Secciones
- Vulnerabilidades y CVEs
- Exploits y pruebas de concepto
- Noticias de seguridad / hacking / malware
- Malware y análisis de amenazas
- Fabricantes de hardware
CERTs / Gobiernos
Fabricantes/ Vendors
- Adobe Security Bulletins
- Oracle Critical Patch Updates
- VMware Security Advisories
- Apple Security Updates
- Google Chrome Releases / Security
- Microsoft Security Bulletins (HTML)
Otros fabricantes y plataformas
Fabricantes de hardware
Vulnerabilidades y CVEs
- [webapps] Langflow 1.8.4 – Path Traversal to Remote Code Executionen 31 de agosto de 2026 a las 00:00
Langflow 1.8.4 – Path Traversal to Remote Code Execution
- [webapps] C-MOR 6.0104 – Cross-Site Scripting (XSS)en 31 de agosto de 2026 a las 00:00
C-MOR 6.0104 – Cross-Site Scripting (XSS)
- [webapps] Linksys E1200_2.0.04 – Unauthenticated OS Command Injectionen 31 de agosto de 2026 a las 00:00
Linksys E1200_2.0.04 – Unauthenticated OS Command Injection
- [webapps] CubeCart 6.7.4 – Cross-Site Scriptingen 31 de agosto de 2026 a las 00:00
CubeCart 6.7.4 – Cross-Site Scripting
- [webapps] CubeCart 6.7.4 – Stored XSSen 31 de agosto de 2026 a las 00:00
CubeCart 6.7.4 – Stored XSS
- [webapps] CubeCart 6.7.4 – SQL injectionen 31 de agosto de 2026 a las 00:00
CubeCart 6.7.4 – SQL injection
- [webapps] CubeCart 6.7.4 – SQLen 31 de agosto de 2026 a las 00:00
CubeCart 6.7.4 – SQL
- [webapps] C-MOR 6.0104 – Directory Traversalen 31 de agosto de 2026 a las 00:00
C-MOR 6.0104 – Directory Traversal
- [remote] CVE-2026-42167 – ProFTPD mod_sql post-authentication SQLi – RCEen 25 de agosto de 2026 a las 00:00
CVE-2026-42167 – ProFTPD mod_sql post-authentication SQLi – RCE
- [webapps] flyto-core 2.26.7 – Arbitrary File Writeen 18 de agosto de 2026 a las 00:00
flyto-core 2.26.7 – Arbitrary File Write
Exploits y pruebas de concepto
- [webapps] Langflow 1.8.4 – Path Traversal to Remote Code Executionen 31 de agosto de 2026 a las 00:00
Langflow 1.8.4 – Path Traversal to Remote Code Execution
- [webapps] C-MOR 6.0104 – Cross-Site Scripting (XSS)en 31 de agosto de 2026 a las 00:00
C-MOR 6.0104 – Cross-Site Scripting (XSS)
- [webapps] Linksys E1200_2.0.04 – Unauthenticated OS Command Injectionen 31 de agosto de 2026 a las 00:00
Linksys E1200_2.0.04 – Unauthenticated OS Command Injection
- [webapps] CubeCart 6.7.4 – Cross-Site Scriptingen 31 de agosto de 2026 a las 00:00
CubeCart 6.7.4 – Cross-Site Scripting
- [webapps] CubeCart 6.7.4 – Stored XSSen 31 de agosto de 2026 a las 00:00
CubeCart 6.7.4 – Stored XSS
- [webapps] CubeCart 6.7.4 – SQL injectionen 31 de agosto de 2026 a las 00:00
CubeCart 6.7.4 – SQL injection
- [webapps] CubeCart 6.7.4 – SQLen 31 de agosto de 2026 a las 00:00
CubeCart 6.7.4 – SQL
- [webapps] C-MOR 6.0104 – Directory Traversalen 31 de agosto de 2026 a las 00:00
C-MOR 6.0104 – Directory Traversal
- [remote] CVE-2026-42167 – ProFTPD mod_sql post-authentication SQLi – RCEen 25 de agosto de 2026 a las 00:00
CVE-2026-42167 – ProFTPD mod_sql post-authentication SQLi – RCE
- [webapps] flyto-core 2.26.7 – Arbitrary File Writeen 18 de agosto de 2026 a las 00:00
flyto-core 2.26.7 – Arbitrary File Write
- [dos] NanaZip 6.5 – DoSen 18 de agosto de 2026 a las 00:00
NanaZip 6.5 – DoS
- [remote] PCMan 2.0.7 – Buffer Overflowen 18 de agosto de 2026 a las 00:00
PCMan 2.0.7 – Buffer Overflow
- [webapps] Linuxfabrik monitoring_plugins_6.0.0 – SSRFen 18 de agosto de 2026 a las 00:00
Linuxfabrik monitoring_plugins_6.0.0 – SSRF
- [webapps] Nodemailer 9.0.0 – File Read/ SSRFen 18 de agosto de 2026 a las 00:00
Nodemailer 9.0.0 – File Read/ SSRF
- [remote] D-Link DNS_340L – OS Command Injectionen 17 de agosto de 2026 a las 00:00
D-Link DNS_340L – OS Command Injection
- [remote] ipTIME A3004T – Remote Code Executionen 17 de agosto de 2026 a las 00:00
ipTIME A3004T – Remote Code Execution
- [webapps] flyto_core 2.26.7 – Server-Side Request Forgeryen 17 de agosto de 2026 a las 00:00
flyto_core 2.26.7 – Server-Side Request Forgery
- [webapps] Duplicati 2.2.0.3 – JWT Signing Key Leaken 17 de agosto de 2026 a las 00:00
Duplicati 2.2.0.3 – JWT Signing Key Leak
- [dos] Nmap 7.99 – Extension Header Integer Underflowen 17 de agosto de 2026 a las 00:00
Nmap 7.99 – Extension Header Integer Underflow
- [webapps] webpack_devserver 5.2.5 – CSRFen 17 de agosto de 2026 a las 00:00
webpack_devserver 5.2.5 – CSRF
Noticias de seguridad / hacking / malware
- Cronos blockchain restarts after $74 million Tectonic exploitpor Bill Toulas en 31 de agosto de 2026 a las 20:47
The Cronos blockchain network has resumed trading activity after a price-manipulation attack on the Tectonic cryptocurrency lending platform allowed an attacker to borrow $74 million. […]
- Microsoft warns of TerminalFix attacks deploying reverse tunnelspor Bill Toulas en 31 de agosto de 2026 a las 18:51
A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious PowerShell commands in Windows Terminal. […]
- North Korean Job Fraud Expands Beyond IT Into Healthcare and Salespor info@thehackernews.com (The Hacker News) en 31 de agosto de 2026 a las 17:24
Threat actors with ties to the Democratic People’s Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected workers employed in sales and marketing and the medical profession. The ongoing insider threat is part of what has been described as the IT worker scheme,
- Microsoft Exchange Online outage causes email failures, auth issuespor Sergiu Gatlan en 31 de agosto de 2026 a las 16:56
Microsoft is investigating a widespread service issue causing authentication issues, email delays and failures, and various other issues for Exchange Online customers. […]
- OpenAI confirms ChatGPT outage as users report errorspor Mayank Parmar en 31 de agosto de 2026 a las 16:50
ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. […]
- Chinese Fire Ant hackers turn Cisco routers into spying platformspor Bill Toulas en 31 de agosto de 2026 a las 14:52
The researchers discovered Fire Ant’s new tactic after finding an active GRE (Generic Routing Encapsulation) tunnel interface on a Cisco IOS XR router that could not be explained by a running configuration or commit history. […]
- File servers are here to stay. Here’s how to manage them securelypor Sponsored by Tenfold Software en 31 de agosto de 2026 a las 14:00
File servers remain a critical part of many IT environments, but managing access securely can become complex as permissions accumulate. tenfold Software outlines five best practices for simplifying file server administration and maintaining least-privilege access. […]
- ⚡ Weekly Recap: Chinese Spy Proxy, AI Agents Go Off-Task, Router Backdoors and Morepor info@thehackernews.com (The Hacker News) en 31 de agosto de 2026 a las 13:50
The boring parts caused most of the trouble. A router shipped ready to listen. A fake check turned the user into the installer. Trusted systems collected traffic and passwords, then cleaned the logs. Old bugs formed new attack chains. Even an AI agent decided its assigned task was optional. Elsewhere, fake apps, helpful support calls, cheap banking kits, exposed systems, and weak defaults kept
- Berlin confirms data theft after Rhysida ransomware attack claimspor Bill Toulas en 31 de agosto de 2026 a las 13:30
Berlin’s city administration has confirmed that cybercriminals are attempting to extort the city after the Rhysida ransomware gang listed it on their data leak site. […]
- ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusionspor info@thehackernews.com (The Hacker News) en 31 de agosto de 2026 a las 12:14
The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN Wallpaper, a genuine Chinese desktop-wallpaper tool
Malware y análisis de amenazas
- ISC Stormcast For Tuesday, September 1st, 2026 https://isc.sans.edu/podcastdetail/10076, (Tue, Sep 1st)en 1 de septiembre de 2026 a las 02:00
- Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)en 1 de septiembre de 2026 a las 00:33
Introduction
- The Coding-Agent Trap: When a «Free» LLM Endpoint Is the Adversary, (Mon, Aug 31st)en 31 de agosto de 2026 a las 20:00
One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide «free» LLM backends. It then received a real coding-agent session &#;x26;#;xe2;&#;x26;#;x80;&#;x26;#;x94; history, filesystem output, working paths, and the agent&#;x26;#;39;s local tool manifest. The honeypot did not request or cause any tool execution; what the request exposed is what a malicious operator in that position could do.
- ISC Stormcast For Monday, August 31st, 2026 https://isc.sans.edu/podcastdetail/10074, (Mon, Aug 31st)en 31 de agosto de 2026 a las 02:00
- YARA-X 1.20.0 Release, (Sun, Aug 30th)en 30 de agosto de 2026 a las 07:14
YARA-X&#;x26;#;39;s 1.20.0 release brings 14 improvements and 13 bugfixes.
- Some Malicious PE Stats, (Thu, Aug 27th)en 28 de agosto de 2026 a las 07:04
During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS. 32bits malware[1]. Can we go a bit further? I (vibe-)coded a Python script based on the pefile library[2] to extract some info from the PE headers. Indeed, the PE file format contains a lot of metadata! They can be accessed using a lot of tools, like Detect It Easy:
- ISC Stormcast For Friday, August 28th, 2026 https://isc.sans.edu/podcastdetail/10072, (Fri, Aug 28th)en 28 de agosto de 2026 a las 02:00
- A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)en 27 de agosto de 2026 a las 09:57
As I’ve mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us here at the Internet Storm Center.
- ISC Stormcast For Thursday, August 27th, 2026 https://isc.sans.edu/podcastdetail/10070, (Thu, Aug 27th)en 27 de agosto de 2026 a las 02:00
- Who Has Admin Rights in your Entra ID Directory?, (Wed, Aug 26th)en 26 de agosto de 2026 a las 15:58
A common thing that folks should «worry» about in Entra (or any platform really) is «who has rights to administer»&#;x26;#;x3f;&#;x26;#;xc2;&#;x26;#;xa0; Who can delete or change key things, or modify them in ways that might not be obvious (accidentally or on purpose).&#;x26;#;xc2;&#;x26;#;xa0; Yes, we trust our people, but if they&#;x26;#;39;ve moved on to other roles or to other organizations, they change from «our people» to «used to be our people».&#;x26;#;xc2;&#;x26;#;xa0;&#;x26;#;xc2;&#;x26;#;xa0;
