Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 54 min 963 titulares en el archivo
Qué se está publicando
Distribución por tema
- martes 1 sep
-
Critical Langflow flaw exploited to steal OpenAI and AWS keys
Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [...]
BleepingComputer Seguridad IA bleepingcomputer.com -
Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure
Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of…
The Hacker News Vulnerabilidades thehackernews.com -
What’s the Scam?
To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own…
Schneier on Security General schneier.com -
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams…
The Hacker News Amenazas thehackernews.com -
Introducing agentic video understanding with Gemini
Google DeepMind Seguridad IA deepmind.google -
Quoting Tarn Adams
They took the letters from me! I have to talk about dwarf behavior now. I can't even talk about dwarf AI. It doesn't exist. It's dwarf behavior, and they misbehave sometimes — Tarn Adams, co-creator of Dwarf Fortress Tags: ai, game-design
Simon Willison Seguridad IA simonwillison.net -
How AI-native companies turn workflows into operating capability
Basis, Clay, and Exa Labs use AI agents to improve onboarding, account management, and developer integrations. See what enterprise leaders can apply.
OpenAI Seguridad IA openai.com -
Leaked Russian Cyber-Operations Training Materials
This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications…
Schneier on Security General schneier.com -
Fake GTA 6 leaked copy drains your crypto wallet
A fake GTA 6 leak is using wallet-draining code to steal cryptocurrency, tokens, and NFTs from eager fans.
Malwarebytes Labs General malwarebytes.com -
Security policies fail to keep up with a hybrid cloud world
Roughly two-thirds of companies have suffered a business-critical app outage due to misconfigured security policies, a Cloud Security Alliance report found.
Cybersecurity Dive Infraestructura cybersecuritydive.com -
Healthcare facilities operator Nutex says patient, employee data stolen in August incident
Cybercriminals breached company data and made an extortion attempt with it, Houston-based Nutex Health said in a filing with federal regulators.
The Record Regulación therecord.media -
datasette-mcp 0.2
Release: datasette-mcp 0.2 "rows" from execute_sql is now an array of objects. Previously it was an array of arrays. This should help weaker models avoid losing track of which positional array element maps to which column. #1 Now depends…
Simon Willison Seguridad IA simonwillison.net -
Frontier AI helps exploit flaws in tests using key industrial devices
A report showed that Claude could help hackers develop attack strategies targeting PLCs used by water utilities and other industries.
Cybersecurity Dive Seguridad IA cybersecuritydive.com -
Python 3.15.0 candidate 2 is here!
Python 3.15.0 candidate 2 is here! Hugo van Kemenade (release manager for Python 3.14 and 3.15) announces the final release candidate for Python 3.15, scheduled for release in October: Entering the release candidate phase, only reviewed…
Simon Willison General simonwillison.net -
Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]
BleepingComputer Amenazas bleepingcomputer.com -
Attackers Steal METR API Key and Burn $600,000 in AI Credits
Attackers used a stolen METR API key for three weeks, consuming model credits worth $600,000
Infosecurity Magazine Seguridad IA infosecurity-magazine.com -
Novocure data breach affects more than 1,400 cancer patients
Healthtech company Novocure says the data of an undisclosed number of employees and more than 1,400 U.S. cancer patients has been exposed in a mid-August cyberattack. [...]
BleepingComputer Amenazas bleepingcomputer.com -
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the…
The Hacker News Vulnerabilidades thehackernews.com -
Why Even the Best Edge Security Still Misses High-Risk Sessions
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations…
BleepingComputer General bleepingcomputer.com -
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
Dark Reading Amenazas darkreading.com -
65% of Enterprises Have Seen AI Agents Act Out of Scope
EMA survey finds 65% of enterprises have seen AI agents act beyond intended scope
Infosecurity Magazine Seguridad IA infosecurity-magazine.com -
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS…
The Hacker News Amenazas thehackernews.com -
Path to Astra: critical capabilities and frontier safeguards
Astra is the first OpenAI model to meet the Critical cybersecurity capability threshold under the Preparedness Framework, with stronger safeguards for release.
OpenAI Seguridad IA openai.com -
How we could save petabytes of cache storage with Zstandard and Pingora
Could we get more cache space with the same hardware? We prototyped compression inside Cloudflare's cache to find out.
Cloudflare Infraestructura blog.cloudflare.com -
White House Launches Pilot Program in Texas to Protect Water Infrastructure
Project Watershed 250 will see water providers in Texas provided with federal and private sector cybersecurity resources amid rising nation-state threats
Infosecurity Magazine General infosecurity-magazine.com -
Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks
Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
TerminalFix looks like ClickFix, but delivers a very different payload
The familiar ClickFix fake CAPTCHA trick has been adapted to deliver a payload that can give attackers access to the victim’s wider network.
Malwarebytes Labs General malwarebytes.com -
33-hour BGP hijack of Softaculous traffic prompts security scramble
Hosting software vendor tells customers to reset credentials and hunt for malicious packages
The Register · Security General theregister.com -
Rockwell Automation RSLinx Classic
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx…
CISA Advisories Vulnerabilidades cisa.gov -
Rockwell Automation Historian ME
View CSAF Summary Successful exploitation of these vulnerabilities could crash the device being accessed; an out-of-bounds write condition may allow remote code execution. The following versions of Rockwell Automation Historian ME are…
CISA Advisories Vulnerabilidades cisa.gov
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.