Interpol's Jackal IV Disrupts West African Crime Infrastructure
The international law enforcement operation focused on disrupting crime-as-a-service networks and supporting infrastructure behind groups like Black Axe.
The international law enforcement operation focused on disrupting crime-as-a-service networks and supporting infrastructure behind groups like Black Axe.
The West African nation launched financing, procurement, and infrastructure policies to boost its sovereign cloud initiative and increase domestic technical knowledge.
An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects. "The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by…
An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a specifically crafted network packet reaches the machine and then runs commands written in a 23-instruction language of its own design.…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code executi…
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threa…
Um grande ataque distribuído de negação de serviço (DDoS) interrompe, desde ontem, a infraestrutura digital compartilhada do governo da Noruega, afetando serviços utilizados pelo setor público, informou a Agência de Digitalização Norueguesa (Digdir). O ataque começou às 3h38 (hor…
O uso não autorizado de aplicações de inteligência artificial, fenômeno conhecido como “Shadow AI”, comprometeu diretamente a postura de segurança de 51% das organizações nos últimos 12 meses, segundo pesquisa da KnowBe4 divulgada hoje. O estudo, que ouviu líderes de segurança, t…
O mais recente relatório da Agência de Segurança Cibernética e Infraestrutura dos EUA (CISA), intitulado “A Tale of Two SOCs“, revela que sistemas de segurança podem falhar mesmo com amplo financiamento, caso não haja analistas treinados para responder aos alertas de forma eficaz…
A fabricante de equipamentos de rede DrayTek publicou correções para onze vulnerabilidades em modelos VigorAP e trinta falhas em VigorSwitches, incluindo três vulnerabilidades críticas que permitem execução remota de comandos com privilégios de root e modificação não autorizada d…
A vulnerabilidade CVE-2026-21962 (CVSS de 10,0), que afeta o Oracle HTTP Server e o plug-in de proxy do Oracle WebLogic Server, está sendo explorada ativamente por agentes maliciosos. A falha foi publicada pela Oracle em 20 de janeiro com atualizações de segurança e a empresa ped…
The Los Angeles County Museum of Art (LACMA) has announced that a breach last year exposed customer and employee information. [...]
O grande desafio atual das lideranças é diferenciar as iniciativas de inteligência artificial que geram ganhos de produtividade e receita daquelas que apenas criam a percepção de inovação, segundo Gustavo Caetano, CEO e fundador da Sambatech. Mais do que adotar novas ferramentas,…
A adoção da inteligência artificial pelas empresas avança mais rápido que a governança, e esse desalinhamento tende a se tornar um dos principais desafios de segurança da próxima década. O problema, porém, é solucionável com uma abordagem de confiança zero aplicada a todo o ciclo…
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. [...]
With some simple HTML that's invisible to users, attackers can manipulate AI-powered email summarizers into producing malicious information.
A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. [...]
Abbott plans to roll out the device, called Libre Duo 10 Day, later this year. The sensor can measure both glucose and ketones.
Attackers can exploit a security bug in NVIDIA's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption.
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial co…