Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 55 min 971 titulares en el archivo
Qué se está publicando
Distribución por tema
- miércoles 5 ago
-
CRLF-Powered Desync Attacks: Beheading HTTP Streams
Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power
PortSwigger Research General portswigger.net -
Can AI do novel security research? Meet the HTTP Terminator
Abstract We all know AI can find bugs. After a decade of research, I asked a harder question: can an autonomous system invent new attack techniques, and use them to hack live websites at scale? Buildi
PortSwigger Research Seguridad IA portswigger.net -
AI agents can't yet do open-ended AI research
Early evidence from two case studies
AI Snake Oil Seguridad IA normaltech.ai -
A few notes on AWS Nitro Enclaves: KMS integration
Nitro Enclaves and Key Management Service (KMS) feel like a natural fit: since the KMS can verify attestation documents generated by the enclaves, developers can offload key management tasks from their applications to the AWS-managed…
Trail of Bits Infraestructura blog.trailofbits.com -
Continuous Offensive Security & AI Pentesting: 20 FAQs
Get answers to 20 common questions about continuous offensive security, AI penetration testing, DAST, and AI red teaming.
Snyk Seguridad IA snyk.io - martes 4 ago
-
Un arresto del FBI demuestra que ni Steam ni las plataformas oficiales son infalibles
Un cibercriminal distribuyó malware mediante videojuegos publicados en Steam e infectó a más de 8.000 equipos. El caso revela los límites de los controles de seguridad y la importancia de verificar qué se descarga, incluso desde…
WeLiveSecurity (ESET) Amenazas welivesecurity.com -
From Input to Impact: Secure AI Where It Runs
Defend the entire AI agentic stack across endpoints, identities, cloud, and apps with SentinelOne's unified platform.
SentinelOne Seguridad IA sentinelone.com -
Nine AI coding agent incidents that ended with deleted data
Nine documented AI coding agent incidents, from Cursor and Gemini CLI to Replit, Kiro and Claude Opus 5. What each agent did and why the guardrails failed.
Adversa AI Seguridad IA adversa.ai -
Stop The Sprawl Snyk Secrets Now Generally Available
Snyk Secrets is now generally available, bringing contextual ML detection, secure-at-commit prevention, and unified secrets governance to the Snyk AI Security Platform.
Snyk Seguridad IA snyk.io -
A First Look at Evo Agentic AppSec: Agentic Remediation and Malicious Code Defense
Explore Snyk’s first Agentic AppSec capabilities: an autonomous Remediation Agent that fixes vulnerabilities and Malicious Code Defense that blocks risky packages before they ship.
Snyk Seguridad IA snyk.io - lunes 3 ago
-
Web scraping: qué es, cómo funciona y cuándo es legal
El web scraping puede ser beneficioso para las empresas, pero también es utilizado por ciberdelincuentes para recopilar y comprometer datos sensibles, lo que representa un riesgo para la seguridad de los usuarios legítimos.
WeLiveSecurity (ESET) General welivesecurity.com -
LLM Heist: Hijacking LiteLLM for Traffic Interception, Key Theft, and Tool-Call Injection
LiteLLM is a popular AI gateway. It provides a unified interface to LLMs and simplifies governance. It also has access to the backend LLM provider keys. All of that makes it a high-value target. Not only for IP and data theft, but also for…
Embrace The Red Seguridad IA embracethered.com -
Top AI Coding Agent security resources — August 2026
August 2026's AI coding agent security roundup: a symlink flaw across six assistants, Cursor's CVSS 9.8 pair, a private repo leak, and a wiped database.
Adversa AI Seguridad IA adversa.ai -
Fake Xeno Roblox Cheats Deliver Powerful Java Stealer Through Discord and Forums
A malware campaign disguised as an “undetected” version of the Xeno Roblox script executor is directly affecting players looking to download a legitimate tool.
Bitdefender Labs Amenazas bitdefender.com -
Welcoming the Nepalese Government to Have I Been Pwned
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteToday, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal…
Troy Hunt General troyhunt.com - domingo 2 ago
-
Weekly Update 515: Seeking Caffeine Utopia
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteApparently, Aussies are so obsessed with coffee that it's referred to as the coffee capital of…
Troy Hunt General troyhunt.com - sábado 1 ago
-
Silver Bullet Security Podcast 159 – Melanie Mitchell
View on Zencastr On Episode 159 of the Silver Bullet Security Podcast, BIML’s Gary McGraw hosts Melanie Mitchell. Melanie talks about the surprising progress made in AI since the ’90s, whether real concepts emerge from data scale alone…
Berryville Institute (BIML) Seguridad IA berryvilleiml.com - viernes 31 jul
-
Capturas de pantalla falsas: el riesgo de confiar en una prueba digital
Las capturas de pantalla pueden ayudar a documentar pagos, reservas o conversaciones, pero cada vez son menos fiables como evidencia y más fáciles de falsificar.
WeLiveSecurity (ESET) General welivesecurity.com -
Top Agentic AI security resources — August 2026
Four teams broke production AI agents in ten days. Twenty resources on the Kiro RCE, Cursor's CVSS 9.8 pair, memory poisoning, and sandbox escapes.
Adversa AI Seguridad IA adversa.ai -
The Good, the Bad and the Ugly in Cybersecurity – Week 31 (2026)
Police flag 4,000 URLs to disrupt The Com, theft victims sue Apple over a $1.8M wallet scam, and OpenAI and Anthropic models reach real systems in cyber tests.
SentinelOne Seguridad IA sentinelone.com - jueves 30 jul
-
Por qué el phishing sigue funcionando: el 73% de las empresas en América Latina lo confirma
Los ciberdelincuentes siguen apostando por el error humano: el phishing mantiene altos niveles de impacto regional.
WeLiveSecurity (ESET) Amenazas welivesecurity.com -
A hole in every one: bypassing the open source AI skill scanners
We ran eight open source AI skill scanners against real attacks. A malicious skill got past all eight, including the current OASB leaderboard leader.
Adversa AI Seguridad IA adversa.ai -
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers…
Krebs on Security General krebsonsecurity.com -
Escaping Linux Sandboxes via PipeWire (CVE-2026-5674)
This post walks through a sandbox escape from a Flatpak application via PipeWire. The vulnerability was discovered using my automated research pipeline with Claude Code and Opus 4.6 back in April 2026. It was an exciting find, as this was…
Embrace The Red Seguridad IA embracethered.com -
The July 2026 Apple Security Update Review
Welcome to our monthly look at Apple security patches. This release shows that Apple is not immune to the bug apocalypse that is impacting other vendors. Last month, they released 37 unique CVEs compare to this month’s 210. Quite a…
Zero Day Initiative Vulnerabilidades thezdi.com -
Building secure Uniswap v4 hooks
Uniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom accounting, and external integrations. This flexibility moves some security responsibilities into application and hook code. The Cork and Bunni…
Trail of Bits General blog.trailofbits.com - martes 28 jul
-
Disrupting supply chain attacks on npm and GitHub Actions
Explore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact. The post Disrupting supply chain attacks on npm and GitHub Actions appeared first on…
GitHub Security Infraestructura github.blog -
How we use /goal to find bugs in Patch the Planet
Codex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the right scope, and the right number of outcomes per run. For Patch the Planet, our joint initiative with OpenAI to find and fix bugs in…
Trail of Bits Seguridad IA blog.trailofbits.com - miércoles 22 jul
-
TSUBAME Report Overflow (Jan-Mar 2026)
This TSUBAME Report Overflow series discusses observation trends from TSUBAME sensors both in Japan and overseas, as well as other topics not covered in the Internet Threat Monitoring Quarterly Report. This article covers monitoring…
JPCERT/CC General blogs.jpcert.or.jp -
Next chapter: Restructuring GitHub’s bug bounty program
GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team. The post Next chapter: Restructuring GitHub’s bug bounty program appeared first…
GitHub Security Vulnerabilidades github.blog
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.