DESTAQUES

Ameaças Cibernéticas

1625 notícias
Ameaças Cibernéticas CISO Advisor 🇧🇷

Pacote malicioso do Jscrambler no npm

A Jscrambler, empresa de segurança para aplicações web, publicou um alerta no sábado informando que um invasor comprometeu suas credenciais de publicação no npm e lançou versões maliciosas de seu pacote, utilizadas para infectar desenvolvedores com um malware que rouba credenciai…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Falha crítica no Zimbra permite execução de código

Uma vulnerabilidade crítica de Cross-Site Scripting (XSS) armazenado no Zimbra Collaboration Suite pode permitir a execução de código malicioso sem qualquer interação do usuário, bastando abrir um e-mail especialmente crafted. A falha, que afeta o Classic Web Client (Classic UI),…

Ameaças Cibernéticas The Hacker News 🇺🇸

CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks

Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on AppleScript droppers or Objective-C-based wrappers, CrashStealer i…

Ameaças Cibernéticas Bleeping Computer 🇺🇸

CISA warns of actively exploited RCE flaws in Joomla extensions

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning that attackers are exploiting vulnerabilities in the iCagenda and Balbooa Forms extensions for Joomla to achieve remote code execution through arbitrary file uploads. [...]

Ameaças Cibernéticas Bleeping Computer 🇺🇸

Breach at the Beach: Play the Ultimate Entra ID CTF

Learn how attackers abuse Entra ID through a free hands-on Capture the Flag. Varonis created the Breach at the Beach CTF to teach defenders how to investigate Entra ID attack techniques using realistic scenarios. [...]

Ameaças Cibernéticas The Hacker News 🇺🇸

Forg365 PhaaS Targets Microsoft 365 with Device Code and AitM Session Theft

A new phishing-as-a-service (PhaaS) operation called Forg365 is using a combination of device code phishing, adversary-in-the-middle (AitM) tactics, antibot evasion, artificial intelligence (AI)-assisted lure creation, and post-compromise mailbox operations targeting Microsoft 36…

Ameaças Cibernéticas Boletim Sec 🇧🇷

GhostCommit mostra risco de vazamento em ferramentas de desenvolvimento com IA

Um novo ataque chamado GhostCommit esconde instruções maliciosas dentro de imagens para enganar agentes de inteligência artificial usados na revisão e geração de código. A técnica pode levar ao vazamento de arquivos com senhas, chaves de API e credenciais de nuvem. O ataque foi d…

Ameaças Cibernéticas Bleeping Computer 🇺🇸

EU sanctions Russian GRU military hackers over cyberattacks

The European Union and the United Kingdom jointly sanctioned dozens of Russian individuals and entities and accused Russia of coordinating a network of hacking groups responsible for attacks across Europe. [...]

Ameaças Cibernéticas The Hacker News 🇺🇸

Attacker Uses Suspected AI-Generated PowerShell Script to Map Active Directory

Cybersecurity researchers have flagged an intrusion in which an unknown threat actor leveraged a vibe-coded PowerShell script for Active Directory (AD) enumeration. "The script looked for the Domain Controller (DC) and mapped users, computers, and domains, before creating a dire…

Link copiado!