Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 31 min 970 titulares en el archivo
Qué se está publicando
Distribución por tema
- jueves 13 ago
-
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release
Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical…
The Hacker News Vulnerabilidades thehackernews.com -
Four corporate investigation mistakes organizations make under pressure
In this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Access gets…
Help Net Security General helpnetsecurity.com -
DDoS attacks hit record scale as 1 Tbps+ campaigns become more common
DDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Cloudflare’s H1 2026 DDoS Threat Report shows threat actors relying on multi-vector…
Help Net Security Amenazas helpnetsecurity.com -
Product showcase: Is this image real? Slop or Not investigates
Slop or Not is an AI text and image detector for iPhone and Mac that runs entirely offline, with no account required. It uses on-device AI models powered by the Apple Neural Engine to detect AI-generated content. According to a recent…
Help Net Security Seguridad IA helpnetsecurity.com - miércoles 12 ago
-
Wireshark 4.6.8 patches 28 security bugs, nine in file parsers
Wireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that reads a capture off disk before any dissection begins: pcapng…
Help Net Security Vulnerabilidades helpnetsecurity.com -
Chinese Loongson processors have leaky caches, researchers find
Attackers could extract data, even working from inside a guest VM
The Register · Security General theregister.com -
Malware Crypting Services and the Threat Actors Who Sell Them
Insikt Group analyzes 24 threat actors selling malware crypting services. Learn about their evasion techniques, market dynamics, and how defenders can prioritize behavioral detection over static analysis.
Recorded Future Amenazas recordedfuture.com -
DeepSeek V4 Pro 0813 (on OpenRouter)
DeepSeek V4 Pro 0813 (on OpenRouter) The latest DeepSeek Pro model is now available, via API only. I had to link to OpenRouter because DeepSeek don't have any obvious announcement page for their new model. I haven't been able to confirm if…
Simon Willison General simonwillison.net -
Smashing Security podcast #480: This is the AI service you should never sign up to
Would you like access to Anthropic's Claude at 90% off the normal price? All you have to do is redirect your traffic to a mysterious service called "Poison Claude". Only problem is that it's run by fraudsters... Meanwhile, a…
Graham Cluley Seguridad IA grahamcluley.com -
"City-Forum" data-theft attacks target Salesforce, ServiceNow portals
An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [...]
BleepingComputer Amenazas bleepingcomputer.com -
Android malware combo takes out loans and relays victims' credit cards
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [...]
BleepingComputer Amenazas bleepingcomputer.com -
'Near-autonomous' AI agents attack Taiwan's nuclear safety agency
Some say the world will end in fire, some say an agentic swarm
The Register · Security Seguridad IA theregister.com -
Long-running Data Theft Campaign Targeting Salesforce, ServiceNow
The "City-Forum" campaign has been active since at least March 2025 and has targeted organizations across multiple sectors with custom tooling.
Dark Reading Amenazas darkreading.com -
Hackers exploit critical Adobe Commerce flaw to hijack customer accounts
Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible
Eight years on, we're still paying to hide the future glimpsed during speculative execution
The Register · Security General theregister.com -
Hundreds of fake Chrome VPN extensions route traffic through a proxy
More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider. [...]
BleepingComputer Infraestructura bleepingcomputer.com -
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor
The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace…
The Hacker News Vulnerabilidades thehackernews.com -
FBI: Hackers using social engineering to breach accounts and steal explicit content
Leaked passwords, social engineering and spoofed social media sites are among the tools hackers are using to gather individuals' private content and sell it online, the FBI said.
The Record Amenazas therecord.media -
Scaling AI agents with trustworthy data
Business and technology leaders need no convincing that the time of agentic AI is here. Organizations are rapidly adopting agents, and few executives doubt the technology’s potential to transform work. But many organizations find that…
MIT Technology Review · IA Seguridad IA technologyreview.com -
Walmart's "Trusted Agent" Approach to Purple Teaming
Walmart co-locates red and blue teams to build trust and improve security through collaborative purple teaming exercises
Dark Reading General darkreading.com -
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. [...]
BleepingComputer General bleepingcomputer.com -
Lazarus hackers exploited Windows zero-day to target defense firms
North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Quoting Florian Herrengt
But then users start to report a weird bug. It's the 4th time your team has been trying to fix it. I mean... asking AI to fix it. Unfortunately, it seems like not even Fable can figure it out. You go talk to the person who worked on this…
Simon Willison Seguridad IA simonwillison.net -
SharePoint Vulnerability Exploited Shortly After PoC Release
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild. The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com -
Uber Freight keeps on trucking after extortion crew breaks in
Helix claims nearly a million files, while the logistics biz says operations never hit the brakes
The Register · Security Amenazas theregister.com -
FBI: Hackers target online accounts to steal nude photos
The FBI warns that cybercriminals are targeting adults' and children's social media and other online accounts to steal sexually explicit images or videos. [...]
BleepingComputer Amenazas bleepingcomputer.com -
737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The…
The Hacker News Infraestructura thehackernews.com -
The Threat Hiding in Your Hiring Process: How Fake Remote Workers Get In
Fake remote workers can exploit gaps between hiring checks, device delivery, and account access to enter organizations under false identities. Specops Software explains how document verification and biometric liveness checks can help…
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America.
Dark Reading Amenazas darkreading.com -
A stranger has been reading Salesforce and ServiceNow portals worldwide for 17 months
Most security stories start with something broken. This one starts with everything working as designed. Researchers at Reco have been tracking a campaign they call City-Forum, named after a domain registered in 2002, abandoned, and now…
Help Net Security Amenazas helpnetsecurity.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.