DESTAQUES

Ameaças Cibernéticas

1629 notícias
Ameaças Cibernéticas CISO Advisor 🇧🇷

Dois anos espionando atividades de hackers norte-coreanos

O pesquisador de segurança Vangelis Stykas, CTO da empresa de cibersegurança Kumio, detalhou na conferência Black Hat, em Las Vegas, uma investigação de 22 meses que resultou no acesso a servidores de comando e controle usados por hackers norte-coreanos. Stykas afirmou ter identi…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Incidentes com Levi Strauss e com fornecedor de defesa

A Levi Strauss & Co. divulgou na sexta-feira (7 de agosto) que hackers obtiveram acesso não autorizado a arquivos corporativos após comprometer três computadores de funcionários por meio de um ataque de engenharia social, de acordo com o comunicado oficial da empresa. A fabricant…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Metabase confirma exploração ativa de falha crítica

A Metabase confirmou que uma vulnerabilidade zero-day crítica, rastreada como GHSA-vwf4-m7j8-wcjf, está sendo ativamente explorada para conceder acesso administrativo completo a instâncias não corrigidas. De acordo com o comunicado da empresa, a falha atinge todas as versões a pa…

Ameaças Cibernéticas The Hacker News 🇺🇸

New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens

New research shows content inside an email can escape its message boundary and interfere with the webmail interface. Across attack chains spanning Outlook, Gmail, Fastmail, Proton Mail, Yahoo Mail, and AOL Mail, the techniques can capture passwords, take over third-party account…

Ameaças Cibernéticas The Hacker News 🇺🇸

Metabase Zero-Day Exploited in Wild Allows Admin Access Without Authentication

Metabase has warned that a maximum-severity security flaw impacting its business intelligence and data visualization software package has been exploited in the wild as a zero-day. The vulnerability (CVSS score: 10.0), which does not carry a CVE identifier, allows an unauthentica…

Ameaças Cibernéticas The Hacker News 🇺🇸

N-able Issues N-central Hotfix 2 as Attackers Reach Managed Systems and Persist

N-able has released a fresh round of hotfixes for N‑central as part of its investigation into ongoing exploitation of a recently disclosed security flaw in the Remote Monitoring and Management (RMM) product. "We are proactively expanding protections in response to ongoing monito…

Ameaças Cibernéticas The Hacker News 🇺🇸

Progress Kemp LoadMaster Flaw Hits CISA KEV After 792 Reported Exploit Attempts

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added a critical-severity security flaw impacting Progress Kemp LoadMaster to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation in the wild. The vulnerability, tr…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Uso corporativo de IA cresceu 158% em um ano

A Infoblox publicou ontem o relatório “Threat Landscape Report 2026”, com dados coletados entre junho de 2025 e junho de 2026, revelando a industrialização do cibercrime impulsionada por IA e automação. De acordo com o documento, o número de grupos de ransomware cresceu 67% no pe…

Ameaças Cibernéticas The Hacker News 🇺🇸

Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer

A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. "These packages appear to use AI slop squatted, or randomly generated typo-squatting …

Ameaças Cibernéticas The Hacker News 🇺🇸

ClickFix Attacks Deliver macOS Stealer That Can Drain Crypto Wallets

ClickFix-style attacks are being used to deliver a Go-based malware capable of stealing cryptocurrency assets, as well as browser-stored passwords, Apple iCloud Keychain data, and cached credentials. The macOS-focused infection chain is designed to deliver a shell script that pr…

Ameaças Cibernéticas The Hacker News 🇺🇸

UNC6671 Vishing Attacks Target Personal Phones to Steal SaaS Data

A recent wave of cyber attacks targeting financial services, private equity, and professional services is attributed to a data extortion group known as UNC6671. "UNC6671 continues to rely on voice phishing (vishing) to target enterprise employees, posing as IT help desk staff fa…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Apura lança BTTneo, plataforma de Threat Intel com IA

A Apura anunciou nesta semana o lançamento da plataforma BTTneo, uma nova geração da sua plataforma de cyber threat intelligence, que substitui a BTTng, conforme explicou a empresa em comunicado. A plataforma consolida a coleta e o processamento de ameaças em escala, com mais de …

Ameaças Cibernéticas Bleeping Computer 🇺🇸

Real emails, hijacked payments: Two H1 2026 attack chains

Gen's H1 2026 Threat Report examines two separate attack chains. One used compromised business inboxes and browser manipulation in a banking-malware campaign, while the other used clipboard hijacking to redirect cryptocurrency payments. [...]

Ameaças Cibernéticas The Hacker News 🇺🇸

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution - Patch ASAP

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. Under additional conditions, the bug can be chained into PHP code execution on the server. Tracked as CVE-2026-6463…

Link copiado!