Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 26 min 968 titulares en el archivo
Qué se está publicando
Distribución por tema
- miércoles 26 ago
-
ICYMI: July 2026 @AWS Security
If you found time for a bit of vacation this summer, you might be in catch-up mode. Here’s a list to help: all the expert blog posts, new service capabilities, code samples, and workshops, in case you missed it, from July 2026. AWS…
AWS Security Infraestructura aws.amazon.com -
What We Still Don’t Know About OpenAI’s Hugging Face Hack
The AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails to explain why it didn't see this fiasco coming.
WIRED · Security Seguridad IA wired.com -
The inside story on why OpenAI agents hacked Hugging Face
The models responsible for last month’s agent hack of Hugging Face had been inadvertently trained to cheat and to communicate with each other, according to an OpenAI technical report released today. The hack, which a group of agents…
MIT Technology Review · IA Seguridad IA technologyreview.com -
FBI Disrupts Chinese Proxy Tools Used in Mass Hacking of US Agencies and Infrastructure
China’s hacking campaign targeted NASA, the Federal Reserve, the US Senate, the Justice Department, and more, according to the DOJ.
WIRED · Security Amenazas wired.com -
Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation
A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider…
AWS Security Infraestructura aws.amazon.com -
Intelligent transcription with Gemini 3.5 Transcribe
Now you can get more intelligent speech-to-text transcription with Gemini 3.5 Transcribe.
Google DeepMind Seguridad IA deepmind.google -
When AI infrastructure becomes the target: Securing gateways and control points
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The post When AI infrastructure becomes the target: Securing…
Microsoft Security Blog Seguridad IA microsoft.com -
Democratizing FinOps with Wiz: Driving Cost Attribution with the Wiz Service Catalog
How the Wiz Cloud Cost automates cost allocation to power developer-led cost optimization and connect cost to business value.
Wiz Infraestructura wiz.io -
The State of Cloud Risk 2026: Most Security Findings Aren’t Real Attacker Opportunities
Wiz Research telemetry reveals why the majority of high-severity findings lack a path to compromise
Wiz Infraestructura wiz.io -
Beyond Patching: What IT Teams Need to Know About Unpatchable Exposures
Executive Summary Most IT teams still operate under a false binary: patch or accept risk. That assumption creates unnecessary operational pressure. Patchless remediation is real and production-proven. Mitigate, Uninstall, Run Custom…
Qualys Vulnerabilidades blog.qualys.com -
When an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusion
On July 9, 2026, an autonomous AI agent escaped an OpenAI evaluation sandbox and conducted a multi-day intrusion into Hugging Face’s Kubernetes environment. Over roughly 17,600 actions, it reached dataset pipelines, production pods, cloud…
Qualys Seguridad IA blog.qualys.com -
Boston Scientific says cyberattack disrupted order processing, shipping
The medical device-maker says it cannot yet determine any financial impact from the attack it suffered this week.
Cybersecurity Dive Amenazas cybersecuritydive.com -
SLEEPWALKER introduce una puerta trasera para Windows que solo despierta con un único paquete de red
SLEEPWALKER es una puerta trasera para Windows diseñada para permanecer inactiva hasta recibir un único paquete de red cifrado y a medida. Cuando llega, el implante descifra y ejecuta un bytecode propio, lo que reduce el rastro en red y…
Hispasec · Una al día General unaaldia.hispasec.com -
Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who’s Exploiting Your Perimeter
A new joint study by Tenable and SentinelOne reveals how state and criminal groups converge on the same vulnerable edge infrastructure.
SentinelOne Vulnerabilidades sentinelone.com -
Spyware for Babies
The New York Times has a long article (alt link) on surveillance systems aimed at babies. They are increasingly using AI. Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels…
Schneier on Security Seguridad IA schneier.com -
CISA Adds Six Known Exploited Vulnerabilities to Catalog
CISA has added six new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2015-3246 Red Hat Libuser Race Condition Vulnerability CVE-2015-5287 Red Hat Automatic Bug Reporting…
CISA Advisories Vulnerabilidades cisa.gov -
CISA Vulnerability Review
Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and…
CISA Advisories Vulnerabilidades cisa.gov -
VMs won't contain cyber-capable agents
As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing…
Trail of Bits Vulnerabilidades blog.trailofbits.com -
Choose your fighter: Balancing competing requirements to select models for your AI SOC
Selecting a model for your security operations center (SOC) and digital forensics and incident response (DFIR) tasks is important, but selecting the best one is more involved than you might think. Here's how to choose.
Cisco Talos Seguridad IA blog.talosintelligence.com -
Exploits and vulnerabilities in Q2 2026
This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.
Securelist (Kaspersky) Seguridad IA securelist.com -
Raised on AI
When my oldest child was born, I immediately set up Gmail and Twitter accounts in her name. I broadly announced her birth online and proceeded to plaster her photo across all sorts of platforms. In short, I began creating her digital…
MIT Technology Review · IA Seguridad IA technologyreview.com -
AI models flub these intelligence tests. Can you fare any better?
Puzzles and games have been central to AI development since the very beginning. Just as we humans like to test our smarts with crosswords or logic puzzles, developers can test how far models have advanced with a gaming gauntlet. The term…
MIT Technology Review · IA Seguridad IA technologyreview.com -
Bill Gates says we’ve passed AI’s danger thresholds. Now what?
It’s a glorious day in Kirkland, Washington, an affluent Seattle suburb on the eastern shore of Lake Washington. The temperature is in the mid-80s, and the sky is incapable of being any more blue. The view from the Gates Ventures…
MIT Technology Review · IA Seguridad IA technologyreview.com -
El Smishing de la Seguridad Social y cómo protegerte Cloudflare ONE
El lunes por la tarde recibí un mensaje SMS de la TGSS (Tesorería General de la Seguridad Social). Por supuesto, como venía del mismo número de teléfono que siempre, se coló en mi lista de mensajes de la TGSS, donde tengo el historial de…
El lado del mal Infraestructura elladodelmal.com -
Why Your AI Application Is Exposed
AI applications can pass security scans yet remain exploitable through chained attacks across models, tools, data, and business workflows. Learn how DAST, AI pentesting, and red teaming work together to expose end-to-end risk.
Snyk Seguridad IA snyk.io - martes 25 ago
-
Recorded Future Launches AI Alert Filtering
AI Alert Filtering is now available. Powered by Recorded Future AI, it automates the first pass of filtering Alerts by relevance so analysts prioritize faster while keeping control.
Recorded Future Seguridad IA recordedfuture.com -
Fast Track ISM-ready cloud environments and IRAP Assessments with Landing Zone Accelerator on AWS
This post announces the availability of a new independent assessment report available on AWS Artifact analyzing how Landing Zone Accelerator on AWS (LZA) can automatically deploy multi-account environments in Amazon Web Services (AWS) with…
AWS Security Infraestructura aws.amazon.com -
A Cautionary Tale About Data Breach Claims, Verification and Carhartt
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteYou're not going to believe this, but turns out you can't always take criminals at their word…
Troy Hunt Amenazas troyhunt.com -
The patch window is collapsing: Why security needs a new control plane
Organizations need protection that operates in the gap between discovery and remediation. The post The patch window is collapsing: Why security needs a new control plane appeared first on Microsoft Security Blog.
Microsoft Security Blog Vulnerabilidades azure.microsoft.com -
WhatsApp añade Passkey para inicios de sesión resistentes al phishing en iOS y Android
Meta anunció una serie de funciones de seguridad para las cuentas de WhatsApp, incluyendo la compatibilidad con passkey para una cuenta. Esto permitirá a los usuarios de dispositivos iOS y Android iniciar sesión en sus cuentas mediante un…
Segu-Info Amenazas blog.segu-info.com.ar
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.