Manuais Archives - Página 2 de 13 - Cloud security resource
Cloud security resource

Categoria: Manuais

  • Ataque cibernético apaga cadastro nacional de imóveis e paralisa romênia

    Ataque cibernético apaga cadastro nacional de imóveis e paralisa romênia

    Ataque apaga cadastro nacional de imóveis e paralisa mercado imobiliário da Romênia Um ataque cibernético de grandes proporções atingiu a Agência Nacional de Cadastro e de Publicidade Imobiliária da Romênia (ANCPI) e resultou na exclusão quase total do banco de dados de registros de terras do país. A invasão foi seguida de uma tentativa de…

  • Falha crítica wp2shell no wordpress permite Rce sem login: versões afetadas

    Falha crítica “wp2shell” no núcleo do WordPress expõe milhões de sites a RCE sem autenticação Pesquisadores da empresa de segurança Searchlight Cyber revelaram uma vulnerabilidade grave no núcleo do WordPress que permite execução remota de código (RCE) sem necessidade de autenticação. A falha, apelidada de “wp2shell”, atinge especificamente as versões 6.9.0 a 6.9.4 e 7.0.0…

  • Vazamento de dados de 500 mil pacientes do Isac leva Anpd a processo de sanção

    Vazamento de dados de 500 mil pacientes do Isac leva Anpd a processo de sanção

    Vazamento expõe dados de 500 mil pacientes de unidades de saúde geridas pelo ISAC e leva ANPD a abrir processo de sanção A Agência Nacional de Proteção de Dados (ANPD) instaurou um processo administrativo sancionador contra o Instituto Saúde e Cidadania (ISAC), organização social responsável pela gestão de unidades públicas de saúde em diversos estados,…

  • Ataque cibernético derruba lucro da asahi em um terço e expõe custo real

    Ataque cibernético derruba lucro da asahi em um terço e expõe custo real

    Ataque cibernético derruba em mais de um terço o lucro do grupo Asahi e expõe custo real dos incidentes digitais O grupo japonês Asahi Group Holdings, gigante do setor de bebidas, sentiu de forma contundente o impacto financeiro de um ataque cibernético ocorrido em setembro de 2025. De acordo com comunicado corporativo divulgado em 8…

  • Common insecure configurations in Aws, azure and Gcp and how to fix them fast

    The fastest way to fix common insecure configurations in AWS, Azure and GCP is to run read-only audits first, then apply small, reversible changes: tighten IAM, lock public access to storage, restrict security groups/firewalls, enable logging, rotate secrets and enforce encryption with managed keys, starting from your highest-value accounts. Quick Risk Snapshot: AWS, Azure, GCP…

  • Continuous cloud security monitoring with metrics, logs, alerts and event correlation

    Continuous cloud security monitoring with metrics, logs, alerts and event correlation

    Continuous cloud security monitoring combines metrics, centralized logs, real-time alerts and event correlation to detect and respond to threats quickly. Start by defining business‑aligned security objectives, then choose ferramentas de monitoramento contínuo de logs em nuvem and SIEM platforms, configure safe alert thresholds, build correlation rules and automate only well‑tested, reversible responses. Monitoring objectives and…

  • Zero trust network access (ztna) and Sse to protect remote cloud access

    Zero trust network access (ztna) and Sse to protect remote cloud access

    Zero Trust Network Access (ZTNA) and Security Service Edge (SSE) protect remote access to cloud resources by replacing flat VPN connectivity with identity‑centric, application‑level access. You authenticate users and devices, evaluate context (location, posture, risk), then grant least‑privilege access only to specific apps, continuously monitoring sessions and blocking or isolating risky behavior. Essential Controls for…

  • Security in saas, paas and iaas: shared responsibilities and hidden risks

    Security in saas, paas and iaas: shared responsibilities and hidden risks

    For security in SaaS, PaaS and IaaS, choose based on how much control you truly need versus how much complexity you can reliably manage. In Brazil (pt_BR), many teams are safer starting SaaS-first, PaaS where you build code, and tightly-governed IaaS only where low-level control or regulatory constraints demand it. Top security contrasts at a…

  • Practical hardening guide for Aws, azure and google cloud security teams

    Practical hardening guide for Aws, azure and google cloud security teams

    Use this guide to harden AWS, Azure and Google Cloud with safe, repeatable steps: lock down identities, segment networks, harden workloads, configure managed services securely, protect pipelines and ensure logging plus incident playbooks. The focus is practical checklists and patterns your security team in Brazil can apply quickly. Critical hardening targets for cloud security Establish…

  • Zero trust in the cloud: implementing least-trust models in multi-cloud environments

    Zero trust in the cloud: implementing least-trust models in multi-cloud environments

    Zero trust na nuvem in multi‑cloud means every request is verified based on identity, device, context and policy, regardless of network location. To implement it safely, start with an accurate asset and identity inventory, design minimal‑trust zones, enforce continuous authentication, microsegment workloads, automate policies, and track clear security and reliability metrics. Foundations to Prioritize Before…