Ingeniero de sistemas y seguridad.Gamer en los ratos libres.Quiero compartir con todo sobre el mundo de la tecnología de manera mas fácil de entender y acercarla cada vez mas.
The Evolution of Account Takeover: Verification Steps and the Rise of Passkeys in 2026 The Changing Landscape of Account Takeover (ATO) Account takeover (ATO) has long been a persistent issue for both users and organizations. Traditionally, attackers would utilize credential stuffing, leveraging bulk buying of stolen login information from data breaches. Automation tools made it…
Unpatched Backdoor in Tenda Firmware Exposes Devices to Unauthenticated Access Background and Context The discovery of a serious vulnerability in Tenda firmware, tracked as CVE-2026-11405, has raised alarm bells within the cybersecurity community. This unpatched backdoor allows unauthenticated attackers to gain access to the web management interface of affected devices, effectively granting them full administrative…
Cómo los ID de dispositivos de Windows son clave para rastrear a los cibercriminales: El caso de Peter Stokes Introducción al caso En un desarrollo significativo en el ámbito de las investigaciones sobre cibercrimen, los fiscales estadounidenses han utilizado un ID de dispositivo de Windows persistente para conectar al joven de 19 años Peter Stokes…
How Windows Device IDs Are Key in Tracing Cybercriminals: The Case of Peter Stokes Introduction to the Case In a significant development in the realm of cybercrime investigations, U.S. prosecutors have leveraged a persistent Windows device ID to connect 19-year-old Peter Stokes to a high-profile hack of a luxury jewelry retailer. This incident, which occurred…
Critical Vulnerability in Writer AI: The Threat of Cross-Tenant Compromise Background and Context In a world increasingly shaped by artificial intelligence, the security of generative AI platforms is of paramount importance. Recently, cybersecurity researchers uncovered a critical session isolation vulnerability in Writer, an enterprise generative AI platform, which has been codenamed **WriteOut**. This vulnerability allows…
Resumen Semanal de Ciberseguridad: Desglosando Botnets Proxy, Ransomware de Navegador y los Desafíos de la Confianza en la Tecnología Botnets Proxy: Una Amenaza Creciente Esta semana se destacó la creciente amenaza que representan los botnets proxy, que se han utilizado cada vez más para enmascarar actividades maliciosas. Estos botnets aprovechan dispositivos comprometidos para enrutar tráfico,…
Weekly Cybersecurity Recap: Unpacking Proxy Botnets, Browser Ransomware, and the Challenges of Trust in Technology Proxy Botnets: A Growing Threat This week highlighted the escalating threat posed by proxy botnets, which have increasingly been utilized to mask malicious activities. These botnets leverage compromised devices to route traffic, making it challenging for cybersecurity professionals to track…
New TrojPix Attack: A Novel Threat to Air-Gapped Systems via Video Cable Emissions Background and Context In an age where cybersecurity is paramount, researchers at Shandong University have unveiled a groundbreaking technique that poses substantial risks even to systems traditionally deemed secure—those that are air-gapped. The TrojPix attack exploits the unintentional emissions from video cables…
Grave vulnerabilidad de seguridad en Opera GX expuso a los usuarios al robo de datos a través de complementos maliciosos Introducción a la vulnerabilidad de Opera GX Opera GX, un navegador web centrado en los juegos desarrollado por Opera Software, recientemente fue objeto de escrutinio debido a una vulnerabilidad de seguridad crítica. Este fallo permitió…
Serious Security Flaw in Opera GX Exposed Users to Data Theft via Malicious Add-ons Introduction to the Opera GX Vulnerability Opera GX, a gaming-centric web browser developed by Opera Software, recently came under scrutiny due to a critical security vulnerability. This flaw allowed malicious websites to automatically install browser extensions, compromising user data without any…