Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 45 min 958 titulares en el archivo
Qué se está publicando
Distribución por tema
313 titulares de severidad Media Limpiar filtros ×
- martes 1 sep
-
Counterfeit installers to system compromise: Tracking a deceptive software download campaign
An active campaign is impersonating legitimate software vendors to deliver malware through look-alike download pages and regenerated installer archives. Microsoft Defender Experts shares observed attack techniques, Defender XDR detections…
Microsoft Security Blog Amenazas microsoft.com -
Guildma (Astaroth) malware infection from Brazilian Portuguese email, (Tue, Sep 1st)
Introduction
SANS Internet Storm Center Amenazas isc.sans.edu -
Another Artifactory CVE under attack by AI agents or humans
Unauthenticated intruders can mint admin tokens, and exposed servers are already being hit
The Register · Security Seguridad IA theregister.com -
Hackers abuse Faronics Deploy admin tool to install ScreenConnect
Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...]
BleepingComputer Amenazas bleepingcomputer.com -
Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks
The model provider gave METR the credits for free. An actual customer would not have been so lucky
The Register · Security General theregister.com -
China's 'Fire Ant' campaign used compromised Cisco routers as platform for more attacks
A hacking operation dubbed Fire Ant "didn’t just compromise systems," according to researchers. "It compromised the trust layer those systems depend on."
The Record Amenazas therecord.media -
AI Model Evaluator METR Hit by Credential Theft, Probing
In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit.
Dark Reading Seguridad IA darkreading.com -
Breeze Comet Executes Hundreds of Fraudulent Transactions via Brazilian Payment Systems
Brazilian financial services, retail, and e-commerce organizations have become the target of a financially motivated threat actor dubbed Breeze Comet (formerly UNC5669) since 2024. Google Threat Intelligence Group (GTIG) and Mandiant teams…
The Hacker News Amenazas thehackernews.com -
Frontier AI helps exploit flaws in tests using key industrial devices
A report showed that Claude could help hackers develop attack strategies targeting PLCs used by water utilities and other industries.
Cybersecurity Dive Seguridad IA cybersecuritydive.com -
Hackers push malicious Virtualizor update in BGP hijacking attack
Hackers delivered malicious updates to the Virtualizor VPS management software after hijacking BGP routing for its update infrastructure and redirecting update requests to malicious servers. [...]
BleepingComputer Amenazas bleepingcomputer.com -
Attackers Steal METR API Key and Burn $600,000 in AI Credits
Attackers used a stolen METR API key for three weeks, consuming model credits worth $600,000
Infosecurity Magazine Seguridad IA infosecurity-magazine.com -
13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds
Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the…
The Hacker News Vulnerabilidades thehackernews.com -
Why Even the Best Edge Security Still Misses High-Risk Sessions
Attackers can hide behind residential proxies, VPNs, and other infrastructure that makes malicious sessions appear legitimate to existing edge security controls. Spur explains how session enrichment adds data points that help organizations…
BleepingComputer General bleepingcomputer.com -
ClickFix Campaign Compromises 31 Orgs, Abuses Polygon Blockchain
The campaign uses EtherHiding to dynamically update its command-and-control server, abusing the blockchain as an attacker-controlled address book.
Dark Reading Amenazas darkreading.com -
Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests
The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS…
The Hacker News Amenazas thehackernews.com -
White House Launches Pilot Program in Texas to Protect Water Infrastructure
Project Watershed 250 will see water providers in Texas provided with federal and private sector cybersecurity resources amid rising nation-state threats
Infosecurity Magazine General infosecurity-magazine.com -
TerminalFix looks like ClickFix, but delivers a very different payload
The familiar ClickFix fake CAPTCHA trick has been adapted to deliver a payload that can give attackers access to the victim’s wider network.
Malwarebytes Labs General malwarebytes.com -
Rockwell Automation RSLinx Classic
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to cause a denial-of-service condition on the affected product. The following versions of Rockwell Automation RSLinx Classic are affected: RSLinx…
CISA Advisories Vulnerabilidades cisa.gov -
Rockwell Automation Redundancy Module Configuration Tool
View CSAF Summary Successful exploitation of these vulnerabilities could allow for an attacker to escalate and execute processes with administrator privileges. The following versions of Rockwell Automation Redundancy Module Configuration…
CISA Advisories Vulnerabilidades cisa.gov -
Rockwell Automation FactoryTalk Activation Manager
View CSAF Summary The following versions of Rockwell Automation FactoryTalk Activation Manager are affected: FactoryTalk Activation Manager V5.02_and_below (CVE-2026-16675) CVSS Vendor Equipment Vulnerabilities v3 7.8 Rockwell Automation…
CISA Advisories Vulnerabilidades cisa.gov -
Threat Actors Don’t Want Better Attacks. They Want Repeatable Ones
The most common way into a company last year was to ask. A web page tells the visitor to prove they are not a robot. While they read the instructions, it quietly places a command on their clipboard. Then it talks them through opening a…
The Hacker News Amenazas thehackernews.com -
Explotan dos fallos críticos en Langflow y Ruby on Rails para robar secretos y desplegar mando y control
Se ha confirmado explotación activa de CVE-2026-0768 en Langflow y CVE-2026-66066 en Ruby on Rails. Los ataques se centran en leer secretos, probar credenciales y preparar infraestructura de mando y control (C2), con riesgo de acabar en…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com -
Introducing Continuous Vulnerability Assessment: Real-Time Defense for the AI Threat Era
Detect exposure to new vulnerabilities the moment they are published with Wiz CVA
Wiz Seguridad IA wiz.io -
Five Venezuelans plead guilty to ATM jackpotting attacks in US
Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. [...]
BleepingComputer Amenazas bleepingcomputer.com -
Attackers Steal METR API Key and Consume AI Credits Worth About $600,000
METR (short for Model Evaluation and Threat Research and pronounced "Meter"), a research non-profit that evaluates frontier artificial intelligence (AI) models for their ability to carry out long-horizon, agentic tasks, disclosed that it…
The Hacker News Seguridad IA thehackernews.com -
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence…
The Hacker News Seguridad IA thehackernews.com -
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Securelist (Kaspersky) Amenazas securelist.com - lunes 31 ago
-
Introducing wrapture
Introducing wrapture New from Graham Dumpleton (of wrapt, mod_wsgi, and New Relic's Python agent fame), who describes Wrapture as taking the monkeypatching ideas from wrapt and extending them to apply to testing and tracing at the same…
Simon Willison Vulnerabilidades simonwillison.net -
Anthropic Users Hit by Infostealer Attacks, Session Thefts
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
Dark Reading Seguridad IA darkreading.com -
'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.
Dark Reading Amenazas darkreading.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.