BackBox.org offers a range of Penetration Testing services to simulate an attack on your network or application. If you are interested in our services, please contact us and we will provide you with further information as well as an initial consultation.
Samsung MagicINFO Vulnerability Exploited Days After PoC Publication
/in General NewsThreat actors started exploiting a vulnerability in Samsung MagicINFO only days after a PoC exploit was published.
The post Samsung MagicINFO Vulnerability Exploited Days After PoC Publication appeared first on SecurityWeek.
SecurityWeek – Read More
Entra ID Data Protection: Essential or Overkill?
/in General NewsMicrosoft Entra ID (formerly Azure Active Directory) is the backbone of modern identity management, enabling secure access to the applications, data, and services your business relies on. As hybrid work and cloud adoption accelerate, Entra ID plays an even more central role — managing authentication, enforcing policy, and connecting users across distributed environments.
That prominence also
The Hacker News – Read More
US Border Agents Are Asking for Help Taking Photos of Everyone Entering the Country by Car
/in General NewsCustoms and Border Protection has called for tech companies to pitch real-time face recognition technology that can capture everyone in a vehicle—not just those in the front seats.
Security Latest – Read More
Android Update Patches FreeType Vulnerability Exploited as Zero-Day
/in General NewsAndroid’s May 2025 security update includes patches for an exploited vulnerability in the FreeType open source rendering engine.
The post Android Update Patches FreeType Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
SecurityWeek – Read More
Google Fixes Actively Exploited Android System Flaw in May 2025 Security Update
/in General NewsGoogle has released its monthly security updates for Android with fixes for 46 security flaws, including one vulnerability that it said has been exploited in the wild.
The vulnerability in question is CVE-2025-27363 (CVSS score: 8.1), a high-severity flaw in the System component that could lead to local code execution without requiring any additional execution privileges.
“The most severe of
The Hacker News – Read More
Critical Langflow Flaw Added to CISA KEV List Amid Ongoing Exploitation Evidence
/in General NewsA recently disclosed critical security flaw impacting the open-source Langflow platform has been added to the Known Exploited Vulnerabilities (KEV) catalog by the U.S. Cybersecurity and Infrastructure Security Agency (CISA), citing evidence of active exploitation.
The vulnerability, tracked as CVE-2025-3248, carries a CVSS score of 9.8 out of a maximum of 10.0.
“Langflow contains a missing
The Hacker News – Read More
Meta, Cisco put open-source LLMs at the core of next-gen SOC workflows
/in General NewsCisco’s Foundation-sec-8B LLM & Meta’s AI Defenders redefine cybersecurity with open-source AI for scalable SOCs.Read More
Security News | VentureBeat – Read More
Chat App Used by Trump Admin Suspends Operation Amid Hack
/in General NewsTM SGNL, a chat app by US-Israeli firm TeleMessage used by Trump officials, halts operations after a breach…
Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto – Read More
AI Domination: RSAC 2025 Social Media Roundup
/in General NewsDocumented in a series of social media posts, cybersecurity experts shared with Dark Reading their insights on RSAC 2025 throughout the week.
darkreading – Read More
Signal Clone Used by Mike Waltz Pauses Service After Reports It Got Hacked
/in General NewsThe communications app TeleMessage, which was spotted on former US national security adviser Mike Waltz’s phone, has suspended “all services” as it investigates reports of at least one breach.
Security Latest – Read More