Edición del 4 de septiembre de 2026

Ciberseguridad — edición del 2026-09-04

Filtración de datos IDScan sued over alleged data breach affecting 153 million drivers
Imagen: BleepingComputer
Lo más reciente Filtración de datos

IDScan sued over alleged data breach affecting 153 million drivers

Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses…

Fuente: BleepingComputer Publicado: 04/09/2026 · 16:56 UTC No se pudo traducir automáticamente (se muestra el original). Resumen parcial: la fuente no incluye más detalle en su RSS; lee la noticia completa en la fuente.
Leer la noticia completa →

Últimas noticias

Phishing Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Imagen: The Hacker News
Phishing

Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters

Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the attacker used them to split financial lure words such as 'funding' to prevent email filters from parsing them," the Microsoft Security Research team said.…

Fuente: The Hacker News Publicado: 04/09/2026 · 15:57 UTC No se pudo traducir automáticamente (se muestra el original). Resumen parcial: la fuente no incluye más detalle en su RSS; lee la noticia completa en la fuente.
Vulnerabilidad Critical Citrix NetScaler auth bypass now leveraged in attacks
Imagen: BleepingComputer
Vulnerabilidad

Critical Citrix NetScaler auth bypass now leveraged in attacks

Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian…

Fuente: BleepingComputer Publicado: 04/09/2026 · 15:25 UTC No se pudo traducir automáticamente (se muestra el original). Resumen parcial: la fuente no incluye más detalle en su RSS; lee la noticia completa en la fuente.
Vulnerabilidad PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
Imagen: The Hacker News
Vulnerabilidad

PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution

PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score: 7.2), has been present since logical decoding was introduced in PostgreSQL 9.4 in 2014. Versions before PostgreSQL 18.6, 17.11, 16.15, 15.19, and 14.24 are…

Fuente: The Hacker News Publicado: 04/09/2026 · 15:20 UTC No se pudo traducir automáticamente (se muestra el original). Resumen parcial: la fuente no incluye más detalle en su RSS; lee la noticia completa en la fuente.
Vulnerabilidad New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
Imagen: The Hacker News
Vulnerabilidad

New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic

A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The attackers named the implant ted in debug strings left in the binary. It is not a HAProxy vulnerability, and installing it requires code execution on the host…

Fuente: The Hacker News Publicado: 04/09/2026 · 14:51 UTC No se pudo traducir automáticamente (se muestra el original). Resumen parcial: la fuente no incluye más detalle en su RSS; lee la noticia completa en la fuente.
Ciberseguridad 39 New Methods That Compromise Passkey Authentication
Imagen: BleepingComputer
Ciberseguridad

39 New Methods That Compromise Passkey Authentication

Passkeys eliminate many password-based attacks, but researchers have documented 39 methods for compromising authentication built around them. Token explains how attackers can abuse authentication prompts, synced credentials, enrollment, recovery, and other trust boundaries without breaking FIDO2 cryptography.

Fuente: BleepingComputer Publicado: 04/09/2026 · 10:01 UTC No se pudo traducir automáticamente (se muestra el original).
Vulnerabilidad Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws
Imagen: The Hacker News
Vulnerabilidad

Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files of any type, including…

Fuente: The Hacker News Publicado: 04/09/2026 · 08:48 UTC No se pudo traducir automáticamente (se muestra el original). Resumen parcial: la fuente no incluye más detalle en su RSS; lee la noticia completa en la fuente.
Vulnerabilidad Múltiples vulnerabilidades en productos de VMware
Imagen: INCIBE-CERT - Avisos
Vulnerabilidad

Múltiples vulnerabilidades en productos de VMware

Múltiples vulnerabilidades en productos de VMware Vie, 04/09/2026 - 09:55 Aviso Recursos Afectados VMware Workstation, versiones 25H2 y 26H1; VMware Fusion, versiones 25H2 y 26H1. Descripción h4urek, de secsys lab, Y² y Stan S de TrendAI Zero Day Initiative han informado sobre 2 vulnerabilidades de severidad crítica que, en caso de ser explotadas, podrían permitir a un atacante ejecutar código en el host . Identificador INCIBE-2026-606 Solución Actualizar los productos afectados a la versión corregida 26H1u1. Detalle CVE-2026-59346 : desbordamiento de enteros.

Fuente: INCIBE-CERT - Avisos Publicado: 04/09/2026 · 07:55 UTC
Vulnerabilidad Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Imagen: The Hacker News
Vulnerabilidad

Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws

Plex is urging users to update their instances to the latest version following the release of an update that patches multiple security flaws. The fixes are available in Plex Media Server 1.43.3 and Plex Desktop 1.115.0. The streaming media service did not elaborate on what those issues are, but said CVE identifiers have been requested for them. "We recommend all server owners and Desktop users…

Fuente: The Hacker News Publicado: 04/09/2026 · 07:35 UTC No se pudo traducir automáticamente (se muestra el original). Resumen parcial: la fuente no incluye más detalle en su RSS; lee la noticia completa en la fuente.
Vulnerabilidad Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day
Imagen: The Hacker News
Vulnerabilidad

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked as CVE-2026-85046 (CVSS score: 8.8), has been described as a type confusion bug in V8, Chrome's JavaScript and WebAssembly engine. "Type confusion in V8 in Google Chrome prior to 152.0.7977.82 allowed a remote…

Fuente: The Hacker News Publicado: 04/09/2026 · 07:18 UTC No se pudo traducir automáticamente (se muestra el original). Resumen parcial: la fuente no incluye más detalle en su RSS; lee la noticia completa en la fuente.
Vulnerabilidad GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests
Imagen: The Hacker News
Vulnerabilidad

GPT-6 Astra Scores 100% on ExploitBench as OpenAI Blocks PoC Exploit Requests

OpenAI on Thursday officially unveiled GPT‑6 Astra, which it described as the "world's most intelligent and aligned model." The development comes days after the artificial intelligence (AI) company said the model had reached the "Critical" cybersecurity capability threshold under its Preparedness Framework. "Astra is state-of-the-art on computer use, browsing, software engineering…

Fuente: The Hacker News Publicado: 04/09/2026 · 06:47 UTC No se pudo traducir automáticamente (se muestra el original). Resumen parcial: la fuente no incluye más detalle en su RSS; lee la noticia completa en la fuente.