Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 55 min 976 titulares en el archivo
Qué se está publicando
Distribución por tema
318 titulares de severidad Media Limpiar filtros ×
- martes 1 sep
-
Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis
Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence…
The Hacker News Seguridad IA thehackernews.com -
Mirage Kitten targeting aviation and FinTech sectors across the Middle East and Africa with a new malware set
Kaspersky researchers have discovered new Mirage Kitten attacks using previously undocumented malware families: NodeRabbit in Node.js and PollCat in JavaScript.
Securelist (Kaspersky) Amenazas securelist.com - lunes 31 ago
-
Introducing wrapture
Introducing wrapture New from Graham Dumpleton (of wrapt, mod_wsgi, and New Relic's Python agent fame), who describes Wrapture as taking the monkeypatching ideas from wrapt and extending them to apply to testing and tracing at the same…
Simon Willison Vulnerabilidades simonwillison.net -
Anthropic Users Hit by Infostealer Attacks, Session Thefts
A threat actor used a variety of infostealers to collect session information and access Claude accounts belonging to an unknown number of users.
Dark Reading Seguridad IA darkreading.com -
'TerminalFix' Campaign Weaponizes PowerShell for Enterprise Attacks
The ClickFix-style campaign features a sophisticated, multistage attack chain that includes reverse tunnels into victim organizations' networks.
Dark Reading Amenazas darkreading.com -
Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines
Next-level ClickFix wave sets off multi-stage attack chain
The Register · Security Amenazas theregister.com -
AI Model Rules Are Not Security Controls
OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls.
Dark Reading Seguridad IA darkreading.com -
North Korean Job Fraud Expands Beyond IT Into Healthcare and Sales
Threat actors with ties to the Democratic People's Republic of Korea (aka DPRK or North Korea) have been observed seeking job opportunities beyond the information technology (IT) sector, with recent investigations identifying suspected…
The Hacker News Amenazas thehackernews.com -
Anthropic cracks down on hijacked user accounts mining AI tokens
Commodity malware steals authenticated sessions, letting thieves freeload on victims' paid usage
The Register · Security Seguridad IA theregister.com -
PaperCut issues emergency patches as threat actors target chained vulnerabilities
The print management software maker faced a wave of attacks in 2023 aimed at higher education customers.
Cybersecurity Dive Vulnerabilidades cybersecuritydive.com -
Introducing Adaptive Intelligence: Undermining the economics of every bot attack
Bot operators have historically had the economic advantage, bypassing static, deterministic detection rules with cheap proxies and retooling. Cloudflare's new Adaptive Intelligence engine flips this dynamic by autonomously learning from…
Cloudflare Infraestructura blog.cloudflare.com -
31th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 31st August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES Manchester Airports Group, the UK operator of Manchester, London Stansted, and East…
Check Point Research General research.checkpoint.com -
Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams
Learn how the Spring Ring campaign abuses Microsoft Teams and voice phishing to deploy malware and target enterprise domain controllers. The post Spring Ring: An Inside Look at Voice Phishing Campaigns in Microsoft Teams appeared first on…
Unit 42 Amenazas unit42.paloaltonetworks.com -
ATM Flaws Reveal Key Weaknesses in the Software Supply Chain
A security researcher discovered nine vulnerabilities impacting ATM encryption and authentication software. But the problems extend far beyond your local cash machine.
WIRED · Security Vulnerabilidades wired.com -
Más de 8.300 servidores Gitea quedan expuestos a ataques de ejecución remota por CVE-2026-60004
Miles de instancias de Gitea accesibles desde Internet seguían sin parchear a finales de agosto frente a CVE-2026-60004, un fallo crítico que permite ejecución remota de comandos. La corrección llegó con Gitea 1.27.1 y el problema ya…
Hispasec · Una al día Vulnerabilidades unaaldia.hispasec.com - domingo 30 ago
-
Boardroom Battles 2026: ASD’s Cyber Priorities & AI Risk
The Australian Signals Directorate’s 2026 board priorities and frontier AI guidance show why speed alone won’t stop AI-era cyber threats.
Huntress Seguridad IA huntress.com -
YARA-X 1.20.0 Release, (Sun, Aug 30th)
YARA-X's 1.20.0 release brings 14 improvements and 13 bugfixes.
SANS Internet Storm Center General isc.sans.edu - viernes 28 ago
-
TerminalFix campaign deploys a reverse tunnel through multistage intrusion
Microsoft Threat Intelligence provides analysis of a ClickFix campaign that uses fake CAPTCHA prompts, DLL sideloading, and a reverse tunnel, with detections and hunting guidance. The post TerminalFix campaign deploys a reverse tunnel…
Microsoft Security Blog Amenazas microsoft.com -
Hundreds of OpenAI Agents Invaded Hugging Face Servers
The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack.
Dark Reading Seguridad IA darkreading.com -
Offensive Security Investments Surge as AI Threats Increase
Omdia's Theresa Lanowitz talks with the Dark Reading News Desk about the potential — and risks — of using agentic AI for penetration testing, red teaming, and other practices.
Dark Reading Seguridad IA darkreading.com -
Microsoft Teams Has Become a Haven for Scammers in China
Fraudsters are exploiting enterprise chat apps like Teams and Webex to trick Chinese victims into transferring large sums of money, fueling a wave of complaints.
WIRED · Security Vulnerabilidades wired.com -
The Good, the Bad and the Ugly in Cybersecurity – Week 35 (2026)
Authorities disrupt global cybercrime rings, attackers abuse DocuSign in NovaCookies phishing, and Spark RAT targets Cambodia with vulnerable drivers.
SentinelOne Amenazas sentinelone.com -
Next-Gen Phishing Tactics Users Aren’t Ready For | Huntress
Move past basic credential harvesting. Discover how modern attackers use ClickFix, BitB, and OAuth consent phishing—and how to train your users with Huntress SAT.
Huntress Amenazas huntress.com -
Teach Yourself to Phish | Huntress
Get ready for a phishing trip! Learn about the strategy behind phishing simulations and how it can help your organization build resilience against real phishing threats.
Huntress Amenazas huntress.com -
A Beginner’s Guide to Phishing Simulation Training for Employees | Huntress
Learn the essentials of phishing simulation training with our beginner's guide. Protect your organization by simulating real phishing attacks.
Huntress Amenazas huntress.com -
Frontier AI tipping the scales toward cyber adversaries
Researchers at Palo Alto Networks’ Unit 42 warn that threat actors are already using AI to accelerate cyberattacks beyond the abilities of modern defenses.
Cybersecurity Dive Seguridad IA cybersecuritydive.com -
Metasploit Wrap Up: Payloads and Exploits, and Scanners, Oh my!
Rapid7 Vulnerabilidades rapid7.com -
Why a cryptographic inventory is key for addressing the quantum computing threat
When quantum computers become generally available, they’ll be able to crack current public-key cryptographic algorithms, putting digitally stored and transmitted data at risk. But the threat already exists, as attackers use the "harvest…
Tenable General tenable.com -
Fake Voicemail SVG Attachments Fuel Large-Scale Phishing Campaign
A large-scale phishing campaign used fake voicemail SVG attachments to bypass email defenses, targeting 5527 organizations with over 26,000 malicious messages
Infosecurity Magazine Amenazas infosecurity-magazine.com -
CISA identifies security hurdles that led to very different results in two red-team engagements
The agency said its recent simulated cyberattacks offered several key lessons for many organizations.
Cybersecurity Dive Amenazas cybersecuritydive.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.