Edición del 1 de septiembre de 2026

Ciberseguridad — edición del 2026-09-01

Malware Sality botnet infrastructure dismantled in joint global takedown
Imagen: BleepingComputer
Lo más reciente Malware

Sality botnet infrastructure dismantled in joint global takedown

International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet.

Fuente: BleepingComputer Publicado: 02/09/2026 · 04:00 UTC No se pudo traducir automáticamente (se muestra el original).
Leer la noticia completa →

Últimas noticias

Ciberseguridad Ilustrativo
Ilustración genérica de la categoría Ciberseguridad; no es una foto real del hecho
Ciberseguridad

FBI Probes Service Selling 153M+ Drivers Licenses

A new identity theft service launched on the dark web this week is selling digital scans of more than 153 million drivers licenses from people in the United States and Canada. Based on interviews with individuals whose licenses are available for purchase on this service, it appears to be siphoning images collected by a widely-used identity verification company based in Louisiana. KrebsOnSecurity also has learned that the New Orleans field office of the Federal Bureau of Investigation (FBI) today launched an official inquiry into the source of the images.

Fuente: Krebs on Security Publicado: 01/09/2026 · 22:40 UTC No se pudo traducir automáticamente (se muestra el original).
Vulnerabilidad Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
Imagen: The Hacker News
Vulnerabilidad

Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure

Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory. "JFrog Artifactory contains an authentication weakness that, under default…

Fuente: The Hacker News Publicado: 01/09/2026 · 17:53 UTC No se pudo traducir automáticamente (se muestra el original). Resumen parcial: la fuente no incluye más detalle en su RSS; lee la noticia completa en la fuente.
Ciberseguridad Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Imagen: The Hacker News
Ciberseguridad

Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems

Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams described the threat actor as "specializing in manipulating payment systems and banking software in Brazil to conduct fraudulent transfers." The adversary…

Fuente: The Hacker News Publicado: 01/09/2026 · 17:19 UTC No se pudo traducir automáticamente (se muestra el original). Resumen parcial: la fuente no incluye más detalle en su RSS; lee la noticia completa en la fuente.
Malware 13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Imagen: The Hacker News
Malware

13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds

Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The injected code runs two operations against a site's visitors: a mobile ad-fraud and gambling-redirect…

Fuente: The Hacker News Publicado: 01/09/2026 · 14:07 UTC No se pudo traducir automáticamente (se muestra el original). Resumen parcial: la fuente no incluye más detalle en su RSS; lee la noticia completa en la fuente.
Malware Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
Imagen: The Hacker News
Malware

Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests

The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian cybersecurity company Kaspersky is tracking…

Fuente: The Hacker News Publicado: 01/09/2026 · 13:08 UTC No se pudo traducir automáticamente (se muestra el original). Resumen parcial: la fuente no incluye más detalle en su RSS; lee la noticia completa en la fuente.
Ciberseguridad Why Even the Best Edge Security Still Misses High-Risk Sessions
Imagen: BleepingComputer
Ciberseguridad

Why Even the Best Edge Security Still Misses High-Risk Sessions

Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations identify risky sessions and make stronger enforcement decisions.

Fuente: BleepingComputer Publicado: 01/09/2026 · 10:01 UTC No se pudo traducir automáticamente (se muestra el original).
Vulnerabilidad Ilustrativo
Ilustración genérica de la categoría Vulnerabilidad; no es una foto real del hecho
Vulnerabilidad

Falta de autorización en OpenNebula de OpenNebula Systems

Falta de autorización en OpenNebula de OpenNebula Systems Mar, 01/09/2026 - 09:54 Aviso Recursos Afectados OpenNebula 7.4. Descripción INCIBE ha coordinado la publicación de una vulnerabilidad de severidad alta que afecta a OpenNebula de OpenNebula Systems, una plataforma para la gestión de datos virtualizados. La vulnerabilidad ha sido descubierta por Yonghwa Lee, Xint de Theori.

Fuente: INCIBE-CERT - Avisos Publicado: 01/09/2026 · 07:54 UTC
Vulnerabilidad Inyección de código en el Core de Lutece
Imagen: INCIBE-CERT - Avisos
Vulnerabilidad

Inyección de código en el Core de Lutece

Inyección de código en el Core de Lutece Mar, 01/09/2026 - 09:28 Aviso Recursos Afectados Lutece Core: versión 7.1.7 y anteriores. Descripción INCIBE ha coordinado la publicación de una vulnerabilidad de severidad crítica en Lutece Core, una plataforma abierta que permite a los gobiernos municipales compartir, reutilizar y adaptar servicios digitales. La vulnerabilidad ha sido descubierta por Dorian Piette (Trachinus).

Fuente: INCIBE-CERT - Avisos Publicado: 01/09/2026 · 07:28 UTC