Ciberseguridad desde Málaga · Redes, anzuelos y amenazas

Noticias de ciberseguridad · semana del 5 al 11 oct 2026

Lo más relevante de la actualidad en ciberseguridad, con enlace a la fuente original.

  1. Ninja Forms plugin flaw exploited to hack WordPress sites

    Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]

    Fuente: BleepingComputer ↗
  2. Cómo convertir la IA agéntica en aliada frente al cibercrimen financiero

    Babel, compañía de origen español especializada en transformación digital con amplia experiencia en el sector financiero, ha analizado los principales retos que afronta el mercado español para transformar la IA agéntica en su principal…

    Fuente: CyberSecurity News ↗
  3. ClickFix Attacks Evolve to Better Hide Malicious Payloads

    Threat actors are now hiding payloads by using DNS TXT records and browser cache pre-fetching, making it tougher to spot early attack stages.

    Fuente: Dark Reading ↗
  4. Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

    On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days. [...]

    Fuente: BleepingComputer ↗
  5. Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

    A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. [...]

    Fuente: BleepingComputer ↗ También en: The Hacker News
  6. Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

    Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name…

    Fuente: The Hacker News ↗
  7. Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps

    The situation illustrates a trend toward using AI and deterministic validation to identify flaws and exploitability, and provide a risk assessment.

    Fuente: Dark Reading ↗
  8. Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

    A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's…

    Fuente: The Hacker News ↗ También en: INCIBE-CERT, BleepingComputer
  9. IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams

    In this video interview, Nick Kakolowski, senior director for CISO research at IANS, talks AI: budgets, ROI, and changes inside security teams.

    Fuente: Dark Reading ↗
  10. 'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates

    Not quite an EDR-killer, but the proof-of-concept cyber technique creates a silent virus detection gap while service runs normally, no exploit required.

    Fuente: Dark Reading ↗
  11. ASOS confirms data breach after “HACKED” in-app notifications

    UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. [...]

    Fuente: BleepingComputer ↗
  12. Alleged dev of Ploutus ATM malware appears in US court after arrest

    The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. [...]

    Fuente: BleepingComputer ↗ También en: The Record
  13. South Korean officials believe AI agents were used to hack several banks

    The personal data of at least 68,000 people was reportedly exposed in breaches of at least seven financial institutions, with officials saying they believe a Chinese cybersecurity tool was used to hack the banks’ systems.

    Fuente: The Record ↗
  14. Osaka Metropolitan University cancels classes after suspected ransomware attack

    Osaka Metropolitan University said on Tuesday that the outage left its internal network, email and a range of administrative and academic systems unavailable.

    Fuente: The Record ↗
  15. S2Grupo impulsa su expansión europea con su llegada al ‘Cyber Security Dynamic Marketplace’ de la OTAN

    S2Grupo ha entrado a formar parte del Cyber Security Dynamic Marketplace (CSDM) de la Agencia de Comunicaciones e Información de la OTAN. Con este acceso, la compañía se sitúa en un grupo limitado de proveedores habilitados para competir…

    Fuente: Red Seguridad ↗
  16. FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

    The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees.

    Fuente: SecurityWeek ↗
  17. How to secure RMM software: 8 controls MSPs should test

    RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM software, from patching and privileged…

    Fuente: BleepingComputer ↗
  18. ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware

    CERT-UA found fake Cloudflare verification pages that led visitors into a now-familiar ClickFix trap. This time the goal was to infect machines with an infostealer.

    Fuente: The Record ↗
  19. Dos fallos en LibreOffice y OpenOffice permiten ejecutar código al abrir hojas de cálculo sin avisos de macros

    Dos vulnerabilidades permiten ejecutar código al abrir documentos ofimáticos manipulados sin depender de los avisos clásicos de macros. LibreOffice Calc ya cuenta con corrección, mientras que en Apache OpenOffice la mitigación pasa por…

    Fuente: Una al día ↗
  20. FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware

    An alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026.

    Fuente: SecurityWeek ↗
  21. Incident affecting ASOS customers

    ASOS has said it is investigating a cyber incident and that some customer personal information may have been accessed.

    Fuente: NCSC-UK ↗
  22. LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

    A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro.…

    Fuente: The Hacker News ↗
  23. Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks

    Citing growing risks posed by more capable and autonomous AI agents, Apple will introduce additional controls.

    Fuente: SecurityWeek ↗
  24. Wikimedia: Rogue OpenAI agents behind unauthorized Wikipedia edits

    The Wikimedia Foundation says rogue OpenAI agents made unauthorized Wikipedia edits and may have been partially responsible for a May outage. [...]

    Fuente: BleepingComputer ↗
  25. Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool

    Beyond the potential misuses of its services, Wikimedia said activity by AI agents can be a drain on web platforms that are already operating with limited resources.

    Fuente: The Record ↗ También en: The Hacker News
  26. Cybersecurity M&A Roundup: 39 Deals Announced in September 2026

    Significant cybersecurity M&A deals announced by Dragos, IBM, Palo Alto Networks, Kiteworks, and Upwind.

    Fuente: SecurityWeek ↗
  27. Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

    Since August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign.

    Fuente: SecurityWeek ↗
  28. Data breach at Denmark’s national population register exposes 8.8 million people

    Denmark is investigating a data breach affecting approximately 8.8 million people after unauthorized users gained access to its national population register.

    Fuente: The Record ↗ También en: BleepingComputer, SecurityWeek
  29. More RMM Tools In the Wild, (Tue, Oct 6th)

    It seems that a trend started… I continue my journey discovering more RMM ("Remote Management & Monitoring") tools abused by threat actors! A few days ago, I wrote a diary[1] about ScreenConnect used in the wild. Today, I found…

    Fuente: SANS ISC ↗
  30. Nikkei discloses breaches of employees’ Microsoft, Google email accounts

    Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. [...]

    Fuente: BleepingComputer ↗
  31. Inyección SQL en la plataforma eLoanApp de RDL Technologies

    Inyección SQL en la plataforma eLoanApp de RDL Technologies Mar, 06/10/2026 - 11:12 Aviso Recursos Afectados Plataforma eLoanApp. Descripción INCIBE ha coordinado la publicación de una vulnerabilidad de severidad alta que afecta a la…

    Fuente: INCIBE-CERT ↗
  32. Social Engineering Detection Moves Into the Live Conversation

    Companies are pouring time and dollars into security awareness training, but little evidence shows it actually works against social engineering.

    Fuente: SecurityWeek ↗
  33. Múltiples vulnerabilidades en productos de MediaTek

    Múltiples vulnerabilidades en productos de MediaTek Mar, 06/10/2026 - 09:56 Aviso Recursos Afectados Determinados dispositivos que incorporan los conjuntos de chips MediaTek indicados en el boletín de seguridad de octubre de 2026.Las…

    Fuente: INCIBE-CERT ↗ También en: INCIBE-CERT
  34. Deserialización insegura en el plugin Magento 2 de TrueLayer

    Deserialización insegura en el plugin Magento 2 de TrueLayer Mar, 06/10/2026 - 10:31 Aviso Recursos Afectados TrueLayer Magento 2 Plugin, versiones 2.4.0 a 2.4.2. Descripción INCIBE ha coordinado la publicación de una vulnerabilidad de…

    Fuente: INCIBE-CERT ↗
  35. Engineer sentenced for locking over 3,000 devices on employer network

    A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer's network in a ransomware-style attack. [...]

    Fuente: BleepingComputer ↗
  36. Autenticación incorrecta en Integrated Lights-Out 7 de HPE

    Autenticación incorrecta en Integrated Lights-Out 7 de HPE Mar, 06/10/2026 - 09:56 Aviso Recursos Afectados HPE Integrated Lights-Out —iLO— 7, versiones de firmware anteriores a la 1.25.00. Descripción HPE ha publicado una vulnerabilidad…

    Fuente: INCIBE-CERT ↗
  37. Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

    A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming…

    Fuente: The Hacker News ↗ También en: SecurityWeek, Una al día, BleepingComputer, INCIBE-CERT
  38. ● Explotada activamente

    Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

    Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched.

    Fuente: SecurityWeek ↗ También en: The Hacker News, INCIBE-CERT
  39. De la obsolescencia a la IA ofensiva: los grandes desafíos que ponen a prueba la resiliencia del sector salud

    El IV Congreso de Ciberseguridad en el Sector Salud abrió sus puertas con la bienvenida institucional a cargo de Alfonso Alcalá Galán, subdirector de Operaciones de la Agencia de Ciberseguridad de la Comunidad de Madrid. Alcalá destacó el…

    Fuente: Red Seguridad ↗
  40. Shares in British clothing company ASOS dive after hackers apparently send push notification

    Several mysteries surround what appeared to be an unauthorized push notification sent to customers of London-based clothing company ASOS.

    Fuente: The Record ↗
  41. OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU

    OpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex in the European Union. [...]

    Fuente: BleepingComputer ↗
  42. ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes

    The Linux backdoor exploits 24 known flaws to compromise IoT devices and uses legitimate public STUN servers to obscure communications.

    Fuente: Dark Reading ↗
  43. Acer impulsa la adopción responsable de la IA en las escuelas europeas

    Para el curso escolar 2026/2027, Acer for Education sigue impulsando la adopción responsable de la inteligencia artificial en las escuelas europeas, basándose en la experiencia de los proyectos piloto puestos en marcha en Reino Unido,…

    Fuente: CyberSecurity News ↗
  44. Alleged ShinyHunters Leader Arrested in Jordan

    Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group.

    Fuente: SecurityWeek ↗ También en: The Record
  45. Patrice Caine, CEO de Thales: «la inteligencia artificial es el gran desafío de la ciberseguridad»

    La inteligencia artificial plantea una gran paradoja para las organizaciones en términos de ciberseguridad: el remedio y la enfermedad nacen de la misma fuente. A la vez que les ayuda a protegerse de manera más eficaz, supone un gran…

    Fuente: Red Seguridad ↗
  46. US, Australia warn of latest Citrix vulnerability after NetScaler advisory

    Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem was not connected to vulnerabilities reported last week that also caused alarm…

    Fuente: The Record ↗
  47. IQVIA fined $7.8 million for failing to properly anonymize health data

    Italy's Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization. [...]

    Fuente: BleepingComputer ↗
  48. Ukraine grocery chain ATB confirms cyberattack as hackers threaten to leak data

    Ukraine’s largest grocery store chain, ATB, confirmed that it was hit by a cyberattack after hackers posted an extortion demand on its website.

    Fuente: The Record ↗
  49. Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

    Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940,…

    Fuente: The Hacker News ↗
  50. Chinese Hackers Impersonate US Officials for AI Cyber Espionage

    An emerging threat group known as TA419 established seemingly legitimate professional relationships with AI policy experts working for US think tanks, universities, and legal organizations.

    Fuente: Dark Reading ↗
  51. University of Illinois Chicago affected by ransomware attack on medical school

    A ransomware attack that affected the University of Illinois Chicago (UIC) College of Medicine resulted in the theft of some information from its servers.

    Fuente: The Record ↗
  52. New Dell System Update flaw lets hackers gain root privileges

    Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible. [...]

    Fuente: BleepingComputer ↗
  53. Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

    Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP).

    Fuente: SecurityWeek ↗
  54. South Korea probes bank breaches amid suspected AI-powered attacks

    South Korea's Financial Services Commission (FSC) held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. [...]

    Fuente: BleepingComputer ↗
  55. Belarusian hacktivists spent two years inside Russian healthcare network, researchers say

    Russian cybersecurity researchers attributed a quiet two-year espionage campaign to the Belarusian Cyber Partisans, a group better known for public attacks against governments and infrastructure.

    Fuente: The Record ↗
  56. tenfold CE: Our free Identity Governance tool just got 2 new features

    tenfold has added shared content governance and real-time event auditing to its free Community Edition for organizations with under 150 users. The new features help teams manage Microsoft 365 sharing and investigate suspicious identity…

    Fuente: BleepingComputer ↗
  57. Japanese media group Nikkei discloses cyberattack targeting journalistic sources

    The Japanese media giant Nikkei disclosed a cyber incident involving an employee email account that may have compromised journalistic sources.

    Fuente: The Record ↗
  58. Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

    ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation.

    Fuente: SecurityWeek ↗
  59. Need for Speed: AI-Driven Attacks Are Changing Security Strategies

    AI-powered attacks are fast, relentless, and automated. How security teams can keep up is top of mind, according to the latest Dark Reading reader poll.

    Fuente: Dark Reading ↗
  60. 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms

    Hackers stole patient information from Clover Health Investments and AngMar Management Services in July.

    Fuente: SecurityWeek ↗
  61. The Credential Layer Is Expanding Faster Than Security Teams Can See It

    Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect,…

    Fuente: The Hacker News ↗
  62. Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

    Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a…

    Fuente: The Hacker News ↗
  63. Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity

    More than 730 cyber breaches affected over 270 million Americans last year, costing an average of $10 million per breach.

    Fuente: SecurityWeek ↗
  64. OpenAI will show visual ads in ChatGPT while you generate images

    OpenAI is expanding ads in ChatGPT, and one of the first new formats will show visual ads while you're generating images. [...]

    Fuente: BleepingComputer ↗
  65. Microsoft: Windows KB5124010 update crashes some games and apps

    Microsoft confirmed over the weekend that some games and applications using AC-3 (Dolby Digital) audio decoding will crash after installing the September 2026 KB5124010 Windows 11 preview update. [...]

    Fuente: BleepingComputer ↗
  66. Google halts open-source bug bounty program amid AI spam surge

    Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. [...]

    Fuente: BleepingComputer ↗
  67. Cinco formas de impulsar a tu equipo con los nuevos ordenadores HP con IA

    La inteligencia artificial (IA) ya no es solo una curiosidad tecnológica: cuando se integra bien en el puesto de trabajo, se traduce en más productividad, mejor colaboración y mayor seguridad para los datos. Pero para aprovecharla de…

    Fuente: Red Seguridad ↗
  68. TTY Logs and the Data it Captures, (Sun, Oct 4th)

    For an experiment, I created a script [1] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs are sent daily at the end of…

    Fuente: SANS ISC ↗