logo

PostgreSQL flaw exploited as zero-day in BeyondTrust breach

ID: 07e90b34-0a3d-5595-9863-b71126485122

STIX ID: report--07e90b34-0a3d-5595-9863-b71126485122

Feed Name: Bleeping Computer

Threat Score
90/100

Date Published: 2025-02-14

Date Updated: 2026-04-20

Author: Sergiu Gatlan

...
...

Rapid7 and public reporting show that attackers exploited multiple zero-day flaws in BeyondTrust Remote Support and a PostgreSQL SQL-injection/RCE flaw to breach 17 BeyondTrust SaaS instances and compromise the U.S. Treasury via a stolen API key; the Treasury intrusion has been attributed to Chinese state-backed APT group Silk Typhoon, which stole unclassified documents related to sanctions and national-security reviews. Rapid7's analysis links a PostgreSQL vulnerability (CVE-2025-1094) to the remote code execution used in the chain, CISA added one of the BeyondTrust flaws to its Known Exploited Vulnerabilities catalog, and patches/mitigations have been issued.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.