Russian APT 'Gamaredon' Upgrades Its Arsenal, Requiring New Defenses
The FSB state-sponsored operation has gotten a lot better at loading its malware and hiding its servers.
The FSB state-sponsored operation has gotten a lot better at loading its malware and hiding its servers.
Pesquisadores da Gen, empresa responsável pela Avast, detectaram 7,4 milhões de incidentes maliciosos desde o início de 2026 roteados por redes de proxy residencial, afetando 572 mil usuários em todo o mundo. O Brasil figura como o terceiro país mais impactado, com 39 mil consumi…
A Mandiant, empresa de inteligência em ameaças do Google Cloud, documentou um ataque que utilizou uma vulnerabilidade zero-day no Cisco Catalyst SD-WAN Manager para escalonar privilégios de uma conta administrativa comprometida para acesso root. O caso, detalhado hoje no blog do …
Educational institutions, the edtech companies they rely on, and, more concerningly, the challenges they pose for schools are the focus of the latest Reporters' Notebook video series.
Os desenvolvedores do cURL informaram à comunidade de TI ter corrigido um número recorde de vulnerabilidades no software, em sua versão mais recente , incluindo uma falha de segurança com 25 anos de existência. O anúncio foi feito por Daniel Stenberg, um dos mantenedores do cURL.…
A GitLab lançou atualizações de segurança para as edições Community (CE) e Enterprise (EE) que resolvem 13 vulnerabilidades, incluindo três falhas de alta gravidade que poderiam permitir execução de código arbitrário e divulgação de informações sensíveis. A empresa recomenda que …
Threat actors are increasingly abusing Shop, the order-tracking app from Shopify, by adding fake purchase receipts in users' order histories to trick them into providing sensitive data or installing remote access software. [...]
With tens of billions of dollars flowing into regional economies from cybercrime, scam centers continue to flourish, despite international and law-enforcement efforts.
A Elytron Cybersecurity, empresa especializada em serviços ofensivos e defensivos de segurança da informação, alerta para a elevação dos riscos cibernéticos durante períodos de grande mobilização social, como a Copa do Mundo, quando cresce a incidência de golpes que exploram o co…
GTA 6 scams are luring fans with fake early access, crypto payments and malware downloads. Learn why PC and Android gamers face the biggest risks online today.
A newly discovered macOS malware dubbed "Gaslight" is designed to confuse AI-assisted malware analysis tools by hiding prompt injection strings and fake debugging data within the executable. [...]
The Bluekit phishing-as-a-service platform continues to evolve with nearly 70 new hostnames identified over the past week and by adding browser-in-the-middle capabilities for improved data theft. [...]
An analysis of a popular Google Chrome ad block extension for YouTube has uncovered the ability to execute arbitrary JavaScript code. According to Island, the extension, named Adblock for YouTube (ID: cmedhionkhpnakcndndgjdbohmhepckk), has more than 10 million installs and carri…
It’s dumb out there again. This week has the usual smell of prod on fire and nobody wanting to admit who left the door open — old creds still working, trusted apps doing sketchy crap, browser tricks jumping the fence, and “normal” workflows turning into phishing pipes because ap…
Account takeover attacks continue to challenge security teams because attackers often operate through legitimate accounts and trusted services. This webinar explores how behavioral AI can help organizations identify compromised accounts faster and automate response workflows. [..…
Brazil’s alert system was taken offline after a fake emergency alert reached phones, with officials investigating a suspected cyberattack and security failure.
After a global lull, ransomware gangs are setting sights on a rich new arena: attacking EU organizations and their suppliers.
A previously undocumented Rust-based macOS implant and information stealer has been found to embed a prompt injection payload designed to trick a malware analyst's artificial intelligence (AI) tools and trick it into aborting or refusing an analysis of the artifact. The malware …
A new, stealthy backdoor named Mistic has been deployed as part of suspected financially motivated attacks aimed at multiple organizations spanning insurance, education, IT, and professional services sectors since April 2026. According to Symantec and Carbon Black's Threat Hunte…
British Scattered Spider Hacker Pleads Guilty to Cyberattacks on TfL; SSM Health Care; Sutter Health The HIPAA Journal