View Ridge Security
Back to Cyber HoseThreat Research & Deep Dives

Attackers Probe GeoServer SQL Injection That Can Enable RCE

πŸ•΅οΈ RESEARCH & DEEP DIVES

  • Attackers Probe GeoServer SQL Injection That Can Enable RCE
    Attackers are probing an unauthenticated GeoServer SQL injection that can enable RCE.

    • GeoServer deployments support government, defense, utilities, science, education, and technology organizations.
    • The flaw affects the jsonArrayContains filter in GeoTools’ gt-jdbc-postgis package with PostGIS 12 or later and String or JSON fields.
    • Affected package versions include 35.0, 34.0–34.4, and 33.1–33.5; fixes are in 35.1, 34.5, and 33.6, and GeoServer 3.0.1, 2.28.5, and 2.27.6.
    • Unauthenticated attackers can inject SQL through CQL filters sent to public OGC WMS and WFS endpoints.
    • WatchTowr observed hundreds of probes from a small pool of IP addresses; elevated PostgreSQL privileges can turn the injection into OS command execution.
      πŸ“„ Source: github.com Β· πŸ“Ž Coverage: hadrian.io Β· πŸ‘ via Cyber Security News
  • MessiahGPT Offers Criminals Low-Cost AI for Ransomware and Phishing
    MessiahGPT is being marketed as a criminal AI service for generating malware and phishing content.

    • Cybercriminals on BreachForums and Telegram are being targeted by the service.
    • MessiahGPT advertises ransomware, phishing kits, stealers, crypters, rootkits, and social-engineering content.
    • The service operates at messiahgpt[.]de and reportedly offers 50 free queries before cryptocurrency subscriptions starting at about $8 per month.
    • Operators claim an uncensored Mixture-of-Experts model trained on unrestricted manuals, dark-web archives, leaked documents, and raw web data; Trellix could not independently verify those claims.
      πŸ“„ Source: trellix.com Β· πŸ“Ž Coverage: cybersecuritynews.com Β· πŸ‘ via Cyber Security News, cryptika.com (discovered)

πŸ”“ CVEs & KEV

  • CVE-2026-15623 β€” CVSS 9.4 β€” Authenticated Blind SQL Injection in Google Cloud SecOps SOAR Dashboard Widge...

  • CVE-2026-22072 β€” CVSS 8.3 β€” Arbitrary URL Loading in WebView Leading to Token Leakage RiskLoading arbitra...

Need help assessing your exposure?

Start with the free Posture Self-Check to see where you stand against the current threat landscape.

Free Posture Self-Check