Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 10 min 957 titulares en el archivo
Qué se está publicando
Distribución por tema
96 titulares en Vulnerabilidades de severidad Media Limpiar filtros ×
- Hoy
-
Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities
Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting…
The Hacker News Vulnerabilidades thehackernews.com - Ayer
-
CVE-2015-3673: Goodbye Rootpipe...(for now?)
Details on bypassing Apple's original rootpipe patch
Objective-See Vulnerabilidades objective-see.org -
In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation
Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion. The post In Other News: Microsoft’s Cloud…
SecurityWeek Vulnerabilidades securityweek.com -
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS…
The Hacker News Vulnerabilidades thehackernews.com -
G7 urges organizations to prepare for quantum cyber threats
In a joint advisory released Thursday, the G7 Cyber Security Working Group and the U.S. Cybersecurity and Infrastructure Security Agency, CISA, said organizations should begin moving to post-quantum cryptography now.
The Record Vulnerabilidades therecord.media -
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media…
The Hacker News Vulnerabilidades thehackernews.com -
September 2026 Patch Tuesday forecast: All we need is more time
The Patch Apocalypse is continuing unabated. We are seeing record numbers of patches being released and reported CVEs continue to grow as well. August 2026 Patch Tuesday was the second biggest in history with 398 resolved CVEs: 42 rated…
Help Net Security Vulnerabilidades helpnetsecurity.com - jueves 3 sep
-
Pegasus Zero-Click Exploit Infects Serbian Student Activist's iPhone
Pegasus infected a Serbian student activist's iPhone through an iMessage zero-click exploit
Infosecurity Magazine Vulnerabilidades infosecurity-magazine.com -
Drowning in CVEs and thirsty for answers? Try CTEM
Boards want to know if they're less exposed than last quarter. Patching metrics aren't the solution
The Register · Security Vulnerabilidades theregister.com -
Atacantes aprovechan un fallo crítico en JFrog Artifactory para emitir tokens de administrador
Una vulnerabilidad crítica en JFrog Artifactory, CVE-2026-82329, se explota de forma activa para generar tokens de administrador sin autenticación en instalaciones self managed con ajustes por defecto. El mayor peligro no es solo el…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com -
Rockwell Automation 1756-ENBT Module
View CSAF Summary Successful exploitation of this vulnerability could crash the module. The device requires a restart to recover. The following versions of Rockwell Automation 1756-ENBT Module are affected: 1756-ENBT module vers:all/*…
CISA Advisories Vulnerabilidades cisa.gov -
Tycon Systems TPDIN-Monitor-WEB2 (Update A)
View CSAF Summary Successful exploitation of these vulnerabilities could result in an attacker accessing sensitive credentials, disrupting connected infrastructure, or manipulating physical equipment, which could present a physical safety…
CISA Advisories Vulnerabilidades cisa.gov -
Inductive Automation Ignition
View CSAF Summary Successful exploitation of this vulnerability could allow any authenticated user to create projects. The following versions of Inductive Automation Ignition are affected: Ignition
CISA Advisories Vulnerabilidades cisa.gov -
OPCFoundation OPC UA LocalDiscoveryServer (LDS)
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to take control of a high-privilege terminal during installation and run arbitrary commands. The following versions of OPCFoundation OPC UA…
CISA Advisories Vulnerabilidades cisa.gov -
Tycon Systems TPDIN-Monitor-WEB3
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle (MitM) attack, cause a factory reset, wipe credentials, or retrieve sensitive information. The following versions…
CISA Advisories Vulnerabilidades cisa.gov -
Rockwell Automation ControlFLASH
View CSAF Summary Successful exploitation of this vulnerability could give an attacker the ability to run any commands or code of the attacker's choice on a target machine at the logged-in user's permission level. The following versions of…
CISA Advisories Vulnerabilidades cisa.gov -
Rockwell Automation ArmorStart LT
View CSAF Summary Successful exploitation of these vulnerabilities could result in a loss of webserver availability or allow an attacker to inject malicious scripts that will be executed when other users access the affected page. The…
CISA Advisories Vulnerabilidades cisa.gov -
Pyramid Solutions NetStaX EtherNet/IP Stack
View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential remote attack vector without the originating device receiving a CIP error indicating that the request could…
CISA Advisories Vulnerabilidades cisa.gov -
Plex warns users to patch security vulnerabilities immediately
Plex urged users this week to update their desktop clients and media servers immediately to patch multiple security vulnerabilities. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Microsoft Teams, Outlook fail to launch on ARM-based Windows PCs
Microsoft is working to fix a known issue that causes crashes and launch failures for Microsoft Teams and New Outlook users after installing updates released since the August 2026 Patch Tuesday. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Pegasus Zero-Click Spyware Exploit Infects Serbian Student Movement Member's iPhone
The iPhone belonging to a member of Serbia's student protest movement was infected with NSO Group's Pegasus spyware, according to new findings from the Citizen Lab in collaboration with the SHARE Foundation. "Our analysis confirmed that an…
The Hacker News Vulnerabilidades thehackernews.com -
Seemplicity Response Options accelerates vulnerability mitigation
Seemplicity announced Response Options for vulnerability management and exposure management workflows. This new capability gives security teams multiple, actionable paths to closing a vulnerability finding based on context. The problem…
Help Net Security Vulnerabilidades helpnetsecurity.com - miércoles 2 sep
-
How Developers Prevent Production Risk at the Source
Fixing security vulnerabilities in code takes seconds, while patching in production creates high operational costs and risk. Discover how empowering developers as your first line of defense eliminates exposure across every phase of your…
Wiz Vulnerabilidades wiz.io -
Sniffing Authentication References on macOS
CVE-2017-7170 was a local priv-esc vulnerability that affected OSX/macOS for over a decade! Here (for the first time!), we dive into the technical details of finding the bug, the core flaw, and exploitation.
Objective-See Vulnerabilidades objective-see.org -
Anatomy of a Silent Domain Takeover
Key Takeaways Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint. The evidence is already in the logs; what is missing is the narrative linking five benign-looking…
Qualys Vulnerabilidades blog.qualys.com -
Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately. How…
Help Net Security Vulnerabilidades helpnetsecurity.com -
Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products. The post Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products appeared first on…
SecurityWeek Vulnerabilidades securityweek.com -
Dropbox accounts breached through Lenovo email verification flaw
Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Exploit Published for Fresh Cleo Harmony Vulnerability
The security defect allows remote attackers to bypass authentication through argument bearer manipulation. The post Exploit Published for Fresh Cleo Harmony Vulnerability appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com - martes 1 sep
-
Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Threat actors exploited commodity vulnerabilities in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.
Dark Reading Vulnerabilidades darkreading.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.