Infosec News

InfoSec News 20250911

  • Publicado: Qui, 11/09/2025 - 14:43

Top News


  • When typing becomes tracking: Study reveals widespread silent keystroke interception

"You type your email address into a website form but never hit submit. Hours later, a marketing email shows up in your inbox. According to new research, that is not a coincidence."

Link

TLP1 : Green

InfoSec News 20250908

  • Publicado: Seg, 08/09/2025 - 17:51

Top News


  • MostereRAT Targets Windows Users With Stealth Tactics

A phishing campaign delivering a new strain of malware, MostereRAT, has been uncovered by cybersecurity researchers. The Remote Access Trojan (RAT) targets Microsoft Windows systems and gives attackers complete control over compromised machines.

Link

TLP1 : Green

InfoSec News 20250905

  • Publicado: Sex, 05/09/2025 - 16:07

Top News


  • Critical SAP S/4HANA vulnerability now exploited in attacks

A critical SAP S/4HANA code injection vulnerability is being leveraged in attacks in the wild to breach exposed servers, researchers warn. The flaw, tracked as CVE-2025-42957, is an ABAP code injection problem in an RFC-exposed function module of SAP S/4HANA, allowing low-privileged authentication users to inject arbitrary code, bypass authorization, and fully take over SAP.

InfoSec News 20250904

  • Publicado: Qui, 04/09/2025 - 16:43

Top News


  • Cloudflare Mitigates Largest Ever Recorded DDoS Attack at 11.5 Tbps

Cloudflare has successfully mitigated the largest DDoS attack (or distributed denial-of-service attack) recorded to date. The attack peaked at 11.5 terabits per second and lasted roughly 35 seconds before being neutralised without disrupting services.

Link

TLP1 : Green

InfoSec News 20250903

  • Publicado: Qua, 03/09/2025 - 15:52

Top News


  • Cloudflare hit by data breach in Salesloft Drift supply chain attack

Cloudflare is the latest company impacted in a recent string of Salesloft Drift breaches, part of a supply-chain attack disclosed last week. The internet giant revealed on Tuesday that the attackers gained access to a Salesforce instance it uses for internal customer case management and customer support, which contained 104 Cloudflare API tokens.

InfoSec News 20250902

  • Publicado: Ter, 02/09/2025 - 16:32

Top News


  • Palo Alto Networks data breach exposes customer info, support cases

Palo Alto Networks suffered a data breach that exposed customer data and support cases after attackers abused compromised OAuth tokens from the Salesloft Drift breach to access its Salesforce instance. The company states that it was one of hundreds of companies affected by a supply-chain attack disclosed last week, in which threat actors abused the stolen authentication tokens to exfiltrate data.

InfoSec News 20250829

  • Publicado: Sex, 29/08/2025 - 13:38

Top News


  • ScamAgent shows how AI could power the next wave of scam calls

"Scam calls have long been a problem for consumers and enterprises, but a new study suggests they may soon get an upgrade. Instead of a human scammer on the other end of the line, future calls could be run entirely by AI."

Link

TLP1 : Green

InfoSec News 20250826

  • Publicado: Ter, 26/08/2025 - 15:59

Top News


  • National Public Data Relaunches Despite 2.9 Billion SSNs Breach

"It is business as usual at National Public Data (NPD) despite the breach that exposed 3 billion Social Security numbers and the subsequent leak."

Link

TLP1 : Green

InfoSec News 20250821

  • Publicado: Qui, 21/08/2025 - 14:43

Top News


  • AI website builder Lovable increasingly abused for malicious activity

"Cybercriminals are increasingly abusing the AI-powered Lovable website creation and hosting platform to generate phishing pages, malware-dropping portals, and various fraudulent websites."

Link

TLP1 : Green

InfoSec News 20250820

  • Publicado: Qua, 20/08/2025 - 14:05

Top News


  • Citizen Lab Reports Hidden VPN Networks Sharing Ownership and Security Flaws

"Citizen Lab’s new report, Hidden Links, uncovers a network of VPN providers like Turbo VPN and VPN Monster that are controlled by a single company and use dangerous security practices, including hard-coded passwords and weak encryption."

Link

TLP1 : Green

Páginas