Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 12 min 963 titulares en el archivo
Qué se está publicando
Distribución por tema
316 titulares de severidad Media Limpiar filtros ×
- lunes 10 ago
-
IT threat evolution in Q2 2026. Non-mobile statistics
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.
Securelist (Kaspersky) Amenazas securelist.com - domingo 9 ago
-
The Hugging Face Hack Was Cheap Persistence at Work
The Hugging Face and OpenAI security incident showed AI doesn't make attackers smarter. It makes persistence cheap, and defenses built for alerts can't keep up.
Recorded Future Seguridad IA recordedfuture.com - viernes 7 ago
-
ICS Security Conference 2026
JPCERT/CC held the ICS Security Conference 2026 on February 10, 2026. This conference aims to share the current threat landscape surrounding Industrial Control System (ICS) in Japan and abroad, as well as initiatives undertaken by…
JPCERT/CC General blogs.jpcert.or.jp - jueves 6 ago
-
Canadian Man Pleads Guilty in Snowflake Extortions
A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy to hack and extort more than 165 organizations that used the cloud data storage…
Krebs on Security Amenazas krebsonsecurity.com - miércoles 5 ago
-
CRLF-Powered Desync Attacks: Beheading HTTP Streams
Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power
PortSwigger Research General portswigger.net -
Can AI do novel security research? Meet the HTTP Terminator
Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Buildi
PortSwigger Research Seguridad IA portswigger.net - martes 4 ago
-
Un arresto del FBI demuestra que ni Steam ni las plataformas oficiales son infalibles
Un cibercriminal distribuyó malware mediante videojuegos publicados en Steam e infectó a más de 8.000 equipos. El caso revela los límites de los controles de seguridad y la importancia de verificar qué se descarga, incluso desde…
WeLiveSecurity (ESET) Amenazas welivesecurity.com -
A First Look at Evo Agentic AppSec: Agentic Remediation and Malicious Code Defense
Explore Snyk’s first Agentic AppSec capabilities: an autonomous Remediation Agent that fixes vulnerabilities and Malicious Code Defense that blocks risky packages before they ship.
Snyk Seguridad IA snyk.io - lunes 3 ago
-
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
A malware campaign disguised as an “undetected” version of the Xeno Roblox script executor is directly affecting players looking to download a legitimate tool.
Bitdefender Labs Amenazas bitdefender.com - jueves 30 jul
-
Por qué el phishing sigue funcionando: el 73% de las empresas en América Latina lo confirma
Los ciberdelincuentes siguen apostando por el error humano: el phishing mantiene altos niveles de impacto regional.
WeLiveSecurity (ESET) Amenazas welivesecurity.com -
A hole in every one: bypassing the open source AI skill scanners
We ran eight open source AI skill scanners against real attacks. A malicious skill got past all eight, including the current OASB leaderboard leader.
Adversa AI Seguridad IA adversa.ai -
Escaping Linux Sandboxes via PipeWire (CVE-2026-5674)
This post walks through a sandbox escape from a Flatpak application via PipeWire. The vulnerability was discovered using my automated research pipeline with Claude Code and Opus 4.6 back in April 2026. It was an exciting find, as this was…
Embrace The Red Seguridad IA embracethered.com -
The July 2026 Apple Security Update Review
Welcome to our monthly look at Apple security patches. This release shows that Apple is not immune to the bug apocalypse that is impacting other vendors. Last month, they released 37 unique CVEs compare to this month’s 210. Quite a…
Zero Day Initiative Vulnerabilidades thezdi.com - martes 28 jul
-
How we use /goal to find bugs in Patch the Planet
Codex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the right scope, and the right number of outcomes per run. For Patch the Planet, our joint initiative with OpenAI to find and fix bugs in…
Trail of Bits Seguridad IA blog.trailofbits.com - miércoles 22 jul
-
TSUBAME Report Overflow (Jan-Mar 2026)
This TSUBAME Report Overflow series discusses observation trends from TSUBAME sensors both in Japan and overseas, as well as other topics not covered in the Internet Threat Monitoring Quarterly Report. This article covers monitoring…
JPCERT/CC General blogs.jpcert.or.jp -
Next chapter: Restructuring GitHub’s bug bounty program
GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team. The post Next chapter: Restructuring GitHub’s bug bounty program appeared first…
GitHub Security Vulnerabilidades github.blog -
From Triage Grind to Strategic Operator: The New AI SOC Career Path
Learn how AI is reshaping SOC careers, elevating analysts from manual triage to strategic threat hunting and AI governance.
SentinelOne Seguridad IA sentinelone.com - martes 21 jul
-
Pwn2Own Ireland 2026 – New Targets and Categories
If you just want to read the rules, you can find them here. Pwn2Own Ireland returns for 2026, and it’s the third year for this event in the Emerald Isle. Despite the dreary Irish skies (and the threat of a random banshee), we had an…
Zero Day Initiative General thezdi.com - martes 14 jul
-
Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch…
Krebs on Security Vulnerabilidades krebsonsecurity.com -
The July 2026 Security Update Review
Well folks. Here we are. The bug apocalypse has fully descended upon us. I’ll do my best to sort this out in some way meaningful, but this month’s release shows us the nay-sayers were right, and I’ve got to hand it to the nay-sayers here…
Zero Day Initiative Vulnerabilidades thezdi.com - lunes 13 jul
-
Update on Attacks by Threat Group APT-C-60 in 2026
In our previous two blog posts (Dec 2024...
JPCERT/CC Amenazas blogs.jpcert.or.jp - miércoles 8 jul
-
HPC AI Workloads Need Runtime Security. The Architecture Already Exists.
Learn how to secure HPC AI infrastructure against runtime and supply chain threats via continuous behavioral monitoring.
SentinelOne Seguridad IA sentinelone.com - lunes 6 jul
-
OWASP CVE Lite CLI Graduates to Lab Project Status
CVE Lite CLI, a fast open source dependency vulnerability scanner for JavaScript and TypeScript projects, has graduated to OWASP Lab Project status three months after its initial release. OWASP CVE Lite CLI graduated to Lab Project status…
OWASP Vulnerabilidades owasp.org - miércoles 1 jul
-
Silver Bullet Security Podcast 158 – Artem Dinaburg
View on Zencastr On Episode 158 of the Silver Bullet Security Podcast, BIML’s Gary McGraw hosts Artem Dinaburg. Artem talks about using Agentic AI to find, fix, and exploit software security defects. We talk decompilation, stochasticism…
Berryville Institute (BIML) Seguridad IA berryvilleiml.com -
The June 2026 Apple Security Update Review
We’re back with our look at the Apple macOS and iOS security updates. As this is a new feature for us, please let us know your feedback on the blog. For June 2026, Apple released 37 unique CVEs across iOS 26.5.2 / iPadOS 26.5.2, macOS…
Zero Day Initiative Vulnerabilidades thezdi.com - lunes 29 jun
-
Inside the Advisory Database and what happens when vulnerability volume breaks records
The GitHub Advisory Database is processing more vulnerability reports than ever before. Here's what's driving the surge, how we're responding, and how the community can help. The post Inside the Advisory Database and what happens when…
GitHub Security Vulnerabilidades github.blog - jueves 25 jun
-
Computer-Use and TOCTOU: What You Click Is Not What You Get!
Last year, Jun Kokatsu disclosed an interesting vulnerability with ChatGPT Operator by exploiting a race condition. I was wondering if I could reproduce this attack chain, and this post describes the results of that research. I had this…
Embrace The Red Seguridad IA embracethered.com - miércoles 24 jun
-
Advancing Product Security: New IoT Guidance and New Engagement
It may be summertime, but the NIST Cybersecurity for the Internet of Things (IoT) Program isn’t hitting the hammock! Organizations are managing growing device complexity, evolving threats, and pressure to turn guidance into operational…
NIST Cybersecurity General nist.gov - martes 9 jun
-
The June 2026 Security Update Review
I’ve made it through Pwn2Own Berlin, had a little vacation, and now I’m back for Patch Tuesday. Microsoft and Adobe didn’t disappoint. In fact, they have heralded my return with the largest Patch Tuesday release ever. Thanks? Take a break…
Zero Day Initiative Vulnerabilidades thezdi.com - miércoles 27 may
-
Football Fever Fuels Scam Campaigns Across Email and Social Media
Football fans are increasingly targeted by scams exploiting club loyalty, national teams, football collectibles, streaming demand, and the growing excitement around the FIFA World Cup 2026, according to Bitdefender Labs. Our most recent…
Bitdefender Labs Vulnerabilidades bitdefender.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.