Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 54 min 957 titulares en el archivo
Qué se está publicando
Distribución por tema
141 titulares de severidad Alta Limpiar filtros ×
- lunes 31 ago
-
Multiple Threat Actors Rapidly Exploit React2Shell: A Case Study of Active Compromise
On December 3, 2025 (local time), a vulnerability allowing unauthenticated remote code execution in React Server Components (RSC) (CVE-2025-55182) was disclosed. JPCERT/CC has received multiple incident reports related to this attack…
JPCERT/CC Vulnerabilidades blogs.jpcert.or.jp -
Quoting Andrew Digby
325 #kakapo! The chicks from this year's record breeding season are now juveniles and so have been added to the population. In 1995 there were just 51 kākāpō left. Recovery of critically endangered species is possible with sustained…
Simon Willison General simonwillison.net -
Healthcare cyberattacks hit pacemakers and millions of patient records
McKesson admits breach as ShinyHunters demands $55.2M
The Register · Security Amenazas theregister.com -
The Guardrails Debate: Security Researcher Changes His Mind
While guardrails are critical, as evidenced by recent high-profile incidents, defenders need help staying ahead of attackers who do not play by the rules.
Dark Reading General darkreading.com -
ValleyRAT masquerading as adware
Threat actors are distributing the ValleyRAT backdoor disguised as adware. We analyze the infection chain, from the malicious installer to the final payload.
Securelist (Kaspersky) Regulación securelist.com -
This month in security with Tony Anscombe – August 2026 edition
Details about the Hugging Face hack, critical infrastructure under attack, a spoofed in-flight Wi-Fi network, and more of this month's cybersecurity news
WeLiveSecurity (ESET) General welivesecurity.com - viernes 28 ago
-
Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety
New research reveals that AI safety refusal lives in a thin neural layer, highlighting the critical need for external, multi-layered security. The post Perturbation Probing: A New Diagnostic for the Fragility of LLM Safety appeared first…
Unit 42 Seguridad IA unit42.paloaltonetworks.com -
Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn
More than 100 companies, including OpenAI, Anthropic, Google and Microsoft, have urged collective action to unlock the power of AI to protect critical public services
Infosecurity Magazine Seguridad IA infosecurity-magazine.com - jueves 27 ago
-
“Sorry, I can’t help with that”: How your guardrails might become the attacker’s best friend
In his first Threat Source newsletter, David Bianco explores the critical need for operational sovereignty in customizing AI guardrails to maintain the defender’s advantage.
Cisco Talos Seguridad IA blog.talosintelligence.com -
Inside 90 days of attacks on AI infrastructure
Wiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft.
Wiz Seguridad IA wiz.io -
Federal authorities disrupt China-backed hacking operation targeting US critical infrastructure
Compromised IoT devices were used in a yearslong campaign against key sectors and federal agencies.
Cybersecurity Dive Amenazas cybersecuritydive.com -
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement…
Krebs on Security Amenazas krebsonsecurity.com -
Threat landscape for industrial automation systems. Q2 2026
The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems.
Securelist (Kaspersky) Amenazas securelist.com - miércoles 26 ago
-
BlueDelta Targets Defense and Diplomacy with HOOKEDGE
Discover how the Russian state-sponsored threat group BlueDelta is using the HOOKEDGE backdoor to target defense and diplomatic organizations across Europe
Recorded Future Amenazas recordedfuture.com - martes 25 ago
-
A Cautionary Tale About Data Breach Claims, Verification and Carhartt
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteYou're not going to believe this, but turns out you can't always take criminals at their word…
Troy Hunt Amenazas troyhunt.com - lunes 24 ago
-
Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense
Explore Mexico’s 2025–2030 Cybersecurity Plan. Learn about key threats, including ransomware, and the roadmap for building durable national cyber defenses.
Recorded Future Amenazas recordedfuture.com -
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
Rapid7 Vulnerabilidades rapid7.com -
Troyanos Info Stealer se distribuyen con infección de sitios de América Latina
Investigadores de ciberseguridad han detectado dos nuevas familias de malware, WordlistLoader y SynkLoader, que se utilizan para distribuir cargas útiles avanzadas y, probablemente, vender acceso a grupos de ransomware. Según los hallazgos…
Segu-Info Amenazas blog.segu-info.com.ar -
Gunra ransomware: what you need to know
The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog.
Graham Cluley Vulnerabilidades fortra.com - viernes 21 ago
-
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the Software Development…
Unit 42 Infraestructura unit42.paloaltonetworks.com -
The Good, the Bad and the Ugly in Cybersecurity – Week 34 (2026)
U.S. indicts Iranian cyber espionage operations, Medusa ransomware breaches 500 organizations, and attackers exploit a critical Windows protocol flaw.
SentinelOne Vulnerabilidades sentinelone.com - jueves 20 ago
-
Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios.
Wiz Amenazas wiz.io -
Frequently asked questions about the active threat to Siemens S7 Series PLCs
A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors.Key…
Tenable Seguridad IA tenable.com - miércoles 19 ago
-
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
OverviewOn August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3…
Rapid7 Vulnerabilidades rapid7.com -
Oracle Critical Patch Update, August 2026 Security Update Review
Oracle released its August edition of Critical Patch Update. The update received patches for 943 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address…
Qualys Vulnerabilidades blog.qualys.com -
NIST Releases Tips & Tactics for Building Automation & Control System Cybersecurity
Recent cyberattacks highlight the growing threat to operational technology (OT) used in critical infrastructure. Whether you work for an infrastructure owner/operator or are a consumer of an infrastructure service, the events of the past…
NIST Cybersecurity Amenazas nist.gov - martes 18 ago
-
Oracle August 2026 Critical Security Patch Update Addresses 925 CVEs
Oracle addresses 925 CVEs in its August 2026 Critical Security Patch Update with 943 patches, including 154 critical updates.Key TakeawaysThe August 2026 Critical Security Patch Update (CSPU) contains fixes for 925 unique CVEs in 943…
Tenable Vulnerabilidades tenable.com -
Thousands of Hacked WordPress Sites, One Operation: Unmasking StopAndProtect
Research by: Jaromír Hořejší (@JaromirHorejsi) Key points Introduction We first noticed a ransomware family called StopAndProtect in the middle of May 2026. Further analysis of the infrastructure reveals that the infection chain starts…
Check Point Research Amenazas research.checkpoint.com - lunes 17 ago
-
Weekly Update 517: Cyber Ransoms
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteThe current ransomware situation is a bit of a kludge (deep breath): a lot of ransomware (which…
Troy Hunt Amenazas troyhunt.com -
Detecting cloud ransomware in Azure with Tenable One’s cloud detection and response capabilities
Learn how Tenable One Cloud Exposure helps you unmask the sophisticated tactics of cybercrime group Storm-0501, which carries out Azure-based cloud ransomware campaigns. Tenable One Cloud Exposure uses AI-powered threat stories to expose…
Tenable Seguridad IA tenable.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.