BREAKING
AI Finds SQL Flaw in FGT Ticketing
How the Attack Worked
Entry PointdeviceUID
Unauthenticated SQL injection
At fgtapi.frontgatetickets.com
Claude's Roleautonomous
Generated nested queries
Bypassed the WAF
From Injection to Super-Admin
1SQL injection
2Read fgs database
3Reset token
4Super-admin access
0+
database tables
0$
Platinum pass value
0h
fix time
No Tickets Issued, Flaw Reported
AI Cuts Both Ways in Security
AI NEWS BLITZ
A researcher used Anthropic's Claude to uncover a critical flaw in a major ticketing platform.