Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 36 min 976 titulares en el archivo
Qué se está publicando
Distribución por tema
217 titulares en Vulnerabilidades Limpiar filtros ×
- martes 11 ago
-
Windows 11 KB5121003 & KB5120240 cumulative updates released
Microsoft has released Windows 11 KB5121003 and KB5120240 cumulative updates for versions 25H2/24H2 and 23H2 to fix security vulnerabilities, bugs, and add new features. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Shattering the Dream – When a Job Offer Becomes a Zero-Day Attack
Key Points Introduction Since early 2026, Check Point Research has tracked a wave of the Operation Dream Job campaign. This wave primarily targeted the defense sector worldwide, with a particular emphasis on companies operating in the…
Check Point Research Vulnerabilidades research.checkpoint.com -
Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws
The security defects could be exploited for arbitrary code execution and denial-of-service. The post Adobe Urges Immediate Patching of Critical ColdFusion, Campaign Classic Flaws appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com -
Zoom Patches Zero-Click Code Execution Vulnerability
Impacting Zoom annotation, the bug could be exploited by a meeting participant to execute code on another participant’s machine. The post Zoom Patches Zero-Click Code Execution Vulnerability appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com -
SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities
SAP released 28 new and two updated security notes, including four notes dealing with critical-severity bugs. The post SAP Patches Critical Code Injection, Memory Corruption Vulnerabilities appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com -
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf…
Securelist (Kaspersky) Vulnerabilidades securelist.com -
Johnson Controls C-CURE 9000 and Victor application server (Update A)
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor application server (Update…
CISA Advisories Vulnerabilidades cisa.gov -
Mira Hormone Monitor, Mira Android App
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token…
CISA Advisories Vulnerabilidades cisa.gov -
Pulsetto Vagus Nerve Stimulator
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings. The following versions of Pulsetto Vagus…
CISA Advisories Vulnerabilidades cisa.gov -
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense…
CISA Advisories Vulnerabilidades cisa.gov -
Cisco warns of high-severity ClamAV flaws with public exploits
Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public…
The Hacker News Vulnerabilidades thehackernews.com - lunes 10 ago
-
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.
Dark Reading Vulnerabilidades darkreading.com -
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.
The Record Vulnerabilidades therecord.media -
The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists
It's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.
Dark Reading Vulnerabilidades darkreading.com -
Coruna, DarkSword iOS Exploits Proliferate Globally
Sophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups.
Dark Reading Vulnerabilidades darkreading.com -
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com - domingo 9 ago
-
Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS
A real Evo Continuous Offensive Security assessment uncovered 33 confirmed vulnerabilities in a multi-tenant enterprise SaaS, including tenant-wide compromise and critical authorization flaws.
Snyk Vulnerabilidades snyk.io - jueves 30 jul
-
The July 2026 Apple Security Update Review
Welcome to our monthly look at Apple security patches. This release shows that Apple is not immune to the bug apocalypse that is impacting other vendors. Last month, they released 37 unique CVEs compare to this month’s 210. Quite a…
Zero Day Initiative Vulnerabilidades thezdi.com - miércoles 22 jul
-
Next chapter: Restructuring GitHub’s bug bounty program
GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team. The post Next chapter: Restructuring GitHub’s bug bounty program appeared first…
GitHub Security Vulnerabilidades github.blog - martes 14 jul
-
Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch…
Krebs on Security Vulnerabilidades krebsonsecurity.com -
The July 2026 Security Update Review
Well folks. Here we are. The bug apocalypse has fully descended upon us. I’ll do my best to sort this out in some way meaningful, but this month’s release shows us the nay-sayers were right, and I’ve got to hand it to the nay-sayers here…
Zero Day Initiative Vulnerabilidades thezdi.com - viernes 10 jul
-
CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys
In this excerpt of a TrendAI Research Services vulnerability report, Yazhi Wang and Jonathan Lein of the TrendAI Research team detail a recently patched remote code execution bug in the Windows HTTP protocol stack. Successful exploitation…
Zero Day Initiative Vulnerabilidades thezdi.com - miércoles 8 jul
-
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake…
Krebs on Security Vulnerabilidades krebsonsecurity.com - lunes 6 jul
-
OWASP CVE Lite CLI Graduates to Lab Project Status
CVE Lite CLI, a fast open source dependency vulnerability scanner for JavaScript and TypeScript projects, has graduated to OWASP Lab Project status three months after its initial release. OWASP CVE Lite CLI graduated to Lab Project status…
OWASP Vulnerabilidades owasp.org - miércoles 1 jul
-
The June 2026 Apple Security Update Review
We’re back with our look at the Apple macOS and iOS security updates. As this is a new feature for us, please let us know your feedback on the blog. For June 2026, Apple released 37 unique CVEs across iOS 26.5.2 / iPadOS 26.5.2, macOS…
Zero Day Initiative Vulnerabilidades thezdi.com - lunes 29 jun
-
Inside the Advisory Database and what happens when vulnerability volume breaks records
The GitHub Advisory Database is processing more vulnerability reports than ever before. Here's what's driving the surge, how we're responding, and how the community can help. The post Inside the Advisory Database and what happens when…
GitHub Security Vulnerabilidades github.blog - martes 9 jun
-
The June 2026 Security Update Review
I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break…
Zero Day Initiative Vulnerabilidades thezdi.com - miércoles 27 may
-
Football Fever Fuels Scam Campaigns Across Email and Social Media
Football fans are increasingly targeted by scams exploiting club loyalty, national teams, football collectibles, streaming demand, and the growing excitement around the FIFA World Cup 2026, according to Bitdefender Labs. Our most recent…
Bitdefender Labs Vulnerabilidades bitdefender.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.