Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 31 min 966 titulares en el archivo
Qué se está publicando
Distribución por tema
- lunes 31 ago
-
Anthropic Users Hit by Infostealer Attacks, Session Thefts
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
Dark Reading Seguridad IA darkreading.com -
'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.
Dark Reading Amenazas darkreading.com -
The Guardrails Debate: Security Researcher Changes His Mind
While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the rules.
Dark Reading General darkreading.com -
The Coding-Agent Trap: When a "Free" LLM Endpoint Is the Adversary, (Mon, Aug 31st)
One of my internet-exposed inference honeypots was discovered, relabeled with sought-after model names, and incorporated into infrastructure apparently used to provide "free" LLM backends. It then received a real coding-agent session…
SANS Internet Storm Center Seguridad IA isc.sans.edu -
La falsa sensación de seguridad: por qué la madurez digital no depende de la cantidad de herramientas
Tener firewall y respaldos no garantiza una protección real. Descubre por qué la madurez digital requiere visibilidad, análisis y respuesta.
WeLiveSecurity (ESET) Infraestructura welivesecurity.com -
OpenClaw 2.0 pours glitter on slow-burning security dumpster fire
Making installation easier and putting a new wrapper on the interface while leaving most of the security to users is a recipe for more trouble with the popular agent harness
The Register · Security General theregister.com -
We invited a direct competitor into Security Hub Extended. Here’s why.
When customers keep pointing you to a solution that overlaps with parts of your own offering, you have a choice to make. This post is about the choice we made with Upwind, and why we’d make it again. AWS Security Hub Extended exists…
AWS Security Infraestructura aws.amazon.com -
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
Next-level ClickFix wave sets off multi-stage attack chain
The Register · Security Amenazas theregister.com -
Is Someone Hacking DoD Refrigerators?
It sure seems like it. The stores confirmed to be affected include Fort Irwin, Calif.; F.E. Warren Air Force Base, Wyo.; Fort Huachuca, Ariz.; Naval Station Newport, R.I.; Columbus Air Force Base, Miss.; and Travis Air Force Base, Calif…
Schneier on Security General schneier.com -
The Hugging Face hack could indicate cultural issues at OpenAI
This story originally appeared in The Algorithm, our weekly newsletter on AI. To get stories like this in your inbox first, sign up here. By now you’ve probably heard about last month’s major AI security incident, in which OpenAI agents…
MIT Technology Review · IA Seguridad IA technologyreview.com -
AI Model Rules Are Not Security Controls
OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.
Dark Reading Seguridad IA darkreading.com -
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected…
The Hacker News Amenazas thehackernews.com -
Automate IAM Identity Center governance with continuous discovery and reporting
AWS IAM Identity Center integrates with external identity provider (IdP) to provide customers with a centralized authentication and authorization solution for AWS resources across AWS Organizations. AWS continues to invest into IAM…
AWS Security Infraestructura aws.amazon.com -
Anthropic cracks down on hijacked user accounts mining AI tokens
Commodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage
The Register · Security Seguridad IA theregister.com -
PaperCut issues emergency patches as threat actors target chained vulnerabilities
The print management software maker faced a wave of attacks in 2023 aimed at higher education customers.
Cybersecurity Dive Vulnerabilidades cybersecuritydive.com -
State-linked actor targets Cisco routers for espionage
An actor known as Fire Ant has expanded its reach into trusted environments, with unique tooling and stealth.
Cybersecurity Dive Amenazas cybersecuritydive.com -
Huntress API Update: New Endpoints, Webhooks, and Automation
The Huntress API has grown from six read-only endpoints into a full integration and automation platform. See what’s new, including webhooks and MCP support.
Huntress Seguridad IA huntress.com -
Breaking the Seal: Static Deobfuscation of JSCeal’s Compiled V8 Bytecode
Research by: hasherezade Key Points Introduction JSCeal is a stealer delivered as compiled V8 bytecode (.jsc) and executed by a bundled Node.js runtime, targeting cryptocurrency applications (other vendors also tag it with the names…
Check Point Research General research.checkpoint.com -
Introducing Adaptive Intelligence: Undermining the economics of every bot attack
Bot operators have historically had the economic advantage, bypassing static, deterministic detection rules with cheap proxies and retooling. Cloudflare's new Adaptive Intelligence engine flips this dynamic by autonomously learning from…
Cloudflare Infraestructura blog.cloudflare.com -
31th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East…
Check Point Research General research.checkpoint.com -
"Si no se parchean las vulnerabilidades KEV, no se está protegido"
El Informe de Vulnerabilidades de CISA para los años 2024 y 2025, publicado recientemente, transmite un mensaje contundente: las brechas de seguridad que acaparan titulares rara vez se basan en vulnerabilidades de día cero. En cambio, la…
Segu-Info Vulnerabilidades blog.segu-info.com.ar -
CISA Adds Two Known Exploited Vulnerabilities to Catalog
CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-81578 PaperCut NG/MF Missing Authentication for Critical Function Vulnerability CVE-2026-82078…
CISA Advisories Vulnerabilidades cisa.gov -
Hiding Prompt Injection in Legal Filing
Someone hid AI instructions into a legal filing. Alternate link.
Schneier on Security Seguridad IA schneier.com -
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on…
Unit 42 Amenazas unit42.paloaltonetworks.com -
ValleyRAT masquerading as adware
Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.
Securelist (Kaspersky) Regulación securelist.com -
ATM Flaws Reveal Key Weaknesses in the Software Supply Chain
A security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local cash machine.
WIRED · Security Vulnerabilidades wired.com -
This month in security with Tony Anscombe – August 2026 edition
Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity news
WeLiveSecurity (ESET) General welivesecurity.com -
Más de 8.300 servidores Gitea quedan expuestos a ataques de ejecución remota por CVE-2026-60004
Miles de instancias de Gitea accesibles desde Internet seguían sin parchear a finales de agosto frente a CVE-2026-60004, un fallo crítico que permite ejecución remota de comandos. La corrección llegó con Gitea 1.27.1 y el problema ya…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com -
OpenAI supports California’s bill to advance youth AI safety
OpenAI supports California SB 1119, advancing strong, age-appropriate AI safeguards for teens while preserving opportunities to learn, create, and explore.
OpenAI Seguridad IA openai.com -
Polimill builds Japan's next-generation public AI infrastructure
Polimill uses OpenAI GPT models and Codex to help municipalities search and use administrative knowledge while accelerating development.
OpenAI Seguridad IA openai.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.