El blog chileno oficial de la Seguridad en Inteligencia Artificial
Lo que pasa en seguridad, filtrado para quien gobierna IA
Dos capas: nuestros análisis sobre gobernanza y seguridad de inteligencia artificial, y un radar que revisa automáticamente las fuentes de referencia del sector y clasifica cada titular por categoría y severidad.
Análisis SeguridadIA
Escritos por nuestro equipo, pensados para decidir: qué controlar primero, con qué evidencia y en qué orden. Los 33 están ordenados por área en Investigación.
Prompt injection: por qué tus guardrails no bastan
La inyección de prompts no es un bug que se parchea, es consecuencia de cómo funciona un modelo de lenguaje. Qué controlar cuando el filtro de entrada falla.
Leer análisisAnatomía de un ataque a un sistema de IA
Dónde empieza y dónde termina la superficie de ataque de una aplicación con modelos: datos, modelo, contexto, herramientas y personas.
Leer análisisEl OWASP Top 10 para LLM explicado sin jerga
Los diez riesgos del estándar traducidos a decisiones concretas de arquitectura, con el control que corresponde a cada uno.
Leer análisisMITRE ATLAS: cómo leer las tácticas de ataque contra IA
Qué es ATLAS, en qué se diferencia de ATT&CK y cómo usarlo para ordenar tu propio modelado de amenazas.
Leer análisisShadow AI: cómo inventariar en dos semanas lo que ya se está usando
Un plan de diez días para levantar el uso real de IA en tu organización, clasificarlo por sensibilidad del dato y decidir qué formalizar, acotar o sustituir.
Leer análisisEnvenenamiento de datos: el ataque que ocurre antes del despliegue
Cómo se contamina un conjunto de entrenamiento o una base vectorial, por qué es difícil de detectar y qué controles aplican en la práctica.
Leer análisisExtracción de modelos y fuga de datos de entrenamiento
Qué puede reconstruir un atacante consultando tu modelo, qué revela sin querer y cómo limitar la exposición sin romper el producto.
Leer análisisAgentes con herramientas: el modelo de permisos que casi nadie diseña
Por qué heredar los permisos del usuario es el error más común en agentes corporativos y cómo se ve un diseño de autorización correcto.
Leer análisisSeis controles de seguridad de IA que puedes implementar este trimestre
Los marcos describen el destino pero no el orden del camino. Seis controles concretos, priorizados por reducción de riesgo sobre esfuerzo, y cómo repartirlos en 90 días.
Leer análisisRadar de amenazas
Titulares recogidos de los feeds públicos de cada medio y clasificados automáticamente. Cada entrada enlaza a la fuente original: aquí solo verás el titular y un extracto breve.
-
Stronger Cybersecurity, Stronger Business: NIST Celebrates 2026 National Small Business Week
Happy National Small Business Week! For over 60 years, the U.S. Small Business Administration has led this initiative to acknowledge the critical contributions of America’s entrepreneurs and small business owners. Part of the U.S…
NIST Cybersecurity General nist.gov -
From DMV to Wallet: Understanding Verifiable Digital Credential Issuance
In our last post in this series, we compared two credential formats that shape the digital identity ecosystem: ISO/IEC 18013-5 and -7 mobile documents (mdocs) and W3C Verifiable Credentials (VCs). Both formats define how a credential is…
NIST Cybersecurity Regulación nist.gov -
AI threats in the wild: The current state of prompt injections on the web
Posted by Thomas Brunner, Yu-Han Liu, Moni PandeAt Google, our Threat Intelligence teams are dedicated to staying ahead of real-world adversarial activity, proactively monitoring emerging threats before they can impact users. Right now…
Google Security Blog Seguridad IA security.googleblog.com -
Bringing Rust to the Pixel Baseband
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks…
Google Security Blog Vulnerabilidades security.googleblog.com -
Protecting Cookies with Device Bound Session Credentials
Posted by Ben Ackerman, Chrome team, Daniel Rubery, Chrome team and Guillaume Ehinger, Google Account Security team Following our April 2024 announcement, Device Bound Session Credentials (DBSC) is now entering public availability for…
Google Security Blog General security.googleblog.com -
Mitigating prompt injection attacks with a layered defense strategy
Posted by Adam Gavish, Google GenAI Security TeamWith the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is…
Google Security Blog Seguridad IA security.googleblog.com -
Google Workspace’s continuous approach to mitigating indirect prompt injections
Posted by Adam Gavish, Google GenAI Security TeamIndirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This technique enables the…
Google Security Blog Seguridad IA security.googleblog.com -
VRP 2025 Year in Review
Posted by Dirk Göhmann, Tony Mendez, and the Vulnerability Rewards Program Team2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉! Originally started in 2010, our…
Google Security Blog Vulnerabilidades security.googleblog.com -
Security for the Quantum Era: Implementing Post-Quantum Cryptography in Android
Posted by Eric Lynch, Product Manager, Android and Dom Elliott, Group Product Manager, Google Play Modern digital security is at a turning point. We are on the threshold of using quantum computers to solve "impossible" problems in drug…
Google Security Blog General security.googleblog.com -
Reflections from the Second NIST Cyber AI Profile Workshop
Thank you to everyone who participated in the Cybersecurity Framework Profile for Artificial Intelligence (Cyber AI Profile) Workshop in January! The input we received on the Preliminary Draft during this workshop has been invaluable and…
NIST Cybersecurity Seguridad IA nist.gov -
All aboard: the NIST Cybersecurity for IoT Program is headed to our next stop! Share your input on where we’re headed during our Future Directions Two-Day Workshop on March 31st.
Workshop Details… We’re looking forward to hearing from the community during our “Future Directions” Workshop! Date: March 31 - April 1, 2026 Where: NIST’s Gaithersburg campus! Registration and Details: HERE Can’t make it? We still want to…
NIST Cybersecurity General nist.gov -
Staying One Step Ahead: Strengthening Android’s Lead in Scam Protection
Posted by Lyubov Farafonova, Product Manager, Phone by Google; Alberto Pastor Nieto, Sr. Product Manager Google Messages and RCS Spam and Abuse We’ve shared how Android’s proactive, multi-layered scam defenses utilize Google AI to protect…
Google Security Blog Seguridad IA security.googleblog.com -
On the Effectiveness of Mutational Grammar Fuzzing
Mutational grammar fuzzing is a fuzzing technique in which the fuzzer uses a predefined grammar that describes the structure of the samples. When a sample gets mutated, the mutations happen in such a way that any resulting samples still…
Google Project Zero Regulación projectzero.google -
Cultivating a robust and efficient quantum-safe HTTPS
Posted by Chrome Secure Web and Networking Team Today we're announcing a new program in Chrome to make HTTPS certificates secure against quantum computers. The Internet Engineering Task Force (IETF) recently created a working group, PKI…
Google Security Blog General security.googleblog.com -
A Deep Dive into the GetProcessHandleFromHwnd API
In my previous blog post I mentioned the GetProcessHandleFromHwnd API. This was an API I didn’t know existed until I found a publicly disclosed UAC bypass using the Quick Assist UI Access application. This API looked interesting so I…
Google Project Zero General projectzero.google -
Celebrating Two Years of CSF 2.0!
Celebrate this milestone with us! Email us at csf [at] nist.gov (csf[at]nist[dot]gov) or tag @NISTcyber on X telling us what your favorite CSF 2.0 resource is (or how your organization has benefitted from implementing the CSF 2.0). Today…
NIST Cybersecurity General nist.gov -
Keeping Google Play & Android app ecosystems safe in 2025
Posted by Vijaya Kaza, VP and GM, App & Ecosystem Trust The Android ecosystem is a thriving global community built on trust, giving billions of users the confidence to download the latest apps. In order to maintain that trust, we’re…
Google Security Blog General security.googleblog.com -
Bypassing Administrator Protection by Abusing UI Access
In my last blog post I introduced the new Windows feature, Administrator Protection and how it aimed to create a secure boundary for UAC where one didn’t exist. I described one of the ways I was able to bypass the feature before it was…
Google Project Zero General projectzero.google
¿Y esto qué significa para ti?
Traducimos el ruido en un plan de control
Leer titulares no reduce el riesgo. Armemos el diagnóstico de tu exposición real y una hoja de ruta de 90 días con responsables y evidencia.