DESTAQUES

Gestão de Riscos

305 notícias
Gestão de Riscos The Hacker News 🇺🇸

Why Modern SOCs Need Multi-Layered Detections

The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely. …

Gestão de Riscos CISO Advisor 🇧🇷

Falha LegacyHive no Windows ganha patch não oficial

Pesquisadores publicaram correções não oficiais e gratuitas para uma falha de dia zero no Windows, chamada de LegacyHive, que permite que atacantes não administradores elevem privilégios e executem código automaticamente em sistemas atualizados. A vulnerabilidade, que ainda não r…

Gestão de Riscos The Hacker News 🇺🇸

N-day is Becoming N-Hour. Patching Faster Won't Save You.

Every patch is a confession. The moment a vendor ships a security fix, the diff between the old code and the new code tells anyone watching exactly what was broken and where. Turn that diff back into a working exploit, and you can hit every system that hasn't updated yet. This i…

Gestão de Riscos CISO Advisor 🇧🇷

Ataque destrói cadastro nacional de imóveis da Romênia

Um hacker invadiu a Agência Nacional de Cadastro e de Publicidade Imobiliária da Romênia (ANCPI) e apagou todo o banco de dados do registro de terras do país, depois de fracassar numa tentativa de extorsão, conforme informações divulgadas pelo jornalista Catalin Cimpanu em sua ne…

Gestão de Riscos Boletim Sec 🇧🇷

OpenSSL corrige falha que pode causar negação de serviço em conexões TLS

Uma vulnerabilidade chamada HollowByte pode permitir ataques de negação de serviço contra servidores que usam versões não corrigidas do OpenSSL. A falha pode ser acionada por uma requisição TLS maliciosa de apenas 11 bytes. O problema não recebeu CVE nem alerta formal do projeto …

Gestão de Riscos The Hacker News 🇺🇸

Mythos Didn't Break Your Security Program. Your Exposure Window Could.

The industry spent the initial months after Anthropic's April 7 Mythos reveal focused on volume. How many new CVEs would Mythos add to an already overloaded pipeline? How quickly would the flood of AI-driven discovery overwhelm triage capabilities? How long would it take adversar…

Gestão de Riscos The Hacker News 🇺🇸

New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code

An anonymous HTTP request can run code on a WordPress site. The bug is in core, so a bare install with zero plugins is exploitable. Every 6.9 and 7.0 site was in range until Friday, when WordPress shipped 6.9.5 and 7.0.2 and enabled what it calls forced updates through its auto-…

Gestão de Riscos Bleeping Computer 🇺🇸

Abbott Laboratories probes two cyber incidents amid extortion claims

Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and…

Gestão de Riscos The Hacker News 🇺🇸

OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests

Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in June with no CVE, no advisory, and no cha…

Link copiado!