{"id":1034,"date":"2026-06-01T16:08:04","date_gmt":"2026-06-01T16:08:04","guid":{"rendered":"https:\/\/cybercolombia.co\/index.php\/2026\/06\/01\/new-linux-flaw-pan-os-exploit-ai-powered-attacks-oauth-phishing-and-more-cyberdefensa-mx\/"},"modified":"2026-06-01T16:08:04","modified_gmt":"2026-06-01T16:08:04","slug":"new-linux-flaw-pan-os-exploit-ai-powered-attacks-oauth-phishing-and-more-cyberdefensa-mx","status":"publish","type":"post","link":"https:\/\/cybercolombia.co\/index.php\/2026\/06\/01\/new-linux-flaw-pan-os-exploit-ai-powered-attacks-oauth-phishing-and-more-cyberdefensa-mx\/","title":{"rendered":"New Linux Flaw, PAN-OS Exploit, AI-Powered Attacks, OAuth Phishing and More \u2013 CYBERDEFENSA.MX"},"content":{"rendered":"<div id=\"articlebody\">\n<p>Monday hit like a cron job with anger issues.<\/p>\n<p>A busted auth path here, a repo-side faceplant there, some \u00abpatched-ish\u00bb thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already thought \u2018curl | sh\u2019 had a personality.<\/p>\n<p>The vibe is simple: old bugs, new wrappers, faster abuse. Patch the obvious crap first. Then read the rest.<\/p>\n<h2 style=\"text-align: left;\"><b>\u26a1 Threat of the Week<\/b><\/h2>\n<p><b>PAN-OS GlobalProtect Authentication Bypass Under Exploitation <\/b>\u2013 Palo Alto Networks warned that a recently disclosed medium-severity security flaw impacting PAN-OS and Prisma Access has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-0257 (CVSS score: 7.8), refers to a case of authentication bypass that could be exploited by bad actors to set up VPN connections. The issue specifically affects firewalls with GlobalProtect portal or gateway configured when authentication override cookies are enabled and a specific certificate configuration exists, the network security company said.<\/p>\n<h2 style=\"text-align: left;\"><b>\ud83d\udd14 Top News<\/b><\/h2>\n<ul>\n<li><b><a href=\"https:\/\/thehackernews.com\/2026\/05\/critical-gogs-rce-vulnerability-lets.html\">Critical Unpatched Flaw in Gogs <\/a><\/b>\u2013 The popular open-source self-hosted Git service Gogs is affected by a critical-severity zero-day vulnerability that exposes servers to remote code execution (RCE), per Rapid7. The injection flaw can be exploited by authenticated attackers via pull requests with malicious branch names. \u00abSince Gogs ships with open registration enabled by default and no limit on repository creation, an unauthenticated attacker can simply create an account and repository on any default-configured instance,\u00bb the cybersecurity firm says. Any repository owner can enable rebase merging with a single toggle in settings, and the entire exploit chain can be operated without interaction from any other user. Attackers with write access to repositories that have rebase enabled can exploit the flaw directly. \u00abThe result is arbitrary command execution as the Gogs server process user, giving the attacker the ability to compromise the server, read every repository on the instance (including other users\u2019 private repos), dump credentials (password hashes, API tokens, SSH keys, 2FA secrets), pivot to other network-accessible systems, and modify any hosted repository\u2019s code,\u00bb Rapid7 said. Gogs servers across Windows, Linux, and macOS that are running default configurations are affected. No patch has been released as of the time of publishing.<\/li>\n<li><b>GlassWorm C2 Taken Down <\/b>\u2013 CrowdStrike, Google, and the Shadowserver Foundation dismantled the GlassWorm malware operation by taking down all four of GlassWorm\u2019s command-and-control (C2) channels simultaneously on May 26, 2026, at 2 p.m. UTC. GlassWorm, since its emergence last year, has conducted a \u00abmulti-pronged campaign\u00bb using trojanized VS Code extensions published on both the Microsoft VS Code Marketplace and Open VSX. The campaign is also known to have introduced malicious code through compromised npm and Python packages. By taking down all four channels at the same time, the action severed the operators\u2019 access to the infected hosts and their ability to deliver new commands. Evidence suggests that GlassWorm\u2019s operators are of Russian origin: the malware checks the system\u2019s locale and avoids infecting machines in CIS countries, and its code contains Russian-language comments. In addition to taking down the GlassWorm infrastructure, CrowdStrike has instructed the infected endpoints to beacon to the benign IP address 164.92.88[.]210. Organizations are advised to check for connections to this IP address to identify potential infections. Despite these efforts, the broader economics of repository abuse remain an ongoing issue. Open-source ecosystems continue to offer attackers low-cost distribution channels with a massive reach when compared to traditional software. This also means operators behind such campaigns can resurface under new accounts, domains, or package names. In other words, it\u2019s only a temporary disruption, not eradication.<\/li>\n<li><b>CERT-In Urges Organizations to Patch Exploited Flaws Within 12 Hours  <\/b>\u2013 Organizations in India have been urged to patch actively exploited vulnerabilities impacting internet-facing or \u00abcrown jewel\u00bb systems within 12 hours, where feasible, so as to better respond to the speed artificial intelligence (AI) now brings to cyber attacks. CERT-In stopped short of framing the timelines as binding, describing them as indicative expectations to be applied according to operational criticality and threat exposure. The agency also warned that AI-assisted attacks are dramatically compressing the time between vulnerability disclosure and exploitation. The framework also recommends one-day remediation for critical externally exposed vulnerabilities, three days for critical internal vulnerabilities affecting high-value systems, and five days for high-severity flaws based on risk prioritization.<\/li>\n<li><b>GREYVIBE Leans on AI for Ukraine Attacks <\/b>\u2013 A previously undocumented Russian group codenamed GREYVIBE has been found to make extensive use of large language models (LLMs) in its attacks against private, government, and military organizations in Ukraine. The end goal is to gather intelligence for the ongoing war. \u00abWhile the activities align with Russian state interests, several observed indicators suggest the group has ties to the broader cybercrime ecosystem, with the group potentially involving current or former cybercriminal actors,\u00bb WithSecure said. The threat actor is believed to have been active since August 2025. What\u2019s notable is the extent to which AI appears to be enmeshed throughout the operation. The group\u2019s use of AI is believed to be \u00aboperationally integrated rather than isolated or experimental.\u00bb<\/li>\n<li><b>AI Chatbot Recommendations Redirect Users to Cryptojacking Malware <\/b>\u2013 A new campaign is using searches for popular tools in AI chatbots to redirect users to sketchy sites that trick users into downloading booby-trapped executables that drop a cryptocurrency miner on compromised hosts. The goals of the campaign are not merely financially motivated. The threat actors have also been found to establish persistent remote access to compromised hosts through ScreenConnect deployments, which could then be leveraged for follow-on activity, such as data theft, lateral movement, or ransomware.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><b>\ud83d\udd25 Trending CVEs<\/b><\/h2>\n<p>Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.<\/p>\n<p>Check the list, patch what you have, and hit the ones marked urgent first \u2013 CVE-2026-8732 (WP Maps Pro plugin), CVE-2026-0257 (Palo Alto Networks PAN-OS and Prisma Access), CVE-2026-27771 (Gitea), CVE-2026-45659 (Microsoft SharePoint), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/780781\">from CVE-2026-9090 through CVE-2026-9098<\/a> (Casdoor), <a href=\"https:\/\/github.com\/notepad-plus-plus\/notepad-plus-plus\/security\/advisories\/GHSA-3x3f-3j39-pj3v\">CVE-2026-48800<\/a>, <a href=\"https:\/\/github.com\/notepad-plus-plus\/notepad-plus-plus\/security\/advisories\/GHSA-7hm3-wp5q-ccv9\">CVE-2026-48778<\/a>, <a href=\"https:\/\/github.com\/notepad-plus-plus\/notepad-plus-plus\/security\/advisories\/GHSA-r39g-3mcw-xcg2\">CVE-2026-48770<\/a> (Notepad++), <a href=\"https:\/\/www.obsidiansecurity.com\/blog\/when-is-stdio-mcp-actually-a-vulnerability\">CVE-2026-40933<\/a> (Flowise), <a href=\"https:\/\/chromereleases.googleblog.com\/search?updated-max=2026-05-27T11:28:00-07:00&amp;max-results=7\">from CVE-2026-9872 through CVE-2026-9893<\/a> (Google Chrome), <a href=\"https:\/\/www.veeam.com\/kb4852\">CVE-2026-32996, CVE-2026-32997<\/a> (Veeam Backup &amp; Replication), <a href=\"https:\/\/support.plesk.com\/hc\/en-us\/articles\/38633651286679-Vulnerability-CVE-2026-44962-in-Plesk-s-APS-Catalog\">CVE-2026-44962<\/a> (Plesk), <a href=\"https:\/\/docs.gitlab.com\/releases\/patches\/patch-release-gitlab-19-0-1-released\/\">CVE-2026-4868, CVE-2026-1402, CVE-2026-6713<\/a> (GitLab), <a href=\"https:\/\/www.oracle.com\/security-alerts\/cspumay2026.html\">CVE-2026-46840, CVE-2026-46775, CVE-2026-46839, CVE-2026-2332<\/a> (Oracle), <a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2026-4480.html\">CVE-2026-4480<\/a> (Samba), <a href=\"https:\/\/www.safebreach.com\/blog\/click-or-trick-cve-2025-59199-escaping-the-sandbox-with-windows-uris\/\">CVE-2025-59199 aka Click Or Trick<\/a> (Microsoft Windows 11), <a href=\"https:\/\/openvpn.net\/connect-docs\/macos-release-notes.html\">CVE-2026-9560<\/a> (OpenVPN Connect for macOS), <a href=\"https:\/\/docs.github.com\/en\/enterprise-server@3.20\/admin\/release-notes#3.20.3\">CVE-2026-9312<\/a> (GitHub Enterprise Server), <a href=\"https:\/\/kb.isc.org\/docs\/aa-0091\">CVE-2026-3593, CVE-2026-5946, CVE-2026-5947<\/a> (BIND 9), <a href=\"https:\/\/github.com\/memcached\/memcached\/wiki\/ReleaseNotes1642\">CVE-2026-47783<\/a> (Memcached), <a href=\"https:\/\/lists.apache.org\/thread\/c1zqxppo1m5z3kbdhjn5p991zk09ynkh\">CVE-2026-44930<\/a> (Apache CXF), <a href=\"https:\/\/www.connectwise.com\/company\/trust\/security-bulletins\/2026-05-21-connectwise-automate-bulletin\">CVE-2026-9089<\/a> (ConnectWise Automate), <a href=\"https:\/\/www.openwall.com\/lists\/oss-security\/2026\/05\/24\/11\">CVE-2026-4115<\/a> (PuTTY), <a href=\"https:\/\/securitylab.github.com\/advisories\/GHSL-2026-140_7-Zip\/\">CVE-2026-48095<\/a> (7-Zip), an argument injection vulnerability in Gogs, a remote code execution vulnerability in <a href=\"https:\/\/medium.com\/@hijack-everything\/post-compromise-rce-in-vs-code-remote-ssh-turning-developer-access-into-cloud-compromise-048eed10ad44\">Microsoft Visual Studio Code Remote-SSH<\/a> extension, and multiple vulnerabilities in <a href=\"https:\/\/roundcube.net\/news\/2026\/05\/24\/security-updates-1.6.16-and-1.7.1\">Roundcube Webmail<\/a>.<\/p>\n<h2 style=\"text-align: left;\"><b>\ud83c\udfa5 Cybersecurity Webinars<\/b><\/h2>\n<ul>\n<li><a href=\"https:\/\/thehacker.news\/beyond-zero-day\">Beyond Zero-Day: How Attackers Actually See Your Network<\/a> \u2192 Zero-days are inevitable. The real battle is what attackers see once they\u2019re inside. Join HD Moore (creator of Metasploit) in this webinar as he reveals how to map your network like an attacker \u2013 exposing hidden assets, forgotten bridges, and dangerous IT\/IoT\/OT connections most teams miss.<\/li>\n<li><a href=\"https:\/\/thehacker.news\/validate-automated-pentesting\">Why Automated Pentesting Falls Short \u2013 And How to Fix It<\/a> \u2192 Automated pentesting tools promised comprehensive security validation, but in reality, they only scratch the surface. After a few runs, new findings drop sharply, leaving critical blind spots in detection, response, and control effectiveness. Join Autumn Stambaugh and Can Y\u00fcceel of Picus Security as they explain why automated pentesting alone isn\u2019t enough \u2013 and how to build a complete validation program that actually closes the gaps.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><b>\ud83d\udcf0 Around the Cyber World<\/b><\/h2>\n<ul>\n<li><b>New Windows Flaw Under Attack <\/b>\u2013 Belgium\u2019s Centre for Cybersecurity (CCB) has <a href=\"https:\/\/ccb.belgium.be\/advisories\/warning-microsoft-patch-tuesday-may-2026-patches-118-vulnerabilities-16-critical-102\">warned<\/a> that a recently patched Windows flaw, <a href=\"https:\/\/msrc.microsoft.com\/update-guide\/vulnerability\/CVE-2026-41089\">CVE-2026-41089<\/a>, has come under active exploitation in the wild. The vulnerability is a stack-based buffer overflow in Windows Netlogon that allows an unauthorized attacker to execute code over a network. There are currently no details on how the vulnerability is being exploited. The vulnerability was addressed by Microsoft as part of its May 2026 Patch Tuesday update.<\/li>\n<li><b>Anthropic Confirms Mythos Release <\/b>\u2013 Anthropic has <a href=\"https:\/\/www.anthropic.com\/news\/claude-opus-4-8\">confirmed<\/a> it intends to bring Mythos-class models to \u00aball our customers in the coming weeks\u00bb and said it\u2019s \u00abmaking swift progress\u00bb on developing stronger cyber safeguards prior to their release.<\/li>\n<li><b>New Linux Flaw CIFSwitch Uncovered <\/b>\u2013 A newly disclosed Linux local privilege escalation (LPE) vulnerability dubbed <a href=\"https:\/\/heyitsas.im\/posts\/cifswitch\/\">CIFSwitch<\/a> has been found to enable low-privileged users to gain root access by abusing a logic flaw between the Linux kernel Common Internet File System (CIFS) client and the userspace helper package, cifs-utils. According to SpaceX security engineer Asim Viladi Oglu Manizada, the kernel-side bug has been around since 2007. A patch for the flaw has been <a href=\"https:\/\/github.com\/torvalds\/linux\/commit\/3da1fdf4efbc490041eb4f836bf596201203f8f2\">pushed<\/a> to mainline Linux as of May 19, 2026.<\/li>\n<li><b>Dashlane Warns of Brute-Force Attack <\/b>\u2013 Dashlane <a href=\"https:\/\/x.com\/dashlane\/status\/2061223178932720047\">said<\/a>: \u00abuser accounts were targeted in a brute force attack by an external party, resulting in the suspension of those accounts as part of Dashlane\u2019s built-in security measures.\u00bb The affected accounts have since been unsuspended. The password management company also noted that it\u2019s taking measures to address the issue, adding that there is no evidence of compromise of Dashlane\u2019s systems. It\u2019s not known who is behind the attack.<\/li>\n<li><b>Global Smishing Operation Impacts 19 Countries <\/b>\u2013 Hunt.io said it identified a coordinated smishing operation spanning 19 countries across Europe, the Americas, and the Caucasus. \u00abThe same infrastructure hitting Romanian taxpayers was also targeting DPD delivery customers in the U.K. and Ireland, road police portals in Bulgaria and Armenia, tax authorities in Greece, and T-Mobile users in the United States,\u00bb the company <a href=\"https:\/\/hunt.io\/blog\/massive-smishing-campaign-governments-postal-telecoms\">said<\/a>. \u00ab1,628 malicious URLs confirmed active across 19 countries and multiple sectors.\u00bb The campaigns are designed to invoke a false sense of emergency using fabricated fines and trick users into making payments and entering their personal information.<\/li>\n<li><b>Microsoft Teams and Google Drive Abused to Deliver Java RAT <\/b>\u2013 An intrusion targeting a customer in the legal industry involved the use of Microsoft Teams voice phishing to deceive the victim into granting remote access via Quick Assist. It was followed by the deployment of a Java-based remote access trojan (RAT) named Nimbus RAT. \u00abNimbus RAT is a self-contained implant that uses Google Drive and Google Sheets for command-and-control (C2), helping its network traffic appear benign,\u00bb eSentire <a href=\"https:\/\/www.esentire.com\/blog\/nimbus-rat-how-threat-actors-are-abusing-microsoft-teams-and-google-drive-to-deploy-a-java-rat\">said<\/a>. \u00abFrom initial Teams contact to RAT execution, the attack took less than 20 minutes.\u00bb The activity overlaps with similar Teams-based social engineering attacks carried out by BlackSuit affiliates.<\/li>\n<li><b>Tracking Site Visitors Via FROST <\/b>\u2013 New research has shown that malicious websites can track visitors by measuring tiny changes in SSD access times as a side channel, turning normal browser activity into a privacy leak. The attack, named <a href=\"https:\/\/hannesweissteiner.com\/pdfs\/frost.pdf\">FROST<\/a> (short for Fingerprinting Remotely using OPFS-based SSD Timing), is a \u00abside-channel attack from JavaScript that exploits OPFS [Origin Private File System] to leak sensitive information from the browser without requiring any user interaction on both Linux and macOS.\u00bb The attack \u00abuses SSD contention measurements from within the browser to fingerprint user activity on a system,\u00bb a group of academics from the Graz University of Technology and Liebherr-Transportation Systems GmbH said. \u00abAfter tricking the victim into clicking a malicious link, an attacker can monitor the victim\u2019s activity on the host system, such as website visits and application usage, without further user interaction.\u00bb The impact of the attack goes beyond website tracking. The study also demonstrated that it\u2019s possible to fingerprint application usage, allowing attackers to potentially infer where specific apps were opened.<\/li>\n<li><b>Instagram Exploit Allegedly Enabled Account Takeover <\/b>\u2013 According to <a href=\"https:\/\/x.com\/DarkWebInformer\/status\/2061253599758315527\">Dark Web Informer<\/a> and <a href=\"https:\/\/x.com\/zachxbt\/status\/2061251183675949365\">ZachXBT<\/a>, Instagram is said to have suffered from an exploit that made it possible to use Meta AI to reset passwords to accounts with no multi-factor authentication (MFA) enabled. The exploit has since been patched.<\/li>\n<li><b>EvilTokens Abuses OAuth Flow, RatPressto Kit Surfaces <\/b>\u2013 The phishing-as-a-service (PhaaS) platform known as EvilTokens is being used to carry out device code phishing attacks at scale. \u00abThese campaigns are notable for abusing the OAuth 2.0 device authorization flow, automating this sophisticated phishing at scale, and using AI to produce realistic, quickly deployable attack infrastructure,\u00bb Netcraft <a href=\"https:\/\/www.netcraft.com\/blog\/eviltokens-and-oauth-abuse\">said<\/a>. The company said it has seen thousands of attacks using the EvilTokens phishing kit. The development coincides with the emergence of a new phishing toolkit dubbed RatPressto that\u2019s being used in an active campaign. The kit, hosted on legitimate-but-compromised WordPress sites, is used to serve ScreenConnect for establishing persistent remote access. \u00abRatPressto has been observed targeting financial organizations, looking to silently exfiltrate credentials, secrets, and sensitive data that could be used to aid further compromise,\u00bb Fortra <a href=\"https:\/\/www.fortra.com\/blog\/ratpressto-phishing-kit\">said<\/a>.<\/li>\n<li><b>Solo Russian-Speaking Threat Actor Linked to Patriot Bait Campaign <\/b>\u2013 A solo Russian-speaking threat actor tracked as \u00abbandcampro\u00bb ran a 5-year MAGA-themed Telegram channel (@americanpatriotus, approximately 17,000 subscribers) and pivoted to AI-automated content, fraud, and credential theft starting September 2025. \u00abA jailbroken Google Gemini served as the actor\u2019s co-worker, generating Q-styled posts, deploying infrastructure, rotating stolen API keys, modeling victim passwords, and running a QAnon-styled chatbot (QFS 2.0 Terminal),\u00bb Trend Micro <a href=\"https:\/\/www.trendmicro.com\/en_us\/research\/26\/e\/inside-the-influence-and-fraud-patriot-bait-campaign.html\">said<\/a>. \u00abSafeguards were bypassed via jailbreaking and non-English prompting, allowing explicit pump-and-dump prompts and instructions to mutate victim passwords to be processed, showing how frontier-AI safety controls can be circumvented through jailbreaks and non-English prompting.\u00bb The campaign once again highlights how AI has significantly cut down the resources needed to run influence operations.<\/li>\n<li><b>SonicWall Scanning Spike Recorded <\/b>\u2013 GreyNoise <a href=\"https:\/\/www.greynoise.io\/blog\/sonicwall-scanning-spike-echoes-pattern-preceded-cve-2026-0400\">said<\/a> it observed a \u00absignificant new spike in scanning of SonicWall SonicOS management interfaces\u00bb between May 9 and May 18, 2026. \u00abApproximately 56% of sessions originate from networks announced in the Netherlands and 44% in Ukraine \u2013 together more than 99% of total volume,\u00bb it said. \u00abA single ASN (AS211736) carries roughly half of the total session volume.\u00bb<\/li>\n<li><b>New Payload Ransomware Emerges <\/b>\u2013 Cybersecurity researchers have analyzed ransomware families like <a href=\"https:\/\/www.picussecurity.com\/resource\/blog\/nightspire-ransomware-attack-chain-tools-and-tactics\">NightSpire<\/a> and <a href=\"https:\/\/darkatlas.io\/blog\/behind-payload-in-depth-technical-analysis-of-payload-ransomware\">Payload<\/a>, with the latter already racking up 50 victims on its leak site since emerging in February 2026. \u00abAlthough the group initially claimed only a limited number of victims, its operations quickly showed a global footprint, with targets across Egypt, Mexico, and Poland,\u00bb Dark Atlas said.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><b>\ud83d\udd27 Cybersecurity Tools<\/b><\/h2>\n<ul>\n<li><a href=\"https:\/\/github.com\/Cisco-Talos\/EvidenceForge\">EvidenceForge<\/a> \u2192 It is an open-source tool from Cisco Talos that generates realistic, multi-format synthetic security logs \u2013 including Windows events, Sysmon, Zeek, and more \u2013 with strong consistency and causal relationships. It\u2019s particularly useful for threat hunting training, detection testing, and research where you need high-quality, non-obvious synthetic data.<\/li>\n<li><a href=\"https:\/\/github.com\/facebook\/mcpguard-dynamic\">MCPGuard-Dynamic<\/a> \u2192 It is an open-source project from Facebook that provides kernel-level sandboxing for LLM agent tool calls using the Model Context Protocol (MCP). It combines policy enforcement, argument validation, and eBPF-based system call guards to restrict what potentially untrusted MCP servers can do \u2013 helping prevent file access, network exfiltration, and privilege escalation attempts.<\/li>\n<\/ul>\n<p><i>Disclaimer: This is strictly for research and learning. It hasn\u2019t been through a formal security audit, so don\u2019t just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you\u2019re doing stays on the right side of the law.<\/i><\/p>\n<h2 style=\"text-align: left;\"><b>Conclusion<\/b><\/h2>\n<p>That\u2019s the week: too much speed, too many defaults, and not enough people treating \u00abminor\u00bb exposed crap like it can become tomorrow\u2019s incident report. The pattern is boring until it\u2019s your box \u2013 attackers keep finding the cheap paths first, because cheap still works.<\/p>\n<p>Patch the loud stuff, audit the weird stuff, and don\u2019t ignore the boring stuff. That\u2019s usually where the fire starts.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>Monday hit like a cron job with anger issues. A busted auth path here, a repo-side faceplant there, some \u00abpatched-ish\u00bb thing already getting chewed on in the wild, and then the usual bonus round: poisoned dev tools, sketchy forum chatter, phishing kits pretending to be productivity, and AI lowering the bar for people who already [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,5],"tags":[2263,114,24,633,2822,15,360,2314,365],"class_list":["post-1034","post","type-post","status-publish","format-standard","hentry","category-noticias","category-trending","tag-aipowered","tag-attacks","tag-cyberdefensa-mx","tag-exploit","tag-flaw","tag-linux","tag-oauth","tag-panos","tag-phishing"],"_links":{"self":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/posts\/1034","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/comments?post=1034"}],"version-history":[{"count":0,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/posts\/1034\/revisions"}],"wp:attachment":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/media?parent=1034"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/categories?post=1034"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/tags?post=1034"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}