DESTAQUES

Ameaças Cibernéticas

1629 notícias
Ameaças Cibernéticas The Hacker News 🇺🇸

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families …

Ameaças Cibernéticas The Hacker News 🇺🇸

NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version before 4.14.0 is affec…

Ameaças Cibernéticas The Hacker News 🇺🇸

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBlo…

Ameaças Cibernéticas The Hacker News 🇺🇸

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks…

Ameaças Cibernéticas Bleeping Computer 🇺🇸

New Dolphin X malware uses AI to rank high-value targets

A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first. [...]

Ameaças Cibernéticas CISO Advisor 🇧🇷

Grupo Cl0p explora falhas no PTC Windchill

A Ransom-ISAC, em colaboração com eCrime.ch e DEFUSED, publicou ontem um alerta sobre a exploração ativa, por afiliados do ransomware Cl0p, de vulnerabilidades em implementações do PTC Windchill e FlexPLM expostas à internet. Os atacantes estão encadeando uma divulgação de inform…

Ameaças Cibernéticas The Hacker News 🇺🇸

Russian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA Codes

A Russian state-supported espionage group spent months reading Western mailboxes through a then-unknown flaw in Zimbra's webmail client. The payload goes after the last 90 days of email, the organization's entire email directory, the password saved in the browser and the codes k…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Campanha usa GitHub Actions para explorar cPanel 

Uma campanha cibernética em larga escala está abusando do GitHub Actions para transformar repositórios open source comprometidos em armas contra servidores de hospedagem, conforme revelou ontem a empresa de segurança Socket.dev. Os atacantes inserem arquivos de workflow malicioso…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Benchmark de malware para sabotagem nuclear desafia modelos de IA

A SentinelOne desenvolveu um novo benchmark para testar a capacidade de modelos de inteligência artificial realizarem investigações de engenharia reversa de longo prazo, utilizando como caso de teste a análise do malware Fast16, descoberto em abril pelo SentinelLabs. O estudo, pu…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Check Point corrige falha zero-day no SmartConsole

A Check Point Software publicou ontem uma correção para uma vulnerabilidade zero-day ativamente explorada no painel administrativo SmartConsole, rastreada como CVE-2026-16232. A falha de bypass de autenticação permite que atacantes não autenticados obtenham um token de login da a…

Ameaças Cibernéticas Bleeping Computer 🇺🇸

Russian hackers exploit Zimbra zero-click flaw for email theft

CISA is warning that the Russian state-sponsored hacking group Laundry Bear, also known as Void Blizzard, is targeting organizations using Zimbra Collaboration email servers by combining phishing attacks with the exploitation of a now-patched Zimbra vulnerability. [...]

Ameaças Cibernéticas CISO Advisor 🇧🇷

Falha crítica no kernel Linux permite escalonamento de privilégios via XFS

Pesquisadores da Qualys Threat Research Unit (TRU) identificaram uma vulnerabilidade de escalonamento local de privilégios no kernel Linux, rastreada como CVE-2026-64600 e apelidada de RefluXFS. A falha, presente desde a versão 4.11 do kernel (2017), afeta sistemas que utilizam o…

Link copiado!