📡 NEWS PROCESSOR

pub-andromeda.oasis // 10000 artĂ­culos // v0.2
total: 10000
mostrando: 54
🥇 gold: 2022
âś… reliable: 4706
⚠️ mixed: 2683
đźš« caution: 589
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 14 fuentes 📊 datos Mon, 25 May 2026 11:29:13
A new coordinated cross-ecosystem software supply chain attack campaign has targeted npm, PyPI, and Crates.io to distribute credential-stealing malware. The campaign, codenamed TrapDoor, spans more than 34 malicious packages across over 384 versions. The earliest activity was recorded on May 22, 20…
80
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 3 fuentes Mon, 25 May 2026 15:02:54
Cybersecurity researchers have shed light on a cross-platform malware called RemotePE that has been put to use by the North Korea-linked Lazarus Group in attacks targeting financial and cryptocurrency organizations. RemotePE, per NCC Group subsidiary Fox-IT, is part of a multi-stage attack chain th…
70
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Mon, 25 May 2026 17:00:00
Ask a cybersecurity pro about Network Detection and Response (NDR) and you might still hear "Noisy," "Too much data." But ask the teams running NDR that includes agentic AI capabilities and you'll hear they're actually using it to catch threats earlier, triage faster, and chase fewer false positives…
94
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 5 fuentes 📊 datos Mon, 25 May 2026 17:32:46
Threat actors are exploiting a recently disclosed critical security flaw in Ghost CMS to inject malicious JavaScript code with an aim to fuel ClickFix attacks. According to QiAnXin XLab, the activity involves the exploitation of CVE-2026-26980 (CVSS score: 9.4), an SQL injection vulnerability in Gh…
98
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 16 fuentes 📎 bien sourced Mon, 25 May 2026 19:43:27
Monday recap. Same mess, new week. A sketchy dev tool got people pwned, old bugs came back from the dead, and security products somehow needed protecting from themselves. A bunch of companies spent the week checking old boxes and forgotten servers they should've patched years ago. Good times. Phis…
87
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 3 fuentes 📊 datos Sat, 23 May 2026 17:25:35
Anthropic on Friday disclosed that Project Glasswing has helped uncover more than 10,000 high- or critical-severity vulnerabilities across some of the most "systemically" important software across the world since the cybersecurity initiative went live last month. Project Glasswing is a defensive …
98
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 16 fuentes Sat, 23 May 2026 21:37:51
A new "coordinated" supply chain attack campaign has impacted eight packages on Packagist including malicious code designed to run a Linux binary retrieved from a GitHub Releases URL. "Although the affected packages were all Composer packages, the malicious code was not added to composer.json," Soc…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 16 fuentes Sat, 23 May 2026 22:05:10
GitHub has rolled out new controls for npm to improve the security of the software supply chain, giving maintainers the ability to explicitly approve a release prior to the packages becoming publicly available for installation. Called staged publishing, the feature is now generally available on npm…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 6 fuentes 📊 datos Sat, 23 May 2026 12:53:48
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability in question is CVE-2026-9082 (CVSS score: 6.5)…
80
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 2 fuentes 📊 datos Sat, 23 May 2026 13:05:13
A maximum-severity security vulnerability impacting LiteSpeed User-End cPanel Plugin has come under active exploitation in the wild. The flaw, tracked as CVE-2026-48172 (CVSS score: 10.0), relates to an instance of incorrect privilege assignment that an attacker could abuse to run arbitrary scripts…
81
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 3 fuentes Sat, 23 May 2026 15:21:13
Cybersecurity researchers have flagged a fresh software supply chain attack campaign that has targeted multiple PHP packages belonging to Laravel-Lang to deliver a comprehensive credential-stealing framework. The affected packages include - laravel-lang/lang laravel-lang/http-statuses lara…
75
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 2 fuentes Fri, 22 May 2026 23:05:02
Authorities in Europe and North America have announced the dismantling of a criminal virtual private network (VPN) service used by criminal actors to obscure the origins of ransomware attacks, data theft, scanning, and denial-of-service attacks. Codenamed Operation Saffron, the disruption of Firs…
70
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Fri, 22 May 2026 17:08:12
1 Introduction This article provides a technical analysis of how many Windows kernel mode drivers can be interacted with from user mode without the hardware they were developed for. This work was motivated by driver-oriented vulnerability research and the need to evaluate the exploitability of indi…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 7 fuentes 📊 datos Fri, 22 May 2026 17:25:24
Cybersecurity researchers have disclosed details of a new automated campaign called Megalodon that has pushed 5,718 malicious commits to 5,561 GitHub repositories within a six-hour window. "Using throwaway accounts and forged author identities (build-bot, auto-ci, ci-bot, pipeline-bot), the attacke…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 8 fuentes Fri, 22 May 2026 21:50:32
The Belarus-aligned threat actor known as Ghostwriter (aka UAC-0057 and UNC1151Ukraine's National Security and Defense Council) has been observed using lures related to Prometheus, a Ukrainian online learning platform, to target government organizations in the country. The activity, per the Compute…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 6 fuentes 📊 datos Fri, 22 May 2026 11:17:33
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex One to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities in question are listed below - CVE-…
90
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 7 fuentes đź”® especulativo Fri, 22 May 2026 14:20:18
The U.S. Department of Justice (DoJ) on Thursday announced the arrest of a Canadian man in connection with allegedly operating a distributed denial-of-service (DDoS) botnet known as Kimwolf. In tandem, Jacob Butler (aka Dort), 23, Ottawa, Canada, has been charged with offenses related to the develo…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 8 fuentes 📊 datos Fri, 22 May 2026 11:06:18
Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker to access sensitive data. Tracked as CVE-2026-20223 (CVSS score: 10.0), the vulnerability arises from insufficient validation and authentication when acce…
97
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 38 fuentes Thu, 21 May 2026 19:47:09
Cybersecurity researchers have disclosed details of a new Linux malware dubbed Showboat that has been put to use in a campaign targeting a telecommunications provider in the Middle East since at least mid-2022. "Showboat is a modular post-exploitation framework designed for Linux systems, capable o…
56
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Thu, 21 May 2026 17:22:14
This week starts small. A token leaks. A bad package slips in. A login trick works. An old tool shows up again. At first, it feels like the usual mess. Then you see the pattern: attackers are not always breaking in. They are using the parts we already trust. That is what makes it worrying. The dan…
97
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 8 fuentes 📊 datos Thu, 21 May 2026 09:14:11
Drupal has released security updates for a "highly critical" security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privilege escalation, or information disclosure. The vulnerability, now tracked as CVE-2026-9082, carries a CVSS score of 6.5 out …
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 10 fuentes Thu, 21 May 2026 09:57:01
GitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device involving a poisoned version of the Nx Console Microsoft Visual Studio Code (VS Code) extension.  The development comes as the Nx team revealed that the extensi…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 19 fuentes 📊 datos Thu, 21 May 2026 13:05:53
Cybersecurity researchers have disclosed details of a vulnerability in the Linux kernel that remained undetected for nine years. The vulnerability, tracked as CVE-2026-46333 (CVSS score: 5.5), is a case of improper privilege management that could permit an unprivileged local user to disclose sensit…
52
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Thu, 21 May 2026 16:00:00
Consider a cached access key on a single Windows machine. It got there the way most cached credentials do - a user logged in, and the key stored itself automatically. Standard AWS behavior. No one misconfigured anything or violated a policy. Yet that single key, which was easily accessible to a mino…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 10 fuentes 📊 datos Thu, 21 May 2026 16:25:57
Microsoft has disclosed that a privilege escalation and a denial-of-service flaw in Defender has come under active exploitation in the wild. The former, tracked as CVE-2026-41091, is rated 7.8 on the CVSS scoring system. Successful exploitation of the flaw could allow an attacker to gain SYSTEM pri…
85
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📎 bien sourced 📊 datos Wed, 20 May 2026 17:28:00
New Industry Data Just Released Suggests Not. On May 19th, 2026, Orchid Security released the results of our Identity Gap: Snapshot 2026. Among the findings, "identity dark matter" (the unseen, unmanaged elements of identity) now overshadows the visible elements 57% vs. 43%. And it couldn't have oc…
66
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Wed, 20 May 2026 18:21:43
Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Discord and Microsoft Graph API for command-and-control (C2 or C&C) communications. Webworm, first publicly documented by Broadcom-owned Symantec …
97
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 13 fuentes Wed, 20 May 2026 20:06:44
Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company's Artifact Signing system to deliver malicious code and conduct ransomware and other attacks, compromising thousands of machines and networks across the world. The tech giant attribut…
94
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 6 fuentes Wed, 20 May 2026 22:36:54
Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (AI) agents. RAMPART, short for Risk Assessment and Measurement Platform for Agentic Red Teaming, functions as a Pytest-native safety and securi…
97
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 12 fuentes 📊 datos Wed, 20 May 2026 13:58:26
Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The zero-day flaw, now tracked as CVE-2026-45585, carries a CVSS score of 6.8. It has been described as a BitLocker security feature bypass. "Microsoft is awar…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 14 fuentes Wed, 20 May 2026 16:00:00
AI-generated lookalike domains are now embedded inside the third-party scripts running on your web properties. Here's why your current stack can't see them, and what detection actually requires. Download the CISO Expert Guide to Typosquatting in the AI Era → TL;DR  Typosquatting is no longer a…
92
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 5 fuentes Wed, 20 May 2026 09:31:15
GitHub on Tuesday said it's investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP listed the platform's source code and internal organizations for sale on a cybercrime forum. "While we currently have no evidence of impact to customer inform…
98
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 18 fuentes 📊 datos Wed, 20 May 2026 10:42:06
Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised. It said the scope of the incident is limited to the Grafana Labs GitHub environment, which includes public and private source code along with…
68
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Tue, 19 May 2026 13:19:23
Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace. The extension in question is rwl.angular-console (version 18.95.0), a popular user interface and plugin for code editors like VS Cod…
59
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Tue, 19 May 2026 14:53:15
Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote code execution and enable an attacker to read arbitrary mails from the virtual appliance. "These vulnerabilities could have …
97
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 10 fuentes 📎 bien sourced 📊 datos Tue, 19 May 2026 16:14:45
Drupal has issued an alert stating that it intends to release a "core security release" for all supported branches on May 20, 2026, from 5-9 p.m. UTC. "The Drupal Security Team urges you to reserve time for core updates at that time because exploits might be developed within hours or days," the mai…
67
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Tue, 19 May 2026 17:00:00
In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across five countries.  The targets of the platform received a message asking them to enter a short code at microsoft.com/devicelog…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 26 fuentes 📊 datos Tue, 19 May 2026 20:26:26
Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation (LPE). Dubbed DirtyDecrypt (aka DirtyCBC), the vulnerability was discovered and reported by the Zellic and V12 security team on May 9, 20…
89
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 5 fuentes 📊 datos Tue, 19 May 2026 22:08:12
Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users. The activity, per HUMAN's Satori Threat Intelligence and Research Team, encompassed 455 malicious Android apps and 183 threat actor-owned command-and-control…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 10 fuentes Tue, 19 May 2026 10:24:17
Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv ecosystem as part of the ongoing Mini Shai-Hulud attack wave. "The attack affects packages tied to the npm maintainer account atool, including …
94
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 15 fuentes Tue, 19 May 2026 10:58:06
In yet another software supply chain attack, threat actors have compromised the popular GitHub Actions workflow, actions-cool/issues-helper, to run malicious code that harvests sensitive credentials and exfiltrates them to an attacker-controlled server. "Every existing tag in the repository has bee…
82
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📎 bien sourced Mon, 18 May 2026 18:30:00
What happens when a phishing email looks clean enough to pass through security, but dangerous enough to expose the business after one click? That is the gap many SOCs still struggle with: the attacks that leave teams unsure what was exposed, who else was targeted, and how far the risk has spread. Ea…
75
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Mon, 18 May 2026 19:20:17
Monday opens with a trust problem. A mail server flaw is under active use. A network control system was targeted. Trusted packages were poisoned. A fake model page pushed a stealer. Then came the familiar ransom claim: the data was returned and deleted. The pattern is clear. One weak dependency can …
69
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Mon, 18 May 2026 22:51:18
INTERPOL has coordinated a first-of-its-kind cybercrime crackdown across the Middle East and North Africa (MENA) that led to 201 arrests and the identification of an additional 382 suspects. The initiative involved the efforts of 13 countries from the region between October 2025 and February 2026, a…
85
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 4 fuentes Mon, 18 May 2026 12:16:37
A new analysis of the Lua-based fast16 malware has confirmed that it was a cyber sabotage tool designed to tamper with nuclear weapons testing simulations. According to Broadcom-owned Symantec and Carbon Black teams, the pre-Stuxnet tool was engineered to corrupt uranium-compression simulations that…
85
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 3 fuentes 📊 datos Mon, 18 May 2026 14:27:26
Cybersecurity researchers have discovered four new npm packages containing information-stealing malware, one of which is a clone of the Shai-Hulud worm open-sourced by TeamPCP. The list of identified packages is below - chalk-tempalte (825 Downloads) @deadcode09284814/axios-util (284 Downloads) axo…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 6 fuentes Mon, 18 May 2026 14:27:34
Chaotic Eclipse, the security researcher behind the recently disclosed Windows flaws, YellowKey and GreenPlasma, has released a proof-of-concept (PoC) for a Windows privilege escalation zero-day flaw that grants attackers SYSTEM privileges on fully patched Windows systems. Codenamed MiniPlasma, the …
98
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 7 fuentes 📎 bien sourced 📊 datos Mon, 18 May 2026 16:24:05
Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors to bypass authentication and execute arbitrary code. Topping the list is a critical flaw impacting Ivanti Xtraction (CVE-2026-8043, CVSS score: 9.6) that could be exp…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 13 fuentes Mon, 18 May 2026 16:53:41
Supply chain attackers are not only trying to slip malicious code into trusted software. They are trying to steal the access that makes trusted software possible. Recently, three separate campaigns hit npm, PyPI, and Docker Hub in a 48-hour window, and all three targeted secrets from developer envir…
93
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 4 fuentes 📊 datos Sun, 17 May 2026 17:27:53
A newly disclosed security flaw impacting NGINX Plus and NGINX Open has come under active exploitation in the wild, days after its public disclosure, according to VulnCheck. The vulnerability, tracked as CVE-2026-42945 (CVSS score: 9.2), is a heap buffer overflow in ngx_http_rewrite_module affecting…
83
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📎 bien sourced Sun, 17 May 2026 12:43:33
Grafana has disclosed that an "unauthorized party" obtained a token that granted them the ability to access the company's GitHub environment and download its codebase. "Our investigation has determined that no customer data or personal information was accessed during this incident, and we have f…
81
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 2 fuentes Sat, 16 May 2026 20:50:48
A critical security vulnerability impacting the Funnel Builder plugin for WordPress has come under active exploitation in the wild to inject malicious JavaScript code into WooCommerce checkout pages with the goal of stealing payment data. Details of the activity were published by Sa…
79
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad âś“ 4 fuentes Fri, 15 May 2026 19:05:04
Cybersecurity researchers have disclosed a set of four security flaws in OpenClaw that could be chained to achieve data theft, privilege escalation, and persistence. The vulnerabilities, collectively dubbed Claw Chain by Cyera, can permit an attacker to establish a foothold, expose s…
62
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Fri, 15 May 2026 22:40:25
The Russian state-sponsored hacking group known as Turla has transformed its custom backdoor Kazuar into a modular peer-to-peer (P2P) botnet that's engineered for stealth and persistent access to compromised hosts. Turla, per the U.S. Cybersecurity and Infrastructure Security Agency…
⚡ Procesando...