Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 42 min 970 titulares en el archivo
Qué se está publicando
Distribución por tema
- viernes 21 ago
-
Say it once: Introducing Bot Preference Sync
Cloudflare's new Bot Preference Sync automatically aligns your robots.txt file with your AI bot policies for Search, Agent, and Training. Easily manage which bots access your content without maintaining static files.
Cloudflare Seguridad IA blog.cloudflare.com -
Connecting the Dots: Securing the Overlooked Corners of the Software Development Lifecycle (SDLC) Supply Chain
Attackers are targeting CI/CD pipelines and developer tools instead of application code, requiring total SDLC visibility and strict security controls The post Connecting the Dots: Securing the Overlooked Corners of the Software Development…
Unit 42 Infraestructura unit42.paloaltonetworks.com -
Where Security Fits in an AI Agent Stack
As AI agents become more capable and operate over longer horizons, building security and trust into the applications they power becomes increasingly important....
NVIDIA · Ciberseguridad Seguridad IA developer.nvidia.com -
NVIDIA AVO Reaches 100% on ARC-AGI-3, Demonstrating a Frontier-Level General-Purpose Architecture for Long-Horizon Autonomous Agents
A frontier language model is only one component of an AI agent. The surrounding agent system—often called a harness—determines how the model receives...
NVIDIA · Ciberseguridad Seguridad IA developer.nvidia.com -
The Good, the Bad and the Ugly in Cybersecurity – Week 34 (2026)
U.S. indicts Iranian cyber espionage operations, Medusa ransomware breaches 500 organizations, and attackers exploit a critical Windows protocol flaw.
SentinelOne Vulnerabilidades sentinelone.com -
The invisible passenger in your car
Kaspersky expert has discovered new Android malware designed to serve ads and build a proxy botnet. It's delivered through legitimate software for DoFun head units.
Securelist (Kaspersky) Amenazas securelist.com - jueves 20 ago
-
AWS Network Firewall now supports rule hit count
As firewall rule sets grow in complexity, security teams face a common challenge: manual log analysis is used to determine which rules are actively matching traffic and which are consuming capacity without being triggered. This lack of…
AWS Security Infraestructura aws.amazon.com -
Six Agent Harness Capabilities for Higher Model Performance
Building a great AI agent isn’t just about choosing the right models. The harness is the architecture surrounding the model. How it renders context, executes...
NVIDIA · Ciberseguridad Seguridad IA developer.nvidia.com -
Is Cyber missing the Marque?
In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber…
Cisco Talos General blog.talosintelligence.com -
Black Hat USA 2026: ¿caerá el descubrimiento de vulnerabilidades en la era de la IA?
El descubrimiento acelerado de vulnerabilidades impulsado por IA plantea una pregunta clave: ¿disminuirá el hallazgo de nuevas fallas de seguridad en el futuro?
WeLiveSecurity (ESET) Vulnerabilidades welivesecurity.com -
From all-or-nothing to task-based OAuth consent
Cloudflare OAuth now supports optional scopes, giving users more control over what an app can access and helping developers build secure consent flows around the task at hand.
Cloudflare Infraestructura blog.cloudflare.com -
Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns
Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaign's infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios.
Wiz Amenazas wiz.io -
Frequently asked questions about the active threat to Siemens S7 Series PLCs
A joint cybersecurity advisory released by multiple U.S. government agencies warns that threat actors are using AI-generated exploitation scripts to target exposed Siemens S7 Series PLCs across critical infrastructure sectors.Key…
Tenable Seguridad IA tenable.com -
RAVEN: extrae información de Elasticsearch y mantiene el acceso después de la rotación de contraseñas
Una nueva herramienta de seguridad ofensiva, denominada RAVEN, muestra cómo un entorno Elasticsearch comprometido puede provocar una pérdida de datos con acceso persistente. LevelBlue afirmó en un informe que sus investigadores describen…
Segu-Info General blog.segu-info.com.ar -
BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary…
Check Point Research General research.checkpoint.com -
UAT-10147 deploys SPECTRE: A cross-platform implant with Linux rootkit and BYOVD capabilities
The newly identified SPECTRE implant represents an evolution in commodity intrusion tooling, integrating cross-platform C2 operations, process injection, credential theft, anti-analysis protections, and kernel-level endpoint detection and…
Cisco Talos Amenazas blog.talosintelligence.com -
UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS…
Cisco Talos Seguridad IA blog.talosintelligence.com -
Identity Abuse Through Trusted Communication Channels
Unit 42 details how attackers exploit enterprise collaboration tools for identity phishing and credential theft. Discover key defense strategies. The post Identity Abuse Through Trusted Communication Channels appeared first on Unit 42.
Unit 42 Vulnerabilidades unit42.paloaltonetworks.com -
Zero-click Grok data theft: Cryptographic Context Injection attack leaks chat histories
Cryptographic Context Injection ships attacker instructions as ciphertext the model decrypts in its own sandbox. It leaked full Grok chat histories, zero-click.
Adversa AI General adversa.ai - miércoles 19 ago
-
Smashing Security podcast #481: Never say this to a robot dog
At Black Hat this month, a group of security researchers took a $9,000 robot dog, plugged Google's AI into its brain, and jailbroke it by telling it - with a completely straight face - that it was a Pokemon. What followed involved a wall…
Graham Cluley Seguridad IA grahamcluley.com -
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026
Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud. The post Microsoft named a Leader in the Frost Radar™: Cloud…
Microsoft Security Blog Infraestructura microsoft.com -
Beyond Deepfakes: Zero Trust Security for the AI Economy
TL;DR: Deepfakes are not merely a detection challenge. They expose fundamental weaknesses in how organizations establish identity, grant authority, and protect data. Appearances alone can no longer serve as proof. CSA research shows how…
Cloud Security Alliance Seguridad IA cloudsecurityalliance.org -
CVE-2026-19490: Critical Vulnerability Affecting Citrix NetScaler ADC and NetScaler Gateway
OverviewOn August 19, 2026, a security advisory was published for CVE-2026-19490, a critical authentication bypass vulnerability affecting Citrix NetScaler ADC and NetScaler Gateway. The vulnerability carries a CVSS v4.0 base score of 9.3…
Rapid7 Vulnerabilidades rapid7.com -
A revisit of remote Spectre attacks on Cloudflare Workers
In 2024 and 2025, we reassessed remote Spectre attacks on our Workers infrastructure. We share details about the new attack primitives like Spectre gadgets, remote timers, achieving co-location and how new defenses further harden…
Cloudflare Infraestructura blog.cloudflare.com -
Wiz Penetration Test Findings is now GA
Transform point-in-time pen-tests into continuous exposure management with unified platform combining pen-test findings and real-time cloud context
Wiz Infraestructura wiz.io -
Cuatro vulnerabilidades críticas siendo explotadas se agregan a KEV (macOS, SharePoint, vCenter, Microsoft IKE)
La Agencia CISA añadió este martes cuatro vulnerabilidades críticas a su catálogo de Vulnerabilidades Explotadas Conocidas (KEV), indicando que están siendo explotadas activamente. Las vulnerabilidades añadidas al catálogo KEV se detallan…
Segu-Info Vulnerabilidades blog.segu-info.com.ar -
Oracle Critical Patch Update, August 2026 Security Update Review
Oracle released its August edition of Critical Patch Update. The update received patches for 943 security vulnerabilities. Some of the vulnerabilities addressed in this update impact more than one product. These patches address…
Qualys Vulnerabilidades blog.qualys.com -
NIST Releases Tips & Tactics for Building Automation & Control System Cybersecurity
Recent cyberattacks highlight the growing threat to operational technology (OT) used in critical infrastructure. Whether you work for an infrastructure owner/operator or are a consumer of an infrastructure service, the events of the past…
NIST Cybersecurity Amenazas nist.gov -
Rapid7 and Licencias OnLine Partner to Accelerate Cybersecurity Maturity across Latin America
Cássio De Alcântara is Director, LATAM Sales at Rapid7.Across Latin America, organizations are embracing cloud, AI, and digital transformation to drive innovation and business growth. These technologies create new opportunities, but also…
Rapid7 Seguridad IA rapid7.com -
Describing attacks with crime script analysis
Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.
Cisco Talos General blog.talosintelligence.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.