🤖 Auto-generated daily threat intelligence digest — July 26, 2026
🚨 Alertas de ciberseguridad para tu empresa
Fuentes: BleepingComputer, Group-IB, MSRC Microsoft, The Hacker News
Un día más en el que la ciberdelincuencia se hace presente, con noticias sobre vulnerabilidades en la cadena de suministro que pueden comprometer la seguridad de tus sistemas, y una nueva oleada de ataques de ransomware que amenazan con desestabilizar tu negocio.
Vulnerabilidad — Chromium: CVE-2026-16804 Use after free in Input
🔍 Qué está pasando
- Se ha identificado una vulnerabilidad en Chromium conocida como CVE-2026-16804, que se trata de un "use after free" en Input.
- Esta vulnerabilidad fue asignada por Google Chrome.
- Microsoft Edge (basado en Chromium) ingiere Chromium, lo que significa que también está afectado.
⚠️ Por qué importa
La vulnerabilidad CVE-2026-16804 en Chromium puede permitir a un atacante ejecutar código arbitrario en el sistema de un usuario, lo que puede llevar a una serie de consecuencias negativas, como el robo de datos, la toma del control del sistema o la instalación de malware. Esta vulnerabilidad puede ser explotada por un atacante malintencionado para obtener acceso no autorizado a la información de un usuario o para causar daño al sistema.
⚙️ Cómo funciona
La vulnerabilidad se debe a un "use after free" en el componente Input de Chromium. En resumen, el componente Input no verifica adecuadamente la memoria que se utiliza después de que un objeto se ha eliminado, lo que permite a un atacante acceder a la memoria y realizar acciones maliciosas.
👁️ Qué vigilar
- Parche disponible: Microsoft Edge (basado en Chromium) ya ha incorporado el parche para esta vulnerabilidad.
- Fuente de información: Consulte Google Chrome Releases para obtener más información sobre esta vulnerabilidad y su solución.
- Recomendación: Los usuarios deben asegurarse de que su navegador esté actualizado para evitar cualquier vulnerabilidad.
🔗 Fuentes consultadas (3):
Vulnerabilidad — Chromium: CVE-2026-16807 Out of bounds write in Codecs
🔍 Qué está pasando
- Se identificó una vulnerabilidad en Chromium conocida como CVE-2026-16807, que implica una escritura fuera de límites en el código de códigos.
- Esta vulnerabilidad fue asignada por Chrome.
- Microsoft Edge (basada en Chromium) ingiere Chromium, lo que significa que está afectada por esta vulnerabilidad.
⚠️ Por qué importa
Esta vulnerabilidad puede permitir a un atacante ejecutar código arbitrario en el contexto de la aplicación, lo que podría llevar a una pérdida de confidencialidad, integridad o disponibilidad de datos. Las organizaciones que utilizan Microsoft Edge o Chromium deben tomar medidas para abordar esta vulnerabilidad lo antes posible.
⚙️ Cómo funciona
La vulnerabilidad se produce cuando el código de códigos de Chromium es capaz de escribir fuera de sus límites de memoria, lo que podría permitir a un atacante ejecutar código arbitrario en el contexto de la aplicación. Esto puede ocurrir cuando el código de códigos procesa datos maliciosos, lo que podría llevar a una ejecución de código no autorizada.
👁️ Qué vigilar
- Verificar si se ha aplicado el parche de seguridad disponible para abordar esta vulnerabilidad.
- Actualizar Microsoft Edge o Chromium a la versión más reciente para asegurarse de que se aborde la vulnerabilidad.
- Realizar una revisión de la configuración de seguridad de la aplicación para garantizar que no estén presentes otras vulnerabilidades similares.
🔗 Fuente consultada: MSRC Microsoft
Cibercrimen — Ransomware in 2026: Same Business, New Rules
The ransomware economy has been rewired. Meet the eight ransomware groups driving the shift, from affiliate breakaways to AI-assisted attacks based on Group-IB Threat Intelligence.
🔗 Fuente consultada: Group-IB
Cibercrimen — JadeProx: Tracing a China-nexus Operation Through an OPSEC Mistake
An open directory and a SEA of victims reaching as far as LATAM all lead to TriBack Loader.
🔗 Fuente consultada: Group-IB
Vulnerabilidad — Risks, Vulnerabilities And Response: Threat Intelligence is Quietly Becoming The Connected Layer in Security
Cyberthreat Intelligence is not a feed bolted on the side, it is the operational impetus behind strengthened security. And that change in role has earned the market its first dedicated industry evaluation.
🔗 Fuente consultada: Group-IB
Cibercrimen — HOLLOWGRAPH: Turning Microsoft 365 Calendars into Covert Command-and-Control Channels
Group-IB uncovers HOLLOWGRAPH, a Windows malware that abuses Microsoft Graph API to exfiltrate files and receive commands from the attacker using Microsoft 365 calendar events, and DNS tunneling to refresh credentials used in C2 communication.
🔗 Fuente consultada: Group-IB
Ciberseguridad — ClickLock Stealer: Paste Once, Lose Everything
Analyzing a new threat targeting macOS users in Europe, North America and MEA
🔗 Fuente consultada: Group-IB
Cibercrimen — Malvertising Sends Malware in Pieces, Then Makes the Browser Build the Executable
A malvertising operation dubbed SourTrade is making victims' browsers build the final Windows executable themselves, using a legitimate Bun runtime as its base instead of serving one complete malicious file from a fixed URL.
Confiant, which detailed the campaign on July 23, 2026, said it has operat
🔗 Fuente consultada: The Hacker News
Vulnerabilidad — Fastjson 1.x RCE Vulnerability Targeted in Attacks With No Patched Available
Security firms ThreatBook and Imperva say attackers are targeting a critical flaw in Fastjson, Alibaba's JSON library for Java. In affected Spring Boot applications, a malicious JSON request can execute code without authentication, with the privileges of the Java process.
Tracked as CVE-2026-16723,
🔗 Fuente consultada: The Hacker News
Vulnerabilidad — Researcher Publishes GitLab RCE PoC Letting Authenticated Users Run Commands as Git
Security researchers at depthfirst published working exploit code on July 24 for a GitLab flaw that GitLab patched six weeks earlier, on June 10. It runs commands as git on any self-managed 18.11.3 server that has not taken the update.
Any authenticated user who can push to a project can run it. Th
🔗 Fuente consultada: The Hacker News
Cibercrimen — CTM360 Research Reveals How Insurance Phishing Has Evolved Into Real-Time Account Hijacking
For years, phishing campaigns targeting financial institutions followed the same playbook. Victims were tricked into entering usernames and passwords, attackers collected the credentials, and accounts were compromised later when an opportunity arose.
That model is changing.
Recent investigations i
🔗 Fuente consultada: The Hacker News
Vulnerabilidad — Cl0p Affiliates Target Internet-Exposed PTC Windchill and FlexPLM with Unauthenticated RCE
Threat actors linked to the Cl0p (aka Chubby Scorpius, FIN11, Graceful Spider, and Lace Tempest) ransomware campaign are exploiting flaws in internet-exposed PTC Windmill and FlexPLM deployments as part of a new data extortion campaign.
"Attackers chain a pre-authentication information disclosure i
🔗 Fuente consultada: The Hacker News
Ciberseguridad — GitHub, PyPI add time-absed defenses against supply chain attacks
GitHub and PyPI (Python Package Index) have introduced a time-based mechanism in the Dependabot dependency management tool to protect against supply-chain attacks and to limit their impact. [...]
🔗 Fuente consultada: BleepingComputer
Ciberseguridad — Steam forum ClickFix attacks infect gamers with XMRig cryptominers
Steam discussion forums are being abused in ClickFix attacks that pretend to be fixes for game and computer problems but actually infect devices with cryptominers. [...]
🔗 Fuente consultada: BleepingComputer
Cibercrimen — Malicious sites use JavaScript to build malware in browser memory
A massive malvertising campaign is using fake Solana, Luno, and TradingView webpages with malicious JavaScript that instructs browsers to assemble malware directly in memory. [...]
🔗 Fuente consultada: BleepingComputer
Top comments (0)