BackBox.org offers a range of Penetration Testing services to simulate an attack on your network or application. If you are interested in our services, please contact us and we will provide you with further information as well as an initial consultation.
VC firm Insight Partners confirms personal data stolen during January hack
/in General NewsThe venture capital firm has over $90 billion in assets under management, including cybersecurity giants.
Security News | TechCrunch – Read More
Security Tools Alone Don’t Protect You — Control Effectiveness Does
/in General News61% of security leaders reported suffering a breach due to failed or misconfigured controls over the past 12 months. This is despite having an average of 43 cybersecurity tools in place.
This massive rate of security failure is clearly not a security investment problem. It is a configuration problem. Organizations are beginning to understand that a security control installed or deployed is not
The Hacker News – Read More
Google Finds Data Theft Malware Used by Russian APT in Select Cases
/in General NewsRussia-linked APT Star Blizzard is using the ClickFix technique in recent attacks distributing the LostKeys malware.
The post Google Finds Data Theft Malware Used by Russian APT in Select Cases appeared first on SecurityWeek.
SecurityWeek – Read More
Improperly Patched Samsung MagicINFO Vulnerability Exploited by Botnet
/in General NewsThe patches for an exploited Samsung MagicINFO vulnerability are ineffective and a Mirai botnet has started targeting it.
The post Improperly Patched Samsung MagicINFO Vulnerability Exploited by Botnet appeared first on SecurityWeek.
SecurityWeek – Read More
Dozens of SysAid Instances Vulnerable to Remote Hacking
/in General NewsSysAid patches IT service management software vulnerabilities that can be chained for unauthenticated remote command execution.
The post Dozens of SysAid Instances Vulnerable to Remote Hacking appeared first on SecurityWeek.
SecurityWeek – Read More
Cisco Patches 35 Vulnerabilities Across Several Products
/in General NewsCisco releases patches for 26 vulnerabilities in IOS and IOS XE software, including 17 critical- and high-severity bugs.
The post Cisco Patches 35 Vulnerabilities Across Several Products appeared first on SecurityWeek.
SecurityWeek – Read More
Masimo Manufacturing Facilities Hit by Cyberattack
/in General NewsHealth technology and consumer electronics firm Masimo detected unauthorized activity on its network in late April.
The post Masimo Manufacturing Facilities Hit by Cyberattack appeared first on SecurityWeek.
SecurityWeek – Read More
Russian Hackers Using ClickFix Fake CAPTCHA to Deploy New LOSTKEYS Malware
/in General NewsThe Russia-linked threat actor known as COLDRIVER has been observed distributing a new malware called LOSTKEYS as part of an espionage-focused campaign using ClickFix-like social engineering lures.
“LOSTKEYS is capable of stealing files from a hard-coded list of extensions and directories, along with sending system information and running processes to the attacker,” the Google Threat
The Hacker News – Read More
Cisco Patches CVE-2025-20188 (10.0 CVSS) in IOS XE That Enables Root Exploits via JWT
/in General NewsCisco has released software fixes to address a maximum-severity security flaw in its IOS XE Wireless Controller that could enable an unauthenticated, remote attacker to upload arbitrary files to a susceptible system.
The vulnerability, tracked as CVE-2025-20188, has been rated 10.0 on the CVSS scoring system.
“This vulnerability is due to the presence of a hard-coded JSON Web Token (JWT) on an
The Hacker News – Read More
‘Lemon Sandstorm’ Underscores Risks to Middle East Infrastructure
/in General NewsThe Iranian state-backed group targeted the operational technology of a critical national infrastructure (CNI) network and persisted in its network for years, but ultimately failed.
darkreading – Read More