Noticias Ciberseguridad

Vulnerabilidades y CVEs


Exploits y pruebas de concepto


Noticias de seguridad / hacking / malware

  • Samsung TVs to stop collecting Texans’ data without express consent
    por Bill Toulas en 1 de marzo de 2026 a las 15:23

    Samsung and the State of Texas have reached a settlement agreement over the alleged unlawful collection of content-viewing information through its smart TVs […]

  • Hackers Weaponize Claude Code in Mexican Government Cyberattack
    por Ionut Arghire en 1 de marzo de 2026 a las 12:30

    The AI was abused to write exploits, create tools, and automatically exfiltrate over 150GB of data. The post Hackers Weaponize Claude Code in Mexican Government Cyberattack appeared first on SecurityWeek.

  • QuickLens Chrome extension steals crypto, shows ClickFix attack
    por Lawrence Abrams en 28 de febrero de 2026 a las 19:18

    A Chrome extension named «QuickLens – Search Screen with Google Lens» has been removed from the Chrome Web Store after it was compromised to push malware and attempt to steal crypto from thousands of users. […]

  • ClawJacked Flaw Lets Malicious Sites Hijack Local OpenClaw AI Agents via WebSocket
    por info@thehackernews.com (The Hacker News) en 28 de febrero de 2026 a las 17:21

    OpenClaw has fixed a high-severity security issue that, if successfully exploited, could have allowed a malicious website to connect to a locally running artificial intelligence (AI) agent and take over control. «Our vulnerability lives in the core system itself – no plugins, no marketplace, no user-installed extensions – just the bare OpenClaw gateway, running exactly as documented,» Oasis

  • $4.8M in crypto stolen after Korean tax agency exposes wallet seed
    por Bill Toulas en 28 de febrero de 2026 a las 15:17

    South Korea’s National Tax Service accidentally exposed the mnemonic recovery phrase of a seized cryptocurrency wallet in an official press release, allowing hackers to steal 6.4 billion won ($4.8M) worth in cryptocurrency. […]

  • Who is the Kimwolf Botmaster “Dort”?
    por BrianKrebs en 28 de febrero de 2026 a las 12:01

    In early January 2026, KrebsOnSecurity revealed how a security researcher disclosed a vulnerability that was used to assemble Kimwolf, the world’s largest and most disruptive botnet. Since then, the person in control of Kimwolf — who goes by the handle «Dort» — has coordinated a barrage of distributed denial-of-service (DDoS), doxing and email flooding attacks against the researcher and this author, and more recently caused a SWAT team to be sent to the researcher’s home. This post examines what is knowable about Dort based on public information.

  • Canadian Tire Data Breach Impacts 38 Million Accounts
    por Ionut Arghire en 28 de febrero de 2026 a las 11:50

    Names, addresses, email addresses, phone numbers, and encrypted passwords were compromised in the attack. The post Canadian Tire Data Breach Impacts 38 Million Accounts appeared first on SecurityWeek.

  • Thousands of Public Google Cloud API Keys Exposed with Gemini Access After API Enablement
    por info@thehackernews.com (The Hacker News) en 28 de febrero de 2026 a las 09:56

    New research has found that Google Cloud API keys, typically designated as project identifiers for billing purposes, could be abused to authenticate to sensitive Gemini endpoints and access private data. The findings come from Truffle Security, which discovered nearly 3,000 Google API keys (identified by the prefix «AIza») embedded in client-side code to provide Google-related services like

  • Pentagon Designates Anthropic Supply Chain Risk Over AI Military Dispute
    por info@thehackernews.com (The Hacker News) en 28 de febrero de 2026 a las 04:57

    Anthropic on Friday hit back after U.S. Secretary of Defense Pete Hegseth directed the Pentagon to designate the artificial intelligence (AI) upstart as a «supply chain risk.» «This action follows months of negotiations that reached an impasse over two exceptions we requested to the lawful use of our AI model, Claude: the mass domestic surveillance of Americans and fully autonomous weapons,» the

  • Friday Squid Blogging: Squid Fishing in Peru
    por Bruce Schneier en 27 de febrero de 2026 a las 22:04

    Peru has increased its squid catch limit. The article says “giant squid,” but they can’t possibly mean that. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.


Malware y análisis de amenazas