Ingeniero de sistemas y seguridad.Gamer en los ratos libres.Quiero compartir con todo sobre el mundo de la tecnología de manera mas fácil de entender y acercarla cada vez mas.
New Supply Chain Attack “SleeperGem” Targets Ruby Developers with Malicious Packages Overview of the SleeperGem Attack Recently uncovered by cybersecurity researchers, the SleeperGem attack represents a significant threat to developers in the Ruby ecosystem. This software supply chain attack involves the distribution of three malicious RubyGems packages designed to compromise developer machines. Upon installation, these…
UAC-0145 Exploits ClickFix CAPTCHAs in Malicious Campaign Against Ukrainian Targets Background and Context In the evolving landscape of cyber warfare, the conflict between Ukraine and Russia stands as a poignant illustration of how digital threats can intersect with geopolitical tensions. The recent activities of the Russian state-sponsored group known as UAC-0145, a sub-unit of the…
Coca-Cola Halts US Fairlife Production Following Ransomware Attack Background and Context The recent decision by Coca-Cola to suspend production of its Fairlife brand in the United States due to a ransomware attack underscores a worrying trend in the corporate world: the increasing vulnerability of major companies to cyber threats. Ransomware attacks, where malicious actors encrypt…
Nueva Vulnerabilidad de OpenSSL: El Fallo HollowByte Plantea un Riesgo Significativo para la Estabilidad del Servidor Entendiendo el Fallo HollowByte El recientemente descubierto fallo HollowByte en OpenSSL presenta una amenaza seria para la estabilidad del servidor, afectando particularmente a los sistemas glibc. Esta vulnerabilidad permite a los atacantes explotar la naturaleza liviana de las solicitudes…
New OpenSSL Vulnerability: The HollowByte Flaw Poses Significant Risk to Server Stability Understanding the HollowByte Flaw The recently discovered HollowByte flaw in OpenSSL presents a serious threat to server stability, particularly affecting glibc systems. This vulnerability allows attackers to exploit the lightweight nature of TLS requests by sending an 11-byte message that leads the OpenSSL…
Unveiling GoSerpent: A New Era of Espionage Malware Targeting Southeast Asia Background and Context Cybersecurity is entering an era marked by increasingly sophisticated attacks, and the emergence of the GoSerpent malware serves as a stark reminder of this reality. Discovered by Kaspersky in February 2026, GoSerpent is a previously undocumented malware variant that has been…
Nueva Vulnerabilidad Revelada: Los Ataques de Inyección de Datos Pueden Manipular Agentes de IA Entendiendo la Nueva Amenaza Un informe reciente ha destacado un preocupante tipo de ataque cibernético conocido como inyección de datos, que supone un riesgo significativo para los agentes de IA. Según los hallazgos, los atacantes pueden manipular sistemas de IA introduciendo…
New Vulnerability Unveiled: Data Injection Attacks can Manipulate AI Agents Understanding the New Threat A recent report has highlighted a troubling type of cyber attack known as data injection, which poses a significant risk to AI agents. According to findings, attackers can manipulate AI systems by introducing false data, leading these agents to make erroneous…
Sentencing of Scattered Spider Hackers Highlights Ongoing Cybersecurity Challenges Background and Context The recent sentencing of Owen Flowers, 18, and Thalha Jubair, 20, to five and a half years in prison for their role in the 2024 cyberattack against Transport for London (TfL) underscores the escalating risks organizations face from cybercriminals. This attack led to…
Evolución de TuxBot v3: La Intersección del Desarrollo de Botnets de IA y IoT Introducción a la Evolución de TuxBot v3 Investigadores en ciberseguridad han revelado la aparición de un nuevo marco de botnet de Internet de las Cosas (IoT) conocido como Evolución de TuxBot v3. Este desarrollo marca un hito significativo en la continua…