Este reporte corresponde a una selección de las últimas noticias, alertas de seguridad, vulnerabilidades, ataques y casos de estudio observados durante las últimas horas. Esta información ha sido recopilada para entregar un panorama general de las amenazas más importantes del momento. El objetivo principal es dar visibilidad rápida sobre los cambios en la tendencia y la evolución del cibercrimen para generar conciencia y estrategias de protección en base a estos riesgos emergentes.
Noticias y Casos de Estudio
- Vice Society: Profiling a Persistent Threat to the Education Sector (paloaltonetworks.com)
- Anatomizing CryptosLabs: a scam syndicate targeting French-speaking Europe for years | Group-IB
- Final defense policy bill chock full of cybersecurity provisions – The Record by Recorded Future
- South Pacific vacations may be wrecked by ransomware • The Register
- UK privacy watchdog reveals more than two dozen data breach incidents – The Record by Recorded Future
- Elon Musk’s Twitter followers targeted in fake crypto giveaway scam (bleepingcomputer.com)
- New Zealand government compromised in third-party cyber attack (cshub.com)
- Is Avast safe to use in 2023? | Kaspersky official blog
- Cyble — Exposed Remote Desktop Protocol actively targeted by Threat Actors to deploy Ransomware
- German Dark Web Drugs Vendor Indicted | Darknetlive
- Flugsvamp 2.0 Admin added to Europe «Most Wanted» list | Darknetlive
- Four Men Arrested In Transnational Wire Fraud And Identity Theft Conspiracy | USAO-MDFL | Department of Justice
- Resecurity – "In The Box" – Mobile Malware Webinjects Marketplace
- 68% of IT leaders are worried about API sprawl – Help Net Security
Ciberataques e Incidentes
- AppleJeus Malware Detection: North Korea-Linked Lazarus APT Spreads Malicious Strains Masquerading as Cryptocurrency Apps – SOC Prime
- Blue Callisto orbits around US Laboratories in 2022 (pwc.com)
- Message from Recorded Future
- Microsoft Alerts Cryptocurrency Industry of Targeted Cyberattacks (thehackernews.com)
- Ransomware attack knocks Rackspace’s Exchange servers offline | Network World
- DEV-0139 launches targeted attacks against the cryptocurrency industry – Microsoft Security Blog
- BackdoorDiplomacy Wields New Tools in Fresh Middle East Campaign (bitdefender.com)
- Russian Actors Use Compromised Healthcare Networks Against Ukrainian Orgs (darkreading.com)
Vulnerabilidades
- PSIRT Advisories | FortiGuard
- Zero Day Initiative — Pwn2Own Toronto 2022 – Day One Results
- Sophos Firewall v19.5 GA Resolves Security Vulnerabilities | Sophos
- CISA adds Google zero-day to exploited vulnerabilities list – The Record by Recorded Future
Malware
- Вайпер CryWiper притворяется шифровальщиком | Securelist
- La Nueva Botnet Basada En Go «Zerobot» Estaría Explotando 21 De Fallas De Seguridad Altas Y Críticas | CronUp Ciberseguridad
Ransomware (nuevas víctimas publicadas)
Fecha de Publicación | Título de la Publicación | Actor de Amenaza |
---|---|---|
2022-12-07 | Albina Asphalt | lorenz |
2022-12-07 | https://afasd.net | royal |
2022-12-07 | Requena | alphv |
2022-12-06 | Feu Vert | vicesociety |
2022-12-06 | PANOLAM | blackbasta |
2022-12-06 | myersontooth.com | lockbit3 |
2022-12-06 | g4s.com | lockbit3 |
2022-12-06 | amundson.co.nz | lockbit3 |
2022-12-06 | INTERSPORT France | hiveleak |
2022-12-06 | Elias Motsoaledi Local Municiapality | alphv |
2022-12-06 | Novak Law Offices | alphv |
2022-12-06 | NCI CABLING INC | alphv |
2022-12-05 | BRYCON Construction | ransomhouse |

Alerta Temprana de Riesgos Cibernéticos (ATRc®)
Attack Surface Management
Cyber Threat Intelligence