{"id":348208,"date":"2025-02-15T16:44:49","date_gmt":"2025-02-15T15:44:49","guid":{"rendered":"https:\/\/sftarticles.wpenginepowered.com\/es\/?p=348208"},"modified":"2025-02-24T21:44:26","modified_gmt":"2025-02-24T20:44:26","slug":"el-gobierno-de-estados-unidos-tiene-un-problema-de-ciberseguridad","status":"publish","type":"post","link":"https:\/\/cms-articles.softonic.io\/es\/el-gobierno-de-estados-unidos-tiene-un-problema-de-ciberseguridad\/","title":{"rendered":"El Gobierno de Estados Unidos tiene un problema de ciberseguridad"},"content":{"rendered":"\n<p class=\"wp-block-paragraph\">Expertos en ciberseguridad han alertado sobre un aumento en los ataques inform\u00e1ticos dirigidos a servidores sensibles del gobierno, aprovechando vulnerabilidades en software gubernamental.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/8713ac42-12d5-11e7-b114-c399bbcf470c\/3632015789\/nordvpn-logo\" alt=\"NordVPN\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">NordVPN<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/nordvpn.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">DESCARGAR<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/nordvpn.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Esta advertencia se origina en la firma de ciberseguridad Trimble, que ha identificado que su herramienta Cityworks ha sido utilizada en estos ataques.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Trimble alert\u00f3 a sus clientes a trav\u00e9s de una carta, en la que menciona el descubrimiento de una vulnerabilidad de deserializaci\u00f3n, <strong>etiquetada como CVE-2025-0994, que permite la ejecuci\u00f3n remota de c\u00f3digo (RCE) con un alto puntaje de severidad de 8.6.<\/strong><\/p>\n\n\n\n<figure class=\"wp-block-embed is-type-rich is-provider-twitter wp-block-embed-twitter\"><div class=\"wp-block-embed__wrapper\">\n<blockquote class=\"twitter-tweet\" data-width=\"550\" data-dnt=\"true\"><p lang=\"en\" dir=\"ltr\">Trimble released security updates for a deserialization vulnerability CVE-2025-0994 impacting its Cityworks Server AMS. This enables threat actors to conduct remote code execution against a customer\u2019s Microsoft IIS web server. Apply updates &amp; learn more ? <a href=\"https:\/\/t.co\/TyBvD9evaQ\">https:\/\/t.co\/TyBvD9evaQ<\/a> <a href=\"https:\/\/t.co\/Bqxe5mVe7r\">pic.twitter.com\/Bqxe5mVe7r<\/a><\/p>&mdash; CISA Cyber (@CISACyber) <a href=\"https:\/\/twitter.com\/CISACyber\/status\/1887934116353462620?ref_src=twsrc%5Etfw\">February 7, 2025<\/a><\/blockquote><script async src=\"https:\/\/platform.twitter.com\/widgets.js\" charset=\"utf-8\"><\/script>\n<\/div><\/figure>\n\n\n\n<h2 class=\"wp-block-heading\">Qu\u00e9 sabemos de esta vulnerabilidad estatal<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">La explotaci\u00f3n de esta vulnerabilidad podr\u00eda permitir a los atacantes desplegar beacons de Cobalt Strike en servidores de Microsoft Internet Information Services (IIS).<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Cityworks, un software de gesti\u00f3n de activos y permisos basado en sistemas de informaci\u00f3n geogr\u00e1fica (GIS), est\u00e1 dise\u00f1ado para ayudar a los gobiernos y servicios p\u00fablicos en la gesti\u00f3n eficiente de su infraestructura y operaciones.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Tras recibir reportes de intentos no autorizados de acceso a implementaciones espec\u00edficas de Cityworks, Trimble ha lanzado actualizaciones para mitigar los riesgos: la versi\u00f3n 15.x se ha actualizado a 15.8.9, y la 23.x a 23.10.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Adem\u00e1s de las actualizaciones, la compa\u00f1\u00eda advirti\u00f3 sobre configuraciones incorrectas de directorios de adjuntos y permisos de identidad IIS sobreelevados en algunas implementaciones on-premise, lo cual podr\u00eda incrementar el riesgo. Trimble enfatiza que estas cuestiones deben abordarse simult\u00e1neamente para reanudar operaciones normales con Cityworks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>La Agencia de Seguridad Cibern\u00e9tica e Infraestructura de EE. UU. (CISA) ha emitido un aviso coordinado<\/strong>, instando a las organizaciones afectadas a aplicar los parches de seguridad de inmediato y realizar un an\u00e1lisis de impacto y evaluaci\u00f3n de riesgos antes de implementar medidas defensivas.<\/p>\n\n\n<div class=\"sc-card-program\">\r\n  <div class=\"sc-card-program__body\">\r\n    <div class=\"sc-card-program__row clearfix\">\r\n      <div class=\"sc-card-program__col-logo\">\r\n        <img decoding=\"async\" class=\"sc-card-program__img\" src=\"https:\/\/images.sftcdn.net\/images\/t_app-icon-s\/p\/8713ac42-12d5-11e7-b114-c399bbcf470c\/3632015789\/nordvpn-logo\" alt=\"NordVPN\" width=\"100px\" height=\"100px\">\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-title\">\r\n        <span class=\"sc-card-program__title\">NordVPN<\/span>\r\n        <a class=\"sc-card-program__button sc-card-program-internal\" href=\"https:\/\/nordvpn.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\">DESCARGAR<\/a>\r\n      <\/div>\r\n      <div class=\"sc-card-program__col-rating\">\r\n        <svg class=\"rating-score__content\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" version=\"1.1\" x=\"0\" y=\"0\" viewbox=\"0 0 50 50\" enable-background=\"new 0 0 50 50\" xml:space=\"preserve\"><path class=\"rating-score__background rating-score--good\" fill=\"none\" stroke-width=\"6\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><path class=\"rating-score__value rating-score__value--0\" fill=\"none\" stroke-width=\"6\" stroke-dashoffset=\"0\" stroke-miterlimit=\"10\" d=\"M40 40c8.3-8.3 8.3-21.7 0-30s-21.7-8.3-30 0 -8.3 21.7 0 30\"><\/path><text class=\"rating-score__number\" content=\"\" text-anchor=\"middle\" transform=\"matrix(1 0 0 1 25 31.0837)\" data-auto=\"app-user-score\"><\/text><\/svg>\r\n      <\/div>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <span class=\"sc-card-program__description\"><\/span>\r\n    <\/div>\r\n    <div class=\"sc-card-program__row\">\r\n      <img decoding=\"async\" class=\"sc-card-program__bigpic\" src=\"\" onerror=\"this.style.display='none'\">\r\n    <\/div>\r\n    <a class=\"sc-card-program__link track-link sc-card-program-internal\" href=\"https:\/\/nordvpn.softonic.com\/android\" target=\"_self\" rel=\"noopener noreferrer\"><\/a>\r\n  <\/div>\r\n<\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Las organizaciones que detecten actividad maliciosa deben seguir los procedimientos internos y <a href=\"https:\/\/www.cisa.gov\/known-exploited-vulnerabilities-catalog\" target=\"_blank\" rel=\"noopener\" title=\"reportar cualquier incidente a CISA para un mejor seguimiento.\">reportar cualquier incidente a CISA para un mejor seguimiento.<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Expertos en ciberseguridad han alertado sobre un aumento en los ataques inform\u00e1ticos dirigidos a servidores sensibles del gobierno, aprovechando vulnerabilidades en software gubernamental. Esta advertencia se origina en la firma de ciberseguridad Trimble, que ha identificado que su herramienta Cityworks ha sido utilizada en estos ataques. Trimble alert\u00f3 a sus clientes a trav\u00e9s de una &hellip; <a href=\"https:\/\/cms-articles.softonic.io\/es\/el-gobierno-de-estados-unidos-tiene-un-problema-de-ciberseguridad\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;El Gobierno de Estados Unidos tiene un problema de ciberseguridad&#8221;<\/span><\/a><\/p>\n","protected":false},"author":9317,"featured_media":348210,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","wpcf-pageviews":2},"categories":[9317],"tags":[12557],"usertag":[],"vertical":[],"content-category":[],"class_list":["post-348208","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","tag-ciberseguridad"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/posts\/348208","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/users\/9317"}],"replies":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/comments?post=348208"}],"version-history":[{"count":0,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/posts\/348208\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/media\/348210"}],"wp:attachment":[{"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/media?parent=348208"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/categories?post=348208"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/tags?post=348208"},{"taxonomy":"usertag","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/usertag?post=348208"},{"taxonomy":"vertical","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/vertical?post=348208"},{"taxonomy":"content-category","embeddable":true,"href":"https:\/\/cms-articles.softonic.io\/es\/wp-json\/wp\/v2\/content-category?post=348208"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}