Ciberseguridad
Vulnerabilidades, mejores prácticas, noticias de brechas y defensa digital.
THREAT TELEMETRY
Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spreadsheet to reconcile them. Someone else is turning that spread
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is t
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when
Kevin Mandia’s new ‘agent swarm’ security startup Armadin raises $255.5M at $2.5B valuation
Kevin Mandia, best known as the founder of Mandiant, has a new startup that is using agent swarms to test and protect enterprises.
Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286
Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android applications abusing the API serving as the main conduit for m
A Flaw in ChatGPT’s Mac App Could Have Let Hackers Grab Sensitive Data
While the focus has been on AI agents’ hacking capabilities, a recently patched vulnerability in a ChatGPT app shows that AI software is itself an inviting—and vulnerable—target.
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful for years. That is t
ThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up requests. A public secret can stay useful f
Police Arrest 16-Year-Old Suspected of Running KillSec, Seize Ransomware Leak Site and Servers
Police in Spain have arrested a 16-year-old whom investigators suspect of running the KillSec ransomware group. KillSec is accused of stealing data from organizations and threatening to publish it on its leak site unless they paid. The 16-year-old was one of 3 people arrested on September 30, when
MetaMask Security Incident Prompts Exit of Affected Ethereum Validators
MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure. "We are actively addressing and remediating the issue internally, in coordination with external partners and security advisors," the software cryptocurrency wallet
Kevin Mandia’s new ‘agent swarm’ security startup Armadin raises $255.5M at $2.5B valuation
Kevin Mandia, best known as the founder of Mandiant, has a new startup that is using agent swarms to test and protect enterprises.
How Financial Services Companies Can Modernize Their Software Supply Chain
Every security leader at a bank, insurer, or asset manager has had a version of this conversation: Security wants to eliminate a class of vulnerabilities. Engineering explains what it would take to upgrade the platform where they live. Somebody prices out the regression testing.
Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version
Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. "It delivers frontier performance in complex workflows across real-world softwa
Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs
Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt Operations & Research (THOR) team, which analyzed the explo
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manage
CISA Adds Exploited Cisco Catalyst SD-WAN Manager Auth Bypass to KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical authentication bypass flaw impacting Cisco Catalyst SD-WAN Manager to its Known Exploited Vulnerabilities (KEV), following reports of active exploitation. The vulnerability, tracked as
Bitget Confirms Third-Party Zero-Day Behind $387.5 Million Cryptocurrency Theft
Cryptocurrency exchange Bitget on Wednesday confirmed that attackers who stole $387.5 million last week exploited a zero-day flaw in third-party security products, citing ongoing investigation findings from SlowMist. "Their investigation identified malicious activity involving third-party security
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system comm
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. "Once executed, the legitimate MSP360 installe
Apple CoreGraphics PoC Emerges as WhatsApp PDF Checks Hint at Possible Delivery Path
Security researchers have published the first public proof-of-concept for CVE-2026-86950, an Apple CoreGraphics flaw Apple says may have been used in attacks against specific targeted individuals. The trigger is a malicious PDF with a crafted embedded font that crashes unpatched
US-Focused CSuite Phishing Steals Microsoft 365 Sessions and Deploys RMM Tools for Remote Access
ANY.RUN researchers traced a US-focused CSuite phishing campaign across 351 sandbox analyses, with 51% of submissions coming from the United States. Technology, manufacturing, government, and consulting organizations showed the highest exposure. By combining Microsoft 365 session
OpenSSL Fixes High-Severity DTLS Flaw That Can Leak Heap Memory Unencrypted
A High-severity OpenSSL flaw can leak heap memory to the other side of a DTLS connection or crash the program, OpenSSL said on September 29 as it released fixes. DTLS, the TLS variant used for UDP traffic, resends a handshake message if no reply arrives before the timer expires.
OpenAI Gets Sued Over the Hugging Face Hack
A nonprofit in California is doing what Hugging Face has not—attempting to hold OpenAI legally accountable for the actions of its agents.
Know Your Enemy: Browser-Based Attack Techniques in 2026
Given that the browser is where business apps are accessed and used, it makes sense that attacks are happening there too. Most breaches today begin in a browser session. Often, they never leave it, with the entire attack chain from initial access to exfiltration playing out in th
Hackers stole millions of US military personnel records during months-long data breach
The Department of Defense notified millions of current and former U.S. military personnel that their personal information had been stolen in a months-long breach.
Google announces Gemini 4 and says it’s so capable that only ‘trusted cyber defenders’ can have it right now
Google today revealed its next AI frontier model, which it's calling Gemini 4 Argon. The new model delivers "frontier performance in complex workflows across real-world software engineering, enterprise knowledge work like legal and finance, and cybersecurity defense," according t
Citrix NetScaler CVE-2026-88772 Exploit Details Show Pre-Auth Path to Shellcode Execution
Cybersecurity researchers have disclosed technical details of a recently patched critical security flaw in Citrix NetScaler ADC and Gateway that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-88772 (CVSS score: 9.5), has been described as a
Cisco Warns of Attackers Exploiting Critical Authentication Bypass in SD-WAN Manager
Attackers are exploiting a new critical zero-day flaw in Cisco Catalyst SD-WAN Manager, the system companies use to manage their Cisco SD-WAN networks, Cisco said in an advisory on September 30. The flaw, CVE-2026-76504, could allow a remote attacker with no login access to use the Manage
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits CVE-2026-73570 (CVSS score: 8.9), an unauthenticated operating system comm
Attackers Exploit NetScaler Flaw for Root Access, Deploy WHIPSHOT and SLAPSHOT
Unknown threat actors have been observed exploiting a newly patched security flaw in Citrix NetScaler ADC and NetScaler Gateway appliances to target organizations in North America and Europe. The activity, observed by Mandiant Consulting and Google Threat Intelligence Group (GTIG
Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other social-engineering content. "Once executed, the legitimate MSP360 installe
Attackers Abuse ChatGPT Custom GPTs to Deliver RAT via ClickFix Lures
Threat actors are abusing ChatGPT Custom GPTs to disguise them as legitimate product offerings and direct unsuspecting victims to malicious sites that employ ClickFix lures to deliver malware. Huntress, which observed the activity in late September 2026, said it marks the abuse o
Tesla secures $30B in new credit lines as it looks to scale Cybercab, Optimus
The company says it won't draw on the new debt facilities this year, as it has already planned at least $25 billion in capital expenditures.
Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to Ukraine, have affected more than 100 organiz
OpenAI Pauses Tool Use After Agent Bypasses Internet Controls to Reach External Chatbot
OpenAI said it has made the decision to pause training of its most powerful models after one of its agents during reinforcement learning (RL) training contacted an external chatbot by exploiting a loophole in its internet-access restrictions. "An agent attempting to complete a se
OpenAI Gets Sued Over the Hugging Face Hack
A nonprofit in California is doing what Hugging Face has not—attempting to hold OpenAI legally accountable for the actions of its agents.
Official MCP Python SDK Flaw Can Let Malicious Servers Steal OAuth Credentials
A malicious MCP server could trick an application built on the official MCP Python SDK into handing over the OAuth credentials it uses to log in to a real service, the SDK's maintainers said in a security advisory. Affected versions sent the client secret, the authorization code,
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities, medical nonpro
French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency saw the data leave. The attack was not sophi
Dutch police arrest ShinyHunters hacker accused of planning two murders
Dutch police said the hacker, arrested for being part of the ShinyHunters cybercriminal gang, had plans to organize the murder of two people on his laptop.
Dutch Police Arrest 24-Year-Old Amsterdam Man in ShinyHunters Investigation
Dutch authorities have confirmed that they arrested a 24-year-old man from Amsterdam in connection with the ShinyHunters group. "It is true that this month a 24-year-old man from Amsterdam was arrested in an investigation into the hacker group ShinyHunters," the Politie Landelijk
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component that could lead to
⚡ Weekly Recap: $387M Crypto Hack, Citrix Exploits, AI Agents Go Off-Script, and More Threats
A domain used as harmless placeholder text showed up in roughly 1,700 repositories. Then somebody registered it and started serving malicious lures. That is the kind of week this was: forgotten assumptions turning into live attack surface. Elsewhere, weak service accounts, old bugs, exposed systems
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Two critical vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway that allow remote code execution have been exploited in the wild, Citrix confirmed on September 27. It released fixes for both, along with six other flaws. One of the two affects every deployment on an affected version, inclu
RatHat Android Malware Console Uses Gemini to Identify Higher-Value Victims
RatHat's operators build and publish the Android banking trojan and control infected phones from a web console, according to security company Cleafy. Cleafy has traced nearly 100 deployments of that console since April 2026. It said this fits a malware-as-a-service model, in whic
OpenAI Pauses Training Its Most Powerful Models After Rogue Agents Target Government
Sam Altman says the company “have not been as fast as we would have liked” at dealing with security breaches, after news of further incidents over the summer forces another temporary halt.
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aime
I've Tested Over 100 Home Security Cameras. Here's Which to Buy
Keep an eye on home wherever you are with the best security cameras, including indoor and outdoor, subscription services, AI smarts, and local recording options.
Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at telecommunications organizations, universities,
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerabilities are listed below - CVE-2026-887
Carbonato Botnet Compromises Docker Hosts to Deploy Telegram-Controlled Hermes AI Agent
Cybersecurity researchers have disclosed details of a new botnet malware called Carbonato that's targeting exposed Docker daemons to deploy an open-source artificial intelligence (AI) agent framework called Hermes Agent. "The implant installs the framework unchanged, then overwri
Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain high-level internal credentials and then,
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could resul
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds write impacting the CoreGraphics component
AI is supercharging hacking, and your local hospitals and banks aren’t ready
In March, Janice Malone began getting calls about suspicious activity from her nonprofit organization, Vivian's Door. Vivian's Door, headquartered in Alabama, typically provided training, resources, and community to underserved and minority-owned businesses. The work sometimes pu
Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26. Citrix has not confirmed the flaws or published a fix. Some
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stage attack chain aime
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could resul
SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question a
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify th
OpenAI pauses training of its ‘most capable models’
As reports of OpenAI's models breaking containment, hacking sites, and generally getting out of control pile up, the company has made the decision to pause training of its most powerful models. The decision was made after a model being tested within a sandbox exploited a loophole
Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue, which described the activity as a four-stag
Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks received credible threat intelligence from federal intelligenc
Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The cross-site request forgery (CSRF) vulnerability
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below - actions-cool/issues-helper actions-cool/main
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273 (CVSS score: 9.8), a critical security flaw that could resul
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerabilities are l
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL injection in the virtuser_query plugin of Roun
Party Invite Phishing Scams Are the New Missed Connections
Email scams that look like an Evite or Paperless Post invitation are meant to snatch your data. For some, they've become an excuse to reconnect with old friends or flames.
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same JavaScript for Automation (JXA) dropper mechanism, but modify th
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are listed below - actions-cool/issues-helper actions-cool/main
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving a limited number of hot wallets," BitGet s
Anonymous Men Have Turned Cyberharassment Into a Group Sport—Here’s One Woman’s Side of the Story
This week on Uncanny Valley, we take you behind our feature on the women struggling after being targeted by the burnerverse.
Anonymous Men Have Turned Cyberharassment Into a Group Sport—Here’s One Woman’s Side of the Story
This week on Uncanny Valley, we take you behind our feature on the women struggling after being targeted by the burnerverse.
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phon
ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pile. Trusted paths get poisoned. Old bugs find new jobs. AI t
Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a generic documentation placeholder for years, the same role e
I Think I Found an AI Agent Worth the Risk
Instinct saved me $550, booked my restaurant reservations, and warned me about a phishing scam. It also wasted $64 and might be a security nightmare.
Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called Psychedelic. "When a visitor interacts with the page, the lure copi
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido, the list of Terra
Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure
Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to obtain remote code execution (RCE). "An unauth
An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later
The country’s prime minister expressed disappointment at being informed of the hack only via email. Now Australia is investigating whether OpenAI broke the law.
An OpenAI Agent Hacked Australia’s Health Service. Their Government Found Out Months Later.
The country’s prime minister expressed disappointment at being informed of the hack only via email. Now Australia is investigating whether OpenAI broke the law.
17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a subscription product with on-chain infrastructur
This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser passwords, and crypto wallet data. Talos has not seen this
The old cybersecurity model is breaking
As concern over AI safety and rogue agents continue to make headlines, it’s no surprise that cybersecurity stocks are rising, or that investors are pouring massive amounts of capital into startups trying to build the next generation of security for an AI-native world. We’re even seeing com
ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold very sensitive data on almost ALL FBI Agents
Saudi Arabia’s new Exobot EVs make the Cybertruck look normal
The Kingdom of Saudi Arabia is mostly known for its global dominance over petroleum production and oil reserves - not necessarily cars and auto manufacturing, and certainly not electric vehicle production. So it was a little surprising on Monday when a Saudi startup called Ceer u
MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick, combines an SSH state-machine flaw (CVE-2
Meta’s Muse AI Assistant Rolled Out With a Serious Security Flaw
Meta says it issued a fix for the Muse zero-day vulnerability that would have let attackers do “whatever” they wanted on a victim’s Mac, highlighting the inherent dangers of AI helpers.
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth authorization server, issuing access tokens to
Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an attacker controls, such as text read from the r
Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the chaining of two vulnerabilities in Chrome
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. Check Point rel
Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector for malicious payloads. According to Aikido
Zyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM Access
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a now-patched security flaw impacting Zyxel GS1900 series switches to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026
WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code. The fix shipped on September 22 in WordPre
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
A new flaw in WordPress core let an anonymous visitor leave a comment that planted a hidden script on the page. If a logged-in administrator later opened that page, the script could run code on the site's server. WordPress fixed the flaw, tracked as CVE-2026-93485 and dubbed "Com
SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. "SideCopy campaign operations typically initiate through spear-phishing campaigns that leverage th
Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no CVE, and no Microsoft advisory. Its author, Abdelhami
One Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a Backdoor
Malware already running on a Mac can quietly take over Meta's Muse assistant and use the broad access its owner granted the app, security researcher Patrick Wardle has shown in a proof-of-concept released on September 21. It works by changing a hidden setting so that when the use
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virginia, involved the e
Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S. District Court for the Eastern District of Virgi
Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to harvest sensitive data. The package, named "tw-
Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent security controls. "Indexed-btree is a malici
Is a Home Security System Subscription Worth It? (2026)
Just about every home security system has paid options, but with a little effort and a focus on local storage, you can build your own without the recurring costs.
Hacking group ShinyHunters claims it breached the FBI, stole agents’ and applicants’ data
The theft of agents' personal information could present a major counterintelligence threat, where agents and their families are extorted into cooperating with a foreign government.
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service to run scripts on it without logging in. C
US and China Discuss Alerting Each Other to AI National Security Threats
Officials discussed setting up a mechanism for the two countries to notify each other of AI incidents which could threaten national security.
TASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard Data
Cybersecurity researchers have disclosed details of a new campaign dubbed TASK#STOMP that delivers a PowerShell backdoor designed to harvest sensitive data from compromised hosts. The backdoor "automatically harvests and exfiltrates business documents, watches the filesystem for
Jade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK Backdoors
The North Korean threat actor known as Jade Sleet has been attributed to the compromise of an India-based "much smaller organization" in the information technology (IT) services industry, once again highlighting how the adversary continues to target developers to breach target ne
Identity Visibility in 2026: The Foundation of Identity Security
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility
Contagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in Crypto
The North Korean threat actors behind the Contagious Interview campaign have compromised at least 30,000 devices located in more than 100 countries and siphoned funds or account credentials from over 7,000 cryptocurrency wallets, according to a new joint cybersecurity advisory. T
ClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 Infrastructure
Threat actors are leveraging ClickFix-like lures to deliver a previously undocumented remote access trojan (RAT) called ChainScript. "ChainScript has appeared under multiple build names, including ComponentTask33, UpdateDigital, HostShared, and OrchidViolet66, while presenting it
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still
Identity Visibility in 2026: The Foundation of Identity Security
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility
Google’s Gemini is the latest AI model to hack other companies
Google said Gemini had "acted appropriately" by ending each hack immediately.
Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening
AI labs are toying with an industry-wide pact to slow development. Meanwhile, widely available AI chatbots are already helping uncover a tidal wave of security flaws.
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still
SolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCE
SolarWinds has released security updates to address a high-severity flaw in Access Rights Manager (ARM) that, if successfully exploited, could lead to an unauthenticated remote code execution vulnerability. The vulnerability, tracked as CVE-2026-28326, is rated 8.8 out of 10.0 on
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affected. But the explo
Identity Visibility in 2026: The Foundation of Identity Security
Identity visibility is a starting point for modern identity security, because stolen and misused credentials are among the most frequently reported initial access vectors in breach research, including Verizon's annual Data Breach Investigations Report. This article explains what identity visibility
Google’s Gemini is the latest AI model to hack other companies
Google said Gemini had "acted appropriately" by ending each hack immediately.
Google’s Gemini is the latest AI model to hack other companies
Google said Gemini had "acted appropriately" by ending each hack immediately.
Google Gemini Broke Into Real Company Systems After Security Test Domain Mix-Up
Google's Gemini model has become the latest artificial intelligence (AI) system to access the internet and break into other companies during a cybersecurity evaluation. The development was first reported by The Wall Street Journal. The incidents occurred in May 2026 as part of a
Gemini went rogue, hacked three companies, and Google hid it
In May, Gemini broke containment and hacked three different companies, but Google didn't disclose the incident until the Wall Street Journal approached the company. The hacks happened during a test of the model's cybersecurity capabilities run by third-party Irregular, which was
Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening
AI labs are toying with an industry-wide pact to slow development. Meanwhile, widely available AI chatbots are already helping uncover a tidal wave of security flaws.
Forget the AI Slowdown—the Vulnerability Explosion Is Already Happening
AI labs are toying with an industry-wide pact to slow development. Meanwhile, widely available AI chatbots are already helping uncover a tidal wave of security flaws.
Critical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the Wild
A critical vulnerability impacting Orkes Conductor is being actively exploited in the wild, according to Fortinet. The vulnerability in question is CVE-2026-58138 (CVSS v3.1 score: 9.8/CVSS v4 score: 9.3), which relates to a case of unauthenticated remote code execution. "Orkes C
CISA Flags Three Linux Kernel Vulnerabilities Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added three security flaws impacting the Linux kernel to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2025-39682 (CV
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many security programs still
An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang
TeamPCP pulled off the worst-ever software supply-chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle.
RatHat Android Malware Abuses ADB to Retain Shell Access After Uninstall
Cybersecurity researchers have flagged a new Android malware called RatHat that's assessed to be operated by China-based threat actors and features an artificial intelligence (AI)-powered system to navigate and control compromised devices. "Distributed primarily via targeted smis
Public Exploits Released for Four Linux Kernel Flaws That Enable Local Root
A security researcher has released working exploit code for four Linux kernel flaws that each let a local user gain root, the highest level of access on a machine. Kernel maintainers have fixed all four over the past few weeks, so a system running an up-to-date kernel is not affe
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required. The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0. "Missing authentication for c
Iran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal Passwords
The Iran-linked "hacktivist" persona known as Handala Hack has been attributed to a Telegram-based surveillance backdoor called HEAVYGRAM and a Delphi-based utility known as CRUDEEXCLUDE. "HEAVYGRAM offers builtin commands supporting remote command execution, system, network and
Critical Unbound DNSSEC Validator Flaw Could Allow RCE via a Malicious DNS Zone
Every release of the Unbound DNS resolver before 1.26.1 has a critical heap overflow in its DNSSEC validator, maintainer NLnet Labs said in an advisory on Wednesday. An attacker who controls a malicious zone and queries a vulnerable resolver can trigger it, enabling remote code e
Critical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host Files
Malicious code running inside a Docker Sandboxes virtual machine on macOS could escape the project directory shared into it and read or change files anywhere else on the host, Docker warns in a security announcement on September 15. The escape runs with the rights of the host acc
Critical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as Root
A critical vulnerability in Check Point's Security Management and Log Servers could allow an attacker without login credentials to run code as root on those servers over the network. The Security Management Server is the system that controls firewall policy and administrator acce
Claimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm Stealer
A financially motivated threat actor has been linked to the development and distribution of a JavaScript (JS)-based information stealer known as PhantomRaven via the npm package registry. "The developer likely wrote the malware using a large language model (LLM), an assessment ma
CISO's Expert Guide to Agentic Pentesting for Websites
Attackers now weaponize new vulnerabilities in about five days (Mandiant, part of Google Cloud). The median organization takes 43 days to patch one (Verizon DBIR 2026). A new free guide explains how autonomous AI agents are closing that gap, and what security leaders must demand
China-Aligned FamousSparrow Deploys SparroWocky Backdoor Across Latin America
The China-aligned state-sponsored threat actor known as FamousSparrow has been observed deploying a previously unreported backdoor called SparroWocky in attacks targeting multiple countries in Latin America since at least August 2025. "SparroWocky is a modular, C++ backdoor," ESE
Can You Prove a New CVE Is Exploitable Before Attackers Do? Learn How in This Webinar
A new CVE drops. Your scanner finds it. The severity score looks ugly. But that still does not answer the question that matters: Can it actually be exploited in your environment? Mythos-class AI is compressing the time between disclosure and working exploitation, while many secur
An Undercover Google Analyst Infiltrated a Notorious Supply-Chain Hacking Gang
TeamPCP pulled off the worst-ever software supply-chain hacking spree and breached thousands of companies. Now Google’s threat intelligence group says it had a mole inside the hackers’ inner circle.
An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.
In July 2025, someone registered a domain that used to belong to a content delivery network. The CDN had been wound down years earlier, and the domain it served assets from was allowed to expire. What it had not lost were its callers. Thousands of websites, code repositories, and
Supply chain attack compromete 127 paquetes NPM populares
Investigadores de seguridad descubren una campaña coordinada de compromiso de cadena de suministro que afecta a 127 paquetes NPM con más de 50 millones de descargas semanales combinadas. El malware exfiltraba credenciales de AWS y tokens de CI/CD.
BlackNova: El ransomware que usa criptografía post-cuántica
Análisis técnico de BlackNova, el primer ransomware documentado que implementa algoritmos de criptografía post-cuántica para el cifrado de archivos, haciendo que las claves sean irrecuperables incluso con computación cuántica.
Fast16, malware anterior a Stuxnet, alteró simulaciones de armas nucleares
Un nuevo análisis del malware Fast16 basado en Lua confirma que fue una herramienta de cibersabotaje diseñada para alterar simulaciones de pruebas de armas nucleares, específic
Phishing con deepfakes de voz: tasa de éxito del 78% en empresas
Nueva investigación revela que los ataques de phishing que utilizan deepfakes de voz generados por IA tienen una tasa de éxito del 78% en entornos empresariales, superando ampliamente al phishing tradicional.
CVE-2026-1234: RCE crítico en OpenSSH afecta millones de servidores
Se ha descubierto una vulnerabilidad de ejecución remota de código en OpenSSH versiones 8.9 a 9.6 que permite a atacantes no autenticados obtener acceso root. Se estima que más de 14 millones de servidores están expuestos. Parche disponible.
Cuatro paquetes npm maliciosos distribuyen infostealers y el malware DDoS Phantom Bot
Investigadores de ciberseguridad descubrieron cuatro paquetes maliciosos de npm que contienen malware para robo de información, incluyendo un clon del gusano Shai-Hulud de códi
Seguridad de la Cadena de Suministro en 2026: Defendiendo el Software Supply Chain con Herramientas de Vanguardia
La seguridad de la cadena de suministro se ha convertido en el talón de Aquiles de la ciberseguridad moderna. Exploramos las estrategias más avanzadas y herramientas emergentes para proteger cada eslabón del desarrollo de software en 2026.
SAST vs DAST 2026: Evolución y Mejores Prácticas en Testing de Seguridad Aplicativa
Exploramos el estado actual de SAST y DAST en 2026, incluyendo integración con IA generativa, herramientas híbridas IAST, y estrategias modernas de DevSecOps. Una guía completa para implementar testing de seguridad efectivo en aplicaciones cloud-native.
Atrapan a gemelos cibercriminales tras olvidar apagar la grabación de Microsoft Teams
Dos gemelos cibercriminales fueron capturados después de olvidar desactivar la grabación de Microsoft Teams durante sus actividades ilícitas. Además, se reportan otros incident
Un sistema de registro hotelero dejó expuestos un millón de pasaportes y licencias de conducir
Un sistema de registro hotelero expuso un millón de pasaportes y licencias de conducir al configurar incorrectamente su almacenamiento en la nube como público. La empresa tecnológica responsable del sistema permitió que cualquier persona accediera a los datos de los clientes sin necesidad de contraseña.
Explotan el CVE-2026-42897 de Microsoft Exchange local mediante un correo manipulado
Microsoft ha revelado una nueva vulnerabilidad de seguridad (CVE-2026-42897) que afecta a las versiones locales de Exchange Server, la cual está siendo explotada activamente en
CISA suma el CVE-2026-20182 de Cisco SD-WAN a su catálogo KEV tras exploits de acceso administrativo
La Agencia de Ciberseguridad e Infraestructura de EE.UU. (CISA) añadió la vulnerabilidad crítica CVE-2026-20182 de Cisco Catalyst SD-WAN Controller a su catálogo de Vulnerabili
Te roban el iPhone y ahí empieza el hackeo
Un ecosistema criminal subterráneo está proporcionando herramientas para desbloquear iPhones robados y realizar ataques de phishing contra los contactos de las víctimas. Los de
Zero-days en Windows exponen bypasses de BitLocker y escalada de privilegios vía CTFMON
Un investigador de ciberseguridad anónimo conocido como Chaotic Eclipse ha revelado dos nuevas vulnerabilidades zero-day en Windows, denominadas YellowKey y GreenPlasma. Estos
Kubernetes Avanzado 2026: Dominando WebAssembly, AI/ML Workloads y Zero-Trust Security
Explora las técnicas más avanzadas de Kubernetes en 2026, incluyendo la integración nativa de WebAssembly, optimización para cargas de trabajo de IA/ML y implementación de arquitecturas zero-trust. Descubre cómo maximizar el rendimiento y seguridad en clusters empresariales.
Los creadores de 'Hacks' odian la IA de verdad, de verdad, de verdad
Los cocreadores de la exitosa serie 'Hacks', Paul W. Downs y Lucia Aniello, expresaron su fuerte rechazo hacia la inteligencia artificial, calificándola como 'profundamente per
SAST vs DAST 2026: La Evolución del Application Security Testing en la Era de AI-DevSecOps
Descubre cómo las herramientas SAST y DAST han evolucionado en 2026 con inteligencia artificial y automatización avanzada. Una guía completa sobre las mejores prácticas actuales para implementar security testing en pipelines modernos de CI/CD.
Criptografía Post-Cuántica en 2026: Implementación Práctica en Sistemas de Producción
La era post-cuántica ya está aquí. Con los estándares NIST finalizados y la adopción masiva de algoritmos como ML-KEM y ML-DSA, exploramos las mejores prácticas para migrar sistemas críticos a la criptografía resistente a computadoras cuánticas.
Zero Trust Architecture 2026: Implementación Práctica con ZTNA 3.0 y Quantum-Ready Security
Descubre cómo implementar arquitecturas Zero Trust modernas con las últimas tecnologías ZTNA 3.0, integración de IA cuántica y micro-segmentación adaptativa. Una guía práctica para profesionales que buscan fortalecer su infraestructura de ciberseguridad.
Las estafas de 'secuestro de reservaciones' apuntan a los viajeros: así puedes protegerte
Los estafadores están realizando llamadas haciéndose pasar por personal de hoteles para solicitar pagos urgentes a los viajeros en esquemas conocidos como 'secuestro de reservas'. Los expertos recomiendan verificar siempre la identidad del llamante contactando directamente al hotel antes de proporcionar información de pago.
Una podadora robótica hackeable abre una nueva pesadilla
Un cortacésped robótico presenta vulnerabilidades de seguridad que permiten ser hackeado, representando nuevos riesgos cibernéticos. Además, Meta elimina oficialmente el cifrad
SAST vs DAST en 2026: La Evolución del Testing de Seguridad con IA y DevSecOps
El panorama del testing de seguridad de aplicaciones ha evolucionado dramáticamente con la integración de IA generativa y las metodologías DevSecOps avanzadas. Exploramos cómo SAST y DAST se han transformado para enfrentar las amenazas modernas de ciberseguridad.
El exploit Dirty Frag del kernel de Linux otorga acceso root en las principales distribuciones
Se ha descubierto una nueva vulnerabilidad de escalada de privilegios locales llamada Dirty Frag que afecta al kernel de Linux y permite obtener acceso root en las principales
SAST vs DAST en 2026: La Evolución de las Pruebas de Seguridad de Aplicaciones en la Era de la IA
El panorama de SAST y DAST ha evolucionado dramáticamente con la integración de IA generativa y análisis de código asistido por ML. Descubre las mejores prácticas actuales y herramientas de vanguardia para 2026.
Paquetes de PyPI distribuyen el malware ZiChatBot mediante APIs de Zulip en Windows y Linux
Investigadores de ciberseguridad han descubierto tres paquetes maliciosos en el repositorio PyPI que distribuyen de forma encubierta el malware ZiChatBot en sistemas Windows y
Explotan activamente el CVE-2026-22679 de Weaver E-cology mediante su API de depuración
Una vulnerabilidad crítica de ejecución remota de código sin autenticación (CVE-2026-22679) en la plataforma empresarial Weaver E-cology está siendo explotada activamente por c
ScarCruft hackea una plataforma de videojuegos para desplegar el malware BirdCall en Android y Windows
El grupo de hackers norcoreano ScarCruft comprometió una plataforma de videojuegos para distribuir el malware BirdCall dirigido a coreanos étnicos en China. Este ataque de cade
Microsoft detalla una campaña de phishing contra 35,000 usuarios en 26 países
Microsoft reveló detalles de una campaña masiva de robo de credenciales que afectó a más de 35,000 usuarios en 26 países entre el 14 y 16 de abril de 2026. Los atacantes utiliz
CISA añade a su catálogo KEV el CVE-2026-31431, una falla de acceso root en Linux explotada activamente
La Agencia de Ciberseguridad e Infraestructura de EE.UU. (CISA) agregó la vulnerabilidad CVE-2026-31431 a su catálogo de Vulnerabilidades Explotadas Conocidas debido a evidenci
Hackean 30,000 cuentas de Facebook mediante una campaña de phishing con Google AppSheet
Una operación de origen vietnamita ha comprometido aproximadamente 30,000 cuentas de Facebook utilizando Google AppSheet como 'relé de phishing' para distribuir correos electró
Seguridad en la Cadena de Suministro de Software: Defendiendo el Código desde el Origen en 2026
La seguridad de la cadena de suministro se ha convertido en el eslabón más crítico de la ciberseguridad moderna. Con ataques sofisticados como el de SolarWinds aún resonando en la industria, exploraremos las mejores prácticas, herramientas y frameworks actuales para proteger cada eslabón del desarrollo de software.
Grupos de cibercrimen usan vishing y abuso de SSO en extorsiones exprés contra plataformas SaaS
Investigadores de ciberseguridad alertan sobre dos grupos criminales, Cordial Spider y Snarky Spider, que están ejecutando ataques de extorsión rápidos y de alto impacto en ent
Boletín ThreatsDay: redadas de SMS Blaster, fallas en OpenEMR, 600 mil hackeos en Roblox y 25 historias más
Esta semana se han detectado nuevas tácticas de ciberataques incluyendo torres celulares falsas para enviar mensajes de estafa y herramientas maliciosas que se instalan automát
Atacan la cadena de suministro de PyTorch Lightning e Intercom-client para robar credenciales
Los actores de amenaza comprometieron el popular paquete de Python Lightning, publicando las versiones maliciosas 2.6.2 y 2.6.3 el 30 de abril de 2026 para robar credenciales. Este ataque a la cadena de suministro de software también afectó al paquete Intercom-client, según reportaron múltiples firmas de seguridad.
Explotan en 36 horas la inyección SQL CVE-2026-42208 de LiteLLM tras su divulgación
Una vulnerabilidad crítica de inyección SQL (CVE-2026-42208) en el paquete Python LiteLLM de BerriAI está siendo explotada activamente por ciberdelincuentes apenas 36 horas des
Zero Trust 3.0: La Nueva Era de la Ciberseguridad Distribuida en 2026
Explora cómo Zero Trust ha evolucionado hacia un modelo distribuido e inteligente en 2026, integrando IA cuántica y mesh security para crear arquitecturas de seguridad verdaderamente adaptativas. Descubre las mejores prácticas y implementaciones actuales.
El gadget anti-IA de moda es una cyberdeck
En TikTok, las mujeres jóvenes se están volviendo virales por crear computadoras caseras y caprichosas dentro de carteras, conocidas como 'cyberdecks'. Estos dispositivos se ha
Extraditan a EE. UU. a un hacker chino de Silk Typhoon por ciberataques a investigaciones sobre COVID
Xu Zewei, un ciudadano chino de 34 años acusado de pertenecer al grupo de hackers Silk Typhoon patrocinado por el estado chino, fue extraditado a Estados Unidos desde Italia tr
Investigadores descubren 'fast16', malware anterior a Stuxnet dirigido a software de ingeniería
Investigadores de ciberseguridad han descubierto un malware basado en Lua llamado 'fast16' que fue creado en 2005, años antes que Stuxnet, y que también tenía como objetivo sab
Seguridad de la Cadena de Suministro: Defendiendo tu Stack Tecnológico en 2026
La seguridad de la cadena de suministro se ha vuelto crítica con el aumento de ataques sofisticados contra dependencias y proveedores. Exploramos las mejores prácticas y herramientas actuales para proteger tu infraestructura tecnológica.
UNC6692 se hace pasar por soporte técnico en Microsoft Teams para desplegar el malware SNOW
Un nuevo grupo de amenazas llamado UNC6692 está suplantando empleados de soporte técnico a través de Microsoft Teams para engañar a víctimas y desplegar malware personalizado l
Explotan en 13 horas la falla CVE-2026-33626 de LMDeploy tras su divulgación
Una vulnerabilidad de alta severidad (CVE-2026-33626) en LMDeploy, un toolkit de código abierto para desplegar modelos de lenguaje, fue explotada activamente en menos de 13 hor
Un grupo no autorizado habría accedido a Mythos, la herramienta cibernética exclusiva de Anthropic
Un grupo no autorizado habría obtenido acceso a Mythos, la herramienta cibernética exclusiva de Anthropic, según reportes recientes. Anthropic confirmó a TechCrunch que está in
Microsoft corrige el CVE-2026-40372, una falla crítica de escalada de privilegios en ASP.NET Core
Microsoft ha lanzado actualizaciones fuera de banda para corregir una vulnerabilidad crítica en ASP.NET Core (CVE-2026-40372) que permite escalada de privilegios, con una puntu
UAC-0247 ataca clínicas y dependencias del gobierno ucraniano con una campaña de malware para robar datos
El equipo de respuesta a emergencias informáticas de Ucrania (CERT-UA) reveló una nueva campaña de malware dirigida por el grupo UAC-0247 contra instituciones gubernamentales y
Abusan de los webhooks de n8n desde octubre de 2025 para distribuir malware por correos de phishing
Desde octubre de 2025, ciberdelincuentes han estado explotando n8n, una plataforma de automatización de flujos de trabajo con IA, para ejecutar campañas de phishing sofisticada
Una falla explotada activamente en nginx-ui (CVE-2026-33032) permite tomar el control total del servidor
Una vulnerabilidad crítica en nginx-ui (CVE-2026-33032) con puntuación CVSS de 9.8 está siendo explotada activamente, permitiendo a los atacantes eludir la autenticación y toma
OpenAI lanza GPT-5.4-Cyber con acceso ampliado para equipos de seguridad
OpenAI lanzó GPT-5.4-Cyber el martes, una variante de su modelo insignia optimizada específicamente para casos de uso de ciberseguridad defensiva, pocos días después de que Ant
Microsoft publica parches para un zero-day de SharePoint y otras 168 vulnerabilidades
Microsoft lanzó actualizaciones para corregir un récord de 169 vulnerabilidades de seguridad en su cartera de productos, incluyendo una falla de día cero en SharePoint que ha s
Explotan activamente el CVE-2025-0520 de ShowDoc en servidores sin parchear
Una vulnerabilidad crítica de carga de archivos sin restricciones (CVE-2025-0520) con puntuación CVSS de 9.4 está siendo explotada activamente en servidores ShowDoc sin parches
El hackeo más tonto del año dejó al descubierto un problema muy real
En abril pasado, un hacker manipuló los anuncios de semáforos peatonales para imitar las voces de Mark Zuckerberg y Elon Musk. Los registros obtenidos por WIRED revelan la falt
APT37 de Corea del Norte usa ingeniería social en Facebook para distribuir el malware RokRAT
El grupo de hackers norcoreano APT37 (también conocido como ScarCruft) ha ejecutado una campaña de ingeniería social en Facebook, donde los atacantes agregan a sus objetivos co
Criptografía Post-Cuántica en 2026: Implementando CRYSTALS-Kyber y ML-DSA en Producción
Con la estandarización completa del NIST y la adopción masiva en 2026, la criptografía post-cuántica ya no es una promesa futura sino una realidad operativa. Analizamos las implementaciones actuales de CRYSTALS-Kyber 1024 y ML-DSA para proteger infraestructuras críticas.
Adobe parcha el CVE-2026-34621 de Acrobat Reader, explotado activamente
Adobe ha lanzado actualizaciones de emergencia para corregir una vulnerabilidad crítica en Acrobat Reader (CVE-2026-34621) con puntuación CVSS de 8.6 que está siendo explotada
Google despliega DBSC en Chrome 146 para bloquear el robo de sesiones en Windows
Google ha implementado las Credenciales de Sesión Vinculadas al Dispositivo (DBSC) en Chrome 146 para todos los usuarios de Windows, una función de seguridad que previene el robo de sesiones tras meses de pruebas beta. La expansión a macOS está planificada para una próxima versión de Chrome.
APT28 despliega el malware PRISMEX en una campaña contra Ucrania y aliados de la OTAN
El grupo de amenazas ruso APT28 ha lanzado una campaña de phishing dirigida contra Ucrania y sus aliados de la OTAN, desplegando un nuevo malware llamado PRISMEX. Este malware
El nuevo ataque GPUBreach logra escalada total de privilegios en la CPU mediante bit-flips en GDDR6
Una nueva investigación académica ha identificado ataques RowHammer contra GPUs de alto rendimiento que permiten escalar privilegios y tomar control completo del sistema host.
Storm-1175, ligado a China, explota zero-days para desplegar rápidamente el ransomware Medusa
El grupo de amenazas chino Storm-1175 ha estado explotando vulnerabilidades zero-day y N-day para desplegar rápidamente el ransomware Medusa en ataques de alta velocidad contra
Fortinet parcha el CVE-2026-35616 de FortiClient EMS, explotado activamente
Fortinet ha lanzado parches de emergencia para una vulnerabilidad crítica (CVE-2026-35616) en FortiClient EMS que está siendo explotada activamente en ataques reales. La falla
TA416, ligado a China, ataca gobiernos europeos con PlugX y phishing basado en OAuth
El grupo de amenazas TA416, vinculado a China, ha atacado gobiernos y organizaciones diplomáticas europeas desde mediados de 2025 utilizando malware PlugX y técnicas de phishin
El gigante de telesalud Hims & Hers reporta el hackeo de su sistema de atención al cliente
La empresa estadounidense de telesalud Hims & Hers reportó que hackers comprometieron su sistema de atención al cliente durante varios días en febrero. Los ciberdelincuentes lo
Hackers explotan el CVE-2025-55182 para vulnerar 766 servidores Next.js y robar credenciales
Los hackers han explotado la vulnerabilidad React2Shell (CVE-2025-55182) para comprometer 766 hosts de Next.js y robar credenciales de bases de datos, claves SSH, secretos de A
Mercor reporta un ciberataque ligado al compromiso del proyecto de código abierto LiteLLM
La startup de reclutamiento con IA Mercor confirmó un incidente de seguridad después de que un grupo de hackers extorsionadores se atribuyera el robo de datos de sus sistemas.
Zero Trust en 2026: Arquitectura de Seguridad para la Era Post-Quantum
La evolución del modelo Zero Trust hacia arquitecturas resistentes a computación cuántica está redefiniendo la ciberseguridad empresarial. Exploramos las implementaciones más avanzadas y las mejores prácticas para desarrolladores senior en el ecosistema tecnológico actual.
El malware DeepLoad usa ClickFix y persistencia por WMI para robar credenciales del navegador
Una nueva campaña utiliza la táctica de ingeniería social ClickFix para distribuir el malware DeepLoad, que emplea ofuscación asistida por IA e inyección de procesos para evadi
TA446 despliega el kit de exploits DarkSword para iOS en una campaña dirigida de spear-phishing
Proofpoint ha revelado una campaña de correos electrónicos dirigidos donde actores de amenazas vinculados a Rusia están utilizando el kit de exploits DarkSword recientemente di
Hackers ligados a Irán vulneran el correo personal del director del FBI y atacan a Stryker con un wiper
Hackers vinculados a Irán lograron vulnerar la cuenta de correo personal de Kash Patel, director del FBI, filtrando fotos y documentos en internet. El grupo Handala Hack Team s
Criptografía Post-Cuántica en 2026: Migración Crítica Hacia la Era Quantum-Safe
La amenaza cuántica es una realidad inminente. En 2026, la migración hacia algoritmos post-cuánticos estandarizados por NIST es crucial para mantener la seguridad criptográfica ante computadoras cuánticas de escala comercial.
Rastrean activamente el CVE-2026-3055 de Citrix NetScaler (CVSS 9.3), una falla de lectura excesiva de memoria
Una vulnerabilidad crítica (CVE-2026-3055) con puntuación CVSS de 9.3 está siendo explorada activamente en Citrix NetScaler ADC y Gateway, permitiendo filtración de información
Arquitectura Zero Trust: Implementación paso a paso en 2026
Guía práctica para implementar una arquitectura Zero Trust en organizaciones modernas: principios fundamentales, herramientas, fases de adopción y casos de uso reales con Cloudflare One y otras soluciones líderes.