DESTAQUES

Ameaças Cibernéticas

1624 notícias
Ameaças Cibernéticas The Hacker News 🇺🇸

Progress Kemp LoadMaster Flaw Could Let Attackers Run Root Commands Pre-Auth

A critical vulnerability in Progress Kemp LoadMaster can let an unauthenticated attacker execute arbitrary commands as root on the appliance by sending a crafted request to its API. The flaw, tracked as CVE-2026-8037, carries a CVSS score of 9.8 according to ZDI. A patch is avai…

Ameaças Cibernéticas The Hacker News 🇺🇸

Oracle E-Business Suite Flaw CVE-2026-46817 Actively Exploited in the Wild

A critical security flaw impacting Oracle E-Business Suite has come under active exploitation in the wild, according to Defused Cyber. The vulnerability, tracked as CVE-2026-46817 (CVSS score: 9.8), refers to an improper privilege management and authentication flaw in Oracle Pay…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Ataque de código Claude sequestra máquinas de devs

Pesquisadores da 0din.ai demonstraram um ataque que explora agentes de codificação baseados em IA, como o Claude Code, para obter acesso remoto a máquinas de desenvolvedores, utilizando um repositório aparentemente inofensivo. O estudo de caso, publicado no dia 25 de junho, mostr…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Ataque à Jaguar Land Rover usou ransomware avançado

O ataque à Jaguar Land Rover (JLR) em setembro do ano passado, que paralisou a produção por semanas e gerou prejuízos de 550 milhões de euros para a montadora, foi uma operação de ransomware avançado que explorou vulnerabilidades em sistemas legados, de acordo com reportagem do T…

Ameaças Cibernéticas CISO Advisor 🇧🇷

Falha no Oracle E-Business Suite explorada em ataques

A Defused, empresa de cibersegurança, identificou exploração ativa de uma vulnerabilidade crítica no Oracle E-Business Suite, conforme publicação do site Security.nl no dia 29 de junho. A falha, registrada como CVE-2026-46817, afeta o componente Oracle Payments e permite que um a…

Ameaças Cibernéticas Dark Reading 🇺🇸

'Djinn' Stealer Targets Cloud, AI Credentials

The infostealer was delivered via CVE-2026-48558, a critical authentication bypass vulnerability in SimpleHelp, targeting credentials linking development and admin environments to wider enterprise systems.

Ameaças Cibernéticas Bleeping Computer 🇺🇸

NAIC says public data stolen in ShinyHunters' PeopleSoft breach

The National Association of Insurance Commissioners (NAIC) says the ShinyHunters extortion group stole only publicly available data, outdated logs, and configuration files after breaching its systems by exploiting a zero-day vulnerability in an Oracle PeopleSoft server. [...]

Ameaças Cibernéticas HIPAA Guide 🇺🇸

Hackers Target Remote Desktop Tools for Access to Healthcare Networks

The healthcare industry continues as the most attacked sector, and while cyberattacks have declined year over year, healthcare has seen the smallest decline out of all verticals, according to a new report from the cybersecurity firm SonicWall. According to its intrusion protectio…

Ameaças Cibernéticas Bleeping Computer 🇺🇸

Critical SimpleHelp flaw exploited to deploy new stealer malware

Hackers are exploiting a recently disclosed critical vulnerability (CVE-2026-48558) in SimpleHelp to deploy Djinn Stealer, a previously undocumented cross-platform information stealer targeting Windows, macOS, and Linux. [...]

Link copiado!