Noticias de ciberseguridad · semana del 28 sept al 4 oct 2026
Lo más relevante de la actualidad en ciberseguridad, con enlace a la fuente original.
Police dismantle KillSec ransomware gang allegedly led by 16-year-old
An international law enforcement operation dubbed "Operation KillSwitch" seized the KillSec ransomware gang's data leak site and servers, led to three arrests, and identified a 16-year-old as the group's alleged administrator. [...]
Fuente: BleepingComputer ↗ También en: Dark ReadingLos 10 peores ciberataques de la historia se podrían haber evitado: las claves para proteger tu empresa
Cada vez que se produce un gran ciberataque surge la misma sensación: que las organizaciones están indefensas frente a delincuentes cada vez más sofisticados. Sin embargo, un análisis de algunos de los incidentes de seguridad más graves…
Fuente: CyberSecurity News ↗Autonomous AI agents tried to hack US, Canadian government websites
Autonomous AI agents using aggressive strategies attempted to hack U.S. and Canadian government websites to find school and divorce statistics. [...]
Fuente: BleepingComputer ↗Iranian accused of hacking American universities extradited from Montenegro
An Iranian national accused by the U.S. of taking part in dozens of breaches involving the theft of academic data and intellectual property has been extradited from Montenegro.
Fuente: The Record ↗Microsoft says threat actors are ahead in the early AI race
Microsoft says cyberattackers are currently benefiting from artificial intelligence faster than defenders, allowing threat actors to speed up vulnerability discovery, malware development, and post-compromise activity while security teams…
Fuente: BleepingComputer ↗OpenAI software attempted to secretly scrape data from dozens of prominent websites
The findings, released Thursday by Asymmetric Security, are just the latest example of rogue behavior spurred by OpenAI’s software.
Fuente: The Record ↗Researchers find Chinese hacking campaigns targeting AI firms, Asian governments
Two separate reports by cybersecurity companies highlight China-linked hacking operations, including a phishing campaign that impersonated Western experts.
Fuente: The Record ↗Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks
Fifteen years after coining the framework, John Kindervag insists zero trust still works in the AI era—if you get the implementation right.
Fuente: SecurityWeek ↗Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains
Hybrid risk intelligence company Osavul has raised $10 million in a Series A funding round led by 33N Ventures.
Fuente: SecurityWeek ↗Teenager suspected of leading KillSec ransomware group as law enforcement seizes servers and leak site
On 30 September 2026, law enforcement took control of KillSec’s leak site, securing at least 110 terabytes of data against further unauthorised access. The cybercrime group used the site to threaten organisations with the publication of…
Fuente: Europol ↗ También en: SecurityWeek, The Record, The Hacker NewsThreatsDay: AI-Powered Zero-Day Chain, 543K Live Secrets, Model Inspection RCE and 13 More Stories
This week, the useful words are boring ones: inspect, cache, compile, store, trust. Each sounds harmless. Each can become an attack path when a system does a little more than people expect. A model check can run code. A cache can mix up…
Fuente: The Hacker News ↗La IA como peligro crítico para la ciberseguridad
Hace apenas unos años, relacionar la Inteligencia Artificial con la ciberseguridad evocaba situaciones de ciencia-ficción de un futuro lejano casi inimaginable. Hoy es un riesgo inmediato que, según algunos ciberexpertos, podría llegar a…
Fuente: Red Seguridad ↗WordPress Backdoor Rebuilds Itself After Cleanup Using Files, Database, and Shared Memory
Cybersecurity researchers have shed light on a WordPress compromise in which threat actors deployed multiple persistence mechanisms to ensure that the final payload kept returning without having to infect the site again. The backdoor has…
Fuente: The Hacker News ↗Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass
Rob Juncker is chief product and technology officer at Mimecast. Is he a hacker? “Unequivocally yes,” he says.
Fuente: SecurityWeek ↗Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says
PwC’s survey found that only 22% of leaders would use fully autonomous AI for cyber defense, while just 21% are implementing quantum-resistant security measures.
Fuente: SecurityWeek ↗The Day-One Hole in Zero Trust Architecture
Zero Trust can verify users once they are established, but onboarding creates a gap where organizations must decide who to trust before strong authentication exists. Specops explains why identity verification should begin before…
Fuente: BleepingComputer ↗Kiteworks patches max severity code injection vulnerability
Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution. [...]
Fuente: BleepingComputer ↗AI Has Changed Attack Speed, Not Security Fundamentals
As AI accelerates vulnerability discovery and exploitation, so-called virtual patching still comes down to defense-in-depth and strong application security fundamentals.
Fuente: SecurityWeek ↗Warlock Ransomware Hits Large Spanish, Portuguese Orgs
A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places.
Fuente: Dark Reading ↗- ● Explotada activamente
Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets
Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits…
Fuente: The Hacker News ↗ También en: SecurityWeek Cyberattack on major Polish invoicing platform exposes customer data
One of Poland’s major online invoicing platforms suffered a data breach that may have exposed information belonging to its users, their customers and business partners.
Fuente: The Record ↗Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation
The Series B brings the AI-powered offensive security startup’s total funding to roughly $445 million only seven months after its public launch.
Fuente: SecurityWeek ↗Microsoft enables Windows settings backup by default for orgs
Microsoft announced that Windows settings backup and restore is now enabled by default on all Microsoft Entra-joined or Microsoft Entra hybrid-joined enterprise systems upgraded to Windows 11 26H2. [...]
Fuente: BleepingComputer ↗Treasury Blacklists Most-Wanted ATM Malware Developer and His Network
The US government continues its crackdown on Tren de Aragua over its ATM jackpotting scheme.
Fuente: SecurityWeek ↗DIVD says Zammad zero-days enabled AI-driven network breach
The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]
Fuente: BleepingComputer ↗ También en: SecurityWeek- ● Explotada activamente
Cisco warns of new SD-WAN zero-day exploited in attacks
Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...]
Fuente: BleepingComputer ↗ También en: The Hacker News, INCIBE-CERT, SecurityWeek, The Hacker News Pentagon Personnel Agency Data Breach Impacts 3 Million People
The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense.
Fuente: SecurityWeek ↗ También en: BleepingComputerOver 543,000 valid credentials exposed in public GitHub repositories
More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data. [...]
Fuente: BleepingComputer ↗ También en: SecurityWeekMúltiples vulnerabilidades en Entradium de Crocantickets
Múltiples vulnerabilidades en Entradium de Crocantickets Jue, 01/10/2026 - 10:04 Aviso Recursos Afectados Entradium. Descripción INCIBE ha coordinado la publicación de 4 vulnerabilidades de severidad media que afectan a Entradium de…
Fuente: INCIBE-CERT ↗Google Launches Gemini 4 Argon With Guardrail-Free Access for Vetted Defenders
The company says its new frontier AI model found a critical vulnerability in software used by hospitals worldwide.
Fuente: SecurityWeek ↗Metamask discloses security incident affecting its infrastructure
On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. [...]
Fuente: BleepingComputer ↗Ejecución remota de código en Next.js de Vercel
Ejecución remota de código en Next.js de Vercel Jue, 01/10/2026 - 08:58 Aviso Recursos Afectados Next.js, versiones desde la 16.2.0 y anteriores a la 16.3.6, cuando se utiliza la implementación de ImageResponse para Node.js y se…
Fuente: INCIBE-CERT ↗- ● Explotada activamente
Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks
Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds…
Fuente: The Hacker News ↗ También en: SANS ISC, SecurityWeek, Dark Reading, INCIBE-CERT, The Hacker News ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)
Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing applications...
Fuente: SANS ISC ↗FTC is Investigating OpenAI and Anthropic Over Possible risks to Consumers
An FTC spokesperson confirmed the investigation but declined further comment.
Fuente: SecurityWeek ↗US sanctions 10 over ATM malware scheme tied to Tren de Aragua
Treasury’s Office of Foreign Assets Control (OFAC) targeted multiple Venezuelan nationals and several companies they control that are part of the effort to launder the money stolen from dozens of ATMs.
Fuente: The Record ↗Hackers Use ChatGPT Custom GPTs in ClickFix Attacks
The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands.
Fuente: SecurityWeek ↗ También en: The Hacker News, Dark ReadingLas universidades se convierten en un objetivo valioso para estafas laborales y secuestro de cuentas
Estudiantes universitarios, antiguos alumnos y personal educativo se han convertido en objetivos recurrentes de estafas laborales, becas falsas e incidentes de secuestro. Los más jóvenes pueden tener menos experiencia con la…
Fuente: CyberSecurity News ↗II Congreso de Ciberseguridad para Pymes
CyberMadrid, el Clúster de Ciberseguridad de Madrid, celebró el pasado 29 de septiembre, el II Congreso de Ciberseguridad para Pymes, una jornada que reunió en el Centro de Innovación DIGITALIZA MADRID a representantes institucionales,…
Fuente: CyberSecurity News ↗Trump, Tech Giants Strike Voluntary AI Safety Accord
The new White House Accord on so-called "Super Intelligence" calls on companies to implement greater controls and oversight over AI safety.
Fuente: Dark Reading ↗Russian state hackers use new RedFlick technique to push malware
The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. [...]
Fuente: BleepingComputer ↗Automakers routinely share personally identifiable connected-car data with third parties, report says
A new study reveals fresh details about how drivers are exposed to a web of large corporations participating in the advertising ecosystem.
Fuente: The Record ↗After reports on suicide deaths, Pentagon puts Cyber Command on notice
An August 31 memo obtained by Recorded Future News shows that the Pentagon's assistant secretary for cyber policy made specific demands of U.S. Cyber Command leadership after reports of a cluster of suicide deaths.
Fuente: The Record ↗El phishing sigue llegando por correo, pero ya no se ve igual
El phishing ya no siempre muestra señales evidentes. Detectar y contener el ataque con rapidez es clave para reducir los daños.
Fuente: WeLiveSecurity ↗Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation
Vulnerability disclosures continue to skyrocket, doubling over the course of the year to more than 10,000 each month, Google researchers warned.
Fuente: The Record ↗As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half
New Swimlane research underscores a paradox: While AI detection and response is essential to giving defenders an edge, one in four security pros say AI limits their skill development.
Fuente: Dark Reading ↗Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks
Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other…
Fuente: The Hacker News ↗CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. [...]
Fuente: BleepingComputer ↗Una campaña explota dos zero-days críticos en Citrix NetScaler para instalar web shells y moverse por la red
Dos vulnerabilidades zero-day críticas en Citrix NetScaler se explotan activamente para lograr ejecución remota de código sin autenticación y desplegar web shells y herramientas de tunelización. Citrix ya publicó parches y CISA ha marcado…
Fuente: Una al día ↗Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net
The APT actor is using a new tactic, dubbed "RedFlick," against Ukrainian-linked targets such as NGOs, think tanks, and journalists to deploy its CosmicPulse backdoor.
Fuente: Dark Reading ↗Google: AI Is Changing the Pace and Profile of Vulnerability Discovery
Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.
Fuente: SecurityWeek ↗AI's Third Wave: Coworkers Break the Security Model That Worked for Agents
Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped…
Fuente: BleepingComputer ↗Mobile malware warning from Ukrainian researchers includes iPhone exploit kit
'Hit and run' iPhone malware known as DarkSword is part of a wave of Russian attacks on iOS and Android devices, according to Ukraine's SSSCIP.
Fuente: The Record ↗Microsoft to block Entra ID script injection attacks starting October
Microsoft has reminded customers that the Entra ID authentication system will get better protection against external script injection attacks starting next month. [...]
Fuente: BleepingComputer ↗WatchGuard Patches Critical Fireware OS Code Injection Vulnerability
WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS.
Fuente: SecurityWeek ↗- ● Explotada activamente
CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The…
Fuente: The Hacker News ↗ También en: SecurityWeek, Una al día, The Record, BleepingComputer, The Hacker News, SecurityWeek TeamViewer urges users to patch severe flaws “as soon as possible”
Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...]
Fuente: BleepingComputer ↗Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox.
Fuente: SecurityWeek ↗Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters
The Russian state-backed hacking group Star Blizzard has expanded its phishing operations this year, using a new technique that makes it easier to infect victims with malware.
Fuente: The Record ↗Incibe presenta al Equipo España para el European Cybersecurity Challenge 2026
El Instituto Nacional de Ciberseguridad, entidad pública encargada de difundir y proteger la ciberseguridad en nuestro país, presenta al equipo español que participará en el European Cybersecurity Challenge, que se celebrará del 12 al 16…
Fuente: Red Seguridad ↗Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit
Attacks by autonomous AI agents are moving out of the lab and into the courtroom, raising unsettled questions about who is liable for what agents do.
Fuente: SecurityWeek ↗Bitget hacked via zero-day in third-party security products
Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. [...]
Fuente: BleepingComputer ↗Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks
The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor.
Fuente: SecurityWeek ↗ShinyHunters Defiant After FBI Calls on Members to Come Forward
In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI.
Fuente: SecurityWeek ↗Múltiples vulnerabilidades en G520 Series Cellular Gateway de Lantronix
Múltiples vulnerabilidades en G520 Series Cellular Gateway de Lantronix Mié, 30/09/2026 - 11:34 Aviso Recursos Afectados Lantronix G520 Series Cellular Gateway, versión de firmware 2.6.0.4R6_stable. Descripción Ievgen Bondarenko ha…
Fuente: INCIBE-CERT ↗Inyección SQL en la aplicación de Integratec
Inyección SQL en la aplicación de Integratec Mié, 30/09/2026 - 10:08 Aviso Recursos Afectados App Integratec. Descripción INCIBE ha coordinado la publicación de una vulnerabilidad de severidad crítica que afecta a la aplicación de…
Fuente: INCIBE-CERT ↗El MCCE reúne al talento universitario en ciberseguridad con la tercera edición de Talent4Cyber
El Ministerio de Defensa, a través del Mando Conjunto del Ciberespacio (MCCE), ha lanzado la tercera edición de Talent4Cyber, el Attack & Defense Hackathon para estudiantes universitarios sobre materia de ciberseguridad y defensa. En…
Fuente: Red Seguridad ↗Múltiples vulnerabilidades en TeamViewer
Múltiples vulnerabilidades en TeamViewer Mié, 30/09/2026 - 09:28 Aviso Recursos Afectados TeamViewer Full Client (Windows, Linux y MacOS): versiones anteriores a la 15.82;TeamViewer Full Client v15.64 (Windows 7 y 8): versiones anteriores…
Fuente: INCIBE ↗Múltiples vulnerabilidades en Instant On APs de HPE Networking
Múltiples vulnerabilidades en Instant On APs de HPE Networking Mié, 30/09/2026 - 09:15 Aviso Recursos Afectados HPE Networking Instant On APs, versiones 3.4.1.0 y anteriores. Descripción HPE Networking ha publicado 18 vulnerabilidades: 5…
Fuente: INCIBE-CERT ↗Múltiples vulnerabilidades en WatchGuard AP de WatchGuard
Múltiples vulnerabilidades en WatchGuard AP de WatchGuard Mar, 29/09/2026 - 09:22 Aviso Recursos Afectados WatchGuard AP, versiones 1.0 y posteriores, pero anteriores a la 3.4.8. Descripción Yukusawa18 ha informado sobre una de las 2…
Fuente: INCIBE-CERT ↗ También en: INCIBE-CERTSouth Africa Seeks Help After Cyberattack Targets Air Traffic Control
As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network.
Fuente: Dark Reading ↗High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL
Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries.
Fuente: SecurityWeek ↗Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development
President Donald Trump on Tuesday said that he and a large group of leaders of artificial intelligence companies had signed a voluntary accord that will include internal and external reviews during a meeting at the White House aimed at…
Fuente: SecurityWeek ↗Microsoft is rolling out Linux container support to WSL
Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available. [...]
Fuente: BleepingComputer ↗Signal adds encypted local backup support to iOS, desktop apps
Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows). [...]
Fuente: BleepingComputer ↗Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution
A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.
Fuente: Dark Reading ↗Former US Air Force members sent to prison over BEC attacks
Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]
Fuente: BleepingComputer ↗ También en: The RecordMás de la mitad de los usuarios españoles de internet ha sufrido fraudes online
El fraude online no deja de evolucionar. La accesibilidad de la Inteligencia Artificial está permitiendo a los ciberdelincuentes automatizar y sofisticar sus ciberataques a gran escala. Así lo demuestra un estudio de mercado de Kaspersky,…
Fuente: CyberSecurity News ↗Las webs que “desnudan” con IA alcanzan los 40 millones de visitas al mes
Una fotografía publicada en una red social, una imagen de perfil o cualquier otra foto accesible online puede convertirse, sin conocimiento ni consentimiento de la persona que aparece en ella, en la materia prima para crear un falso…
Fuente: CyberSecurity News ↗Custom ChatGPTs push ClickFix attacks to deploy RAT malware
Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]
Fuente: BleepingComputer ↗Controversial spyware firm Paragon to go public by end of year
The company plans to close the deal around the end of the year at which point Paragon will begin trading on Nasdaq under the REDLattice umbrella.
Fuente: The Record ↗OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference
Altman made a slew of product announcements and updates, including the company’s new agents, called Dots.
Fuente: SecurityWeek ↗FBI tells ShinyHunters members to turn themselves in after recent arrest
The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders. [...]
Fuente: BleepingComputer ↗OpenAI apologizes for agents breaching Australian government websites without authorization
The artificial intelligence giant acknowledged it botched its response to the incidents and should have done more to promptly notify and work with the Australian government in the days after it discovered the breaches.
Fuente: The Record ↗French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks
An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency…
Fuente: The Hacker News ↗Windows 11 2026 Update released, here's everything you need to know
Microsoft has started rolling out Windows 11 26H2 to everyone, and while it's this year's big annual feature update, you probably won't notice a massive difference after installing it. [...]
Fuente: BleepingComputer ↗DARPA Selects Xint to Use AI in Securing Military Messaging Apps
The AIxCC competition winner will analyze messaging app code and compiled binaries for vulnerabilities, with technology that could also help commercial customers secure their software.
Fuente: SecurityWeek ↗Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor
Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to…
Fuente: The Hacker News ↗New Spectre v2 attack variant leaks Linux root password hash in minutes
A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average. [...]
Fuente: BleepingComputer ↗Cloudflare Announces Public Certificate Authority for the Post-Quantum Web
Automated certificates for everyone, built for today, and hardened for the era of quantum computing.
Fuente: Dark Reading ↗New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks
Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel
Fuente: SecurityWeek ↗New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses
A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system…
Fuente: The Hacker News ↗PDF malicioso: uno de los principales formatos utilizados en amenazas por correo electrónico en América Latina
Los PDF son uno de los formatos más utilizados por los ciberdelincuentes para distribuir phishing y malware por correo electrónico en América Latina.
Fuente: WeLiveSecurity ↗Automated AI agent used to breach cybersecurity nonprofit DIVD
The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." [...]
Fuente: BleepingComputer ↗Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks
Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at…
Fuente: The Hacker News ↗ También en: Dark ReadingRemoteThreat Launches With $7 Million for Offensive Operations Platform
The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe.
Fuente: SecurityWeek ↗Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown
Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During the shutdown, this activity…
Fuente: The Hacker News ↗Catch threats before they escalate with real-time Identity Telemetry
Identity governance helps control who should have access, but periodic reviews alone may not reveal attacks as they happen. tenfold Software explains how real-time identity telemetry can help security teams investigate suspicious activity…
Fuente: BleepingComputer ↗101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent
Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project…
Fuente: The Hacker News ↗Scans for Wordfence Protected Websites, (Tue, Sep 29th)
Starting yesterday, our sensors picked up a small number of scans for "wordfence-waf.php". This particular script is used by Wordfence, a solution to protect WordPress sites. During the Wordfence install, the wordpress-waf.php file will…
Fuente: SANS ISC ↗Una campaña automatizada saquea servidores de desarrollo Vite expuestos para robar secretos de AWS y Azure
Una oleada de escaneos masivos está buscando servidores de desarrollo de Vite publicados en Internet para extraer ficheros sensibles y hacerse con credenciales de AWS y Microsoft Azure. Los ataques explotan CVE-2026-39364, un fallo que…
Fuente: Una al día ↗Reco Raises $55 Million for Agentic Security
The company will use the funds to expand its sales, partnerships, channels, and customer support teams.
Fuente: SecurityWeek ↗Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims
According to Dodo Pizza, the potentially compromised information included customers’ names, addresses, email addresses, phone numbers, dates of birth and order details.
Fuente: The Record ↗Arizona Supreme Court says hackers stole residents’ personal data
A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.
Fuente: The Record ↗Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks
Rig provides an identity dependencies graph to distinguish between legitimate users and rogue AI agents
Fuente: SecurityWeek ↗Vietnamese man charged in $16 million 'pig butchering' crypto scam
A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. [...]
Fuente: BleepingComputer ↗Four Cyber Threats Harboring Big Plans for the Future
- AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations.
Fuente: SecurityWeek ↗OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training
The GPT-6.1 Astra model was slated to debut in ChatGPT and Codex in October, but it fell short of expectations.
Fuente: SecurityWeek ↗Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation
Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest,…
Fuente: KrebsOnSecurity ↗ También en: BleepingComputer, SecurityWeekMúltiples vulnerabilidades en T-CPE301K 4G Mini WiFi Router de Shenzhen Dbit Network Equipment
Múltiples vulnerabilidades en T-CPE301K 4G Mini WiFi Router de Shenzhen Dbit Network Equipment Mar, 29/09/2026 - 11:58 Aviso Recursos Afectados T-CPE301K 4G Mini WiFi Router (Dbit). Descripción INCIBE ha coordinado la publicación de 2…
Fuente: INCIBE-CERT ↗OpenAI cancela el lanzamiento de GPT-6.1 Astra: su propio equipo de seguridad ha visto que el modelo no era fiable
OpenAI ha dejado en suspenso GPT-6.1 Astra, el modelo que planeaba lanzar en octubre, después de que sus propios investigadores descubrieran que el sistema no se comportaba de forma suficientemente fiable durante las pruebas internas. La…
Fuente: Xataka ↗Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft
The malware framework uses a modular architecture and a custom executable file format for long-term persistence.
Fuente: SecurityWeek ↗Kiteworks patches critical flaw, brings customer systems online
American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. [...]
Fuente: BleepingComputer ↗Apple patches CoreGraphics zero-day flaw exploited in attacks
Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]
Fuente: BleepingComputer ↗ENISA alerta de que los ataques a proveedores amplían el impacto de las ciberamenazas en la UE
Las dependencias tecnológicas pueden convertir un incidente que afecta a un proveedor en un problema para numerosas organizaciones. Esa es una de las principales conclusiones del ENISA Threat Landscape 2026, un informe que examina las…
Fuente: Red Seguridad ↗Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog
The platform combines open source software and a reference system design to keep AI agents within set boundaries.
Fuente: SecurityWeek ↗ También en: Dark ReadingDual NetScaler Zero-Days Trigger Chaos for Citrix Customers
The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.
Fuente: Dark Reading ↗One Packet Can Crash OT Servers in Industrial Sectors
A high-severity zero-day vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments.
Fuente: Dark Reading ↗Barcelona Cybersecurity Congress analizará el impacto de la IA en la ciberseguridad industrial
Barcelona Cybersecurity Congress (BCC), la plataforma comercial y divulgativa europea de ciberseguridad, reunirá en su séptima edición a algunos de los mayores expertos en este ámbito para analizar su impacto en la actividad industrial a…
Fuente: CyberSecurity News ↗Alertan del fraude que se activa al mover el ratón y simula el bloqueo del navegador
Un simple movimiento del ratón puede activar una estafa de soporte técnico que simula la pérdida de control del equipo. La campaña, analizada por Netskope Threat Labs, transforma un clic publicitario en una falsa alerta y en un aparente…
Fuente: CyberSecurity News ↗Japan's Keio confirms ransomware attack disrupted business systems
Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...]
Fuente: BleepingComputer ↗Times Car confirms data breach affecting 6.6 million user accounts
Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]
Fuente: BleepingComputer ↗Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts
The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.
Fuente: Dark Reading ↗- ● Explotada activamente
Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign
The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.
Fuente: SecurityWeek ↗ También en: The Record Misconfigured Supabase apps expose data in over 16,000 databases
Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. [...]
Fuente: BleepingComputer ↗AI Agents Are Privileged Users; Who Is Auditing Their Access?
Enterprises regularly rigorously monitor human employees, while autonomous AI agents quietly operate with broad privileges that could turn them into the next generation of insider threats.
Fuente: Dark Reading ↗IAM for AI agents: A Practical Enterprise Framework
What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of…
Fuente: The Hacker News ↗Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M
The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain…
Fuente: The Hacker News ↗Modulate Raises $25 Million to Advance Deepfake Detection
The misuse and abuse of AI-generated voice is growing. Modulate’s intention is to allow real time detection and intervention.
Fuente: SecurityWeek ↗New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections
A New Mexico jury has found Facebook liable for deceiving users about privacy protections on the platform.
Fuente: SecurityWeek ↗ También en: The RecordChrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions
A purported ad-blocker exfiltrates reams of sensitive information, and benefits from having Google's stamp of approval despite researcher warnings.
Fuente: Dark Reading ↗JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack
The "agentic threat actor" may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases.
Fuente: Dark Reading ↗ También en: BleepingComputerCall for Presentations Open for 2026 CISO Forum Virtual Summit
SecurityWeek seeks original, vendor-neutral presentations that help cybersecurity leaders navigate emerging threats, strengthen resilience, and address the strategic challenges facing today’s enterprise security programs.
Fuente: SecurityWeek ↗80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking
Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how…
Fuente: BleepingComputer ↗Cyberattack on Polish medical software provider exposes patient data
Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to hit the country’s medical sector in recent months.
Fuente: The Record ↗Former US soldier gets nearly six-year sentence for hacking, extorting telecoms
A former soldier in the U.S. Army was sentenced to more than five years in federal prison after pleading guilty to hacking into several telecommunications companies and leaking sensitive records.
Fuente: The Record ↗Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon
Cameron John Wagenius was sentenced to 70 months in prison for stealing information from the wireless carriers.
Fuente: SecurityWeek ↗Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway
The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.
Fuente: NCSC-UK ↗DC Health Agency Exposes 400,000 Beneficiary Records
The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed.
Fuente: SecurityWeek ↗OpenAI frena en seco el entrenamiento de sus modelos más potentes: sus agentes de IA se han vuelto a descontrolar
OpenAI ha detenido el entrenamiento de sus modelos de IA más avanzados tras una serie de incidentes inesperados, incluyendo el de un modelo de prueba que encontró la forma de acceder a una red pública. Según cuenta The Verge, el incidente…
Fuente: Xataka ↗Correos y SMS suplantan a la DGT para robar tus datos con falsas multas
Correos y SMS suplantan a la DGT para robar tus datos con falsas multas Lun, 28/09/2026 - 12:09 Aviso Recursos Afectados Personas que hayan recibido estas comunicaciones, especialmente quienes hayan accedido al enlace y facilitado…
Fuente: INCIBE ↗Ciberataque contra Adif y Renfe con Inteligencia Artificial avanzada
El sector de las infraestructuras críticas de transporte en España permanece en alerta tras confirmarse un ciberataque grave contra las empresas ferroviarias Adif y Renfe. Una banda de ciberdelincuentes logró comprometer la seguridad…
Fuente: Red Seguridad ↗Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability
The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised.
Fuente: SecurityWeek ↗Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist
Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. [...]
Fuente: BleepingComputer ↗Creíamos que el hackeo de Renfe había expuesto correos y nombres. Eso solo era la punta del iceberg
El pasado viernes supimos que Renfe había sufrido un ciberataque que logró acceso a los sistemas de Adif. Inicialmente el problema parecía ser limitado, porque se habló de robo de nombres y correos electrónicos, sin acceso a información…
Fuente: Xataka ↗Múltiples vulnerabilidades en TPVEnlanube
Múltiples vulnerabilidades en TPVEnlanube Lun, 28/09/2026 - 09:53 Aviso Recursos Afectados TPVEnlanube. Descripción INCIBE ha coordinado la publicación de 3 vulnerabilidades de severidad media que afectan a TPVEnlanube, un software para…
Fuente: INCIBE-CERT ↗US soldier gets 70 months in prison for extorting 10 tech, telecom firms
A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. [...]
Fuente: BleepingComputer ↗- ● Explotada activamente
Múltiples vulnerabilidades en productos de Citrix
Múltiples vulnerabilidades en productos de Citrix Lun, 28/09/2026 - 08:51 Aviso Recursos Afectados Las siguientes versiones compatibles de NetScaler ADC y NetScaler Gateway:NetScaler ADC y NetScaler Gateway 14.1, anteriores a…
Fuente: INCIBE-CERT ↗ CISA orders feds to patch exploited Citrix flaws by Wednesday
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]
Fuente: BleepingComputer ↗OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email
OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website. [...]
Fuente: BleepingComputer ↗