GRANT ALL PRIVILEGES ON *.* TO 'attacker'@'localhost' IDENTIFIED BY 'pass'; FLUSH PRIVILEGES;

The phpMyAdmin splash looked exactly like every phpMyAdmin splash: clean, archaic, a relic with faded buttons that promised either salvation or calamity. The nonprofit’s users table sat like a ledger in a quiet church. Donations — timestamps, amounts, donor emails — lay there like prayers in a ledger book. She felt the weight of it: money owed to people feeding children, camp programs, and a grassroots health clinic.

In the quiet hours of a Friday night, Sam sat before a glowing terminal, eyes fixed on a target: a misconfigured server running an old version of . As a security researcher, Sam knew that a single oversight could be a gateway.