Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 57 min 970 titulares en el archivo
Qué se está publicando
Distribución por tema
- miércoles 19 ago
-
Prison for data analyst who tried to extort $2.5 million from his employer
When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume. But what the 27-year-old from Charlotte, North…
Graham Cluley General bitdefender.com - martes 18 ago
-
Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs
Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates.Key TakeawaysThe August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943…
Tenable Vulnerabilidades tenable.com -
Recorded Future Launches 6 New Capabilities for Third-Party Risk
Recorded Future has launched native risk ratings capabilities inside its Third-Party Risk product, uniting threat intelligence and risk ratings in a single workflow.
Recorded Future General recordedfuture.com -
Remediation Agents, Demystified: Why Fixing Beats Finding
See how Snyk’s Remediation Agent uses security intelligence, breakability analysis, and validation to turn vulnerabilities into mergeable pull requests.
Snyk Vulnerabilidades snyk.io -
State of AI Cybersecurity 2026: 77% of Security Stacks Include AI, But Trust is Lagging
Originally published by Darktrace. AI is now embedded throughout the cybersecurity stack, but findings from the State of AI Cybersecurity 2026 show that adoption is growing much faster than trust or understanding. As vendors strive to…
Cloud Security Alliance Seguridad IA cloudsecurityalliance.org -
MITRE's New Continuous Remote Attestation Framework for the AI Era
As AI makes decisions on infrastructure that changes by the minute, MITRE is formalizing how to verify those systems stay trustworthy while they run, not just when they boot. Why MITRE built a new framework For most of computing history…
Cloud Security Alliance Seguridad IA cloudsecurityalliance.org -
EU AI Act Compliance for High-Risk AI Systems: What Your Organization Needs to Know
A Q&A about the EU AI Act with Schellman CEO Avani Desai on risk classification, AI literacy, and the August 2 deadline Schellman CEO, Avani Desai, recently joined a DataCamp panel webinar, "Deadline Approaching: EU AI Act Compliance for…
Cloud Security Alliance Seguridad IA cloudsecurityalliance.org -
We Asked an AI Agent to Close a Linear Ticket. It Dropped a Production Table.
Originally published by Eve Security. A developer opens Cursor, points it at a Linear ticket, and asks it to implement the fix. Cursor loads ticket-work, a small skill that standardizes how the agent pulls context from Linear and closes…
Cloud Security Alliance Seguridad IA cloudsecurityalliance.org -
AI Governance Programs: What CISOs Say vs. What They Actually Do
Security leaders have heard the phrase “AI has expanded the attack surface” enough times. The more interesting story is the widening gap between what CISOs say they're doing about it and what's actually happening inside their…
Cloud Security Alliance Seguridad IA cloudsecurityalliance.org -
Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)
In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks. The post Threat Brief: Mitigating…
Unit 42 General unit42.paloaltonetworks.com -
CVE-2026-68820 is in KEV. Here Is What CISA BOD 26-04 Actually Requires Now
Executive Summary CVE-2026-68820 is an actively exploited Windows vulnerability listed in CISA’s Known Exploited Vulnerabilities (KEV) Catalog, with a remediation deadline as suggested by CISA BOD 26-04. CISA BOD 26-04 introduces…
Qualys Vulnerabilidades blog.qualys.com -
Hunting MacSync Stealer infrastructure through behavioral pivots
MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots. The post Hunting MacSync Stealer infrastructure through…
Microsoft Security Blog General microsoft.com -
Quishing: cómo los códigos QR pueden eludir la seguridad corporativa
El quishing se ha convertido en una alternativa popular al phishing tradicional. Así es como las empresas pueden cerrar esa brecha.
WeLiveSecurity (ESET) Amenazas welivesecurity.com -
SafePal y Trezor revelan sendas brechas de datos en sus sistemas de pedidos
SafePal ha revelado que una vulnerabilidad de autorización en un complemento de seguimiento de pedidos expuso los nombres, direcciones de correo electrónico, direcciones de envío, números de teléfono y detalles de compra de aproximadamente…
Segu-Info Vulnerabilidades blog.segu-info.com.ar -
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Research by: Jaromír Hořejší (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts…
Check Point Research Amenazas research.checkpoint.com -
New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles
You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use…
Rapid7 Seguridad IA rapid7.com -
Legacy Operating Models Can’t Keep Pace With IT Complexity, Cloud Security Alliance Survey Finds
Study reveals that fragmented ownership and limited visibility have made manual policy management a production risk SEATTLE – Aug. 18, 2026 — Fragmented operating models spanning teams, tools, and environments and which are still heavily…
Cloud Security Alliance Infraestructura cloudsecurityalliance.org -
Top 10 zero-click attacks against AI agents
Ten documented zero-click attacks on AI agents in shipped products: what each one broke, which CVEs followed, and the controls that reduce the risk.
Adversa AI Seguridad IA adversa.ai -
Benchmarking Secure-and-Functional Remediation and How Snyk Agent Fix Lifts Frontier-Model Fix Rates by over 14%
A benchmark of secure, functional vulnerability fixes across JavaScript, Java, and Python shows Snyk Intelligence helps frontier models break past a 72–75% performance plateau.
Snyk Vulnerabilidades snyk.io - lunes 17 ago
-
Weekly Update 517: Cyber Ransoms
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteThe current ransomware situation is a bit of a kludge (deep breath): a lot of ransomware (which…
Troy Hunt Amenazas troyhunt.com -
PurpleDelta's Fraudulent Employment Operations
Learn how North Korean IT worker threat cluster "PurpleDelta" uses AI-generated personas, sophisticated tradecraft, and custom ChatGPT assistants to infiltrate organizations. Discover key indicators of compromise and mitigation strategies…
Recorded Future Seguridad IA recordedfuture.com -
CopyCop Targets AI Investment in Armenia
The Russian influence network CopyCop is targeting Western-backed AI and infrastructure projects in Armenia, including the Firebird AI data center, to undermine the country’s westward geopolitical realignment.
Recorded Future Seguridad IA recordedfuture.com -
Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities
Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose…
Tenable Seguridad IA tenable.com -
An “invisible” car? Researcher uses machine learning to hide vehicles from Flock cameras
A cybersecurity expert has demonstrated how computer-generated patterns can successfully prevent surveillance cameras from detecting vehicles - such as the controversial AI-powered Flock licence plate readers that are becoming increasingly…
Graham Cluley Seguridad IA bitdefender.com -
17th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 17th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Colombia’s Ministry of Justice has experienced a ransomware attack that affected part of…
Check Point Research Amenazas research.checkpoint.com -
Cadena de exploits para videollamadas VoLTE Unisoc otorga acceso completo al kernel de Android
Investigadores de seguridad de SSD Secure Disclosure han publicado una cadena de exploits en dos etapas que permite el acceso completo al kernel de Android en dispositivos con firmware de módem Unisoc mediante una videollamada VoLTE, sin…
Segu-Info Vulnerabilidades blog.segu-info.com.ar -
Stronger Cybersecurity Programs Start with People: NIST Wants Your Input on the Path Forward for Human-Centered Cybersecurity
When was the last time a cybersecurity process at work made you want to scream? Maybe it was a password requirement so complicated you had to write it down (defeating the purpose), a phishing simulation test that felt more like a trap than…
NIST Cybersecurity Amenazas nist.gov -
How QR-code phishing can slip past corporate security measures
Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap.
WeLiveSecurity (ESET) Amenazas welivesecurity.com - domingo 16 ago
-
Recovering Encrypted LLM Reasoning Traces
A few days ago, a paper named “Stealing Reasoning Traces from Proprietary LLM APIs” was published. It describes a simple, yet super elegant way to recover encrypted LLM reasoning traces. Naturally, I had to try it. Background AI labs like…
Embrace The Red Seguridad IA embracethered.com - viernes 14 ago
-
The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure
Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous…
Tenable Seguridad IA tenable.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.