Výsledky hledání

sektor: obchod× v celém archivu zrušit filtry

19 karet z 19 položek CZ · EN/orig

1

Financially Motivated Threat Actor BREEZE COMET Targets Brazil

Introduction Beginning in 2024 Mandiant investigated a string of compromises affecting Brazilian financial services, retail, and eCommerce organizations. Google Threat Intelligence Group (GTIG) tracks this activity as BREEZE COMET (formerly UNC5669), a financially motivated threat actor specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers. This activity overlaps with operations publicly reported as Plump Spider and SHADOW-AETHER-064. In…

Google Mandiant finance obchod US

tg: varování tg: zneužíváno tg: rozbor tp: malware tp: podvod tp: únik dat tp: AI

Mandiant / Google TI ·

1

2

1

Beware of fake Indeed interview apps used to install spyware

From several independent reports, we’ve seen evidence of scammers using fake Android “interview” apps to target job seekers on the Indeed platform.Indeed is one of the world’s largest employment websites, giving scammers access to a huge pool of potential victims, especially in a competitive job market.What we foundA user in the UK posted on our forums after being instructed by a supposed employer on Indeed to install an “Interview App.”A user in Brasil submitted an anonymized report after…

Indeed obchod US

Malwarebytes Labs ·

1

Uso de credenciales embebidas en Virtuagym

Embedded credentials in Virtuagym Fri, 08/21/2026 - 11:51 Aviso Affected Resources Virtuagym / Resamania Backend API & Mobile Apps. All versions are affected at the time of reporting. Description INCIBE has coordinated the disclosure of a high-severity vulnerability affecting the backend API and mobile app of Virtuagym, a comprehensive technology platform and mobile app specialising in the fitness and health sector. The vulnerability was discovered by Pau Hinojosa.This vulnerability has been…

EPSS 0.00 CVSS 8.6 CVE-2026-12587 Virtuagym zdravotnictví obchod ES

INCIBE-CERT ·

1

2

1

Curiouser and Curiouser

Welcome to this week’s edition of the Threat Source newsletter. “Experiment is the mother of knowledge.” ― Madeleine L'Engle, A Wrinkle in Time“Don't slide down the rabbit hole. The way down is a breeze, but climbing back's a battle.” ― Kate Morton, The Clockmaker's Daughter Hacker Summer Camp has come and gone, which means it’s time for you to start planning next year’s trip. I’m surely going to recap Camp Season, right? Nope.One of the things that I’ve really enjoyed lately is a segment on…

Microsoft Cisco Signal Shopify finance obchod US

Cisco Talos ·

2

How to fake a data trail (and maybe lower prices) (Lock and Code S07E16)

It may sound entirely bizarre but the prices you once paid for hotels, educational classes, or staplers could have all been higher because you used a Mac computer, lived in a certain zip code, or lacked an Office Depot in your neighborhood. No, really. In 2012, The Wall Street Journal reported that the travel booking site Orbitz showed Mac users pricier hotel options than PC users, because the company had determined that Mac users spend, on average, 30% more a night on hotels. That same year,…

Orbitz Staples Target Delta Airlines obchod US

Malwarebytes Labs ·

10th August – Threat Intelligence Report

For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City and others, has suffered a cyberattack that forced some operations onto manual processes. The authority claims it has contained the intrusion, but degraded systems caused delays while affected services were restored. Ryde, an electric scooter operator in…

EPSS 0.31 CVSS 10.0 CVE-2026-12537 CVE-2026-54316 CVE-2026-64638 Cloudflare Google Anthropic Cisco finance obchod obrana IL

Check Point Research ·

2

CaptiveCrunch: Midnight Blizzard targets travelers worldwide for malware delivery and credential theft

In this article The CaptiveCrunch campaignStorm-2945 and Midnight BlizzardCaptiveCrunch tradecraft and toolingHow to protect against CaptiveCrunch activityMicrosoft Defender detections and hunting guidanceIndicators of compromise Since early May 2026, Microsoft Threat Intelligence has observed Storm-2945, a sub-cluster of Midnight Blizzard, conducting widespread but targeted traffic manipulation attacks involving hospitality sector networks served by captive portals worldwide. Despite some…

Microsoft telekomunikace obchod doprava US

Microsoft Security Blog ·

1

Cisco Catalyst SD-WAN Controller, Catalyst SD-WAN Manager, and Catalyst SD-WAN Validator Authenticated Privilege Escalation Vulnerability

A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by uploading a crafted file to the…

KEV ✓ EPSS 0.92 CVE-2026-20127 CVE-2026-20182 CVE-2026-20245 Cisco telekomunikace energetika doprava finance obchod zdravotnictví US 2 zdrojů

Cisco PSIRT · Mandiant / Google TI

1

1

Nová forma phishingu zneužívá aplikace pro sledování objednávek

Objevila se nová forma phishingového útoku, která zneužívá legitimní aplikace pro sledování objednávek k zobrazování falešných účtenek za údajné nákupy nebo předplatná. Aktuálně jsou takové útoky hlášeny především v aplikaci Shop od společnosti Shopify, nelze však vyloučit využití této techniky i v dalších aplikacích pro sledování objednávek. Namísto tradičních phishingových e-mailů se podvodné zprávy zobrazují přímo v prostředí aplikace, kde uživatelé běžně sledují své skutečné objednávky, což…

Shopify Norton Apple McAfee obchod CZ

CSIRT.CZ (CZ.NIC) ·

1

1