El blog chileno oficial de la Seguridad en Inteligencia Artificial
Lo que pasa en seguridad, filtrado para quien gobierna IA
Dos capas: nuestros análisis sobre gobernanza y seguridad de inteligencia artificial, y un radar que revisa automáticamente las fuentes de referencia del sector y clasifica cada titular por categoría y severidad.
Análisis SeguridadIA
Escritos por nuestro equipo, pensados para decidir: qué controlar primero, con qué evidencia y en qué orden. Los 33 están ordenados por área en Investigación.
Prompt injection: por qué tus guardrails no bastan
La inyección de prompts no es un bug que se parchea, es consecuencia de cómo funciona un modelo de lenguaje. Qué controlar cuando el filtro de entrada falla.
Leer análisisAnatomía de un ataque a un sistema de IA
Dónde empieza y dónde termina la superficie de ataque de una aplicación con modelos: datos, modelo, contexto, herramientas y personas.
Leer análisisEl OWASP Top 10 para LLM explicado sin jerga
Los diez riesgos del estándar traducidos a decisiones concretas de arquitectura, con el control que corresponde a cada uno.
Leer análisisMITRE ATLAS: cómo leer las tácticas de ataque contra IA
Qué es ATLAS, en qué se diferencia de ATT&CK y cómo usarlo para ordenar tu propio modelado de amenazas.
Leer análisisShadow AI: cómo inventariar en dos semanas lo que ya se está usando
Un plan de diez días para levantar el uso real de IA en tu organización, clasificarlo por sensibilidad del dato y decidir qué formalizar, acotar o sustituir.
Leer análisisEnvenenamiento de datos: el ataque que ocurre antes del despliegue
Cómo se contamina un conjunto de entrenamiento o una base vectorial, por qué es difícil de detectar y qué controles aplican en la práctica.
Leer análisisExtracción de modelos y fuga de datos de entrenamiento
Qué puede reconstruir un atacante consultando tu modelo, qué revela sin querer y cómo limitar la exposición sin romper el producto.
Leer análisisAgentes con herramientas: el modelo de permisos que casi nadie diseña
Por qué heredar los permisos del usuario es el error más común en agentes corporativos y cómo se ve un diseño de autorización correcto.
Leer análisisSeis controles de seguridad de IA que puedes implementar este trimestre
Los marcos describen el destino pero no el orden del camino. Seis controles concretos, priorizados por reducción de riesgo sobre esfuerzo, y cómo repartirlos en 90 días.
Leer análisisRadar de amenazas
Titulares recogidos de los feeds públicos de cada medio y clasificados automáticamente. Cada entrada enlaza a la fuente original: aquí solo verás el titular y un extracto breve.
-
Token Jacking: Cybercriminals Could Be Stealing Your AI Resources
Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys. The post Token Jacking: Cybercriminals Could Be Stealing Your AI Resources appeared first on Unit 42.
Unit 42 Seguridad IA unit42.paloaltonetworks.com -
Improving GPT‑5.6 Sol in ChatGPT—and expanding access to GPT-5.6 Luna for free users
ChatGPT introduces improved GPT-5.6 Sol with better accuracy and consistency, plus expanded access for free users and unlimited everyday chats with GPT-5.6 Luna.
OpenAI Seguridad IA openai.com -
Meta AI Hacked External Systems During Cybersecurity Testing
The incident involved a testing environment set up by Irregular, similar to what Anthropic reported last week. The post Meta AI Hacked External Systems During Cybersecurity Testing appeared first on SecurityWeek.
SecurityWeek Seguridad IA securityweek.com -
Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison
Maksim Silnikau was the creator and administrator of the ransomware group and involved in Angler EK’s distribution. The post Belarusian Ransom Cartel Mastermind Gets 16 Years in Prison appeared first on SecurityWeek.
SecurityWeek Amenazas securityweek.com -
Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access
Attackers broke into an organization's Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an executable to disk. They fed Java source code to the…
The Hacker News Vulnerabilidades thehackernews.com -
Microsoft extends zero trust deeper into enterprise AI
Microsoft expanded its Zero Trust for AI strategy with updates to the Zero Trust Assessment tool and the Zero Trust Workshop. The additions help organizations assess security posture, prioritize remediation, and apply zero trust principles…
Help Net Security Seguridad IA helpnetsecurity.com -
AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model
Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent's tools with no check that a model turn had authorized them. In several of the attack paths, the…
The Hacker News Infraestructura thehackernews.com -
Photos: Black Hat USA 2026 Arsenal
This week Help Net Security is at the Mandalay Bay, where Arsenal is running alongside the Briefings. If you’ve never been, it’s the corner of Black Hat that feels least like a conference and most like a workshop: a room full of stations…
Help Net Security General helpnetsecurity.com -
Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells
Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink. According to a new report from VulnCheck, the implant appears in all 21 firmware images currently…
The Hacker News Amenazas thehackernews.com -
Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities
Patches were rolled out for two dozen vulnerabilities, including one with public proof-of-concept (PoC) code. The post Cisco Patches Critical SD-WAN, IOS XE, FMC Vulnerabilities appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com -
Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service
A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service operation he stood up in 2021. Between 2021 and 2023, Ransom Cartel…
The Hacker News Amenazas thehackernews.com -
CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild
A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and Infrastructure Security Agency (CISA). The vulnerability in question…
The Hacker News Vulnerabilidades thehackernews.com -
Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability
Tracked as CVE-2026-63077, the critical bug can be exploited without authentication for remote code execution. The post Hackers Start Exploiting Recent JetBrains TeamCity Vulnerability appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com -
Snowflake Hacker Pleads Guilty Over Breaches Affecting at Least 100 Million People
Connor Riley Moucka pleaded guilty in Seattle federal court on Wednesday to computer fraud, wire fraud, aggravated identity theft and a related conspiracy over the 2024 breaches of Snowflake customer accounts. The intrusions reached at…
The Hacker News Regulación thehackernews.com -
OWASP 2026 LLM Top 10: “The model will be fooled”
The OWASP GenAI Security Project has released the 2026 edition of its Top 10 for LLM Applications and, for the first time, the list was influenced by real-world incidents. The two top entries – Prompt Injection and Sensitive Information…
Help Net Security Seguridad IA helpnetsecurity.com -
Working with the American Psychological Association on youth mental health and AI
OpenAI and the American Psychological Association advance evidence-based guidance, resources, and safeguards for responsible AI use and youth mental health.
OpenAI Seguridad IA openai.com -
Chinese router vendor denies its firmware contains backdoors – but pauses downloads to fix security issues anyway
It’s just a remote maintenance function, says Zbtlink
The Register · Security Amenazas theregister.com -
State Department says Trump raised cyber scam compound issue with Xi
President Donald Trump has talked with Chinese President Xi Jinping about Southeast Asian scam compounds, a State Department official told senators at a hearing on the transnational issue.
The Record General therecord.media -
Republic of Georgia alleges foreign disinfo campaign sought to scare off Russian tourists
Georgia's State Security Service is investigating whether foreign entities were behind the spread of fabricated stories claiming that Georgians were mistreating Russian tourists.
The Record Amenazas therecord.media -
OpenAI reveals its rogue agent swarm went a little bit Borg ahead of Hugging Face hack
It started with an 'impossible task' and led to AI deciding it needed to act as a collective intelligence
The Register · Security Seguridad IA theregister.com -
An AI model from Meta also hacked another company during testing
An AI model from Meta also hacked another company during testing Stop me if you've heard this one before: An AI model from the parent company of Facebook and Instagram hacked into another company’s systems during cybersecurity testing, a…
Simon Willison Seguridad IA simonwillison.net -
From asking to doing: How the world is putting ChatGPT to work
New OpenAI Signals data shows how people use ChatGPT worldwide, with country-level insights on adoption, usage trends, and evolving behavior.
OpenAI Seguridad IA openai.com -
Introducing Muse Code and Muse Spark 1.2
Introducing Muse Code and Muse Spark 1.2 Yet more evidence that the most important characteristic of any model these days is long-sequence agentic tool calling. Meta shipped their own coding agent as part of getting that to work! Muse…
Simon Willison Seguridad IA simonwillison.net -
Third-party cyber evaluations involving OpenAI models
Third-party cyber evaluations involving OpenAI models And another one. I had to create a accidental-cyberattacks tag to keep track of them all! This post from OpenAI covers both the UK AI Safety Institute attack (see my previous post) and…
Simon Willison Seguridad IA simonwillison.net -
AI Sends Global Crime Syndicates Into Fraud Nirvana
Organized crime is convincingly scamming at scale, making billions thanks to AI-enabled voice cloning, deepfake real-time video overlays, LLM-driven persona management, and automated translation.
Dark Reading Seguridad IA darkreading.com
¿Y esto qué significa para ti?
Traducimos el ruido en un plan de control
Leer titulares no reduce el riesgo. Armemos el diagnóstico de tu exposición real y una hoja de ruta de 90 días con responsables y evidencia.