El blog chileno oficial de la Seguridad en Inteligencia Artificial
Lo que pasa en seguridad, filtrado para quien gobierna IA
Dos capas: nuestros análisis sobre gobernanza y seguridad de inteligencia artificial, y un radar que revisa automáticamente las fuentes de referencia del sector y clasifica cada titular por categoría y severidad.
Análisis SeguridadIA
Escritos por nuestro equipo, pensados para decidir: qué controlar primero, con qué evidencia y en qué orden. Los 33 están ordenados por área en Investigación.
Prompt injection: por qué tus guardrails no bastan
La inyección de prompts no es un bug que se parchea, es consecuencia de cómo funciona un modelo de lenguaje. Qué controlar cuando el filtro de entrada falla.
Leer análisisAnatomía de un ataque a un sistema de IA
Dónde empieza y dónde termina la superficie de ataque de una aplicación con modelos: datos, modelo, contexto, herramientas y personas.
Leer análisisEl OWASP Top 10 para LLM explicado sin jerga
Los diez riesgos del estándar traducidos a decisiones concretas de arquitectura, con el control que corresponde a cada uno.
Leer análisisMITRE ATLAS: cómo leer las tácticas de ataque contra IA
Qué es ATLAS, en qué se diferencia de ATT&CK y cómo usarlo para ordenar tu propio modelado de amenazas.
Leer análisisShadow AI: cómo inventariar en dos semanas lo que ya se está usando
Un plan de diez días para levantar el uso real de IA en tu organización, clasificarlo por sensibilidad del dato y decidir qué formalizar, acotar o sustituir.
Leer análisisEnvenenamiento de datos: el ataque que ocurre antes del despliegue
Cómo se contamina un conjunto de entrenamiento o una base vectorial, por qué es difícil de detectar y qué controles aplican en la práctica.
Leer análisisExtracción de modelos y fuga de datos de entrenamiento
Qué puede reconstruir un atacante consultando tu modelo, qué revela sin querer y cómo limitar la exposición sin romper el producto.
Leer análisisAgentes con herramientas: el modelo de permisos que casi nadie diseña
Por qué heredar los permisos del usuario es el error más común en agentes corporativos y cómo se ve un diseño de autorización correcto.
Leer análisisSeis controles de seguridad de IA que puedes implementar este trimestre
Los marcos describen el destino pero no el orden del camino. Seis controles concretos, priorizados por reducción de riesgo sobre esfuerzo, y cómo repartirlos en 90 días.
Leer análisisRadar de amenazas
Titulares recogidos de los feeds públicos de cada medio y clasificados automáticamente. Cada entrada enlaza a la fuente original: aquí solo verás el titular y un extracto breve.
-
'Asimov was right' about rules for robots, says ex-US Cyber Director
Humans will get the AI models they deserve
The Register · Security Seguridad IA theregister.com -
How HSP GRUPPE builds AI capabilities for tax advisory
Discover how HSP GRUPPE uses ChatGPT Enterprise to boost productivity, improve work quality, and create more capacity for tax advisory and client service.
OpenAI Seguridad IA openai.com -
OpenAI drops ChatGPT text chat limits for free users, adds new safeguards for teens
OpenAI has updated GPT-5.6 Sol, the model behind ChatGPT for Plus and Pro subscribers, and pushed a new model, GPT-5.6 Luna, out to everyone using the free tier. The company is also removing the rate limit on text conversations for free…
Help Net Security Seguridad IA helpnetsecurity.com -
Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets
A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic's and Google's own coding-agent repositories. On OpenAI's, it was enough to hijack the next agent run. Novee…
The Hacker News Seguridad IA thehackernews.com -
Keepit AI Truth Cloud protects the data behind enterprise AI
Keepit announced AI Truth Cloud, transforming backup from a compliance requirement into the strategically valuable data asset an organization can hold. As AI agents take on business-critical decisions, AI Truth Cloud positions Keepit as…
Help Net Security Seguridad IA helpnetsecurity.com -
What the first year of EU AI Act transparency enforcement could look like
In this Help Net Security interview, Edwin Weijdema, Field CTO at Veeam, answers questions on Article 50 of the EU AI Act and what the first year of enforcement might bring. He explains why corrective orders will likely outnumber large…
Help Net Security Seguridad IA helpnetsecurity.com -
ShieldFont fights AI scraping by handing crawlers the wrong words
Isaque Seneda and Gabriel Abrucio built a web font that draws one set of words on screen and leaves a different set in the page’s source code. A person reading in a browser sees the writing as written. A scraper pulling the HTML gets…
Help Net Security Seguridad IA helpnetsecurity.com -
Gut feeling does nothing against AI spear phishing texts
A banker at a credit union sat down at a table with a dozen printed text messages, all of them written for that banker personally, and put them in order from the one most likely to get a click down to the one least likely. One of them…
Help Net Security Seguridad IA helpnetsecurity.com -
How the famed USENIX Security conf is managing a flood of papers in the AI era
AI usage is evident but isn't yet a serious problem
The Register · Security Seguridad IA theregister.com -
OpenAI rolls out a major ChatGPT upgrade, even if you don’t pay for it
OpenAI is rolling out a more reliable version of ChatGPT GPT-5.6 Sol for Plus and Pro users, while Free users are getting unlimited text chats with GPT-5.6 Luna. [...]
BleepingComputer Seguridad IA bleepingcomputer.com -
When Agentic Glue Melts: Exploiting Cloudflare Code Mode and Workers
By Yarden Porat, Check Point Research Key Points The short version We set out to break Cloudflare Code Mode, and ended up breaking Cloudflare Workers too. We did both by targeting workerd, the runtime beneath both: an in-process sandbox…
Check Point Research Seguridad IA research.checkpoint.com -
Researcher Claims Control of ChatGPT Secure Sandbox
A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT's isolated sandbox during a session at Black Hat USA 2026.
Dark Reading Seguridad IA darkreading.com -
AI struggles to patch vulns without adult supervision
Left alone, autonomous fixes often fail to fully remediate flaws
The Register · Security Seguridad IA theregister.com -
Why metaphor may dictate your security strategy
In this week's newsletter, Martin looks at how the metaphors we use to describe AI "escaping" its sandbox can completely change how we react to the threat.
Cisco Talos Seguridad IA blog.talosintelligence.com -
Humans in the loop miss a third of dangerous AI coding agent requests
You wouldn't let Claude Code cat your AWS credentials or Kubernetes config on request, would you?
The Register · Security Seguridad IA theregister.com -
Meta AI model hacked a company during misconfigured cyber test
Meta has become the latest AI company to confirm that one of its models hacked a real organization during cybersecurity testing, as similar incidents continue to emerge following OpenAI'sOpenAI's initial disclosure that its agents breached…
BleepingComputer Seguridad IA bleepingcomputer.com -
How AI Exposed a Browser Security Gap that Enterprises Cannot Ignore
AI did not create a new browser security problem. It exposed one that enterprises have long been able to ignore. Skyhigh Security explains why browsers have become a critical control point for governing data movement, AI interactions, and…
BleepingComputer Seguridad IA bleepingcomputer.com -
Photos: Black Hat USA 2026
Photo gallery from the Business Hall at Black Hat USA 2026. Interesting booths, demo stages, crowded aisles, and the moments in between. The second gallery is here. Featured vendors: Stellar Cyber, Tines, Filigran, Delinea, Prophet AI, Air…
Help Net Security Seguridad IA helpnetsecurity.com -
Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts
Zenity researchers reported the findings to Anthropic and OpenAI in late 2025 and early 2026, but they remain unpatched. The post Zero-Click AI Browser Hacking: Claude and ChatGPT Atlas Hijacked via Emails, X Posts appeared first on…
SecurityWeek Seguridad IA securityweek.com -
Three in four AI-generated vulnerability patches leave something broken
Ask a frontier model to patch a real vulnerability and it will hand you something that looks like a fix. It reads like the patch a maintainer would write. When there is a test, it often passes. Roughly one time in four, it is a fix…
Help Net Security Seguridad IA helpnetsecurity.com -
AI Recommendation Poisoning: How "Ask AI" Buttons Silently Alter LLM Memory
A new class of prompt injection is spreading across commercial websites. It requires no malware, no stolen credentials, and no zero-day exploit. It abuses a standard feature built into almost every major AI assistant: pre-filled deep…
The Hacker News Seguridad IA thehackernews.com -
Discounted Claude access bought on the gray market may expose every prompt you send
More than half a dozen services advertised on underground forums and messaging platforms, offering discounted or “unlimited” token access to frontier AI models, were discovered by Okta. Okta believes the trend is likely driven by Chinese…
Help Net Security Seguridad IA helpnetsecurity.com -
Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys. The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first on Unit 42.
Unit 42 Seguridad IA unit42.paloaltonetworks.com -
Improving GPT‑5.6 Sol in ChatGPT—and expanding access to GPT-5.6 Luna for free users
ChatGPT introduces improved GPT-5.6 Sol with better accuracy and consistency, plus expanded access for free users and unlimited everyday chats with GPT-5.6 Luna.
OpenAI Seguridad IA openai.com -
Meta AI Hacked External Systems During Cybersecurity Testing
The incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week. The post Meta AI Hacked External Systems During Cybersecurity Testing appeared first on SecurityWeek.
SecurityWeek Seguridad IA securityweek.com
¿Y esto qué significa para ti?
Traducimos el ruido en un plan de control
Leer titulares no reduce el riesgo. Armemos el diagnóstico de tu exposición real y una hoja de ruta de 90 días con responsables y evidencia.