Ciberseguridad desde Málaga · Redes, anzuelos y amenazas

Noticias de ciberseguridad · semana del 28 sept al 4 oct 2026

Lo más relevante de la actualidad en ciberseguridad, con enlace a la fuente original.

  1. Signal adds encypted local backup support to iOS, desktop apps

    Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows). [...]

    Fuente: BleepingComputer ↗
  2. Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution

    A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.

    Fuente: Dark Reading ↗
  3. Former US Air Force members sent to prison over BEC attacks

    Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]

    Fuente: BleepingComputer ↗ También en: The Record
  4. Más de la mitad de los usuarios españoles de internet ha sufrido fraudes online

    El fraude online no deja de evolucionar. La accesibilidad de la Inteligencia Artificial está permitiendo a los ciberdelincuentes automatizar y sofisticar sus ciberataques a gran escala. Así lo demuestra un estudio de mercado de Kaspersky,…

    Fuente: CyberSecurity News ↗
  5. Las webs que “desnudan” con IA alcanzan los 40 millones de visitas al mes

    Una fotografía publicada en una red social, una imagen de perfil o cualquier otra foto accesible online puede convertirse, sin conocimiento ni consentimiento de la persona que aparece en ella, en la materia prima para crear un falso…

    Fuente: CyberSecurity News ↗
  6. Custom ChatGPTs push ClickFix attacks to deploy RAT malware

    Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]

    Fuente: BleepingComputer ↗
  7. Controversial spyware firm Paragon to go public by end of year

    The company plans to close the deal around the end of the year at which point Paragon will begin trading on Nasdaq under the REDLattice umbrella.

    Fuente: The Record ↗
  8. OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference

    Altman made a slew of product announcements and updates, including the company’s new agents, called Dots.

    Fuente: SecurityWeek ↗
  9. FBI tells ShinyHunters members to turn themselves in after recent arrest

    The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders. [...]

    Fuente: BleepingComputer ↗
  10. OpenAI apologizes for agents breaching Australian government websites without authorization

    The artificial intelligence giant acknowledged it botched its response to the incidents and should have done more to promptly notify and work with the Australian government in the days after it discovered the breaches.

    Fuente: The Record ↗
  11. ● Explotada activamente

    CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The…

    Fuente: The Hacker News ↗ También en: SecurityWeek, Una al día, The Record, BleepingComputer
  12. French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

    An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency…

    Fuente: The Hacker News ↗
  13. Windows 11 2026 Update released, here's everything you need to know

    Microsoft has started rolling out Windows 11 26H2 to everyone, and while it's this year's big annual feature update, you probably won't notice a massive difference after installing it. [...]

    Fuente: BleepingComputer ↗
  14. DARPA Selects Xint to Use AI in Securing Military Messaging Apps

    The AIxCC competition winner will analyze messaging app code and compiled binaries for vulnerabilities, with technology that could also help commercial customers secure their software.

    Fuente: SecurityWeek ↗
  15. Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

    Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to…

    Fuente: The Hacker News ↗
  16. New Spectre v2 attack variant leaks Linux root password hash in minutes

    A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average. [...]

    Fuente: BleepingComputer ↗
  17. Cloudflare Announces Public Certificate Authority for the Post-Quantum Web

    Automated certificates for everyone, built for today, and hardened for the era of quantum computing.

    Fuente: Dark Reading ↗
  18. New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

    Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel

    Fuente: SecurityWeek ↗
  19. New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

    A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system…

    Fuente: The Hacker News ↗
  20. Automated AI agent used to breach cybersecurity nonprofit DIVD

    The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." [...]

    Fuente: BleepingComputer ↗
  21. Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

    Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at…

    Fuente: The Hacker News ↗ También en: Dark Reading
  22. RemoteThreat Launches With $7 Million for Offensive Operations Platform

    The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe.

    Fuente: SecurityWeek ↗
  23. Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

    Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During the shutdown, this activity…

    Fuente: The Hacker News ↗
  24. Catch threats before they escalate with real-time Identity Telemetry

    Identity governance helps control who should have access, but periodic reviews alone may not reveal attacks as they happen. tenfold Software explains how real-time identity telemetry can help security teams investigate suspicious activity…

    Fuente: BleepingComputer ↗
  25. 101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

    Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project…

    Fuente: The Hacker News ↗
  26. Scans for Wordfence Protected Websites, (Tue, Sep 29th)

    Starting yesterday, our sensors picked up a small number of scans for "wordfence-waf.php". This particular script is used by Wordfence, a solution to protect WordPress sites. During the Wordfence install, the wordpress-waf.php file will…

    Fuente: SANS ISC ↗
  27. Una campaña automatizada saquea servidores de desarrollo Vite expuestos para robar secretos de AWS y Azure

    Una oleada de escaneos masivos está buscando servidores de desarrollo de Vite publicados en Internet para extraer ficheros sensibles y hacerse con credenciales de AWS y Microsoft Azure. Los ataques explotan CVE-2026-39364, un fallo que…

    Fuente: Una al día ↗
  28. Reco Raises $55 Million for Agentic Security

    The company will use the funds to expand its sales, partnerships, channels, and customer support teams.

    Fuente: SecurityWeek ↗
  29. Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

    The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands.

    Fuente: SecurityWeek ↗
  30. Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims

    According to Dodo Pizza, the potentially compromised information included customers’ names, addresses, email addresses, phone numbers, dates of birth and order details.

    Fuente: The Record ↗
  31. Arizona Supreme Court says hackers stole residents’ personal data

    A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.

    Fuente: The Record ↗
  32. Pentagon Personnel Agency Data Breach Impacts 3 Million People

    The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense.

    Fuente: SecurityWeek ↗
  33. Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks

    Rig provides an identity dependencies graph to distinguish between legitimate users and rogue AI agents

    Fuente: SecurityWeek ↗
  34. Vietnamese man charged in $16 million 'pig butchering' crypto scam

    A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. [...]

    Fuente: BleepingComputer ↗
  35. Four Cyber Threats Harboring Big Plans for the Future

    - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations.

    Fuente: SecurityWeek ↗
  36. OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training

    The GPT-6.1 Astra model was slated to debut in ChatGPT and Codex in October, but it fell short of expectations.

    Fuente: SecurityWeek ↗
  37. Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

    Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest,…

    Fuente: KrebsOnSecurity ↗ También en: BleepingComputer, SecurityWeek
  38. Múltiples vulnerabilidades en T-CPE301K 4G Mini WiFi Router de Shenzhen Dbit Network Equipment

    Múltiples vulnerabilidades en T-CPE301K 4G Mini WiFi Router de Shenzhen Dbit Network Equipment Mar, 29/09/2026 - 11:58 Aviso Recursos Afectados T-CPE301K 4G Mini WiFi Router (Dbit). Descripción INCIBE ha coordinado la publicación de 2…

    Fuente: INCIBE-CERT ↗
  39. OpenAI cancela el lanzamiento de GPT-6.1 Astra: su propio equipo de seguridad ha visto que el modelo no era fiable

    OpenAI ha dejado en suspenso GPT-6.1 Astra, el modelo que planeaba lanzar en octubre, después de que sus propios investigadores descubrieran que el sistema no se comportaba de forma suficientemente fiable durante las pruebas internas. La…

    Fuente: Xataka ↗
  40. Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

    The malware framework uses a modular architecture and a custom executable file format for long-term persistence.

    Fuente: SecurityWeek ↗
  41. Kiteworks patches critical flaw, brings customer systems online

    American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. [...]

    Fuente: BleepingComputer ↗
  42. Apple patches CoreGraphics zero-day flaw exploited in attacks

    Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]

    Fuente: BleepingComputer ↗
  43. Múltiples vulnerabilidades en WatchGuard AP de WatchGuard

    Múltiples vulnerabilidades en WatchGuard AP de WatchGuard Mar, 29/09/2026 - 09:22 Aviso Recursos Afectados WatchGuard AP, versiones 1.0 y posteriores, pero anteriores a la 3.4.8. Descripción Yukusawa18 ha informado sobre una de las 2…

    Fuente: INCIBE-CERT ↗
  44. ● Explotada activamente

    Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

    Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds…

    Fuente: The Hacker News ↗ También en: SANS ISC, SecurityWeek
  45. ENISA alerta de que los ataques a proveedores amplían el impacto de las ciberamenazas en la UE

    Las dependencias tecnológicas pueden convertir un incidente que afecta a un proveedor en un problema para numerosas organizaciones. Esa es una de las principales conclusiones del ENISA Threat Landscape 2026, un informe que examina las…

    Fuente: Red Seguridad ↗
  46. Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog

    The platform combines open source software and a reference system design to keep AI agents within set boundaries.

    Fuente: SecurityWeek ↗ También en: Dark Reading
  47. Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers

    The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.

    Fuente: Dark Reading ↗
  48. One Packet Can Crash OT Servers in Industrial Sectors

    A high-severity zero-day vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments.

    Fuente: Dark Reading ↗
  49. Barcelona Cybersecurity Congress analizará el impacto de la IA en la ciberseguridad industrial

    Barcelona Cybersecurity Congress (BCC), la plataforma comercial y divulgativa europea de ciberseguridad, reunirá en su séptima edición a algunos de los mayores expertos en este ámbito para analizar su impacto en la actividad industrial a…

    Fuente: CyberSecurity News ↗
  50. Alertan del fraude que se activa al mover el ratón y simula el bloqueo del navegador

    Un simple movimiento del ratón puede activar una estafa de soporte técnico que simula la pérdida de control del equipo. La campaña, analizada por Netskope Threat Labs, transforma un clic publicitario en una falsa alerta y en un aparente…

    Fuente: CyberSecurity News ↗
  51. Japan's Keio confirms ransomware attack disrupted business systems

    Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...]

    Fuente: BleepingComputer ↗
  52. Times Car confirms data breach affecting 6.6 million user accounts

    Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]

    Fuente: BleepingComputer ↗
  53. Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts

    The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.

    Fuente: Dark Reading ↗
  54. ● Explotada activamente

    Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

    The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.

    Fuente: SecurityWeek ↗ También en: The Record
  55. Misconfigured Supabase apps expose data in over 16,000 databases

    Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. [...]

    Fuente: BleepingComputer ↗
  56. AI Agents Are Privileged Users; Who Is Auditing Their Access?

    Enterprises regularly rigorously monitor human employees, while autonomous AI agents quietly operate with broad privileges that could turn them into the next generation of insider threats.

    Fuente: Dark Reading ↗
  57. IAM for AI agents: A Practical Enterprise Framework

    What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of…

    Fuente: The Hacker News ↗
  58. Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

    The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain…

    Fuente: The Hacker News ↗
  59. Modulate Raises $25 Million to Advance Deepfake Detection

    The misuse and abuse of AI-generated voice is growing. Modulate’s intention is to allow real time detection and intervention.

    Fuente: SecurityWeek ↗
  60. New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections

    A New Mexico jury has found Facebook liable for deceiving users about privacy protections on the platform.

    Fuente: SecurityWeek ↗ También en: The Record
  61. Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions

    A purported ad-blocker exfiltrates reams of sensitive information, and benefits from having Google's stamp of approval despite researcher warnings.

    Fuente: Dark Reading ↗
  62. JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack

    The "agentic threat actor" may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases.

    Fuente: Dark Reading ↗ También en: BleepingComputer
  63. Call for Presentations Open for 2026 CISO Forum Virtual Summit

    SecurityWeek seeks original, vendor-neutral presentations that help cybersecurity leaders navigate emerging threats, strengthen resilience, and address the strategic challenges facing today’s enterprise security programs.

    Fuente: SecurityWeek ↗
  64. 80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

    Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how…

    Fuente: BleepingComputer ↗
  65. Cyberattack on Polish medical software provider exposes patient data

    Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to hit the country’s medical sector in recent months.

    Fuente: The Record ↗
  66. Former US soldier gets nearly six-year sentence for hacking, extorting telecoms

    A former soldier in the U.S. Army was sentenced to more than five years in federal prison after pleading guilty to hacking into several telecommunications companies and leaking sensitive records.

    Fuente: The Record ↗
  67. Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon

    Cameron John Wagenius was sentenced to 70 months in prison for stealing information from the wireless carriers.

    Fuente: SecurityWeek ↗
  68. Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway

    The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.

    Fuente: NCSC-UK ↗
  69. DC Health Agency Exposes 400,000 Beneficiary Records

    The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed.

    Fuente: SecurityWeek ↗
  70. OpenAI frena en seco el entrenamiento de sus modelos más potentes: sus agentes de IA se han vuelto a descontrolar

    OpenAI ha detenido el entrenamiento de sus modelos de IA más avanzados tras una serie de incidentes inesperados, incluyendo el de un modelo de prueba que encontró la forma de acceder a una red pública. Según cuenta The Verge, el incidente…

    Fuente: Xataka ↗
  71. Correos y SMS suplantan a la DGT para robar tus datos con falsas multas

    Correos y SMS suplantan a la DGT para robar tus datos con falsas multas Lun, 28/09/2026 - 12:09 Aviso Recursos Afectados Personas que hayan recibido estas comunicaciones, especialmente quienes hayan accedido al enlace y facilitado…

    Fuente: INCIBE ↗
  72. Ciberataque contra Adif y Renfe con Inteligencia Artificial avanzada

    El sector de las infraestructuras críticas de transporte en España permanece en alerta tras confirmarse un ciberataque grave contra las empresas ferroviarias Adif y Renfe. Una banda de ciberdelincuentes logró comprometer la seguridad…

    Fuente: Red Seguridad ↗
  73. Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

    The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised.

    Fuente: SecurityWeek ↗
  74. Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist

    Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. [...]

    Fuente: BleepingComputer ↗
  75. Creíamos que el hackeo de Renfe había expuesto correos y nombres. Eso solo era la punta del iceberg

    El pasado viernes supimos que Renfe había sufrido un ciberataque que logró acceso a los sistemas de Adif. Inicialmente el problema parecía ser limitado, porque se habló de robo de nombres y correos electrónicos, sin acceso a información…

    Fuente: Xataka ↗
  76. Múltiples vulnerabilidades en TPVEnlanube

    Múltiples vulnerabilidades en TPVEnlanube Lun, 28/09/2026 - 09:53 Aviso Recursos Afectados TPVEnlanube. Descripción INCIBE ha coordinado la publicación de 3 vulnerabilidades de severidad media que afectan a TPVEnlanube, un software para…

    Fuente: INCIBE-CERT ↗
  77. US soldier gets 70 months in prison for extorting 10 tech, telecom firms

    A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. [...]

    Fuente: BleepingComputer ↗
  78. ● Explotada activamente

    Múltiples vulnerabilidades en productos de Citrix

    Múltiples vulnerabilidades en productos de Citrix Lun, 28/09/2026 - 08:51 Aviso Recursos Afectados Las siguientes versiones compatibles de NetScaler ADC y NetScaler Gateway:NetScaler ADC y NetScaler Gateway 14.1, anteriores a…

    Fuente: INCIBE-CERT ↗
  79. CISA orders feds to patch exploited Citrix flaws by Wednesday

    The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]

    Fuente: BleepingComputer ↗
  80. OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email

    OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website. [...]

    Fuente: BleepingComputer ↗