Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 55 min 963 titulares en el archivo
Qué se está publicando
Distribución por tema
316 titulares de severidad Media Limpiar filtros ×
- martes 19 may
-
Microsoft’s MSHTA Legacy Tool Still Powers Malware Campaigns on Windows
Bitdefender security researchers have discovered that attackers continue to exploit Microsoft HTML Application Host (MSHTA), a legacy utility available by default on Windows systems that can execute VBScript and JavaScript from local or…
Bitdefender Labs Vulnerabilidades bitdefender.com - sábado 16 may
-
Pwn2Own Berlin 2026: Day Three Results and Master of Pw
Following two days of intense competition, Day Three of Pwn2Own Berlin 2026 brought the curtain down on an incredible event. Security researchers delivered their final exploits, pushing enterprise systems to the limit one last time as the…
Zero Day Initiative Vulnerabilidades thezdi.com - viernes 15 may
-
Raising the bar: Quality, shared responsibility, and the future of GitHub’s bug bounty program
We're updating our bug bounty program standards to prioritize quality submissions, clarify shared responsibility boundaries, and evolve how we reward low-risk findings. The post Raising the bar: Quality, shared responsibility, and the…
GitHub Security Vulnerabilidades github.blog -
Pwn2Own Berlin 2026 - Day Two Results
Day Two of Pwn2Own Berlin 2026 and the stakes continue to rise! Security researchers are back on the Pwn2Own stage, pushing enterprise systems to their limits as the competition heats up. More exploits, more surprises, and more standout…
Zero Day Initiative Vulnerabilidades thezdi.com -
TSUBAME Report Overflow (Oct-Dec 2025)
This TSUBAME Report Overflow series discuss monitoring trends of overseas TSUBAME sensors and other activities which the Internet Threat Monitoring Quarterly Reports do not include. This article covers the monitoring results for the period…
JPCERT/CC General blogs.jpcert.or.jp - lunes 4 may
-
Copirate 365 at DEF CON: Plundering in the Depths of Microsoft Copilot (CVE-2026-24299)
This is a writeup of my DEF CON Singapore talk that walks through vulnerabilities and exploits in M365 Copilot and Consumer Copilot. I disclosed these to Microsoft last year. MSRC assigned CVE-2026-24299 and the issues are now patched…
Embrace The Red Seguridad IA embracethered.com - viernes 17 abr
-
Breaking Opus 4.7 with ChatGPT (Hacking Claude's Memory)
In this post, we explore how ChatGPT generated an adversarial image that hijacked my Claude Opus 4.7 to invoke the memory tool and persist false memories for future chats. This matters because Opus 4.6+ is genuinely a lot harder to attack…
Embrace The Red Seguridad IA embracethered.com - viernes 10 abr
-
Bringing Rust to the Pixel Baseband
Posted by Jiacheng Lu, Software Engineer, Google Pixel Team Google is continuously advancing the security of Pixel devices. We have been focusing on hardening the cellular baseband modem against exploitation. Recognizing the risks…
Google Security Blog Vulnerabilidades security.googleblog.com - miércoles 8 abr
-
Given Enough Agents, All Bugs Become Shallow
Agents are becoming extremely effective at finding security vulnerabilities. They are relentless in analyzing code and you can spin up multiple of them to go through source code quickly. given enough agents, all bugs are shallow— Johann…
Embrace The Red Vulnerabilidades embracethered.com - jueves 2 abr
-
Mitigating prompt injection attacks with a layered defense strategy
Posted by Adam Gavish, Google GenAI Security TeamWith the rapid adoption of generative AI, a new wave of threats is emerging across the industry with the aim of manipulating the AI systems themselves. One such emerging attack vector is…
Google Security Blog Seguridad IA security.googleblog.com -
Google Workspace’s continuous approach to mitigating indirect prompt injections
Posted by Adam Gavish, Google GenAI Security TeamIndirect prompt injection (IPI) is an evolving threat vector targeting users of complex AI applications with multiple data sources, such as Workspace with Gemini. This technique enables the…
Google Security Blog Seguridad IA security.googleblog.com - miércoles 1 abr
-
Study of Binaries Created with Rust through Reverse Engineering
Rust has been gaining attention in recent years as a language expected to replace C and C++, due to its memory safety and high performance. While Rust continues to be adopted as a programming language, malware developed using Rust…
JPCERT/CC Amenazas blogs.jpcert.or.jp - martes 31 mar
-
VRP 2025 Year in Review
Posted by Dirk Göhmann, Tony Mendez, and the Vulnerability Rewards Program Team2025 marked a special year in the history of vulnerability rewards and bug bounty programs at Google: our 15th anniversary 🎉🎉🎉! Originally started in 2010, our…
Google Security Blog Vulnerabilidades security.googleblog.com - lunes 30 mar
-
TSUBAME Report Overflow (Jul-Sep 2025)
This TSUBAME Report Overflow series discusses monitoring trends observed by overseas TSUBAME sensors, as well as other activities that are not included in the Internet Threat Monitoring Quarterly Reports. This article covers the monitoring…
JPCERT/CC General blogs.jpcert.or.jp - miércoles 18 mar
-
Windsurf IDE Extension Drops Malware via Solana Blockchain
Bitdefender researchers have discovered a malicious Windsurf IDE (integrated development environment) extension that deploys a multi-stage NodeJS stealer by using the Solana blockchain as the payload infrastructure.
Bitdefender Labs Amenazas bitdefender.com - miércoles 11 mar
-
Windows and macOS Malware Spreads via Fake “Claude Code” Google Ads
Bitdefender’s security researchers have discovered a malicious Google Ads campaign targeting anyone searching for downloads related to Claude, the large language model developed by Anthropic.
Bitdefender Labs Seguridad IA bitdefender.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.