Secciones
- Vulnerabilidades y CVEs
- Exploits y pruebas de concepto
- Noticias de seguridad / hacking / malware
- Malware y análisis de amenazas
- Fabricantes de hardware
CERTs / Gobiernos
Fabricantes/ Vendors
- Adobe Security Bulletins
- Oracle Critical Patch Updates
- VMware Security Advisories
- Apple Security Updates
- Google Chrome Releases / Security
- Microsoft Security Bulletins (HTML)
Otros fabricantes y plataformas
Fabricantes de hardware
Vulnerabilidades y CVEs
- [webapps] WordPress Quiz Maker 6.7.0.56 – SQL Injectionen 25 de diciembre de 2025 a las 00:00
WordPress Quiz Maker 6.7.0.56 – SQL Injection
- [webapps] Chained Quiz 1.3.5 – Unauthenticated Insecure Direct Object Reference via Cookieen 25 de diciembre de 2025 a las 00:00
Chained Quiz 1.3.5 – Unauthenticated Insecure Direct Object Reference via Cookie
- [webapps] FreeBSD rtsold 15.x – Remote Code Execution via DNSSLen 25 de diciembre de 2025 a las 00:00
FreeBSD rtsold 15.x – Remote Code Execution via DNSSL
- [webapps] Summar Employee Portal 3.98.0 – Authenticated SQL Injectionen 16 de diciembre de 2025 a las 00:00
Summar Employee Portal 3.98.0 – Authenticated SQL Injection
- [webapps] esm-dev 136 – Path Traversalen 16 de diciembre de 2025 a las 00:00
esm-dev 136 – Path Traversal
- [webapps] Pluck 4.7.7-dev2 – PHP Code Executionen 8 de diciembre de 2025 a las 00:00
Pluck 4.7.7-dev2 – PHP Code Execution
- [webapps] RosarioSIS 6.7.2 – Cross-Site Scripting (XSS)en 3 de diciembre de 2025 a las 00:00
RosarioSIS 6.7.2 – Cross-Site Scripting (XSS)
- [webapps] phpMyFAQ 2.9.8 – Cross-Site Request Forgery(CSRF)en 3 de diciembre de 2025 a las 00:00
phpMyFAQ 2.9.8 – Cross-Site Request Forgery(CSRF)
- [webapps] phpMyFAQ 2.9.8 – Cross-Site Request Forgery (CSRF)en 3 de diciembre de 2025 a las 00:00
phpMyFAQ 2.9.8 – Cross-Site Request Forgery (CSRF)
- [webapps] openSIS Community Edition 8.0 – SQL Injectionen 3 de diciembre de 2025 a las 00:00
openSIS Community Edition 8.0 – SQL Injection
Exploits y pruebas de concepto
- [webapps] WordPress Quiz Maker 6.7.0.56 – SQL Injectionen 25 de diciembre de 2025 a las 00:00
WordPress Quiz Maker 6.7.0.56 – SQL Injection
- [webapps] Chained Quiz 1.3.5 – Unauthenticated Insecure Direct Object Reference via Cookieen 25 de diciembre de 2025 a las 00:00
Chained Quiz 1.3.5 – Unauthenticated Insecure Direct Object Reference via Cookie
- [webapps] FreeBSD rtsold 15.x – Remote Code Execution via DNSSLen 25 de diciembre de 2025 a las 00:00
FreeBSD rtsold 15.x – Remote Code Execution via DNSSL
- [webapps] Summar Employee Portal 3.98.0 – Authenticated SQL Injectionen 16 de diciembre de 2025 a las 00:00
Summar Employee Portal 3.98.0 – Authenticated SQL Injection
- [webapps] esm-dev 136 – Path Traversalen 16 de diciembre de 2025 a las 00:00
esm-dev 136 – Path Traversal
- [webapps] Pluck 4.7.7-dev2 – PHP Code Executionen 8 de diciembre de 2025 a las 00:00
Pluck 4.7.7-dev2 – PHP Code Execution
- [webapps] RosarioSIS 6.7.2 – Cross-Site Scripting (XSS)en 3 de diciembre de 2025 a las 00:00
RosarioSIS 6.7.2 – Cross-Site Scripting (XSS)
- [webapps] phpMyFAQ 2.9.8 – Cross-Site Request Forgery(CSRF)en 3 de diciembre de 2025 a las 00:00
phpMyFAQ 2.9.8 – Cross-Site Request Forgery(CSRF)
- [webapps] phpMyFAQ 2.9.8 – Cross-Site Request Forgery (CSRF)en 3 de diciembre de 2025 a las 00:00
phpMyFAQ 2.9.8 – Cross-Site Request Forgery (CSRF)
- [webapps] openSIS Community Edition 8.0 – SQL Injectionen 3 de diciembre de 2025 a las 00:00
openSIS Community Edition 8.0 – SQL Injection
- [webapps] phpMyFaq 2.9.8 – Cross Site Request Forgery (CSRF)en 3 de diciembre de 2025 a las 00:00
phpMyFaq 2.9.8 – Cross Site Request Forgery (CSRF)
- [webapps] phpIPAM 1.4 – SQL-Injectionen 3 de diciembre de 2025 a las 00:00
phpIPAM 1.4 – SQL-Injection
- [webapps] OpenRepeater 2.1 – OS Command Injectionen 3 de diciembre de 2025 a las 00:00
OpenRepeater 2.1 – OS Command Injection
- [webapps] phpMyAdmin 5.0.0 – SQL Injectionen 3 de diciembre de 2025 a las 00:00
phpMyAdmin 5.0.0 – SQL Injection
- [webapps] RosarioSIS 6.7.2 – Cross Site Scripting (XSS)en 3 de diciembre de 2025 a las 00:00
RosarioSIS 6.7.2 – Cross Site Scripting (XSS)
- [webapps] PluckCMS 4.7.10 – Unrestricted File Uploaden 3 de diciembre de 2025 a las 00:00
PluckCMS 4.7.10 – Unrestricted File Upload
- [webapps] Django 5.1.13 – SQL Injectionen 3 de diciembre de 2025 a las 00:00
Django 5.1.13 – SQL Injection
- [webapps] MobileDetect 2.8.31 – Cross-Site Scripting (XSS)en 3 de diciembre de 2025 a las 00:00
MobileDetect 2.8.31 – Cross-Site Scripting (XSS)
- [webapps] MaNGOSWebV4 4.0.6 – Reflected XSSen 3 de diciembre de 2025 a las 00:00
MaNGOSWebV4 4.0.6 – Reflected XSS
- [webapps] YOURLS 1.8.2 – Cross-Site Request Forgery (CSRF)en 2 de diciembre de 2025 a las 00:00
YOURLS 1.8.2 – Cross-Site Request Forgery (CSRF)
Noticias de seguridad / hacking / malware
- Microsoft updates Windows DLL that triggered security alertspor Sergiu Gatlan en 14 de enero de 2026 a las 16:44
Microsoft has resolved a known issue that was causing security applications to incorrectly flag a core Windows component, the company said in a service alert posted this week. […]
- AI Agents Are Becoming Privilege Escalation Pathspor info@thehackernews.com (The Hacker News) en 14 de enero de 2026 a las 15:07
AI agents have quickly moved from experimental tools to core components of daily workflows across security, engineering, IT, and operations. What began as individual productivity aids, like personal code assistants, chatbots, and copilots, has evolved into shared, organization-wide agents embedded in critical processes. These agents can orchestrate workflows across multiple systems, for example:
- ConsentFix debrief: Insights from the new OAuth phishing attackpor Sponsored by Push Security en 14 de enero de 2026 a las 15:01
ConsentFix is an OAuth phishing technique abusing browser-based authorization flows to hijack Microsoft accounts. Push Security shares new insights from continued tracking, community research, and evolving attacker techniques. […]
- RedVDS Cybercrime Service Disrupted by Microsoft and Law Enforcementpor Eduard Kovacs en 14 de enero de 2026 a las 15:00
RedVDS enables threat actors to set up servers that can be used for phishing, BEC attacks, account takeover, and fraud. The post RedVDS Cybercrime Service Disrupted by Microsoft and Law Enforcement appeared first on SecurityWeek.
- Hackers Exploit c-ares DLL Side-Loading to Bypass Security and Deploy Malwarepor info@thehackernews.com (The Hacker News) en 14 de enero de 2026 a las 14:18
Security experts have disclosed details of an active malware campaign that’s exploiting a DLL side-loading vulnerability in a legitimate binary associated with the open-source c-ares library to bypass security controls and deliver a wide range of commodity trojans and stealers. «Attackers achieve evasion by pairing a malicious libcares-2.dll with any signed version of the legitimate ahost.exe (
- Predator Spyware Turns Failed Attacks Into Intelligence for Future Exploitspor Kevin Townsend en 14 de enero de 2026 a las 14:00
The Predator spyware is more sophisticated and dangerous than previously realized. The post Predator Spyware Turns Failed Attacks Into Intelligence for Future Exploits appeared first on SecurityWeek.
- Reprompt attack let hackers hijack Microsoft Copilot sessionspor Bill Toulas en 14 de enero de 2026 a las 14:00
Researchers identified an attack method dubbed «Reprompt» that could allow attackers to infiltrate a user’s Microsoft Copilot session and issue commands to exfiltrate sensitive data. […]
- Novee Emerges From Stealth With $51.5 Million in Fundingpor Ionut Arghire en 14 de enero de 2026 a las 13:15
Novee provides continuous AI-driven penetration testing to uncover and address novel vulnerabilities. The post Novee Emerges From Stealth With $51.5 Million in Funding appeared first on SecurityWeek.
- Cloud marketplace Pax8 accidentally exposes data on 1,800 MSP partnerspor Ax Sharma en 14 de enero de 2026 a las 12:01
Cloud marketplace and distributor Pax8 has confirmed that it mistakenly sent an email to fewer than 40 UK-based partners containing a spreadsheet with internal business information, including MSP customer and Microsoft licensing data. […]
- Fortinet Fixes Critical FortiSIEM Flaw Allowing Unauthenticated Remote Code Executionpor info@thehackernews.com (The Hacker News) en 14 de enero de 2026 a las 11:53
Fortinet has released updates to fix a critical security flaw impacting FortiSIEM that could allow an unauthenticated attacker to achieve code execution on susceptible instances. The operating system (OS) injection vulnerability, tracked as CVE-2025-64155, is rated 9.4 out of 10.0 on the CVSS scoring system. «An improper neutralization of special elements used in an OS command (‘OS command
Malware y análisis de amenazas
- Phishing scammers are posting fake “account restricted” comments on LinkedInen 14 de enero de 2026 a las 15:55
Fake LinkedIn comments warning of account restrictions are designed to trick users into revealing their login details.
- Online shoppers at risk as Magecart skimming hits major payment networksen 14 de enero de 2026 a las 12:03
A Magecart campaign is skimming card data from online checkouts tied to major payment networks, including AmEx, Diners Club, and Mastercard.
- How real software downloads can hide remote backdoorsen 14 de enero de 2026 a las 11:02
Attackers use legitimate open-source software as cover, relying on user trust to compromise systems. We dive into an example.
- ISC Stormcast For Wednesday, January 14th, 2026 https://isc.sans.edu/podcastdetail/9766, (Wed, Jan 14th)en 14 de enero de 2026 a las 02:30
- January 2026 Microsoft Patch Tuesday Summary, (Tue, Jan 13th)en 13 de enero de 2026 a las 19:05
Today, Microsoft released patches for 113 vulnerabilities. One of these vulnerabilities affected the Edge browser and was patched upstream by Chromium.
- Data broker fined after selling Alzheimer’s patient info and millions of sensitive profilesen 13 de enero de 2026 a las 16:05
A data broker was fined by California regulators for selling sensitive data on Alzheimer’s patients and millions of others.
- Why iPhone users should update and restart their devices nowen 13 de enero de 2026 a las 12:55
Apple has confirmed active exploitation, but full protections are limited to iPhones running iOS 26+ (yes, the one with Liquid Glass).
- ISC Stormcast For Tuesday, January 13th, 2026 https://isc.sans.edu/podcastdetail/9764, (Tue, Jan 13th)en 13 de enero de 2026 a las 02:00
- Received an Instagram password reset email? Here’s what you need to knowen 12 de enero de 2026 a las 21:04
Instagram users received emails last week about purported password reset attempts. At the same time, Instagram data appeared on the dark web.
- Regulators around the world are scrutinizing Grok over sexual deepfakesen 12 de enero de 2026 a las 14:04
Grok’s apology is unlikely to be the end of the story after the AI tool was used to generate content that may constitute illegal child sexual abuse material.
