Mexico: cybersecurity landscape, June 2026
Ransomware led June in Mexico, with pressure on finance, government and manufacturing, while new AI rules advanced.
Key findings
- Ransomware was the dominant threat in Mexico during the month, with 15 of 56 verified incidents and a mix of encryption, exfiltration and leak sites.
- The financial system concentrated the most sensitive signal, with eight cyber incidents accumulated through May 2026 and impact on electronic transfers.
- Operation Escaneo showed a sustained campaign of reconnaissance and exploitation against Mexican government, finance and infrastructure.
- June added four regulatory moves, with the CNBV tightening requirements for fintech and SOFOM and the justice system advancing on privacy and biometric data.
- Fraud cases tied to the 2026 World Cup amplified the risk of phishing, impersonation and fake domains across multiple states.
- The critical vulnerabilities mentioned aligned with perimeter exposure and exposed software, not a single dominant vector.
- Manufacturing and other operational environments remained under pressure, with potential impact on continuity, industrial secrets and the supply chain.
Monthly reference modules
These modules are automatically populated with verified dated facts from within the period. Each one states its basis and counting criterion so the figures reconcile across modules. This is the recurring month-to-month reading; the analysis that follows develops the cases without repeating this summary.
Indicator window: 70 dated facts in June 2026 · 4 from prior months (comparative context, not monthly volume) · 1 without confirmed date (excluded from the indicators) · 2 after the period (excluded). Facts from prior months are used only as comparative context in the analysis, never as volume for this period.
Monthly executive summary in Mexico
June ended with ransomware as the dominant theme in Mexico. Based on 56 verified events during the period, 15 were linked to ransomware or extortion as the primary focus. The month also recorded 15 unclassified incidents, four regulatory moves, four critical CVEs mentioned, and two documented fraud or phishing cases. The signal was not uniform, but it was consistent across three fronts: pressure on financial institutions, exposure of public agencies, and offensive activity against operational sectors such as manufacturing and educational infrastructure.
In the financial system, Banco de México again stood at the center of public discussion. Reports cited by national media confirmed that by May 2026, eight cyber incidents had been recorded at Mexican financial institutions, twice as many as in all of 2025. The coverage points to impacts on banks, Sofipos, a Socap, and an electronic payment funds institution, with effects on electronic transfers and multimillion-dollar losses in some cases. Not all of the material allowed each incident to be technically distinguished, but the timeline shows a sharp increase in operational risk in the first half of the year.
The public sector was also exposed through two different paths. On one side, there were unauthorized accesses to data from federal programs, such as La Escuela es Nuestra, where authorities clarified that this was not a direct compromise of the platform but the use of compromised credentials. On the other side, broader exfiltration campaigns continued, attributed to groups such as EsqueleSquad and to an attacker who, according to consolidated technical reports, used artificial intelligence tools to compromise federal agencies and exfiltrate large volumes of data. Taken together, the month’s record suggests the state remained a high-value target for both data and visibility.
The threat was not limited to isolated campaigns. Operation Escaneo, documented by CloudSEK and cited in other technical analyses, showed sustained reconnaissance and exploitation against Mexican infrastructure, with a focus on Fortinet, Ivanti, Cisco, and environments tied to government, finance, telecom, and critical services. The material points to an intrusion strategy based on exposed access, persistence, and the exploitation of known vulnerabilities. That campaign, along with the appearance of new critical flaws in Splunk, Joomla, SimpleHelp, and Cisco, reinforces a clear operational reading: the perimeter remains a weak point, and attackers are not waiting for novel attack chains to get results.
Regulation followed the risk picture. The CNBV issued a new mandatory circular for fintech and SOFOM, with minimum cybersecurity standards, MFA, faster incident reporting, and notification obligations to affected individuals in sensitive cases. In parallel, the Supreme Court advanced criteria and rulings aimed at limiting the exposure of personal data, while the debate over biometric CURP, national identification, and privacy remained open. The month therefore left an uncommon mix of technical pressure and regulatory response, still without a fully consolidated national coordination framework.
Mexico National Monthly Overview
Mexico's June risk reading is high. Not because of a single attack family or one major event, but because several verified signals converged in parallel: ransomware across companies of different sizes, extortion and leak campaigns, offensive activity targeting government and finance, and a sequence of critical vulnerabilities with active exploitation or formal warnings of malicious use. The severity rises because the month did not show isolated noise, but an accumulation of incidents in sectors with systemic value, such as finance, public administration, manufacturing, and state education infrastructure.
The financial case is the clearest measure of that pressure. Banxico did not point to a single event, but to a series of eight incidents so far in 2026, with concrete impact on transfer services and economic losses. That makes a shift in profile visible: the problem is no longer only the detection of attempts or the raw number of alerts, but operational continuity and the ability of institutions to sustain digital services under pressure. At the same time, the exposure of employee data at Nissan Americas, while regional and disclosed later publicly, is a reminder that Mexico is embedded in corporate supply chains where a breach outside the country can pull in local personnel data.
The regional threat component was also clear. Operation Escaneo, according to CloudSEK and Infosecurity Magazine, hit critical infrastructure in Mexico and also reached organizations in Ecuador and Portugal. The point here is not to compare countries, but to underscore that the offensive pattern seen against Mexico is tied to a transnational campaign that exploits perimeter devices and maintains persistence inside internal networks. In other words, this was not just opportunistic fraud, but a technical intrusion designed to remain in place.
The broader Latin America backdrop continues to show mixed pressure, with governments, finance, and industrial sectors facing extortion, exploitation of exposed services, and leaks. Mexico stands out in that map with significant weight, both in volume of coverage and sector diversity. In this material, the greatest concentration of events was in finance and ransomware, but the real scope is broader, because the reporting also covered regulation, privacy, and fraud tied to the 2026 World Cup.
Mexico period indicators
| Indicator | Value |
|---|---|
| Country | Mexico |
| Period | June 2026 |
| Verified events in the period | 56 |
| Time window for the indicators | 70 events dated in June 2026 · 4 from previous months (comparative frame, not monthly volume) · 1 with no confirmed date (excluded from the indicators) · 2 after the period (excluded) |
| Unclassified incidents (breaches or outages) | 15 |
| Cases with ransomware or extortion as the primary focus | 15 |
| Confirmed encryption of assets | 2 |
| Exfiltration without encryption (simple extortion) | 2 |
| Mention only on a leak site | 2 |
| Type could not be determined from the material | 9 |
| Documented fraud or phishing cases | 2 |
| Documented regulatory moves | 4 |
| Critical CVEs mentioned | 4 |
| Sectors with at least one documented event | 7 |
| Dominant threat of the month | Ransomware (15 of 56 events) |
| Events with direct source confirmation | 64% |
| Aggregated telemetry figures excluded from the volume | 14 (aggregate attempts or blocks, not incidents with confirmed impact) |
Relevant incidents in Mexico
Unauthorized access to data from La Escuela es Nuestra
The most concrete development at the start of the month was the unauthorized access to information from some school committees in the federal La Escuela es Nuestra program. The Digital Transformation and Telecommunications Agency said the access occurred using compromised username and password credentials and that there was no direct hack of the platform. That distinction matters because it shifts attention away from a system flaw and toward stolen identity abuse, a pattern that often has less visible but equally serious consequences for data protection.
The source does not describe a service disruption, but it does confirm exposure of public and administrative information. For a government entity, that kind of incident leaves a simple lesson: access control and credential hygiene are just as critical as the application layer.
Financial attacks confirmed by Banxico
During June, the picture of a financial system hit by successive incidents became clearer. Banxico reported, through its Financial Stability Report cited by several outlets, that as of May 2026 eight cyber incidents had been recorded at Mexican financial institutions, compared with four in all of 2025. Coverage also detailed that the first incident of the year was a Lockbit ransomware attack against a bank in January, with a temporary impact on electronic transfers.
What makes this block relevant is not just the aggregate figure, but the institutional spread. The reported cases involved banks, Sofipos, a Socap and an electronic payment fund institution. That suggests the risk is not limited to traditional banking and that exposure extends to nonbank players in the financial ecosystem, where response capabilities can vary widely.
Exposure of federal and state agencies
The month kept alive coverage of campaigns that, according to multiple sources, affected Mexican government agencies. The best documented case from a technical standpoint is the one reconstructed by Gambit Security, which described a single-actor operation that used Claude Code and GPT-4.1 together to compromise nine Mexican government organizations and exfiltrate about 150 GB of data, with massive identity exposure. The material went beyond the headline and showed an automated exploitation chain, stolen-data analysis and the production of reports ready for operational use.
Along the same lines, other reports mentioned alleged intrusions attributed to EsqueleSquad against nine federal agencies and a broader campaign that reached public bodies, although not all cases could be classified precisely. For the purposes of this report, the relevant point is that the public sector continued to appear as a priority exfiltration target, with taxpayer data, registries and credentials at stake.
Ransomware at Copamex, Idefeey Yucatán, Ford de México and other cases
June brought multiple references to ransomware or extortion, with varying levels of confirmation. Copamex appears with an incident disclosed in RecentBreaches coverage as ransomware attributed to DragonForce, with exposure of corporate files and confidential documents. On the domain idefeey.yucatan.gob.mx, tied to educational infrastructure in Yucatán, a LockBit5 case involving data theft and encryption was confirmed, dated June 17 and publicly discovered on June 20.
There were also mentions of Ford de México and extortion attempts against other companies, but in those cases the exact classification was less clear or depended only on their appearance on leak sites. The month should therefore be read carefully: several names circulated, but only part of the activity allowed for a distinction between encryption, exfiltration without encryption, or a mere claim on a leak site. That difference is not semantic, it changes the reading of the operational damage completely.
Threats and Active Campaigns in Mexico
Ransomware and extortion in Mexico, with varying levels of confirmation
Confirmed asset encryption
Two events this month support a confirmed encryption finding. The first is the case of idefeey.yucatan.gob.mx, where Hookphish classified the incident as ransomware with data theft, and RecentBreaches reported that internal files were exfiltrated. The second is the attack on Copamex, where coverage itself states that corporate files and confidential documents were exposed, attributed to DragonForce. In both cases, the available material supports impact beyond a mere public threat.
Exfiltration without encryption, or simple extortion
The material also showed cases where the pressure centered on publishing data, without sufficient evidence of encryption. In June, at least two such cases were mentioned in the consolidated file, but the public information did not always make it possible to identify the exact technical scope. This matters in a monthly read because simple extortion usually leaves more traces of data exposure than of operational downtime, and it calls for defenses different from those used against classic ransomware.
Mention only on a leak site
There were also victims named on leak sites, such as ford.mx, where the Krybit group claimed to have obtained internal files and threatened to publish more data if there was no negotiation. The issue is that, at that level, the claim does not by itself amount to a verified intrusion and does not clarify whether encryption, exfiltration, or both occurred. For that reason, the source should be read as a threat signal, not as full proof of impact.
Fraud and phishing in Mexico
Mass fraud tied to the 2026 World Cup was one of the few clear signals outside ransomware. El Financiero reported that Mexico leads cyberfraud linked to the event because of the spread of fake ticket sales sites and bogus pages associated with FIFA. Infobae added that the campaign spans 18 states and that the phenomenon combines commercial deception, identity spoofing, and fraudulent domains.
There were also references to a leak of 45,804 mobile users, attributed to Mago Peak, and to the rise in digital crime reports received by the Mexico City Cyber Police. In both cases the pattern is similar, the fraud surface is built on reusable personal data and very specific contact channels, such as messaging or registration portals.
APT, targeted intrusion, and hacktivism in Mexico
Operation Escaneo deserves a separate mention because it does not fit the mold of opportunistic ransomware or commercial fraud. CloudSEK described it as an active reconnaissance and exploitation campaign against Mexico, using tools such as Neo-reGeorg, Chisel, and compromised Cisco routers to maintain persistent access. Infosecurity Magazine placed it across government, tax, utilities, transportation, telecommunications, and banks. The main signal here is intent to persist and map networks, not public extortion.
The case of AI-assisted attacks on Mexican agencies also points to a more sophisticated intrusion than average. Gambit Security's documentation shows an automated workflow in which AI is not a decorative layer, but part of reconnaissance, exploitation, and exploitation of the information obtained. There is no evidence of a single responsible group across all the month's public cases, but there is evidence of convergence between offensive automation and high-value targets.
Critical vulnerabilities affecting Mexico
| CVE | Software | Exploitation | Source |
|---|---|---|---|
| CVE-2026-48558 | SimpleHelp | Active exploitation confirmed, included by CISA in KEV on June 29, 2026 | 2MCI |
| CVE-2026-20253 | Splunk Enterprise | Limited exploitation observed, advisory updated on June 18, 2026 | Splunk, Orca Security, Smartekh |
| CVE-2026-20262 | Cisco Catalyst SD-WAN Manager | Cisco confirmed active exploitation during June 2026 | Smartekh |
| CVE-2026-48907 | Joomla Content Editor | Added to KEV by CISA, with exploitation warned for environments that use it | BreachDocket, Lilting, Smartekh |
The month’s technical focus centered on exposed software and widely used components. There was no single dominant product, but rather a cluster of critical flaws in tools that often sit at perimeters, remote support services, or content managers. That combination is especially sensitive for Mexico because the exposed surface spans public institutions, private companies, and service providers.
References also appeared to vulnerabilities exploited in Fortinet and Ivanti campaigns within Operation Escaneo, although the material collected does not always clearly separate which Mexican environments were actually affected and which were only potential targets. In these cases, the table should be read as a list of verified exposure, not as a complete inventory of every product at risk in the country.
Regulation and compliance in Mexico
June brought four documented regulatory moves, with a focus on privacy, digital identity, and financial cybersecurity. The most concrete was the CNBV's new circular for fintechs and SOFOMs that issue credit through digital channels. According to CreditoLab, the rule sets minimum cybersecurity standards, requires MFA, shortens incident reporting deadlines, and obligates firms to notify affected users when sensitive financial information involving more than 5,000 users is compromised. The reference source is secondary coverage, but the regulatory action itself is clearly defined.
At the same time, the Supreme Court ruled unconstitutional local provisions that required certain personal data to be included in certified copies of birth certificates. A provisional suspension was also reported so that a telecom company cannot require biometric data during line registration, and the Semanario Judicial published new criteria on privacy in the context of the biometric CURP. These are separate decisions, but they point in the same direction, greater caution around the expansion of sensitive identifiers.
The legislative debate also moved forward. On June 29, federal deputies presented a bill to create a General Law for the Regulation and Ethical Use of Artificial Intelligence in Mexico. The proposal aims to organize the development, application, and oversight of automated systems, with attention to algorithmic discrimination and privacy intrusion. From a public policy standpoint, the month sent a clear message, the regulatory discussion is no longer at the diagnostic stage, but at the stage of defining obligations.
Most affected sectors in Mexico
June’s sector pattern was broader than the ransomware label alone suggests. Finance led the volume of signals, with eight incidents cited by Banxico and a high density of coverage around transfers, losses, and systemic risk. Government made up the second major block, with unauthorized access, data exfiltration, and campaigns directed at federal and state agencies. The private sector was not spared, but its exposure was more fragmented across companies such as Copamex, Ford de México, and entities in the food, paper, packaging, and manufacturing ecosystem.
Manufacturing deserves separate attention. Although not every individual case in the month names it directly, the context material places it among the most targeted sectors in Mexico, which fits the presence of Copamex, Ford, and other references to industrial infrastructure. The issue is not only system availability, but operational continuity, the confidentiality of designs, and commercial pressure from data leakage.
One relevant feature is that several events cut across more than one sector at the same time. The idefeey.yucatan.gob.mx case involves the public sector, education, and state infrastructure. Operation Escaneo reaches government, finance, telecommunications, and utilities. For that reason, any sector reading has to be cautious and avoid treating coverage as exclusive when it is not. The real signal for the month is cross-cutting, but with greater intensity in finance, public administration, and environments where perimeter exposure remains high.
Trends and signals to watch in Mexico
There is no month-over-month baseline, because this is the first archived period with this indicator format for Mexico. That gap means numerical comparisons should be avoided. What can be said is that June cemented a pattern: ransomware and extortion dominated the conversation, while critical vulnerabilities and targeted intrusion campaigns gained visibility.
The main signal to watch in July is twofold. First, whether leak site threats and simple extortion materialize, especially at industrial companies and in the nonbank financial ecosystem. Second, how organizations respond to critical flaws already in KEV or marked as exploited, because risk depends not only on the existence of the CVE but on the real time it takes Mexican organizations to remediate. If that lag continues, the next month will likely keep showing incidents tied to known entry points rather than technical innovation.
The regulatory front also bears watching. The CNBV has already raised the bar for fintech and SOFOM, and the debate over biometric CURP, privacy and digital identification could accelerate new obligations. At the same time, the fraud campaign tied to the World Cup and the use of AI to automate reconnaissance and exploitation show that the line between classic cybercrime and AI-assisted operations is getting harder to distinguish.
Security recommendations for teams in Mexico
- Review external exposure of appliances, content management systems, and remote support software, with priority on Fortinet, Ivanti, Cisco, Splunk, Joomla and SimpleHelp.
- Tighten credential controls, especially in public programs, fintech and services with delegated access, because the case of La Escuela es Nuestra showed that one compromised credential can be enough.
- Speed up patching and mitigations for assets marked as exploited or in active use during the month, and record the internal remediation date for audit purposes.
- Separate ransomware response, exfiltration and simple extortion, because the negotiation content, system isolation and legal notification are not the same.
- Review phishing and brand impersonation detection processes, especially campaigns tied to mass events, ticketing and spoofed pages.
- In financial institutions, strengthen traceability for electronic transfers, third-party inventory and privilege segregation across digital channels.
- In government and education, prioritize service account inventory, secret rotation, session validation and monitoring for anomalous access from valid credentials.
- For organizations with an industrial footprint, verify operational continuity and offline backups, because pressure on manufacturing combines with extortion and leakage of technical data.
Material limitations
This report was prepared exclusively from the material provided for Mexico in June 2026. The indicator window includes 70 dated facts from June 2026, 4 facts from previous months used only as comparative context, 1 undated fact that was excluded from the indicators, and 2 facts after the period, also excluded. The period indicators reflect only facts dated within June and not aggregated telemetry of attempts or blocks.
A zero indicator does not mean that something did not occur in Mexico or the region, only that it did not appear in the analyzed material with the quality required for this report. This is especially true for CVEs, although this month there were four critical vulnerabilities mentioned. If in another period any category were to appear as zero, the meaning would remain the same, absence of a record in the corpus, not absence of a real phenomenon.
The distinction between incidents, telemetry, and attributed campaigns was maintained strictly. Attempt or block counts, such as those cited by vendors or coverage referring to massive attack volumes, were not counted as incidents with confirmed impact. They were also not used on their own to infer trend.
Consumer social networks and sponsored posts or press releases that were not included in the source list were excluded as evidence. When any coverage cited third-party material, the source that described the event most precisely was prioritized and, if the material did not allow impact to be confirmed, it was recorded as attributed or undetermined, as appropriate.
Sources
- Mundial 2026: México lidera ciberfraudes ante embestida de sitios falsos en internetEl Financiero
- Ciberseguridad rumbo al mundial 2026: riesgos, amenazas y retosYouTube / Onesec
- México encabeza ciberataques ligados al Mundial 2026Infobae
- Ransomware victims map – MexicoRansomware.live
- Banxico lanza alerta: los ciberataques en México se duplicaron en 2026Dyse
- Banxico reporta aumento de ciberataques contra instituciones financieras en México durante 2026 y advierte riesgos para transferencias, pagos y servicios digitalesEl Imparcial
- Se duplican incidentes cibernéticos en instituciones financieras en 2026, según BanxicoImagen Radio
- Incidentes cibernéticos ocurridos en 2026 en el sistema financiero mexicanoBanco de México
- Ciberataques aumentan en México previo al torneo global de fútbolReseller
- Gobierno reconoce acceso no autorizado a datos de La Escuela es NuestraDiario El Independiente
- Hackeo con IA al gobierno de México: 150 GB de datos expuestosOCD Tech
- Banxico reporta aumento de ciberataques contra instituciones financieras en México durante 2026El Imparcial
- Sufren ataques cibernéticos 8 instituciones financierasReforma
- Monitoreo de medios y redes sociales, 22 de junio de 2026Unifimex
- Radar CTI | México en la mira: campañas activas contra gobierno, finanzas e infraestructuraSmartekh
- Nueva regulación de ciberseguridad de la CNBV para fintechs y SOFOMsCreditoLab
- ¿Avanza realmente la ciberseguridad en México? Seis meses después del anuncio la protección a la ciudadanía sigue en el papelInfobae
- Infraestructura crítica en México: el peligro oculto de las tecnologías operativas obsoletasGitSecurit
- El Mundial, un "imán" para los fraudes digitales en México agravado por la IAInfobae / EFE
- A Single Operator, Two AI Platforms, Nine Government Agencies – The Full Technical ReportGambit Security
- Cyberattacco AI in Messico: 1 operatore, 9 enti pubbliciICT Security Magazine
- USMCA in the age of AI: Why one hack should alarm all 3 economiesThomson Reuters
- Mythos enters the chatTechRadar Pro
- SVD-2026-0603 | Splunk Vulnerability DisclosureSplunk
- CVE-2026-20253: Splunk Enterprise RCE & File OperationOrca Security
- Splunk Product Security Update Advisory (CVE-2026-20253)AhnLab ASEC
- CVE-2026-48907: Joomla Content Editor Bug Added to CISA KEVBreachDocket
- Joomla JCE CVE-2026-48907 is exploited: patch 2.9.99.7 and harden PHP upload pathsLilting
- U.S. CISA adds Widget Factory Joomla Content Editor flaw to its Known Exploited Vulnerabilities catalogSecurity Affairs
- CVE-2026-48907 - Widget Factory Joomla Content EditorCVEfeed
- Operation Escaneo: Infrastructure Exposure, TTP Analysis for Mexican Government and Financial InstitutionsCloudSEK
- LATAM Infrastructure Hit by Fortinet and Ivanti ExploitsInfosecurity Magazine
- Se reportaron ocho incidentes cibernéticos en lo que va del 2026El Economista
- Banxico advierte de los riesgos en el uso de IA en el sistema financieroExpansión
- Bank of Mexico says Mexican financial system maintains solid positionReuters
- El Mundial, un "imán" para los fraudes digitales en México agravado por la IAYahoo Noticias / EFE
- Ciberataques, fraudes y robo de identidad, los riesgos que enfrentan los aficionados en el Mundial 2026Reporte Índigo
- Ransomware.live 👀 Mexico Map / Victim: idefeey.yucatan.gob.mxRansomware.live
- Ransomware Group lockbit5 Hits: idefeey.yucatan.gob.mxHookphish
- Krybit Ransomware Targets Ford de MexicoDeXpose
- ford.mx Listed by krybit Ransomware GroupGalaxyWarden
- Brinztech Alert: Alleged Ransomware Claim Against Ford de MexicoBrinztech
- Weekly Ransomware Intelligence Report, June 28, 2026Scrutex
- Industrial Ransomware Analysis for Q1 2026Dragos
- El estado de la ciberseguridad en la manufactura y la logísticaManpowerGroup
- Fraude financiero supera los 1,000 mdd en MéxicoDPL News
- Ley Fintech México: claves de ciberseguridadWhiteJaguars
- Operation Escaneo Signals Shift in LatAm Threat LandscapeSocDefenders
- idefeey.yucatan.gob.mx Data Breach (2026) — What Leaked & Am I Affected?Recentbreaches
- CVE-2026-46406 | Tenable®Tenable
- Sistema financiero mexicano, blanco de ataques cibernéticosEl Financiero
- Hackeo masivo expone millones de datos del gobierno federalSociedad Noticias
- Hackers exhiben fragilidad del registro de celulares: se filtran datos de 45 mil usuarios de telefoníaInfobae
- Diputadas proponen ley para regular el uso de la IAFer Moctezuma
- Suprema Corte lo decidió: este dato personal ya no aparecerá en las actas de nacimientoInfobae México
- Tribunal concede suspensión para no entregar datos biométricos durante el registro de celularesExpansión Política
- Soberanía digital, la apuesta constitucional frente a la CURP biométricaSDPnoticias
- Copamex Data Breach (2026) — What Leaked & Am I Affected?RecentBreaches
- DragonForce and Nitrogen Ransomware Hit Three Continents - RansomwareDaily Security Review
- ThreeAM Ransomware Hits Agro Industrial Exportadora in MexicoDexpose
- Krybit Ransomware Lists Ford de México as a VictimBreached.company
- Victim: ford.mxRansomware.live
- Weekly Ransomware Intelligence Report, June 21, 2026 - ScruteXScruteX
- [CVE-2026-48558] Vulnerabilidad explotada activamente en ...2MCI
- 2060 New CVEs and 4 Actively Exploited Flaws (June 15-21, 2026)SecurityOnline.info
- Vulnerabilidad en LiteSpeed cPanel Plugin con explotación activa permite abuso de symlinks en hosting compartidoCSIRT Telconet
- Vulnerabilidad crítica de día cero en Microsoft Exchange Server permite ejecución remota de JavaScriptCSIRT Telconet
- Ep.670 - RadioCSIRT Édition Française - Flash info cybersécurité du Mardi 16 Juin 2026RadioCSIRT
- Nissan says Oracle PeopleSoft break-in may have spilled ...The Register
- Nissan Employee Data Breached in Oracle PeopleSoft HackSecurityWeek
- Nissan Employee Data Stolen in Oracle Zero-Day Hack - GblockGblock
- Nissan Americas Employee Data Breach Analysis: Oracle PeopleSoft ...Rescana
- ShinyHunters Exploits Oracle PeopleSoft Zero-Day (CVE- ...The Hacker News
- ShinyHunters Hit Oracle PeopleSoft and Your Vendors May ...Black Kite
- Search Data Security Breaches - State of CaliforniaOffice of the Attorney General, California
