Brazil: Cybersecurity Situation, September 2026
Brazil ended September with more incidents, ransomware, and AI-enabled fraud; the focus was judicial
Key findings
- Brazil ended September with 73 verified events, 21 unclassified incidents, and 15 cases with ransomware or extortion as the primary focus, with a clear predominance of operational incidents.
- The month’s most serious cases were concentrated in the public judicial sector, with TJMT down and BRBJUS affected by a reported diversion of R$ 43 million.
- Pix and identity fraud remained the main financial vector, now under greater pressure from deepfakes, voice cloning, and automated suspicion flags.
- The Central Bank and ANPD increased requirements for traceability, reporting, and oversight, especially for virtual assets, digital platforms, and the Pix arrangement.
- The critical CVEs mentioned during the month affected email, remote access, firewall, identity, and self-managed software, with several KEV notices and active exploitation.
- The SEO poisoning campaign against .gov.br domains showed that public infrastructure is also used as a vector for monetization and trust manipulation.
- September’s picture is one of high risk due to the accumulation of incidents, extortion pressure, synthetic fraud, and simultaneous regulatory tightening.
Reference monthly modules
These modules are completed automatically using verified dated facts within the period. Each one states its source basis and counting method so the figures reconcile across modules. They are the recurring month-to-month readout, and the analysis that follows expands on the cases without repeating this summary.
Indicator window: 76 dated facts in September 2026 · 1 from prior months (comparative context, not monthly volume) · 2 without confirmed dates (excluded from the indicators). Facts from prior months are used only as comparative context in the analysis, never as volume for this period.
Executive summary for the month in Brazil
Brazil closed September 2026 with a mix of operational incidents, extortion campaigns, AI-supported fraud, and tighter regulation that reshaped priorities across the financial system and data protection. Across 73 verified events during the period, incidents were the main focus, with 21 cases, followed by 15 episodes where ransomware or extortion was the primary theme, 6 documented fraud or phishing cases, 7 regulatory moves, and 6 critical CVEs mentioned.
The month produced two high-impact breaches or disruptions in the judicial public sector. The Mato Grosso Court of Justice suspended deadlines, hearings, and sessions after taking its systems offline because of a security incident, with credential access and password resets. At the same time, BRBJUS, the platform used for judicial deposits in Bahia, suffered an outage that led to a reported diversion of R$ 43 million and forced partial, then full restoration, with additional controls and an ongoing review.
On the financial front, the Central Bank issued BCB Resolutions 587, 588, and 589, which strengthened how fraud flags are handled in Pix, expanded reporting to Coaf on transfers involving self-custodied wallets, and set restrictions for dealing with unauthorized counterparties. The regulatory tightening unfolded alongside a wave of increasingly synthetic digital fraud, with deepfakes, voice cloning, and credential theft fueling campaigns against banks, e-commerce operations, and payment systems.
The risk picture for Brazil this month is high. Not because of a single large cross-sector intrusion, but because of the accumulation of confirmed incidents in justice, finance, transport, and health, along with active exploitation of critical vulnerabilities and a fraud surface that keeps expanding. The material also shows sustained pressure on technology vendors, digital platforms, and agencies handling sensitive data, with the public and financial sectors absorbing much of the impact.
National snapshot for the month in Brazil
Brazil saw an unusual concentration of operational and extortion incidents in September, with direct impact on sensitive services, while the financial regulator and the data authority continued closing regulatory gaps. The dominant trend was incidents, not informational noise. Judicial systems went offline, a court deposits platform was affected, a transport incident potentially exposed data, and a sustained wave of financial fraud and synthetic identity abuse continued.
The severity observed can be explained by three tracks moving in parallel. First was the operational track, with TJMT and BRBJUS as the most visible cases. Second was the fraud track, where Pix, e-commerce and facial biometrics concentrated identity abuse, altered QR codes and unauthorized payments. Third was the institutional track, with ANPD expanding oversight and the Central Bank rewriting rules for virtual assets and the Pix arrangement.
The regional signal was also intense. Brazil continued to appear as the main Latin American target in several reports, both for attack volume and for the centrality of its financial system and public agencies. In that context, the month exposed not only concrete victims, but a pattern of sustained pressure on critical infrastructure, personal data and payment channels.
The comparison with the previous month reinforces that reading. Unclassified incidents increased, documented fraud and phishing declined, and regulatory moves were reduced, but the number of critical CVEs mentioned went up. That shift does not point to less risk, but to a rebalancing, more operational impact and more technical exposure within the same monthly window.
Period indicators in Brazil
| Indicator | September 2026 | August 2026 | Change |
|---|---|---|---|
| Verified events in the period | 73 | 69 | +4 |
| Time window for the indicators | 76 events dated in September 2026 | 1 from prior months, 2 without confirmed date | Comparative frame, not monthly volume |
| Uncategorized incidents, breaches or outages | 21 | 6 | +15 |
| Cases with ransomware or extortion as the primary focus | 15 | 17 | -2 |
| Confirmed asset encryption | 1 | n/a | n/a |
| Leak site mention only | 3 | n/a | n/a |
| Unclear classification based on available material | 11 | n/a | n/a |
| Documented fraud or phishing cases | 6 | 9 | -3 |
| Documented regulatory actions | 7 | 11 | -4 |
| Critical CVEs mentioned | 6 | 4 | +2 |
| Sectors with at least one documented event | 7 | 7 | No change |
| Predominant threat of the month | Incidents (21 of 73 events) | Unclassified (19 of 69 events) | Change in dominance |
| Events with direct source confirmation | 74% | n/a | n/a |
| Aggregated telemetry figures excluded from the volume | 3 | n/a | Not incidents with confirmed impact |
Relevant incidents in Brazil
Mato Grosso Court, system outage and credential breach
The Tribunal de Justiça de Mato Grosso was the clearest case of operational disruption in Brazil’s public sector this month. The court took its systems offline, suspended procedural deadlines, hearings, and trial sessions, and later confirmed that user network credentials had been accessed during the incident. Recovery was gradual, with password resets and technical testing before a partial return.
The available material does not allow the initial vector to be identified precisely, but it does show that the impact was real and sustained. The outage affected Processo Judicial Eletrônico and other institutional systems, and the court ultimately brought in the Federal Police and the Civil Police. Operationally, the case fits as a breach with confirmed service disruption.
BRBJUS and Banco de Brasília, fund diversion in court deposits
The second most significant incident affected BRBJUS, the platform used to manage judicial deposits in Bahia. Available coverage reported a diversion of R$ 43 million and partial, then full, service unavailability, with staggered restorations and additional controls. The TJBA clarified that the affected environment was external to the court and administered by BRB.
Here, the material does allow for both financial and operational impact. The issue was not limited to an extortion claim or a mention on a leak site, but to a service outage with concrete consequences for judicial deposits. The subsequent coordination between the court and the bank to restore the environment was also documented.
Viação Águia Branca, ticketing incident
Viação Águia Branca reported a cybersecurity incident on its official ticket sales sites and said 7.883 customers may have had their data exposed. The company said the issue was contained the same day, did not affect the app or the Zap Passagens channel, and did not alter issued tickets or travel data.
The case falls into the category of a limited breach, although with reputational and compliance impact. The material does not confirm exfiltration or specific techniques, but it does confirm notice to the ANPD and individual communication to potentially affected users.
CAPES, unauthorized access to the Meus Dados Platform
CAPES confirmed a security incident on the Plataforma Meus Dados that allowed unauthorized access to personal data available in the system. The technical investigation was still ongoing, but the agency identified CPF, email address, phone number, and banking data as potentially accessible, while restricting the affected functionality and strengthening monitoring.
This incident matters because it combines data exposure with a formal institutional response. The material does not include an external attribution for the attack or an exact number of affected users, but it does include a clear breach notification and containment measures, making it material for the monthly public sector tally.
Court of Justice of Bahia, partial restorations of BRBJUS
The BRBJUS sequence should be seen both as an incident and as a recovery process. The court reported an initial outage, then a partial restoration with functions such as guide registration and balance inquiries, and finally the full return of the system with electronic payment of alvarás. At all times, it stressed that the incident occurred in an external technology environment.
That timeline shows a pattern repeated in Brazil when a critical platform fails, containment, testing, staged restoration, and a review of contractual or technical governance. The case did not only affect judicial deposits, it also exposed public service dependence on third party managed infrastructure.
Active Threats and Campaigns in Brazil
Ransomware and Extortion in Brazil
Ransomware and extortion activity in Brazil remained high, but this month’s material shows a mix of confirmed encryption, leaks, and unverified claims. The only case with confirmed asset encryption in the period’s reporting was the one involving judicial and service incidents, while most other events stayed at the level of group claims or leak site listings without complete independent proof.
Among the cases mentioned only on leak sites are K3G Solutions Brazil, Camorim Serviços Marítimos, and Receita Federal, each with different degrees of verification and with the caveat that the source does not always specify whether encryption occurred. In the K3G Solutions case, for example, the material refers to a publication threat and estimated exfiltration, but not to encryption confirmed by the victim.
There were also extortion incidents targeting manufacturing, technology, transportation, and education organizations, but in several cases the public evidence was limited to trackers or aggregators. For this report, that points to clear extortion pressure, but not to a uniform tally of technical impact.
| Case | Impact type | Status in the material |
|---|---|---|
| K3G Solutions Brazil, Panzer | Exfiltration and extortion, the source does not specify whether encryption occurred | Claim and tracking on a leak site, with no public confirmation from the company |
| Receita Federal do Brasil, Emperador | Leak site mention only, with a data claim | No official confirmation of intrusion |
| Camorim Serviços Marítimos, LockBit 5.0 | Leak site mention only, with a disclosure threat | Group claim, without independent validation |
| Vexy targeting Brazilian manufacturing | Data-broker style extortion | Tracker entry, with no public impact details |
Fraud, Phishing, and Synthetic Identity in Brazil
Fraud was one of the densest threat areas of the month, especially across the financial system. Pix drew multiple signals, from altered QR codes and copy-paste codes in online stores to new Central Bank rules for flagging suspicious CPFs and CNPJs, rejecting associated transactions, and notifying the user. At the same time, the courts and police continued documenting schemes built around stolen credentials, fake sites, and identity impersonation.
The clearest development was the consolidation of deepfakes and voice cloning as fraud tools. The material cites the theft of R$ 80 mil through facial recognition fooled by AI, campaigns that already account for 1 in every 15 fraud cases detected in Brazil in 2026, and estimated losses of R$ 1,8 mil millones between July 2025 and April 2026. That places synthetic identity among the top operational and financial risks.
There were also more traditional phishing campaigns, but more coordinated ones. The fake exam case for the police, which used the Cebraspe brand to carry out fraudulent Pix payments, shows a mix of social engineering, institutional impersonation, and abuse of trust in APIs or automated checks.
APT, AI-Assisted Intrusion, and Hacktivism in Brazil
There was no major classic state APT case in the September material, but there were several campaigns with persistent intrusion traits, automated tooling, and impact on public infrastructure. The most visible was the SEO poisoning operation against .gov.br domains, attributed to a Chinese-speaking actor, which compromised public servers and used search authority to redirect traffic to gambling and phishing.
In parallel, Unit 42, Cloud Security Alliance, and other sources described campaigns in Latin America with AI support, tunneling, custom RATs, and SOCKS5 proxies, with a financial focus in Brazil. Case CL-CRI-1163, in particular, involved phishing with a resume attachment, RATs, and SockTz to create a reverse SOCKS5 proxy. The material does not frame it as a state APT, but it does present it as organized and sustained intrusion.
There were also signs of hacktivism or broader abuse of public infrastructure. The Gambling Goblin campaign against .gov.br sites did not seek espionage or encryption, but rather reputation manipulation and monetization through gambling, with direct impact on Brazil’s public attack surface.
Critical vulnerabilities affecting Brazil
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-20079 | Cisco Secure Firewall Management Center and Security Cloud Control Firewall Management | CTIR Gov reported it as critical and listed in CISA KEV | CTIR Gov, Alert 81/2026 |
| CVE-2026-62911 | Microsoft Exchange Server 2016, 2019 and Subscription Edition | Authentication bypass through credential capture and replay | CTIR Gov, Recommendation 15/2026 |
| CVE-2026-85706 | GitLab Community Edition and Enterprise Edition self-managed | Arbitrary file read, active exploitation and use in ransomware attacks | ITShow, Censys, Rapid7 |
| CVE-2026-76460 | Cisco Identity Services Engine | Vulnerability with potential impact on confidentiality, integrity or availability, listed in KEV | CTIR Gov, Alert 87/2026 |
| CVE-2026-85880 | Microsoft Windows 10 1607, 1809, 21H2 and 22H2 | Issue listed in KEV with recommendation for immediate patching | CTIR Gov, Alert 84/2026 |
| CVE-2026-93616 | Multiple products, not specified in the excerpt | Critical vulnerability included in KEV | CTIR Gov, Alert 89/2026 |
September’s technical pattern was clear, nearly all of the critical issues arrived with active exploitation or inclusion in KEV. That makes patching priority in Brazil depend not only on theoretical severity, but on real exposure and the presence of infrastructure with exposed edge systems, cloud identity, remote access or collaboration and commerce software.
Regulation and compliance in Brazil
Brazil had an intense regulatory agenda in September, with two main fronts, virtual assets and oversight of digital platforms. The Central Bank issued Resolutions BCB 587, 588 and 589, which tightened the regime for Pix, reporting to Coaf, and the relationship with unauthorized virtual asset providers. Implementation was also phased, with some provisions taking effect in October 2026 and others slated for 2027.
The most visible regulatory effect was on fraud and traceability. The new rules allow suspicious CPFs or CNPJs to be flagged, related transactions to be rejected, and participants to be required to retain the grounds and notify the user. At the same time, automatic reporting was expanded for transfers involving self-custodied wallets, and restrictions advanced for institutions that operate with unauthorized counterparties.
ANPD also made moves. It opened a public consultation on the oversight rule and the administrative sanctioning process, called a public hearing, and continued applying measures to platforms such as Discord. The Digital ECA framework sits in the background, because the data authority is already acting on services and platforms with likely impacts on minors and data protection.
| Measure | Authority | Operational scope | Date or effective date |
|---|---|---|---|
| Resolution BCB 587 | Central Bank | Fraud suspicion flag, review, notification and participant liability | September 2026, with blocks effective from 18/09/2026, February 2027 and July 2027 |
| Resolution BCB 588 | Central Bank | Reporting to Coaf of self-custody transfers from US$ 10,000 | In force since 1/10/2026, with specific supervisory effects from 1/1/2027 |
| Resolution BCB 589 | Central Bank | Restriction on operating with unauthorized counterparties and new reporting obligations | In force since 1/10/2026, with later milestones in November 2026 and January 2027 |
| ANPD public consultation | ANPD | Review of the oversight process and sanctioning process | Open during September 2026 |
| ANPD oversight of Discord | ANPD | Requirement for explanations over alleged noncompliance with suspension | 21/09/2026 |
The compliance reading is that Brazil is pushing regulated entities toward greater traceability, documentation of decisions and faster incident response. That applies to banks, fintechs, exchanges, digital platforms and, increasingly, public agencies with exposed services.
Most affected sectors in Brazil
The public sector felt the biggest impact this month in terms of disruption and exposure. Justice, federal agencies, data platforms, and bodies with shared infrastructure concentrated the most sensitive incidents. The issue was not just the number of events, but their ability to suspend deadlines, block hearings, take systems offline, or expose credentials and personal data.
The financial sector remained a structural target, driven by both fraud and technical exploitation. Pix, banks, fintechs, BRB, BRBJUS, and the deepfake cases show that money remains the strongest incentive and the fastest extraction channel. Regulatory pressure also fell on that ecosystem, a sign that the regulator sees sustained tension between innovation, availability, and fraud control.
Transport and logistics saw fewer cases, but they were no less relevant. Águia Branca showed that an incident in the sales channel is enough to trigger notification, containment, and access review. In health care, the picture was more about operational continuity and extortion than mass exposure, although Brazil's history in the sector and the mention of incidents at clinics and hospitals point to a persistent attack surface.
Trends and signals to watch in Brazil
Compared with August, September saw a sharp rise in unclassified incidents, a drop in documented fraud or phishing, and fewer regulatory moves, but more critical CVEs were cited. That mix suggests September was not a lower-risk month, but one with more operational and technical activity materializing in specific verticals.
The leading threat shifted from "unclassified" in August to "incidents" in September. That change matters because it points to more events with verifiable impact and less noise from complaints that were not categorized. Put another way, the September material makes it easier to see where the risk is hitting, even if it does not mean the ecosystem is any less hostile.
Two signals are still worth tracking. The first is the convergence of financial fraud and synthetic identity, which no longer appears as a lab-side trend but as behavior embedded in real campaigns. The second is the link between exploitation of critical CVEs and exposure of edge, identity, and collaboration services, a pattern that could keep affecting government, telecom, and the financial sector.
At the regional level, Brazil remains the main threat pressure point in Latin America. That does not mean everything is happening in Brazil, but rather that a disproportionate share of activity, especially financial and extortion-related activity, continues to concentrate there.
Recommendations for security teams in Brazil
Prioritize identity and access containment in judicial, financial, and government systems. If credentials were accessed or services became unavailable, the immediate focus should be reset, revocation, traceability, and session monitoring.
Review fraud rules in payment channels, especially Pix, QR, and transfers with strengthened authentication. This month’s material shows abuse of suspicion labels, fake accounts, voice cloning, and manipulation of receipts and payment confirmations.
Accelerate patching for the critical CVEs listed by CTIR Gov and for vulnerabilities with confirmed active exploitation in KEV. The most exposed surfaces are email, firewalls, remote access, collaboration tools, and self-managed software.
Review third-party exposure and the governance of external platforms. The BRBJUS and Águia Branca cases show that dependence on vendors or outside environments can turn a technical outage into an operational and reputational incident.
Strengthen fraud detection with non-biometric signals. This month made it clear that facial biometrics alone are not enough against deepfakes, face swaps, and voice cloning.
Keep notification and evidence procedures ready for ANPD, the Central Bank, and sector authorities. The cost of delay is no longer only reputational, it can also become a regulatory compliance issue.
Validate SEO poisoning controls, web hardening, and integrity monitoring on public or high-reputation sites. The campaign against .gov.br showed that a compromised site can be used as distribution and monetization infrastructure.
Frequently Asked Questions
What September clash tied justice, fraud, and operational continuity in Brazil?
The month linked two areas often analyzed separately, service disruption and financial fraud. The TJMT lost availability and credentials, while BRBJUS suffered downtime and funds diversion. Both cases show that a technical breach in Brazil can end up affecting court processes and money at the same time.
How are the Central Bank's new rules connected to Pix scams and deepfakes?
The Central Bank's new resolutions focus on suspicious markers, CPF and CNPJ traceability, and tighter controls over transfers involving self-custody. They respond to fraud that already uses deepfakes, voice cloning, altered QR codes, and stolen credentials, so regulation and technical controls are now aligned on the same front.
What is the link between critical CVEs and the sectors hit hardest this month?
The critical vulnerabilities affected the very surfaces most often seen in Brazilian incidents: email, remote access, identity, collaboration, and exposed public services. The clearest case was GitLab, with active exploitation, while CTIR Gov prioritized Cisco and Microsoft flaws that could affect government, finance, and critical operations.
Why does the report separate ransomware, extortion, and simple mention on a leak site?
Because they are not the same. In September there was one case with confirmed operational impact, several extortion claims, and several mentions on leak sites without public confirmation. Treating them as one would erase important differences for a CISO, especially when the source does not specify whether there was encryption or only the posting of the claim.
Which sectors should keep the closest watch on the compliance agenda?
Finance, the public sector, and digital platforms should keep the closest watch. The Central Bank tightened Pix and controls over virtual assets, while the ANPD expanded oversight of platforms and imposed measures on services affecting minors. That requires banks, fintechs, exchanges, and agencies handling sensitive data to coordinate legal, security, and operations teams.
Material limitations
This report was built exclusively from the material provided for September 2026 and from facts dated within that window. Facts from earlier months were used only as comparative context when the material allowed it, and any facts without a confirmed date were left out of the period indicators, although they may have been cited as qualitative context.
A zero value or an absence in the table does not mean the event did not occur in Brazil or in the region, only that it did not appear in the material analyzed for this month or could not be confirmed with the available evidence. This is especially important for CVEs, because the count reflects only what was recorded in the corpus, not the full set of vulnerabilities exploited in the country.
Aggregated telemetry on attempts, blocks or weekly vendor averages was excluded from the incident volume and can only be mentioned as background internet noise, not as confirmed impact. Promotional material, advertorials and some commercial releases were also left out as counting inputs, although they could still serve as context if corroborated by stronger sources.
Finally, the regulatory section includes decisions, consultations and rulings that fell within the time window, but it does not assume that every secondary press claim is equivalent to a rule already published. When the material did not allow us to determine whether there was encryption, exfiltration or only a claim on a leak site, that limitation was stated explicitly rather than forcing a classification.
Sources
- Digitale Vermögenswerte: Brasilien startet Echtzeit-WarnsystemAd-hoc-news
- BC endurece regras contra fraudes e altera funcionamento do PixTI Inside
- O que muda para empresas que trabalham com ativos virtuaisTransfero
- BC pode cortar Pix e contas de exchanges sem autorização em outubroObitcoin
- Ciberseguro enfrenta deepfakeValor Econômico
- Cibersegurança entra na agenda estratégica do transporteValor Econômico
- SEGURANÇA: IEC participa da 8° edição do Guardião CibernéticoInstituto Evandro Chagas (IEC/SVSA/MS)
- Active Exploitation Alert: Adobe Commerce / Magento CVE-2026-71362Rescana
- ALERTA 90/2026Centro de Tratamento e Resposta a Incidentes Cibernéticos de Governo (CTIR Gov)
- ALERTA 88/2026Centro de Tratamento e Resposta a Incidentes Cibernéticos de Governo (CTIR Gov)
- Comunicado sobre incidente de segurança na Plataforma Meus DadosCAPES — Coordenação de Aperfeiçoamento de Pessoal de Nível Superior
- ALERTA 88/2026Centro de Tratamento e Resposta a Incidentes Cibernéticos de Governo (CTIR Gov)
- Bancos em estado de alerta com aumento de invasõesCorreio Braziliense
- Ransomware Attacks This Week: 221 Victims Across 47 Groups, September 14 to September 20Kalir
- ALERTA 90/2026CTIR Gov
- ALERTA 89/2026Centro de Tratamento e Resposta a Incidentes Cibernéticos de Governo (CTIR Gov)
- Brazil's tax agency appears on a young crew's leak siteIntelFusions
- Autocustódia de cripto entra no radar do Coaf em outubroSpaceMoney
- BCB amplia regras para carteiras autocustodiadasSpaceMoney
- Guardião Cibernético mobiliza instituições em sete cidades e ...LRCA Defense Consulting
- Advogado analisa novas regras do BC para controle de ativos virtuaisMigalhas
- ANPD abre consulta pública sobre novas regras para fiscalizar plataformas digitaisPortal do Holanda
- ALERTA 85/2026CTIR Gov
- WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV CatalogThe Hacker News
- CISA warns of SharePoint, WSO2, Adobe Commerce flaws exploited in attacksBleepingComputer
- ALERTA 86/2026Centro de Tratamento e Resposta a Incidentes Cibernéticos de Governo (CTIR Gov)
- Exército simula defesa cibernética no Brasil às vésperas da eleiçãoOpera Mundi
- ANSN testa resposta do setor nuclear a incidentes cibernéticos em cenários inéditosAutoridade Nacional de Segurança Nuclear
- COMUNICADO – Restabelecimento Integral do BRBJusTribunal de Justiça da Bahia
- Revolut Breach: Hacker Used Blockchain Analytics to Identify Targets in Data BreachArkham Intelligence
- Governo mira 13 apps de 'namorados de IA' por riscos a menoresIG Tecnologia
- Golpes de site falso, WhatsApp e redes sociais lideram fraudes contra clientes de banco; veja como se protegerCorreio24Horas
- Operação Fake Card investiga fraude em cartões de benefícios e movimentação de R$ 437,8 milhõesMinistério da Justiça e Segurança Pública
- fraude bancáriaISTOÉ
- TikTok pode ter coletado dados de 20% das crianças brasileiras em apenas 1 anoJornal Aqui Paulínia
- EUA: Meta fecha acordo de US$ 18 bilhões com 48 Estados e adota limite de tempo para menoresJornal Aqui Paulínia
- Cyware Weekly Threat Intelligence - September 25, 2026Cyware
- Weekly Intelligence Report - 25 Sep 2026CYFIRMA
- BC determina aviso ao Coaf de transferências cripto com autocustódia a partir de US$ 10 milExame
- Ciberlab apoia polícias civis em operações contra fraudes eletrônicas em três estadosMinistério da Justiça e Segurança Pública
- Criptomoedas: transferências de US$ 10 mil serão informadas ao CoafEstadão
- Vale-alimentação: Prefeitura é alvo de operação que investiga fraude de R$ 437 milhõesBNews
- CNEN participa do Exercício Guardião Cibernético 8.0Comissão Nacional de Energia Nuclear
- Ataque hacker desvia R$ 43 milhões e deixa clientes e advogados à espera de depósitos judiciais na BahiaAloAlô Bahia
- ‘Companheiros de IA’: Ministério da Justiça encaminha pedido de investigação à ANPD contra chatbotsO Globo
- n0n ransomware ameaça destruir backups para ampliar pressão sobre vítimasMinuto da Segurança
- ANEEL é Integrada Ao Sistema Brasileiro De Inteligência Para Reforçar Proteção De Infraestruturas CríticasCenário Energia
- Right To Know - September 2026, Vol. 45Clark Hill
- Boletim do CISC de Vulnerabilidades — 22 de setembro de 2026Centro de Prevenção, Tratamento e Resposta a Incidentes Cibernéticos de Governo (CISC)
- ANPD debate novas regras - audiência pública sobre fiscalização de plataformas digitais e ECA DigitalALT Digital LATAM
- Grupo Caberj — INCRANSOM Ransomware AttackBreach House
- Operação Firewall: golpe cibernético desviou R$ 424 milCampo Grande News
- Brazilian Government Opens Consultation on Regulatory Oversight of Data Privacy and Online ProtectionGlobal Policy Watch
- ANA participa do Exercício Guardião Cibernético 8.0 com foco na proteção do espaço cibernético brasileiro e infraestruturas críticasAgência Nacional de Águas e Saneamento Básico
- Resolução BCB N° 589 | Banco CentralOkai
- Victim: RECEITA FEDERAL DO BRASIL – emperadorRansomware.live
- Emerging Ransomware Gang Uses Backup Destruction ThreatsInfosecurity Magazine
- Receita Federal aparece em portal de ransomware grupo Emperador com suposto vazamentoTechstart
- Cyber Alert: Brazil — Receita Federal do BrasilHackmanac
- Armas, vigilancia, espionaje...; casos de uso indebido de la IA, según estudio de AnthropicTeleamazonas
- BC amplia controle sobre criptomoedas e mira carteiras própriasAgência Brasil
- BC altera regras para criptoativos e amplia comunicações ao CoafCNN Brasil
- Central Bank changes Pix rules and regulates hybrid billing and the marking of customers suspected of fraudGSGA
- Times BrasilTimes Brasil
- Brasil fica de fora de projetos avançados de OpenAI e Anthropic em meio a série de invasões por agentes de IAFolha de S.Paulo
- Emperador claims Brazil’s federal tax authority — alleged 6.3GB of government dataDaily Dark Web Intelligence
- Uma hora para avisar a ANSN: a minuta de segurança cibernética nuclear e as duas remissões que precisam de consertoProcTracker
- Portaria que inclui a ANEEL no Sistema Brasileiro de Inteligência é publicadaAgência Nacional de Energia Elétrica
- Brasil | Guardião Cibernético mobiliza setor de telecom em exercício de defesa cibernéticaDPL News
- Quem pode acessar seus dados bancários? BC prepara novas regras para o Open FinanceValor Investe
- PF faz operação contra fraudes bancárias eletrônicas e golpes digitaisPolícia Federal
- Hackers invadem sistema do BRB e desviam R$ 43 milhõesCorreio Braziliense
- Ministério da Justiça pede investigação de IAs de 'companhia' infantilUOL Tilt
- Exercício Guardião Cibernético 8.0 reúne cerca de 1.300 participantes em BrasíliaMinistério da Defesa do Brasil
- Curitiba vai sediar o maior exercício de defesa cibernética do Hemisfério SulBanda B
- Craisa — THEGENTLEMEN Ransomware AttackBreach House
- Cibersegurança e inteligência artificial: os destaquesIT Show
- KREMLIN Banking Malware Bypasses Chrome Security to ...GBHackers
- Governo pede apuração contra chatbots que simulam amizade e romanceG1
- MJSP anuncia três atos para reforçar proteção de brasileiros no ambiente digitalMinistério da Justiça e Segurança Pública (MJSP)
- Governo pede investigação sobre chatbots que simulam amizade e romance e aponta riscos para usuários no BrasilOlhar Digital
- Banco Central atualiza normas contra fraudes no PixMix Vale
- COMUNICADO – Sistema BRBJUSTribunal de Justiça da Bahia
- Hackers usam inteligência artificial para fraudar biometria, furtam R$ 80 mil de conta e banco é condenado a estornar valor e pagar indenizaçãoSuper Rádio Tupi
- Rio recebe o maior treinamento de cibersegurança do Hemisfério SulO Globo
- Como o Santander está lidando com golpes digitaisConsumidor Moderno
- Polícia Civil indiciа 268 suspeitos por fraudes digitais em SP em 2026; veja os golpes mais comunsG1
- Panzer Ransomware Strikes K3G Solutions BrazilDexpose
- Gemini 'hackeia' três empresas em teste de segurança e acende alerta no GoogleExame
- Ransomware Group Panzer Hits: Honda (Peru) – with K3G Solutions Brazil alert sectionHookPhish
- Desinformación y fraude hechos con Claude que reporta AnthropicLupa
- Águia Branca confirma ataque hacker: dados de 7.883 clientes podem ter sido comprometidosMelhor e-Tech
- INCAN restablece sus servicios de radioterapia tras ciberataqueLa Hora
- Atacantes exploram falha no framework Issabel permitindo execução de comandos no sistema sem autenticaçãoCEVIU
- Ransomware group Panzer hits K3G Solutions BrazilHackerFeeds
- Novas regras do Banco Central para bancos e fintechsSerasa
- K3G Solutions Brazil Ransomware Claim (2026) — What’s Alleged & Am I Affected?Recent Breaches
- Exército faz operação contra ataques cibernéticos. Febraban participaCapital S/A
- K3G Solutions Brazil ransomware attack — panzer leakKalir Pulse
- K3G Solutions Brazil Listed by Panzer Ransomware GroupGalaxyWarden
- K3G Solutions Brazil — PANZER Ransomware AttackBreach House
- Pix terá novas regras para fraudes, cobrança híbrida e contas-salárioAgência Brasil
- Banco Central fortalece regras de segurança e combate de fraudes no PixCNN Brasil
- Entenda quais são as mudanças no Pix anunciadas pelo BCPoder360
- IA do Google invade 3 empresas de forma autônoma pela 1ª vezPoder360
- Google's Gemini hacks 3 real companies in security testXinhua
- Boletín Semanal de Ciberseguridad, 12-18 de septiembreTelefonica Tech
- ConnectWise ScreenConnect CVE-2026-84869 Actively ...Aviatrix Threat Research Center
- Hospitais não pedem pagamentos por telefone; veja como se protegerProjeto Comprova
- Victim: K3G Solutions Brazil – PanzerRansomware.live
- ThreatsDay: Self-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New StoriesThe Hacker News
- Ransomware Play publica a la fabricante brasileña MetallcoKalir Pulse
- Ransomware Panzer publica a la consultora brasileña K3G SolutionsKalir Pulse
- ECA Digital completa um ano e MJSP consolida ações de enfrentamento à violência contra crianças e adolescentes na internetMinistério da Justiça e Segurança Pública do Brasil
- BC endurece regras contra fraudes e altera funcionamento do PixTI Inside
- Poder360Poder360
- BC aperta regras do Pix contra fraudes; entenda o que mudaMoney Times
- BC amplia uso do PIX em contas-salário e reforça regras de segurança e combate a fraudesG1
- Brazil Central Bank Tightens Pix Rules, Immediate Exclusion and Fraud Mark Accountabilityheadtopics
- Central Bank tightens rules against fraud and changes how Pix works.TI Inside
- IA e golpes via Pix colocam Brasil em top 3 de ataques digitais no mundoFenati
- Justiça mantém condenação de hackers que roubaram ...Convergência Digital
- Cyware Daily Threat Intelligence – September 18, 2026 (Panzer ransomware overview)Cyware
- All Records - Breach House (entry for K3G Solutions Brazil)Breach House
- LockBit5 ransomware lists Taiwanese firm tpi.tw - Pulse - Kalir.ioPulse - Kalir.io
- Viação Águia Branca sofre ataque cibernético que afetou quase 8 mil clientesTecMundo / Estadão
- Banco Central muda regras do Pix: veja o que mudaCampo Grande News
- BC atualiza regulamento do Pix e ajusta regras de penalidadeTribuna do Sertão
- Banco Central amplia regras para devolução de valores do PixMix Vale
- Brazil Pix: Mandatory Rule for Large Banks EndsThe Rio Times
- BC anuncia novas regras de funcionamento do Pix; veja o que mudaCongresso em Foco
- Pix terá novas normas contra fraudes, cobrança híbrida e uso em conta-salárioRede98
- Bancos do Brasil Ficam Proibidos de Negociar com Empresas de Cripto Não Autorizadas Após 30 de OutubroFinanceFeeds
- Lucas Barreto — senador (PSD-AP)Congresso Quanta
- 1 ano de ECA Digital: o que mudou para crianças e adolescentesAgênciaGov / EBC
- ECA Digital: redes sociais com menores têm até hoje para entregar relatórioUOL Tilt
- Brasil é o 3º país mais atacado por cibercriminosos, diz TrellixIT Forum
- Plataformas para crianças devem publicar relatório de transparência até esta quintaSenado Federal do Brasil
- Golpe feito exclusivamente para bancos no Brasil usa o Ethereum como 'central de comando'Bitnoticias
- TJDFT condena hackers por ataque cibernético a hospitalValor Econômico
- Um ano do ECA Digital: materiais sobre aferição de idade e design manipulativoData Privacy Brasil
- Brasil atrai 53% dos ataques cibernéticos da América Latina, alerta estudo da JC2Sec e BitsightTI Inside
- Após morte de jovem, Discord classifica como baixo risco de suicídio e automutilação entre adolescentesFolha de S.Paulo
- ECA Digital: Roblox e Kwai divulgam relatórios - comparação exige cuidado com os dadosJornal da Justiça
- TJDFT mantém condenação por invasão de sistema hospitalar, extorsão e ataque a serviço de utilidade públicaJuristas
- 1 ano de ECA Digital: o que mudou para crianças e adolescentes?Ministério dos Direitos Humanos e da Cidadania do Brasil
- Tribunal da Bahia manda BRB cumprir plano de contingência após ataque hackerConvergência Digital
- Revolut Data Breach: 5 Months, 680 High-Profile Accounts, $3M RansomSecurityWeek
- ECA Digital completa um ano e é marco na proteção de crianças e adolescentes na internetAutoridade Nacional de Proteção de Dados (ANPD)
- Golpes financeiros que usam deepfake crescem 830% no BrasilSITEPD
- Tentativas de golpe digital somam três mensagens por segundo no paísMixvale / TRBN
- Brasil é o 3º país com mais ataques cibernéticos, aponta estudoTRBN / Monitor do Mercado / Let’s Money
- SHADOW-AETHER-064 (Threat actor): news timeline & CVEs · ZeroHourZeroHour
- Unit 42 (Organization): news timeline & CVEs · ZeroHourZeroHour
- Arresto por usar ChatGPT: cae hombre en BrasilABC Economía
- Unit 42 says hackers used AI tools against LatAm targetsReuters
- Golpes com deepfake crescem 830% no Brasil, diz VU - IPNews - O Portal da ConectividadeIPNews
- Golpes financeiros que usam deepfake crescem 830% no Brasilsitepd.org.br
- Cibersegurança e nuvem: o que a BCB 538 exigeMerc Group
- Tribunal mantém penas de hackers que invadiram sistemas de ...Correio Braziliense
- Panzer (Threat actor): news timeline & CVEsZeroHour
- Brazil fines TikTok parent ByteDance over teen data handlingThe Daily Star / Reuters
- ANPD aplica multa de R$ 153,7 milhões: 5 lições para o mercadoDNALaw
- ANPD multa TikTok em R$ 153,7 milhõesFATÍVIA
- A nova era da conformidade com a proteção de dados no BrasilMigalhas
- Viação Águia Branca sofre ataque cibernéticoA Gazeta
- Águia Branca registra incidente de cibersegurança que pode ter afetado 7.883 clientesÔnibus & Transporte
- Após era da facial, biometria das veias da mão é a nova aposta da cibersegurançaInfoMoney
- Golpes com voz e rosto clonados por IA já são 1 em cada 15 fraudes no BrasilPortal do Holanda
- Hackers invadem banco digital e pedem R$ 15 milhões de resgateInvestidor10
- Revolut says no direct demand received over alleged data breachReuters
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session TokensF4N6
- KREMLIN malware uses Ethereum to update attack serversCrypto.news
- Hospitais não pedem pagamentos por telefone; veja como se protegerGauchaZH
- Unit 42 search result for CL-CRI-1163Palo Alto Networks Unit 42
- Unit 42 search result referencing SockTz and CL-CRI-1163Palo Alto Networks Unit 42
- Sept. 15 Advisory: GitLab Critical Path Traversal VulnerabilityCensys
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session TokensThe Hacker News (síntesis de Elastic Security Labs)
- Usuário de rede social ganha o direito de desligar o algoritmo e escolher o que aparece no feed, prevê Projeto de Lei na CâmaraBanda B
- Prova de vida com IA reduz fraude por deepfake no PicPayCentral do Varejo
- Golpes com deepfake disparam 830% no Brasil e já respondem por 1 em cada 15 fraudes do paísTI Inside
- Hackers hijack government servers to promote illegal gamblingEscudo Digital
- A fake Brazilian police recruitment exam abuses the real CEBRASPE brand to run a double PIX payment scamCarlesi.vg
- Autorização PSAV no BCB: prazo vence em outubro de 2026FCM Law
- Deepfake scams surge 830% in Brazil and now account for 1 in every 15 frauds in the countryTI Inside (en inglés)
- PL 145/2024 - Ficha de tramitaçãoSenado Federal do Brasil
- PF aponta fraude de R$ 17 bilhões em operações entre Master e BRBDiário do Grande ABC
- 'Precisamos excluir a data': Banco Master usou Word, PDFs e códigos para fabricar documentos falsos, diz PFG1
- Bancos vão cruzar dados com operadoras para travar golpes no PixEmpréstimo Digital
- Presidente da ANPD rebate ataques por 'superpoderes' e defende cerco às redesVeja
- PF aponta 'participação dolosa' e 'manifesta autoridade' de Augusto Lima em fraudes entre Master e BRBO Globo
- Brazil’s Top Court Gives Police Deadline on Banker’s DataBloomberg
- Artigo: O comportamento do usuário pode ser uma defesa contra fraudesO POVO
- CVE-2026-85706: Critical GitLab Path Traversal Exploited in the WildRapid7
- Critical Path Traversal in GitLab CE and EE Under Active ExploitationBeazley Security Labs
- Vírus frauda QR Code, Pix Copia e Cola e cartão em ecommerces brasileiros sem deixar vestígioFolha de S.Paulo
- KREMLIN Banking Malware Hijacks Chrome and Edge to Steal Credentials and Session Tokens in BrazilWorld Cyber News
- Remessas internacionais e a nova Lei Geral de Cibersegurança: a confiança será ainda mais valiosaTI Inside
- Una red global secuestra webs gubernamentales para mostrar apuestas y descargas ilegales sin tocar la URL oficialInfobae
- A ANPD já multa por causa de IA — e sua empresa nem sabe se está expostaStartSe
- Remessas internacionais e a nova Lei Geral de Cibersegurança: a confiança será ainda mais valiosaTIInside
- New Coup Change QR Pix Code in Online StoresGround News
- Golpe recém-descoberto troca QR Code do Pix em lojas virtuais sem mudar o valor da compraPortal do Holanda
- Master usou ferramentas como Word e PDF para fabricar documentos falsosMetropoles
- Banco Master Founder Claims Brazil's Central Bank Reviewed His Drafts Before SubmissionTechTimes
- Brazil's New Capital Rules Take Effect, Around 290 Crypto ...BTCC
- Investigação interna do Master apontou produção 'industrial' de documentos usados em carteiras do BRB, diz PFValor Econômico
- Exército Brasileiro reúne mais de 240 instituições em maior simulação de ataque cibernético do Hemisfério Sul contra setores críticosTimes Brasil | CNBC
- Procon-SP orienta consumidores sobre novo golpe que altera QR Code PixAgência SP / Procon-SP
- 553 victims for Brazil - Ransomware.liveRansomware.live
- Master sem sigilo: saiba o que há em cada documentoPoder360
- Hackers Use Claude and GPT-Powered Tools to Help ...CybersecurityNews
- Caso Master: relatório da PF expõe 'fábrica de documentos' para validar crédito vendido ao BRBG1
- Brazil election challenger Bolsonaro under investigation for Banco Master-linked probeReuters
- Microsoft mapea vectores de ataque en aplicaciones web cloud: primera matriz unificada para entornos serverlessCiberseguridad LATAM
- ANPD busca ampliar a fiscalização sobre plataformas e serviços digitaisDPL News
- Brazil Digital Regulation Monitor | September 2026Licks Legal / Tech Regulation BR
- Só dez startups 'cripto' devem obter licença do BCValor Econômico
- BC exige até R$ 37,2 mi e enxuga mercado cripto no BrasilLetsMoney
- Brazil VASP Licence: BCB Rules, Deadlines and FAQ (2026)FCM Law
- Victim: Tuboaços da Amazônia Ltda.Ransomware.live
- Empresas de Criptoativos do Brasil Têm até 30 de Outubro para Solicitar Autorização ou Enfrentam Corte de MercadoFinanceFeeds
- O que é VASP (PSAV)? Entenda quem precisa de autorização do Banco CentralNDM Advogados
- Brazilian top court unseals probe into multibillion-dollar bank fraudReuters
- Vorcaro tinha grupo de WhatsApp com servidores do Banco Central, apontam investigadoresBBC Brasil
- Funcionário do BC teria recebido até R$ 760 mil mensais, diz PFPoder360
- Active Exploitation Alert: ConnectWise ScreenConnect Improper Privilege Management / Missing Authorization (CVE-2026-84869) Added to CISA KEVRescana
- PREVIC institui Política de Governança de DadosSuperintendência Nacional de Previdência Complementar (Previc)
- Brazil Ransomware & Cyber AttacksBreach House
- Tuboaços da Amazônia Ltda. Ransomware Attack by Nightspire (2026)Cyber Threat Intelligence
- GitLab security advisory (AV26-917)Canadian Centre for Cyber Security
- Rede chinesa invade sites '.gov.br' em fraude de apostas onlineTecMundo
- Ransomware no Brasil: ataques batem recorde em 2026Sky.One
- Китайские хакеры атакуют госсайты Бразилии через ApacheTechora.ru
- Projetos de Lei sobre Inteligência Artificial no BrasilLCF Consulting
- ALERTA 79/2026GSI/CTIR Gov
- AmorSaúde Data Breach in 2026BreachSense
- ANSN abre consulta pública sobre requisitos de segurança cibernética para instalações nucleares e radiativasAutoridade Nacional de Segurança Nuclear
- Timeline da regulamentação de IA no Brasil (2019–2026)LCF Consulting
- 브라질을 표적으로 삼는 금전적 동기의 공격자 BREEZE COMETGoogle Cloud
- IA agêntica e zero-days pressionam cyber no BrasilCISO Advisor
- ALERTA 81/2026GSI - Presidência da República
- Banco Central aperta regras do Pix para novos celularesMixVale
- ALERTA 80/2026GSI/CTIR Gov
- ANPD abre consulta pública para atualização das regras de fiscalização e processo sancionadorCescon Barrieu
- Câmeras de segurança em condomínio e LGPDLEM Advogados
- Brazil Removes R$500 Cap on Contactless Pix Payments From October 1Clearingpost
- Palavra de segurança: como se proteger de golpes com IAWeLiveSecurity (ESET)
- ANPD prepara centro de inteligência artificial e mira rolagem infinita, diz diretoraFolha de S.Paulo
- Banco Central exige cinco comprovações para autorizar empresas cripto no BrasilBitnoticias
- Prevenção à lavagem de dinheiro e carteiras autocustodiadas: o deslocamento do dever para o perímetro reguladoRevista Tópicos
- CISA Adds 5 Actively Exploited Artifactory, ScreenConnect ...The Hacker News
- ANPD abre inscrições para audiência e inicia consulta pública para atualização do regulamento de fiscalizaçãoAgência Nacional de Proteção de Dados (ANPD)
- Victim: amorsaude.com.brRansomware.live
- Banco Central endurece regras após caso Master e reforça proteção a investidoresA Revista
- Ransomware Alert: AmorSaúdeFalconFeeds.io
- Fraudes sofisticadas sobem quase 500%, mas avalanche de ‘deepfake caseiro’ acende alertaEstadão Bluestudio
- Pix avança em maturidade regulatória com novo MEDCryptoid
- Hackers conectaron a Claude y GPT‑4.1 directamente a ataques; sus propios servidores los delataron.SecurityLab LATAM
- VEXY Ransomware Gang: 3 Technology Sector Victims in 5 Days ...Security Arsenal
- Golpe do PIX: Como Recuperar o Dinheiro e o Dever do BancoGabriel Valerio Advocacia
- CVE-2026-83548 & 83549 : SonicWall SMA 1000 zero-days chainés en RCEAyinedjimi Consultants
- Attackers Use AI-Assisted Intrusions and Data Exfiltration to Target Latin American OrganizationsVarutra (Threatpost-style)
- TCU dá 60 dias para Saúde explicar atraso em 97% das entregas de remédios em acordo com a Fiocruzg1
- Vexy Ransomware ransomware group - Discover all the ...Breach House
- Unit 42Palo Alto Networks Unit 42
- Slim Spider Steals Crypto Custody Secrets From Brazilian Financial ...The Hacker News
- Alerta por ciberseguridad: crecen un 25% los ataques con secuestro de información y revelan cuáles son los países más afectadosEl Destape Web
- Ransomware Group lockbit5 Hits: amorsaude.com.brHookPhish
- 巴西8月勒索软件攻击创年内新高,中资企业数据安全风险上升China Brazil Insight
- Blog OpenClaw Brasil: Tutoriais e Automação IAOpenClaw Brasil
- Dever de cuidado do ECA Digital: a lição do caso DiscordIDP Blog
- Boletim do CISC de Vulnerabilidadesgov.br
- New Cybercrime Group 'Slim Spider' Targets Brazilian Banks' Crypto and Instant Payment SystemsCISO AI / CrowdStrike coverage
- ANPD aplica maior multa da história por dados de menoresAraujo Policastro Advogados
- Telecom e radiodifusão terão planos setoriais para infraestruturas críticasAmirt
- Análise: bloqueio do Discord expõe fragilidades da proteção de dados no Brasil360 News
- Brasilianische Banken verkaufen Kryptowährungen an Kunden, ohne sie in ihren Büchern zu führenCryptoNews.net
- Brazil's banks sell crypto to clients while keeping it off their balance sheetsCryptopolitan
- Los bancos brasileños venden criptomonedas a sus clientes sin registrarlas en sus libros contablesMitre
- Brazil banks add crypto but hold none on balance sheetsCrypto.news
- Exigências de Pentest para Bancos e Instituições FinanceirasVantico
- Banco Central atualiza regras do Pix para reforçar segurança | Diário TVGloboplay
- Pix: consumidor ganha mais prazo para contestar devoluções fraudulentasHora AGHA
- Global Digital Policy Roundup: August 2026Tech Policy Press
- Pedro Martins - análise sobre a multa da ANPD à ByteDance/TikTokData Privacy Brasil Research
- CISA KEV Flash: 12 CVEs Added — Microsoft, SonicWall, N-able and Adobe Commerce Under Active AttackSecurityArsenal
- Exploited SonicWall SMA1000 Flaws Need More Than PatchingQuasa
- CVE-2026-83548 – SonicWall SMA1000 WorkPlace Unauthenticated SSRFProjectDiscovery
- RECOMENDAÇÃO 17/2026GSI/CTIR Gov
- RECOMENDAÇÃO 17/2026GSI/CTIR Gov
- Chinese network hacks '.gov.br' websites in online betting schemeBNLData (Brasil)
- Brazilian government and education websites abused for SEO manipulation by Gambling GoblinThe Hacker News
- Congresso entra em compasso de espera após esforço concentrado; veja o que ficou para trásND Mais
- Coyote Banking Trojan targets Brazilian usersSecurity Affairs
- Golpe do Pix em e-commerce: 90 lojas afetadas no BrasilIstoÉ Dinheiro
- Redbelt Security aponta ataques contra Microsoft e VMwareItsection
- Microsoft's Two-Track Patch Tuesday: Cloud Identity Flaws Fixed Before Disclosure, Windows Still Catching UpYahoo Tech
- Microsoft Patch Tuesday: 974 Bugs, 2 Zero-Days [2026]Shattered.io
- Bulletin de sécurité Commvault (AV26-899)Centre canadien pour la cybersécurité
- Bulletin de sécurité Fortinet (AV26-898)Centre canadien pour la cybersécurité
- Critical Infrastructure Threat Intelligence BriefingBorder Cyber Group
- Quando a informação que protege uma cidade passa a ameaçá-laUniversidade Federal de Juiz de Fora (UFJF)
- GSI define diretrizes para planos de segurança de infraestruturas críticasAtlas Público
- Agência multa TikTok em R$ 153,7 milhões por falhas na proteção de dados de crianças e adolescentesDrops de Jogos / UAI
- Brazylia karze ByteDance za dane nieletnich na TikTokuNeoteo
- Le Brésil inflige 153,7 millions de R$ à ByteDance pour les données de mineurs sur TikTokNeoteo
- ¿Qué puede aprender Brasil de la regulación global en ciberseguridad?Telefónica
- Deepfake pode transformar biometria facial em uma falsa sensação de segurança nos bancosPortal Contábeis
- GPT-6 assusta o mundo, mas lei de IA do Brasil emperra há 3 anosTV Sim Brasil
- Lula defende inteligência artificial em português para reduzir dependência externaBrasil em Folhas
- GPT-6 assusta o mundo, mas lei de IA do Brasil emperra há 3 anosTV Sim Brasil
- Esforço concentrado do Congresso precisa ter Marco Legal de Cibersegurança na agendaConvergência Digital
- Golpe do sósia usa tecnologia para tentar burlar biometriaAgência Brasil
- Golpe do sósia usa tecnologia para tentar enganar biometria facialTV Sim Brasil
- Weltweiter SEO-Betrug: Gambling Goblin kapert brasilianische RegierungsseitenIT-daily
- ブラジル政府サイトを悪用した大規模SEO詐欺JAPANSecuritySummit
- Tema Segurança DigitalCongresso em Foco
- Marco Legal da IA: por que a votação nunca acontece no BrasilPortalsegurancatec
- Nova regra do Pix agora permite anexar provas para contestar golpes; vejaTechtudo
- ИИ научил хакеров взламывать быстрее. Прятаться пока не научилRambler
- Agencia brasileña multa a TikTok por fallos en la protección de datos de menoresLa República Online
- Alerta por fraude agéntico en Colombia: la nueva era de la inteligencia artificial que suplanta identidades en la bancaElextra Medios
- 7th September – Threat Intelligence Report - Gambling Goblin campaign overviewCheck Point Research
- Thegentlemen ransomware claims Lider AviacaoTechWalrus
- Brazil's ANPD Uses a Guest-Session Theory to Fine TikTok $30 Million — and Rewrite What 'Processing' MeansPeople of Internet
- MPF cobra TikTok após encontrar anúncios de mercúrio direcionados a garimpeiros no BrasilO Globo
- Radar de Privacidade HDPO — Edição 20HDPO
- El ransomware crece 25.5% en América Latina y México concentra 17.93% de los ataquesEl Economista
- Vírus brasileiro automatiza invasões com IA e vende ...Fenati
- BraZetsu | Mallory malware profileMallory
- Mais uma exchange cripto fecha as portas no Brasil sob nova regulação do BCInfoMoney
- Comprovante do Pix vai mudar após Banco Central decidir banir propagandas e fechar o cerco contra golpesNSC Total
- チェック・ポイント・リサーチ、中国語話者の脅威グループ「Gambling Goblin」を発見し、大規模なSEO詐欺の手口を公開Check Point Software Technologies
- Sedigi defende integração entre setores para prevenir fraudes digitaisMinistério da Justiça e Segurança Pública
- Los atacantes aprovechan el uso continuo de herramientas de IA para atacar organizaciones en América LatinaPalo Alto Networks Unit 42
- Atacantes expõem uso contínuo de ferramentas de IA em ataques contra organizações na América LatinaPalo Alto Networks Unit 42
- Novas regras do PIX: BC amplia segurança e combate a fraudesG1
- 'Breeze Comet' Tears Into Brazilian & Global Financial SystemsDarkReading
- Comissão de Segurança Pública apresenta parecer sobre o PL 3751/2025Atlas Público
- Comissão de Segurança Pública apresenta substitutivo ao PL 3751/2025 para combater crimes financeiros virtuaisAtlas Público
- Comissão aprova projeto que aumenta pena por indução a crime onlineTV Sim Brasil
- Instrução Normativa BCB nº 774: Análise e ImpactosCadoc.ai
- Versão 2 — Instrução Normativa BCB N° 774Okai
- BC monitora uso de IA por instituições financeiras e mapeia riscosJornal de Brasília
- BCB amplia regras do Pix para informar bloqueios, padronizar comprovantes e reforçar contestaçãoAtlas Público
- Sistemas mais complexos acentuam riscos cibernéticosValor Econômico
- Agência multa TikTok em R$ 153,7 milhões por falhas na proteção de dados de crianças e adolescentesCCBJ
- MED do Pix: o dinheiro que você recebeu pode ser bloqueado — e o prazo mudouApogeu.tech
- Vexy Ransomware ransomware group — victims, leak site & IOCsDarkfield
- Attacks — AI-Augmented Intrusions in Latin AmericaMachine Speed - AI-Cyber Intelligence
- AI-Augmented Intrusions Hit Latin American Government and FinanceCloud Security Alliance (CSA) Labs
- Reconhecimento facial é suspenso nas escolas públicas do ParanáQuero Bolsa
- Proteção de dados de crianças e adolescentes exige mais que adequação à LGPDR7 / Portal EdiCase
- Proteção de dados de crianças e adolescentes exige mais que adequação à LGPDTerra
- A peneira do BC começa a enxugar o mercado de criptomoedasVeja
- BC proíbe anúncios e ofertas em comprovantes de pagamento do PixCNN Brasil
- Coinext encerra operações no Brasil: Veja como sacar ...TechCripto
- Coinext encerra operações, culpa BC e amplia onda de fechamento de corretoras cripto no BrasilPortal do Bitcoin
- Banco Central proíbe publicidade em comprovantes do PixTribuna do Agreste
- Pix: a nova regra de segurança para ajudar a evitar golpes - BBCBBC News Brasil
- Campaña secuestra tráfico de sitios gubernamentales ...Nivel4
- Alternative CISO Daily Briefing – 2026-09-03Cloud Security Alliance
- CVE-2026-73749 - Exploits & SeverityFeedly
- Risky BulletinRisky Business
- Attackers Expose Ongoing AI Tool Use Targeting Organizations in Latin AmericaPalo Alto Networks Unit 42
- CISO Daily Briefing – September 3, 2026Cloud Security Alliance
- PL 1828/2023 - Senado FederalSenado Federal
- Ransomware.live victim databaseRansomware.live
- PL 169/2026 - ficha de tramitaçãoSenado Federal (Brasil)
- Cobertura sobre projetos contra fraudes eletrônicasCongresso em Foco
- Regulamentação de cripto: cinco pontos que empresas precisam comprovar para obter autorização do Banco CentralFincatch
- PL 2780/2024 - ficha de tramitaçãoSenado Federal (Brasil)
- Brazil udario na ByteDance zbog podataka maloletnikaNaslovi.net / PCPress
- PL 5255/2026Senado Federal do Brasil
- 「Gambling Goblin」、ブラジル政府機関サイトをSEO兵器に変えるBlackHatNews Tokyo
- Senado aprova projeto do Redata, que incentiva data centers no BrasilCorreio24horas
- Biometria em Canteiros de Obra e LGPDDataGuide
- Вредоносные модули Apache для SEO-накрутки — VMTechVMTech
- Gaming the system: how a Chinese-speaking actor turned Brazilian government sites into an SEO weaponCheck Point Research
- Projeto de Lei n° 5184, de 2026 - Senado FederalSenado Federal
- Marco legal da IA no Brasil: o que está em discussãoAvia Hub
- Fraudes financeiras cibernéticas estão mais sofisticadas, alerta BCCNN Brasil
- Proteção de dados pessoais no Brasil: passado, presente e futuroData Privacy Brasil
- BC alerta para criptomoedas no escoamento de fraudesSpaceMoney
- ANPD suspende o uso de reconhecimento facial em escolas públicas do ParanáData Privacy Brasil
- Breeze Comet did not phish bank customers. It got inside Pix, STR and Boleto and pushed hundreds of transactionsRootnotes.in
- USDC in Brazil: Rails, BRL Stablecoins & the Arc AngleTrustSwap
- Nova regra do Pix para combater fraudes entra em vigorTecmundo
- Grupo hacker mira sistemas de pagamentos no Brasil e usa IA para acelerar ataques, mostra GoogleValor Econômico
- Bolsonaro AI Video: Brazil Court Rules on Deepfake BanThe Rio Times
- TSE deepfake: Tribunal define regras para uso de IA nas eleiçõesG1 (Globo)
- A era da autorregulação acabou? Plataformas digitais entram em uma nova fase de responsabilidade no BrasilBroadcast / Saftec Digital
- ANPD abre tomadas de subsídios sobre próxima agenda regulatória e avaliação de resultado regulatórioAgência Nacional de Proteção de Dados (ANPD)
- TikTok é multado em R$ 153,7 milhões pela ANPDQuasa.io
- Como é a nova regra do PIX que pode ajudar a inibir golpesG1
- Requisitos de segurança do BACEN: guia para instituições financeirasProdist
- Fintech Laws and Regulations 2026 | BrazilGlobal Legal Insights
- ANPD Vira Agência Reguladora: O Que a Lei 15.352/2026 ...DataGuide
- SonicWall SMA 1000 : zero-days chainés CVSS 10, KEV CISAAyinedjimi Consultants
- LGPD na prática jurídica: lições das recentes sanções e o papel da advocaciaProcessei
- Hackers invadem empresas brasileiras e fazem centenas de transações fraudulentas via PixCybersecBrazil
- Incentivo para instalação de data centers no Brasil é aprovado pelo SenadoAgência Senado
- Brazil Bans Advertising and Hyperlinks on Pix Payment Receipts from March 2027ClearingPost
- LGPD no varejo: principais riscos e desafiosDataGuide
- Nova regulação de ativos virtuais (SPSAV): quais são as principais mudanças?BlockBR
- LGPD no marketing: o que pode e o que não podeDataGuide
- Dados de saúde e LGPD: o guia de governança para clínicasDataGuide
- Fraudes financeiras cibernéticas estão cada vez mais sofisticadas, diz Banco CentralValor Econômico
- ISO 27701: o que é, para que serve e por que é o próximo ...DataGuide
- Aprovada punição para quem incita crimes em ambientes coletivos (PL 2170/2023)Rádio Senado
- Projeto de Lei nº 3066/2025 - ficha de tramitaçãoSenado Federal (Brasil)
- Brasil acelera sistema para monitorear operaciones con criptomonedas en tiempo realCryptonews
- Nova regra do Pix começa a valer nesta terça-feira (01/09)DOL
- BACEN estende regras prudenciais às prestadoras de ativos virtuaisVidigal Neto Advogados
- PL 1077/2019 - situação da tramitaçãoCongresso Nacional (Brasil)
- Banco Central aperta regras e transforma auditoria de exchanges no BrasilBitNotícias
- O que o Brasil tem a dizer sobre o acordo bilionário da Meta nos EUAUOL Tilt
- PSAV: o que é e qual o prazo para se adequar à regulação do Banco CentralTransfeera
- Entra em vigor nova regra do Banco Central nessa terça-feiraIstoÉ Dinheiro
- Governo lança medidas para padronizar uso de biometria em portos e aeroportosG1
- Golpes com IA: como a legislação e o mercado respondem às fraudes biométricasAJN1
- IA reforça defesa dos bancos no combate à fraudeValor Econômico
- Ferramenta amplia o cerco e rastreia a trilha do dinheiroValor Econômico
- Brazil becomes biggest regulatory test yet of online safety enforcementBiometric Update
- Regulações Banco Central (BACEN): BCB 538, CMN 4658...Vantico
- Projeto de lei assegura ressarcimento a vítima de fraude com PixPoder360
- Troca de chip acende alerta de fraude para bancos e operadoras que cruzam dados do celularReal Nacional
- Fraudes digitais e engenharia social: a responsabilidade civil das instituições bancárias e de pagamentoJusBrasil
- Financially Motivated Threat Actor BREEZE COMET Targets BrazilGoogle Cloud Blog
- Emperador ransomware group claims breach of Uniguaçu (Brazilian education sector)Threadlinqs Intelligence
- Accountability na LGPD: prova substitui o papelOnery
- Brazil tightens its grip on cryptocurrencies after a $180 million theftArabic Trader
- Gambling Goblin Turns Brazilian Government Sites Into SEO WeaponsInfosecurity Magazine
- Comitê-Executivo da CREDEN realiza 2ª reunião anualGabinete de Segurança Institucional da Presidência da República (GSI)
- Internet-Exposed OT: Why 100+ Water-Sector Systems Were TargetedOrasec
- Tributação especial para datacenters está na pauta do Senado esta semanaRádio Senado
- Banco Central do Brasil vai lançar sistema de alerta contra ameaças cripto após ataque de US$ 180 milhõesBingX
- Cid Gomes deve relatar o PL do Redata no SenadoAgência Infra
- Бразилия внедряет систему оповещения о криптовалютах для нейтрализации киберугрозBitcoin News
- Brazylia wdraża system ostrzegania o kryptowalutach w celu neutralizacji zagrożeń cybernetycznychBitcoin News
- Two Brazil central bank rules landed in AugustDomestic Monero (blog)
- Senado pode votar na próxima semana incentivos fiscais para data centersAgência Senado
- Núcleo de Excelência em OftalmologiaBreachsense
- CrowdStrike’s Record Quarter Has a Clear CatalystMonetaryElite
- Veja novas regras do Banco Central para criptoativosASA Brasil
- Yahoo Tech, PreferredData, EmberOT, Orasec, The Hacker NewsYahoo Tech, PreferredData, EmberOT, Orasec, The Hacker News
- AI-Generated Exploits and OT SecurityZscaler
- Bancos e fintechs debatem inovação e maior regulaçãoValor Econômico
- Redata avança no Congresso, mas data centers no Brasil não garantem soberania digitalAtitude Popular
- Desenvolvimento seguroSevenRed
- Regular a inteligência artificial sem sufocar o futuroiG Economia
- ラテンアメリカにおける不正検知・防止市場の規模、シェア、動向、成長および2026~2034年の予測Market Insights
- Como o Banco Central vai usar IA para detectar fraude no PixGCN / Banco Central do Brasil
- BCB avança em vigilância de corretoras com HypernativeSpaceMoney
- RadarCoop – Atualização Semanal – 26/8/2026Jornal Coop
- Jornal Cruzeiro do SulJornal Cruzeiro do Sul
- Alcolumbre diz que vai pautar Redata na semana que vemTNonline
- ANPD impõe multa de R$ 153,7 milhões ao TikTok e critica respostas genéricas sobre dados de criançasPortal Veredão
- O produto é o problema: acordo da Meta com a Justiça americana sobre redes sociais tem impactos para além dos EUATerra
- Resolução BCB nº 584 amplia controles sobre Criptoativos e reforça mecanismos de prevenção a fraudesCryptoid
- KRYBIT Ransomware Gang: 13 Victims in 48 HoursSecurity Arsenal
- TCU dá 60 dias para Saúde explicar atraso em 97% das entregas de medicamentos à FiocruzBioRed Brasil
- Ataque hacker no TJMT suspende prazos e audiências em MT - UOLUOL
- Ataque hacker paralisa sistemas do Tribunal de Justiça do Mato GrossoConvergência Digital
- TJMT aciona PF e Polícia Civil após ataque cibernéticoMutum Notícias
- Hackers invadem sistema do BRB e desviam R$ 43 milhõesConvergência Digital
- Ataque cibernético ao BRB desvia R$ 43 milhõesIT Show
- BRBJUS desvia R$ 43 milhões do TJ-BA | Quenty AIQuenty AI
- Ransomware no Brasil em 2026: grupos ativos e setoresTripla
- Brasil sofre 4 mil ciberataques por semana e manufatura industrial é o principal alvoAutoData
- Brasil registrou 753,8 bilhões de tentativas de ataque cibernético em um anoG1
- Ransomware attacks in Brazil: 157 confirmed incidents, 2018 ...RansomNews
- Intrusão no TJMT paralisa sistemas judiciaisIBSEC
- Cibersegurança: ataques com IA e falhas críticas 2026IT Show
- Nota à sociedade sobre incidente de segurança em sua infraestrutura tecnológicaTribunal de Justiça de Mato Grosso
- Nota à sociedade sobre incidente de segurança na infraestrutura tecnológicaTribunal de Justiça de Mato Grosso
- Rede chinesa ataca sites governamentais brasileiros com fraude de apostasFala Canedo
- TCU manda INSS reforçar segurança após vazamento de dadosFolha de S.Paulo
- Brazil INSS AI Agent Attack Steals 375 LoginsThe Rio Times
- Ataque cibernético tira PJe e outros sistemas do TJMT do arTeleSíntese
- Ataque cibernético expõe fragilidades do TJMT e especialista em segurança cita falta de informação sobre extensão do problemaOlhar Direto
- Polícia derruba plataforma suspeita de vender dados pessoaisRevista Oeste
- Brasil informa Europa sobre suposta interferência eleitoral de EUA e RússiaCNN Brasil
- Brasil informou autoridades francesas e alemãs sobre suposta interferência eleitoral dos EUA e da RússiaDiário do Comércio
- Grupo de Vorcaro acessou sistemas do MPF para obter dados sigilosos e monitorar adversários, revela PFBrasil 247
- LGPD em Debate: STF Define Limites para Requisição de Dados em 2026CanalERP
- ANPD multa recorde: O que muda agora no tratamento de dados de menoresMigalhas
- Prefeitura do Rio de Janeiro atualiza índice de adequação à LGPDConsultor Jurídico (ConJur)
- ANPD cobra Discord por lives ativas após suspensãoSpaceMoney
- LockBit 5.0 Compromises Camorim Serviços Marítimos - DeXposeDeXpose
- Vexy Ransomware | WatchGuard TechnologiesWatchGuard Technologies
- TheGentlemen Ransomware Attack on Multipla Contabilidade EmpresarialMalware.news
- MINISTÉRIO DA FAZENDA - SECRETARIA DA RECEITA FEDERAL DO BRASIL data breach — Emperador ransomware attack (2026)Orizon Darkfield
- Ransomware in Brazil: attacks hit record high in 2026Skyone Solutions
- ALERTA 87/2026 — Vulnerabilidade em Cisco Identity Services Engine (CVE-2026-76460)Gabinete de Segurança Institucional (CTIR Gov)
- ALERTA 84/2026 — Vulnerabilidade em Microsoft Windows (CVE-2026-85880)Gabinete de Segurança Institucional (CTIR Gov)
- RECOMENDAÇÃO 15/2026 — Vulnerabilidade em Microsoft Exchange Server (CVE-2026-62911)Gabinete de Segurança Institucional (CTIR Gov)
- Boletim de Vulnerabilidades de 28-09-2026 — Exploração ativa de bypass de autenticação em dispositivos FortinetCentro Integrado de Segurança Cibernética (CISC)
- Receita Federal Do Brasil Ransomware Claim (2026) — What’s Alleged & Am I Affected?RecentBreaches
- Emperador Targets Receita Federal do Brasil in Ransomware AttackDexpose
