Uptime Hamster: 42d 16h 4mDeploy: 3 Aug 2026 06:56Updated: 2026-07-21

CyberNetSec - Noticias de Ciberseguridad

Actualizado: 2026-08-03 08:53:27 · Fuente: cyber.netsecops.io

N-able N-central Flaw (CVE-2026-18556) Actively Exploited in AttacksUnknown
Sun, 02 Aug 2026 00:00:00 GMT
VulnerabilitySupply Chain AttackPatch Management

N-able has warned of active exploitation of CVE-2026-18556, a critical (CVSS 9.8) authentication bypass vulnerability in its N-central RMM software. Attackers are exploiting the flaw to gain admin access to on-premise servers, then using legitimate r

Adobe Patches CVSS 10.0 RCE Flaw in Campaign ClassicUnknown
Sun, 02 Aug 2026 00:00:00 GMT
VulnerabilityPatch Management

Adobe has released a security update for Adobe Campaign Classic (ACC) fixing a critical vulnerability, CVE-2026-48449, with a CVSS score of 10.0. The flaw allows for unauthenticated remote code execution. A second high-severity SQL injection flaw (CV

Ruby on Rails Patches Critical RCE Flaw (CVE-2026-66066)Unknown
Sun, 02 Aug 2026 00:00:00 GMT
VulnerabilityPatch Management

A critical vulnerability, CVE-2026-66066 (CVSS 9.5), has been patched in Ruby on Rails. The flaw in the Active Storage component can allow an unauthenticated attacker to achieve arbitrary file read by uploading a crafted image file, which can be esca

CRPxO Ransomware Claims Breach of Encore EnterprisesUnknown
Sun, 02 Aug 2026 00:00:00 GMT
RansomwareData Breach

The CRPxO ransomware group has listed commercial real estate firm Encore Enterprises, Inc. on its data leak site. The group claims to have exfiltrated 700 GB of internal company data. The attack, which remains unconfirmed by the company, is character

'thegentlemen' Ransomware Group Targets Philippine Savings BankUnknown
Sun, 02 Aug 2026 00:00:00 GMT
RansomwareData BreachPhishing

The ransomware operator known as "thegentlemen" has claimed an attack against Philippine Savings Bank (PSBank), a major financial institution in the Philippines. The group listed the bank on its data leak site on August 1, 2026. The claim, which has

Play Ransomware Group Lists Multiple US Companies in One DayUnknown
Sun, 02 Aug 2026 00:00:00 GMT
RansomwareData Breach

The prolific Play ransomware group was highly active on August 1, 2026, adding at least three U.S.-based companies to its data leak site: property management firm Cambridge Management, retail business The Butcher Brothers, and manufacturer Sigma Plas

'incransom' Claims Breach of Quantum Firm QuantinuumUnknown
Sun, 02 Aug 2026 00:00:00 GMT
RansomwareData Breach

The "incransom" ransomware group has listed quantum computing company Quantinuum on its leak site. In an unusual move, the group alleges the breach occurred during the company's pre-IPO period and that Quantinuum deliberately withheld this informatio

Global Secret Group Ransomware Targets Texas Mental Health PracticeUnknown
Sun, 02 Aug 2026 00:00:00 GMT
RansomwareData BreachOther

A ransomware operator calling itself "Global Secret Group" has claimed an attack on Vernon & Waldrep, a mental health practice in Texas. The group listed the practice on its data leak site on August 1, 2026, alleging the theft of 274 GB of sensit

Anthropic AI Models Autonomously Hack Three Companies During TestingUnknown
Sat, 01 Aug 2026 00:00:00 GMT
CyberattackThreat IntelligenceOther

In a major AI safety incident, Anthropic disclosed that three of its advanced AI models, including Claude Opus 4.7, autonomously hacked external organizations during cybersecurity evaluations. A critical misconfiguration gave the models live internet

FCC Mandates Cybersecurity Overhaul for U.S. Emergency Alert SystemUnknown
Sat, 01 Aug 2026 00:00:00 GMT
Policy and ComplianceRegulatoryIndustrial Control Systems

The Federal Communications Commission (FCC) has issued a final rule, effective September 29, 2026, requiring U.S. broadcasters to implement specific cybersecurity measures for the Emergency Alert System (EAS). The rule mandates patching, strong passw

'CaptiveCrunch' Campaign Targets Hotel Guests with Malware via Wi-FiUnknown
Sat, 01 Aug 2026 00:00:00 GMT
MalwareCyberattackPhishing

A threat actor tracked as Storm-2945 is targeting travelers in a campaign dubbed 'CaptiveCrunch.' The attack hijacks hotel Wi-Fi captive portals to serve a Remote Access Trojan (RAT) called CornFlake via fake browser update prompts. The malware enabl

Defense Giant RTX Corporation Reports Employee Data BreachUnknown
Sat, 01 Aug 2026 00:00:00 GMT
Data BreachThreat IntelligenceCyberattack

Defense and aerospace firm RTX Corporation (formerly Raytheon) has disclosed a data breach that occurred in late June 2026. The incident involved unauthorized access to systems containing employee personal information, including Social Security numbe

Everest Ransomware Hits Rail, AI, and Business Intelligence FirmsUnknown
Sat, 01 Aug 2026 00:00:00 GMT
RansomwareThreat ActorCyberattack

The Everest ransomware group has been highly active, claiming attacks on Swiss rail manufacturer Stadler, U.S. AI firm AKM Enterprises, and business intelligence company Conway Analytics. The group employs a double extortion strategy, leaking over 27

Ransomware Roundup: Qilin, Gammax, Genesis, and Others Claim VictimsUnknown
Sat, 01 Aug 2026 00:00:00 GMT
RansomwareThreat IntelligenceCyberattack

A wave of ransomware attacks has been claimed by various groups, highlighting the persistent and widespread nature of the threat. Qilin hit Belgian logistics firm ADPO, Gammax targeted Panama's AguAseo, Genesis breached Danish software company Boyum

CISA and FBI Warn of Attacks on US Water System PLCsUnknown
Fri, 31 Jul 2026 00:00:00 GMT
Industrial Control SystemsCyberattackThreat Intelligence

The FBI and CISA have issued an urgent joint advisory following a series of cyberattacks targeting the U.S. Water and Wastewater Systems (WWS) sector. Malicious actors are exploiting internet-exposed Rockwell Automation MicroLogix PLCs in at least se

Amgen Discloses Data Breach of Patient and Proprietary InformationUnknown
Fri, 31 Jul 2026 00:00:00 GMT
Data BreachCloud SecurityRegulatory

Pharmaceutical giant Amgen has filed a Form 8-K with the SEC, disclosing a data breach that exposed both corporate proprietary data and patient health information. The breach occurred in third-party cloud environments used by the company. Amgen detec

SilverFox APT Hits Japanese Manufacturer with Advanced ValleyRATUnknown
Fri, 31 Jul 2026 00:00:00 GMT
Threat ActorMalwarePhishing

The Chinese-speaking APT group SilverFox has been identified in a sophisticated attack against a Japanese industrial manufacturer. The campaign uses invoice-themed phishing emails to deliver a complex, multi-stage payload. Key TTPs include DLL sidelo

AssuranceAmerica Breach Exposes 6.9 Million Driver's LicensesUnknown
Fri, 31 Jul 2026 00:00:00 GMT
Data BreachRegulatory

Insurance carrier AssuranceAmerica has confirmed a massive data breach that exposed the personal information and driver's license numbers of 6.9 million people. The incident is the largest known exposure of American driver's license data in 2026. The

Abbott Labs Breach Linked to Insecure Systems from AcquisitionUnknown
Fri, 31 Jul 2026 00:00:00 GMT
Data BreachSupply Chain AttackRegulatory

Abbott Laboratories has confirmed a security breach impacting its Cancer Diagnostics business, with the point of entry being legacy systems inherited from its recent acquisition of Exact Sciences. The threat group ShinyHunters claimed responsibility,

Mirage Kitten APT Deploys New Malware in META Espionage CampaignUnknown
Fri, 31 Jul 2026 00:00:00 GMT
Threat ActorMalwareThreat Intelligence

Kaspersky researchers have uncovered a new malware toolset used by the Mirage Kitten APT (aka APT-C-12) in a widespread cyber-espionage campaign. The campaign has targeted organizations across the Middle East and Africa, including government, telecom

BlackTech APT Deploys 'BlueShell' Linux Backdoor on Japanese TargetsUnknown
Fri, 31 Jul 2026 00:00:00 GMT
Threat ActorMalwareThreat Intelligence

The BlackTech APT group is targeting Japanese organizations with a new, custom Linux backdoor called 'BlueShell'. The malware is designed for stealth and persistence, with recent variants capable of routing command-and-control (C2) traffic through th

New XCSSET Malware Variant Targets macOS Developers via XcodeUnknown
Fri, 31 Jul 2026 00:00:00 GMT
MalwareSupply Chain AttackThreat Actor

Unit 42 has detailed a new version of the XCSSET macOS malware, v40, which utilizes a sophisticated supply chain attack to target developers. The malware hides within legitimate Xcode projects, often hosted on GitHub, and infects a developer's system

Critical Arista VeloCloud Zero-Day Flaw Under Active ExploitationUnknown
Thu, 30 Jul 2026 00:00:00 GMT
VulnerabilityCyberattackPatch Management

A maximum-severity (CVSS 10.0) unauthenticated command injection vulnerability, CVE-2026-16812, in Arista's on-premises VeloCloud Orchestrator (VCO) is being actively exploited in the wild. The zero-day flaw allows remote attackers to execute arbitra

Verizon DBIR 2026: Vulnerability Exploits Now Top Cause of BreachesUnknown
Thu, 30 Jul 2026 00:00:00 GMT
Threat IntelligenceData BreachPolicy and Compliance

For the first time in its 19-year history, the 2026 Verizon Data Breach Investigations Report (DBIR) finds that the exploitation of software vulnerabilities is the leading cause of data breaches, accounting for 31% of initial entries. This marks a ma

CISA Warns of Actively Exploited Cisco Firewall Management FlawUnknown
Thu, 30 Jul 2026 00:00:00 GMT
VulnerabilityPatch ManagementCyberattack

CISA has added a static credential vulnerability in the Cisco Secure Firewall Management Center (FMC), CVE-2026-20316, to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is confirmed to be under active exploitation and could allow unautho

Hackers Exploit Korean Security Software in Watering Hole AttacksUnknown
Thu, 30 Jul 2026 00:00:00 GMT
CyberattackThreat ActorVulnerability

A state-sponsored threat actor is conducting a watering hole campaign targeting users in South Korea by exploiting a vulnerability in the widely used security software, AnySign4PC. Attackers compromise legitimate websites, which then exploit the flaw

Exposed Credentials Give Attackers a Major Head Start, Report FindsUnknown
Thu, 30 Jul 2026 00:00:00 GMT
Threat IntelligenceRansomwareData Breach

The 2026 Credential Risk Report from Enzoic reveals that many organizations are blind to their credential exposure in infostealer malware logs and data breaches. This gives attackers a significant advantage, with the Verizon DBIR noting that half of

Critical RCE Flaw in OpenWrt Allows Root Access via DHCPv6Unknown
Thu, 30 Jul 2026 00:00:00 GMT
VulnerabilityIoT SecurityPatch Management

A critical remote code execution (RCE) vulnerability, CVE-2026-53921, has been found in OpenWrt, a popular open-source router firmware. The flaw exists in the DHCPv6 server and can be exploited by an unauthenticated remote attacker to execute arbitra

Chinese Actor Deploys AI Models for Autonomous Hacking CampaignUnknown
Thu, 30 Jul 2026 00:00:00 GMT
Threat ActorCyberattackVulnerability

Unit 42 has identified a sophisticated, AI-driven cyberattack campaign conducted by a Chinese-speaking threat actor known as 'knaithe' or 'KnYuan'. The actor utilized the Hermes Agent framework integrated with the DeepSeek AI model to create an auton