BackBox.org offers a range of Penetration Testing services to simulate an attack on your network or application. If you are interested in our services, please contact us and we will provide you with further information as well as an initial consultation.
New Malware Hits 300,000 Users with Rogue Chrome and Edge Extensions
/in General NewsAn ongoing, widespread malware campaign has been observed installing rogue Google Chrome and Microsoft Edge extensions via a trojan distributed via fake websites masquerading as popular software.
“The trojan malware contains different deliverables ranging from simple adware extensions that hijack searches to more sophisticated malicious scripts that deliver local extensions to steal private data
The Hacker News – Read More
Russian Midnight Blizzard Breached UK Home Office via Microsoft
/in General NewsRussian hacking group Midnight Blizzard breached the UK Home Office, stealing sensitive data. Learn how they exploited supply…
Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – Read More
Cisco Warns of Critical RCE Zero-Days in End of Life IP Phones
/in General NewsCisco has issued a warning about critical remote code execution zero-days affecting the web-based management interface of the Small Business SPA 300 and SPA 500 series IP phones, which are no longer supported.
Cyware News – Latest Cyber News – Read More
North Korea Kimsuky Launch Phishing Attacks on Universities
/in General NewsCybersecurity analysts have uncovered critical details about the North Korean advanced persistent threat (APT) group Kimsuky, which has been targeting universities as part of its global espionage operations.
Cyware News – Latest Cyber News – Read More
CISA Warns of Hackers Abusing Cisco Smart Install Feature
/in General NewsThe U.S. Cybersecurity and Infrastructure Security Agency (CISA) has advised organizations to disable the legacy Cisco Smart Install (SMI) feature due to recent attacks exploiting it.
Cyware News – Latest Cyber News – Read More
Russian Spies Hacked UK Government Systems Earlier This Year, Stole Data and Emails
/in General NewsRussian spies hacked UK government systems earlier this year, stealing data and emails in a nation-state attack. The breach targeted the Home Office’s systems, which had not been previously reported.
Cyware News – Latest Cyber News – Read More
Microsoft Warns of Unpatched Office Vulnerability Leading to Data Breaches
/in General NewsMicrosoft has disclosed an unpatched zero-day in Office that, if successfully exploited, could result in unauthorized disclosure of sensitive information to malicious actors.
The vulnerability, tracked as CVE-2024-38200 (CVSS score: 7.5), has been described as a spoofing flaw that affects the following versions of Office –
Microsoft Office 2016 for 32-bit edition and 64-bit editions
Microsoft
The Hacker News – Read More
Google Researchers Found Nearly a Dozen Flaws in Popular Qualcomm Software for Mobile GPUs
/in General NewsThe vulnerabilities, which have been patched, may have novel appeal to attackers as an avenue to compromising phones.
Security Latest – Read More
Experts Uncover Severe AWS Flaws Leading to RCE, Data Theft, and Full-Service Takeovers
/in General NewsCybersecurity researchers have discovered multiple critical flaws in Amazon Web Services (AWS) offerings that, if successfully exploited, could result in serious consequences.
“The impact of these vulnerabilities range between remote code execution (RCE), full-service user takeover (which might provide powerful administrative access), manipulation of AI modules, exposing sensitive data, data
The Hacker News – Read More
Intel has news – good, bad and ugly – about Raptor Lake bug patch. Here’s what to know
/in General NewsUsers must download and install a BIOS update as the patch won’t be made available via Windows Update.
Latest stories for ZDNET in Security – Read More