Threats Affecting Spain
View all threats affecting or targeting Spain. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Spain
Click on any threat for detailed analysis and mitigation recommendations
0 A previously unknown modular multi-stage framework named MovieReaper has been discovered targeting users through compromised torrent files. Attackers compromised the public torrent repository itorrents[.]org, enabling them to distribute malicious loaders disguised as popular movies, including "The Odyssey." The campaign began in mid-August 2026 and affected hundreds of victims across multiple countries. The malware employs a sophisticated infection chain with fileless execution, utilizing blockchain network Solana for C2 infrastructure resilience. The framework includes multiple stages: an initial loader with anti-sandbox checks, shellcode that retrieves C2 addresses from Solana blockchain, UAC bypass with persistence mechanisms, and a final file manager module providing comprehensive file system access. The campaign demonstrates advanced evasion techniques including manual API resolution, vectored exception handling, and in-memory execution. Join the discussion | CVE Database V5 | 09/17/2026, 16:23:20 UTC Added: 02/24/2026, 14:47:12 UTC |
The Spanish Data Protection Agency (AEPD) reported the first known data breach executed by an autonomous AI agent. The AI agent chained together multiple attack phases including a successful login, vulnerability discovery, and access to personal data such as invoices. This incident marks a potential milestone in autonomous cyberattacks where AI agents independently plan and execute complex attack sequences. The investigation is ongoing, and the exact method of breach remains unclear. The AEPD highlights the need to incorporate AI adversarial risks into risk management, improve incident response speed, enhance credential protection, and adopt AI-assisted defense mechanisms with human oversight. Join the discussion | SecurityWeek | 09/16/2026, 16:39:19 UTC Added: 09/16/2026, 16:46:36 UTC |
0 Mbed TLS before 3.6.4 has a race condition in AESNI detection if certain compiler optimizations occur. An attacker may be able to extract an AES key from a multithreaded program, or perform a GCM forgery. Join the discussion | CVE Database V5 | 09/15/2026, 00:00:00 UTC Added: 07/04/2025, 14:54:28 UTC |
An unpatched zero-day vulnerability dubbed StyleSmuggler affects all current versions of Magento and Adobe Commerce, including 2.4.9, enabling unauthenticated remote code execution. Active exploitation began on September 4th, 2026. The attack operates in two stages: injecting malicious PHP code into Magento's template system using styles properties to evade safeguards, then executing the poisoned code via failed payment emails. Upon successful compromise, attackers deploy a Rust-based backdoor disguised as legitimate system processes (kworker, fc-cache, or chronyd) that connects to command and control servers. The backdoor uses NTP-shaped UDP traffic for C2 communication to evade detection. A second unrelated attacker has also been observed exploiting the same vulnerability to deploy PHP web shells. Affected merchants should deploy immediate mitigation measures, scan for compromise, and temporarily disable GraphQL until an official patch is released. Join the discussion | CVE Database V5 | 09/07/2026, 17:15:59 UTC Added: 09/09/2025, 13:33:51 UTC |
0 FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable due to insufficiently sanitized user-supplied data allowing unauthenticated access to FreePBX Administrator leading to arbitrary database manipulation and remote code execution. This issue has been patched in endpoint versions 15.0.66, 16.0.89, and 17.0.3. Join the discussion | CVE Database V5 | 09/03/2026, 00:00:00 UTC Added: 08/28/2025, 16:47:48 UTC |
ThreatFabric researchers discovered StreamRat, a sophisticated Android banking trojan distributed through Meta and TikTok advertisements disguised as a free TV-streaming service targeting Spanish-speaking users. The campaign reached approximately 570,000 potential victims, primarily in Spain. StreamRat employs a two-stage installation process, utilizing a dropper that implements internet-blocking mechanisms via non-functional VPN connections. Once installed, the trojan abuses Accessibility Services and MediaProjection API to provide operators with near-complete device control, featuring VNC and hidden-screen control, UI-tree collection, keylogging, credential-stealing overlays, and screen-blocking capabilities. The malware appears designed as a Malware-as-a-Service offering, with a sophisticated control panel supporting multiple user roles and WebSocket-based C2 communications. Join the discussion | AlienVault OTX General | 09/02/2026, 13:39:04 UTC Added: 09/02/2026, 16:22:27 UTC |
0 Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blind SQL injection attacks. An unauthenticated attacker could extract sensitive data (emails, password reset tokens) and achieve full account takeover without password cracking. This vulnerability is fixed in 3.73.0. Join the discussion | CVE Database V5 | 09/01/2026, 00:00:00 UTC Added: 02/06/2026, 21:30:09 UTC |
Manic is a newly discovered Android malware family that steals banking credentials, intercepts sensitive data, and allows remote control of infected devices. It uniquely exfiltrates stolen data even without an internet connection by exploiting Android Accessibility services to capture keystrokes and replay them on targeted apps. The malware targets banking apps, government apps, crypto wallets, and two-factor authentication apps across multiple European countries. Infection vectors likely include unofficial app stores, malicious APKs, and phishing links, with no evidence of distribution via Google Play. Manic abuses Accessibility permissions to spy on users, grant itself additional permissions, and prevent removal. It overlays an invisible keyboard to capture passwords and sensitive input. The malware has been active since at least May 2026 and continues to evolve to evade detection. Join the discussion | Kaspersky Security Blog | 08/31/2026, 17:18:45 UTC Added: 08/31/2026, 17:22:57 UTC |
BraZetsu is a sophisticated Python-based Windows malware framework attributed to the Brazilian threat actor Exilware, functioning as a comprehensive toolkit for Initial Access Brokers. Unlike standard infostealers, BraZetsu transforms compromised systems into commercial assets through deep reconnaissance capabilities targeting Iberian and Latin American corporate, financial, industrial, and law enforcement environments. The framework scans for standardized financial remittance files in Brazilian CNAB format, extracts detailed browser histories, and employs AI-enhanced data triage for target prioritization. Operating through a modular architecture with stealth techniques, BraZetsu powers the Infected Marketplace where Exilware commercializes initial access to compromised hosts. The platform allows criminal customers to remotely execute secondary malicious payloads on purchased access, creating a persistent threat-multiplier effect. Tracked since February 2026, BraZetsu demonstrates rapid technical progressi... Join the discussion | AlienVault OTX General | 08/31/2026, 15:42:36 UTC Added: 09/01/2026, 08:52:34 UTC |
Between late September 2025 and early April 2026, the threat group BlueDelta conducted espionage campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye. They deployed HOOKEDGE, a lightweight Windows batch-script backdoor, via macro-enabled Word documents with diplomatic-themed lures. HOOKEDGE shares code and tradecraft overlap with the HEADLACE backdoor and abuses legitimate webhook services for command-and-control, payload staging, and data exfiltration. The implant was continuously refined to evade sandbox detection and adapt to webhook service constraints. BlueDelta used a tiered operational model, deploying second-stage payloads with shorter beaconing intervals for high-value targets while preserving initial access infrastructure. Join the discussion | AlienVault OTX General | 08/27/2026, 17:37:41 UTC Added: 08/28/2026, 09:07:13 UTC |
Showing 1 to 10 of 20283 results