Brazil: cybersecurity landscape, July 2026
Brazil closed July with ransomware as the dominant theme, greater regulatory pressure, and three critical CVEs under active exploitation.
Key findings
- Ransomware displaced generic incidents as the leading threat in Brazil during July, with 25 of 64 verified events.
- Healthcare remained the most exposed sector, with verifiable cases of encryption, exfiltration, and leak site claims.
- ANPD stepped up its sanctions and monitoring agenda, while new decrees expanded obligations for digital platforms.
- The Central Bank moved toward prudential oversight of cyber risk in Pix, with potential operational restrictions for weaker institutions.
- Five critical CVEs were mentioned with active exploitation or prioritized mitigation, concentrated in VPNs, CMS, and SharePoint.
- Brazil maintained a disproportionate position in the regional ransomware map and in campaigns that abused legitimate infrastructure.
- Security teams should prioritize perimeter exposure, exfiltration prevention, and document traceability for regulators.
Monthly reference modules
These modules are completed automatically with the verified, dated facts within the period. Each one states its basis and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading; the later analysis develops the cases without repeating this summary.
Indicator window: 66 dated facts in July 2026 · 1 from earlier months (comparative frame, not monthly volume). Facts from earlier months are used only as a comparative frame in the analysis, never as volume for this period.
Monthly executive summary in Brazil
July 2026 painted a harsher picture for Brazil on two fronts that feed into each other. On one side, ransomware became the month’s dominant threat, with 25 verified incidents out of 64, and at least five episodes in which asset encryption was confirmed. On the other, the regulatory front accelerated with 13 documented moves, almost all tied to the ANPD, the Marco Civil da Internet, and the new perimeter of requirements for platforms, banks, and fintechs.
The clearest signal came from the health sector. The Isac Tecnología em Saúde case led to an ANPD sanctioning process over the exposure of nearly 500,000 patients, while SPDM and Reni Farmácias Associadas appeared in public ransomware records during the second half of the month. At the same time, Brazil continued to rank among the countries under the heaviest regional ransomware pressure, and healthcare again stood out as a particularly targeted sector, though it was not the only one hit by digital extortion.
The other notable development was in the prudential layer. The Central Bank advanced a restriction scheme for institutions with cybersecurity weaknesses in Pix, with limits on hours, amounts, and the registration of new keys, along with the possibility of temporary exclusion from the system. That shift did not stem from a confirmed July intrusion, but from an accumulated risk reading of the payments ecosystem and earlier attacks on the technology supply chain.
On the technical exposure side, the month added five critical CVEs mentioned in Brazilian and official material, all with active exploitation or elevated risk classification. The pattern is consistent, VPNs, content managers, and web components were at the center of the attack surface. For a country with 81% direct confirmation in the sources and 7 sectors with documented incidents, the problem was not a lack of signal, but the simultaneity of criminal pressure, exploited vulnerabilities, and tougher regulatory demands.
Brazil’s National Snapshot for the Month
Brazil’s risk reading for July 2026 is high. Not because of a single incident, but because of the mix of volume, recurrence, and severity. The month ended with ransomware as the dominant theme, a base of 64 verified events, 10 unclassified incidents, and 13 regulatory moves. That mix points to an environment in which the criminal market kept finding exposed attack surface, while the state responded with tighter oversight and more concrete obligations for digital and financial actors.
The pressure was not limited to one sector. Healthcare was the most visible front because of its social impact and the sensitivity of the data exposed, but the material also shows activity across energy, technology, consumer services, real estate, agriculture, and corporate services. In several cases, the public source only allows confirmation that the victim was named on a leak site; in others, such as Isac or msgas.com.br, there were firmer indicators of exfiltration or encryption. That unevenness matters, because it forces a distinction between claim, leak, and confirmed encryption.
Compared with the rest of Latin America, Brazil continued to occupy a disproportionate place. The sources cited in July place it as the regional ransomware epicenter in healthcare, among the countries with the most claimed victims by extortion groups, and also among the most exposed to campaigns that abuse legitimate infrastructure, from government domains to trusted email channels. The country appears not only as a target, but also as an environment where criminal activity, regulation, and uneven control maturity converge.
The operational picture changes when the financial front is examined. Pix was at the center of the debate as infrastructure that the Central Bank can condition to raise cybersecurity standards. The regulatory message is clear, institutions with weak controls face not only fraud or disruption, but also functional restrictions. That raises the cost of noncompliance and brings cybersecurity closer to traditional prudential supervision.
Brazil period indicators
| Indicator | July 2026 value | Previous month | Change | Scope / note |
|---|---|---|---|---|
| Verified facts in the period | 64 | 67 | -3 | Base for all indicators, only dated facts within the period |
| Indicator time window | 66 facts dated in July 2026 · 1 from previous months (comparative framework, not July volume) | Same | N/A | Comparative framework included in the file, not counted as July volume |
| Unclassified incidents (breaches or outages) | 10 | 25 | -15 | Breaches or outages not sufficiently classified in the source material |
| Cases with ransomware or extortion as the primary focus | 25 | 15 | +10 | Includes cases where ransomware or extortion was the main focus |
| Confirmed asset encryption | 5 | Not provided | N/A | Subset within ransomware, only when confirmed by the source material |
| Unable to determine classification from the material | 20 | Not provided | N/A | Subset within ransomware, exact impact could not be determined |
| Documented fraud or phishing cases | 0 | 5 | -5 | No documented cases appeared in July |
| Documented regulatory moves | 13 | 6 | +7 | Acts, decrees, consultations, sanctions, and regulatory announcements |
| Critical CVEs mentioned | 5 | 2 | +3 | Critical vulnerabilities mentioned in the analyzed material |
| Sectors with at least one documented fact | 7 | 7 | No change | One fact can affect more than one sector |
| Dominant threat of the month | Ransomware (25 of 64 facts) | Incidents (25 of 67 facts) | Shift in focus | Dominance by number of facts, not isolated severity |
| Facts with direct source confirmation | 81% | Not provided | N/A | Percentage of direct confirmation across the period facts |
| Aggregate telemetry figures excluded from volume | 2 (aggregate attempts or blocks: not incidents with confirmed impact) | Not provided | N/A | Telemetry, not confirmed intrusions |
Relevant Incidents in Brazil
Isac Tecnologia em Saúde and the exposure of 500,000 patients
ANPD opened an administrative sanction proceeding against Isac Tecnologia em Saúde over a ransomware incident that affected about 500,000 patients from public units. The most relevant part of the case is not just the volume, but the sequence of exposure, because the material confirms file encryption that left administrative systems unavailable, although the institution itself said there was no technical evidence of exfiltration or disclosure of personal data.
That distinction matters. For operational and regulatory purposes, the difference between encryption and exfiltration changes the response, the type of notification, and the legal exposure. Here, there was an attack with functional impact, plus a formal investigation by the data authority. In July, this case stood out as one of the few episodes where the source allowed the form of harm to be distinguished.
SPDM on Global Secret Group's leak site
SPDM was publicly listed by Global Secret Group with 847 GB of claimed data and 871,912 files across 76,047 folders. The material confirms the publication on the leak site and the scale of the claim, but does not allow the primary source to show whether encryption was visible or whether the case was limited to extortion with exfiltration. Even so, the fact that a large hospital provider was exposed in this way increases sector-wide risk.
Sinop Energia and pressure on power infrastructure
Sinop Energia, operator of the Sinop hydroelectric plant in Mato Grosso, was listed by Global Secret Group as a ransomware victim with 300 GB of exfiltrated data. The case adds a different piece to July's picture, shifting attention from health to energy infrastructure, with potentially broader impact because of its ties to essential services. The public evidence supports the claim and the leaked volume, but not a detailed public confirmation of greater operational disruption.
msgas.com.br and the Blackwater case
The Brazilian gas company msgas.com.br was documented as a Blackwater victim, with exposure of customer personal data, contracts, and internal data according to independent technical analysis. Unlike other cases that appear only in trackers, this one includes a more concrete description of what was stolen. The public breach record also provides a more useful timeline, with publication on 25 July and earlier disclosure in June.
Reni Farmácias Associadas and Doommageddon
Reni Farmácias Associadas appears in public ransomware records as a Doommageddon victim, with the incident discovered on 19 July. The available material confirms the organization's inclusion in the victim ecosystem and its presence in health care, but does not make it possible to determine whether there was encryption, exfiltration, or both. It is a good example of why the report separates leak site reference from verified impact.
Francisco Imóveis and redeplastrs.com.br in July records
ransomware.live recorded Francisco Imóveis and redeplastrs.com.br as Doommageddon and Blackfield victims, respectively, with attacks estimated for 1 July and discoveries in the first days of the month. These mentions broaden ransomware's footprint in Brazil beyond the sectors that usually draw attention, but the material does not provide enough technical detail to classify them beyond their public inclusion as victims.
Active threats and campaigns in Brazil
Ransomware and extortion, with three levels of evidence
The July material points to three distinct layers. First, cases with confirmed encryption, such as Isac Tecnologia em Saúde. Second, cases with confirmed data exfiltration or theft, such as SPDM and Sinop Energia. Third, mentions on leak sites where the source does not specify the real impact, such as Reni Farmácias Associadas, Francisco Imóveis, or redeplastrs.com.br. That distinction matters, because the overall figure of 25 cases with ransomware or extortion as the primary focus combines related, but not identical, phenomena.
Within that set, extortion showed clear operational maturity. Several attacks against Brazil relied on data publication, reputational pressure and disruption of supply chains, rather than highly visible mass encryption. That logic appears especially in health care and energy. The takeaway for defensive teams is straightforward, backup controls are no longer enough on their own if the organization does not also protect credentials, exposed surfaces and exfiltration paths.
Fraud and phishing, with no documented cases in the period
There were no fraud or phishing cases documented as incidents in the period within the verified July material. That does not mean there was no risk, because the month did bring regulatory and contextual signals around financial fraud, impersonation and platform abuse, but those events are not included in the incident count because they were not presented as individual operational cases with confirmed impact.
APT, hacktivism and abuse of legitimate infrastructure
Brazil also appeared in campaigns that do not fit pure ransomware. PhantomEnigma, for example, abused more than 20 Brazilian government sites to distribute malware and targeted banks and public agencies using trusted domains and legitimate email. That pattern does not confirm state sponsorship or a closed APT attribution, but it does show a trust-engineering tactic that raises the risk of initial delivery.
Along the same lines, a reported intrusion into PagBank's payments ecosystem appeared in a manifesto from a group identifying itself as 1877 Team. The available material offers no independent confirmation from authorities or from the provider itself, so it should be read as an allegation, not a verified incident. Even with that caution, the episode is useful for tracking threat actors' appetite for Brazilian financial infrastructure.
Critical vulnerabilities with impact in Brazil
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-48907 | Joomla Content Editor (JCE) | Active exploitation confirmed by CTIR Gov in Brazil; fixes were recommended immediately | CTIR Gov / Portal Gov.br, 2026-07-10 |
| CVE-2026-56291 | Balbooa Forms for Joomla | Active exploitation in real-world environments, added to CISA's KEV catalog | DFT Info, 2026-07-12 |
| CVE-2026-45659 | Microsoft SharePoint on-premises | Active exploitation reported by CISA for remote code execution | CEVIU News, 2026-07-17 |
| CVE-2026-332201 | Microsoft SharePoint on-premises | Active exploitation reported by CISA for spoofing | CEVIU News, 2026-07-17 |
| CVE-2026-56164 | Microsoft SharePoint on-premises | Active exploitation reported by CISA for privilege escalation | CEVIU News, 2026-07-17 |
The concentration of vulnerabilities in web components and internet-facing platforms was no coincidence. In July, the material also linked active exploitation of enterprise VPNs to real compromises in Brazilian organizations, especially through CVE-2024-24919. The practical result is a fairly clear attack surface, perimeter access, CMS, form components, and enterprise collaboration.
Regulation and compliance in Brazil
Regulatory activity was one of the month’s densest themes. ANPD closed the first phase of monitoring on 56 data processing agents, with 27 full compliance cases, 8 with pending items, and 21 with no response. That snapshot shows a regulator already prepared to move from policy to sanctions, not only in the abstract terrain of the LGPD, but in basic controls, support channels, and assignment of responsibility.
That was joined by a new operating framework for digital platforms. Decrees 12.975/2026 and 12.976/2026 took effect on July 20 and expanded duties on content moderation, illegal advertising, transparency, appeals mechanisms, and liability for systemic failures. ANPD was left as the central authority to oversee a substantial part of the regime. The shift is clear, more obligations and more traceability, with less room for platform inertia.
The case of women online drew a sensitive line. Decree 12.976 imposed deadlines to take non-consensual intimate content offline, including when it is manipulated with artificial intelligence, and gave ANPD authority to regulate, supervise, and investigate violations. In parallel, the authority updated its reporting channels and began monitoring the generation and modification of intimate content by AI. That combination of rulemaking and enforcement capacity is already producing concrete effects.
The Central Bank followed a different but converging logic. Its discussion of Pix starts from a prudential view of cyber risk and pushes it to the center of financial supervision. The possibility of limiting operating hours, transaction amounts, key registration, and even suspending access to the system was presented not as an isolated penalty, but as a preventive response to institutions with weak controls. For banks and fintechs, that makes cybersecurity an operating condition of the business.
There were also announcements from Susep, ANPD consultations with PNUD, and several legislative proposals in progress, including PL 4.752/2025 on the Legal Framework for Cybersecurity. The pattern is consistent, Brazil is not only responding to incidents, it is also rewriting the regulatory perimeter that defines who can operate, under what obligations, and with what minimum controls.
Most Affected Sectors in Brazil
Healthcare was the month’s most exposed sector because of the combination of volume, data exposure, and social cost. Isac Tecnología en Saúde, SPDM, and Reni Farmácias Associadas point to a pattern that does not need much interpretation. Clinics, hospitals, care providers, and technology vendors across the health ecosystem are under pressure. The context material also reinforces that healthcare is one of the areas where Brazil concentrates a very high share of regional ransomware activity.
Corporate services also remained under pressure. Lucas Alcaraz’s analysis placed that segment as the main ransomware target in Brazil in 2026 within the available material, and several victims disclosed in July fit that pattern. The reason is familiar, criminal groups continue to target places where operations must keep running, payments are possible, and third-party chains are broad.
Energy and utilities stood out through Sinop Energia and msgas.com.br. Although the number of incidents is lower than in healthcare, the systemic risk is higher. An incident in this kind of environment can affect service continuity, sector regulation, and, potentially, critical infrastructure.
Technology, consumer sectors, and real estate rounded out the map. These are not sectors that dominate public discussion every month, but July showed that ransomware and extortion were not confined to the usual verticals. That spread suggests the month should not be read only as a story about hospitals, but as broad pressure on organizations with digital exposure and ability to pay.
Trends and signals to watch in Brazil
The comparison with the previous month shows a clear shift in focus. In June, the report's main threat category had been incidents, with 25 of 67 events. In July, ransomware moved to the top, with 25 of 64 events. This is not just a statistical change, it signals that extortion returned to shape the local agenda more strongly than breaches or generic disruptions.
The profile of unclassified incidents also changed. They fell from 25 to 10 compared with the previous month. That suggests better classification quality in the coverage, but also more cases where the material made it possible to identify the ransomware component with greater precision. At the same time, documented fraud or phishing cases went from 5 to 0, which does not eliminate the problem, but does indicate that July was dominated by other fronts.
Regulatory activity rose sharply. Regulatory moves increased from 6 to 13, and that is not incidental. The state responded to incidents and structural risks with more monitoring, more decrees, and more public consultations. For security teams, that means risk is no longer measured only in infections or leaks, but also in the ability to meet oversight demands, provide documentation, and respond quickly.
In critical vulnerabilities, the jump from 2 to 5 CVEs mentioned is a sign of a broader exposed surface. It does not mean there was more exploitation than in other months, but it does show that July brought more references to flaws that were actively exploited or clearly prioritized by response agencies. The focus should remain on VPNs, CMS, SharePoint, and internet-exposed components.
Compared with the rest of Latin America, Brazil remained an outlier in both volume and the concentration of claimed victims. The region saw cross-cutting campaigns against health, services, and government, but Brazil maintained a distinct density of ransomware and a more active regulatory ecosystem. That combination makes it a regional reference case, not just another country on the map.
Security recommendations for teams in Brazil
First, harden remote access and perimeter exposure. July’s reporting again put VPNs, gateways, and access solutions at the center of intrusions. Patching, mandatory MFA, privileged credential review, and access segmentation should no longer be treated as cycle tasks, but as permanent, auditable controls.
Second, review the ability to contain exfiltration, not just encryption. In Brazil, several cases this month showed that the most likely damage is no longer just downtime, but data publication and secondary extortion. That requires outbound monitoring, detection of anomalous transfers, hardened backups, and an incident response plan that includes legal and regulatory communications.
Third, prepare evidence for the regulator before you need it. ANPD showed a more aggressive agenda, the Central Bank did too, and several sectors came under specific scrutiny. Security and compliance teams should have updated inventories of assets, owners, remediation evidence, support channels, and incident traceability ready to go. If it is not documented, July made it clear that it can count as noncompliance.
Fourth, prioritize business and collaboration web platforms. The month combined CVEs in CMS, forms, SharePoint, and widely used enterprise solutions. That means accelerating exposure inventories, patch cycles, third-party component validation, and searches for legacy configurations that can no longer withstand current pressure.
Fifth, for critical sectors such as healthcare, energy, and financial services, align cybersecurity with operational continuity. July’s cases show that adversaries target the places where downtime is most costly. Response plans should include tested recovery, isolation of vital systems, identity protection, and drills that go beyond crisis-room exercises.
Material limitations
This report was prepared exclusively from the facts provided for Brazil, July 2026, and from the comparative framework explicitly identified as belonging to previous months. The time window for the indicators is the one stated at the outset, 66 facts dated July 2026 and 1 fact from previous months used only for comparison, not as part of the month's volume.
A value of 0, especially in documented fraud or phishing cases, means that no facts of that type appeared in the July material analyzed. It does not mean that fraud or phishing did not occur in Brazil during the month, only that no verifiable record of it was found in this corpus. The same applies to CVEs and any category not observed in the period, no record does not mean no activity in the region.
The distinction between ransomware with confirmed encryption, extortion with exfiltration, and a simple mention on a leak site was preserved whenever the material allowed it. In several cases, the source did not specify whether encryption occurred, and in those cases no additional classification was imposed. Telemetry totals were also excluded, because they correspond to automated attempts or blocks and not to intrusions with confirmed impact.
All sources not eligible for citation under this report's rules were excluded from the body, including consumer social media posts and LinkedIn posts, as well as any promotional or sponsored material that did not function as a verifiable primary source. When trends or risk assessments were mentioned, official agencies, CERT/CSIRT, vendor advisories, and victim records were prioritized over commercial reports or marketing content.
Sources
- Brasil BCB Resolución 580: PSAVs como Tipo 3PtyCoin
- Ransomware groups are hammering your vulnerable VPNsCSO Online
- Top 5 Ransomware Groups in Q2 2026: Who They Are ...Brandefense
- Ransomware Groups Increasingly Deploy EDR Killers to Sidestep DefensesInfosecurity Magazine
- Akira group profileransomware.live
- A fiscalização da ANPD e o fim da cultura do improvisoJornal do Brasil
- PhantomEnigma Infects Organizations with Malware via Hijacked Government WebsitesHackRead
- Ransomware en el primer semestre de 2026: qué grupos atacan y qué sectores son los más afectadosESET / WeLiveSecurity
- Actualité cybersécurité — Veille quotidienneFactualRisk
- Sinop Energia Data Breach in 2026BreachSense
- Victim: SPDMGlobal Secret Group (ransomware.live)
- IA a visar a Tecnologia Operacional: Novas Perspetivas de AmeaçaCryptonomist
- Spdm Listed by Global Secret Group Ransomware GroupGalaxy Warden
- Sinop Energia Listed by Global Secret Group Ransomware GroupGalaxyWarden
- Healthcare victims in Brazilransomware.live
- Energy & Utilities – Brazil victims listingransomware.live
- Compliance para Saúde: LGPD, HIPAA, CFM, ANVISAVantico
- Ransom! msgas.com.br (JUL-2026)Hendry Adrian
- Impact Analysis of Ransomware Attacks on EMEA HealthcareFlare.io
- msgas.com.br — BLACKWATER Ransomware AttackBreach House
- Republicanos dos EUA pedem pressão sobre Brasil por PL que regula big techsUOL
- Ransomware avança 17,8% e mira o Brasil e toda a LATAMEstado de Minas
- Brasil vira epicentro de ransomware na saúde na América Latina; especialistas alertam para riscos de IA sem governançaPortal Information Management
- Oposição pede urgência para derrubar decreto de Lula sobre big techsPoder360
- Golpe da falsa central bancária fica mais sofisticado e liga o alerta da FebrabanO Banco Digital Notícias
- Fraudes digitais se consolidam como maior crime patrimonial do país, com mais de 250 golpes por horaO Globo
- Deepfake Íntimo Agora É Crime: Decreto 12.976/2026 e MultasRibeiro Cavalcante Advocacia
- Fenasbac and GASA Report Outlines a Cross-Sector Response to Digital Scams in BrazilGASA / Fenasbac
- Incidentes cibernéticos crescem em pequenas e medias empresas no paísG1
- Setor de saúde lidera ranking mundial de ataques cibernéticosSINDPD
- A ressalva que ficou de fora: o decreto da moderação copiou modelo europeu, mas não trouxe exceção eleitoralAtlas Público
- Marco Civil da Internet ganha novas regras e amplia deveresSampi
- Brasil concentra 51% dos ataques de ransomware ao setor ...Brasilia e Aqui
- Decreto define prazos para plataformas digitais retirarem do ar conteúdos de violência contra mulheresAgência Gov
- Entenda o que muda com os decretos de Lula para as big techsPoder360
- Brazil's New Platform Decrees Turn a Court Ruling Into a Standing Compliance RegimePeople of Internet
- Plataformas digitais têm novas regras a partir desta 2ª feiraPoder360
- Brasil: el Gobierno implementa medidas contra las big techLa Nación
- PDL 460/2026Senado Federal do Brasil
- Plataformas digitais têm novas regras a partir desta segunda (20); Jess e Mehero comentamYouTube / programa jornalístico
- Plataformas digitais têm novas regras a partir desta 2° feiraPoder360
- Ransomware Wing — víctimas, grupos y patronesPulse (Kalir.io)
- Decretos que aumentam responsabilidade de big techs entram em vigor, apesar de projetos no CongressoEstadão
- Decretos sobre big techs estão em vigorFolha de Alphaville
- Plataformas digitais tem novas obrigações no Brasil a partir desta segunda-feira, dia 20Rádio Educadora
- Entrada de blog técnica sobre Banana RAT / SHADOW-WATER-063Igor Urraza
- Brasil lidera ataques de ransomware na américa latina em 2026 e expõe falhasLucas Alcaraz
- ANPD formaliza contratação de técnica gerencial com salário de R$ 10,3 milO Tempo
- Decreto que estabelece diretrizes de proteção às mulheres na internet já está em vigorMinistério das Mulheres - Governo Federal do Brasil
- STF ajusta tese sobre responsabilidade civil de plataformas digitaisSMAB Advogados
- Ransomware Tracker - Derp.caDerp.ca
- Especialistas revelam por que o Brasil virou alvo prioritário do ransomwareDireto Notícias
- Qilin Leads Global Ransomware Victim Claims Across ...Mallory.ai
- ANPD abre consulta sobre novas regras para plataformas digitais: o que pode mudar para usuários e empresasAdvemFoco
- 20+ Hijacked Government Websites Became an Attack ChannelAllSec.sh / The Hacker News
- Hijacked Websites: When Trusted Sites Turn DangerousPendergrass Consulting
- Banco Central estuda restringir acesso ao Pix para instituições com falhas de cibersegurançaDestak News Brasil
- PL 4752/2025 - Senado FederalSenado Federal
- Pix com mudanças? Entenda o que BC estuda sobre segurança cibernéticaMetrópoles
- Il ransomware cambia bersaglio e assedia la filiera sanitariaTom's Hardware Italia
- ANPD em 2026: principais regulamentos, consultas públicas e tendênciasLHBM Advogados
- Ataque hacker expõe dados de 500 mil pacientes e leva ANPD a investigar falhas na proteçãoO Hoje
- BC estuda restringir Pix para instituições com falhas de segurançaNC News
- Brazil May Cut Off Pix Access for Cyber-Weak BanksThe Rio Times
- No solo pasa en Europa: estos países restringen las redes sociales para adolescentes en 2026Semana
- Banco Central ameaça tirar Pix de bancos que descumprirem novas regrasFDR
- CVE-2026-56291: RCE no Balbooa Forms com Exploração AtivaDFT Info / JRT Technology Solutions
- CISA Agrega Vulnerabilidades Críticas de Extensiones Joomla iCagenda y Balbooa Forms al catálogo KEVDevel Group
- 'Deepfakes' impulsionam fraudes em contratos e desafiam fintechsFinsiders Brasil
- Vulnerabilidad crítica en Balbooa Forms para JoomlaTechConsulting
- ANPD investiga ataque hacker que atingiu dados de pacientes em AlagoasO Jornal Extra (Alagoas)
- CVE-2026-56291 — Balbooa Forms for Joomla: unauthenticated file-upload RCE exploited as a zero-dayCTI Pilot
- Ataque de ransomware contra o Isac registra vazamento de dados de 500 mil pacientesTI Inside
- CVE-2026-56291: Balbooa Forms Joomla Extension RCESentinelOne
- Banco Central endurece regras do Pix e bancos que não se adequarem podem perder acesso ao sistemaEstado de Minas
- Brasil é epicentro de ransomware em saúde na América LatinaCISO Advisor
- CVE-2026-56291 - Kritische RCE-Lücke in Balbooa FormsCyberwald
- ANPD abre processo contra Isac após ataque hacker expor dados de 500 mil pacientesCyberSec Brazil
- Após ataques hackers, BC quer restrições para instituições frágeisPoder360
- Brasil concentra el 51% de los ataques de ransomwareCiberLATAM
- CVE-2026-56291 - Joomla Extension - balbooa.com - Unauthenticated file upload in Balbooa Forms extension < 2.4.1CVEfeed
- Instituição de saúde que atua no RS é alvo de processo por falhas na proteção de dados de 500 mil pacientesGaúchaZH
- ANPD apura vazamento de dados de 500 mil pacientesPoder360
- ANPD investiga ataque hacker contra organização que administra unidades de saúde em ALCada Minuto
- BC estuda limitar acesso ao Pix e reforçar segurançaDiário do Comércio
- Banco Central reforça arcabouço antifraude e de governança no Pix e no sistema de pagamentosCSMV
- Banco Central planeja mudanças no sistema Pix; entendaDOL (Diário Online)
- O Novo Paradigma do Pix: Banco Central Eleva Risco Cibernético ao Nível de Capital e Liquidez na SupervisãoGazeta Mercantil
- Ataque cibernético vaza dados de 500 mil pacientes e empresa é alvo de investigação federalO Globo
- Marco Legal da Cibersegurança põe cooperativas em alertaBR Cooperativo
- ANPD instaura processo de sanção contra OS por falha na proteção de dados de 500 mil pacientesLegismap
- Elytron aponta alta de ransomware na saúde no BrasilIT Section
- ANPD sanciona a Isac por filtrar 500 mil datos de pacientesLinkedIn (Consejo de Seguridad de la Información y Ciberseguridad)
- Leia a íntegra do projeto que aumenta punição a crimes sexuais on-linePoder360
- Pente-fino no Pix: Banco Central prepara nova fiscalização que pode bloquear recurso de instituições por falhas de segurançaND Mais
- Brasil concentra 51% dos ataques de ransomware ao setor de saúde na América LatinaSaúde Digital News
- Senado aumenta punição a crimes sexuais online contra criançasFolha de Vilhena
- PL 3066/2025Senado Federal
- ¿Qué es el ransomware y cómo proteger tu empresa en 2026?Aufiero Informática
- Fiscalização LGPD 2026: ANPD vira agência reguladoraVisie
- Brasil concentra maior número de ataques de ransomware ao setor de saúde na América LatinaSantotech
- Projeto de Lei nº 2338, de 2023Senado Federal do Brasil
- Brazil's National Data Protection Authority: How regulators investigate and enforce its data protection lawCompliance Week
- BC estuda limitar acesso ao Pix a instituições mais vulneráveis a ataques cibernéticosFolha de S.Paulo
- Radar Semanal de Cibersegurança — 06/jul/2026Defender360
- Debatedores defendem Marco Legal da Cibersegurança como prioridadeSenado Federal
- Brasil é o 3° país mais atacado por ransomware; especialistas explicam o motivoOlhar Digital
- Mapa de vítimas de ransomware no BrasilRansomware.live
- Ataques cibernéticos disparam no Brasil e superam média globalSindpd
- Cyber Snapshot de 13 de Julho de 2026: vazamentos em saúde, governança de IA, e defesa em camadasYouTube - Cyber Snapshot
- Cyber Snapshot de 27 de Julho de 2026: recorde na Patch Tuesday, Perigo na Higiene CibernéticaYouTube - Cyber Snapshot
- IPEN promove workshop internacional sobre planejamento e resposta a incidentes de segurança cibernética em instalações nuclearesIPEN/CNEN
- Banco Central Pode Suspender PIX de Bancos com Falhas de SegurançaPix Fácil
- Fim do Pix? BC mira instituições financeiras que descumprirem exigênciasFDR
- Cortes no orçamento do BC ameaçam segurança e inovação do PixFolha de S.Paulo
- Brasil lidera ataques de ransomware na América Latina em 2026 e expõe falhaslucasalcaraz.com
- Activity Other/BRRansomware.live
- ANPD conclui monitoramento de encarregados de dados e vai avaliar sanção a 21 empresas e órgãos públicosAutoridade Nacional de Proteção de Dados (ANPD)
- Progress on ANPD's enforcement agenda over eight years of the LGPDTozziniFreire Advogados
- ANPD intensifica fiscalização da LGPD e notifica 56 organizações por falhas na proteção de dadosCorreio 24 Horas
- Marco Civil da InternetAutoridade Nacional de Proteção de Dados (ANPD)
- Entram em vigor diretrizes de proteção às mulheres na internet e de enfrentamento da violência em ambiente digitalMinistério da Justiça e Segurança Pública (MJSP)
- Decreto 12.975/2026: prazo de 20 de julho para plataformas digitaisHDPO Advogados
- Susep divulga Manual de Orientações sobre Segurança Cibernética para supervisionadasSuperintendência de Seguros Privados (Susep)
- ANPD e PNUD selecionam consultores para realização de estudos sobre IA, proteção de dados e publicidade digital voltada a crianças e adolescentesAutoridade Nacional de Proteção de Dados (ANPD)
- A ANPD virou agência reguladora. O que muda para o board das empresas?PierSec
- ANPD instaura processo contra a Claro por irregularidades no compartilhamento de dados pessoais de clientes com a SerasaLeonardi Advogados
- ANPD opens proceeding against Claro over irregularities in the sharing of customer personal data with SerasaLeonardi Advogados
- Projeto de Lei para instituir o Marco Legal da CibersegurançaUniversidade Federal de Pelotas (UFPel)
- Projeto de Lei nº 4.752, de 2025Senado Federal
- Senado vai celebrar Dia da Proteção de Dados e terá frente parlamentar de IASenado Federal
- Comissão aprova regras para reforçar investigações de crimes cometidos pela internetA Notícia Certa
- Comissão aprova projeto para incentivar infraestrutura digital e soberania nacionalBom Dia Sorocaba
- Panorama ANPD: 59 atos normativos publicados em julho de 2026Eutropio
- ANPD releases English version of Technology Radar on Artificial Intelligence and Data ProtectionAutoridade Nacional de Proteção de Dados (ANPD)
- Instituto é investigado após vazamento de dados de pacientes na Bahia e outros estadosG1
- Publicación sobre ataque de Section9 ransomware a empresa agrícola brasileiraTweetThreatNews (X)
- ALERTA 56/2026 - Vulnerabilidade crítica com exploração ativa no Joomla JCECTIR Gov / Portal Gov.br
- ALERTA 60/2026 — Vulnerabilidades críticas que afetam o FortiOS e o FortiProxyGabinete de Segurança Institucional - CTIR Gov
- CISA Alerta: Exploração Ativa de VulnerabilidadesCEVIU News
- Security advisory sobre vulnerabilidades ativamente exploradas em Microsoft SharePoint ServerCERT-EU
- Known Exploited Vulnerabilities: Live CISA KEV CatalogSenserva
- Suposto ataque a gateway de pagamento no Brasil: o que se sabe (e o que ainda não se sabe) sobre o caso PagBankVigilant
- Alleged PagBank Breach Exposes 10 Billion TransactionsFemtosec
- Homologação ANATEL Módulos IoT 2026: Wi-Fi, BT, Zigbee e LoRa ...YesCert
- Anatel aperta o cerco à oferta ilegal do serviço de banda largaConvergência Digital
- Agriculture and Food Production — BRransomware.live
