BackBox.org offers a range of Penetration Testing services to simulate an attack on your network or application. If you are interested in our services, please contact us and we will provide you with further information as well as an initial consultation.
SonicWall NetExtender Trojan and ConnectWise Exploits Used in Remote Access Attacks
/in General NewsUnknown threat actors have been distributing a trojanized version of SonicWall’s SSL VPN NetExtender application to steal credentials from unsuspecting users who may have installed it.
“NetExtender enables remote users to securely connect and run applications on the company network,” SonicWall researcher Sravan Ganachari said. “Users can upload and download files, access network drives, and use
The Hacker News – Read More
Mainline Health, Select Medical Each Disclose Data Breaches Impacting 100,000 People
/in General NewsMainline Health and Select Medical Holdings have suffered data breaches that affect more than 100,000 individuals.
The post Mainline Health, Select Medical Each Disclose Data Breaches Impacting 100,000 People appeared first on SecurityWeek.
SecurityWeek – Read More
North Korea-linked Supply Chain Attack Targets Developers with 35 Malicious npm Packages
/in General NewsCybersecurity researchers have uncovered a fresh batch of malicious npm packages linked to the ongoing Contagious Interview operation originating from North Korea.
According to Socket, the ongoing supply chain attack involves 35 malicious packages that were uploaded from 24 npm accounts. These packages have been collectively downloaded over 4,000 times. The complete list of the JavaScript
The Hacker News – Read More
Russian APT Hits Ukrainian Government With New Malware via Signal
/in General NewsRussia-linked APT28 deployed new malware against Ukrainian government targets through malicious documents sent via Signal chats.
The post Russian APT Hits Ukrainian Government With New Malware via Signal appeared first on SecurityWeek.
SecurityWeek – Read More
New WordPress Malware Hides on Checkout Pages and Imitates Cloudflare
/in General NewsWordfence exposes a sophisticated WordPress malware campaign using a rogue WordPress Core plugin. Active since 2023, it steals credit cards and credentials with advanced anti-detection.
Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto – Read More
These battery-powered 4K security cameras give Ring and Blink a run for their money
/in General NewsTP-Link’s new cameras feature 4K capabilities with 24/7 recording, thanks to the HomeBase H500. They’re also cheaper than their closest competitors.
Latest stories for ZDNET in Security – Read More
Microsoft Extends Windows 10 Security Updates for One Year with New Enrollment Options
/in General NewsMicrosoft on Tuesday announced that it’s extending Windows 10 Extended Security Updates (ESU) for an extra year by letting users either pay a small fee of $30 or by sync their PC settings to the cloud.
The development comes ahead of the tech giant’s upcoming October 14, 2025, deadline, when it plans to officially end support and stop providing security updates for devices running Windows 10. The
The Hacker News – Read More
Africa Sees Surge in Cybercrime as Law Enforcement Struggles
/in General NewsCybercrime accounts for more than 30% of all reported crime in East Africa and West Africa, with online scams, ransomware, business email compromise, and digital sextortion taking off.
darkreading – Read More
Threat Actor Trojanizes Copy of SonicWall NetExtender VPN App
/in General NewsA threat actor hacked a version of SonicWall’s NetExtender SSL VPN application in an effort to trick users into installing a Trojanized version of the product.
darkreading – Read More
China-Nexus ‘LapDogs’ Network Thrives on Backdoored SOHO Devices
/in General NewsThe campaign infected devices in the US and Southeast Asia to build an operational relay box (ORB) network for use as an extensive cyber-espionage infrastructure.
darkreading – Read More