Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 13 min 957 titulares en el archivo
Qué se está publicando
Distribución por tema
57 titulares en Vulnerabilidades de severidad Crítica Limpiar filtros ×
- Ayer
-
Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Google corrige un día cero de V8 en Chrome que se explota de forma activa
Google ha distribuido una actualización urgente de Chrome para corregir CVE-2026-85046, un zero-day en V8 con explotación activa. La solución pasa por actualizar a Chrome 152.0.7977.82 o superior y reiniciar el navegador para aplicar el…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com -
Actualización de Chrome corrige vulnerabilidad Zero-Day de V8 que se encuentra activamente explotada
Google publicó el jueves actualizaciones de seguridad para corregir 12 vulnerabilidades, incluyendo una que ha sido explotada activamente. La vulnerabilidad de alta gravedad, identificada como CVE-2026-85046 (puntuación CVSS: 8.8), se…
Segu-Info Vulnerabilidades blog.segu-info.com.ar -
Sangoma Switchvox Vulnerabilities Exploited in the Wild
Tracked as CVE-2026-9586, the unauthenticated SQL injection flaw can be exploited remotely for arbitrary code execution. The post Sangoma Switchvox Vulnerabilities Exploited in the Wild appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com -
New CrowdStrike 'FalconFlank' zero-day grants SYSTEM privileges
An anonymous security researcher who uses the "Nightmare Eclipse" handle released a CrowdStrike Falcon zero-day exploit named "FalconFlank" that lets attackers escalate privileges on up-to-date Windows systems. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Google patches actively exploited Chrome zero-day (CVE-2026-85046)
Google has patched 12 vulnerabilities affecting its popular Chrome browser, among them CVE-2026-85046, which has been exploited in the wild. “Google is aware that an exploit for CVE-2026-85046 exists in the wild,” the company said in a…
Help Net Security Vulnerabilidades helpnetsecurity.com -
CISA Adds One Known Exploited Vulnerability to Catalog
CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-85046 Google Chromium V8 Type Confusion Vulnerability This type of vulnerability is a frequent…
CISA Advisories Vulnerabilidades cisa.gov -
Google warns of new Chrome zero-day flaw exploited in attacks
Google has updated the Chrome browser to address an actively exploited high-severity zero-day flaw in the V8 engine and 11 other vulnerabilities. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Google Patches 6th Chrome Zero-Day of 2026
Google’s Chrome 152 security update resolves 12 vulnerabilities, including a high-severity type confusion flaw in the V8 engine. The post Google Patches 6th Chrome Zero-Day of 2026 appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com -
Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described…
The Hacker News Vulnerabilidades thehackernews.com - jueves 3 sep
-
Prolific Microsoft 0-day hunter drops CrowdStrike Falcon exploit PoC
A shared security 'Nightmare'
The Register · Security Vulnerabilidades theregister.com -
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day…
The Hacker News Vulnerabilidades thehackernews.com -
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows…
The Hacker News Vulnerabilidades thehackernews.com - miércoles 2 sep
-
SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
Dark Reading Vulnerabilidades darkreading.com -
Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
OverviewOn September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549, can be…
Rapid7 Vulnerabilidades rapid7.com -
SonicWall's SMA1000 boxes under active attack again
Miscreants use chained zero days to pwn boxen as third-party SOCs say further attacks 'almost certain'
The Register · Security Vulnerabilidades theregister.com -
CISA Adds Seven Known Exploited Vulnerabilities to Catalog
CISA has added seven new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9586 Sangoma Switchvox SQL Injection Vulnerability CVE-2026-48710 Kludex Starlette HTTP…
CISA Advisories Vulnerabilidades cisa.gov -
Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain
SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in zero-day attacks. The vulnerabilities, discovered internally by…
The Hacker News Vulnerabilidades thehackernews.com -
SonicWall SMA 1000 appliances under attack via zero-day flaws
Attackers are exploiting two previously undisclosed vulnerabilities (CVE-2026-83548, CVE-2026-83549) in SonicWall SMA 1000 appliances, the vendor confirmed on Tuesday. The vulnerabilities (CVE-2026-83548, CVE-2026-83549) The SonicWall SMA…
Help Net Security Vulnerabilidades helpnetsecurity.com -
GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends
Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government and agency geoportals. The project shipped fixes in…
The Hacker News Vulnerabilidades thehackernews.com -
Hackers Chain Two New SonicWall Zero-Day Vulnerabilities
SonicWall has urged customers to patch two new zero-day vulnerabilities being exploited in the wild
Infosecurity Magazine Vulnerabilidades infosecurity-magazine.com -
SonicWall warns of actively exploited SMA1000 zero-day flaws
SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks
The vulnerabilities CVE-2026-83549 and CVE-2026-83548 can be chained for unauthenticated remote code execution. The post SonicWall Warns of Two SMA1000 Zero-Days Exploited in Attacks appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com - lunes 31 ago
-
"Si no se parchean las vulnerabilidades KEV, no se está protegido"
El Informe de Vulnerabilidades de CISA para los años 2024 y 2025, publicado recientemente, transmite un mensaje contundente: las brechas de seguridad que acaparan titulares rara vez se basan en vulnerabilidades de día cero. En cambio, la…
Segu-Info Vulnerabilidades blog.segu-info.com.ar -
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability CVE-2026-82078…
CISA Advisories Vulnerabilidades cisa.gov - viernes 28 ago
-
PaperCut NG/MF Critical Zero-Day Exploited in the Wild
Overview On August 27, 2026, PaperCut Software published an urgent security advisory stating that it is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF. PaperCut has confirmed customer incidents…
Rapid7 Vulnerabilidades rapid7.com -
CISA impone un parche urgente por un fallo crítico en Citrix NetScaler con explotación activa
CISA ha metido CVE-2026-8452 en su catálogo Known Exploited Vulnerabilities y obliga a las agencias federales de EEUU a parchear Citrix NetScaler antes del 29 de agosto de 2026. La falla, que empezó describiéndose como un problema de…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com - jueves 27 ago
-
PaperCut Zero-Day: Active Exploitation and Pre-Auth RCE
PaperCut NG and PaperCut MF are under active exploitation. Huntress reproduced a pre-auth RCE chain and shares urgent patching, exposure, and detection guidance.
Huntress Vulnerabilidades huntress.com -
CISA suma seis fallos explotados al catálogo KEV y eleva la urgencia de parcheo en NetScaler, Linux y SQL Server
CISA añadió el 26 de agosto de 2026 seis vulnerabilidades al catálogo Known Exploited Vulnerabilities (KEV), una señal de explotación activa que suele marcar prioridades inmediatas de corrección. El lote incluye un fallo reciente en Citrix…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com - miércoles 26 ago
-
CISA Adds Six Known Exploited Vulnerabilities to Catalog
CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability CVE-2015-5287 Red Hat Automatic Bug Reporting…
CISA Advisories Vulnerabilidades cisa.gov
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.