DESTAQUES

Ameaças Cibernéticas

1624 notícias
Ameaças Cibernéticas Boletim Sec 🇧🇷

Ataques de Prompt Injection crescem à medida que empresas adotam IA

A adoção de chatbots e assistentes com inteligência artificial nas empresas acelerou nos últimos meses. Equipes de atendimento, suporte interno, jurídico e financeiro passaram a contar com interfaces conversacionais alimentadas por LLMs para automatizar tarefas e responder pergun…

Ameaças Cibernéticas The Hacker News 🇺🇸

Langflow RCE Exploited to Deploy Monero Miner on Exposed AI App Endpoints

Threat actors are continuing to exploit a critical Langflow vulnerability as part of fresh attacks designed to deliver a Monero cryptocurrency miner. The activity has been found to weaponize CVE-2026-33017 (CVSS score: 9.3), an unauthenticated remote code execution (RCE) vulnera…

Ameaças Cibernéticas Bleeping Computer 🇺🇸

Lessons from the Underground: How to Combat Business Email Compromise

Business Email Compromise is more than an email scam. It's a coordinated operation involving compromised accounts, financial research, and cash-out networks. Flare explores how underground forums reveal how BEC attacks are planned and executed. [...]

Ameaças Cibernéticas The Hacker News 🇺🇸

282 iOS AI Apps Leak API Keys and Open AI Proxy Access in Network Traffic Study

Researchers tested 444 AI chatbot apps for iPhone and found that 282 of them, nearly two-thirds, exposed paid AI access through their network traffic. In many cases, the path in was visible just by watching what the app sent: a plaintext API key, a reusable token, or a backend s…

Ameaças Cibernéticas Boletim Sec 🇧🇷

Cibercriminosos exploram falha crítica no Oracle EBS

Cibercriminosos estão explorando ativamente uma vulnerabilidade crítica no Oracle E-Business Suite, sistema usado por empresas para processos financeiros, pagamentos e operações corporativas. A falha foi identificada como CVE-2026-46817 e recebeu pontuação CVSS 9.8. O problema af…

Ameaças Cibernéticas The Hacker News 🇺🇸

What the Numbers Say About FIFA 2026 Cyber Risk

The FIFA World Cup 2026 opened on June 11. By that date, according to Check Point Research, the fraud infrastructure targeting it had already been built, staged, and partially deployed. Threat actor activity was pre-planned, months out, across three sectors and at least ten langu…

Ameaças Cibernéticas Boletim Sec 🇧🇷

Falha crítica no Gemini CLI permite execução de comandos

Uma vulnerabilidade crítica no Gemini CLI, ferramenta de linha de comando do Google voltada a desenvolvedores, pode permitir que invasores executem comandos em ambientes automatizados de desenvolvimento, especialmente em fluxos do GitHub Actions. A falha foi identificada como CVE…

Ameaças Cibernéticas The Hacker News 🇺🇸

New BioShocking Attack Tricks AI Browsers Into Leaking User Credentials

Convince an AI browser that it is playing a game, and it can hand over your login details. That is the finding behind BioShocking, a technique from security firm LayerX that tricked six AI browsers and assistants into copying a user's credentials and sending them to an attacker. …

Link copiado!