DESTAQUES

Ameaças Cibernéticas

1626 notícias
Ameaças Cibernéticas The Hacker News 🇺🇸

SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines

Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue gems are listed below - git_credentia…

Ameaças Cibernéticas CISO Advisor 🇧🇷

wp2shell: falha crítica no núcleo do WordPress permite RCE

Pesquisadores da Searchlight Cyber identificaram uma vulnerabilidade de execução remota de código (RCE) sem autenticação no núcleo do WordPress, apelidada de “wp2shell”, que afeta as versões 6.9.0 a 6.9.4 e 7.0.0 a 7.0.1. De acordo com o comunicado publicado ontem, o ataque não r…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Comércio é o setor mais atacado por bots de IA

O setor de comércio tornou-se o principal alvo de ataques impulsionados por inteligência artificial, com quase metade de todo o tráfego (47,9%) registrado na rede global da Akamai em dezembro de 2025 sendo composto por bots de IA, conforme relatório “Securing the Agentic Storefro…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Ransomware ‘The Gentlemen’ lidera no 2T de 2026

O grupo de ransomware The Gentlemen assumiu a primeira posição em número de vítimas no segundo trimestre de 2026, com 300 organizações listadas em seu site de vazamentos, superando o Qilin (289 vítimas), que liderava há quatro trimestres consecutivos, conforme relatório da ReliaQ…

Ameaças Cibernéticas The Hacker News 🇺🇸

UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware

Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealing malware. According to the Computer Emergency Response Team of Ukraine (CERT-UA), the activity has be…

Ameaças Cibernéticas The Hacker News 🇺🇸

SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access

A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days prior their public disclosure since June 22, 2026. Cybersecurity company Volexity is tracking the act…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Falha HollowByte permite DDoS em servidores OpenSSL

Pesquisadores da Okta identificaram uma vulnerabilidade, denominada HollowByte, que permite que atacantes não autenticados provoquem uma condição de negação de serviço (DoS) em servidores OpenSSL com um payload malicioso de apenas 11 bytes. A equipe do OpenSSL corrigiu silenciosa…

Ameaças Cibernéticas The Hacker News 🇺🇸

Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT

Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, marks an expansion of ChainVeil, which w…

Link copiado!