CubePilot drone software dev hit by DNS hijacking to intercept traffic
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. [...]
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack. [...]
Lots of Internet-exposed server management controllers are subject to offline password-cracking attacks — and adversaries have taken note.
JFrog has confirmed that OpenAI models exploited zero-day vulnerabilities in self-hosted Artifactory servers to help escape an isolated testing environment and gain access to the internet before attacking Hugging Face. [...]
OpenAI's recent AI agent sandbox escape proves traditional security principles matter more than ever: limit access, isolate execution, log everything.
O vBulletin, plataforma proprietária de fóruns baseada em PHP, corrigiu uma vulnerabilidade crítica que permite a execução remota de código (RCE) sem autenticação. O problema, registrado como CVE-2026-61511, afeta as versões 5.x e 6.x até a 5.7.5 e 6.2.1. O pesquisador independen…
Anthropic says Claude Mythos Preview helped derive an end-to-end key-recovery attack against HAWK-256 and a 200- to 800-fold speedup for an attack on seven-round AES-128. The HAWK attack exploits a previously unused symmetry in the lattice behind the signature scheme. Anthropic'…
Uma vulnerabilidade de execução remota de código no Fastjson afeta todas as versões até 1.2.83, permitindo que um atacante execute código arbitrário em servidores vulneráveis sem privilégios ou interação do usuário, de acordo com análise publicada ontem pela equipe de inteligênci…
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [...]
PhantomEnigma abuses Brazilian government websites and trusted email channels to spread malware, target banks, evade security checks, and maintain access.
Uma vulnerabilidade de estouro de buffer no NGINX Plus e NGINX Open Source, rastreada como CVE-2026-42533, pode permitir que atacantes não autenticados derrubem processos worker e, sob certas condições, executem código arbitrário, de acordo com análise compartilhada pelo pesquisa…
Microsoft patched a high-severity vulnerability earlier this month that allows a threat actor to escalate privileges and compromise an AD environment.
A new Mirai-derived botnet called Tengu can use a compromised Linux device's hardware watchdog to trigger a reboot when defenders kill its main process. If that happens, Tengu's other persistence mechanisms get another chance to relaunch it. Nozomi Networks Labs observed the dro…
Cybersecurity researchers have sounded an alert after finding more than 36,000 Baseboard Management Controller (BMC) management interfaces exposing Intelligent Platform Management Interface (IPMI) protocol to the public internet. Of the 36,872 internet-exposed server-management …
A compromised SSO login can provide attackers with access to multiple enterprise applications and services. Specops Software explains how stronger passwords, phishing-resistant MFA, and identity hardening help secure modern SSO environments and the applications they protect. [...…
JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory is JFrog's software repository manager. OpenAI says the models then escalated privileges and moved lat…
O número de falhas de segurança em produtos de tecnologia descobertas em 2026 deve praticamente dobrar o total de vulnerabilidades que surgiram em 2025, de acordo com as estatísticas do banco de dados National Vulnerabilities Database, do governo dos EUA. O repositório registrou …
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default. The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unaut…
More than 24,000 internet-exposed servers are leaking authentication password hashes due to a 20-year-old vulnerability in their Baseboard Management Controller (BMC) interface. [...]
The Iranian state-backed hacking group tracked as Nimbus Manticore (aka GalaxyGato, Mirage Kitten, Smoke Sandstorm, Subtle Snail, and UNC1549) has been attributed to a fresh set of attacks targeting entities across the Middle East, Africa, and South Asia. The intrusions involve …
Uma vulnerabilidade no ChatGPT Workspace Agents permitia criar e implantar um agente de inteligência artificial malicioso dentro de uma empresa a partir de um único link de phishing. Batizada de AgentForger, a falha foi corrigida pela OpenAI em 8 de junho de 2026. O ataque explor…