Noticias de ciberseguridad · semana del 5 al 11 oct 2026
Lo más relevante de la actualidad en ciberseguridad, con enlace a la fuente original.
Corea del Sur detecta indicios de IA en ataques a sus principales bancos y el presidente exige respuestas
Cuando pensamos en inteligencia artificial solemos hacerlo desde el lado de quien intenta ganar tiempo, automatizar tareas o analizar enormes cantidades de información. Pero esas mismas capacidades también pueden ponerse al servicio de…
Fuente: Xataka ↗La IA, el cibercrimen como servicio y los conflictos híbridos impulsan una nueva era de riesgo digital
El informe Mid-Year Threat Landscape 2026 de Inetum revela un incremento sostenido de la actividad maliciosa, con más de 60.000 alertas gestionadas por su LiveSOC en el primer semestre de 2026 y un crecimiento de amenazas cada vez más…
Fuente: CyberSecurity News ↗La IA ya interviene en todas las fases del ciberataque
La inteligencia artificial está dejando de ser una herramienta puntual para convertirse en una nueva capa operativa de los ciberataques. Los grupos vinculados a Estados ya la emplean en diferentes fases de una intrusión, desde la…
Fuente: CyberSecurity News ↗'AgentCorruption' Puts AWS Environments At Risk With Single Prompt
A now-patched vulnerability in AWS Bedrock AgentCore could allow an attacker to use one AI chatbot to take over an organization's entire fleet.
Fuente: Dark Reading ↗Lawmakers warn Google could expose Spirit Airlines data in $10 million AI training deal
The proposed sale would include about 100 million emails, 500 million Microsoft Teams messages, employment contracts, employee and timecard records and payroll and tax information, Rep. Steven Horsford (D-NV) said in a press release.
Fuente: The Record ↗Ransomware attack disrupts Japan's IDCF Cloud used by govt clients
IDC Frontier, a major Japanese cloud and digital infrastructure company, disclosed that its IDCF Cloud service was targeted in a ransomware attack that caused an outage at a data center cluster serving the eastern part of the country. [...]
Fuente: BleepingComputer ↗Low-cost Android phones ship with residential proxy malware
A malware campaign dubbed 'Midnight Mimosa' has been discovered on low-cost Android smartphones that ship with malicious software embedded in their firmware, allowing attackers to silently install apps, perform ad fraud, and turn devices…
Fuente: BleepingComputer ↗International coalition seizes tools used by cyber firm behind Flax Typhoon
The U.S. and other nations took down digital tools and infrastructure by Beijing-based Integrity Tech that allowed "widespread vulnerability scanning and, in some cases, intrusions" as part of the Flax Typhoon campaign.
Fuente: The Record ↗Venezuelan Cartel's Malware Honcho Nabbed for ATM Jackpotting
The first cybercriminal to ever make the FBI's "10 Most Wanted Fugitives" list allegedly infused Tren de Aragua's violent criminal operations with cash.
Fuente: Dark Reading ↗FBI Says China-Linked Hackers Ran Portal Giving Third Parties Access to Stolen Emails
Hackers tied to a Chinese cybersecurity company stole email from government organizations, law enforcement agencies, healthcare systems, and religious institutions in Southeast Asia, the FBI and agencies in 6 other countries said on…
Fuente: The Hacker News ↗Russian Spies Give 'MatchBoil' Malware a Stealthy Facelift
Cyber-espionage actor UAC-0099 has been steadily refining its flagship dropper in campaigns targeting Ukrainian organizations.
Fuente: Dark Reading ↗ThreatsDay: Ransomware Affiliate Betrayal, WhatsApp RAT, Exposed Hacker Tools and 12 More Stories
The crooks have trust problems of their own. One ransomware affiliate decided to keep the profits for himself. Elsewhere, an attacker left a server exposed, complete with tools and traces of an intrusion. Apparently, keeping things secure…
Fuente: The Hacker News ↗FakeGit malware campaign returns with 17,610 malicious GitHub repos
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer. [...]
Fuente: BleepingComputer ↗DOJ charges ransomware recovery CEO for secretly paying hackers
The owner of a ransomware recovery firm was hit with wire fraud charges for allegedly making secret ransom payments while overcharging the victims of attacks.
Fuente: The Record ↗ASOS: Hackers tricked way into employee account before sending rogue push notification
The company said its investigation, carried out with external experts, found the attackers had accessed “some personal information, including names and contact details, and certain non-personal account related information.”
Fuente: The Record ↗Reconstructing AI Agent Activity: Two New Scripts for Forensic Review, (Thu, Oct 8th)
We just did a major update to FOR577 and added a lot of new material on day 5 about investigating AI usage in incident response. In the new material we dicsuss 8 of the most popular AI coding assistants and agents including Claude Code,…
Fuente: SANS ISC ↗Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said. The Tokyo-based center, which takes incident…
Fuente: The Hacker News ↗Crypto thief who splurged on gold grills sentenced in London
A 25-year-old man who helped steal nearly $260,000 in cryptocurrency through a SIM-swapping fraud scheme was sentenced to two and a half years in prison at a London court.
Fuente: The Record ↗Cisco Patches a Dozen Critical Vulnerabilities
The security defects could lead to unauthorized access, information leaks, privilege escalation, DoS attacks, and remote code execution.
Fuente: SecurityWeek ↗UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use in attacks…
Fuente: The Hacker News ↗Cisco warns of critical flaws allowing Nexus switch takeover
Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches. [...]
Fuente: BleepingComputer ↗Leaked chats show Russian extortion gang sending ‘agents’ into US law firms
In leaked chats, members track dozens of victims, haggle over multimillion-dollar payments and direct operatives based in the United States whom they call “agents.”
Fuente: The Record ↗Security Awareness Training Isn’t Dead, but It Needs a Rethink
All enterprises conduct security awareness training for their employees. But whether this has tangible benefits is debatable.
Fuente: SecurityWeek ↗ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks. The activity, per…
Fuente: The Hacker News ↗Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products
A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's…
Fuente: The Hacker News ↗ También en: INCIBE-CERT, BleepingComputer, The Hacker News, BleepingComputer, SANS ISC, Una al día, SecurityWeekOAuth grants pile up faster than you can review them. Here's how to keep up.
OAuth grants create data highways between SaaS apps, AI agents, and other tools. And, they are multiplying faster than any security team can review them. As the recent Klue breach showed, attackers are taking notice and exploiting…
Fuente: BleepingComputer ↗Hackers target two South Korean megachurches, potentially exposing congregant data
Two of South Korea's largest Protestant churches are investigating cyberattacks that may have exposed sensitive information about hundreds of thousands of members, including personal details, financial records and internal documents.
Fuente: The Record ↗Uranium crypto exchange hacker convicted for stealing $53 million
A Maryland man was found guilty of stealing more than $53 million after hacking the decentralized crypto exchange Uranium Finance twice in April 2021. [...]
Fuente: BleepingComputer ↗Thousands of cheap Android phones shipped with ad-fraud malware
"It’s on the phone before the owner switches it on for the first time, and it can’t be uninstalled," researchers at Bitdefender said about ad fraud malware found on thousands of cheap Android devices.
Fuente: The Record ↗US posts $10 million reward for accused Chinese ‘Hafnium’ hacker
U.S. officials say Zhang Yu was a prominent figure in the Hafnium campaign, which saw hackers breach thousands of computers and steal troves of documents.
Fuente: The Record ↗ También en: SecurityWeekSonicWall and Splunk Patch Critical Vulnerabilities
Critical and high-severity vulnerabilities could allow attackers to bypass authentication, execute arbitrary code, and elevate their privileges.
Fuente: SecurityWeek ↗Russian-aligned spies upgrade malware used in attacks on Ukrainian transport, energy firms
Russian-aligned hackers have targeted Ukrainian transportation, manufacturing and energy companies with a constantly evolving malware strain designed to harvest system data, according to new research.
Fuente: The Record ↗Microsoft Teams to get support for third-party deepfake detection tools
Microsoft will soon introduce support for third-party deepfake detection solutions and impersonation protection in Teams meetings. [...]
Fuente: BleepingComputer ↗Writing the Next Chapter
Dark Reading is about to begin a new decade in its storied history, and we have some breaking news of our own to share.
Fuente: Dark Reading ↗Major Yandex data center in Russia hit by Ukrainian drone strike
A drone strike on a large Yandex data center caused a significant disruption to the Russian tech giant's network, with connectivity reportedly falling to around 70 percent of normal levels.
Fuente: The Record ↗China-linked malicious actors called out by UK and international partners for targeting sensitive data globally
Joint advisory with international partners highlights malicious targeting of organisations from a range of sectors across the globe.
Fuente: NCSC-UK ↗ASOS links data breach to social engineering attack, credential theft
ASOS is sending updates to affected customers about the cybersecurity incident it suffered earlier this week, confirming that hackers accessed some personal data. [...]
Fuente: BleepingComputer ↗Rein Security Raises $25 Million to Guard AI Agents at Runtime
The cybersecurity startup will invest in product innovation, agentic research, and employee base expansion.
Fuente: SecurityWeek ↗Owner of Empire cybercrime market gets 40 years in prison
The co-creator of Empire Market, one of the largest dark web marketplaces before its shutdown, has been sentenced to 40 years in prison for facilitating $430 million in illegal transactions from 2018 to 2020. [...]
Fuente: BleepingComputer ↗TP-Link Faces State Lawsuits and New Scrutiny Over ISP Router Flaws
SEC Consult has published technical details on vulnerabilities mentioned in a complaint filed by several US states.
Fuente: SecurityWeek ↗Fake Decryption Tools Masked $11M Markup in Ransomware Recovery Scheme
Zohar Pinhasi was paying ransoms to obtain decryption keys and then charging victims substantially more for remediation.
Fuente: SecurityWeek ↗Omisión de autenticación en múltiples productos de Frappe Technologies
Omisión de autenticación en múltiples productos de Frappe Technologies Jue, 08/10/2026 - 11:23 Aviso Recursos Afectados Frappe Cloud;ERPNext registration service. Descripción INCIBE ha coordinado la publicación de una vulnerabilidad de…
Fuente: INCIBE-CERT ↗Hornetsecurity refuerza la seguridad y la protección de datos de los Hospitales San Juan de Dios España
Hornetsecurity by Proofpoint ha anunciado una colaboración en materia de seguridad con los Hospitales San Juan de Dios España para mejorar su ciberresiliencia frente a los ataques. La incorporación de sus soluciones de protección de datos…
Fuente: Red Seguridad ↗Oracle Health Data Breach Tally Climbs to Nearly 20 Million
The figure is far higher than the counts that surfaced in earlier filings and patient notifications.
Fuente: SecurityWeek ↗Los equipos de ciberseguridad de las organizaciones crecen de manera desigual, alerta un estudio de Isaca
Ante una oleada constante de ciberataques en el último año, Isaca ha publicado un nuevo estudio que refleja el crecimiento desigual de las organizaciones en sus equipos de defensa. El informe State of Cybersecurity 2026 muestra cómo…
Fuente: Red Seguridad ↗FortiBleed Attackers Locking Victims Out of Fortinet Devices
Attackers are creating new accounts and deleting existing ones and passwords to prevent legitimate access.
Fuente: SecurityWeek ↗Múltiples vulnerabilidades en productos de MediaTek
Múltiples vulnerabilidades en productos de MediaTek Mar, 06/10/2026 - 09:56 Aviso Recursos Afectados Determinados dispositivos que incorporan los conjuntos de chips MediaTek indicados en el boletín de seguridad de octubre de 2026.Las…
Fuente: INCIBE-CERT ↗ También en: INCIBE-CERT, INCIBE-CERT, INCIBE-CERT, INCIBE-CERT- ● Explotada activamente
Path Traversal en FortiMail de Fortinet
Path Traversal en FortiMail de Fortinet Jue, 08/10/2026 - 08:56 Aviso Recursos Afectados Las siguientes versiones de FortiMail:8.0.0 a 8.0.1;7.6.0 a 7.6.6;7.4.0 a 7.4.8;7.2.0 a 7.2.9. Descripción Fortinet ha publicado una vulnerabilidad…
Fuente: INCIBE-CERT ↗ Inyección SQL en la plataforma de demostración de NetBoard CRM
Inyección SQL en la plataforma de demostración de NetBoard CRM Jue, 08/10/2026 - 08:52 Aviso Recursos Afectados NetBoard CRM Demo Platform. Última versión de demostración (noviembre de 2025). Descripción INCIBE ha coordinado la…
Fuente: INCIBE-CERT ↗Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland
On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities. [...]
Fuente: BleepingComputer ↗Ransomware recovery CEO charged over secret ransom payments
The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to recover encrypted…
Fuente: BleepingComputer ↗Australian Gov't Weighs Mandatory AI Incident Reporting
In the wake of an agentic attack against its own Medicare systems, Australia's government is feeling out what regulations might look like for frontier AI companies.
Fuente: Dark Reading ↗FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators. [...]
Fuente: BleepingComputer ↗Citizen Lab Slams Trump Administration, 'Techno-Fascist' Executives
The Citizen Lab's Ron Deibert warns the US government is pushing for pervasive surveillance and says certain technology executives are all too happy to help.
Fuente: Dark Reading ↗Las víctimas de ransomware crecen un 19% en España mientras la IA acelera el robo masivo de datos
Zscaler, Inc., la plataforma de ciberseguridad de la era de la inteligencia artificial, ha publicado nuevos datos de su informe Zscaler ThreatLabz 2026 Ransomware Report, que muestran que el ransomware sigue creciendo y que la…
Fuente: CyberSecurity News ↗Detectan dominios de phishing de AliExpress antes de su activación
EfficientIP Research Labs ha publicado una investigación sobre una campaña de phishing que imitaba a AliExpress y utilizaba dominios desechables como puntos de entrada hacia un sitio fraudulento. El análisis muestra cómo el tráfico DNS…
Fuente: CyberSecurity News ↗Anthropic Gives Vetted Defenders Fewer Claude Guardrails
Anthropic has merged Project Glasswing into a tiered access program for its advanced cyber LLMs, including Opus, Sonnet, and Mythos.
Fuente: Dark Reading ↗Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were not breached, but any domain ending in .gh…
Fuente: The Hacker News ↗ También en: BleepingComputerOpenAI Agent Escape Causes Wikimedia Service Outage
Autonomous agents also tried to abuse other websites and services hosted by the foundation, using them as proxies for unauthorized activities.
Fuente: Dark Reading ↗$11 million plan for psychological support at Cyber Command gets fresh boost from lawmakers
Lawmakers who oversee military cyber policy as well as the Fort Meade, Maryland, hub for those agencies say an $11 million mental health program should be locked in to defense spending legislation.
Fuente: The Record ↗Arizona courts say hackers stole info on more than 1.3 million people
The investigation into the incident revealed cybercriminals were able to breach the Fines/Fees and Restitution Enforcement (FARE) Program, a statewide program that helps the court collect outstanding debts tied to traffic and criminal…
Fuente: The Record ↗Amatera: qué es y cómo funciona el infostealer que lidera las detecciones en América Latina
Analizamos cómo funciona Amatera, el infostealer que roba credenciales, cookies y activos digitales y se propaga mediante campañas de ingeniería social como ClickFix.
Fuente: WeLiveSecurity ↗Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK…
Fuente: The Hacker News ↗SonicWall warns of max severity SSRF flaw in SMA1000 gateways
SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances. [...]
Fuente: BleepingComputer ↗ También en: The Hacker NewsPath Traversal en SenNet Datalogger Serie 200 de Satel Iberia
Path Traversal en SenNet Datalogger Serie 200 de Satel Iberia Mié, 07/10/2026 - 17:56 Aviso Recursos Afectados SenNet Datalogger serie 200 V7.0m-1.53h. Descripción INCIBE ha coordinado la publicación de una vulnerabilidad de severidad…
Fuente: INCIBE-CERT ↗Microsoft Outlook to block MSIX attachments starting November
Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month. [...]
Fuente: BleepingComputer ↗Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in…
Fuente: The Hacker News ↗PoeLLM malware infects exposed AI servers in cryptomining attacks
A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads. [...]
Fuente: BleepingComputer ↗Oklahoma judge’s Flock ruling shows the power of Supreme Court’s digital evidence decision
How a recent Supreme Court decision on geofencing influenced a federal judge to toss a sheriff's Flock camera evidence in a drug trafficking case.
Fuente: The Record ↗Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts
Southern Company is notifying customers that their utility account information was accessed by hackers.
Fuente: SecurityWeek ↗Cyber experts call on CISA to create mandatory federal OT rules
The Operational Technology Cybersecurity Coalition (OTCC) released a white paper on Tuesday urging the Cybersecurity and Infrastructure Security Agency (CISA) to create a new directive centered around operational technology, which is used…
Fuente: The Record ↗Ransomware has a new target. Is your backup ready?
Ransomware groups are increasingly targeting backup infrastructure to eliminate recovery options and increase pressure on victims to pay. Kaseya explains why organizations need isolated, immutable, and regularly tested backups that…
Fuente: BleepingComputer ↗Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity
More than 730 cyber breaches affected over 270 million Americans last year, costing an average of $10 million per breach.
Fuente: SecurityWeek ↗ También en: The RecordShinyHunters Extorted Boeing Spin-off Prior to Arrests
A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has…
Fuente: KrebsOnSecurity ↗Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany
The individual was detained in May and has been extradited to Germany to face hacking charges.
Fuente: SecurityWeek ↗Russian cyberattacks against UK are 'Putin Tax' costing $3.3 billion, says lawmaker
A report by a Labour MP and an academic argues that if the British public cannot see what Russian activity costs, it cannot weigh that burden against the cost of defending against it.
Fuente: The Record ↗Hadrian Raises $40 Million to Expand Autonomous Offensive Security Platform
Hadrian offers an agentic offensive security platform that allows defenders to operate at the same speed as attackers.
Fuente: SecurityWeek ↗FBI, Secret Service add to warnings of FortiBleed credential stealing campaign
Users of two types of Fortinet hardware should take steps to limit their exposure to a now-global credential stealing campaign, U.S. federal law enforcement says.
Fuente: The Record ↗Advantest Discloses Data Breach Months After Ransomware Attack
The Japanese chip testing giant said hackers stole personal information from its servers in the February 2026 cyberattack.
Fuente: SecurityWeek ↗El ‘phishing’ se consolida como la principal amenaza para los trabajadores de la UE, según un nuevo Eurobarómetro
Tres de cada cuatro empleados de la Unión Europea se encuentran con correos electrónicos, mensajes o enlaces sospechosos en el trabajo. Así lo pone de manifiesto la Comisión Europea en su nuevo Eurobarómetro con motivo del Mes Europeo de…
Fuente: Red Seguridad ↗Chrome 155 Update Patches 247 Vulnerabilities
Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.
Fuente: SecurityWeek ↗Musician sent to prison for $10 million streaming fraud using AI bots
A North Carolina musician was sentenced to 18 months in prison for collecting more than $10 million in royalties from Spotify, Apple Music, Amazon Music, and YouTube Music in a massive streaming royalty fraud scheme. [...]
Fuente: BleepingComputer ↗Advantest confirms personal information stolen in ransomware attack
Advantest Corporation is notifying affected individuals that a ransomware attack earlier this year exposed their personally identifiable data. [...]
Fuente: BleepingComputer ↗Anthropic Introduces 3-Tier Cyber Verification Program for AI Access
Anthropic is integrating the CVP and Project Glasswing into a single offering, with three levels of access to its most capable AI models.
Fuente: SecurityWeek ↗Cómo detectar el phishing antes de hacer clic: 5 pistas
Acabas de recibir un correo electrónico que parece completamente normal y el nombre del remitente tiene un aspecto oficial. El mensaje te mete prisa para que hagas algo inmediatamente. Ojo, porque tras esa aparente normalidad puede…
Fuente: Red Seguridad ↗ASOS confirms data breach after “HACKED” in-app notifications
UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. [...]
Fuente: BleepingComputer ↗ También en: SecurityWeekAkamai anuncia un acuerdo de 11.600 millones de dólares con Anthropic para ampliar sus servicios en la nube
Akamai Technologies ha anunciado una ampliación de su colaboración con Anthropic a través de un acuerdo contractual de 11.600 millones de dólares a lo largo de siete años. Esta alianza tiene como objetivo gestionar la demanda de cargas de…
Fuente: Red Seguridad ↗Múltiples vulnerabilidades en BugTracker.NET
Múltiples vulnerabilidades en BugTracker.NET Mié, 07/10/2026 - 10:09 Aviso Recursos Afectados BugTracker.NET 3.6.8 Descripción INCIBE ha coordinado la publicación de 3 vulnerabilidades de severidad alta que afectan a BugTracker.NET, una…
Fuente: INCIBE-CERT ↗Europol urges early action to protect cryptocurrencies and sensitive data from quantum threats
The timing of these capabilities remains uncertain. However, this should not be the main concern. Adapting systems and coordinating security upgrades will take time. Therefore, regardless of the nature of the threats that may emerge,…
Fuente: Europol ↗Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool
Beyond the potential misuses of its services, Wikimedia said activity by AI agents can be a drain on web platforms that are already operating with limited resources.
Fuente: The Record ↗ También en: The Hacker News, BleepingComputer, SecurityWeekAtlassian Patches Critical Vulnerability Affecting 8 Products
Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory.
Fuente: SecurityWeek ↗ También en: CERT-EUMúltiples vulnerabilidades en SMA 1000 de SonicWall
Múltiples vulnerabilidades en SMA 1000 de SonicWall Mié, 07/10/2026 - 09:01 Aviso Recursos Afectados SonicWall SMA 1000, incluidos los modelos 6210, 7210 y 8200v, con las siguientes versiones:12.4.3-03526 y anteriores;12.5.0-02952 y…
Fuente: INCIBE-CERT ↗Boletín de seguridad de Android de octubre de 2026
Boletín de seguridad de Android de octubre de 2026 Mié, 07/10/2026 - 09:01 Aviso Recursos Afectados Dispositivos con las siguientes versiones de Android, en función de cada vulnerabilidad:Android 14;Android 15;Android 16;Android 16…
Fuente: INCIBE-CERT ↗Android’s October 2026 Updates Patch 25 Vulnerabilities
The patches resolve a critical vulnerability in Android’s System component that could lead to privilege escalation.
Fuente: SecurityWeek ↗Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System
The Arizona Supreme Court said the information was copied for people dating back as far as 30 years.
Fuente: SecurityWeek ↗Ninja Forms plugin flaw exploited to hack WordPress sites
Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]
Fuente: BleepingComputer ↗Cómo convertir la IA agéntica en aliada frente al cibercrimen financiero
Babel, compañía de origen español especializada en transformación digital con amplia experiencia en el sector financiero, ha analizado los principales retos que afronta el mercado español para transformar la IA agéntica en su principal…
Fuente: CyberSecurity News ↗ClickFix Attacks Evolve to Better Hide Malicious Payloads
Threat actors are now hiding payloads by using DNS TXT records and browser cache pre-fetching, making it tougher to spot early attack stages.
Fuente: Dark Reading ↗Critical Healthcare Systems Aren't Quantum-Ready
A study of 2.5 million devices across 50 healthcare organization suggests the sector has a long way to go in getting ready for the post-quantum cryptography era.
Fuente: Dark Reading ↗Hackers exploit 32 zero-days on first day of Pwn2Own Ireland
On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days. [...]
Fuente: BleepingComputer ↗Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes
A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. [...]
Fuente: BleepingComputer ↗ También en: The Hacker NewsLinux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan
Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name…
Fuente: The Hacker News ↗Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps
The situation illustrates a trend toward using AI and deterministic validation to identify flaws and exploitability, and provide a risk assessment.
Fuente: Dark Reading ↗IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams
In this video interview, Nick Kakolowski, senior director for CISO research at IANS, talks AI: budgets, ROI, and changes inside security teams.
Fuente: Dark Reading ↗'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates
Not quite an EDR-killer, but the proof-of-concept cyber technique creates a silent virus detection gap while service runs normally, no exploit required.
Fuente: Dark Reading ↗Alleged dev of Ploutus ATM malware appears in US court after arrest
The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. [...]
Fuente: BleepingComputer ↗ También en: The RecordSouth Korean officials believe AI agents were used to hack several banks
The personal data of at least 68,000 people was reportedly exposed in breaches of at least seven financial institutions, with officials saying they believe a Chinese cybersecurity tool was used to hack the banks’ systems.
Fuente: The Record ↗Osaka Metropolitan University cancels classes after suspected ransomware attack
Osaka Metropolitan University said on Tuesday that the outage left its internal network, email and a range of administrative and academic systems unavailable.
Fuente: The Record ↗S2Grupo impulsa su expansión europea con su llegada al ‘Cyber Security Dynamic Marketplace’ de la OTAN
S2Grupo ha entrado a formar parte del Cyber Security Dynamic Marketplace (CSDM) de la Agencia de Comunicaciones e Información de la OTAN. Con este acceso, la compañía se sitúa en un grupo limitado de proveedores habilitados para competir…
Fuente: Red Seguridad ↗FBI Blames Contractor’s Missed Patch for ShinyHunters Breach
The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees.
Fuente: SecurityWeek ↗How to secure RMM software: 8 controls MSPs should test
RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM software, from patching and privileged…
Fuente: BleepingComputer ↗ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware
CERT-UA found fake Cloudflare verification pages that led visitors into a now-familiar ClickFix trap. This time the goal was to infect machines with an infostealer.
Fuente: The Record ↗Dos fallos en LibreOffice y OpenOffice permiten ejecutar código al abrir hojas de cálculo sin avisos de macros
Dos vulnerabilidades permiten ejecutar código al abrir documentos ofimáticos manipulados sin depender de los avisos clásicos de macros. LibreOffice Calc ya cuenta con corrección, mientras que en Apache OpenOffice la mitigación pasa por…
Fuente: Una al día ↗FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware
An alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026.
Fuente: SecurityWeek ↗Incident affecting ASOS customers
ASOS has said it is investigating a cyber incident and that some customer personal information may have been accessed.
Fuente: NCSC-UK ↗LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings
A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro.…
Fuente: The Hacker News ↗Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks
Citing growing risks posed by more capable and autonomous AI agents, Apple will introduce additional controls.
Fuente: SecurityWeek ↗Cybersecurity M&A Roundup: 39 Deals Announced in September 2026
Significant cybersecurity M&A deals announced by Dragos, IBM, Palo Alto Networks, Kiteworks, and Upwind.
Fuente: SecurityWeek ↗Long-Running NPM Malware Campaign Accumulates 40,000 Downloads
Since August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign.
Fuente: SecurityWeek ↗Data breach at Denmark’s national population register exposes 8.8 million people
Denmark is investigating a data breach affecting approximately 8.8 million people after unauthorized users gained access to its national population register.
Fuente: The Record ↗ También en: BleepingComputer, SecurityWeekMore RMM Tools In the Wild, (Tue, Oct 6th)
It seems that a trend started… I continue my journey discovering more RMM ("Remote Management & Monitoring") tools abused by threat actors! A few days ago, I wrote a diary[1] about ScreenConnect used in the wild. Today, I found…
Fuente: SANS ISC ↗Nikkei discloses breaches of employees’ Microsoft, Google email accounts
Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. [...]
Fuente: BleepingComputer ↗Inyección SQL en la plataforma eLoanApp de RDL Technologies
Inyección SQL en la plataforma eLoanApp de RDL Technologies Mar, 06/10/2026 - 11:12 Aviso Recursos Afectados Plataforma eLoanApp. Descripción INCIBE ha coordinado la publicación de una vulnerabilidad de severidad alta que afecta a la…
Fuente: INCIBE-CERT ↗Social Engineering Detection Moves Into the Live Conversation
Companies are pouring time and dollars into security awareness training, but little evidence shows it actually works against social engineering.
Fuente: SecurityWeek ↗Deserialización insegura en el plugin Magento 2 de TrueLayer
Deserialización insegura en el plugin Magento 2 de TrueLayer Mar, 06/10/2026 - 10:31 Aviso Recursos Afectados TrueLayer Magento 2 Plugin, versiones 2.4.0 a 2.4.2. Descripción INCIBE ha coordinado la publicación de una vulnerabilidad de…
Fuente: INCIBE-CERT ↗Engineer sentenced for locking over 3,000 devices on employer network
A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer's network in a ransomware-style attack. [...]
Fuente: BleepingComputer ↗Autenticación incorrecta en Integrated Lights-Out 7 de HPE
Autenticación incorrecta en Integrated Lights-Out 7 de HPE Mar, 06/10/2026 - 09:56 Aviso Recursos Afectados HPE Integrated Lights-Out —iLO— 7, versiones de firmware anteriores a la 1.25.00. Descripción HPE ha publicado una vulnerabilidad…
Fuente: INCIBE-CERT ↗Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming…
Fuente: The Hacker News ↗ También en: SecurityWeek, Una al día, BleepingComputer, INCIBE-CERT- ● Explotada activamente
Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier
Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched.
Fuente: SecurityWeek ↗ También en: The Hacker News, INCIBE-CERT De la obsolescencia a la IA ofensiva: los grandes desafíos que ponen a prueba la resiliencia del sector salud
El IV Congreso de Ciberseguridad en el Sector Salud abrió sus puertas con la bienvenida institucional a cargo de Alfonso Alcalá Galán, subdirector de Operaciones de la Agencia de Ciberseguridad de la Comunidad de Madrid. Alcalá destacó el…
Fuente: Red Seguridad ↗Shares in British clothing company ASOS dive after hackers apparently send push notification
Several mysteries surround what appeared to be an unauthorized push notification sent to customers of London-based clothing company ASOS.
Fuente: The Record ↗OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU
OpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex in the European Union. [...]
Fuente: BleepingComputer ↗ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes
The Linux backdoor exploits 24 known flaws to compromise IoT devices and uses legitimate public STUN servers to obscure communications.
Fuente: Dark Reading ↗Acer impulsa la adopción responsable de la IA en las escuelas europeas
Para el curso escolar 2026/2027, Acer for Education sigue impulsando la adopción responsable de la inteligencia artificial en las escuelas europeas, basándose en la experiencia de los proyectos piloto puestos en marcha en Reino Unido,…
Fuente: CyberSecurity News ↗Alleged ShinyHunters Leader Arrested in Jordan
Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group.
Fuente: SecurityWeek ↗ También en: The RecordPatrice Caine, CEO de Thales: «la inteligencia artificial es el gran desafío de la ciberseguridad»
La inteligencia artificial plantea una gran paradoja para las organizaciones en términos de ciberseguridad: el remedio y la enfermedad nacen de la misma fuente. A la vez que les ayuda a protegerse de manera más eficaz, supone un gran…
Fuente: Red Seguridad ↗US, Australia warn of latest Citrix vulnerability after NetScaler advisory
Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem was not connected to vulnerabilities reported last week that also caused alarm…
Fuente: The Record ↗IQVIA fined $7.8 million for failing to properly anonymize health data
Italy's Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization. [...]
Fuente: BleepingComputer ↗Ukraine grocery chain ATB confirms cyberattack as hackers threaten to leak data
Ukraine’s largest grocery store chain, ATB, confirmed that it was hit by a cyberattack after hackers posted an extortion demand on its website.
Fuente: The Record ↗Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940,…
Fuente: The Hacker News ↗Chinese Hackers Impersonate US Officials for AI Cyber Espionage
An emerging threat group known as TA419 established seemingly legitimate professional relationships with AI policy experts working for US think tanks, universities, and legal organizations.
Fuente: Dark Reading ↗University of Illinois Chicago affected by ransomware attack on medical school
A ransomware attack that affected the University of Illinois Chicago (UIC) College of Medicine resulted in the theft of some information from its servers.
Fuente: The Record ↗New Dell System Update flaw lets hackers gain root privileges
Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible. [...]
Fuente: BleepingComputer ↗Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports
Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP).
Fuente: SecurityWeek ↗South Korea probes bank breaches amid suspected AI-powered attacks
South Korea's Financial Services Commission (FSC) held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. [...]
Fuente: BleepingComputer ↗Belarusian hacktivists spent two years inside Russian healthcare network, researchers say
Russian cybersecurity researchers attributed a quiet two-year espionage campaign to the Belarusian Cyber Partisans, a group better known for public attacks against governments and infrastructure.
Fuente: The Record ↗tenfold CE: Our free Identity Governance tool just got 2 new features
tenfold has added shared content governance and real-time event auditing to its free Community Edition for organizations with under 150 users. The new features help teams manage Microsoft 365 sharing and investigate suspicious identity…
Fuente: BleepingComputer ↗Japanese media group Nikkei discloses cyberattack targeting journalistic sources
The Japanese media giant Nikkei disclosed a cyber incident involving an employee email account that may have compromised journalistic sources.
Fuente: The Record ↗Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws
ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation.
Fuente: SecurityWeek ↗Need for Speed: AI-Driven Attacks Are Changing Security Strategies
AI-powered attacks are fast, relentless, and automated. How security teams can keep up is top of mind, according to the latest Dark Reading reader poll.
Fuente: Dark Reading ↗250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms
Hackers stole patient information from Clover Health Investments and AngMar Management Services in July.
Fuente: SecurityWeek ↗The Credential Layer Is Expanding Faster Than Security Teams Can See It
Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect,…
Fuente: The Hacker News ↗Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a…
Fuente: The Hacker News ↗OpenAI will show visual ads in ChatGPT while you generate images
OpenAI is expanding ads in ChatGPT, and one of the first new formats will show visual ads while you're generating images. [...]
Fuente: BleepingComputer ↗Microsoft: Windows KB5124010 update crashes some games and apps
Microsoft confirmed over the weekend that some games and applications using AC-3 (Dolby Digital) audio decoding will crash after installing the September 2026 KB5124010 Windows 11 preview update. [...]
Fuente: BleepingComputer ↗Google halts open-source bug bounty program amid AI spam surge
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. [...]
Fuente: BleepingComputer ↗Cinco formas de impulsar a tu equipo con los nuevos ordenadores HP con IA
La inteligencia artificial (IA) ya no es solo una curiosidad tecnológica: cuando se integra bien en el puesto de trabajo, se traduce en más productividad, mejor colaboración y mayor seguridad para los datos. Pero para aprovecharla de…
Fuente: Red Seguridad ↗TTY Logs and the Data it Captures, (Sun, Oct 4th)
For an experiment, I created a script [1] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs are sent daily at the end of…
Fuente: SANS ISC ↗