Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 4 min 968 titulares en el archivo
Qué se está publicando
Distribución por tema
- jueves 27 ago
-
How to build an exposure management program the business trusts: Lessons from Tenable’s CSO
Discover how Tenable’s shift to an AI-driven exposure management program helped Tenable’s CSO, Robert Huber, overcome tool sprawl, unify data silos, mitigate the risk of rapid AI adoption, and shift from presenting granular, technical…
Tenable Seguridad IA tenable.com -
Identity-as-a-Service: Uncovering Dark Web Marketplaces Trading Executive SSNs
IntroductionDespite modern verification controls, identity theft remains one of the most pervasive threats to both individuals and enterprise organizations. U.S. Federal Trade Commission statistics show over 1 million identity theft…
Rapid7 Infraestructura rapid7.com -
Piloting the world's first double-blind AI evaluations
Piloting the world's first double-blind AI evaluations
Google DeepMind Seguridad IA deepmind.google -
Federal authorities disrupt China-backed hacking operation targeting US critical infrastructure
Compromised IoT devices were used in a yearslong campaign against key sectors and federal agencies.
Cybersecurity Dive Amenazas cybersecuritydive.com -
Mitsubishi Electric CNC Series (Update A)
View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause an out-of-bounds read, resulting in a denial-of-service condition in the affected products. The following versions of Mitsubishi…
CISA Advisories Vulnerabilidades cisa.gov -
Ebyte NA111-M
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to fully compromise the device. The following versions of Ebyte NA111-M are affected: NA111-M Firmware 9013-2-17 (CVE-2026-73125, CVE-2026-76179…
CISA Advisories Vulnerabilidades cisa.gov -
Mitsubishi Electric Multiple FA Products (Update D)
View CSAF Summary Successful exploitation of this vulnerability could allow a remote attacker to cause a denial-of-service (DoS) condition, a timeout error, or a communication delay by sending a specially crafted UDP packet to the product…
CISA Advisories Vulnerabilidades cisa.gov -
Xiiaozet LK100W
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to take control over the device. The following versions of Xiiaozet LK100W are affected: LK100W
CISA Advisories Vulnerabilidades cisa.gov -
Applied Systems Engineering ASE2000 V2 Communications Test Set
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to read or write arbitrary local files, cause the application to issue outbound network requests, or intercept the connection to impersonate the…
CISA Advisories Vulnerabilidades cisa.gov -
All-Line Equipment Company Fuel-Boss
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to execute arbitrary commands or code remotely on affected systems. The following versions of All-Line Equipment Company Fuel-Boss are affected…
CISA Advisories Vulnerabilidades cisa.gov -
Rockwell Automation OTTO Fleet Manager
View CSAF Summary Successful exploitation of this vulnerability could reduce the computational cost required for an attacker to perform offline brute-force attacks against stored password hashes. The following versions of Rockwell…
CISA Advisories Vulnerabilidades cisa.gov -
Back to the Future: Why Agentic AI Needs a Strong Identity Foundation
As AI matures, enterprises and customers are rapidly deploying agents seeking to unlock the next level of automation and productivity. Agentic AI shows potential to handle a multitude of use cases, from buying personal items on Amazon to…
NIST Cybersecurity Seguridad IA nist.gov -
Version Control DFIR: a Cheatsheet to GitHub, GitLab, Bitbucket, and Azure DevOps
A practitioner’s guide to log visibility, incident readiness, and threat hunting across the major version control services.
Wiz Infraestructura wiz.io -
Two Alleged ‘TeamPCP’ Hackers Arrested in Australia
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement…
Krebs on Security Amenazas krebsonsecurity.com -
CISA suma seis fallos explotados al catálogo KEV y eleva la urgencia de parcheo en NetScaler, Linux y SQL Server
CISA añadió el 26 de agosto de 2026 seis vulnerabilidades al catálogo Known Exploited Vulnerabilities (KEV), una señal de explotación activa que suele marcar prioridades inmediatas de corrección. El lote incluye un fallo reciente en Citrix…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com -
Threat landscape for industrial automation systems. Q2 2026
The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems.
Securelist (Kaspersky) Amenazas securelist.com -
JavaScript obfuscation: From party trick to phishing kit
Learn the basics of what obfuscation is, why a researcher would try to reverse it, and several ways to approach the problem.
Cisco Talos Amenazas blog.talosintelligence.com -
LLM-Based Social Engineering Scams
OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive: The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators…
Schneier on Security Seguridad IA schneier.com -
A polymorphic phishing page (that occasionally breaks itself), (Thu, Aug 27th)
As I've mentioned before in some of my diaries, from time to time, I like to go over phishing messages that get caught in my various spam traps or sent to us here at the Internet Storm Center.
SANS Internet Storm Center Amenazas isc.sans.edu -
US Navy tells sailors and their families: scrub your social media, enemies are watching
The US Navy has told its entire workforce of 340,000 active-duty personnel, 58,000 reservists, and 210,000 civilian employees to clean up their social media profiles, because adversaries might be using them to determine who they are, where…
Graham Cluley General bitdefender.com -
AI-driven OSINT in the wrong hands – and why everyone could be a target for fraud
It’s getting cheaper and easier for cybercriminals to research potential victims. Here’s what’s still in your control.
WeLiveSecurity (ESET) Seguridad IA welivesecurity.com -
Cloudflare Connect 2026 en San Francisco: Fórmate, Certificate y Lidera la Transformación.
Los días 19, 20 y 21 tendrá lugar Cloudflare Connect 2026 en San Francisco, el evento para Clientes, Partners y Creadores de Internet de Cloudflare. Es el evento del año de la compañía. El evento más importante si quieres entender hacia…
El lado del mal Infraestructura elladodelmal.com -
Breaking Claude Code Opus 5 Auto Mode
In this post, we explore how a simple website summary request hijacks Claude Code Opus 5 in Auto Mode and achieves code execution with 60-80% attack success rate using a small sample size. This is interesting because a third-party…
Embrace The Red Seguridad IA embracethered.com - miércoles 26 ago
-
ISC Stormcast For Thursday, August 27th, 2026 https://isc.sans.edu/podcastdetail/10070, (Thu, Aug 27th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
SANS Internet Storm Center General isc.sans.edu -
BlueDelta Targets Defense and Diplomacy with HOOKEDGE
Discover how the Russian state-sponsored threat group BlueDelta is using the HOOKEDGE backdoor to target defense and diplomatic organizations across Europe
Recorded Future Amenazas recordedfuture.com -
Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency
A hacker calling themselves "CYBERLEEK" has been leaking gameplay footage from GTA 6 ahead of its official reveal this week - but they're not asking Rockstar Games for a ransom. Instead, they've launched their own cryptocurrency, promising…
Graham Cluley Amenazas grahamcluley.com -
Real-Time IT Incident Detection and Intelligence with NVIDIA NIM Inference Microservices and ITMonitron
In today’s fast-paced IT environment, not all incidents begin with obvious alarms. They may start as subtle, scattered signals, a missed alert, a quiet SLO...
NVIDIA · Ciberseguridad General developer.nvidia.com -
How Hackers Exploit AI’s Problem-Solving Instincts
As multimodal AI models advance from perception to reasoning, and even start acting autonomously, new attack surfaces emerge. These threats don’t just target...
NVIDIA · Ciberseguridad Seguridad IA developer.nvidia.com -
State of AI Cybersecurity 2026: 87% of Security Professionals are Seeing More AI-Driven Threats, But Few Feel Ready to Stop Them
Originally published by Darktrace. Findings from our annual survey of 1,500+ cyber professionals reveal that security leaders are confronting a surge in AI-driven attacks, which are faster, more personalized, and harder to detect than…
Cloud Security Alliance Seguridad IA cloudsecurityalliance.org -
Top 6 Claude in Chrome Security Risks to Model Before You Roll It Out
Most teams evaluate a browser agent like a browser extension. Check the permissions, check the vendor, check for open CVEs, approve or deny. That framing produced two clean patch cycles in 2026 and no reduction in exposure. Two problems…
Cloud Security Alliance Seguridad IA cloudsecurityalliance.org
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.