BackBox.org offers a range of Penetration Testing services to simulate an attack on your network or application. If you are interested in our services, please contact us and we will provide you with further information as well as an initial consultation.
Phantom Secrets: Undetected Secrets Expose Major Corporations
/in General NewsMajor secrets, including cloud environment credentials, internal infrastructures, and telemetry platforms, have been found exposed on the internet due to Git-based processes and Source Code Management (SCM) platforms behavior.
Cyware News – Latest Cyber News – Read More
Prompt Injection Flaw in Vanna AI Exposes Databases to RCE Attacks
/in General NewsCybersecurity researchers have disclosed a high-severity security flaw in the Vanna.AI library that could be exploited to achieve remote code execution vulnerability via prompt injection techniques.
The vulnerability, tracked as CVE-2024-5565 (CVSS score: 8.1), relates to a case of prompt injection in the “ask” function that could be exploited to trick the library into executing arbitrary
The Hacker News – Read More
Evolve Bank Data Leaked After LockBit’s ‘Federal Reserve Hack’
/in General NewsThe LockBit ransomware group claimed to have hacked the US Federal Reserve, but leaked data from an Arkansas-based bank.
The post Evolve Bank Data Leaked After LockBit’s ‘Federal Reserve Hack’ appeared first on SecurityWeek.
SecurityWeek – Read More
Russian National Indicted for Cyber Attacks on Ukraine Before 2022 Invasion
/in General NewsA 22-year-old Russian national has been indicted in the U.S. for his alleged role in staging destructive cyber attacks against Ukraine and its allies in the days leading to Russia’s full-blown military invasion of Ukraine in early 2022.
Amin Timovich Stigal, the defendant in question, is assessed to be affiliated with the Main Directorate of the General Staff of the Armed Forces of the Russian
The Hacker News – Read More
‘Phantom’ Source Code Secrets Haunt Major Organizations
/in General NewsAqua Security shows that code in repositories remains accessible even after being deleted or overwritten, continuing to leak secrets.
The post ‘Phantom’ Source Code Secrets Haunt Major Organizations appeared first on SecurityWeek.
SecurityWeek – Read More
Update: MOVEit Transfer Vulnerability Targeted Amid Disclosure Drama
/in General NewsThe non-profit cybersecurity organization, the Shadowserver Foundation, has observed exploitation attempts against CVE-2024-5806. They noted that the exploitation began soon after the vulnerability details were made public.
Cyware News – Latest Cyber News – Read More
Critical SQLi Vulnerability Found in Fortra FileCatalyst Workflow Application
/in General NewsA critical security flaw has been disclosed in Fortra FileCatalyst Workflow that, if left unpatched, could allow an attacker to tamper with the application database.
Tracked as CVE-2024-5276, the vulnerability carries a CVSS score of 9.8. It impacts FileCatalyst Workflow versions 5.1.6 Build 135 and earlier. It has been addressed in version 5.1.6 build 139.
“An SQL injection vulnerability in
The Hacker News – Read More
Chinese Cyberspies Employ Ransomware in Attacks for Diversion
/in General NewsThe adoption of ransomware in cyberespionage attacks helps adversaries blur the lines between APT and cybercriminal activity, leading to potential misattribution or concealing the true nature of the operation.
Cyware News – Latest Cyber News – Read More
Critical ADOdb Vulnerabilities Fixed in Ubuntu
/in General NewsThese vulnerabilities include SQL injection attacks, cross-site scripting (XSS) attacks, and authentication bypasses. Ubuntu has released updates for various versions, including Ubuntu 22.04 LTS, 20.04 LTS, 18.04 ESM, and 16.04 ESM.
Cyware News – Latest Cyber News – Read More
Chinese Espionage Group “ChamelGang” Uses Attacks for Disruption and Data Theft
/in General NewsBeware! Chinese cyberespionage group ChamelGang targets critical infrastructure like aviation and government systems. SentinelOne report reveals potential attacks across Asia. Learn more about ChamelGang’s cyberespionage activities.
Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – Read More