Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 51 min 961 titulares en el archivo
Qué se está publicando
Distribución por tema
- miércoles 2 sep
-
The Dacls RAT ...now on macOS!
A sophisticated Lazarus Group implant has arrived on macOS. In this post, we deconstruct the Mac variant of a OSX.Dacls, detailing its install logic, persistence, and capabilities.
Objective-See General objective-see.org -
The 'S' in Zoom, Stands for Security
Today we uncover two (local) security flaws in Zoom's latest macOS client. First, a privilege escalation vulnerability, and second, a method to surreptitiously access a user's webcam and microphone (via Zoom).
Objective-See Vulnerabilidades objective-see.org -
Sniffing Authentication References on macOS
CVE-2017-7170 was a local priv-esc vulnerability that affected OSX/macOS for over a decade! Here (for the first time!), we dive into the technical details of finding the bug, the core flaw, and exploitation.
Objective-See Vulnerabilidades objective-see.org -
Weaponizing a Lazarus Group Implant
The Lazarus group's latest implant/loader supports in-memory loading of 2nd-stage payloads. In this post we describe exactly how to repurposing this 1st-stage loader to execute *our* custom 'fileless' payloads!
Objective-See General objective-see.org -
The Mac Malware of 2019
Our annual report on all the Mac malware of the year - including samples for download, infection vectors, persistence mechanisms, payloads and more!
Objective-See Amenazas objective-see.org -
Mass Surveillance, is an (un)Complicated Business
A massively popular iOS application turns out to be a government spy tool! Here, we analyze the app; decrypting its binary and studying its network traffic.
Objective-See General objective-see.org -
AI Agents Are Now Emailing Me with Their Security Concerns
I received the two emails below earlier in the month. They’re vaguely coherent. I suppose I shouldn’t be surprised that the corpus that AIs are training on contain data suggesting that I am someone to write to with random computer and…
Schneier on Security Seguridad IA schneier.com -
AI agents carried out every step of this ransomware attack – then left the victim an 80-page security audit
Adding insult to injury
The Register · Security Seguridad IA theregister.com -
Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs
Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. "The Fairwind…
The Hacker News Seguridad IA thehackernews.com -
Amazon’s AI assistant can now spot fake emails from the company
Amazon is trying to combat impersonation scams with a new feature that allows you to use its AI assistant to determine whether an email, text message, or phone call actually came from the company. With the update, you can ask Alexa for…
The Verge · IA Seguridad IA theverge.com -
[Virtual Event] What Every Enterprise Should Know About Securing Cloud Assets in the Age of AI
Dark Reading Seguridad IA darkreading.com -
[Virtual Event] Building a Secure AI Strategy for the Enterprise
Dark Reading Seguridad IA darkreading.com -
Health data of more than 9.5 million people leaked from Aesto record system
The healthcare data company Aesto informed federal regulators this week that more than 9.5 million people had sensitive information leaked during a cyberattack last December.
The Record Regulación therecord.media -
Critical SonicWall SMA1000 Vulnerabilities CVE-2026-83548, CVE-2026-83549 Exploited in the Wild
OverviewOn September 1, 2026, SonicWall disclosed two vulnerabilities affecting SonicWall SMA1000 appliances that the vendor says are being actively exploited in the wild. The vulnerabilities, CVE-2026-83548 and CVE-2026-83549, can be…
Rapid7 Vulnerabilidades rapid7.com -
Threat Gang 'Springs' Vishing Attacks on Microsoft Teams Users
The "Spring Ring" operation aims to compromise users of the collaboration suite to remotely access their sessions, spread malware, and even take over infrastructure.
Dark Reading Amenazas darkreading.com -
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
An active malware campaign is using bogus software-download websites to impersonate trusted vendors and distribute malicious installers. "The campaign has targeted users looking to download popular software and has resulted in compromises…
The Hacker News Amenazas thehackernews.com -
Researchers fear safety disaster ahead of OpenAI’s Astra release
OpenAI is on the cusp of releasing its most powerful AI model yet, Astra, following weeks of delays to shore up safety protocols after its agents attacked real targets during testing. As details about the model trickle out, researchers are…
The Verge · IA Seguridad IA theverge.com -
llm-gemini 0.34
Release: llm-gemini 0.34 New model gemini-3.8-flash for Gemini 3.8 Flash, with low, medium and high thinking levels. #146 Fixed async responses failing to record the resolved model version. Thanks, Charlie Tonneslan. #137 Tags: llm, gemini
Simon Willison Seguridad IA simonwillison.net -
Proactive cyber defense for governments and enterprises
Google DeepMind General deepmind.google -
Introducing Gemini 3.8 Flash and 3.8 Flash Cyber
Google DeepMind Seguridad IA deepmind.google -
The Trump administration is supporting OpenAI in the NYT copyright lawsuit
The Trump administration has intervened in The New York Times' copyright lawsuit against OpenAI, making an argument in favor of the AI lab. The landmark lawsuit, filed in December 2023, alleging that OpenAI unlawfully trained its AI…
The Verge · IA Seguridad IA theverge.com -
SonicWall's SMA1000 boxes under active attack again
Miscreants use chained zero days to pwn boxen as third-party SOCs say further attacks 'almost certain'
The Register · Security Vulnerabilidades theregister.com -
Tech support scams look different now. Here’s what to watch for
Tech support scams have evolved beyond fake virus warnings. Here’s how scammers reach their targets now, and how to stay safe.
Malwarebytes Labs General malwarebytes.com -
Hackers exploit critical JFrog Artifactory flaw to forge admin tokens
A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Google is sending MrBeast into the wilderness, armed with AI
MrBeast will feature Gemini, Google Health, and the Fitbit Air in upcoming videos as part of a multi-year partnership with Google. The deal will kick off with a video featuring Jimmy "MrBeast" Donaldson turning to Gemini for wilderness…
The Verge · IA Seguridad IA theverge.com -
UK Moves to Block High-Risk Tech Suppliers From Critical Infrastructure
Late amendments to the Cyber Security and Resilience Bill would give ministers new powers to restrict risky technology providers as supply chain attacks intensify. The post UK Moves to Block High-Risk Tech Suppliers From Critical…
SecurityWeek Infraestructura securityweek.com -
New pro-Ukraine hacker group targets Russian companies with custom ransomware
The group, which calls itself VantaCore, has targeted at least seven known victims, Russian cybersecurity firm F6 said in a report published this week.
The Record Amenazas therecord.media -
Russian Man Extradited Over Malware Campaign Targeting Freelancers
Russian man extradited to US over malware campaign that targeted 80,000 freelance users
Infosecurity Magazine Amenazas infosecurity-magazine.com -
Anatomy of a Silent Domain Takeover
Key Takeaways Modern AD attacks use legitimate protocols end-to-end, no malware, no exploit, nothing for signature tools to fingerprint. The evidence is already in the logs; what is missing is the narrative linking five benign-looking…
Qualys Vulnerabilidades blog.qualys.com -
Revolut scam wave steals £180,000 from Jersey residents in just four weeks
If you live in Jersey and bank with Revolut, you should be on your guard against scam phone calls. Because local police on the largest of the Channel Islands have warned that over a single four-week period, an astonishing 75% of all scam…
Graham Cluley General bitdefender.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.