Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 5 min 961 titulares en el archivo
Qué se está publicando
Distribución por tema
198 titulares en General Limpiar filtros ×
- martes 11 ago
-
How Trail of Bits helps verify the integrity of your Signal chats
Every Signal chat starts the same way: the client asks the Signal server for the public key associated with your contact’s phone number. But how do you know the server gave you the right key? A compromised server could provide a false…
Trail of Bits General blog.trailofbits.com -
DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi
This is why we can't have nice things, people
The Register · Security General theregister.com -
Two wars and a World Cup lead to epic DDoS attacks on publishers
Ukraine, Iran, and football inspire geopolitically motivated DDoS attacks, while 1 Tbps traffic jams up 519 percent
The Register · Security General theregister.com -
Mozilla updates GPG signing key for Firefox releases after exposure
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. [...]
BleepingComputer General bleepingcomputer.com -
Citrix expands Platform Flex with observability and secure developer services
Citrix has announced new services for Citrix Platform Flex, extending its flexible credit model with additional options for delivering, monitoring and securing digital work environments. The new offerings include Citrix Experience Insights…
Help Net Security General helpnetsecurity.com -
Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G
Researchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, disrupt communications, downgrade connections to 2G, and in some…
Help Net Security General helpnetsecurity.com -
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole…
The Hacker News General thehackernews.com -
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories. That key is how a user, or a…
The Hacker News General thehackernews.com -
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
Audit logs found no unexpected visitors, but release verification still needs an update
The Register · Security General theregister.com -
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the…
The Hacker News General thehackernews.com -
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP…
The Hacker News General thehackernews.com -
Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G
Researchers find standards-compliant functionality can be abused to hijack modems, downgrade connections, and even execute code
The Register · Security General theregister.com -
Locking your ssh-agent exposed local-only keys until OpenSSH 10.5
Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether a request came from your own machine or arrived down a…
Help Net Security General helpnetsecurity.com -
Mozilla Issues New Firefox GPG Key Following Exposure
The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek.
SecurityWeek General securityweek.com -
Cybersecurity jobs available right now: August 11, 2026
CTI Detection Engineer Department of Parliamentary Services | Australia | Hybrid – View job details As a CTI Detection Engineer, you will lead the detection lifecycle by identifying detection gaps, developing and validating detection…
Help Net Security General helpnetsecurity.com - lunes 10 ago
-
Introducing Muse Glimmer
Introducing Muse Glimmer Meta are back in the open weights game! Muse Glimmer is a brand new 30B model under a clean Apache 2.0 license (a step up from the janky Llama licenses of old). They claim to have optimized it for exactly the kind…
Simon Willison General simonwillison.net -
Multistate Water System Attacks Widen, Iran Suspected
Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.
Dark Reading General darkreading.com -
Tutores de IA en la educación: ¿qué tan seguros son?
Los tutores de IA pueden ofrecer una ayuda útil, pero su calidad y sus medidas de seguridad varían mucho. Estos son algunos aspectos que conviene comprobar antes de incorporarlos al proceso de aprendizaje.
WeLiveSecurity (ESET) General welivesecurity.com -
10th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City…
Check Point Research General research.checkpoint.com - viernes 7 ago
-
ICS Security Conference 2026
JPCERT/CC held the ICS Security Conference 2026 on February 10, 2026. This conference aims to share the current threat landscape surrounding Industrial Control System (ICS) in Japan and abroad, as well as initiatives undertaken by…
JPCERT/CC General blogs.jpcert.or.jp - jueves 6 ago
-
CSS:the bomb inside your inbox
Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this
PortSwigger Research General portswigger.net - miércoles 5 ago
-
CRLF-Powered Desync Attacks: Beheading HTTP Streams
Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power
PortSwigger Research General portswigger.net - lunes 3 ago
-
Web scraping: qué es, cómo funciona y cuándo es legal
El web scraping puede ser beneficioso para las empresas, pero también es utilizado por ciberdelincuentes para recopilar y comprometer datos sensibles, lo que representa un riesgo para la seguridad de los usuarios legítimos.
WeLiveSecurity (ESET) General welivesecurity.com -
Welcoming the Nepalese Government to Have I Been Pwned
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteToday, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal…
Troy Hunt General troyhunt.com - domingo 2 ago
-
Weekly Update 515: Seeking Caffeine Utopia
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteApparently, Aussies are so obsessed with coffee that it's referred to as the coffee capital of…
Troy Hunt General troyhunt.com - viernes 31 jul
-
Capturas de pantalla falsas: el riesgo de confiar en una prueba digital
Las capturas de pantalla pueden ayudar a documentar pagos, reservas o conversaciones, pero cada vez son menos fiables como evidencia y más fáciles de falsificar.
WeLiveSecurity (ESET) General welivesecurity.com - jueves 30 jul
-
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers…
Krebs on Security General krebsonsecurity.com -
Building secure Uniswap v4 hooks
Uniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom accounting, and external integrations. This flexibility moves some security responsibilities into application and hook code. The Cork and Bunni…
Trail of Bits General blog.trailofbits.com - miércoles 22 jul
-
TSUBAME Report Overflow (Jan-Mar 2026)
This TSUBAME Report Overflow series discusses observation trends from TSUBAME sensors both in Japan and overseas, as well as other topics not covered in the Internet Threat Monitoring Quarterly Report. This article covers monitoring…
JPCERT/CC General blogs.jpcert.or.jp - martes 21 jul
-
LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found…
Krebs on Security General krebsonsecurity.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.