DESTAQUES

Ameaças Cibernéticas

1626 notícias
Ameaças Cibernéticas HIPAA Clicks 🇺🇸

Major Healthcare Software Vendor Investigating Cyberattack

The healthcare technology company Craneware is investigating a cybersecurity incident and has confirmed that a significant amount of data was […] The post Major Healthcare Software Vendor Investigating Cyberattack appeared first on The HIPAA Journal.

Ameaças Cibernéticas The Hacker News 🇺🇸

AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code

Hidden text on a web page was enough to make Kiro, AWS's agentic coding IDE, rewrite its own configuration file and run an attacker's code on a developer's machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary …

Ameaças Cibernéticas CISO Advisor 🇧🇷

Grupo Qilin explora falha crítica em VPN da Palo Alto

O grupo de ransomware Qilin está explorando ativamente uma falha crítica de autenticação no GlobalProtect VPN, da Palo Alto Networks, para invadir redes corporativas e implantar criptografia em todo o domínio, conforme revelou ontem a empresa de cibersegurança Arctic Wolf. A vuln…

Ameaças Cibernéticas The Hacker News 🇺🇸

Zimbra Patches Critical SNMP Command Injection and Four XSS Vulnerabilities

Zimbra has rolled out fixes to address multiple critical security issues, including a command injection flaw in the Simple Network Management Protocol (SNMP) monitoring component. As many as nine security vulnerabilities have been patched in Zimbra 10.1.20. Topping the list is a…

Ameaças Cibernéticas Boletim Sec 🇧🇷

Malware usa calendários do Microsoft 365 para ocultar arquivos roubados

Um novo malware de espionagem chamado HollowGraph transforma calendários comprometidos do Microsoft 365 em canais ocultos para receber comandos e retirar arquivos roubados. A ameaça usa eventos marcados para 13 de maio de 2050, uma data distante que reduz a chance de descoberta p…

Ameaças Cibernéticas Boletim Sec 🇧🇷

Falha crítica wp2shell permite controle remoto de sites WordPress

O WordPress lançou atualizações emergenciais para corrigir a wp2shell, uma cadeia crítica de vulnerabilidades que permite a execução remota de código sem autenticação. O ataque pode comprometer instalações padrão, mesmo sem plugins vulneráveis ou interação do administrador. A ame…

Ameaças Cibernéticas The Hacker News 🇺🇸

WordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass Scanning

Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable websites. The two security flaws, tracked as CVE-2026-63030 and CVE-2026-60137, have b…

Ameaças Cibernéticas The Hacker News 🇺🇸

New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack

Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go ransomware designed to encrypt model wei…

Link copiado!