PCI DSS

Tech Optimizer
February 14, 2025
Researchers have identified a SQL injection vulnerability, CVE-2025-1094, in PostgreSQL's interactive terminal tool, psql. This vulnerability is linked to another vulnerability, CVE-2024-12356, related to remote code execution in BeyondTrust's products. CVE-2025-1094 arises from a flawed assumption about the security of escaped untrusted input and allows attackers to inject malicious SQL statements due to the processing of invalid UTF-8 characters. It has a CVSS 3.1 base score of 8.1, indicating high severity, and can lead to arbitrary code execution through psql's meta-command functionality. The vulnerability affects all supported PostgreSQL versions prior to 17.3, 16.7, 15.11, 14.16, and 13.19. Users are advised to upgrade to these patched versions to mitigate risks. A Metasploit module targeting this vulnerability has been developed, emphasizing the urgency for organizations to implement patches.
Winsage
October 1, 2024
Businesses considering remaining on Windows 10 must evaluate the implications for their cyber insurance coverage, particularly regarding compliance with the Payment Card Industry Data Security Standard (PCI DSS). Non-compliance can result in denied claims or loss of coverage. Key concerns include adherence to PCI DSS standards and the implementation of necessary security measures for point-of-sale systems, such as file integrity monitoring, anti-malware solutions, timely patches, and audit logging. Failing to maintain these protections while operating point-of-sale systems can jeopardize customer data and cyber insurance benefits.
Search