UNIX CONSULTINGCiberseguridad, defensa y compliance IA Volver al sitio

Vigilancia ciberseguridad

Últimas señales de ciberseguridad

Esta vigilancia agrega fuentes institucionales, proveedores de seguridad, equipos de investigación y medios especializados. Cada ficha añade una lectura corta para ayudar a dirección IT, CISOs, DPOs, pymes, grandes cuentas y sector público a identificar temas que conviene priorizar.

Fuentes seguidas INCIBE CISA Microsoft MSRC Cisco Security Advisories SANS ISC The Hacker News GitHub Security Lab

FreeIPA Flaw Chain Lets Anonymous Clients Create Reusable Administrator Credentials

The Hacker News

A flaw in FreeIPA lets a client that has never logged in create a Kerberos identity of its own choosing in the directory and end... Lectura Unix Consulting: La señal se relaciona con usos IA, asistentes, modelos o datos manipulados por estos sistemas. Debe leerse con enfoque de gobernanza: qué datos...

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

The Hacker News

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source... Lectura Unix Consulting: Esta señal debe compararse con el inventario aplicativo, la exposición a Internet y el proceso de patch management. Lo importante no es solo la...

BengalSEO Poisons Bing Search Results to Deliver MayaBot and Tech Support Scams

The Hacker News

Cybersecurity researchers have disclosed details of a sprawling search engine optimization (SEO) poisoning campaign that paves... Lectura Unix Consulting: La señal se relaciona con usos IA, asistentes, modelos o datos manipulados por estos sistemas. Debe leerse con enfoque de gobernanza: qué datos...

Grindr to Pay £26 Million to Settle U.K. Claims Over HIV Status Data Sharing

The Hacker News

Online dating app Grindr has opted to pay £26 million ($35.1 million) to settle a lawsuit in the U.K. over allegations that it... Lectura Unix Consulting: La señal se relaciona con usos IA, asistentes, modelos o datos manipulados por estos sistemas. Debe leerse con enfoque de gobernanza: qué datos...

Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks

The Hacker News

Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that's targeting Microsoft 365 and... Lectura Unix Consulting: La señal se relaciona con usos IA, asistentes, modelos o datos manipulados por estos sistemas. Debe leerse con enfoque de gobernanza: qué datos...

⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More

The Hacker News

Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out... Lectura Unix Consulting: Esta señal debe compararse con el inventario aplicativo, la exposición a Internet y el proceso de patch management. Lo importante no es solo la...

Your Cloud Security Checklist Doesn't Work the Way You Think It Does

The Hacker News

If managing security across multiple cloud providers wasn't hard enough, each one fails in a different way. For the 2026 Cloud... Lectura Unix Consulting: La señal se relaciona con usos IA, asistentes, modelos o datos manipulados por estos sistemas. Debe leerse con enfoque de gobernanza: qué datos...

Critical MikroTik Vulnerability - Patch Now, (Sun, Sep 6th)

SANS ISC

Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication... Lectura Unix Consulting: Esta señal debe compararse con el inventario aplicativo, la exposición a Internet y el proceso de patch management. Lo importante no es solo la...

numbat - AI agent observability, (Fri, Sep 4th)

SANS ISC

La señal se relaciona con usos IA, asistentes, modelos o datos manipulados por estos sistemas. Debe leerse con enfoque de gobernanza: qué datos entran en la herramienta, qué accesos se conceden y qué trazas siguen auditables. Revisar los datos manipulados,...

Cisco IOS XR Software Security Hardening Release: September 2026

Cisco Security Advisories

As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco IOS XR Software engineering team has... Lectura Unix Consulting: Esta señal debe compararse con el inventario aplicativo, la exposición a Internet y el proceso de patch management. Lo importante no es solo la...

CISA Adds One Known Exploited Vulnerability to Catalog

CISA

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog , based on evidence of active... Lectura Unix Consulting: Esta señal debe compararse con el inventario aplicativo, la exposición a Internet y el proceso de patch management. Lo importante no es solo la...

Chromium: CVE-2026-84359 Information leak in Skia

Microsoft MSRC

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see... Lectura Unix Consulting: Esta señal debe compararse con el inventario aplicativo, la exposición a Internet y el proceso de patch management. Lo importante no es solo la...

Chromium: CVE-2026-84358 Improper privilege management in Downloads

Microsoft MSRC

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see... Lectura Unix Consulting: Esta señal debe compararse con el inventario aplicativo, la exposición a Internet y el proceso de patch management. Lo importante no es solo la...

Chromium: CVE-2026-84357 Improper input validation in Omnibox

Microsoft MSRC

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see... Lectura Unix Consulting: Esta señal debe compararse con el inventario aplicativo, la exposición a Internet y el proceso de patch management. Lo importante no es solo la...

Chromium: CVE-2026-84356 UI misrepresentation in FullScreen

Microsoft MSRC

This CVE was assigned by Chrome. Microsoft Edge (Chromium-based) ingests Chromium, which addresses this vulnerability. Please see... Lectura Unix Consulting: Esta señal debe compararse con el inventario aplicativo, la exposición a Internet y el proceso de patch management. Lo importante no es solo la...

Tycon Systems TPDIN-Monitor-WEB3

CISA

View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to perform a man-in-the-middle... Lectura Unix Consulting: Esta señal debe compararse con el inventario aplicativo, la exposición a Internet y el proceso de patch management. Lo importante no es solo la...

Pyramid Solutions NetStaX EtherNet/IP Stack

CISA

View CSAF Summary Successful exploitation of this vulnerability could result in memory corruption, a device crash, or a potential... Lectura Unix Consulting: Esta señal debe compararse con el inventario aplicativo, la exposición a Internet y el proceso de patch management. Lo importante no es solo la...

IXON VPN Client

CISA

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform remote code execution on the... Lectura Unix Consulting: Esta señal debe compararse con el inventario aplicativo, la exposición a Internet y el proceso de patch management. Lo importante no es solo la...

Cisco Advance Notification for Publication of September 2, 2026, Security Advisories

Cisco Security Advisories

On September 2, 2026, the Cisco Product Security Incident Response Team (PSIRT) published the following advisories: Cisco... Lectura Unix Consulting: Esta señal debe compararse con el inventario aplicativo, la exposición a Internet y el proceso de patch management. Lo importante no es solo la...

Ver archivo completo