Noticias de ciberseguridad · semana del 28 sept al 4 oct 2026
Lo más relevante de la actualidad en ciberseguridad, con enlace a la fuente original.
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds…
Fuente: The Hacker News ↗ También en: SANS ISCOne Packet Can Crash OT Servers in Industrial Sectors
A high-severity zero-day vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments.
Fuente: Dark Reading ↗Japan's Keio confirms ransomware attack disrupted business systems
Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...]
Fuente: BleepingComputer ↗Times Car confirms data breach affecting 6.6 million user accounts
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]
Fuente: BleepingComputer ↗Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.
Fuente: Dark Reading ↗Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest,…
Fuente: KrebsOnSecurity ↗ También en: BleepingComputer- ● Explotada activamente
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.
Fuente: SecurityWeek ↗ También en: The Record Misconfigured Supabase apps expose data in over 16,000 databases
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. [...]
Fuente: BleepingComputer ↗AI Agents Are Privileged Users; Who Is Auditing Their Access?
Enterprises regularly rigorously monitor human employees, while autonomous AI agents quietly operate with broad privileges that could turn them into the next generation of insider threats.
Fuente: Dark Reading ↗Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at…
Fuente: The Hacker News ↗IAM for AI agents: A Practical Enterprise Framework
What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of…
Fuente: The Hacker News ↗Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain…
Fuente: The Hacker News ↗Modulate Raises $25 Million to Advance Deepfake Detection
The misuse and abuse of AI-generated voice is growing. Modulate’s intention is to allow real time detection and intervention.
Fuente: SecurityWeek ↗New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections
A New Mexico jury has found Facebook liable for deceiving users about privacy protections on the platform.
Fuente: SecurityWeek ↗ También en: The RecordChrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
A purported ad-blocker exfiltrates reams of sensitive information, and benefits from having Google's stamp of approval despite researcher warnings.
Fuente: Dark Reading ↗US, UK warn of exploited Citrix NetScaler zero-day bugs
Incident responders began warning of potential vulnerabilities in NetScaler Gateway products on Saturday before cybersecurity agencies in the Netherlands, U.S. and U.K. released advisories on Sunday confirming vulnerabilities. Citrix…
Fuente: The Record ↗JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack
The "agentic threat actor" may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases.
Fuente: Dark Reading ↗ También en: BleepingComputerCall for Presentations Open for 2026 CISO Forum Virtual Summit
SecurityWeek seeks original, vendor-neutral presentations that help cybersecurity leaders navigate emerging threats, strengthen resilience, and address the strategic challenges facing today’s enterprise security programs.
Fuente: SecurityWeek ↗80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how…
Fuente: BleepingComputer ↗Cyberattack on Polish medical software provider exposes patient data
Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to hit the country’s medical sector in recent months.
Fuente: The Record ↗Former US soldier gets nearly six-year sentence for hacking, extorting telecoms
A former soldier in the U.S. Army was sentenced to more than five years in federal prison after pleading guilty to hacking into several telecommunications companies and leaking sensitive records.
Fuente: The Record ↗Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Cameron John Wagenius was sentenced to 70 months in prison for stealing information from the wireless carriers.
Fuente: SecurityWeek ↗Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
Fuente: NCSC-UK ↗- ● Explotada activamente
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The…
Fuente: The Hacker News ↗ También en: SecurityWeek, Una al día DC Health Agency Exposes 400,000 Beneficiary Records
The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed.
Fuente: SecurityWeek ↗Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog
The platform combines open source software and a reference system design to keep AI agents within set boundaries.
Fuente: SecurityWeek ↗OpenAI frena en seco el entrenamiento de sus modelos más potentes: sus agentes de IA se han vuelto a descontrolar
OpenAI ha detenido el entrenamiento de sus modelos de IA más avanzados tras una serie de incidentes inesperados, incluyendo el de un modelo de prueba que encontró la forma de acceder a una red pública. Según cuenta The Verge, el incidente…
Fuente: Xataka ↗Correos y SMS suplantan a la DGT para robar tus datos con falsas multas
Correos y SMS suplantan a la DGT para robar tus datos con falsas multas Lun, 28/09/2026 - 12:09 Aviso Recursos Afectados Personas que hayan recibido estas comunicaciones, especialmente quienes hayan accedido al enlace y facilitado…
Fuente: INCIBE ↗Ciberataque contra Adif y Renfe con Inteligencia Artificial avanzada
El sector de las infraestructuras críticas de transporte en España permanece en alerta tras confirmarse un ciberataque grave contra las empresas ferroviarias Adif y Renfe. Una banda de ciberdelincuentes logró comprometer la seguridad…
Fuente: Red Seguridad ↗Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised.
Fuente: SecurityWeek ↗Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. [...]
Fuente: BleepingComputer ↗Creíamos que el hackeo de Renfe había expuesto correos y nombres. Eso solo era la punta del iceberg
El pasado viernes supimos que Renfe había sufrido un ciberataque que logró acceso a los sistemas de Adif. Inicialmente el problema parecía ser limitado, porque se habló de robo de nombres y correos electrónicos, sin acceso a información…
Fuente: Xataka ↗Múltiples vulnerabilidades en TPVEnlanube
Múltiples vulnerabilidades en TPVEnlanube Lun, 28/09/2026 - 09:53 Aviso Recursos Afectados TPVEnlanube. Descripción INCIBE ha coordinado la publicación de 3 vulnerabilidades de severidad media que afectan a TPVEnlanube, un software para…
Fuente: INCIBE-CERT ↗US soldier gets 70 months in prison for extorting 10 tech, telecom firms
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. [...]
Fuente: BleepingComputer ↗- ● Explotada activamente
Múltiples vulnerabilidades en productos de Citrix
Múltiples vulnerabilidades en productos de Citrix Lun, 28/09/2026 - 08:51 Aviso Recursos Afectados Las siguientes versiones compatibles de NetScaler ADC y NetScaler Gateway:NetScaler ADC y NetScaler Gateway 14.1, anteriores a…
Fuente: INCIBE-CERT ↗ CISA orders feds to patch exploited Citrix flaws by Wednesday
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]
Fuente: BleepingComputer ↗OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email
OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website. [...]
Fuente: BleepingComputer ↗