Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 29 min 959 titulares en el archivo
Qué se está publicando
Distribución por tema
314 titulares de severidad Media Limpiar filtros ×
- lunes 31 ago
-
'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.
Dark Reading Amenazas darkreading.com -
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
Next-level ClickFix wave sets off multi-stage attack chain
The Register · Security Amenazas theregister.com -
AI Model Rules Are Not Security Controls
OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.
Dark Reading Seguridad IA darkreading.com -
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected…
The Hacker News Amenazas thehackernews.com -
Anthropic cracks down on hijacked user accounts mining AI tokens
Commodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage
The Register · Security Seguridad IA theregister.com -
PaperCut issues emergency patches as threat actors target chained vulnerabilities
The print management software maker faced a wave of attacks in 2023 aimed at higher education customers.
Cybersecurity Dive Vulnerabilidades cybersecuritydive.com -
Introducing Adaptive Intelligence: Undermining the economics of every bot attack
Bot operators have historically had the economic advantage, bypassing static, deterministic detection rules with cheap proxies and retooling. Cloudflare's new Adaptive Intelligence engine flips this dynamic by autonomously learning from…
Cloudflare Infraestructura blog.cloudflare.com -
31th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East…
Check Point Research General research.checkpoint.com -
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on…
Unit 42 Amenazas unit42.paloaltonetworks.com -
ATM Flaws Reveal Key Weaknesses in the Software Supply Chain
A security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local cash machine.
WIRED · Security Vulnerabilidades wired.com -
Más de 8.300 servidores Gitea quedan expuestos a ataques de ejecución remota por CVE-2026-60004
Miles de instancias de Gitea accesibles desde Internet seguían sin parchear a finales de agosto frente a CVE-2026-60004, un fallo crítico que permite ejecución remota de comandos. La corrección llegó con Gitea 1.27.1 y el problema ya…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com - domingo 30 ago
-
Boardroom Battles 2026: ASD’s Cyber Priorities & AI Risk
The Australian Signals Directorate’s 2026 board priorities and frontier AI guidance show why speed alone won’t stop AI-era cyber threats.
Huntress Seguridad IA huntress.com -
YARA-X 1.20.0 Release, (Sun, Aug 30th)
YARA-X's 1.20.0 release brings 14 improvements and 13 bugfixes.
SANS Internet Storm Center General isc.sans.edu - viernes 28 ago
-
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel…
Microsoft Security Blog Amenazas microsoft.com -
Hundreds of OpenAI Agents Invaded Hugging Face Servers
The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack.
Dark Reading Seguridad IA darkreading.com -
Offensive Security Investments Surge as AI Threats Increase
Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration testing, red teaming, and other practices.
Dark Reading Seguridad IA darkreading.com -
Microsoft Teams Has Become a Haven for Scammers in China
Fraudsters are exploiting enterprise chat apps like Teams and Webex to trick Chinese victims into transferring large sums of money, fueling a wave of complaints.
WIRED · Security Vulnerabilidades wired.com -
The Good, the Bad and the Ugly in Cybersecurity – Week 35 (2026)
Authorities disrupt global cybercrime rings, attackers abuse DocuSign in NovaCookies phishing, and Spark RAT targets Cambodia with vulnerable drivers.
SentinelOne Amenazas sentinelone.com -
Next-Gen Phishing Tactics Users Aren’t Ready For | Huntress
Move past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing—and how to train your users with Huntress SAT.
Huntress Amenazas huntress.com -
Teach Yourself to Phish | Huntress
Get ready for a phishing trip! Learn about the strategy behind phishing simulations and how it can help your organization build resilience against real phishing threats.
Huntress Amenazas huntress.com -
A Beginner’s Guide to Phishing Simulation Training for Employees | Huntress
Learn the essentials of phishing simulation training with our beginner's guide. Protect your organization by simulating real phishing attacks.
Huntress Amenazas huntress.com -
Frontier AI tipping the scales toward cyber adversaries
Researchers at Palo Alto Networks’ Unit 42 warn that threat actors are already using AI to accelerate cyberattacks beyond the abilities of modern defenses.
Cybersecurity Dive Seguridad IA cybersecuritydive.com -
Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!
Rapid7 Vulnerabilidades rapid7.com -
Why a cryptographic inventory is key for addressing the quantum computing threat
When quantum computers become generally available, they’ll be able to crack current public-key cryptographic algorithms, putting digitally stored and transmitted data at risk. But the threat already exists, as attackers use the "harvest…
Tenable General tenable.com -
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
A large-scale phishing campaign used fake voicemail SVG attachments to bypass email defenses, targeting 5527 organizations with over 26,000 malicious messages
Infosecurity Magazine Amenazas infosecurity-magazine.com -
CISA identifies security hurdles that led to very different results in two red-team engagements
The agency said its recent simulated cyberattacks offered several key lessons for many organizations.
Cybersecurity Dive Amenazas cybersecuritydive.com -
Some Malicious PE Stats, (Thu, Aug 27th)
During my last FOR610 session, a student asked me if I had some statistics in mind about the compilers used to generate malicious PE files? A couple of months ago, I shared some stats about the trend in 64bits VS. 32bits malware[1]. Can we…
SANS Internet Storm Center Amenazas isc.sans.edu - jueves 27 ago
-
Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs
IntroductionDespite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft…
Rapid7 Infraestructura rapid7.com -
Mitsubishi Electric CNC Series (Update A)
View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products. The following versions of Mitsubishi…
CISA Advisories Vulnerabilidades cisa.gov -
Ebyte NA111-M
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device. The following versions of Ebyte NA111-M are affected: NA111-M Firmware 9013-2-17 (CVE-2026-73125, CVE-2026-76179…
CISA Advisories Vulnerabilidades cisa.gov
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.