Visualização normal

Antes de ontemStream principal

“I’m Allowed”: Hackers Use Simple Claims to Bypass AI Guardrails

Cisco Talos found hackers using simple authorization claims to bypass AI guardrails, build DDoS attack tools, steal credentials and access live camera services.

Brazil Health Surveillance Database Exposed 79GB of Sensitive Records

Brazil's SISVISA health surveillance system left 102,215 files totaling 79GB open online, including tax IDs and identity documents, without password protection.

Shai-Hulud npm Worm Returns, Poisoning Over 1,280 npm Packages

Shai-Hulud npm worm spreads through Keyv and hundreds of packages with 2 billion monthly downloads, stealing npm, GitHub, cloud and CI credentials in real time.

Thermo Fisher Patches Forensic DNA File Tampering Flaw in Its Software

Thermo Fisher patched CVE-2026-17583 in five supported DNA analysis products by adding digital signatures that help laboratories detect modified forensic files.

Hackers Use Fake FIFA World Cup 2026 T-Shirt Offers to Spread Voidrift Malware

A fake FIFA World Cup 2026 T-shirt giveaway scam is spreading Voidrift malware through personalized emails using company logos and trusted websites to bypass security filters.

Bluekit Phishing Kit Uses Browser-in-the-Middle Attacks to Evade Detection

A new phishing-as-a-service (PHaaS) platform called Bluekit is letting cybercriminals steal user accounts using a tricky method. While…

Anonymous-Linked Hacktivist Aubrey Cottle Jailed Over Texas GOP Cyberattack

Canadian hacktivist Aubrey Cottle, known as Kirtaner and once linked to Anonymous, gets 18 months for a 2021 Texas GOP website cyberattack.

Woodgnat Hackers Use Mistic RAT to Broker Access for Ransomware Gangs

Woodgnat Hackers use Backdoor.Mistic, a stealthy RAT, to let brokers compromise networks and sell entry points to ransomware groups, putting firms at risk.

macOS Flaw Allowed Standard Users to Disable CrowdStrike and Kandji Security Tools

A macOS XPC flaw let regular users disable CrowdStrike and Kandji tools, exposing security gaps that vendors patched after XM Cyber reported the security issue.

Fake GTA 6 Early Access Websites Target Gamers with Malware and Crypto Scams

GTA 6 scams are luring fans with fake early access, crypto payments and malware downloads. Learn why PC and Android gamers face the biggest risks online today.

Suspected Cyberattack Sends Fake Emergency Alert to Phones Across Brazil

Brazil’s alert system was taken offline after a fake emergency alert reached phones, with officials investigating a suspected cyberattack and security failure.

New GhostShell Hacking Group Targets Ukraine’s Drone Defense Sector

Researchers warn GhostShell is using fake drone documents to target Ukrainian defence teams, stealing passwords and sensitive data in a new cyber campaign.

Fake npm Packages Impersonate PostCSS Tool to Steal Chrome Passwords

JFrog warns of malicious npm packages that mimic PostCSS tooling, drop a Windows RAT, and target Chrome-stored passwords through a staged infection setup route.

‘Cordyceps’ CI/CD Flaw Exposes Microsoft, Google, Apache Repos to Pipeline Hijacking

Novee Security reveals Cordyceps, a CI/CD vulnerability in GitHub Actions workflows that let anonymous users poison builds and expose tokens across major projects today.

New CryptoBandits Malware Uses USB Drives and Tor to Steal Crypto

Microsoft researchers warn of a new dual-action cryptocurrency clipper (CryptoBandits Malware) spreading through USB devices to alter wallet addresses and steal crypto assets.

2 Scattered Spider-Linked Hackers Plead Guilty Over £39M TfL Cyberattack

Two teenagers face sentencing after admitting to a massive Scattered Spider cyberattack that hit Transport for London (TfL) and US healthcare networks.

Beats Studio Buds Flaw Could Let Nearby Attackers Eavesdrop on Users

Apple has released a security update to patch a Beats Studio Buds flaw that let nearby hackers listen to conversations through the microphone.

Texas Parks and Wildlife Data Breach Affects Over 3M License Customers

Around 3 million Texas licence holders face a data breach after hackers targeted a third-party vendor, exposing driver's licences and passport numbers.

Scammers Use Fake GitHub Stars, VirusTotal Reviews to Spread Crypto Clipper

A multi-platform malware campaign abuses fake trust signals to infect Windows and Mac users with a crypto clipper packed with 15,500 attacker wallets.

Salesforce Disables Klue Integration After OAuth Token Theft Hits Customer Data

Icarus extortion group used a legacy Klue Battlecards credential to bypass security and steal bulk Salesforce records from affected companies.
❌
❌