PostgreSQL flaw exploited as zero-day in BeyondTrust breach
ID: 07e90b34-0a3d-5595-9863-b71126485122
STIX ID: report--07e90b34-0a3d-5595-9863-b71126485122
Feed Name: Bleeping Computer
Rapid7 and public reporting show that attackers exploited multiple zero-day flaws in BeyondTrust Remote Support and a PostgreSQL SQL-injection/RCE flaw to breach 17 BeyondTrust SaaS instances and compromise the U.S. Treasury via a stolen API key; the Treasury intrusion has been attributed to Chinese state-backed APT group Silk Typhoon, which stole unclassified documents related to sanctions and national-security reviews. Rapid7's analysis links a PostgreSQL vulnerability (CVE-2025-1094) to the remote code execution used in the chain, CISA added one of the BeyondTrust flaws to its Known Exploited Vulnerabilities catalog, and patches/mitigations have been issued.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
