Blog

Latest articles and insights

SimplyProxies — our UK mobile proxy service. Real 4G/5G devices, pay-as-you-go from £2/GB. Free 500 MB trial, no card.

Try it free
HB

E is for Exploit: CVE-2026-17543 — SQL Injection in PHP's pgsql Extension via the `E'...'` Backslash Breakout

On July 30, 2026, NIST’s National Vulnerability Database published CVE-2026-17543, a SQL injection vulnerability sitting not in some neglected WordPress plugin, but in PHP itself — specifically the pgsql extension that ships with the language. NVD scores it 9.8 Critical (C…

HB

One Quote Too Many: CVE-2026-17351 — How a Backslash Broke pgAdmin's AI Assistant Read-Only Guard (Twice)

On July 24, 2026, a security researcher going by Kai Aizen (SnailSploit) reported a bypass of a patch that was less than six weeks old. The patch, shipped in pgAdmin 4 v9.16 on June 18, was supposed to stop the AI Assistant from executing anything but read-only SQL. The bypass, …

HB

MCP as a Backdoor: CVE-2026-66012 — How a Missing Authorization Check in SiYuan's MCP Endpoint Turns Anonymous Readers into Administrators

On July 25, 2026, NIST’s National Vulnerability Database published CVE-2026-66012, a missing-authorization vulnerability in SiYuan — the privacy-first, block-level note-taking application with over 45,000 GitHub stars and a large Docker-hosted user base. NVD scores it 10.0…

Tags

Account-Takeover Agentic-AI android Android Android-Adb Android-apktool Android-Avd Android-Studio Anti-Bot API-Security Authentication Automotive Backslash-Breakout Baseband Bot-Detection Browser-Automation Browser-Fingerprinting Buffer-Overflow C2 Cache-Key-Collision Camoufox CAN-Bus CAPTCHA Chrome Cloudflare Command-Injection Container-Escape Cross-Site-Scripting Cudy CWE-121 CWE-122 CWE-125 CWE-1333 CWE-23 CWE-288 CWE-290 CWE-347 CWE-384 CWE-706 CWE-798 CWE-862 CWE-89 CWE-926 CWE-94 Data-Scraping Denial-of-Service Diagnostics Elixir Embedded-Systems Exploit FastGPT Firmware Frida Geolocation GooglePlay Hardware Heap-Overflow Hi-Browser html-sanitize-ex HTTP2 Hugging-Face Identity-Confusion Information Security Integer-Overflow IoT JNI JWT Lexer-Differential Linux Linux-Kernel llama-cpp LLaMA-Factory LLM LwM2M Machine-Learning MCP MediaTek Memory Disclosure MindsDB Missing-Authorization mitmproxy Mobile-Security MQTT Network-Analysis Networking OAuth OAuth2 OBD2 OIDC OpenID-Connect Out-of-Bounds Page-Cache Patchright Path-Traversal Penetration Testing pgAdmin PHP phpIPAM Playwright PostgreSQL Privilege-Escalation Prompt-Injection Python Race-Condition RCE ReDoS Reverse Engineering Reverse-Engineering Router Ruby Samsung-Bixby Samsung-Exynos Security Security-Research Session Hijacking Session-Hijacking SiYuan SMS Snapchat SNMP Speech-Recognition SQL-Injection SSD SSL-Pinning STIG-Manager Supply-Chain TECNO Tenda Traefik UC-Browser UDS Vulnerability Web Applications Web Scraping Web-Crawling Web-Scraping Web-Security WebGPU Websocket WeChat Wi-Fi Zammad Zephyr Zero-Day