DESTAQUES

Ameaças Cibernéticas

1624 notícias
Ameaças Cibernéticas HIPAA Clicks 🇺🇸

AdaptHealth Reports Material Cybersecurity Incident and Theft of Patient Data

AdaptHealth, a publicly traded healthcare company that provides home medical equipment, diabetes supplies, and sleep therapy products, has informed the […] The post AdaptHealth Reports Material Cybersecurity Incident and Theft of Patient Data appeared first on The HIPAA Journal.

Ameaças Cibernéticas The Hacker News 🇺🇸

European Parliament Member Investigating Spyware Was Hacked With Pegasus

A new report from the Citizen Lab has revealed that former Member of the European Parliament Stelios Kouloglou had his mobile device repeatedly hacked with the notorious Pegasus spyware while serving on a committee that was tasked with investigating the abuse of such commercial s…

Ameaças Cibernéticas Boletim Sec 🇧🇷

CISA alerta para falha explorada no Microsoft SharePoint Server

A CISA alertou que uma vulnerabilidade no Microsoft SharePoint Server está sendo explorada em ataques reais. A falha, identificada como CVE-2026-45659, permite execução remota de código em servidores locais da plataforma. O problema afeta implantações on-premises do SharePoint Se…

Ameaças Cibernéticas The Hacker News 🇺🇸

PamStealer Uses Fake Maccy Sites and PAM Checks to Steal Mac Login Passwords

Cybersecurity researchers have flagged a new macOS information stealer called PamStealer that employs a series of clever tricks to infect systems and siphon sensitive data. The stealer, discovered by Jamf Threat Labs, is distributed as a compiled AppleScript (.scpt) file imperso…

Ameaças Cibernéticas CISO Advisor 🇧🇷

CISA alerta para exploração ativa no SharePoint

A agência de cibersegurança dos Estados Unidos, CISA, alertou ontem que atacantes começaram a explorar uma vulnerabilidade crítica de execução remota de código no Microsoft SharePoint, registrada como CVE-2026-45659. A falha, que permite que atacantes autenticados com privilégios…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Cisco confirma exploração ativa de falha no Unified CM

A Cisco confirmou ontem que atacantes estão explorando ativamente uma vulnerabilidade no Unified Communications Manager (Unified CM), sistema central de telefonia IP da empresa. A falha, registrada como CVE-2026-20230, havia sido corrigida no início de junho, mas a empresa só ago…

Ameaças Cibernéticas CISO Advisor 🇧🇷

FortiBleed alimenta ataques de ransomware, diz a SOCRadar

A campanha FortiBleed, que comprometeu mais de 430 mil firewalls FortiGate em todo o mundo, está diretamente ligada a operações de ransomware das famílias INC Ransom e Lynx, de acordo com uma análise publicada pela SOCRadar em 1º de julho. A descoberta, feita pela unidade de pesq…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Falha no Citrix NetScaler é explorada um dia após divulgação

Uma vulnerabilidade crítica no Citrix NetScaler ADC e Gateway, registrada como CVE-2026-8451 e classificada com CVSS 8.8, está sendo ativamente explorada em ataques desde o dia seguinte à sua divulgação pública, de acordo com uma análise publicada pela Lupovis em 1º de julho. O p…

Ameaças Cibernéticas The Hacker News 🇺🇸

Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials

Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access. "Although tactics differ between affiliates, common patterns emerged in tradecraft through use of legitimate Rem…

Ameaças Cibernéticas The Hacker News 🇺🇸

ToddyCat-Linked Umbrij Malware Abuses OAuth to Access Gmail via Google API

The threat actor known as ToddyCat has been attributed to a new malware called Umbrij that's designed to gain surreptitious access to a victim's email correspondence via the Google API. "In this campaign, the attackers focused their attention on corporate email communications ho…

Ameaças Cibernéticas Boletim Sec 🇧🇷

Ransomware usa drivers assinados para burlar proteções no Windows

Cibercriminosos estão usando drivers legítimos do Windows para desativar antivírus e ferramentas de detecção em ataques contra empresas. A técnica é conhecida como BYOVD, sigla em inglês para “traga seu próprio driver vulnerável”. O método se aproveita de drivers reais, assinados…

Link copiado!