Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 50 min 957 titulares en el archivo
Qué se está publicando
Distribución por tema
86 titulares en Amenazas de severidad Media Limpiar filtros ×
- martes 1 sep
-
Hackers abuse Faronics Deploy admin tool to install ScreenConnect
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]
BleepingComputer Amenazas bleepingcomputer.com -
China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks
A hacking operation dubbed Fire Ant "didn’t just compromise systems," according to researchers. "It compromised the trust layer those systems depend on."
The Record Amenazas therecord.media -
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams…
The Hacker News Amenazas thehackernews.com -
Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]
BleepingComputer Amenazas bleepingcomputer.com -
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
Dark Reading Amenazas darkreading.com -
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS…
The Hacker News Amenazas thehackernews.com -
Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a…
The Hacker News Amenazas thehackernews.com -
Five Venezuelans plead guilty to ATM jackpotting attacks in US
Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. [...]
BleepingComputer Amenazas bleepingcomputer.com -
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Securelist (Kaspersky) Amenazas securelist.com - lunes 31 ago
-
'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.
Dark Reading Amenazas darkreading.com -
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
Next-level ClickFix wave sets off multi-stage attack chain
The Register · Security Amenazas theregister.com -
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected…
The Hacker News Amenazas thehackernews.com -
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on…
Unit 42 Amenazas unit42.paloaltonetworks.com - viernes 28 ago
-
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel…
Microsoft Security Blog Amenazas microsoft.com -
The Good, the Bad and the Ugly in Cybersecurity – Week 35 (2026)
Authorities disrupt global cybercrime rings, attackers abuse DocuSign in NovaCookies phishing, and Spark RAT targets Cambodia with vulnerable drivers.
SentinelOne Amenazas sentinelone.com -
Next-Gen Phishing Tactics Users Aren’t Ready For | Huntress
Move past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing—and how to train your users with Huntress SAT.
Huntress Amenazas huntress.com -
Teach Yourself to Phish | Huntress
Get ready for a phishing trip! Learn about the strategy behind phishing simulations and how it can help your organization build resilience against real phishing threats.
Huntress Amenazas huntress.com -
A Beginner’s Guide to Phishing Simulation Training for Employees | Huntress
Learn the essentials of phishing simulation training with our beginner's guide. Protect your organization by simulating real phishing attacks.
Huntress Amenazas huntress.com -
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
A large-scale phishing campaign used fake voicemail SVG attachments to bypass email defenses, targeting 5527 organizations with over 26,000 malicious messages
Infosecurity Magazine Amenazas infosecurity-magazine.com -
CISA identifies security hurdles that led to very different results in two red-team engagements
The agency said its recent simulated cyberattacks offered several key lessons for many organizations.
Cybersecurity Dive Amenazas cybersecuritydive.com -
Some Malicious PE Stats, (Thu, Aug 27th)
During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS. 32bits malware[1]. Can we…
SANS Internet Storm Center Amenazas isc.sans.edu - jueves 27 ago
-
JavaScript obfuscation: From party trick to phishing kit
Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.
Cisco Talos Amenazas blog.talosintelligence.com -
A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)
As I've mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us here at the Internet Storm Center.
SANS Internet Storm Center Amenazas isc.sans.edu - miércoles 26 ago
-
Boston Scientific says cyberattack disrupted order processing, shipping
The medical device-maker says it cannot yet determine any financial impact from the attack it suffered this week.
Cybersecurity Dive Amenazas cybersecuritydive.com - martes 25 ago
-
WhatsApp añade Passkey para inicios de sesión resistentes al phishing en iOS y Android
Meta anunció una serie de funciones de seguridad para las cuentas de WhatsApp, incluyendo la compatibilidad con passkey para una cuenta. Esto permitirá a los usuarios de dispositivos iOS y Android iniciar sesión en sus cuentas mediante un…
Segu-Info Amenazas blog.segu-info.com.ar - viernes 21 ago
-
The invisible passenger in your car
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.
Securelist (Kaspersky) Amenazas securelist.com - martes 18 ago
-
Quishing: cómo los códigos QR pueden eludir la seguridad corporativa
El quishing se ha convertido en una alternativa popular al phishing tradicional. Así es como las empresas pueden cerrar esa brecha.
WeLiveSecurity (ESET) Amenazas welivesecurity.com - lunes 17 ago
-
Stronger Cybersecurity Programs Start with People: NIST Wants Your Input on the Path Forward for Human-Centered Cybersecurity
When was the last time a cybersecurity process at work made you want to scream? Maybe it was a password requirement so complicated you had to write it down (defeating the purpose), a phishing simulation test that felt more like a trap than…
NIST Cybersecurity Amenazas nist.gov -
How QR-code phishing can slip past corporate security measures
Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap.
WeLiveSecurity (ESET) Amenazas welivesecurity.com - jueves 13 ago
-
Curiouser and Curiouser
In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.
Cisco Talos Amenazas blog.talosintelligence.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.