Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 25 min 976 titulares en el archivo
Qué se está publicando
Distribución por tema
205 titulares en General Limpiar filtros ×
- miércoles 12 ago
-
Post-quantum migration gets harder when every user holds a key
In this Help Net Security interview, Christopher Smith, CEO of Quantus, discusses what cryptographic inventories turn up in banks and hospitals, including default passwords and admin keys still held by former employees. He explains where…
Help Net Security General helpnetsecurity.com -
338 million attack simulations reveal the state of enterprise defense
First, a bit of good news: Enterprise defenses are recovering. However, it’s a narrow recovery, with a twist. Today, organizations are better at stopping loud attacks but have barely moved the needle at all against the quiet ones. This…
Help Net Security General helpnetsecurity.com - martes 11 ago
-
Google says Chrome cuts 7 billion unwanted Android notifications a day to fight abuse
Google says Chrome's anti-abuse systems reduced unwanted notifications on Android by more than 7 billion per day during the first quarter of 2026. [...]
BleepingComputer General bleepingcomputer.com -
Signal adds an extra layer of security to make sure you're actually chatting with the right person
One big caveat, though: You need your contact's phone number
The Register · Security General theregister.com -
datasette-upload-dbs 0.5a0
Release: datasette-upload-dbs 0.5a0 This plugin has been around for a while - it lets users upload a brand new SQLite database to a hosted Datasette instance, at which point that database will start being served by that instance. It can…
Simon Willison General simonwillison.net -
NSA installs DHS lawyer as new general counsel
Kerianne Tobitsch, who most recently served as a senior lawyer at the Homeland Security Department, is the NSA's new general counsel, sources told Recorded Future News.
The Record General therecord.media -
Zoom Annotation Flaws Could Let a Meeting Participant Hijack Another Attendee's Client
Anyone sharing their screen on a Zoom call could have taken over the computers of everyone watching, and anyone watching could have taken over the presenter's. The flaw sat in the annotation tool, the feature that lets participants draw…
The Hacker News General thehackernews.com -
How Trail of Bits helps verify the integrity of your Signal chats
Every Signal chat starts the same way: the client asks the Signal server for the public key associated with your contact’s phone number. But how do you know the server gave you the right key? A compromised server could provide a false…
Trail of Bits General blog.trailofbits.com -
DEF CON dingus suspected of trying to take over Delta in-flight Wi-Fi
This is why we can't have nice things, people
The Register · Security General theregister.com -
Two wars and a World Cup lead to epic DDoS attacks on publishers
Ukraine, Iran, and football inspire geopolitically motivated DDoS attacks, while 1 Tbps traffic jams up 519 percent
The Register · Security General theregister.com -
Mozilla updates GPG signing key for Firefox releases after exposure
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. [...]
BleepingComputer General bleepingcomputer.com -
Citrix expands Platform Flex with observability and secure developer services
Citrix has announced new services for Citrix Platform Flex, extending its flexible credit model with additional options for delivering, monitoring and securing digital work environments. The new offerings include Citrix Experience Insights…
Help Net Security General helpnetsecurity.com -
Malicious SIMs can hijack smartphones, steal files, and lock them onto 2G
Researchers have found that compromised or malicious SIM cards can issue commands to some smartphones and cellular-connected devices, allowing attackers to steal information, disrupt communications, downgrade connections to 2G, and in some…
Help Net Security General helpnetsecurity.com -
A Malicious SIM Card Can Run Attacker Code Inside the Modems Behind Cellular IoT Devices
A malicious SIM card can order the device it sits in to run commands of the attacker's choosing. On the cellular modules built into electric-vehicle chargers, industrial routers, and car telematics units, that is enough to take the whole…
The Hacker News General thehackernews.com -
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was committed by mistake to one of the company's own private code repositories. That key is how a user, or a…
The Hacker News General thehackernews.com -
Mozilla revokes Firefox signing key after unencrypted copy lands in GitHub
Audit logs found no unexpected visitors, but release verification still needs an update
The Register · Security General theregister.com -
Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers
Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording. The onboarding paperwork is the…
The Hacker News General thehackernews.com -
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged installation components that researchers chained to SYSTEM access on a fully updated Windows 11 machine. The same PnP…
The Hacker News General thehackernews.com -
Malicious SIMs can shut down phones, steal files, and drag 5G back to 2G
Researchers find standards-compliant functionality can be abused to hijack modems, downgrade connections, and even execute code
The Register · Security General theregister.com -
Locking your ssh-agent exposed local-only keys until OpenSSH 10.5
Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether a request came from your own machine or arrived down a…
Help Net Security General helpnetsecurity.com -
Mozilla Issues New Firefox GPG Key Following Exposure
The previous GPG signing subkey was inadvertently added to a GitHub repository and Mozilla decided to revoke it. The post Mozilla Issues New Firefox GPG Key Following Exposure appeared first on SecurityWeek.
SecurityWeek General securityweek.com -
Cybersecurity jobs available right now: August 11, 2026
CTI Detection Engineer Department of Parliamentary Services | Australia | Hybrid – View job details As a CTI Detection Engineer, you will lead the detection lifecycle by identifying detection gaps, developing and validating detection…
Help Net Security General helpnetsecurity.com - lunes 10 ago
-
Introducing Muse Glimmer
Introducing Muse Glimmer Meta are back in the open weights game! Muse Glimmer is a brand new 30B model under a clean Apache 2.0 license (a step up from the janky Llama licenses of old). They claim to have optimized it for exactly the kind…
Simon Willison General simonwillison.net -
Multistate Water System Attacks Widen, Iran Suspected
Attacks targeting water systems just keep flowing across a dozen states, against ill-secured, Internet-exposed PLCs.
Dark Reading General darkreading.com -
Tutores de IA en la educación: ¿qué tan seguros son?
Los tutores de IA pueden ofrecer una ayuda útil, pero su calidad y sus medidas de seguridad varían mucho. Estos son algunos aspectos que conviene comprobar antes de incorporarlos al proceso de aprendizaje.
WeLiveSecurity (ESET) General welivesecurity.com -
10th August – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 10th August, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES North Carolina Ports, the US authority operating the ports of Wilmington, Morehead City…
Check Point Research General research.checkpoint.com - viernes 7 ago
-
ICS Security Conference 2026
JPCERT/CC held the ICS Security Conference 2026 on February 10, 2026. This conference aims to share the current threat landscape surrounding Industrial Control System (ICS) in Japan and abroad, as well as initiatives undertaken by…
JPCERT/CC General blogs.jpcert.or.jp - jueves 6 ago
-
CSS:the bomb inside your inbox
Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this
PortSwigger Research General portswigger.net - miércoles 5 ago
-
CRLF-Powered Desync Attacks: Beheading HTTP Streams
Abstract In this paper we’ll show that HTTP Header Injection is severely underestimated. Forget open redirects or Cross-Site Scripting and instead, embrace the catastrophic potential of the CRLF-Power
PortSwigger Research General portswigger.net - lunes 3 ago
-
Web scraping: qué es, cómo funciona y cuándo es legal
El web scraping puede ser beneficioso para las empresas, pero también es utilizado por ciberdelincuentes para recopilar y comprometer datos sensibles, lo que representa un riesgo para la seguridad de los usuarios legítimos.
WeLiveSecurity (ESET) General welivesecurity.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.