tgindex
SysAdmin 24x7

Noticias y alertas de seguridad informática. Chat y contacto: t.me/sysadmin24x7chat

Последний пост
12 авг.
Последнее чтение
15 авг.
Постов за неделю
2
Всего постов
20
Тип
открытый
Язык
испанский
Категория
Криптовалюты (по похожим)
В каталоге с
13 авг.
Подписчики
4 404
+3 за 2 дн.
Сутки
0
0,00%
Неделя
 
Месяц
 
Просмотров на пост
1 001
20 постов
Вовлечённость
22,7%
к подписчикам
Постов в день
0,3
всего 20
Упоминаний
0
каналов
Охват размещения
оценка
1/24сутки в ленте
314
1/48двое суток
359
1/72трое суток
388

Оценка по просмотрам недавних постов: пост набирает почти всё за первые сутки.

Посты

  • Microsoft - Aug 2026 Security Updates https://msrc.microsoft.com/update-guide/releaseNote/2026-Aug

  • SAP Security Patch Day - August 2026 https://support.sap.com/en/my-support/knowledge-base/security-notes-news/august-2026.html

  • VMSA-2026-0005.1: VMware Avi Load Balancer addresses multiple vulnerabilities (CVE-2026-47865, CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, CVE-2026-47871) Advisory ID: VMSA-2026-0005.1 Advisory Severity: Critical CVSSv3 Range: 7.1 - 9.8 Synopsis: VMware Avi Load Balancer addresses multiple vulnerabilities (CVE-2026-47865, CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, CVE-2026-47871) Issue date: 2026-07-14 Updated on: 2026-08-07 1. Impacted Products VMware Avi Load Balancer 2. Introduction Multiple vulnerabilities in Avi Load Balancer were privately reported to Broadcom. Patches are available to remediate these vulnerabilities in the affected Broadcom product. https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37926

  • Keyv and friends compromised in active Shai-Hulud supply chain attack On August 4, 2026, attackers compromised the GitHub account of the maintainer behind keyv, a key-value storage library with roughly 127 million weekly npm downloads, and used that access to inject a credential-stealing worm across the entire package family. The same maintainer owns cacheable (29M downloads/month), flat-cache (565M downloads/month), file-entry-cache (557M downloads/month), and several other widely-used caching utilities, all of which were swept up in the same attack. https://www.aikido.dev/blog/keyv-and-friends-compromised-in-npm-supply-chain-attack

  • Feliz SysAdminDay a tod@s Día del Administrador de Sistemas Informáticos Viernes 31 de julio de 2026

  • VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) Advisory ID:  VMSA-2026-0006 Advisory Severity: Critical CVSSv3 Range: 2.7-9.8 Synopsis: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) Issue date: 2026-07-29 CVE(s) CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709   Impacted Products VMware ESX VMware vCenter VMware Workstation VMware Fusion VMware Cloud Foundation VMware vSphere Foundation VMware Telco Cloud Platform VMware Telco Cloud Infrastructure  Introduction Multiple vulnerabilities in VMware ESX, vCenter, Workstation, and Fusion were privately reported to Broadcom. Updates are available to remediate these vulnerabilities in affected Broadcom products.  https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/38017

  • 23 июл.1 0542

    Oracle Critical Patch Update Advisory - July 2026 https://www.oracle.com/security-alerts/cpujul2026.html

  • 15 июл.1 4092

    SonicWall SMA1000 Series Appliances Affected By Multiple Vulnerabilities Advisory ID SNWLID-2026-0008 First Published 2026-07-14 Workaround false Status Applicable CVE CVE-2026-15409, CVE-2026-15410 CWE CWE-918, CWE-94 CVSS v3 10.0 https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008

  • 15 июл.1 3773

    CISA Urges SharePoint Hardening After New Exploitations Release DateJuly 14, 2026 CISA is aware of active exploitation of vulnerabilities CVE-2026-32201, CVE-2026-45659, and CVE-2026-56164, enabling cyber threat actors to gain unauthorized access to on-premises SharePoint Server instances. https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-hardening-after-new-exploitations

  • 15 июл.1 0972

    Microsoft - July 2026 Security Updates https://msrc.microsoft.com/update-guide/releaseNote/2026-Jul

  • 9 июл.1 2953

    Neutralización incorrecta de elementos especiales en FortiSandbox de Fortinet Fecha 09/07/2026 Importancia 5 - Crítica Recursos Afectados FortiSandbox 5.0: versiones desde 5.0.0 a 5.0.5; FortiSandbox 4.4: versiones desde 4.4.0 a 4.4.8; FortiSandbox Cloud 5.0: versiones desde 5.0.4 a 5.0.5; FortiSandbox PaaS 5.0: versiones desde 5.0.4 a 5.0.5. Descripción Adham El Karn, del equipo de seguridad de productos de Fortinet, ha reportado una vulnerabilidad de severidad critica que, en caso de ser explotada, podría permitir a un atacante ejecutar código o comandos no autorizados. https://www.incibe.es/incibe-cert/alerta-temprana/avisos/neutralizacion-incorrecta-de-elementos-especiales-en-fortisandbox-de-fortinet

  • 5 июл.1 1092

    Bad Epoll: The bug missed by Mythos https://github.com/J-jaeyoung/bad-epoll

  • 3 июл.1 0811

    [Actualización 02/07/2026] Falsificación de solicitudes del lado del servidor en productos de Cisco Fecha 04/06/2026 Importancia 4 - Alta Recursos Afectados Cisco Unified CM, versión 14, y Unified CM SME, versión 15, si tienen habilitado el servicio WebDialer. Descripción Cisco ha publicado una vulnerabilidad de severidad alta que podría permitir a un atacante remoto, no autenticado, realizar ataques de falsificación de solicitudes del lado del servidor (SSRF) a través de un dispositivo afectado. [Actualización 02/07/2026] El equipo PSIRT de Cisco tiene conocimiento de que existe código de prueba de concepto para explotar la vulnerabilidad descrita en este aviso. Solución Actualizar a las versiones 14SU6 y 15SU5 (septiembre de 2026) o COP 1, respectivamente. https://www.incibe.es/incibe-cert/alerta-temprana/avisos/falsificacion-de-solicitudes-del-lado-del-servidor-en-productos-de-cisco

  • Múltiples vulnerabilidades en NetScaler de Citrix Fecha 03/07/2026 Importancia 4 - Alta Recursos Afectados NetScaler ADC y NetScaler Gateway 14.1 anteriores a 14.1-72.61; NetScaler ADC y NetScaler Gateway 13.1 anteriores a 13.1-63.18; FIPS de NetScaler ADC anteriores a 14.1-72.61 FIPS; Compatibilidad con FIPS y NDcPP de NetScaler ADC anteriores a la versión 13.1-37.272. Descripción Citrix ha publicado 6 vulnerabilidades: 5 de severidad alta y 1 de severidad media que, en caso de ser explotadas, podrían permitir a un atacante leer la memoria, provocar un comportamiento impredecible o una denegación de servicio. Solución Cloud Software Group insta a los clientes afectados a que instalen las versiones actualizadas correspondientes. NetScaler ADC y NetScaler Gateway versiones 14.1-72.61 y posteriores. NetScaler ADC y NetScaler Gateway 13.1-63.18 y versiones posteriores de 13.1. NetScaler ADC 14.1-FIPS 14.1-72.61 FIPS y versiones posteriores de 14.1-FIPS. NetScaler ADC 13.1-FIPS y 13.1-NDcPP 13.1.37.272 y versiones posteriores de 13.1-FIPS y 13.1-NDcPP. https://www.incibe.es/incibe-cert/alerta-temprana/avisos/multiples-vulnerabilidades-en-netscaler-de-citrix

  • SolarWinds Serv-U Unauthenticated Denial of Service Vulnerability (CVE-2026-28318) Summary SolarWinds Serv-U is susceptible to specially crafted POST requests that crash the Serv-U service without authentication using Content-Encoding: deflate. Affected Products SolarWinds Serv-U 15.5.4 and below Fixed Software Release SolarWinds Serv-U 15.5.4 HF1 https://www.solarwinds.com/trust-center/security-advisories/cve-2026-28318

  • 10 июн.1 2411

    CNA: VulnCheck Updated: 2026-06-04 Published: 2026-06-04 Title: WordPress Plugin ad manager wd 1.0.11 Arbitrary File Download Description WordPress Plugin ad manager wd 1.0.11 contains an arbitrary file download vulnerability that allows unauthenticated attackers to download sensitive files by manipulating the path parameter. Attackers can send GET requests to the edit.php endpoint with export=export_csv and a malicious path parameter to read arbitrary files like wp-config.php accessible to the web server. https://www.cve.org/CVERecord?id=CVE-2019-25727

  • 9 июн.1 0821

    Microsoft - June 2026 Security Updates https://msrc.microsoft.com/update-guide/releaseNote/2026-Jun

  • 9 июн.1 1713

    Vulnerability Resolved in Veeam Backup & Replication 12.3.2.4854 KB ID: 4869 Product: Veeam Backup & Replication | 12 | 12.1 | 12.2 | 12.3 | 12.3.1 | 12.3.2 Published: 2026-06-09 CVE-2026-44963 A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user. Severity: Critical https://www.veeam.com/kb4869

  • VMSA-2026-0004: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724) Advisory ID:  VMSA-2026-0004 Advisory Severity: Important CVSSv3 Range: 8.0 Synopsis: VMware Cloud Foundation Operations updates address multiple vulnerabilities (CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724) Issue date: 2026-06-08 CVE(s) CVE-2026-41722, CVE-2026-41723 and CVE-2026-41724 Impacted Products VMware Aria Operations VMware Cloud Foundation Operations VMware Cloud Foundation VMware vSphere Foundation VMware Telco Cloud Platform Introduction Multiple vulnerabilities in VMware Cloud Foundation Operations were privately reported to Broadcom. Patches and updates are available to remediate these vulnerabilities in affected Broadcom products.  https://support.broadcom.com/web/ecx/support-content-notification/-/external/content/SecurityAdvisories/0/37513

  • Desbordamiento de búfer en productos Poly Voice de HP Fecha 02/06/2026 Importancia 5 - Crítica Recursos Afectados HP Poly VVX con versiones anteriores a UCS 6.4.8; HP Poly Trio 8300 con versiones anteriores a UCS 8.1.7; HP Poly Trio 8500 con versiones anteriores UCS 7.2.8; HP Poly Trio 8800 con versiones anteriores a UCS 7.2.8. Descripción Stephen Fewer, de Rapid7, ha reportado una vulnerabilidad de severidad crítica que, en caso de ser explotada, podría permitir a un atacante la ejecución remota de código comprometiendo la confidencialidad, integridad y disponibilidad de los sistemas afectados.  Solución HP recomienda actualizar los dispositivos afectados a las versiones de firmware corregidas publicadas mediante HP Poly Lens. Como medida de mitigación adicional, se recomienda deshabilitar la conectividad ICE (Interactive Connectivity Establishment) cuando no sea necesaria. https://www.incibe.es/incibe-cert/alerta-temprana/avisos/desbordamiento-de-bufer-en-productos-poly-voice-de-hp

SysAdmin 24x7 — tgindex