Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 51 min 959 titulares en el archivo
Qué se está publicando
Distribución por tema
212 titulares en Vulnerabilidades Limpiar filtros ×
- miércoles 19 ago
-
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
OverviewOn August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3…
Rapid7 Vulnerabilidades rapid7.com -
Cuatro vulnerabilidades críticas siendo explotadas se agregan a KEV (macOS, SharePoint, vCenter, Microsoft IKE)
La Agencia CISA añadió este martes cuatro vulnerabilidades críticas a su catálogo de Vulnerabilidades Explotadas Conocidas (KEV), indicando que están siendo explotadas activamente. Las vulnerabilidades añadidas al catálogo KEV se detallan…
Segu-Info Vulnerabilidades blog.segu-info.com.ar -
Oracle Critical Patch Update, August 2026 Security Update Review
Oracle released its August edition of Critical Patch Update. The update received patches for 943 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address…
Qualys Vulnerabilidades blog.qualys.com - martes 18 ago
-
Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs
Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates.Key TakeawaysThe August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943…
Tenable Vulnerabilidades tenable.com -
Remediation Agents, Demystified: Why Fixing Beats Finding
See how Snyk’s Remediation Agent uses security intelligence, breakability analysis, and validation to turn vulnerabilities into mergeable pull requests.
Snyk Vulnerabilidades snyk.io -
CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now
Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces…
Qualys Vulnerabilidades blog.qualys.com -
SafePal y Trezor revelan sendas brechas de datos en sus sistemas de pedidos
SafePal ha revelado que una vulnerabilidad de autorización en un complemento de seguimiento de pedidos expuso los nombres, direcciones de correo electrónico, direcciones de envío, números de teléfono y detalles de compra de aproximadamente…
Segu-Info Vulnerabilidades blog.segu-info.com.ar -
Benchmarking Secure-and-Functional Remediation and How Snyk Agent Fix Lifts Frontier-Model Fix Rates by over 14%
A benchmark of secure, functional vulnerability fixes across JavaScript, Java, and Python shows Snyk Intelligence helps frontier models break past a 72–75% performance plateau.
Snyk Vulnerabilidades snyk.io - lunes 17 ago
-
Cadena de exploits para videollamadas VoLTE Unisoc otorga acceso completo al kernel de Android
Investigadores de seguridad de SSD Secure Disclosure han publicado una cadena de exploits en dos etapas que permite el acceso completo al kernel de Android en dispositivos con firmware de módem Unisoc mediante una videollamada VoLTE, sin…
Segu-Info Vulnerabilidades blog.segu-info.com.ar - viernes 14 ago
-
The Good, the Bad and the Ugly in Cybersecurity – Week 33 (2026)
Courts sentence Com member for sextorting 117 minors, joint advisory warns of Gunra ransomware, and ShieldBreak bypasses MS Defender for SYSTEM access.
SentinelOne Vulnerabilidades sentinelone.com - jueves 13 ago
-
Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040)
Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About CVE-2026-55040 Tracked as CVE-2026-55040, the vulnerability was patched by Microsoft as…
Help Net Security Vulnerabilidades helpnetsecurity.com -
WordPress 7.0.4 Patches Remote Code Execution Vulnerability
Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files. The post WordPress 7.0.4 Patches Remote Code Execution Vulnerability appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com -
Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com -
Critical VMware vCenter Vulnerability in Attackers’ Crosshairs
Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com -
Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges. The post Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com -
Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)
A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog…
Help Net Security Vulnerabilidades helpnetsecurity.com -
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical…
The Hacker News Vulnerabilidades thehackernews.com - miércoles 12 ago
-
Wireshark 4.6.8 patches 28 security bugs, nine in file parsers
Wireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that reads a capture off disk before any dissection begins: pcapng…
Help Net Security Vulnerabilidades helpnetsecurity.com -
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace…
The Hacker News Vulnerabilidades thehackernews.com -
Lazarus hackers exploited Windows zero-day to target defense firms
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
SharePoint Vulnerability Exploited Shortly After PoC Release
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild. The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com -
The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In
Fake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help…
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Exposed: Woeful security at UK criminal records office that led to sensitive data leak
Nobody patched the CMS or read the alerts, and ACRO still cannot tell whether info was exfiltrated
The Register · Security Vulnerabilidades theregister.com -
Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom Toolset
Researchers observed the novel campaign exploiting unauthenticated guest access to quietly enumerate and exfiltrate exposed data from both platforms. The post Stealthy ‘City-Forum’ Attacks Target Salesforce and ServiceNow With Custom…
SecurityWeek Vulnerabilidades securityweek.com -
Three intrusions at UK criminal records office went undetected for two years
Unread antivirus alerts and an unpatched content management system exposed Britain's ACRO to three separate data breaches, according to a reprimand notice.
The Record Vulnerabilidades therecord.media -
Hackers leverage new Microsoft SharePoint exploit in attacks
Hackers have already begun using a proof-of-concept (PoC) exploit for a critical Microsoft SharePoint vulnerability, published by cybersecurity company Rapid7 on Tuesday. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
CISA gives federal agencies two weeks to patch Microsoft bug exploited in DPRK campaign
Researchers disclosed the bug to Microsoft after examining a long-running campaign by North Korean hackers to exploit the job application process.
The Record Vulnerabilidades therecord.media -
Lazarus hackers pair fake job offers with Windows zero-day exploit
The North Korea-linked Lazarus group is using fake job offers, trojanized PDF software and a Windows zero-day in attacks aimed primarily at the defense sector, Check Point researchers have found. The activity is part of Operation Dream…
Help Net Security Vulnerabilidades helpnetsecurity.com -
Adobe Patches Three CVSS 10.0 ColdFusion and Campaign Classic Flaws
Adobe has shipped updates to address multiple critical security vulnerabilities impacting ColdFusion, Commerce, and Campaign Classic that, if successfully exploited, could result in arbitrary code execution and privilege escalation. The…
The Hacker News Vulnerabilidades thehackernews.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.