Seguridad en AWS: Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Acc...

La señal de hoy The Hacker News ha publicado Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data (25 de agosto de 2026). The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attac ...

25 de agosto de 2026 · 2 min · David Gómez

Seguridad en AWS: Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active...

La señal de hoy The Hacker News ha publicado Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation (19 de agosto de 2026). The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting A ...

23 de agosto de 2026 · 2 min · David Gómez

Seguridad en AWS: Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

La señal de hoy The Hacker News ha publicado Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution (20 de agosto de 2026). A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution. “A remote code execution ...

22 de agosto de 2026 · 2 min · David Gómez

Seguridad en AWS: Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code...

La señal de hoy The Hacker News ha publicado Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution (21 de agosto de 2026). Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant’s cloud-based identity and access management service. It was previ ...

21 de agosto de 2026 · 2 min · David Gómez