📡 NEWS PROCESSOR

pub-andromeda.oasis // 10000 artículos // v0.3
total: 10000
mostrando: 150
🥇 gold: 2424
✅ reliable: 4979
⚠️ mixed: 2259
🚫 caution: 338
98
fiabilidad
Axios RELIABLE 7.5 geopolítica ✓ 48 fuentes 📎 bien sourced Sun, 23 Aug 2026 23:15:35
President Trump defended the expansion of data centers in an interview with his former fixer, Michael Cohen, that aired in full on Sunday.Why it matters: Trump's support comes as data centers face growing backlash in both red and blue states.What he's saying: Trump told Cohen during their interview …
agrupados por: centers
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 43 fuentes Fri, 28 Aug 2026 00:06:19
OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations o…
agrupados por: days · exploit
95
fiabilidad
BleepingComputer RELIABLE 8.0 ciberseguridad ✓ 9 fuentes Thu, 27 Aug 2026 12:31:53
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. [...]
agrupados por: exploited · papercut · zero · emergency · patch · releases
96
fiabilidad
BleepingComputer RELIABLE 8.0 ciberseguridad ✓ 7 fuentes Fri, 21 Aug 2026 08:25:33
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. [...]
agrupados por: cisa · exploited
84
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 2 fuentes 📊 datos Fri, 28 Aug 2026 13:50:59
Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026. These campaigns, per Recorded Future Insikt Group, have led to the deployment of a previously undocument…
97
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 11 fuentes 📊 datos Fri, 28 Aug 2026 15:15:15
cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & W…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 6 fuentes 📊 datos Fri, 28 Aug 2026 16:28:29
VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLANTE…
90
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 4 fuentes 📊 datos Fri, 28 Aug 2026 16:50:32
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provide…
63
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Fri, 28 Aug 2026 17:00:00
An Identity Fabric knits fragmented identity systems into a coherent layer that observes how identities behave across applications, APIs, and infrastructure. As enterprise access spans more cloud services and automated workloads, identity security depends less on static configuration and more on run…
89
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 4 fuentes 📊 datos Fri, 28 Aug 2026 17:37:24
Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the…
94
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 7 fuentes 📊 datos Fri, 28 Aug 2026 20:57:26
Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities. The extensions, per Socket security researcher Karlo Zanki, share sim…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 7 fuentes 📊 datos Fri, 28 Aug 2026 21:26:55
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in…
71
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Fri, 28 Aug 2026 21:50:46
Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks. Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks fro…
74
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 3 fuentes Fri, 28 Aug 2026 22:42:15
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's trust…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 6 fuentes 📊 datos Sat, 29 Aug 2026 02:08:47
Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE i…
98
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 8 fuentes 📎 bien sourced Sat, 29 Aug 2026 03:00:52
Berlin's state government has confirmed that it is the target of an extortion attempt following the August compromise of the city's state administrative network, and said it will not meet the extortionists' demands. The same statement disclosed that forensic work had found further data outflows in …
95
fiabilidad
BleepingComputer RELIABLE 8.0 ciberseguridad ✓ 12 fuentes Fri, 28 Aug 2026 14:18:55
A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. [...]
agrupados por: commands · execute · flaw
78
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 2 fuentes 📊 datos Thu, 27 Aug 2026 20:42:16
A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing the…
agrupados por: systems · water
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 9 fuentes Thu, 20 Aug 2026 22:29:44
The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens S7 SeriesProgrammable Logic Controllers (PLCs) to conduct reconnaissance and c…
agrupados por: plcs · siemens · target
97
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 41 fuentes Tue, 25 Aug 2026 23:47:17
The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an "unprecedented, whole-of-government, economic campaign" against the nation and its enablers. "We are launching an economic onslaught against Iran's financial connections around the…
agrupados por: hackers · linked
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 6 fuentes Wed, 26 Aug 2026 11:17:28
Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple's Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask for their device passcode. SOCRadar Threat Research Unit (STR…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 9 fuentes 📊 datos Wed, 26 Aug 2026 11:57:07
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS score: 9.8), a case of remote code execution that allows an at…
79
fiabilidad
The Register RELIABLE 7.5 tecnología ✓ 2 fuentes 📊 datos Mon, 24 Aug 2026 23:39:39
Its own command language, 23 instructions - signs point to 'well-resourced operation rather than an opportunistic one'
agrupados por: backdoor · sleepwalker
97
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 8 fuentes 📊 datos Wed, 26 Aug 2026 13:24:12
An eight-month INTERPOL operation targeting West African organized crime groups has led to arrests of 58 people and the identification of 263 suspects. "The operation, which brought together 22 countries from six continents, is a response to the escalating global threat posed by West African crimin…
agrupados por: arrests · crackdown
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 10 fuentes Wed, 26 Aug 2026 15:08:45
OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook an…
85
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 3 fuentes 📊 datos Wed, 26 Aug 2026 15:57:23
Aikido Security has published research that recreates the Australian gym-booking incident in a synthetic environment, finding that Claude Opus 4.6, running on the OpenClaw agent harness, exploited a client-side-only booking restriction in 9 of 10 runs. The original incident was first reported by AB…
54
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Wed, 26 Aug 2026 17:06:49
The SOC we've always known was built around a model that guarantees most of the alert queue will never receive analyst review. There's never time. In a traditional SOC, the typical progression follows a well-known pattern: an alert arrives; a detection engine assigns a severity score. The issue then…
84
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 3 fuentes 📊 datos Wed, 26 Aug 2026 17:25:00
The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem f…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 8 fuentes Wed, 26 Aug 2026 18:37:02
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has published the results of two red team assessments it conducted simultaneously against two critical infrastructure organizations, using what it described as similar tradecraft while recording sharply different defensive outcomes. B…
agrupados por: critical · infrastructure
83
fiabilidad
Dark Reading RELIABLE 8.0 ciberseguridad ✓ 2 fuentes 📊 datos Wed, 26 Aug 2026 11:33:40
The adversary-in-the-middle (AitM) phishing service lowers the barrier to entry for actors to create attacks and steal more than just user credentials.
agrupados por: microsoft · novacookies · sessions
59
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Wed, 26 Aug 2026 21:05:05
Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 11 fuentes Wed, 26 Aug 2026 22:12:03
The U.S. Department of Justice (DoJ) on Wednesday announced the disruption of two hacking platforms named QScan and QTRouter operated by Chinese threat actors to target critical infrastructure and other sensitive networks in the country. The activity has been attributed to a Chinese state-sponsored…
92
fiabilidad
BleepingComputer RELIABLE 8.0 ciberseguridad ✓ 5 fuentes Wed, 26 Aug 2026 14:48:24
A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation. [...]
agrupados por: access · defeats · gputhor · nvidia · root
67
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Thu, 27 Aug 2026 15:03:38
Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell access and payload…
82
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 2 fuentes Thu, 27 Aug 2026 16:30:57
Individuals and organizations in Cambodia have emerged as the target of a new campaign that delivers an open-source remote access trojan (RAT) called Spark RAT. "The samples employ diverse lure themes, suggesting an effort to appeal to a broad range of potential victims. These include government no…
98
fiabilidad
War on the Rocks RELIABLE 8.0 defensa ✓ 18 fuentes 📎 bien sourced 📊 datos Tue, 18 Aug 2026 07:00:57
On June 26, 2026, the Civil Police of Rio de Janeiro, through its specialized firearms, ammunition, and explosives unit, raided a clandestine workshop in Rio das Pedras, on the city’s west side. Investigators said the group used a 3D printer seized at the scene to produce pistol frames and structura…
agrupados por: chain · supply · hackers · alleged · australia · teampcp
86
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 4 fuentes Thu, 27 Aug 2026 17:26:30
Security teams have spent years trying to detect threats faster. AI is changing the harder part: how much time defenders have left to act. Advanced AI models can now help attackers discover vulnerabilities, generate exploit code, and move through weaknesses faster than traditional security processe…
agrupados por: build · learn
87
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 4 fuentes 📊 datos Thu, 27 Aug 2026 19:09:56
Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE i…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 6 fuentes 📊 datos Thu, 27 Aug 2026 20:43:00
Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting server…
82
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 2 fuentes Mon, 24 Aug 2026 23:11:11
Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts to access malicious sites, adding that it found lookalike g…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 20 fuentes 📊 datos Tue, 25 Aug 2026 11:42:35
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2…
96
fiabilidad
BleepingComputer RELIABLE 8.0 ciberseguridad ✓ 11 fuentes 📊 datos Mon, 24 Aug 2026 15:26:32
Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. [...]
agrupados por: miniorange · target · wordpress
61
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Tue, 25 Aug 2026 16:44:07
Vulnerability management has been a staple of security programs since the dawn of the cybersecurity discipline. The symbiotic relationship between vulnerability and patch management teams has also existed for that time and has gone through waves of contention and thankfulness. While this relationshi…
65
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Tue, 25 Aug 2026 17:03:44
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE. While threat actors are known to abuse legitimate services to point to additional …
66
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Tue, 25 Aug 2026 17:22:43
Cybersecurity researchers have disclosed details of a new campaign that uses a cluster of 24 npm packages as free phishing infrastructure for redirecting to ClickFix-style fake CAPTCHA pages. "While the malware is simply a single HTML page inside the npm package, and while downloading it wouldn't d…
74
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Tue, 25 Aug 2026 17:26:15
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor authentication. According to ANY.RUN research, 48% of targeted email addresse…
90
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 4 fuentes 📊 datos Tue, 25 Aug 2026 18:49:41
Meta on Tuesday announced a set of WhatsApp account security features, including support for multiple passkeys to a single account to help users with both iOS and Android devices sign into their accounts using the phishing-resistant method. The tech giant said more than 1 billion people use a passk…
agrupados por: adds · multiple · passkeys · whatsapp
80
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 3 fuentes Tue, 25 Aug 2026 19:37:37
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself. The findings were shared with The Hacker News ahead of public…
agrupados por: behind · model
78
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 3 fuentes 📊 datos Mon, 24 Aug 2026 17:00:00
Big security risks come in small packages. While enterprise security teams focus on policing the proliferation of employees using ChatGPT and Claude for quick drafting tasks, a more urgent threat is posed by a handful of AI super-adopters who are quietly hardcoding unvetted tools into critical busin…
72
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Mon, 24 Aug 2026 17:21:36
Cybersecurity researchers have flagged a cyber espionage campaign targeting Myanmar that uses graduation ceremony invitation lures to deliver a Go backdoor called QUICAgent. The campaign, codenamed Operation QUICSILVER, has been found to target government and information technology sectors, per Seq…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 6 fuentes 📊 datos Mon, 24 Aug 2026 17:26:34
Red Hat and the Keycloak project have released patches to address a critical security flaw in the open-source identity and access management server that could allow an unauthenticated remote attacker to take over any user account by forcing a password reset. The vulnerability, assigned the CVE iden…
80
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 3 fuentes Mon, 24 Aug 2026 17:28:00
If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at a pace your security team was never built to handle. More …
61
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Mon, 24 Aug 2026 18:05:36
Cybersecurity researchers have flagged two new malware families called WordlistLoader and SynkLoader that's used to deliver next-stage payloads and likely sell access to ransomware groups. According to findings from Gen Digital, WordlistLoader is being used to deliver Amatera Stealer (aka ACR Stea…
71
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Mon, 24 Aug 2026 20:02:10
A package gets installed. A login prompt opens. A box sits exposed to the internet. Nothing looks unusual yet. That’s roughly the mood this week. Trusted tools turn hostile, old weak spots get fresh attention, AI makes exploit work cheaper, and researchers keep finding attacks that sound harder tha…
68
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Mon, 24 Aug 2026 13:38:31
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors. The vast majority of the targets are located in Brazil, Bolivia, China, Canad…
99
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 14 fuentes 📎 bien sourced 📊 datos Fri, 21 Aug 2026 11:36:11
Update: The story was updated after publication to note that the vulnerability has not been exploited. Although the security bulletin originally marked the "Exploited" field under the Exploitability Assessment table as "Yes," on August 21, 2026, Microsoft corrected the "Exploited" status to "No" af…
agrupados por: microsoft · entra · patches · code · execution · flaw
85
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 2 fuentes 📊 datos Thu, 20 Aug 2026 19:18:24
Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the isolated environment. The vulnerability ("GHSA-864f-rcv7-6rh4"), which has yet…
agrupados por: host · isolated
94
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 12 fuentes Fri, 21 Aug 2026 01:29:19
Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think tanks across Europe, as well as academia and think tanks within the U.S. These …
agrupados por: abuse · oauth
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 17 fuentes 📊 datos Fri, 21 Aug 2026 01:52:35
The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded and executed a remote payload during compilation. The affected releases are ar…
agrupados por: chain · rust · supply
86
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 4 fuentes Thu, 20 Aug 2026 17:31:24
Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) terminal reads over near-field communication (NFC), without breaking any of the car…
agrupados por: card · contactless · expired · payments · visa
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 7 fuentes Wed, 19 Aug 2026 16:55:28
Cybersecurity researchers have flagged a global cybercrime operation that abuses thousands of hacked WordPress websites as infrastructure to disseminate malware, commandeer infected hosts, store stolen documents, screenshots, and activity logs created to track the status of the activity. "The opera…
76
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 2 fuentes 📊 datos Wed, 19 Aug 2026 17:00:00
Most email defenses still do the job they did a decade ago. Scan the message, look for something malicious, block it. That worked when the danger sat in the payload, a bad link or an attachment. It stopped working when the danger moved into the message's intent, and it is failing now that the sender…
86
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 3 fuentes 📊 datos Wed, 19 Aug 2026 17:04:28
Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. The activity, codenamed Operatio…
84
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 3 fuentes Wed, 19 Aug 2026 18:42:17
A previously unreported cyber espionage operation dubbed SilkParasite has been observed targeting government bodies in Central Asia. The intrusion set makes use of seven remote access tool (RAT) families, five of which have never been previously documented: DriveSilkRAT, CookiETagRAT, NomadRAT, Gog…
agrupados por: asian · central · rats · silkparasite
76
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Wed, 19 Aug 2026 23:36:44
OpenAI on Tuesday revealed that it paused reinforcement learning (RL) training for its latest artificial intelligence (AI) models for two weeks while it shored up additional defenses and increased the scope of its monitoring to avert another Hugging Face-like incident. "As models become more capabl…
83
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 3 fuentes 📊 datos Thu, 20 Aug 2026 00:32:40
Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021. The end-to-end …
90
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 5 fuentes 📊 datos Thu, 20 Aug 2026 11:34:34
Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475, carries a CVSS score of 9.0 out of 10.0. It has been described as a case of u…
74
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 2 fuentes 📊 datos Thu, 20 Aug 2026 14:12:03
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the extensions are part of a broader set of 77 browser add-ons that share source code…
86
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Thu, 20 Aug 2026 16:08:28
Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally. Zimperium zLabs, in a Wednesday report, said the Android malware also features…
64
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Thu, 20 Aug 2026 16:35:11
Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary commands to the software's spacecraft and instrument command bus. The chain, t…
93
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 5 fuentes Thu, 20 Aug 2026 16:56:08
A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fintech and cryptocurrency services, and military-focused communications. "Manic si…
80
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Thu, 20 Aug 2026 17:09:35
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a low-bandwidth request stream by up to 350x against the origin serv…
82
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 3 fuentes 📊 datos Thu, 20 Aug 2026 17:15:00
In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it.  The incident began when a Meta employee posted a technical question on an internal forum. An engineer used an approved AI age…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 11 fuentes 📊 datos Thu, 20 Aug 2026 18:54:28
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection tha…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 7 fuentes Thu, 20 Aug 2026 19:05:13
Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and virtualization technology company, the issues affect customer-managed NetScale…
97
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 7 fuentes Thu, 20 Aug 2026 20:06:27
Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controlled server after the user asks it to summarize an ordinary web page. The AI secu…
66
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Thu, 20 Aug 2026 22:53:48
A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to code execution. Elsewhere, exposed systems, old bugs, odd hiding tricks, and AI-…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 11 fuentes 📊 datos Fri, 21 Aug 2026 12:34:25
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated attacker to modify or delete publicly acc…
86
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 4 fuentes Fri, 21 Aug 2026 15:33:11
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review. Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardl…
61
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Fri, 21 Aug 2026 16:51:39
Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover patterns hidden within large datasets, and support faster decision-making. Cyber…
84
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 3 fuentes Fri, 21 Aug 2026 21:11:44
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said the end goal of the malware is to serve a multi-stage downloader to enable ad fra…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 7 fuentes 📊 datos Fri, 21 Aug 2026 21:22:10
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging from Windows 7 through Windows 11 25H2, with no software flaw exploited and no …
74
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Sat, 22 Aug 2026 00:23:00
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux implant dubbed RedC2 4.0. "When the module loads, it locates the bundled binary,…
88
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 4 fuentes 📊 datos Sat, 22 Aug 2026 20:02:41
The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the settlement, the social media platform will pay $300 million immediately, and an add…
68
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Mon, 10 Aug 2026 18:49:58
North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting document-search tools to files in its possession, and collecting the software parts…
97
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 11 fuentes Mon, 10 Aug 2026 20:30:29
A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are back, supply chains are getting stranger, and some exploit paths are so short …
93
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 10 fuentes Mon, 10 Aug 2026 22:08:37
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's previous use of Medusa ransomware, the Microsoft Threat Intelli…
73
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Mon, 10 Aug 2026 22:59:17
AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jumps 10 to 50 times, the problem is no longer just finding vulnerabilities. It is…
97
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 11 fuentes Tue, 11 Aug 2026 11:18:44
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike traditional software supply chain attacks, zero source code files wer…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 10 fuentes 📊 datos Tue, 11 Aug 2026 12:25:45
Attackers shut down a steam turbine and the process-water treatment system at a Polish combined heat and power plant by coming in over the private cellular network the local grid operator uses to reach remote equipment. The plant supplies heat to roughly 50,000 residents. Recovery began at about 7:…
83
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 3 fuentes Tue, 11 Aug 2026 14:46:24
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public health, financial services, government services and facilitie…
94
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 9 fuentes Tue, 11 Aug 2026 15:54:00
A malicious tool server connected to an AI coding assistant can quietly walk off with SSH keys, environment secrets, source code, and customer data without ever sending one obviously harmful instruction. The trick can work even after a blunt version of the same theft is refused: split the request i…
70
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Tue, 11 Aug 2026 16:18:26
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP path can be triggered over Remote Desktop without physical hard…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 9 fuentes Tue, 11 Aug 2026 17:05:03
Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in P…
73
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 2 fuentes Tue, 11 Aug 2026 17:34:51
Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories. That key is how a user, or a Linux distribution packaging the browser, confirms a downloaded …
61
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Tue, 11 Aug 2026 17:35:03
A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole device over. Researchers at the University of Birmingham and …
85
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 2 fuentes 📊 datos Tue, 11 Aug 2026 18:41:23
OpenAI on Monday unveiled a new cybersecurity-focused model called GPT‑5.6‑Cyber that it said is focused on vulnerability research, penetration testing, and incident response. "Built on GPT‑5.6 Sol, it is trained to improve capabilities on several specialized cybersecurity tasks (e.g., finding zero…
73
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Tue, 11 Aug 2026 22:05:27
The ransomware group known as DeadLock has been observed using decentralized infrastructure to facilitate victim communications and data leak operations in a bid to improve operational resilience. "Its recovery ecosystem combines the Session messaging network with blockchain-backed services that st…
80
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 2 fuentes 📊 datos Tue, 11 Aug 2026 22:17:44
Security researchers found a way to enter Microsoft SharePoint servers as any user, including an administrator, with no valid account. A significant part of the work that found it was done through an AI agent. The flaw, tracked as CVE-2026-55040 (CVSS 9.1), affects SharePoint Server Subscription Ed…
56
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Wed, 12 Aug 2026 00:06:47
The Computer Emergency Response Team of Ukraine (CERT-UA) has disclosed details of a new social engineering campaign orchestrated by Russian nation-state threat actors targeting IT workers in the country by masquerading as recruiters to trick them into installing malware. CERT-UA pinned the activit…
49
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Wed, 12 Aug 2026 00:38:47
Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter's. The flaw sat in the annotation tool, the feature that lets participants draw and type on a shared screen, and it asked nothing of the victi…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 7 fuentes 📊 datos Wed, 12 Aug 2026 01:06:37
Cybersecurity researchers have discovered a new version of the Kimwolf/AISURU Android and Internet of Things (IoT) botnet that comes with significant improvements to improve its operational resilience and conduct distributed denial-of-service (DDoS) attacks. The new version, tracked as Kimwolf v7, …
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 31 fuentes 📊 datos Wed, 12 Aug 2026 01:40:55
Microsoft released its monthly security updates on Tuesday, and one of the flaws it closed is already being used in attacks. The bug sits in a core Windows kernel driver that handles network socket operations. An attacker with code already running on a machine can use it to escalate to SYSTEM. That…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 9 fuentes 📊 datos Wed, 12 Aug 2026 11:45:58
Cisco has warned that a new vulnerability impacting Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software has been exploited in the wild. The high-severity flaw, tracked as CVE-2026-20349 (CVSS score: 8.6), is a case of insufficient error check…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 10 fuentes 📊 datos Wed, 12 Aug 2026 12:11:38
The security researcher going by the name Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has released a proof-of-concept (PoC) for a new Microsoft zero-day called ShieldBreak. The vulnerability, rooted in Microsoft Defender for Windows, demonstrates a patch bypass for …
99
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 10 fuentes 📎 bien sourced 📊 datos Wed, 12 Aug 2026 13:01:40
SAP has released patches to address a maximum-severity security flaw impacting Commerce Cloud (Data Hub Adapter) that could result in arbitrary code execution. The vulnerability, assigned the CVE identifier CVE-2026-58231, is rated 10.0 on the CVSS scoring system. It has been described as a case of…
62
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Wed, 12 Aug 2026 13:34:52
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it o…
94
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 6 fuentes 📊 datos Wed, 12 Aug 2026 14:31:54
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO. The vulnerability in question is CVE-2026-59310 (CVSS score: 9.8), a directory-traversal vulnerability in the VMware vCenter server that a malici…
89
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 4 fuentes 📊 datos Wed, 12 Aug 2026 16:43:03
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The most severe of the flaws are listed below - CVE-2026-48362…
74
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Wed, 12 Aug 2026 17:11:34
Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none. According to Picus Labs' new Blue Report 2026, which measured more than 338 million real attack simulations across actual client production environments in the first half of …
93
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 27 fuentes Wed, 12 Aug 2026 17:17:38
A newly disclosed flaw in the way OpenAI, Anthropic, and Google carried hidden AI reasoning between API calls let researchers recover internal reasoning and secrets from session logs, including API keys and passwords. The weakness affected encrypted reasoning objects used by the providers' reasonin…
68
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Wed, 12 Aug 2026 19:39:50
A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extensions, published across at least 40 Chrome Web Store develop…
93
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 6 fuentes Wed, 12 Aug 2026 23:09:27
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace companies across France, Germany, Brazil, and India. The activit…
76
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 2 fuentes 📊 datos Thu, 13 Aug 2026 11:39:48
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical security feature bypass that stems from weak authentication.…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 13 fuentes 📊 datos Fri, 10 Jul 2026 13:40:12
A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S. for their role in conspiring with the now-defunct BlackCat ransomware operators to extort multiple victims and working with two other cybersecurity professionals to target additi…
87
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 4 fuentes 📊 datos Fri, 10 Jul 2026 14:30:05
Security firm Coinspect has disclosed a crypto wallet flaw it calls Ill Bloom, and attackers are already using it. The flaw is in how some wallet software generated its recovery phrase, the words that control the money. When that phrase is made with weak randomness, an attacker can work it out and t…
88
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 5 fuentes 📊 datos Fri, 10 Jul 2026 16:00:20
A threat actor has been targeting organizations spanning multiple sectors with voice-based fake security requests that prompt Microsoft 365 users to enroll a new Entra passkey with an aim to carry out data extortion attacks. The threat actor, tracked by Okta under the moniker O-UNC-066, has deploye…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 13 fuentes 📊 datos Fri, 10 Jul 2026 16:26:23
Researchers ran 281 of the most popular free VPN apps on the Google Play Store through a new testing system and found that many fail at the basics people install a VPN for, i.e., keeping their traffic private and secure. The apps flagged with at least one problem have been installed more than 2.4 b…
70
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Fri, 10 Jul 2026 17:00:02
A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operation's inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million websites. Far fewer were actually broken into, but the exposed files showed res…
68
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Fri, 10 Jul 2026 17:09:40
Most enterprises assume their asset inventory is close enough to accurate. The evidence suggests otherwise. According to a survey of over 600 security leaders in the 2026 Axonius Actionability Report, only 45% of organizations consolidate their asset and exposure data into a single view, and every d…
72
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Fri, 10 Jul 2026 17:17:43
A single wrong variable on one line in XQUIC, Alibaba's QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. He says it needs no login …
67
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Fri, 10 Jul 2026 18:45:23
The China-linked cybercrime group known as Silver Fox has been attributed to a new Rust-based remote access trojan (RAR) called MODBEACON. Chinese cybersecurity company QiAnXin said that while the threat cluster may appear like a low-sophistication, high-activity operation that propagates malware v…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 9 fuentes Fri, 10 Jul 2026 19:49:50
Details have emerged about three now-patched security flaws in the OpenClaw personal artificial intelligence (AI) assistant that, if successfully exploited, could enable credential theft, privilege escalation, and arbitrary code execution on the host. A brief description of the high-severity vulner…
60
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Fri, 10 Jul 2026 20:21:49
Researchers at Ledger's Donjon security team have shown that a precisely timed laser pulse, aimed at the chip inside a Tangem crypto wallet card, can reset the card's password to anything the attacker picks. No old password. No backup card. Once it is reset, whoever did it controls the wallet and c…
80
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 3 fuentes Fri, 10 Jul 2026 21:27:14
Researchers at firmware security firm Binarly have found six new flaws in U-Boot, the small program that starts up hardware as varied as home routers, smart cameras, and the management chips inside data-center servers. Four of the bugs can crash a device. The other two could let an attacker who sli…
81
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 2 fuentes 📊 datos Fri, 10 Jul 2026 21:59:00
Unknown threat actors compromised the Injective Labs SDK project's GitHub repository and leveraged it to publish a malicious package on the npm registry to steal cryptocurrency wallet private keys and mnemonic seed phrases. The compromised version, @injectivelabs/sdk-ts@1.20.21, came embedded with …
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 12 fuentes 📎 bien sourced Fri, 10 Jul 2026 22:00:00
Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The Hacker News that it is responding to a "credible external security threat." The company has temporarily disabled access to the affected accounts, a step it says …
94
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 6 fuentes Sat, 11 Jul 2026 12:15:55
Zimbra is urging customers to apply updates to address a critical security vulnerability impacting the Classic Web Client that could result in arbitrary code execution. The vulnerability has been described as a case of stored cross-site scripting (XSS) that could allow specially crafted emails to e…
93
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 5 fuentes 📊 datos Sat, 11 Jul 2026 23:19:31
Cybersecurity researchers have disclosed details of sustained cyber espionage activity against several Pakistani law enforcement organizations undertaken by suspected China- and India-aligned threat actors between February 2024 and April 2026. "At Balochistan Police, the compromised assets included…
74
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad 📊 datos Sat, 11 Jul 2026 23:29:26
The jscrambler npm package was compromised, and simply installing its 8.14.0 release runs an infostealer on your machine. Published on July 11, 2026, the malicious version carries a preinstall hook that drops and executes a native binary, one build each for Windows, macOS, and Linux. Socket flagged…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 14 fuentes Tue, 07 Jul 2026 17:00:00
Software supply chain security was hard enough. Then AI joined the build pipeline. For five years, "software supply chain security" meant one question: what's in your code? Which open-source packages, which versions, which transitive dependencies three layers deep that nobody chose on purpose? So…
68
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Tue, 07 Jul 2026 18:57:09
Cybersecurity researchers have disclosed details of a now-patched critical session isolation vulnerability in Writer, an enterprise generative artificial intelligence (AI) platform, that could result in cross-tenant compromise. The one-click vulnerability has been codenamed WriteOut by the Sand Sec…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 7 fuentes 📊 datos Tue, 07 Jul 2026 18:57:20
U.S. prosecutors linked an alleged Scattered Spider hacker to a break-in at a luxury jewelry retailer using a persistent Windows device ID, according to a newly unsealed federal complaint. Microsoft records tied that ID first to the account the attackers used to keep access during the May 2025 intr…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 9 fuentes Tue, 07 Jul 2026 19:34:50
A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization's private repositories, researchers at Noma Security have shown. The attacker needs only to open a normal-looking issue on a public repository, with no stolen credentials and no access to the organization…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 7 fuentes 📊 datos Tue, 07 Jul 2026 20:44:14
A Microsoft 365 device code phishing campaign has been observed leveraging collaboration-themed lures to take control of victim accounts between the last week of June 2026 and into early July, per findings from ZeroBEC. "The campaign did not depend on a fake Microsoft password page. It used a malic…
92
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 6 fuentes Tue, 07 Jul 2026 22:07:33
A critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project. From there, they could read live conversations, steal the data users shared, and make the bots send atta…
81
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 3 fuentes Tue, 07 Jul 2026 22:40:15
A new Android malware operation called RedWing is being rented out on Telegram as a ready-made bank-fraud service. It lets even low-skill criminals take over a victim's phone, steal their banking logins, and capture the one-time codes that protect their accounts. Zimperium's zLabs, which found the …
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 8 fuentes 📊 datos Wed, 08 Jul 2026 11:03:12
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four security flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2026-48282 (CVSS score: 10.0) - A path traversal vulnera…
93
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 5 fuentes 📊 datos Wed, 08 Jul 2026 11:46:44
Researchers at Nebula Security have disclosed GhostLock (CVE-2026-43499), a 15-year-old Linux kernel flaw that lets any logged-in user take full root control of a machine that has not been patched. The vulnerable code has shipped by default in essentially every mainstream distribution since 2011. T…
70
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 4 fuentes 📊 datos Wed, 08 Jul 2026 14:34:33
A Chinese threat actor tracked as UAT-7810 is actively refining its bespoke malware to expand its Operational Relay Box (ORB) network by breaking into internet-facing networking devices. According to findings from Cisco Talos, UAT-7810 is an advanced persistent threat (APT) actor that's responsible…
88
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 5 fuentes Wed, 08 Jul 2026 16:51:07
An AI coding assistant that refuses to answer a dangerous request in its chat box can answer it anyway if the same request is broken into small, ordinary-looking steps inside a code editor. That is the finding of a new study of GitHub Copilot by researchers Abhishek Kumar and Carsten Maple. The mod…
76
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Wed, 08 Jul 2026 17:00:00
For years, account takeover (ATO) followed a predictable script. Attackers bought stolen credentials in bulk, ran them through automated tools, and waited for matches. Credential stuffing was cheap, scalable, and for defenders, relatively well understood. That era is ending. Not because attackers g…
52
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad Wed, 08 Jul 2026 17:21:24
New research shows that a signed Git commit's hash is not the one-of-a-kind name that much of the software world assumes it to be. Given any signed commit, someone without the signing key can mint a second commit with the same files, author, and date, and a valid signature, GitHub still stamps "Veri…
86
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 4 fuentes Wed, 08 Jul 2026 18:22:15
A new banking fraudulent operation is targeting customers of Mexican banks, fintech, payment processors, and cryptocurrency exchanges using ClickFix lures. The activity cluster, tracked by Elastic Security Labs under the moniker REF6045, involves infecting victims through fake CAPTCHA verification …
82
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 4 fuentes Wed, 08 Jul 2026 18:30:00
A recent EvilTokens campaign targeting businesses across the US and Europe is exposing a new email security blind spot. This “ghost phishing” technique keeps the malicious page hidden until it decrypts and comes to life inside the victim’s browser. For security leaders, the risk is clear: tradition…
96
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 8 fuentes 📊 datos Wed, 08 Jul 2026 20:08:05
Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution. The list of vulnerabilities is as follows - CVE-2026-50746 (CVSS sco…
91
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 4 fuentes Wed, 08 Jul 2026 20:37:24
AI coding assistants have a habit of making things up. Ask one to fetch a popular tool, and it will sometimes hand back a real-sounding name for a project that does not exist. New research, which its authors call HalluSquatting, turns that habit into an attack: work out the fake names an AI reliabl…
94
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 6 fuentes Wed, 08 Jul 2026 22:32:12
Sophos looked at a week of its own endpoint data and found that AI coding agents such as Claude Code, Cursor, and OpenAI Codex are setting off detection rules written to catch human intruders. The agents are not malicious. They just do a lot of things that, to a behavioral engine, look exactly like…
73
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 2 fuentes 📊 datos Thu, 09 Jul 2026 09:31:49
Cybersecurity researchers have disclosed details of a new threat actor dubbed Lurking Lizard that has been operating an end-to-end malicious residential proxy business using an infrastructure comprising more than 230 lookalike domains. The activity dates back to at least August 2022, according to D…
95
fiabilidad
The Hacker News RELIABLE 7.5 ciberseguridad ✓ 8 fuentes Thu, 09 Jul 2026 09:57:18
Researchers at Wiz found that a flaw in six popular AI coding assistants lets a booby-trapped code project quietly take control of a developer's computer. The assistant asks permission to edit one harmless-looking file, but the write lands on a sensitive one instead. The affected tools are Amazon Q…
⚡ Procesando...