DESTAQUES

Ameaças Cibernéticas

1630 notícias
Ameaças Cibernéticas The Hacker News 🇺🇸

U.S. Sanctions Iran-Linked Hackers Behind Critical Infrastructure Breaches

The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial co…

Ameaças Cibernéticas The Hacker News 🇺🇸

A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw

Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker …

Ameaças Cibernéticas The Hacker News 🇺🇸

Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA recor…

Ameaças Cibernéticas The Hacker News 🇺🇸

24 npm Packages Abuse unpkg Mirrors to Host Fake Cloudflare CAPTCHA Pages

Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downl…

Ameaças Cibernéticas Boletim Sec 🇧🇷

Novo malware para Mac sequestra sessões autenticadas do navegador

Um novo malware para macOS chamado AmnesiaStealer permite que invasores roubem dados e assumam silenciosamente o controle de navegadores já autenticados. A ameaça combina infostealer, persistência e sequestro de sessões ativas. A infecção começa com uma página falsa que imita o G…

Ameaças Cibernéticas The Hacker News 🇺🇸

E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands

Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services to …

Ameaças Cibernéticas Boletim Sec 🇧🇷

Cisco lança patches para falhas graves em soluções corporativas

A Cisco corrigiu nove vulnerabilidades críticas nas plataformas Crosswork e Secure Workload, incluindo falhas com pontuação máxima CVSS 10.0. Segundo a empresa, não há indícios de exploração ativa. No Crosswork, as falhas são rastreadas como CVE-2026-20030, CVE-2026-20357, CVE-20…

Ameaças Cibernéticas Boletim Sec 🇧🇷

CISA alerta para vulnerabilidade explorada ativamente no Zimbra

Uma vulnerabilidade de execução remota de código no Zimbra Collaboration Suite está sendo explorada ativamente em ataques, permitindo que invasores não autenticados executem comandos no sistema operacional de servidores vulneráveis. A falha é rastreada como CVE-2026-73570. O prob…

Ameaças Cibernéticas The Hacker News 🇺🇸

Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access

Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed b…

Ameaças Cibernéticas Bleeping Computer 🇺🇸

Unpatched Calix flaw lets hackers bypass NAT to expose internal devices

An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the public internet. [...]

Link copiado!