blog

AI and cybersecurity insights crafted by leading experts shaping the future of digital trust.

CISA advierte sobre vulnerabilidad crítica en switches de red utilizados en infraestructuras críticas

Vulnerabilities

CISA advierte sobre vulnerabilidad crítica en switches de red utilizados en infraestructuras críticas

3 Oct 2024

All

Malware Infostealer actualiza sus técnicas para eludir la nueva protección de Google Chrome

3 Oct 2024

NIST Lanza los Primeros Estándares de Cifrado para Resistir la Computación Cuántica

All

NIST Lanza los Primeros Estándares de Cifrado para Resistir la Computación Cuántica

2 Oct 2024

NoName Refuerza Su Arsenal con el Malware RansomHub: Una Amenaza Creciente para PYMES

All

El Ransomware Embargo Escala sus Ataques a Entornos en la Nube

30 Sep 2024

EL FALLO FUE DESCUBIERTO POR LA FIRMA DE SEGURIDAD EN LA NUBE WIZ, QUE INFORMÓ A NVIDIA EL 1 DE SEPTIEMBRE DE 2024. EN UN ESCENARIO HIPOTÉTICO DE ATAQUE, UN ACTOR MALICIOSO PODRÍA CREAR UNA IMAGEN DE CONTENEDOR MALICIOSA QUE, AL EJECUTARSE EN LA PLATAFORMA OBJETIVO, LE OTORGARÍA ACCESO COMPLETO AL SISTEMA DE ARCHIVOS DEL HOST. ESTO PODRÍA MATERIALIZARSE EN UN ATAQUE A LA CADENA DE SUMINISTRO, DONDE LA VÍCTIMA ES ENGAÑADA PARA EJECUTAR UNA IMAGEN MALICIOSA, O MEDIANTE SERVICIOS QUE COMPARTEN RECURSOS DE GPU. UNA VEZ QUE EL ATACANTE OBTIENE ACCESO AL HOST, PODRÍA ALCANZAR LOS SOCKETS UNIX DEL CONTAINER RUNTIME (DOCKER.SOCK/CONTAINERD.SOCK), LO QUE LE PERMITIRÍA EJECUTAR COMANDOS ARBITRARIOS CON PRIVILEGIOS DE ROOT, TOMANDO CONTROL TOTAL DE LA MÁQUINA.

Vulnerabilities

Vulnerabilidad Crítica en NVIDIA Container Toolkit Podría Otorgar Acceso Completo al Host a Atacantes

30 Sep 2024

Paquete de PyPI Comprometido para Propagar Malware Nova Sentinel

All

Malware PondRAT Infecta Paquetes de Python Dirigidos a Desarrolladores de Software

30 Sep 2024

ready to take your business to the next level?

Get in touch today and receive a complimentary consultation.