Ciberseguridad desde Málaga · Redes, anzuelos y amenazas

Noticias de ciberseguridad · semana del 5 al 11 oct 2026

Lo más relevante de la actualidad en ciberseguridad, con enlace a la fuente original.

  1. FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins

    The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators. [...]

    Fuente: BleepingComputer ↗
  2. Las víctimas de ransomware crecen un 19% en España mientras la IA acelera el robo masivo de datos

    Zscaler, Inc., la plataforma de ciberseguridad de la era de la inteligencia artificial, ha publicado nuevos datos de su informe Zscaler ThreatLabz 2026 Ransomware Report, que muestran que el ransomware sigue creciendo y que la…

    Fuente: CyberSecurity News ↗
  3. Detectan dominios de phishing de AliExpress antes de su activación

    EfficientIP Research Labs ha publicado una investigación sobre una campaña de phishing que imitaba a AliExpress y utilizaba dominios desechables como puntos de entrada hacia un sitio fraudulento. El análisis muestra cómo el tráfico DNS…

    Fuente: CyberSecurity News ↗
  4. Anthropic Gives Vetted Defenders Fewer Claude Guardrails

    Anthropic has merged Project Glasswing into a tiered access program for its advanced cyber LLMs, including Opus, Sonnet, and Mythos.

    Fuente: Dark Reading ↗
  5. Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains

    Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were not breached, but any domain ending in .gh…

    Fuente: The Hacker News ↗ También en: BleepingComputer
  6. US posts $10 million reward for accused Chinese ‘Hafnium’ hacker

    U.S. officials say Zhang Yu was a prominent figure in the Hafnium campaign, which saw hackers breach thousands of computers and steal troves of documents.

    Fuente: The Record ↗
  7. OpenAI Agent Escape Causes Wikimedia Service Outage

    Autonomous agents also tried to abuse other websites and services hosted by the foundation, using them as proxies for unauthorized activities.

    Fuente: Dark Reading ↗
  8. $11 million plan for psychological support at Cyber Command gets fresh boost from lawmakers

    Lawmakers who oversee military cyber policy as well as the Fort Meade, Maryland, hub for those agencies say an $11 million mental health program should be locked in to defense spending legislation.

    Fuente: The Record ↗
  9. Arizona courts say hackers stole info on more than 1.3 million people

    The investigation into the incident revealed cybercriminals were able to breach the Fines/Fees and Restitution Enforcement (FARE) Program, a statewide program that helps the court collect outstanding debts tied to traffic and criminal…

    Fuente: The Record ↗
  10. Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer

    Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed MALFEX by CloudSEK…

    Fuente: The Hacker News ↗
  11. SonicWall warns of max severity SSRF flaw in SMA1000 gateways

    SonicWall has released hotfixes to address a maximum-severity server-side request forgery (SSRF) flaw in SMA1000 series appliances. [...]

    Fuente: BleepingComputer ↗ También en: The Hacker News
  12. Path Traversal en SenNet Datalogger Serie 200 de Satel Iberia

    Path Traversal en SenNet Datalogger Serie 200 de Satel Iberia Mié, 07/10/2026 - 17:56 Aviso Recursos Afectados SenNet Datalogger serie 200 V7.0m-1.53h. Descripción INCIBE ha coordinado la publicación de una vulnerabilidad de severidad…

    Fuente: INCIBE-CERT ↗
  13. Microsoft Outlook to block MSIX attachments starting November

    Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month. [...]

    Fuente: BleepingComputer ↗
  14. Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely

    A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is available. The flaw is in…

    Fuente: The Hacker News ↗
  15. PoeLLM malware infects exposed AI servers in cryptomining attacks

    A cryptomining campaign targeting exposed AI services is using PoeLLM malware to turn compromised servers into scanners and exploit launchpads. [...]

    Fuente: BleepingComputer ↗
  16. Critical Atlassian Flaw Lets Unauthenticated Attackers Read Known Files Across 8 Products

    A critical flaw in 8 Atlassian Data Center products, which customers host themselves, allows an attacker with no login access to read specific files in each product's web application root directory. The attacker must already know a file's…

    Fuente: The Hacker News ↗ También en: INCIBE-CERT, BleepingComputer, The Hacker News, BleepingComputer, SANS ISC, Una al día
  17. Oklahoma judge’s Flock ruling shows the power of Supreme Court’s digital evidence decision

    How a recent Supreme Court decision on geofencing influenced a federal judge to toss a sheriff's Flock camera evidence in a drug trafficking case.

    Fuente: The Record ↗
  18. Georgia Power, Alabama Power Data Breach Hits 400,000 Accounts

    Southern Company is notifying customers that their utility account information was accessed by hackers.

    Fuente: SecurityWeek ↗
  19. Cyber experts call on CISA to create mandatory federal OT rules

    The Operational Technology Cybersecurity Coalition (OTCC) released a white paper on Tuesday urging the Cybersecurity and Infrastructure Security Agency (CISA) to create a new directive centered around operational technology, which is used…

    Fuente: The Record ↗
  20. Ransomware has a new target. Is your backup ready?

    Ransomware groups are increasingly targeting backup infrastructure to eliminate recovery options and increase pressure on victims to pay. Kaseya explains why organizations need isolated, immutable, and regularly tested backups that…

    Fuente: BleepingComputer ↗
  21. Senate Passes Bipartisan Bill to Strengthen Healthcare Cybersecurity

    More than 730 cyber breaches affected over 270 million Americans last year, costing an average of $10 million per breach.

    Fuente: SecurityWeek ↗ También en: The Record
  22. ShinyHunters Extorted Boeing Spin-off Prior to Arrests

    A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has…

    Fuente: KrebsOnSecurity ↗
  23. Qilin Ransomware Suspect Arrested in Japan, Extradited to Germany

    The individual was detained in May and has been extradited to Germany to face hacking charges.

    Fuente: SecurityWeek ↗
  24. Russian cyberattacks against UK are 'Putin Tax' costing $3.3 billion, says lawmaker

    A report by a Labour MP and an academic argues that if the British public cannot see what Russian activity costs, it cannot weigh that burden against the cost of defending against it.

    Fuente: The Record ↗
  25. Hadrian Raises $40 Million to Expand Autonomous Offensive Security Platform

    Hadrian offers an agentic offensive security platform that allows defenders to operate at the same speed as attackers.

    Fuente: SecurityWeek ↗
  26. FBI, Secret Service add to warnings of FortiBleed credential stealing campaign

    Users of two types of Fortinet hardware should take steps to limit their exposure to a now-global credential stealing campaign, U.S. federal law enforcement says.

    Fuente: The Record ↗
  27. Advantest Discloses Data Breach Months After Ransomware Attack

    The Japanese chip testing giant said hackers stole personal information from its servers in the February 2026 cyberattack.

    Fuente: SecurityWeek ↗
  28. El ‘phishing’ se consolida como la principal amenaza para los trabajadores de la UE, según un nuevo Eurobarómetro

    Tres de cada cuatro empleados de la Unión Europea se encuentran con correos electrónicos, mensajes o enlaces sospechosos en el trabajo. Así lo pone de manifiesto la Comisión Europea en su nuevo Eurobarómetro con motivo del Mes Europeo de…

    Fuente: Red Seguridad ↗
  29. Chrome 155 Update Patches 247 Vulnerabilities

    Four critical-severity use-after-free defects were fixed in Chromecast, Browser, Navigation, and Track.

    Fuente: SecurityWeek ↗
  30. Musician sent to prison for $10 million streaming fraud using AI bots

    A North Carolina musician was sentenced to 18 months in prison for collecting more than $10 million in royalties from Spotify, Apple Music, Amazon Music, and YouTube Music in a massive streaming royalty fraud scheme. [...]

    Fuente: BleepingComputer ↗
  31. Advantest confirms personal information stolen in ransomware attack

    Advantest Corporation is notifying affected individuals that a ransomware attack earlier this year exposed their personally identifiable data. [...]

    Fuente: BleepingComputer ↗
  32. Anthropic Introduces 3-Tier Cyber Verification Program for AI Access

    Anthropic is integrating the CVP and Project Glasswing into a single offering, with three levels of access to its most capable AI models.

    Fuente: SecurityWeek ↗
  33. Cómo detectar el phishing antes de hacer clic: 5 pistas

    Acabas de recibir un correo electrónico que parece completamente normal y el nombre del remitente tiene un aspecto oficial. El mensaje te mete prisa para que hagas algo inmediatamente. Ojo, porque tras esa aparente normalidad puede…

    Fuente: Red Seguridad ↗
  34. ASOS confirms data breach after “HACKED” in-app notifications

    UK fashion retailer ASOS confirmed a data breach Tuesday after hackers sent unauthorized push notifications through its mobile app while claiming to have stolen customer data from the company's Snowflake environment. [...]

    Fuente: BleepingComputer ↗ También en: SecurityWeek
  35. Akamai anuncia un acuerdo de 11.600 millones de dólares con Anthropic para ampliar sus servicios en la nube

    Akamai Technologies ha anunciado una ampliación de su colaboración con Anthropic a través de un acuerdo contractual de 11.600 millones de dólares a lo largo de siete años. Esta alianza tiene como objetivo gestionar la demanda de cargas de…

    Fuente: Red Seguridad ↗
  36. Múltiples vulnerabilidades en BugTracker.NET

    Múltiples vulnerabilidades en BugTracker.NET Mié, 07/10/2026 - 10:09 Aviso Recursos Afectados BugTracker.NET 3.6.8 Descripción INCIBE ha coordinado la publicación de 3 vulnerabilidades de severidad alta que afectan a BugTracker.NET, una…

    Fuente: INCIBE-CERT ↗
  37. Europol urges early action to protect cryptocurrencies and sensitive data from quantum threats

    The timing of these capabilities remains uncertain. However, this should not be the main concern. Adapting systems and coordinating security upgrades will take time. Therefore, regardless of the nature of the threats that may emerge,…

    Fuente: Europol ↗
  38. Wikimedia Foundation: OpenAI agents tried to edit pages and compromise notes tool

    Beyond the potential misuses of its services, Wikimedia said activity by AI agents can be a drain on web platforms that are already operating with limited resources.

    Fuente: The Record ↗ También en: The Hacker News, BleepingComputer, SecurityWeek
  39. Atlassian Patches Critical Vulnerability Affecting 8 Products

    Unauthenticated attackers could exploit the flaw to access specific files in the web application root directory.

    Fuente: SecurityWeek ↗ También en: CERT-EU
  40. Múltiples vulnerabilidades en SMA 1000 de SonicWall

    Múltiples vulnerabilidades en SMA 1000 de SonicWall Mié, 07/10/2026 - 09:01 Aviso Recursos Afectados SonicWall SMA 1000, incluidos los modelos 6210, 7210 y 8200v, con las siguientes versiones:12.4.3-03526 y anteriores;12.5.0-02952 y…

    Fuente: INCIBE-CERT ↗
  41. Múltiples vulnerabilidades en productos de MediaTek

    Múltiples vulnerabilidades en productos de MediaTek Mar, 06/10/2026 - 09:56 Aviso Recursos Afectados Determinados dispositivos que incorporan los conjuntos de chips MediaTek indicados en el boletín de seguridad de octubre de 2026.Las…

    Fuente: INCIBE-CERT ↗ También en: INCIBE-CERT, INCIBE-CERT
  42. Boletín de seguridad de Android de octubre de 2026

    Boletín de seguridad de Android de octubre de 2026 Mié, 07/10/2026 - 09:01 Aviso Recursos Afectados Dispositivos con las siguientes versiones de Android, en función de cada vulnerabilidad:Android 14;Android 15;Android 16;Android 16…

    Fuente: INCIBE-CERT ↗
  43. Android’s October 2026 Updates Patch 25 Vulnerabilities

    The patches resolve a critical vulnerability in Android’s System component that could lead to privilege escalation.

    Fuente: SecurityWeek ↗
  44. Personal Information for Over 1 Million People Stolen in a Cyberattack on Arizona’s Court System

    The Arizona Supreme Court said the information was copied for people dating back as far as 30 years.

    Fuente: SecurityWeek ↗
  45. Ninja Forms plugin flaw exploited to hack WordPress sites

    Hackers are exploiting stored cross-site scripting (XSS) vulnerabilities in two unrelated WordPress plugins, Ninja Forms and WPC Product Bundles for WooCommerce, to install backdoors and create rogue admin accounts. [...]

    Fuente: BleepingComputer ↗
  46. Cómo convertir la IA agéntica en aliada frente al cibercrimen financiero

    Babel, compañía de origen español especializada en transformación digital con amplia experiencia en el sector financiero, ha analizado los principales retos que afronta el mercado español para transformar la IA agéntica en su principal…

    Fuente: CyberSecurity News ↗
  47. ClickFix Attacks Evolve to Better Hide Malicious Payloads

    Threat actors are now hiding payloads by using DNS TXT records and browser cache pre-fetching, making it tougher to spot early attack stages.

    Fuente: Dark Reading ↗
  48. Critical Healthcare Systems Aren't Quantum-Ready

    A study of 2.5 million devices across 50 healthcare organization suggests the sector has a long way to go in getting ready for the post-quantum cryptography era.

    Fuente: Dark Reading ↗
  49. Hackers exploit 32 zero-days on first day of Pwn2Own Ireland

    On the first day of the Pwn2Own Ireland 2026 competition, security researchers hacked the Samsung Galaxy S26 twice and earned $388,500 after exploiting 32 zero-days. [...]

    Fuente: BleepingComputer ↗
  50. Fake ChatGPT, Gemini Sites steal advertising accounts, MFA codes

    A new campaign targeting ad account managers uses fake ChatGPT, Gemini, Claude, and Perplexity sites that steal login credentials and multi-factor authentication (MFA) codes through browser-in-browser attacks. [...]

    Fuente: BleepingComputer ↗ También en: The Hacker News
  51. Linux Backdoors Impersonate Email Security Tools to Evade Detection in Korea and Taiwan

    Linux backdoors targeting telecom and network appliances in South Korea and Taiwan have been disguising their traffic as email services and seemingly legitimate processes to blend in and evade detection. Threat actors are known to name…

    Fuente: The Hacker News ↗
  52. Google's PageBreak AI Agent Finds 500 Flaws in Its Web Apps

    The situation illustrates a trend toward using AI and deterministic validation to identify flaws and exploitability, and provide a risk assessment.

    Fuente: Dark Reading ↗
  53. IANS' Kakolowski: How AI Is Reshaping CISO Budgets & Security Teams

    In this video interview, Nick Kakolowski, senior director for CISO research at IANS, talks AI: budgets, ROI, and changes inside security teams.

    Fuente: Dark Reading ↗
  54. 'BigDiskBuster' Leaves Microsoft Defender Running While Blocking Updates

    Not quite an EDR-killer, but the proof-of-concept cyber technique creates a silent virus detection gap while service runs normally, no exploit required.

    Fuente: Dark Reading ↗
  55. Alleged dev of Ploutus ATM malware appears in US court after arrest

    The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. [...]

    Fuente: BleepingComputer ↗ También en: The Record
  56. South Korean officials believe AI agents were used to hack several banks

    The personal data of at least 68,000 people was reportedly exposed in breaches of at least seven financial institutions, with officials saying they believe a Chinese cybersecurity tool was used to hack the banks’ systems.

    Fuente: The Record ↗
  57. Osaka Metropolitan University cancels classes after suspected ransomware attack

    Osaka Metropolitan University said on Tuesday that the outage left its internal network, email and a range of administrative and academic systems unavailable.

    Fuente: The Record ↗
  58. S2Grupo impulsa su expansión europea con su llegada al ‘Cyber Security Dynamic Marketplace’ de la OTAN

    S2Grupo ha entrado a formar parte del Cyber Security Dynamic Marketplace (CSDM) de la Agencia de Comunicaciones e Información de la OTAN. Con este acceso, la compañía se sitúa en un grupo limitado de proveedores habilitados para competir…

    Fuente: Red Seguridad ↗
  59. FBI Blames Contractor’s Missed Patch for ShinyHunters Breach

    The FBI has removed an Accenture contractor over a data breach that exposed personal information of thousands of bureau employees.

    Fuente: SecurityWeek ↗
  60. How to secure RMM software: 8 controls MSPs should test

    RMM platforms give MSPs privileged access across customer environments, making their security controls critical to limiting risk. Acronis outlines eight controls MSPs should test when evaluating RMM software, from patching and privileged…

    Fuente: BleepingComputer ↗
  61. ClickFix campaign in Ukraine compromises over 100 websites to spread Lunex malware

    CERT-UA found fake Cloudflare verification pages that led visitors into a now-familiar ClickFix trap. This time the goal was to infect machines with an infostealer.

    Fuente: The Record ↗
  62. Dos fallos en LibreOffice y OpenOffice permiten ejecutar código al abrir hojas de cálculo sin avisos de macros

    Dos vulnerabilidades permiten ejecutar código al abrir documentos ofimáticos manipulados sin depender de los avisos clásicos de macros. LibreOffice Calc ya cuenta con corrección, mientras que en Apache OpenOffice la mitigación pasa por…

    Fuente: Una al día ↗
  63. FBI Arrests ‘Most Wanted’ Developer of Ploutus ATM Malware

    An alleged leader of Tren de Aragua’s ATM jackpotting activities, Canelon Aguirre was on the FBI’s top 10 most wanted list since March 2026.

    Fuente: SecurityWeek ↗
  64. Incident affecting ASOS customers

    ASOS has said it is investigating a cyber incident and that some customer personal information may have been accessed.

    Fuente: NCSC-UK ↗
  65. LibreOffice and OpenOffice Flaws Let Malicious Spreadsheets Run Code Without Macro Warnings

    A malicious spreadsheet can make LibreOffice and Apache OpenOffice run an attacker's code as soon as the file is opened, security researchers have shown. There is no warning first, of the kind either program shows before it runs a macro.…

    Fuente: The Hacker News ↗
  66. Apple to Tighten Full Disk Access Controls in macOS Amid AI Risks

    Citing growing risks posed by more capable and autonomous AI agents, Apple will introduce additional controls.

    Fuente: SecurityWeek ↗
  67. Cybersecurity M&A Roundup: 39 Deals Announced in September 2026

    Significant cybersecurity M&A deals announced by Dragos, IBM, Palo Alto Networks, Kiteworks, and Upwind.

    Fuente: SecurityWeek ↗
  68. Long-Running NPM Malware Campaign Accumulates 40,000 Downloads

    Since August 2023, attackers have published eight malicious packages as part of the MALFEX supply chain campaign.

    Fuente: SecurityWeek ↗
  69. Data breach at Denmark’s national population register exposes 8.8 million people

    Denmark is investigating a data breach affecting approximately 8.8 million people after unauthorized users gained access to its national population register.

    Fuente: The Record ↗ También en: BleepingComputer, SecurityWeek
  70. More RMM Tools In the Wild, (Tue, Oct 6th)

    It seems that a trend started… I continue my journey discovering more RMM ("Remote Management & Monitoring") tools abused by threat actors! A few days ago, I wrote a diary[1] about ScreenConnect used in the wild. Today, I found…

    Fuente: SANS ISC ↗
  71. Nikkei discloses breaches of employees’ Microsoft, Google email accounts

    Over the weekend, Japanese publishing giant Nikkei disclosed that unknown attackers recently breached two employee email accounts and used one to send thousands of phishing emails. [...]

    Fuente: BleepingComputer ↗
  72. Inyección SQL en la plataforma eLoanApp de RDL Technologies

    Inyección SQL en la plataforma eLoanApp de RDL Technologies Mar, 06/10/2026 - 11:12 Aviso Recursos Afectados Plataforma eLoanApp. Descripción INCIBE ha coordinado la publicación de una vulnerabilidad de severidad alta que afecta a la…

    Fuente: INCIBE-CERT ↗
  73. Social Engineering Detection Moves Into the Live Conversation

    Companies are pouring time and dollars into security awareness training, but little evidence shows it actually works against social engineering.

    Fuente: SecurityWeek ↗
  74. Deserialización insegura en el plugin Magento 2 de TrueLayer

    Deserialización insegura en el plugin Magento 2 de TrueLayer Mar, 06/10/2026 - 10:31 Aviso Recursos Afectados TrueLayer Magento 2 Plugin, versiones 2.4.0 a 2.4.2. Descripción INCIBE ha coordinado la publicación de una vulnerabilidad de…

    Fuente: INCIBE-CERT ↗
  75. Engineer sentenced for locking over 3,000 devices on employer network

    A former core infrastructure engineer at an industrial company headquartered in New Jersey was sentenced to 32 months in prison for locking thousands of devices on his employer's network in a ransomware-style attack. [...]

    Fuente: BleepingComputer ↗
  76. Autenticación incorrecta en Integrated Lights-Out 7 de HPE

    Autenticación incorrecta en Integrated Lights-Out 7 de HPE Mar, 06/10/2026 - 09:56 Aviso Recursos Afectados HPE Integrated Lights-Out —iLO— 7, versiones de firmware anteriores a la 1.25.00. Descripción HPE ha publicado una vulnerabilidad…

    Fuente: INCIBE-CERT ↗
  77. Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

    A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session forgery stemming…

    Fuente: The Hacker News ↗ También en: SecurityWeek, Una al día, BleepingComputer, INCIBE-CERT
  78. ● Explotada activamente

    Exploitation of Citrix NetScaler Zero-Day Hits Appliances Patched Days Earlier

    Citrix has confirmed that a new zero-day vulnerability, CVE-2026-88779, emerged just days after two other exploited flaws were patched.

    Fuente: SecurityWeek ↗ También en: The Hacker News, INCIBE-CERT
  79. De la obsolescencia a la IA ofensiva: los grandes desafíos que ponen a prueba la resiliencia del sector salud

    El IV Congreso de Ciberseguridad en el Sector Salud abrió sus puertas con la bienvenida institucional a cargo de Alfonso Alcalá Galán, subdirector de Operaciones de la Agencia de Ciberseguridad de la Comunidad de Madrid. Alcalá destacó el…

    Fuente: Red Seguridad ↗
  80. Shares in British clothing company ASOS dive after hackers apparently send push notification

    Several mysteries surround what appeared to be an unauthorized push notification sent to customers of London-based clothing company ASOS.

    Fuente: The Record ↗
  81. OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU

    OpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex in the European Union. [...]

    Fuente: BleepingComputer ↗
  82. ClingSTUN Turns Vulnerable IoT Devices Into Proxy Nodes

    The Linux backdoor exploits 24 known flaws to compromise IoT devices and uses legitimate public STUN servers to obscure communications.

    Fuente: Dark Reading ↗
  83. Acer impulsa la adopción responsable de la IA en las escuelas europeas

    Para el curso escolar 2026/2027, Acer for Education sigue impulsando la adopción responsable de la inteligencia artificial en las escuelas europeas, basándose en la experiencia de los proyectos piloto puestos en marcha en Reino Unido,…

    Fuente: CyberSecurity News ↗
  84. Alleged ShinyHunters Leader Arrested in Jordan

    Known as Rey, the suspect is reportedly helping the FBI identify and locate other members of the extortion group.

    Fuente: SecurityWeek ↗ También en: The Record
  85. Patrice Caine, CEO de Thales: «la inteligencia artificial es el gran desafío de la ciberseguridad»

    La inteligencia artificial plantea una gran paradoja para las organizaciones en términos de ciberseguridad: el remedio y la enfermedad nacen de la misma fuente. A la vez que les ayuda a protegerse de manera más eficaz, supone un gran…

    Fuente: Red Seguridad ↗
  86. US, Australia warn of latest Citrix vulnerability after NetScaler advisory

    Citrix confirmed late on Friday that it was “tracking a newly observed issue” related to some customer-managed NetScaler deployments but claimed the problem was not connected to vulnerabilities reported last week that also caused alarm…

    Fuente: The Record ↗
  87. IQVIA fined $7.8 million for failing to properly anonymize health data

    Italy's Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymization. [...]

    Fuente: BleepingComputer ↗
  88. Ukraine grocery chain ATB confirms cyberattack as hackers threaten to leak data

    Ukraine’s largest grocery store chain, ATB, confirmed that it was hit by a cyberattack after hackers posted an extortion demand on its website.

    Fuente: The Record ↗
  89. Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes

    Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as CVE-2026-96940,…

    Fuente: The Hacker News ↗
  90. Chinese Hackers Impersonate US Officials for AI Cyber Espionage

    An emerging threat group known as TA419 established seemingly legitimate professional relationships with AI policy experts working for US think tanks, universities, and legal organizations.

    Fuente: Dark Reading ↗
  91. University of Illinois Chicago affected by ransomware attack on medical school

    A ransomware attack that affected the University of Illinois Chicago (UIC) College of Medicine resulted in the theft of some information from its servers.

    Fuente: The Record ↗
  92. New Dell System Update flaw lets hackers gain root privileges

    Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible. [...]

    Fuente: BleepingComputer ↗
  93. Google Narrows Open Source Bug Bounty Amid Wave of Invalid Automated Reports

    Google has temporarily stopped accepting product vulnerability reports through its Open Source Software Vulnerability Reward Program (OSS VRP).

    Fuente: SecurityWeek ↗
  94. South Korea probes bank breaches amid suspected AI-powered attacks

    South Korea's Financial Services Commission (FSC) held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. [...]

    Fuente: BleepingComputer ↗
  95. Belarusian hacktivists spent two years inside Russian healthcare network, researchers say

    Russian cybersecurity researchers attributed a quiet two-year espionage campaign to the Belarusian Cyber Partisans, a group better known for public attacks against governments and infrastructure.

    Fuente: The Record ↗
  96. tenfold CE: Our free Identity Governance tool just got 2 new features

    tenfold has added shared content governance and real-time event auditing to its free Community Edition for organizations with under 150 users. The new features help teams manage Microsoft 365 sharing and investigate suspicious identity…

    Fuente: BleepingComputer ↗
  97. Japanese media group Nikkei discloses cyberattack targeting journalistic sources

    The Japanese media giant Nikkei disclosed a cyber incident involving an employee email account that may have compromised journalistic sources.

    Fuente: The Record ↗
  98. Linux Backdoor Abuses STUN Protocol, Exploits Dozens of Flaws

    ClingSTUN operates as a back-connect proxy backdoor, sets up persistence, and contains exploits for self-propagation.

    Fuente: SecurityWeek ↗
  99. Need for Speed: AI-Driven Attacks Are Changing Security Strategies

    AI-powered attacks are fast, relentless, and automated. How security teams can keep up is top of mind, according to the latest Dark Reading reader poll.

    Fuente: Dark Reading ↗
  100. 250,000 Impacted by Data Breaches at New Jersey, Texas Healthcare Firms

    Hackers stole patient information from Clover Health Investments and AngMar Management Services in July.

    Fuente: SecurityWeek ↗
  101. The Credential Layer Is Expanding Faster Than Security Teams Can See It

    Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capabilities: Detect,…

    Fuente: The Hacker News ↗
  102. Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

    Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not because it introduces a…

    Fuente: The Hacker News ↗
  103. OpenAI will show visual ads in ChatGPT while you generate images

    OpenAI is expanding ads in ChatGPT, and one of the first new formats will show visual ads while you're generating images. [...]

    Fuente: BleepingComputer ↗
  104. Microsoft: Windows KB5124010 update crashes some games and apps

    Microsoft confirmed over the weekend that some games and applications using AC-3 (Dolby Digital) audio decoding will crash after installing the September 2026 KB5124010 Windows 11 preview update. [...]

    Fuente: BleepingComputer ↗
  105. Google halts open-source bug bounty program amid AI spam surge

    Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. [...]

    Fuente: BleepingComputer ↗
  106. Cinco formas de impulsar a tu equipo con los nuevos ordenadores HP con IA

    La inteligencia artificial (IA) ya no es solo una curiosidad tecnológica: cuando se integra bien en el puesto de trabajo, se traduce en más productividad, mejor colaboración y mayor seguridad para los datos. Pero para aprovecharla de…

    Fuente: Red Seguridad ↗
  107. TTY Logs and the Data it Captures, (Sun, Oct 4th)

    For an experiment, I created a script [1] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs are sent daily at the end of…

    Fuente: SANS ISC ↗