Windows 11 cumulative updates KB5124008 & KB5122880 released
Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]
Microsoft has released Windows 11 KB5124008 and KB5122880 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]
Two separate attacks demonstrate how threat actors are finding new ways to compromise organizations by using the popular social engineering tactic.
A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster under the name Slim Spider. "The adversa…
SAP has addressed 20 vulnerabilities across multiple products in its September 2026 security updates, including a maximum-severity memory corruption flaw in the SAP Kernel code. [...]
Check Point Research said in a report published today that a single instruction planted in a ChatGPT conversation could cause ChatGPT to quietly work for an attacker while answering the user's question as usual. In the company's proof of concept, that hidden work read data from …
Threat actors are continuing to leverage artificial intelligence (AI) to streamline their operations, with one financially motivated hacking group employing an autonomous, multi-agent attack framework to carry out a large-scale credential harvesting campaign within six hours. Go…
Adobe has released an emergency fix for CVE-2026-75650, an actively exploited max-severity zero-day vulnerability dubbed StyleSmuggler, that impacts multiple versions of Magento and Adobe Commerce. [...]
Threat actors are increasingly switching from AI-powered coding assistants to multi-agent frameworks that automate every stage of an attack. [...]
A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.
Researchers at the security firm Calif have built a worm that takes over a WeChat account via an incoming call and demonstrated it spreading among three test phones. The person being called does not have to answer or touch their phone for it to work, but the caller must already …
Uma vulnerabilidade zero day ainda sem correção oficial no Magento Open Source e Adobe Commerce está sendo explorada para executar código remotamente e instalar backdoors em lojas virtuais. A falha foi chamada de StyleSmuggler e os primeiros ataques foram observados em 4 de setem…
Uma vulnerabilidade crítica no ASUS Control Center Enterprise (ACC) pode permitir que invasores remotos assumam controle completo do servidor de gerenciamento e dos dispositivos administrados pela plataforma. A falha é identificada como CVE-2026-75754 e recebeu pontuação CVSS 10.…
A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end up in the administrators group, Red Hat says. FreeIPA is the system that determines who may log in across a Linux domain and maintains all identities …
Uma vulnerabilidade grave no MikroTik RouterOS está sendo alvo de ataques contra roteadores expostos à internet. A falha pode permitir acesso não autenticado ao equipamento e abrir caminho para controle da rede administrada pelo dispositivo. A MikroTik confirmou o problema em 3 d…
Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild. The vulnerability, now tracked as CVE-2026-75650 (CVSS score: 10.0), has been codenamed StyleSmuggle…
Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves the way for malware deployment and tech support scams. The campaign, discovered by the DFIR Report in March 2026, has been codenamed BengalSEO. It has o…
Cibercriminosos estão explorando ativamente duas vulnerabilidades críticas no sistema operacional RouterOS para assumir o controle remoto de roteadores MikroTik sem necessidade de autenticação, conforme alertas emitidos pela fabricante e pelo governo da Polônia. As falhas, regist…
A Microsoft e o governo da Bélgica emitiram alertas sobre campanhas de ataque que utilizam o Microsoft Teams como vetor principal. O Safeonweb, uma iniciativa do Centro de Cibersegurança da Bélgica (CBB), relatou ter recebido múltiplas notificações de casos de fraude contra diret…
Um ataque em larga escala explora uma vulnerabilidade zero-day no Magento e no Adobe Commerce, plataformas que equipam mais de 160 mil sites, para instalar um backdoor persistente em servidores Linux. A primeira tentativa de invasão foi registrada em 4 de setembro. A falha, batiz…
Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. "Requiring prior administrative or code execution access, its installer injects the extension directl…