BlueDucky: A New Tool Exploits Bluetooth Vulnerability With 0-Click Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new tool dunned BlueDucky, automating the exploitation of a critical Bluetooth pairing vulnerability that allows for 0-click code execution on unpatched devices. This revelation comes on the heels of …

macOS Flaw Let Attackers Escalate Privilege & Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical flaw impacting macOS has been uncovered that gives unauthorized users, including those with guest access, the capacity to escalate privileges and take complete root control of the system. According …

Adobe ColdFusion Flaw Let Attackers Gain Access to Sensitive Files – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Adobe has addressed a critical vulnerability in its ColdFusion software, which could have allowed attackers to read files arbitrarily from the system. The flaw, identified as CVE-2024-20767, has been patched, …

CISA & FBI : Hackers Exploiting SQL Injection Flaws To Hack Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA and the FBI released the Secure by Design Alert to address SQL injection vulnerabilities in software that affect thousands of organizations. A persistent class of defects in commercial software …

New Zealand Parliamentary Network Hacked by Chinese Hackers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

New Zealand has joined the United Kingdom in strongly condemning the People’s Republic of China (PRC) for its state-backed cyber activities, which have recently targeted democratic institutions, including the UK’s …

Rank Math SEO Plugin Flaw Exposes 2M+ Websites to Cyber Attack

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A significant vulnerability has been identified in the Rank Math SEO plugin for WordPress. This flaw, cataloged under CVE-2023-32600, exposes over two million websites to potential cyber-attacks, posing a severe …