DESTAQUES

Ameaças Cibernéticas

1629 notícias
Ameaças Cibernéticas The Hacker News 🇺🇸

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution. The vulnerability, tracked as CVE-2026-59726 (CVSS score: 1…

Ameaças Cibernéticas The Hacker News 🇺🇸

Nine-Year Fraud Campaign Clones Russian Company Sites to Steal Advance Payments

Cybersecurity researchers have disclosed details of a large-scale fraud campaign that involves creating lookalike websites of major Russian companies with an aim to siphon funds from international firms for more than nine years. According to Russian cybersecurity vendor F6, the …

Ameaças Cibernéticas The Hacker News 🇺🇸

Mythos Asks the Right Question. It Doesn't Answer It.

AI is compressing exploit timelines. The real question isn't whether your vulnerability management playbook needs to change, it's which part of it you've been getting wrong all along. The conversation happening in security circles right now goes something like this: Mythos is he…

Ameaças Cibernéticas The Hacker News 🇺🇸

Researchers Show a Single Malicious Webpage Visit Can Compromise Tor Browser

Nebula Security says a patched Firefox JIT flaw could be triggered by simply visiting a malicious webpage and was also used to compromise Tor Browser. Tracked as CVE-2026-10702, the bug provides arbitrary code execution inside the browser's renderer process. Mozilla rated it Hig…

Ameaças Cibernéticas Boletim Sec 🇧🇷

Cibercriminosos escondem malware em comando de instalação do Claude Code

Cibercriminosos estão escondendo malware em um falso comando de instalação do Claude Code para infectar computadores macOS. A campanha usa anúncios patrocinados e páginas aparentemente legítimas para alcançar desenvolvedores interessados na ferramenta de inteligência artificial. …

Ameaças Cibernéticas Boletim Sec 🇧🇷

Botnet Tengu usa 25 métodos para derrubar serviços online

Uma nova botnet chamada Tengu está infectando dispositivos de Internet das Coisas e sistemas Linux embarcados para executar ataques de negação de serviço, redirecionar tráfego e manter acesso persistente. A ameaça é uma versão modernizada do malware Mirai. A infecção observada co…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Alerta para falha CVSS 10 no VeloCloud Orchestrator

A Arista Networks publicou ontem (27 de julho) um aviso de segurança sobre uma vulnerabilidade de injeção de comandos no VeloCloud Orchestrator (VCO) on-prem, classificada com a pontuação máxima de gravidade CVSS 10.0. A falha, rastreada como CVE-2026-16812, pode permitir que um …

Ameaças Cibernéticas The Hacker News 🇺🇸

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content into a live Git hook and run shell commands as the Gitea service account. Tracked as CVE-2026-…

Ameaças Cibernéticas The Hacker News 🇺🇸

Flying Eagle Android RAT Traces Found on 170 Servers as Source Code Circulates

Source code for the Flying Eagle Android remote access trojan (RAT) framework is circulating through criminal Telegram channels. Hunt.io and independent researcher NetAskari traced matching control panels and certificates to 170 internet servers. They linked the framework to a f…

Ameaças Cibernéticas The Hacker News 🇺🇸

Two Compromised joyfill npm Packages Run RAT When Imported Into Node.js

Beta release versions of two npm packages in the @joyfill namespace have been compromised to deliver a remote access trojan (RAT) associated with the DEV#POPPER malware family. The list of affected packages is as follows - @joyfill/layouts@0.1.2-2773.beta.0 @joyfill/compon…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Apple corrige falhas de execução de código em imagens no iOS e macOS

A Apple publicou ontem atualizações de segurança para iOS, iPadOS e macOS que corrigem vulnerabilidades permitindo a execução de código arbitrário em iPhones, iPads e Macs por meio de imagens maliciosas. As falhas afetam os componentes AppleDouble, ImageIO e SceneKit. Vulnerabili…

Link copiado!