, which could allow attackers to exfiltrate or modify data across Google services like BigQuery and Google…
JADEPUFFER, an autonomous AI-driven ransomware, executed a complete extortion operation exploiting CVE-2025-3248. The attack began with a compromised Langflow instance, allowing the AI to gain initial access without…
A critical denial-of-service (DoS) vulnerability, CVE-2026-46863, has been identified in MySQL version 8.4.10, affecting Fedora users. This vulnerability allows remote exploitation without authentication, potentially…
On May 20, 2026, GitHub confirmed a significant security breach involving a poisoned Visual Studio Code (VS Code) extension that compromised an employee's device. The attack, attributed to the TeamPCP hacking group,…
Ian Carroll, a security researcher, exploited an unauthenticated SQL injection vulnerability in Front Gate Tickets, a subsidiary of Live Nation, with assistance from Anthropic's Claude AI. This flaw allowed him to gain…
A significant SQL injection vulnerability has been identified in the python-asyncmy driver used in Fedora 42 and 44. This vulnerability, cataloged as CVE-2025-65896, was published on December 2, 2025, and affects users…