Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 38 min 956 titulares en el archivo
Qué se está publicando
Distribución por tema
47 titulares en Infraestructura Limpiar filtros ×
- jueves 20 ago
-
From all-or-nothing to task-based OAuth consent
Cloudflare OAuth now supports optional scopes, giving users more control over what an app can access and helping developers build secure consent flows around the task at hand.
Cloudflare Infraestructura blog.cloudflare.com - miércoles 19 ago
-
Microsoft named a Leader in the Frost Radar™: Cloud Workload Protection Platforms, 2026
Microsoft is named a visionary leader in the 2026 Frost Radar for Cloud Workload Protection Platforms, recognized for unified runtime security with Microsoft Defender for Cloud. The post Microsoft named a Leader in the Frost Radar™: Cloud…
Microsoft Security Blog Infraestructura microsoft.com -
A revisit of remote Spectre attacks on Cloudflare Workers
In 2024 and 2025, we reassessed remote Spectre attacks on our Workers infrastructure. We share details about the new attack primitives like Spectre gadgets, remote timers, achieving co-location and how new defenses further harden…
Cloudflare Infraestructura blog.cloudflare.com -
Wiz Penetration Test Findings is now GA
Transform point-in-time pen-tests into continuous exposure management with unified platform combining pen-test findings and real-time cloud context
Wiz Infraestructura wiz.io - martes 18 ago
-
Legacy Operating Models Can’t Keep Pace With IT Complexity, Cloud Security Alliance Survey Finds
Study reveals that fragmented ownership and limited visibility have made manual policy management a production risk SEATTLE – Aug. 18, 2026 — Fragmented operating models spanning teams, tools, and environments and which are still heavily…
Cloud Security Alliance Infraestructura cloudsecurityalliance.org - jueves 13 ago
-
AWS key exposed in JavaScript may have lit way to Beacon's charity data
CRM provider confirms customer database was copied and probably downloaded in readable form
The Register · Security Infraestructura theregister.com -
153GB of stolen credentials surface after LiteLLM supply chain attack
A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtained and…
Help Net Security Infraestructura helpnetsecurity.com - miércoles 12 ago
-
Hundreds of fake Chrome VPN extensions route traffic through a proxy
More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users' traffic through SOCKS5 proxies operated by a single provider. [...]
BleepingComputer Infraestructura bleepingcomputer.com -
737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One
A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The…
The Hacker News Infraestructura thehackernews.com -
Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed…
The Hacker News Infraestructura thehackernews.com - martes 11 ago
-
Wesco confirms security incident after ExfilSquad claims data theft
Global supply chain and distribution giant Wesco has confirmed in a statement for BleepingComputer that it is investigating a cybersecurity incident. [...]
BleepingComputer Infraestructura bleepingcomputer.com -
DDoS attacks over 1 Tbps surged fivefold in the second quarter
Cloudflare says it mitigated more than 800 network-layer distributed denial-of-service (DDoS) attacks exceeding 1 Tbps in the second quarter of the year. [...]
BleepingComputer Infraestructura bleepingcomputer.com -
BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platform's plugins team to temporarily disable their downloads. "Unlike…
The Hacker News Infraestructura thehackernews.com - miércoles 5 ago
-
A few notes on AWS Nitro Enclaves: KMS integration
Nitro Enclaves and Key Management Service (KMS) feel like a natural fit: since the KMS can verify attestation documents generated by the enclaves, developers can offload key management tasks from their applications to the AWS-managed…
Trail of Bits Infraestructura blog.trailofbits.com - martes 28 jul
-
Disrupting supply chain attacks on npm and GitHub Actions
Explore the changes we've shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact. The post Disrupting supply chain attacks on npm and GitHub Actions appeared first on…
GitHub Security Infraestructura github.blog - lunes 13 jul
-
Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for…
Krebs on Security Infraestructura krebsonsecurity.com - martes 9 jun
-
OWASP Dependency-Track 5.0 Is Now Generally Available
The largest redesign in the project’s history brings horizontal scaling, fault tolerance, and software supply chain integrity verification to the widely used open source platform. [Wilmington, DE], June 3, 2026. OWASP Dependency-Track, the…
OWASP Infraestructura owasp.org
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.