Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 27 min 959 titulares en el archivo
Qué se está publicando
Distribución por tema
141 titulares de severidad Alta Limpiar filtros ×
- martes 11 ago
-
Johnson Controls C-CURE 9000 and Victor application server (Update A)
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker with network access to achieve remote code execution. The following versions of Johnson Controls C-CURE 9000 and Victor application server (Update…
CISA Advisories Vulnerabilidades cisa.gov -
US and South Korea warn of Gunra ransomware targeting govt agencies
U.S. federal agencies and South Korea's National Policy Agency warned government and critical infrastructure organizations worldwide to secure their systems against Gunra ransomware attacks. [...]
BleepingComputer Amenazas bleepingcomputer.com -
Ransomware gangs don’t need control system access to disrupt industrial production
Disrupting IT systems that support industrial environments can be enough to interrupt production, even when ransomware operators do not gain direct access to industrial control systems (ICS), according to Dragos. The company identified…
Help Net Security Amenazas helpnetsecurity.com -
Gunra Ransomware Exploits Fortinet and Schneider Electric Flaws to Breach Networks
Cybersecurity and intelligence agencies from South Korea and the U.S. warned of Gunra ransomware attacks targeting critical infrastructure sectors and organizations across the world. Targets of these attacks include healthcare and public…
The Hacker News Vulnerabilidades thehackernews.com -
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike…
The Hacker News Infraestructura thehackernews.com - lunes 10 ago
-
FBI, South Korea warn of Gunra ransomware gang targeting critical infrastructure
The Gunra ransomware gang is breaching critical infrastructure organizations through vulnerabilities in popular brands of firewalls, the FBI and South Korea’s government warned.
The Record Vulnerabilidades therecord.media -
The Patch Gap: Why Defenders Need to Think in Chains, Not Checklists
It's time to turn from CVSS-backed patching to choke-point patching focused on breaking chains to critical assets.
Dark Reading Vulnerabilidades darkreading.com -
New StormEncryptor ransomware used by former Medusa affiliate
A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]
BleepingComputer Amenazas bleepingcomputer.com -
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from the adversary's…
The Hacker News Amenazas thehackernews.com -
DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations…
Microsoft Security Blog Amenazas microsoft.com -
Cyberattack on Steam hardware shipper leaks names, addresses, and order data
Video game publisher Valve is alerting customers in Europe to a data breach at CEVA Logistics, its Steam hardware shipping partner. Reports from affected customers began surfacing on social media earlier today, after Valve started sending…
Help Net Security Amenazas helpnetsecurity.com -
CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns
The current GPT-5.6-Sol has been assigned a ‘high’ cybersecurity threshold, but Astra could reach the maximum ‘critical’ threshold. The post OpenAI’s Upcoming Astra Model Raises Autonomous Cyberattack Concerns appeared first on…
SecurityWeek Seguridad IA securityweek.com - domingo 9 ago
-
Show, Don't Tell: What Evo Continuous Offensive Security Found in a Real Enterprise SaaS
A real Evo Continuous Offensive Security assessment uncovered 33 confirmed vulnerabilities in a multi-tenant enterprise SaaS, including tenant-wide compromise and critical authorization flaws.
Snyk Vulnerabilidades snyk.io - viernes 7 ago
-
The Good, the Bad and the Ugly in Cybersecurity – Week 32 (2026)
Snowflake hacker's guilty plea covers a 100M-record breach, Mythos 5 spends 34 hours trying to backdoor real code, and ChainDrop's worm spreads via npm.
SentinelOne Amenazas sentinelone.com - lunes 3 ago
-
Top AI Coding Agent security resources — August 2026
August 2026's AI coding agent security roundup: a symlink flaw across six assistants, Cursor's CVSS 9.8 pair, a private repo leak, and a wiped database.
Adversa AI Seguridad IA adversa.ai - viernes 31 jul
-
Top Agentic AI security resources — August 2026
Four teams broke production AI agents in ten days. Twenty resources on the Kiro RCE, Cursor's CVSS 9.8 pair, memory poisoning, and sandbox escapes.
Adversa AI Seguridad IA adversa.ai - martes 28 jul
-
Disrupting supply chain attacks on npm and GitHub Actions
Explore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact. The post Disrupting supply chain attacks on npm and GitHub Actions appeared first on…
GitHub Security Infraestructura github.blog - domingo 19 jul
-
Autonomous AI Intrusions Are Here: Lessons from the Hugging Face Compromise
Hugging Face disclosed an intrusion that, according to them, was driven end to end by an autonomous AI agent system. Along similar lines, Sysdig recently published a blog on JADEPUFFER, which it assesses to be an agent-driven ransomware…
Embrace The Red Seguridad IA embracethered.com - viernes 10 jul
-
CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys
In this excerpt of a TrendAI Research Services vulnerability report, Yazhi Wang and Jonathan Lein of the TrendAI Research team detail a recently patched remote code execution bug in the Windows HTTP protocol stack. Successful exploitation…
Zero Day Initiative Vulnerabilidades thezdi.com - lunes 4 may
-
Stronger Cybersecurity, Stronger Business: NIST Celebrates 2026 National Small Business Week
Happy National Small Business Week! For over 60 years, the U.S. Small Business Administration has led this initiative to acknowledge the critical contributions of America’s entrepreneurs and small business owners. Part of the U.S…
NIST Cybersecurity General nist.gov
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.