Saltar al contenido
Mar. Jul 28th, 2026
Trending News: Cifrado de datos en plataformas SaaS: todo lo que debes exigir al proveedorCondenan a un ucraniano a 5 años de cárcel por ayudar a trabajadores de TI norcoreanos a infiltrarse en EE.UU.Encuentran una puerta trasera en un software anti-ransomwareFiltran datos de directivos del INCIBE y de la Policía sin vulnerar los sistemas de estas institucionesCruz Roja Española tendrá que pagar una multa de 80.000 euros por violar la privacidad de pacientesClaude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES AttackCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachNimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert RelaysResearcher Says AI Helped Develop Linux Traffic-Control Race Into Root ExploitCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging InAttackers Exploit Arista VeloCloud Orchestrator Command Injection FlawMicrosoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the CostNVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA FrameworkDysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid DisruptionOperation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams UpdatePublic Exploit Released for Patched vBulletin Pre-Auth Code Execution FlawRogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and Moren8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n ProcessCruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows MalwareGitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package AdoptionTELESHIM Abuses Telegram for C2 in Attacks Against Middle East GovernmentsMalvertising Sends Malware in Pieces, Then Makes the Browser Build the ExecutableDevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate PayoutsCl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCECTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account HijackingFastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched AvailableResearcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as GitGolden Chickens Resurfaces With Four New Malware Families and Modular ImplantsBlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware DeliveryCertighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain ControllerBing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s ServersChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing LinkSeeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can DoHacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance MinistryKimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers SayNodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private ChatsFake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 AttacksGoogle Adds Selfie Video Recovery for Users Locked Out of Their AccountsRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA CodesChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare AttacksAndroid Spyware, PLC Attacks, AI Image Prompt Injection + 12 More StoriesChaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and EdgeClaude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac FilesAttackers Weaponize GitHub Actions Runners to Target cPanel and WHM ServersHow Synthetic Identity Fraud is Coming for Machine IdentitiesNine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL InstallsCheck Point Patches Exploited SmartConsole Flaw Allowing Full Admin AccessAdobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web DataBasic-Fit sufre una brecha de datos que afecta a sus usuarios españolesEl grupo de ransomware Lockbit 5.0 reivindica un ciberataque contra Cegasa EnergíaHackean el sistema de control de inundaciones de la Plaza de San Marcos en VeneciaEl Gobierno prepara una campaña institucional de urgencia por el aumento de la ciberdelincuenciaHelvetia Caser confirma la brecha de datos en un correo enviado a sus clientesGitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP TierUbuntu snap-confine Flaw Could Give Local Users Root on Default Desktop InstallsThe Fastest Path to AI Adoption Runs Through SecurityHackers Exploit Windmill Flaw to Read Arbitrary Server Files Without AuthenticationWhy Modern SOCs Need Multi-Layered DetectionsOpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat BenchmarkMicrosoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review AgentsPolice Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFATrojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working LibraryApple Fixes Hide My Email Bug That Exposed Real Addresses in Mail LogsNightSpire, el ransomware que ha ‘taladrado’ a una ferretería españolaLos hackers también vuelven a lo presencial… y se hacen pasar por personal de TI de tu empresaCypherLoc: el scareware que bloquea el navegador y ya acumula 2,8 millones de ataques en 2026Los ciberataques a proveedores ponen en alerta a las empresas españolasLa Agencia Espacial Española niega haber sufrido un ciberataqueNew Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an ExploitGoogle Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software VulnerabilitiesAWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run CodeZimbra Patches Critical SNMP Command Injection and Four XSS VulnerabilitiesCritical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoCQilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial AccessN-day is Becoming N-Hour. Patching Faster Won’t Save You.Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCsCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code ExecutionWordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass ScanningNew ENCFORGE Ransomware Targets AI Model Files in Langflow RCE AttackFakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader MalwareExposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware CampaignMythos Didn’t Break Your Security Program. Your Exposure Window Could.HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and MoreRussian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and UkraineRussian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCsNew 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During ExtractionSleeperGem Uses Three Malicious RubyGems Packages to Target Developer MachinesWorld’s Largest AI Model Repository Hugging Face Breached by Autonomous AI AgentCritical NGINX Vulnerability Can Crash Workers and May Allow Remote Code ExecutionSonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root AccessUAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih MalwareNew GoSerpent Malware Targets Southeast Asian Governments and Diplomats for EspionageNew wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run CodeOpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS RequestsGoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate TheftSeven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Chicago 12, Melborne City, USA
The Digital Fortress
  • Home
  • Blog
  • Sample Page
  • Get Started
Mar. Jul 28th, 2026
Trending News: Cifrado de datos en plataformas SaaS: todo lo que debes exigir al proveedorCondenan a un ucraniano a 5 años de cárcel por ayudar a trabajadores de TI norcoreanos a infiltrarse en EE.UU.Encuentran una puerta trasera en un software anti-ransomwareFiltran datos de directivos del INCIBE y de la Policía sin vulnerar los sistemas de estas institucionesCruz Roja Española tendrá que pagar una multa de 80.000 euros por violar la privacidad de pacientesClaude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES AttackCritical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root24,650 Internet-Exposed BMCs Disclose IPMI Password Hashes Before LoginTengu Botnet Reboots Compromised Linux Devices When Defenders Kill Its ProcessJFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face BreachNimbus Manticore Deploys NightLedger and Turns Victim Systems Into Covert RelaysResearcher Says AI Helped Develop Linux Traffic-Control Race Into Root ExploitCritical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging InAttackers Exploit Arista VeloCloud Orchestrator Command Injection FlawMicrosoft Says New Cybersecurity AI Model Helps MDASH Hit 95.95% at Half the CostNVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA FrameworkDysphoria IoT Botnet Adds Blockchain C2 and Victim Relays After JackSkid DisruptionOperation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams UpdatePublic Exploit Released for Patched vBulletin Pre-Auth Code Execution FlawRogue AI Agents, Check Point Exploit, Slopsquatting, ClickFix Lures and Moren8n Sandbox Escape Lets Workflow Editors Run OS Commands as the n8n ProcessCruciferra Crypter Uses BYOVD and Process Ghosting to Hide Windows MalwareGitHub Adds 3-Day Dependabot Cooldown to Limit Poisoned Package AdoptionTELESHIM Abuses Telegram for C2 in Attacks Against Middle East GovernmentsMalvertising Sends Malware in Pieces, Then Makes the Browser Build the ExecutableDevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate PayoutsCl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCECTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account HijackingFastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched AvailableResearcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as GitGolden Chickens Resurfaces With Four New Malware Families and Modular ImplantsBlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware DeliveryCertighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain ControllerBing Images Flaws Let Crafted SVGs Run Commands as SYSTEM on Microsoft’s ServersChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing LinkSeeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can DoHacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance MinistryKimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers SayNodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private ChatsFake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 AttacksGoogle Adds Selfie Video Recovery for Users Locked Out of Their AccountsRussian Espionage Group Exploited Zimbra Zero-Day to Steal Mail and 2FA CodesChina-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare AttacksAndroid Spyware, PLC Attacks, AI Image Prompt Injection + 12 More StoriesChaos Ransomware Uses msaRAT to Route C2 Traffic Through Headless Chrome and EdgeClaude Cowork Flaw Could Let AI Agent Escape Its VM and Access Mac FilesAttackers Weaponize GitHub Actions Runners to Target cPanel and WHM ServersHow Synthetic Identity Fraud is Coming for Machine IdentitiesNine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL InstallsCheck Point Patches Exploited SmartConsole Flaw Allowing Full Admin AccessAdobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web DataBasic-Fit sufre una brecha de datos que afecta a sus usuarios españolesEl grupo de ransomware Lockbit 5.0 reivindica un ciberataque contra Cegasa EnergíaHackean el sistema de control de inundaciones de la Plaza de San Marcos en VeneciaEl Gobierno prepara una campaña institucional de urgencia por el aumento de la ciberdelincuenciaHelvetia Caser confirma la brecha de datos en un correo enviado a sus clientesGitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP TierUbuntu snap-confine Flaw Could Give Local Users Root on Default Desktop InstallsThe Fastest Path to AI Adoption Runs Through SecurityHackers Exploit Windmill Flaw to Read Arbitrary Server Files Without AuthenticationWhy Modern SOCs Need Multi-Layered DetectionsOpenAI Says Its AI Models Escaped Sandbox, Targeted Hugging Face to Cheat BenchmarkMicrosoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review AgentsPolice Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFATrojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working LibraryApple Fixes Hide My Email Bug That Exposed Real Addresses in Mail LogsNightSpire, el ransomware que ha ‘taladrado’ a una ferretería españolaLos hackers también vuelven a lo presencial… y se hacen pasar por personal de TI de tu empresaCypherLoc: el scareware que bloquea el navegador y ya acumula 2,8 millones de ataques en 2026Los ciberataques a proveedores ponen en alerta a las empresas españolasLa Agencia Espacial Española niega haber sufrido un ciberataqueNew Bit2Watt Attack Could Let Cloud Tenants Disrupt Power Grids Without an ExploitGoogle Launches Gemini 3.5 Flash Cyber AI to Find and Fix Software VulnerabilitiesAWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run CodeZimbra Patches Critical SNMP Command Injection and Four XSS VulnerabilitiesCritical SharePoint RCE CVE-2026-50522 Under Active Exploitation After Public PoCQilin Ransomware Attackers Exploit PAN-OS Authentication Bypass for Initial AccessN-day is Becoming N-Hour. Patching Faster Won’t Save You.Open-Source Android AI Agents Could Let Invisible Screen Text Run Code on Host PCsCritical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code ExecutionWordPress wp2shell Exploitation Grows as Public Exploit Fuels Mass ScanningNew ENCFORGE Ransomware Targets AI Model Files in Langflow RCE AttackFakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader MalwareExposed Server Reveals AI-Assisted Phishing Toolkit Behind WebDAV Malware CampaignMythos Didn’t Break Your Security Program. Your Exposure Window Could.HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050WordPress RCE, SonicWall 0-Days, AI Service Attacks, SharePoint 0-Day and MoreRussian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and UkraineRussian-Speaking Hacker Uses Google Gemini CLI to Control Botnet of Eight Dental Clinic PCsNew 7-Zip Vulnerability Could Let Crafted XZ Archives Run Code During ExtractionSleeperGem Uses Three Malicious RubyGems Packages to Target Developer MachinesWorld’s Largest AI Model Repository Hugging Face Breached by Autonomous AI AgentCritical NGINX Vulnerability Can Crash Workers and May Allow Remote Code ExecutionSonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root AccessUAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih MalwareNew GoSerpent Malware Targets Southeast Asian Governments and Diplomats for EspionageNew wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run CodeOpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS RequestsGoldenEyeDog Subgroup Linked to DigiCert Breach and Code-Signing Certificate TheftSeven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT
Chicago 12, Melborne City, USA
  • Home
  • Blog
  • Sample Page
The Digital Fortress
  • Get Started

Etiqueta Private

  1. Inicio
  2. NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats
  • adminadmin
  • Access
  • Admin
  • julio 24, 2026
  • 0 Comentarios
NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats

Swati KhandelwalJul 24, 2026Web Security / Vulnerability Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high…

Continue reading
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data
  • adminadmin
  • Agentic
  • Data
  • julio 7, 2026
  • 0 Comentarios
Public GitHub Issue Could Trick GitHub Agentic Workflows Into Leaking Private Repo Data

A public issue can trick GitHub Agentic Workflows into leaking the contents of an organization’s private repositories, researchers at Noma Security have shown. The attacker needs only to open a…

Continue reading
WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private
  • adminadmin
  • Finally
  • Numbers
  • junio 29, 2026
  • 0 Comentarios
WhatsApp is Finally Getting Usernames to Help Keep Phone Numbers Private

Ravie LakshmananJun 29, 2026Privacy / Social Media WhatsApp on Monday officially announced the start of global reservations of usernames with an aim to protect the privacy of more than three…

Continue reading
Gitea Vulnerability Exposes Private Container Images without Authentication
  • adminadmin
  • Authentication
  • Container
  • mayo 27, 2026
  • 0 Comentarios
Gitea Vulnerability Exposes Private Container Images without Authentication

Ravie LakshmananMay 27, 2026Vulnerability / Software Security Cybersecurity researchers have disclosed a security flaw in Gitea, an open-source, self-hosted platform for version control, that allows unauthenticated remote attackers to pull…

Continue reading
Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts
  • adminadmin
  • Artifacts
  • Cloud
  • marzo 31, 2026
  • 0 Comentarios
Vertex AI Vulnerability Exposes Google Cloud Data and Private Artifacts

Ravie LakshmananMar 31, 2026Cloud Security / AI Security Cybersecurity researchers have disclosed a security «blind spot» in Google Cloud’s Vertex AI platform that could allow artificial intelligence (AI) agents to…

Continue reading

Recent Posts

  • Cifrado de datos en plataformas SaaS: todo lo que debes exigir al proveedor
  • Condenan a un ucraniano a 5 años de cárcel por ayudar a trabajadores de TI norcoreanos a infiltrarse en EE.UU.
  • Encuentran una puerta trasera en un software anti-ransomware
  • Filtran datos de directivos del INCIBE y de la Policía sin vulnerar los sistemas de estas instituciones
  • Cruz Roja Española tendrá que pagar una multa de 80.000 euros por violar la privacidad de pacientes

Recent Comments

No hay comentarios que mostrar.

Archives

  • julio 2026
  • junio 2026
  • mayo 2026
  • abril 2026
  • marzo 2026
  • febrero 2026
  • agosto 2024

Categories

  • Uncategorized

Other Story

Uncategorized

Cifrado de datos en plataformas SaaS: todo lo que debes exigir al proveedor

  • admin
  • julio 28, 2026
Cifrado de datos en plataformas SaaS: todo lo que debes exigir al proveedor
Uncategorized

Condenan a un ucraniano a 5 años de cárcel por ayudar a trabajadores de TI norcoreanos a infiltrarse en EE.UU.

  • admin
  • julio 28, 2026
Condenan a un ucraniano a 5 años de cárcel por ayudar a trabajadores de TI norcoreanos a infiltrarse en EE.UU.
Uncategorized

Encuentran una puerta trasera en un software anti-ransomware

  • admin
  • julio 28, 2026
Encuentran una puerta trasera en un software anti-ransomware
Uncategorized

Filtran datos de directivos del INCIBE y de la Policía sin vulnerar los sistemas de estas instituciones

  • admin
  • julio 28, 2026
Filtran datos de directivos del INCIBE y de la Policía sin vulnerar los sistemas de estas instituciones
Uncategorized

Cruz Roja Española tendrá que pagar una multa de 80.000 euros por violar la privacidad de pacientes

  • admin
  • julio 28, 2026
Cruz Roja Española tendrá que pagar una multa de 80.000 euros por violar la privacidad de pacientes
Uncategorized

Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack

  • admin
  • julio 28, 2026
Claude AI Just Cracked a Post-Quantum Test Scheme and Found a Faster 7-Round AES Attack
Copyright © 2026 The Digital Fortress | Powered by Desert Themes
Back to Top