<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Substack de ResolveSec]]></title><description><![CDATA[O meu Substack pessoal]]></description><link>https://resolvesec.substack.com</link><image><url>https://substackcdn.com/image/fetch/$s_!qk81!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc14cace1-1573-42ab-9981-032693d297d0_4501x4501.png</url><title>Substack de ResolveSec</title><link>https://resolvesec.substack.com</link></image><generator>Substack</generator><lastBuildDate>Fri, 03 Apr 2026 19:01:21 GMT</lastBuildDate><atom:link href="https://resolvesec.substack.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[ResolveSec]]></copyright><language><![CDATA[pt]]></language><webMaster><![CDATA[resolvesec@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[resolvesec@substack.com]]></itunes:email><itunes:name><![CDATA[ResolveSec]]></itunes:name></itunes:owner><itunes:author><![CDATA[ResolveSec]]></itunes:author><googleplay:owner><![CDATA[resolvesec@substack.com]]></googleplay:owner><googleplay:email><![CDATA[resolvesec@substack.com]]></googleplay:email><googleplay:author><![CDATA[ResolveSec]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[The “Autonomous AI” Lie: The Moltbook Case and Your Money]]></title><description><![CDATA[Many entrepreneurs and managers are making a fatal mistake: they believe the hype before verifying the foundations.]]></description><link>https://resolvesec.substack.com/p/the-autonomous-ai-lie-the-moltbook</link><guid isPermaLink="false">https://resolvesec.substack.com/p/the-autonomous-ai-lie-the-moltbook</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Thu, 02 Apr 2026 08:10:16 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!40zl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49047fc7-f429-4fac-a493-91c5f1a3e8b1_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!40zl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49047fc7-f429-4fac-a493-91c5f1a3e8b1_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!40zl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49047fc7-f429-4fac-a493-91c5f1a3e8b1_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!40zl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49047fc7-f429-4fac-a493-91c5f1a3e8b1_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!40zl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49047fc7-f429-4fac-a493-91c5f1a3e8b1_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!40zl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49047fc7-f429-4fac-a493-91c5f1a3e8b1_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!40zl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49047fc7-f429-4fac-a493-91c5f1a3e8b1_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/49047fc7-f429-4fac-a493-91c5f1a3e8b1_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1946786,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://resolvesec.substack.com/i/186964229?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49047fc7-f429-4fac-a493-91c5f1a3e8b1_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!40zl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49047fc7-f429-4fac-a493-91c5f1a3e8b1_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!40zl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49047fc7-f429-4fac-a493-91c5f1a3e8b1_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!40zl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49047fc7-f429-4fac-a493-91c5f1a3e8b1_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!40zl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F49047fc7-f429-4fac-a493-91c5f1a3e8b1_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Many entrepreneurs and managers are making a fatal mistake: they believe the hype before verifying the foundations.</p><p>The case of Moltbook &#8212; a social network where &#8220;AI agents&#8221; supposedly interacted on their own &#8212; is a perfect lesson in how a lack of basic security can destroy trust in your business in the blink of an eye.</p><h4>What Happened (The Short Version)</h4><p>Moltbook promised the future: an internet of AI agents working independently. But behind the scenes, the door was wide open. Researchers from Wiz discovered a public database without any password protection.</p><p>Inside were millions of API keys and tokens.</p><p><strong>The real risk:</strong> Anyone could use those keys to impersonate an AI, publish content, or manipulate data. That &#8220;autonomy&#8221; everyone admired? It could have just been someone faking it, because the house keys were left under the doormat.</p><h4>Why This Destroys Businesses</h4><p>If you sell technology or use AI to automate your business, your most valuable currency is trust.</p><ul><li><p><strong>Hype vs. Reality:</strong> Moltbook grew fast because people thought the AIs were independent. When it was revealed the system was insecure, the narrative shifted from &#8220;incredible AI&#8221; to &#8220;poorly configured system.&#8221;</p></li><li><p><strong>Security Is Not Optional:</strong> This wasn&#8217;t a failure of artificial intelligence. It was a failure of basic hygiene. They forgot the basics: access control and credential protection.</p></li><li><p><strong>The Entrepreneur&#8217;s Responsibility:</strong> If you give an AI the authority to act on your behalf, your security standards must be higher, not lower.</p></li></ul><h4>What You Can Learn Today (Practical Actions)</h4><p>Don&#8217;t let ambition run faster than your security. If you are building or using AI platforms:</p><ol><li><p><strong>Protect the Keys:</strong> Treat API keys like the combination to your safe. Never leave them in accessible locations or without authentication.</p></li><li><p><strong>Verify Identity:</strong> Ensure that what the AI does can be traced and verified. If you can&#8217;t prove who did what, your automation is a risk, not an asset.</p></li><li><p><strong>Security First, Hype Later:</strong> Before aggressive marketing about &#8220;autonomy,&#8221; ensure your backend systems are mature.</p></li></ol><h4>Conclusion: Intelligence Without Control Is Danger</h4><p>Moltbook shows that AI only has value if we can trust those who hold the keys. In the world of cybersecurity, the focus is shifting toward <strong>Agentic Threat Intelligence (ATI)</strong> &#8212; where AI works with rules, governance, and context awareness.</p><p>The goal? To let AI investigate and respond to threats in minutes, but within controlled and secure boundaries.</p><p><strong>Would you like us to analyze if your current AI systems are leaving your &#8220;house keys&#8221; exposed like in the Moltbook case?<br></strong></p><div><hr></div><h2>A Mentira da &#8220;IA Aut&#243;noma&#8221;: O Caso Moltbook e o Teu Dinheiro</h2><p>Muitos empreendedores e gestores est&#227;o a cometer um erro fatal: acreditam no <em>hype</em> antes de verificarem os alicerces.</p><p>O caso da <strong>Moltbook</strong> &#8212; uma rede social onde &#8220;agentes de IA&#8221; supostamente interagiam sozinhos &#8212; &#233; a li&#231;&#227;o perfeita de como a falta de seguran&#231;a b&#225;sica pode destruir a confian&#231;a no teu neg&#243;cio num piscar de olhos.</p><div><hr></div><h3>O Que Aconteceu (A Vers&#227;o Curta)</h3><p>A Moltbook prometia o futuro: uma internet de agentes de IA a trabalhar de forma independente. Mas, nos bastidores, a porta estava aberta. Investigadores da <strong>Wiz</strong> descobriram uma base de dados p&#250;blica, sem qualquer password.</p><p>L&#225; dentro, estavam <strong>milh&#245;es de chaves API e tokens</strong>.</p><p><strong>O risco real:</strong> Qualquer pessoa podia usar essas chaves para se fazer passar por uma IA, publicar conte&#250;do ou manipular dados. Aquela &#8220;autonomia&#8221; que todos admiravam? Podia ser apenas algu&#233;m a fingir, porque as chaves de casa estavam debaixo do tapete.</p><div><hr></div><h3>Por Que &#201; Que Isto Destr&#243;i Neg&#243;cios?</h3><p>Se tu vendes tecnologia ou usas IA para automatizar o teu neg&#243;cio, a tua moeda mais valiosa &#233; a <strong>confian&#231;a</strong>.</p><ol><li><p><strong>Hype vs. Realidade:</strong> A Moltbook cresceu r&#225;pido porque as pessoas achavam que as IAs eram independentes. Quando se soube que o sistema era inseguro, a narrativa mudou de &#8220;IA incr&#237;vel&#8221; para &#8220;sistema mal configurado&#8221;.</p></li><li><p><strong>Seguran&#231;a N&#227;o &#201; Opcional:</strong> N&#227;o foi uma falha da intelig&#234;ncia artificial. Foi uma falha de <strong>higiene b&#225;sica</strong>. Esqueceram-se do b&#225;sico: controlo de acessos e prote&#231;&#227;o de credenciais.</p></li><li><p><strong>Responsabilidade do Empreendedor:</strong> Se d&#225;s autoridade a uma IA para agir em teu nome, o teu padr&#227;o de seguran&#231;a tem de ser <strong>mais alto</strong>, n&#227;o mais baixo.</p></li></ol><div><hr></div><h3>O Que Podes Aprender Hoje (A&#231;&#245;es Pr&#225;ticas)</h3><p>N&#227;o deixes que a ambi&#231;&#227;o corra mais depressa do que a tua seguran&#231;a. Se est&#225;s a construir ou a usar plataformas de IA:</p><ul><li><p><strong>Protege as Chaves:</strong> Trata as chaves API como se fossem o c&#243;digo do teu cofre. Nunca as deixes em locais acess&#237;veis ou sem autentica&#231;&#227;o.</p></li><li><p><strong>Verifica a Identidade:</strong> Garante que o que a IA faz pode ser rastreado e verificado. Se n&#227;o consegues provar quem fez o qu&#234;, a tua automa&#231;&#227;o &#233; um risco, n&#227;o um ativo.</p></li><li><p><strong>Seguran&#231;a Primeiro, Hype Depois:</strong> Antes de marketing agressivo sobre &#8220;autonomia&#8221;, garante que os teus sistemas de <em>backend</em> s&#227;o maduros.</p></li></ul><div><hr></div><h3>Conclus&#227;o: Intelig&#234;ncia Sem Controlo &#201; Perigo</h3><p>A Moltbook mostra que a IA s&#243; tem valor se pudermos confiar em quem det&#233;m as chaves. No mundo da ciberseguran&#231;a, o foco est&#225; a mudar para a <strong>Agentic Threat Intelligence (ATI)</strong> &#8212; onde a IA trabalha com regras, governan&#231;a e consci&#234;ncia do contexto.</p><p><strong>O objetivo?</strong> Deixar a IA investigar e responder a amea&#231;as em minutos, mas dentro de limites controlados e seguros.</p><p><strong>Quer que n&#243;s fa&#231;amos uma analise se os seus sistemas de IA atuais est&#227;o a deixar as &#8220;chaves de casa&#8221; expostas como no caso Moltbook?</strong></p><p></p>]]></content:encoded></item><item><title><![CDATA[Your Website Isn’t Slow—It’s Under Attack ]]></title><description><![CDATA[(And Russia Isn&#8217;t Stopping)]]></description><link>https://resolvesec.substack.com/p/your-website-isnt-slowits-under-attack</link><guid isPermaLink="false">https://resolvesec.substack.com/p/your-website-isnt-slowits-under-attack</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Thu, 26 Mar 2026 09:10:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Gg7v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862e08ae-d7f0-467f-9a06-8c641dc5560e_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Gg7v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862e08ae-d7f0-467f-9a06-8c641dc5560e_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Gg7v!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862e08ae-d7f0-467f-9a06-8c641dc5560e_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Gg7v!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862e08ae-d7f0-467f-9a06-8c641dc5560e_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Gg7v!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862e08ae-d7f0-467f-9a06-8c641dc5560e_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Gg7v!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862e08ae-d7f0-467f-9a06-8c641dc5560e_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Gg7v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862e08ae-d7f0-467f-9a06-8c641dc5560e_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/862e08ae-d7f0-467f-9a06-8c641dc5560e_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1772663,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://resolvesec.substack.com/i/186957042?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862e08ae-d7f0-467f-9a06-8c641dc5560e_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Gg7v!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862e08ae-d7f0-467f-9a06-8c641dc5560e_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!Gg7v!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862e08ae-d7f0-467f-9a06-8c641dc5560e_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!Gg7v!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862e08ae-d7f0-467f-9a06-8c641dc5560e_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!Gg7v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F862e08ae-d7f0-467f-9a06-8c641dc5560e_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Most managers look at a crashing website and think: <em>&#8220;It&#8217;s just a server glitch.&#8221;</em> <strong>Wrong.</strong></p><p>Between January 26 and February 1, 2026, the pro-Russian group <strong>NoName057(16)</strong> launched a massive campaign with nearly <strong>6,000 coordinated attacks</strong>.</p><p>They aren&#8217;t hobbyists playing in a basement. They are using a specialized framework called <strong>DDoSia</strong> to paralyze critical infrastructure across 16 countries simultaneously.</p><div><hr></div><h3>The Digital War Zone</h3><p>The UK was the primary target (55% of attacks), but Ukraine and Czechia are also in the crosshairs. The goal? <strong>Total chaos.</strong> They don&#8217;t just hit governments; they hit:</p><ul><li><p><strong>Private Sector (49.2%)</strong>: Companies like yours, business services, and financial institutions.</p></li><li><p><strong>Critical Infrastructure</strong>: Water utilities, energy brokers, and transportation systems.</p></li><li><p><strong>Secure Portals</strong>: 65.1% of attacks focused on <strong>Port 443 (HTTPS)</strong>. They are going after the very services you thought were &#8220;safe&#8221; because they have the green padlock.</p></li></ul><h3>The &#8220;Exhaustion&#8221; Strategy</h3><p>They use a lethal hybrid approach. It&#8217;s like sending a million trucks to block the highway (Volumetric Attack) while simultaneously sending a thousand fake customers to your front door just to ask for the time and tie up your staff (Application Layer Attack).</p><p>The result? <strong>Your legitimate customers can&#8217;t get in.</strong> You lose money and reputation every single second your services are down.</p><div><hr></div><h3>What You Must Do (Before the Lights Go Out)</h3><p>Migrating to a defensive posture isn&#8217;t a &#8220;next quarter&#8221; project. It is a survival necessity for <strong>today</strong>.</p><ol><li><p><strong>Cloud-Based Shields</strong>: If you are running your own infrastructure without a shield (Cloudflare, Akamai, AWS Shield), you are asking to be run over. Filter the traffic before it hits your doorstep.</p></li><li><p><strong>Rate Limiting</strong>: Configure your servers to stop &#8220;talking&#8221; to entities that aren&#8217;t actually transacting. Lock down your HTTP GET and POST request limits.</p></li><li><p><strong>Incident Response</strong>: Who do you call at 3 AM when the site drops? If you don&#8217;t have a specific number and a battle plan ready, you&#8217;ve already lost.</p></li></ol><p><strong>The Bottom Line:</strong> Threats like NoName057(16) thrive on negligence. They use crowdsourced volunteers and gamification to attack. You must use technology and strategy to survive.</p><p>Don&#8217;t let your company become a &#8220;statistic&#8221; in the next SOCRadar threat report.</p><p><strong>Would you like us to draft a technical checklist for your IT team based on these specific attack vectors?</strong></p><div><hr></div><h2>O Teu Site N&#227;o Est&#225; Lento, Est&#225; Sob Ataque (E a R&#250;ssia n&#227;o vai parar)</h2><p>A maioria dos gestores olha para um site em baixo e pensa: <em>&#8220;&#201; o servidor.&#8221;</em> <strong>Errado.</strong></p><p>Entre 26 de janeiro e 1 de fevereiro de 2026, o grupo pro-Russo <strong>NoName057(16)</strong> lan&#231;ou uma campanha massiva com quase <strong>6.000 ataques coordenados</strong>.</p><p>Eles n&#227;o est&#227;o a brincar aos hackers na cave. Est&#227;o a usar uma ferramenta chamada <strong>DDoSia</strong> para paralisar infraestruturas cr&#237;ticas em 16 pa&#237;ses simultaneamente.</p><h3>O Cen&#225;rio de Guerra Digital</h3><p>O Reino Unido foi o alvo principal (55% dos ataques), mas a Ucr&#226;nia e a Ch&#233;quia tamb&#233;m est&#227;o na mira. O objetivo? <strong>Caos total.</strong> Eles n&#227;o atacam apenas o governo. Eles atacam:</p><ul><li><p><strong>Setor Privado (49%):</strong> Empresas como a tua, servi&#231;os financeiros e consultoras.</p></li><li><p><strong>Infraestrutura Cr&#237;tica:</strong> &#193;gua, energia e transportes.</p></li><li><p><strong>Portas Seguras:</strong> 65% dos ataques focaram-se no <strong>Porto 443 (HTTPS)</strong>. Ou seja, tentaram quebrar os servi&#231;os que tu achavas que estavam &#8220;seguros&#8221; porque tinham o cadeado verde.</p></li></ul><h3>A Estrat&#233;gia de &#8220;Exaust&#227;o&#8221;</h3><p>Eles usam uma abordagem h&#237;brida. &#201; como se enviassem um milh&#227;o de cami&#245;es para bloquear a autoestrada (Ataque Volum&#233;trico) e, ao mesmo tempo, enviassem mil pessoas falsas para a porta da tua loja apenas para perguntar as horas e ocupar os teus funcion&#225;rios (Ataque de Aplica&#231;&#227;o).</p><p>O resultado? <strong>O teu cliente leg&#237;timo n&#227;o consegue entrar.</strong> E tu perdes dinheiro a cada segundo.</p><h3>O Que Tens de Fazer (Antes que a luz se apague)</h3><p>A migra&#231;&#227;o para uma postura defensiva n&#227;o &#233; um &#8220;projeto para o pr&#243;ximo trimestre&#8221;. &#201; uma necessidade de sobreviv&#234;ncia para <strong>hoje</strong>.</p><ol><li><p><strong>Prote&#231;&#227;o na Nuvem:</strong> Se geres a tua pr&#243;pria infraestrutura sem um escudo (Cloudflare, Akamai, AWS Shield), est&#225;s a pedir para ser atropelado. Filtra o tr&#225;fego antes que ele chegue &#224; tua porta.</p></li><li><p><strong>Limita&#231;&#227;o de Taxa (Rate Limiting):</strong> Configura os teus servidores para n&#227;o aceitarem &#8220;conversas&#8221; infinitas de quem n&#227;o est&#225; a comprar nada.</p></li><li><p><strong>Plano de Resposta:</strong> Quem deves ligar &#224;s 3 da manh&#227; quando o site cair? Se n&#227;o tens um n&#250;mero na agenda, j&#225; perdeste.</p></li></ol><p><strong>Resumo:</strong> Amea&#231;as como o grupo NoName057(16) prosperam na neglig&#234;ncia. Eles usam volunt&#225;rios e gamifica&#231;&#227;o para atacar. Tu tens de usar tecnologia e estrat&#233;gia para sobreviver.</p><p>N&#227;o sejas a empresa que serve de &#8220;estat&#237;stica&#8221; no pr&#243;ximo relat&#243;rio da SOCRadar.</p><p><strong>Visita-nos em: https://www.resolvesec.com </strong></p>]]></content:encoded></item><item><title><![CDATA[O teu maior inimigo não é um hacker Russo ]]></title><description><![CDATA[(&#201; o teu funcion&#225;rio preferido)]]></description><link>https://resolvesec.substack.com/p/o-teu-maior-inimigo-nao-e-um-hacker</link><guid isPermaLink="false">https://resolvesec.substack.com/p/o-teu-maior-inimigo-nao-e-um-hacker</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Thu, 19 Mar 2026 09:10:42 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!hcfb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cf99d92-8301-41bd-8ffc-94552e89e0bd_1024x1024.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hcfb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cf99d92-8301-41bd-8ffc-94552e89e0bd_1024x1024.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hcfb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cf99d92-8301-41bd-8ffc-94552e89e0bd_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!hcfb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cf99d92-8301-41bd-8ffc-94552e89e0bd_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!hcfb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cf99d92-8301-41bd-8ffc-94552e89e0bd_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!hcfb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cf99d92-8301-41bd-8ffc-94552e89e0bd_1024x1024.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hcfb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cf99d92-8301-41bd-8ffc-94552e89e0bd_1024x1024.png" width="1024" height="1024" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/5cf99d92-8301-41bd-8ffc-94552e89e0bd_1024x1024.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1024,&quot;width&quot;:1024,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1465048,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://resolvesec.substack.com/i/186286297?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cf99d92-8301-41bd-8ffc-94552e89e0bd_1024x1024.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hcfb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cf99d92-8301-41bd-8ffc-94552e89e0bd_1024x1024.png 424w, https://substackcdn.com/image/fetch/$s_!hcfb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cf99d92-8301-41bd-8ffc-94552e89e0bd_1024x1024.png 848w, https://substackcdn.com/image/fetch/$s_!hcfb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cf99d92-8301-41bd-8ffc-94552e89e0bd_1024x1024.png 1272w, https://substackcdn.com/image/fetch/$s_!hcfb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F5cf99d92-8301-41bd-8ffc-94552e89e0bd_1024x1024.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A maioria dos fundadores e CEOs vive com medo de um ataque externo. Imaginam uma sala escura com c&#243;digo verde a cair.</p><p><strong>Tenho m&#225;s not&#237;cias: O perigo j&#225; est&#225; dentro do teu escrit&#243;rio. E ele usa Slack.</strong></p><p>Um novo relat&#243;rio da Fortinet acaba de revelar a verdade brutal: <strong>77% das empresas</strong> sofreram incidentes de seguran&#231;a internos nos &#250;ltimos 18 meses.</p><p>Aqui est&#225; o que precisas de saber, sem &#8220;tech-speak&#8221;.</p><h3>1. O problema n&#227;o &#233; mal&#237;cia, &#233; estupidez (ou conveni&#234;ncia)</h3><p>N&#227;o tens espi&#245;es infiltrados. Tens pessoas a tentar trabalhar mais r&#225;pido.</p><ul><li><p><strong>62% dos incidentes</strong> v&#234;m de erro humano puro.</p></li><li><p>O teu melhor funcion&#225;rio quer resumir uma ata, mete dados confidenciais no <strong>ChatGPT</strong>, e pronto &#8212; os teus segredos industriais agora fazem parte do treino da IA.</p></li><li><p>Algu&#233;m envia um Excel para o email pessoal para trabalhar no fim de semana. <strong>Parab&#233;ns, acabaste de perder o controlo dos teus dados.</strong></p></li></ul><h3>2. O Pre&#231;o da &#8220;Rapidez&#8221;</h3><p>Achas que investir em seguran&#231;a &#233; caro? V&#234; estes n&#250;meros:</p><ul><li><p><strong>41% das empresas</strong> perderam entre <strong>1 a 10 milh&#245;es de d&#243;lares</strong> com estes &#8220;erros&#8221;.</p></li><li><p>N&#227;o &#233; s&#243; o dinheiro. &#201; a reputa&#231;&#227;o, as multas regulat&#243;rias e o tempo de paragem operacional.</p></li><li><p>Os teus dados de clientes e propriedade intelectual s&#227;o o teu maior ativo. Se n&#227;o os proteges, n&#227;o tens um neg&#243;cio, tens um castelo de cartas.</p></li></ul><h3>3. O ponto cego dos gestores</h3><p><strong>72% dos l&#237;deres de seguran&#231;a</strong> admitem: eles n&#227;o fazem ideia de como os funcion&#225;rios usam os dados. As ferramentas antigas (DLP tradicional) est&#227;o mortas. Elas bloqueiam ficheiros, mas n&#227;o entendem o <strong>comportamento</strong>.</p><p>Se n&#227;o sabes <em>quem</em> est&#225; a fazer <em>o qu&#234;</em> com a tua informa&#231;&#227;o, est&#225;s a voar &#224;s cegas.</p><h3>O teu Plano de A&#231;&#227;o (No-Regret Moves):</h3><p>Se queres parar de sangrar dados, precisas de tr&#234;s coisas hoje:</p><ol><li><p><strong>Visibilidade Total:</strong> Tens de saber que ferramentas de IA e SaaS a tua equipa est&#225; a usar. Se n&#227;o consegues medir, n&#227;o consegues gerir.</p></li><li><p><strong>An&#225;lise Comportamental:</strong> Para de olhar para ficheiros e come&#231;a a olhar para comportamentos anormais (ex: algu&#233;m a descarregar toda a base de dados de clientes &#224;s 2h da manh&#227;).</p></li><li><p><strong>Cultura &gt; Software:</strong> Alinha os RH, o Jur&#237;dico e o IT. A seguran&#231;a n&#227;o &#233; um &#8220;problema dos tipos da inform&#225;tica&#8221;, &#233; um problema de gest&#227;o de risco.</p></li></ol><p><strong>Resumo:</strong> A seguran&#231;a em 2026 n&#227;o &#233; sobre construir muros mais altos. &#201; sobre saber o que se passa dentro da casa.</p><p>Quem ignora o risco interno est&#225; a pagar para ser roubado. N&#227;o sejas essa pessoa.</p><p><strong>--- English Version Below ---</strong></p><h1>Your Biggest Enemy Isn&#8217;t a Russian Hacker (It&#8217;s Your Favorite Employee)</h1><p>Most founders and CEOs live in fear of an external attack. They imagine a dark room with green code falling down.</p><p><strong>I have bad news: The danger is already inside your office. And it&#8217;s using Slack.</strong></p><p>A new report from Fortinet just revealed the brutal truth: <strong>77% of companies</strong> suffered internal security incidents in the last 18 months.</p><p>Here is what you need to know, without the &#8220;tech-speak&#8221;.</p><h3>1. The Problem Isn&#8217;t Malice, It&#8217;s Stupidity (or Convenience)</h3><p>You don&#8217;t have undercover spies. You have people trying to work faster.</p><ul><li><p><strong>62% of incidents</strong> come from pure human error.</p></li><li><p>Your best employee wants to summarize a meeting, pastes confidential data into <strong>ChatGPT</strong>, and boom &#8212; your trade secrets are now part of the AI&#8217;s training data.</p></li><li><p>Someone sends an Excel sheet to their personal email to work over the weekend. <strong>Congratulations, you just lost control of your data.</strong></p></li></ul><h3>2. The Price of &#8220;Speed&#8221;</h3><p>Think investing in security is expensive? Look at these numbers:</p><ul><li><p><strong>41% of companies</strong> lost between <strong>$1M and $10M</strong> due to these &#8220;mistakes&#8221;.</p></li><li><p>It&#8217;s not just the money. It&#8217;s reputation, regulatory fines, and operational downtime.</p></li><li><p>Your customer data and intellectual property are your biggest assets. If you don&#8217;t protect them, you don&#8217;t have a business, you have a house of cards.</p></li></ul><h3>3. The Management Blind Spot</h3><p><strong>72% of security leaders</strong> admit: they have no clue how employees are using data. Old tools (traditional DLP) are dead. They block files but don&#8217;t understand <strong>behavior</strong>.</p><p>If you don&#8217;t know <em>who</em> is doing <em>what</em> with your information, you&#8217;re flying blind.</p><h3>Your Action Plan (No-Regret Moves):</h3><p>If you want to stop bleeding data, you need three things today:</p><ol><li><p><strong>Full Visibility:</strong> You must know what AI and SaaS tools your team is using. If you can&#8217;t measure it, you can&#8217;t manage it.</p></li><li><p><strong>Behavioral Analysis:</strong> Stop looking at files and start looking at abnormal behaviors (e.g., someone downloading your entire customer database at 2 AM).</p></li><li><p><strong>Culture &gt; Software:</strong> Align HR, Legal, and IT. Security isn&#8217;t an &#8220;IT problem,&#8221; it&#8217;s a risk management problem.</p></li></ol><p><strong>Summary:</strong> Security in 2026 isn&#8217;t about building higher walls. It&#8217;s about knowing what&#8217;s happening inside the house.</p><p>Those who ignore internal risk are paying to be robbed. Don&#8217;t be that guy.</p><p>Visit us at: https://www.resolvesec.com</p>]]></content:encoded></item><item><title><![CDATA[O Teu Cofre Digital Vai Ficar Transparente]]></title><description><![CDATA[(E a Europol est&#225; preocupada)]]></description><link>https://resolvesec.substack.com/p/o-teu-cofre-digital-vai-ficar-transparente</link><guid isPermaLink="false">https://resolvesec.substack.com/p/o-teu-cofre-digital-vai-ficar-transparente</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Thu, 12 Mar 2026 08:20:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!dosr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7551f04-87cc-4297-b37d-284efc72499a_2752x1536.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dosr!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7551f04-87cc-4297-b37d-284efc72499a_2752x1536.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dosr!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7551f04-87cc-4297-b37d-284efc72499a_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!dosr!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7551f04-87cc-4297-b37d-284efc72499a_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!dosr!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7551f04-87cc-4297-b37d-284efc72499a_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!dosr!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7551f04-87cc-4297-b37d-284efc72499a_2752x1536.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dosr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7551f04-87cc-4297-b37d-284efc72499a_2752x1536.png" width="1456" height="813" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7551f04-87cc-4297-b37d-284efc72499a_2752x1536.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:813,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6259571,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://resolvesec.substack.com/i/185544618?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7551f04-87cc-4297-b37d-284efc72499a_2752x1536.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dosr!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7551f04-87cc-4297-b37d-284efc72499a_2752x1536.png 424w, https://substackcdn.com/image/fetch/$s_!dosr!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7551f04-87cc-4297-b37d-284efc72499a_2752x1536.png 848w, https://substackcdn.com/image/fetch/$s_!dosr!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7551f04-87cc-4297-b37d-284efc72499a_2752x1536.png 1272w, https://substackcdn.com/image/fetch/$s_!dosr!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7551f04-87cc-4297-b37d-284efc72499a_2752x1536.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A maioria dos gestores ouve falar de &#8220;Computa&#231;&#227;o Qu&#226;ntica&#8221; e desliga.<br>Pensam: <em>&#8220;Isso &#233; coisa para daqui a 10 anos. Preocupo-me depois.&#8221;</em></p><p>Tenho m&#225;s not&#237;cias.<br>Se trabalhas com dados financeiros ou sens&#237;veis, o &#8220;depois&#8221; j&#225; come&#231;ou.</p><p>A Europol acabou de lan&#231;ar um relat&#243;rio urgente para o setor financeiro.<br>A mensagem &#233; simples: <strong>A encripta&#231;&#227;o que usas hoje vai morrer.</strong><br>Os computadores qu&#226;nticos v&#227;o conseguir partir as chaves de seguran&#231;a atuais como se fossem palitos.</p><h4>&#8220;Mas os computadores qu&#226;nticos ainda n&#227;o existem...&#8221;</h4><p>Existem, mas ainda n&#227;o s&#227;o potentes o suficiente.<br>Mas o ataque j&#225; come&#231;ou. Chama-se <strong>&#8220;Harvest Now, Decrypt Later&#8221;</strong>.</p><p>Os hackers (e governos estrangeiros) est&#227;o a roubar os teus dados encriptados <em>hoje</em>.<br>Eles guardam-nos.<br>E daqui a 5 anos, quando tiverem o computador qu&#226;ntico, desencriptam tudo.<br>Se os teus dados (segredos industriais, dados de clientes, registos financeiros) ainda forem valiosos daqui a 5 anos... <strong>j&#225; foste roubado e nem sabes.</strong></p><h4>O Plano da Europol (Sem &#8220;Tech-Speak&#8221;)</h4><p>O relat&#243;rio diz para parares de tentar &#8220;resolver tudo de uma vez&#8221;.<br>Em vez disso, usa uma abordagem de <strong>Risco vs. Tempo de Vida</strong>:</p><ol><li><p><strong>Dados de Curta Dura&#231;&#227;o:</strong> (Ex: uma password de uso &#250;nico). N&#227;o te preocupes.</p></li><li><p><strong>Dados de Longa Dura&#231;&#227;o:</strong> (Ex: Hipotecas, Segredos de Estado, Dados Gen&#233;ticos). <strong>Prioridade M&#225;xima.</strong></p></li></ol><h4>O Que Podes Fazer Hoje (A&#231;&#245;es &#8220;Sem Arrependimento&#8221;)</h4><p>A Europol chama-lhe &#8220;No-Regret Moves&#8221;. Coisas que deves fazer j&#225;, independentemente de quando o computador qu&#226;ntico chegar:</p><ol><li><p><strong>Invent&#225;rio de Criptografia:</strong> Sabes onde &#233; que a tua empresa usa encripta&#231;&#227;o? A maioria n&#227;o sabe. Descobre.</p></li><li><p><strong>Limpeza de &#8220;Lixo&#8221;:</strong> Elimina pr&#225;ticas obsoletas que j&#225; s&#227;o inseguras hoje (como SHA-1 ou chaves RSA curtas).</p></li><li><p><strong>Encripta&#231;&#227;o H&#237;brida:</strong> Come&#231;a a testar algoritmos p&#243;s-qu&#226;nticos em coisas n&#227;o cr&#237;ticas (como o site p&#250;blico).</p></li></ol><p><strong>Resumo:</strong><br>A migra&#231;&#227;o para a seguran&#231;a p&#243;s-qu&#226;ntica n&#227;o &#233; um projeto de TI para 2030.<br>&#201; um projeto de gest&#227;o de risco para 2026.<br>Quem come&#231;ar agora, vai gastar menos e sofrer menos.<br>Quem esperar pelo &#8220;dia Q&#8221;, vai entrar em p&#226;nico.</p><p>N&#227;o sejas o gestor que &#233; apanhado com as cal&#231;as na m&#227;o quando a matem&#225;tica mudar.</p><p>Visita-nos em: https://www.resolvesec.com</p>]]></content:encoded></item><item><title><![CDATA[A tua equipa está a usar o ChatGPT para programar? ]]></title><description><![CDATA[(Ent&#227;o tens um problema de seguran&#231;a)]]></description><link>https://resolvesec.substack.com/p/a-tua-equipa-esta-a-usar-o-chatgpt</link><guid isPermaLink="false">https://resolvesec.substack.com/p/a-tua-equipa-esta-a-usar-o-chatgpt</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Thu, 05 Mar 2026 09:10:58 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ohIi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffccc0d2d-0328-4e37-8acb-a068460c93e0_1718x917.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ohIi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffccc0d2d-0328-4e37-8acb-a068460c93e0_1718x917.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ohIi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffccc0d2d-0328-4e37-8acb-a068460c93e0_1718x917.png 424w, https://substackcdn.com/image/fetch/$s_!ohIi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffccc0d2d-0328-4e37-8acb-a068460c93e0_1718x917.png 848w, https://substackcdn.com/image/fetch/$s_!ohIi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffccc0d2d-0328-4e37-8acb-a068460c93e0_1718x917.png 1272w, https://substackcdn.com/image/fetch/$s_!ohIi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffccc0d2d-0328-4e37-8acb-a068460c93e0_1718x917.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ohIi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffccc0d2d-0328-4e37-8acb-a068460c93e0_1718x917.png" width="1456" height="777" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fccc0d2d-0328-4e37-8acb-a068460c93e0_1718x917.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:777,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2432459,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://resolvesec.substack.com/i/185519596?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffccc0d2d-0328-4e37-8acb-a068460c93e0_1718x917.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ohIi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffccc0d2d-0328-4e37-8acb-a068460c93e0_1718x917.png 424w, https://substackcdn.com/image/fetch/$s_!ohIi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffccc0d2d-0328-4e37-8acb-a068460c93e0_1718x917.png 848w, https://substackcdn.com/image/fetch/$s_!ohIi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffccc0d2d-0328-4e37-8acb-a068460c93e0_1718x917.png 1272w, https://substackcdn.com/image/fetch/$s_!ohIi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffccc0d2d-0328-4e37-8acb-a068460c93e0_1718x917.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Se tens programadores na tua equipa, tenho uma novidade para ti: <strong>95% deles est&#227;o a usar IA para escrever c&#243;digo.</strong><br>N&#227;o interessa se tu permites ou n&#227;o. Eles est&#227;o a fazer.<br>Porque &#233; mais r&#225;pido. Porque &#233; mais f&#225;cil.</p><p>E isso &#233; &#243;timo para a produtividade.<br>Mas &#233; um pesadelo absoluto para a tua seguran&#231;a.</p><p>Um estudo novo da Black Duck confirmou o que todos suspeitamos:<br>Enquanto 95% das empresas usam IA para gerar c&#243;digo, <strong>apenas 24% verificam se esse c&#243;digo &#233; seguro.</strong></p><h4>O Problema da &#8220;Caixa Negra&#8221;</h4><p>Quando um humano escreve c&#243;digo, ele (geralmente) sabe o que escreveu.<br>Quando a IA escreve c&#243;digo, ela &#8220;vomita&#8221; blocos inteiros que funcionam... mas ningu&#233;m sabe bem o que est&#225; l&#225; dentro.</p><p>Estamos a encher o nosso software de:</p><ol><li><p><strong>Vulnerabilidades:</strong> A IA aprendeu com c&#243;digo da internet. Se o c&#243;digo na internet tinha bugs, o teu c&#243;digo novo tamb&#233;m tem.</p></li><li><p><strong>Problemas Legais:</strong> Aquele bocado de c&#243;digo que o Copilot sugeriu? Pode ter uma licen&#231;a que te obriga a tornar todo o teu software p&#250;blico.</p></li><li><p><strong>Depend&#234;ncias Fantasma:</strong> A IA adora importar bibliotecas que nem precisas, aumentando a superf&#237;cie de ataque.</p></li></ol><h4>A Regra de Ouro: Trata a IA como um &#8220;Estagi&#225;rio B&#234;bado&#8221;</h4><p>A IA &#233; r&#225;pida, mas n&#227;o &#233; respons&#225;vel.<br>Tu n&#227;o deixarias um estagi&#225;rio publicar c&#243;digo na produ&#231;&#227;o sem revis&#227;o, pois n&#227;o?<br>Ent&#227;o porque &#233; que deixas a IA?</p><p>Jason Soroko (da Sectigo) disse a melhor frase sobre isto:<br><em>&#8220;O c&#243;digo gerado por IA deve ser tratado como software de terceiros.&#8221;</em></p><p>Ou seja: N&#227;o confies. Verifica.</p><h4>O Que Tens de Fazer (O Plano de A&#231;&#227;o)</h4><p>N&#227;o pro&#237;bas a IA. Isso &#233; lutar contra a mar&#233;.<br>Em vez disso, cria barreiras de seguran&#231;a:</p><ol><li><p><strong>Exige SBOMs (Software Bill of Materials):</strong> &#201; a lista de ingredientes do teu software. Tens de saber exatamente o que est&#225; l&#225; dentro.</p></li><li><p><strong>Scan Autom&#225;tico:</strong> O volume de c&#243;digo vai explodir (estima-se que 95% do c&#243;digo ser&#225; IA at&#233; 2030). Humanos n&#227;o conseguem rever tudo. Precisas de ferramentas autom&#225;ticas que procurem bugs <em>antes</em> do c&#243;digo entrar.</p></li><li><p><strong>Pol&#237;tica de &#8220;Copy-Paste&#8221;:</strong> Deixa claro &#224; equipa: &#8220;Se a IA escreveu, tu &#233;s respons&#225;vel por entender cada linha antes de fazer commit.&#8221;</p></li></ol><p><strong>Resumo:</strong><br>A IA &#233; um acelerador.<br>Se o teu processo de seguran&#231;a for bom, vais andar mais r&#225;pido.<br>Se o teu processo de seguran&#231;a for mau, vais espetar-te contra a parede a 300km/h.</p><p>A escolha &#233; tua.</p><p>https://www.resolvesec.com</p>]]></content:encoded></item><item><title><![CDATA[O Teu “Cérebro de IA” Está Aberto ao Mundo ]]></title><description><![CDATA[(Alerta Cr&#237;tico n8n)]]></description><link>https://resolvesec.substack.com/p/o-teu-cerebro-de-ia-esta-aberto-ao</link><guid isPermaLink="false">https://resolvesec.substack.com/p/o-teu-cerebro-de-ia-esta-aberto-ao</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Thu, 26 Feb 2026 09:10:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1mU0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31967a23-60e0-499c-ab35-089f9cd97c88_1344x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1mU0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31967a23-60e0-499c-ab35-089f9cd97c88_1344x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1mU0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31967a23-60e0-499c-ab35-089f9cd97c88_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!1mU0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31967a23-60e0-499c-ab35-089f9cd97c88_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!1mU0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31967a23-60e0-499c-ab35-089f9cd97c88_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!1mU0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31967a23-60e0-499c-ab35-089f9cd97c88_1344x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1mU0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31967a23-60e0-499c-ab35-089f9cd97c88_1344x768.png" width="1344" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/31967a23-60e0-499c-ab35-089f9cd97c88_1344x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1344,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1610931,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://resolvesec.substack.com/i/184415401?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31967a23-60e0-499c-ab35-089f9cd97c88_1344x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1mU0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31967a23-60e0-499c-ab35-089f9cd97c88_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!1mU0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31967a23-60e0-499c-ab35-089f9cd97c88_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!1mU0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31967a23-60e0-499c-ab35-089f9cd97c88_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!1mU0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F31967a23-60e0-499c-ab35-089f9cd97c88_1344x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Se a tua empresa est&#225; a apostar em Automa&#231;&#227;o e Intelig&#234;ncia Artificial, h&#225; uma grande probabilidade de estares a usar o <strong>n8n</strong>.<br>&#201; a ferramenta do momento. Liga tudo a tudo. &#201; o sistema nervoso central das opera&#231;&#245;es modernas.</p><p>E &#233; exatamente por isso que esta not&#237;cia &#233; um pesadelo.</p><p>Foi descoberta uma falha de gravidade m&#225;xima (chamada &#8220;Ni8mare&#8221;) no n8n.<br>Neste momento, <strong>60.000 empresas</strong> t&#234;m as suas automa&#231;&#245;es expostas na internet, prontas a serem hackeadas.</p><h4>Porque &#233; que isto &#233; pior do que um site em baixo?</h4><p>O n8n n&#227;o guarda apenas &#8220;dados&#8221;. Ele guarda as <strong>chaves mestras</strong>.<br>Para automatizar processos, tu d&#225;s ao n8n acesso a tudo:</p><ul><li><p>As tuas chaves da OpenAI/ChatGPT.</p></li><li><p>As tuas credenciais da Base de Dados de Clientes.</p></li><li><p>Os teus tokens do Slack, Google Drive e CRM.</p></li></ul><p>Se um hacker entra no teu n8n, ele n&#227;o precisa de partir mais portas. Tu j&#225; lhe deste as chaves de todas as divis&#245;es da casa.<br>Ele pode roubar a tua propriedade intelectual, ler os teus dados confidenciais e usar a tua conta de IA para gerar custos astron&#243;micos.</p><h4>O Erro T&#233;cnico (Simplificado)</h4><p>A falha (CVE-2026-21858) permite que algu&#233;m de fora, sem password, engane o sistema e assuma o controlo total.<br>Basta teres um fluxo de trabalho (workflow) que aceite ficheiros (como um formul&#225;rio) para estares em risco.</p><h4>O Que Tens de Fazer (Agora, n&#227;o amanh&#227;)</h4><p>Se usas n8n (ou se a tua equipa de &#8220;Growth&#8221; ou &#8220;Inova&#231;&#227;o&#8221; usa), p&#225;ra de ler e faz isto:</p><ol><li><p><strong>Atualiza J&#225;:</strong> A vers&#227;o segura &#233; a <strong>1.121.0</strong> ou superior. Se tens uma vers&#227;o anterior, est&#225;s vulner&#225;vel.</p></li><li><p><strong>Esconde o Servidor:</strong> Porque &#233; que a tua ferramenta de automa&#231;&#227;o interna est&#225; acess&#237;vel a toda a internet? Coloca-a atr&#225;s de uma VPN ou restringe o acesso apenas ao IP do escrit&#243;rio.</p></li><li><p><strong>Roda as Chaves:</strong> Se o teu n8n esteve exposto sem atualiza&#231;&#227;o, assume o pior. Regenera as chaves de API (OpenAI, Google, etc.) que estavam l&#225; guardadas.</p></li></ol><p><strong>Resumo:</strong><br>A automa&#231;&#227;o d&#225; velocidade ao neg&#243;cio. Mas velocidade sem trav&#245;es &#233; apenas um acidente &#224; espera de acontecer.<br>N&#227;o deixes que a ferramenta que te poupa tempo seja a que te destr&#243;i o neg&#243;cio.</p><p>Verifica a vers&#227;o do n8n hoje.</p>]]></content:encoded></item><item><title><![CDATA[O Teu Site Moderno Tem uma Porta Aberta]]></title><description><![CDATA[(Alerta React/Next.js)]]></description><link>https://resolvesec.substack.com/p/o-teu-site-moderno-tem-uma-porta</link><guid isPermaLink="false">https://resolvesec.substack.com/p/o-teu-site-moderno-tem-uma-porta</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Thu, 19 Feb 2026 09:30:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!1rey!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F813be255-ab9f-4b2a-b7d9-07a830a0ad7e_1344x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!1rey!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F813be255-ab9f-4b2a-b7d9-07a830a0ad7e_1344x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!1rey!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F813be255-ab9f-4b2a-b7d9-07a830a0ad7e_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!1rey!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F813be255-ab9f-4b2a-b7d9-07a830a0ad7e_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!1rey!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F813be255-ab9f-4b2a-b7d9-07a830a0ad7e_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!1rey!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F813be255-ab9f-4b2a-b7d9-07a830a0ad7e_1344x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!1rey!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F813be255-ab9f-4b2a-b7d9-07a830a0ad7e_1344x768.png" width="1344" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/813be255-ab9f-4b2a-b7d9-07a830a0ad7e_1344x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1344,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:819905,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://resolvesec.substack.com/i/183652024?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F813be255-ab9f-4b2a-b7d9-07a830a0ad7e_1344x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!1rey!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F813be255-ab9f-4b2a-b7d9-07a830a0ad7e_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!1rey!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F813be255-ab9f-4b2a-b7d9-07a830a0ad7e_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!1rey!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F813be255-ab9f-4b2a-b7d9-07a830a0ad7e_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!1rey!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F813be255-ab9f-4b2a-b7d9-07a830a0ad7e_1344x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Se a tua empresa lan&#231;ou um site novo, uma &#225;rea de cliente ou uma app nos &#250;ltimos 2 anos, h&#225; 90% de probabilidade de estares a usar <strong>React</strong> ou <strong>Next.js</strong>.<br>&#201; a tecnologia da moda. &#201; r&#225;pida, &#233; bonita e os programadores adoram.</p><p>Mas o CNCS (Centro Nacional de Ciberseguran&#231;a) acabou de avisar: <strong>Tem um buraco gigante.</strong></p><h4>O Problema (Sem &#8220;Tech-Speak&#8221;)</h4><p>Imagina que tens uma loja com uma porta autom&#225;tica.<br>A porta devia abrir apenas para clientes.<br>Mas descobriram que se algu&#233;m gritar uma palavra m&#225;gica espec&#237;fica, a porta n&#227;o s&#243; abre, como d&#225; ao estranho as chaves do armaz&#233;m.</p><p>A falha (CVE-2025-55182) est&#225; no &#8220;motor&#8221; que faz o site funcionar (React Server Components).<br>Um hacker pode enviar um pedido simples pela internet (HTTP) e ganhar controlo do servidor.<br><strong>Sem login. Sem password. Acesso direto.</strong></p><h4>Quem Est&#225; em Risco?</h4><p>Quase toda a gente que investiu em &#8220;transforma&#231;&#227;o digital&#8221; recentemente.<br>Se usas:</p><ul><li><p><strong>Next.js</strong> (vers&#245;es 14, 15 ou 16)</p></li><li><p><strong>React</strong> (vers&#227;o 19)</p></li></ul><p>...ent&#227;o tens de agir.</p><h4>A Conversa que Tens de Ter Hoje</h4><p>N&#227;o tentes resolver isto sozinho. Chama a tua ag&#234;ncia web ou o teu chefe de desenvolvimento e pergunta isto:</p><ol><li><p><em>&#8220;O nosso site/app usa Next.js ou React Server Components?&#8221;</em></p></li><li><p><em>&#8220;Se sim, j&#225; atualiz&#225;mos para a vers&#227;o segura que saiu esta semana?&#8221;</em></p></li></ol><p>Se eles disserem &#8220;Ah, isso &#233; s&#243; para sites grandes&#8221;, <strong>est&#227;o a mentir</strong>.<br>Os hackers usam rob&#244;s que varrem a internet &#224; procura de qualquer site com esta vers&#227;o. N&#227;o interessa se &#233;s a Google ou a Padaria da Esquina. Se o software &#233; vulner&#225;vel, o rob&#244; entra.</p><h4>Resumo</h4><p>A tecnologia moderna &#233; fant&#225;stica para o neg&#243;cio, mas exige manuten&#231;&#227;o.<br>Um site n&#227;o &#233; um cartaz que colas na parede e esqueces. &#201; um organismo vivo.<br>Se n&#227;o o vacinas (atualizas), ele adoece.</p><p>Confirma a vers&#227;o hoje. N&#227;o deixes a porta da loja aberta.</p><p>Visita-nos em: https://www.resolvesec.com</p>]]></content:encoded></item><item><title><![CDATA[O teu antivírus diz que está tudo bem. Ele está a mentir. ]]></title><description><![CDATA[(O caso Nezha)]]></description><link>https://resolvesec.substack.com/p/o-teu-antivirus-diz-que-esta-tudo</link><guid isPermaLink="false">https://resolvesec.substack.com/p/o-teu-antivirus-diz-que-esta-tudo</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Thu, 12 Feb 2026 09:24:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!85vs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9601df-1efb-485e-9627-c8b9fb854fbe_1344x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!85vs!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9601df-1efb-485e-9627-c8b9fb854fbe_1344x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!85vs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9601df-1efb-485e-9627-c8b9fb854fbe_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!85vs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9601df-1efb-485e-9627-c8b9fb854fbe_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!85vs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9601df-1efb-485e-9627-c8b9fb854fbe_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!85vs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9601df-1efb-485e-9627-c8b9fb854fbe_1344x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!85vs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9601df-1efb-485e-9627-c8b9fb854fbe_1344x768.png" width="1344" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ec9601df-1efb-485e-9627-c8b9fb854fbe_1344x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1344,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1239348,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://resolvesec.substack.com/i/183230823?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9601df-1efb-485e-9627-c8b9fb854fbe_1344x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!85vs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9601df-1efb-485e-9627-c8b9fb854fbe_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!85vs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9601df-1efb-485e-9627-c8b9fb854fbe_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!85vs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9601df-1efb-485e-9627-c8b9fb854fbe_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!85vs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fec9601df-1efb-485e-9627-c8b9fb854fbe_1344x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Imagina que tens um sistema de alarme em casa que detecta ladr&#245;es.<br>Mas e se o ladr&#227;o entrar vestido com a farda da empresa de limpeza?<br>O alarme n&#227;o toca. Ele tem a chave. Ele &#8220;pertence&#8221; ali.</p><p>&#201; exatamente isto que est&#225; a acontecer agora nos servidores de muitas empresas.</p><p>Os hackers descobriram uma nova &#8220;farda de limpeza&#8221;: uma ferramenta chamada <strong>Nezha</strong>.<br>O Nezha n&#227;o &#233; um v&#237;rus. &#201; um software leg&#237;timo, <em>open-source</em>, usado por administradores de sistemas para monitorizar servidores. &#201; &#250;til, &#233; gr&#225;tis e funciona bem.</p><p>E &#233; por isso que &#233; perigoso.</p><h4>O Truque de Mestre (Zero Dete&#231;&#245;es)</h4><p>Os investigadores da Ontinue descobriram que os criminosos est&#227;o a instalar o Nezha nos sistemas das v&#237;timas.<br>Quando passaram o Nezha pelo VirusTotal (o motor que usa 72 antiv&#237;rus diferentes), sabes quantos detectaram perigo?<br><strong>Zero.</strong></p><p>Para o teu antiv&#237;rus, o Nezha &#233; &#8220;amigo&#8221;.<br>Mas nas m&#227;os do hacker, ele d&#225; acesso total (Root/System). Permite copiar ficheiros, correr comandos e controlar tudo remotamente.<br>&#201; o crime perfeito: usar as tuas pr&#243;prias ferramentas contra ti.</p><h4>A Era do &#8220;Living off the Land&#8221;</h4><p>Isto tem um nome t&#233;cnico: <em>Living off the Land</em> (Viver da Terra).<br>Os hackers deixaram de trazer as suas pr&#243;prias armas (malware) porque elas s&#227;o detectadas. Agora, usam as ferramentas que j&#225; existem no teu sistema (TeamViewer, AnyDesk, PowerShell, e agora Nezha).</p><p>&#201; como ser assaltado com a tua pr&#243;pria faca de cozinha.</p><h4>Como &#233; que te Proteges de Algo que &#233; &#8220;Leg&#237;timo&#8221;?</h4><p>Se o antiv&#237;rus est&#225; cego, tens de mudar a estrat&#233;gia.<br>Deixas de procurar &#8220;ficheiros maus&#8221; e come&#231;as a procurar <strong>&#8220;comportamentos estranhos&#8221;</strong>.</p><ol><li><p><strong>Invent&#225;rio Brutal:</strong> A tua equipa de TI sabe exatamente que ferramentas de acesso remoto (RMM) s&#227;o permitidas? Se o Nezha n&#227;o est&#225; na lista branca, &#233; para bloquear.</p></li><li><p><strong>Contexto &#233; Rei:</strong> Porque &#233; que o servidor de contabilidade est&#225; a comunicar com um IP na China &#224;s 3 da manh&#227; usando uma ferramenta de monitoriza&#231;&#227;o nova? O software pode ser leg&#237;timo, mas o comportamento n&#227;o &#233;.</p></li></ol><h4>A Pergunta para o Teu Diretor de TI:</h4><p><em>&#8220;N&#243;s bloqueamos ferramentas de acesso remoto n&#227;o autorizadas, ou confiamos apenas que o antiv&#237;rus vai apanhar tudo?&#8221;</em></p><p>Se a resposta for &#8220;confiamos no antiv&#237;rus&#8221;, tens a porta aberta.<br>Os hackers mudaram de t&#225;tica. A tua defesa tamb&#233;m tem de mudar.</p>]]></content:encoded></item><item><title><![CDATA[10.000 Empresas Têm a Porta Aberta]]></title><description><![CDATA[(E a culpa &#233; de um &#8220;Patch&#8221; de 2020)]]></description><link>https://resolvesec.substack.com/p/10000-empresas-tem-a-porta-aberta</link><guid isPermaLink="false">https://resolvesec.substack.com/p/10000-empresas-tem-a-porta-aberta</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Thu, 05 Feb 2026 09:30:08 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!tciF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fedab23-f9e4-423c-a770-415e95b114ac_1344x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!tciF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fedab23-f9e4-423c-a770-415e95b114ac_1344x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!tciF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fedab23-f9e4-423c-a770-415e95b114ac_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!tciF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fedab23-f9e4-423c-a770-415e95b114ac_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!tciF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fedab23-f9e4-423c-a770-415e95b114ac_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!tciF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fedab23-f9e4-423c-a770-415e95b114ac_1344x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!tciF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fedab23-f9e4-423c-a770-415e95b114ac_1344x768.png" width="1344" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7fedab23-f9e4-423c-a770-415e95b114ac_1344x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1344,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1271397,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://resolvesec.substack.com/i/183650975?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fedab23-f9e4-423c-a770-415e95b114ac_1344x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!tciF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fedab23-f9e4-423c-a770-415e95b114ac_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!tciF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fedab23-f9e4-423c-a770-415e95b114ac_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!tciF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fedab23-f9e4-423c-a770-415e95b114ac_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!tciF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7fedab23-f9e4-423c-a770-415e95b114ac_1344x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Imagina que tens um cofre de alta seguran&#231;a.<br>Tens uma chave (Password) e um c&#243;digo secreto (2FA).<br>Sentes-te seguro, certo?</p><p>Agora imagina que o ladr&#227;o descobre que, se escrever o teu nome com letras <strong>MAI&#218;SCULAS</strong> em vez de min&#250;sculas... o cofre abre sem pedir o c&#243;digo.</p><p>Parece uma piada de mau gosto?<br>N&#227;o &#233;. &#201; a realidade de <strong>10.000 empresas</strong> neste momento.</p><p>Uma falha cr&#237;tica nas Firewalls da <strong>Fortinet</strong> (uma das marcas mais usadas no mundo) permite que hackers entrem na tua rede saltando o 2FA.<br>Basta mudar uma letra no nome de utilizador. Sim, &#233; assim t&#227;o est&#250;pido.</p><h4>O Verdadeiro Esc&#226;ndalo (N&#227;o &#233; a falha)</h4><p>Bugs acontecem. O software tem falhas. &#201; normal.<br>O esc&#226;ndalo &#233; este: <strong>A Fortinet corrigiu isto em Julho de 2020.</strong></p><p>Estamos em 2026.<br>Passaram <strong>5 anos</strong>.<br>E ainda h&#225; 10.000 diretores de TI que n&#227;o carregaram no bot&#227;o &#8220;Atualizar&#8221;.</p><p>Isto n&#227;o &#233; um problema t&#233;cnico. &#201; um problema de <strong>neglig&#234;ncia de gest&#227;o</strong>.<br>Se a tua empresa for hackeada por isto, n&#227;o foi um &#8220;ciberataque sofisticado&#8221;. Foi porque deixaste a janela aberta durante 5 anos.</p><h4>Porque &#233; que isto te interessa? (O Custo da Pregui&#231;a)</h4><p>Os hackers adoram estas falhas &#8220;velhas&#8221;.<br>Eles n&#227;o querem ter trabalho. Eles usam scanners autom&#225;ticos que procuram estas firewalls desatualizadas.<br>Se a tua firewall aparecer na lista, eles entram. Instalam Ransomware. Pedem resgate.</p><p>E tu pagas milh&#245;es porque algu&#233;m se esqueceu de fazer uma manuten&#231;&#227;o b&#225;sica em 2021.</p><h4>A Pergunta para Fazer Hoje (Sem falta)</h4><p>N&#227;o assumas que est&#225; feito. A confian&#231;a &#233; boa, o controlo &#233; melhor.<br>Envia isto ao teu respons&#225;vel de TI agora:</p><p><em>&#8220;Temos equipamentos Fortinet? Se sim, confirma-me por escrito que n&#227;o estamos vulner&#225;veis ao CVE-2020-12812 (aquele do bypass de 2FA).&#8221;</em></p><p>Se a resposta demorar mais de 5 minutos... preocupa-te.<br>Se a resposta for &#8220;acho que sim&#8221;... preocupa-te muito.</p><p>A seguran&#231;a n&#227;o &#233; sobre comprar a ferramenta mais cara. &#201; sobre manter a ferramenta a funcionar.<br>Fecha a porta.</p>]]></content:encoded></item><item><title><![CDATA[A Tua Password “Secreta” já está na internet há 4 anos]]></title><description><![CDATA[(E tu continuas a us&#225;-la)]]></description><link>https://resolvesec.substack.com/p/a-tua-password-secreta-ja-esta-na</link><guid isPermaLink="false">https://resolvesec.substack.com/p/a-tua-password-secreta-ja-esta-na</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Thu, 29 Jan 2026 09:20:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!c9K6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5c2bed-7c81-4c32-bca3-d7edc902aaee_1344x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!c9K6!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5c2bed-7c81-4c32-bca3-d7edc902aaee_1344x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c9K6!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5c2bed-7c81-4c32-bca3-d7edc902aaee_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!c9K6!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5c2bed-7c81-4c32-bca3-d7edc902aaee_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!c9K6!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5c2bed-7c81-4c32-bca3-d7edc902aaee_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!c9K6!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5c2bed-7c81-4c32-bca3-d7edc902aaee_1344x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c9K6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5c2bed-7c81-4c32-bca3-d7edc902aaee_1344x768.png" width="1344" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ac5c2bed-7c81-4c32-bca3-d7edc902aaee_1344x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1344,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1238786,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://resolvesec.substack.com/i/183226987?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5c2bed-7c81-4c32-bca3-d7edc902aaee_1344x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!c9K6!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5c2bed-7c81-4c32-bca3-d7edc902aaee_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!c9K6!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5c2bed-7c81-4c32-bca3-d7edc902aaee_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!c9K6!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5c2bed-7c81-4c32-bca3-d7edc902aaee_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!c9K6!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fac5c2bed-7c81-4c32-bca3-d7edc902aaee_1344x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Vamos ser honestos por um minuto.<br>Tu tens aquela password. Aquela que usas para o email, para o Facebook, para o LinkedIn e, se calhar, at&#233; para o banco.<br>Talvez mudes um n&#250;mero no fim. Talvez ponhas uma mai&#250;scula.<br>Mas a base &#233; a mesma.</p><p>Tenho m&#225;s not&#237;cias: <strong>Os hackers j&#225; a t&#234;m.</strong></p><p>Um estudo novo da Kaspersky analisou todas as fugas de dados de 2025 e descobriu um n&#250;mero assustador:<br><strong>54% das passwords roubadas este ano J&#193; ERAM CONHECIDAS.</strong></p><p>Leste bem. Mais de metade das &#8220;novas&#8221; v&#237;timas foram hackeadas com chaves velhas. Chaves que j&#225; andavam a circular na Dark Web h&#225; 3 ou 4 anos.</p><h4>O Problema N&#227;o &#233; a Tecnologia, &#201;s Tu (Somos N&#243;s)</h4><p>N&#243;s somos criaturas de h&#225;bitos. E somos pregui&#231;osos.<br>A an&#225;lise mostrou que:</p><ul><li><p>10% das passwords t&#234;m datas (1990 a 2025). Parab&#233;ns, puseste o ano de nascimento do teu filho. Um g&#233;nio.</p></li><li><p>O cl&#225;ssico &#8220;12345&#8221; continua vivo.</p></li><li><p>Nomes pr&#243;prios e pa&#237;ses s&#227;o mais que muitos.</p></li></ul><p>O hacker n&#227;o precisa de ser um g&#233;nio do <em>Matrix</em> para entrar na tua conta. Ele s&#243; precisa de pegar numa lista antiga (que custa 5&#8364; na net) e testar.<br>Se tu &#233;s parte dos 54% que recicla passwords, ele entra. Simples.</p><h4>A Morte da Password (Finalmente)</h4><p>A ind&#250;stria da seguran&#231;a cansou-se de pedir &#224;s pessoas para criarem passwords complexas. Ningu&#233;m faz isso.<br>Por isso, a solu&#231;&#227;o mudou.</p><p>Se ainda est&#225;s a confiar na mem&#243;ria para a tua seguran&#231;a, est&#225;s em 2010.<br>Em 2026, tens duas sa&#237;das:</p><ol><li><p><strong>Gestor de Passwords:</strong> Um cofre digital que cria senhas gigantes e aleat&#243;rias para ti. Tu s&#243; decoras uma, ele decora as outras 500.</p></li><li><p><strong>Passkeys (O Futuro):</strong> Usar a tua cara (FaceID) ou o teu dedo (TouchID) como chave. Sem c&#243;digos para decorar, sem c&#243;digos para roubar.</p></li></ol><h4>O Desafio de Hoje</h4><p>Faz um favor a ti pr&#243;prio (e &#224; tua empresa).<br>Vai ao site <strong>&#8220;Have I Been Pwned&#8221;</strong>. P&#245;e l&#225; o teu email.<br>Se aparecer a vermelho... para tudo o que est&#225;s a fazer.</p><p><strong>Muda a password. Ativa o 2FA (MFA).</strong><br>N&#227;o sejas a estat&#237;stica dos 54%.<br>N&#227;o facilites o trabalho a quem te quer roubar.</p>]]></content:encoded></item><item><title><![CDATA[O teu site WordPress é uma bomba relógio]]></title><description><![CDATA[(E tu n&#227;o sabes quando vai rebentar)]]></description><link>https://resolvesec.substack.com/p/o-teu-site-wordpress-e-uma-bomba</link><guid isPermaLink="false">https://resolvesec.substack.com/p/o-teu-site-wordpress-e-uma-bomba</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Thu, 22 Jan 2026 09:25:19 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!iskH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaa7c69-6f5c-41e1-a1e9-50c3a0dcc688_1344x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!iskH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaa7c69-6f5c-41e1-a1e9-50c3a0dcc688_1344x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!iskH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaa7c69-6f5c-41e1-a1e9-50c3a0dcc688_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!iskH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaa7c69-6f5c-41e1-a1e9-50c3a0dcc688_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!iskH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaa7c69-6f5c-41e1-a1e9-50c3a0dcc688_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!iskH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaa7c69-6f5c-41e1-a1e9-50c3a0dcc688_1344x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!iskH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaa7c69-6f5c-41e1-a1e9-50c3a0dcc688_1344x768.png" width="1344" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bcaa7c69-6f5c-41e1-a1e9-50c3a0dcc688_1344x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1344,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1030105,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://resolvesec.substack.com/i/183658286?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaa7c69-6f5c-41e1-a1e9-50c3a0dcc688_1344x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!iskH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaa7c69-6f5c-41e1-a1e9-50c3a0dcc688_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!iskH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaa7c69-6f5c-41e1-a1e9-50c3a0dcc688_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!iskH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaa7c69-6f5c-41e1-a1e9-50c3a0dcc688_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!iskH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbcaa7c69-6f5c-41e1-a1e9-50c3a0dcc688_1344x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Se tens um site, h&#225; 43% de hip&#243;teses de ele ser feito em <strong>WordPress</strong>.<br>&#201; a plataforma mais popular do mundo. &#201; f&#225;cil, &#233; flex&#237;vel e, muitas vezes, &#233; barato de fazer.</p><p>Mas h&#225; um &#8220;custo escondido&#8221; que ningu&#233;m te conta quando te vendem o site por 500&#8364; ou 1000&#8364;.<br><strong>A Manuten&#231;&#227;o.</strong></p><p>Esta semana, mais um plugin popular (o <em>King Addons for Elementor</em>) abriu uma cratera de seguran&#231;a.<br>Uma falha cr&#237;tica (CVE-2025-8489) permite que qualquer estranho se torne <strong>Administrador</strong> do teu site.<br>Sem password. Sem hackear a NASA.<br>Ele simplesmente &#8220;entra&#8221; e passa a ser o dono. Pode apagar tudo, roubar dados de clientes ou redirecionar o teu tr&#225;fego para sites de burlas.</p><h4>O Problema N&#227;o &#233; o WordPress. &#201; o &#8220;Set and Forget&#8221;.</h4><p>O erro n&#250;mero 1 dos empres&#225;rios &#233; tratar o site como um folheto impresso.<br><em>&#8220;J&#225; paguei, est&#225; feito, agora &#233; s&#243; deixar estar.&#8221;</em></p><p><strong>Errado.</strong><br>Um site WordPress &#233; feito de pe&#231;as de Lego (Plugins).<br>Tu tens o plugin para o formul&#225;rio, o plugin para o design (Elementor), o plugin para o SEO.<br>Cada um destes plugins &#233; feito por uma empresa diferente. E cada um deles precisa de atualiza&#231;&#245;es constantes.</p><p>Se tu n&#227;o atualizas:</p><ol><li><p>O plugin fica velho.</p></li><li><p>Os hackers descobrem uma falha (como esta).</p></li><li><p>Eles usam rob&#244;s para varrer a internet &#224; procura de quem n&#227;o atualizou.</p></li><li><p>Tu &#233;s hackeado.</p></li></ol><p>N&#227;o &#233; uma quest&#227;o de &#8220;se&#8221;, &#233; uma quest&#227;o de &#8220;quando&#8221;.<br>S&#243; nesta falha espec&#237;fica, j&#225; foram registadas <strong>50.000 tentativas de ataque</strong>.</p><h4>A Verdade Dura sobre &#8220;Sites Baratos&#8221;</h4><p>Quando contratas algu&#233;m para fazer um site e n&#227;o contratas um plano de manuten&#231;&#227;o mensal, est&#225;s a comprar um carro e a decidir nunca mudar o &#243;leo.<br>Vai andar bem durante uns meses. Mas um dia o motor parte.</p><h4>O Que Tens de Fazer Hoje:</h4><ol><li><p><strong>Pergunta Chata:</strong> Vai ter com quem te fez o site e pergunta: <em>&#8220;Quem &#233; respons&#225;vel por atualizar os plugins do nosso WordPress? &#201;s tu ou sou eu?&#8221;</em></p></li><li><p><strong>A&#231;&#227;o Imediata:</strong> Se usas Elementor ou &#8220;King Addons&#8221;, verifica se est&#225; tudo atualizado para a &#250;ltima vers&#227;o (51.1.35 ou superior).</p></li><li><p><strong>Mudan&#231;a de Mentalidade:</strong> P&#225;ra de ver a manuten&#231;&#227;o do site como um &#8220;custo chato&#8221;. V&#234; como um seguro.</p></li></ol><p>Um site desatualizado n&#227;o &#233; um ativo. &#201; um passivo.<br>E neste momento, pode ser a porta de entrada para perderes o controlo do teu neg&#243;cio digital.</p><p>Atualiza. Ou paga o pre&#231;o.</p>]]></content:encoded></item><item><title><![CDATA[Your WordPress Site Is a Ticking Time Bomb]]></title><description><![CDATA[(And You Don&#8217;t Know When It Will Explode)]]></description><link>https://resolvesec.substack.com/p/your-wordpress-site-is-a-ticking</link><guid isPermaLink="false">https://resolvesec.substack.com/p/your-wordpress-site-is-a-ticking</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Thu, 22 Jan 2026 08:03:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ky-v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bc021e2-09f3-49b1-a4b8-72a11880dbd7_1344x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ky-v!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bc021e2-09f3-49b1-a4b8-72a11880dbd7_1344x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ky-v!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bc021e2-09f3-49b1-a4b8-72a11880dbd7_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!ky-v!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bc021e2-09f3-49b1-a4b8-72a11880dbd7_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!ky-v!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bc021e2-09f3-49b1-a4b8-72a11880dbd7_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!ky-v!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bc021e2-09f3-49b1-a4b8-72a11880dbd7_1344x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ky-v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bc021e2-09f3-49b1-a4b8-72a11880dbd7_1344x768.png" width="1344" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9bc021e2-09f3-49b1-a4b8-72a11880dbd7_1344x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1344,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1030105,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://resolvesec.substack.com/i/183658646?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bc021e2-09f3-49b1-a4b8-72a11880dbd7_1344x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ky-v!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bc021e2-09f3-49b1-a4b8-72a11880dbd7_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!ky-v!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bc021e2-09f3-49b1-a4b8-72a11880dbd7_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!ky-v!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bc021e2-09f3-49b1-a4b8-72a11880dbd7_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!ky-v!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9bc021e2-09f3-49b1-a4b8-72a11880dbd7_1344x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>If you have a website, there is a 43% chance it is built on <strong>WordPress</strong>.<br>It is the most popular platform in the world. It&#8217;s easy, flexible, and often, cheap to build.</p><p>But there is a &#8220;hidden cost&#8221; no one tells you about when they sell you a website for $500 or $1,000.<br><strong>Maintenance.</strong></p><p>This week, yet another popular plugin (<em>King Addons for Elementor</em>) opened a massive security crater.<br>A critical flaw (CVE-2025-8489) allows any stranger to become an <strong>Administrator</strong> of your site.<br>No password needed. No hacking the NASA mainframe.<br>They simply &#8220;walk in&#8221; and become the owner. They can delete everything, steal customer data, or redirect your traffic to scam sites.</p><h4>The Problem Isn&#8217;t WordPress. It&#8217;s the &#8220;Set and Forget&#8221; Mindset.</h4><p>The #1 mistake business owners make is treating their website like a printed brochure.<br><em>&#8220;I paid for it, it&#8217;s done, now I just leave it alone.&#8221;</em></p><p><strong>Wrong.</strong><br>A WordPress site is made of Lego pieces (Plugins).<br>You have a plugin for forms, a plugin for design (Elementor), a plugin for SEO.<br>Each of these is made by a different company. And each of them needs constant updates.</p><p>If you don&#8217;t update:</p><ol><li><p>The plugin gets old.</p></li><li><p>Hackers discover a flaw (like this one).</p></li><li><p>They use bots to scan the internet for anyone who hasn&#8217;t updated.</p></li><li><p>You get hacked.</p></li></ol><p>It&#8217;s not a matter of &#8220;if&#8221;, it&#8217;s a matter of &#8220;when&#8221;.<br>For this specific flaw alone, <strong>50,000 attack attempts</strong> have already been recorded.</p><h4>The Hard Truth About &#8220;Cheap Websites&#8221;</h4><p>When you hire someone to build a site but don&#8217;t pay for a monthly maintenance plan, you are buying a car and deciding never to change the oil.<br>It will run fine for a few months. But one day, the engine will blow.</p><h4>What You Need To Do Today:</h4><ol><li><p><strong>The Annoying Question:</strong> Go to whoever built your site and ask: <em>&#8220;Who is responsible for updating our WordPress plugins? Is it you, or is it me?&#8221;</em></p></li><li><p><strong>Immediate Action:</strong> If you use Elementor or &#8220;King Addons&#8221;, check if everything is updated to the latest version (51.1.35 or higher).</p></li><li><p><strong>Mindset Shift:</strong> Stop seeing website maintenance as an &#8220;annoying cost&#8221;. See it as insurance.</p></li></ol><p>An outdated website is not an asset. It is a liability.<br>And right now, it could be the open door to losing control of your digital business.</p><p>Update it. Or pay the price.</p><p>Visit us htpps://www.resolvesec.com </p>]]></content:encoded></item><item><title><![CDATA[56.000 Programadores Instalaram um Vírus no WhatsApp dos Clientes ]]></title><description><![CDATA[(E nem sabiam)]]></description><link>https://resolvesec.substack.com/p/56000-programadores-instalaram-um</link><guid isPermaLink="false">https://resolvesec.substack.com/p/56000-programadores-instalaram-um</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Fri, 16 Jan 2026 10:57:18 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!TlwO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73155aaf-f25e-4923-9073-cedb79c450e0_917x917.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!TlwO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73155aaf-f25e-4923-9073-cedb79c450e0_917x917.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!TlwO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73155aaf-f25e-4923-9073-cedb79c450e0_917x917.png 424w, https://substackcdn.com/image/fetch/$s_!TlwO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73155aaf-f25e-4923-9073-cedb79c450e0_917x917.png 848w, https://substackcdn.com/image/fetch/$s_!TlwO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73155aaf-f25e-4923-9073-cedb79c450e0_917x917.png 1272w, https://substackcdn.com/image/fetch/$s_!TlwO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73155aaf-f25e-4923-9073-cedb79c450e0_917x917.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!TlwO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73155aaf-f25e-4923-9073-cedb79c450e0_917x917.png" width="917" height="917" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/73155aaf-f25e-4923-9073-cedb79c450e0_917x917.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:917,&quot;width&quot;:917,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1317550,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://resolvesec.substack.com/i/182848940?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73155aaf-f25e-4923-9073-cedb79c450e0_917x917.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!TlwO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73155aaf-f25e-4923-9073-cedb79c450e0_917x917.png 424w, https://substackcdn.com/image/fetch/$s_!TlwO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73155aaf-f25e-4923-9073-cedb79c450e0_917x917.png 848w, https://substackcdn.com/image/fetch/$s_!TlwO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73155aaf-f25e-4923-9073-cedb79c450e0_917x917.png 1272w, https://substackcdn.com/image/fetch/$s_!TlwO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F73155aaf-f25e-4923-9073-cedb79c450e0_917x917.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Imagina que contratas um seguran&#231;a para a tua loja.<br>Ele veste o uniforme, cumpre o hor&#225;rio e protege a porta.<br>Mas, sem tu saberes, ele fez uma c&#243;pia da chave da loja e deu-a a um gangue. E todas as noites, enquanto dormes, eles entram, leem o teu correio e roubam o que querem.</p><p>Foi exatamente isto que aconteceu no mundo do software esta semana.</p><p>Um pacote chamado <strong>&#8216;lotusbail&#8217;</strong> estava dispon&#237;vel no <strong>npm</strong> (o &#8220;supermercado&#8221; de c&#243;digo onde os programadores v&#227;o buscar pe&#231;as para construir os teus sites e apps).<br>Parecia uma ferramenta leg&#237;tima para ligar o WhatsApp ao teu software.<br>Funcionava perfeitamente.</p><p>O problema?<br>Enquanto fazia o trabalho dele, estava a roubar <strong>TUDO</strong>.</p><h4>O Golpe Perfeito (O Cavalo de Troia Digital)</h4><p>Este c&#243;digo malicioso n&#227;o se limitava a partir coisas. Era silencioso.</p><ol><li><p><strong>Roubava as Chaves:</strong> Capturava os tokens de sess&#227;o (basicamente, o login sem password).</p></li><li><p><strong>Lia as Mensagens:</strong> Cada mensagem enviada ou recebida passava primeiro pelo hacker.</p></li><li><p><strong>Acesso Eterno:</strong> O mais assustador? O c&#243;digo vinculava o telem&#243;vel do hacker &#224; conta da v&#237;tima. Mesmo que o programador apagasse o c&#243;digo malicioso amanh&#227;, o hacker <strong>continuava l&#225; dentro</strong>, como um dispositivo emparelhado.</p></li></ol><p>Esteve ativo durante <strong>6 meses</strong>.<br>Teve <strong>56.000 downloads</strong>.</p><p>Isto significa que 56.000 projetos, empresas ou programadores confiaram cegamente num peda&#231;o de c&#243;digo que encontraram na internet.</p><h4>A Li&#231;&#227;o para Quem Gere Neg&#243;cios (N&#227;o para Programadores)</h4><p>Tu, CEO ou Gestor, n&#227;o precisas de saber o que &#233; um &#8220;WebSocket&#8221; ou &#8220;RSA&#8221;.<br>Mas precisas de saber isto:</p><p><strong>O Software Moderno &#233; um Lego de Pe&#231;as Desconhecidas.</strong><br>O teu site, a tua app, o teu CRM... s&#227;o feitos de milhares de pequenas pe&#231;as de c&#243;digo (bibliotecas) que v&#234;m de terceiros.<br>Se o teu programador (ou a tua ag&#234;ncia) n&#227;o fizer a &#8220;higiene&#8221; dessas pe&#231;as, est&#225;s a meter estranhos dentro de casa.</p><h4>O que deves perguntar &#224; tua equipa de TI Hoje:</h4><p>N&#227;o assumas que est&#225; tudo bem. Faz estas 2 perguntas:</p><ol><li><p><em>&#8220;N&#243;s usamos bibliotecas externas para integrar com WhatsApp ou redes sociais?&#8221;</em></p></li><li><p><em>&#8220;Como &#233; que validamos se esse c&#243;digo &#233; seguro? Monitorizamos o comportamento ou s&#243; confiamos na fonte?&#8221;</em></p></li></ol><p>A Koi Security (quem descobriu isto) avisou: <strong>Ler o c&#243;digo j&#225; n&#227;o chega.</strong> Os hackers escondem-se demasiado bem. &#201; preciso ver o que o c&#243;digo <em>faz</em> quando est&#225; a correr.</p><p><strong>Conclus&#227;o:</strong><br>O &#8220;Gr&#225;tis&#8221; e &#8220;Open Source&#8221; &#233; incr&#237;vel. Construiu a internet.<br>Mas a confian&#231;a cega &#233; cara.<br>Neste caso, custou a privacidade de milhares de contas de WhatsApp.</p><p>Verifica os teus dispositivos emparelhados no WhatsApp agora. Se vires l&#225; um &#8220;Chrome no Linux&#8221; que n&#227;o conheces... j&#225; sabes de onde veio.</p>]]></content:encoded></item><item><title><![CDATA[O Teu Painel de Controlo é a Arma do Hacker ]]></title><description><![CDATA[(Alerta Ivanti)]]></description><link>https://resolvesec.substack.com/p/o-teu-painel-de-controlo-e-a-arma</link><guid isPermaLink="false">https://resolvesec.substack.com/p/o-teu-painel-de-controlo-e-a-arma</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Mon, 12 Jan 2026 09:06:03 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!uRTx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62dcd23c-57bc-43a8-90e4-caef48cce7fa_1344x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uRTx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62dcd23c-57bc-43a8-90e4-caef48cce7fa_1344x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uRTx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62dcd23c-57bc-43a8-90e4-caef48cce7fa_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!uRTx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62dcd23c-57bc-43a8-90e4-caef48cce7fa_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!uRTx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62dcd23c-57bc-43a8-90e4-caef48cce7fa_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!uRTx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62dcd23c-57bc-43a8-90e4-caef48cce7fa_1344x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uRTx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62dcd23c-57bc-43a8-90e4-caef48cce7fa_1344x768.png" width="1344" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/62dcd23c-57bc-43a8-90e4-caef48cce7fa_1344x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1344,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1282992,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://resolvesec.substack.com/i/183651663?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62dcd23c-57bc-43a8-90e4-caef48cce7fa_1344x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!uRTx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62dcd23c-57bc-43a8-90e4-caef48cce7fa_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!uRTx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62dcd23c-57bc-43a8-90e4-caef48cce7fa_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!uRTx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62dcd23c-57bc-43a8-90e4-caef48cce7fa_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!uRTx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F62dcd23c-57bc-43a8-90e4-caef48cce7fa_1344x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Imagina que &#233;s o capit&#227;o de um navio.<br>Est&#225;s na ponte de comando, a olhar para os radares e mapas.<br>Sentes-te no controlo.<br>Mas, sem saberes, cada vez que tocas num bot&#227;o do painel, est&#225;s a dar ordens para afundar o barco.</p><p>&#201; isto que est&#225; a acontecer com o <strong>Ivanti Endpoint Manager</strong>.</p><p>O CNCS (Centro Nacional de Ciberseguran&#231;a) acabou de lan&#231;ar um alerta vermelho.<br>H&#225; uma falha cr&#237;tica (CVE-2025-10573) no software que usas para gerir os computadores da tua empresa.</p><h4>Como Funciona o Ataque (Simples)</h4><p>&#201; uma armadilha de &#8220;espera&#8221;.</p><ol><li><p>O hacker (que nem precisa de login) deixa um c&#243;digo malicioso &#8220;plantado&#8221; no sistema.</p></li><li><p>Ele espera.</p></li><li><p>Quando o teu Administrador de TI entra no painel para trabalhar... <strong>BOOM.</strong></p></li><li><p>O c&#243;digo executa-se <em>com os privil&#233;gios do Administrador</em>.</p></li></ol><p>Basicamente, o hacker usa a conta do teu chefe de TI para roubar a empresa.<br>N&#227;o precisa de partir a porta. Ele entra &#224; boleia de quem tem a chave mestra.</p><h4>O Perigo Real</h4><p>O Ivanti EPM &#233; usado para gerir <em>todos</em> os computadores da rede.<br>Se o hacker controlar isto, ele controla tudo. Pode instalar ransomware em 500 port&#225;teis ao mesmo tempo com um clique.</p><h4>O Que Tens de Fazer (Agora)</h4><p>Se usas Ivanti na tua empresa, tens duas op&#231;&#245;es. N&#227;o h&#225; terceira via.</p><p><strong>Op&#231;&#227;o A (A Correta):</strong><br>Atualiza para a vers&#227;o <strong>2024 SU4 SR1</strong>. J&#225;.<br>N&#227;o esperes pelo fim de semana. N&#227;o esperes pela &#8220;janela de manuten&#231;&#227;o&#8221;. Faz hoje.</p><p><strong>Op&#231;&#227;o B (O penso r&#225;pido):</strong><br>Se n&#227;o consegues atualizar j&#225;, <strong>tira a consola da Internet.</strong><br>Porque &#233; que o painel de gest&#227;o da tua empresa est&#225; acess&#237;vel a partir da China ou da R&#250;ssia?<br>Bloqueia o acesso. S&#243; quem est&#225; no escrit&#243;rio (ou na VPN) &#233; que deve ver esse login.</p><p><strong>Resumo:</strong><br>As ferramentas de gest&#227;o s&#227;o o alvo favorito dos hackers porque s&#227;o as &#8220;chaves do reino&#8221;.<br>Se n&#227;o as proteges, est&#225;s a dar a arma ao inimigo.</p><p>Pergunta ao TI: <em>&#8220;O nosso Ivanti est&#225; exposto &#224; net? E j&#225; aplic&#225;mos o patch SR1?&#8221;</em></p>]]></content:encoded></item><item><title><![CDATA[7.75 Mil Milhões de Dólares: Porque é que a ServiceNow acabou de comprar a Armis]]></title><description><![CDATA[(E o que isso diz sobre o futuro da tua empresa)]]></description><link>https://resolvesec.substack.com/p/775-mil-milhoes-de-dolares-porque</link><guid isPermaLink="false">https://resolvesec.substack.com/p/775-mil-milhoes-de-dolares-porque</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Fri, 09 Jan 2026 10:05:31 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Q00B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d92bad7-0552-4684-995d-c7228043c868_8000x4501.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Q00B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d92bad7-0552-4684-995d-c7228043c868_8000x4501.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Q00B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d92bad7-0552-4684-995d-c7228043c868_8000x4501.png 424w, https://substackcdn.com/image/fetch/$s_!Q00B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d92bad7-0552-4684-995d-c7228043c868_8000x4501.png 848w, https://substackcdn.com/image/fetch/$s_!Q00B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d92bad7-0552-4684-995d-c7228043c868_8000x4501.png 1272w, https://substackcdn.com/image/fetch/$s_!Q00B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d92bad7-0552-4684-995d-c7228043c868_8000x4501.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Q00B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d92bad7-0552-4684-995d-c7228043c868_8000x4501.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7d92bad7-0552-4684-995d-c7228043c868_8000x4501.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:238424,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://resolvesec.substack.com/i/182845658?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d92bad7-0552-4684-995d-c7228043c868_8000x4501.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Q00B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d92bad7-0552-4684-995d-c7228043c868_8000x4501.png 424w, https://substackcdn.com/image/fetch/$s_!Q00B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d92bad7-0552-4684-995d-c7228043c868_8000x4501.png 848w, https://substackcdn.com/image/fetch/$s_!Q00B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d92bad7-0552-4684-995d-c7228043c868_8000x4501.png 1272w, https://substackcdn.com/image/fetch/$s_!Q00B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d92bad7-0552-4684-995d-c7228043c868_8000x4501.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Acabou de acontecer mais um &#8220;terramoto&#8221; no mercado de tecnologia.<br>A <strong>ServiceNow</strong> abriu a carteira e pagou <strong>7,75 mil milh&#245;es de d&#243;lares</strong> pela <strong>Armis</strong>.</p><p>Para quem n&#227;o anda nestas lides, isto pode parecer s&#243; mais uma not&#237;cia de Wall Street.<br>Mas se leres nas entrelinhas, isto &#233; um sinal gigante de para onde o mundo est&#225; a ir.</p><p>Aqui est&#225; a tradu&#231;&#227;o do &#8220;corporat&#234;s&#8221; para portugu&#234;s claro:</p><h4>1. O &#8220;Velho&#8221; IT Morreu. Viva o OT.</h4><p>A Armis n&#227;o &#233; uma empresa de antiv&#237;rus normal. Eles s&#227;o especialistas em <strong>IoT (Internet das Coisas)</strong> e <strong>OT (Tecnologia Operacional)</strong>.<br>Estamos a falar de proteger bra&#231;os rob&#243;ticos em f&#225;bricas, m&#225;quinas de resson&#226;ncia magn&#233;tica em hospitais, sensores em oleodutos.</p><p>A ServiceNow percebeu o &#243;bvio: <strong>O mundo digital j&#225; n&#227;o vive s&#243; em computadores.</strong> Vive em tudo. E se tudo est&#225; ligado, tudo pode ser hackeado.<br>Se a tua empresa tem m&#225;quinas ligadas &#224; net e achas que o &#8220;antiv&#237;rus do port&#225;til&#8221; chega, est&#225;s a jogar um jogo perigoso.</p><h4>2. A Consolida&#231;&#227;o &#233; Real (O &#8220;Winner Takes All&#8221;)</h4><p>Repara na tend&#234;ncia de 2025:</p><ul><li><p>Google compra Wiz (32MM$).</p></li><li><p>Palo Alto compra CyberArk (25MM$).</p></li><li><p>ServiceNow compra Armis (7.75MM$).</p></li></ul><p>As grandes plataformas est&#227;o a engolir as ferramentas especializadas.<br>O futuro n&#227;o &#233; teres 50 softwares de seguran&#231;a diferentes que n&#227;o falam uns com os outros. O futuro &#233; teres <strong>uma plataforma central</strong> que gere tudo.<br>A complexidade &#233; inimiga da seguran&#231;a. A simplicidade (e integra&#231;&#227;o) &#233; o futuro.</p><h4>3. &#8220;Ciberseguran&#231;a Proativa&#8221; n&#227;o &#233; Buzzword, &#233; Dinheiro</h4><p>A ServiceNow diz que quer &#8220;ciberseguran&#231;a proativa nativa em IA&#8221;.<br>Traduzindo: Eles querem resolver o problema <strong>antes</strong> de ele acontecer.<br>Porque resolver depois (reativo) custa 100x mais.</p><h4>O Que Isto Significa Para Ti?</h4><p>Se uma empresa que fatura 3.4 mil milh&#245;es por trimestre est&#225; a apostar todas as fichas em <strong>Visibilidade Total de Ativos (Asset Management)</strong> e <strong>Seguran&#231;a de IoT</strong>, talvez tu devesses fazer o mesmo (numa escala menor, claro).</p><p>A li&#231;&#227;o de 7 mil milh&#245;es de d&#243;lares &#233; esta:<br><strong>N&#227;o podes proteger o que n&#227;o v&#234;s.</strong></p><p>A Armis vale tanto dinheiro porque d&#225; <strong>visibilidade</strong>. Diz-te exatamente o que est&#225; ligado &#224; tua rede.<br>Tu sabes o que est&#225; ligado &#224; tua rede agora? Ou tens l&#225; uma impressora Wi-Fi de 2015 que &#233; a porta de entrada para um hacker?</p><p>Pensa nisso.</p>]]></content:encoded></item><item><title><![CDATA[Os teus Fones de 300€ são um Espião]]></title><description><![CDATA[(E tu puseste-os nos ouvidos)]]></description><link>https://resolvesec.substack.com/p/os-teus-fones-de-300-sao-um-espiao</link><guid isPermaLink="false">https://resolvesec.substack.com/p/os-teus-fones-de-300-sao-um-espiao</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Wed, 07 Jan 2026 10:32:23 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!vVfV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc8e625c-4c0b-4237-ae42-2d6d79b1e8ae_1344x768.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vVfV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc8e625c-4c0b-4237-ae42-2d6d79b1e8ae_1344x768.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vVfV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc8e625c-4c0b-4237-ae42-2d6d79b1e8ae_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!vVfV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc8e625c-4c0b-4237-ae42-2d6d79b1e8ae_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!vVfV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc8e625c-4c0b-4237-ae42-2d6d79b1e8ae_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!vVfV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc8e625c-4c0b-4237-ae42-2d6d79b1e8ae_1344x768.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vVfV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc8e625c-4c0b-4237-ae42-2d6d79b1e8ae_1344x768.png" width="1344" height="768" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dc8e625c-4c0b-4237-ae42-2d6d79b1e8ae_1344x768.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:768,&quot;width&quot;:1344,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1117678,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://resolvesec.substack.com/i/183234082?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc8e625c-4c0b-4237-ae42-2d6d79b1e8ae_1344x768.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vVfV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc8e625c-4c0b-4237-ae42-2d6d79b1e8ae_1344x768.png 424w, https://substackcdn.com/image/fetch/$s_!vVfV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc8e625c-4c0b-4237-ae42-2d6d79b1e8ae_1344x768.png 848w, https://substackcdn.com/image/fetch/$s_!vVfV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc8e625c-4c0b-4237-ae42-2d6d79b1e8ae_1344x768.png 1272w, https://substackcdn.com/image/fetch/$s_!vVfV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc8e625c-4c0b-4237-ae42-2d6d79b1e8ae_1344x768.png 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Est&#225;s numa chamada confidencial.<br>Talvez a negociar um contrato, a discutir um despedimento ou a partilhar dados financeiros.<br>Est&#225;s a usar os teus fones de cancelamento de ru&#237;do de topo (Sony, Bose, JBL).<br>Sentes-te seguro. Ningu&#233;m &#224; tua volta consegue ouvir a conversa.</p><p><strong>Errado.</strong><br>Algu&#233;m pode estar a ouvir. E pior: pode estar a entrar no teu telem&#243;vel <em>atrav&#233;s</em> dos fones.</p><p>Acabaram de ser descobertas 3 vulnerabilidades cr&#237;ticas (CVE-2025-20700 a 20702) nos chips Bluetooth da <strong>Airoha</strong>.<br>Se nunca ouviste falar da Airoha, n&#227;o te preocupes. Mas de certeza que conheces os clientes deles:<br><strong>Sony, Bose, JBL, Marshall, Jabra.</strong></p><p>Basicamente, as marcas que tu e a tua equipa usam todos os dias.</p><h4>O &#8220;Cavalo de Troia&#8221; no teu Ouvido</h4><p>A maioria das pessoas acha que hackear &#233; &#8220;entrar no computador&#8221;.<br>Mas os hackers s&#227;o como a &#225;gua: procuram a fenda mais pequena.</p><p>Estes fones n&#227;o s&#227;o apenas colunas. S&#227;o mini-computadores.<br>E esta falha permite que um atacante pr&#243;ximo:</p><ol><li><p><strong>Ou&#231;a as tuas conversas</strong> (espionagem industrial gratuita).</p></li><li><p><strong>Roube dados sens&#237;veis.</strong></p></li><li><p><strong>Controle o teu telem&#243;vel</strong> (o &#8220;Hijack&#8221; completo).</p></li></ol><p>Imagina o cen&#225;rio: O teu Diretor Financeiro est&#225; no aeroporto, com os seus Bose, a falar com o banco. O hacker est&#225; sentado na cadeira ao lado, a beber um caf&#233; e a copiar tudo.</p><h4>O Que Tens de Fazer (N&#227;o entres em p&#226;nico, age)</h4><p>N&#227;o precisas de deitar os fones ao lixo. Mas precisas de tratar os teus &#8220;gadgets&#8221; como tratas o teu computador.</p><ol><li><p><strong>Atualiza o Firmware:</strong> Vai &#224; app dos teus fones (Sony Headphones, Bose Music, etc.) AGORA. Se houver um update, instala. As marcas s&#233;rias j&#225; est&#227;o a lan&#231;ar corre&#231;&#245;es.</p></li><li><p><strong>Desliga o Bluetooth:</strong> Se n&#227;o est&#225;s a usar, desliga. Andar com o Bluetooth ligado 24/7 em locais p&#250;blicos &#233; pedir para ser encontrado.</p></li><li><p><strong>A Regra de Ouro:</strong> Se a conversa &#233; <em>mesmo</em> secreta (segredos de estado, fus&#245;es, c&#243;digos nucleares)... usa fios. O cabo nunca &#233; hackeado.</p></li></ol><p><strong>Resumo:</strong><br>A tecnologia &#233; incr&#237;vel, mas &#233; vulner&#225;vel.<br>Da pr&#243;xima vez que puseres os fones para te &#8220;isolares do mundo&#8221;, lembra-te: podes estar a abrir a porta a quem te quer roubar.</p><p>Verifica os updates da tua equipa hoje.</p>]]></content:encoded></item><item><title><![CDATA[O teu negócio vai ser atacado. A única dúvida é se sobrevives. ]]></title><description><![CDATA[Vamos parar com as met&#225;foras po&#233;ticas.]]></description><link>https://resolvesec.substack.com/p/o-teu-negocio-vai-ser-atacado-a-unica</link><guid isPermaLink="false">https://resolvesec.substack.com/p/o-teu-negocio-vai-ser-atacado-a-unica</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Fri, 02 Jan 2026 12:01:21 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/956979ca-de69-441d-89ff-13f16fffbeee_8000x4501.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Vamos parar com as met&#225;foras po&#233;ticas.<br>N&#227;o interessa &#8220;ser ou n&#227;o ser&#8221;. Interessa <strong>&#8220;pagar ou n&#227;o pagar&#8221;</strong>.</p><p>A pergunta n&#227;o &#233; <em>se</em> vais ser atacado. &#201; <em>quando</em>.<br>E quando acontecer, s&#243; h&#225; dois cen&#225;rios poss&#237;veis:</p><ol><li><p><strong>Cen&#225;rio A:</strong> O caos instala-se. Ningu&#233;m sabe o que fazer. Pagas o resgate (e financias o crime), perdes a confian&#231;a dos clientes e o teu CFO tem um ataque card&#237;aco a ver os preju&#237;zos.</p></li><li><p><strong>Cen&#225;rio B:</strong> O sistema detecta, bloqueia e recupera. O neg&#243;cio continua. Tomas um caf&#233; e segues a vida.</p></li></ol><p>A diferen&#231;a entre o A e o B n&#227;o &#233; sorte. &#201; <strong>Matem&#225;tica</strong>.</p><h4>O erro que o CEO comete (e que custa milh&#245;es)</h4><p>A maioria dos CEOs delega isto: <em>&#8220;O CIO trata da tecnologia, o CFO trata do dinheiro.&#8221;</em></p><p>Errado.<br>Na ciberseguran&#231;a moderna, <strong>Tecnologia = Dinheiro.</strong></p><ul><li><p>O CIO est&#225; preocupado com <em>Ransomware</em> e IA.</p></li><li><p>O CFO est&#225; preocupado com <em>Multas</em> e Reputa&#231;&#227;o.</p></li></ul><p>Se eles n&#227;o falarem a mesma l&#237;ngua, tens um buraco no barco. O CIO pede or&#231;amento para &#8220;<strong>Zero Trust</strong>&#8221; e o CFO nega porque acha que &#233; &#8220;brinquedo novo&#8221;. Resultado? O ataque entra por essa falha.</p><h4>A lista de compras para sobreviver (sem tretas)</h4><p>N&#227;o precisas de 50 ferramentas. Precisas de resolver 3 problemas:</p><p><strong>1. O problema da entrada (como eles entram)</strong></p><ul><li><p><strong>A Solu&#231;&#227;o:</strong> Higiene B&#225;sica Agressiva.</p></li><li><p>MFA em tudo (n&#227;o negoci&#225;vel).</p></li><li><p>Forma&#231;&#227;o anti-phishing (o elo mais fraco &#233; a Dona Maria, n&#227;o o servidor).</p></li><li><p>EDR (antiv&#237;rus com ester&#243;ides) em todas as m&#225;quinas.</p></li></ul><p><strong>2. O problema do fornecedor (o cavalo de Troia)</strong></p><ul><li><p>Tu podes ser seguro, mas o teu fornecedor de software n&#227;o &#233;.</p></li><li><p><strong>A Solu&#231;&#227;o:</strong> Contratos blindados. Exige certifica&#231;&#245;es (ISO 27001) ou auditorias. Se eles n&#227;o garantem seguran&#231;a, troca.</p></li></ul><p><strong>3. O problema do dinheiro (quando tudo falha)</strong></p><ul><li><p>&#192;s vezes, o inimigo ganha.</p></li><li><p><strong>A Solu&#231;&#227;o:</strong> Seguros Cibern&#233;ticos e Backups Offline.</p></li><li><p>O seguro paga a conta. O backup devolve-te os dados. Sem isto, est&#225;s a jogar roleta russa com o teu patrim&#243;nio.</p></li></ul><h4>Conclus&#227;o</h4><p>Deixa o Shakespeare para o teatro.<br>No mundo real, a ciberseguran&#231;a n&#227;o &#233; uma pe&#231;a, &#233; uma guerra.</p><p>E nesta guerra, s&#243; h&#225; dois tipos de empresas:<br>As que se preparam.<br>E as que pagam o resgate.</p><p>Qual delas queres ser?</p>]]></content:encoded></item><item><title><![CDATA[Do Zero à Compliance: O Playbook de 5 Passos para não seres multado]]></title><description><![CDATA[Se leste os dois primeiros artigos, j&#225; sabes duas coisas:]]></description><link>https://resolvesec.substack.com/p/do-zero-a-compliance-o-playbook-de</link><guid isPermaLink="false">https://resolvesec.substack.com/p/do-zero-a-compliance-o-playbook-de</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Fri, 26 Dec 2025 12:10:29 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/ec3a8654-aba4-4806-bd62-5dacdb45e3cc_8001x4501.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Se leste os dois primeiros artigos, j&#225; sabes duas coisas:</p><ol><li><p>A NIS2 n&#227;o &#233; uma sugest&#227;o, &#233; uma obriga&#231;&#227;o com multas de milh&#245;es.</p></li><li><p>A tua empresa (ou os teus clientes) provavelmente est&#225; na lista.</p></li></ol><p>Agora, a pergunta de um milh&#227;o de euros: <strong>&#8220;Como &#233; que eu resolvo isto sem parar a empresa e sem ir &#224; fal&#234;ncia?&#8221;</strong></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://resolvesec.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscrever&quot;,&quot;language&quot;:&quot;pt&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Obrigado por ler Substack de ResolveSec! Subscreva gratuitamente para receber novos posts e apoiar o meu trabalho.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digite o seu e-mail..." tabindex="-1"><input type="submit" class="button primary" value="Subscrever"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p>Muitos consultores cobrariam uma fortuna s&#243; para te dizer o que vou escrever nas pr&#243;ximas linhas. Mas na <strong>ResolveSec</strong>, acreditamos em entregar valor primeiro.</p><p>Aqui tens o roteiro pr&#225;tico. N&#227;o &#233; magia, &#233; m&#233;todo.</p><h4>Passo 1: O Invent&#225;rio (N&#227;o podes proteger o que n&#227;o v&#234;s)</h4><p>A maioria das empresas n&#227;o sabe o que tem. Servidores antigos ligados &#224; rede? Port&#225;teis de ex-funcion&#225;rios? Softwares que ningu&#233;m usa?<br>A NIS2 exige que saibas exatamente o que tens.</p><ul><li><p><strong>A&#231;&#227;o:</strong> Faz uma lista exaustiva de todos os ativos (hardware, software, dados).</p></li><li><p><strong>A Pergunta:</strong> &#8220;Se isto desaparecer amanh&#227;, a empresa para?&#8221; Se a resposta &#233; sim, &#233; cr&#237;tico.</p></li></ul><h4>Passo 2: A An&#225;lise de Risco (Onde &#233; que d&#243;i mais?)</h4><p>N&#227;o tentes proteger tudo com a mesma intensidade. Isso &#233; caro e ineficiente.<br>Tens de identificar as tuas &#8220;J&#243;ias da Coroa&#8221;.</p><ul><li><p><strong>A&#231;&#227;o:</strong> Identifica as amea&#231;as reais. Ransomware? Roubo de dados de clientes? Paragem da produ&#231;&#227;o?</p></li><li><p><strong>A Pergunta:</strong> &#8220;Qual &#233; o pior cen&#225;rio poss&#237;vel e quanto tempo aguentamos parados?&#8221;</p></li></ul><h4>Passo 3: A Higiene B&#225;sica (O &#8220;Pareto&#8221; da Seguran&#231;a)</h4><p>80% dos ataques resolvem-se com 20% do esfor&#231;o. Antes de comprares firewalls da NASA, faz o b&#225;sico que a NIS2 exige:</p><ul><li><p><strong>MFA (Autentica&#231;&#227;o Multifator):</strong> Ativa isto em TUDO. &#201; a vacina mais barata que existe.</p></li><li><p><strong>Backups:</strong> T&#234;m de ser frequentes, testados e, idealmente, um deles deve estar &#8220;offline&#8221; (fora da rede).</p></li><li><p><strong>Updates:</strong> Software desatualizado &#233; uma porta aberta. Fecha-a.</p></li></ul><h4>Passo 4: O Plano de Incidente (O que fazer quando a casa arder)</h4><p>A NIS2 obriga-te a reportar incidentes graves em <strong>24 horas</strong>. Se fores atacado, n&#227;o vais ter tempo para pensar. Tens de ter um gui&#227;o.</p><ul><li><p><strong>A&#231;&#227;o:</strong> Cria um documento simples: Quem ligamos? Como isolamos a rede? Como comunicamos com os clientes/autoridades?</p></li><li><p><strong>O Teste:</strong> Uma vez por ano, simula um ataque. Vais descobrir que o plano no papel falha na pr&#225;tica. Corrige.</p></li></ul><h4>Passo 5: A Cadeia de Fornecedores (O Efeito Domin&#243;)</h4><p>Lembras-te do artigo anterior? Tu &#233;s respons&#225;vel por quem contratas.</p><ul><li><p><strong>A&#231;&#227;o:</strong> Rev&#234; os contratos. Exige garantias de seguran&#231;a aos teus parceiros de TI, cloud e software. Se eles n&#227;o garantem, o risco &#233; teu.</p></li></ul><p></p><h4>A Verdade Dura (O &#8220;Catch&#8221;)</h4><p>Este plano de 5 passos parece simples no papel. E &#233;.<br>Mas a execu&#231;&#227;o &#233; onde a maioria falha.</p><p>Fazer um invent&#225;rio d&#225; trabalho. Configurar backups &#224; prova de bala exige t&#233;cnica. Criar um plano de resposta a incidentes que cumpra as 24h da lei exige experi&#234;ncia.</p><p>Se queres dormir descansado sabendo que a tua empresa est&#225; blindada e em conformidade, envia-nos uma mensagem.</p><p>Vamos resolver isto.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://resolvesec.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscrever&quot;,&quot;language&quot;:&quot;pt&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Obrigado por ler Substack de ResolveSec! Subscreva gratuitamente para receber novos posts e apoiar o meu trabalho.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digite o seu e-mail..." tabindex="-1"><input type="submit" class="button primary" value="Subscrever"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[A Lista: A tua empresa é "Essencial", "Importante" ou está na "Zona de Risco"? ]]></title><description><![CDATA[(E o custo de ignorar isto)]]></description><link>https://resolvesec.substack.com/p/a-lista-a-tua-empresa-e-essencial</link><guid isPermaLink="false">https://resolvesec.substack.com/p/a-lista-a-tua-empresa-e-essencial</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Fri, 19 Dec 2025 12:10:21 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/6be567ce-c47c-4ec1-bcba-d0f4dfeec962_8001x4501.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>No &#250;ltimo artigo, fal&#225;mos sobre como a NIS2 acabou com a brincadeira. Agora, vamos ao que interessa: <strong>Ser&#225; que tens um alvo nas costas?</strong></p><p>Muitos empres&#225;rios cometem o erro cl&#225;ssico: <em>&#8220;A minha empresa n&#227;o &#233; uma central nuclear nem um banco, por isso estou safo.&#8221;</em></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://resolvesec.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscrever&quot;,&quot;language&quot;:&quot;pt&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Obrigado por ler Substack de ResolveSec! Subscreva gratuitamente para receber novos posts e apoiar o meu trabalho.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digite o seu e-mail..." tabindex="-1"><input type="submit" class="button primary" value="Subscrever"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p><strong>Errado.</strong></p><p>A NIS2 expandiu drasticamente o &#226;mbito da ciberseguran&#231;a. A rede foi lan&#231;ada ao mar e apanhou muito mais peixe do que na vers&#227;o anterior. Se tens mais de 50 trabalhadores ou faturas mais de 10 milh&#245;es de euros, &#233; muito prov&#225;vel que estejas na lista.</p><p>E mesmo que sejas mais pequeno, podes ser apanhado pelo &#8220;Efeito Domin&#243;&#8221; (j&#225; l&#225; vamos).</p><p>Vamos dividir isto como deve ser. A NIS2 cria duas categorias de empresas. Descobre onde est&#225;s:</p><h4>1. As Entidades Essenciais (A &#8220;Elite&#8221; Cr&#237;tica)</h4><p>Estas s&#227;o as empresas que, se pararem, o pa&#237;s para. Se est&#225;s aqui, a supervis&#227;o &#233; proativa (v&#227;o andar em cima de ti <em>antes</em> de haver problemas) e as exig&#234;ncias s&#227;o m&#225;ximas.</p><ul><li><p><strong>Energia</strong> (Eletricidade, G&#225;s, Petr&#243;leo, Hidrog&#233;nio)</p></li><li><p><strong>Transportes</strong> (A&#233;reo, Ferrovi&#225;rio, Mar&#237;timo, Rodovi&#225;rio)</p></li><li><p><strong>Banca e Mercados Financeiros</strong></p></li><li><p><strong>Sa&#250;de</strong> (Hospitais, Laborat&#243;rios, Fabricantes de Dispositivos M&#233;dicos e Farmac&#234;uticos)</p></li><li><p><strong>&#193;gua</strong> (Pot&#225;vel e Residuais)</p></li><li><p><strong>Infraestrutura Digital</strong> (IXPs, DNS, Data Centers, Cloud, Telcos)</p></li><li><p><strong>Administra&#231;&#227;o P&#250;blica</strong></p></li><li><p><strong>Espa&#231;o</strong></p></li></ul><p><strong>A Fatura:</strong> Se falhares aqui, as multas v&#227;o at&#233; <strong>10.000.000&#8364;</strong> ou <strong>2% do volume de neg&#243;cios global</strong> (o que for maior). Sim, leste bem. O que for <em>maior</em>.</p><h4>2. As Entidades Importantes (O Motor da Economia)</h4><p>Estas empresas t&#234;m um impacto significativo na economia e na sociedade. A supervis&#227;o aqui &#233; reativa (v&#227;o cair-te em cima <em>depois</em> de haver um incidente ou den&#250;ncia), mas as regras s&#227;o para cumprir na mesma.</p><ul><li><p><strong>Servi&#231;os Postais e de Correio</strong></p></li><li><p><strong>Gest&#227;o de Res&#237;duos</strong></p></li><li><p><strong>Qu&#237;micos</strong> (Fabrico, produ&#231;&#227;o e distribui&#231;&#227;o)</p></li><li><p><strong>Alimenta&#231;&#227;o</strong> (Produ&#231;&#227;o, processamento e distribui&#231;&#227;o em massa)</p></li><li><p><strong>Ind&#250;stria Transformadora</strong> (Fabrico de computadores, eletr&#243;nica, m&#225;quinas, ve&#237;culos)</p></li><li><p><strong>Fornecedores Digitais</strong> (Motores de busca, Marketplaces, Redes Sociais)</p></li><li><p><strong>Investiga&#231;&#227;o</strong></p></li></ul><p><strong>A Fatura:</strong> Aqui, as multas v&#227;o at&#233; <strong>7.000.000&#8364;</strong> ou <strong>1,4% do volume de neg&#243;cios global</strong>. Continua a ser dinheiro suficiente para fechar muitas portas.</p><h4>3. A &#8220;Zona de Risco&#8221; (O Efeito Domin&#243;)</h4><p><em>&#8220;Frederico, a minha empresa n&#227;o est&#225; em nenhuma dessas listas. Estou livre!&#8221;</em></p><p>Calma. Ainda n&#227;o acab&#225;mos.</p><p>A NIS2 introduz uma obriga&#231;&#227;o cr&#237;tica para as Entidades Essenciais e Importantes: <strong>Seguran&#231;a da Cadeia de Abastecimento (Supply Chain Security).</strong></p><p>Isto significa que as grandes empresas s&#227;o agora <strong>obrigadas</strong> a garantir que os seus fornecedores s&#227;o seguros.</p><p>Se tu vendes software, servi&#231;os de limpeza, contabilidade, marketing ou parafusos para uma empresa que seja &#8220;Essencial&#8221; ou &#8220;Importante&#8221;, <strong>tu passas a ser um risco para eles.</strong></p><p>Eles v&#227;o bater-te &#224; porta e dizer: <em>&#8220;Ou cumpres os requisitos de seguran&#231;a da NIS2, ou n&#227;o podemos continuar a trabalhar contigo.&#8221;</em></p><p>De repente, a conformidade n&#227;o &#233; uma lei do governo. &#201; um requisito comercial. &#201; a diferen&#231;a entre manteres o teu maior cliente ou perd&#234;-lo para o concorrente que j&#225; tratou disto.</p><h4>O Custo da Ina&#231;&#227;o</h4><p>Ignorar a NIS2 tem tr&#234;s custos:</p><ol><li><p><strong>O Custo Legal:</strong> As multas astron&#243;micas que fal&#225;mos acima.</p></li><li><p><strong>O Custo Operacional:</strong> O preju&#237;zo de um ataque (ransomware, paragem, recupera&#231;&#227;o de dados).</p></li><li><p><strong>O Custo Comercial:</strong> Perder clientes porque n&#227;o consegues provar que &#233;s seguro.</p></li></ol><h4>O Que Fazer Agora?</h4><p>Se te identificaste em qualquer um destes grupos, parab&#233;ns: tens trabalho a fazer.</p><p>Mas n&#227;o entres em p&#226;nico. A conformidade n&#227;o se atinge num dia, mas come&#231;a com um passo. N&#227;o precisas de gastar milh&#245;es, precisas de gastar <em>bem</em>.</p><p>No pr&#243;ximo e &#250;ltimo artigo desta s&#233;rie, vou abrir o jogo. Vou dar-te o <strong>Playbook &#8220;Do Zero &#224; Compliance&#8221;</strong>. Um guia passo-a-passo, sem tretas, sobre como levar a tua empresa de &#8220;alvo f&#225;cil&#8221; para &#8220;fortaleza digital&#8221;.</p><p>Prepara o bloco de notas. Vamos falar de solu&#231;&#245;es.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://resolvesec.substack.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscrever&quot;,&quot;language&quot;:&quot;pt&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Obrigado por ler Substack de ResolveSec! Subscreva gratuitamente para receber novos posts e apoiar o meu trabalho.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Digite o seu e-mail..." tabindex="-1"><input type="submit" class="button primary" value="Subscrever"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[A Era da "Segurança de Cinema" Acabou: Porque é que a UE quer multar-te em 10 Milhões]]></title><description><![CDATA[(e porque a culpa agora &#233; tua)]]></description><link>https://resolvesec.substack.com/p/a-era-da-seguranca-de-cinema-acabou</link><guid isPermaLink="false">https://resolvesec.substack.com/p/a-era-da-seguranca-de-cinema-acabou</guid><dc:creator><![CDATA[ResolveSec]]></dc:creator><pubDate>Fri, 12 Dec 2025 12:35:39 GMT</pubDate><enclosure url="https://substack-post-media.s3.amazonaws.com/public/images/da04a8f9-7b46-4319-a9b7-eac55dbf5f0e_8001x4501.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p>Esquece o <em>Mr. Robot</em>. Esquece o <em>hacker</em> de capuz numa cave escura a teclar furiosamente c&#243;digo verde num ecr&#227; preto enquanto a banda sonora aumenta de intensidade.</p><p>Isso &#233; Hollywood. Isso vende bilhetes de cinema. Mas n&#227;o &#233; isso que vai levar a tua empresa &#224; fal&#234;ncia.</p><p>A realidade dos ataques inform&#225;ticos em 2025 &#233; muito mais aborrecida &#8212; e muito mais perigosa.</p><p>A realidade &#233; um <em>bot</em> automatizado na R&#250;ssia ou na China a enviar 10 milh&#245;es de emails de <em>phishing</em>.<br>A realidade &#233; a Dona Maria da Contabilidade, cansada numa sexta-feira &#224; tarde, a clicar num PDF chamado &#8220;Fatura_Vencida.pdf&#8221;.<br>A realidade &#233; o teu servidor ser encriptado em 30 segundos e aparecer um ficheiro de texto a pedir 500.000&#8364; em Bitcoin para te devolverem a tua pr&#243;pria empresa.</p><p>N&#227;o h&#225; m&#250;sica dram&#225;tica. H&#225; apenas sil&#234;ncio, telefones a tocar de clientes furiosos e o teu neg&#243;cio parado.</p><p>Foi para acabar com este &#8220;Velho Oeste&#8221; digital que a Uni&#227;o Europeia criou a <strong>NIS2</strong>.</p><h4>O Que &#233; a NIS2?</h4><p>A <strong>NIS2</strong> (Network and Information Security 2) n&#227;o &#233; mais uma daquelas normas burocr&#225;ticas para encher papelada e agradar a auditores.</p><p>&#201; a resposta da Europa a um facto simples: <strong>tudo est&#225; ligado.</strong></p><p>Se a empresa que gere a energia for atacada, o hospital para. Se o hospital parar, pessoas morrem. Se a log&#237;stica parar, os supermercados ficam vazios.</p><p>A primeira vers&#227;o (NIS) era um &#8220;pedido simp&#225;tico&#8221;. A NIS2 &#233; um ultimato.</p><p>A UE percebeu que a &#8220;seguran&#231;a volunt&#225;ria&#8221; n&#227;o funciona. Por isso, decidiram falar a &#250;nica l&#237;ngua que toda a gente entende: <strong>Dinheiro e Responsabilidade.</strong></p><h4>O Que Muda Para Ti? (O Ganho e a Dor)</h4><p>A maioria dos empres&#225;rios olha para a <em>compliance</em> (conformidade) como um imposto. &#8220;L&#225; tenho eu de gastar dinheiro nisto.&#8221;</p><p>Se pensares assim, j&#225; perdeste.</p><p>Deves olhar para isto atrav&#233;s da <strong>Equa&#231;&#227;o de Valor (</strong>do Alex Hormozi<strong>)</strong>:</p><ol><li><p><strong>O Risco (A Dor):</strong> Com a NIS2, as multas podem chegar aos <strong>10 Milh&#245;es de Euros</strong> ou <strong>2% do teu volume de neg&#243;cios global</strong>. Mas pior que a multa: os administradores (sim, tu, CEO) podem ser <strong>pessoalmente responsabilizados</strong> por neglig&#234;ncia. Acabou-se o &#8220;ah, isso &#233; problema do departamento de TI&#8221;. Se a casa arder, a culpa &#233; de quem tem as chaves.</p></li><li><p><strong>A Oportunidade (O Ganho):</strong> A ciberseguran&#231;a deixou de ser uma quest&#227;o t&#233;cnica para ser uma <strong>Vantagem Competitiva</strong>.</p><ul><li><p>Grandes empresas (as &#8220;Entidades Essenciais&#8221;) v&#227;o ser obrigadas a garantir que os seus fornecedores s&#227;o seguros.</p></li><li><p>Se tu tiveres a conformidade NIS2 e o teu concorrente n&#227;o, adivinha quem ganha o contrato?</p></li><li><p>A seguran&#231;a passa a ser um ativo de confian&#231;a. Tu tornas-te a op&#231;&#227;o de &#8220;risco zero&#8221; para os teus clientes.</p></li></ul></li></ol><h4>O Que o Mundo Ganha (E Tu Tamb&#233;m)</h4><p>A NIS2 vem elevar a &#8220;imunidade de grupo&#8221; do ecossistema empresarial europeu.</p><ul><li><p><strong>Menos tempo de inatividade:</strong> Menos preju&#237;zo.</p></li><li><p><strong>Mais confian&#231;a no mercado:</strong> Mais neg&#243;cios.</p></li><li><p><strong>Regras claras:</strong> Sabes exatamente o que tens de fazer (n&#227;o h&#225; adivinha&#231;&#227;o).</p></li></ul><h4>O Pr&#243;ximo Passo</h4><p>Neste momento deves estar a pensar: <em>&#8220;Ok, Frederico, j&#225; percebi que o assunto &#233; s&#233;rio. Mas ser&#225; que a minha empresa est&#225; na lista? Eu vendo sapatos/fa&#231;o software/tenho uma f&#225;brica, isto aplica-se a mim?&#8221;</em></p><p>A resposta pode surpreender-te. A rede &#233; mais larga do que pensas.</p><p>No pr&#243;ximo artigo, vou partilhar a <strong>&#8220;Lista da Verdade&#8221;</strong>. Vamos ver, preto no branco, quem s&#227;o as <strong>Entidades Essenciais</strong> e as <strong>Entidades Importantes</strong>. E, mais importante, o que acontece se tentares ignorar isto.</p><p>Fica atento. A ignor&#226;ncia, neste caso, n&#227;o &#233; uma b&#234;n&#231;&#227;o. &#201; uma multa.</p><p>Sabe mais em: https://www.resolvesec.com</p>]]></content:encoded></item></channel></rss>