Ciberseguridad desde Málaga · Redes, anzuelos y amenazas

Noticias de ciberseguridad · semana del 28 sept al 4 oct 2026

Lo más relevante de la actualidad en ciberseguridad, con enlace a la fuente original.

  1. ● Explotada activamente

    Cisco warns of new SD-WAN zero-day exploited in attacks

    Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...]

    Fuente: BleepingComputer ↗ También en: The Hacker News, INCIBE-CERT, SecurityWeek
  2. Google Rolls Out Gemini 4 Argon to Trusted Cyber Defenders, Plans Guardrail-Free Version

    Google on Wednesday announced its latest frontier artificial intelligence (AI) model, Gemini 4 Argon, that it said is being rolled out to a set of trusted cyber defenders through its Fairwind Program. "It delivers frontier performance in…

    Fuente: The Hacker News ↗ También en: SecurityWeek
  3. Metamask discloses security incident affecting its infrastructure

    On Thursday, cryptocurrency wallet provider MetaMask has disclosed an ongoing infrastructure security incident affecting some of its infrastructure. [...]

    Fuente: BleepingComputer ↗
  4. Ejecución remota de código en Next.js de Vercel

    Ejecución remota de código en Next.js de Vercel Jue, 01/10/2026 - 08:58 Aviso Recursos Afectados Next.js, versiones desde la 16.2.0 y anteriores a la 16.3.6, cuando se utiliza la implementación de ImageResponse para Node.js y se…

    Fuente: INCIBE-CERT ↗
  5. ● Explotada activamente

    Apple Patches CoreGraphics Flaw Possibly Exploited in Targeted Attacks

    Apple has released security updates to address a vulnerability in older versions of iOS, iPadOS, and macOS that it said may have been exploited in targeted attacks. The vulnerability, tracked as CVE-2026-86950, refers to an out-of-bounds…

    Fuente: The Hacker News ↗ También en: SANS ISC, SecurityWeek, Dark Reading, INCIBE-CERT, The Hacker News
  6. ScreenConnect Client (Ab)used by Attackers, (Thu, Oct 1st)

    Threat Actors do not always use top-notch techniques or very complex malware to perform their attacks. Sometimes, they just abuse of existing applications...

    Fuente: SANS ISC ↗
  7. Bitget hacked via zero-day in third-party security products

    Cryptocurrency exchange Bitget revealed today that attackers who stole $387.5 million last week breached its systems after exploiting a zero-day flaw in third-party security products. [...]

    Fuente: BleepingComputer ↗ También en: The Hacker News
  8. MetaMask Security Incident Prompts Exit of Affected Ethereum Validators

    MetaMask on Thursday said it's responding to what it described as an "ongoing security incident" impacting part of its infrastructure. "We are actively addressing and remediating the issue internally, in coordination with external…

    Fuente: The Hacker News ↗
  9. Citrix NetScaler Post-Exploitation Payload Creates Superuser, Maps Web Shell to CSS-Like URLs

    Threat actors have been observed exploiting a critical pre-authentication command injection vulnerability in Citrix NetScaler ADC and NetScaler Gateway to drop web shells and attempt theft of configuration data. LevelBlue's Threat Hunt…

    Fuente: The Hacker News ↗
  10. FTC is Investigating OpenAI and Anthropic Over Possible risks to Consumers

    An FTC spokesperson confirmed the investigation but declined further comment.

    Fuente: SecurityWeek ↗
  11. US sanctions 10 over ATM malware scheme tied to Tren de Aragua

    Treasury’s Office of Foreign Assets Control (OFAC) targeted multiple Venezuelan nationals and several companies they control that are part of the effort to launder the money stolen from dozens of ATMs.

    Fuente: The Record ↗
  12. Hackers Use ChatGPT Custom GPTs in ClickFix Attacks

    The personalized versions of ChatGPT were used to impersonate legitimate products and trick users into executing PowerShell commands.

    Fuente: SecurityWeek ↗ También en: The Hacker News, Dark Reading
  13. Las universidades se convierten en un objetivo valioso para estafas laborales y secuestro de cuentas

    Estudiantes universitarios, antiguos alumnos y personal educativo se han convertido en objetivos recurrentes de estafas laborales, becas falsas e incidentes de secuestro. Los más jóvenes pueden tener menos experiencia con la…

    Fuente: CyberSecurity News ↗
  14. II Congreso de Ciberseguridad para Pymes

    CyberMadrid, el Clúster de Ciberseguridad de Madrid, celebró el pasado 29 de septiembre, el II Congreso de Ciberseguridad para Pymes, una jornada que reunió en el Centro de Innovación DIGITALIZA MADRID a representantes institucionales,…

    Fuente: CyberSecurity News ↗
  15. Trump, Tech Giants Strike Voluntary AI Safety Accord

    The new White House Accord on so-called "Super Intelligence" calls on companies to implement greater controls and oversight over AI safety.

    Fuente: Dark Reading ↗
  16. Russian state hackers use new RedFlick technique to push malware

    The Russian state actor Star Blizzard has been using a new malware installation tactic dubbed "RedFlick" to deploy its signature CosmicPulse backdoor. [...]

    Fuente: BleepingComputer ↗
  17. Automakers routinely share personally identifiable connected-car data with third parties, report says

    A new study reveals fresh details about how drivers are exposed to a web of large corporations participating in the advertising ecosystem.

    Fuente: The Record ↗
  18. DIVD says Zammad zero-days enabled AI-driven network breach

    The Dutch Institute for Vulnerability Disclosure (DIVD) says that the breach of its network was possible by exploiting a chain of two zero-day vulnerabilities in the open-source Zammad ticketing system. [...]

    Fuente: BleepingComputer ↗
  19. After reports on suicide deaths, Pentagon puts Cyber Command on notice

    An August 31 memo obtained by Recorded Future News shows that the Pentagon's assistant secretary for cyber policy made specific demands of U.S. Cyber Command leadership after reports of a cluster of suicide deaths.

    Fuente: The Record ↗
  20. Google: Vulnerability disclosures double to 10,000 per month as AI fuels exploitation

    Vulnerability disclosures continue to skyrocket, doubling over the course of the year to more than 10,000 each month, Google researchers warned.

    Fuente: The Record ↗
  21. As AI Reshapes the SOC Career Ladder, Satisfaction Rises for 91%, but Entry Gets Harder for Nearly Half

    New Swimlane research underscores a paradox: While AI detection and response is essential to giving defenders an edge, one in four security pros say AI limits their skill development.

    Fuente: Dark Reading ↗
  22. Over 543,000 valid credentials exposed in public GitHub repositories

    More than 543,000 credentials exposed in public GitHub repositories were still valid in July despite the platform's security measures to prevent accidental leaks of sensitive data. [...]

    Fuente: BleepingComputer ↗
  23. ● Explotada activamente

    Attackers Exploit Zimbra Flaw to Deploy Web Shells and Harvest Authentication Secrets

    Threat actors have weaponized a now-patched security flaw in Zimbra Collaboration Suite (ZCS) to deploy web shells and access mailbox data, according to findings from the Microsoft Security Research team. The attack exploits…

    Fuente: The Hacker News ↗
  24. Attackers Abuse MSP360 to Deploy ScreenConnect in Dual-RMM Phishing Attacks

    Microsoft has warned of phishing campaigns distributing an installer for the MSP360 Remote Monitoring and Management (RMM) software under the guise of meeting invitations, PDF-themed lures, software update prompts, and other…

    Fuente: The Hacker News ↗
  25. CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. [...]

    Fuente: BleepingComputer ↗
  26. Una campaña explota dos zero-days críticos en Citrix NetScaler para instalar web shells y moverse por la red

    Dos vulnerabilidades zero-day críticas en Citrix NetScaler se explotan activamente para lograr ejecución remota de código sin autenticación y desplegar web shells y herramientas de tunelización. Citrix ya publicó parches y CISA ha marcado…

    Fuente: Una al día ↗
  27. Russia's Star Blizzard Ditches ClickFix to Widen Phishing Net

    The APT actor is using a new tactic, dubbed "RedFlick," against Ukrainian-linked targets such as NGOs, think tanks, and journalists to deploy its CosmicPulse backdoor.

    Fuente: Dark Reading ↗
  28. Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

    Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution.

    Fuente: SecurityWeek ↗
  29. AI's Third Wave: Coworkers Break the Security Model That Worked for Agents

    Persistent AI coworkers may operate continuously with standing access, creating identity risks that existing security models were not designed to handle. Token Security explains why these agents need their own identities, owners, scoped…

    Fuente: BleepingComputer ↗
  30. Mobile malware warning from Ukrainian researchers includes iPhone exploit kit

    'Hit and run' iPhone malware known as DarkSword is part of a wave of Russian attacks on iOS and Android devices, according to Ukraine's SSSCIP.

    Fuente: The Record ↗
  31. Microsoft to block Entra ID script injection attacks starting October

    Microsoft has reminded customers that the Entra ID authentication system will get better protection against external script injection attacks starting next month. [...]

    Fuente: BleepingComputer ↗
  32. WatchGuard Patches Critical Fireware OS Code Injection Vulnerability

    WatchGuard has rolled out patches for 15 code execution, DoS, authorization, and path traversal bugs in Fireware OS.

    Fuente: SecurityWeek ↗
  33. ● Explotada activamente

    CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The…

    Fuente: The Hacker News ↗ También en: SecurityWeek, Una al día, The Record, BleepingComputer, The Hacker News, SecurityWeek
  34. TeamViewer urges users to patch severe flaws “as soon as possible”

    Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...]

    Fuente: BleepingComputer ↗
  35. Chrome, Firefox Updates Patch Over 100 Vulnerabilities

    Some of the flaws could allow remote attackers to execute arbitrary code or escape the browser sandbox.

    Fuente: SecurityWeek ↗
  36. Russian FSB-linked hackers scale up phishing attacks against Ukraine supporters

    The Russian state-backed hacking group Star Blizzard has expanded its phishing operations this year, using a new technique that makes it easier to infect victims with malware.

    Fuente: The Record ↗
  37. Incibe presenta al Equipo España para el European Cybersecurity Challenge 2026

    El Instituto Nacional de Ciberseguridad, entidad pública encargada de difundir y proteger la ciberseguridad en nuestro país, presenta al equipo español que participará en el European Cybersecurity Challenge, que se celebrará del 12 al 16…

    Fuente: Red Seguridad ↗
  38. Anthropic Flags AI Agent Liability Risks as OpenAI Faces Hacking Lawsuit

    Attacks by autonomous AI agents are moving out of the lab and into the courtroom, raising unsettled questions about who is liable for what agents do.

    Fuente: SecurityWeek ↗
  39. Russian APT Star Blizzard Uses ‘RedFlick’ Infection Chain in Recent Attacks

    The state-sponsored group has launched larger-scale phishing campaigns to deploy the CosmicPulse backdoor.

    Fuente: SecurityWeek ↗
  40. ShinyHunters Defiant After FBI Calls on Members to Come Forward

    In the wake of a suspected leader’s arrest, ShinyHunters says it never intended to publish data stolen from the FBI.

    Fuente: SecurityWeek ↗
  41. Múltiples vulnerabilidades en G520 Series Cellular Gateway de Lantronix

    Múltiples vulnerabilidades en G520 Series Cellular Gateway de Lantronix Mié, 30/09/2026 - 11:34 Aviso Recursos Afectados Lantronix G520 Series Cellular Gateway, versión de firmware 2.6.0.4R6_stable. Descripción Ievgen Bondarenko ha…

    Fuente: INCIBE-CERT ↗
  42. Inyección SQL en la aplicación de Integratec

    Inyección SQL en la aplicación de Integratec Mié, 30/09/2026 - 10:08 Aviso Recursos Afectados App Integratec. Descripción INCIBE ha coordinado la publicación de una vulnerabilidad de severidad crítica que afecta a la aplicación de…

    Fuente: INCIBE-CERT ↗
  43. El MCCE reúne al talento universitario en ciberseguridad con la tercera edición de Talent4Cyber

    El Ministerio de Defensa, a través del Mando Conjunto del Ciberespacio (MCCE), ha lanzado la tercera edición de Talent4Cyber, el Attack & Defense Hackathon para estudiantes universitarios sobre materia de ciberseguridad y defensa. En…

    Fuente: Red Seguridad ↗
  44. Múltiples vulnerabilidades en TeamViewer

    Múltiples vulnerabilidades en TeamViewer Mié, 30/09/2026 - 09:28 Aviso Recursos Afectados TeamViewer Full Client (Windows, Linux y MacOS): versiones anteriores a la 15.82;TeamViewer Full Client v15.64 (Windows 7 y 8): versiones anteriores…

    Fuente: INCIBE ↗
  45. Múltiples vulnerabilidades en Instant On APs de HPE Networking

    Múltiples vulnerabilidades en Instant On APs de HPE Networking Mié, 30/09/2026 - 09:15 Aviso Recursos Afectados HPE Networking Instant On APs, versiones 3.4.1.0 y anteriores. Descripción HPE Networking ha publicado 18 vulnerabilidades: 5…

    Fuente: INCIBE-CERT ↗
  46. Múltiples vulnerabilidades en WatchGuard AP de WatchGuard

    Múltiples vulnerabilidades en WatchGuard AP de WatchGuard Mar, 29/09/2026 - 09:22 Aviso Recursos Afectados WatchGuard AP, versiones 1.0 y posteriores, pero anteriores a la 3.4.8. Descripción Yukusawa18 ha informado sobre una de las 2…

    Fuente: INCIBE-CERT ↗ También en: INCIBE-CERT
  47. South Africa Seeks Help After Cyberattack Targets Air Traffic Control

    As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network.

    Fuente: Dark Reading ↗
  48. High-Severity Vulnerabilities Patched in OpenSSL, WolfSSL

    Roughly a dozen vulnerabilities have been patched in each of the open source cryptographic libraries.

    Fuente: SecurityWeek ↗
  49. Trump Says Top Tech Firms Have Signed Accord to ‘Self-Police’ AI Development

    President Donald Trump on Tuesday said that he and a large group of leaders of artificial intelligence companies had signed a voluntary accord that will include internal and external reviews during a meeting at the White House aimed at…

    Fuente: SecurityWeek ↗
  50. Microsoft is rolling out Linux container support to WSL

    Microsoft is taking Windows Subsystem for Linux beyond just running Linux distributions, as WSL Containers is now generally available. [...]

    Fuente: BleepingComputer ↗
  51. Signal adds encypted local backup support to iOS, desktop apps

    Signal, the secure messaging app, released version 8.30, completing the rollout of its secure backups feature across all supported operating systems (Android, iOS, Linux, macOS, and Windows). [...]

    Fuente: BleepingComputer ↗
  52. Unsloth Studio Flaw Turns Routine Model Inspection Into Code Execution

    A patched Unsloth Studio vulnerability allows malicious AI models to execute arbitrary Python code during inspection, via the trust_remote_code setting.

    Fuente: Dark Reading ↗
  53. Former US Air Force members sent to prison over BEC attacks

    Two former members of the United States Air Force were sentenced to a combined 189 months in federal prison for their roles in a multi-year series of business email compromise (BEC) scams and phishing campaigns. [...]

    Fuente: BleepingComputer ↗ También en: The Record
  54. Más de la mitad de los usuarios españoles de internet ha sufrido fraudes online

    El fraude online no deja de evolucionar. La accesibilidad de la Inteligencia Artificial está permitiendo a los ciberdelincuentes automatizar y sofisticar sus ciberataques a gran escala. Así lo demuestra un estudio de mercado de Kaspersky,…

    Fuente: CyberSecurity News ↗
  55. Las webs que “desnudan” con IA alcanzan los 40 millones de visitas al mes

    Una fotografía publicada en una red social, una imagen de perfil o cualquier otra foto accesible online puede convertirse, sin conocimiento ni consentimiento de la persona que aparece en ella, en la materia prima para crear un falso…

    Fuente: CyberSecurity News ↗
  56. Custom ChatGPTs push ClickFix attacks to deploy RAT malware

    Custom variants of OpenAI's ChatGPT promoted in sponsored Google results are directing unsuspecting users to malicious sites that use ClickFix attacks to deliver malware. [...]

    Fuente: BleepingComputer ↗
  57. Controversial spyware firm Paragon to go public by end of year

    The company plans to close the deal around the end of the year at which point Paragon will begin trading on Nasdaq under the REDLattice umbrella.

    Fuente: The Record ↗
  58. OpenAI CEO Announces New AI Agent and Avoids Mention of Security Concerns at Developer Conference

    Altman made a slew of product announcements and updates, including the company’s new agents, called Dots.

    Fuente: SecurityWeek ↗
  59. FBI tells ShinyHunters members to turn themselves in after recent arrest

    The FBI is warning members of the ShinyHunters extortion group to turn themselves in after Dutch police arrested a man the bureau described as one of the group's alleged leaders. [...]

    Fuente: BleepingComputer ↗
  60. OpenAI apologizes for agents breaching Australian government websites without authorization

    The artificial intelligence giant acknowledged it botched its response to the incidents and should have done more to promptly notify and work with the Australian government in the days after it discovered the breaches.

    Fuente: The Record ↗
  61. French Tax Data Theft Using Stolen Staff Passwords Went Undetected for Seven Weeks

    An attacker used stolen passwords of staff at France's tax administration to take tax data on hundreds of thousands of taxpayers and businesses in June and July. Neither the tax administration nor France's national cybersecurity agency…

    Fuente: The Hacker News ↗
  62. Windows 11 2026 Update released, here's everything you need to know

    Microsoft has started rolling out Windows 11 26H2 to everyone, and while it's this year's big annual feature update, you probably won't notice a massive difference after installing it. [...]

    Fuente: BleepingComputer ↗
  63. DARPA Selects Xint to Use AI in Securing Military Messaging Apps

    The AIxCC competition winner will analyze messaging app code and compiled binaries for vulnerabilities, with technology that could also help commercial customers secure their software.

    Fuente: SecurityWeek ↗
  64. Russia's Star Blizzard Targets 100+ Organizations With Fake Event Invites to Deliver Backdoor

    Russian state hackers known as Star Blizzard have been using fake event invitations to trick people into installing a backdoor on their Windows computers, according to Microsoft. The campaigns, aimed at people and organizations tied to…

    Fuente: The Hacker News ↗
  65. New Spectre v2 attack variant leaks Linux root password hash in minutes

    A new Branch Target Reuse (BTR) attack has been devised that can recover root password hashes on Intel computers running Linux in 3-5 minutes on average. [...]

    Fuente: BleepingComputer ↗
  66. Cloudflare Announces Public Certificate Authority for the Post-Quantum Web

    Automated certificates for everyone, built for today, and hardened for the era of quantum computing.

    Fuente: Dark Reading ↗
  67. New Spectre v2 Variant Exposes Intel, AMD, Arm CPUs to Data Leaks

    Branch Target Reuse (BTR) is a new Spectre v2 attack targeting JIT compilers in web browsers, language runtimes, and the operating system kernel

    Fuente: SecurityWeek ↗
  68. New Spectre-v2 BTR Attack Leaks Linux Memory Despite Existing Defenses

    A group of academics from VUSec and Scuola Superiore Sant'Anna have disclosed details of a new Spectre CPU vulnerability variant that affects Just-In-Time (JIT) engines present in web browsers, language runtimes, and the operating system…

    Fuente: The Hacker News ↗
  69. PDF malicioso: uno de los principales formatos utilizados en amenazas por correo electrónico en América Latina

    Los PDF son uno de los formatos más utilizados por los ciberdelincuentes para distribuir phishing y malware por correo electrónico en América Latina.

    Fuente: WeLiveSecurity ↗
  70. Automated AI agent used to breach cybersecurity nonprofit DIVD

    The Dutch Institute for Vulnerability Disclosure (DIVD) suffered an AI-driven cyberattack that the organization described as "loud and very, very messy." [...]

    Fuente: BleepingComputer ↗
  71. Hackers Use NeedyMantis to Maintain Long-Term Access in Breached Networks

    Hackers have used a malware family called NeedyMantis to maintain long-term access to networks they had already breached, Microsoft said in a technical analysis. The malware has been seen in a small number of targeted intrusions at…

    Fuente: The Hacker News ↗ También en: Dark Reading
  72. RemoteThreat Launches With $7 Million for Offensive Operations Platform

    The company emerged from stealth mode with pre-seed funding from Osage University Partners and DataTribe.

    Fuente: SecurityWeek ↗
  73. Kiteworks Fixes Critical Flaw Found During Nine-Hour Precautionary Shutdown

    Kiteworks on Monday said it worked with federal intelligence authorities over the weekend as it identified and addressed a critical security vulnerability during the scheduled precautionary shutdown. "During the shutdown, this activity…

    Fuente: The Hacker News ↗
  74. Catch threats before they escalate with real-time Identity Telemetry

    Identity governance helps control who should have access, but periodic reviews alone may not reveal attacks as they happen. tenfold Software explains how real-time identity telemetry can help security teams investigate suspicious activity…

    Fuente: BleepingComputer ↗
  75. 101 Malicious npm Packages Add Developers' WhatsApp Accounts to Groups Without Consent

    Cybersecurity researchers have identified a cluster of 101 npm packages that are used to trap developers into a WhatsApp group subscriber campaign dubbed PhantomSub. "The malicious packages abuse the 'Baileys' WhatsApp open source project…

    Fuente: The Hacker News ↗
  76. Scans for Wordfence Protected Websites, (Tue, Sep 29th)

    Starting yesterday, our sensors picked up a small number of scans for "wordfence-waf.php". This particular script is used by Wordfence, a solution to protect WordPress sites. During the Wordfence install, the wordpress-waf.php file will…

    Fuente: SANS ISC ↗
  77. Una campaña automatizada saquea servidores de desarrollo Vite expuestos para robar secretos de AWS y Azure

    Una oleada de escaneos masivos está buscando servidores de desarrollo de Vite publicados en Internet para extraer ficheros sensibles y hacerse con credenciales de AWS y Microsoft Azure. Los ataques explotan CVE-2026-39364, un fallo que…

    Fuente: Una al día ↗
  78. Reco Raises $55 Million for Agentic Security

    The company will use the funds to expand its sales, partnerships, channels, and customer support teams.

    Fuente: SecurityWeek ↗
  79. Russian pizza chain with 1,500 locations confirms cyberattack following hacker claims

    According to Dodo Pizza, the potentially compromised information included customers’ names, addresses, email addresses, phone numbers, dates of birth and order details.

    Fuente: The Record ↗
  80. Arizona Supreme Court says hackers stole residents’ personal data

    A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.

    Fuente: The Record ↗
  81. Pentagon Personnel Agency Data Breach Impacts 3 Million People

    The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense.

    Fuente: SecurityWeek ↗
  82. Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks

    Rig provides an identity dependencies graph to distinguish between legitimate users and rogue AI agents

    Fuente: SecurityWeek ↗
  83. Vietnamese man charged in $16 million 'pig butchering' crypto scam

    A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. [...]

    Fuente: BleepingComputer ↗
  84. Four Cyber Threats Harboring Big Plans for the Future

    - AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations.

    Fuente: SecurityWeek ↗
  85. OpenAI Calls Off GPT-6.1 Astra Launch, Details Safety Cases for Frontier Training

    The GPT-6.1 Astra model was slated to debut in ChatGPT and Codex in October, but it fell short of expectations.

    Fuente: SecurityWeek ↗
  86. Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

    Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest,…

    Fuente: KrebsOnSecurity ↗ También en: BleepingComputer, SecurityWeek
  87. Múltiples vulnerabilidades en T-CPE301K 4G Mini WiFi Router de Shenzhen Dbit Network Equipment

    Múltiples vulnerabilidades en T-CPE301K 4G Mini WiFi Router de Shenzhen Dbit Network Equipment Mar, 29/09/2026 - 11:58 Aviso Recursos Afectados T-CPE301K 4G Mini WiFi Router (Dbit). Descripción INCIBE ha coordinado la publicación de 2…

    Fuente: INCIBE-CERT ↗
  88. OpenAI cancela el lanzamiento de GPT-6.1 Astra: su propio equipo de seguridad ha visto que el modelo no era fiable

    OpenAI ha dejado en suspenso GPT-6.1 Astra, el modelo que planeaba lanzar en octubre, después de que sus propios investigadores descubrieran que el sistema no se comportaba de forma suficientemente fiable durante las pruebas internas. La…

    Fuente: Xataka ↗
  89. Daemon Tools Hackers’ NeedyMantis Malware Dissected by Microsoft

    The malware framework uses a modular architecture and a custom executable file format for long-term persistence.

    Fuente: SecurityWeek ↗
  90. Kiteworks patches critical flaw, brings customer systems online

    American tech company Kiteworks has lifted a precautionary advisory asking customers to shut down systems after patching a critical vulnerability. [...]

    Fuente: BleepingComputer ↗
  91. Apple patches CoreGraphics zero-day flaw exploited in attacks

    Apple released security updates to fix a zero-day vulnerability exploited in "extremely sophisticated" targeted attacks on iOS devices. [...]

    Fuente: BleepingComputer ↗
  92. ENISA alerta de que los ataques a proveedores amplían el impacto de las ciberamenazas en la UE

    Las dependencias tecnológicas pueden convertir un incidente que afecta a un proveedor en un problema para numerosas organizaciones. Esa es una de las principales conclusiones del ENISA Threat Landscape 2026, un informe que examina las…

    Fuente: Red Seguridad ↗
  93. Nvidia Unveils AI Agent Safety Platform With Hardware-Based Watchdog

    The platform combines open source software and a reference system design to keep AI agents within set boundaries.

    Fuente: SecurityWeek ↗ También en: Dark Reading
  94. Dual NetScaler Zero-Days Trigger Chaos for Citrix Customers

    The critical vulnerabilities, which impact default configurations of NetScaler products, essentially give attackers a skeleton key to customers' networks.

    Fuente: Dark Reading ↗
  95. One Packet Can Crash OT Servers in Industrial Sectors

    A high-severity zero-day vulnerability affects the TDengine time-series database used across industrial, IoT, energy, and automotive environments.

    Fuente: Dark Reading ↗
  96. Barcelona Cybersecurity Congress analizará el impacto de la IA en la ciberseguridad industrial

    Barcelona Cybersecurity Congress (BCC), la plataforma comercial y divulgativa europea de ciberseguridad, reunirá en su séptima edición a algunos de los mayores expertos en este ámbito para analizar su impacto en la actividad industrial a…

    Fuente: CyberSecurity News ↗
  97. Alertan del fraude que se activa al mover el ratón y simula el bloqueo del navegador

    Un simple movimiento del ratón puede activar una estafa de soporte técnico que simula la pérdida de control del equipo. La campaña, analizada por Netskope Threat Labs, transforma un clic publicitario en una falsa alerta y en un aparente…

    Fuente: CyberSecurity News ↗
  98. Japan's Keio confirms ransomware attack disrupted business systems

    Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...]

    Fuente: BleepingComputer ↗
  99. Times Car confirms data breach affecting 6.6 million user accounts

    Japanese car-sharing service Times Car has confirmed that approximately 6.6 million user accounts were compromised in a cyberattack disclosed late last week. [...]

    Fuente: BleepingComputer ↗
  100. Carbonato Botnet Puts an AI Agent on Hacked Docker Hosts

    The botnet uses the open source Hermes Agent AI framework to execute commands via Telegram and steal AI API keys from exposed Docker hosts.

    Fuente: Dark Reading ↗
  101. ● Explotada activamente

    Google Warns of ShinyHunters’ Fresh Oracle PeopleSoft Campaign

    The extortion group has modified its exploit in new attacks targeting the PeopleSoft vulnerability CVE-2026-35273.

    Fuente: SecurityWeek ↗ También en: The Record
  102. Misconfigured Supabase apps expose data in over 16,000 databases

    Researchers found more than 16,000 misconfigured Supabase databases exposing readable tables with personally identifiable information, passwords, or authentication tokens. [...]

    Fuente: BleepingComputer ↗
  103. AI Agents Are Privileged Users; Who Is Auditing Their Access?

    Enterprises regularly rigorously monitor human employees, while autonomous AI agents quietly operate with broad privileges that could turn them into the next generation of insider threats.

    Fuente: Dark Reading ↗
  104. IAM for AI agents: A Practical Enterprise Framework

    What is IAM for AI agents? AI agents authenticate, invoke tools, and act across enterprise systems with delegated authority. IAM for AI Agents is the identity-control architecture that governs those actors. This guide covers the limits of…

    Fuente: The Hacker News ↗
  105. Bitget Says Attacker Exploited Third-Party Security Product Flaw to Steal $388M

    The attacker who stole about $388 million from the cryptocurrency exchange Bitget gained access through a vulnerability in a third-party security product the exchange used, Bitget said on Monday. The attacker exploited the flaw to obtain…

    Fuente: The Hacker News ↗
  106. Modulate Raises $25 Million to Advance Deepfake Detection

    The misuse and abuse of AI-generated voice is growing. Modulate’s intention is to allow real time detection and intervention.

    Fuente: SecurityWeek ↗
  107. New Mexico Jury Finds Facebook Liable for Deceiving Users About Privacy Protections

    A New Mexico jury has found Facebook liable for deceiving users about privacy protections on the platform.

    Fuente: SecurityWeek ↗ También en: The Record
  108. Chrome Store Hosts 'Poper Blocker' Spyware Downloaded by Millions

    A purported ad-blocker exfiltrates reams of sensitive information, and benefits from having Google's stamp of approval despite researcher warnings.

    Fuente: Dark Reading ↗
  109. JadePuffer AI Actor Compromises Azure Tenant in Destructive Cloud Attack

    The "agentic threat actor" may have used exposed credentials to access resources and delete cloud-based storage, applications, and databases.

    Fuente: Dark Reading ↗ También en: BleepingComputer
  110. Call for Presentations Open for 2026 CISO Forum Virtual Summit

    SecurityWeek seeks original, vendor-neutral presentations that help cybersecurity leaders navigate emerging threats, strengthen resilience, and address the strategic challenges facing today’s enterprise security programs.

    Fuente: SecurityWeek ↗
  111. 80,000+ Organizations Had AI Logins Stolen: From Shadow AI to LLMjacking

    Infostealer logs exposed AI account credentials and sessions tied to more than 80,000 corporate domains, creating risks ranging from stolen conversations to LLMjacking. SOCRadar examines the growing market for stolen AI logins and how…

    Fuente: BleepingComputer ↗
  112. Cyberattack on Polish medical software provider exposes patient data

    Hackers stole personal data from a Polish healthcare software provider in the latest cyberattack to hit the country’s medical sector in recent months.

    Fuente: The Record ↗
  113. Former US soldier gets nearly six-year sentence for hacking, extorting telecoms

    A former soldier in the U.S. Army was sentenced to more than five years in federal prison after pleading guilty to hacking into several telecommunications companies and leaking sensitive records.

    Fuente: The Record ↗
  114. Prison Sentence for Former US Soldier Who Hacked AT&T and Verizon

    Cameron John Wagenius was sentenced to 70 months in prison for stealing information from the wireless carriers.

    Fuente: SecurityWeek ↗
  115. Exploitation of vulnerabilities affecting Citrix NetScaler ADC and Citrix NetScaler Gateway

    The NCSC is urging UK organisations to promptly mitigate vulnerabilities affecting Citrix NetScaler ADC and Gateway, two of which are being actively exploited.

    Fuente: NCSC-UK ↗
  116. DC Health Agency Exposes 400,000 Beneficiary Records

    The Medicaid IDs and other information of Medicaid and DC Healthcare Alliance beneficiaries were exposed.

    Fuente: SecurityWeek ↗
  117. OpenAI frena en seco el entrenamiento de sus modelos más potentes: sus agentes de IA se han vuelto a descontrolar

    OpenAI ha detenido el entrenamiento de sus modelos de IA más avanzados tras una serie de incidentes inesperados, incluyendo el de un modelo de prueba que encontró la forma de acceder a una red pública. Según cuenta The Verge, el incidente…

    Fuente: Xataka ↗
  118. Correos y SMS suplantan a la DGT para robar tus datos con falsas multas

    Correos y SMS suplantan a la DGT para robar tus datos con falsas multas Lun, 28/09/2026 - 12:09 Aviso Recursos Afectados Personas que hayan recibido estas comunicaciones, especialmente quienes hayan accedido al enlace y facilitado…

    Fuente: INCIBE ↗
  119. Ciberataque contra Adif y Renfe con Inteligencia Artificial avanzada

    El sector de las infraestructuras críticas de transporte en España permanece en alerta tras confirmarse un ciberataque grave contra las empresas ferroviarias Adif y Renfe. Una banda de ciberdelincuentes logró comprometer la seguridad…

    Fuente: Red Seguridad ↗
  120. Kiteworks Urges Server Shutdown, Finds Advanced Forms Vulnerability

    The company says the measure was precautionary and that it has no evidence of Kiteworks or customer systems being compromised.

    Fuente: SecurityWeek ↗
  121. Bitget resumes Bitcoin withdrawals after $387.5 million crypto heist

    Cryptocurrency exchange Bitget has resumed Bitcoin withdrawals suspended after suspected North Korean hackers breached its systems last week and stole over $350 million. [...]

    Fuente: BleepingComputer ↗
  122. Creíamos que el hackeo de Renfe había expuesto correos y nombres. Eso solo era la punta del iceberg

    El pasado viernes supimos que Renfe había sufrido un ciberataque que logró acceso a los sistemas de Adif. Inicialmente el problema parecía ser limitado, porque se habló de robo de nombres y correos electrónicos, sin acceso a información…

    Fuente: Xataka ↗
  123. Múltiples vulnerabilidades en TPVEnlanube

    Múltiples vulnerabilidades en TPVEnlanube Lun, 28/09/2026 - 09:53 Aviso Recursos Afectados TPVEnlanube. Descripción INCIBE ha coordinado la publicación de 3 vulnerabilidades de severidad media que afectan a TPVEnlanube, un software para…

    Fuente: INCIBE-CERT ↗
  124. US soldier gets 70 months in prison for extorting 10 tech, telecom firms

    A former U.S. Army soldier has been sentenced to 70 months in prison for hacking and extorting at least 10 U.S. technology and telecommunications companies between April 2023 and December 2024. [...]

    Fuente: BleepingComputer ↗
  125. ● Explotada activamente

    Múltiples vulnerabilidades en productos de Citrix

    Múltiples vulnerabilidades en productos de Citrix Lun, 28/09/2026 - 08:51 Aviso Recursos Afectados Las siguientes versiones compatibles de NetScaler ADC y NetScaler Gateway:NetScaler ADC y NetScaler Gateway 14.1, anteriores a…

    Fuente: INCIBE-CERT ↗
  126. CISA orders feds to patch exploited Citrix flaws by Wednesday

    The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies over the weekend to secure their systems against attacks exploiting two critical Citrix NetScaler vulnerabilities. [...]

    Fuente: BleepingComputer ↗
  127. OpenAI is preparing “o,” an always-on ChatGPT assistant that could handle email

    OpenAI is testing a new always-on assistant called "o", and references to the unannounced feature briefly showed up on the company's website. [...]

    Fuente: BleepingComputer ↗