Noticias de ciberseguridad · semana del 21 al 27 sept 2026
Lo más relevante de la actualidad en ciberseguridad, con enlace a la fuente original.
2026-014: Critical Vulnerabilities in Citrix NetScaler ADC and Gateway
On 27 September 2026, Citrix published a security bulletin addressing 8 vulnerabilities affecting customer-managed Citrix NetScaler ADC and Citrix NetScaler Gateway, among which 2 critical unauthenticated Remote Code Execution (RCE)…
Fuente: CERT-EU ↗Citrix admins warned to shut down NetScalers over 2 exploited zero-days
Two unpatched Citrix NetScaler zero-day vulnerabilities are reportedly being exploited in attacks, with cybersecurity agencies, security researchers, and IT providers privately warning organizations about the flaws ahead of patches…
Fuente: BleepingComputer ↗[Virtual Event] Cybersecurity Outlook 2027
Fuente: Dark Reading ↗Wireshark 4.6.9 Released, (Sun, Sep 27th)
Wireshark release 4.6.9 fixes 19 vulnerabilities and 16 bugs.
Fuente: SANS ISC ↗Cloudflare fixes Containers cross-tenant flaw exposing customer data
Cloudflare has fixed a vulnerability in Containers and Sandboxes that allowed customers with a Workers Paid account to recover residual data from other customers' containers on the same physical host. [...]
Fuente: BleepingComputer ↗Anthropic turns Claude into an AI marketplace with 2,000+ plugins and connectors
Anthropic has just announced a new Claude Marketplace, and it brings all AI-related tools into one place, including plugins, connectors, agents, and more. [...]
Fuente: BleepingComputer ↗- ● Explotada activamente
Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks
CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28.
Fuente: SecurityWeek ↗ Warning: Two Unpatched Citrix NetScaler RCE Zero-Days Under Active Exploitation
Two new unpatched zero-day vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway appliances that allow remote code execution are being actively exploited in the wild, security firm watchTowr said on September 26. Citrix has not…
Fuente: The Hacker News ↗- ● Explotada activamente
Attackers Bypass WAFs to Exploit Oracle PeopleSoft Flaw and Deploy Web Shells
Google is warning of renewed mass exploitation of a known security vulnerability in Oracle PeopleSoft as part of a campaign targeting multiple sectors globally. The ShinyHunters-linked activity involves the weaponization of CVE-2026-35273…
Fuente: The Hacker News ↗ También en: BleepingComputer Lunex Stealer Abuses AMD Driver to Disable Security Monitoring and Steal Browser Credentials
The Psychedelic Stealer malware distributed via compromised Ukrainian websites using ClickFix-style Cloudflare verification checks is part of a wider malware-as-a-service (MaaS) platform called Lunex. The new findings come from Ontinue,…
Fuente: The Hacker News ↗China and US Agree to Establish AI Safety Channel and Continue Trade and Military Talks
The US and China agreed to set up a communication mechanism for artificial intelligence-related incidents.
Fuente: SecurityWeek ↗Claude Opus 5.5 uses 95% fewer em dashes, but its answers are getting longer
Anthropic's Claude Opus 5.5 appears to be changing how it writes, with new analysis showing fewer obvious AI writing patterns, shorter sentences, and simpler wording compared with Opus 5. [...]
Fuente: BleepingComputer ↗Microsoft pauses KB5002907 update after Office license deactivations
Microsoft has paused the rollout of the KB5002907 Microsoft 365 update after users report that it deactivated, or in some cases completely removed, perpetual Office 2016 and Office 2019 installations. [...]
Fuente: BleepingComputer ↗GitHub Actions re-enabled with Mini Shai-Hulud payload still active
Two third-party GitHub Actions previously compromised in a Mini Shai-Hulud campaign were re-enabled by their maintainer and remained accessible for more than a week despite still pointing to malicious code. [...]
Fuente: BleepingComputer ↗El ciberataque a Renfe y Adif confirma lo que la IA llevaba meses avisando. 500GB de datos de clientes quedan al descubierto
Algo pasaba cuando la web de Adif mostraba un tierno gatito negro y ya lo sabemos: Adif y Renfe han sufrido un ciberataque en el que se han filtrado 500 GB de información privada de sus clientes, como ha adelantado El Mundo. El incidente…
Fuente: Xataka ↗OpenAI's AI agents accidentally uploaded user-provided images to third-party sites
OpenAI says its AI agents uploaded user-provided images to third-party image-hosting services while carrying out research and evaluation tasks. [...]
Fuente: BleepingComputer ↗New x47.c Windows Botnet Weaponizes xAI Grok, AI API Draining
The Windows botnet relies on AI to maintain persistence, using xAI Grok to choose from predefined actions.
Fuente: SecurityWeek ↗Zero Trust for AI Agents Starts With Fixing Zero Visibility
The way we talk about AI agents is shifting, and the way we implement them requires an even more fundamental shift. While earlier discourse focused on how quickly organizations could stand up agents and how much productivity they could…
Fuente: The Hacker News ↗OpenAI Says Its Models Engaged With US Government Websites in New Model Misbehavior Disclosure
OpenAI’s CEO said there is an “extensive and ongoing review related to our agents’ use of internet access during training and evaluation.”
Fuente: SecurityWeek ↗Elementor CSRF Flaw Lets Attackers Take Over Sites After Admin Clicks Crafted Link
Details have emerged about a high-severity security flaw in the Elementor Website Builder WordPress plugin that could be exploited by an unauthenticated attacker to create rogue administrator accounts and take control of a site. The…
Fuente: The Hacker News ↗SharePoint RCE and MikroTik RouterOS Flaws Actively Exploited in the Wild
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added two security flaws impacting Microsoft SharePoint and Mikrotik RouterOS to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active…
Fuente: The Hacker News ↗Kiteworks Urges Customers to Shut Down Systems for 9 Hours Over Possible Cyber Attack
Kiteworks (formerly Accellion) is urging customers to shut down their systems as a precautionary measure for nine hours over the weekend after it received threat intelligence about an imminent cyber attack. "Kiteworks received credible…
Fuente: The Hacker News ↗U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in federal prison today…
Fuente: KrebsOnSecurity ↗Kiteworks urges 6-hour server shutdown over potential zero-day attacks
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent cyberattack. [...]
Fuente: BleepingComputer ↗ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path…
Fuente: BleepingComputer ↗How the CISO CFO Relationship is a Key to Cybersecurity Success
Building a financial bridge: Organizations where CISOs and CFOs align on cybersecurity strategy to protect assets, manage risk and enable business growth are better prepared to face today's threat landscape.
Fuente: Dark Reading ↗Kiteworks urges customers to stop using platform after warning from federal intelligence agencies
Frank Balonis, CISO at Kiteworks, told Recorded Future News that the company “received credible threat intelligence from federal intelligence authorities indicating that a threat actor may attempt to target some Kiteworks systems for…
Fuente: The Record ↗Labcorp to overhaul data security practices, pay $2.3 million fine for cybersecurity failings
Security changes include creating an incident response plan for vendor security failings, limiting how much data Labcorp shares with vendors and building an expansive risk management team charged with tracking vendors’ compliance with…
Fuente: The Record ↗AI Sandbox Escapes: Why Forensic Readiness Matters More Than Containment
When autonomous AI agents "escape the sandbox," the real story isn't rogue machines — it's the same access-control failures we've seen for decades.
Fuente: Dark Reading ↗Elementor WordPress flaw lets attackers create admin accounts
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...]
Fuente: BleepingComputer ↗What We Missed: Google Gemini Joins the AI Escape Party
In this video conversation, Dark Reading editors discuss some of the news they didn't get a chance to cover, from Google Gemini models breaking containment to ShinyHunters ratting on TeamPCP hackers.
Fuente: Dark Reading ↗WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of…
Fuente: The Hacker News ↗ También en: BleepingComputerVibe coding y seguridad: 5 preguntas para evaluar los riesgos de una app
Las aplicaciones desarrolladas mediante vibe coding pueden contener errores difíciles de detectar. Estas claves te ayudarán a evaluar sus riesgos de seguridad y privacidad
Fuente: WeLiveSecurity ↗Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions
Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it's offering up to $250 in free usage credits, so more users can give it a try. [...]
Fuente: BleepingComputer ↗Cross-Site Scripting almacenado de StockAgile de Novadigits technologies
Cross-Site Scripting almacenado de StockAgile de Novadigits technologies Vie, 25/09/2026 - 17:28 Aviso Recursos Afectados API y el panel de gestión de StockAgile. Descripción INCIBE ha coordinado la publicación de 7 vulnerabilidades de…
Fuente: INCIBE-CERT ↗Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthorized transfers involving…
Fuente: The Hacker News ↗ También en: SecurityWeek, The RecordIn Other News: Clop Leak Site Takeover, Docker Botnet Hunts AI Keys, Water Utility Exposure
Noteworthy stories that might have slipped under the radar: BragJack attack against browser AI assistants, TDengine flaw threatens industrial telemetry uptime, Ubuntu update overhaul.
Fuente: SecurityWeek ↗Cyberattack hits Welsh police force, may have affected staff data
Dyfed-Powys Police in Wales said a cyberattack affecting the force disrupted some non-emergency systems and may have compromised staff information.
Fuente: The Record ↗OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex
OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it's unclear when it'll begin rolling out. [...]
Fuente: BleepingComputer ↗With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created by agent…
Fuente: BleepingComputer ↗Stopping IT Worker Scams Requires Revamped HR Process
Training human-resource managers in the latest tactics and warning signs goes a long way toward blunting the threat, but automated analysis can help even more.
Fuente: Dark Reading ↗Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHub Actions are…
Fuente: The Hacker News ↗PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to rely on the same…
Fuente: The Hacker News ↗A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)
Introduction
Fuente: SANS ISC ↗Microsoft plans to deprecate Windows Deployment Services
Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. [...]
Fuente: BleepingComputer ↗CISA Election Security Plan Flags Patching Barriers, Voter Database Attacks
Homeland Security Secretary Markwayne Mullin tasked CISA with developing the plan in July.
Fuente: SecurityWeek ↗Kosovar Owner of Rydox Marketplace Pleads Guilty in US Court
Ardit Kutleshi created and operated Rydox, which allowed miscreants to trade PII and cybercrime tools and services.
Fuente: SecurityWeek ↗OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files
An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister Anthony Albanese said. The portal publishes aggregate figures, such as spending, and…
Fuente: The Hacker News ↗ También en: The RecordThe SOC Doesn't Need to Start Over with Every Alert
Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry. The routine version looks like this. An attacker…
Fuente: The Hacker News ↗Windows, Linux, Android File Notification Systems Leak User Activity
Researchers show that file-change notification systems can leak keystroke timing, browsing activity, and WhatsApp media events.
Fuente: SecurityWeek ↗Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authentication SQL…
Fuente: The Hacker News ↗‘SalesBleed’ Flaws in Salesforce Agentforce Enabled Zero-Click Data Exfiltration
Three vulnerabilities in Salesforce Agentforce allowed hackers to hijack trusted agents, steal data, and launch phishing attacks.
Fuente: SecurityWeek ↗AWS logra la acreditación NATO Restricted para su Región ‘Cloud’ en España
Amazon Web Services (AWS) ha anunciado, el 22 de septiembre, la obtención de las aprobaciones a nivel nacional para procesar información clasificada al nivel de «difusión limitada» (DL) para la región AWS Europa (España) y la acreditación…
Fuente: Red Seguridad ↗La Fundación Borredá abre una nueva etapa para potenciar sus capacidades al servicio de la seguridad
La Fundación Borredá ha iniciado una nueva etapa que tendrá por objetivo consolidar su estrategia como entidad al servicio de la seguridad. Una de las novedades es la incorporación de Rocío Ayala como directora de la entidad, cuyo…
Fuente: Red Seguridad ↗Russia's Hybrid Cyber-Physical War in Europe Heats Up
A storm is raging in the form of cyber sabotage, disinformation, and drone attacks on European nations, particularly those that provide material support to Ukraine.
Fuente: Dark Reading ↗"La certificación ENS de Nivel Alto reconoce nuestra capacidad para ofrecer servicios ‘cloud’ seguros en los entornos más exigentes"
Qualys ha obtenido la certificación del Esquema Nacional de Seguridad (ENS) de Nivel Alto. ¿Qué supone este hito para la compañía? ¿Hasta qué punto cree que puede convertirse en una ventaja competitiva? La certificación ENS de Nivel Alto…
Fuente: Red Seguridad ↗Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk space that earlier…
Fuente: The Hacker News ↗ISC Stormcast For Tuesday, September 22nd, 2026 https://isc.sans.edu/podcastdetail/10104, (Tue, Sep 22nd)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Fuente: SANS ISC ↗ También en: SANS ISC, SANS ISC, SANS ISC'Salesbleed' Exploits Salesforce Agents to Enable Slack Phishing
Agentic AI can smuggle arbitrary instructions from the Web, across multiple apps, into trusted internal communications channels.
Fuente: Dark Reading ↗SectopRAT Returns, Hiding Inside a Legitimate Application
The latest activity from the remote access Trojan (RAT) shows why organizations should monitor the behavior of applications rather than blindly trusting them, experts say.
Fuente: Dark Reading ↗Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the…
Fuente: The Hacker News ↗ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pile. Trusted paths…
Fuente: The Hacker News ↗El Plan IA360: Nuevo paradigma de la IA empresarial en España
El avance exponencial de la inteligencia artificial ha dejado de ser una promesa de futuro para convertirse en el motor del cambio estructural de nuestra sociedad. En este contexto de transformación acelerada, el anuncio gubernamental del…
Fuente: Red Seguridad ↗Placeholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious Content
The "third-party[.]com" domain, commonly used as a documentation placeholder, has been observed serving a ClickFix lure to Windows browsers while displaying a harmless decoy to other users. "third-party[.]com has been a generic…
Fuente: The Hacker News ↗La presión sobre la ciberseguridad de las PyMEs: agentes de IA en expansión, amenazas tradicionales en aceleración
A medida que la inteligencia artificial abre nuevas vías de acceso a los sistemas empresariales y acelera amenazas ya conocidas, las PyMEs necesitan una protección que se adapte a sus recursos, tiempo y capacidades técnicas.
Fuente: WeLiveSecurity ↗3 Cyber Threats That Defined the Summer of 2026
This installment of the Reporters' Notebook video series discusses the impact of AI agents breaching Hugging Face, Fairlife's ransomware attack, and Iranian-linked threat actors compromising a dozen US water systems. It was a busy summer.
Fuente: Dark Reading ↗Hacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic Stealer
An active ClickFix campaign has been observed compromising legitimate Ukrainian business websites to inject bogus Cloudflare verification pages and trick victims into downloading a previously undocumented information stealer called…
Fuente: The Hacker News ↗How to Build a SASE Framework for Modern Cybersecurity
Securing edge computing requires organizations to fundamentally rethink security governance. This step-by-step guide to building a SASE framework provides the path forward. (Third in a three-part series.)
Fuente: Dark Reading ↗Ghost Service Accounts Enable M365 Data Theft in Chile
Even if the organization locks down employee accounts, forgotten and lost service accounts can still undo the organization's entire M365 environment.
Fuente: Dark Reading ↗Prompt-Injection Bug Hits $4B Agentic AI App 'Manus'
AI apps that interpret external data (read: most AI apps) need exceptionally rigorous security filters, or attackers can take advantage.
Fuente: Dark Reading ↗Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls
The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as CEVA and TKW…
Fuente: The Hacker News ↗Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore
AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified as AI-assisted are…
Fuente: The Hacker News ↗17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360
ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in late 2023 to a…
Fuente: The Hacker News ↗Múltiples vulnerabilidades en GitLab
Múltiples vulnerabilidades en GitLab Jue, 24/09/2026 - 10:15 Aviso Recursos Afectados GitLab Community Edition (CE) y Enterprise Edition (EE):versiones desde la 13.11 hasta la 19.2.6;versiones 19.3 anteriores a la 19.3.3;versiones 19.4…
Fuente: INCIBE-CERT ↗Elemento de ruta de búsqueda sin controlar en Evope Collector
Elemento de ruta de búsqueda sin controlar en Evope Collector Jue, 24/09/2026 - 09:44 Aviso Recursos Afectados Collector versión 1.1.6.9.0, Core: 1.1.3.2.4, Update: 1.1.0.3.6 – Models: Evope.Service.exe y wtsapi32.dll. Descripción INCIBE…
Fuente: INCIBE-CERT ↗TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords
Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the activity has…
Fuente: The Hacker News ↗One URL, Three Different Tricks, (Thu, Sep 24th)
Yesterday, we received a phishing email with an interesting link. At first sight, it looks like garbage, but every piece of it has been carefully crafted to confuse basic security controls. Here is the defanged link:
Fuente: SANS ISC ↗- ● Explotada activamente
Inclusión de archivos PHP en WordPress
Inclusión de archivos PHP en WordPress Mié, 23/09/2026 - 11:04 Aviso Recursos Afectados Las siguientes versiones de WordPress:de 7.1.0 a 7.1.1;de 7.0.0 a 7.0.5;de 6.9.0 a 6.9.8;de 6.8.0 a 6.8.9;de 6.7.0 a 6.7.8;de 6.6.0 a 6.6.8;de 6.5.0 a…
Fuente: INCIBE-CERT ↗ También en: The Hacker News SASE Converges Network & Security Into One Cloud Solution
Enterprise computing is moving to the edge. Keeping it secure requires tactics far beyond putting up firewalls. (Second in a three-part series.)
Fuente: Dark Reading ↗EDR Evasion Stack Helps Process Injection Slip Past Defenses
A process parameter-poisoning technique evades EDR by injecting code into process initialization structures without using the Windows APIs that EDR tools typically watch out for.
Fuente: Dark Reading ↗El 92% de las pymes españolas ha sufrido un incidente de ciberseguridad en el último año
Los resultados de la encuesta global “Inside the 2026 SMB Threat Landscape: From Phishing and Scams to Fake AI Tools”, realizada entre pequeñas y medianas empresas (pymes) ponen de manifiesto la creciente necesidad de contar con una…
Fuente: CyberSecurity News ↗la IA impulsa el paso hacia ataques de malware más precisos
WatchGuard Technologies, empresa global en ciberseguridad unificada para proveedores de servicios gestionados (MSP), anuncia las conclusiones de su último Global Threat Report. El informe semestral revela que los actores de amenazas están…
Fuente: CyberSecurity News ↗GitLab Email Addresses Can Be Weaponized for Supply Chain Attacks
Incoming email addresses automatically assigned to each user on the platform contain highly privileged access tokens that attackers can use.
Fuente: Dark Reading ↗Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry
Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a distribution vector…
Fuente: The Hacker News ↗A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You
The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start CI/CD jobs that run…
Fuente: The Hacker News ↗MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key
Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska calls MikroTrick,…
Fuente: The Hacker News ↗UAE, Saudi Arabia Face Onslaught of Increasingly Complex Cyberattacks
The United Arab Emirates and Kingdom of Saudi Arabia together absorbed 50% of all cyberattacks recorded across the Gulf region in the first half of 2026.
Fuente: Dark Reading ↗Attackers Manipulate AI Chatbots in Mass Disinformation, Phishing Campaign
Threat actors are poisoning ChatGPT, Gemini, and Google AI Overview answers by seeding the Web with malicious links and data and then optimizing the content.
Fuente: Dark Reading ↗This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move
A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server, Cisco Talos said on September 22. The models can choose to steal Windows credentials, saved browser…
Fuente: The Hacker News ↗Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI
Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Windows, Linux, and…
Fuente: The Hacker News ↗New cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server Control
A flaw in cPanel's CalDAV and CardDAV service lets anyone with a cPanel hosting account run code as root and take "full control of the server," the company said on September 22. A second bug in the WP Toolkit plugin, used to install and…
Fuente: The Hacker News ↗545 Hackers Tested It First. Now XRanges for AI Scores Your Security Agent
Autonomous security agents are getting good at finding bugs. Nobody has a good way to measure how good. Point one at a realistic target and what comes back is a report the agent wrote about itself: confident prose, a list of findings, and…
Fuente: The Hacker News ↗Anthropic and OpenAI Models Still Attempt Restricted Actions in Safety Tests
Anthropic and OpenAI on Tuesday announced new models, with both artificial intelligence (AI) companies noting that they are continuing to invest in improving alignment to combat risky behavior. Opus 5.5, per Anthropic, is a "major step up…
Fuente: The Hacker News ↗Exploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container Escape
A use-after-free in the Linux kernel's AF_UNIX socket subsystem can be used to escape a container and gain root on the host, security firm DepthFirst said in research published September 22. The flaw, tracked as CVE-2026-80521 (CVSS…
Fuente: The Hacker News ↗Múltiples vulnerabilidades en Analytics and Location Engine de HPE
Múltiples vulnerabilidades en Analytics and Location Engine de HPE Mié, 23/09/2026 - 11:08 Aviso Recursos Afectados HPE Networking Analytics and Location Engine (ALE), versión 5.0.0.0 y anteriores. Descripción HPE ha publicado 10…
Fuente: INCIBE-CERT ↗- ● Explotada activamente
F5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth Servers
Attackers are exploiting a critical flaw in F5 BIG-IP Access Policy Manager (APM) that lets them run code on a BIG-IP system without logging in, F5 says. The flaw, CVE-2026-94127, affects only systems in which APM serves as an OAuth…
Fuente: The Hacker News ↗ También en: INCIBE-CERT Chinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP Malware
A Chinese threat actor codenamed UTA0565 has been observed exploiting the recently disclosed Google Chrome-Microsoft Windows exploit chain as zero-days through fake websites. The attacks, detected on September 3 and 4, 2026, involved the…
Fuente: The Hacker News ↗Múltiples vulnerabilidades en Observability Self-Hosted de SolarWinds
Múltiples vulnerabilidades en Observability Self-Hosted de SolarWinds Mié, 23/09/2026 - 10:18 Aviso Recursos Afectados SolarWinds Observability Self-Hosted, versiones anteriores a 2026.2.3. Descripción Kai Huang, de Armadin, ha informado…
Fuente: INCIBE-CERT ↗Múltiples vulnerabilidades en el panel de administración de Microweber
Múltiples vulnerabilidades en el panel de administración de Microweber Mié, 23/09/2026 - 10:00 Aviso Recursos Afectados Panel de administración de Microweber en la versión v2.0.19. Descripción INCIBE ha coordinado la publicación de 2…
Fuente: INCIBE-CERT ↗- ● Explotada activamente
Check Point Warns of Management Server Zero-Day Exploited in Targeted Attacks
Attackers exploited a previously unknown flaw in Check Point's Security Management Server in a handful of targeted attacks on July 23, the company said. The flaw, CVE-2026-93616, allows an attacker who can access the server's web service…
Fuente: The Hacker News ↗ También en: INCIBE-CERT - ● Explotada activamente
New CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based Setups
Attackers are exploiting a new flaw in on-premises VeloCloud Orchestrator (VCO), the server that manages the Edge devices in a VeloCloud SD-WAN, Arista said on September 22. The flaw, tracked as CVE-2026-93952, may allow a remote attacker…
Fuente: The Hacker News ↗ También en: INCIBE-CERT Critical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG Input
A new security vulnerability in Next.js could allow attackers to run code on a server via ImageResponse, the feature that generates Open Graph and other social preview images, Vercel said. The risk applies when an app puts values an…
Fuente: The Hacker News ↗ShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job Applicants
The cyber extortion group known as ShinyHunters on Tuesday claimed it had breached the U.S. Federal Bureau of Investigation and stolen data belonging to current and former employees at the agency. "We have compromised the FBI. We hold…
Fuente: The Hacker News ↗Relays Are Masking Chinese Access to Frontier AI Models in the US
More than 80,000 AI relay servers are helping users in China mask their identities while they access cutting-edge large language models (LLMs), probably to clone them.
Fuente: Dark Reading ↗Detectada campaña de vishing en España que suplanta a Amazon y reclama entre 100 y 190 euros
Un nuevo intento de fraude telefónico circula en España en el que los ciberdelincuentes se hacen pasar por Amazon para informar a sus víctimas de un supuesto cargo de entre 100 y 190 euros por la renovación de una suscripción al servicio,…
Fuente: CyberSecurity News ↗Casi la mitad de los responsables de TI no está preparada para gestionar la IA de forma segura
Las empresas están adoptando la IA más rápido de lo que tardan en gestionarla de forma segura. Los nuevos hallazgos de Barracuda Research revelan que casi la mitad de los altos directivos de TI afirman que sus equipos carecen de las…
Fuente: CyberSecurity News ↗How the CISO-CMO Alliance Builds Trust Before Crisis Strikes
Cybersecurity and brand reputation are inextricably linked. Security and marketing leaders who establish regular touchpoints, develop joint crisis communications plans, and translate security risks into their brand impact position their…
Fuente: Dark Reading ↗Microsoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox Compromises
Microsoft on Tuesday announced the takedown of the EvilTokens device code phishing service that it said used artificial intelligence (AI) "at every step of the attack chain." The action, carried out with authorization from the U.S.…
Fuente: The Hacker News ↗ También en: Dark ReadingDeception by Design: CISA's Guide to Tricking Cybercriminals
The Cybersecurity and Infrastructure Security Agency (CISA) is going old school to help organizations with limited resources set traps for hackers.
Fuente: Dark Reading ↗The Truth about GET and HTTP Standards, (Tue, Sep 22nd)
On Friday, Xavier talked about the newly introduced HTTP Query method. This new method was introduced to allow "GET" requests that include a body. The main reason for this was that GET requests typically do not contain a body. But what if…
Fuente: SANS ISC ↗WordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some Servers
WordPress has fixed a critical flaw in its core software that lets an attacker with no account make a site load a PHP file from outside its theme folders. On some servers, that can go further, allowing the attacker to run their own code.…
Fuente: The Hacker News ↗Malicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate Credentials
Cybersecurity researchers have disclosed details of a malicious npm package named "tw-pkgprobe-7731" that masquerades as a security tool targeting developers integrating Twilio into their applications, while stealthily attempting to…
Fuente: The Hacker News ↗Amid Ongoing Rogue Incidents, Debate Over AI Safety Gets Real
As more reports of misalignment incidents underscore AI risks, large AI labs, regular businesses, and even nations are searching for better ways to keep control and be secure.
Fuente: Dark Reading ↗2026-013: Critical Vulnerability in F5 BIG-IP APM
On 22 September 2026, F5 published an advisory addressing a critical vulnerability affecting its BIG-IP APM product. The vendor confirmed active exploitation in the wild. CERT-EU recommends taking appropriate actions as soon as possible.
Fuente: CERT-EU ↗Critical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without Credentials
A critical vulnerability in Bifrost, an open-source AI gateway that routes requests to more than 20 LLM providers, allows an unauthenticated attacker to run arbitrary commands on the gateway server with a single HTTP request. The flaw,…
Fuente: The Hacker News ↗Researcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender Updates
A zero-day proof-of-concept tool that stops Microsoft Defender from installing platform and signature updates by filling all available disk space was published on GitHub on September 19. The tool, called BigDiskBuster, has no patch, no…
Fuente: The Hacker News ↗¿Existen los Robux gratis en Roblox? Qué es verdad y qué es una estafa
Los Robux gratis son una promesa habitual en Roblox. Descubre qué ofertas son legítimas y cómo evitar las estafas más comunes.
Fuente: WeLiveSecurity ↗LausivLoader analysis, or how to pass data between malware stages, (Thu, Sep 17th)
At the end of August, a malspam message was caught in the quarantine of a mail gateway operated by one of my customers. The message was not especially remarkable – it asked the recipient to review some attached requirements…
Fuente: SANS ISC ↗AI Agents Are Rewriting the Rules of Lateral Movement
Security teams have spent decades asking whether an identity has too much access. AI agents raise a harder question: how can we determine which paths an autonomous system can discover, given the access it already has? A person may try…
Fuente: The Hacker News ↗More Than a Third of Industrial Orgs See Cybersecurity Risk as a Top Obstacle to Growth, Study Finds
Industrial companies are increasing cybersecurity investment as connected operations, AI adoption, and IT/OT convergence expand operational risk.
Fuente: Dark Reading ↗DORA Year Two: Can Your SOC Actually See the Attack?
When the Digital Operational Resilience Act (DORA) became enforceable across the European Union in January 2025, it triggered an administrative sprint. Financial entities spent the first year establishing risk governance, assessing…
Fuente: The Hacker News ↗New Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host Memory
A new flaw in the Linux kernel's KVM virtualization code for ARM64 processors can leave a freed piece of host memory exposed to a guest virtual machine on hosts with nested virtualization enabled. The bug, tracked as CVE-2026-89775,…
Fuente: The Hacker News ↗SharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCE
A SharePoint Server vulnerability that Microsoft initially classified as a spoofing flaw with a CVSS score of 6.5 actually enables authenticated remote code execution, according to full technical details published today by Viettel Cyber…
Fuente: The Hacker News ↗Shai-Hulud Attack Nips Cyber-Firm CrowdSec's GitHub Data
Threat actors stole the contents of 170 private repositories using an OAuth token stolen from a former employee's computer through the TanStack npm supply chain attack.
Fuente: Dark Reading ↗Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before Removal
A malicious npm package named "indexed-btree" has been observed hiding its malicious behavior within application code rather than using lifecycle scripts, indicating that threat actors are likely shifting tactics in response to recent…
Fuente: The Hacker News ↗Accenture y Anthropic se alían e invertirán 2.000 millones en seguridad de la IA
Accenture y Anthropic anunciaron, el 21 de septiembre, una colaboración para crear un equipo de evaluadores integrados que trabajará junto con los equipos internos y los socios de seguridad de Anthropic para evaluar y someter a los…
Fuente: Red Seguridad ↗SideCopy Broadens India Targeting to Academia With ReverseRAT Spear-Phishing
The threat actor known as SideCopy has been observed using spear-phishing lures to target academic institutions in India, expanding their strategic focus beyond government entities. "SideCopy campaign operations typically initiate through…
Fuente: The Hacker News ↗Inyección de comandos en R95 de D-Link
Inyección de comandos en R95 de D-Link Mar, 22/09/2026 - 09:33 Aviso Recursos Afectados D-Link R95, revisión de hardware Ax y versión de firmware BE9500_1.00.16.D-Link continúa verificando si otras revisiones de hardware o versiones de…
Fuente: INCIBE ↗How AI Agents Can Trigger Runaway Costs for Enterprises
Unbounded consumption is an issue that OWASP currently ranks sixth in its Top 10 for LLM Applications, and it could be an extremely costly one.
Fuente: Dark Reading ↗ShinyHunters Hacked Cl0p. Now What About Cl0p's Victims?
ShinyHunters defaced Cl0p's Dark Web site and claims to have stolen victim data, potentially exposing organizations that paid ransoms to renewed extortion attempts.
Fuente: Dark Reading ↗Cybercriminals Are Hiding New Malware in Torrents for Popular Films
Victims have been identified in Africa, including in Kenya and Uganda.
Fuente: Dark Reading ↗Rogue Behavior: OpenAI Reveals More Model Misalignment Incidents
The AI giant disclosed six examples of concerning model activity and published a new framework for investigating and disclosing such incidents.
Fuente: Dark Reading ↗One does not simply defend agentically
Defenders can’t use AI in the same way attackers can, but there’s much they can do to unlock the potential of agentic cyber defence.
Fuente: NCSC-UK ↗La Ley EU KIDS limita el acceso de los niños a las redes sociales
La futura Ley EU Kids transformará el acceso de los niños a las redes sociales en España, garantizando un entorno digital más y seguro. Con este marco regulatorio, Bruselas busca unificar los criterios de protección digital infantil en…
Fuente: Red Seguridad ↗El Parlamento Europeo reclama una respuesta común y más anticipada frente a las amenazas híbridas
El Parlamento Europeo ha aprobado un informe para reforzar la respuesta de la Unión Europea frente a las amenazas híbridas, con especial atención a la detección temprana, el intercambio de inteligencia y la coordinación entre Estados…
Fuente: Red Seguridad ↗Múltiples vulnerabilidades en DIR-822A de D-Link
Múltiples vulnerabilidades en DIR-822A de D-Link Lun, 21/09/2026 - 08:45 Aviso Recursos Afectados D-Link DIR-822A, versión A_101.Las revisiones de hardware y regiones afectadas todavía se encuentran pendientes de confirmación por parte…
Fuente: INCIBE ↗