Threats Affecting Mozambique
View all threats affecting or targeting Mozambique. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Mozambique
Click on any threat for detailed analysis and mitigation recommendations
AnonyMousKIT is an AI-powered Phishing-as-a-Service platform that targets stolen Apple devices by disabling Activation Lock. It automates credential harvesting via email, SMS, WhatsApp, and AI-driven voice phishing calls, primarily targeting device owners with personalized lures. The platform operates through a decentralized supply chain with hundreds of reseller storefronts and operators, mainly conducting vishing calls to Brazil. Operational logs leaked due to coding vulnerabilities reveal extensive infrastructure and operator details. This campaign monetizes stolen iPhones by bypassing security features through industrialized social engineering. MediumCampaign Join the discussion | AlienVault OTX General | 08/27/2026, 08:04:55 UTC Added: 08/28/2026, 00:37:15 UTC |
A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument school_id can lead to improper authorization. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 02/06/2026, 10:32:07 UTC Added: 02/06/2026, 10:45:26 UTC |
A security vulnerability has been detected in Portabilis i-Educar up to 2.9.10. Affected by this issue is some unknown functionality of the file app/Http/Controllers/AccessLevelController.php of the component User Type Handler. The manipulation leads to insecure inherited permissions. The attack may be initiated remotely. The exploit has been disclosed publicly and may be used. Join the discussion | CVE Database V5 | 10/09/2025, 20:02:06 UTC Added: 10/10/2025, 03:36:11 UTC |
New Predator spyware infrastructure revealed activity in Mozambique for first time Source: https://securityaffairs.com/179036/hacking/new-predator-spyware-infrastructure-revealed-activity-in-mozambique-for-first-time.html Join the discussion | Reddit InfoSec News | 06/16/2025, 10:26:36 UTC Added: 06/16/2025, 10:34:21 UTC |
0 A reflected Cross-Site Scripting vulnerability in the standard documentation upload functionality in Portabilis i-Educar 2.9 allows attacker to craft malicious urls with arbitrary javascript in the 'titulo_documento' parameter. Join the discussion | CVE Database V5 | 12/18/2024, 00:00:00 UTC Added: 02/25/2026, 21:38:22 UTC |
0 Multiple stored cross-site scripting (XSS) vulnerabilities in the component /configuracao/gateway_pagamento.php of WeGIA v3.2.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the id or name parameter. Join the discussion | CVE Database V5 | 12/05/2024, 00:00:00 UTC Added: 02/25/2026, 21:38:06 UTC |
0 Portabilis i-Educar 2.8.0 is vulnerable to SQL Injection in the "getDocuments" function of the "InstituicaoDocumentacaoController" class. The "instituicao_id" parameter in "/module/Api/InstituicaoDocumentacao?oper=get&resource=getDocuments&instituicao_id" is not properly sanitized, allowing an unauthenticated remote attacker to inject malicious SQL commands. Join the discussion | CVE Database V5 | 11/06/2024, 00:00:00 UTC Added: 02/25/2026, 21:43:48 UTC |
Showing 1 to 7 of 7 results