DESTAQUES

Ameaças Cibernéticas

1629 notícias
Ameaças Cibernéticas The Hacker News 🇺🇸

Public Exploit Released for Patched vBulletin Pre-Auth Code Execution Flaw

Public exploit details released on July 27 show how an unauthenticated request can reach PHP's eval() function inside vBulletin and execute code on an unpatched forum server. The attack requires no account, administrative access, or interaction from another user. SSD Secure Disc…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Versão atual do FastJson traz falha com CVSS 9.0

Uma vulnerabilidade crítica de RCE (execução remota de código) foi descoberta na biblioteca de serialização JSON FastJson versão 1.2.83, mantida pelo AliBaba — até agora considerada a versão segura e recomendada para uso. A falha está sendo explorada no ambiente do Spring Boot, e…

Ameaças Cibernéticas The Hacker News 🇺🇸

Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update

Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools. "The victim was directed through compromised web infrastructure to a counterfeit Microsoft S…

Ameaças Cibernéticas HIPAA Clicks 🇺🇸

MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals

MCBS, LLC, an Augusta, Georgia-based healthcare management and revenue cycle management company, has announced a major data incident involving the […] The post MCBS Announces Cybersecurity Incident Impacting 1.26M Individuals appeared first on The HIPAA Journal.

Ameaças Cibernéticas Boletim Sec 🇧🇷

Falhas críticas ameaçam ambientes remotos de desenvolvimento da JetBrains

A JetBrains corrigiu vulnerabilidades críticas no IntelliJ IDEA e no TeamCity que poderiam permitir execução de código, alteração de pipelines e acesso indevido a arquivos. As atualizações devem ser aplicadas com prioridade em ambientes de desenvolvimento compartilhados. No Intel…

Ameaças Cibernéticas Boletim Sec 🇧🇷

Cl0p explora falha no Windchill para roubar projetos industriais

O grupo de extorsão Cl0p está explorando servidores PTC Windchill e FlexPLM expostos à internet para roubar projetos, especificações técnicas e outros dados confidenciais. A campanha mira especialmente organizações dos setores industrial, automotivo, aeroespacial, de defesa e var…

Ameaças Cibernéticas The Hacker News 🇺🇸

Cruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows Malware

The China-linked cybercrime group behind the use of income tax-related phishing lures targeting Indian taxpayers, tax professionals, and corporate finance teams has been observed using a sophisticated crypter service called Cruciferra. According to a new analysis by Proofpoint, …

Ameaças Cibernéticas The Hacker News 🇺🇸

TELESHIM Abuses Telegram for C2 in Attacks Against Middle East Governments

Cybersecurity researchers have flagged fresh malicious cyber activity by a threat actor with ties to East Asia targeting government entities in the Middle East. The intrusions have resulted in the deployment of previously unreported malware families dubbed TELESHIM, MIXEDKEY, an…

Ameaças Cibernéticas CISO Advisor 🇧🇷

SolarWinds corrige 15 vulnerabilidades críticas

A SolarWinds publicou a versão 2026.3 de seu software de transferência gerenciada de arquivos (MFT) Serv-U, corrigindo um conjunto de 15 vulnerabilidades que, em sua maioria, receberam classificação crítica (CVSS 9.1). O pacote de correções aborda falhas que podem permitir desde …

Ameaças Cibernéticas The Hacker News 🇺🇸

Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process. Tracke…

Link copiado!