Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 1 min 956 titulares en el archivo
Qué se está publicando
Distribución por tema
- Ayer
-
numbat - AI agent observability, (Fri, Sep 4th)
Enterprises face an unmanaged crisis of AI agent and MCP server sprawl, characterized by rapid, decentralized proliferation of autonomous agents, protocol connections operating with excessive privilege, opaque execution paths, and identity…
SANS Internet Storm Center Seguridad IA isc.sans.edu -
The Pelican comparison grid for Astra is pretty interesting
I got access to GPT-6 Astra this afternoon, so naturally I used it to generate SVGs of pelicans riding bicycles - at low, medium, high, xhigh and max reasoning levels (Astra doesn't support reasoning=none). Then I rendered those pelicans…
Simon Willison General simonwillison.net -
Friday Squid Blogging: Squid on a Stick at the New York State Fair
Looks tasty. As usual, you can also use this squid post to talk about the security stories in the news that I haven’t covered. Blog moderation policy.
Schneier on Security General schneier.com -
CVE-2015-3673: Goodbye Rootpipe...(for now?)
Details on bypassing Apple's original rootpipe patch
Objective-See Vulnerabilidades objective-see.org -
ASCII smuggling isn't just an AI security risk
Phishers find a new use for invisible Unicode tag characters
The Register · Security Seguridad IA theregister.com -
How to secure edge AI in customer-owned environments
As AI moves into customer-owned environments, organizations need new ways to verify the systems, software, and AI assets they trust before releasing sensitive data, credentials, and models. The post How to secure edge AI in customer-owned…
Microsoft Security Blog Seguridad IA microsoft.com -
Architecting memory and storage in the AI era
The era of AI inference has arrived. Imagine a healthcare system analyzing millions of data points in real time to accelerate life-saving medical research, or an intelligent assistant instantly resolving thousands of complex customer needs…
MIT Technology Review · IA Seguridad IA technologyreview.com -
OSPAR 2026 report now available with 167 services in scope
We’re pleased to confirm the successful completion of our annual Amazon Web Services (AWS) Outsourced Service Provider’s Audit Report (OSPAR) assessment on July 29, 2026, in line with the OSPAR version 2.0 framework. The Association of…
AWS Security Regulación aws.amazon.com -
Roland is getting into generative AI music with Melody Flip
It's not quite the "push button; get song" of Suno, but Roland's new Melody Flip tool marks the company's foray into generative AI music. Available as a plug-in for your digital audio workstation (DAW), Melody Flip offers around 250…
The Verge · IA Seguridad IA theverge.com -
OpenAI's rogue agents were caught communicating via public wikis
Here we go again... Discovery of a new OpenAI agent message board by Sydney Von Arx, Cormac Slade Byrd, Spencer Kitts, and Thomas Larsen describes the latest accidental cyberattack by models being trained by OpenAI. This time it was agents…
Simon Willison Seguridad IA simonwillison.net -
The hidden work of modernizing Malwarebytes
Why disciplined dependency modernization is one of the highest-leverage engineering investments a security product can make.
Malwarebytes Labs Amenazas malwarebytes.com -
IDScan sued over alleged data breach affecting 153 million drivers
Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver's licenses. [...]
BleepingComputer Regulación bleepingcomputer.com -
Using a VM to Contain an AI Agent
It won’t work: My suspicion was that GPT 5.6-Cyber would succeed, but the frequency and manner of its success removed all doubt. We have to reassess sandboxing quality for capable AI agents, and in general the software stack with which…
Schneier on Security Seguridad IA schneier.com -
In Other News: Microsoft’s Cloud Patches, Hacked Dropbox Accounts, Guardio’s $1.1B Valuation
Noteworthy stories that might have slipped under the radar: Microsoft rolled out patches for cloud services, hackers compromised 5,000 Dropbox accounts, and Guardio is now valued at $1.1 billion. The post In Other News: Microsoft’s Cloud…
SecurityWeek Vulnerabilidades securityweek.com -
HPE Patches Critical RCE Vulnerabilities in AOS-CX
Nearly two dozen issues, tracked collectively as CVE-2026-73749 (CVSS score of 9.8), were addressed with the updates. The post HPE Patches Critical RCE Vulnerabilities in AOS-CX appeared first on SecurityWeek.
SecurityWeek Vulnerabilidades securityweek.com -
OpenAI Pledges $1 Billion to Bring Frontier AI to Critical Infrastructure Defenders
The Daybreak initiative will provide subsidized AI cyber capabilities, training and technical assistance, though OpenAI has disclosed few details about costs and eligibility. The post OpenAI Pledges $1 Billion to Bring Frontier AI to…
SecurityWeek Seguridad IA securityweek.com -
Microsoft says virtually nobody was grabbing NYT articles through its chatbot
Microsoft's Copilot rarely reproduces even full sentences from news articles and books, let alone substantive chunks that could substitute for the original, the company says in new legal filings as it fights copyright claims from…
The Verge · IA Seguridad IA theverge.com -
Silver Bullet Security Podcast 160 – Aaron Bedra
View on Zencastr On Episode 160 of the Silver Bullet Security Podcast, BIML’s Gary McGraw hosts Aaron Bedra. Aaron talks about enterprise adoption of AI/ML from his perspective at the intersection of security engineering and executive…
Berryville Institute (BIML) Seguridad IA berryvilleiml.com -
Rogue OpenAI agents used dead German web site to communicate in May, months before Hugging Face incident
Two cases of agents escaping to solve unsolvable problems paints an uncomfortable question: Is the entire internet in OpenAI's experimental agentic firing line?
The Register · Security Seguridad IA theregister.com -
Companies Have Six Months to Prepare for Automated Attacks
Frontier AI models have already demonstrated they can autonomously — and in some cases, inadvertently — conduct end-to-end compromises, but the situation will become more urgent very soon.
Dark Reading Seguridad IA darkreading.com -
Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters
Microsoft is alerting of a "high-volume phishing campaign" that's using invisible Unicode tag characters to bypass email filters. "Instead of using these characters to hide instructions from people while exposing them to AI models, the…
The Hacker News Seguridad IA thehackernews.com -
Nvidia’s $12.9B Hugging Face deal could benefit enterprises
The chipmaker’s acquisition could eventually bring additional security resources and model evaluation tools to the platform, according to experts.
Cybersecurity Dive General cybersecuritydive.com -
US, Britain to coordinate on scam center takedowns
The U.S. Department of Justice and the U.K.'s National Crime Agency and Crown Prosecutor signed a memorandum to cooperate on cases involving Southeast Asian scam operations.
The Record General therecord.media -
Critical Citrix NetScaler auth bypass now leveraged in attacks
Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution
PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS…
The Hacker News Vulnerabilidades thehackernews.com -
New Ted Backdoor Hides Inside Victims' Own HAProxy Builds to Intercept Web Traffic
A previously undocumented Linux toolkit has been found compiled directly into the trojanized HAProxy load balancers of two South Korean organizations, where it intercepted web traffic and served altered pages to selected visitors. The…
The Hacker News Amenazas thehackernews.com -
UK account-hack losses surge as new reporting system exposes hidden cases
In its first annual assessment, published Friday, the City of London Police said victims reported losing £6.3 million ($8.5 million) to account hacks in the year ending March 31, up from £1.2 million ($1.6 million) a year earlier.
The Record General therecord.media -
Google corrige un día cero de V8 en Chrome que se explota de forma activa
Google ha distribuido una actualización urgente de Chrome para corregir CVE-2026-85046, un zero-day en V8 con explotación activa. La solución pasa por actualizar a Chrome 152.0.7977.82 o superior y reiniciar el navegador para aplicar el…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com -
Actualización de Chrome corrige vulnerabilidad Zero-Day de V8 que se encuentra activamente explotada
Google publicó el jueves actualizaciones de seguridad para corregir 12 vulnerabilidades, incluyendo una que ha sido explotada activamente. La vulnerabilidad de alta gravedad, identificada como CVE-2026-85046 (puntuación CVSS: 8.8), se…
Segu-Info Vulnerabilidades blog.segu-info.com.ar -
Microsoft says some users can’t open the Teams desktop client
Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. [...]
BleepingComputer General bleepingcomputer.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.