Radar de seguridad e inteligencia artificial
Noticias
Revisamos cada hora los feeds públicos de 60 fuentes de referencia y clasificamos cada titular por tema y severidad. Aquí verás el titular y un extracto breve: la noticia se lee en su fuente original.
en 24 horas
semana
crítica
en seguimiento
Actualización horaria Última revisión hace 9 min 961 titulares en el archivo
Qué se está publicando
Distribución por tema
- jueves 3 sep
-
Terminated employee cost company hundreds of thousands of dollars because nobody revoked access
They had more access than the average Joe, and IT didn't track what needed to be cut off
The Register · Security General theregister.com -
To keep the AI hacking genie bottled up, try one-way networks
Sandboxes, permissions, and VMs aren't enough to keep frontier models at bay. "Data diodes" might do the job
The Register · Security Seguridad IA theregister.com -
Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon
The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. "FalconFlank is a 0day…
The Hacker News Vulnerabilidades thehackernews.com -
Top AI coding agent security resources — September 2026
September 2026's AI coding agent security roundup: vendor default GitHub Actions reaching RCE, GhostJacking through WAF logs, and OWASP's new skill risk list.
Adversa AI Seguridad IA adversa.ai -
Your threat feed is someone else’s database: What ingesting malware intel at scale takes
The advice is to consume shared threat intelligence. Join the ISAC. Wire the community feeds into your pipeline. This looks like a fine advice and I agree to it. What nobody mentions you is the operating manual, because the access was…
Help Net Security Regulación helpnetsecurity.com -
CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers' crosshairs. The vulnerabilities are as follows…
The Hacker News Vulnerabilidades thehackernews.com -
III Edición del Programa de Especialización de Quantum y Post-Quantum Computing para Ciberseguridad: Últimas plazas para el 9 de Noviembre
Como ya os conté hace dos años comenzamos con la idea Pablo García Bringas y yo, de meternos en un nuevo proyecto de divulgación y formación avanzada en tecnologías Quantum, en este caso centradas en Ciberseguridad, y que configuramos un…
El lado del mal General elladodelmal.com -
When AI quietly breaks things, who pays?
David Halbreich, an insurance recovery partner at Reed Smith, breaks down how AI companies should handle coverage gaps that come up as the industry grows. He covers straddle claims that fall between tail and go-forward D&O policies after a…
Help Net Security Seguridad IA helpnetsecurity.com -
Windows memory integrity switches on automatically for eligible devices in October 2026
Beginning in October 2026, Windows quality updates start enabling memory integrity protection on eligible devices with little or no additional configuration. On machines where Virtualization-based Security is not already running, those…
Help Net Security General helpnetsecurity.com - miércoles 2 sep
-
Honeypot-Omaha and batch.py [Guest Diary], (Wed, Sep 2nd)
[This is a Guest Diary by Frank Igbokwe, an ISC intern as part of the SANS.edu BACS program]
SANS Internet Storm Center General isc.sans.edu -
ISC Stormcast For Thursday, September 3rd, 2026 https://isc.sans.edu/podcastdetail/10080, (Thu, Sep 3rd)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
SANS Internet Storm Center General isc.sans.edu -
How Developers Prevent Production Risk at the Source
Fixing security vulnerabilities in code takes seconds, while patching in production creates high operational costs and risk. Discover how empowering developers as your first line of defense eliminates exposure across every phase of your…
Wiz Vulnerabilidades wiz.io -
H1 2026 Malware Vulnerability Trends
Learn how adversaries abuse trusted tools, AI, and developer environments for cyberattacks. Get actionable insights on ransomware, mobile threats, and supply chain security.
Recorded Future Seguridad IA recordedfuture.com -
Safety overview: GPT-6 Astra
GPT-6 Astra is our most capable broadly deployed model and our first to reach the Critical level of cybersecurity capability under our Preparedness Framework.
OpenAI Regulación openai.com -
Hey LLM, instalame esta
Los archivos de documentación de más de 100 sitios web hacen referencia a contenido ejecutable potencialmente peligroso que se instala automáticamente al ser visitado por numerosos agentes de IA. Varias decenas de empresas, algunas de…
Segu-Info Seguridad IA blog.segu-info.com.ar -
Smashing Security podcast #483: This AI helps thieves steal your iPhone
You've had your iPhone stolen. A day later, you get a text from Apple saying they've found it, and a very helpful woman called Alice from Apple Support calls to walk you through recovering it. She's polite. She's professional. But she is…
Graham Cluley Seguridad IA grahamcluley.com -
Impersonating IT support: how threat actors turn a remote session into enterprise-wide access
Microsoft Threat Intelligence observed a human-operated intrusion campaign that abuses Microsoft Teams external collaboration to impersonate IT support, gain remote access, and deploy a Node.js-based implant. Learn how attackers move from…
Microsoft Security Blog Amenazas microsoft.com -
2026 Cloud Security Index: How Risk Differs Across AWS, Azure, and Google Cloud
Originally published by Intruder. Juggling multiple cloud providers is complicated enough without each one failing in different places. But that's what Intruder’s 2026 Cloud Security Index found: the issues that dominate on AWS barely…
Cloud Security Alliance Infraestructura cloudsecurityalliance.org -
Claude Mythos only model to complete full cyber kill chain, experts say
Cyber Weapon Index finds AI attacks 'imminent'
The Register · Security Seguridad IA theregister.com -
AI’s Vulnerability Surge May Be More Manageable Than First Feared
New research suggests the coming Vulnpocalypse may not be so overwhelming for enterprise security teams — if they have the right strategies.
Dark Reading Seguridad IA darkreading.com -
Hackers exploit Sangoma Switchvox flaw to deploy reverse shells
Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE
The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor's edge devices.
Dark Reading Vulnerabilidades darkreading.com -
Managing identity source transition for AWS IAM Identity Center
September 2, 2026: This post was republished to include Active Directory migration strategies and automation for permission sets. AWS IAM Identity Center manages user access to Amazon Web Services (AWS) resources, including both AWS…
AWS Security Infraestructura aws.amazon.com -
Google says its new Gemini 3.8 Flash model ‘works harder’ but might cost more
Google launched Gemini 3.8 Flash, arriving just a few weeks after its predecessor. The company claims the new model "works harder" than Gemini 3.7 Flash by performing more reasoning steps on complex tasks and "calling tools iteratively."…
The Verge · IA Seguridad IA theverge.com -
AI Gives Cybercriminals a Dangerous Time Advantage
Former cybercriminal Brett Johnson provides a look inside the mind of a threat actor and discusses where AI provides the most value for attackers.
Dark Reading Seguridad IA darkreading.com -
OpenLeash Adds a Human Check to Risky AI Agent Actions
The security tool intercepts potentially dangerous agent actions, blocking clear threats and requesting human approval when intent is uncertain. The post OpenLeash Adds a Human Check to Risky AI Agent Actions appeared first on SecurityWeek.
SecurityWeek Seguridad IA securityweek.com -
WordPress backup plugin flaw exposes millions of sites to takeover attacks
An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. [...]
BleepingComputer Vulnerabilidades bleepingcomputer.com -
Infostealer secuestra sesiones de Claude y consume créditos sin autorización
Un malware infostealer secuestra sesiones de Claude y consume créditos sin autorización. Conoce qué hizo Anthropic al respecto.
WeLiveSecurity (ESET) Seguridad IA welivesecurity.com -
Russian national facing 20 years for malware campaign that infected 80,000 freelancers
Searzhudin Tamirlanovich Aktulaev appeared in a San Francisco federal court on Monday after being arrested in Cyprus in May 2025 and extradited to the U.S. last week.
The Record Amenazas therecord.media -
Agentic security: Detection and response at machine speed
After talking with enterprise security leaders over the past year, one thing has become clear: the rise of autonomous AI agents is the most significant shift in security posture since the move to cloud. Organizations across every industry…
AWS Security Seguridad IA aws.amazon.com
Del titular al control
Leer noticias no reduce el riesgo
En el blog publicamos análisis propios que traducen esto en decisiones: qué controlar primero, con qué evidencia y en qué orden.