Ingeniero de sistemas y seguridad.Gamer en los ratos libres.Quiero compartir con todo sobre el mundo de la tecnología de manera mas fácil de entender y acercarla cada vez mas.

New Supply Chain Attack “SleeperGem” Targets Ruby Developers with Malicious Packages

New Supply Chain Attack “SleeperGem” Targets Ruby Developers with Malicious Packages Overview of the SleeperGem Attack Recently uncovered by cybersecurity researchers, the SleeperGem attack represents a significant threat to developers in the Ruby ecosystem. This software supply chain attack involves the distribution of three malicious RubyGems packages designed to compromise developer machines. Upon installation, these…

UAC-0145 Exploits ClickFix CAPTCHAs in Malicious Campaign Against Ukrainian Targets

UAC-0145 Exploits ClickFix CAPTCHAs in Malicious Campaign Against Ukrainian Targets

UAC-0145 Exploits ClickFix CAPTCHAs in Malicious Campaign Against Ukrainian Targets Background and Context In the evolving landscape of cyber warfare, the conflict between Ukraine and Russia stands as a poignant illustration of how digital threats can intersect with geopolitical tensions. The recent activities of the Russian state-sponsored group known as UAC-0145, a sub-unit of the…

Nueva Vulnerabilidad de OpenSSL: El Fallo HollowByte Plantea un Riesgo Significativo para la Estabilidad del Servidor

Nueva Vulnerabilidad de OpenSSL: El Fallo HollowByte Plantea un Riesgo Significativo para la Estabilidad del Servidor Entendiendo el Fallo HollowByte El recientemente descubierto fallo HollowByte en OpenSSL presenta una amenaza seria para la estabilidad del servidor, afectando particularmente a los sistemas glibc. Esta vulnerabilidad permite a los atacantes explotar la naturaleza liviana de las solicitudes…

New OpenSSL Vulnerability: The HollowByte Flaw Poses Significant Risk to Server Stability

New OpenSSL Vulnerability: The HollowByte Flaw Poses Significant Risk to Server Stability Understanding the HollowByte Flaw The recently discovered HollowByte flaw in OpenSSL presents a serious threat to server stability, particularly affecting glibc systems. This vulnerability allows attackers to exploit the lightweight nature of TLS requests by sending an 11-byte message that leads the OpenSSL…

Nueva Vulnerabilidad Revelada: Los Ataques de Inyección de Datos Pueden Manipular Agentes de IA

Nueva Vulnerabilidad Revelada: Los Ataques de Inyección de Datos Pueden Manipular Agentes de IA Entendiendo la Nueva Amenaza Un informe reciente ha destacado un preocupante tipo de ataque cibernético conocido como inyección de datos, que supone un riesgo significativo para los agentes de IA. Según los hallazgos, los atacantes pueden manipular sistemas de IA introduciendo…