A partir de 2024, o grupo de inteligência de ameaças do Google identificou o ator de ameaças BREEZE COMET, que visa organizações financeiras no Brasil, manipulando sistemas de pagamento para realizar transferências fraudulentas. O uso de inteligência artificial para desenvolver malware pode aumentar a escala e sofisticação dessas operações.
- •BREEZE COMET é um ator de ameaças motivado financeiramente.
- •O grupo utiliza malware personalizado e sites confiáveis para acesso inicial.
- •As operações visam bancos, processadores de pagamento e fintechs.
Why it matters: A crescente sofisticação das ameaças cibernéticas, como as de BREEZE COMET, pressiona as instituições financeiras a reforçarem suas defesas, especialmente em um ambiente onde a digitalização de serviços financeiros está em rápida expansão. Isso pode impactar a confiança do consumidor e a segurança do sistema financeiro como um todo.
Successful exploitation of vulnerabilities in Rockwell Automation RSLinx Classic could lead to denial-of-service conditions. Versions affected include RSLinx Classic <=4.50, with critical vulnerabilities identified (CVE-2026-9621, CVE-2026-9622, CVE-2026-9624, CVE-2026-9625). A fix is available in version 4.60.
- •Vulnerabilities could cause denial-of-service in RSLinx Classic.
- •Affected versions include RSLinx Classic <=4.50.
- •Critical vulnerabilities identified with CVSS score of 8.6.
Why it matters: The vulnerabilities in RSLinx Classic highlight the risks associated with outdated software in critical manufacturing sectors. This situation pressures organizations to prioritize timely updates and robust security practices to safeguard their infrastructure against potential attacks.
The Rockwell Automation Logix Platform has critical vulnerabilities (CVE-2026-9637) affecting multiple versions, leading to potential denial-of-service attacks. This issue arises from improper input validation during CIP message processing, which could cause major nonrecoverable faults requiring a power cycle for recovery.
- •Rockwell Automation Logix Platform affected by CVE-2026-9637.
- •Vulnerabilities span ControlLogix, CompactLogix, and GuardLogix models.
- •Improper input validation can lead to denial-of-service attacks.
Why it matters: These vulnerabilities highlight significant risks in critical manufacturing infrastructure, potentially disrupting operations and leading to costly downtimes. Addressing these issues is crucial for maintaining operational integrity and security in automated environments.
A banker used WhatsApp's single view feature to send screenshots. iOS logs helped reconstruct the conversations.
- •The Federal Police accessed deleted messages from an iPhone.
- •The use of screenshots on WhatsApp was a strategy employed by the banker.
- •iOS logs were crucial for the investigation.
Why it matters: This case signals the increasing capability of authorities to access digital data, which may pressure companies to enhance user security and privacy. The way data is managed and protected can impact consumer trust and regulatory compliance.
Microsoft will expand the automatic activation of the Memory Integrity feature in Windows 11 starting in October. However, users of older PCs should monitor performance, as the new protection may impact the performance of older devices.
- •The Memory Integrity feature will be automatically enabled in Windows 11.
- •The change will take effect starting October 2023.
- •Users of older PCs should be mindful of performance.
Why it matters: This change signals Microsoft's commitment to prioritizing security, potentially pressuring other companies to adopt similar measures. Additionally, concerns about performance on older hardware may influence the adoption of new updates by both users and businesses.
Developed by CISA and partners, this guidance outlines best practices for organizations to communicate effectively during IT and operational technology outages. It emphasizes clarity, accountability, and transparency in crisis messaging, aiming to inform stakeholders while aligning with legal and operational requirements. The guidance is crucial for maintaining trust and minimizing panic during service disruptions.
- •CISA and FBI released guidance for crisis communication.
- •Focus on clarity, accountability, and transparency.
- •Addresses communication during IT and OT outages.
Why it matters: Effective crisis communication is essential for maintaining operational integrity and public trust, especially in interconnected systems where outages can have widespread effects. This guidance signals a proactive approach to managing risks associated with cyber threats and operational failures, which is vital for critical infrastructure resilience.
A Comcast adicionou detecção de movimento aos seus roteadores sem fio, enviando notificações quando movimento é detectado. Embora a funcionalidade possa ser útil, há preocupações significativas sobre privacidade, já que informações geradas podem ser compartilhadas com terceiros, incluindo autoridades legais, sem aviso prévio ao usuário.
- •Comcast lançou detecção de movimento em seus roteadores.
- •Usuários recebem notificações quando movimento é detectado.
- •A funcionalidade tem limitações relacionadas ao ambiente doméstico.
Why it matters: A introdução de recursos de vigilância em dispositivos comuns como roteadores pode sinalizar uma nova era de monitoramento doméstico, levantando questões sobre privacidade e segurança de dados. Isso pressiona as empresas a reconsiderar como gerenciam e protegem as informações dos usuários em um ambiente cada vez mais conectado.