Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 51 min 961 titulares en el archivo
Qué se está publicando
Distribución por tema
314 titulares de severidad Media Limpiar filtros ×
- lunes 24 ago
-
24th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting payment…
Check Point Research General research.checkpoint.com - viernes 21 ago
-
The invisible passenger in your car
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.
Securelist (Kaspersky) Amenazas securelist.com - jueves 20 ago
-
BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary…
Check Point Research General research.checkpoint.com -
Identity Abuse Through Trusted Communication Channels
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.
Unit 42 Vulnerabilidades unit42.paloaltonetworks.com -
Zero-click Grok data theft: Cryptographic Context Injection attack leaks chat histories
Cryptographic Context Injection ships attacker instructions as ciphertext the model decrypts in its own sandbox. It leaked full Grok chat histories, zero-click.
Adversa AI General adversa.ai - miércoles 19 ago
-
A revisit of remote Spectre attacks on Cloudflare Workers
In 2024 and 2025, we reassessed remote Spectre attacks on our Workers infrastructure. We share details about the new attack primitives like Spectre gadgets, remote timers, achieving co-location and how new defenses further harden…
Cloudflare Infraestructura blog.cloudflare.com -
Describing attacks with crime script analysis
Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.
Cisco Talos General blog.talosintelligence.com - martes 18 ago
-
Recorded Future Launches 6 New Capabilities for Third-Party Risk
Recorded Future has launched native risk ratings capabilities inside its Third-Party Risk product, uniting threat intelligence and risk ratings in a single workflow.
Recorded Future General recordedfuture.com -
Remediation Agents, Demystified: Why Fixing Beats Finding
See how Snyk’s Remediation Agent uses security intelligence, breakability analysis, and validation to turn vulnerabilities into mergeable pull requests.
Snyk Vulnerabilidades snyk.io -
AI Governance Programs: What CISOs Say vs. What They Actually Do
Security leaders have heard the phrase “AI has expanded the attack surface” enough times. The more interesting story is the widening gap between what CISOs say they're doing about it and what's actually happening inside their…
Cloud Security Alliance Seguridad IA cloudsecurityalliance.org -
Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)
In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks. The post Threat Brief: Mitigating…
Unit 42 General unit42.paloaltonetworks.com -
Quishing: cómo los códigos QR pueden eludir la seguridad corporativa
El quishing se ha convertido en una alternativa popular al phishing tradicional. Así es como las empresas pueden cerrar esa brecha.
WeLiveSecurity (ESET) Amenazas welivesecurity.com -
New Report: AI threats are here. Why Q2 2026 signals the end of traditional patch cycles
You can’t patch everything. So what do you fix first? Findings in Q2 2026 have changed traditional answers.The latest Quarterly Threat Landscape Report from Rapid7 Labs shows vulnerability disclosures still surging while attackers use…
Rapid7 Seguridad IA rapid7.com -
Top 10 zero-click attacks against AI agents
Ten documented zero-click attacks on AI agents in shipped products: what each one broke, which CVEs followed, and the controls that reduce the risk.
Adversa AI Seguridad IA adversa.ai -
Benchmarking Secure-and-Functional Remediation and How Snyk Agent Fix Lifts Frontier-Model Fix Rates by over 14%
A benchmark of secure, functional vulnerability fixes across JavaScript, Java, and Python shows Snyk Intelligence helps frontier models break past a 72–75% performance plateau.
Snyk Vulnerabilidades snyk.io - lunes 17 ago
-
PurpleDelta's Fraudulent Employment Operations
Learn how North Korean IT worker threat cluster "PurpleDelta" uses AI-generated personas, sophisticated tradecraft, and custom ChatGPT assistants to infiltrate organizations. Discover key indicators of compromise and mitigation strategies…
Recorded Future Seguridad IA recordedfuture.com -
Cadena de exploits para videollamadas VoLTE Unisoc otorga acceso completo al kernel de Android
Investigadores de seguridad de SSD Secure Disclosure han publicado una cadena de exploits en dos etapas que permite el acceso completo al kernel de Android en dispositivos con firmware de módem Unisoc mediante una videollamada VoLTE, sin…
Segu-Info Vulnerabilidades blog.segu-info.com.ar -
Stronger Cybersecurity Programs Start with People: NIST Wants Your Input on the Path Forward for Human-Centered Cybersecurity
When was the last time a cybersecurity process at work made you want to scream? Maybe it was a password requirement so complicated you had to write it down (defeating the purpose), a phishing simulation test that felt more like a trap than…
NIST Cybersecurity Amenazas nist.gov -
How QR-code phishing can slip past corporate security measures
Quishing has become a popular alternative to traditional phishing. Here’s how businesses can close the gap.
WeLiveSecurity (ESET) Amenazas welivesecurity.com - viernes 14 ago
-
The Agentic AI threat cluster: Seven incidents, three actors, and what they mean for your exposure
Tenable’s Research Special Operations (RSO) team has been tracking a cluster of agentic AI threat activity since late July 2026. The Taiwan autonomous AI cyber attack confirmed what the cluster data already showed: near-autonomous…
Tenable Seguridad IA tenable.com - jueves 13 ago
-
Curiouser and Curiouser
In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers.
Cisco Talos Amenazas blog.talosintelligence.com -
Black Hat USA 2026: Will vulnerability discovery eventually decline in the AI era?
And will today’s surge in AI-driven vulnerability discovery eventually make tomorrow’s software safer?
WeLiveSecurity (ESET) Seguridad IA welivesecurity.com -
Fortinet Patches Authentication Flaws in FortiWeb and FortiManager
The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com -
Searchlight Cyber combines exposure and threat intelligence in new PTEM platform
Searchlight Cyber has launched its Preemptive Threat Exposure Management (PTEM) platform, combining exposure visibility with real-world attacker intelligence to help organizations prioritize and reduce the exposures most likely to be…
Help Net Security General helpnetsecurity.com -
Dissecting the JWR phishing framework
Cisco Talos recently identified an undocumented phishing framework, internally branded "JWR" by its developer, built to convincingly impersonate checkout and login pages across major payment and shopping platforms.
Cisco Talos Regulación blog.talosintelligence.com -
'Jewelbug' APT Balances State Espionage & Cryptocurrency Theft
Researchers discovered hackers-for-hire performing cyber espionage and financially motivated heists from the same Web panel.
Dark Reading Amenazas darkreading.com -
DDoS attacks hit record scale as 1 Tbps+ campaigns become more common
DDoS attacks grew in scale during the first half of 2026, bringing larger traffic floods, shorter attack durations, and increasingly automated campaigns. Cloudflare’s H1 2026 DDoS Threat Report shows threat actors relying on multi-vector…
Help Net Security Amenazas helpnetsecurity.com - miércoles 12 ago
-
Wireshark 4.6.8 patches 28 security bugs, nine in file parsers
Wireshark 4.6.8 fixes 28 security bugs in the protocol analyzer, and nine of them fire when someone opens a saved capture file. Those nine sit in file parsers, the code that reads a capture off disk before any dissection begins: pcapng…
Help Net Security Vulnerabilidades helpnetsecurity.com -
Chinese Loongson processors have leaky caches, researchers find
Attackers could extract data, even working from inside a guest VM
The Register · Security General theregister.com -
Malware Crypting Services and the Threat Actors Who Sell Them
Insikt Group analyzes 24 threat actors selling malware crypting services. Learn about their evasion techniques, market dynamics, and how defenders can prioritize behavioral detection over static analysis.
Recorded Future Amenazas recordedfuture.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.