Esta web funciona sin JavaScript en gran parte del contenido, pero algunas funciones opcionales como mapas, métricas o gestión avanzada del consentimiento pueden no estar disponibles.

Alertes et avis

Dernières alertes d'organismes officiels et de sources vérifiées sur les fraudes, la cybersécurité et les risques émergents.

Abonnez-vous au flux Scam Alert

Recevez toutes les fiches de fraude et nouveautés dans votre lecteur RSS, sans algorithme ni publicité.

https://scam-alert.org/fr/rss.xml

Compatible avec Feedly, Inoreader, NetNewsWire, Reeder et tout lecteur RSS.

Ouvrir dans le lecteur RSS

Qu'est-ce que RSS ?

Standard ouvert pour recevoir les mises à jour de sites dans une application, sans créer de compte ni voir de publicité.

Dernières alertes

Mis à jour le 20 avril 2026 à 04:56
🔐 Cybersécurité The Hacker News

Vercel Breach Tied to Context AI Hack Exposes Limited Customer Credentials

Web infrastructure provider Vercel has disclosed a security breach that allows bad actors to gain unauthorized access to "certain" internal Vercel systems. The incident stemmed from the compromise of Context.ai, a third-party artificial intelligence (AI) tool, that was used by an employee at the company. "The attacker

Lire la suite →
🎯 Threat intel SANS Internet Storm Center

ISC Stormcast For Monday, April 20th, 2026 https://isc.sans.edu/podcastdetail/9898, (Mon, Apr 20th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Lire la suite →
📰 Presse Escudo Digital

Merz decide el martes si entierra el FCAS: España pierde 700 millones si cae

Los mediadores francoalemanes no han logrado acuerdo entre Dassault y Airbus, según ‘Handelsblatt’. El canciller alemán se reunirá con Macron el jueves en Chipre y antes de esa cita debe resolver si mantiene a Berlín dentro del mayor programa militar europeo del siglo.

Lire la suite →
🔐 Cybersécurité BleepingComputer

Vercel confirms breach as hackers claim to be selling stolen data

Cloud development platform Vercel has disclosed a security incident after threat actors claimed to have breached its systems and are attempting to sell stolen data. [...]

Lire la suite →
🔐 Cybersécurité BleepingComputer

Apple account change alerts abused to send phishing emails

Apple account change notifications are being abused to send fake iPhone purchase phishing scams within legitimate emails sent from Apple's servers, increasing legitimacy and potentially allowing them to bypass spam filters. [...]

Lire la suite →
🔐 Cybersécurité BleepingComputer

NIST to stop rating non-priority flaws due to volume increase

The National Institute of Standards and Technology will stop assigning severity scores to lower-priority vulnerabilities due to the growing workload from rising submission volumes. [...]

Lire la suite →
📰 Presse Escudo Digital

Axiomático: el presidente Sánchez lo sabe

El liderazgo implica control y responsabilidad. En el caso de Sánchez, su perfil autocrático hace axiomático que conociera lo que ocurría bajo su mando.

Lire la suite →
📰 Presse Escudo Digital

El móvil que no suena, pero crees oír: el síndrome de la hiperconexión digital

Las notificaciones fantasma son señales de una vida conectada en exceso.

Lire la suite →
📰 Presse Escudo Digital

El organismo oficial de EE.UU. que clasifica las vulnerabilidades de ciberseguridad no da a basto

El Instituto Nacional de Estándares y Tecnología (NIST) seguirá añadiendo CVE, pero ha comunicado que únicamente actualizará los detalles de aquellas fallas que cumplan ciertos criterios.

Lire la suite →
📰 Presse Escudo Digital

Ni F-16 ni cazas pesados: por qué Ucrania apuesta por el Gripen sueco

En un mensaje difundido en redes sociales, Zelenski ha expresado que, "tenemos mucha cooperación con Suecia y estamos listos para expandir nuestra fuerza aérea gracias al Gripen".

Lire la suite →
🔐 Cybersécurité BleepingComputer

Critical flaw in Protobuf library enables JavaScript code execution

Proof-of-concept exploit code has been published for a critical remote code execution flaw in protobuf.js, a widely used JavaScript implementation of Google's Protocol Buffers. [...]

Lire la suite →
🔐 Cybersécurité BleepingComputer

Microsoft Teams right-click paste broken by Edge update bug

Microsoft is warning that a recent Microsoft Edge browser update introduced a bug that breaks right-click paste in chats in the Microsoft Teams desktop client. [...]

Lire la suite →
🔐 Cybersécurité The Hacker News

[Webinar] Eliminate Ghost Identities Before They Expose Your Enterprise Data

In 2024, compromised service accounts and forgotten API keys were behind 68% of cloud breaches. Not phishing. Not weak passwords. Unmanaged non-human identities that nobody was watching. For every employee in your org, there are 40 to 50 automated credentials: service accounts, API tokens, AI agent connections, and OAu

Lire la suite →
🔐 Cybersécurité The Hacker News

$13.74M Hack Shuts Down Sanctioned Grinex Exchange After Intelligence Claims

Grinex, a Kyrgyzstan-incorporated cryptocurrency exchange sanctioned by the U.K. and the U.S. last year, said it's suspending operations after it blamed Western intelligence agencies for a $13.74 million hack. The exchange said it fell victim to what it described as a large-scale cyber attack that bore hallmarks of for

Lire la suite →
🔐 Cybersécurité The Hacker News

Mirai Variant Nexcorium Exploits CVE-2024-3721 to Hijack TBK DVRs for DDoS Botnet

Threat actors are exploiting security flaws in TBK DVR and end‑of‑life (EoL) TP-Link Wi-Fi routers to deploy Mirai-botnet variants on compromised devices, according to findings from Fortinet FortiGuard Labs and Palo Alto Networks Unit 42. The attack targeting TBK DVR devices has been found to exploit CVE-2024-3721 (CVS

Lire la suite →
🔐 Cybersécurité Dark Reading

How NIST's Cutback of CVE Handling Impacts Cyber Teams

Industry and ad hoc coalitions appear poised to help fill the gap created by NIST's decision to cut back on CVE data enrichment.

Lire la suite →
🔐 Cybersécurité Dark Reading

Tycoon 2FA Phishers Scatter, Adopt Device Code Phishing

In embracing device code phishing, attackers trick victims into handing over account access by using a service's legitimate new-device login flow.

Lire la suite →
🔐 Cybersécurité The Record

Ransomware attack continues to disrupt healthcare in London nearly two years later

More than 18 months after a ransomware attack disrupted care at hospitals in South East London, documents show at least one NHS trust is still working without fully restored systems and managing large backlogs of delayed test results.

Lire la suite →
🔐 Cybersécurité The Record

Four arrested in latest ‘PowerOFF’ DDoS-for-hire takedown

More than 20 countries participated in a coordinated takedown of platforms selling cheap access to distributed denial-of-service (DDoS) attacks.

Lire la suite →
🔐 Cybersécurité Dark Reading

Every Old Vulnerability Is Now an AI Vulnerability

AI's danger isn't that it's creating new bugs, it's that it's amplifying old ones.

Lire la suite →
🔐 Cybersécurité The Record

Ukraine confirms suspected APT28 campaign targeting prosecutors, anti-corruption agencies

The intrusions exploited vulnerabilities in the open-source Roundcube webmail platform that allow attackers to execute malicious code when a victim simply opens an email in their inbox.

Lire la suite →
🔐 Cybersécurité The Hacker News

Three Microsoft Defender Zero-Days Actively Exploited; Two Still Unpatched

Huntress is warning that threat actors are exploiting three recently disclosed security flaws in Microsoft Defender to gain elevated privileges in compromised systems. The activity involves the exploitation of three vulnerabilities that are codenamed BlueHammer (requires GitHub sign-in), RedSun, and UnDefend, all of wh

Lire la suite →
🔐 Cybersécurité The Record

In defeat for Trump, House extends electronic spying program for just 10 days

The House passed stopgap legislation to extend a warrantless government surveillance power for 10 days, following a failed lobbying campaign by the Trump administration.

Lire la suite →
🔐 Cybersécurité Dark Reading

Coast Guard's New Cybersecurity Rules Offers Lessons for CISOs

The Maritime Transportation Security Act (MTSA) requires plans to protect OT systems, audits by independent third parties, and a hybrid OT-security role.

Lire la suite →
🎯 Threat intel SANS Internet Storm Center

ISC Stormcast For Friday, April 17th, 2026 https://isc.sans.edu/podcastdetail/9896, (Fri, Apr 17th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Lire la suite →
🎯 Threat intel SANS Internet Storm Center

Lumma Stealer infection with Sectop RAT (ArechClient2), (Fri, Apr 17th)

Introduction

Lire la suite →
🔐 Cybersécurité Dark Reading

NIST Revamps CVE Framework to Focus on High-Impact Vulnerabilities

The National Institute of Standards and Technology carved a new path for vulnerability remediation by changing the way it prioritizes software flaws.

Lire la suite →
🎯 Threat intel SANS Internet Storm Center

[Guest Diary] Compromised DVRs and Finding Them in the Wild, (Thu, Apr 16th)

[This is a Guest Diary by Alec Jaffe, an ISC intern as part of the SANS.edu Bachelor&&#x23&#x3b;39&#x3b;s Degree in Applied Cybersecurity (BACS) program [1].

Lire la suite →
🔐 Cybersécurité The Record

New Jersey men given lengthy sentences for running North Korean laptop farms

The DOJ said Kejia Wang, 42, was sentenced to nine years in prison and Zhenxing Wang, 39, was given a nearly eight-year sentence for an operation that generated more than $5 million for the government of North Korea.

Lire la suite →
🏛️ Organismes officiels INCIBE-CERT Avisos

Crosss-Site Scripting en la integración de jQuery de Drupal

Crosss-Site Scripting en la integración de jQuery de Drupal Jue, 16/04/2026 - 14:05 Aviso Recursos Afectados Drupal core en las versiones comprendidas entre : 8.0.0 y 10.5.9, esta última sin incluir; 10.6.0 y 10.6.7, esta última sin incluir; 11.0.0 y 11.2.11, esta última sin incluir; 11.3.0 y 11.3.7, esta última sin in

Lire la suite →
🏛️ Organismes officiels INCIBE-CERT Avisos

Múltiples vulnerabilidades en varios productos de Cisco

Múltiples vulnerabilidades en varios productos de Cisco Jue, 16/04/2026 - 10:05 Aviso Recursos Afectados Cisco Webex Services, basados en la nube y que hayan sido configurados para emplear integración SSO con Control Hub. Cisco Identity Services Engine (ISE) y Cisco ISE Passive Identity Connector (ISE-PIC), independien

Lire la suite →
⚠️ Fraude Fraud of the Day

Retirement Checks After Death

A Michigan resident has been sentenced for defrauding a public pension system by unlawfully collecting retirement benefits after the death of a family member, prosecutors announced. According to the Michigan Attorney General’s Office, the defendant concealed the pension recipient’s death for years, allowing monthly ben

Lire la suite →
🎯 Threat intel SANS Internet Storm Center

ISC Stormcast For Thursday, April 16th, 2026 https://isc.sans.edu/podcastdetail/9894, (Thu, Apr 16th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Lire la suite →
🏛️ Organismes officiels INCIBE-CERT Avisos

Actualizaciones de seguridad de Microsoft de abril de 2026

Actualizaciones de seguridad de Microsoft de abril de 2026 Mié, 15/04/2026 - 23:00 Aviso Recursos Afectados .NET .NET Framework .NET and Visual Studio .NET, .NET Framework, Visual Studio Applocker Filter Driver (applockerfltr.sys) Azure Logic Apps Azure Monitor Agent Desktop Window Manager Function Discovery Service (f

Lire la suite →
🎯 Threat intel Securelist

Threat landscape for industrial automation systems in Q4 2025

The report contains industrial threat statistics for Q4 2025. It covers various infection vectors and malware types, as well as regional statistics and statistics by industry.

Lire la suite →
🏛️ Organismes officiels INCIBE-CERT Avisos

Múltiples vulnerabilidades en Identity Exposure de Tenable

Múltiples vulnerabilidades en Identity Exposure de Tenable Mié, 15/04/2026 - 10:02 Aviso Recursos Afectados Tenable Identity Exposure, versión 3.77.16 y anteriores. Descripción Tenable ha publicado un aviso donde informa de 19 vulnerabilidades, 1 de severidad crítica, 10 altas, 6 medias y 3 bajas. En caso de ser explot

Lire la suite →
🏛️ Organismes officiels INCIBE-CERT Avisos

Múltiples vulnerabilidades en FortiSandbox

Múltiples vulnerabilidades en FortiSandbox Mié, 15/04/2026 - 09:43 Aviso Recursos Afectados FortiSandbox 4.4, desde la versión 4.4.0 hasta la 4.4.8. Solo para la vulnerabilidad CVE-2026-39813 también se ve afectado: FortiSandbox 5.0, desde la versión 5.0.0 hasta la 5.0.5. Descripción Samuel de Lucas Maroto de KPMG Spai

Lire la suite →
🔐 Cybersécurité Krebs on Security

Patch Tuesday, April 2026 Edition

Microsoft today pushed software updates to fix a staggering 167 security vulnerabilities in its Windows operating systems and related software, including a SharePoint Server zero-day and a publicly disclosed weakness in Windows Defender dubbed "BlueHammer." Separately, Google Chrome fixed its fourth zero-day of 2026, a

Lire la suite →
⚠️ Fraude Fraud of the Day

Coding for Cash

An Oklahoma-based medical clinic owner has been charged for allegedly orchestrating a Medicare fraud scheme that prosecutors say generated millions of dollars in improper reimbursements by exploiting billing codes rather than providing legitimate care. According to the U.S. Attorney’s Office for the Northern District o

Lire la suite →
🎯 Threat intel Securelist

JanelaRAT: a financial threat targeting users in Latin America

Kaspersky GReAT experts describe the latest JanelaRAT campaign detailing infection chain and malware functionality updates.

Lire la suite →
🎯 Threat intel Securelist

The long road to your crypto: ClipBanker and its marathon infection chain

Threat actors are distributing a Trojan disguised as Proxifier software; through a multi-stage infection chain, it delivers ClipBanker – malware that replaces cryptocurrency wallet addresses in the clipboard.

Lire la suite →
⚠️ Fraude Fraud of the Day

Benefits Built on False Households

Pennsylvania authorities have charged multiple individuals in a Supplemental Nutrition Assistance Program (SNAP) fraud scheme that used falsified household information and identity manipulation to obtain benefits for ineligible recipients. According to the Pennsylvania Attorney General’s Office and the U.S. Department

Lire la suite →
🎯 Threat intel Securelist

Financial cyberthreats in 2025 and the outlook for 2026

In this report, Kaspersky experts share their insights into the 2025 financial threat landscape, including regional statistics and trends in phishing, PC malware, and infostealers.

Lire la suite →
🔐 Cybersécurité Krebs on Security

Russia Hacked Routers to Steal Microsoft Office Tokens

Hackers linked to Russia's military intelligence units are using known flaws in older Internet routers to mass harvest authentication tokens from Microsoft Office users, security experts warned today. The spying campaign allowed state-backed Russian hackers to quietly siphon authentication tokens from users on more tha

Lire la suite →
⚠️ Fraude Fraud of the Day

Refunds Routed the Wrong Way

Arizona officials have uncovered a large‑scale income tax fraud scheme that leveraged stolen identities, falsified employment records, and sophisticated digital filing tactics to divert millions in fraudulent refunds. According to the Arizona Department of Revenue (ADOR) and the IRS Criminal Investigation Division (IRS

Lire la suite →
🔐 Cybersécurité Krebs on Security

Germany Doxes “UNKN,” Head of RU Ransomware Gangs REvil, GandCrab

An elusive hacker who went by the handle "UNKN" and ran the early Russian ransomware groups GandCrab and REvil now has a name and a face. Authorities in Germany say 31-year-old Russian Daniil Maksimovich Shchukin headed both cybercrime gangs and helped carry out at least 130 acts of computer sabotage and extortion agai

Lire la suite →
⚠️ Fraude Fraud of the Day

Billing for Care That Never Happened

A Texas healthcare provider has agreed to a multimillion‑dollar settlement following allegations that it submitted fraudulent claims to Medicaid for services that were never rendered. According to the Texas Office of the Attorney General and the U.S. Department of Health and Human Services Office of Inspector General (

Lire la suite →
🎯 Threat intel Securelist

A laughing RAT: CrystalX combines spyware, stealer, and prankware features

Kaspersky researchers analyze a new CrystalX RAT distributed as MaaS and featuring extensive spyware, stealer, and prankware capabilities.

Lire la suite →
🔐 Cybersécurité Krebs on Security

‘CanisterWorm’ Springs Wiper Attack Targeting Iran

A financially motivated data theft and extortion group is attempting to inject itself into the Iran war, unleashing a worm that spreads through poorly secured cloud services and wipes data on infected systems that use Iran's time zone or have Farsi set as the default language.

Lire la suite →
🔐 Cybersécurité Krebs on Security

Feds Disrupt IoT Botnets Behind Huge DDoS Attacks

The U.S. Justice Department joined authorities in Canada and Germany in dismantling the online infrastructure behind four highly disruptive botnets that compromised more than three million hacked Internet of Things (IoT) devices, such as routers and web cameras. The feds say the four botnets -- named Aisuru, Kimwolf, J

Lire la suite →

Sources surveillées

Sources RSS externes dont le portail agrège les informations :

🏛️ Organismes officiels

  • INCIBE-CERT Avisos Active

    Avisos y alertas tempranas de INCIBE-CERT sobre vulnerabilidades, incidentes y riesgos relevantes.

  • INCIBE-CERT Vulnerabilidades Active

    Repositorio de vulnerabilidades y publicaciones coordinadas por INCIBE-CERT.

  • Europol Active

    Organismo supranacional relevante para operaciones y comunicados sobre fraude y cibercrimen en Europa.

    EN Unión Europea Voir la source →

⚠️ Fraude

  • Fraud of the Day En intégration

    Publicación especializada en esquemas de fraude, investigación y respuesta institucional.

    EN Internacional Voir la source →
  • Fraud Intelligence / Counter Fraud En intégration

    Análisis de fraude corporativo, compliance y prevención.

    EN Internacional Voir la source →
  • Sequence Inc En intégration

    Comentarios y análisis especializados sobre fraude, escándalos y casos judiciales.

    EN Internacional Voir la source →

🔐 Cybersécurité

  • Krebs on Security Active

    Blog de investigación sobre cibercrimen y seguridad, muy útil para contexto de fraude, brechas y amenazas.

    EN Internacional Voir la source →
  • BleepingComputer Active

    Medio especializado en malware, incidentes, fraude tecnológico y noticias urgentes de ciberseguridad.

    EN Internacional Voir la source →
  • The Hacker News Active

    Medio global muy activo en ciberseguridad, incidentes, explotación y phishing.

    EN Internacional Voir la source →
  • WeLiveSecurity ES Active

    Medio editorial de ESET con contenidos de estafas, campañas y seguridad en español.

    ES Internacional Voir la source →
  • Dark Reading En intégration

    Medio de referencia en ciberseguridad y threat intelligence.

    EN Internacional Voir la source →
  • The Record En intégration

    Cobertura periodística de ciberseguridad, ciberdelito y operaciones estatales.

    EN Internacional Voir la source →

🎯 Threat intel

  • SANS Internet Storm Center En intégration

    Fuente técnica de amenazas, indicadores, campañas y actividad maliciosa observada.

    EN Internacional Voir la source →
  • Securelist En intégration

    Investigación de amenazas de Kaspersky, útil para campañas, APT, fraude y malware.

    EN Internacional Voir la source →
  • Sophos News - Security Operations En intégration

    Noticias y análisis de operaciones de seguridad, campañas y técnicas de ataque.

    EN Internacional Voir la source →

📰 Presse

  • Escudo Digital Active

    Medio en español sobre seguridad, ciberseguridad y tecnología, útil para noticias locales y regionales.