DEV Community

Christian Marbel Vega Mamani
Christian Marbel Vega Mamani

Posted on

πŸ›‘οΈ Threat Intel Diario β€” 26/07/2026

πŸ€– Auto-generated daily threat intelligence digest β€” July 26, 2026

🚨 Alertas de ciberseguridad para tu empresa
Fuentes: BleepingComputer, Group-IB, MSRC Microsoft, The Hacker News

Un dΓ­a mΓ‘s en el que la ciberdelincuencia se hace presente, con noticias sobre vulnerabilidades en la cadena de suministro que pueden comprometer la seguridad de tus sistemas, y una nueva oleada de ataques de ransomware que amenazan con desestabilizar tu negocio.



Vulnerabilidad β€” Chromium: CVE-2026-16804 Use after free in Input

πŸ” QuΓ© estΓ‘ pasando

  • Se ha identificado una vulnerabilidad en Chromium conocida como CVE-2026-16804, que se trata de un "use after free" en Input.
  • Esta vulnerabilidad fue asignada por Google Chrome.
  • Microsoft Edge (basado en Chromium) ingiere Chromium, lo que significa que tambiΓ©n estΓ‘ afectado.

⚠️ Por qué importa

La vulnerabilidad CVE-2026-16804 en Chromium puede permitir a un atacante ejecutar cΓ³digo arbitrario en el sistema de un usuario, lo que puede llevar a una serie de consecuencias negativas, como el robo de datos, la toma del control del sistema o la instalaciΓ³n de malware. Esta vulnerabilidad puede ser explotada por un atacante malintencionado para obtener acceso no autorizado a la informaciΓ³n de un usuario o para causar daΓ±o al sistema.

βš™οΈ CΓ³mo funciona

La vulnerabilidad se debe a un "use after free" en el componente Input de Chromium. En resumen, el componente Input no verifica adecuadamente la memoria que se utiliza despuΓ©s de que un objeto se ha eliminado, lo que permite a un atacante acceder a la memoria y realizar acciones maliciosas.

πŸ‘οΈ QuΓ© vigilar

  • Parche disponible: Microsoft Edge (basado en Chromium) ya ha incorporado el parche para esta vulnerabilidad.
  • Fuente de informaciΓ³n: Consulte Google Chrome Releases para obtener mΓ‘s informaciΓ³n sobre esta vulnerabilidad y su soluciΓ³n.
  • RecomendaciΓ³n: Los usuarios deben asegurarse de que su navegador estΓ© actualizado para evitar cualquier vulnerabilidad.

πŸ”— Fuentes consultadas (3):



Vulnerabilidad β€” Chromium: CVE-2026-16807 Out of bounds write in Codecs

πŸ” QuΓ© estΓ‘ pasando

  • Se identificΓ³ una vulnerabilidad en Chromium conocida como CVE-2026-16807, que implica una escritura fuera de lΓ­mites en el cΓ³digo de cΓ³digos.
  • Esta vulnerabilidad fue asignada por Chrome.
  • Microsoft Edge (basada en Chromium) ingiere Chromium, lo que significa que estΓ‘ afectada por esta vulnerabilidad.

⚠️ Por qué importa

Esta vulnerabilidad puede permitir a un atacante ejecutar cΓ³digo arbitrario en el contexto de la aplicaciΓ³n, lo que podrΓ­a llevar a una pΓ©rdida de confidencialidad, integridad o disponibilidad de datos. Las organizaciones que utilizan Microsoft Edge o Chromium deben tomar medidas para abordar esta vulnerabilidad lo antes posible.

βš™οΈ CΓ³mo funciona

La vulnerabilidad se produce cuando el cΓ³digo de cΓ³digos de Chromium es capaz de escribir fuera de sus lΓ­mites de memoria, lo que podrΓ­a permitir a un atacante ejecutar cΓ³digo arbitrario en el contexto de la aplicaciΓ³n. Esto puede ocurrir cuando el cΓ³digo de cΓ³digos procesa datos maliciosos, lo que podrΓ­a llevar a una ejecuciΓ³n de cΓ³digo no autorizada.

πŸ‘οΈ QuΓ© vigilar

  • Verificar si se ha aplicado el parche de seguridad disponible para abordar esta vulnerabilidad.
  • Actualizar Microsoft Edge o Chromium a la versiΓ³n mΓ‘s reciente para asegurarse de que se aborde la vulnerabilidad.
  • Realizar una revisiΓ³n de la configuraciΓ³n de seguridad de la aplicaciΓ³n para garantizar que no estΓ©n presentes otras vulnerabilidades similares.

πŸ”— Fuente consultada: MSRC Microsoft


Cibercrimen β€” Ransomware in 2026: Same Business, New Rules

The ransomware economy has been rewired. Meet the eight ransomware groups driving the shift, from affiliate breakaways to AI-assisted attacks based on Group-IB Threat Intelligence.

πŸ”— Fuente consultada: Group-IB


Cibercrimen β€” JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake

An open directory and a SEA of victims reaching as far as LATAM all lead to TriBack Loader.

πŸ”— Fuente consultada: Group-IB


Vulnerabilidad β€” Risks, Vulnerabilities And Response: Threat Intelligence is Quietly Becoming The Connected Layer in Security

Cyberthreat Intelligence is not a feed bolted on the side, it is the operational impetus behind strengthened security. And that change in role has earned the market its first dedicated industry evaluation.

πŸ”— Fuente consultada: Group-IB


Cibercrimen β€” HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels

Group-IB uncovers HOLLOWGRAPH, a Windows malware that abuses Microsoft Graph API to exfiltrate files and receive commands from the attacker using Microsoft 365 calendar events, and DNS tunneling to refresh credentials used in C2 communication.

πŸ”— Fuente consultada: Group-IB


Ciberseguridad β€” ClickLock Stealer: Paste Once, Lose Everything

Analyzing a new threat targeting macOS users in Europe, North America and MEA

πŸ”— Fuente consultada: Group-IB


Cibercrimen β€” Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable

A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL.

Confiant, which detailed the campaign on July 23, 2026, said it has operat

πŸ”— Fuente consultada: The Hacker News


Vulnerabilidad β€” Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available

Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.

Tracked as CVE-2026-16723,

πŸ”— Fuente consultada: The Hacker News


Vulnerabilidad β€” Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git

Security researchers atΒ depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update.

Any authenticated user who can push to a project can run it. Th

πŸ”— Fuente consultada: The Hacker News


Cibercrimen β€” CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking

For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose.

That model is changing.

Recent investigations i

πŸ”— Fuente consultada: The Hacker News


Vulnerabilidad β€” Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE

Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.

"Attackers chain a pre-authentication information disclosure i

πŸ”— Fuente consultada: The Hacker News


Ciberseguridad β€” GitHub, PyPI add time-absed defenses against supply chain attacks

GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. [...]

πŸ”— Fuente consultada: BleepingComputer


Ciberseguridad β€” Steam forum ClickFix attacks infect gamers with XMRig cryptominers

Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. [...]

πŸ”— Fuente consultada: BleepingComputer


Cibercrimen β€” Malicious sites use JavaScript to build malware in browser memory

A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. [...]

πŸ”— Fuente consultada: BleepingComputer

Top comments (0)