El blog chileno oficial de la Seguridad en Inteligencia Artificial
Lo que pasa en seguridad, filtrado para quien gobierna IA
Dos capas: nuestros análisis sobre gobernanza y seguridad de inteligencia artificial, y un radar que revisa automáticamente las fuentes de referencia del sector y clasifica cada titular por categoría y severidad.
Análisis SeguridadIA
Escritos por nuestro equipo, pensados para decidir: qué controlar primero, con qué evidencia y en qué orden. Los 33 están ordenados por área en Investigación.
Prompt injection: por qué tus guardrails no bastan
La inyección de prompts no es un bug que se parchea, es consecuencia de cómo funciona un modelo de lenguaje. Qué controlar cuando el filtro de entrada falla.
Leer análisisAnatomía de un ataque a un sistema de IA
Dónde empieza y dónde termina la superficie de ataque de una aplicación con modelos: datos, modelo, contexto, herramientas y personas.
Leer análisisEl OWASP Top 10 para LLM explicado sin jerga
Los diez riesgos del estándar traducidos a decisiones concretas de arquitectura, con el control que corresponde a cada uno.
Leer análisisMITRE ATLAS: cómo leer las tácticas de ataque contra IA
Qué es ATLAS, en qué se diferencia de ATT&CK y cómo usarlo para ordenar tu propio modelado de amenazas.
Leer análisisShadow AI: cómo inventariar en dos semanas lo que ya se está usando
Un plan de diez días para levantar el uso real de IA en tu organización, clasificarlo por sensibilidad del dato y decidir qué formalizar, acotar o sustituir.
Leer análisisEnvenenamiento de datos: el ataque que ocurre antes del despliegue
Cómo se contamina un conjunto de entrenamiento o una base vectorial, por qué es difícil de detectar y qué controles aplican en la práctica.
Leer análisisExtracción de modelos y fuga de datos de entrenamiento
Qué puede reconstruir un atacante consultando tu modelo, qué revela sin querer y cómo limitar la exposición sin romper el producto.
Leer análisisAgentes con herramientas: el modelo de permisos que casi nadie diseña
Por qué heredar los permisos del usuario es el error más común en agentes corporativos y cómo se ve un diseño de autorización correcto.
Leer análisisSeis controles de seguridad de IA que puedes implementar este trimestre
Los marcos describen el destino pero no el orden del camino. Seis controles concretos, priorizados por reducción de riesgo sobre esfuerzo, y cómo repartirlos en 90 días.
Leer análisisRadar de amenazas
Titulares recogidos de los feeds públicos de cada medio y clasificados automáticamente. Cada entrada enlaza a la fuente original: aquí solo verás el titular y un extracto breve.
-
PipeNetwork/minimax-h3-mlx
PipeNetwork/minimax-h3-mlx MiniMax released MiniMax-H3 two days ago - they describe it as a "a general-purpose, omni-modal generative system", which in practice means it accepts text, images, audio and video and can use them to generate up…
Simon Willison General simonwillison.net -
Iran Cyberattacks Against Minnesota Water Systems
Attribution is preliminary, and so far it seems no real damage. And it seems like this is a campaign that has targeted at least seven states. And, because this is where the US is right now, Trump doesn’t believe it’s Iran and that…
Schneier on Security Amenazas schneier.com -
Smoke#Screen RMM Takeover Gambit Exposes Threat Actor Playbook
The attacks use diverse social engineering lures and rotating payloads to deliver ScreenConnect for persistent remote access to compromised networks.
Dark Reading Amenazas darkreading.com -
Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps
Microsoft expands its Zero Trust for AI strategy to enhance security for AI and DevSecOps environments with new tools and guidance. The post Advance Zero Trust for AI: New tools and guidance to secure AI agents and DevSecOps appeared first…
Microsoft Security Blog Seguridad IA microsoft.com -
128 Seconds to disruption: Microsoft Defender stops ransomware at QNET
Microsoft Defender automatically isolated a compromised QNET endpoint in 128 seconds, stopping a multi-stage attack before the payload could persist or spread. The post 128 Seconds to disruption: Microsoft Defender stops ransomware at QNET…
Microsoft Security Blog Amenazas microsoft.com -
llm 0.32
Release: llm 0.32 See my detailed blog post about this release. Tags: llm
Simon Willison Seguridad IA simonwillison.net -
Bypassing AI guardrails is so easy a script kiddie can do it
Claiming 'it's my server' was often enough to persuade models to help
The Register · Security Seguridad IA theregister.com -
This one time, at Hacker Summer Camp …
What to expect as BSides, Black Hat, and DEF CON descend on Las Vegas
The Register · Security Amenazas theregister.com -
Feds get 3 days to patch N-able God mode flaw under active exploit
Experts warn hotfix not optional. MSPs warned attacker gains 'full administrative access to an N-central console'
The Register · Security Vulnerabilidades theregister.com -
AI helps Microsoft bug hunters chase a record $20M payday
Broader bounty rules added to a swelling volume of machine-assisted vulnerability reports
The Register · Security Seguridad IA theregister.com -
From Input to Impact: Secure AI Where It Runs
Defend the entire AI agentic stack across endpoints, identities, cloud, and apps with SentinelOne's unified platform.
SentinelOne Seguridad IA sentinelone.com -
The Frontier AI Vulnerability Burst: Industrializing Autonomous Zero-Day Discovery in Open-Source Software
Frontier AI is reshaping vulnerability discovery. Learn how our NOVA system found 14,000+ unknown vulnerabilities across the open-source software supply chain. The post The Frontier AI Vulnerability Burst: Industrializing Autonomous…
Unit 42 Seguridad IA unit42.paloaltonetworks.com -
AI Notetaker Lets Hackers Spy on Government, Corporate Video Calls
A Google Firebase misconfiguration lets users of tl;dv, an AI meeting tool, query any other users' meeting information and potentially join calls.
Dark Reading Seguridad IA darkreading.com -
Almost Half of Malware Samples Communicate Direct to IP
Nearly half of C2 malware bypasses DNS by connecting directly to IP addresses. Zero trust IP enforcement secures networks against these threats. The post Almost Half of Malware Samples Communicate Direct to IP appeared first on Unit 42.
Unit 42 Amenazas unit42.paloaltonetworks.com -
Tennessee congressional hopeful accused of shooting license plate cameras
Cops arrest budding politician for allegedly dealing with Flock's expansion the American way
The Register · Security General theregister.com -
Thermo Fisher Applied Biosystems Genetic Analyzers
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to modify .fsa/.hid output files, tampering with DNA data and resulting in inaccurate test results. The following versions of Thermo Fisher Applied…
CISA Advisories Vulnerabilidades cisa.gov -
Acrisure KARR BT and DR-100
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to perform unauthorized vehicle control operations. The following versions of Acrisure KARR BT and DR-100 are affected: KARR BT firmware
CISA Advisories Vulnerabilidades cisa.gov -
CISA Adds Three Known Exploited Vulnerabilities to Catalog
CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-9198 IBM Langflow Code Injection Vulnerability CVE-2026-18556 N-able N-central Authentication…
CISA Advisories Vulnerabilidades cisa.gov -
Some Claude Chats Are Searchable on Google
And it’s personal information (alternate link): The exposed data includes an AI-powered therapy app that someone appears to have vibe-coded, notes on meetings, and a dashboard someone made apparently to analyze medical billing data…
Schneier on Security Seguridad IA schneier.com -
“Keep going, bro. You’ve got this!” A data-driven look at how adversaries are weaponizing AI
Talos has collected prompt logs from threat actor endpoints running various applications, such as Claude Code, CodeX, Cursor, or Gemini. This blog is an analysis of the ways we've seen bad actors leveraging cloud-based AI.
Cisco Talos Seguridad IA blog.talosintelligence.com -
Device Code Phishing Up 1,500% in 2026; Vishing Doubles
Newer social engineering techniques help attackers ignore entrenched security controls and limit the evidence they leave behind.
Dark Reading Amenazas darkreading.com -
New ways to learn and teach with ChatGPT Work and Codex
Explore new education plugins for ChatGPT Work and Codex that help K–12 teachers, college educators, and students learn, teach, research, and build.
OpenAI Seguridad IA openai.com -
Apple is getting this wrong
OpenAI addresses Apple’s baseless lawsuit, corrects claims about its employees, and shares messages documenting what happened.
OpenAI Seguridad IA openai.com -
Attackers Exploit N-able Patch Bypass Flaw on RMM Servers
Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access.
Dark Reading Vulnerabilidades darkreading.com -
New Tool Traces AI Videos Back to Their Source
Researchers dug into the root of the problem with the goal of promoting industry collaboration on improved protective measures.
Dark Reading Seguridad IA darkreading.com
¿Y esto qué significa para ti?
Traducimos el ruido en un plan de control
Leer titulares no reduce el riesgo. Armemos el diagnóstico de tu exposición real y una hoja de ruta de 90 días con responsables y evidencia.