BackBox.org offers a range of Penetration Testing services to simulate an attack on your network or application. If you are interested in our services, please contact us and we will provide you with further information as well as an initial consultation.
SmarterMail Fixes Critical Unauthenticated RCE Flaw with CVSS 9.3 Score
/in General NewsSmarterTools has addressed two more security flaws in SmarterMail email software, including one critical security flaw that could result in arbitrary code execution.
The vulnerability, tracked as CVE-2026-24423, carries a CVSS score of 9.3 out of 10.0.
“SmarterTools SmarterMail versions prior to build 9511 contain an unauthenticated remote code execution vulnerability in the ConnectToHub API
The Hacker News – Read More
Ex-Google Engineer Convicted for Stealing 2,000 AI Trade Secrets for China Startup
/in General NewsA former Google engineer accused of stealing thousands of the company’s confidential documents to build a startup in China has been convicted in the U.S., the Department of Justice (DoJ) announced Thursday.
Linwei Ding (aka Leon Ding), 38, was convicted by a federal jury on seven counts of economic espionage and seven counts of theft of trade secrets for taking over 2,000 documents containing
The Hacker News – Read More
Two Ivanti EPMM Zero-Day RCE Flaws Actively Exploited, Security Updates Released
/in General NewsIvanti has rolled out security updates to address two security flaws impacting Ivanti Endpoint Manager Mobile (EPMM) that have been exploited in zero-day attacks, one of which has been added by the U.S. Cybersecurity and Infrastructure Security Agency (CISA) to its Known Exploited Vulnerabilities (KEV) catalog.
The critical-severity vulnerabilities are listed below –
CVE-2026-1281 (CVSS score:
The Hacker News – Read More
This tiny USB-C mic is the easiest way to make your phone videos sound professionally recorded
/in General NewsShure’s MV88 USB-C microphone is a beginner-friendly option with lots of customization.
Latest news – Read More
Microsoft’s latest zero-day patch blocks a viral Office document hack – how to protect your PC ASAP
/in General NewsThis emergency zero-day patch prevents attackers from slipping past built-in protections and compromising your system.
Latest news – Read More
More Critical Flaws on n8n Could Compromise Customer Security
/in General NewsA new around of vulnerabilities in the popular AI automation platform could let attackers hijack servers and steal credentials.
darkreading – Read More
Trump Administration Rescinds Biden-Era SBOM Guidance
/in General NewsFederal agencies will no longer be required to solicit software bills of material (SBOMs) from tech vendors, nor attestations that they comply with NIST’s Secure Software Development Framework (SSDF). What that means long term is unclear.
darkreading – Read More
Fintech firm Marquis blames hack at firewall provider SonicWall for its data breach
/in General NewsThe fintech giant said it plans to “seek recoupment of any expenses” from its firewall provider SonicWall after a 2025 data breach exposed customer firewall configurations.
Security News | TechCrunch – Read More
Why France just dumped Teams and Zoom for homegrown videoconferencing
/in General NewsAiming to replace all US videoconferencing services by 2027, the deployment is the EU’s latest policy move in support of digital sovereignty. And there’s more to come.
Latest news – Read More
Samsung is giving away free 24-inch monitors – here’s how to get yours
/in General NewsRight now, when you buy the Odyssey G9 OLED gaming monitor from Samsung, you’ll get a 24-inch essential screen for free.
Latest news – Read More