James Luther

Solidaridad
James Luther
Incidente de Seguridad en Notificaciones Push de ASOS

Noticias

Brecha en Notificaciones Push de ASOS: Xuanye Group Secuestra el Canal de Mensajería Móvil

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: ASOS.com (Comercio Electrónico de Moda Global) Threat Actor / Attribution: Xuanye Group (Grupo de Extorsión Cibernética) Impact / Records Compromised: Nombres de clientes, correos electrónicos, teléfonos, direcciones de entrega, historial de búsquedas

By James Luther
Brecha de Datos Médicos en Photon Health

Noticias

Filtración en Photon Health: Zero-Day de Inyección SQL en Metabase Expone Recetas Médicas de Pacientes

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🏛️Incident Overview: Target / Organization: Photon Health, Inc. (Plataforma de Prescripción Médica Digital) Threat Actor / Attribution: Actor Desconocido (Extorsión Financiera) Impact / Records Compromised: Nombres de pacientes, direcciones, números de teléfono, fechas de nacimiento, recetas médicas completas

By James Luther
Vulnerabilidades Críticas en Apache HTTP Server 2.4.69

Noticias

Boletín de Seguridad en Apache HTTP Server: Vulnerabilidades Críticas de RCE y Desincronización en 2.4.68

📌Security Roundup Series: Semana del 9 de Octubre de 2026 • 4 min read deep dive🛡️Vulnerability Intelligence: CVE ID: CVE-2026-42356 & CVE-2026-42528 (CWE-444 (Interpretación Inconsistente de Peticiones HTTP) / CWE-120 (Desbordamiento de Búfer)) Severity: ALTA / CRÍTICA (CVSS 8.8 / 7.5) Status: Publicación Oficial de Seguridad el 9 de Octubre de

By James Luther
ColibriSec Weekly Security Roundup October 2 2026

News

Security Roundup: Fortinet FortiMail Zero-Day, Cisco SD-WAN KEV, Agentic AI DIVD Breach, KillSec Takedown (Week of October 2, 2026)

Executive Summary: The week of September 26 to October 2, 2026, marked a watershed moment in cybersecurity, defined by the real-world operationalization of autonomous agentic AI exploit chains, critical zero-days across foundational edge appliances, and historic international law enforcement takedowns. Federal authorities added active zero-days in Fortinet FortiMail (CVE-2026-104286) and

By James Luther