JetBrains warns of critical TeamCity remote code execution flaw
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. [...]
JetBrains is warning of a critical authentication bypass vulnerability affecting TeamCity On-Premises that could be exploited to achieve remote code execution. [...]
A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.
Exploits can give persistent server access that survives credential rotation and disk re-imaging.
A VMware alertou os clientes, ontem, sobre duas vulnerabilidades críticas que podem permitir que atacantes obtenham acesso a servidores vCenter. A empresa publicou atualizações para corrigir os problemas. O vCenter, solução para gerenciar máquinas virtuais e servidores virtualiza…
Pesquisadores da Silent Push demonstraram em um artigo técnico, que uma única técnica de ataque a registros DNS pendentes pode comprometer infraestruturas de governo, bancos, farmacêuticas e montadoras em escala global. A simulação, batizada de “Danglegeddon”, identificou 16 mil …
Um pesquisador de segurança revelou uma vulnerabilidade no Microsoft Copilot para Word que permite a propagação autônoma de instruções maliciosas entre documentos, criando um worm baseado em inteligência artificial. A falha, divulgada publicamente após 144 dias de coordenação com…
A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.
Threat actors with ties to North Korea have been attributed to a sophisticated macOS malvertising campaign that involves redirecting users to fake web pages displaying a full-screen non-existent update sequence to deliver malware as part of a new iteration of the long-running Con…
Amazon linked multiple high-profile open-source software supply chain attacks targeting the Node Package Manager (npm) ecosystem to North Korean hackers. [...]
Residential security company Brinks Home has disclosed that hackers breached some of its systems and are threatening to leak allegedly stolen data. [...]
Threat actors are impersonating IT support staff in Microsoft Teams calls to gain remote access to corporate devices and deploy Chaos ransomware in attacks targeting North American organizations. [...]
A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a recruiter call, or a familiar service behaving slightly wrong. Behind it: reused credentials, exposed systems, quiet loaders, abused trust, and expl…
American semiconductor company Analog Devices announced that an unauthorized party accessed some of its systems and exfiltrated certain files. [...]
Attackers rarely stop after gaining initial access. Huntress analyzes a real-world intrusion to show how threat actors establish persistence, disable defenses, and reshape compromised systems, and why defenders must investigate the original entry point rather than simply remove t…
Uma vulnerabilidade no mecanismo JavaScript do Firefox pode permitir o comprometimento do Tor Browser apenas com a abertura de uma página maliciosa. A falha afeta versões sem as correções mais recentes e não exige downloads ou permissões adicionais. Registrado como CVE-2026-10702…
A Broadcom corrigiu cinco vulnerabilidades em produtos VMware que podem permitir desvio de autenticação, execução de código e escape de máquinas virtuais. As falhas atingem ambientes corporativos baseados em vCenter, ESX, Cloud Foundation, Workstation e Fusion. A mais grave, CVE-…
A NVIDIA corrigiu uma vulnerabilidade crítica no VIRTIO-Net do BlueField-3 que pode permitir a execução de código em ambientes virtualizados. A falha representa risco principalmente para data centers, plataformas de nuvem e infraestruturas com máquinas virtuais de diferentes usuá…
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE b…
The Chinese cybercrime group known as Silver Fox has been observed using new drivers as part of bring your own vulnerable driver (BYOVD) attacks targeting a Japanese organization in the industrial manufacturing sector to ultimately deliver ValleyRAT (aka Winos 4.0) for persistent…
The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommuni…