Sign in

BolhaSec

@bolhasec.com
668 followers 144 following 6.5K posts

#bolhasec pra ser retweetado @sushicomabacate.com

PostsRepliesMedia
BolhaSec @bolhasec.com · 13/04/2026
Notícia da BleepingComputer "The silent “Storm”: New infostealer hijacks sessions, decrypts server-side" #bolhasec
bleepingcomputer.com
The silent “Storm”: New infostealer hijacks sessions, decrypts server-side
New "Storm" infostealer skips local decryption, sending browser data to attacker servers. Varonis shows how server-side decryption enables session hijacking, bypassing passwords and MFA.
001
BolhaSec @bolhasec.com · 13/04/2026
Notícia da BleepingComputer "Nearly 4,000 US industrial devices exposed to Iranian cyberattacks" #bolhasec
bleepingcomputer.com
Nearly 4,000 US industrial devices exposed to Iranian cyberattacks
The attack surface targeted by Iranian-linked hackers in cyberattacks against U.S. critical infrastructure networks includes thousands of Internet-exposed programmable logic controllers (PLCs) manufac...
001
BolhaSec @bolhasec.com · 13/04/2026
Notícia da BleepingComputer "Microsoft: Canadian employees targeted in payroll pirate attacks" #bolhasec
bleepingcomputer.com
Microsoft: Canadian employees targeted in payroll pirate attacks
A financially motivated threat actor tracked as Storm-2755 is stealing Canadian employees' salary payments after hijacking their accounts in payroll pirate attacks.
001
Reposted by BolhaSec
Vico @vicoo.bsky.social · 03/04/2026
Pessoal de Tech que quer fazer amizades e trocar uma ideia, entrem no meu grupo de amigos lá no Discord! Tô precisando bater um papo... discord.gg/7eeXcdeaPD #bolhasec #bolhadev
discord.gg
Join the Vico’s Manor Discord Server!
O grupo de amigos do Vico no Discord! | 23 members
022
Reposted by BolhaSec
CyberTaters @potato.software · 01/04/2026
🔗 ravenastar.com --- 💚 "A cor verde significa esperança, liberdade e renovação." --- PotatoSecurity Educator ・CTI・Digital Forensics Investigator ・DevSecOps・Blue Team・Segurança Digital・Psicologia・Ciência da Computação・OSINT ⫘ 🏷️ #potatosecurity #ravenastar #infosec #bolhasec #bolhatech
023
BolhaSec @bolhasec.com · 21/03/2026
Notícia da BleepingComputer "Alabama man pleads guilty to hacking, extorting hundreds of women" #bolhasec
bleepingcomputer.com
Alabama man pleads guilty to hacking, extorting hundreds of women
A 22-year-old Alabama man pleaded guilty to extortion, cyberstalking, and computer fraud charges after hijacking the social media accounts of hundreds of young women (including minors).
001
BolhaSec @bolhasec.com · 21/03/2026
Notícia da BleepingComputer "Amazon: Drone strikes damaged AWS data centers in Middle East" #bolhasec
bleepingcomputer.com
Amazon: Drone strikes damaged AWS data centers in Middle East
Amazon has confirmed that three Amazon Web Services (AWS) data centers in the United Arab Emirates (UAE) and one in Bahrain have been damaged by drone strikes, causing an extensive outage that is stil...
001
BolhaSec @bolhasec.com · 21/03/2026
Notícia da SecurityWeek "Quantum Decryption of RSA is Much Closer than Expected" #bolhasec
securityweek.com
Quantum Decryption of RSA Is Much Closer Than Expected
The JVG algorithm factors RSA and ECC keys using fewer quantum resources than Shor’s algorithm, accelerating the time needed to break today’s public-key cryptography.
001
BolhaSec @bolhasec.com · 21/03/2026
Notícia da BleepingComputer "CISA warns that RESURGE malware can be dormant on Ivanti devices" #bolhasec
bleepingcomputer.com
CISA warns that RESURGE malware can be dormant on Ivanti devices
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has released new details about RESURGE, a malicious implant used in zero-day attacks exploiting CVE-2025-0282 to breach Ivanti Connect ...
001
BolhaSec @bolhasec.com · 21/03/2026
Notícia da SecurityWeek "Honeywell, Researcher Clash Over Impact of Building Controller Vulnerability" #bolhasec
securityweek.com
Honeywell, Researcher Clash Over Impact of Building Controller Vulnerability
Researcher finds high-risk vulnerability in Honeywell building management controller, but the vendor disputes the severity and impact.
001
BolhaSec @bolhasec.com · 21/03/2026
Notícia da BleepingComputer "$4.8M in crypto stolen after Korean tax agency exposes wallet seed" #bolhasec
bleepingcomputer.com
$4.8M in crypto stolen after Korean tax agency exposes wallet seed
South Korea's National Tax Service accidentally exposed the mnemonic recovery phrase of a seized cryptocurrency wallet in an official press release, allowing hackers to steal 6.4 billion won ($4.8M) w...
001
BolhaSec @bolhasec.com · 21/03/2026
Notícia da BleepingComputer "Microsoft testing Windows 11 batch file security improvements" #bolhasec
bleepingcomputer.com
Microsoft testing Windows 11 batch file security improvements
Microsoft is rolling out new Windows 11 Insider Preview builds that improve security and performance during batch file or CMD script execution.
001
BolhaSec @bolhasec.com · 21/03/2026
Notícia da SecurityWeek "900 Sangoma FreePBX Instances Infected With Web Shells" #bolhasec
securityweek.com
900 Sangoma FreePBX Instances Infected With Web Shells
Hackers exploited CVE-2025-64328, a FreePBX command injection vulnerability, to infect hundreds of instances with web shells.
001
BolhaSec @bolhasec.com · 21/03/2026
Notícia da BleepingComputer "Star Citizen game dev discloses breach affecting user data" #bolhasec
bleepingcomputer.com
Star Citizen game dev discloses breach affecting user data
Cloud Imperium Games (CIG), the game developer behind Star Citizen and Squadron 42, says attackers breached systems containing some users' personal information in January.
101
BolhaSec @bolhasec.com · 21/03/2026
Notícia da SecurityWeek "Vulnerability in MS-Agent AI Framework Can Allow Full System Compromise" #bolhasec
securityweek.com
Vulnerability in MS-Agent AI Framework Can Allow Full System Compromise
A ModelScope MS-Agent vulnerability allows attackers to feed malicious commands to AI agents and modify system files or steal data.
011
BolhaSec @bolhasec.com · 20/03/2026
Notícia da BleepingComputer "Europol-coordinated action disrupts Tycoon2FA phishing platform" #bolhasec
bleepingcomputer.com
Europol-coordinated action disrupts Tycoon2FA phishing platform
An international law enforcement operation coordinated by Europol has disrupted Tycoon2FA, a major phishing-as-a-service (PhaaS) platform linked to tens of millions of phishing messages each month.
001
BolhaSec @bolhasec.com · 20/03/2026
Notícia da BleepingComputer "Europol-led crackdown on The Com hackers leads to 30 arrests" #bolhasec
bleepingcomputer.com
Europol-led crackdown on The Com hackers leads to 30 arrests
A yearlong Europol-coordinated operation dubbed "Project Compass" has led to 30 arrests and 179 suspects being tied to "The Com," an online cybercrime collective that targets children and teenagers.
001
BolhaSec @bolhasec.com · 20/03/2026
Notícia da BleepingComputer "Hacker mass-mails HungerRush extortion emails to restaurant patrons" #bolhasec
bleepingcomputer.com
Hacker mass-mails HungerRush extortion emails to restaurant patrons
Customers of restaurants using the HungerRush point-of-sale (POS) platform say they received emails from a threat actor attempting to extort the company, warning that restaurant and customer data coul...
001
BolhaSec @bolhasec.com · 20/03/2026
Notícia da SecurityWeek "Critical FreeScout Vulnerability Leads to Full Server Compromise" #bolhasec
securityweek.com
Critical FreeScout Vulnerability Leads to Full Server Compromise
A critical-severity FreeScout vulnerability can be exploited for remote code execution without authentication or user interaction.
001
BolhaSec @bolhasec.com · 20/03/2026
Notícia da SecurityWeek "Fig Security Launches With $38 Million to Bolster SecOps Resilience" #bolhasec
securityweek.com
Fig Security Launches With $38 Million to Bolster SecOps Resilience
Fig Security emerged from stealth mode with $38 million in funding across seed and Series A rounds for its SecOps platform.
001
BolhaSec @bolhasec.com · 20/03/2026
Notícia da BleepingComputer "Samsung TVs to stop collecting Texans’ data without express consent" #bolhasec
bleepingcomputer.com
Samsung TVs to stop collecting Texans’ data without express consent
Samsung and the State of Texas have reached a settlement agreement over the alleged unlawful collection of content-viewing information through its smart TVs
001
BolhaSec @bolhasec.com · 20/03/2026
Notícia da SecurityWeek "Canadian Tire Data Breach Impacts 38 Million Accounts" #bolhasec
securityweek.com
Canadian Tire Data Breach Impacts 38 Million Accounts
The personal information of more than 38 million Canadian Tire customers was stolen in an October 2025 data breach.
001
BolhaSec @bolhasec.com · 20/03/2026
Notícia da SecurityWeek "38 Million Allegedly Impacted by ManoMano Data Breach" #bolhasec
securityweek.com
38 Million Allegedly Impacted by ManoMano Data Breach
A hacker claims to have stolen the personal information of nearly 38 million ManoMano customers from a Zendesk instance.
001
BolhaSec @bolhasec.com · 20/03/2026
Notícia da BleepingComputer "QuickLens Chrome extension steals crypto, shows ClickFix attack" #bolhasec
bleepingcomputer.com
QuickLens Chrome extension steals crypto, shows ClickFix attack
A Chrome extension named "QuickLens - Search Screen with Google Lens" has been removed from the Chrome Web Store after it was compromised to push malware and attempt to steal crypto from thousands of ...
001
BolhaSec @bolhasec.com · 20/03/2026
Notícia da SecurityWeek "In Other News: ATT&CK Advisory Council, Russian Cyberattacks Aid Missile Strikes, Predator Bypasses iOS Indicators" #bolhasec
securityweek.com
In Other News: ATT&CK Advisory Council, Russian Cyberattacks Aid Missile Strikes, Predator Bypasses iOS Indicators
Cyber valuations surged in 2025, OpenAI disrupts malicious AI use, and ShinyHunters claims Odido data breach.
001
BolhaSec @bolhasec.com · 20/03/2026
Notícia da SecurityWeek "Anthropic Refuses to Bend to Pentagon on AI Safeguards as Dispute Nears Deadline" #bolhasec
securityweek.com
Anthropic Refuses to Bend to Pentagon on AI Safeguards as Dispute Nears Deadline
Anthropic wants assurances from the Pentagon that Claude won’t be used for mass surveillance of Americans or in fully autonomous weapons.
011
BolhaSec @bolhasec.com · 20/03/2026
Notícia da BleepingComputer "Microsoft Teams will tag third-party bots trying to join meetings" #bolhasec
bleepingcomputer.com
Microsoft Teams will tag third-party bots trying to join meetings
Microsoft says Teams will soon automatically tag third-party bots in lobbies, allowing organizers to control whether they can join meetings.
021
BolhaSec @bolhasec.com · 20/03/2026
Notícia da BleepingComputer "Ukrainian man pleads guilty to running AI-powered fake ID site" #bolhasec
bleepingcomputer.com
Ukrainian man pleads guilty to running AI-powered fake ID site
A Ukrainian man has pleaded guilty to operating OnlyFake, an AI-powered website that generated and sold more than 10,000 photos of fake identification documents to customers worldwide.
001
BolhaSec @bolhasec.com · 20/03/2026
Notícia da SecurityWeek "OpenClaw Vulnerability Allowed Websites to Hijack AI Agents" #bolhasec
securityweek.com
OpenClaw Vulnerability Allowed Websites to Hijack AI Agents
An OpenClaw vulnerability allowed malicious websites to take over AI agents, exposing sensitive information and enabling data theft.
011
BolhaSec @bolhasec.com · 20/03/2026
Notícia da SecurityWeek "Chilean Carding Shop Operator Extradited to US" #bolhasec
securityweek.com
Chilean Carding Shop Operator Extradited to US
Chilean national extradited to the US over his role in running a cybercrime operation that involved the trafficking of payment card data.
001
BolhaSec @bolhasec.com · 19/03/2026
Notícia da BleepingComputer "APT37 hackers use new malware to breach air-gapped networks" #bolhasec
bleepingcomputer.com
APT37 hackers use new malware to breach air-gapped networks
North Korean hackers are deploying newly uncovered tools to move data between internet-connected and air-gapped systems, spread via removable drives, and conduct covert surveillance.
011
BolhaSec @bolhasec.com · 19/03/2026
Notícia da BleepingComputer "UK warns of Iranian cyberattack risks amid Middle-East conflict" #bolhasec
bleepingcomputer.com
UK warns of Iranian cyberattack risks amid Middle-East conflict
The United Kingdom's National Cyber Security Centre (NCSC) alerted British organizations to a heightened risk of Iranian cyberattacks amid the ongoing conflict in the Middle East.
001
BolhaSec @bolhasec.com · 19/03/2026
Notícia da BleepingComputer "LexisNexis confirms data breach as hackers leak stolen files" #bolhasec
bleepingcomputer.com
LexisNexis confirms data breach as hackers leak stolen files
American data analytics company LexisNexis Legal & Professional has confirmed to BleepingComputer that hackers breached its servers and accessed some customer and business information.
002
BolhaSec @bolhasec.com · 19/03/2026
Notícia da BleepingComputer "UH Cancer Center data breach affects nearly 1.2 million people" #bolhasec
bleepingcomputer.com
UH Cancer Center data breach affects nearly 1.2 million people
The University of Hawaii confirmed that a ransomware gang stole the data of nearly 1.2 million individuals in August 2025 after breaching its Cancer Center's Epidemiology Division.
001
BolhaSec @bolhasec.com · 19/03/2026
Notícia da BleepingComputer "ClawJacked attack let malicious websites hijack OpenClaw to steal data" #bolhasec
bleepingcomputer.com
ClawJacked attack let malicious websites hijack OpenClaw to steal data
Security researchers have disclosed a high-severity vulnerability dubbed "ClawJacked" in the popular AI agent OpenClaw that allowed a malicious website to silently bruteforce access to a locally runni...
001
BolhaSec @bolhasec.com · 19/03/2026
Notícia da SecurityWeek "AI Security Firm JetStream Launches With $34 Million in Seed Funding" #bolhasec
securityweek.com
AI Security Firm JetStream Launches With $34 Million in Seed Funding
JetStream Security launched with $34 million in seed funding to help organizations gain visibility into AI assets across their environments.
001
BolhaSec @bolhasec.com · 19/03/2026
Notícia da SecurityWeek "US-Israel and Iran Trade Cyberattacks: Pro-West Hacks Cause Disruption as Tehran Retaliates" #bolhasec
securityweek.com
US-Israel and Iran Trade Cyberattacks: Pro-West Hacks Cause Disruption as Tehran Retaliates
The escalating conflict between the United States, Israel, and Iran has unfolded alongside extensive cyber operations
001
BolhaSec @bolhasec.com · 19/03/2026
Notícia da BleepingComputer "Fake Google Security site uses PWA app to steal credentials, MFA codes" #bolhasec
bleepingcomputer.com
Fake Google Security site uses PWA app to steal credentials, MFA codes
A phishing campaign is using a fake Google Account security page to deliver a web-based app capable of stealing one-time passcodes, harvesting cryptocurrency wallet addresses, and proxying attacker tr...
002
BolhaSec @bolhasec.com · 19/03/2026
Notícia da SecurityWeek "Iran Cyber Front: Hacktivist Activity Rises, but State-Sponsored Attacks Stay Low" #bolhasec
securityweek.com
Iran Cyber Front: Hacktivist Activity Rises, but State-Sponsored Attacks Stay Low
Security firms monitoring US-Israel-Iran cyberattacks report that while hacktivist attacks spiked, state-sponsored actors remain quiet.
001
BolhaSec @bolhasec.com · 19/03/2026
Notícia da BleepingComputer "How Deepfakes and Injection Attacks Are Breaking Identity Verification" #bolhasec
bleepingcomputer.com
How Deepfakes and Injection Attacks Are Breaking Identity Verification
Deepfakes and injection attacks are targeting identity verification moments, from onboarding to account recovery. Incode explains why enterprises must validate the full session—media, device integrity...
001
BolhaSec @bolhasec.com · 19/03/2026
Notícia da SecurityWeek "LastPass Warns of New Phishing Campaign" #bolhasec
securityweek.com
LastPass Warns of New Phishing Campaign
LastPass is warning users of a new phishing campaign that aims to trick them into handing over their master password.
001
BolhaSec @bolhasec.com · 19/03/2026
Notícia da BleepingComputer "CISA flags VMware Aria Operations RCE flaw as exploited in attacks" #bolhasec
bleepingcomputer.com
CISA flags VMware Aria Operations RCE flaw as exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a VMware Aria Operations vulnerability tracked as CVE-2026-22719 to its Known Exploited Vulnerabilities catalog, flagging the...
001
BolhaSec @bolhasec.com · 19/03/2026
Notícia da BleepingComputer "FBI seizes LeakBase cybercrime forum, data of 142,000 members" #bolhasec
bleepingcomputer.com
FBI seizes LeakBase cybercrime forum, data of 142,000 members
The FBI has seized the LeakBase cybercrime forum, a major online forum used by cybercriminals buy and sell hacking tools and stolen data.
001
BolhaSec @bolhasec.com · 19/03/2026
Notícia da BleepingComputer "Florida woman imprisoned for massive Microsoft license fraud scheme" #bolhasec
bleepingcomputer.com
Florida woman imprisoned for massive Microsoft license fraud scheme
A Florida woman was sentenced to 22 months in prison for running a massive years-long scheme to traffic thousands of stolen Microsoft Certificate of Authenticity (COA) labels.
001
BolhaSec @bolhasec.com · 19/03/2026
Notícia da SecurityWeek "Zurich Acquires Beazley in $11 Billion Deal to Lead Cyberinsurance" #bolhasec
securityweek.com
Zurich Acquires Beazley in $11 Billion Deal to Lead Cyberinsurance
The deal awaits final shareholder and regulatory approvals and is expected to be completed in the second half of 2026.
001
BolhaSec @bolhasec.com · 18/03/2026
Notícia da SecurityWeek "Trump Orders All Federal Agencies to Phase Out Use of Anthropic Technology" #bolhasec
securityweek.com
Trump Orders All Federal Agencies to Phase Out Use of Anthropic Technology
President Trump ordered federal agencies to stop using Anthropic technology after the company’s dispute with the Pentagon over AI safety.
001
BolhaSec @bolhasec.com · 18/03/2026
Notícia da BleepingComputer "CISA warns feds to patch iOS flaws exploited in crypto-theft attacks" #bolhasec
bleepingcomputer.com
CISA warns feds to patch iOS flaws exploited in crypto-theft attacks
CISA ordered U.S. federal agencies to patch three iOS security flaws targeted in cyberespionage and crypto-theft attacks using the Coruna exploit kit.
001
BolhaSec @bolhasec.com · 18/03/2026
Notícia da SecurityWeek "Cloned AI Tool Sites Distribute Malware in ‘InstallFix’ Campaign" #bolhasec
securityweek.com
Cloned AI Tool Sites Distribute Malware in 'InstallFix' Campaign
A newly discovered InstallFix campaign relies on malicious commands on cloned installation webpages to trick victims into installing malware.
001
BolhaSec @bolhasec.com · 18/03/2026
Notícia da SecurityWeek "Russian Ransomware Operator Pleads Guilty in US" #bolhasec
securityweek.com
Russian Ransomware Operator Pleads Guilty in US
A 43-year-old Russian national has pleaded guilty in a US court to charges stemming from his role in the Phobos ransomware operation.
001
BolhaSec @bolhasec.com · 18/03/2026
Notícia da BleepingComputer "Android gets patches for Qualcomm zero-day exploited in attacks" #bolhasec
bleepingcomputer.com
Android gets patches for Qualcomm zero-day exploited in attacks
Google has released security updates to patch 129 Android security vulnerabilities, including an actively exploited zero-day flaw in a Qualcomm display component.
001