Ciberseguridad desde Málaga · Redes, anzuelos y amenazas

Noticias de ciberseguridad · semana del 21 al 27 sept 2026

Lo más relevante de la actualidad en ciberseguridad, con enlace a la fuente original.

  1. 2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway

    On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE)…

    Fuente: CERT-EU ↗
  2. Citrix admins warned to shut down NetScalers over 2 exploited zero-days

    Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches…

    Fuente: BleepingComputer ↗
  3. [Virtual Event] Cybersecurity Outlook 2027

    Fuente: Dark Reading ↗
  4. Cloudflare fixes Containers cross-tenant flaw exposing customer data

    Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host. [...]

    Fuente: BleepingComputer ↗
  5. Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors

    Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more. [...]

    Fuente: BleepingComputer ↗
  6. ● Explotada activamente

    Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

    CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.

    Fuente: SecurityWeek ↗
  7. Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation

    Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26. Citrix has not…

    Fuente: The Hacker News ↗
  8. ● Explotada activamente

    Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells

    Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273…

    Fuente: The Hacker News ↗ También en: BleepingComputer
  9. Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials

    The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue,…

    Fuente: The Hacker News ↗
  10. China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks

    The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents.

    Fuente: SecurityWeek ↗
  11. Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer

    Anthropic's Claude Opus 5.5 appears to be changing how it writes, with new analysis showing fewer obvious AI writing patterns, shorter sentences, and simpler wording compared with Opus 5. [...]

    Fuente: BleepingComputer ↗
  12. Microsoft pauses KB5002907 update after Office license deactivations

    Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. [...]

    Fuente: BleepingComputer ↗
  13. GitHub Actions re-enabled with Mini Shai-Hulud payload still active

    Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. [...]

    Fuente: BleepingComputer ↗
  14. El ciberataque a Renfe y Adif confirma lo que la IA llevaba meses avisando. 500GB de datos de clientes quedan al descubierto

    Algo pasaba cuando la web de Adif mostraba un tierno gatito negro y ya lo sabemos: Adif y Renfe han sufrido un ciberataque en el que se han filtrado 500 GB de información privada de sus clientes, como ha adelantado El Mundo. El incidente…

    Fuente: Xataka ↗
  15. OpenAI's AI agents accidentally uploaded user-provided images to third-party sites

    OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. [...]

    Fuente: BleepingComputer ↗
  16. New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining

    The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions.

    Fuente: SecurityWeek ↗
  17. Zero Trust for AI Agents Starts With Fixing Zero Visibility

    The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could…

    Fuente: The Hacker News ↗
  18. OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure

    OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.”

    Fuente: SecurityWeek ↗
  19. Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link

    Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The…

    Fuente: The Hacker News ↗
  20. SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active…

    Fuente: The Hacker News ↗
  21. Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack

    Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks received credible…

    Fuente: The Hacker News ↗
  22. U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

    A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today…

    Fuente: KrebsOnSecurity ↗
  23. Kiteworks urges 6-hour server shutdown over potential zero-day attacks

    Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. [...]

    Fuente: BleepingComputer ↗
  24. ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

    The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path…

    Fuente: BleepingComputer ↗
  25. How the CISO CFO Relationship is a Key to Cybersecurity Success

    Building a financial bridge: Organizations where CISOs and CFOs align on cybersecurity strategy to protect assets, manage risk and enable business growth are better prepared to face today's threat landscape.

    Fuente: Dark Reading ↗
  26. AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment

    When autonomous AI agents "escape the sandbox," the real story isn't rogue machines — it's the same access-control failures we've seen for decades.

    Fuente: Dark Reading ↗
  27. Elementor WordPress flaw lets attackers create admin accounts

    A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...]

    Fuente: BleepingComputer ↗
  28. What We Missed: Google Gemini Joins the AI Escape Party

    In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from Google Gemini models breaking containment to ShinyHunters ratting on TeamPCP hackers.

    Fuente: Dark Reading ↗
  29. WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of…

    Fuente: The Hacker News ↗ También en: BleepingComputer
  30. Vibe coding y seguridad: 5 preguntas para evaluar los riesgos de una app

    Las aplicaciones desarrolladas mediante vibe coding pueden contener errores difíciles de detectar. Estas claves te ayudarán a evaluar sus riesgos de seguridad y privacidad

    Fuente: WeLiveSecurity ↗
  31. Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions

    Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it's offering up to $250 in free usage credits, so more users can give it a try. [...]

    Fuente: BleepingComputer ↗
  32. In Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure

    Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul.

    Fuente: SecurityWeek ↗
  33. OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex

    OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it's unclear when it'll begin rolling out. [...]

    Fuente: BleepingComputer ↗
  34. With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance

    AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent…

    Fuente: BleepingComputer ↗
  35. Stopping IT Worker Scams Requires Revamped HR Process

    Training human-resource managers in the latest tactics and warning signs goes a long way toward blunting the threat, but automated analysis can help even more.

    Fuente: Dark Reading ↗
  36. Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

    Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are…

    Fuente: The Hacker News ↗
  37. Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

    Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving…

    Fuente: The Hacker News ↗ También en: SecurityWeek
  38. PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

    Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same…

    Fuente: The Hacker News ↗
  39. Microsoft plans to deprecate Windows Deployment Services

    Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. [...]

    Fuente: BleepingComputer ↗
  40. CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks

    Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July.

    Fuente: SecurityWeek ↗
  41. Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court

    Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services.

    Fuente: SecurityWeek ↗
  42. The SOC Doesn't Need to Start Over with Every Alert

    Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry. The routine version looks like this. An attacker…

    Fuente: The Hacker News ↗
  43. Windows, Linux, Android File Notification Systems Leak User Activity

    Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events.

    Fuente: SecurityWeek ↗
  44. Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

    The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL…

    Fuente: The Hacker News ↗
  45. ‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration

    Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks.

    Fuente: SecurityWeek ↗
  46. Russia's Hybrid Cyber-Physical War in Europe Heats Up

    A storm is raging in the form of cyber sabotage, disinformation, and drone attacks on European nations, particularly those that provide material support to Ukraine.

    Fuente: Dark Reading ↗
  47. Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

    A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk space that earlier…

    Fuente: The Hacker News ↗
  48. 'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing

    Agentic AI can smuggle arbitrary instructions from the Web, across multiple apps, into trusted internal communications channels.

    Fuente: Dark Reading ↗
  49. SectopRAT Returns, Hiding Inside a Legitimate Application

    The latest activity from the remote access Trojan (RAT) shows why organizations should monitor the behavior of applications rather than blindly trusting them, experts say.

    Fuente: Dark Reading ↗
  50. Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

    A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the…

    Fuente: The Hacker News ↗
  51. ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

    This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pile. Trusted paths…

    Fuente: The Hacker News ↗
  52. Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content

    The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a generic…

    Fuente: The Hacker News ↗
  53. La presión sobre la ciberseguridad de las PyMEs: agentes de IA en expansión, amenazas tradicionales en aceleración

    A medida que la inteligencia artificial abre nuevas vías de acceso a los sistemas empresariales y acelera amenazas ya conocidas, las PyMEs necesitan una protección que se adapte a sus recursos, tiempo y capacidades técnicas.

    Fuente: WeLiveSecurity ↗
  54. 3 Cyber Threats That Defined the Summer of 2026

    This installment of the Reporters' Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife's ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer.

    Fuente: Dark Reading ↗
  55. Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer

    An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called…

    Fuente: The Hacker News ↗
  56. How to Build a SASE Framework for Modern Cybersecurity

    Securing edge computing requires organizations to fundamentally rethink security governance. This step-by-step guide to building a SASE framework provides the path forward. (Third in a three-part series.)

    Fuente: Dark Reading ↗
  57. Ghost Service Accounts Enable M365 Data Theft in Chile

    Even if the organization locks down employee accounts, forgotten and lost service accounts can still undo the organization's entire M365 environment.

    Fuente: Dark Reading ↗
  58. Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'

    AI apps that interpret external data (read: most AI apps) need exceptionally rigorous security filters, or attackers can take advantage.

    Fuente: Dark Reading ↗
  59. Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

    The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW…

    Fuente: The Hacker News ↗
  60. Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

    AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are…

    Fuente: The Hacker News ↗
  61. 17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

    ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a…

    Fuente: The Hacker News ↗
  62. OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files

    An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said. The portal publishes aggregate figures, such as spending, and…

    Fuente: The Hacker News ↗
  63. TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

    Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has…

    Fuente: The Hacker News ↗
  64. ● Explotada activamente

    Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

    Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticated attacker to…

    Fuente: The Hacker News ↗
  65. SASE Converges Network & Security Into One Cloud Solution

    Enterprise computing is moving to the edge. Keeping it secure requires tactics far beyond putting up firewalls. (Second in a three-part series.)

    Fuente: Dark Reading ↗
  66. EDR Evasion Stack Helps Process Injection Slip Past Defenses

    A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.

    Fuente: Dark Reading ↗
  67. GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks

    Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.

    Fuente: Dark Reading ↗
  68. Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

    Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector…

    Fuente: The Hacker News ↗
  69. A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

    The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run…

    Fuente: The Hacker News ↗
  70. MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

    Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick,…

    Fuente: The Hacker News ↗
  71. UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks

    The United Arab Emirates and Kingdom of Saudi Arabia together absorbed 50% of all cyberattacks recorded across the Gulf region in the first half of 2026.

    Fuente: Dark Reading ↗
  72. Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign

    Threat actors are poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the Web with malicious links and data and then optimizing the content.

    Fuente: Dark Reading ↗
  73. This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

    A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser…

    Fuente: The Hacker News ↗
  74. Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

    Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and…

    Fuente: The Hacker News ↗
  75. New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control

    A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and…

    Fuente: The Hacker News ↗
  76. 545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent

    Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and…

    Fuente: The Hacker News ↗
  77. Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests

    Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a "major step up…

    Fuente: The Hacker News ↗
  78. Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape

    A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS…

    Fuente: The Hacker News ↗
  79. ● Explotada activamente

    F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers

    Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth…

    Fuente: The Hacker News ↗
  80. Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware

    A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the…

    Fuente: The Hacker News ↗
  81. Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input

    A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an…

    Fuente: The Hacker News ↗
  82. ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants

    The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold…

    Fuente: The Hacker News ↗
  83. Relays Are Masking Chinese Access to Frontier AI Models in the US

    More than 80,000 AI relay servers are helping users in China mask their identities while they access cutting-edge large language models (LLMs), probably to clone them.

    Fuente: Dark Reading ↗
  84. How the CISO-CMO Alliance Builds Trust Before Crisis Strikes

    Cybersecurity and brand reputation are inextricably linked. Security and marketing leaders who establish regular touchpoints, develop joint crisis communications plans, and translate security risks into their brand impact position their…

    Fuente: Dark Reading ↗
  85. Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises

    Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S.…

    Fuente: The Hacker News ↗ También en: Dark Reading
  86. Deception by Design: CISA's Guide to Tricking Cybercriminals

    The Cybersecurity and Infrastructure Security Agency (CISA) is going old school to help organizations with limited resources set traps for hackers.

    Fuente: Dark Reading ↗
  87. ● Explotada activamente

    Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks

    Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service…

    Fuente: The Hacker News ↗
  88. WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers

    WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code.…

    Fuente: The Hacker News ↗
  89. Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials

    Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to…

    Fuente: The Hacker News ↗
  90. Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real

    As more reports of misalignment incidents underscore AI risks, large AI labs, regular businesses, and even nations are searching for better ways to keep control and be secure.

    Fuente: Dark Reading ↗
  91. 2026-013: Critical Vulnerability in F5 BIG-IP APM

    On 22 September 2026, F5 published an advisory addressing a critical vulnerability affecting its BIG-IP APM product. The vendor confirmed active exploitation in the wild. CERT-EU recommends taking appropriate actions as soon as possible.

    Fuente: CERT-EU ↗
  92. Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials

    A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw,…

    Fuente: The Hacker News ↗
  93. Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates

    A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no…

    Fuente: The Hacker News ↗
  94. ¿Existen los Robux gratis en Roblox? Qué es verdad y qué es una estafa

    Los Robux gratis son una promesa habitual en Roblox. Descubre qué ofertas son legítimas y cómo evitar las estafas más comunes.

    Fuente: WeLiveSecurity ↗
  95. AI Agents Are Rewriting the Rules of Lateral Movement

    Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A person may try…

    Fuente: The Hacker News ↗
  96. ● Explotada activamente

    New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups

    Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker…

    Fuente: The Hacker News ↗
  97. More Than a Third of Industrial Orgs See Cybersecurity Risk as a Top Obstacle to Growth, Study Finds

    Industrial companies are increasing cybersecurity investment as connected operations, AI adoption, and IT/OT convergence expand operational risk.

    Fuente: Dark Reading ↗
  98. DORA Year Two: Can Your SOC Actually See the Attack?

    When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing…

    Fuente: The Hacker News ↗
  99. New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory

    A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775,…

    Fuente: The Hacker News ↗
  100. SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE

    A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber…

    Fuente: The Hacker News ↗
  101. Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data

    Threat actors stole the contents of 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.

    Fuente: Dark Reading ↗
  102. Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal

    A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent…

    Fuente: The Hacker News ↗
  103. SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing

    The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. "SideCopy campaign operations typically initiate through…

    Fuente: The Hacker News ↗
  104. How AI Agents Can Trigger Runaway Costs for Enterprises

    Unbounded consumption is an issue that OWASP currently ranks sixth in its Top 10 for LLM Applications, and it could be an extremely costly one.

    Fuente: Dark Reading ↗
  105. ShinyHunters Hacked Cl0p. Now What About Cl0p's Victims?

    ShinyHunters defaced Cl0p's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.

    Fuente: Dark Reading ↗
  106. Cybercriminals Are Hiding New Malware in Torrents for Popular Films

    Victims have been identified in Africa, including in Kenya and Uganda.

    Fuente: Dark Reading ↗
  107. Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents

    The AI giant disclosed six examples of concerning model activity and published a new framework for investigating and disclosing such incidents.

    Fuente: Dark Reading ↗
  108. One does not simply defend agentically

    Defenders can’t use AI in the same way attackers can, but there’s much they can do to unlock the potential of agentic cyber defence.

    Fuente: NCSC-UK ↗