BackBox.org offers a range of Penetration Testing services to simulate an attack on your network or application. If you are interested in our services, please contact us and we will provide you with further information as well as an initial consultation.
JumpCloud Remote Assist Vulnerability Can Expose Systems to Takeover
/in General NewsThe issue allows attackers to write arbitrary data to any file, or delete arbitrary files to obtain System privileges.
The post JumpCloud Remote Assist Vulnerability Can Expose Systems to Takeover appeared first on SecurityWeek.
SecurityWeek – Read More
Why Data Security and Privacy Need to Start in Code
/in General NewsAI-assisted coding and AI app generation platforms have created an unprecedented surge in software development. Companies are now facing rapid growth in both the number of applications and the pace of change within those applications. Security and privacy teams are under significant pressure as the surface area they must cover is expanding quickly while their staffing levels remain largely
The Hacker News – Read More
Fortinet FortiGate Under Active Attack Through SAML SSO Authentication Bypass
/in General NewsThreat actors have begun to exploit two newly disclosed security flaws in Fortinet FortiGate devices, less than a week after public disclosure.
Cybersecurity company Arctic Wolf said it observed active intrusions involving malicious single sign-on (SSO) logins on FortiGate appliances on December 12, 2025. The attacks exploit two critical authentication bypasses (CVE-2025-59718 and CVE-2025-59719
The Hacker News – Read More
Google to Kill Popular Dark Web Report Tool
/in General NewsThis marks another abrupt end to a Google service that users had come to rely on.
The post Google to Kill Popular Dark Web Report Tool appeared first on TechRepublic.
Security Archives – TechRepublic – Read More
700Credit Data Breach Exposing Details of 5.6 Million Consumers
/in General NewsUS auto loan service 700Credit confirms a data breach exposed names, addresses, and Social Security numbers of dealership customers. Free credit monitoring is offered.
Hackread – Cybersecurity News, Data Breaches, AI, and More – Read More
In-the-Wild Exploitation of Fresh Fortinet Flaws Begins
/in General NewsThreat actors are exploiting the two critical authentication bypass vulnerabilities against FortiGate appliances.
The post In-the-Wild Exploitation of Fresh Fortinet Flaws Begins appeared first on SecurityWeek.
SecurityWeek – Read More
Coupang CEO Quits After Breach Hits 33.7M South Koreans
/in General NewsThe e-commerce firm’s data breach exposed nearly two-thirds of the entire country’s population after hackers operated undetected for five months.
The post Coupang CEO Quits After Breach Hits 33.7M South Koreans appeared first on TechRepublic.
Security Archives – TechRepublic – Read More
React2Shell Vulnerability Actively Exploited to Deploy Linux Backdoors
/in General NewsThe security vulnerability known as React2Shell is being exploited by threat actors to deliver malware families like KSwapDoor and ZnDoor, according to findings from Palo Alto Networks Unit 42 and NTT Security.
“KSwapDoor is a professionally engineered remote access tool designed with stealth in mind,” Justin Moore, senior manager of threat intel research at Palo Alto Networks Unit 42, said in a
The Hacker News – Read More
Fake ‘Leonardo DiCaprio’ Torrent Spreads Agent Tesla Malware
/in General NewsA fake Leonardo DiCaprio movie torrent is spreading Agent Tesla malware through trusted Windows tools
The post Fake ‘Leonardo DiCaprio’ Torrent Spreads Agent Tesla Malware appeared first on TechRepublic.
Security Archives – TechRepublic – Read More
Google to Shut Down Dark Web Monitoring Tool in February 2026
/in General NewsGoogle has announced that it’s discontinuing its dark web report tool in February 2026, less than two years after it was launched as a way for users to monitor if their personal information is found on the dark web.
To that end, scans for new dark web breaches will be stopped on January 15, 2026, and the feature will cease to exist effective February 16, 2026.
“While the report offered general
The Hacker News – Read More