Cybersecurity News

Filters
Tag
Reset

Filtered by tag: remote code execution × Clear

From Screen Share to Root Access: Breaking Down CVE-2026-43760 and CVE-2026-65400 on macOS

Two vulnerabilities in macOS's Screen Sharing server were patched in a recent Apple update. CVE-2026-43760 allows pre-authenticated remote code execution, meaning attackers need no credentials to exploit it. CVE-2026-65400 can grant root-level access. Together, the flaws present a serious risk to users with Screen Sharing enabled. Apple has released fixes and users are urged to update immediately.

Inside an Oracle Database SQL Injection Attack | Huntress

Attackers exploited a SQL injection vulnerability in an Oracle Database-connected application to achieve full OS-level remote code execution. By abusing Oracle's built-in Java functionality, they compiled and executed malicious Java source code directly within the database, ultimately deploying the Khunt post-exploitation toolkit for further access and lateral movement.