Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 13 min 968 titulares en el archivo
Qué se está publicando
Distribución por tema
445 titulares de severidad Info Limpiar filtros ×
- lunes 10 ago
-
Russian military hackers pose as recruiters to target Ukrainian IT workers
Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency.
The Record Amenazas therecord.media - sábado 8 ago
-
BIML Moderates an NSF Panel on #MLsec
McGraw was honored to host an illustrious panel of academics and security researchers (of the science flavor) discussing the future of machine learning security and privacy. Of course we didn’t stick to the script.
Berryville Institute (BIML) Seguridad IA berryvilleiml.com - jueves 6 ago
-
CSS:the bomb inside your inbox
Gareth Heyes - gareth.heyes@portswigger.net - @garethheyes It's quite common for webmail clients to render untrusted CSS in a trusted UI. They attempt to make this safe using CSS sanitization. In this
PortSwigger Research General portswigger.net -
Top MCP security resources — August 2026
August 2026 MCP security roundup: the July 28 spec revision hardens authorization, a confused deputy hijacks Azure DevOps review agents, and scanners arrive.
Adversa AI Seguridad IA adversa.ai - miércoles 5 ago
-
AI agents can't yet do open-ended AI research
Early evidence from two case studies
AI Snake Oil Seguridad IA normaltech.ai -
A few notes on AWS Nitro Enclaves: KMS integration
Nitro Enclaves and Key Management Service (KMS) feel like a natural fit: since the KMS can verify attestation documents generated by the enclaves, developers can offload key management tasks from their applications to the AWS-managed…
Trail of Bits Infraestructura blog.trailofbits.com -
Continuous Offensive Security & AI Pentesting: 20 FAQs
Get answers to 20 common questions about continuous offensive security, AI penetration testing, DAST, and AI red teaming.
Snyk Seguridad IA snyk.io - martes 4 ago
-
From Input to Impact: Secure AI Where It Runs
Defend the entire AI agentic stack across endpoints, identities, cloud, and apps with SentinelOne's unified platform.
SentinelOne Seguridad IA sentinelone.com -
Nine AI coding agent incidents that ended with deleted data
Nine documented AI coding agent incidents, from Cursor and Gemini CLI to Replit, Kiro and Claude Opus 5. What each agent did and why the guardrails failed.
Adversa AI Seguridad IA adversa.ai -
Stop The Sprawl Snyk Secrets Now Generally Available
Snyk Secrets is now generally available, bringing contextual ML detection, secure-at-commit prevention, and unified secrets governance to the Snyk AI Security Platform.
Snyk Seguridad IA snyk.io - lunes 3 ago
-
Web scraping: qué es, cómo funciona y cuándo es legal
El web scraping puede ser beneficioso para las empresas, pero también es utilizado por ciberdelincuentes para recopilar y comprometer datos sensibles, lo que representa un riesgo para la seguridad de los usuarios legítimos.
WeLiveSecurity (ESET) General welivesecurity.com -
LLM Heist: Hijacking LiteLLM for Traffic Interception, Key Theft, and Tool-Call Injection
LiteLLM is a popular AI gateway. It provides a unified interface to LLMs and simplifies governance. It also has access to the backend LLM provider keys. All of that makes it a high-value target. Not only for IP and data theft, but also for…
Embrace The Red Seguridad IA embracethered.com -
Welcoming the Nepalese Government to Have I Been Pwned
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteToday, we welcome the 47th government onboarded to Have I Been Pwned’s free gov service: Nepal…
Troy Hunt General troyhunt.com - domingo 2 ago
-
Weekly Update 515: Seeking Caffeine Utopia
Presently sponsored by: Report URI: Guarding you from rogue JavaScript! Don’t get pwned; get real-time alerts & prevent breaches #SecureYourSiteApparently, Aussies are so obsessed with coffee that it's referred to as the coffee capital of…
Troy Hunt General troyhunt.com - sábado 1 ago
-
Silver Bullet Security Podcast 159 – Melanie Mitchell
View on Zencastr On Episode 159 of the Silver Bullet Security Podcast, BIML’s Gary McGraw hosts Melanie Mitchell. Melanie talks about the surprising progress made in AI since the ’90s, whether real concepts emerge from data scale alone…
Berryville Institute (BIML) Seguridad IA berryvilleiml.com - viernes 31 jul
-
Capturas de pantalla falsas: el riesgo de confiar en una prueba digital
Las capturas de pantalla pueden ayudar a documentar pagos, reservas o conversaciones, pero cada vez son menos fiables como evidencia y más fáciles de falsificar.
WeLiveSecurity (ESET) General welivesecurity.com -
The Good, the Bad and the Ugly in Cybersecurity – Week 31 (2026)
Police flag 4,000 URLs to disrupt The Com, theft victims sue Apple over a $1.8M wallet scam, and OpenAI and Anthropic models reach real systems in cyber tests.
SentinelOne Seguridad IA sentinelone.com - jueves 30 jul
-
Read This Before You Buy That TV Streaming Stick
Security experts have been sounding the alarm for years about the risks of using generic TV boxes that promise unlimited content streaming for a one-time fee, warning that they secretly rent the user's Internet connection out to strangers…
Krebs on Security General krebsonsecurity.com -
Building secure Uniswap v4 hooks
Uniswap v4 hooks let developers add custom behavior to pools, including dynamic fees, custom accounting, and external integrations. This flexibility moves some security responsibilities into application and hook code. The Cork and Bunni…
Trail of Bits General blog.trailofbits.com - martes 21 jul
-
LG to Ban Residential Proxies from Smart TV Apps
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn one's television into an always-on residential proxy node. The move comes less than a month after researchers found…
Krebs on Security General krebsonsecurity.com - lunes 20 jul
-
The Agentic SOC: Transforming Data into Defensive Velocity
Transform SOC data chaos into autonomous intelligence with modern AI pipelines and agentic AI to empower human analysts.
SentinelOne Seguridad IA sentinelone.com - jueves 16 jul
-
From Indirect Prompt Injection to DNS Exfiltration in macOS Terminal
This is a follow-up to my previous Terminal DiLLMa research, and there is a positive outcome: Apple fixed a macOS Terminal behavior that enabled a DNS-based data exfiltration technique. DNS Requests via ANSI Escape Codes David Leadbeater…
Embrace The Red Seguridad IA embracethered.com - lunes 13 jul
-
What will be left for us to work on?
My keynote at ICML 2026
AI Snake Oil General normaltech.ai -
Lessons Learned from CISA’s Recent GitHub Leak
The Cybersecurity and Infrastructure Security Agency (CISA) has issued a postmortem on a data leak in which a contractor published dozens of internal CISA credentials -- including AWS Govcloud keys -- in a public GitHub repository for…
Krebs on Security Infraestructura krebsonsecurity.com -
Rust-proof your code with our new Testing Handbook chapter
We’ve added a new chapter to our Testing Handbook: a comprehensive guide to security testing Rust programs. This chapter covers the tools and techniques we use at Trail of Bits to validate the security of Rust programs and systems. fn…
Trail of Bits General blog.trailofbits.com - jueves 9 jul
-
Up the Stack: How AI’s Escape From the Commodity Trap Risks Enterprise Lock-in
Critics and boosters are both looking in the wrong place
AI Snake Oil Seguridad IA normaltech.ai - miércoles 8 jul
-
Mutation testing comes to DAML
In April we released Mewt, our open-source mutation-testing engine that finds the gaps in your test suite. Today we’re expanding it with support for DAML, the language Canton Network applications are written in. Mewt now reads DAML…
Trail of Bits General blog.trailofbits.com - martes 7 jul
-
The Call of the Bird
This article was shared in our internal BIML thread and prompted a reflection from my days at Shazam: Before VoiceAI and LLMs… there were birdsongs. This is a great story, success on many levels, of one of the world’s first, far-reaching…
Berryville Institute (BIML) General berryvilleiml.com - miércoles 1 jul
-
The Autonomous SOC, Revisited: What 18 Months on the Road Has Taught Us
Explore SentinelOne's Autonomous SOC maturity model to map your journey toward AI autonomy through strict governance.
SentinelOne Seguridad IA sentinelone.com - martes 30 jun
-
Verifiable Digital Credential Presentment
This blog post is #4 in our series on Verifiable Digital Credentials (VDCs). Our other posts can be found via Post #1, Post #2, and Post #3. In earlier posts, we discussed how verifiable digital credentials (VDCs) are issued and compared…
NIST Cybersecurity General nist.gov
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.