WhatsApp adds stronger two-step verification, multiple passkeys
WhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. [...]
WhatsApp has started rolling out several new account security features, including support for multiple passkeys and stronger two-step verification. [...]
Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck's CVE Numbering Authority (CNA) record. The CNA recor…
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability. [...]
By Christy Winter - For decades, paper-based authorizations have stalled the healthcare industry, creating administrative backlogs for care teams and critical treatment delays for patients. On average, practices spend 13 hours each week completing 40 prior authorizations per clin…
Accertify Expands Fraud Prevention Capabilities into Healthcare with HIPAA Compliance Business Wire
Accertify Expands Fraud Prevention Capabilities into Healthcare with HIPAA Compliance Yahoo Finance
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of tar…
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downl…
O agente de pentest conhecido como, Yaga, desenvolvido pela empresa de cibersegurança ofensiva HackerSec, atingiu 98,8% de efetividade em cenários white box na nova versão mais recente do YagaBench. Nas demais modalidades, o agente registrou 96,2% em black box e 97% em gray box, …
Um novo malware para macOS chamado AmnesiaStealer permite que invasores roubem dados e assumam silenciosamente o controle de navegadores já autenticados. A ameaça combina infostealer, persistência e sequestro de sessões ativas. A infecção começa com uma página falsa que imita o G…
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services to …
A Cisco corrigiu nove vulnerabilidades críticas nas plataformas Crosswork e Secure Workload, incluindo falhas com pontuação máxima CVSS 10.0. Segundo a empresa, não há indícios de exploração ativa. No Crosswork, as falhas são rastreadas como CVE-2026-20030, CVE-2026-20357, CVE-20…
Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. Wh…
Uma vulnerabilidade de execução remota de código no Zimbra Collaboration Suite está sendo explorada ativamente em ataques, permitindo que invasores não autenticados executem comandos no sistema operacional de servidores vulneráveis. A falha é rastreada como CVE-2026-73570. O prob…
O maior risco da medicina de precisão não é a máquina errar. É formarmos uma geração incapaz de perceber quando ela erra - e essa conta chega ao caixa antes de chegar ao prontuário. The post Medicina de precisão exige médicos capazes de discordar da inteligência artificial appear…
RecruitTrap scam uses fake recruitment pages on mobile devices to hide URL clues, reject personal emails and steal corporate login credentials.
Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups. [...]
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including administrators. The vulnerabilities, as disclosed b…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabili…
Pesquisadores da Truffle Security identificaram 10.616 chaves de acesso da Amazon Web Services (AWS) ativas e válidas, expostas publicamente entre agosto de 2022 e agosto de 2026, conforme relatório publicado pela empresa em 19 de agosto de 2026. Do total, 817 chaves estavam vinc…