BackBox.org offers a range of Penetration Testing services to simulate an attack on your network or application. If you are interested in our services, please contact us and we will provide you with further information as well as an initial consultation.
GitLab Warns of Critical Pipeline Execution Vulnerability
/in General NewsGitLab released updates covering versions 17.1.7, 17.2.5, and 17.3.2 for GitLab Community Edition (CE) and Enterprise Edition (EE), addressing a total of 18 security issues.
Cyware News – Latest Cyber News – Read More
TrickMo Android Trojan Exploits Accessibility Services for On-Device Banking Fraud
/in General NewsCybersecurity researchers at Cleafy discovered a new variant of the TrickMo Android banking trojan that evades analysis and displays fake login screens to steal banking credentials.
Cyware News – Latest Cyber News – Read More
Chinese-Made Port Cranes in US Included ‘Backdoor’ Modems, House Report Says
/in General NewsA recent congressional investigation revealed that Chinese-made port cranes in the United States contained hidden modems that could provide unauthorized access to the machines.
Cyware News – Latest Cyber News – Read More
Fileless Remcos RAT Campaign Leverages CVE-2017-0199 Flaw
/in General NewsIn a newly uncovered advanced malware campaign, threat actors are using a complex, fileless approach to deliver the Remcos Remote Access Trojan (RAT), leveraging a benign-looking Excel document as the attack vector.
Cyware News – Latest Cyber News – Read More
Hackers Have Sights Set on Four Microsoft Vulnerabilities, CISA Warns
/in General NewsFederal civilian agencies have until the end of the month to address these issues. The vulnerabilities are part of Microsoft’s monthly security release, with CVE-2024-43491 considered the most concerning due to its severity score.
Cyware News – Latest Cyber News – Read More
Targeted Campaigns in Retail Sector Involve Domain Fraud, Brand Impersonation, and Ponzi Schemes
/in General NewsThreat actors are actively engaging in domain fraud, brand impersonation, and Ponzi schemes targeting the retail sector, which plays a significant role in the global economy.
Cyware News – Latest Cyber News – Read More
New Vo1d Malware Infects 1.3 Million Android Streaming Boxes
/in General NewsThe Vo1d malware campaign targets specific Android firmware versions like Android 7.1.2 and Android 10.1. The malware modifies system files to launch itself on boot and persist on the device.
Cyware News – Latest Cyber News – Read More
Citrix Workspace App Users Urged to Update Following Two Privilege Escalation Flaws
/in General NewsUsers of Citrix Workspace App are advised to update due to two privilege escalation flaws. Cloud Software Group disclosed vulnerabilities (CVE-2024-7889 & CVE-2024-7890) in the Windows app, allowing attackers to gain high-level access.
Cyware News – Latest Cyber News – Read More
Update: Protecting Against RCE Attacks Abusing WhatsUp Gold Vulnerabilities
/in General NewsTrend Micro researchers uncovered remote code execution attacks targeting Progress Software’s WhatsUp Gold using the vulnerabilities tracked as CVE-2024-6670 and CVE-2024-6671.
Cyware News – Latest Cyber News – Read More
Ivanti Warns of Active Exploitation of Newly Patched Cloud Appliance Vulnerability
/in General NewsIvanti has revealed that a newly patched security flaw in its Cloud Service Appliance (CSA) has come under active exploitation in the wild.
The high-severity vulnerability in question is CVE-2024-8190 (CVSS score: 7.2), which allows remote code execution under certain circumstances.
“An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows
The Hacker News – Read More