BackBox.org offers a range of Penetration Testing services to simulate an attack on your network or application. If you are interested in our services, please contact us and we will provide you with further information as well as an initial consultation.
6 Best Open Source Password Managers for Mac in 2024
/in General NewsExplore the top open-source password managers available for Mac users. Find the best one that suits your needs and secure your online accounts effectively.
Security | TechRepublic – Read More
530k Impacted by Data Breach at Wisconsin Healthcare Organization
/in General NewsThe personal information of 500,000 people was compromised in a data breach at Group Health Cooperative of South Central Wisconsin.
The post 530k Impacted by Data Breach at Wisconsin Healthcare Organization appeared first on SecurityWeek.
SecurityWeek – Read More
Microsoft Patches Two Zero-Days Exploited for Malware Delivery
/in General NewsMicrosoft patches CVE-2024-29988 and CVE-2024-26234, two zero-day vulnerabilities exploited by threat actors to deliver malware.
The post Microsoft Patches Two Zero-Days Exploited for Malware Delivery appeared first on SecurityWeek.
SecurityWeek – Read More
Webinar: Learn How to Stop Hackers from Exploiting Hidden Identity Weaknesses
/in General NewsWe all know passwords and firewalls are important, but what about the invisible threats lurking beneath the surface of your systems?
Identity Threat Exposures (ITEs) are like secret tunnels for hackers – they make your security way more vulnerable than you think.
Think of it like this: misconfigurations, forgotten accounts, and old settings are like cracks in your digital fortress walls. Hackers
The Hacker News – Read More
Novel Ahoi Attacks Could Compromise Confidential VMs
/in General NewsThe researchers presented two variations of what they call Ahoi attacks. One of them, dubbed Heckler, involves a malicious hypervisor injecting interrupts to alter data and control flow, breaking the integrity and confidentiality of CVMs.
Cyware News – Latest Cyber News – Read More
Vedalia APT Group Exploits Oversized LNK Files in Malware Campaign
/in General NewsThe Vedalia APT group has ingeniously utilized LNK files with double extensions, effectively masking the malicious .lnk extension. This tactic deceives users into believing the files are harmless, increasing the likelihood of execution.
Cyware News – Latest Cyber News – Read More
Microsoft Fixes 149 Flaws in Huge April Patch Release, Zero-Days Included
/in General NewsMicrosoft has released security updates for the month of April 2024 to remediate a record 149 flaws, two of which have come under active exploitation in the wild.
Of the 149 flaws, three are rated Critical, 142 are rated Important, three are rated Moderate, and one is rated Low in severity. The update is aside from 21 vulnerabilities that the company addressed in its
The Hacker News – Read More
Top MITRE ATT&CK Techniques and How to Defend Against Them
/in General NewsA cheat sheet for all of the most common techniques hackers use, and general principles for stopping them.
darkreading – Read More
Critical ‘BatBadBut’ Rust Vulnerability Exposes Windows Systems to Attacks
/in General NewsA critical security flaw in the Rust standard library could be exploited to target Windows users and stage command injection attacks.
The vulnerability, tracked as CVE-2024-24576, has a CVSS score of 10.0, indicating maximum severity. That said, it only impacts scenarios where batch files are invoked on Windows with untrusted arguments.
“The Rust standard library did not properly escape
The Hacker News – Read More
New Jamf Tools Give Enterprise IT Security and Compliance Controls
/in General NewsThe device management company introduced a Fleet Hardening Score and Privilege Escalation (the good kind) to its endpoint security platform for Apple devices.
darkreading – Read More