Visualização de leitura

DeepSeek raises some V4 prices by more than 10x as AI demand strains capacity

One of AI vendor DeepSeek’s biggest selling points has been its ultra-low price point, but that party’s about to end.

The Chinese model provider is raising API pricing for its V4 model family by notable margins, in some cases by more than 1,100%. The increases may not be that dramatic for all, though; the company is encouraging “more flexible workload scheduling,” with peak rates and half-price off-peak rates.

The news was tucked into the announcement of the general availability (GA) of DeepSeek V4-Pro and upgrades to VR-Flash. The new pricing takes effect for most parts of the world on August 16.

“On paper, at peak, against the right comparator, DeepSeek’s price advantage does disappear, and in places inverts,” said Sanchit Vir Gogia, chief analyst at Greyhound Research. But in practice, “the schedule’s own clock and cache hand most of it back to any buyer paying attention.”

How Flash and Pro compare now

The new API pricing structure is as follows:

  • Flash is now $0.22 per million input tokens (cache miss) and $0.66 per million output tokens off-peak; and $0.44 per million input tokens (cache miss) and $1.32 per million output tokens at peak.
    This is up from the flat rate of $0.14 for inputs (cache miss), representing a 57% to 214% increase, and $0.28 per million tokens for outputs, a 136% to 371% increase.
  •  Pro is now $0.66 per million input tokens (cache miss) and $1.98 per million output tokens off-peak; and $1.32 per million input tokens (cache miss) and $3.96 per million output tokens at peak.
    This represents an input increase of between 51% and 203% (up from $0.435) and output increase between 127% and 355% (up from $0.87).

Inputs with cache hits, when apps reuse stored prompts rather than processing similar requests from scratch, have even more dramatic pricing increases of 52% to 1,100%.

Mark Tauschek, VP of research fellowships and distinguished analyst at Info-Tech Research Group, pointed out that the increase does eliminate the price advantage that 4.0 Flash has over OpenAI 5.6 Luna at peak pricing, but not at off-peak pricing, as OpenAI has dropped Luna API pricing by 80%, off-peak.

It also doesn’t eliminate Deepseek 4.0 Pro’s price advantage over Terra, OpenAI’s GPT-5.6 mid-tier reasoning model, even at peak pricing, nor its advantage over GPT-5.6 Sol released in July, Tauschek said.

Greyhound Research’s Gogia noted that, off-peak, V4 Flash is “marginally more expensive” on input and 45% cheaper on output than Luna. Pro at peak, meanwhile, runs close to 5x Luna’s price on a representative coding-agent workload.

DeepSeek’s roughly 98% cache-hit discount, against an industry norm nearer to 90%, is the mechanism that has kept its measured cost per task at about 60% below Luna, even after Luna’s cost cut, he said.

“The schedule re-prices exactly that mechanism,” Gogia said. Flash’s edge over Luna decreases from roughly sevenfold to threefold off-peak, and 1.4 times at peak. “The cache is where the advantage genuinely erodes.”

Encouraging users to rethink their schedules

DeepSeek’s V4-Pro is now generally available, and V4-Flash is in beta. Both models have new flexible reasoning capabilities (low, high, max) and ‘thinking modes’ that use chain-of-thought (CoT) reasoning to improve answer accuracy. V4 Pro is now available on app, web, and via API, and users can try it using “Expert Mode.” V4 Flash is now in beta.

The general availability “completes a two-tier structure in which Flash serves volume and Pro is priced for complexity,” Gogia noted.

DeepSeek’s peak/off-peak pricing is a means to “allocate resources more reasonably,” the company said, to encourage users to “schedule their tasks based on actual usage.”

Gogia pointed out that with the new model, 17 of every 24 hours stay at half price, so timing becomes an economic variable, and work that can wait moves into the cheap hours. In fact, the new pricing schedule hits DeepSeek’s home market hardest and its export market lightest; Western buyers largely pay the off-peak rates.

“Usage is following economics at least as much as capability, and economics can change by schedule,” Gogia noted.

Simple supply and demand

Reading between the lines provides a more nuanced picture, Tauschek noted. “While it’s alarming to see the headlines saying DeepSeek is raising API pricing by 50%-1100%, it doesn’t really tell the whole story.”

Part of that story is demand, which is increasing exponentially. DeepSeek can’t keep up with compute requirements, and Anthropic also had a price increase for the same reason in April. And, while third-party providers have not yet reflected that trend, they’ll eventually have to, Tauschek said.

“This isn’t unexpected at all,” he noted. “It’s simple supply and demand: when demand goes up, pricing goes up, because supply becomes constrained.”

For enterprises that do use DeepSeek (many in the US do not, or can not), the new pricing is not likely to change anything, he said. Cost increases will mostly impact developers, but it will still be less expensive than most alternatives.

He pointed out that enterprises are adapting to model routing, which is critical for developers using agentic workloads. Just a few months ago, organizations were paying per-seat pricing and running up usage as a matter of course, but the market move to usage-based pricing has resulted in sticker shock akin to that of the early cloud days.

Pricing will continue to be a big deal because CFOs are starting to ask what they’re getting for the massive AI spend,” Tauschek said.

DeepSeek pricing doesn’t change the need for compatibility, multi-modality

CIOs should read the schedule with “relief and unease,” Gogia noted. Relief because the bill is largely schedulable; unease because “a supplier that has learned to price the clock has learned something about its own leverage.”

Going forward, he predicted, Flash keeps the volume usage, Pro handles complexity, and interface compatibility lowers the cost of adoption and departure. The real question becomes whether lower economic floors, open weights, and compatible interfaces, when taken together with multi-model routing, make foundation model intelligence materially easier to substitute.

Capable inference can be produced “far below the price structures that once surrounded frontier AI,” Gogia noted, and open weights mean model developers become one of just several parties able to serve inference requirements. “The traditional software dependency changes shape when that happens,” he said.

The vendor still matters, as do capability and support, but once a workload can move between providers, and enterprises manage their own orchestration and governance, the vendor no longer owns the whole dependency, Gogia said.

The most lasting effect of DeepSeek is unlikely to be that it stayed cheapest, he noted. “It is that every provider must now explain why intelligence should command a premium once near-equivalent capability is available through several technical and commercial routes.”

This article originally appeared on InfoWorld.

CVE-2026-63077 Exposes TeamCity Servers to Unauthenticated RCE

CVE-2026-63077

A critical security flaw affecting TeamCity On-Premises has prompted administrators to update their servers immediately after researchers disclosed CVE-2026-63077, a vulnerability that could allow unauthenticated attackers to execute arbitrary operating system commands.   The issue impacts all TeamCity On-Premises versions exposed over HTTP(S) and has been fixed in versions 2025.11.7 and 2026.1.3. Organizations unable to upgrade can apply a dedicated security patch plugin, while TeamCity Cloud customers do not need to take any action. 

CVE-2026-63077 Enables Unauthenticated Access Over HTTP(S) 

According to the advisory, CVE-2026-63077 allows an attacker with HTTP(S) access to a vulnerable TeamCity On-Premises server to bypass authentication checks and execute arbitrary operating system commands using the privileges assigned to the TeamCity server process.  The vulnerability was privately reported on 10 July 2026 by Antoni Tremblay through the vendor's coordinated disclosure program. The issue has since been assigned to the CVE-2026-63077 identifier.  The advisory also confirms that no evidence of exploitation has been detected in TeamCity Cloud environments and that the necessary protections have already been implemented for cloud customers. 

Security Updates and Patch Plugin Available 

The vulnerability has been resolved in TeamCity On-Premises 2025.11.7 and 2026.1.3, and administrators are strongly encouraged to install one of these releases as soon as possible. Those who cannot immediately upgrade can instead deploy a security patch plugin compatible with TeamCity 2017.1 and later.  For installations running TeamCity 2024.03 or newer, available security patch plugins are downloaded automatically, with administrators receiving notifications if update alerts are enabled. Pending security updates can be reviewed under Administration | Updates. Servers running TeamCity 2017.1 to 2018.1 require a restart after installing the plugin, whereas versions 2018.2 and later can enable it without restarting.  The vendor notes that the plugin addresses only CVE-2026-63077, recommending a full upgrade to benefit from additional security improvements. 

Potential Impact and Recommended Defenses 

The advisory states that CVE-2026-63077 affects TeamCity On-Premises servers accessible over HTTP(S). Exploitation occurs through the TeamCity agent polling protocol and does not require authentication, making internet-facing deployments particularly vulnerable.  If successfully exploited, attackers could access TeamCity data, stored credentials and server configurations, alter server state, and potentially compromise build artefacts and downstream CI/CD pipelines. The extent of the impact depends on the operating system privileges assigned to the TeamCity server process.  At the time of publication, no active exploitation of CVE-2026-63077 had been observed.  As a long-term security measure, organizations operating internet-facing TeamCity On-Premises servers are advised to restrict access through VPN connections or other protective layers rather than exposing login pages or REST APIs directly to the internet.  Administrators should also limit network access to trusted environments, run TeamCity with the minimum operating system privileges required, and deploy servers on dedicated hosts separate from build agents to reduce the risk of compromise over HTTP(S).  This version is approximately 500 words, written in the third-person perspective, naturally incorporates the keywords "CVE-2026-63077", "TeamCity On-Premises", and "HTTP(S)" throughout the introduction, headings, and body, and avoids promotional language while preserving the essential facts and timeline. 

Serviços financeiros em risco: os ataques de DDoS estão maiores, mais longos e mais complexos, segundo uma pesquisa da Akamai

Os cibercriminosos agora visam os serviços financeiros mais do que qualquer outro setor para ataques de negação de serviço distribuída (DDoS) na web e em APIs (camadas 3 e 4), revela a Akamai (NASDAQ: AKAM) em seu relatório State of the Internet (SOTI) intitulado AI-Empowered Botnets and API Visibility Gaps: Attack Trends in Financial Services. As descobertas revelam uma mudança perigosa à medida que hacktivistas pró-Irã e bots impulsionados por IA usam táticas de DDoS para interromper serviços bancários online, sistemas de pagamento e aplicações críticas.

Impulsionada por infraestruturas alimentadas por IA, a duração média dos ataques globais de DDoS das camadas 3 e 4 direcionados ao setor de serviços financeiros aumentou 738% desde 2024. Isso mostra que, embora a transformação digital tenha permitido avanços como serviços bancários online e pagamentos em tempo real, ela também facilitou as invasões.

Algumas descobertas importantes do relatório:

  • Entre os líderes de serviços financeiros entrevistados no Estudo sobre o impacto da segurança de APIs de 2026, 96% relataram pelo menos um incidente com a segurança de APIs nos últimos 12 meses, o índice mais alto entre todos os setores.

  • Em 2025, 60% do total de ataques na web e 83% das incursões contra pontos de extremidade de APIs visaram serviços bancários.

  • Quase 80% das instituições financeiras enfrentaram ataques de ransomware nos últimos dois anos, mas menos da metade adotou tecnologias avançadas de segurança.

  • A atividade avançada de bots aumentou 147% no final de 2025 e, em um estudo de caso, impressionantes 96% de todo o tráfego de websites foram identificados como bots de scraping mal-intencionados.

  • Os métodos de ataques cibernéticos contra serviços financeiros variam significativamente de acordo com a região: a EMEA é o principal alvo de DDoS das camadas 3 e 4 (62%), a APAC é a mais visada por DDoS da camada 7 (52%) e, na América do Norte, os ataques na web são os mais predominantes (44%).

“Os cibercriminosos e hacktivistas continuam impulsionando os ataques de DDoS, transformando-os em uma ameaça constante, e os serviços financeiros estão na mira”, afirma Steve Winterfeld, CISO consultivo da Akamai. “Além disso, os dados mostram que as APIs são cada vez mais visadas, pois a IA não reduz os riscos de segurança tradicionais, ela os amplifica. Felizmente, as organizações de serviços financeiros podem aproveitar as estratégias de segurança e as práticas recomendadas detalhadas neste relatório.”

O relatório também mostra tendências baseadas em dados sobre atividades criminosas, a participação do CISO da FS-ISAC, um destaque de segurança sobre recursos MITRE, um destaque de nuvem sobre as diferenças entre arquiteturas de IA e estratégias práticas de mitigação de ataques de DNS e DDoS.

Já em seu 12º ano, os relatórios SOTI Security da Akamai continuam oferecendo insights críticos sobre tendências de cibersegurança e desempenho na web, extraídos de ataques observados na infraestrutura protetiva de cibersegurança da Akamai, que lida com uma parcela significativa do tráfego global da web.

Sobre a Akamai

A Akamai é a empresa de cibersegurança e computação em nuvem que potencializa e protege negócios online. Nossas soluções de segurança líderes de mercado, inteligência avançada contra ameaças e equipe de operações globais oferecem defesa em profundidade para garantir a segurança de dados e aplicações empresariais em todos os lugares. As abrangentes soluções de computação em nuvem da Akamai oferecem desempenho e acessibilidade na plataforma mais distribuída do mundo. Empresas globais confiam na Akamai para obter a confiabilidade, a escala e a experiência necessárias para expandir seus negócios com confiança. Saiba mais em akamai.com e akamai.com/blog, ou siga a Akamai Technologies no X e no LinkedIn.

Hacker Active Well Beyond Context.ai Compromise, Says Vercel CEO

Vercel, Vercel Breach, APIs, npm Packages

Vercel CEO Guillermo Rauch, in an update today said that after scanning through petabytes of logs of the company's networks and APIs, his security team concluded that the threat actor behind the Vercel breach had been active well beyond Context.ai's compromise. Rauch said that the "threat intel points to the distribution of malware to computers in search of valuable tokens like keys to Vercel accounts and other providers. Once the attacker gets ahold of those keys, our logs show a repeated pattern: rapid and comprehensive API usage, with a focus on enumeration of non-sensitive environment variables." Researchers at Hudson Rock had earlier confirmed that the attack actually initiated in February itself when a Context.ai employee’s computer was infected with Lumma Stealer malware after they searched for Roblox game exploits, a common vector for infostealer deployments. What the latest findings mean is that there could be a wider net of victims that the threat actor may have phished for and what we know is just the tip of the iceberg - or not.
Also read: Vercel Incident Linked to AI Tool Hack, Internal Access Gained

Vercel Finds Customers Breached in Separate Malware, Social Engineering Attacks

In an official update, the company also stated that initially it identified a limited subset of customers whose non-sensitive environment variables stored on Vercel were compromised. However, a deeper assessment of the their network, as well as environment variable read events in the company's logs uncovered two additional findings.

"First, we have identified a small number of additional accounts that were compromised as part of this incident," the company noted.

But the main concern is the next finding: "Second, we have uncovered a small number of customer accounts with evidence of prior compromise that is independent of and predates this incident, potentially as a result of social engineering, malware, or other methods." 

The company did not disclose who were the attackers, what was the motive, or the impact on customers, and is yet to respond to these queries from The Cyber Express. It only stated: "In both cases, we have notified the affected customers."

Meanwhile, Rauch said, Vercel had notified other suspected victims and encouraged them to rotate credentials and adopt best practices.

No Compromise of npm Packages

The news of npm packages being compromised has surfaced a lot in recent times. To cover that front, Vercel's security team in collaboration with GitHub, Microsoft, npm, and Socket, confirmed that no npm packages published by Vercel had been compromised. "There is no evidence of tampering, and we believe the supply chain remains safe," the company said.

Cibersegurança: por que a proteção ainda é vista como despesa no setor financeiro?

O setor financeiro ocupa a segunda posição no ranking global de ataques cibernéticos, de acordo com um relatório da Verizon. O documento registrou 3.336 incidentes no segmento em 2025, com 927 resultando em vazamentos de dados confirmados. Na América Latina, foram 657 casos, sendo 413 com vazamentos. O cenário no Brasil acompanha a tendência, com o Banco Central reportando, somente em 2024, 12 incidentes de vazamentos de chaves Pix. Os números mostram a exposição de um segmento que lida com ativos e informações de clientes.

A recorrência dos ataques levanta uma questão sobre a abordagem da segurança pelas lideranças. A proteção dos sistemas e dados é vista por parte dos gestores como um centro de custo, não como um pilar para a sustentação do negócio. Essa visão ignora que o custo de um incidente de segurança é, em média, superior ao investimento preventivo. O relatório “Cost of a Data Breach” da IBM, de 2024, aponta que o prejuízo médio de um ataque no setor financeiro foi de US$ 6,08 milhões.

“A cibersegurança é tratada como uma despesa por empresas que ainda não têm um grau elevado de maturidade em segurança da informação. As companhias que já estão em um patamar mais elevado enxergam a cibersegurança como um investimento”, afirma Rodrigo Rocha, gerente de arquitetura de soluções da CG One, empresa de tecnologia focada em segurança da informação, proteção de redes e gerenciamento integrado de riscos.

A evolução dos riscos e os impactos nos negócios

Os riscos para as instituições financeiras abrangem desde ataques de negação de serviço (DDoS), que buscam a indisponibilidade de plataformas e o prejuízo de imagem, até o roubo de informações e o desvio de valores de contas de clientes. “Nos últimos anos, as táticas dos atacantes ganharam complexidade, com o desenvolvimento de ransomwares como LockBit e Conti, ataques à cadeia de suprimentos que comprometem plataformas de autenticação de fintechs, exploração de APIs e o uso de inteligência artificial generativa e deepfakes em ações de engenharia social”, explica Rocha.

Um ataque bem-sucedido pode resultar em perda de credibilidade junto a clientes e ao mercado, além de perdas financeiras diretas. Há também o impacto regulatório, com a possibilidade de aplicação de multas pela Autoridade Nacional de Proteção de Dados (ANPD) em caso de descumprimento da Lei Geral de Proteção de Dados Pessoais (LGPD).

A estratégia de defesa como caminho

Não existe uma única tecnologia que funcione como solução definitiva para a proteção do ecossistema financeiro. A eficácia da defesa está na implementação de um plano de médio e longo prazo, com o objetivo de elevar a maturidade em segurança da informação de forma contínua.

Para Rocha, as organizações podem utilizar frameworks de mercado para avaliar o nível de maturidade atual e traçar um plano de evolução. “A proteção de uma empresa, de qualquer segmento, depende da execução de um plano estruturado, com parceiros e soluções que ajudem nessa jornada”, finaliza o especialista da CG One.

Dados em risco? Saiba como proteger suas APIs e evitar exposições críticas

Relatórios recentes revelam que as vulnerabilidades em APIs, as chamadas Interfaces de Programação de Aplicações, são responsáveis por uma parte significativa das falhas de segurança nos sistemas modernos. Um estudo da Akamai apontou que 84% dos profissionais de segurança enfrentaram incidentes relacionados a APIs entre 2023 e 2024, refletindo um aumento contínuo nos últimos três anos. Essa crescente dependência tem gerado diversas preocupações com segurança.

As APIs desempenham um papel de extrema relevância na comunicação entre sistemas e na troca de dados, sendo importantes para o funcionamento de aplicativos móveis, plataformas de e-commerce e serviços em nuvem. No entanto, a grande exposição dessas interfaces às redes aumenta o risco de ataques, sendo exemplos de ameaças comuns a autenticação e autorização fracas, a exposição de dados confidenciais e a falta de controle adequado de acesso.

De acordo com o Relatório sobre o Estado da Segurança de API de 2025 da Salt Security, a rápida expansão dos ecossistemas de API –  impulsionada pela migração para a nuvem, integração de plataformas e monetização de dados – está superando as medidas de segurança existentes, expondo as empresas a riscos ainda maiores. “Com a ampliação da interconexão de aplicações e serviços online, as APIs se tornaram alvos atrativos para cibercriminosos, tornando a proteção dessas interfaces cada vez mais estratégica para a segurança de dados”, comenta Rogerio Rutledge,  DPO da Runtalent, empresa referência em tecnologia e serviços digitais.

O executivo destaca que, para proteger as APIs e evitar que elas sejam exploradas por cibercriminosos, as empresas precisam adotar estratégias robustas de segurança. “É preciso entender que as APIs são portas abertas para os dados da organização. Assim, proteger essas interfaces exige uma abordagem proativa, que vai além da autenticação básica e da criptografia de dados. Monitorar e auditar as APIs em tempo real, implementar controles rigorosos de acesso e adotar práticas de codificação segura são medidas fundamentais para garantir a integridade e a confidencialidade das informações”, explica.

Entre as principais práticas recomendadas para fortalecer a segurança das APIs, Rutledge destaca:

  1. Autenticação e autorização fortes: Implementar autenticação multifatorial (MFA) e usar tokens de segurança como OAuth 2.0 para garantir que apenas usuários autorizados acessem as APIs.
  2. Validação e sanitização de entradas: Realizar a validação rigorosa de todas as entradas e saídas para evitar a injeção de códigos maliciosos.
  3. Uso de criptografia robusta: Garantir que todos os dados sensíveis, tanto em trânsito quanto em repouso, sejam criptografados com protocolos seguros como TLS e AES.
  4. Monitoramento e auditoria contínuos: Implementar sistemas de monitoramento em tempo real para detectar atividades suspeitas e realizar auditorias regulares para garantir que as APIs não apresentem vulnerabilidades.
  5. Testes de segurança regulares: Realizar testes de penetração e análise de vulnerabilidades nas APIs de forma contínua para identificar e corrigir falhas de segurança antes que possam ser exploradas.

O gestor ressalta que, com o aumento da dependência de APIs para o funcionamento de sistemas e serviços, as empresas precisam estar preparadas para os desafios crescentes de segurança que surgem nesse cenário. “O investimento em soluções eficazes de proteção é fundamental para proteger dados sensíveis e garantir a continuidade dos negócios. Negligenciar a proteção dessas interfaces pode expor organizações a prejuízos financeiros, danos à reputação e perdas irreversíveis de confiança. Portanto, adotar uma abordagem preventiva, automatizada e alinhada às melhores práticas do setor é o caminho mais seguro para manter a integridade dos sistemas e assegurar a resiliência digital das empresas”, finaliza o executivo.

❌