BackBox News

Latest news and insights on Security

Zero-Click Apple Shortcuts Vulnerability Allows Silent Data Theft

Zero-Click Apple Shortcuts Vulnerability Allows Silent Data Theft

Vulnerability CVE-2024-23204, affecting Apple’s popular Shortcuts app, suggests a critical need for ongoing security awareness in the macOS and iOS ecosystem.

darkreading – ​Read More

iSoon’s Secret APT Status Exposes China’s Foreign Hacking Machinations

iSoon’s Secret APT Status Exposes China’s Foreign Hacking Machinations

Chinese government agencies are paying an APT, masked as a legitimate company, to spy on foreign and domestic targets of political interest.

darkreading – ​Read More

Insurers Use Claims Data to Recommend Cybersecurity Technologies

Insurers Use Claims Data to Recommend Cybersecurity Technologies

Policy holders using certain technologies — such as managed detection and response (MDR) services, Google Workspace, and email security gateways — gain premium discounts from cyber insurers.

darkreading – ​Read More

Hubris May Have Contributed to Downfall of Ransomware Kingpin LockBit

Hubris May Have Contributed to Downfall of Ransomware Kingpin LockBit

The most prolific ransomware group in recent years was on the decline at the time of its takedown, security researchers say.

darkreading – ​Read More

NSA Cybersecurity Director Rob Joyce to Retire

NSA Cybersecurity Director Rob Joyce to Retire

His retirement will go into effect on March 31, concluding 34 years of service to the National Security Agency.

darkreading – ​Read More

FTC Slams Avast with $16.5 Million Fine for Selling Users’ Browsing Data

FTC Slams Avast with $16.5 Million Fine for Selling Users’ Browsing Data

The U.S. Federal Trade Commission (FTC) has hit antivirus vendor Avast with a $16.5 million fine over charges that the firm sold users’ browsing data to advertisers after claiming its products would block online tracking.
In addition, the company has been banned from selling or licensing any web browsing data for advertising purposes. It will also have to notify users whose browsing data was

The Hacker News – ​Read More

Pharmacy Delays Across US Blamed on Nation-State Hackers

Pharmacy Delays Across US Blamed on Nation-State Hackers

Healthcare tech provider Change Healthcare says a suspected nation-state threat actor breached its systems, causing pharmacy transaction delays nationwide.

darkreading – ​Read More

Leak Reveals the Unusual Path of ‘Urgent’ Russian Threat Warning

Leak Reveals the Unusual Path of ‘Urgent’ Russian Threat Warning

The US Congress was preparing to vote on a key foreign surveillance program last week. Then a wild Russian threat appeared.

Security Latest – ​Read More

Researchers Detail Apple’s Recent Zero-Click Shortcuts Vulnerability

Researchers Detail Apple’s Recent Zero-Click Shortcuts Vulnerability

Details have emerged about a now-patched high-severity security flaw in Apple’s Shortcuts app that could permit a shortcut to access sensitive information on the device without users’ consent.
The vulnerability, tracked as CVE-2024-23204 (CVSS score: 7.5), was addressed by Apple on January 22, 2024, with the release of iOS 17.3, iPadOS 17.3, macOS Sonoma 14.3, and 

The Hacker News – ​Read More

Here Are the Secret Locations of ShotSpotter Gunfire Sensors

Here Are the Secret Locations of ShotSpotter Gunfire Sensors

The locations of microphones used to detect gunshots have been kept hidden from police and the public. A WIRED analysis of leaked coordinates confirms arguments critics have made against the technology.

Security Latest – ​Read More

BackBox.org offers a range of Penetration Testing services to simulate an attack on your network or application. If you are interested in our services, please contact us and we will provide you with further information as well as an initial consultation.