BackBox.org offers a range of Penetration Testing services to simulate an attack on your network or application. If you are interested in our services, please contact us and we will provide you with further information as well as an initial consultation.
Over 10,000 WordPress Sites at Risk: Critical File Deletion Flaw Found in InPost Plugins
/in General NewsThe vulnerability, known as CVE-2024-6500, affects the InPost PL and InPost for WooCommerce plugins, allowing attackers to read and delete sensitive files like the wp-config.php configuration file.
Cyware News – Latest Cyber News – Read More
Cyberattack Disrupts Microchip Technology Manufacturing Facilities
/in General NewsMicrochip Technology has disclosed a cyberattack impacting operations at some of its manufacturing facilities.
The post Cyberattack Disrupts Microchip Technology Manufacturing Facilities appeared first on SecurityWeek.
SecurityWeek – Read More
Unmasking Styx Stealer: How a Hacker’s Slip Led to an Intelligence Treasure Trove
/in General NewsStyx Stealer is based on the Phemedrone Stealer and is available for purchase online. It has the ability to steal passwords, cookies, crypto wallet data, and messenger sessions, as well as gather system information.
Cyware News – Latest Cyber News – Read More
CERT-UA Warns of New Vermin-Linked Phishing Attacks with PoW Bait
/in General NewsThe Computer Emergency Response Team of Ukraine (CERT-UA) has warned of new phishing attacks that aim to infect devices with malware.
The activity has been attributed to a threat cluster it tracks as UAC-0020, which is also known as Vermin. The exact scale and scope of the attacks are presently unknown.
The attack chains commence with phishing messages with photos of alleged prisoners of war (
The Hacker News – Read More
GiveWP WordPress Plugin Vulnerability Puts 100,000+ Websites at Risk
/in General NewsA maximum-severity security flaw has been disclosed in the WordPress GiveWP donation and fundraising plugin that exposes more than 100,000 websites to remote code execution attacks.
The flaw, tracked as CVE-2024-5932 (CVSS score: 10.0), impacts all versions of the plugin prior to version 3.14.2, which was released on August 7, 2024. A security researcher, who goes by the online alias villu164,
The Hacker News – Read More
Singapore updates OT security blueprint to focus on data sharing and cyber resilience
/in General NewsSingapore’s national operational technology masterplan has been updated to address the ‘increasingly perilous’ cyber threat landscape.
Latest stories for ZDNET in Security – Read More
New Phishing Attacks Target Eastern European Bank Users on iOS and Android
/in General NewsCybercriminals exploit Progressive Web Apps (PWAs) in the latest phishing scam, targeting mobile users in Czechia, Hungary, and…
Hackread – Latest Cybersecurity, Tech, Crypto & Hacking News – Read More
An AWS Configuration Issue Could Expose Thousands of Web Apps
/in General NewsAmazon has updated its instructions for how customers should more securely implement AWS’s traffic-routing service known as Application Load Balancer, but it’s not clear everyone will get the memo.
Security Latest – Read More
Detecting AWS Account Compromise: Key Indicators in CloudTrail Logs for Stolen API Keys
/in General NewsAs cloud infrastructure becomes the backbone of modern enterprises, ensuring the security of these environments is paramount. With AWS (Amazon Web Services) still being the dominant cloud it is important for any security professional to know where to look for signs of compromise. AWS CloudTrail stands out as an essential tool for tracking and logging API activity, providing a comprehensive
The Hacker News – Read More
Czech Mobile Users Targeted in New Banking Credential Theft Scheme
/in General NewsMobile users in the Czech Republic are the target of a novel phishing campaign that leverages a Progressive Web Application (PWA) in an attempt to steal their banking account credentials.
The attacks have targeted the Czech-based Československá obchodní banka (CSOB), as well as the Hungarian OTP Bank and the Georgian TBC Bank, according to Slovak cybersecurity company ESET.
“The phishing
The Hacker News – Read More