π€ Auto-generated daily threat intelligence digest β July 26, 2026
π¨ Alertas de ciberseguridad para tu empresa
Fuentes: BleepingComputer, Group-IB, MSRC Microsoft, The Hacker News
Un dΓa mΓ‘s en el que la ciberdelincuencia se hace presente, con noticias sobre vulnerabilidades en la cadena de suministro que pueden comprometer la seguridad de tus sistemas, y una nueva oleada de ataques de ransomware que amenazan con desestabilizar tu negocio.
Vulnerabilidad β Chromium: CVE-2026-16804 Use after free in Input
π QuΓ© estΓ‘ pasando
- Se ha identificado una vulnerabilidad en Chromium conocida como CVE-2026-16804, que se trata de un "use after free" en Input.
- Esta vulnerabilidad fue asignada por Google Chrome.
- Microsoft Edge (basado en Chromium) ingiere Chromium, lo que significa que tambiΓ©n estΓ‘ afectado.
β οΈ Por quΓ© importa
La vulnerabilidad CVE-2026-16804 en Chromium puede permitir a un atacante ejecutar cΓ³digo arbitrario en el sistema de un usuario, lo que puede llevar a una serie de consecuencias negativas, como el robo de datos, la toma del control del sistema o la instalaciΓ³n de malware. Esta vulnerabilidad puede ser explotada por un atacante malintencionado para obtener acceso no autorizado a la informaciΓ³n de un usuario o para causar daΓ±o al sistema.
βοΈ CΓ³mo funciona
La vulnerabilidad se debe a un "use after free" en el componente Input de Chromium. En resumen, el componente Input no verifica adecuadamente la memoria que se utiliza despuΓ©s de que un objeto se ha eliminado, lo que permite a un atacante acceder a la memoria y realizar acciones maliciosas.
ποΈ QuΓ© vigilar
- Parche disponible: Microsoft Edge (basado en Chromium) ya ha incorporado el parche para esta vulnerabilidad.
- Fuente de informaciΓ³n: Consulte Google Chrome Releases para obtener mΓ‘s informaciΓ³n sobre esta vulnerabilidad y su soluciΓ³n.
- RecomendaciΓ³n: Los usuarios deben asegurarse de que su navegador estΓ© actualizado para evitar cualquier vulnerabilidad.
π Fuentes consultadas (3):
Vulnerabilidad β Chromium: CVE-2026-16807 Out of bounds write in Codecs
π QuΓ© estΓ‘ pasando
- Se identificΓ³ una vulnerabilidad en Chromium conocida como CVE-2026-16807, que implica una escritura fuera de lΓmites en el cΓ³digo de cΓ³digos.
- Esta vulnerabilidad fue asignada por Chrome.
- Microsoft Edge (basada en Chromium) ingiere Chromium, lo que significa que estΓ‘ afectada por esta vulnerabilidad.
β οΈ Por quΓ© importa
Esta vulnerabilidad puede permitir a un atacante ejecutar cΓ³digo arbitrario en el contexto de la aplicaciΓ³n, lo que podrΓa llevar a una pΓ©rdida de confidencialidad, integridad o disponibilidad de datos. Las organizaciones que utilizan Microsoft Edge o Chromium deben tomar medidas para abordar esta vulnerabilidad lo antes posible.
βοΈ CΓ³mo funciona
La vulnerabilidad se produce cuando el cΓ³digo de cΓ³digos de Chromium es capaz de escribir fuera de sus lΓmites de memoria, lo que podrΓa permitir a un atacante ejecutar cΓ³digo arbitrario en el contexto de la aplicaciΓ³n. Esto puede ocurrir cuando el cΓ³digo de cΓ³digos procesa datos maliciosos, lo que podrΓa llevar a una ejecuciΓ³n de cΓ³digo no autorizada.
ποΈ QuΓ© vigilar
- Verificar si se ha aplicado el parche de seguridad disponible para abordar esta vulnerabilidad.
- Actualizar Microsoft Edge o Chromium a la versiΓ³n mΓ‘s reciente para asegurarse de que se aborde la vulnerabilidad.
- Realizar una revisiΓ³n de la configuraciΓ³n de seguridad de la aplicaciΓ³n para garantizar que no estΓ©n presentes otras vulnerabilidades similares.
π Fuente consultada: MSRC Microsoft
Cibercrimen β Ransomware in 2026: Same Business, New Rules
The ransomware economy has been rewired. Meet the eight ransomware groups driving the shift, from affiliate breakaways to AI-assisted attacks based on Group-IB Threat Intelligence.
π Fuente consultada: Group-IB
Cibercrimen β JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
An open directory and a SEA of victims reaching as far as LATAM all lead to TriBack Loader.
π Fuente consultada: Group-IB
Vulnerabilidad β Risks, Vulnerabilities And Response: Threat Intelligence is Quietly Becoming The Connected Layer in Security
Cyberthreat Intelligence is not a feed bolted on the side, it is the operational impetus behind strengthened security. And that change in role has earned the market its first dedicated industry evaluation.
π Fuente consultada: Group-IB
Cibercrimen β HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
Group-IB uncovers HOLLOWGRAPH, a Windows malware that abuses Microsoft Graph API to exfiltrate files and receive commands from the attacker using Microsoft 365 calendar events, and DNS tunneling to refresh credentials used in C2 communication.
π Fuente consultada: Group-IB
Ciberseguridad β ClickLock Stealer: Paste Once, Lose Everything
Analyzing a new threat targeting macOS users in Europe, North America and MEA
π Fuente consultada: Group-IB
Cibercrimen β Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL.
Confiant, which detailed the campaign on July 23, 2026, said it has operat
π Fuente consultada: The Hacker News
Vulnerabilidad β Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.
Tracked as CVE-2026-16723,
π Fuente consultada: The Hacker News
Vulnerabilidad β Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Security researchers atΒ depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update.
Any authenticated user who can push to a project can run it. Th
π Fuente consultada: The Hacker News
Cibercrimen β CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose.
That model is changing.
Recent investigations i
π Fuente consultada: The Hacker News
Vulnerabilidad β Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.
"Attackers chain a pre-authentication information disclosure i
π Fuente consultada: The Hacker News
Ciberseguridad β GitHub, PyPI add time-absed defenses against supply chain attacks
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. [...]
π Fuente consultada: BleepingComputer
Ciberseguridad β Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. [...]
π Fuente consultada: BleepingComputer
Cibercrimen β Malicious sites use JavaScript to build malware in browser memory
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. [...]
π Fuente consultada: BleepingComputer
Top comments (0)