Visualização normal

Antes de ontemStream principal

Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years

5 de Maio de 2026, 20:00

Copy Fail (CVE-2026-31431) is a critical Linux kernel LPE that allows stealthy root access. This flaw impacts millions of systems. Read our analysis.

The post Copy Fail: What You Need to Know About the Most Severe Linux Threat in Years appeared first on Unit 42.

The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1)

1 de Maio de 2026, 21:10

Unit 42 analyzes npm supply chain evolution post-Shai Hulud. Discover wormable malware, CI/CD persistence, multi-stage attacks and more.

The post The npm Threat Landscape: Attack Surface and Mitigations (Updated May 1) appeared first on Unit 42.

Threat Brief: Widespread Impact of the Axios Supply Chain Attack

1 de Abril de 2026, 15:30

Unit 42 discusses the supply chain attack targeting Axios. Learn about the full attack chain, from the dropper to forensic cleanup.

The post Threat Brief: Widespread Impact of the Axios Supply Chain Attack appeared first on Unit 42.

Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17)

17 de Abril de 2026, 19:35

Unit 42 details recent Iranian cyberattack activity, sharing direct observations of phishing, hacktivist activity and cybercrime. We include recommendations for defenders.

The post Threat Brief: Escalation of Cyber Risk Related to Iran (Updated April 17) appeared first on Unit 42.

Critical Vulnerabilities in Ivanti EPMM Exploited

17 de Fevereiro de 2026, 17:35

We discuss widespread exploitation of Ivanti EPMM zero-day vulns CVE-2026-1281 and CVE-2026-1340. Attackers are deploying web shells and backdoors.

The post Critical Vulnerabilities in Ivanti EPMM Exploited appeared first on Unit 42.

Nation-State Actors Exploit Notepad++ Supply Chain

11 de Fevereiro de 2026, 20:00

Unit 42 reveals new infrastructure associated with the Notepad++ attack. This expands understanding of threat actor operations and malware delivery.

The post Nation-State Actors Exploit Notepad++ Supply Chain appeared first on Unit 42.

Threat Brief: MongoDB Vulnerability (CVE-2025-14847)

13 de Janeiro de 2026, 17:30

Database platform MongoDB disclosed CVE-2025-14847, called MongoBleed. This is an unauthenticated memory disclosure vulnerability with a CVSS score of 8.7.

The post Threat Brief: MongoDB Vulnerability (CVE-2025-14847) appeared first on Unit 42.

Exploitation of Critical Vulnerability in React Server Components (Updated December 12)

12 de Dezembro de 2025, 18:40

We discuss the CVSS 10.0-rated RCE vulnerability in the Flight protocol used by React Server Components. This is tracked as CVE-2025-55182.

The post Exploitation of Critical Vulnerability in React Server Components (Updated December 12) appeared first on Unit 42.

❌
❌