Windows 0-day drops the same day Microsoft releases record number of patches
HiveLegacy is a "powerful primitive" that's likely capable of other nefarious actions.
HiveLegacy is a "powerful primitive" that's likely capable of other nefarious actions.
Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit with not so successful results. "While t…
A Russian-speaking threat actor known as "bandcampro" used Google's open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. [...]
A Sophos anunciou hoje o Sophos Fusion, o primeiro sistema de defesa em cibersegurança nativo em inteligência artificial do setor, projetado para oferecer resposta coordenada e automatizada a ameaças na velocidade da IA. A plataforma unifica operações de segurança, endpoint, rede…
A identidade se tornou o vetor de acesso inicial dominante para ataques de ransomware, com quatro em cada cinco incidentes (79%) tendo origem em credenciais comprometidas, segundo o sétimo relatório anual State of Ransomware da Sophos. A pesquisa independente, conduzida com líder…
Five malicious versions of AsyncAPI packages were published to the Node Package Manager (npm) in a supply-chain attack that delivered a remote access trojan with info-stealing capabilities. [...]
A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes from inside the wallet's own desktop software. Sometimes it w…
When combined with another exploit, the "PromptFiction" vulnerability, which has been fixed, could have enabled an end-to-end attack on a targeted system.
Intruder built an AI-powered "vulnerability vending machine" that combines code slicing with LLMs to automatically discover complex software vulnerabilities. The company explains how the system found and exploited a previously unknown WordPress plugin zero-day, with additional di…
Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly component CVE-2026-15719, a site isolati…
Sistemas desenvolvidos com o auxílio de inteligência artificial estão se tornando alvo crescente de ataques. Empresas de todos os tamanhos adotaram IA no desenvolvimento, das pequenas startups às grandes corporações, e a superfície de ataque cresceu proporcionalmente à velocidade…
Simple age-old bugs give bad actors access to developers' secrets and source code-rich environments.
A one-click Claude Desktop flaw allowed attackers to submit concealed instructions without review, exposing chats and enabling code execution on some systems remotely.
Uma vulnerabilidade ainda sem correção no editor de código Cursor pode permitir que arquivos maliciosos sejam executados automaticamente em computadores Windows quando o usuário abre um repositório preparado por invasores. A falha afeta o processo usado pelo Cursor para localizar…
O grupo de ransomware Qilin foi observado usando uma técnica capaz de extrair credenciais de praticamente todas as contas de um domínio Windows, ampliando o risco de movimentação lateral e controle completo da rede. A atividade explorou o próprio mecanismo de sincronização do Act…
A Microsoft confirmou ontem a existência de uma vulnerabilidade zero-day no BitLocker, registrada como CVE-2026-50661, que permite que invasores com acesso físico ao dispositivo contornem completamente a criptografia de disco do sistema. A falha, classificada como um bypass de re…
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. The Windows User Profile Service, a…
A SonicWall confirmou ontem que invasores estão explorando ativamente duas vulnerabilidades em seus appliances da série SMA1000, classificadas como CVE-2026-15409 e CVE-2026-15410, e emitiu um alerta urgente para que os clientes instalem as correções de segurança recém-publicadas…
A SAP lançou seu pacote de segurança de julho de 2026 com correções para 16 novas vulnerabilidades, um alerta adicional publicado no GitHub e três atualizações de problemas divulgados anteriormente. Quatro falhas foram classificadas como críticas. A vulnerabilidade mais grave, CV…
Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. Whatever that binary does, it does as you, with your source, your SSH key…