Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 49 min 961 titulares en el archivo
Qué se está publicando
Distribución por tema
212 titulares en Vulnerabilidades Limpiar filtros ×
- martes 11 ago
-
CISA: Microsoft SharePoint flaw now exploited in ransomware attacks
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Head Mare APT is exploiting vulnerabilities in an unpatched TrueConf server to deliver PhantomCore and PhantomGraph to video conference participants
Kaspersky experts have discovered malicious TrueConf software installers. The Head Mare APT group uses them to deliver the PhantomCore and PhantomGraph backdoors to target systems by exploiting vulnerabilities in an unpatched TrueConf…
Securelist (Kaspersky) Vulnerabilidades securelist.com -
Johnson Controls C-CURE 9000 and Victor application server (Update A)
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor application server (Update…
CISA Advisories Vulnerabilidades cisa.gov -
Mira Hormone Monitor, Mira Android App
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access unauthorized health profile information, make changes to health information, cause a denial-of-service condition, disclose session token…
CISA Advisories Vulnerabilidades cisa.gov -
Pulsetto Vagus Nerve Stimulator
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to use hidden commands to disable electrical safety mechanisms or modify other stimulation output settings. The following versions of Pulsetto Vagus…
CISA Advisories Vulnerabilidades cisa.gov -
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense…
CISA Advisories Vulnerabilidades cisa.gov -
Cisco warns of high-severity ClamAV flaws with public exploits
Cisco warned of two high-severity vulnerabilities affecting the Secure Endpoint Connector that allow threat actors to crash the ClamAV scanning process in denial-of-service (DoS) attacks. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public…
The Hacker News Vulnerabilidades thehackernews.com - lunes 10 ago
-
Metabase SQL Zero-Day Attacks Could Have Wide Blast Radius
The maximum-severity vulnerability, which still has no CVE, allows malicious, remote administrator access to the business-analytics platform and its downstream users.
Dark Reading Vulnerabilidades darkreading.com -
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.
The Record Vulnerabilidades therecord.media -
The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists
It's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.
Dark Reading Vulnerabilidades darkreading.com -
Coruna, DarkSword iOS Exploits Proliferate Globally
Sophisticated iPhone exploit chains previously limited to nation-states are spreading far and wide to organized cybercrime groups.
Dark Reading Vulnerabilidades darkreading.com -
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com - domingo 9 ago
-
Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS
A real Evo Continuous Offensive Security assessment uncovered 33 confirmed vulnerabilities in a multi-tenant enterprise SaaS, including tenant-wide compromise and critical authorization flaws.
Snyk Vulnerabilidades snyk.io - jueves 30 jul
-
The July 2026 Apple Security Update Review
Welcome to our monthly look at Apple security patches. This release shows that Apple is not immune to the bug apocalypse that is impacting other vendors. Last month, they released 37 unique CVEs compare to this month’s 210. Quite a…
Zero Day Initiative Vulnerabilidades thezdi.com - miércoles 22 jul
-
Next chapter: Restructuring GitHub’s bug bounty program
GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team. The post Next chapter: Restructuring GitHub’s bug bounty program appeared first…
GitHub Security Vulnerabilidades github.blog - martes 14 jul
-
Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch…
Krebs on Security Vulnerabilidades krebsonsecurity.com -
The July 2026 Security Update Review
Well folks. Here we are. The bug apocalypse has fully descended upon us. I’ll do my best to sort this out in some way meaningful, but this month’s release shows us the nay-sayers were right, and I’ve got to hand it to the nay-sayers here…
Zero Day Initiative Vulnerabilidades thezdi.com - viernes 10 jul
-
CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys
In this excerpt of a TrendAI Research Services vulnerability report, Yazhi Wang and Jonathan Lein of the TrendAI Research team detail a recently patched remote code execution bug in the Windows HTTP protocol stack. Successful exploitation…
Zero Day Initiative Vulnerabilidades thezdi.com - miércoles 8 jul
-
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake…
Krebs on Security Vulnerabilidades krebsonsecurity.com - lunes 6 jul
-
OWASP CVE Lite CLI Graduates to Lab Project Status
CVE Lite CLI, a fast open source dependency vulnerability scanner for JavaScript and TypeScript projects, has graduated to OWASP Lab Project status three months after its initial release. OWASP CVE Lite CLI graduated to Lab Project status…
OWASP Vulnerabilidades owasp.org - miércoles 1 jul
-
The June 2026 Apple Security Update Review
We’re back with our look at the Apple macOS and iOS security updates. As this is a new feature for us, please let us know your feedback on the blog. For June 2026, Apple released 37 unique CVEs across iOS 26.5.2 / iPadOS 26.5.2, macOS…
Zero Day Initiative Vulnerabilidades thezdi.com - lunes 29 jun
-
Inside the Advisory Database and what happens when vulnerability volume breaks records
The GitHub Advisory Database is processing more vulnerability reports than ever before. Here's what's driving the surge, how we're responding, and how the community can help. The post Inside the Advisory Database and what happens when…
GitHub Security Vulnerabilidades github.blog - martes 9 jun
-
The June 2026 Security Update Review
I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break…
Zero Day Initiative Vulnerabilidades thezdi.com - miércoles 27 may
-
Football Fever Fuels Scam Campaigns Across Email and Social Media
Football fans are increasingly targeted by scams exploiting club loyalty, national teams, football collectibles, streaming demand, and the growing excitement around the FIFA World Cup 2026, according to Bitdefender Labs. Our most recent…
Bitdefender Labs Vulnerabilidades bitdefender.com - martes 19 may
-
Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows
Bitdefender security researchers have discovered that attackers continue to exploit Microsoft HTML Application Host (MSHTA), a legacy utility available by default on Windows systems that can execute VBScript and JavaScript from local or…
Bitdefender Labs Vulnerabilidades bitdefender.com - sábado 16 may
-
Pwn2Own Berlin 2026: Day Three Results and Master of Pw
Following two days of intense competition, Day Three of Pwn2Own Berlin 2026 brought the curtain down on an incredible event. Security researchers delivered their final exploits, pushing enterprise systems to the limit one last time as the…
Zero Day Initiative Vulnerabilidades thezdi.com - viernes 15 may
-
Raising the bar: Quality, shared responsibility, and the future of GitHub’s bug bounty program
We're updating our bug bounty program standards to prioritize quality submissions, clarify shared responsibility boundaries, and evolve how we reward low-risk findings. The post Raising the bar: Quality, shared responsibility, and the…
GitHub Security Vulnerabilidades github.blog -
Pwn2Own Berlin 2026 - Day Two Results
Day Two of Pwn2Own Berlin 2026 and the stakes continue to rise! Security researchers are back on the Pwn2Own stage, pushing enterprise systems to their limits as the competition heats up. More exploits, more surprises, and more standout…
Zero Day Initiative Vulnerabilidades thezdi.com - viernes 10 abr
-
Bringing Rust to the Pixel Baseband
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks…
Google Security Blog Vulnerabilidades security.googleblog.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.