Translucid Security

Inteligência de Ameaças

  • Painel
  • Notícias
  • CVEs
  • Exploits
  • Ransomware
  • OT / ICS
Translucid Security
ENPT-BR

Notícias de segurança · Avisos de fabricantes· 1 de 26 fontes com falhaBleepingComputer: erro

Notícias de cibersegurança

Atualizando resultados…
Categoria
Classificação
Buscar notícias
Ordenação
GeralUrgenteCrítica

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that connects a GitLab instance to AI models, and only organizations that…

há 22 minThe Hacker News
MalwareBaixa

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India, the Philippines, Cambodia, Pakistan, Thailand, and Myanmar,…

há 22 minThe Hacker News
VulnerabilidadeUrgenteCrítica

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are listed below - CVE-2026-63688 (CVSS score: 10.0) - A missing aut…

há 54 minThe Hacker News
VulnerabilidadeUrgenteCrítica

Kiteworks & Citrix Incidents Show Challenges of Zero-Day Response

One company told customers to power down its data-protection platform during a nine-hour window, while the other remained mum on reported attacks prior to releasing a patch for its product.

há 59 minDark Reading
VulnerabilidadeBaixa

SWIFT Banking & Government Middleware Enables RCE

Patch middleware vulnerabilities now to avoid hardware-based MFA exploits in ultra-sensitive environments.

há 1 hDark Reading
GeralBaixa

Is Your Organization Ready for 2027's AI Accountability Era?

Organizations may face an artificial intelligence (AI) reckoning over the next year. Omdia and Gartner weigh in on how to tackle the governance, security, and value challenges ahead.

há 1 hDark Reading
GeralBaixa

Is It Fair to Blame 'Rogue' AI for Security Failures?

"Rogue AI" terminology anthropomorphizes LLMs and shifts risk responsibility from vendors. Defenders should treat agents as untrusted, nondeterministic software systems, not sentient beings with malicious intent.

há 2 hDark Reading
VazamentoBaixa

US sanctions Tren de Aragua gang members in ATM hacks crackdown

The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. [...]

há 2 hBleepingComputer
VulnerabilidadeBaixa

In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies on AI Chats

Noteworthy stories that might have slipped under the radar: Kiteworks patches over 100 vulnerabilities, Microsoft publishes 2026 Digital Defense Report, AI finds 24 Android app flaws. The post In Other News: $15K iCloud Spoofing Bugs, AI Policy Experts Phished, Adblocker Spies o…

há 3 hSecurityWeek
VazamentoBaixa

Microsoft: AI Cuts Post-Compromise Attack Time to Minutes

Microsoft has warned that threat actors have gained the advantage over defenders by using AI to enhance the speed and scale of attacks

há 3 hInfosecurity Magazine
GeralBaixa

The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and why browser-level controls can help close the gap. [...]

há 3 hBleepingComputer
VulnerabilidadeBaixa

Vulnerability Backlogs Are an Ownership Problem

Organizations don't need better vulnerability scanners; they need to know who owns their assets and has the authority and capacity to actually fix them.

há 3 hDark Reading
MalwareBaixa

macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor

The dropper “carries a complete universal Mach-O inside itself, roughly 756 KB in the development build, and extracts it at runtime. The post macOS Users Targeted by Fake Zoom Installer Carrying CloudSyncD Backdoor appeared first on SecurityWeek .

há 4 hSecurityWeek
MalwareBaixa

Malicious Linux Implants Mimic Asian Mail Security Products

A trio of newly discovered backdoors walk and quack like legitimate edge solutions, so it's hard to tell they're not.

há 4 hDark Reading
VulnerabilidadeBaixa

Dell asks admins to patch max severity CSM flaws as soon as possible

Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. [...]

há 5 hBleepingComputer
VazamentoBaixa

OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for violating our policies on accessing and handling sensitive compa…

há 5 hThe Hacker News
VazamentoBaixa

Crypto Scammers Hijack Microsoft’s Official X Account

Hackers used the account, which has 13 million followers, to amplify a Clippy-themed cryptocurrency account. The post Crypto Scammers Hijack Microsoft’s Official X Account appeared first on SecurityWeek .

há 6 hSecurityWeek
VulnerabilidadeAlta

Kritisk sårbarhet i FortiMail

Fortinet har publicerat information om en kritisk sårbarhet i FortiMail. Sårbarheten, CVE-2026-104286, har fått en CVSS-klassning på 9.8 och påverkar FortiMail managements gränssnitt. Ett framgångsrikt utnyttjande kan innebära att en oautentiserad angripare kan skriva godtycklig…

há 6 hCERT-SE
VulnerabilidadeBaixa

Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report

The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that sprea…

há 6 hThe Hacker News
VazamentoBaixa

In Rare Move, Alleged Iranian State Hacker Extradited to US

Amir Barati, an alleged member of the Mabna Institute, was indicted for targeting universities, private organizations, and government entities in the US and abroad. The post In Rare Move, Alleged Iranian State Hacker Extradited to US appeared first on SecurityWeek .

há 6 hSecurityWeek
GeralBaixa

Antar du vår utmaning? / Do you accept our challenge?

CERT-SE presenterar vår årliga utmaning (CTF) som sker under cybersäkerhetsmånaden [1, 2]. Utmaningen vänder sig till alla med it-säkerhetsintresse oavsett kunskapsnivå.

há 7 hCERT-SE
VulnerabilidadeCrítica

Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks

The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025. The post Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks appeared first on SecurityWeek .

há 8 hSecurityWeek
VazamentoBaixa

Microsoft’s X account hacked in crypto pump-and-dump scheme

On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. [...]

há 8 hBleepingComputer
MalwareAlta

Police Target KillSec Ransomware Group with Arrests and Seizures

Investigators have disrupted the operations of ransomware group KillSec and arrested several key suspects

há 8 hInfosecurity Magazine

Mostrando 24 de 523 notícias