DESTAQUES

Últimas Notícias

3476 notícias
Ameaças Cibernéticas Boletim Sec 🇧🇷

Falha de autenticação em VPN da Palo Alto é usada em ataques de ransomware

Operadores ligados ao ransomware Qilin exploraram uma falha no PAN-OS para invadir redes corporativas e criptografar sistemas. Os ataques observados em junho de 2026 começaram pelo serviço de VPN GlobalProtect, instalado em firewalls da Palo Alto Networks. Identificada como CVE-2…

Ameaças Cibernéticas Bleeping Computer 🇺🇸

CISA orders urgent action on actively exploited Langflow RCE flaw

The Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday ordered U.S. government agencies to prioritize patching an actively exploited vulnerability in the Langflow visual framework for building AI agents. [...]

Ameaças Cibernéticas Boletim Sec 🇧🇷

Cibercriminosos exploram vulnerabilidade crítica em instalações do SharePoint

Uma vulnerabilidade crítica no Microsoft SharePoint Server foi explorada em ataques para executar código remotamente sem autenticação. Registrada como CVE-2025-53770, a falha recebeu pontuação CVSS de 9,8 e afeta instalações locais da plataforma. O problema envolve a desserializa…

Gestão de Riscos The Hacker News 🇺🇸

Why Modern SOCs Need Multi-Layered Detections

The cycle is over. For years, cybersecurity followed a familiar pattern: defenses improved, attackers adapted, and the back-and-forth continued. Today, AI-equipped attackers are simply outpacing defenses. Most intrusions now bypass endpoint and malware-based detection entirely. …

Privacidade & Dados Bleeping Computer 🇺🇸

Stop renting storage space — this lifetime 2TB plan is yours for $59

Cloud storage costs tend to creep up over time, since most services charge monthly or annually for as long as you use them. FileJump's Lifetime Plan skips that model entirely, offering 2TB of cloud storage for a single payment of $59 (MSRP $467). [...]

Ameaças Cibernéticas Boletim Sec 🇧🇷

Agentes de IA recomendam repositórios maliciosos para distribuir malware

Uma campanha chamada AgentBaiting está usando falsas extensões de inteligência artificial para induzir agentes e desenvolvedores a instalar malware. A operação FakeGit reúne cerca de 7.600 repositórios maliciosos no GitHub, dos quais mais de 800 se apresentam como Skills ou servi…

Ameaças Cibernéticas The Hacker News 🇺🇸

Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library

Cybersecurity researchers have discovered a NuGet typosquat that's unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it's designed to rig live game results on Digitain. The package, named "Newtonsoftt.Json.Net," masquerades …

Ameaças Cibernéticas Bleeping Computer 🇺🇸

OpenAI says its AI models hacked Hugging Face during testing

OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. [...]

Ameaças Cibernéticas The Hacker News 🇺🇸

Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents

A single invisible comment in an Azure DevOps pull request can turn a reviewer's own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft's official Azure DevOps MCP server, and it …

Link copiado!