El blog chileno oficial de la Seguridad en Inteligencia Artificial
Lo que pasa en seguridad, filtrado para quien gobierna IA
Dos capas: nuestros análisis sobre gobernanza y seguridad de inteligencia artificial, y un radar que revisa automáticamente las fuentes de referencia del sector y clasifica cada titular por categoría y severidad.
Análisis SeguridadIA
Escritos por nuestro equipo, pensados para decidir: qué controlar primero, con qué evidencia y en qué orden. Los 33 están ordenados por área en Investigación.
Prompt injection: por qué tus guardrails no bastan
La inyección de prompts no es un bug que se parchea, es consecuencia de cómo funciona un modelo de lenguaje. Qué controlar cuando el filtro de entrada falla.
Leer análisisAnatomía de un ataque a un sistema de IA
Dónde empieza y dónde termina la superficie de ataque de una aplicación con modelos: datos, modelo, contexto, herramientas y personas.
Leer análisisEl OWASP Top 10 para LLM explicado sin jerga
Los diez riesgos del estándar traducidos a decisiones concretas de arquitectura, con el control que corresponde a cada uno.
Leer análisisMITRE ATLAS: cómo leer las tácticas de ataque contra IA
Qué es ATLAS, en qué se diferencia de ATT&CK y cómo usarlo para ordenar tu propio modelado de amenazas.
Leer análisisShadow AI: cómo inventariar en dos semanas lo que ya se está usando
Un plan de diez días para levantar el uso real de IA en tu organización, clasificarlo por sensibilidad del dato y decidir qué formalizar, acotar o sustituir.
Leer análisisEnvenenamiento de datos: el ataque que ocurre antes del despliegue
Cómo se contamina un conjunto de entrenamiento o una base vectorial, por qué es difícil de detectar y qué controles aplican en la práctica.
Leer análisisExtracción de modelos y fuga de datos de entrenamiento
Qué puede reconstruir un atacante consultando tu modelo, qué revela sin querer y cómo limitar la exposición sin romper el producto.
Leer análisisAgentes con herramientas: el modelo de permisos que casi nadie diseña
Por qué heredar los permisos del usuario es el error más común en agentes corporativos y cómo se ve un diseño de autorización correcto.
Leer análisisSeis controles de seguridad de IA que puedes implementar este trimestre
Los marcos describen el destino pero no el orden del camino. Seis controles concretos, priorizados por reducción de riesgo sobre esfuerzo, y cómo repartirlos en 90 días.
Leer análisisRadar de amenazas
Titulares recogidos de los feeds públicos de cada medio y clasificados automáticamente. Cada entrada enlaza a la fuente original: aquí solo verás el titular y un extracto breve.
-
Meta AI Hacked External Systems During Cybersecurity Testing
The incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week. The post Meta AI Hacked External Systems During Cybersecurity Testing appeared first on SecurityWeek.
SecurityWeek Seguridad IA securityweek.com -
Microsoft extends zero trust deeper into enterprise AI
Microsoft expanded its Zero Trust for AI strategy with updates to the Zero Trust Assessment tool and the Zero Trust Workshop. The additions help organizations assess security posture, prioritize remediation, and apply zero trust principles…
Help Net Security Seguridad IA helpnetsecurity.com -
OWASP 2026 LLM Top 10: “The model will be fooled”
The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications and, for the first time, the list was influenced by real-world incidents. The two top entries – Prompt Injection and Sensitive Information…
Help Net Security Seguridad IA helpnetsecurity.com -
Working with the American Psychological Association on youth mental health and AI
OpenAI and the American Psychological Association advance evidence-based guidance, resources, and safeguards for responsible AI use and youth mental health.
OpenAI Seguridad IA openai.com -
OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack
It started with an 'impossible task' and led to AI deciding it needed to act as a collective intelligence
The Register · Security Seguridad IA theregister.com -
An AI model from Meta also hacked another company during testing
An AI model from Meta also hacked another company during testing Stop me if you've heard this one before: An AI model from the parent company of Facebook and Instagram hacked into another company’s systems during cybersecurity testing, a…
Simon Willison Seguridad IA simonwillison.net -
From asking to doing: How the world is putting ChatGPT to work
New OpenAI Signals data shows how people use ChatGPT worldwide, with country-level insights on adoption, usage trends, and evolving behavior.
OpenAI Seguridad IA openai.com -
Introducing Muse Code and Muse Spark 1.2
Introducing Muse Code and Muse Spark 1.2 Yet more evidence that the most important characteristic of any model these days is long-sequence agentic tool calling. Meta shipped their own coding agent as part of getting that to work! Muse…
Simon Willison Seguridad IA simonwillison.net -
Third-party cyber evaluations involving OpenAI models
Third-party cyber evaluations involving OpenAI models And another one. I had to create a accidental-cyberattacks tag to keep track of them all! This post from OpenAI covers both the UK AI Safety Institute attack (see my previous post) and…
Simon Willison Seguridad IA simonwillison.net -
AI Sends Global Crime Syndicates Into Fraud Nirvana
Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.
Dark Reading Seguridad IA darkreading.com -
Incident Report: unsanctioned agent behaviour during cyber testing
Incident Report: unsanctioned agent behaviour during cyber testing It happened again. This time it was the UK government's AI Security Institute who accidentally attacked other companies while running an evaluation with models with the…
Simon Willison Seguridad IA simonwillison.net -
AI Browsers Vulnerable to 'PleaseFix' Zero-Click Agent Hijacking
Attackers can take control of agents through malicious instructions hidden in content supplied to AI browsers, and there's no simple fix for the threat.
Dark Reading Seguridad IA darkreading.com -
No Perfect Fix for AI Browser Prompt Injection Flaws
AI browsers from top vendors remain vulnerable to prompt injection attacks despite multiple security guardrails, according to new research.
Dark Reading Seguridad IA darkreading.com -
Prompt injection isn't the bug, AI agent frameworks are
Check Point researchers tried to break the frameworks enterprises use to build AI apps. Now they're telling Black Hat attendees what they found
The Register · Security Seguridad IA theregister.com -
One-shotting a Raccoon Heist game using Claude Fable 5
Back in 2022 I tweeted screenshots of a game concept generated by GPT-3 and some concept "art" created using DALL-E. Today, on the fourth anniversary of that tweet, I decided to see if Claude Fable 5 (running in Claude Code for web) could…
Simon Willison Seguridad IA simonwillison.net -
OpenAI Disrupts Poipet Scam Network Using ChatGPT Across Multiple Fraud Schemes
OpenAI said it disrupted a Cambodia-based scam operation that used its generative artificial intelligence (AI) chatbot ChatGPT to facilitate a wide range of investment, romance, gambling, and law enforcement impersonation schemes. To that…
The Hacker News Seguridad IA thehackernews.com -
Flaws in Google APK for Python Unlock Agent-to-Agent Attack
Google has fixed the issues, which exploited a trust boundary between two AI agents with different privilege levels to trigger automation that could compromise the supply chain.
Dark Reading Seguridad IA darkreading.com -
IBM's agentic AI platform is under active attack - patch now
A critical Langflow flaw allowing RCE on default deployments is being exploited, says the CISA
The Register · Security Seguridad IA theregister.com -
Poison Claude Sells Discounted Claude Access While Its Operator Sees Every Customer Prompt
Cybersecurity researchers have discovered more than half-a-dozen services advertisements for illegal access to artificial intelligence (AI) models on underground cybercrime forums and messaging platforms. One such service, Poison Claude…
The Hacker News Seguridad IA thehackernews.com -
Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports
Two security flaws in Paperclip could let attackers execute commands on a network server or a developer's computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on…
The Hacker News Seguridad IA thehackernews.com -
Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug
HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious: An unauthenticated flaw in Veeam's console that hands…
The Hacker News Seguridad IA thehackernews.com -
How AI-powered phishing killed blocklists for good
AI is helping attackers create disposable phishing infrastructure and rapidly evolving toolkits that blocklists cannot track fast enough. Push Security explains why browser-level, technique-based detection offers a more durable defense…
BleepingComputer Seguridad IA bleepingcomputer.com -
AI researchers let models off the leash – then watched as they tried to add malware to a FOSS project
Models used social engineering and collaborated among themselves to solve a security challenge
The Register · Security Seguridad IA theregister.com -
New release of LLM adds support for reasoning traces, OpenAI Responses, server-side tools, and smarter logging
I released LLM 0.32 this morning, the most significant new version of LLM since the initial launch of the project. The new version includes support for visible reasoning traces, server-side provider tools, redesigned content-addressable…
Simon Willison Seguridad IA simonwillison.net -
OpenAI, Anthropic AI agents targeted real people and systems in cyber tests
OpenAI and Anthropic have confirmed that their AI models were involved in separate, newly disclosed third-party cybersecurity testing incidents that resulted in a real website being breached and social engineering attacks against people…
BleepingComputer Seguridad IA bleepingcomputer.com
¿Y esto qué significa para ti?
Traducimos el ruido en un plan de control
Leer titulares no reduce el riesgo. Armemos el diagnóstico de tu exposición real y una hoja de ruta de 90 días con responsables y evidencia.