Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 48 min 957 titulares en el archivo
Qué se está publicando
Distribución por tema
96 titulares en Vulnerabilidades de severidad Media Limpiar filtros ×
- martes 1 sep
-
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the…
The Hacker News Vulnerabilidades thehackernews.com -
Rockwell Automation RSLinx Classic
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx…
CISA Advisories Vulnerabilidades cisa.gov -
Rockwell Automation Redundancy Module Configuration Tool
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges. The following versions of Rockwell Automation Redundancy Module Configuration…
CISA Advisories Vulnerabilidades cisa.gov -
Rockwell Automation FactoryTalk Activation Manager
View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation…
CISA Advisories Vulnerabilidades cisa.gov -
Explotan dos fallos críticos en Langflow y Ruby on Rails para robar secretos y desplegar mando y control
Se ha confirmado explotación activa de CVE-2026-0768 en Langflow y CVE-2026-66066 en Ruby on Rails. Los ataques se centran en leer secretos, probar credenciales y preparar infraestructura de mando y control (C2), con riesgo de acabar en…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com - lunes 31 ago
-
Introducing wrapture
Introducing wrapture New from Graham Dumpleton (of wrapt, mod_wsgi, and New Relic's Python agent fame), who describes Wrapture as taking the monkeypatching ideas from wrapt and extending them to apply to testing and tracing at the same…
Simon Willison Vulnerabilidades simonwillison.net -
PaperCut issues emergency patches as threat actors target chained vulnerabilities
The print management software maker faced a wave of attacks in 2023 aimed at higher education customers.
Cybersecurity Dive Vulnerabilidades cybersecuritydive.com -
ATM Flaws Reveal Key Weaknesses in the Software Supply Chain
A security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local cash machine.
WIRED · Security Vulnerabilidades wired.com -
Más de 8.300 servidores Gitea quedan expuestos a ataques de ejecución remota por CVE-2026-60004
Miles de instancias de Gitea accesibles desde Internet seguían sin parchear a finales de agosto frente a CVE-2026-60004, un fallo crítico que permite ejecución remota de comandos. La corrección llegó con Gitea 1.27.1 y el problema ya…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com - viernes 28 ago
-
Microsoft Teams Has Become a Haven for Scammers in China
Fraudsters are exploiting enterprise chat apps like Teams and Webex to trick Chinese victims into transferring large sums of money, fueling a wave of complaints.
WIRED · Security Vulnerabilidades wired.com -
Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!
Rapid7 Vulnerabilidades rapid7.com - jueves 27 ago
-
Mitsubishi Electric CNC Series (Update A)
View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products. The following versions of Mitsubishi…
CISA Advisories Vulnerabilidades cisa.gov -
Ebyte NA111-M
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device. The following versions of Ebyte NA111-M are affected: NA111-M Firmware 9013-2-17 (CVE-2026-73125, CVE-2026-76179…
CISA Advisories Vulnerabilidades cisa.gov -
Mitsubishi Electric Multiple FA Products (Update D)
View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product…
CISA Advisories Vulnerabilidades cisa.gov -
Xiiaozet LK100W
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to take control over the device. The following versions of Xiiaozet LK100W are affected: LK100W
CISA Advisories Vulnerabilidades cisa.gov -
Applied Systems Engineering ASE2000 V2 Communications Test Set
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the…
CISA Advisories Vulnerabilidades cisa.gov -
All-Line Equipment Company Fuel-Boss
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. The following versions of All-Line Equipment Company Fuel-Boss are affected…
CISA Advisories Vulnerabilidades cisa.gov -
Rockwell Automation OTTO Fleet Manager
View CSAF Summary Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. The following versions of Rockwell…
CISA Advisories Vulnerabilidades cisa.gov - miércoles 26 ago
-
Beyond Patching: What IT Teams Need to Know About Unpatchable Exposures
Executive Summary Most IT teams still operate under a false binary: patch or accept risk. That assumption creates unnecessary operational pressure. Patchless remediation is real and production-proven. Mitigate, Uninstall, Run Custom…
Qualys Vulnerabilidades blog.qualys.com -
Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who’s Exploiting Your Perimeter
A new joint study by Tenable and SentinelOne reveals how state and criminal groups converge on the same vulnerable edge infrastructure.
SentinelOne Vulnerabilidades sentinelone.com -
CISA Vulnerability Review
Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and…
CISA Advisories Vulnerabilidades cisa.gov -
VMs won't contain cyber-capable agents
As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing…
Trail of Bits Vulnerabilidades blog.trailofbits.com - martes 25 ago
-
The patch window is collapsing: Why security needs a new control plane
Organizations need protection that operates in the gap between discovery and remediation. The post The patch window is collapsing: Why security needs a new control plane appeared first on Microsoft Security Blog.
Microsoft Security Blog Vulnerabilidades azure.microsoft.com -
PayRange API
View CSAF Summary Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a…
CISA Advisories Vulnerabilidades cisa.gov -
FURUNO FA-50 Class B AIS Transponder
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to alter device settings. The following versions of FURUNO FA-50 Class B AIS Transponder are affected: FURUNO FA-50 Class B AIS Transponder…
CISA Advisories Vulnerabilidades cisa.gov -
Keycloak corrige un fallo crítico en el restablecimiento de contraseñas que permite tomar cuentas sin autenticación
Keycloak ha corregido una vulnerabilidad crítica, CVE-2026-18963, que permite a un atacante remoto y sin autenticación forzar el restablecimiento de contraseña de cualquier usuario y hacerse con su cuenta. La prioridad pasa por actualizar…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com - jueves 20 ago
-
Identity Abuse Through Trusted Communication Channels
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.
Unit 42 Vulnerabilidades unit42.paloaltonetworks.com - martes 18 ago
-
Remediation Agents, Demystified: Why Fixing Beats Finding
See how Snyk’s Remediation Agent uses security intelligence, breakability analysis, and validation to turn vulnerabilities into mergeable pull requests.
Snyk Vulnerabilidades snyk.io -
Benchmarking Secure-and-Functional Remediation and How Snyk Agent Fix Lifts Frontier-Model Fix Rates by over 14%
A benchmark of secure, functional vulnerability fixes across JavaScript, Java, and Python shows Snyk Intelligence helps frontier models break past a 72–75% performance plateau.
Snyk Vulnerabilidades snyk.io - lunes 17 ago
-
Cadena de exploits para videollamadas VoLTE Unisoc otorga acceso completo al kernel de Android
Investigadores de seguridad de SSD Secure Disclosure han publicado una cadena de exploits en dos etapas que permite el acceso completo al kernel de Android en dispositivos con firmware de módem Unisoc mediante una videollamada VoLTE, sin…
Segu-Info Vulnerabilidades blog.segu-info.com.ar
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.