Wiz ZeroDay.Cloud Event Reveals 20-Year-Old PostgreSQL Vulnerabilities
2026-05-04T20:51:45Z•857a1c7df184a5b3cf16b6841e71d33e417b748234e497e9284dce749d3a210c
active-exploitationalphvblackcatbotnetcPanelchina-linkeddata-destructionddosgoogle-appsheetgoogle-drivejenkinsopenclawpaperclippatchespgcryptophishingpostgresqlprivilege-escalationransomwaresecurity-infrastructurethreat-intelligencevect-2.0zero-day
What happened
A set of high-impact security stories: researchers at Wiz ZeroDay.Cloud disclosed decades-old, critical PostgreSQL flaws (pgcrypto) prompting urgent patching; a new VECT 2.0 ransomware strain irreversibly destroys victims’ data; a critical cPanel vulnerability enabling login bypass and root access was actively exploited before fixes; misconfigured Jenkins servers have been abused to deploy a DDoS botnet against gaming infrastructure; Google AppSheet/Drive is being used in large-scale Facebook phishing; SOCRadar reported a massive China-linked operation (OpenClaw/Paperclip) responsible for tens
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- hackread
- Record identifier
- 857a1c7df184a5b3cf16b6841e71d33e417b748234e497e9284dce749d3a210c
- Enrichment time
- 2026-05-04T20:51:45Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.