vBulletin Forums Breached: Dark Web Sale of Millions of Accounts

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

vBulletin, a widely used forum software, has been compromised, potentially exposing millions of user accounts. The breach was facilitated by a software vulnerability, specifically affecting versions 4.2.2 and 4.2.3. The …

TeamViewer macOS Client Vulnerability Let Attackers Escalate Privileges

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical vulnerability has been identified in the TeamViewer Client for macOS. If exploited, this flaw could allow attackers to escalate their privileges on the system, posing a severe security …

Google Revealed Kernel Address Sanitizer to Harden Android Firmware & Beyond

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Google has unveiled its latest initiative the implementation of the Kernel Address Sanitizer (KASan) to enhance firmware security. This development comes as the focus on lower-level firmware security intensifies, given …

BlueDucky: A New Tool Exploits Bluetooth Vulnerability With 0-Click Code Execution

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A new tool dunned BlueDucky, automating the exploitation of a critical Bluetooth pairing vulnerability that allows for 0-click code execution on unpatched devices. This revelation comes on the heels of …

macOS Flaw Let Attackers Escalate Privilege & Gain Root Access

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

A critical flaw impacting macOS has been uncovered that gives unauthorized users, including those with guest access, the capacity to escalate privileges and take complete root control of the system. According …

Adobe ColdFusion Flaw Let Attackers Gain Access to Sensitive Files – PoC Released

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

Adobe has addressed a critical vulnerability in its ColdFusion software, which could have allowed attackers to read files arbitrarily from the system. The flaw, identified as CVE-2024-20767, has been patched, …

CISA & FBI : Hackers Exploiting SQL Injection Flaws To Hack Servers

Blog WriterCybersecurity News - Original News Source is cybersecuritynews.com

CISA and the FBI released the Secure by Design Alert to address SQL injection vulnerabilities in software that affect thousands of organizations. A persistent class of defects in commercial software …