BackBox.org offers a range of Penetration Testing services to simulate an attack on your network or application. If you are interested in our services, please contact us and we will provide you with further information as well as an initial consultation.
Compromised RVTools Installer Spreading Bumblebee Malware
/in General NewsRVTools installer on its official site was found delivering malware. Research shows it spread Bumblebee loader. Users urged to verify downloads.
Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto – Read More
The Crowded Battle: Key Insights from the 2025 State of Pentesting Report
/in General NewsIn the newly released 2025 State of Pentesting Report, Pentera surveyed 500 CISOs from global enterprises (200 from within the USA) to understand the strategies, tactics, and tools they use to cope with the thousands of security alerts, the persisting breaches and the growing cyber risks they have to handle. The findings reveal a complex picture of progress, challenges, and a shifting mindset
The Hacker News – Read More
CloudSEK Raises $19 Million for Threat Intelligence Platform
/in General NewsThreat protection and intelligence firm CloudSEK raises $19 million in funding from new and existing investors.
The post CloudSEK Raises $19 Million for Threat Intelligence Platform appeared first on SecurityWeek.
SecurityWeek – Read More
O2 Service Vulnerability Exposed User Location
/in General NewsA vulnerability in O2’s implementation of the IMS standard resulted in user location data being exposed in network responses.
The post O2 Service Vulnerability Exposed User Location appeared first on SecurityWeek.
SecurityWeek – Read More
New Nitrogen Ransomware Targets Financial Firms in the US, UK and Canada
/in General NewsNitrogen, a ransomware strain, has emerged as a major threat to organizations worldwide, with a particular focus on…
Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto – Read More
Go-Based Malware Deploys XMRig Miner on Linux Hosts via Redis Configuration Abuse
/in General NewsCybersecurity researchers are calling attention to a new Linux cryptojacking campaign that’s targeting publicly accessible Redis servers.
The malicious activity has been codenamed RedisRaider by Datadog Security Labs.
“RedisRaider aggressively scans randomized portions of the IPv4 space and uses legitimate Redis configuration commands to execute malicious cron jobs on vulnerable systems,”
The Hacker News – Read More
Malicious PyPI Packages Exploit Instagram and TikTok APIs to Validate User Accounts
/in General NewsCybersecurity researchers have uncovered malicious packages uploaded to the Python Package Index (PyPI) repository that act as checker tools to validate stolen email addresses against TikTok and Instagram APIs.
All three packages are no longer available on PyPI. The names of the Python packages are below –
checker-SaGaF (2,605 downloads)
steinlurks (1,049 downloads)
sinnercore (3,300 downloads)
The Hacker News – Read More
‘Operation RoundPress’ Targets Ukraine in XSS Webmail Attacks
/in General NewsA cyber-espionage campaign is targeting Ukrainian government entities with a series of sophisticated spear-phishing attacks that exploit XSS vulnerabilities.
darkreading – Read More
Serviceaide Leak Exposes Records of 500,000 Catholic Health Patients
/in General NewsServiceaide data leak exposes sensitive health info of 500K Catholic Health patients due to misconfigured database; risk of ID theft and fraud.
Hackread – Latest Cybersecurity, Hacking News, Tech, AI & Crypto – Read More
Trump Signs Controversial Law Targeting Nonconsensual Sexual Content
/in General NewsThe Take It Down Act requires platforms to remove instances of “intimate visual depiction” within two days. Free speech advocates warn it could be weaponized to fuel censorship.
Security Latest – Read More