Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 44 min 958 titulares en el archivo
Qué se está publicando
Distribución por tema
212 titulares en Vulnerabilidades Limpiar filtros ×
- lunes 31 ago
-
Más de 8.300 servidores Gitea quedan expuestos a ataques de ejecución remota por CVE-2026-60004
Miles de instancias de Gitea accesibles desde Internet seguían sin parchear a finales de agosto frente a CVE-2026-60004, un fallo crítico que permite ejecución remota de comandos. La corrección llegó con Gitea 1.27.1 y el problema ya…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com - viernes 28 ago
-
Microsoft Teams Has Become a Haven for Scammers in China
Fraudsters are exploiting enterprise chat apps like Teams and Webex to trick Chinese victims into transferring large sums of money, fueling a wave of complaints.
WIRED · Security Vulnerabilidades wired.com -
Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!
Rapid7 Vulnerabilidades rapid7.com -
PaperCut NG/MF Critical Zero-Day Exploited in the Wild
Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents…
Rapid7 Vulnerabilidades rapid7.com -
CISA impone un parche urgente por un fallo crítico en Citrix NetScaler con explotación activa
CISA ha metido CVE-2026-8452 en su catálogo Known Exploited Vulnerabilities y obliga a las agencias federales de EEUU a parchear Citrix NetScaler antes del 29 de agosto de 2026. La falla, que empezó describiéndose como un problema de…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com - jueves 27 ago
-
PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE
PaperCut NG and PaperCut MF are under active exploitation. Huntress reproduced a pre-auth RCE chain and shares urgent patching, exposure, and detection guidance.
Huntress Vulnerabilidades huntress.com -
Mitsubishi Electric CNC Series (Update A)
View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products. The following versions of Mitsubishi…
CISA Advisories Vulnerabilidades cisa.gov -
Ebyte NA111-M
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device. The following versions of Ebyte NA111-M are affected: NA111-M Firmware 9013-2-17 (CVE-2026-73125, CVE-2026-76179…
CISA Advisories Vulnerabilidades cisa.gov -
Mitsubishi Electric Multiple FA Products (Update D)
View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product…
CISA Advisories Vulnerabilidades cisa.gov -
Xiiaozet LK100W
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to take control over the device. The following versions of Xiiaozet LK100W are affected: LK100W
CISA Advisories Vulnerabilidades cisa.gov -
Applied Systems Engineering ASE2000 V2 Communications Test Set
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the…
CISA Advisories Vulnerabilidades cisa.gov -
All-Line Equipment Company Fuel-Boss
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. The following versions of All-Line Equipment Company Fuel-Boss are affected…
CISA Advisories Vulnerabilidades cisa.gov -
Rockwell Automation OTTO Fleet Manager
View CSAF Summary Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. The following versions of Rockwell…
CISA Advisories Vulnerabilidades cisa.gov -
CISA suma seis fallos explotados al catálogo KEV y eleva la urgencia de parcheo en NetScaler, Linux y SQL Server
CISA añadió el 26 de agosto de 2026 seis vulnerabilidades al catálogo Known Exploited Vulnerabilities (KEV), una señal de explotación activa que suele marcar prioridades inmediatas de corrección. El lote incluye un fallo reciente en Citrix…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com - miércoles 26 ago
-
Beyond Patching: What IT Teams Need to Know About Unpatchable Exposures
Executive Summary Most IT teams still operate under a false binary: patch or accept risk. That assumption creates unnecessary operational pressure. Patchless remediation is real and production-proven. Mitigate, Uninstall, Run Custom…
Qualys Vulnerabilidades blog.qualys.com -
Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who’s Exploiting Your Perimeter
A new joint study by Tenable and SentinelOne reveals how state and criminal groups converge on the same vulnerable edge infrastructure.
SentinelOne Vulnerabilidades sentinelone.com -
CISA Adds Six Known Exploited Vulnerabilities to Catalog
CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability CVE-2015-5287 Red Hat Automatic Bug Reporting…
CISA Advisories Vulnerabilidades cisa.gov -
CISA Vulnerability Review
Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and…
CISA Advisories Vulnerabilidades cisa.gov -
VMs won't contain cyber-capable agents
As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing…
Trail of Bits Vulnerabilidades blog.trailofbits.com - martes 25 ago
-
The patch window is collapsing: Why security needs a new control plane
Organizations need protection that operates in the gap between discovery and remediation. The post The patch window is collapsing: Why security needs a new control plane appeared first on Microsoft Security Blog.
Microsoft Security Blog Vulnerabilidades azure.microsoft.com -
Vulnerabilidad de Oracle WebLogic, explotada activamente, permite a atacantes no autenticados acceder a datos críticos
La Agencia CISA añadió el lunes una vulnerabilidad de máxima gravedad que afecta a Oracle HTTP Server y Oracle WebLogic Server a su catálogo de Vulnerabilidades Explotadas Conocidas (KEV), citando evidencia de explotación activa.La…
Segu-Info Vulnerabilidades blog.segu-info.com.ar -
PayRange API
View CSAF Summary Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a…
CISA Advisories Vulnerabilidades cisa.gov -
FURUNO FA-50 Class B AIS Transponder
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to alter device settings. The following versions of FURUNO FA-50 Class B AIS Transponder are affected: FURUNO FA-50 Class B AIS Transponder…
CISA Advisories Vulnerabilidades cisa.gov -
Keycloak corrige un fallo crítico en el restablecimiento de contraseñas que permite tomar cuentas sin autenticación
Keycloak ha corregido una vulnerabilidad crítica, CVE-2026-18963, que permite a un atacante remoto y sin autenticación forzar el restablecimiento de contraseña de cualquier usuario y hacerse con su cuenta. La prioridad pasa por actualizar…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com - lunes 24 ago
-
CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A…
Qualys Vulnerabilidades blog.qualys.com -
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
Rapid7 Vulnerabilidades rapid7.com -
Gunra ransomware: what you need to know
The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog.
Graham Cluley Vulnerabilidades fortra.com - viernes 21 ago
-
The Good, the Bad and the Ugly in Cybersecurity – Week 34 (2026)
U.S. indicts Iranian cyber espionage operations, Medusa ransomware breaches 500 organizations, and attackers exploit a critical Windows protocol flaw.
SentinelOne Vulnerabilidades sentinelone.com - jueves 20 ago
-
Black Hat USA 2026: ¿caerá el descubrimiento de vulnerabilidades en la era de la IA?
El descubrimiento acelerado de vulnerabilidades impulsado por IA plantea una pregunta clave: ¿disminuirá el hallazgo de nuevas fallas de seguridad en el futuro?
WeLiveSecurity (ESET) Vulnerabilidades welivesecurity.com -
Identity Abuse Through Trusted Communication Channels
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.
Unit 42 Vulnerabilidades unit42.paloaltonetworks.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.