Secciones
- Vulnerabilidades y CVEs
- Exploits y pruebas de concepto
- Noticias de seguridad / hacking / malware
- Malware y análisis de amenazas
- Fabricantes de hardware
CERTs / Gobiernos
Fabricantes/ Vendors
- Adobe Security Bulletins
- Oracle Critical Patch Updates
- VMware Security Advisories
- Apple Security Updates
- Google Chrome Releases / Security
- Microsoft Security Bulletins (HTML)
Otros fabricantes y plataformas
Fabricantes de hardware
Vulnerabilidades y CVEs
- [webapps] Flowise 3.0.4 – Remote Code Execution (RCE)en 31 de octubre de 2025 a las 00:00
Flowise 3.0.4 – Remote Code Execution (RCE)
- [webapps] Casdoor 2.95.0 – Cross-Site Request Forgery (CSRF)en 29 de octubre de 2025 a las 00:00
Casdoor 2.95.0 – Cross-Site Request Forgery (CSRF)
- [remote] Ilevia EVE X1/X5 Server 4.7.18.0.eden – Reverse Rootshellen 16 de septiembre de 2025 a las 00:00
Ilevia EVE X1/X5 Server 4.7.18.0.eden – Reverse Rootshell
- [local] Microsoft Windows Server 2025 Hyper-V NT Kernel Integration VSP – Elevation of Privilegeen 16 de septiembre de 2025 a las 00:00
Microsoft Windows Server 2025 Hyper-V NT Kernel Integration VSP – Elevation of Privilege
- [remote] ClipBucket 5.5.0 – Arbitrary File Uploaden 16 de septiembre de 2025 a las 00:00
ClipBucket 5.5.0 – Arbitrary File Upload
- [remote] ClipBucket 5.5.2 Build #90 – Server-Side Request Forgery (SSRF)en 16 de septiembre de 2025 a las 00:00
ClipBucket 5.5.2 Build #90 – Server-Side Request Forgery (SSRF)
- [webapps] Tourism Management System 2.0 – Arbitrary Shell Uploaden 16 de septiembre de 2025 a las 00:00
Tourism Management System 2.0 – Arbitrary Shell Upload
- [webapps] Casdoor 2.55.0 – Cross-Site Request Forgery (CSRF)en 16 de septiembre de 2025 a las 00:00
Casdoor 2.55.0 – Cross-Site Request Forgery (CSRF)
- [webapps] dotCMS 25.07.02-1 – Authenticated Blind SQL Injectionen 16 de septiembre de 2025 a las 00:00
dotCMS 25.07.02-1 – Authenticated Blind SQL Injection
- [webapps] ELEX WooCommerce WordPress Plugin 1.4.3 – SQL Injectionen 16 de septiembre de 2025 a las 00:00
ELEX WooCommerce WordPress Plugin 1.4.3 – SQL Injection
Exploits y pruebas de concepto
- [webapps] Flowise 3.0.4 – Remote Code Execution (RCE)en 31 de octubre de 2025 a las 00:00
Flowise 3.0.4 – Remote Code Execution (RCE)
- [webapps] Casdoor 2.95.0 – Cross-Site Request Forgery (CSRF)en 29 de octubre de 2025 a las 00:00
Casdoor 2.95.0 – Cross-Site Request Forgery (CSRF)
- [remote] Ilevia EVE X1/X5 Server 4.7.18.0.eden – Reverse Rootshellen 16 de septiembre de 2025 a las 00:00
Ilevia EVE X1/X5 Server 4.7.18.0.eden – Reverse Rootshell
- [local] Microsoft Windows Server 2025 Hyper-V NT Kernel Integration VSP – Elevation of Privilegeen 16 de septiembre de 2025 a las 00:00
Microsoft Windows Server 2025 Hyper-V NT Kernel Integration VSP – Elevation of Privilege
- [remote] ClipBucket 5.5.0 – Arbitrary File Uploaden 16 de septiembre de 2025 a las 00:00
ClipBucket 5.5.0 – Arbitrary File Upload
- [remote] ClipBucket 5.5.2 Build #90 – Server-Side Request Forgery (SSRF)en 16 de septiembre de 2025 a las 00:00
ClipBucket 5.5.2 Build #90 – Server-Side Request Forgery (SSRF)
- [webapps] Tourism Management System 2.0 – Arbitrary Shell Uploaden 16 de septiembre de 2025 a las 00:00
Tourism Management System 2.0 – Arbitrary Shell Upload
- [webapps] Casdoor 2.55.0 – Cross-Site Request Forgery (CSRF)en 16 de septiembre de 2025 a las 00:00
Casdoor 2.55.0 – Cross-Site Request Forgery (CSRF)
- [webapps] dotCMS 25.07.02-1 – Authenticated Blind SQL Injectionen 16 de septiembre de 2025 a las 00:00
dotCMS 25.07.02-1 – Authenticated Blind SQL Injection
- [webapps] ELEX WooCommerce WordPress Plugin 1.4.3 – SQL Injectionen 16 de septiembre de 2025 a las 00:00
ELEX WooCommerce WordPress Plugin 1.4.3 – SQL Injection
- [webapps] XWiki Platform 15.10.10 – Metasploit Module for Remote Code Execution (RCE)en 16 de septiembre de 2025 a las 00:00
XWiki Platform 15.10.10 – Metasploit Module for Remote Code Execution (RCE)
- [webapps] Concrete CMS 9.4.3 – Stored XSSen 16 de septiembre de 2025 a las 00:00
Concrete CMS 9.4.3 – Stored XSS
- [local] Mbed TLS 3.6.4 – Use-After-Freeen 16 de septiembre de 2025 a las 00:00
Mbed TLS 3.6.4 – Use-After-Free
- [remote] HTTP/2 2.0 – Denial Of Service (DOS)en 16 de septiembre de 2025 a las 00:00
HTTP/2 2.0 – Denial Of Service (DOS)
- [remote] HTMLDOC 1.9.13 – Stack Buffer Overflowen 16 de septiembre de 2025 a las 00:00
HTMLDOC 1.9.13 – Stack Buffer Overflow
- [remote] GeoVision ASManager Windows Application 6.1.2.0 – Remote Code Execution (RCE)en 26 de agosto de 2025 a las 00:00
GeoVision ASManager Windows Application 6.1.2.0 – Remote Code Execution (RCE)
- [local] GeoVision ASManager Windows Application 6.1.2.0 – Credentials Disclosureen 26 de agosto de 2025 a las 00:00
GeoVision ASManager Windows Application 6.1.2.0 – Credentials Disclosure
- [webapps] StoryChief Wordpress Plugin 1.0.42 – Arbitrary File Uploaden 26 de agosto de 2025 a las 00:00
StoryChief Wordpress Plugin 1.0.42 – Arbitrary File Upload
- [remote] Ivanti Endpoint Manager Mobile 12.5.0.0 – Authentication Bypassen 26 de agosto de 2025 a las 00:00
Ivanti Endpoint Manager Mobile 12.5.0.0 – Authentication Bypass
- [webapps] Lingdang CRM 8.6.4.7 – SQL Injectionen 26 de agosto de 2025 a las 00:00
Lingdang CRM 8.6.4.7 – SQL Injection
Noticias de seguridad / hacking / malware
- CISA Adds Actively Exploited XSS Bug CVE-2021-26829 in OpenPLC ScadaBR to KEVpor info@thehackernews.com (The Hacker News) en 30 de noviembre de 2025 a las 09:23
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has updated its Known Exploited Vulnerabilities (KEV) catalog to include a security flaw impacting OpenPLC ScadaBR, citing evidence of active exploitation. The vulnerability in question is CVE-2021-26829 (CVSS score: 5.4), a cross-site scripting (XSS) flaw that affects Windows and Linux versions of the software via
- Japanese beer giant Asahi says data breach hit 1.5 million peoplepor Bill Toulas en 29 de noviembre de 2025 a las 15:17
Asahi Group Holdings, Japan’s largest beer producer, has finished the investigation into the September cyberattack and found that the incident has impacted up to 1.9 million individuals. […]
- Leak confirms OpenAI is preparing ads on ChatGPT for public roll outpor Mayank Parmar en 29 de noviembre de 2025 a las 11:31
OpenAI is now internally testing ‘ads’ inside ChatGPT that could redefine the web economy. […]
- Friday Squid Blogging: Flying Neon Squid Found on Israeli Beachpor Bruce Schneier en 28 de noviembre de 2025 a las 20:56
A meter-long flying neon squid (Ommastrephes bartramii) was found dead on an Israeli beach. The species is rare in the Mediterranean.
- Man behind in-flight Evil Twin WiFi attacks gets 7 years in prisonpor Bill Toulas en 28 de noviembre de 2025 a las 18:25
A 44-year-old man was sentenced to seven years and four months in prison for operating an «evil twin» WiFi network to steal the data of unsuspecting travelers at various airports across Australia. […]
- Microsoft: Windows updates make password login option invisiblepor Sergiu Gatlan en 28 de noviembre de 2025 a las 18:07
Microsoft warned users that Windows 11 updates released since August may cause the password sign-in option to disappear from the lock screen options, even though the button remains functional. […]
- Public GitLab repositories exposed more than 17,000 secretspor Bill Toulas en 28 de noviembre de 2025 a las 17:43
After scanning all 5.6 million public repositories on GitLab Cloud, a security engineer discovered more than 17,000 exposed secrets across over 2,800 unique domains. […]
- Legacy Python Bootstrap Scripts Create Domain-Takeover Risk in Multiple PyPI Packagespor info@thehackernews.com (The Hacker News) en 28 de noviembre de 2025 a las 16:27
Cybersecurity researchers have discovered vulnerable code in legacy Python packages that could potentially pave the way for a supply chain compromise on the Python Package Index (PyPI) via a domain takeover attack. Software supply chain security company ReversingLabs said it found the «vulnerability» in bootstrap files provided by a build and deployment automation tool named «zc.buildout.» «The
- North Korean Hackers Deploy 197 npm Packages to Spread Updated OtterCookie Malwarepor info@thehackernews.com (The Hacker News) en 28 de noviembre de 2025 a las 16:18
The North Korean threat actors behind the Contagious Interview campaign have continued to flood the npm registry with 197 more malicious packages since last month. According to Socket, these packages have been downloaded over 31,000 times, and are designed to deliver a variant of OtterCookie that brings together the features of BeaverTail and prior versions of OtterCookie. Some of the
- French Football Federation discloses data breach after cyberattackpor Sergiu Gatlan en 28 de noviembre de 2025 a las 16:12
The French Football Federation (FFF) disclosed a data breach on Friday after attackers used a compromised account to gain access to administrative management software used by football clubs. […]
Malware y análisis de amenazas
- How CVSS v4.0 works: characterizing and scoring vulnerabilitiesen 28 de noviembre de 2025 a las 12:42
This blog explains why vulnerability scoring matters, how CVSS works, and what’s new in version 4.0.
- Millions at risk after nationwide CodeRED alert system outage and data breachen 27 de noviembre de 2025 a las 14:40
A ransomware attack against the CodeRED emergency alert platform has triggered warnings across the US.
- Holiday shoppers targeted as Amazon and FBI warn of surge in account takeover attacksen 27 de noviembre de 2025 a las 13:18
Scammers are stepping up their game for the holidays, impersonating brands to trick people into handing over their accounts.
- Fake LinkedIn jobs trick Mac users into downloading Flexible Ferret malwareen 26 de noviembre de 2025 a las 14:11
Scammers are using fake jobs and a phony video update to infect Mac users with a multi-stage stealer designed for long-term access and data theft.
- ISC Stormcast For Wednesday, November 26th, 2025 https://isc.sans.edu/podcastdetail/9716, (Wed, Nov 26th)en 26 de noviembre de 2025 a las 03:10
- New ClickFix wave infects users with hidden malware in images and fake Windows updatesen 25 de noviembre de 2025 a las 16:08
ClickFix just got more convincing, hiding malware in PNG images and faking Windows updates to make users run dangerous commands.
- WhatsApp closes loophole that let researchers collect data on 3.5B accountsen 25 de noviembre de 2025 a las 11:30
A weak spot in WhatsApp’s API allowed researchers to scrape data linked to 3.5 billion registered accounts, including profile photos and “about” text.
- ISC Stormcast For Tuesday, November 25th, 2025 https://isc.sans.edu/podcastdetail/9714, (Tue, Nov 25th)en 25 de noviembre de 2025 a las 02:00
- The hidden costs of illegal streaming and modded Amazon Fire TV Sticksen 24 de noviembre de 2025 a las 20:30
New research shows that «modded Amazon Fire TV Sticks» and piracy apps often lead to scams, stolen data, and financial loss.
- Black Friday scammers offer fake gifts from big-name brands to empty bank accountsen 24 de noviembre de 2025 a las 17:36
Inside a massive malicious ad campaign that mimics brands like LEGO, Lululemon, and Louis Vuitton to trick shoppers into handing over bank details.
