Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 31 min 976 titulares en el archivo
Qué se está publicando
Distribución por tema
205 titulares en General Limpiar filtros ×
- lunes 24 ago
-
Weekly Update 518: IoT Doorlock Nirvana with UniFi
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteI genuinely think I've nailed the IoT door lock situation! Well, Ubiquiti has, but I think I've…
Troy Hunt General troyhunt.com - domingo 23 ago
-
El propio controlador de Microsoft Defender puede utilizarse como arma para eliminar el software de seguridad al arrancar el sistema.
Check Point Research ha revelado una técnica que utiliza el controlador de remediación de arranque de Microsoft Defender, firmado legítimamente, para realizar operaciones arbitrarias de archivos y registro a nivel de kernel en sistemas…
Segu-Info General blog.segu-info.com.ar -
Welcoming the Sri Lankan Government to Have I Been Pwned
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteToday, we welcome the 48th government onboarded to Have I Been Pwned’s free gov service: Sri…
Troy Hunt General troyhunt.com - jueves 20 ago
-
Is Cyber missing the Marque?
In this week's newsletter, new author Mick Baccio introduces himself and explores the operational and security implications of the new White House memorandum regarding private sector participation in government-authorized offensive cyber…
Cisco Talos General blog.talosintelligence.com -
RAVEN: extrae información de Elasticsearch y mantiene el acceso después de la rotación de contraseñas
Una nueva herramienta de seguridad ofensiva, denominada RAVEN, muestra cómo un entorno Elasticsearch comprometido puede provocar una pérdida de datos con acceso persistente. LevelBlue afirmó en un informe que sus investigadores describen…
Segu-Info General blog.segu-info.com.ar -
BTR Reforged: Weaponizing Defender’s Remediation Driver as a Kernel Operation Primitive
Research by: Jiří Vinopal (@vinopaljiri) Abstract What if a trusted security component could be repurposed into an attacker-controlled kernel primitive? What if a signed Microsoft remediation driver could be instructed to execute arbitrary…
Check Point Research General research.checkpoint.com -
Zero-click Grok data theft: Cryptographic Context Injection attack leaks chat histories
Cryptographic Context Injection ships attacker instructions as ciphertext the model decrypts in its own sandbox. It leaked full Grok chat histories, zero-click.
Adversa AI General adversa.ai - miércoles 19 ago
-
Describing attacks with crime script analysis
Martin explores how using crime script analysis to describe an attack with everyday language makes the situation accessible to non-technical audiences and identify points where the crime can be disrupted.
Cisco Talos General blog.talosintelligence.com -
Prison for data analyst who tried to extort $2.5 million from his employer
When Cameron Curry discovered that his contract as a data analyst wasn't going to be renewed, he could have updated his LinkedIn profile. He could have started sending out his resume. But what the 27-year-old from Charlotte, North…
Graham Cluley General bitdefender.com - martes 18 ago
-
Recorded Future Launches 6 New Capabilities for Third-Party Risk
Recorded Future has launched native risk ratings capabilities inside its Third-Party Risk product, uniting threat intelligence and risk ratings in a single workflow.
Recorded Future General recordedfuture.com -
Threat Brief: Mitigating Large-Scale Credential Attacks (Updated August 18)
In August 2026, the actor TheHatman claimed to have stolen large volume of credentials from organizations' Microsoft Entra tenants. We provide guidance on mitigating large-scale credential attacks. The post Threat Brief: Mitigating…
Unit 42 General unit42.paloaltonetworks.com -
Hunting MacSync Stealer infrastructure through behavioral pivots
MacSync Stealer rapidly rotates domains to evade detection, but its behavior remains consistent. Learn how Microsoft uncovered 30+ related domains using durable hunting pivots. The post Hunting MacSync Stealer infrastructure through…
Microsoft Security Blog General microsoft.com - viernes 14 ago
-
Who’s Tracking You? Use This New Service to Find Out
It can be daunting to determine who's responsible for showing ads on the websites we visit, or who's harvesting data from the mobile apps we use every day. That information is already semi-public, but it is not easily parsed and…
Krebs on Security General krebsonsecurity.com - jueves 13 ago
-
Venture Firm Team8 Secures Additional $365 Million
The Israeli company has nearly $2 billion in total assets under management since 2014. The post Venture Firm Team8 Secures Additional $365 Million appeared first on SecurityWeek.
SecurityWeek General securityweek.com -
Searchlight Cyber combines exposure and threat intelligence in new PTEM platform
Searchlight Cyber has launched its Preemptive Threat Exposure Management (PTEM) platform, combining exposure visibility with real-world attacker intelligence to help organizations prioritize and reduce the exposures most likely to be…
Help Net Security General helpnetsecurity.com -
White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs
Contracts may require a $1 million bond, which will be forfeited if a company fails to comply with operational requirements. The post White House Mobilizes Security Firms for Operations Against Foreign Cybercrime Gangs appeared first on…
SecurityWeek General securityweek.com -
Passwords stored in public Google Doc then showed up in search results
Developer spotted hostname and credential string lurking in autocomplete
The Register · Security General theregister.com -
Four corporate investigation mistakes organizations make under pressure
In this Help Net Security video, Christine Gadsby, VP and Chief Security Advisor at BlackBerry, explains why corporate investigations go wrong before the forensic team arrives. The first hours matter more than leaders assume. Access gets…
Help Net Security General helpnetsecurity.com - miércoles 12 ago
-
Chinese Loongson processors have leaky caches, researchers find
Attackers could extract data, even working from inside a guest VM
The Register · Security General theregister.com -
DeepSeek V4 Pro 0813 (on OpenRouter)
DeepSeek V4 Pro 0813 (on OpenRouter) The latest DeepSeek Pro model is now available, via API only. I had to link to OpenRouter because DeepSeek don't have any obvious announcement page for their new model. I haven't been able to confirm if…
Simon Willison General simonwillison.net -
Spectre rears its ugly head again as researchers show some RISC-V chips are susceptible
Eight years on, we're still paying to hide the future glimpsed during speculative execution
The Register · Security General theregister.com -
Walmart's "Trusted Agent" Approach to Purple Teaming
Walmart co-locates red and blue teams to build trust and improve security through collaborative purple teaming exercises
Dark Reading General darkreading.com -
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows into installing vulnerable or insecure vendor software and gain SYSTEM privileges. [...]
BleepingComputer General bleepingcomputer.com -
Signal’s new security feature checks if your encrypted chats were tampered with
Signal has introduced a feature called automatic key verification, giving users a new way to confirm that nobody has secretly interfered with their encrypted chats. “Signal is always end-to-end encrypted, and automatic key verification…
Help Net Security General helpnetsecurity.com -
WhatsApp Unveils New Scam Alert Feature
Signal has also made a security announcement: an automatic key verification feature to complement its safety number system. The post WhatsApp Unveils New Scam Alert Feature appeared first on SecurityWeek.
SecurityWeek General securityweek.com -
Walmart Leaders Transform Security Operations Without Going Bananas
The big-box giant has scaled its defenses by encouraging trust and innovation. Good communications, transparency and team spirit are key factors.
Dark Reading General darkreading.com -
Enterprise Defenses Recovered at the Edge and Collapsed Inside
Enterprise defenses are tuned to catch the attacks that make noise. This year's data shows attackers winning by making none. According to Picus Labs' new Blue Report 2026, which measured more than 338 million real attack simulations across…
The Hacker News General thehackernews.com -
Signal adds new security feature to thwart man-in-the-middle attacks
Signal has introduced Automatic Key Verification, a new security feature that gives users a new way to ensure their encrypted chats haven't been intercepted. [...]
BleepingComputer General bleepingcomputer.com -
Crytica’s RDAi detects OT device tampering from within
Crytica Security has developed a patented solution that delivers rapid, deterministic threat detection for operational technology (OT), protecting the embedded systems and connected devices that underpin critical infrastructure, national…
Help Net Security General helpnetsecurity.com -
Weekly Update 516: Live From Vietnam
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteA little wind noise, a little connectivity flakiness, and a little lip-sync issues from…
Troy Hunt General troyhunt.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.