news
PostgreSQL and MongoDB Leftovers
-
PostgreSQL ☛ pg_ivm 1.16 released
IVM Development Group is pleased to announce the release of pg_ivm 1.16.
-
PostgreSQL ☛ pgvector 0.8.7 Released
pgvector 0.8.7 is now available. This release fixes a buffer overflow with IVFFlat index builds (CVE-2026-103484), which can lead to arbitrary code execution. Users are encouraged to upgrade when possible.
-
PostgreSQL ☛ pg_vault_tde v1.7.2 : Critical crash fixes, new on-disk format, and stability improvements
Version 1.7.2 of
pg_vault_tdeis now available. This is a binary patch release where extension version stays at 1.7, but users can distinguish the build at runtime usingpg_vault_tde_build_version(). -
Connor Tumbleson ☛ Software & Secure Defaults
A long time ago somewhere in 2015 I remember hearing about a bunch of MongoDB databases were wiped with ransom notes left. At first I was so curious how an attacker did this, then I realized it was just public accessible databases with no authentication.
When you think about that - it's hardly a hack. Just a misconfiguration of a system in a highly insecure way. So what did MongoDB do? They changed the defaults to produce a more secure system by default (authentication and only binding to 127.0.0.1).