50+ Vulnerabilities Later: Hard Truths About PostgreSQL in the Cloud
Over the last year, I reported more than 50 vulnerabilities affecting PostgreSQL-based platforms, extensions, and managed providers. Some were simple privilege mistakes, some were memory corruption bugs, and some affected multiple vendors at the same time. Finding the bugs was often the easy part. What came after was much more complicated. In this talk, I will share the lessons I learned while trying to responsibly disclose and coordinate vulnerabilities across the PostgreSQL and PaaS ecosystem. We will look at what happens when PostgreSQL core, extension maintainers, cloud providers, bug bounty programs, and security teams all have different threat models, responsibilities, release cycles, and definitions of what a security vulnerability actually is. This is not a talk about blaming individual vendors or maintainers. It is about the recurring problems that appear when one vulnerability crosses several projects and organisations at once, and the uncomfortable gaps that researchers discover only after they start reporting at scale. Whether you are a maintainer, cloud provider, DBA, security engineer, or simply curious about how vulnerability disclosure works behind the scenes, you will leave this session with a clearer understanding of where coordination breaks down, why these problems keep repeating, and what we can do better as an ecosystem.
Mehmet İnce is a hacker at heart, with more than two decades of experience across offensive security, vulnerability research, and cybersecurity product engineering. He is the co-founder and CTO of PRODAFT, a Europe-based threat intelligence company helping organizations understand, track, and respond to advanced cyber threats. Throughout his career, Mehmet has discovered and responsibly disclosed more than 300 zero-day vulnerabilities across widely used products, platforms, and enterprise technologies. His work sits at the intersection of research, attacker behaviour, and real-world product engineering, where building and breaking systems often inform each other. As a technical leader, he has led multiple cybersecurity products from zero to production, from research and architecture to implementation, scaling, and long-term evolution. His work is shaped by a hacker mindset: practical, impact-driven, and focused on turning deep technical research into tools security teams can rely on.