<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>TAC Information Services - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/tac-information-services/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 04 Sep 2026 13:26:42 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/tac-information-services/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Blind SQL Injection Vulnerability in GOLDENHORN ONEIT</title><link>https://feed.craftedsignal.io/briefs/2026-09-goldenhorn-sqli/</link><pubDate>Fri, 04 Sep 2026 13:26:42 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-goldenhorn-sqli/</guid><description>A blind SQL injection vulnerability (CVE-2026-18198) in TAC Information Services GOLDENHORN ONEIT allows unauthenticated attackers to execute arbitrary SQL queries.</description><content:encoded><![CDATA[<p>CVE-2026-18198 is a blind SQL injection vulnerability affecting the TAC Information Services GOLDENHORN ONEIT platform. The vulnerability is caused by improper neutralization of special elements within SQL commands, enabling unauthorized actors to manipulate database queries. This flaw resides in versions prior to the Göbeklitepe release. Successful exploitation allows an attacker to interact with the backend database, potentially leading to unauthorized data exfiltration, modification of application logic, or complete compromise of the database integrity. Because the vulnerability is blind in nature, attackers typically leverage time-based or boolean-based inference techniques to extract data, making the activity subtle and difficult to detect without specialized web application firewall or database auditing logs.</p>
<h2 id="impact">Impact</h2>
<p>The vulnerability carries a CVSS v3.1 base score of 8.8, indicating a high level of risk to confidentiality and integrity. If exploited, an attacker could extract sensitive information stored in the application database or bypass authentication mechanisms. The scope of impact includes all organizations currently running versions of GOLDENHORN ONEIT earlier than the Göbeklitepe release.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritized actions for security teams:</p>
<ul>
<li>Patch immediately by upgrading all instances of GOLDENHORN ONEIT to the Göbeklitepe release or later.</li>
<li>Review web server access logs for anomalous SQL syntax, such as sleep functions, binary operators, or unexpected union statements, directed at the GOLDENHORN ONEIT application.</li>
<li>Implement strict input validation and parameterized queries at the application level to mitigate against SQL injection vectors.</li>
<li>Deploy WAF rules configured to detect and block common SQL injection patterns (e.g., OR 1=1, UNION SELECT, WAITFOR DELAY) targeting application endpoints.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>web-application-vulnerability</category><category>sql-injection</category><category>cve-2026-18198</category></item></channel></rss>