Novo ataque AirSnitch contorna isolamento de clientes Wi-Fi

Pesquisadores apresentaram o AirSnitch, uma série de ataques que compromete o isolamento de clientes em redes Wi-Fi, permitindo comunicação não autorizada entre dispositivos. A técnica explora comportamentos de rede de baixo nível e afeta roteadores de fabricantes principais, incluindo Netgear, D-Link e Cisco. Apresentado no Simpósio de Segurança de Redes e Sistemas Distribuídos 2026, os achados destacam vulnerabilidades em configurações residenciais, de escritório e empresariais.

Redes Wi-Fi, que conectam mais de 6 bilhões de usuários em todo o mundo, dependem do isolamento de clientes para impedir que dispositivos se comuniquem diretamente uns com os outros, mesmo quando criptografados. No entanto, nova pesquisa demonstra que ataques AirSnitch podem contornar essa proteção ao mirar nas Camadas 1 e 2 da pilha de rede, levando a uma dessincronização de identidade cross-layer.

Artigos relacionados

Dramatic server room scene illustrating the SSHStalker Linux botnet infecting thousands of vulnerable servers via SSH exploits.
Imagem gerada por IA

Researchers discover SSHStalker botnet infecting Linux servers

Reportado por IA Imagem gerada por IA

Flare researchers have identified a new Linux botnet called SSHStalker that has compromised around 7,000 systems using outdated exploits and SSH scanning. The botnet employs IRC for command-and-control while maintaining dormant persistence without immediate malicious activities like DDoS or cryptomining. It targets legacy Linux kernels, highlighting risks in neglected infrastructure.

One week after the FCC banned sales of new foreign-made Wi-Fi routers over national security risks, new details emerge on implicated cyberattacks and growing criticism of the broad policy's effectiveness.

Reportado por IA

A hacking technique called DarkSword, used by Russian hackers, can compromise iPhones running iOS 18 simply by visiting infected websites. Discovered in the wild, this tool has been deployed in espionage and cybercriminal campaigns to target thousands of devices indiscriminately. It is now available online in a reusable form, risking a large portion of iPhone users worldwide.

New research from ETH Zurich and USI Lugano reveals vulnerabilities in popular password managers, challenging their assurances that servers cannot access user vaults. The study analyzed Bitwarden, Dashlane, and LastPass, identifying ways attackers with server control could steal or modify data, particularly when features like account recovery or sharing are enabled. Companies have begun patching the issues while defending their overall security practices.

Reportado por IA

Windscribe has introduced a new Android beta version of its VPN app featuring native support for AmneziaWG. This update aims to help users bypass deep packet inspection and counter internet censorship in countries like Iran and Russia. The launch addresses ongoing challenges faced by individuals seeking secure online access in restrictive environments.

Security researchers have uncovered critical vulnerabilities in the n8n automation tool. A previously released patch failed to fully address the issues, leaving users exposed. Experts provide guidance on protecting systems amid these discoveries.

Reportado por IA

A straightforward hack enabled the owner of a new DJI Romo robot vacuum to connect with thousands of other devices worldwide. The incident highlights an ongoing security vulnerability in the product. TechRadar reported the details on February 18, 2026.

terça-feira, 07 de abril de 2026, 17:23h

Western agencies warn of russian hackers on tp-link routers

sábado, 04 de abril de 2026, 14:25h

Daniel Stenberg warns of risks in curl project

quarta-feira, 11 de março de 2026, 07:15h

14,000 Asus routers infected by takedown-resistant KadNap malware

quarta-feira, 11 de março de 2026, 02:47h

Dutch intelligence accuses Russia of hacker attacks on WhatsApp and Signal

quinta-feira, 26 de fevereiro de 2026, 11:39h

Zyxel warns of critical RCE flaw in over a dozen routers

quarta-feira, 25 de fevereiro de 2026, 22:24h

CrowdStrike warns of rapid network intrusions by attackers

segunda-feira, 23 de fevereiro de 2026, 08:01h

Malicious npm packages harvest crypto keys and secrets

quinta-feira, 19 de fevereiro de 2026, 09:18h

Experts claim ransomware attacks increasingly target firewalls

sábado, 14 de fevereiro de 2026, 06:39h

SSHStalker botnet uses IRC to target Linux servers

quarta-feira, 04 de fevereiro de 2026, 19:25h

Russian hackers exploit Microsoft Office vulnerability days after patch

 

 

 

Este site usa cookies

Usamos cookies para análise para melhorar nosso site. Leia nossa política de privacidade para mais informações.
Recusar