{"id":1884,"date":"2026-08-03T15:50:39","date_gmt":"2026-08-03T15:50:39","guid":{"rendered":"https:\/\/cybercolombia.co\/index.php\/2026\/08\/03\/rogue-ai-models-88m-bitcoin-theft-water-system-attacks-and-dangling-dns-hijacks-cyberdefensa-mx\/"},"modified":"2026-08-03T15:50:39","modified_gmt":"2026-08-03T15:50:39","slug":"rogue-ai-models-88m-bitcoin-theft-water-system-attacks-and-dangling-dns-hijacks-cyberdefensa-mx","status":"publish","type":"post","link":"https:\/\/cybercolombia.co\/index.php\/2026\/08\/03\/rogue-ai-models-88m-bitcoin-theft-water-system-attacks-and-dangling-dns-hijacks-cyberdefensa-mx\/","title":{"rendered":"Rogue AI Models, $88M Bitcoin Theft, Water-System Attacks and Dangling DNS Hijacks \u2013 CYBERDEFENSA.MX"},"content":{"rendered":"<div id=\"articlebody\">\n<p>This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended.<\/p>\n<p>Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, poisoned dependencies, weak defaults, and tooling that moved from forum chatter to real targets.<\/p>\n<p>The full weekly recap report follows.<\/p>\n<h2 style=\"text-align: left;\"><strong>\u26a1 Threat of the Week<\/strong><\/h2>\n<p><strong>Anthropic Disclosed its Models Targeted 3 Organizations <\/strong>\u2013 Anthropic revealed that three of its models, including Claude Opus 4.7, Mythos 5, and an unnamed research model, breached three unnamed organizations during cybersecurity testing without its knowledge. The AI firm said the earliest incidents date back to April 2026, adding it made the discoveries after launching a \u00ablarge-scale retrospective review\u00bb in response to the recent Hugging Face incident. \u00abAfter reviewing 141,006 evaluation runs where Claude could have obtained internet access, we identified three incidents in which a model accessed the internet from within or while interacting with the evaluation environment of Irregular, one of our third-party evaluation partners, and then gained unauthorized access to the production infrastructure of three different organizations,\u00bb it said.<\/p>\n<h2 style=\"text-align: left;\"><strong>\ud83d\udd14 Top News<\/strong><\/h2>\n<ul>\n<li><strong><a href=\"https:\/\/thehackernews.com\/2026\/08\/coldcard-hardware-wallet-flaw-linked-to.html\" target=\"_blank\">Coldcard Hardware Wallet Flaw Linked to $88.6M Bitcoin Theft <\/a><\/strong>\u2013 A vulnerability in Coldcard hardware wallet firmware is said to have been exploited to steal an estimated $88.6 million in Bitcoin from thousands of wallets whose seed phrases were generated using a flawed random number generator. \u00abColdcard firmware contains an RNG integration error that causes ngu.random to use MicroPython\u2019s deterministic Yasmarang fallback instead of the STM32 hardware RNG,\u00bb Square Engineering <a href=\"https:\/\/engineering.block.xyz\/blog\/predictable-rng-fallback-and-32-bit-reseed-in-coldcard-firmware\" target=\"_blank\">said<\/a>. \u00abThis does not mean every remote attacker can immediately recover every seed. Practical cost depends on available UID information, boot timing, prior RNG calls, and derivation cost.\u00bb<\/li>\n<li><strong>Russian Hackers Exploit Microsoft OWA Flaw to Maintain Mailbox Access <\/strong>\u2013 Russian threat actors exploited a security flaw in Microsoft Outlook Web Access (OWA), to target U.S. and European government entities, as well as the telecommunications, financial, hospitality, and aerospace sectors. The activity, which began on July 22, 2026, involves the weaponization of CVE-2026-42897 (CVSS score: 8.1), a cross-site scripting (XSS) vulnerability in OWA. It was flagged by Microsoft as having been exploited in attacks as far back as May 2026. The activity has been attributed to Laundry Bear. The new wave of exploitation revolving around CVE-2026-42897 culminates with the deployment of a previously unknown JavaScript browser-based implant codenamed OWAReaper that\u2019s specifically built for persistent access within Microsoft\u2019s webmail client.<\/li>\n<li><strong>Critical Rails Flaw Leads to Arbitrary File Read <\/strong>\u2013 Ruby on Rails shipped patches for a critical Active Storage vulnerability (CVE-2026-66066, CVSS score: 9.5) that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads. The flaw can be exploited to expose Rails process environment and secrets such as secret_key_base, master key, database passwords, cloud storage credentials, and API tokens, which may enable remote code execution or lateral movement into connected systems. CVE-2026-66066 is exploitable when libvips is used, enabling an attacker to upload a specially crafted image to a vulnerable application and read arbitrary files on the server. A key prerequisite for the attack is that the server must allow image uploads from untrusted users. Additional details of the flaw have been <a href=\"https:\/\/discuss.rubyonrails.org\/t\/cve-2026-66066-attack-details-and-tools-to-perform-a-forensic-investigation\/91441\" target=\"_blank\">released<\/a> by the Rails team, along with tools to <a href=\"https:\/\/github.com\/rails\/rails-forensics-CVE-2026-66066\" target=\"_blank\">help assess<\/a> vulnerable applications. \u00abBecause this vulnerability requires no authentication and targets the default image processor in modern Rails environments, it is essential to apply vendor patches and rotate secrets immediately,\u00bb Akamai <a href=\"https:\/\/www.akamai.com\/blog\/security-research\/rails-active-storage-rce-cve-2026-66066\" target=\"_blank\">said<\/a>.<\/li>\n<li><strong>Coordinated Attacks Target 30+ Minnesota Water Systems <\/strong>\u2013 A <a href=\"https:\/\/mn.gov\/mnit\/media\/blog\/?id=761869\" target=\"_blank\">coordinated cyber attack campaign<\/a> targeted over 30 water systems in Minnesota on July 26 and 27, 2026. \u00abThe nature and extent of the impact varied by system, and the investigation is still determining how many experienced operational disruptions,\u00bb Minnesota IT Services (MNIT) said. The activity has not been <a href=\"https:\/\/apnews.com\/article\/cyberattack-minnesota-water-systems-5bb1dcbaab8e3231889700c38a21e8ea\" target=\"_blank\">officially attributed<\/a> to any known threat actor, although <a href=\"https:\/\/www.nytimes.com\/2026\/07\/30\/us\/politics\/minnesota-water-cyberattack-iran.html\" target=\"_blank\">Iranian threat actors<\/a> have been previously implicated in similar attacks targeting water facilities in the U.S. \u00abAt this time, there are no active requests from Minnesota communities for residents to modify their drinking water use,\u00bb MNIT <a href=\"https:\/\/mn.gov\/mnit\/media\/blog\/?id=761869#\/detail\/appId\/1\/id\/762209\" target=\"_blank\">added<\/a>. The development has prompted the U.S. government to <a href=\"https:\/\/www.cisa.gov\/news-events\/alerts\/2026\/07\/30\/cisa-urges-water-and-wastewater-systems-sector-protect-ot-against-activity-targeting-plcs\" target=\"_blank\">issue an advisory<\/a>, urging \u00abcritical infrastructure owners, operators, and integrators to remove publicly exposed PLCs and other operational technology (OT) from the internet as soon as possible.\u00bb Threat actors targeting exposed PLCs have modified passwords to lock out operators and disconnected the PLCs by changing their IP addresses, resulting in boil water notices and sustained manual operations. Organizations are advised to disconnect the PLC from the internet, enable password protection and change default passwords, and allowlist IPs to only allow remote access from known engineering laptops or other critical OT assets. Censys <a href=\"https:\/\/censys.com\/blog\/cisa-alert-water-tower-plc-targeting\/\" target=\"_blank\">said<\/a> it identified 4,148 internet-exposed hosts that respond to EtherNet\/IP and self-identify as Rockwell Automation\/Allen-Bradley, with more than 70% of them located in the U.S. Similarly, there are 4,117 internet-exposed hosts that fingerprint as Siemens SIMATIC S7-1200 and 2,072 internet-exposed hosts that fingerprint as Schneider Electric hardware. Over the weekend, Michigan <a href=\"https:\/\/apnews.com\/article\/cyberattack-minnesota-water-systems-77d52a1d7356e608500a1ddb0ec373a6\" target=\"_blank\">reported<\/a> cyber attacks on nine of the state\u2019s water systems but an official told Associated Press that all systems were operating \u00absafely.\u00bb The campaign underscores the escalating threat to poorly protected operational technology (OT) assets from adversaries seeking to disrupt critical infrastructure services across the U.S. and elsewhere.<\/li>\n<li><strong>Hijacked Wi-Fi Networks Lead to CornFlake Malware <\/strong>\u2013 Storm-2945, a sub-cluster associated with Midnight Blizzard (aka APT29), has been conducting \u00abwidespread but targeted traffic manipulation attacks\u00bb involving hospitality sector networks served by captive portals across the world. The campaign, ongoing since May 2026, has been codenamed CaptiveCrunch by Microsoft. This involves manipulating DNS and HTTP traffic from networks served by captive portals to redirect user traffic through actor-controlled infrastructure. \u00abAs part of the CaptiveCrunch campaign, Storm-2945 has leveraged their AitM position to redirect users through actor-controlled phishing infrastructure and has also delivered malware purporting to be browser or operating system updates in response to automated connectivity checks issued by users\u2019 browsers,\u00bb Microsoft said. This includes a fully-featured Windows remote access trojan (RAT) called CornFlake with capabilities to conduct system enumeration, collect files and keystrokes, steal credentials and session tokens, conduct audio and video surveillance, monitor for removable media, and provide the threat actor a remote shell on infected systems. Also delivered via the trojan is a PowerShell-based infostealer called ChocoShell to harvest browser session cookies, saved passwords, Microsoft 365 Single Sign-On (SSO) tokens, and Wi-Fi credentials from compromised systems. The campaign is orchestrated via a web-based C2 panel called FruitStone. The infrastructure employs a variety of ClickFix techniques to trick the victim into downloading and executing the malware. There is also evidence indicating that the attackers are using similar ClickFix landings for Android devices to download and install an APK file. As of July 16, 2026, a portion of CaptiveCrunch landing pages have been found to redirect users to device code authentication flow experiences.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><strong>\u200e\ufe0f\ud83d\udd25 Trending CVEs<\/strong><\/h2>\n<p>Bugs drop weekly, and the gap between a patch and an exploit is shrinking fast. These are the heavy hitters for the week: high-severity, widely used, or already being poked at in the wild.<\/p>\n<p>Check the list, patch what you have, and hit the ones marked urgent first \u2013 CVE-2026-48449 (Adobe Campaign Classic), CVE-2026-18556, CVE-2026-18577 (N-able N-central), CVE-2026-44827, CVE-2026-45804, CVE-2026-44513 (Hugging Face Diffusers), CVE-2026-17583 (Thermo Fisher Scientific), CVE-2026-66066 (Rails), CVE-2026-10702 (Mozilla Firefox), CVE-2026-60004, <a href=\"https:\/\/github.com\/go-gitea\/gitea\/security\/advisories\/GHSA-xxjv-752h-3vp2\" target=\"_blank\">CVE-2026-58443<\/a> (Gitea), CVE-2026-63077, CVE-2026-59792, CVE-2026-59793, CVE-2026-59794, CVE-2026-59795, CVE-2026-59796 (JetBrains TeamCity), CVE-2026-61511 (vBulletin), <a href=\"https:\/\/karmainsecurity.com\/KIS-2026-13\" target=\"_blank\">CVE-2026-53264<\/a> (Linux Kernel), CVE-2026-53921 (OpenWrt), <a href=\"https:\/\/support.apple.com\/en-us\/100100\" target=\"_blank\">CVE-2026-64765, CVE-2026-64766, CVE-2026-64764, CVE-2026-64763, CVE-2026-43776, CVE-2026-43818, CVE-2026-28981<\/a> (Apple iOS and macOS), <a href=\"https:\/\/www.vulncheck.com\/advisories\/libssh2-heap-buffer-overflow-via-etm-cipher-negotiation\" target=\"_blank\">CVE-2026-66032, CVE-2026-66033, CVE-2026-66034, CVE-2026-66035<\/a> (libssh2), <a href=\"https:\/\/community.progress.com\/s\/article\/LoadMaster-Critical-Security-Bulletin-July-2026-CVE-2026-59686-CVE-2026-59687-CVE-2026-59688-CVE-2026-59689-CVE-2026-59690\" target=\"_blank\">from CVE-2026-59686 through CVE-2026-59690<\/a> (Progress Kemp LoadMaster), from CVE-2026-66036 through CVE-2026-66041 (FFmpeg), <a href=\"https:\/\/www.vulncheck.com\/advisories\/phpmyfaq-before-remote-code-execution-via-configuration-api\" target=\"_blank\">CVE-2026-66398<\/a> (phpMyFAQ), <a href=\"https:\/\/github.com\/vercel\/next.js\/security\/advisories\" target=\"_blank\">CVE-2026-64645, CVE-2026-64649, CVE-2026-64642, CVE-2026-64641<\/a> (Next.js), <a href=\"https:\/\/nvd.nist.gov\/vuln\/detail\/CVE-2026-13385\" target=\"_blank\">CVE-2026-13385<\/a> (ASUS), <a href=\"https:\/\/chromereleases.googleblog.com\/2026\/07\/stable-channel-update-for-desktop_01320465736.html\" target=\"_blank\">from CVE-2026-16804 through CVE-2026-16807<\/a> (Google Chrome), <a href=\"https:\/\/github.com\/kimai\/kimai\/security\/advisories\/GHSA-jr9p-4h4j-6c58\" target=\"_blank\">CVE-2026-52824<\/a> (Kimai), <a href=\"https:\/\/support.citrix.com\/support-home\/kbsearch\/article?articleNumber=CTX696734&amp;articleURL=Citrix_Secure_Access_Client_for_Windows_and_Citrix_Endpoint_Analysis_Client_for_Windows_Security_Bulletin_for_CVE_2026_53565_and_CVE_2026_53566\" target=\"_blank\">CVE-2026-53565, CVE-2026-53566<\/a> (Citrix Secure Access Client for Windows and Citrix Endpoint Analysis Client for Windows), <a href=\"https:\/\/www.tp-link.com\/us\/support\/faq\/5192\/\" target=\"_blank\">CVE-2026-9770, CVE-2026-13230<\/a> (TP-Link Kasa EC70 v4 and EC71 v4 smart cameras), <a href=\"https:\/\/www.zerodayinitiative.com\/advisories\/ZDI-26-401\/\" target=\"_blank\">CVE-2026-15682<\/a> (AnyDesk), <a href=\"https:\/\/www.dell.com\/support\/kbdoc\/en-us\/000481268\/dsa-2026-278-security-update-for-dell-powerprotect-data-domain-multiple-vulnerabilities\" target=\"_blank\">CVE-2026-53481, CVE-2026-53483<\/a> (Dell PowerProtect Data Domain), <a href=\"https:\/\/community.notepad-plus-plus.org\/topic\/27604\/notepad-release-8.9.7\" target=\"_blank\">CVE-2026-52886, CVE-2026-54758, CVE-2026-57233<\/a> (Notepad++), <a href=\"https:\/\/patchstack.com\/database\/wordpress\/plugin\/miniorange-oauth-oidc-single-sign-on\/vulnerability\/wordpress-oauth-single-sign-on-sso-oauth-client-plugin-38-5-8-broken-authentication-vulnerability\" target=\"_blank\">CVE-2026-57807<\/a> (miniOrange OAuth Single Sign On \u2013 SSO WordPress plugin), <a href=\"https:\/\/documentation.solarwinds.com\/en\/success_center\/servu\/content\/release_notes\/servu_2026-3_release_notes.htm\" target=\"_blank\">CVE-2026-28302, from CVE-2026-28304 through CVE-2026-28317, CVE-2026-28321<\/a> (SolarWinds Serv-U), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/141367\" target=\"_blank\">CVE-2026-16771<\/a> (AT&amp;T Arris BGW210-700), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/293714\" target=\"_blank\">CVE-2026-13723<\/a> (Develar), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/305509\" target=\"_blank\">CVE-2026-16637<\/a> (OPeNDAP Hyrax), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/281278\" target=\"_blank\">CVE-2026-15969, CVE-2026-15971, CVE-2026-15974, CVE-2026-15976, CVE-2026-15977, CVE-2026-15978<\/a> (SGLang), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/790363\" target=\"_blank\">CVE-2026-15657, CVE-2026-15658<\/a> (foreUP), <a href=\"https:\/\/kb.cert.org\/vuls\/id\/243636\" target=\"_blank\">CVE-2026-16503, CVE-2026-16504<\/a> (VPS.org), <a href=\"https:\/\/helpx.adobe.com\/security\/products\/bridge\/apsb26-89.html\" target=\"_blank\">CVE-2026-48395, CVE-2026-48396<\/a> (Adobe Bridge), <a href=\"https:\/\/embracethered.com\/blog\/posts\/2026\/pipewire-flatpak-linux-sandbox-escape-cve-2026-5674\/\" target=\"_blank\">CVE-2026-5674<\/a> (PipeWire PulseAudio), <a href=\"https:\/\/www.catchify.sa\/post\/pre-auth-rce-unifi-os-one-request-to-root\" target=\"_blank\">CVE-2026-34909<\/a> (Ubiquiti UniFi OS), and <a href=\"https:\/\/escape.tech\/blog\/escape-research-pii-disclosure-keycloak-cve-2026-17059\/\" target=\"_blank\">CVE-2026-17059<\/a> (keycloak-services).<\/p>\n<h2 style=\"text-align: left;\"><strong>\ud83c\udfa5 Cybersecurity Webinars<\/strong><\/h2>\n<ul>\n<li><strong><a href=\"https:\/\/thehacker.news\/ai-threat-readiness\" target=\"_blank\">AI Can Build Exploits in Minutes. Can Your Security Team Keep Up?<\/a><\/strong> \u2192 AI is collapsing the time between vulnerability disclosure and attack. Advanced models can now uncover flaws, generate working exploits, and chain them into complete attack paths at machine speed. This webinar presents a practical framework for gaining the visibility, context, and response speed needed to investigate and stop threats before attackers pull ahead.<\/li>\n<li><strong><a href=\"https:\/\/thehacker.news\/ai-coding-risk\" target=\"_blank\">How to Control the Open-Source Security Debt Created by AI Coding Tools<\/a><\/strong> \u2192 Learn how AI coding tools are expanding unvetted open-source use, accelerating vulnerability backlogs, and weakening existing governance. This webinar shows how to measure the resulting remediation debt, connect it to breach, audit, and productivity risks, and identify which governance models can contain it without slowing development.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><strong>\ud83d\udcf0 Around the Cyber World<\/strong><\/h2>\n<ul>\n<li><strong>Now-Patched Gitea Flaw Detailed <\/strong>\u2013 NoScope shared additional technical details of a security flaw in Gitea (CVE-2026-27771, CVSS score: 8.2) that was patched back in May 2026. The vulnerability allowed unauthenticated remote attackers to pull private container images from Gitea deployments without requiring an account, password, or other credentials. \u00abGitea\u2019s container registry implements the OCI Distribution Specification, which authenticates clients with a bearer token issued by a dedicated token service. On affected versions, that token service issued a valid, signed JWT to requesters presenting no credentials at all,\u00bb NoScope <a href=\"https:\/\/www.noscope.com\/blog\/how-noscope-found-the-gitea-flaw\" target=\"_blank\">said<\/a>. \u00abThe token was honest about what it represented, carrying UserID: -1 and an empty Scope, but no registry read endpoint ever consulted those fields. Catalog listing, tag enumeration, manifest retrieval and blob download all accepted it. Any unauthenticated party on the internet could enumerate every container repository on an instance, including those marked private, and pull their layers.\u00bb<\/li>\n<li><strong>SQLite Critical CVEs or AI Slop? <\/strong>\u2013 JFrog said it <a href=\"https:\/\/research.jfrog.com\/post\/sqlite-critical-cves-or-llm-slops\/\" target=\"_blank\">uncovered<\/a> a set of SQLite CVEs (CVE-2026-51302, CVE-2026-51303, CVE-2026-51300, CVE-2026-51297, CVE-2026-51296, and CVE-2026-51304) that seem to be instances of AI-generated slop making their way into official vulnerability feeds and receiving critical severity scores before technical validation. The analysis found that the advisories referenced functions that didn\u2019t exist in the affected SQLite versions, cited incorrect or impossible source code locations, included PoCs that failed to reproduce any vulnerability, and, most importantly, were not listed on SQLite\u2019s official CVE page. The findings show that organizations must take steps to distinguish legitimate vulnerabilities from questionable or AI-generated vulnerability reports before initiating unnecessary remediation, patching efforts, or automated security workflows.<\/li>\n<li><strong>LegacyHive Flaw Detailed <\/strong>\u2013 LevelBlue published a technical breakdown of LegacyHive, a PoC released by Chaotic Eclipse (aka Nightmare-Eclipse) last month coinciding with the release of Microsoft\u2019s Patch Tuesday update. The <a href=\"https:\/\/www.levelblue.com\/blogs\/spiderlabs-blog\/legacyhive-nightmare-eclipses-latest-zero-day-drop-with-a-stripped-poc\" target=\"_blank\">vulnerability<\/a> is a Local Privilege Escalation (LPE) vulnerability affecting Windows User Profile, a component responsible for loading and unloading Windows user profiles. On exploitation, LegacyHive can allow attackers to load other users\u2019 hives and gain access to application data and Windows Explorer history, among others. \u00abFor EDR platforms with visibility into native Windows APIs, the strongest signals are user-mode invocations of NtCreateDirectoryObjectEx and NtCreateSymbolicLinkObject,\u00bb LevelBlue <a href=\"https:\/\/www.levelblue.com\/blogs\/spiderlabs-blog\/legacyhive-hunting-windows-profile-initialization-abuse-through-offline-registry-manipulation\" target=\"_blank\">said<\/a>. \u00abThese functions are rarely used outside system components, debugging tools, or specialized research utilities. Seeing both from the same process should immediately warrant investigation. Even without NT API telemetry, LegacyHive leaves a distinctive execution chain. The attack combines offline access to ntuser.dat or UsrClass.dat, modification of registry hives through Microsoft\u2019s Offline Registry API, batch oplock requests, and CreateProcessWithLogonW using LOGON_WITH_PROFILE. Each operation is legitimate in isolation but observing them together within a short time window is highly unusual and well suited for behavioral correlation by EDR and SIEM platforms.\u00bb<\/li>\n<li><strong>Chinese Military Taps Into U.S. Models <\/strong>\u2013 According to a <a href=\"https:\/\/www.reuters.com\/world\/asia-pacific\/chinese-military-researchers-tap-us-ai-models-train-defence-systems-2026-07-31\/\" target=\"_blank\">new report<\/a> from Reuters, Chinese military researchers have distilled cutting-edge models developed by U.S. companies OpenAI and Anthropic to train domestic AI systems to advance the country\u2019s defense capabilities. The report was based on a review of more than 80 Chinese academic papers and patents.<\/li>\n<li><strong>Exposed Police Dashboard Lays Bare How China Tracks Foreigners <\/strong>\u2013 An internet-exposed police dashboard named \u00abDynamic Control Platform for Overseas Personnel\u00bb has revealed how law enforcement agencies in the country track over 700 foreigners, including those in the northern Chinese city of Zhangjiakou. \u00abIn total, it had entries for nearly 12,000 people, which included fugitives, people from Hong Kong and Taiwan, as well as more than 300 foreign journalists,\u00bb The New York Times <a href=\"https:\/\/www.nytimes.com\/2026\/08\/02\/world\/asia\/china-surveillance-foreigners-database.html\" target=\"_blank\">reported<\/a>. \u00abSome of them had not been to Zhangjiakou.\u00bb The dashboard displayed entries about people grouped by nationality, with their birth date, sex, marital status, address and occupation, and sometimes their religion. The leak was discovered by security researcher and journalist Marc Hofer. The system is believed to be developed by a Beijing company named Origin Dynamic, which filed a patent application in 2023 for a similar \u00abinformation interface for non-Chinese citizens.\u00bb<\/li>\n<li><strong>The Problem of DangleGeddon <\/strong>\u2013 Cybersecurity researchers have once again <a href=\"https:\/\/www.silentpush.com\/blog\/danglegeddon\/\" target=\"_blank\">warned<\/a> of the risks posed by dangling DNS infrastructure across government, banking, automotive, manufacturing, and pharmaceutical sectors. A dangling DNS record is an active Domain Name System entry (DNS) that points to a resource no longer owned, used, or controlled by the original organization. This typically occurs when web applications, cloud storage, or virtual servers are deleted without first removing their corresponding CNAME or A records from the domain registrar. An attacker can leverage this behavior to claim that abandoned cloud service name or IP address, effectively <a href=\"https:\/\/learn.microsoft.com\/en-us\/azure\/security\/fundamentals\/subdomain-takeover\" target=\"_blank\">hijacking a trusted subdomain<\/a>. This, in turn, can permit the attacker to host malicious content and serve phishing pages or malware, inflict reputational damage by abusing the trusted brand\u2019s subdomain, steal user credentials to create convincing phishing pages that appear to be legitimate services, perform cookie theft, and bypass security controls if the legitimate brand\u2019s subdomain is allowlisted in security tools. In one case analyzed by Silent Push, an unspecified automotive company left a dangling DNS record pointing to a developmental application gateway hosted by an Azure virtual machine (VM). \u00abThis device can potentially be operationalized and passively receive stored XSS from internal scripts and API calls,\u00bb it said. \u00abDevelopers\u2019 credentials, like API keys and authentication headers, could be harvested for reuse to expand access into the company. In addition, the VM could serve as a platform for malware hosting with the coveted TLS lock.\u00bb<\/li>\n<li><strong>Microsoft Teams Vishing Leads to Chaos Ransomware <\/strong>\u2013 A Microsoft Teams voice phishing (vishing) campaign tracked as STAC4749 has used a \u00abconsistent set of IT-themed cloud domains and personas to gain remote access to victims\u2019 systems\u00bb between February and June 2026 in attacks targeting dozens of North American organizations. \u00abFollowing initial access, STAC4749 operators deployed a modular post-exploitation toolset, including a custom loader and backdoor to maintain persistent, controlled access and support follow-on activity,\u00bb Sophos <a href=\"https:\/\/www.sophos.com\/en-us\/blog\/chaos-in-teams-vishing\" target=\"_blank\">said<\/a>. \u00abIn several incidents, attackers later leveraged this access to deploy Chaos ransomware.\u00bb\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjcG7QvDiBQ8UfedCoIPwM8jzK2wvb1_mX4HrGjLGzPmUacDZWRxWIzqBYatQIp2Dp_R_igixw_bEcX5kAZ17lIQ6pur9i5kyCmeosxgVF1MiGRbp9c2hq6FLRLwdjkigNzYhO1BaINzDWwroC4OYzb0XJlbljk7bybEyaHF7ZJBpoFI8Lj1ZWiCxQOyLju\/s1700-e365\/sta.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjcG7QvDiBQ8UfedCoIPwM8jzK2wvb1_mX4HrGjLGzPmUacDZWRxWIzqBYatQIp2Dp_R_igixw_bEcX5kAZ17lIQ6pur9i5kyCmeosxgVF1MiGRbp9c2hq6FLRLwdjkigNzYhO1BaINzDWwroC4OYzb0XJlbljk7bybEyaHF7ZJBpoFI8Lj1ZWiCxQOyLju\/s1700-e365\/sta.png\" alt=\"\" border=\"0\" data-original-height=\"499\" data-original-width=\"941\"\/><\/a><\/div>\n<\/li>\n<li><strong>IAB Uses Teams Phishing for Ransomware Attacks <\/strong>\u2013 A suspected initial access broker (IAB) for ransomware attacks has been observed using Teams vishing that convinces victims to launch a Quick Assist remote support session. The initial access is used to run PowerShell scripts to gather host information and deploy a Go-based backdoor dubbed GoGRPC. Four different versions of the backdoor have been spotted: Lep, Giver, Pet, and Kind. \u00abThese variants have overlapping capabilities but notable implementation differences,\u00bb Zscaler <a href=\"https:\/\/www.zscaler.com\/blogs\/security-research\/helpdesk-hijackers-teams-vishing-quick-assist-and-gogrpc-backdoor\" target=\"_blank\">said<\/a>. \u00abGoGRPC is actively evolving. Each variant modifies its payloads and capabilities, adding or removing functionality to better support the threat actor\u2019s objectives. Recent changes indicate an increased targeting of corporate environments, which may be tied to ransomware attacks.\u00bb In some instances, the threat actor has also deployed a backdoor called BlindDoor, a Go-based reverse SOCKS proxy known as RevSocket, and a Python-based reverse SOCKS proxy referred to as PyGRPC.<\/li>\n<li><strong>Arch Linux Disables AUR Package Adoption Amid Malware <\/strong>\u2013 Arch Linux has taken the step of temporarily disabling package adoption due to a <a href=\"https:\/\/discourse.ifin.network\/t\/new-aur-attack-prompts-adoption-lock\/698\" target=\"_blank\">surge in malicious takeovers<\/a> of existing packages. \u00abDue to the current influx of malicious package adoptions and follow-up commits made via the AUR, package adoption is currently disabled while we are handling the situation,\u00bb the maintainers <a href=\"https:\/\/lists.archlinux.org\/archives\/list\/aur-general@lists.archlinux.org\/thread\/DRDEU3JUSC72CB265XHXPFA3DFSLXPBP\/\" target=\"_blank\">said<\/a>. \u00abWe will send a follow-up once we\u2019re able to. In the meantime, feel free to report suspicious adoption events or commits that haven\u2019t been dealt with yet, and stay vigilant!\u00bb In June 2026, a separate campaign targeted AUR via more than 400 packages.<\/li>\n<li><strong>New Dolphin X Infostealer Spotted <\/strong>\u2013 A new infostealer called Dolphin X uses an AI behavioral profiler to score and prioritize infected users based on their application usage, browsing activity, and installed software to identify high-value victims and maximize profits. The malware targets more than 300 applications and attempts to exfiltrate browser passwords, cryptocurrency wallets, SSH keys, and cloud tokens. Dolphin X has been advertised on the cybercrime underground by a vendor using the alias Kontraktnik since May 2026. A lifetime subscription ranges from $1,140 for basic access to $3,420 for the full-featured version. \u00abA single archive can contain data from nine browsers, more than 100 wallet extensions, 65 desktop wallets, 10 password managers, and 30 cloud command-line tools,\u00bb Varonis <a href=\"https:\/\/www.varonis.com\/blog\/dolphin-x-stealer\" target=\"_blank\">said<\/a>. \u00abThis gives the malware potential access to everything from a victim\u2019s personal accounts to the credentials used to manage their employer\u2019s cloud environment.\u00bb<\/li>\n<li><strong>Attackers Turn to Microsoft\u2019s Trusted Login System for Phishing <\/strong>\u2013 Bad actors are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft\u2019s legitimate authentication infrastructure in phishing attacks, allowing them to bypass security controls. Check Point said it identified more than 200 phishing emails targeting users across approximately 120 organizations worldwide between June 25 and the second week of July 2026. \u00abThe messages impersonated Microsoft Teams task notifications from HR and directed recipients to a legitimate Microsoft sign-in page,\u00bb it <a href=\"https:\/\/blog.checkpoint.com\/email-security\/attackers-are-turning-microsofts-trusted-login-system-into-their-latest-phishing-weapon\/\" target=\"_blank\">said<\/a>. \u00abVictims were then prompted to grant permissions to an attacker-controlled application, allowing the campaign to abuse Microsoft\u2019s trusted authentication flow while concealing its malicious intent.\u00bb<\/li>\n<li><strong>FBI Arrests Man Accused of Using Steam Games to Drain Victims\u2019 Crypto Wallets <\/strong>\u2013 The U.S. Federal Bureau of Investigation (FBI) <a href=\"https:\/\/techcrunch.com\/2026\/07\/17\/fbi-arrests-man-accused-of-using-steam-games-to-drain-victims-crypto-wallets\/\" target=\"_blank\">arrested<\/a> Zyaire Wilkins, a 21-year-old Florida resident and student, of uploading fake video games that contained malware to Steam that, when downloaded and installed by unsuspecting gamers, stole their passwords and other valuable data, and drained their cryptocurrency wallets. Per the FBI, Wilkins and his accomplices are alleged to have infected around 8,000 victims, and then hacked around 80 cryptocurrency wallets to steal at least $220,000 worth of cryptocurrency.<\/li>\n<li><strong>Turning Keystroke Noise to Text <\/strong>\u2013 A new study from a group of academics from Tohoku University has demonstrated a new acoustic side-channel attack that can reconstruct text typed on a laptop by just analyzing the sound of keystrokes. While prior attacks relied on collecting labeled recordings from the target keyboard beforehand or required specialized hardware, the latest eavesdropping attack enables stealthy eavesdropping in two real-world scenarios, including physical spaces (public and semi-public) and online meetings. The system works by first isolating individual keystrokes from an audio recording, grouping similar sounds together, and then using a Transformer-based language model to determine the most likely sequence of characters. \u00abOur method combines unsupervised acoustic clustering with Transformer-based language model inference and iterative self-training, enabling stable character inference under highly uncertain acoustic-to-character mappings,\u00bb the researchers <a href=\"https:\/\/arxiv.org\/abs\/2607.22094\" target=\"_blank\">said<\/a>. \u00abWe demonstrate that the proposed method achieves over 99% reconstruction accuracy with only 100-150 observed keystrokes under a close-proximity recording setup using a smartphone placed near the target device, significantly outperforming prior unsupervised baselines in low-data regimes.\u00bb<\/li>\n<li><strong>Two Open-Source Software Supply Chain Attack Campaigns <\/strong>\u2013 Socket has flagged a fake corepack.org site that\u2019s impersonating Corepack, a Node.js tool for managing package managers, and using it as a lure to deliver an infostealer and proxyware to developers who download it. \u00abThe site has existed in some form since early 2026 as a low-quality, apparently AI-generated imitation, but it recently started serving executable downloads,\u00bb Socket <a href=\"https:\/\/socket.dev\/blog\/fake-corepack-site-distributes-infostealer-and-proxyware\" target=\"_blank\">said<\/a>. \u00abCorepack is not distributed as a Windows installer, and the real project has no official website at corepack.org. Any download offered there should be treated as malicious.\u00bb It\u2019s assessed that the site is AI-generated. In a related development, JFrog identified a massive set of 148 npm packages that are disguised as student web proxies, but hide mutable remote code execution vectors and a high-performance Wisp-compatible WebSocket traffic generator. \u00abThey were designed to silently enlist visiting browsers into distributed denial-of-service botnets while generating aggressive popunder advertising revenue,\u00bb it <a href=\"https:\/\/research.jfrog.com\/post\/lucide-proxy-npm-malware-campaign\/\" target=\"_blank\">said<\/a>. Some aspects of the campaign were <a href=\"https:\/\/safedep.io\/malicious-npm-terminal3airport-proxy-adware-spam\/\" target=\"_blank\">highlighted<\/a> by SafeDep in late May 2026.<\/li>\n<li><strong>AI linked to more than half of cybercrime in Africa <\/strong>\u2013 A new report from INTERPOL has found that AI is enabling 55% of reported cybercrimes across Africa, making attacks faster, more scalable, and increasingly difficult for victims and platforms to detect. This encompasses digital sextortion and online harassment, as well as sophisticated business email compromise (BEC) schemes. \u00abThe absence of real-time, inter-agency data sharing between banks, telecoms and law enforcement creates a dangerous blind spot in efforts to combat financial fraud,\u00bb INTERPOL <a href=\"https:\/\/www.interpol.int\/en\/News-and-Events\/News\/2026\/INTERPOL-report-finds-AI-linked-to-more-than-half-of-cybercrime-in-Africa\" target=\"_blank\">said<\/a>. \u00abThis vulnerability is being exploited by criminals who have moved beyond simply stealing existing credentials to creating entirely synthetic identities. Combining real personal data with fabricated elements, these AI-generated digital personas can bypass even advanced biometric verification systems and have been used to open bank accounts, secure mobile loans and register SIM cards under false names.\u00bb<\/li>\n<li><strong>Security Risks of Exposed MCP Servers <\/strong>\u2013 Google-owned Wiz has warned that enterprises are exposing Model Context Protocol (MCP) servers to the internet, with some of them returning full tool catalog to an anonymous caller, fetching real data, and revealing a sensitive backend. \u00abThese expose sensitive data like employee PII and internal business records, write and delete operations on production systems, and in some cases code execution and access to cloud credentials,\u00bb Wiz <a href=\"https:\/\/www.wiz.io\/blog\/the-risk-hiding-behind-exposed-mcp-servers\" target=\"_blank\">said<\/a>. \u00abThe protocol\u2019s first widely-used version shipped without an authentication mechanism. The spec added OAuth 2.1 in March 2025, but nearly all the servers we found still run the original version and don\u2019t use it. The pattern is the same across most of them: backend credentials baked into the deployment, a managed cloud endpoint that\u2019s internet-reachable by default, no auth layer added on top.\u00bb<\/li>\n<li><strong>Nuclear-Sabotage Malware Benchmark Trick Most Frontier AI Models <\/strong>\u2013 A multi-stage reverse-engineering benchmark developed by SentinelOne <a href=\"https:\/\/www.sentinelone.com\/labs\/frontier-models-tackle-autonomous-long-horizon-malware-analysis\/\" target=\"_blank\">tests<\/a> \u00abwhether a model can keep a malware investigation trustworthy as new evidence repeatedly invalidates its earlier conclusions,\u00bb in contrast to other AI benchmarks that test bounded tasks. Developed based on its own analysis of the Fast16 malware, the study found that \u00abOpenAI\u2019s GPT-5.6 Sol was the only publicly available model to complete the full eight-stage investigation, giving concrete shape to what \u2018Frontier-class\u2019 capabilities offer analysts.\u00bb That said, humans remain essential to define objectives, expose blind spots, and retain final publication authority.<\/li>\n<li><strong>An Open Directory Reveals NGINX Rift and Ghost CMS Exploits <\/strong>\u2013 An exposed directory on a Singapore-hosted VPS, 165.154.236[.]93, has been found to stage exploits for NGINX Rift (CVE-2026-42945), a long-standing heap overflow, and a blind SQL injection in the Ghost Content API (CVE-2026-26980), alongside Splunk, PaperCut, Samba, WebLogic, and D-Link NAS tooling. \u00abThe recovered shell history from the directory recorded the attacker running the exploits against live external infrastructure, using out-of-band (OOB) DNS callbacks to verify execution, and using the same server to catch reverse shells,\u00bb Hunt.io <a href=\"https:\/\/hunt.io\/blog\/open-directory-nginx-rift-ghost-cms-multi-cve\" target=\"_blank\">said<\/a>. \u00abAlongside the web exploits were a broader RCE toolkit and pre-staged install files for AdaptixC2 and SuperShell. The target list spanned eleven countries across five continents and leaned heavily toward high-value sectors: federal and state government, universities, healthcare and financial services.\u00bb The activity is believed to be the work of a Chinese-speaking threat actor.<\/li>\n<li><strong>CISA Issues Guidance to Isolate Vital Systems and Manage OSS Risks <\/strong>\u2013 The U.S. Cybersecurity and Infrastructure Security Agency (CISA) issued guidance to help critical infrastructure operators protect essential services from growing cyber threats and ensure continuity of operations during cyber incidents or geopolitical crises by maintaining robust isolation and recovery plans. \u00abState-sponsored cyber actors target critical infrastructure for several nefarious reasons such as espionage or service disruption, often linked to broader geopolitical conflicts,\u00bb CISA <a href=\"https:\/\/www.cisa.gov\/news-events\/news\/cisa-joins-australia-and-others-publish-guidance-isolate-operational-technology-and-enabling-systems\" target=\"_blank\">said<\/a>. \u00abDuring crises or conflicts, operators of critical infrastructure and network defenders may isolate essential operational technology (OT) systems as an emergency measure to prevent adversaries from executing cyberattacks, to contain ongoing threats, and to facilitate the restoration of compromised systems.\u00bb The agency has also <a href=\"https:\/\/www.cisa.gov\/news-events\/news\/cisa-guide-helps-federal-agencies-securely-and-effectively-use-open-source-software\" target=\"_blank\">outlined<\/a> considerations and best practices for federal entities to securely use, evaluate, and publish open-source software. \u00abThe guidance urges agencies to obtain sufficient transparency into all relevant components, including training data, of the AI system before deeming the product as OSS for risk management purposes,\u00bb it said. \u00abOnly with transparency and access can agencies understand and study the software, analyze it for vulnerabilities, and remediate any found vulnerabilities or risks.\u00bb\n<div class=\"separator\" style=\"clear: both;\"><a href=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjs9WQEJ2908NIYAw6wl3Akg496COozq8HN8tFf4OMiqRvjE-bkev4Rhp9Bsdh_71mNo4cibTXP9u8F48oe9dKO7esB8f39YclJIjl6CW2mT9wTW35pWTQWYmxptnmi2-GfrmGPCSUFBVD4sZdQlou8HGO2AZ1Avag7fXs6oS3cGUezKafWjcfk_CMNN-7d\/s1700-e365\/critical.png\" style=\"clear: left; display: block; float: left;  text-align: center;\"><img decoding=\"async\" src=\"https:\/\/blogger.googleusercontent.com\/img\/b\/R29vZ2xl\/AVvXsEjs9WQEJ2908NIYAw6wl3Akg496COozq8HN8tFf4OMiqRvjE-bkev4Rhp9Bsdh_71mNo4cibTXP9u8F48oe9dKO7esB8f39YclJIjl6CW2mT9wTW35pWTQWYmxptnmi2-GfrmGPCSUFBVD4sZdQlou8HGO2AZ1Avag7fXs6oS3cGUezKafWjcfk_CMNN-7d\/s1700-e365\/critical.png\" alt=\"\" border=\"0\" data-original-height=\"668\" data-original-width=\"1016\"\/><\/a><\/div>\n<\/li>\n<li><strong>RubyGems Cryptojacking Campaign <\/strong>\u2013 A set of 199 malicious gems published to RubyGems has been found to embed an identical XMRig cryptojacking payload to mine Monero cryptocurrency on developer systems. \u00abEach gem is a trojanized copy of a popular, legitimate Ruby library,\u00bb Palo Alto Networks Unit 42 <a href=\"https:\/\/github.com\/PaloAltoNetworks\/Unit42-timely-threat-intel\/blob\/main\/2026-07-22-RubyGems-Cryptojacking-Campaign.txt\" target=\"_blank\">said<\/a>. \u00abThe payload uses a 5-hour delayed Thread.new{sleep 18000; \u2026} trigger to evade sandbox analysis.\u00bb In addition to taking steps to achieve persistence via multiple methods, the malware uses SSH for lateral movement and is capable of infecting other ecosystems, including Node.js, Python, Docker, Git, and VS Code extensions. Mend.io, which also <a href=\"https:\/\/www.mend.io\/blog\/rubygems-cryptomining-campaign\/\" target=\"_blank\">shared<\/a> details of the campaign, said the payload is hidden inside a dotfile (lib\/.threadpool.rb) that standard directory scans skip by default.<\/li>\n<li><strong>Email Threat Landscape in Q2 2026 <\/strong>\u2013 Microsoft <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/07\/23\/email-threat-landscape-q2-2026-trends-and-insights\/\" target=\"_blank\">said<\/a> phishing volume linked to the Tycoon 2FA phishing platform, including QR code phishing and CAPTCHA-gated phishing, fell 92% from pre-disruption averages in the second quarter of 2026 between April and June. However, the tech giant said it \u00abobserved continued growth in Teams-based social engineering, particularly voice phishing (vishing), with weekly malicious call attempts reaching nearly ten times the mid-2025 baseline by the end of the quarter.\u00bb Microsoft said it detected approximately 7.6 billion email-based phishing threats throughout the quarter, with monthly volumes declining modestly from 2.7 billion in April to 2.4 billion in June. HTML and PDF attachments remained the two most common malicious payload types across the quarter, together accounting for roughly 60-70% of all payload-based attacks each month. In early June 2026, Microsoft said it detected a large-scale BEC campaign that reached more than 67,000 users across more than 42,000 organizations in under three hours, most of them in the U.S., with an aim to redirect salary payments to attacker-controlled bank accounts.<\/li>\n<\/ul>\n<h2 style=\"text-align: left;\"><strong>\ud83d\udd27 Cybersecurity Tools<\/strong><\/h2>\n<ul>\n<li><a href=\"https:\/\/github.com\/e-m-b-a\/emba\" target=\"_blank\">EMBA<\/a> \u2192 Firmware is where critical bugs hide longest because it is opaque, fragmented, and painful to inspect manually. EMBA turns that black box into an actionable security report: it extracts embedded-device firmware, runs static and emulation-based analysis, builds an SBOM, and flags outdated components, insecure binaries, vulnerable scripts, and hard-coded credentials through a command-line workflow with web-based reporting. Built for penetration testers, product-security teams, and developers, it compresses days of firmware triage into a repeatable open-source process.<\/li>\n<li><a href=\"https:\/\/github.com\/OpenVanta\/GrantGuard\" target=\"_blank\">GrantGuard<\/a> \u2192 Every \u00abalways allow\u00bb click in Claude Code can leave behind a standing permission that remains long after the task ends, with pasted API keys, credential-store access, unrestricted `git push`, or destructive commands buried in rarely reviewed settings. GrantGuard is an open-source, local-only tool that finds these accumulated grants, classifies them by risk, and lets users remove unsafe permissions through a browser interface or CLI, without sending settings off-device or loading third-party runtime packages.<\/li>\n<\/ul>\n<p><em>Disclaimer: This is strictly for research and learning. It hasn\u2019t been through a formal security audit, so don\u2019t just blindly drop it into production. Read the code, break it in a sandbox first, and make sure whatever you\u2019re doing stays on the right side of the law.<\/em><\/p>\n<h2 style=\"text-align: left;\"><strong>Conclusion<\/strong><\/h2>\n<p>The useful question is not whether a system is exposed. It is which quiet assumption lets it reach farther than intended: a default, a trusted workflow, an abandoned endpoint, or code nobody checked.<\/p>\n<p>That is where the next incident is probably waiting. Not in the loudest alert, but in the handoff everyone assumes belongs to someone else. Check the boundaries. Then check what crosses them.<\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>This week kept coming back to permission. A model crossed a boundary. A wallet trusted bad randomness. Webmail kept an intruder around. Public systems, package feeds, hotel networks, and login flows all gave away more than intended. Some of it was clever. Most of it was just access left lying around: old bugs, exposed gear, [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":1885,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[25,5],"tags":[4183,114,4184,24,4187,1639,4188,4182,929,4185,4186],"class_list":["post-1884","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-noticias","category-trending","tag-88m","tag-attacks","tag-bitcoin","tag-cyberdefensa-mx","tag-dangling","tag-dns","tag-hijacks","tag-models","tag-rogue","tag-theft","tag-watersystem"],"_links":{"self":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/posts\/1884","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/comments?post=1884"}],"version-history":[{"count":0,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/posts\/1884\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/media\/1885"}],"wp:attachment":[{"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/media?parent=1884"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/categories?post=1884"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cybercolombia.co\/index.php\/wp-json\/wp\/v2\/tags?post=1884"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}