logo

Critical PostgreSQL bug tied to zero-day attack on US Treasury

ID: e67214c7-c54d-54f7-bbf8-8a50c6693ea4

STIX ID: report--e67214c7-c54d-54f7-bbf8-8a50c6693ea4

Feed Name: The Register (Security)

Threat Score
90/100

Date Published: 2025-02-14

Date Updated: 2026-04-26

Author: Connor Jones

...
...

Rapid7 disclosed CVE-2025-1094, a high-severity SQL injection in the PostgreSQL interactive tool (psql) that enables arbitrary code execution by abusing invalid UTF-8 handling; this bug was a required component in an exploit chain combined with a BeyondTrust zero-day (CVE-2024-12356) used in the December intrusion against the US Treasury, and fixes were released on February 13 with technical analysis and IOCs published by Rapid7 and AttackerKB.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.