SQL Injection Is Boring - Advanced Threats You're Not Watching

Everyone knows how to prevent basic SQL injection, but modern attackers have moved well beyond textbook exploits. In PostgreSQL deployments, subtle misconfigurations and overlooked features can open doors to far more sophisticated attacks. This talk uncovers the next generation of database threats that rarely make it into security checklists. We will look at: 1/ Privilege escalation via extensions and Foreign Data Wrappers, where seemingly harmless extensions can leak credentials or access external systems. 2/ Timing and side-channel attacks that extract secrets by measuring query latency and caching behavior. 3/ Abusing logical replication and LISTEN/NOTIFY as stealthy data exfiltration channels hidden in plain sight. 4/ Role inheritance and Row-Level Security pitfalls where attackers exploit complex permission hierarchies. Attendees will learn how to spot these attack surfaces, configure PostgreSQL securely, and apply defense-in-depth strategies like strict role design, immutable infrastructure, and continuous auditing. Whether you are a DBA, developer, or security engineer, this session will challenge the assumption that SQL injection is the only real database risk and give you actionable steps to harden your PostgreSQL environment against today’s most overlooked threats.
Speaker

Narendra is a Senior Database Specialist Solutions Architect at AWS with 21 years of experience across Oracle, PostgreSQL, SQL Server, and MySQL including a decade of deep PostgreSQL specialization. He helps enterprises …









