DESTAQUES

Ameaças Cibernéticas

1629 notícias
Ameaças Cibernéticas The Hacker News 🇺🇸

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive data and downstream credentials without exploiting a software vulnerability. We scanned public GitHub com…

Ameaças Cibernéticas The Hacker News 🇺🇸

Open VSX Removes 77 Malicious Evil Twin Extensions Exfiltrating Developer Data

A cluster of 77 extensions on the Open VSX marketplace has been found to impersonate legitimate developer tools while transmitting information about the systems and development environments on which they were installed. The "evil twin" extensions were uploaded to the repository …

Ameaças Cibernéticas The Hacker News 🇺🇸

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild. The list of vulnerabilities is as follows - CVE-2026-9198 (CVSS sc…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Falha em BMC expõe 24 mil data centers a ataque

Mais de 24 mil interfaces de gerenciamento de servidores acessíveis pela internet divulgam hashes de autenticação antes do login. A vulnerabilidade CVE-2013-4786, introduzida em 2004 no protocolo IPMI 2.0, permite que invasores obtenham hashes de senha e os decifrem offline. A fa…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Ataque a pacotes NPM afeta mais de 430 bibliotecas de software

Um invasor comprometeu a conta de um mantenedor de pacotes populares no npm e espalhou um programa malicioso que rouba credenciais de acesso. Segundo Ilyas Makari, que divulgou o caso em 4 de agosto, o ataque atingiu diretamente o pacote keyv, usado em cerca de 127 milhões de dow…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Ferramentas para injeção de prompt a US$ 150/mês

A Proofpoint identificou que atacantes estão desenvolvendo e vendendo, em fóruns clandestinos, ferramentas para explorar injeção indireta de prompt (IDPI), com “assinaturas” a partir de US$ 150 por mês. As ofertas incluem geradores de IDPI para e-mails, PDFs, convites de calendár…

Ameaças Cibernéticas Bleeping Computer 🇺🇸

77 Open VSX extensions found harvesting developer info

77 extensions on the Open VSX marketplace impersonated legitimate developer tools while transmitting information about the systems and development environments where they were installed. [...]

Ameaças Cibernéticas CISO Advisor 🇧🇷

Estudo indica recorde de DDoS e pico de 4.5 Tbps

A Huge Networks, empresa brasileira especializada em mitigação de DDoS e infraestrutura cloud, publicou hoje seu relatório HugeReport. O estudo, desenvolvido com dados registrados pela empresa no atendimento a seus clientes, indica que houve 108.393 ataques DDoS em junho de 2026,…

Ameaças Cibernéticas The Hacker News 🇺🇸

Greatness PhaaS Adds Device Code Phishing to Bypass MFA and Steal Tokens

The commercial phishing-as-a-service (PhaaS) toolkit known as Greatness has become the latest crimeware solution to add support for device code phishing, a rapidly growing cyber threat that abuses the legitimate OAuth 2.0 Device Authorization Grant to bypass Multi-Factor Authenti…

Link copiado!