Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 17 min 974 titulares en el archivo
Qué se está publicando
Distribución por tema
- martes 28 jul
-
How we use /goal to find bugs in Patch the Planet
Codex’s /goal feature amplifies bug hunting, but getting good results requires the right prompt, the right scope, and the right number of outcomes per run. For Patch the Planet, our joint initiative with OpenAI to find and fix bugs in…
Trail of Bits Seguridad IA blog.trailofbits.com - miércoles 22 jul
-
TSUBAME Report Overflow (Jan-Mar 2026)
This TSUBAME Report Overflow series discusses observation trends from TSUBAME sensors both in Japan and overseas, as well as other topics not covered in the Internet Threat Monitoring Quarterly Report. This article covers monitoring…
JPCERT/CC General blogs.jpcert.or.jp -
Next chapter: Restructuring GitHub’s bug bounty program
GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team. The post Next chapter: Restructuring GitHub’s bug bounty program appeared first…
GitHub Security Vulnerabilidades github.blog -
From Triage Grind to Strategic Operator: The New AI SOC Career Path
Learn how AI is reshaping SOC careers, elevating analysts from manual triage to strategic threat hunting and AI governance.
SentinelOne Seguridad IA sentinelone.com - martes 21 jul
-
LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found…
Krebs on Security General krebsonsecurity.com -
Pwn2Own Ireland 2026 – New Targets and Categories
If you just want to read the rules, you can find them here. Pwn2Own Ireland returns for 2026, and it’s the third year for this event in the Emerald Isle. Despite the dreary Irish skies (and the threat of a random banshee), we had an…
Zero Day Initiative General thezdi.com - lunes 20 jul
-
The Agentic SOC: Transforming Data into Defensive Velocity
Transform SOC data chaos into autonomous intelligence with modern AI pipelines and agentic AI to empower human analysts.
SentinelOne Seguridad IA sentinelone.com - domingo 19 jul
-
Autonomous AI Intrusions Are Here: Lessons from the Hugging Face Compromise
Hugging Face disclosed an intrusion that, according to them, was driven end to end by an autonomous AI agent system. Along similar lines, Sysdig recently published a blog on JADEPUFFER, which it assesses to be an agent-driven ransomware…
Embrace The Red Seguridad IA embracethered.com - jueves 16 jul
-
From Indirect Prompt Injection to DNS Exfiltration in macOS Terminal
This is a follow-up to my previous Terminal DiLLMa research, and there is a positive outcome: Apple fixed a macOS Terminal behavior that enabled a DNS-based data exfiltration technique. DNS Requests via ANSI Escape Codes David Leadbeater…
Embrace The Red Seguridad IA embracethered.com - martes 14 jul
-
Microsoft Patches a Record 570 Security Flaws
Microsoft Corp. today released software updates to plug at least 570 security holes in its Windows operating systems and other software, almost triple the number of vulnerabilities the software giant fixed in its record-smashing Patch…
Krebs on Security Vulnerabilidades krebsonsecurity.com -
The July 2026 Security Update Review
Well folks. Here we are. The bug apocalypse has fully descended upon us. I’ll do my best to sort this out in some way meaningful, but this month’s release shows us the nay-sayers were right, and I’ve got to hand it to the nay-sayers here…
Zero Day Initiative Vulnerabilidades thezdi.com - lunes 13 jul
-
What will be left for us to work on?
My keynote at ICML 2026
AI Snake Oil General normaltech.ai -
Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for…
Krebs on Security Infraestructura krebsonsecurity.com -
Rust-proof your code with our new Testing Handbook chapter
We’ve added a new chapter to our Testing Handbook: a comprehensive guide to security testing Rust programs. This chapter covers the tools and techniques we use at Trail of Bits to validate the security of Rust programs and systems. fn…
Trail of Bits General blog.trailofbits.com -
Update on Attacks by Threat Group APT-C-60 in 2026
In our previous two blog posts (Dec 2024...
JPCERT/CC Amenazas blogs.jpcert.or.jp - viernes 10 jul
-
CVE-2026-47291: Remote Code Execution in the Windows HTTP.sys
In this excerpt of a TrendAI Research Services vulnerability report, Yazhi Wang and Jonathan Lein of the TrendAI Research team detail a recently patched remote code execution bug in the Windows HTTP protocol stack. Successful exploitation…
Zero Day Initiative Vulnerabilidades thezdi.com - jueves 9 jul
-
Up the Stack: How AI’s Escape From the Commodity Trap Risks Enterprise Lock-in
Critics and boosters are both looking in the wrong place
AI Snake Oil Seguridad IA normaltech.ai - miércoles 8 jul
-
HPC AI Workloads Need Runtime Security. The Architecture Already Exists.
Learn how to secure HPC AI infrastructure against runtime and supply chain threats via continuous behavioral monitoring.
SentinelOne Seguridad IA sentinelone.com -
Felons, Fraudsters Flog Offensive Cybersecurity Startup
A cybersecurity startup dangling millions of dollars to acquire zero-day security vulnerabilities in popular software is run by a pair of far-right conspiracy theorists and convicted felons whose most recent ventures included fake…
Krebs on Security Vulnerabilidades krebsonsecurity.com -
Mutation testing comes to DAML
In April we released Mewt, our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt now reads DAML…
Trail of Bits General blog.trailofbits.com - martes 7 jul
-
The Call of the Bird
This article was shared in our internal BIML thread and prompted a reflection from my days at Shazam: Before VoiceAI and LLMs… there were birdsongs. This is a great story, success on many levels, of one of the world’s first, far-reaching…
Berryville Institute (BIML) General berryvilleiml.com - lunes 6 jul
-
OWASP CVE Lite CLI Graduates to Lab Project Status
CVE Lite CLI, a fast open source dependency vulnerability scanner for JavaScript and TypeScript projects, has graduated to OWASP Lab Project status three months after its initial release. OWASP CVE Lite CLI graduated to Lab Project status…
OWASP Vulnerabilidades owasp.org - miércoles 1 jul
-
Silver Bullet Security Podcast 158 – Artem Dinaburg
View on Zencastr On Episode 158 of the Silver Bullet Security Podcast, BIML’s Gary McGraw hosts Artem Dinaburg. Artem talks about using Agentic AI to find, fix, and exploit software security defects. We talk decompilation, stochasticism…
Berryville Institute (BIML) Seguridad IA berryvilleiml.com -
The June 2026 Apple Security Update Review
We’re back with our look at the Apple macOS and iOS security updates. As this is a new feature for us, please let us know your feedback on the blog. For June 2026, Apple released 37 unique CVEs across iOS 26.5.2 / iPadOS 26.5.2, macOS…
Zero Day Initiative Vulnerabilidades thezdi.com -
The Autonomous SOC, Revisited: What 18 Months on the Road Has Taught Us
Explore SentinelOne's Autonomous SOC maturity model to map your journey toward AI autonomy through strict governance.
SentinelOne Seguridad IA sentinelone.com - martes 30 jun
-
Verifiable Digital Credential Presentment
This blog post is #4 in our series on Verifiable Digital Credentials (VDCs). Our other posts can be found via Post #1, Post #2, and Post #3. In earlier posts, we discussed how verifiable digital credentials (VDCs) are issued and compared…
NIST Cybersecurity General nist.gov - lunes 29 jun
-
Inside the Advisory Database and what happens when vulnerability volume breaks records
The GitHub Advisory Database is processing more vulnerability reports than ever before. Here's what's driving the surge, how we're responding, and how the community can help. The post Inside the Advisory Database and what happens when…
GitHub Security Vulnerabilidades github.blog - jueves 25 jun
-
Computer-Use and TOCTOU: What You Click Is Not What You Get!
Last year, Jun Kokatsu disclosed an interesting vulnerability with ChatGPT Operator by exploiting a race condition. I was wondering if I could reproduce this attack chain, and this post describes the results of that research. I had this…
Embrace The Red Seguridad IA embracethered.com - miércoles 24 jun
-
Advancing Product Security: New IoT Guidance and New Engagement
It may be summertime, but the NIST Cybersecurity for the Internet of Things (IoT) Program isn’t hitting the hammock! Organizations are managing growing device complexity, evolving threats, and pressure to turn guidance into operational…
NIST Cybersecurity General nist.gov - martes 23 jun
-
Fake shops target shoppers across Europe with fake Samsung deals, counterfeit goods and World Cup scams
A Bitdefender Labs investigation identified more than 55 fake-shop campaigns targeting consumers across 12 European countries between March and May 2026. The campaigns mimicked some of the world’s most recognizable brands, including…
Bitdefender Labs Amenazas bitdefender.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.