Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 9 min 961 titulares en el archivo
Qué se está publicando
Distribución por tema
314 titulares de severidad Media Limpiar filtros ×
- jueves 27 ago
-
Mitsubishi Electric Multiple FA Products (Update D)
View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product…
CISA Advisories Vulnerabilidades cisa.gov -
Xiiaozet LK100W
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to take control over the device. The following versions of Xiiaozet LK100W are affected: LK100W
CISA Advisories Vulnerabilidades cisa.gov -
Applied Systems Engineering ASE2000 V2 Communications Test Set
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the…
CISA Advisories Vulnerabilidades cisa.gov -
All-Line Equipment Company Fuel-Boss
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. The following versions of All-Line Equipment Company Fuel-Boss are affected…
CISA Advisories Vulnerabilidades cisa.gov -
Rockwell Automation OTTO Fleet Manager
View CSAF Summary Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. The following versions of Rockwell…
CISA Advisories Vulnerabilidades cisa.gov -
Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps
A practitioner’s guide to log visibility, incident readiness, and threat hunting across the major version control services.
Wiz Infraestructura wiz.io -
JavaScript obfuscation: From party trick to phishing kit
Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.
Cisco Talos Amenazas blog.talosintelligence.com -
A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)
As I've mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us here at the Internet Storm Center.
SANS Internet Storm Center Amenazas isc.sans.edu -
Breaking Claude Code Opus 5 Auto Mode
In this post, we explore how a simple website summary request hijacks Claude Code Opus 5 in Auto Mode and achieves code execution with 60-80% attack success rate using a small sample size. This is interesting because a third-party…
Embrace The Red Seguridad IA embracethered.com - miércoles 26 ago
-
How Hackers Exploit AI’s Problem-Solving Instincts
As multimodal AI models advance from perception to reasoning, and even start acting autonomously, new attack surfaces emerge. These threats don’t just target...
NVIDIA · Ciberseguridad Seguridad IA developer.nvidia.com -
State of AI Cybersecurity 2026: 87% of Security Professionals are Seeing More AI-Driven Threats, But Few Feel Ready to Stop Them
Originally published by Darktrace. Findings from our annual survey of 1,500+ cyber professionals reveal that security leaders are confronting a surge in AI-driven attacks, which are faster, more personalized, and harder to detect than…
Cloud Security Alliance Seguridad IA cloudsecurityalliance.org -
Top 6 Claude in Chrome Security Risks to Model Before You Roll It Out
Most teams evaluate a browser agent like a browser extension. Check the permissions, check the vendor, check for open CVEs, approve or deny. That framing produced two clean patch cycles in 2026 and no reduction in exposure. Two problems…
Cloud Security Alliance Seguridad IA cloudsecurityalliance.org -
Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation
A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider…
AWS Security Infraestructura aws.amazon.com -
When AI infrastructure becomes the target: Securing gateways and control points
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity. The post When AI infrastructure becomes the target: Securing…
Microsoft Security Blog Seguridad IA microsoft.com -
The State of Cloud Risk 2026: Most Security Findings Aren’t Real Attacker Opportunities
Wiz Research telemetry reveals why the majority of high-severity findings lack a path to compromise
Wiz Infraestructura wiz.io -
Beyond Patching: What IT Teams Need to Know About Unpatchable Exposures
Executive Summary Most IT teams still operate under a false binary: patch or accept risk. That assumption creates unnecessary operational pressure. Patchless remediation is real and production-proven. Mitigate, Uninstall, Run Custom…
Qualys Vulnerabilidades blog.qualys.com -
When an AI Agent Turned Attacker: What Qualys Sees Across Every Phase of the Hugging Face Kubernetes Intrusion
On July 9, 2026, an autonomous AI agent escaped an OpenAI evaluation sandbox and conducted a multi-day intrusion into Hugging Face’s Kubernetes environment. Over roughly 17,600 actions, it reached dataset pipelines, production pods, cloud…
Qualys Seguridad IA blog.qualys.com -
Boston Scientific says cyberattack disrupted order processing, shipping
The medical device-maker says it cannot yet determine any financial impact from the attack it suffered this week.
Cybersecurity Dive Amenazas cybersecuritydive.com -
Edge Infrastructure Under Siege: What Two Independent Datasets Reveal About Who’s Exploiting Your Perimeter
A new joint study by Tenable and SentinelOne reveals how state and criminal groups converge on the same vulnerable edge infrastructure.
SentinelOne Vulnerabilidades sentinelone.com -
CISA Vulnerability Review
Most compromises do not rely on advanced techniques or cutting-edge tools. Cyber threat actors scan the internet looking for exposed, well-known software vulnerabilities to exploit. Basic security failures enable most compromises and…
CISA Advisories Vulnerabilidades cisa.gov -
VMs won't contain cyber-capable agents
As part of Patch the Planet, we received preview access to GPT 5.6-Cyber with a simple task: evaluate its cyber capabilities. Recent events inspired me to give it a challenge to work through: escape the VM I’d normally use for sandboxing…
Trail of Bits Vulnerabilidades blog.trailofbits.com -
Exploits and vulnerabilities in Q2 2026
This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.
Securelist (Kaspersky) Seguridad IA securelist.com -
Why Your AI Application Is Exposed
AI applications can pass security scans yet remain exploitable through chained attacks across models, tools, data, and business workflows. Learn how DAST, AI pentesting, and red teaming work together to expose end-to-end risk.
Snyk Seguridad IA snyk.io - martes 25 ago
-
The patch window is collapsing: Why security needs a new control plane
Organizations need protection that operates in the gap between discovery and remediation. The post The patch window is collapsing: Why security needs a new control plane appeared first on Microsoft Security Blog.
Microsoft Security Blog Vulnerabilidades azure.microsoft.com -
WhatsApp añade Passkey para inicios de sesión resistentes al phishing en iOS y Android
Meta anunció una serie de funciones de seguridad para las cuentas de WhatsApp, incluyendo la compatibilidad con passkey para una cuenta. Esto permitirá a los usuarios de dispositivos iOS y Android iniciar sesión en sus cuentas mediante un…
Segu-Info Amenazas blog.segu-info.com.ar -
PayRange API
View CSAF Summary Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a…
CISA Advisories Vulnerabilidades cisa.gov -
FURUNO FA-50 Class B AIS Transponder
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to alter device settings. The following versions of FURUNO FA-50 Class B AIS Transponder are affected: FURUNO FA-50 Class B AIS Transponder…
CISA Advisories Vulnerabilidades cisa.gov -
State divergence enables unauthorized access
We found and reported a bug in Provenance Blockchain, a public proof-of-stake chain built on Cosmos SDK, that lets any user grant themselves admin control over marker accounts without holding a single token. Provenance covers a range of…
Trail of Bits General blog.trailofbits.com -
Keycloak corrige un fallo crítico en el restablecimiento de contraseñas que permite tomar cuentas sin autenticación
Keycloak ha corregido una vulnerabilidad crítica, CVE-2026-18963, que permite a un atacante remoto y sin autenticación forzar el restablecimiento de contraseña de cualquier usuario y hacerse con su cuenta. La prioridad pasa por actualizar…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com -
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic…
Unit 42 Seguridad IA unit42.paloaltonetworks.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.