DESTAQUES

Ameaças Cibernéticas

1624 notícias
Ameaças Cibernéticas CISO Advisor 🇧🇷

Alerta para expansão acelerada de infostealers na América Latina

A Vision Cybersecurity, empresa brasileira especialista em segurança digital, identificou uma expansão acelerada da atividade de infostealers na América Latina, com mais de 5 milhões de credenciais domésticas comprometidas e quase 100 mil credenciais corporativas expostas. A empr…

Ameaças Cibernéticas Bleeping Computer 🇺🇸

FFmpeg fixes PixelSmash flaw in widely used video decoder

A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and can also trigger a denial-of-service  condition in applications like Kodi, Emby, Nextcloud, PhotoPrism, and OBS Studio. [...]

Ameaças Cibernéticas CISO Advisor 🇧🇷

Fortinet reage à campanha FortiBleed

Em resposta oficial ao avanço da massiva campanha de roubo de credenciais batizada de FortiBleed, a Fortinet emitiu um posicionamento técnico esclarecendo que as intrusões não estão associadas à exploração de novas falhas de segurança (zero-days) em seus produtos. De acordo com a…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Nova botnet AryStinger infecta roteadores D-Link

Uma nova operação de cibercrime baseada na formação de redes zumbis, batizada de botnet AryStinger, comprometeu com sucesso milhares de roteadores da fabricante D-Link ao redor do mundo. A campanha maliciosa utiliza táticas de varredura em massa para identificar dispositivos de r…

Ameaças Cibernéticas The Hacker News 🇺🇸

ShapedPlugin WordPress Pro Plugins Backdoored in Supply Chain Attack

Multiple WordPress plugins from ShapedPlugin were compromised in a supply chain attack after unknown threat actors managed to tamper with the official release channels and push backdoor code. "Attackers compromised the vendor's build and distribution pipeline, injecting backdoor…

Ameaças Cibernéticas Bleeping Computer 🇺🇸

Microsoft fixes AutoGen Studio flaw that enabled code execution

A vulnerability chain dubbed AutoJack in Microsoft's AutoGen Studio interface for prototyping AI agents could let attackers manipulate an agent into executing arbitrary commands on its host system simply by visiting a malicious webpage. [...]

Ameaças Cibernéticas The Hacker News 🇺🇸

29-Year-Old Squid Proxy Bug 'Squidbleed' Can Leak Cleartext HTTP Requests

A heap over-read in the Squid web proxy can leak another user's cleartext HTTP request, including any credentials or session tokens it carries, to anyone already allowed to send traffic through the same proxy. The bug traces to a 1997 FTP-parsing change and is still live in Squi…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Ataque à Klue comprometeu contas de empresas de segurança

O ataque à plataforma de inteligência competitiva Klue resultou no comprometimento de contas de negócios de pelo menos cinco empresas de segurança, que tiveram dados de seus ambientes Salesforce comprometidos, conforme revelações publicadas no último fim de semana. A intrusão, de…

Ameaças Cibernéticas The Hacker News 🇺🇸

New OXLOADER Loader Uses Malicious Google Ads to Deliver CastleStealer

Cybersecurity researchers have disclosed details of a new campaign that delivers CastleStealer by means of a previously unreported malware loader dubbed OXLOADER. According to Elastic Security Labs, the campaign leverages malicious Google Ads as a starting point to distribute th…

Ameaças Cibernéticas The Hacker News 🇺🇸

Stop Your Legacy Infrastructure from Hijacking Your AI Agents

Earlier this month, I spoke at the Gartner Security & Risk Management Summit about a blind spot most security programs are still not accounting for - how attackers are circumventing AI security programs by using legacy infrastructure to hijack AI agents. AI adoption is moving fa…

Link copiado!