BackBox.org offers a range of Penetration Testing services to simulate an attack on your network or application. If you are interested in our services, please contact us and we will provide you with further information as well as an initial consultation.
Hackers Threaten to Leak Planned Parenthood Data
/in General NewsPlus: Kaspersky’s US business sold, Nigerian sextortion scammers jailed, and Europe’s controversial encryption plans return.
Security Latest – Read More
BlindEagle Targets Colombian Insurance Sector with BlotchyQuasar
/in General NewsThe BlindEagle APT group has recently targeted the Colombian insurance sector. The attack chain starts with a phishing email impersonating DIAN, the Colombian tax authority.
Cyware News – Latest Cyber News – Read More
Veeam Backup & Replication Faces RCE Flaw Allows Full System Takeover
/in General NewsA critical Remote Code Execution (RCE) flaw, CVE-2024-40711, with a CVSS score of 9. 8 has been discovered in Veeam Backup & Replication, allowing unauthorized attackers to take full control over systems.
Cyware News – Latest Cyber News – Read More
Apache fixes critical OFBiz remote code execution vulnerability
/in General NewsApache has addressed a critical remote code execution vulnerability in its OFBiz software, which could allow attackers to run malicious code on Linux and Windows servers. OFBiz is a CRM and ERP suite that serves as a Java-based web framework.
Cyware News – Latest Cyber News – Read More
Fog Ransomware Now Targeting the Financial Sector
/in General NewsFog, a variant of STOP/DJVU family, targets various sectors, exploiting VPN vulnerabilities to infiltrate network defenses. After infiltration, Fog ransomware disables protective measures, encrypts vital files, and demands ransom via the Tor network.
Cyware News – Latest Cyber News – Read More
North Korean Threat Actors Deploy COVERTCATCH Malware via LinkedIn Job Scams
/in General NewsThreat actors affiliated with North Korea have been observed leveraging LinkedIn as a way to target developers as part of a fake job recruiting operation.
These attacks employ coding tests as a common initial infection vector, Google-owned Mandiant said in a new report about threats faced by the Web3 sector.
“After an initial chat conversation, the attacker sent a ZIP file that contained
The Hacker News – Read More
FBI Cracks Down on Dark Web Marketplace Managed by Russian and Kazakh Nationals
/in General NewsTwo men have been indicted in the U.S. for their alleged involvement in managing a dark web marketplace called WWH Club that specializes in the sale of sensitive personal and financial information.
Alex Khodyrev, a 35-year-old Kazakhstan national, and Pavel Kublitskii, a 37-year-old Russian national, have been charged with conspiracy to commit access device fraud and conspiracy to commit wire
The Hacker News – Read More
Penpie DeFi platform files reports with FBI, Singapore police after $27 million crypto theft
/in General NewsThe Penpie DeFi platform recently reported a $27 million cryptocurrency theft to the FBI and Singapore police. Hackers targeted the protocol, stealing ethereum and prompting Penpie to halt withdrawals and deposits.
Cyware News – Latest Cyber News – Read More
New Stealthy Malware Campaign Dubbed DarkCracks Exploits GLPI and WordPress Sites
/in General NewsDarkCracks isn’t your typical malware campaign—it’s a sophisticated Launcher designed for long-term exploitation. It deploys malicious payloads through public websites, like school portals and booking systems, to infect unsuspecting users.
Cyware News – Latest Cyber News – Read More
CyberVolk Ransomware: A New and Evolving Threat to Global Cybersecurity
/in General NewsCyberVolk, infamous for DDoS attacks and data breaches, has gained particular notoriety for its ransomware, detected in July 2024, due to its advanced features and capabilities.
Cyware News – Latest Cyber News – Read More