Saltar al contenido
Vie. Sep 25th, 2026
Trending News: La ciberestafa que está arrasando en el Black Friday de 2025: el paquete no solicitadoWordPress se refuerza: nuevas medidas de seguridad tras detectar 8.000 nuevas vulnerabilidades en 2024Los mods de Minecraft, un campo de minas propicio para la propagación de malware y el robo de datos personalesAsí opera Kraken, un nuevo y peligroso grupo de ransomwareCiberespías chinos usan la IA de Claude para automatizar el 90% de una campaña de ataquesPamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer PersistenceCompromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud MalwareThe SOC Doesn’t Need to Start Over with Every AlertBitget Says Suspected North Korean Hackers Stole $351.6M After Backend CompromiseRoundcube Pre-Auth SQL Injection Flaw Actively Exploited in the WildWSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEVCloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk DataLos pagos por ransomware en EE.UU. superan los 2.100 millones en tres añosLas ciberestafas que están proliferando a raíz de la implantación de VerifactuEl servicio de salud irlandés compensará a cada víctima de su ciberataque con 750 eurosHackers vinculados a Corea del Norte aprovechan un fallo crítico en ReactAI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More StoriesUnpatched OnePlus Flaws Let Installed Android Apps Gain Root Without PermissionsPlaceholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious ContentHacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic StealerSecrets Sprawl Is an Identity Problem That AI Just Made Impossible to IgnoreCorp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects CallsAttackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default PasswordsOpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public FilesExploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container EscapeAttackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp RegistryAnthropic and OpenAI Models Still Attempt Restricted Actions in Safety TestsA Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You545 Hackers Tested It First. Now XRanges for AI Scores Your Security AgentMikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH KeyThis Windows Malware is Built to Let Up to Four AI Models Vote on Its Next MoveCompromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPINew cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server ControlChinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP MalwareF5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth ServersCritical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG InputShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job ApplicantsResearcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender UpdatesMalicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate CredentialsWordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some ServersFiltrados los datos de altos cargos de Transportes como ‘venganza’ por la tragedia de AdamuzEl hacker contradice a PcComponentes y muestra pruebas de acceso a sus sistemas internosReino Unido lanza un servicio llamado Report Fraud para hacer frente al ciberdelito y el fraude onlineIngram Micro confirma que un ataque de ransomware expuso datos de más de 42.000 personasAlerta en Fortinet: los cortafuegos FortiGate parcheados han sido hackeadosCheck Point Warns of Management Server Zero-Day Exploited in Targeted AttacksCritical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without CredentialsMicrosoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox CompromisesSharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCENew Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host MemoryNew CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based SetupsAI Agents Are Rewriting the Rules of Lateral MovementCan Your SOC Actually See the Attack?Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before RemovalSideCopy Broadens India Targeting to Academia With ReverseRAT Spear-PhishingZyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM AccessWordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin SessionOne Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a BackdoorGoogle Fined €403 Million Over GDPR Violations Tied to Location DataLos conflictos internacionales impulsan nuevas campañas de ciberataques en 2025Moltbook, la nueva red social de agentes de IA, expone toda su base de datosEl 90% de las compañías dispone de un plan director de ciberseguridad validado por la alta direcciónUn ex ingeniero de Google, condenado por espionaje económico y robo de secretos de IA para ChinaCuenta atrás para la XVIII edición del Foro de la Privacidad del Data Privacy InstituteContagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in CryptoFake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDRTASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard DataCisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser HijacksClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 InfrastructureJade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK BackdoorsThe Foundation of Identity SecuritySolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCEClaude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained FlawsGoogle Gemini Broke Into Real Company Systems After Security Test Domain Mix-UpCritical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub RepositoriesCISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildPublic Exploits Released for Four Linux Kernel Flaws That Enable Local RootUn hombre conecta su aspiradora robot con un mando de PS5 y obtiene el control de miles de dispositivosLa web para adultos Frivol.com filtra una base de datos, exponiendo casi medio millón de cuentas de emailLa brecha entre inversión en ciberresiliencia y preparación adecuada aumenta la vulnerabilidad de las empresas españolasUn hacker ucraniano se declara culpable de operar OnlyFake, un portal de venta de pasaportes generados con IAEl software para psicólogos Eholo sufre una grave filtración de datosNew WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code ExecutionPlugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding AgentsTransparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege EscalationWeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension StorageClaimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm StealerIran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal PasswordsCritical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host FilesRatHat Android Malware Abuses ADB to Retain Shell Access After UninstallSelf-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New StoriesCritical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as RootU.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS AttacksCisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active AttacksGyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
Chicago 12, Melborne City, USA
The Digital Fortress
  • Home
  • Blog
  • Sample Page
  • Get Started
Vie. Sep 25th, 2026
Trending News: La ciberestafa que está arrasando en el Black Friday de 2025: el paquete no solicitadoWordPress se refuerza: nuevas medidas de seguridad tras detectar 8.000 nuevas vulnerabilidades en 2024Los mods de Minecraft, un campo de minas propicio para la propagación de malware y el robo de datos personalesAsí opera Kraken, un nuevo y peligroso grupo de ransomwareCiberespías chinos usan la IA de Claude para automatizar el 90% de una campaña de ataquesPamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer PersistenceCompromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud MalwareThe SOC Doesn’t Need to Start Over with Every AlertBitget Says Suspected North Korean Hackers Stole $351.6M After Backend CompromiseRoundcube Pre-Auth SQL Injection Flaw Actively Exploited in the WildWSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEVCloudflare Fixes Flaw That Let One Container Read Another Customer’s Leftover Disk DataLos pagos por ransomware en EE.UU. superan los 2.100 millones en tres añosLas ciberestafas que están proliferando a raíz de la implantación de VerifactuEl servicio de salud irlandés compensará a cada víctima de su ciberataque con 750 eurosHackers vinculados a Corea del Norte aprovechan un fallo crítico en ReactAI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More StoriesUnpatched OnePlus Flaws Let Installed Android Apps Gain Root Without PermissionsPlaceholder third-party[.]com Referenced Across 1,700+ Repositories Now Serves Malicious ContentHacked Ukrainian Sites Serve Fake Cloudflare ClickFix Lures for Psychedelic StealerSecrets Sprawl Is an Identity Problem That AI Just Made Impossible to IgnoreCorp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects CallsAttackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default PasswordsOpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public FilesExploit Released for Unpatched Ubuntu Linux Flaw Enabling Host-Root Container EscapeAttackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp RegistryAnthropic and OpenAI Models Still Attempt Restricted Actions in Safety TestsA Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You545 Hackers Tested It First. Now XRanges for AI Scores Your Security AgentMikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH KeyThis Windows Malware is Built to Let Up to Four AI Models Vote on Its Next MoveCompromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPINew cPanel Flaw Lets a Hosting Account Run Code as Root, Take Full Server ControlChinese Hackers Exploit Chrome-Windows Zero-Day Chain to Deploy CLEANGULP MalwareF5 Patches Critical BIG-IP APM Zero-Day Exploited for Unauthenticated RCE on OAuth ServersCritical Next.js ImageResponse Flaw Can Lead to Server Code Execution via Crafted SVG InputShinyHunters Claims FBI Breach, Says It Stole Data on Agents and Job ApplicantsResearcher Drops BigDiskBuster Zero-Day PoC That Blocks Microsoft Defender UpdatesMalicious npm Package Poses as Twilio Bug-Bounty Probe, Can Exfiltrate CredentialsWordPress Issues Patch for Critical Flaw That Can Enable Code Execution on Some ServersFiltrados los datos de altos cargos de Transportes como ‘venganza’ por la tragedia de AdamuzEl hacker contradice a PcComponentes y muestra pruebas de acceso a sus sistemas internosReino Unido lanza un servicio llamado Report Fraud para hacer frente al ciberdelito y el fraude onlineIngram Micro confirma que un ataque de ransomware expuso datos de más de 42.000 personasAlerta en Fortinet: los cortafuegos FortiGate parcheados han sido hackeadosCheck Point Warns of Management Server Zero-Day Exploited in Targeted AttacksCritical Bifrost AI Gateway Flaw Lets Attackers Run Commands Without CredentialsMicrosoft Takes Down EvilTokens Device-Code Phishing Service Tied to 12,000 Inbox CompromisesSharePoint Flaw Initially Listed as Spoofing by Microsoft Enables Authenticated RCENew Linux Kernel Flaw Gives ARM64 KVM Guests Read-Write Access to Host MemoryNew CVSS 10.0 VeloCloud Orchestrator Flaw Actively Exploited in Certificate-Based SetupsAI Agents Are Rewriting the Rules of Lateral MovementCan Your SOC Actually See the Attack?Malicious npm Package indexed-btree Hid Its Loader in Runtime Code Before RemovalSideCopy Broadens India Targeting to Academia With ReverseRAT Spear-PhishingZyxel and Veeam Flaws Under Active Exploitation With Command and SYSTEM AccessWordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin SessionOne Hidden Meta Muse Setting Could Let Attackers Turn the AI Assistant Into a BackdoorGoogle Fined €403 Million Over GDPR Violations Tied to Location DataLos conflictos internacionales impulsan nuevas campañas de ciberataques en 2025Moltbook, la nueva red social de agentes de IA, expone toda su base de datosEl 90% de las compañías dispone de un plan director de ciberseguridad validado por la alta direcciónUn ex ingeniero de Google, condenado por espionaje económico y robo de secretos de IA para ChinaCuenta atrás para la XVIII edición del Foro de la Privacidad del Data Privacy InstituteContagious Interview Campaign Compromises 30,000 Devices, Steals $10.71M in CryptoFake LastPass Authenticator Installer Abuses Microsoft-Signed Driver to Kill Antivirus and EDRTASK#STOMP PowerShell Backdoor Steals Documents, Wi-Fi Passwords, and Clipboard DataCisco 0-Day, AI Agent RCE, ClickFix Attacks, ClickFix Surge, and Browser HijacksClickFix Lures Deploy ChainScript RAT Using Polygon to Rotate C2 InfrastructureJade Sleet Linked to Indian IT Provider Breach With FLATROOF and ROOFDECK BackdoorsThe Foundation of Identity SecuritySolarWinds Patches ARM Hard-Coded Key Flaw Enabling Unauthenticated RCEClaude Opus 5 Helped Researchers Take Over OpenAI Staff Accounts via Chained FlawsGoogle Gemini Broke Into Real Company Systems After Security Test Domain Mix-UpCritical Pre-Auth RCE in Orkes Conductor Workflow Platform Exploited in the WildCrowdSec Says TanStack npm Attack Led to Copy of 170 Private GitHub RepositoriesCISA Flags Three Linux Kernel Vulnerabilities Exploited in the WildPublic Exploits Released for Four Linux Kernel Flaws That Enable Local RootUn hombre conecta su aspiradora robot con un mando de PS5 y obtiene el control de miles de dispositivosLa web para adultos Frivol.com filtra una base de datos, exponiendo casi medio millón de cuentas de emailLa brecha entre inversión en ciberresiliencia y preparación adecuada aumenta la vulnerabilidad de las empresas españolasUn hacker ucraniano se declara culpable de operar OnlyFake, un portal de venta de pasaportes generados con IAEl software para psicólogos Eholo sufre una grave filtración de datosNew WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code ExecutionPlugin4Shell Lets Repository Owners Swap Pinned Plugin Code Across Four AI Coding AgentsTransparent Tribe Deploys New Rust Backdoor Using Private GitHub Repositories for C2An Abandoned CDN Domain Was Re-Registered. Thousands of Sites Still Call It.Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege EscalationWeaselBiscuit Stealer Spreads via 13 npm Packages to Harvest Chrome Extension StorageClaimed Bug Bounty Hunter Likely Used LLM to Build PhantomRaven npm StealerIran-Linked Handala Hack Tied to HEAVYGRAM Telegram Backdoor That Can Steal PasswordsCritical Docker Sandboxes Flaw Lets Malicious Guest Code Read and Modify macOS Host FilesRatHat Android Malware Abuses ADB to Retain Shell Access After UninstallSelf-Rewriting Agents, 800+ Flaws Patched, Insider SIM Swaps and 22 More New StoriesCritical Check Point Management Flaw Lets Unauthenticated Attackers Run Code as RootU.S. Seizes NightmareStresser Domains Linked to Hundreds of Thousands of DDoS AttacksCisco Warns of New Zero-Day ISE Auth Bypass (CVSS 10.0) Exploited in Active AttacksGyazo Breach Exposes 23.62 Million User Records and 490 Million Image Metadata Records
Chicago 12, Melborne City, USA
  • Home
  • Blog
  • Sample Page
The Digital Fortress
  • Get Started
Top Tags
  • Flaw
  • Malware
  • Flaws
  • Exploited
  • Code
  • Attacks
  • Microsoft
  • Attackers
Uncategorized
La ciberestafa que está arrasando en el Black Friday de 2025: el paquete no solicitado
  • admin
  • septiembre 25, 2026
Uncategorized
WordPress se refuerza: nuevas medidas de seguridad tras detectar 8.000 nuevas vulnerabilidades en 2024
  • admin
  • septiembre 25, 2026
Uncategorized

La ciberestafa que está arrasando en el Black Friday de 2025: el paquete no solicitado

  • Por admin
  • septiembre 25, 2026
  • 0 Comentarios
  • 4 views
Uncategorized

WordPress se refuerza: nuevas medidas de seguridad tras detectar 8.000 nuevas vulnerabilidades en 2024

  • Por admin
  • septiembre 25, 2026
  • 0 Comentarios
  • 4 views
Uncategorized

Los mods de Minecraft, un campo de minas propicio para la propagación de malware y el robo de datos personales

  • Por admin
  • septiembre 25, 2026
  • 0 Comentarios
  • 7 views
Uncategorized

Así opera Kraken, un nuevo y peligroso grupo de ransomware

  • Por admin
  • septiembre 25, 2026
  • 0 Comentarios
  • 3 views
Uncategorized

Ciberespías chinos usan la IA de Claude para automatizar el 90% de una campaña de ataques

  • Por admin
  • septiembre 25, 2026
  • 0 Comentarios
  • 2 views
Uncategorized

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

  • Por admin
  • septiembre 25, 2026
  • 0 Comentarios
  • 3 views
Uncategorized
La ciberestafa que está arrasando en el Black Friday de 2025: el paquete no solicitado
  • admin
  • septiembre 25, 2026
Uncategorized
WordPress se refuerza: nuevas medidas de seguridad tras detectar 8.000 nuevas vulnerabilidades en 2024
  • admin
  • septiembre 25, 2026

Uncategorized

1530  

Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
  • adminadmin
  • Browser
  • Build
  • julio 25, 2026
  • 0 Comentarios
Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A malvertising operation dubbed SourTrade is making victims’ browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file…

Continue reading
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts
  • adminadmin
  • Affiliate
  • Builds
  • julio 25, 2026
  • 0 Comentarios
DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts

The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to…

Continue reading
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
  • adminadmin
  • Affiliates
  • Cl0p
  • julio 25, 2026
  • 0 Comentarios
Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Ravie LakshmananJul 25, 2026Vulnerability / Ransomware Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and…

Continue reading
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
  • adminadmin
  • Account
  • CTM360
  • julio 25, 2026
  • 0 Comentarios
CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an…

Continue reading
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
  • adminadmin
  • 1.x
  • Attacks
  • julio 25, 2026
  • 0 Comentarios
Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Swati KhandelwalJul 25, 2026Vulnerability / Application Security Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba’s JSON library for Java. In affected Spring Boot…

Continue reading
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
  • adminadmin
  • Authenticated
  • Commands
  • julio 25, 2026
  • 0 Comentarios
Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Swati KhandelwalJul 25, 2026Vulnerability / Application Security Security researcher Yuhang Wu at depthfirst has published a working proof-of-concept (PoC) exploit that executes commands as git on an unpatched self-managed GitLab…

Continue reading
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants
  • adminadmin
  • Chickens
  • Families
  • julio 24, 2026
  • 0 Comentarios
Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

Ravie LakshmananJul 24, 2026Threat Intelligence / Browser Security The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are…

Continue reading
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery
  • adminadmin
  • BlueNoroff
  • Crypto
  • julio 24, 2026
  • 0 Comentarios
BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery

The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing…

Continue reading
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller
  • adminadmin
  • Active
  • Certighost
  • julio 24, 2026
  • 0 Comentarios
Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller

Swati KhandelwalJul 24, 2026Vulnerability / Enterprise Security Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for…

Continue reading
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers
  • adminadmin
  • Bing
  • Commands
  • julio 24, 2026
  • 0 Comentarios
Bing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s Servers

A crafted SVG submitted to Bing’s image search ran commands as NT AUTHORITY\SYSTEM on Microsoft’s production image-processing workers, and as root on the Linux machines in the same fleet. XBOW’s…

Continue reading

Paginación de entradas

1 … 55 56 57 … 153

Recent Posts

  • La ciberestafa que está arrasando en el Black Friday de 2025: el paquete no solicitado
  • WordPress se refuerza: nuevas medidas de seguridad tras detectar 8.000 nuevas vulnerabilidades en 2024
  • Los mods de Minecraft, un campo de minas propicio para la propagación de malware y el robo de datos personales
  • Así opera Kraken, un nuevo y peligroso grupo de ransomware
  • Ciberespías chinos usan la IA de Claude para automatizar el 90% de una campaña de ataques

Recent Comments

No hay comentarios que mostrar.

Archives

  • septiembre 2026
  • agosto 2026
  • julio 2026
  • junio 2026
  • mayo 2026
  • abril 2026
  • marzo 2026
  • febrero 2026
  • agosto 2024

Categories

  • Uncategorized

Other Story

Uncategorized

La ciberestafa que está arrasando en el Black Friday de 2025: el paquete no solicitado

  • admin
  • septiembre 25, 2026
La ciberestafa que está arrasando en el Black Friday de 2025: el paquete no solicitado
Uncategorized

WordPress se refuerza: nuevas medidas de seguridad tras detectar 8.000 nuevas vulnerabilidades en 2024

  • admin
  • septiembre 25, 2026
WordPress se refuerza: nuevas medidas de seguridad tras detectar 8.000 nuevas vulnerabilidades en 2024
Uncategorized

Los mods de Minecraft, un campo de minas propicio para la propagación de malware y el robo de datos personales

  • admin
  • septiembre 25, 2026
Los mods de Minecraft, un campo de minas propicio para la propagación de malware y el robo de datos personales
Uncategorized

Así opera Kraken, un nuevo y peligroso grupo de ransomware

  • admin
  • septiembre 25, 2026
Así opera Kraken, un nuevo y peligroso grupo de ransomware
Uncategorized

Ciberespías chinos usan la IA de Claude para automatizar el 90% de una campaña de ataques

  • admin
  • septiembre 25, 2026
Ciberespías chinos usan la IA de Claude para automatizar el 90% de una campaña de ataques
Uncategorized

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

  • admin
  • septiembre 25, 2026
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Copyright © 2026 The Digital Fortress | Powered by Desert Themes
Back to Top