Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 55 min 957 titulares en el archivo
Qué se está publicando
Distribución por tema
313 titulares de severidad Media Limpiar filtros ×
- miércoles 2 sep
-
OpenLeash Adds a Human Check to Risky AI Agent Actions
The security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain. The post OpenLeash Adds a Human Check to Risky AI Agent Actions appeared first on SecurityWeek.
SecurityWeek Seguridad IA securityweek.com -
Infostealer secuestra sesiones de Claude y consume créditos sin autorización
Un malware infostealer secuestra sesiones de Claude y consume créditos sin autorización. Conoce qué hizo Anthropic al respecto.
WeLiveSecurity (ESET) Seguridad IA welivesecurity.com -
Russian national facing 20 years for malware campaign that infected 80,000 freelancers
Searzhudin Tamirlanovich Aktulaev appeared in a San Francisco federal court on Monday after being arrested in Cyprus in May 2025 and extradited to the U.S. last week.
The Record Amenazas therecord.media -
Sniffing Authentication References on macOS
CVE-2017-7170 was a local priv-esc vulnerability that affected OSX/macOS for over a decade! Here (for the first time!), we dive into the technical details of finding the bug, the core flaw, and exploitation.
Objective-See Vulnerabilidades objective-see.org -
The Mac Malware of 2019
Our annual report on all the Mac malware of the year - including samples for download, infection vectors, persistence mechanisms, payloads and more!
Objective-See Amenazas objective-see.org -
Health data of more than 9.5 million people leaked from Aesto record system
The healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December.
The Record Regulación therecord.media -
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.
Dark Reading Amenazas darkreading.com -
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises…
The Hacker News Amenazas thehackernews.com -
Researchers fear safety disaster ahead of OpenAI’s Astra release
OpenAI is on the cusp of releasing its most powerful AI model yet, Astra, following weeks of delays to shore up safety protocols after its agents attacked real targets during testing. As details about the model trickle out, researchers are…
The Verge · IA Seguridad IA theverge.com -
Russian Man Extradited Over Malware Campaign Targeting Freelancers
Russian man extradited to US over malware campaign that targeted 80,000 freelance users
Infosecurity Magazine Amenazas infosecurity-magazine.com -
Anatomy of a Silent Domain Takeover
Key Takeaways Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint. The evidence is already in the logs; what is missing is the narrative linking five benign-looking…
Qualys Vulnerabilidades blog.qualys.com -
Legacy Lenovo login opens 5,000 Dropbox accounts to attackers
Cloud storage biz severs old integration and urges victims to reset credentials
The Register · Security Infraestructura theregister.com -
Malicious .git Configs Can Make Claude, Codex, Cursor, and Other AI Agents Run Attacker Code
Manifold Security has disclosed eight security flaws across seven command-line AI coding agents in which a repository's own Git configuration names a command that the agent runs on the developer's machine, four of them still unpatched at…
The Hacker News Seguridad IA thehackernews.com -
Scammers are getting smarter about where they target you
New Malwarebytes research reveals how different scams are tailored to different platforms.
Malwarebytes Labs Amenazas malwarebytes.com -
Exploitation of Sangoma Switchvox flaw is underway (CVE-2026-9586)
A threat actor is actively targeting internet-exposed Sangoma Switchvox instance through a recently patched SQL injection flaw (CVE-2026-9586), and organizations running them should check for signs of compromise immediately. How…
Help Net Security Vulnerabilidades helpnetsecurity.com -
Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products
The industrial giant has released advisories for its RSLinx Classic, ArmorStart, ControlFLASH, FactoryTalk, and other products. The post Rockwell Automation Patches Over a Dozen Vulnerabilities Across Products appeared first on…
SecurityWeek Vulnerabilidades securityweek.com -
Dropbox accounts breached through Lenovo email verification flaw
Dropbox is warning some users that an unauthorized party accessed their accounts by exploiting a flaw in Lenovo's email verification process to register fraudulent Lenovo IDs. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Exploit Published for Fresh Cleo Harmony Vulnerability
The security defect allows remote attackers to bypass authentication through argument bearer manipulation. The post Exploit Published for Fresh Cleo Harmony Vulnerability appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com -
Sality, one of the longest-running botnets, finally gets disrupted
U.S. and European authorities disrupted the long-running botnet Sality, turning the malware’s peer-to-peer architecture against itself to cut thousands of infected computers off from operators.
The Record Amenazas therecord.media -
Malicious Virtualizor Update Served via BGP Hijacking
Using a technically valid TLS certificate for Softaculous’ domains, a threat actor diverted traffic to fake software updates. The post Malicious Virtualizor Update Served via BGP Hijacking appeared first on SecurityWeek.
SecurityWeek Amenazas securityweek.com -
Attackers are going after prominent individuals through OAuth phishing, FBI warns
Attackers are targeting prominent individuals, their relatives and personal contacts to gain persistent access to their accounts, including private emails and files, the FBI has warned. The FBI’s Internet Crime Complaint Center (IC3) says…
Help Net Security Amenazas helpnetsecurity.com -
Nutex Health Says Patient Data Stolen, Hackers Threaten Leak
The US healthcare provider confirmed that sensitive patient and employee data, alongside financial and business information, were exfiltrated by a third party
Infosecurity Magazine Amenazas infosecurity-magazine.com -
An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation
Using autonomous AI agents, an attacker breached an enterprise network in a matter of hours. Understand how to address and defend against agentic attacks. The post An AI-Assisted Cyber Attack: Inside a Unit 42 Investigation appeared first…
Unit 42 Seguridad IA unit42.paloaltonetworks.com -
Extradited Russian Hacker Faces Charges Over Excel Malware Campaign That Infected Thousands
The U.S. Department of Justice (DoJ) has charged a Russian national, extradited from Cyprus on August 28, with using roughly 255 fake accounts on a freelance platform to send malware-laced Excel attachments to about 80,000 of its users in…
The Hacker News Amenazas thehackernews.com -
US charges Russian for infecting 80,000 freelancers with malware
A California federal grand jury has indicted a Russian national for his role in a phishing campaign that infected thousands of freelancers with TVRAT and DarkVNC malware. [...]
BleepingComputer Amenazas bleepingcomputer.com -
A battery storage cyberattack would look exactly like a badly tuned controller
Batteries connected to the grid make money by reacting to frequency, pushing power out when it sags and soaking it up when it rises. A few hundred of them moving together, on command from someone who should not have the command, would look…
Help Net Security Amenazas helpnetsecurity.com -
FulcrumSec Claims Responsibility for Manchester Airport Group Breach
Threat group FulcrumSec claims MAG breach and leaks 550GB of data online
Infosecurity Magazine General infosecurity-magazine.com -
Sality botnet infrastructure dismantled in joint global takedown
International law enforcement agencies and private partners have seized Sality malware infrastructure in a joint action aiming to disrupt and take down the peer-to-peer (P2P) botnet. [...]
BleepingComputer Amenazas bleepingcomputer.com -
Authorities Turn Sality's P2P Network Against Itself, Cutting Off New Malware Payloads
The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by…
The Hacker News Amenazas thehackernews.com - martes 1 sep
-
Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency
Threat actors exploited commodity vulnerabilities in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores.
Dark Reading Vulnerabilidades darkreading.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.