
This 'classic' decades-old SQL injection flaw could let hackers take over entire Windows servers, thanks to a nifty database trick
THE SO WHAT
Attackers are weaponizing old primitives in new ways — a decades-old SQL injection plus a database-resident toolkit is enough to own Windows servers. If your threat model assumes ‘we fixed SQLi years ago’, you need a fresh audit of database objects, stored procedures, and app-layer defenses.
READ THE SOURCE
MORE FROM THE WIRE
Deep & Emerging TechAre target-date funds hurting Americans as they live longer?
If default target-date glide paths are too conservative for longer lifespans, the retirement "autopilot" many employees rely on may be structurally underfunding their later years. Employers and fintechs building benefits products have an opening — and a risk — to revisit defaults, education, and personalized allocation rather than assuming the 60/40-at-65 playbook still works.
Deep & Emerging TechTop US hedge funds targeted by major vishing campaign — Blackstone, KKR and CME among those under fire
A vishing crew pulling in $10M+ by targeting top hedge funds shows social engineering is scaling like a business line, not a side hustle. If you handle high-value transactions or trading instructions, tighten voice-based authentication this week — callbacks, codewords, and out-of-band checks need to be policy, not folklore.
Deep & Emerging TechZohran Mamdani’s NYC Tech Team Is What DOGE Should Have Been
A city pulling in Silicon Valley and USDS veterans to rebuild core services is a bet that modern civic tech is an execution problem, not a tooling problem. If you sell into government or run public-facing infrastructure, expect procurement and expectations to shift toward product-minded teams who will scrutinize UX, APIs, and delivery cadence, not just compliance boxes.
Deep & Emerging TechPost-Quantum Cryptography Timelines: When Will Organizations Migrate?
Everyone from governments to banks agrees a cryptographically relevant quantum computer is coming — they just disagree on when — which means migration planning is now a governance issue, not a research hobby. If you hold long-lived sensitive data, start inventorying crypto dependencies and vendor timelines this quarter; waiting for consensus on dates is the risky move.