Brazil Cybersecurity Snapshot, Aug. 2026
ANPD tightened penalties, Pix changed antifraud rules, and fraud, ransomware, and leaks rose with a focus on financial services
Key findings
- The month’s biggest signal was regulatory: ANPD fined ByteDance over TikTok, and the Central Bank deepened antifraud controls for Pix and virtual assets.
- Ransomware’s relative weight fell from July, but claims and confirmed cases continued to affect government, health, education, and defense.
- Fraud displaced ransomware as the most visible threat theme, with Pix, deepfakes, fake bank call centers, and attacks on payment processors.
- Financial services faced the highest operational pressure, driven by the mix of fraud, crypto, payments, open finance, and transnational police action.
- Health and government remained highly exposed through leaks and leak-site claims, with SISVISA, LATAM Pass, Mobilemed, and Intranet Gov Brasil among the most visible names.
- Four critical CVEs were mentioned with active exploitation or real impact, requiring patch prioritization for internet-exposed products.
- The comparison with July shows a more diversified attack surface, less dominated by ransomware and more shaped by compliance, identity, and fraud prevention.
Monthly reference modules
These modules are completed automatically with verified dated facts within the period. Each one states its basis and counting criterion so the figures reconcile across modules. They are the recurring month-to-month reading; the analysis that follows develops the cases without repeating this summary.
Indicator window: 76 dated facts in August 2026 · 2 from previous months (comparison framework, not monthly volume). Facts from previous months are used only as a comparison framework in the analysis, never as volume for this period.
Executive monthly summary for Brazil
August 2026 brought Brazil a mix of tougher regulation, data incidents in sensitive sectors, and sustained pressure from banking fraud, with ANPD, the Central Bank and the Federal Police at the center of the agenda. The month’s clearest signal was the R$ 153.7 million fine against ByteDance in the TikTok case, alongside new rules for Pix and virtual assets, while operational risk was concentrated in government, finance, health care and telecommunications.
The month closed with 69 verified events within the analysis window, 17 cases with ransomware or extortion as the primary focus, 9 documented fraud or phishing episodes, and 11 regulatory moves. The dominant threat was classified as unclassified, with 19 of 69 events, reflecting a mix of breaches, regulatory pressure, fraud campaigns and leak site activity without a single dominant pattern.
On the incident front, Brazil saw disclosures and claims of data breaches involving LATAM Pass, Mobilemed, SISVISA, Intranet Gov Brasil, Grupo Rái, ICN and city governments in Espírito Santo and Minas Gerais. Not all of them were confirmed with the same level of evidence, and in several cases the source only records the claim made by the actor or an aggregator, but the accumulation of signals pointed to a broad, cross-sector attack surface, with emphasis on digital services, health care, education and public administration.
The most consistent part of the month was the anti-fraud front. The Central Bank advanced a centralized fraud probability indicator for Pix, plus tracing of subsequent transfers, analysis windows for virtual assets and a 24-hour precautionary hold on certain crypto transactions. In parallel, the Federal Police dismantled banking fraud networks, and regulation kept adding compliance obligations for digital platforms and financial providers.
Monthly national overview in Brazil
Brazil showed high risk pressure in August, not from a single attack type, but from the overlap of fraud, ransomware, leaks, and tighter state controls. The alert level rose because of the number of verified events, the exposure of critical sectors, and the frequency of regulatory moves responding to an abuse environment that is already well established.
The qualitative reading remains high because severity was uneven but steady. There was a major data protection fine, a restructuring of the Pix and cryptoasset framework, a cross-border criminal investigation into bank fraud, and several incidents involving sensitive information in health care, transportation, government, and payment systems. At the same time, the month did not show one campaign that explains all the noise, but several active fronts in parallel.
The regional picture also helps explain the moment. Reports from Check Point, Exame, TI Inside, and Folha placed Brazil among the countries hardest hit by ransomware and with thousands of weekly attacks per organization, although those figures come from telemetry and not confirmed incidents. In that context, the country stands out as one of Latin America's main exposure hubs, with greater tension in finance, government, and digital services.
Brazil period indicators
| Indicator | August 2026 value | Previous month | Change |
|---|---|---|---|
| Verified facts for the period (base for all indicators) | 69 | 64 | +5 |
| Indicator time window | 76 facts dated August 2026, 2 from previous months (comparison frame, not monthly volume) | Same | No change |
| Unclassified incidents (breaches or outages) | 6 | 10 | -4 |
| Cases with ransomware or extortion as the primary focus | 17 | 25 | -8 |
| Non-encrypted exfiltration (simple extortion) | 2 | Not reported | N/A |
| Leak site mention only | 2 | Not reported | N/A |
| Classification could not be determined from the material | 13 | Not reported | N/A |
| Documented fraud or phishing cases | 9 | 0 | +9 |
| Documented regulatory moves | 11 | 13 | -2 |
| Critical CVEs mentioned | 4 | 5 | -1 |
| Sectors with at least one documented fact | 7 | 7 | No change |
| Predominant threat of the month | Unclassified (19 of 69 facts) | Ransomware (25 of 64 facts) | Shift in focus |
| Facts with direct source confirmation | 81% | Not reported | N/A |
| Aggregated telemetry figures excluded from volume | 7 aggregated attempts or blocks, not incidents with confirmed impact | Not reported | N/A |
Relevant incidents in Brazil
ANPD fines ByteDance in the TikTok case
The ANPD fined ByteDance R$ 153.7 million and ordered the deletion of data collected improperly after finding irregularities in the handling of children’s and teenagers’ data. The case cemented the regulator’s role as a central player this month and renewed debate over age verification, platform design, and responsibility for minors’ data.
The penalty was based on five violations of the LGPD and came with specific corrective measures. Among them, the authority required the deletion of data from teenagers whose legal guardians do not regularize the situation within the deadline, and left open the possibility of administrative appeals. The case was also read as a sign of tougher enforcement against large-scale platforms.
LATAM Pass incident reported to the ANPD
LATAM confirmed an unauthorized access incident that affected a limited portion of LATAM Pass members and notified the ANPD. The company said it applied containment and additional cybersecurity measures, while media coverage detailed exposure of personal data, loyalty data and, according to some sources, partial card data.
The case stood out because of the type of data exposed and the potential volume of users, although the company itself kept the exact scope limited. It fit into a month in which sensitive data incidents received high public visibility, but did not all lead to major operational disruption.
SISVISA database exposure
A database linked to the SISVISA system left 102,215 records and about 79 GB of Brazilian health information exposed without authentication. The material included identifiers, tax data, regulatory documents, licensing records and other sensitive files, making it one of the month’s most significant healthcare leaks.
The exposure was discovered by a researcher and later removed from public access, but the lack of a clear official response left questions about how long the exposure lasted and whether third parties accessed it. It was a clear example of availability and confidentiality risk, with no signs of a sophisticated attack.
Attack on Itaguaí Construções Navais
ICN confirmed a ransomware attack that encrypted data in its IT environment. The company operates in the Itaguaí naval complex, and the episode was treated as a significant incident by the defense sector, with coverage linking the case to a possible LockBit 5.0 claim.
The available material shows operational impact through encryption, not just a mention on a leak site. However, the full scope of the intrusion and any exfiltration was not clearly documented, so the most cautious reading is that the event caused confirmed damage, but with only partial technical detail.
Pix instability and Central Bank response
On August 23, the Central Bank reported a temporary instability in Pix, ruled out a cyberattack, and said the service was quickly restored. Although there was no evidence of intrusion, the episode sharpened public attention on operational resilience and on dependence on the instant payments system.
At the same time, the regulator announced and explained a new defense layer for Pix, with a fraud probability score, standardized alerts, automated information sharing and expanded precautionary measures. From a risk perspective, the message was clear, fraud had become a top regulatory front.
Financial fraud and extortion campaign against TAG
TAG, a receivables registrar controlled by Stone, faced a fraud attempt involving about R$ 350 million in card payments. The operation was blocked and did not cause financial loss or data exposure, according to the company and later coverage.
The value of the case lies in the sophistication of the attempt, not in the damage it caused. The scheme included changes to receivables ownership and the use of sector alerts to stop the maneuver, which again shows that financial fraud in Brazil increasingly relies on coordination among platforms, registrars and shared monitoring mechanisms.
Operação Klonen and cross-border banking fraud
The Federal Police dismantled an organization tied to electronic banking fraud, money laundering and asset concealment, in an investigation that began with an attack on a German financial institution. The operation included arrest warrants and asset seizures, and showed the link between digital fraud, crypto assets and laundering structures.
The case matters because it goes beyond Brazil’s borders and shows how the country can serve both as the origin of the operation and as the place where judicial measures are carried out. It also confirms that banking fraud is not limited to social engineering, but can scale into transnational schemes with their own technical and financial infrastructure.
Active Threats and Campaigns in Brazil
Ransomware and simple extortion
There were 17 cases in August where ransomware or extortion was the primary focus, but the source only allowed a clear classification for a minority. In two cases, exfiltration without encryption was documented, in two there was only a mention on a leak site, and in 13 it was not possible to determine the exact impact from the available material.
That split matters because it prevents treating the whole block as if it were the same thing. A site listed by an actor is not the same as a data theft without encryption, or an attack with confirmed downtime. All three modes were present in Brazil, with preliminary signals outnumbering full confirmations.
Grupo Rái and LockBit 5.0
LockBit 5.0 claimed Grupo Rái in early August, and several aggregators showed it as data leaked or as a victim listed on a leak site. The recovered material did not allow a firm confirmation of operational damage, so the case should be read as an extortion claim with partial public evidence.
The significance of the case is not only the company targeted, but also LockBit 5.0's continued visibility in Brazil. This month's coverage again shows that the country remains among the markets most targeted by ransomware operators focused on data publication.
Mobilemed and Kazu
Mobilemed was claimed by Kazu as a victim in the health sector, with accounts that mention exfiltration and a ransom demand, but no official confirmation from the company. Some coverage describes it as an attack with possible broad impact on medical imaging and diagnostics, while other reports only repeat the actor's claim.
The taxonomy matters here. The available evidence supports describing it as a ransomware claim and, in some records, an alleged exfiltration, but not confirmed encryption. For the country report, that means keeping the case in the category of extortion with impact that cannot be verified in detail.
Intranet Gov Brasil and The Gentlemen
Intranet Gov Brasil was listed by The Gentlemen on leak sites and by incident aggregators as a claimed victim. There was no public confirmation from the federal government or from the state-owned companies mentioned in the material, so the case remains a leak site mention without corporate corroboration.
Even so, the claim matters because of the type of asset targeted, a portal and internal network for public services. The appearance of this name alongside other campaigns against municipal entities confirms that the government sector remained in the crosshairs of extortion groups throughout the month.
Fraud and phishing
The month showed a clear expansion in fraud, with nine documented cases and a strong bias toward banking, payments, and impersonation. The fake bank call center, social engineering against bank customers, deepfakes used for identity verification, and the TAG scheme point to the same abuse pattern, exploiting trust, urgency, and automation.
Fraud against crypto assets and payment methods also appeared, with the Central Bank accelerating controls to curb abuse of transfers and the PF disrupting electronic fraud networks. The operational takeaway is that attacks on identity and payment sessions carried more weight than classic intrusion.
APT, hacktivism and critical infrastructure
Brazil did not record a single local APT campaign in the material that dominated the month, but it was affected by the Lazarus context, the Siemens S7 advisory, and the debate over critical infrastructure. Added to that were disinformation lures and public-facing interface campaigns, such as the attempts against Rondônia portals and Flávio Bolsonaro's site.
In energy, water, government, and telecommunications, the risk was more closely tied to exposure and reconnaissance than to confirmed sabotage. The underlying threat was the combination of exposed attack surfaces, outdated critical software, and opportunistic campaigns seeking credentials, remote access, or public visibility.
Critical vulnerabilities with impact in Brazil
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-68820 | Windows Ancillary Function Driver for WinSock (AFD.sys) | Active exploitation, privilege escalation, used as a zero-day in observed campaigns | CTIR Gov.br, Tenable, SecurityWeek |
| CVE-2026-8037 | Progress LoadMaster | Active real-world exploitation, command injection | CTIR Gov.br, SecurityOnline.info, Decryption Digest |
| CVE-2026-34486 | Apache Tomcat | Active exploitation, exposure of sensitive traffic in Apache Tribes clusters | CTIR Gov.br, CISA cited by f4n6 and Cybersecurity News |
| CVE-2026-48907 | Joomla Content Editor (JCE) | Active exploitation, web shells and persistence in institutional sites | Mallory.ai and CTIR Gov.br |
The month's vulnerability readout was limited, but significant. The material identified four critical CVEs, and all four show either active exploitation or direct operational impact. This does not mean there are no other relevant flaws outside the material, only that August's corpus prioritized these four as the verifiable signal.
Regulation and compliance in Brazil
Brazil tightened a regulatory agenda in August focused on data, fraud, and platform oversight. The clearest example was ANPD’s sanction against ByteDance, which showed the regulator is no longer limited to educational warnings and is willing to impose steep fines and specific data-deletion orders.
At the same time, the Central Bank moved ahead with Resolução BCB nº 584, which extends anti-fraud rules to virtual assets and sets a 24-hour precautionary hold for certain transfers. It also introduced authorization deadlines for virtual asset service providers, with a deadline of October 2026 and parts of the framework taking operational effect in January 2027.
In Pix, the regulator deepened its intervention with a centralized fraud-probability score, tracing of the money trail, and additional precautionary measures, including restricting new keys in cases of risk. This regulatory architecture is not cosmetic, because it responds to fraud already observed and to the need to coordinate banks, registries, and payment systems.
ANPD also kept expanding its compliance agenda. It published its semiannual report on the regulatory agenda, reviewed inspection and sanction rules, regulated transparency reporting, and maintained monitoring of platforms and AI tools to protect minors. In parallel, the Senate and the Chamber continued discussing texts on data protection, public security, and algorithmic transparency.
Most Affected Sectors in Brazil
The month hit at least seven sectors, but not evenly. Financial services were hit hardest in terms of both intensity and variety, with banking fraud, Pix, card payments, open finance, crypto assets, and police operations against money laundering networks. Government and public administration remained highly exposed, through both leaks and extortion campaigns and defacement.
Healthcare and pharmaceuticals also stood out. SISVISA, Mobilemed, and the Bahia case involving health data show that health information remains an attractive target, both for its regulatory sensitivity and its value in extortion. The logic is familiar, but the month confirmed that it remains active.
Telecommunications, logistics, and digital services added incidents or risk signals. LATAM, Uber Freight, Vivo, and various platform providers reflected a common pattern, dependence on identities, remote access, customer data, and third-party chains. The surface is fragmented, but the vector repeats.
In energy and utilities, the material did not show confirmed OT incidents in Brazil, but it did include alerts on critical infrastructure, campaigns against Siemens S7 PLCs, and references to sector-specific risk. That is enough to justify heightened vigilance, but not enough to make the vertical a focus of confirmed incidents for the month.
Trends and signals to watch in Brazil
Compared with the previous month, ransomware as the primary focus fell from 25 cases to 17, and unclassified incidents dropped from 10 to 6. At the same time, documented fraud and phishing rose sharply from 0 to 9, while regulatory moves declined from 13 to 11. The main shift was qualitative, the month moved away from being dominated by ransomware and instead combined fraud, regulation, and leaks.
That shift matters because it points to a more diversified visible risk. In July, the narrative was more centered on system hijacking. In August, the agenda moved toward data protection, identity, payments, virtual assets, and platform oversight. Ransomware did not disappear, but it lost relative centrality to other vectors.
Another clear signal is the consolidation of fraud as a cross-cutting problem. The mix of social engineering, deepfakes, fake portals, mule accounts, and attacks on registrars points to a more professional criminal ecosystem. The Central Bank and the PF responded with tougher tools, which will likely drive more behavioral controls and traceability.
On vulnerabilities, the month showed fewer critical CVEs mentioned than in July, from 5 to 4, but each carried real operational weight. The repeated presence of active exploitation and urgent patches in widely used software indicates that technical risk remains heavily concentrated in edge products, web platforms, and identity and access components.
Security recommendations for teams in Brazil
Five priorities stand out. First, banks, fintechs, and PSPs should review anti-fraud controls in Pix, identity checks, transfer monitoring, and detection of account ownership changes or mule accounts. The month showed that fraud is shifting toward automated, coordinated flows, not just isolated scams.
Second, organizations that handle sensitive data, especially in health, education, and government, should strengthen segmentation, backups, and public exposure controls. The SISVISA, Mobilemed, and municipal portal cases show that leak exposure does not depend only on ransomware, but also on weak configurations and accessible repositories.
Third, patch prioritization should be reviewed for the month’s four critical CVEs, with special focus on products exposed to the internet. Apache Tomcat, LoadMaster, Windows AFD, and JCE concentrate the type of exploitation that turns into a real incident fastest when exposure is public.
Fourth, compliance teams should treat the new regulatory wave as a security issue, not only a legal one. ANPD and the Central Bank are pushing controls on transparency, retention, traceability, consent, and reporting, so privacy, fraud, and cybersecurity now operate as one management block.
Fifth, the third-party chain should be reviewed. Several stories this month relied on vendors, registrars, cloud platforms, loyalty services, and third-party software, which makes it necessary to audit access, contracts, logging, and shared response capacity.
FAQ
What changed most between July and August in Brazil: ransomware, fraud, or regulation?
In August, ransomware lost relative weight compared with July, while fraud and phishing cases increased and the number of regulatory moves edged down slightly. The clearest shift was toward payments, identity, and personal data, which becomes clear when the period indicators are read alongside the trends section.
Which sector was most exposed based on confirmed incidents, and why?
The financial sector was the most exposed by the variety of events, followed by government and health. The combination of TAG, Pix, cryptocurrencies, Operação Klonen, LATAM Pass, SISVISA, and Mobilemed shows that pressure came from several fronts, not a single vector, and those fronts touched payments, identity, and sensitive data.
Do the 4 critical CVEs for the month mean there were four incidents in Brazil?
No. They mean that four critical vulnerabilities were mentioned in the material analyzed, several of them with active exploitation, but not that each one produced a separate Brazilian incident. The vulnerabilities table and the limitations section make clear that the absence of more CVEs in the month does not mean there was no regional exposure.
How confirmed was the Intranet Gov Brasil case?
It remained a leak site claim without public confirmation from the Brazilian government or the technical entities cited. That sets it apart from ICN, where an attack with encryption was confirmed, and from other cases where the material allows only a preliminary attribution.
What was the main regulatory signal for banks and fintechs?
The main signal was the tightening of oversight on fraud, Pix, and virtual assets. The Central Bank advanced on fraud probability scoring, money tracing, and precautionary crypto retention, while ANPD kept hardening sanctions and transparency. The two agendas appear separately in the body, but they converge in operational compliance.
Was there activity in Brazilian critical infrastructure without confirmed OT incidents?
Yes. There were alerts and signs of exposure, especially in energy, water, and industrial control, but no confirmed Brazilian OT incident appeared in the material. The risk was documented through international advisories and local coverage, so monitoring must continue even though the month did not register a completed OT operational impact.
Material limitations
This report was built exclusively from the material provided for Brazil in August 2026. The time window for the indicators includes 76 dated events in August 2026 and 2 events from prior months used only as a comparative frame, not as part of the month's volume. No internet or external material was used.
The table indicators are reproduced exactly as provided and describe what happened in the country, not the research process. A zero value, especially for CVEs or comparative categories, means that element did not appear in the material analyzed for the period, not that it did not exist in Brazil or the region.
Aggregated telemetry figures, such as attack attempts, blocks, scans, and weekly vendor averages, were also excluded from the count because they are not incidents with confirmed impact. When those figures are mentioned in the report, they are used only as context and always with the source and measurement window identified.
Primary sources were prioritized, including official agencies, CSIRTs, technical advisories from affected vendors, and regulatory statements. Promotional, sponsored, or low-verifiability sources were excluded from the main narrative as a sole basis for trend analysis, and undated events were not included in the counts. When a story depended only on a leak site or an aggregator, it was treated as an unconfirmed claim.
Sources
- El Banco Central amplía las reglas antifraude a los activos virtuales e instituye una retención cautelar de 24 horasGSGA Advogados
- Resolução BCB nº 584/2026: o novo padrão de compliance para ativos virtuais em fintechs e instituições de pagamentoIMGordiano
- O relógio do BACEN: porque modernização deixou de ser opcionalSolutis
- Brazil's $319B Crypto Market Faces October Licensing DeadlineYahoo Finance
- CertiK Intel3D - A Era das PSAVs e o Novo Padrão de Segurança do BrasilMinuto da Segurança
- BC fecha cerco: empresas cripto sem autorização terão de encerrar operações em outubroBitnoticias
- Pix ganha novas regras de segurança e mais prazo para contestacao de golpesFederação dos Empregados em Estabelecimentos Bancários do Paraná (FEEB-PR)
- Ferramenta amplia o cerco e rastreia a trilha do dinheiroValor Econômico
- Lei diz que dado de saúde de paciente, como diagnósticos e exames, é sensívelO Globo
- BC: Vazam 28 mil chaves Pix da Pefisa, braço financeiro do grupo PernambucanasConvergência Digital
- PL 2006/2026Senado Federal do Brasil
- Telecomunicações | Tecnologia, IA e Infraestruturas Críticas – Junho e Julho 2026Lefosse Advogados
- Ataque cibernético a usina no Reino Unido acende alerta sobre infraestrutura energética conectadaCryptoID
- Ministério do Trabalho e Emprego pretende apurar vazamento dos números do CagedValor Econômico
- Brazil deploys crypto alert system to neutralize cyber threatsBitcoin News
- Na Mídia - ANPD amplia pressão por proteção de dadosNIC.br
- Banco Central do Brasil vai lançar sistema de alerta contra ameaças cripto após ataque de US$ 180 milhõesBingX Flash News
- Insegurança jurídica também é insegurança da informaçãoRevista EcoTour News
- Como o Banco Central vai usar IA para detectar fraude no PixOVALE
- Proposta de Emenda à Constituição n° 18, de 2025Senado Federal do Brasil
- Projeto obriga plataformas a informar de forma simplificada como usam dados pessoaisCâmara dos Deputados
- ALERTA 76/2026GSI / CTIR Gov
- Understanding Brazil's $29.7 Million TikTok Fine Over Children's DataTech Policy Press
- Cibersegurança para concessionárias / PWS CloudPWS Cloud
- ANPD em 2026: fiscalização em escala e uma agenda mais ampla para o ambiente digitalDaniel Advogados
- Ataques cibernéticos: como o sistema financeiro se reforça para lidar com as ameaças virtuaisEstadão
- Projeto obriga plataformas a informar de forma simplificada como usam dados pessoaisBom Dia Sorocaba
- Após bloqueio no Discord e multa recorde ao TikTok, ANPD promete ampliar ofensiva sobre as redes sociaisO Globo
- Brazil fines TikTok owner €25 million for violations in child and adolescent data protectionPlataforma Media
- Multa de R$ 153,7 milhões e dados apagados: entenda em sete pontos a punição da ANPD ao TikTok no BrasilO Globo
- BCB avança em vigilância de corretoras com HypernativeSpaceMoney
- Pix muda para 'seguir' dinheiro em contas laranjas usadas em golpesUOL
- Fraudes digitais e bancárias: o que mudou com a nova leiFSA Brasil
- Bodyshop para Bancos e Fintechs: Tecnologia, Segurança e Compliance em Setores ReguladosMacher Tecnologia
- Vivemos uma epidemia de tentativas de golpes com engenharia social, diz diretor da FebrabanGlobo / Febraban
- PL 3278/26: plataformas digitais terão que simplificar informações de uso de dados ao usuárioMixVale
- Seu rosto como ativo?Capital Digital
- Informações de 251 milhões de brasileiros são vendidas por hacker na internetMix Vale
- CCJ do Senado prevê votação da PEC da Segurança na próxima semanaCiberjornal
- PL 2470/2026 - Atividade LegislativaSenado Federal do Brasil
- Capítulo 6 — Proteção de Dados Pessoais e a LGPDDireito.Legal
- Na era do deepfake, criminosos trocam roubo de senhas por 'clonagem de pessoas' com IA, revela estudo da Certta e NexusNexus / CERTTA
- www.neooftalmo.com.br Ransomware Claim (2026) — What’s Alleged & Am I Affected?Recent Breaches
- Victim: www.neooftalmo.com.br (Krybit)Ransomware.live
- Após sancionar Discord, ANPD aplica multa contra TikTok. Entenda os casosMetrópoles
- Vivo amplia proteção digital com novo SOC Agêntico e parceria com Palo AltoTI Inside
- ALERTA 72/2026Gabinete de Segurança Institucional da Presidência da República (CTIR Gov.br)
- ALERTA 71/2026Gabinete de Segurança Institucional da Presidência da República (CTIR Gov.br)
- Kazu Ransomware Targets Brazil's MobilemedDexpose.io
- IA já está sendo usada para atacar infraestrutura crítica, e o alerta da NSA muda o tom da conversaEurisko
- Por que o Brasil multou o TikTok e suspendeu lives do Discord? Entenda a diferença entre os casosG1
- Brazil fines TikTok owner ByteDance for unlawful processing of teenagers' dataReuters
- ANPD multa dona do TikTok por falhas em tratar dados de crianças e adolescentesAgência Estado / UOL
- Brasil multa TikTok em R$ 153,7 mi por falhar em proteger dados de menoresUOL Tilt
- ANPD estima que TikTok coletou dados de ao menos 20% das crianças do BrasilO Globo
- Tire suas dúvidas sobre a multa aplicada pela ANPD ao TikTok no paísFolha de S.Paulo
- ANPD multa TikTok em R$ 153,7 milhões por falhas na proteção de dados de crianças e adolescentesANPD
- BC prepara sistema de alertas para ameaças envolvendo criptoativosValor Econômico
- Checagem de antecedentes para bancos e fintechs: como estruturar sem violar a LGPDGedanken
- Despacho Decisório nº 27/2026/CGS/SFI – Processo administrativo sancionador contra ByteDance BrasilImprensa Nacional / Diário Oficial da União
- Multas da ANPD: como empresas e advogados se preparamJusDocs
- BC trabalha em revisão de regras de parcerias no open finance até o fim do anoValor Econômico
- PEC da Segurança: relator decide manter texto da Câmara para acelerar aprovação no SenadoO Globo
- 'Deepfake caseiro' dispara e vira nova ameaça de golpes e fraudes financeirasO Globo
- Mobilemed sofre ataque de ransomware com roubo de 23,5 TB de dados, diz grupo KazueAgora
- Bitget cria diretoria de compliance no BrasilSpaceMoney
- Resolução BCB nº 584 amplia controles sobre Criptoativos e reforça mecanismos de prevenção a fraudesCryptoID
- Fatia dos deepfakes em fraudes sobe de 0,1% para 6,5% e inflama desconfiançaInfoMoney
- Marco Legal de Inteligência Artificial só vota depois das eleiçõesABRANET
- ANPD monitora 22 plataformas e apps para proteger menoresUOL Tilt
- Agência federal brasileira multa TikTok em R$ 153,7 milhões por dados de crianças e adolescentesExame
- ANPD multa TikTok em R$ 153,7 milhões por falhas no tratamento de dados de crianças e adolescentesValor Econômico
- ANPD: Consolidação como Agência ReguladoraCescon Barrieu
- Soberania digital em 2026: o que já obriga a sua empresaInterney
- ANPD abre monitoramento sobre 22 plataformas e ferramentas de IA para combater crimes digitaisCorreio do Povo
- Ataque cibernético ligado ao Irã paralisa usina de energia por 4 diasTecmundo
- Resolução BCB 559: Pix passa a exigir auditoria independenteMerc Group
- Galípolo: Não existe essa falsa dicotomia entre segurança e inovaçãoValor
- API Keys From 659 Stripe Merchants Leaked Alongside 688,000 Customer RecordsFinanceFeeds
- PL 2234/2022 - Atividade LegislativaSenado Federal do Brasil
- Filtran claves API de 659 comercios de Stripe y exponen 688.000 registros de clientesDiarioBitcoin
- Data Privacy Brasil participa de evento do STF sobre ECA Digital e apresenta os deveres de prevenção e segurança da leiData Privacy Brasil
- Over 50000 Stripe API Keys Exposed in Public Code RepositoriesGate.com
- Vivo amplía la protección digital de las empresas con nuevo SOC y alianza con Palo Alto NetworksBNamericas
- Ransomware Attacks This Week: 287 Victims Across 53 Groups…Scrutex.ai
- Daily Briefing – Monday, 24th August 2026APJ One
- LM Mobilidade avança em retomada de operações após ataque cibernéticoValor Econômico
- BC avalia mudanças no Pix de madrugada para ampliar combate a fraudesO Globo
- Listado de víctimas atribuidas a KazuIntel and Breaches (X)
- Penalidades do Pix: o que o BC exige e quanto custa falharOpServices
- BC quer reforçar segurança do Pix e mira transações feitas ...ICL Notícias
- A tutela dos dados pessoais do consumidor de crédito nas instituições de pagamentoLacerda Diniz Advogados
- Senado analisa propostas sobre Pix, criptomoedas e segurança financeira digitalRádio Senado
- PL 5092/2026 - Atividade LegislativaSenado Federal do Brasil
- Victim: Brazil Mobilemed: Cloud PACS Platform – kazuRansomware.live
- Qilin Ransomware Claims a Chilean Technology Company as Brazil’s Healthcare Sector Faces Another Ransomware Attack + VideoUnderCode News
- Brazil’s Mobilemed Hit by Ransomware: Healthcare Imaging Services Face Another Dangerous Cybersecurity Test + VideoUnderCode News
- Ransomware Group kazu Hits: Meducar: Telemedicine and Patient Management SystemHookPhish
- Ransomware Group kazu Hits: Brazil Mobilemed: Cloud PACS PlatformHookPhish
- MPV 1319/2025Congresso Nacional do Brasil
- Kazu Ransomware Claims Two More Healthcare Targets, Putting Cloud Medical Systems Under Growing Pressure + VideoUndercode News
- BC admite instabilidade no Pix, mas diz que já foi resolvida; razões ainda estão sendo apuradasO Globo
- Banco Central identifica instabilidade no Pix e descarta ataque cibernéticoTimes Brasil
- Pix tem instabilidade pela manhã e volta ao normal; BC descarta ataqueO Tempo
- Brazil Mobilemed: Cloud PACS PlatformDragons Community
- Захист дітей в інтернеті замість тотальної заборони соцмереж: досліджуємо досвід БразиліїZnayshov
- DPO em incidentes de segurança e vazamentos de dadosMacher Tecnologia
- DPO em incidentes de segurança e vazamentos de dadosMacher Tecnologia
- Weekly Threat Intelligence Report: Late August 2026SecurityOnline.info
- PL 2338/2023 - Senado FederalSenado Federal do Brasil
- PL 2830/2019 - Senado FederalSenado Federal do Brasil
- Ransomware Alert: ICN - Itaguaí Construções Navais listed as LockBit 5.0 victimFalconFeeds.io
- Instrução Normativa BCB nº 770: Análise e ImpactosCadoc.ai
- LockBit 5.0 Compromises Brazilian Defense Contractor ICNDexpose.io
- icnavais.com Ransomware Claim (2026) — What’s Alleged & Am I Affected?Recent Breaches
- Comissão aprova incentivos para desenvolver IA brasileiraPortal do Comércio
- Como a regulação do Banco Central está mudando o mercado de criptomoedas no BrasilMercado Hoje UAI
- LATAM Pass sofre ataque cibernético e expõe dados de clientesMinuto da Segurança
- Alta de 308% nos conteúdos falsos com IA acende alerta da ANPD sobre golpes com deepfakesPortal Information Management (Docmanagement.com.br)
- Regulamentações do ECA Digital e do Marco Civil são debatidas em webinar com MJSP e ANPDGobierno de Brasil (gov.br)
- Banco Central adota novas regras de segurança no Pix para barrar golpesPortal Mais 360
- ANPD avalia como plataformas digitais atuam para prevenir conteúdos criminosos e proteger crianças e mulheres na internetAgência Nacional de Proteção de Dados (ANPD)
- ECA Digital: conheça as regras de proteção de crianças e adolescentes no ambiente onlineAgência Gov
- ECA Digital: conheça as regras de proteção de crianças e adolescentes no ambiente onlineMinistério dos Direitos Humanos e da Cidadania
- Guia Definitivo da LGPD nas Empresas: Passo a passo para adequação completa em 2026DPO.net
- ANPD inicia monitoramento de redes sociais e ferramentas de IA para proteção de crianças, adolescentes e mulheresG1
- Latam Pass Data Breach: Exposed BIN Data Creates Fraud Risk Beyond Partial Card ClaimsTechTimes
- Notícias de privacidade e proteção de dados – agosto 2026DPOExpert
- Ataque a infraestructuras críticas: CISA, FBI, NSA, DOE y EPA alertan por PLC Siemens S7 con IAMoncloa.com
- Stripe Merchant API Keys Leak Exposes 688K Customer RecordsDarknetsearch
- ANPD avalia como plataformas digitais atuam para prevenir conteúdos criminosos e proteger crianças e mulheres na internetANPD
- Sem Marco Legal, ANPD e setores avançam na regulação da IATozziniFreire Advogados
- Pix ganha novas regras contra fraudes e prazo de contestação chega a 80 diasSeu Crédito Digital
- Pix passa por novas mudanças e Banco Central reforça segurança contra fraudesFinanças Guiada
- Digital education and comprehensive protection: challenges in implementing Law No. 15.211/2025 in the school contextRevista Tópicos
- Arquitetura de risco das plataformas e responsabilidade civil preventiva: ANPD e DiscordCarvalho Almeida Advogados
- Mendonça manda PF investigar suspeita de novos vazamentos em caso de LulinhaG1
- Vazamento expõe 659 chaves Stripe e atinge 30 lojistas no BrasilBitnoticias
- Radar de Privacidade HDPO — Edição 17HDPO
- Operação mira quadrilha por fraude de R$ 50 mi contra empresasCorreio Braziliense
- Dados de clientes do programa de fidelidade da Latam são vazadosValor Econômico
- Comissão da Câmara aprova inclusão de inteligência artificial na política nacional de educação digitalAPUFSC
- MPF cobra Discord sobre políticas de proteção a crianças e adolescentesVeja
- BC reforça combate a fraudes de ativos virtuaisCantarino Brasileiro
- Polícia Civil faz operação contra quadrilha de furtos eletrônicos que causaram prejuízo de R$ 50 milhões em empresasG1
- LGPD e cibersegurança ganham destaque na indústria automotivaSegs
- LATAM Pass sofre invasão cibernética e expõe dados de clientesTecmundo
- Latam: dados de clientes são vazadosFolha de S.Paulo
- Latam confirma vazamento limitado de dados de clientes do Latam PassBrasil 247
- Banco Central do Brasil advances to contracting HypernativeHypernative
- BCB publica Manual de Padrões para Iniciação do Pix versão 2.10.0Atlas Público
- LATAM confirma incidente de vazamento de dados de clientesBrazil Stock Guide
- Brazil's regulator shuts down biometric matching for classroom attendanceBiometric Update
- LGPD na saúde em 2026: o ano da virada regulatóriaMedicinasa
- BC endurece regras para bitcoin com retenção de 24 horasSpaceMoney
- BC reforça combate a fraudes com novas regras para transferências de ativos virtuaisMinistério da Fazenda / Conselho de Recursos do Sistema Financeiro Nacional
- Pix consolida liderança nos pagamentos digitais e projeta novas evolucoes ate 2030Ministério da Fazenda / Conselho de Recursos do Sistema Financeiro Nacional
- Data privacy in Brazil: ANPD takes action against tech giantsManageEngine Insights
- Latam diz que falha de segurança expôs nome, endereço e parte do cartão de crédito dos clientesMercado & Eventos
- PL 2114/2026Senado Federal do Brasil
- ANPD publica metodologia de testagem do Sandbox regulatório em inteligência artificial e proteção de dadosANPD
- Pix Mais Rígido: As Regras do Banco Central que Impõem Limites e Aumentam a Segurança em 2026Sindifisco-MS
- Governança de IA no setor financeiro: LGPD e BACENMoov2
- Instrução Normativa BCB nº 769: Análise e ImpactosCadoc.ai
- Incidente de segurança afeta dados de 500 mil pacientes e leva ANPD a instaurar processo sancionador contra organização socialLeonardi Advogados
- Microsoft 365 Service Degradation Disrupts Users Across South AmericaCybersecurity News
- MP investiga vazamento de dados de 290 pacientes na BahiaTribuna da Bahia
- ALERTA 68/2026Gabinete de Segurança Institucional da Presidência da República (CTIR Gov.br)
- The FBI and its partners are warning industrial control system owners and operators about an active cyber threat targeting Siemens S7 Series PLCsFBI Cyber Division
- Cyber / Brief — 22 Aug 2026Cyberverso
- US warns Siemens devices can be hacked amid fears Iran is breaching water plantsReuters
- EUA emitem alerta sobre ataques de hackers a dispositivos da Siemens em infraestruturas críticasValor Econômico
- PL 1099/2025 - Atividade LegislativaSenado Federal do Brasil
- PF desarticula grupo criminoso responsável por invasões a sistemas de instituições financeiras (Operação Pane Seca)Polícia Federal do Brasil
- PF realiza operação contra vazamento de dados de investigaçõesPoder360
- Responsabilidade e dever de supervisão no ecossistema BaaSMigalhas
- Pix fica mais rígido em setembro: confira as principais mudançasTNH1
- Pix fica mais rígido em setembro: confira as principais mudançasQuadra Contabilidade / Portal de notícias empresariais
- Alvo de hackers, Pix precisa de PEC para evoluir, dizem auditoresPoder360
- Banco Central estuda novidades para o Pix, incluindo conexão com outros paísesPortal Zumm
- Banco Central impõe novas regras ao Pix que bancos devem seguir a partir de agostoMixVale
- Após suspender lives do Discord, ANPD avalia incluir mais plataformas em fiscalizaçãoExame
- Guia reúne regras para empresas de ativos digitais se adequarem ao Banco CentralMSN Brasil
- Muitas empresas cripto vão fechar no Brasil, diz ex-vice presidente da BinanceBitnoticias
- Ransomware Alert: Prefeitura Municipal de Arcos reportedly victim of EMPERADORFalconFeeds.io (X)
- Prefeitura Municipal de Arcos — EMPERADOR Ransomware AttackBreach House
- Victim: Prefeitura Municipal de Arcosransomware.live
- Check Point registra 2% das vítimas de ransomware no BrasilIT Section
- Multa ou bloqueio? Advogado diz até onde ANPD pode punir Discord no BrasilCNN Brasil
- Observatório do PL nº 3.102/2022: a tramitação, o que muda na Lei nº 8.691/1993 e a posição da ASCONASCON
- PLP 235/2026Senado Federal do Brasil
- BC vai criar barreira para evitar ofensas no PixASA
- Prefeitura Municipal de Arcos – listing as alleged victim of EmperadorRansomware.live
- Emperador Ransomware Attack on Prefeitura Municipal de ArcosDexpose
- ANPD publica relatório de acompanhamento e execução da agenda regulatória no 1º semestre deste anoANPD
- PL 2338/2023Senado Federal
- O avanço do estelionato em um Brasil cada vez mais digitalFonte Segura / Fórum Brasileiro de Segurança Pública
- Ransomnews: API Keys From 659 Stripe Merchants Leaked Alongside 688,000 Customer RecordsWuBlockchain / Ransomnews
- Há 8 anos, LGPD dá garantias de controle de dados pessoais ao cidadãoSenado Federal
- BC cria retenção cautelar para transferências de ativos virtuaisConsultor Jurídico (ConJur)
- Ciberataques crescem 45% no Brasil em julho, aponta pesquisaExame
- Brazil: National Data Protection Agency closes consultation on implementation framework under Decree No. 12,976 of 2026Digital Policy Alert
- AI Agent Deployment in Brazil: LGPD and BACEN RequirementsTFSF Ventures
- Relatório da Fortinet aponta que ataques cibernéticos no Brasil dobraram em 2026Gazeta Brasil
- Brazil Targets Crypto Fraud With up to 24-Hour Transfer HoldUPay Blog
- Golpe do Desenrola cria sites falsos e cobra Pix com promessa de 99% de descontoAlerta Gov
- PDL 175/2024Senado Federal
- Senado recebe PL 5093/2026 que propõe inclusão digital como direito da pessoa idosaAtlas Público
- Comunicação Empresarial Estratégica: Gestão de Crises, Reputação Digital, Responsabilidade Civil e Governança CorporativaAdministradores.com.br
- Setor financeiro enfrenta uma tentativa de fraude a cada nove segundosSindicato dos Bancários de Cascavel e Região
- PL 5093/2026 - Atividade LegislativaSenado Federal
- Brazil's Data Protection Agency Faces Landmark Test on Kids and Facial RecognitionTech Policy Press
- PIX MUDA EM 1º DE SETEMBRO: VEJA AS NOVAS ...Redefonte News
- Police bust cybercrime ring accused of stealing €30 million ...HelpNetSecurity
- Infraestrutura bancária se prepara para a era da IA e dos serviços em nuvemClaro Próximo Nível
- Brasil combate el fraude con criptomonedas con una retención de transferencias de hasta 24 horasUPay Blog (español)
- Die Cyberangriffe der KW33/2026 im ÜberblickComputerWeekly (edición alemana)
- MED 2.0 amplia rastreamento de dinheiro desviado em golpes via Pix e pode aumentar chances de recuperaçãoSão José Urgente
- Registradora ligada à Stone consegue evitar fraude de R$ 350 milhõesValor Econômico
- Tentativa de fraude em empresa da Stone tenta desviar R$ 350 milhões em pagamentos de cartãoFolha de S.Paulo
- Hackers reivindicam ataque e Uber Freight apura violação de dadosMixVale
- Stone's TAG targeted in attempted R$350m receivables fraudValor International
- Regulação cripto amadurece após casos FTX e 3ACSpaceMoney
- Registradora da Stone identifica fraude de R$ 350 milhõesVero Notícias
- Instrução Normativa BCB nº 767/2026 altera prazos de vigência do ...Eutrop.io
- Caso Discord: até onde pode ir a ANPD na aplicação do ECA DigitalJOTA
- O que muda nas redes sociais com as novas regras da ECA DigitalPortal do Holanda
- Novas Regras do Pix: o Que Muda em Setembro de 2026Adriano Freire Blog
- Oito anos de LGPD. O que aprendemos até agora?LHLaw
- LGPD completa oito anos com ANPD mais forte e pressão sobre empresasLexLegal
- 8 anos da LGPD e o que ainda vem pela frenteTozziniFreire
- Pix vai ter indicador de probabilidade de fraude, anuncia BCASA
- Ataque informático ao Commerzbank resulta na detenção de quatro suspeitos no BrasilTugaTech
- ANPD suspende o uso de reconhecimento facial em escolas públicas do ParanáData Privacy Brasil
- Ataque cibernético atinge sistemas da ICN em ItaguaíJornal Atual
- Check Point registra alta de 45% nos ciberataques no BrasilIT Section
- BC amplia prevenção de fraude sem uniformizar controle sobre ativosConsultor Jurídico (ConJur)
- Resolução BCB nº 584 amplia controles sobre Criptoativos e reforça mecanismos de prevenção a fraudesCryptoid
- Juiz afasta responsabilidade da Caixa por golpe do falso advogadoMigalhas
- Investigation of banking hack leads to arrests in Germany, BrazilThe Record
- Pix ganha novas regras de segurança; fique por dentro!CBN Vitória
- FICCO/RO desarticula esquema de fraudes eletrônicas contra instituições financeiras (Operação Ouroboros)Polícia Federal do Brasil
- ANPD suspende lives no DiscordData Privacy Brasil
- 5ª edição da Reunião do Comitê Nacional de Segurança de Infraestruturas CríticasGabinete de Segurança Institucional da Presidência da República
- Ransomware attacks reach highest volume in the last 12 months.TI Inside
- PF mira grupo suspeito de desviar R$ 180 milhões de instituição financeira alemã após ataque cibernéticoG1
- Quadrilha invade sistema de banco e exige 10 bitcoins para não vazar dadosCorreio Braziliense
- Banco Central avalia novas ações antifraude via PixRevista Amanhã
- Brazil: ANPD regulates Digital ECA transparency reportsBaker McKenzie
- Nova era cripto no Brasil: compliance e capital em focoSpaceMoney
- 5ª edição da Reunião do Comitê Nacional de Segurança de Infraestruturas CríticasGabinete de Segurança Institucional da Presidência da República (GSI)
- Uso de reconhecimento facial para registrar presença de alunos é suspenso em escolas do ParanáBrasil de Fato
- PF deflagra operação contra fraudes bancárias eletrônicas e lavagem de dinheiro (Operação Klonen)Polícia Federal do Brasil
- ANPD tem poder para fiscalizar Discord, mas competências ainda são discutíveis, dizem especialistasFolha de S.Paulo
- Lazarus mira setor de defesa e aeroespacial no Brasil com zero-day do WindowsCyberSec Brazil
- Lei Geral de Cibersegurança amplia desafios para o setor financeiroCryptoID
- Relatório aponta prazo de 30 de outubro para mercado cripto brasileiro e destaca novo padrão de comprovação regulatóriafincatch.com.br
- BCY-ADV-2026-021 — Apache Tomcat CVE-2026-34486Barr Cyber
- Nota pública sobre a determinação da suspensão da funcionalidade de lives no Discord por parte da ANPDData Privacy Brasil
- Alerta Cibernético | KzarkaKzarka
- Banco Central reforça combate a fraudes com novas regras para transferências de ativos virtuaisAgência Gov (Governo Federal do Brasil)
- Brazil agency orders Discord platform to suspend livestreaming over child safety concernsReuters
- Brazil gives Discord 3 days to halt Go Live for all local usersPPC Land
- Novo marco regulatório do Banco Central: Paulo de Matos Junior examina apetite institucional por criptoativosBluestudio / Estadão
- ABToken lança autorregulação cripto e prepara treinamento para a Polícia FederalTradingView / Cointelegraph Brasil
- ECA digital encorpou campo de fiscalização da ANDPG1
- ABToken cria autorregulação e treinará Polícia FederalSpaceMoney
- Plataformas digitais acessadas por crianças e adolescentes precisam publicar relatório de transparência até 17 de setembroANPD
- La sofisticación de "The Gentlemen": Kaspersky alerta sobre ransomware con backdoors a medida que impacta LatamTecknow News
- Brazil: ANPD regulates Digital ECA transparency reportsBaker McKenzie / Ethics.ai
- Fortinet: tentativas de ciberataques caem 20% no primeiro trimestre de 2026Mobile Time
- GDPR, LGPD e CCPA em 2026: Guia Completo de ...SecurePrivacy.ai
- ANPD suspende transmissões ao vivo do Discord no BrasilG1
- Brasil registra quase 250 bilhões de ataques cibernéticos até julhoCorreio Braziliense
- ANPD amplia estrutura para fiscalizar IA, biometria e proteção de criançasCanaltech
- Comissão de Ciência e Tecnologia aprova parecer sobre PL que regulamenta uso de IA na segurança públicaAtlas Público
- Custo de Vazamento de Dados no Brasil sob a LGPDNextGuard Insurance
- Proteção a crianças: ANPD suspende lives no DiscordTV Brasil
- Novas regras do Banco Central, PIX e Drex elevam a ciberseguranca financeiraEstado de Minas
- CCTI aprova parecer do PL 6706/2025 que cria auditoria algorítmica preventiva em sistemas de IAAtlas Público
- Em medida preventiva, ANPD determina que Discord suspenda transmissões ao vivo no BrasilGov.br ANPD
- Brazil Brings Crypto Under Central Bank Supervision: The New ...Bitzo
- Virtual asset fraud prevention: what BCB Resolution 584/2026 changes in BrazilUnblockpay
- Discord suspenso pela ANPD: veja o que muda e riscos de ...G1
- Vigilância da ANPD sobre IA e biometria é ampliada no BrasilSpaceMoney
- Pacific News #300: O Grito do PovoPacificSec
- O Discord foi banido? Veja 10 perguntas e respostas sobre a decisão da ANPD que afeta a rede no BrasilO Globo
- El INCIBE-CERT alerta de 421 vulnerabilidades Microsoft; una ya está siendo explotada de forma activaMoncloa.com / INCIBE-CERT
- Discord: ANPD não está atualizada para tratar o ECA Digital, diz professorCNN Brasil
- Artigo 50 do AI Act: Transparência para Chatbots e Deepfakes em 2026SecurePrivacy.ai
- Uber Freight reportedly investigating after hacking group claims data breachTechCrunch
- ANPD pode multar Discord em até R$ 50 mi por cada falha em segurançaPoder360
- Banco Central quer usar IA para barrar ameaças no PixSpaceMoney
- Portaria GABPR/ANPD nº 553, de 10-08-2026LegisMap
- ANPD esclarece relatórios de transparência do ECA DigitalTrench Rossi Watanabe
- Governança de IA no Atendimento: LGPD e Decisões ...PortalCustomer
- ECA Digital 2026: 7 regras que as redes terão de seguir para proteger menoresTechtudo
- Entenda quando os bancos são responsaveis por fraudesBRA1
- La sofisticación de "The Gentlemen": Kaspersky alerta sobre ransomware con backdoors a medida que impacta LatamTecknow News
- A comprehensive analysis of the BCB VASP licensing regimeAying / Certik analysis
- Blockchain e fintechs no Brasil: criação de valor, governança e risco em infraestruturas financeiras programáveisRevista Tópicos
- Banco Central redefine as regras dos criptoativosTJS Auditores
- Virtual asset fraud prevention: what BCB Resolution 584/2026 changes in BrazilUnblockpay
- resolução bcb nº 584, de 07.08.2026 - Leis e NormasLegismap
- Regulação de Ativos Virtuais: BCB 584/2026 no Combate à EvasãoContábeis
- ANPD Issues Guidelines on the Publication of Transparency ReportsLicks Legal
- DESPACHO DECISÓRIO CD/ANPD Nº 122/2026 (DOU DE 11.08.2026)Legismap
- IA: Fraudes cognitivas e colapso de confiança no ecossistema de pagamentosJundiaí Agora
- When crime goes digital: Lessons from Brazil's 2026 ...BioCatch
- Sites de quatro Câmaras do ES são alvo de ataque hackerFolha Vitória
- Como golpistas fazem vítimas no golpe da falsa central bancáriaG1 (Globo)
- Shopping de BH sofre ataque virtual e tem dados pessoais críticos expostosDiário do Comércio
- CVE-2026-8037: Injeção Crítica no LoadMaster — Exploração AtivaDFT INFORMATICA
- CVE-2026-8037 LoadMaster: CISA KEV Root RCE, Patch ...Decryption Digest
- August 2026 Patch Tuesday: Microsoft Fixes 421 CVEs, One Exploited Zero-DaySecurityWeek
- August 2026 Microsoft Patch TuesdayTenable
- Expert CVE Analysis: Patch Tuesday August 2026Automox
- Uber Freight says its investigating cyber incident following hacker claimsReuters
- Uber Freight investigating data security incident after Helix claims breachSC World
- A estratégia do Banco Central para levar o Pix para outros paísesVeja
- CertiK Intel3D PSAV and the New Brazil Security StandardCertiK
- Weekly CISA KEV Updates: 10 August 2026HackerStorm
- Weekly CVE Report: 6 Actively Exploited Flaws and 1877 New CVEsSecurityOnline.info
- Intranet Gov Brasil Data Breach in 2026Breachsense
- Pix ganha novas regras de segurança e 80 dias para contestaçõesCantarinobrasileiro
- LGPD em 2026: a fase pedagógica da ANPD acabouMD2Tech
- VASP Authorisation BrazilGlobal Law Experts
- Brazil's October Crypto Deadline Signals a New Era of ComplianceCryptowisser
- Brazil Crypto Regulation MonitorCryptoassets.gi
- BC destaca oito itens na agenda de segurança do Pix em relatórioFolha de Pernambuco
- Deputada apresenta projeto para anular bloqueio de 24h no envio de criptomoedasPortal do Bitcoin
- Banco Central avalia medidas para coibir xingamentos e ameaças em campo de mensagem do PixTribuna do Sertão
- DIREWOLF Ransomware Gang: 10 Victims Posted in 24 HoursSecurityArsenal
- Esforço concentrado do Congresso precisa ter Marco Legal de Cibersegurança na agendaConvergência Digital
- BC avalia medidas para coibir xingamentos e ameaças em campo de mensagem do PixO Globo
- cesmac.edu.br Listed by krybit Ransomware GroupGalaxyWarden
- Multicloud para bancos: o que é, vantagens e regulaçãoTopaz Evolution
- THEGENTLEMEN Ransomware Gang: 25 New Victims Posted, Sector Targeting Analysis and Detection RulesSecurity Arsenal
- BC destaca oito itens na agenda de segurança do Pix em relatórioPortal do Holanda
- Ataque cibernético paralisa sistemas da ICN em ItaguaíJornal Atual
- IA coloca Brasil no alvo de onda de sequestros de sistemas de empresasFolha de S.Paulo
- Brazil to tighten crypto fraud controls with new 24-hour wait on transfers to self-custody wallets or offshore firmsThe Block
- CVE-2026-68820 — CVSS 7.0, HIGHCVE Security
- Latin America's public bodies keep appearing on leak sitesIntelFusions
- ANPD abre processo contra Discord por caso de adolescente de 13 anosPoder360
- Post sobre 83 nuevas víctimas de ransomware, incluyendo Intranet Gov BrasilIntel and Breaches
- CVE-2026-68820 | Microsoft Windows AFD.sys VulnerabilityUpGuard
- CVE-2026-8037 Progress LoadMaster Command Injection Under Active ExploitationSecurityArsenal
- Golpistas usam programas do governo como isca para fraudes na internetBand
- Victim: Intranet Gov Brasil - Ransomware.liveRansomware.live
- Alerta Máximo: Ransomware e Golpes em Alta no Início de Agosto 2026Kzarka
- Invasão hacker em prefeituras do ES: o que se sabe?ES Hoje
- Ransomware Group thegentlemen Hits: Intranet Gov BrasilHookPhish
- Intranet Gov Brasil Listed by The Gentlemen Ransomware GroupGalaxy Warden
- O que esperar dos esforços concentrados no CongressoTELETIME News
- ALERTA: Anúncios e e-mails falsos são usados em golpes contra quem procura renegociar dívidasgov.br (Ministério da Fazenda)
- Resolução BCB Nº 584 DE 07/08/2026 - FederalLegisWeb
- Apache Tomcat Encryption Vulnerability Actively ExploitedCybersecurity News
- ANPD instaura processo de fiscalização contra o Discord para apurar falhas na proteção de crianças e adolescentesANPD
- ANPD abre investigação que pode levar à suspensão do Discord no BrasilUOL Tilt
- Intranet Gov Brasil Listed by thegentlemen Ransomware GroupGalaxyWarden
- PF investiga suspeita de fraudes em inscrições no CPFPortal Gov.br
- CVE-2026-8037: Patch Progress LoadMaster After CISA KEVWindowsForum
- Alya Construtora Listed by ransomhouse Ransomware GroupGalaxyWarden
- Vazamento de dados do Sistema de Saúde: Bahia entre os expostosBahia Notícias
- Exposed SISVISA Database Leaks 102,000 Brazilian Health Surveillance RecordsSecurity Affairs
- Nova lei amplia medidas de combate à violência sexual contra crianças e adolescentes no ambiente digitalMinistério da Justiça e Segurança Pública do Brasil
- Lula sanciona lei que aumenta combate à violência contra crianças e adolescentes na internetRádio Itatiaia
- Lei que aumenta punição a crimes digitais contra crianças é sancionadaAgência Brasil
- Estatísticas de incidentes no Brasil: os números de 2026OpServices
- Lula sanciona projeto que aumenta penas para crimes cometidos contra crianças e adolescentes na internetG1
- Governo Lula endurece penas de crimes digitais contra criançasPoder360
- Data leaks : 10 fuites de données majeures du 13 août 2026 (dont Meta)Dcod.ch
- Banca y ciberseguridad:Inteligencia artificial no supervisada: la tecnología que aprende por sí sola para combatir el fraude interno en el sector financieroTrendTIC
- Pesquisador de segurança descobre banco de dados desprotegido no setor SaúdeComputer Weekly Brasil
- ALERTA 67/2026Gabinete de Segurança Institucional da Presidência da República (CTIR Gov.br)
- CVE-2026-34486 Apache Tomcatf4n6
- CCT debate regulamentação de data centers para inteligência artificial – Audiência pública sobre PL 3.018/2024Senado Federal do Brasil / TV Senado
- 100K+ sensitive documents exposed in Brazilian health surveillance platform breachIT Nerd Blog
- LockBit 5.0 Strikes Brazilian Communications Leader Grupo RáiDexpose.io
- rai.com.br Listed by Lockbit5 Ransomware GroupGalaxyWarden
- rai.com.br data breach — Lockbit5 ransomware leak (2026)Darkfield / Orizon One
- Victim: rai.com.br – lockbit5Ransomware.live (pro)
- CVE Weekly Roundup: July 27 – August 2, 2026SecurityOnline.info
- PREVENTIVE ALERT: ALLEGED DATA COMPROMISE AND EXFILTRATION UNDER ASSESSMENT — HEALTHCARE/HOSPITAL SECTOR (BRAZIL / HOSPITAL DI CAMP)VECERTRadar (X)
- Vítimas de golpes bancários têm mais chances de recuperar o dinheiro perdido; entenda o que mudouCorreio dos Municípios-AL
- Fraudes financeiras no Brasil: o novo perfil dos ataquesEvertec Trends
- OpenAI descobre mais casos em que sua IA escapou de isolamento, diz agênciaG1
- El fallo de la IA autónoma: un agente de OpenAI logra vulnerar cuatro plataformas tecnológicasInfobae Brasil
- ‘Hacker’ autônomo: como IA da OpenAI 'invadiu' várias plataformas e por que isso preocupa analistas e empresasO Globo
- Data Privacy Brasil expande Assembleia e institui nova diretoria – A transformação da ANPDData Privacy Brasil
- ANPD prepara concurso para 50 especialistas — banca em definiçãoMeu Preparatório
- ANPD conclui monitoramento de encarregados e avança para possível aplicação de sançõesDNA Law
- Deadlock over key appointments unlikely to constrain Brazil's privacy watchdogMLex
- Facções aplicam golpes digitais usando programas do governoCarta de Notícias
- CISA Urges Water Sector to Protect OT After Coordinated Attacks on PLCsSecurityWeek
- CISA alerta para ataques a PLCs expostos no setor de águaiMasters
- Lobby das big techs reduz chances de votação de PL dos mercados digitais antes das eleições, avalia governoCONTEE
- Modelos da OpenAI "rebeldes" expõem os riscos da confiança excessiva na IAEstadão
- ANPD é a primeira da América do Sul a integrar rede internacional de agências de segurança no ambiente digitalConvergência Digital
- IA da OpenAI invadiu outra empresa antes de ataque 'sem ...G1
- Prompt Injection Judicial: el caso que anticipa los nuevos riesgos legales de la IAECIJA
- ANA e ANPD firmam Acordo de Cooperação Técnica para proteção de dados pessoais nos setores de recursos hídricos e saneamento básicoAgência Nacional de Águas e Saneamento Básico (ANA)
- OpenAI revela que ataque à IA atingiu mais alvos do que se sabia; entenda falha de segurançaBBC News Brasil
- Brazil ransomware victim mapransomware.live
- Infraestructura gubernamental comprometida: ANY.RUN descubre campaña PhantomEnigmaQ2B Studio
- IA da OpenAI escapa de teste controlado e invade plataforma: o que muda para empresas e usuáriosÉpoca Negócios
- Caso Discord: até onde pode ir a ANPD na aplicação do ECA digitalJOTA
- Group: Global Secret GroupRansomware.live
- Banco Central mira IA para travar fraude no Pix em tempo realO Agente Financeiro
- Banco Central prepara mudanças no Pix para reforçar segurançaContabilidade Cidadã
- Autenticación Fuerte y Biometría: Seguridad sin Fricción en LATAMWAU
- Ataques cibernéticos crescem 44% no Brasil; IA soberana ganha espaço como estratégia de defesaTI Inside
- Brasil vira epicentro de ataques cibernéticos na América ...Sindpd-SP
- Seis em cada dez empresas sofreram ataques cibernéticosEstadão Blue Studio
- Ataques de ransomware fazem 26 vítimas de sequestro e extorsão de dados em julhoTI Inside
- Municipal Portals and Subdomains of Brazil's Rondônia State Targeted in Hacktivist Defacement CampaignBrinztech
- Site de Flávio sofre mais de 3.000 tentativas de invasão em oito diasFolha de S.Paulo
- Seminário de Segurança Cibernética reforça importância da proteção da informação na CNENCNEN
- Tele.Síntese reúne autoridades em evento de cibersegurançaTele.Síntese
- Хищение €30 млн через уязвимость в немецком банке: аресты в БразилииTechora
- July 2026 Cyber Threats Surge: Ransomware Attacks Double Year Over Year as GenAI Data Exposure WidensCheck Point Research
- Fortinet Cybersecurity Summit Brasil 2026 em SPSecureway
- Campanha de Flávio Bolsonaro relata 3,2 mil tentativas de invasão a site em oito diasMuita Informação
- Fraude na filiação impede Flávio Bolsonaro de registrar candidatura à PresidênciaO Globo
- TSE lança cartilha sobre uso 'responsável' de IA por campanhas em meio a dúvidas sobre deepfake eleitoralO Globo
- 'Desacreditar o sistema de votação é desconvidar o eleitor a comparecer às urnas', diz presidente do TSEG1
- Cibercriminosos usam falsas oportunidades de emprego para aplicar golpes e invadir empresasTecmundo
- Lockbit5Ransomware.live
- Victim: rai.com.brRansomware.live
- Lockbit5Ransomlook
- Lazarus Exploits Windows Zero-Day to Gain SYSTEM PrivilegesThe Hacker News
- Lazarus Group Hacked Defense Workers With Windows Kernel Zero-Day for Five WeeksTechTimes
- Golpistas avançam do roubo de senhas para o uso de IA para clonar pessoas no Brasil, revela estudoG1
- 0wnzs3c Date: 2026-08-09 Distribution Platform: MediaFire (TJMT .zip)VECERTRadar (X/Twitter)
- ANPD publica relatório de acompanhamento e execução da agenda regulatória do 1º semestre deste anoAgência Nacional de Proteção de Dados (ANPD)
- ANPD finaliza fiscalização de encarregados de dados e pode instaurar processos sancionadores contra 21 entidadesLeonardi Advogados
- Novas regras e o impacto da LGPD nas empresasWSVP
- Câmara avança em regulação de inteligência artificial com foco na proteção de dados e custos para empresasMixVale
- Parlamentares destacam avanços na legislação sobre proteção de dadosSenado Federal
- ECA Digital: agosto abre a etapa II da fiscalização da ANPDHDPO
- ANPD amplia fiscalização de plataformas e IAMacher Tecnologia
- uva.edu.br Listed by L Group Ransomware GroupGalaxyWarden
- Direwolf ransomware reportedly targeted Chat Jurídico in BrazilTweetThreatNews
- Active Exploitation of Joomla JCE Flaw Leads to Webshells on ...Mallory.ai
- CISA Flags Six Actively Exploited NetScaler, SQL Server ...Mallory.ai
- Patch Tuesday Agosto 2026: Proteja Infraestruturas MicrosoftIBSEC
- ANPD multa TikTok em R$ 153,7 milhões por falhas na proteção de menoresG1
- TikTok leva multa inédita no Brasil: o que causou a decisão? E o que muda? Veja perguntas e respostasG1
- Controladora do TikTok, ByteDance é multada em R$ 153,7 milhões pela ANPDValor Econômico
- Multa da ANPD se refere a práticas de 2021 e não reflete o plano de 2025, afirma TikTokValor Econômico
- Brazilian Agency Fines TikTok $30 million for Failures in Protecting Childrens and Teenagers DataFolha de S.Paulo
- Brasil multó a TikTok por casi 30 millones de dólares por fallos en la protección de datos de menoresInfobae
- Resolução BCB N° 584 | Banco CentralOkai
- BC reforça combate a fraudes com novas regras para transferências de ativos virtuaisMinistério da Fazenda / Governo Federal do Brasil
- BC publica norma de retenção de stablecoins por 24 horas; setor cripto se pronunciaExame
