Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 54 min 970 titulares en el archivo
Qué se está publicando
Distribución por tema
- martes 25 ago
-
The patch window is collapsing: Why security needs a new control plane
Organizations need protection that operates in the gap between discovery and remediation. The post The patch window is collapsing: Why security needs a new control plane appeared first on Microsoft Security Blog.
Microsoft Security Blog Vulnerabilidades azure.microsoft.com -
WhatsApp añade Passkey para inicios de sesión resistentes al phishing en iOS y Android
Meta anunció una serie de funciones de seguridad para las cuentas de WhatsApp, incluyendo la compatibilidad con passkey para una cuenta. Esto permitirá a los usuarios de dispositivos iOS y Android iniciar sesión en sus cuentas mediante un…
Segu-Info Amenazas blog.segu-info.com.ar -
The Path to the Autonomous SOC: The Early Returns of AI & What It Means for Cybersecurity
Discover how early-stage AI yields rapid SOC returns, driving platform consolidation and reducing analyst burnout in this blog post.
SentinelOne Seguridad IA sentinelone.com -
What's in a tag name? JavaScript, apparently
I was on my laptop, as I often am when there's rubbish on telly, and found myself wondering what characters are allowed in a tag. I knew they had to begin with "a-zA-Z", but what about after that? I t
PortSwigger Research General portswigger.net -
Vulnerabilidad de Oracle WebLogic, explotada activamente, permite a atacantes no autenticados acceder a datos críticos
La Agencia CISA añadió el lunes una vulnerabilidad de máxima gravedad que afecta a Oracle HTTP Server y Oracle WebLogic Server a su catálogo de Vulnerabilidades Explotadas Conocidas (KEV), citando evidencia de explotación activa.La…
Segu-Info Vulnerabilidades blog.segu-info.com.ar -
PayRange API
View CSAF Summary Successful exploitation of this vulnerability could allow a remote, authenticated or unauthenticated attacker to disclose sensitive information, arbitrarily modify the device to cause a denial of service, or alter a…
CISA Advisories Vulnerabilidades cisa.gov -
FURUNO FA-50 Class B AIS Transponder
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to alter device settings. The following versions of FURUNO FA-50 Class B AIS Transponder are affected: FURUNO FA-50 Class B AIS Transponder…
CISA Advisories Vulnerabilidades cisa.gov -
The County Prosecutors Who Became ICE Informants
Illinois prosecutors shared defendants’ personal data with federal immigration agents without criminal warrants, public disclosure, or legislative oversight.
WIRED · Security General wired.com -
State divergence enables unauthorized access
We found and reported a bug in Provenance Blockchain, a public proof-of-stake chain built on Cosmos SDK, that lets any user grant themselves admin control over marker accounts without holding a single token. Provenance covers a range of…
Trail of Bits General blog.trailofbits.com -
Keycloak corrige un fallo crítico en el restablecimiento de contraseñas que permite tomar cuentas sin autenticación
Keycloak ha corregido una vulnerabilidad crítica, CVE-2026-18963, que permite a un atacante remoto y sin autenticación forzar el restablecimiento de contraseña de cualquier usuario y hacerse con su cuenta. La prioridad pasa por actualizar…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com -
The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution
Explore Unit 42 research on AI-enabled malware. Learn how existing behavioral detection and endpoint analytics stop AI-authored code before execution. The post The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic…
Unit 42 Seguridad IA unit42.paloaltonetworks.com -
The safety penalty: Reclaiming operational sovereignty in the age of AI
As frontier AI models become increasingly restrictive, security teams are facing a "safety penalty" that hampers real-time incident response. Discover how organizations can move toward operational sovereignty to ensure their defensive AI…
Cisco Talos Seguridad IA blog.talosintelligence.com -
I spent a day at a robot “carnival” in Shanghai. Here’s what I saw.
Humanoid robots are having a moment in China. The popular machines are part of the country’s strategy to bring artificial intelligence into daily life. Embedding the technology into physical systems—an idea called embodied AI—was a key…
MIT Technology Review · IA Seguridad IA technologyreview.com -
Septiembre: Media Party Barcelona, Cancún Latam CISO Summit & Barcelona AI Summit
Hoy tengo mir sesión en el Máster en IA Aplicada & Optimización de Procesos Productivos que os conté hace ya unos meses. Es mi vuelta a dar charlas después del verano, y en Septiembre tengo una serie de actividades que estoy organizándome…
El lado del mal Seguridad IA elladodelmal.com -
日本のビジネスパーソンを対象としたWiz調査で 「AI導入加速」はクラウド移行を上回ることが明らかに
同時に8割以上がAIによるサイバー攻撃への備えに遅れを感じ、60%がAIセキュリティへの投資を計画
Wiz General wiz.io -
OWASP Agentic Skills Top 10 explained: the ten agent skill risks, and which to fix first
OWASP's newest Top 10 covers the skill layer: prose files agents load and act on. What all ten risks mean, and the order to fix them.
Adversa AI Seguridad IA adversa.ai - lunes 24 ago
-
CVE-2026-69414 ShieldBreak Zero-Day: No Patch, and CISA BOD 26-04 Gives You 14 Days
Executive Summary ShieldBreak (CVE-2026-69414) is a zero-day elevation-of-privilege vulnerability in the Microsoft Malware Protection Engine used by Microsoft Defender, allowing a low-privilege local attacker to escalate to SYSTEM. A…
Qualys Vulnerabilidades blog.qualys.com -
Mexico’s Cybersecurity Plan 2025-2030: Turning Ambition Into Defense
Explore Mexico’s 2025–2030 Cybersecurity Plan. Learn about key threats, including ransomware, and the roadmap for building durable national cyber defenses.
Recorded Future Amenazas recordedfuture.com -
ChatGPT for Teens: el desafío de hacer la IA más segura para los adolescentes
A medida que la inteligencia artificial gana espacio entre los adolescentes, controles parentales y nuevas medidas de protección buscan reducir sus riesgos.
WeLiveSecurity (ESET) Seguridad IA welivesecurity.com -
The Cloudflare Blog — brought to you by EmDash
We migrated the Cloudflare Blog to EmDash to prove our stack at massive scale. Here is how we stress-tested performance, safely routed production traffic, and redesigned the frontend experience.
Cloudflare Infraestructura blog.cloudflare.com -
Rapid7 Analysis: Microsoft SharePoint Remote Code Execution (CVE-2026-63520)
Rapid7 Vulnerabilidades rapid7.com -
Troyanos Info Stealer se distribuyen con infección de sitios de América Latina
Investigadores de ciberseguridad han detectado dos nuevas familias de malware, WordlistLoader y SynkLoader, que se utilizan para distribuir cargas útiles avanzadas y, probablemente, vender acceso a grupos de ransomware. Según los hallazgos…
Segu-Info Amenazas blog.segu-info.com.ar -
Malicious Firefox add-ons caught stealing cryptowallet seed phrases and browser credentials
Every time you add an extension or plugin to your browser, there's a risk that you might be doing more than managing your cryptocurrency wallet, generating passwords, taking notes, or tracking sports results. There's a chance that you have…
Graham Cluley General bitdefender.com -
How to encourage smarter AI use in the classroom
This article is from Making AI Work, MIT Technology Review’s limited-run newsletter examining how to apply LLMs across industries. To receive it in your inbox, sign up here. Chatbots took many schools by surprise upon their release a few…
MIT Technology Review · IA Seguridad IA technologyreview.com -
24th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 24th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Latvia’s Road Traffic Safety Directorate (CSDD) has confirmed a breach affecting payment…
Check Point Research General research.checkpoint.com -
Gunra ransomware: what you need to know
The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog.
Graham Cluley Vulnerabilidades fortra.com -
Tempos por Tweets: Tempos para tu Comunidad, y Tempos por apoyar perfiles en X
El servicio de Tempos x Tweets lleva años funcionando en MyPublicInbox, pero recientemente ha sufrido un rediseño de funcionamiento, y quería contaros cómo funciona. Yo reparto todos los días Tempos gratis a todos los usuarios de Twitter/X…
El lado del mal General elladodelmal.com -
Weekly Update 518: IoT Doorlock Nirvana with UniFi
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteI genuinely think I've nailed the IoT door lock situation! Well, Ubiquiti has, but I think I've…
Troy Hunt General troyhunt.com - domingo 23 ago
-
El propio controlador de Microsoft Defender puede utilizarse como arma para eliminar el software de seguridad al arrancar el sistema.
Check Point Research ha revelado una técnica que utiliza el controlador de remediación de arranque de Microsoft Defender, firmado legítimamente, para realizar operaciones arbitrarias de archivos y registro a nivel de kernel en sistemas…
Segu-Info General blog.segu-info.com.ar -
Welcoming the Sri Lankan Government to Have I Been Pwned
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteToday, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri…
Troy Hunt General troyhunt.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.