🛡️ Radar de Seguridad

SALVI & ASOCIADOS — Gerencia de Ciberseguridad • Actualizado: 30/07/2026 10:00
🔍 Monitoreo de Amenazas — Últimas 24 horas

🚨 Noticias y Alertas

  • Russian hackers exploit Exchange OWA zero-day for long-term mailbox access [Ver →]
  • Cisco warns of FMC static credential flaw exploited in zero-day attacks [Ver →]
  • Un zero-day en Cisco Secure FMC abre la puerta a accesos con credenciales estáticas [Ver →]
  • Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts [Ver →]
  • Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation [Ver →]
  • Health-ISAC warns of rising ShinyHunters data theft attacks on healthcare [Ver →]
  • OpenAI agent used exposed credentials at 4 services in Hugging Face breach [Ver →]
  • Hackers disrupt over 30 Minnesota water utilities in coordinated OT attack [Ver →]

🔴 Vulnerabilidades Críticas

🔴 CVE-2026-54680 9.9 — CRÍTICA
Logging operator automates the deployment and configuration of Kubernetes logging pipelines. Prior to 6.6.0, the Fluentd configuration renderer FluentRender in pkg/sdk/logging/mode...
🔴 CVE-2026-58046 9.9 — CRÍTICA
Improper neutralization in the Plesk XML-RPC API allows a remote authenticated low-privileged user to perform SQL injection and read arbitrary data from the Plesk database, leading...
🔴 CVE-2026-60112 9.8 — CRÍTICA
AMMOS Instrument Toolkit (AIT) GUI before 2.5.1 contains a missing authentication vulnerability that allows any unauthenticated network attacker to obtain a valid session and issue...
🔴 CVE-2026-60113 9.8 — CRÍTICA
AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) Interface before 2.2.2 contains a missing authentication vulnerability in the Space Link Extension (SLE) interface manager t...
🔴 CVE-2026-67191 9.8 — CRÍTICA
Xlight FTP Server before 3.9.5 contains a pre-authentication heap buffer overflow vulnerability that allows remote unauthenticated attackers to write past the end of a heap buffer ...
🔴 CVE-2026-41939 9.8 — CRÍTICA
Care Everywhere Gateway 14.3.10 contains a hard-coded credentials vulnerability in the bundled WildFly 8.2.0.Final management interface that allows unauthenticated remote attackers...
🔴 CVE-2026-16610 9.8 — CRÍTICA
The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive...
🔴 CVE-2026-58066 9.8 — CRÍTICA
Rocket.Chat's SAML SSO before versions 8.7.0, 8.6.1, 8.5.2, 8.4.5, 8.3.7, 8.2.7, 8.1.7, 8.0.8, and 7.10.14 verified XML signatures but did not bind the validated signature to samlp...
🔴 CVE-2026-44090 9.8 — CRÍTICA
Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the devic...
🔴 CVE-2026-44101 9.8 — CRÍTICA
Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and c...

🏴‍☠️ Ataques de Ransomware

  • 💀 **Siam Stabilizers and Chemicals Co., Ltd. / SSC** | Grupo: gunra | Origen: TH | Fecha: 2026-07-30
  • 💀 **servitelco** | Grupo: qilin | Origen: CL | Fecha: 2026-07-30
  • 💀 **Orimar** | Grupo: qilin | Origen: BE | Fecha: 2026-07-30
  • 💀 **Indian Motos Inmot** | Grupo: qilin | Origen: EC | Fecha: 2026-07-30
  • 💀 **Yue Ki Industrial** | Grupo: morpheus | Origen: TW | Fecha: 2026-07-30
  • 💀 **Warwick Fabrics** | Grupo: kairos | Origen: NZ | Fecha: 2026-07-30
  • 💀 **Adpo** | Grupo: qilin | Origen: BE | Fecha: 2026-07-30
  • 💀 **Van Eijck International Car Rescue** | Grupo: aurora | Origen: NL | Fecha: 2026-07-30
  • 💀 **Evosys Laser GmbH** | Grupo: aurora | Origen: DE | Fecha: 2026-07-30
  • 💀 **Pyramid Analytics B.V.** | Grupo: aurora | Origen: NL | Fecha: 2026-07-30