DESTAQUES

Ameaças Cibernéticas

1625 notícias
Ameaças Cibernéticas The Hacker News 🇺🇸

New Ghost Phishing Wave Is Breaking Traditional Email Security

A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser. For security leaders, the risk…

Ameaças Cibernéticas The Hacker News 🇺🇸

SCMBANKER Malware Uses ClickFix Lures to Target Mexican Banking Users

A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures. The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake C…

Ameaças Cibernéticas Boletim Sec 🇧🇷

BeyondTrust corrige falhas críticas que permitem acesso sem autenticação

A BeyondTrust corrigiu quatro vulnerabilidades graves em suas soluções Remote Support e Privileged Remote Access, usadas por empresas para suporte remoto e acesso seguro a sistemas internos. Duas falhas receberam pontuação máxima de 9,2 e podem permitir invasões sem necessidade d…

Ameaças Cibernéticas The Hacker News 🇺🇸

The Verification Step Is the New ATO Battleground in 2026

For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credentials in bulk, ran them through automated tools, and waited for matches. Credential stuffing was cheap, scalable, and for defenders, relatively well understood. That era is ending. Not…

Ameaças Cibernéticas The Hacker News 🇺🇸

China-Linked UAT-7810 Expands ORB Network With New LONGLEASH Malware

A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking devices. According to findings from Cisco Talos, UAT-7810 is an advanced persistent threat (APT) acto…

Ameaças Cibernéticas The Hacker News 🇺🇸

CISA Adds 4 Actively Exploited Adobe, Joomla, and Langflow Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-48282 (CVSS score: 10.0) - A pa…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Falha crítica no Gitea é explorada em ataques

Atacantes estão explorando ativamente a vulnerabilidade CVE-2026-20896 (CVSS 9.8) no Gitea, plataforma de desenvolvimento auto-hospedada, para contornar a autenticação e acessar repositórios e segredos de código. A falha, específica das imagens oficiais Docker do Gitea, permite q…

Ameaças Cibernéticas Bleeping Computer 🇺🇸

Chinese hackers develop LONGLEASH malware to expand ORB network

Chinese hackers tracked as 'UAT-7810' are actively evolving their malware to expand their Operational Relay Box (ORB) network by compromising internet-facing networking devices, primarily unpatched Ruckus routers. [...]

Ameaças Cibernéticas CISO Advisor 🇧🇷

EtherRAT é instalado via engenharia social no Teams

Atores de ameaça estão abusando de chamadas de voz no Microsoft Teams, se passando por funcionários do suporte de TI corporativo para enganar funcionários e instalar o malware EtherRAT, conforme alertou ontem a Unit 42, da Palo Alto Networks. A campanha combina e-mails de phishin…

Ameaças Cibernéticas CISO Advisor 🇧🇷

BeyondTrust corrige duas falhas críticas 

A BeyondTrust alertou ontem seus clientes sobre duas vulnerabilidades críticas em suas plataformas Remote Support (RS) e Privileged Remote Access (PRA), que poderiam permitir que atacantes não autenticados contornassem controles de acesso. As falhas, registradas como CVE-2026-401…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Identificador do Windows 11 leva cibercriminoso à prisão

O Departamento de Justiça dos EUA, com auxílio do FBI e da polícia finlandesa, prendeu na semana passada um jovem de 19 anos, suspeito de integrar o grupo de extorsão Scattered Spider. O preso é Peter Stokes, que tem dupla cidadania americana e estoniana, e foi detido em Helsinqu…

Link copiado!