BackBox.org offers a range of Penetration Testing services to simulate an attack on your network or application. If you are interested in our services, please contact us and we will provide you with further information as well as an initial consultation.
PerfektBlue Bluetooth Vulnerabilities Expose Millions of Vehicles to Remote Code Execution
/in General NewsCybersecurity researchers have discovered a set of four security flaws in OpenSynergy’s BlueSDK Bluetooth stack that, if successfully exploited, could allow remote code execution on millions of transport vehicles from different vendors.
The vulnerabilities, dubbed PerfektBlue, can be fashioned together as an exploit chain to run arbitrary code on cars from at least three major automakers,
The Hacker News – Read More
Cyberstarts Launches $300M Liquidity Fund to Help Startups Retain Top Talent
/in General NewsWith IPOs taking longer than ever, the venture firm’s fund aims to keep startup veterans motivated while staying private.
The post Cyberstarts Launches $300M Liquidity Fund to Help Startups Retain Top Talent appeared first on SecurityWeek.
SecurityWeek – Read More
Critical Wing FTP Server Vulnerability (CVE-2025-47812) Actively Being Exploited in the Wild
/in General NewsA recently disclosed maximum-severity security flaw impacting the Wing FTP Server has come under active exploitation in the wild, according to Huntress.
The vulnerability, tracked as CVE-2025-47812 (CVSS score: 10.0), is a case of improper handling of null (”) bytes in the server’s web interface, which allows for remote code execution. It has been addressed in version 7.4.4.
“The user and
The Hacker News – Read More
Iranian-Backed Pay2Key Ransomware Resurfaces with 80% Profit Share for Cybercriminals
/in General NewsAn Iranian-backed ransomware-as-a-service (RaaS) named Pay2Key has resurfaced in the wake of the Israel-Iran-U.S. conflict last month, offering bigger payouts to cybercriminals who launch attacks against Israel and the U.S.
The financially motivated scheme, now operating under the moniker Pay2Key.I2P, is assessed to be linked to a hacking group tracked as Fox Kitten (aka Lemon Sandstorm).
”
The Hacker News – Read More
Securing Data in the AI Era
/in General NewsThe 2025 Data Risk Report: Enterprises face potentially serious data loss risks from AI-fueled tools. Adopting a unified, AI-driven approach to data security can help.
As businesses increasingly rely on cloud-driven platforms and AI-powered tools to accelerate digital transformation, the stakes for safeguarding sensitive enterprise data have reached unprecedented levels. The Zscaler ThreatLabz
The Hacker News – Read More
McDonald’s Chatbot Recruitment Platform Leaked 64 Million Job Applications
/in General NewsTwo vulnerabilities in an internal API allowed unauthorized access to contacts and chats, exposing the information of 64 million McDonald’s applicants.
The post McDonald’s Chatbot Recruitment Platform Leaked 64 Million Job Applications appeared first on SecurityWeek.
SecurityWeek – Read More
Critical Wing FTP Server Vulnerability Exploited
/in General NewsWing FTP Server vulnerability CVE-2025-47812 can be exploited for arbitrary command execution with root or system privileges.
The post Critical Wing FTP Server Vulnerability Exploited appeared first on SecurityWeek.
SecurityWeek – Read More
July 2025 Breaks a Decade of Monthly Android Patches
/in General NewsSince August 2015, Google has delivered a constant stream of monthly security patches for Android. Until July 2025.
The post July 2025 Breaks a Decade of Monthly Android Patches appeared first on SecurityWeek.
SecurityWeek – Read More
Rowhammer Attack Demonstrated Against Nvidia GPU
/in General NewsResearchers demonstrated GPUHammer — a Rowhammer attack against GPUs — by degrading the accuracy of machine learning models.
The post Rowhammer Attack Demonstrated Against Nvidia GPU appeared first on SecurityWeek.
SecurityWeek – Read More
TikTok Faces Fresh European Privacy Investigation Over China Data Transfers
/in General NewsThe Irish Data Privacy Commission announced that TikTok is facing a new European Union privacy investigation into user data sent to China.
The post TikTok Faces Fresh European Privacy Investigation Over China Data Transfers appeared first on SecurityWeek.
SecurityWeek – Read More