<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[Brodersen | Dark News]]></title><description><![CDATA[El mundo de la ciberseguridad, la privacidad y el hacking, resumido todos los viernes. Leído por trabajadores IT, hackers y entusiastas tech.]]></description><link>https://www.brodersendarknews.com</link><image><url>https://substackcdn.com/image/fetch/$s_!IYLi!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc9e5d6eb-31e4-405b-aa05-c3406c99d672_512x512.png</url><title>Brodersen | Dark News</title><link>https://www.brodersendarknews.com</link></image><generator>Substack</generator><lastBuildDate>Mon, 15 Jun 2026 10:03:31 GMT</lastBuildDate><atom:link href="https://www.brodersendarknews.com/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[Juan Brodersen]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[juanbrodersen@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[juanbrodersen@substack.com]]></itunes:email><itunes:name><![CDATA[Juan Brodersen]]></itunes:name></itunes:owner><itunes:author><![CDATA[Juan Brodersen]]></itunes:author><googleplay:owner><![CDATA[juanbrodersen@substack.com]]></googleplay:owner><googleplay:email><![CDATA[juanbrodersen@substack.com]]></googleplay:email><googleplay:author><![CDATA[Juan Brodersen]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Hackean cuentas de Instagram: Meta explica cómo robaron más de 20 mil perfiles]]></title><description><![CDATA[Adem&#225;s: ShinyHunters hackea PeopleSoft de Oracle, WhatsApp bloquea una campa&#241;a de spyware, Apple va a cambiar passwords por su cuenta y Google puede ser responsable de respuestas falsas en Overviews.]]></description><link>https://www.brodersendarknews.com/p/hackean-instagram-meta-chatbot-soporte</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/hackean-instagram-meta-chatbot-soporte</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Fri, 12 Jun 2026 11:02:52 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!wUMV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7cbea3-c974-48cb-9bd1-712e6f4298d9_1806x1126.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><p><strong>&#127748;</strong><em><strong> Dark News entra en un receso por vacaciones y vuelve el 10 de julio</strong></em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>5~12<br>jun</h1><h2><strong>&#9889;TL;DR</strong></h2><p>Malware, robo de cuentas y una nueva v&#237;ctima de <strong>ShinyHunters</strong> que impacta en un supply chain de al menos 100 organizaciones. No tenemos (casi) temas relacionados con IA en la selecci&#243;n de temas. Hace mucho no pasaba, as&#237; que volvemos un poco a las ra&#237;ces.</p><p>Durante <a href="https://www.brodersendarknews.com/i/200151802/roban-cuentas-de-instagram-a-traves-del-bot-de-soporte">la semana pasada</a>, un <strong>hackeo de cuentas de Instagram</strong> (muchas de alto perfil) llam&#243; la atenci&#243;n porque se hab&#237;a logrado hacer sin intervenci&#243;n del usuario, abusando el chatbot de soporte. Ahora, <strong>Meta cont&#243; qu&#233; pas&#243;</strong>. </p><p>El hackeo atribuido a ShinyHunters (cuyo DLS tiene un captcha horrible que hace que entrar sea muy dif&#237;cil) fue a un producto de <strong>Oracle</strong> muy usado. Y <strong>Microsoft</strong> tuvo que retirar paquetes infectados con malware para robar credenciales.</p><p>En el mundo de las regulaciones, un tribunal regional alem&#225;n decret&#243; que <strong><a href="https://the-decoder.com/landmark-german-ruling-declares-googles-ai-overviews-are-googles-own-words-and-makes-it-liable-for-false-answers/">Google puede ser responsable</a></strong> de producir respuestas falsas en los res&#250;menes de IA que salen arriba de los resultados (Overviews). Puede ser un precedente fuerte. Y <strong>Meta elimin&#243; de su app Meta AI</strong> <a href="https://arstechnica.com/tech-policy/2026/06/one-day-after-discovery-meta-pulls-facial-recognition-code-from-its-smart-glasses/">el c&#243;digo de un sistema de reconocimiento facial</a> para sus anteojos inteligentes, un d&#237;a despu&#233;s de que <a href="https://www.wired.com/story/meta-removes-face-recognition-code-meta-ai-app-smart-glasses/">WIRED</a> revelara que ya estaba integrado en una app instalada en m&#225;s de <strong>50 millones de tel&#233;fonos.</strong></p><p>Si dej&#233; de lado darle desarrollo a los temas <em>IA-related</em> es en parte por el marketing que est&#225; rondando a los anuncios del tipo &#8220;Anthropic lanz&#243; <strong>Fable 5</strong>, la versi&#243;n p&#250;blica de Mythos, y ya hay preocupaciones por la seguridad&#8221;. Hay una narrativa de &#8220;es tan poderoso que asusta&#8221; que est&#225; empezando a cansar. </p><p>Me gust&#243; este <em>take</em> de <a href="https://www.themediastack.co.uk/p/anthropics-fable-5-the-most-capable">este newsletter</a>: &#8220;Fable 5 se presenta como un modelo capaz de ejecutar trabajo intelectual durante varios d&#237;as, no s&#243;lo de hacerlo m&#225;s r&#225;pido. Para agencias y medios construidos sobre horas facturables, la pregunta inc&#243;moda ya no es qu&#233; puede hacer el modelo, sino <strong>qu&#233; le hace al modelo de negocio</strong>&#8221;.</p><p>Me gust&#243; mucho esta nota que me comparti&#243; un amigo de <strong>Axios</strong>, las <em><a href="https://www.axios.com/2026/06/09/ceo-ai-lessons-year-experiment">Confesiones de una rata de laboratorio IA</a>.</em></p><p>La perlita de la semana fue un usuario que <a href="https://x.com/the2ndfloorguy/status/2064704204166635930?s=20">reverse&#243; una pulsera de seguimiento biom&#233;trico</a> para ver qu&#233; compa&#241;ero le generaba m&#225;s stress, midiendo las pulsaciones por minuto. </p><p>No es mala idea tener <strong>antipat&#237;as laborales</strong> justificadas con datos.</p><div><hr></div><h3><strong>&#128197; Importante: agenda del newsletter</strong></h3><p>Dark News entra en un receso de <strong>tres semanas</strong>. Hacia fin de mes viajo a DC para el <strong>AWS Summit</strong>, una conferencia de sector p&#250;blico a la que voy desde hace algunos a&#241;os y de la cual siempre me llevo alguna nota o fuente (<a href="https://www.clarin.com/tecnologia/revolucion-inteligencia-artificial-ocurrio-ahora-construir-dave-levy-aws_0_yIYCr3dPCy.html">ver</a>).</p><p>El newsletter vuelve a su programaci&#243;n habitual el viernes 10 de julio. Para cerrar un poco el gap, es probable que, si llego, publique <strong>una entrega fuera de agenda el domingo 5 de julio</strong>.</p><p>Viene siendo un a&#241;o intenso y necesito unas vacaciones para cargar energ&#237;as para la segunda parte, que va a ser como siempre con el viaje a <strong>DEF CON / Black Hat</strong>, la cobertura de <strong>Ekoparty</strong> y m&#225;s.</p><p>Hasta entonces, gracias por leer. Si te dan ganas de ver algo fuera de agenda y sos de los &#250;ltimos suscriptores que se sumaron, ac&#225; est&#225; <strong><a href="https://www.brodersendarknews.com/t/entrevistas">la secci&#243;n Entrevistas</a></strong> del newsletter. Te puede interesar.</p><div><hr></div><p><em>En esta edici&#243;n:</em></p><ul><li><p>&#128275; <em><a href="https://www.brodersendarknews.com/i/201095193/meta-confirma-como-robaron-mas-de-20-mil-cuentas-de-instagram">Meta confirma c&#243;mo robaron m&#225;s de 20 mil cuentas de Instagram</a></em></p></li><li><p>&#127970; <em><a href="https://www.brodersendarknews.com/i/201095193/shinyhunters-hackea-peoplesoft-de-oracle-y-afecta-a-100-organizaciones">ShinyHunters hackea PeopleSoft de Oracle y afecta a 100 organizaciones</a></em></p></li><li><p>&#128373;&#65039;<em> <a href="https://www.brodersendarknews.com/i/201095193/whatsapp-bloquea-una-nueva-campana-de-spyware">WhatsApp bloquea una nueva campa&#241;a de spyware</a></em></p></li><li><p>&#128273;<em> <a href="https://www.brodersendarknews.com/i/201095193/apple-va-a-cambiar-contrasenas-comprometidas-sin-intervencion-del-usuario">Apple va a cambiar contrase&#241;as comprometidas sin intervenci&#243;n del usuario</a></em></p></li><li><p>&#9878;&#65039; <em><a href="https://www.brodersendarknews.com/i/201095193/google-puede-ser-responsable-directo-por-respuestas-falsas-de-ai-overviews">Google puede ser &#8220;responsable directo&#8221; por respuestas falsas de AI Overviews</a></em></p></li><li><p>&#128230; <em><a href="https://www.brodersendarknews.com/i/201095193/otra-vez-paquetes-de-microsoft-infectados-con-malware-para-robar-credenciales">Otra vez: paquetes de Microsoft, infectados con malware para robar credenciales</a></em></p></li></ul><div><hr></div><p>&#9200; <em>Substack dice que leer este correo completo lleva 13 minutos</em></p><p><em>Dark News #208</em></p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.kulkan.com/?utm_source=newsletter&amp;utm_medium=dark_news&amp;utm_campaign=quote#quote" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qXPk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 424w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 848w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 1272w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qXPk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png" width="600" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/379ea089-6930-4e5c-a652-27cb153177d8_600x300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:136661,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.kulkan.com/?utm_source=newsletter&amp;utm_medium=dark_news&amp;utm_campaign=quote#quote&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/193094978?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!qXPk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 424w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 848w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 1272w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></div><h3><strong>Meta confirma c&#243;mo robaron m&#225;s de 20 mil cuentas de Instagram</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!wUMV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7cbea3-c974-48cb-9bd1-712e6f4298d9_1806x1126.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!wUMV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7cbea3-c974-48cb-9bd1-712e6f4298d9_1806x1126.png 424w, https://substackcdn.com/image/fetch/$s_!wUMV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7cbea3-c974-48cb-9bd1-712e6f4298d9_1806x1126.png 848w, https://substackcdn.com/image/fetch/$s_!wUMV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7cbea3-c974-48cb-9bd1-712e6f4298d9_1806x1126.png 1272w, https://substackcdn.com/image/fetch/$s_!wUMV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7cbea3-c974-48cb-9bd1-712e6f4298d9_1806x1126.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!wUMV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7cbea3-c974-48cb-9bd1-712e6f4298d9_1806x1126.png" width="1456" height="908" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4e7cbea3-c974-48cb-9bd1-712e6f4298d9_1806x1126.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:908,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2247955,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/201095193?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7cbea3-c974-48cb-9bd1-712e6f4298d9_1806x1126.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!wUMV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7cbea3-c974-48cb-9bd1-712e6f4298d9_1806x1126.png 424w, https://substackcdn.com/image/fetch/$s_!wUMV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7cbea3-c974-48cb-9bd1-712e6f4298d9_1806x1126.png 848w, https://substackcdn.com/image/fetch/$s_!wUMV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7cbea3-c974-48cb-9bd1-712e6f4298d9_1806x1126.png 1272w, https://substackcdn.com/image/fetch/$s_!wUMV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e7cbea3-c974-48cb-9bd1-712e6f4298d9_1806x1126.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Reuters</figcaption></figure></div><p>Meta revel&#243; que <a href="https://www.bleepingcomputer.com/news/security/meta-ai-support-data-breach-affects-20-000-instagram-accounts/">20.225 cuentas de Instagram fueron robadas</a> en un incidente que <strong>explot&#243; una falla</strong> en su sistema de soporte asistido por IA (un chatbot, b&#225;sicamente) para recuperaci&#243;n de cuentas.</p><p><strong>Qu&#233; pas&#243;.</strong> High Touch Support, una herramienta de Meta para ayudar a usuarios que perdieron acceso a sus cuentas, permit&#237;a pedir un link de reseteo de contrase&#241;a, pero <strong>no verificaba correctamente</strong> si el email ingresado pertenec&#237;a a la cuenta apuntada.</p><p><strong>C&#243;mo funcionaba.</strong> Los atacantes pod&#237;an cargar una direcci&#243;n de correo propia y <strong>recibir el enlace</strong> para cambiar la contrase&#241;a de una cuenta ajena. Despu&#233;s del reseteo, lograban entrar si la v&#237;ctima no ten&#237;a activada la autenticaci&#243;n en dos pasos.</p><p><strong>El alcance.</strong> Meta dijo que identific&#243; <strong>20.225</strong> <strong>usuarios</strong> afectados. En una presentaci&#243;n ante la fiscal&#237;a de Maine (EE.UU.), la empresa inform&#243; que 30 usuarios de esa jurisdicci&#243;n fueron potencialmente comprometidos. El breach habr&#237;a ocurrido el 17 de abril y Meta detect&#243; la vulnerabilidad el 31 de mayo.</p><p><strong>Qu&#233; datos pudieron quedar expuestos.</strong> Meta dijo que no sabe con precisi&#243;n qu&#233; informaci&#243;n fue vista o robada. Pero advirti&#243; que los atacantes podr&#237;an haber accedido a emails, tel&#233;fonos, fechas de nacimiento, publicaciones, fotos, videos, historias, mensajes directos, actividad de la cuenta, datos del perfil y servicios vinculados.</p><p><strong>Qu&#233; hizo Meta.</strong> La empresa deshabilit&#243; el sistema HTS y todos los enlaces de reseteo generados. Tambi&#233;n oblig&#243; a las cuentas afectadas a pasar por un control de seguridad, cambiar la contrase&#241;a y volver a autenticarse.</p><p><strong>Qu&#233; sigue.</strong> Meta dijo que <strong>corregir&#225;</strong> el chequeo de autenticaci&#243;n antes de volver a lanzar la herramienta y que revisar&#225; procesos similares de recuperaci&#243;n de cuentas en sus otras plataformas.</p><h3>ShinyHunters hackea PeopleSoft de Oracle y afecta a 100 organizaciones</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!B9U8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780d78ac-8704-4e75-a7a5-37276aa36f44_1674x1099.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!B9U8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780d78ac-8704-4e75-a7a5-37276aa36f44_1674x1099.png 424w, https://substackcdn.com/image/fetch/$s_!B9U8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780d78ac-8704-4e75-a7a5-37276aa36f44_1674x1099.png 848w, https://substackcdn.com/image/fetch/$s_!B9U8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780d78ac-8704-4e75-a7a5-37276aa36f44_1674x1099.png 1272w, https://substackcdn.com/image/fetch/$s_!B9U8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780d78ac-8704-4e75-a7a5-37276aa36f44_1674x1099.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!B9U8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780d78ac-8704-4e75-a7a5-37276aa36f44_1674x1099.png" width="1456" height="956" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/780d78ac-8704-4e75-a7a5-37276aa36f44_1674x1099.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:956,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2531773,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/201095193?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780d78ac-8704-4e75-a7a5-37276aa36f44_1674x1099.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!B9U8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780d78ac-8704-4e75-a7a5-37276aa36f44_1674x1099.png 424w, https://substackcdn.com/image/fetch/$s_!B9U8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780d78ac-8704-4e75-a7a5-37276aa36f44_1674x1099.png 848w, https://substackcdn.com/image/fetch/$s_!B9U8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780d78ac-8704-4e75-a7a5-37276aa36f44_1674x1099.png 1272w, https://substackcdn.com/image/fetch/$s_!B9U8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F780d78ac-8704-4e75-a7a5-37276aa36f44_1674x1099.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Reuters</figcaption></figure></div><p>ShinyHunters asegura haber robado datos de m&#225;s de 100 organizaciones tras atacar servidores <strong>Oracle PeopleSoft</strong>, una suite de aplicaciones para gestionar funciones cr&#237;ticas que usan grandes empresas, universidades y organismos.</p><p><strong>Qu&#233; pas&#243;.</strong> <a href="https://www.bleepingcomputer.com/news/security/oracle-peoplesoft-servers-hacked-in-shinyhunters-data-theft-attacks/">Seg&#250;n BleepingComputer</a>, clientes de Oracle PeopleSoft empezaron a recibir demandas de extorsi&#243;n firmadas por ShinyHunters. El grupo dijo haber comprometido unas 300 instancias en m&#225;s de 100 organizaciones, con mayor&#237;a de v&#237;ctimas en el sector educativo.</p><p><strong>C&#243;mo entraron.</strong> Los atacantes afirman haber usado una <strong>cadena de vulnerabilidades</strong> viejas y zero days. El &#233;xito del ataque, seg&#250;n el propio grupo, depender&#237;a de la configuraci&#243;n de cada instancia. Oracle no hab&#237;a respondido ni publicado informaci&#243;n al momento del reporte.</p><p><strong>El contexto.</strong> PeopleSoft suele manejar datos sensibles de empleados, estudiantes, proveedores y operaciones internas. Eso lo vuelve un blanco atractivo para extorsi&#243;n: no hace falta cifrar sistemas si el atacante logra robar informaci&#243;n suficiente para presionar a la v&#237;ctima.</p><p><strong>Qu&#233; se sabe.</strong> La Universidad de Nottingham fue se&#241;alada como v&#237;ctima y reconoci&#243; un incidente de ciberseguridad. Un investigador tambi&#233;n encontr&#243; directorios expuestos con herramientas asociadas a la campa&#241;a, incluidos agentes MeshCentral, scripts de credential spraying y archivos para dejar notas de rescate en servidores PeopleSoft comprometidos.</p><p>Todav&#237;a no se conoce del todo el alcance del ataque.</p><h3>WhatsApp bloquea una nueva campa&#241;a de spyware</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2Wpe!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34016b37-58d4-483f-a3b7-28c704d57d22_1608x1087.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2Wpe!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34016b37-58d4-483f-a3b7-28c704d57d22_1608x1087.png 424w, https://substackcdn.com/image/fetch/$s_!2Wpe!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34016b37-58d4-483f-a3b7-28c704d57d22_1608x1087.png 848w, https://substackcdn.com/image/fetch/$s_!2Wpe!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34016b37-58d4-483f-a3b7-28c704d57d22_1608x1087.png 1272w, https://substackcdn.com/image/fetch/$s_!2Wpe!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34016b37-58d4-483f-a3b7-28c704d57d22_1608x1087.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2Wpe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34016b37-58d4-483f-a3b7-28c704d57d22_1608x1087.png" width="1456" height="984" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/34016b37-58d4-483f-a3b7-28c704d57d22_1608x1087.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:984,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1501264,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/201095193?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34016b37-58d4-483f-a3b7-28c704d57d22_1608x1087.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2Wpe!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34016b37-58d4-483f-a3b7-28c704d57d22_1608x1087.png 424w, https://substackcdn.com/image/fetch/$s_!2Wpe!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34016b37-58d4-483f-a3b7-28c704d57d22_1608x1087.png 848w, https://substackcdn.com/image/fetch/$s_!2Wpe!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34016b37-58d4-483f-a3b7-28c704d57d22_1608x1087.png 1272w, https://substackcdn.com/image/fetch/$s_!2Wpe!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F34016b37-58d4-483f-a3b7-28c704d57d22_1608x1087.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: EFE</figcaption></figure></div><p>WhatsApp dijo que <a href="https://hackread.com/whatsapp-blocked-pegasus-spyware-campaign-nso/">bloque&#243; una nueva campa&#241;a</a> de spyware vinculada a <strong>NSO Group</strong>, la empresa israel&#237; detr&#225;s de <strong>Pegasus</strong>, y le pidi&#243; a una corte federal de Estados Unidos que declare a la compa&#241;&#237;a en desacato por violar una orden judicial permanente.</p><p><strong>Qu&#233; pas&#243;</strong>. La presentaci&#243;n llega despu&#233;s de una victoria legal clave de WhatsApp y Meta contra NSO. La corte ya hab&#237;a prohibido a NSO volver a apuntar contra WhatsApp o sus usuarios, tras determinar que la empresa viol&#243; leyes federales y estatales contra el hacking en un ataque de 2019 que afect&#243; a unas 1.400 cuentas.</p><p><strong>El nuevo caso.</strong> <a href="https://about.fb.com/news/2026/06/fighting-spyware-an-update-from-whatsapp/">WhatsApp dijo que</a> esta vez la actividad no explot&#243; una vulnerabilidad desconocida de la app. Seg&#250;n la compa&#241;&#237;a, la campa&#241;a us&#243; <em>spear phishing</em>: intentos dirigidos para llevar a usuarios a sitios maliciosos externos, mediante links enviados por WhatsApp u otros canales. </p><p>Es una t&#233;cnica similar a campa&#241;as <em>One Click</em> asociadas antes con NSO.</p><p><strong>Por qu&#233; importa.</strong> La disputa ahora gira en torno a si un proveedor de spyware puede seguir probando vectores contra un servicio que una corte ya le orden&#243; no tocar. WhatsApp quiere que el juez trate la nueva actividad como una violaci&#243;n de la medida judicial, no como un incidente separado que debe discutirse desde cero.</p><p><strong>El contexto.</strong> NSO est&#225; bajo restricciones comerciales de Estados Unidos desde 2021, cuando el Departamento de Comercio la agreg&#243; a la Entity List por vender spyware a gobiernos extranjeros. Seg&#250;n autoridades estadounidenses, esas herramientas fueron usadas para <strong>apuntar contra periodistas</strong>, funcionarios, activistas, acad&#233;micos, empresarios y trabajadores de embajadas.</p><h3>Apple va a cambiar contrase&#241;as comprometidas sin intervenci&#243;n del usuario</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oWEG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9eb9c7-4b4e-49e6-8285-0f471b4f04a8_1553x879.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oWEG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9eb9c7-4b4e-49e6-8285-0f471b4f04a8_1553x879.png 424w, https://substackcdn.com/image/fetch/$s_!oWEG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9eb9c7-4b4e-49e6-8285-0f471b4f04a8_1553x879.png 848w, https://substackcdn.com/image/fetch/$s_!oWEG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9eb9c7-4b4e-49e6-8285-0f471b4f04a8_1553x879.png 1272w, https://substackcdn.com/image/fetch/$s_!oWEG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9eb9c7-4b4e-49e6-8285-0f471b4f04a8_1553x879.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oWEG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9eb9c7-4b4e-49e6-8285-0f471b4f04a8_1553x879.png" width="1456" height="824" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9e9eb9c7-4b4e-49e6-8285-0f471b4f04a8_1553x879.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:824,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:232965,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/201095193?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9eb9c7-4b4e-49e6-8285-0f471b4f04a8_1553x879.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oWEG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9eb9c7-4b4e-49e6-8285-0f471b4f04a8_1553x879.png 424w, https://substackcdn.com/image/fetch/$s_!oWEG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9eb9c7-4b4e-49e6-8285-0f471b4f04a8_1553x879.png 848w, https://substackcdn.com/image/fetch/$s_!oWEG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9eb9c7-4b4e-49e6-8285-0f471b4f04a8_1553x879.png 1272w, https://substackcdn.com/image/fetch/$s_!oWEG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9e9eb9c7-4b4e-49e6-8285-0f471b4f04a8_1553x879.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Apple</figcaption></figure></div><p>Qu&#233; pas&#243;. <strong>Apple</strong> anunci&#243; en WWDC una nueva funci&#243;n para la app Passwords de iOS 27: <strong><a href="https://9to5mac.com/2026/06/11/security-bite-apples-most-impressive-agentic-ai-feature-yet-is-hiding-in-the-passwords-app/">podr&#225; cambiar contrase&#241;as</a></strong> autom&#225;ticamente cuando detecte que fueron filtradas, reutilizadas o consideradas inseguras.</p><p><strong>Por qu&#233; importa.</strong> Hasta ahora, la app <strong>avisaba el problema</strong>, pero el usuario ten&#237;a que entrar a cada servicio y resolverlo a mano. Con esta funci&#243;n, Apple intenta convertir esa alerta en una acci&#243;n autom&#225;tica: detectar el login comprometido, generar una clave fuerte y actualizarla con m&#237;nima intervenci&#243;n.</p><p><strong>El contexto.</strong> La funci&#243;n encaja en la <strong>nueva ola de IA &#8220;ag&#233;ntica&#8221;</strong>: sistemas que ya no solo recomiendan, sino que ejecutan tareas en nombre del usuario. En seguridad, eso puede reducir fricci&#243;n y mejorar h&#225;bitos b&#225;sicos, aunque tambi&#233;n abre una pregunta obvia: qu&#233; pasa cuando delegamos a un agente el control operativo de nuestras credenciales.</p><p>Varios analistas se expresaron <strong>en contra</strong> de la medida.</p><p><strong>Qu&#233; se sabe.</strong> La funci&#243;n llegar&#225; con <strong>iOS 27</strong>, cuya beta para desarrolladores sale ahora, beta p&#250;blica el mes que viene y lanzamiento general previsto para septiembre.</p><h3>Google puede ser &#8220;responsable directo&#8221; por respuestas falsas de AI Overviews</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WXGZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dc81d2-48cf-4572-8fd5-622e30452dcb_1572x948.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WXGZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dc81d2-48cf-4572-8fd5-622e30452dcb_1572x948.png 424w, https://substackcdn.com/image/fetch/$s_!WXGZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dc81d2-48cf-4572-8fd5-622e30452dcb_1572x948.png 848w, https://substackcdn.com/image/fetch/$s_!WXGZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dc81d2-48cf-4572-8fd5-622e30452dcb_1572x948.png 1272w, https://substackcdn.com/image/fetch/$s_!WXGZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dc81d2-48cf-4572-8fd5-622e30452dcb_1572x948.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WXGZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dc81d2-48cf-4572-8fd5-622e30452dcb_1572x948.png" width="1456" height="878" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/37dc81d2-48cf-4572-8fd5-622e30452dcb_1572x948.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:878,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:418651,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/201095193?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dc81d2-48cf-4572-8fd5-622e30452dcb_1572x948.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WXGZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dc81d2-48cf-4572-8fd5-622e30452dcb_1572x948.png 424w, https://substackcdn.com/image/fetch/$s_!WXGZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dc81d2-48cf-4572-8fd5-622e30452dcb_1572x948.png 848w, https://substackcdn.com/image/fetch/$s_!WXGZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dc81d2-48cf-4572-8fd5-622e30452dcb_1572x948.png 1272w, https://substackcdn.com/image/fetch/$s_!WXGZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F37dc81d2-48cf-4572-8fd5-622e30452dcb_1572x948.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Reuters</figcaption></figure></div><p>Un tribunal regional de M&#250;nich resolvi&#243; que <strong><a href="https://the-decoder.com/landmark-german-ruling-declares-googles-ai-overviews-are-googles-own-words-and-makes-it-liable-for-false-answers/">Google puede ser responsable directo</a></strong> por respuestas falsas generadas por sus AI Overviews (los res&#250;menes de IA que aparecen arriba de los resultados).</p><p><strong>Qu&#233; pas&#243;.</strong> La Justicia alemana dict&#243; una medida cautelar contra Google por <strong>vincular err&#243;neamente a dos editoriales de M&#250;nich con estafas</strong>, trampas de suscripci&#243;n y pr&#225;cticas comerciales dudosas. Seg&#250;n el fallo, esos se&#241;alamientos no aparec&#237;an en las fuentes citadas por el buscador.</p><p><strong>La clave.</strong> El tribunal consider&#243; que los <strong>AI Overviews</strong> <strong>son contenido propio de Google</strong>. La raz&#243;n es que el sistema no se limita a listar resultados, sino que reescribe, combina y ordena informaci&#243;n en una respuesta nueva, con afirmaciones entendibles por s&#237; solas.</p><p><strong>La defensa.</strong> Google sostuvo que los usuarios pod&#237;an revisar los enlaces y verificar la informaci&#243;n. El tribunal rechaz&#243; ese argumento: la posibilidad de chequear despu&#233;s una afirmaci&#243;n falsa <strong>no elimina la responsabilidad</strong> por haberla publicado.</p><p><strong>Qu&#233; dice Google.</strong> La empresa dijo que sus res&#250;menes est&#225;n dise&#241;ados para reflejar informaci&#243;n existente en la web y <strong>que &#8220;la enorme mayor&#237;a&#8221; de las respuestas son correctas</strong>. Tambi&#233;n se&#241;al&#243; que revisa el fallo, que todav&#237;a no est&#225; firme.</p><p><strong>Por qu&#233; importa.</strong> La decisi&#243;n marca una l&#237;nea jur&#237;dica relevante para la b&#250;squeda con IA. Si una respuesta generada atribuye hechos falsos a una empresa o a un usuario, <strong>el responsable podr&#237;a ser el proveedor del sistema</strong>, aunque la informaci&#243;n haya sido producida autom&#225;ticamente.</p><p><strong>El contexto.</strong> El fallo tambi&#233;n apunta al problema de escala. Un an&#225;lisis citado por la nota se&#241;ala que los AI Overviews de Google responden bien el 91% de las veces.</p><p>En un producto usado por millones de usuarios, ese margen de error puede traducirse en <strong>una gran cantidad de respuestas falsas.</strong> El criterio alem&#225;n, si se consolida, podr&#237;a impactar tambi&#233;n sobre otros servicios que generan respuestas a partir de contenido web, como <strong>ChatGPT</strong>, <strong>Claude</strong> o <strong>Perplexity</strong>.</p><h3>Otra vez: paquetes de Microsoft, infectados con malware para robar credenciales</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Gd7H!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999167e8-29fd-4c7a-9a38-020f632487ef_1678x1108.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Gd7H!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999167e8-29fd-4c7a-9a38-020f632487ef_1678x1108.png 424w, https://substackcdn.com/image/fetch/$s_!Gd7H!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999167e8-29fd-4c7a-9a38-020f632487ef_1678x1108.png 848w, https://substackcdn.com/image/fetch/$s_!Gd7H!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999167e8-29fd-4c7a-9a38-020f632487ef_1678x1108.png 1272w, https://substackcdn.com/image/fetch/$s_!Gd7H!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999167e8-29fd-4c7a-9a38-020f632487ef_1678x1108.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Gd7H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999167e8-29fd-4c7a-9a38-020f632487ef_1678x1108.png" width="1456" height="961" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/999167e8-29fd-4c7a-9a38-020f632487ef_1678x1108.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:961,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2451342,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/201095193?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999167e8-29fd-4c7a-9a38-020f632487ef_1678x1108.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Gd7H!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999167e8-29fd-4c7a-9a38-020f632487ef_1678x1108.png 424w, https://substackcdn.com/image/fetch/$s_!Gd7H!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999167e8-29fd-4c7a-9a38-020f632487ef_1678x1108.png 848w, https://substackcdn.com/image/fetch/$s_!Gd7H!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999167e8-29fd-4c7a-9a38-020f632487ef_1678x1108.png 1272w, https://substackcdn.com/image/fetch/$s_!Gd7H!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F999167e8-29fd-4c7a-9a38-020f632487ef_1678x1108.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Oficinas de Microsoft en Nueva York. Foto: AFP</figcaption></figure></div><p>Decenas de paquetes open source de Microsoft <a href="https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealer/">fueron </a><strong><a href="https://arstechnica.com/security/2026/06/for-the-2nd-time-in-weeks-microsoft-packages-laced-with-credential-stealer/">comprometidos</a> con malware</strong> dise&#241;ado para robar credenciales cuando los desarrolladores los abr&#237;an desde agentes de programaci&#243;n con IA.</p><p><strong>Qu&#233; pas&#243;.</strong> Investigadores detectaron 73 paquetes maliciosos en GitHub. Los sistemas autom&#225;ticos de la plataforma los bloquearon, pero GitHub inform&#243; que hab&#237;an sido deshabilitados por una &#8220;violaci&#243;n de los t&#233;rminos de servicio&#8221;, sin advertir de entrada que eran maliciosos ni recomendar a los desarrolladores asumir que sus sistemas pod&#237;an estar comprometidos.</p><p><strong>El giro.</strong> Microsoft reci&#233;n el lunes admiti&#243; la posibilidad de contenido malicioso. En un correo dijo que hab&#237;a removido temporalmente algunos repositorios mientras investigaba.</p><p><strong>Por qu&#233; importa.</strong> Es el segundo ataque de supply chain en dos meses contra una cuenta oficial de repositorios de Microsoft. En mayo, StepSecurity document&#243; el compromiso del <strong>SDK Python Durable Task </strong>en PyPI, un paquete con unas 400.000 descargas mensuales.</p><p><strong>Qu&#233; robaba.</strong> El <em>payload</em>, de 28 KB, buscaba credenciales de AWS, Azure, GCP, Kubernetes, administradores de contrase&#241;as y m&#225;s de 90 configuraciones de herramientas de desarrollo. Tambi&#233;n pod&#237;a moverse lateralmente por infraestructuras cloud e infectar otras m&#225;quinas de desarrolladores.</p><p><strong>La novedad.</strong> En esta campa&#241;a, el robo de credenciales se activaba cuando un desarrollador abr&#237;a los paquetes desde agentes como Claude Code, Gemini CLI, Cursor o VS Code.</p><div><hr></div><h4><strong>&#128275; Breaches y hacks</strong></h4><ul><li><p><a href="https://support.dashlane.com/hc/en-us/articles/36038764990866-Security-advisory-Brute-force-attack-on-Dashlane-user-accounts">Dashlane</a> dio detalles del breach</p></li><li><p>Hackean la blockchain de <a href="https://thecryptocurrencypost.net/tesseradao-tsr-25m-exploit-on-bnb-chain-via-unauthorized-mint/">TesseraDAO</a> por 2,5 millones de d&#243;lares</p></li><li><p>Hackean a la <a href="https://www.bleepingcomputer.com/news/security/oxford-university-discloses-data-breach-after-careerconnect-platform-hack/">Universidad de Oxford</a></p></li></ul><h4><strong>&#128274; Ransomware</strong></h4><ul><li><p>Check Point <a href="https://www.bleepingcomputer.com/news/security/check-point-links-vpn-zero-day-attacks-to-qilin-ransomware-gang/">conecta</a> un zero day en una VPN a campa&#241;as de Qilin</p></li><li><p>Suspenden clases en una <a href="https://www.theregister.com/cyber-crime/2026/06/08/ransomware-attack-shuts-illinois-high-school-until-wednesday/5252322">escuela de Illinois</a> por un ransomware</p></li><li><p>ShinyHunters publica 234 GB de datos de <a href="https://securityaffairs.com/193274/data-breach/dentaquest-breach-shinyhunters-publish-data-impacting-2-6m-people.html">DentaQuest</a></p></li></ul><h4><strong>&#128163; Exploits y malware</strong></h4><ul><li><p>Microsoft da de baja 73 repositorios de <a href="https://opensourcemalware.com/blog/miasma-reaches-azure">GitHub infectados</a></p></li><li><p><a href="https://www.bleepingcomputer.com/news/security/nfcshare-android-malware-spreads-via-fake-banking-app-updates-on-github/">NFCShare Android</a> se propaga a trav&#233;s de apps falsas de home banking alojadas en GitHub</p></li><li><p>Un <a href="https://securityaffairs.com/193352/hacking/cve-2026-23111-linux-nf_tables-flaw-enables-root-exploits.html">bug en Linux</a> permite que usuarios locales obtengan permisos de administrador</p></li></ul><h4><strong>&#128269; Threat intel y vulnerabilidades</strong></h4><ul><li><p><a href="https://www.securityweek.com/google-patches-5th-chrome-zero-day-exploited-in-2026/">Google parchea</a> el quinto zero day de 2026</p></li><li><p>Vulnerabilidad cr&#237;tica en un <a href="https://www.securityweek.com/everest-forms-vulnerability-exploited-to-hack-wordpress-sites/">servicio de WordPress</a></p></li><li><p>Reportes: <a href="https://www.gartner.com/en/newsroom/press-releases/2026-06-01-gartner-identifies-strategic-focus-areas-for-cisos-to-seize-moments-of-opportunity-among-ai-chaos">Gartner</a>, <a href="https://genai.owasp.org/resource/state-of-agentic-ai-security-and-governance/">OWASP</a>, <a href="https://www.wordfence.com/blog/2026/06/quarterly-wordpress-threat-intelligence-report-q1-2026/">Wordfence</a>, <a href="https://blog.incogni.com/are-job-search-platforms-exploiting-job-seekers-for-their-personal-data/">Incogni</a>, <a href="https://ics-cert.kaspersky.com/publications/reports/2026/06/09/threat-landscape-for-industrial-automation-systems-q1-2026/">Kaspersky</a>.</p></li></ul><h4><strong>&#128736;&#65039; Tools y updates</strong></h4><ul><li><p><a href="https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop_0877304591.html">Chrome</a>, <a href="https://msrc.microsoft.com/update-guide/releaseNote/2026-Jun">Microsoft</a> y <a href="https://www.tp-link.com/us/support/faq/5120/">TP-Link</a> lanzan actualizaciones de seguridad</p></li><li><p>Una <a href="https://www.bleepingcomputer.com/news/apple/new-apple-feature-automatically-changes-your-compromised-passwords/">nueva funci&#243;n de Apple</a> cambia autom&#225;ticamente contrase&#241;as comprometidas</p></li><li><p><a href="https://www.nvidia.com/en-us/security/">NVIDIA</a> publica una lista de updates</p></li></ul><h4><strong>&#128203; Privacidad y regulaciones</strong></h4><ul><li><p>Massachusetts intenta regular la venta de <a href="https://techcrunch.com/2026/06/08/massachusetts-votes-to-pass-new-privacy-rights-bill-that-bans-sale-of-precise-location-data/">datos personales</a></p></li><li><p>Gran Breta&#241;a quiere que empresas tech <a href="https://www.theguardian.com/technology/2026/jun/08/starmer-tech-firms-ultimatum-block-explicit-images-children-phones">proh&#237;ban fotos de desnudos</a> de menores</p></li><li><p>Buscan <a href="https://www.abc27.com/news/top-stories/pennsylvania-lawmaker-seeks-visual-indicator-if-smart-glasses-are-recording/">regular el uso</a> de los smart glasses para que sea claro cuando est&#233;n grabando</p><p></p></li></ul><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial generativa para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/hackean-instagram-meta-chatbot-soporte?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/hackean-instagram-meta-chatbot-soporte?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Ariel Waissbein: Argentina quiere “ponerle nombre y apellido” a sus infraestructuras críticas, pero le faltan recursos]]></title><description><![CDATA[Especial Industrial Cyber Summit: la Disposici&#243;n 1/2026 del Centro Nacional de Ciberseguridad, las filtraciones de datos y la ciberseguridad cu&#225;ntica, entre lo m&#225;s destacado de la conferencia.]]></description><link>https://www.brodersendarknews.com/p/ariel-waissbein-industrial-cyber-summit</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/ariel-waissbein-industrial-cyber-summit</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Sun, 07 Jun 2026 12:12:27 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!lkrR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8994f925-53af-4a77-8ac0-97ed8bdfed02_7008x4672.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><p><strong>&#128204; </strong><em><strong>Edici&#243;n fuera de agenda</strong></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><div class="pullquote"><p><strong>Presentado por:</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5xcT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61825f10-5d3b-42e3-9e97-9c8667f617bf_600x300.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5xcT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61825f10-5d3b-42e3-9e97-9c8667f617bf_600x300.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5xcT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61825f10-5d3b-42e3-9e97-9c8667f617bf_600x300.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5xcT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61825f10-5d3b-42e3-9e97-9c8667f617bf_600x300.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5xcT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61825f10-5d3b-42e3-9e97-9c8667f617bf_600x300.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5xcT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61825f10-5d3b-42e3-9e97-9c8667f617bf_600x300.jpeg" width="600" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/61825f10-5d3b-42e3-9e97-9c8667f617bf_600x300.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:131875,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/200656011?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61825f10-5d3b-42e3-9e97-9c8667f617bf_600x300.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5xcT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61825f10-5d3b-42e3-9e97-9c8667f617bf_600x300.jpeg 424w, https://substackcdn.com/image/fetch/$s_!5xcT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61825f10-5d3b-42e3-9e97-9c8667f617bf_600x300.jpeg 848w, https://substackcdn.com/image/fetch/$s_!5xcT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61825f10-5d3b-42e3-9e97-9c8667f617bf_600x300.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!5xcT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F61825f10-5d3b-42e3-9e97-9c8667f617bf_600x300.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></div><h1>07<br>jun</h1><h2><strong>&#9889;TL;DR</strong></h2><p>El jueves pasado se hizo la tercera edici&#243;n del <strong><a href="https://cybersummit.io/industrial-cybersummit-argentina-2026/">Industrial Cyber Summit Argentina 2026</a></strong>, una conferencia que re&#250;ne en Buenos Aires al mundo de los riesgos ciberf&#237;sicos, la protecci&#243;n de activos cr&#237;ticos y la cada vez m&#225;s frecuente amenaza de los ataques cin&#233;ticos.</p><p>Es el tercer a&#241;o consecutivo que se realiza la cumbre. Tuve la oportunidad de asistir a las dos ediciones anteriores y es muy interesante ver c&#243;mo fue creciendo, esta vez con m&#225;s de 550 asistentes. Flavia Mendez, CEO y fundadora del Summit, hizo el kickoff y llev&#243; adelante una entrevista con <strong><a href="https://www.brodersendarknews.com/p/ariel-wata-waissbein-agencia-ciberseguridad">Ariel Wata Waissbein</a></strong>, director del <strong><a href="https://www.argentina.gob.ar/noticias/se-presento-el-centro-nacional-de-ciberseguridad">Centro Nacional de Ciberseguridad (CNC)</a></strong>.</p><p>La charla tuvo valor period&#237;stico, principalmente, porque Waissbein no suele hablar mucho en p&#250;blico, o al menos no es una figura f&#225;cil para entrevistas. En parte, por eso, centro esta entrega especial en algunas ideas que arroj&#243; sobre <strong>el estado del Estado</strong>: c&#243;mo est&#225; el panorama de la ciberseguridad en Argentina y qu&#233; est&#225;n haciendo desde el Centro. </p><p>A partir de la primera disposici&#243;n del Centro, <a href="https://www.brodersendarknews.com/i/197269600/el-gobierno-da-180-dias-a-organismos-estatales-para-preparar-sus-sistemas-ante-ciberataques">la 1/2026 publicada en mayo de este a&#241;o</a>, el Centro quiere armar un mapa preciso de cu&#225;les son las organizaciones que realmente importan para la continuidad del pa&#237;s, sentarse con cada una, medir su madurez de ciberseguridad y definir un camino de mejora posible. <strong>Qu&#233; es cr&#237;tico y en qu&#233; medida.</strong> Dijo el funcionario:</p><blockquote><p><em>Desde el Comit&#233; de Ciberseguridad ven&#237;amos hablando de la necesidad de ponerle nombre y apellido a las infraestructuras cr&#237;ticas. En el decreto de 2019 estaban definidos los sectores. Lo que hicimos en 2025 fue trabajar <strong>en un procedimiento para definir organizaciones concretas</strong>: este organismo del Estado, esta empresa. Eso nos permite sentarnos despu&#233;s con cada una de ellas a hablar de c&#243;mo protegerlas. Porque <strong>es dif&#237;cil decir &#8216;todo energ&#237;a tiene que estar seguro&#8217;</strong>. Eso es un mont&#243;n. Hay empresas chicas, y en telecomunicaciones tambi&#233;n hay empresas de todo tama&#241;o. Si empezamos a escribir requerimientos m&#237;nimos, para algunas va a ser rid&#237;culo e inimplementable. Entonces, estamos trabajando para armar con ellas <strong>un modelo de madurez</strong> y ver d&#243;nde est&#225;n paradas, y c&#243;mo evolucionar hacia un estadio aceptable de ciberseguridad, donde el riesgo sea algo que podamos aceptar.</em></p></blockquote><p>&#8220;El Centro existe desde este a&#241;o y estamos <strong>consiguiendo los recursos, en un pa&#237;s donde la plata hay que conseguirla</strong>. As&#237; que ah&#237; vamos&#8221;, remat&#243;.</p><p>Una idea que me pareci&#243; interesante de la charla fue que Waissbein dijo que cree que desde la Direcci&#243;n se deber&#237;a realizar una suerte de &#8220;post mortem p&#250;blico&#8221;, para que los ciudadanos sepan qu&#233; pas&#243; cuando se filtran datos o se hackea un organismo. Esto, tambi&#233;n, period&#237;sticamente, tendr&#237;a <strong>much&#237;simo valor</strong>. </p><p>Sobre esto, desde la organizaci&#243;n me propusieron moderar un panel sobre la protecci&#243;n de las infraestructuras p&#250;blicas, con Mara Misto (encargada de seguridad del Banco Central, <a href="https://www.prensariohub.com/usuaria-primera-mujer-ciso-del-ano-que-desvela-a-los-cisos-hoy/">CISO del a&#241;o</a>), Ezequiel Gutesman (Subdirector Ejecutivo del CNC) y Pedro Janices (encargado de la seguridad del PAMI).</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nx05!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5272cb2-0d47-4e5e-8a6d-0426d84f96a4_7008x4672.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nx05!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5272cb2-0d47-4e5e-8a6d-0426d84f96a4_7008x4672.jpeg 424w, https://substackcdn.com/image/fetch/$s_!nx05!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5272cb2-0d47-4e5e-8a6d-0426d84f96a4_7008x4672.jpeg 848w, https://substackcdn.com/image/fetch/$s_!nx05!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5272cb2-0d47-4e5e-8a6d-0426d84f96a4_7008x4672.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!nx05!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5272cb2-0d47-4e5e-8a6d-0426d84f96a4_7008x4672.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nx05!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5272cb2-0d47-4e5e-8a6d-0426d84f96a4_7008x4672.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e5272cb2-0d47-4e5e-8a6d-0426d84f96a4_7008x4672.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1969107,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/200656011?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5272cb2-0d47-4e5e-8a6d-0426d84f96a4_7008x4672.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nx05!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5272cb2-0d47-4e5e-8a6d-0426d84f96a4_7008x4672.jpeg 424w, https://substackcdn.com/image/fetch/$s_!nx05!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5272cb2-0d47-4e5e-8a6d-0426d84f96a4_7008x4672.jpeg 848w, https://substackcdn.com/image/fetch/$s_!nx05!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5272cb2-0d47-4e5e-8a6d-0426d84f96a4_7008x4672.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!nx05!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe5272cb2-0d47-4e5e-8a6d-0426d84f96a4_7008x4672.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Entrevistando a Mara Misto, CISO del Banco Central. Foto: Lucas Todaro</figcaption></figure></div><p>Destaco en esta entrega, tambi&#233;n, el panel de ciencia con tres expertos que hablaron sobre el problema cu&#225;ntico y el <a href="https://www.brodersendarknews.com/p/ekoparty-2025-mercado-libre-computadora-cuantica">famoso </a><strong><a href="https://www.brodersendarknews.com/p/ekoparty-2025-mercado-libre-computadora-cuantica">Q-Day</a></strong>.</p><div><hr></div><p><em>En esta edici&#243;n:</em></p><ul><li><p>&#127991;&#65039; <em>Ariel Waissbein: Argentina quiere &#8220;ponerle nombre y apellido&#8221; a sus infraestructuras cr&#237;ticas, pero todav&#237;a busca recursos</em></p></li><li><p>&#9883;&#65039; <em>Ciberseguridad cu&#225;ntica: &#8220;No podemos esperar a que el mercado autorregule&#8221;</em></p></li></ul><div><hr></div><p>&#9200; <em>Substack dice que leer este correo completo lleva 15 minutos</em></p><p><em>Dark News #207</em></p><div><hr></div><h3>Ariel Waissbein: Argentina quiere &#8220;ponerle nombre y apellido&#8221; a sus infraestructuras cr&#237;ticas, pero todav&#237;a busca recursos</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!lkrR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8994f925-53af-4a77-8ac0-97ed8bdfed02_7008x4672.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!lkrR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8994f925-53af-4a77-8ac0-97ed8bdfed02_7008x4672.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lkrR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8994f925-53af-4a77-8ac0-97ed8bdfed02_7008x4672.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lkrR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8994f925-53af-4a77-8ac0-97ed8bdfed02_7008x4672.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lkrR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8994f925-53af-4a77-8ac0-97ed8bdfed02_7008x4672.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!lkrR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8994f925-53af-4a77-8ac0-97ed8bdfed02_7008x4672.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8994f925-53af-4a77-8ac0-97ed8bdfed02_7008x4672.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1907631,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/200656011?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8994f925-53af-4a77-8ac0-97ed8bdfed02_7008x4672.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!lkrR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8994f925-53af-4a77-8ac0-97ed8bdfed02_7008x4672.jpeg 424w, https://substackcdn.com/image/fetch/$s_!lkrR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8994f925-53af-4a77-8ac0-97ed8bdfed02_7008x4672.jpeg 848w, https://substackcdn.com/image/fetch/$s_!lkrR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8994f925-53af-4a77-8ac0-97ed8bdfed02_7008x4672.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!lkrR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8994f925-53af-4a77-8ac0-97ed8bdfed02_7008x4672.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Flavia Mendez, CEO del Summit, junto a Ariel &#8220;Wata&#8221; Waissbein. Foto: Lucas Todaro</figcaption></figure></div><p>Argentina est&#225; armando una nueva etapa de su pol&#237;tica de ciberseguridad: el <strong>Centro Nacional de Ciberseguridad</strong> quiere identificar con precisi&#243;n qu&#233; organismos y empresas integran <strong>el mapa</strong> de infraestructuras cr&#237;ticas, construir un modelo de madurez propio y mejorar la respuesta estatal ante filtraciones de datos.</p><p>Todav&#237;a con una gran limitaci&#243;n: <strong>recursos escasos</strong>.</p><p><strong>Qu&#233; pas&#243;.</strong> Ariel &#8220;Wata&#8221; Waissbein, director del Centro Nacional de Ciberseguridad, dijo durante un panel en el Industrial Cyber Summit que el Gobierno busca &#8220;ponerle nombre y apellido&#8221; a las infraestructuras cr&#237;ticas. La idea es pasar de una definici&#243;n general por sectores, como energ&#237;a o telecomunicaciones, a una lista de organizaciones concretas: organismos del Estado y empresas que necesitan un nivel de protecci&#243;n especial.</p><p><strong>Por qu&#233; importa.</strong> Esa definici&#243;n es la base para cualquier pol&#237;tica real de protecci&#243;n, seg&#250;n dijo. Waissbein explic&#243; que resulta dif&#237;cil exigir seguridad a &#8220;todo energ&#237;a&#8221; o &#8220;todo telecomunicaciones&#8221; como si fueran bloques homog&#233;neos. </p><p>En esos sectores conviven empresas grandes, organismos p&#250;blicos, operadores chicos y actores con capacidades muy distintas. Un mismo requerimiento m&#237;nimo puede ser razonable para unos, pero <strong>&#8220;rid&#237;culo e inimplementable&#8221;</strong> para otros.</p><p><strong>El plan.</strong> El Centro trabaja en un modelo de madurez inspirado en marcos como <strong>NIST Cybersecurity Framework o NIS2</strong>, adaptado a la realidad argentina. La idea es sentarse con cada infraestructura cr&#237;tica, medir d&#243;nde est&#225; parada y definir c&#243;mo puede evolucionar hacia un nivel aceptable de ciberseguridad. El objetivo no es eliminar todo riesgo, sino llevarlo a un punto que el Estado pueda aceptar y administrar.</p><p><strong>El contexto.</strong> El nuevo organismo naci&#243; despu&#233;s de la divisi&#243;n de la <strong><a href="https://www.clarin.com/tecnologia/hackeos-estado-avances-criticas-dicen-agencia-federal-ciberseguridad-estrategia-nacional_0_i6qijATbDn.html">Agencia Federal de Ciberseguridad</a></strong>, que funcionaba dentro de la <strong>SIDE</strong>. Waissbein explic&#243; que esa ubicaci&#243;n generaba <strong>problemas de confianza</strong>: hab&#237;a actores que no quer&#237;an compartir informaci&#243;n por temor a que se usara para fines distintos de la ciberseguridad. La decisi&#243;n oficial fue separar la ciberseguridad de la Secretar&#237;a de Inteligencia y crear el Centro Nacional de Ciberseguridad.</p><p><strong>Qu&#233; viene.</strong> El Gobierno tambi&#233;n trabaja en un SOC nacional, con apoyo de <strong>un pr&#233;stamo del BID</strong> (<a href="https://www.iadb.org/es/proyecto/AR-L1343">ver</a>), para monitorear la estructura nacional, entender cu&#225;ndo ocurren incidentes y reportarlos mejor desde el CERT. El alcance formal del Centro incluye al sector p&#250;blico nacional y a las infraestructuras cr&#237;ticas, con colaboraci&#243;n hacia provincias y municipios.</p><p><strong>El l&#237;mite.</strong> Waissbein reconoci&#243; que el organismo todav&#237;a est&#225; consiguiendo recursos. &#8220;El centro existe desde este a&#241;o, estamos consiguiendo los recursos <strong>en un pa&#237;s donde la plata hay que conseguirla</strong>&#8221;, dijo. </p><p>Seg&#250;n explic&#243;, el financiamiento del BID puede ayudar a dar &#8220;pasos grandes&#8221;, aunque el proceso burocr&#225;tico todav&#237;a est&#225; en marcha.</p><p><strong>Filtraciones.</strong> Otro eje de la entrevista fue la <strong>circulaci&#243;n de datos de ciudadanos argentinos</strong> en foros, bots de Telegram y sitios de filtraciones. Waissbein dijo que el Centro investiga cada leak para determinar si se trata de datos nuevos, datos viejos reciclados o bases infladas por los propios atacantes. </p><p>Tambi&#233;n plante&#243; que muchas filtraciones atribuidas a organismos como RENAPER en realidad pueden venir de terceros que consumen esos datos.</p><p><strong>El problema.</strong> La superficie de riesgo crece cuando las bases p&#250;blicas circulan entre organismos y sistemas con <strong>controles d&#233;biles</strong>. Waissbein mencion&#243; pr&#225;cticas como cachear datos o compartir un mismo usuario y contrase&#241;a entre muchos empleados, lo que despu&#233;s impide saber qui&#233;n accedi&#243; a qu&#233; informaci&#243;n cuando ocurre una fuga.</p><p><strong>Transparencia.</strong> El Centro quiere avanzar hacia reportes o <em><strong>postmortems</strong></em><strong> de incidentes</strong>, idealmente junto con los organismos afectados. La idea es precisar qu&#233; pas&#243;, qu&#233; volumen de datos se filtr&#243; y qu&#233; decisiones deber&#237;an tomarse despu&#233;s. </p><p>Waissbein puso como ejemplo el <strong>n&#250;mero de tr&#225;mite del DNI</strong>: si ese dato se filtra, el Estado debe discutir si sigue siendo v&#225;lido usarlo como mecanismo de identificaci&#243;n para abrir cuentas o validar tr&#225;mites.</p><p><strong>El panorama.</strong> El Centro Nacional de Ciberseguridad quiere ordenar un ecosistema fragmentado: definir infraestructuras cr&#237;ticas, medir madurez, mejorar reportes, investigar filtraciones y escribir disposiciones cuando haga falta.</p><p>La ambici&#243;n ya est&#225; planteada, pero la ejecuci&#243;n, en gran parte, <strong>depende del presupuesto</strong>.</p><h3><strong>Ciberseguridad cu&#225;ntica: &#8220;No podemos esperar a que el mercado autorregule&#8221;</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!smYl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97449374-47e1-4817-a265-2e02e768a3e5_5663x3775.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!smYl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97449374-47e1-4817-a265-2e02e768a3e5_5663x3775.jpeg 424w, https://substackcdn.com/image/fetch/$s_!smYl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97449374-47e1-4817-a265-2e02e768a3e5_5663x3775.jpeg 848w, https://substackcdn.com/image/fetch/$s_!smYl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97449374-47e1-4817-a265-2e02e768a3e5_5663x3775.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!smYl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97449374-47e1-4817-a265-2e02e768a3e5_5663x3775.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!smYl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97449374-47e1-4817-a265-2e02e768a3e5_5663x3775.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/97449374-47e1-4817-a265-2e02e768a3e5_5663x3775.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:18457102,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/200656011?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97449374-47e1-4817-a265-2e02e768a3e5_5663x3775.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!smYl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97449374-47e1-4817-a265-2e02e768a3e5_5663x3775.jpeg 424w, https://substackcdn.com/image/fetch/$s_!smYl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97449374-47e1-4817-a265-2e02e768a3e5_5663x3775.jpeg 848w, https://substackcdn.com/image/fetch/$s_!smYl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97449374-47e1-4817-a265-2e02e768a3e5_5663x3775.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!smYl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F97449374-47e1-4817-a265-2e02e768a3e5_5663x3775.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Lucas Todaro</figcaption></figure></div><p>Otro de los paneles destacados de la conferencia tuvo que ver con <strong>ciberseguridad cu&#225;ntica</strong>.</p><p>La conversaci&#243;n reuni&#243; a <strong>Fernando Lombardo</strong>, doctor y licenciado en Ciencias F&#237;sicas, profesor asociado e investigador principal del <strong>CONICET</strong>, <strong>Adriana Baravalle</strong>, directora del Laboratorio de Tecnolog&#237;as Exponenciales de la Universidad Austral e investigadora de la Facultad Militar Conjunta de la <strong>UNDef</strong> y <strong>Sebasti&#225;n Uchitel</strong>, investigador superior del CONICET y profesor en la <strong>UBA</strong>, la Universidad de San Andr&#233;s y el Imperial College London.</p><p><strong>La discusi&#243;n.</strong> El panel dej&#243; una foto del estado de la cuesti&#243;n: la computaci&#243;n cu&#225;ntica ya existe como campo experimental, pero <strong>todav&#237;a est&#225; lejos de romper criptograf&#237;a a gran escala</strong>. </p><p><strong>Convergencia.</strong> Baravalle plante&#243; que el riesgo ya no puede pensarse s&#243;lo como un problema de criptograf&#237;a. IA, computaci&#243;n cu&#225;ntica, ciberseguridad e infraestructuras cr&#237;ticas empiezan a cruzarse en un mismo mapa de amenazas, capacidades y decisiones. Esa transici&#243;n exige <strong>perfiles t&#233;cnicos formados en m&#225;s de una disciplina</strong>, inversi&#243;n en ciencia y coordinaci&#243;n entre academia, Estado y empresas.</p><p><strong>Autonom&#237;a.</strong> Uchitel llev&#243; la conversaci&#243;n hacia rob&#243;tica y sistemas aut&#243;nomos. Su punto fue que la autonom&#237;a cambi&#243; de escala: ya no se trata s&#243;lo de m&#225;quinas que ejecutan una tarea puntual, sino de sistemas que combinan sensores, herramientas, objetivos de largo plazo e IA. En seguridad, el desaf&#237;o es verificar que esos sistemas se mantengan dentro de <strong>comportamientos seguros</strong>, sobre todo cuando operan en entornos cr&#237;ticos.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oRq-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ddcdd9f-cf65-4573-9c22-0bb1bffc1a6f_1352x905.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oRq-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ddcdd9f-cf65-4573-9c22-0bb1bffc1a6f_1352x905.png 424w, https://substackcdn.com/image/fetch/$s_!oRq-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ddcdd9f-cf65-4573-9c22-0bb1bffc1a6f_1352x905.png 848w, https://substackcdn.com/image/fetch/$s_!oRq-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ddcdd9f-cf65-4573-9c22-0bb1bffc1a6f_1352x905.png 1272w, https://substackcdn.com/image/fetch/$s_!oRq-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ddcdd9f-cf65-4573-9c22-0bb1bffc1a6f_1352x905.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oRq-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ddcdd9f-cf65-4573-9c22-0bb1bffc1a6f_1352x905.png" width="1352" height="905" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8ddcdd9f-cf65-4573-9c22-0bb1bffc1a6f_1352x905.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:905,&quot;width&quot;:1352,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2143330,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/200656011?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ddcdd9f-cf65-4573-9c22-0bb1bffc1a6f_1352x905.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oRq-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ddcdd9f-cf65-4573-9c22-0bb1bffc1a6f_1352x905.png 424w, https://substackcdn.com/image/fetch/$s_!oRq-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ddcdd9f-cf65-4573-9c22-0bb1bffc1a6f_1352x905.png 848w, https://substackcdn.com/image/fetch/$s_!oRq-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ddcdd9f-cf65-4573-9c22-0bb1bffc1a6f_1352x905.png 1272w, https://substackcdn.com/image/fetch/$s_!oRq-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8ddcdd9f-cf65-4573-9c22-0bb1bffc1a6f_1352x905.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Fernando Lombardo, Adriana Baravalle y Sebasti&#225;n Uchitel, disertantes sobre seguridad cu&#225;ntica. Foto: Lucas Todaro</figcaption></figure></div><p>Para profundizar este punto, despu&#233;s del panel <strong>Dark News</strong> habl&#243; con Lombardo y Baravalle.</p><p><strong>Riesgo.</strong> Lombardo explic&#243; que la amenaza cu&#225;ntica tiene una <strong>base cient&#237;fica real</strong>, aunque todav&#237;a no existe una capacidad operativa a escala:</p><blockquote><p><em>Desde la f&#237;sica, <strong>el riesgo existe y est&#225; bien fundamentado</strong>: ciertos esquemas criptogr&#225;ficos s&#237; ser&#237;an vulnerables ante computadoras cu&#225;nticas suficientemente grandes. Eso est&#225; demostrado hace a&#241;os. Lo que todav&#237;a no existe es esa capacidad a escala real. Entonces, no estamos frente a una amenaza inmediata, pero s&#237; frente a un cambio tecnol&#243;gico serio que obliga a prepararse desde ahora.</em></p></blockquote><p><strong>Escala.</strong> El punto t&#233;cnico est&#225; en la diferencia entre los prototipos actuales y una computadora cu&#225;ntica tolerante a fallas:</p><blockquote><p><em>Lo real es que sabemos, desde la f&#237;sica cu&#225;ntica y la teor&#237;a de la informaci&#243;n cu&#225;ntica, que una computadora cu&#225;ntica tolerante a fallas, con una cantidad suficiente de qubits l&#243;gicos, podr&#237;a comprometer ciertos sistemas criptogr&#225;ficos que usamos hoy. Eso no es una promesa comercial ni una moda: es algo que conocemos hace d&#233;cadas. Ahora, <strong>de ah&#237; a pensar que ma&#241;ana alguien va a romper la seguridad de Internet</strong> con una computadora cu&#225;ntica hay un salto enorme.</em></p></blockquote><p><strong>Capacidades.</strong> Para Lombardo, Argentina deber&#237;a prepararse con ciencia y tecnolog&#237;a propias, sin esperar soluciones importadas: </p><blockquote><p><em><strong>La seguridad digital no est&#225; en riesgo ma&#241;ana a la ma&#241;ana</strong>. Pero s&#237; hay una discusi&#243;n cient&#237;fica y tecnol&#243;gica seria sobre c&#243;mo prepararnos para herramientas que probablemente cambien algunas reglas en los pr&#243;ximos a&#241;os o d&#233;cadas. Nuestro pa&#237;s no deber&#237;a esperar que las respuestas vengan de afuera: tenemos la <strong>masa cr&#237;tica de cient&#237;ficos y tecn&#243;logos</strong> para estudiar estos problemas hoy, y pese a las dificultades, lo estamos haciendo. Pero se necesita mucho m&#225;s entendimiento y apoyo.</em></p></blockquote><p><strong>Regulaci&#243;n.</strong> Baravalle plante&#243; que, en infraestructuras cr&#237;ticas, el Estado tiene que fijar un piso antes de que la tecnolog&#237;a llegue a una escala de riesgo mayor: </p><blockquote><p><em>Cuando hablamos de infraestructuras cr&#237;ticas (energ&#237;a, agua, defensa, salud), la respuesta natural es regulaci&#243;n primero, porque el costo de un fallo no lo absorbe una empresa: lo absorbe la sociedad. <strong>Ah&#237; no podemos esperar que el mercado autorregule</strong>. El Estado tiene que fijar el piso antes de que la tecnolog&#237;a llegue&#8221;.</em></p></blockquote><p><strong>Sectores.</strong> En el &#225;mbito privado, Baravalle marc&#243; que la respuesta depende del tipo de actividad y del nivel de exposici&#243;n p&#250;blica: </p><blockquote><p><em>Cuando hablamos de industria privada, manufactura o log&#237;stica, la ecuaci&#243;n se invierte. Una regulaci&#243;n prematura sobre tecnolog&#237;as que todav&#237;a est&#225;n madurando puede congelar la adopci&#243;n antes de que entendamos bien qu&#233; estamos regulando. Entonces, la respuesta honesta es: <strong>depende del sector</strong>, del nivel de exposici&#243;n p&#250;blica y del horizonte de riesgo.</em></p></blockquote><p><strong>Dependencia.</strong> Baravalle tambi&#233;n ubic&#243; el problema en una discusi&#243;n geopol&#237;tica sobre est&#225;ndares, hardware y capacidad de decisi&#243;n: </p><blockquote><p><em>Argentina opera infraestructura cr&#237;tica con tecnolog&#237;a <strong>mayoritariamente importada</strong>. Eso significa que cuando China o Estados Unidos toman decisiones sobre est&#225;ndares cu&#225;nticos, sobre qu&#233; algoritmos poscu&#225;nticos se adoptan, sobre qu&#233; hardware se exporta y a qui&#233;n, nosotros no estamos en esa conversaci&#243;n. NIST ya public&#243; sus primeros est&#225;ndares poscu&#225;nticos. La Uni&#243;n Europea est&#225; construyendo los propios. <strong>Am&#233;rica Latina, en general, est&#225; mirando desde afuera.</strong></em></p></blockquote><p><strong>Ventana.</strong> La advertencia de fondo es que la transici&#243;n poscu&#225;ntica todav&#237;a est&#225; a tiempo de planificarse, pero esa ventana no ser&#225; indefinida:</p><blockquote><p><em>El riesgo cu&#225;ntico nos da una ventana de oportunidad. T<strong>odav&#237;a no lleg&#243; el D&#237;a Q</strong>. Pero la ventana se est&#225; cerrando y, si no la usamos para construir esa capacidad colectiva de decisi&#243;n, vamos a terminar adoptando por defecto lo que otros decidan por nosotros.</em></p></blockquote><p>M&#225;s all&#225; de estos temas, que son una selecci&#243;n sobre el Summit, recomiendo estar atentos <a href="https://www.youtube.com/@TheCyberSummit">al canal de </a><strong><a href="https://www.youtube.com/@TheCyberSummit">YouTube</a></strong>, donde se van a subir todas las charlas, entre las cuales est&#225; la keynote que estuvo a cargo del <strong>SANS Institute</strong>, referente mundial en entrenamiento en ciberseguridad.</p><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial generativa para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/ariel-waissbein-industrial-cyber-summit?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/ariel-waissbein-industrial-cyber-summit?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Internet muerto: empresas contaminan Reddit para manipular resultados de Google y respuestas de ChatGPT]]></title><description><![CDATA[Adem&#225;s: una vulnerabilidad en el chatbot de soporte de Meta permiti&#243; robar cuentas de Instagram, Microsoft quiere volver "adictos" a sus usuarios a la IA y demanda por monopolio contra Valve.]]></description><link>https://www.brodersendarknews.com/p/internet-muerto-contaminan-reddit-influir-resultados-chatgpt-google</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/internet-muerto-contaminan-reddit-influir-resultados-chatgpt-google</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Fri, 05 Jun 2026 11:04:30 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-dge!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2802e3e1-ca4d-4a6d-bf8e-7aa717d891a0_1883x1180.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>29 may~<br>5 jun</h1><h2><strong>&#9889;TL;DR</strong></h2><p>Si existi&#243; una web primigenia, otra 2.0 (redes sociales) y una (fallida) 3.0 que le quiso poner blockchain a todo, parecer&#237;a que estamos ante una nueva fase. <strong>Bienvenidos a la era de una </strong><em><strong>web fake</strong></em> que intenta parecer leg&#237;tima.</p><p>Una <a href="https://www.404media.co/companies-are-using-reddit-to-manipulate-chatgpt-and-google-ai-search/">investigaci&#243;n de 404media</a> de esta semana revel&#243; c&#243;mo distintas empresas vinculadas al negocio de las terapias hormonales y el biohacking est&#225;n manipulando Reddit, una de las plataformas de comunidad m&#225;s conocidas del mundo, con <strong>posteos que pretenden ser org&#225;nicos</strong> pero que apuntan a ser <em>scrapeados</em> por un bot, deglutidos por una IA y <strong>regurgitados en el output</strong> de la consulta de un usuario.</p><p>El caso puntual encaja en una <a href="https://www.wired.com/story/googles-ai-overviews-can-scam-you-heres-how-to-stay-safe/">tendencia palpable</a> en casi cualquier red social de la actualidad, donde todo parece artificial. Lo &#250;nico que importa es <a href="https://www.theverge.com/tech/900302/ai-seo-industry-google-search-chatgpt-gemini-marketing">influir en los datos</a> que scrapean los LLM.</p><p>En una semana todav&#237;a dominada por <a href="https://www.brodersendarknews.com/i/199246943/microsoft-enfrenta-a-un-investigador-por-la-publicacion-de-zero-days">el drama entre Microsoft y un researcher</a> que public&#243; <strong>zero days</strong> (<a href="https://x.com/vxunderground/status/2061927345166979098">defendido</a> por sus pares), todo hace pensar que ya estamos ante una &#233;poca donde el contenido <strong>se escribe, edita y produce para los bots</strong>. </p><p>La web <strong>ya no es para nosotros</strong>, los humanos (aunque un bot est&#233; <em>scrapeando</em> esto y el &#8220;nosotros&#8221; sea relativo).</p><p>En el mundo de las vulnerabilidades, un abuso del chatbot de soporte de Instagram permiti&#243; que un grupo de hackers <a href="https://databreaches.net/2026/06/02/hackers-simply-asked-meta-ai-to-give-them-access-to-high-profile-instagram-accounts-it-worked/">&#8220;simplemente le pidiera a Meta AI que les dieran acceso a cuentas de alto perfil. Y funcion&#243;&#8221;</a>. El tema tuvo mucha repercusi&#243;n por los riesgos de los chatbots de soporte t&#233;cnico, aunque el soporte humano tambi&#233;n es un vector de ataque frecuente (<em>vishing, smishing</em>).</p><p>Saliendo de la IA, el <strong>robo cripto</strong> de la semana lo protagoniz&#243; el portal <a href="https://www.theblock.co/post/403108/cosmos-based-gravity-bridge-drained-of-5-4-million-in-suspected-key-compromise-researchers-say">Gravity Bridge</a>, con USD 5,4 millones. Y el <strong>otro drama de la comunidad lo </strong>protagoniz&#243; el bug bounty, que carg&#243; contra HackerOne por <a href="https://x.com/lean0x2f/status/2061837408576913534?s=46&amp;t=ZDX62AReSiixA4MBbwVSog">reutilizar t&#233;cnicas</a> de reportes para buscar vulnerabilidades. Hay bronca entre hunters. </p><p>En el mundo de las regulaciones, Valve, quiz&#225;s la empresa m&#225;s querida por la comunidad gamer, enfrenta una demanda antimonopolio por controlar los precios de Steam (&#191;de d&#243;nde pens&#225;bamos que sal&#237;an esos descuentos del 85%?).</p><p>Y la perlita de la semana es para este (odioso) pasajero que le puso a su dispositivo Bluetooth <strong><a href="https://www.instagram.com/reel/DZCjRGsDwt-/?igsh=aG0zemg0aWFxdmVm">la &#250;nica palabra de cuatro letras en ingl&#233;s</a></strong> que te puede meter en un problema en serio en el mundo de la aeron&#225;utica: el avi&#243;n tuvo que volver al aeropuerto para identificarlo.</p><p>Por &#250;ltimo, encontr&#233; que est&#225;n usando IA para <a href="https://www.bbc.com/future/article/20260527-plots-love-letters-and-diplomacy-the-medieval-secrets-being-revealed-by-ai">descifrar manuscritos medievales</a>. <strong>Apenas el 1% del material</strong> manuscrito en graf&#237;as desconocidas disponible en bibliotecas est&#225; descifrado. Por ejemplo, el <strong><a href="https://en.wikipedia.org/wiki/Borg_cipher">manuscrito de Borg</a></strong>, en el Vaticano, estuvo 400 a&#241;os sin poder leerse. En menos de media hora, la IA logr&#243; traducir con precisi&#243;n 500 s&#237;mbolos del Borg cipher. </p><p>No todo est&#225; perdido, o al menos hay algunas noticias de las cuales agarrarse para no perder la esperanza.</p><div><hr></div><p><em>En esta edici&#243;n:</em></p><ul><li><p>&#129302; <em><a href="https://www.brodersendarknews.com/i/200151802/empresas-contaminan-reddit-para-manipular-resultados-de-google-y-respuestas-de-chatgpt">Empresas contaminan Reddit para manipular resultados de Google y respuestas de ChatGPT</a></em></p></li><li><p>&#128248; <em><a href="https://www.brodersendarknews.com/i/200151802/roban-cuentas-de-instagram-a-traves-del-bot-de-soporte">Roban cuentas de Instagram a trav&#233;s del bot de soporte</a></em></p></li><li><p>&#127918; <em><a href="https://www.brodersendarknews.com/i/200151802/valve-enfrenta-una-demanda-antimonopolio">Valve enfrenta una demanda antimonopolio</a></em></p></li><li><p>&#129504; <em><a href="https://www.brodersendarknews.com/i/200151802/microsoft-quiere-que-sus-usuarios-sean-adictos-a-la-ia">Microsoft quiere que sus usuarios sean &#8220;adictos&#8221; a la IA</a></em></p></li><li><p>&#127963;&#65039; <em><a href="https://www.brodersendarknews.com/i/200151802/estados-unidos-donald-trump-ahora-quiere-regular-a-los-llm">Estados Unidos: Donald Trump ahora quiere regular a los LLM</a></em></p></li></ul><div><hr></div><p>&#9200; <em>Substack dice que leer este correo completo lleva 15 minutos</em></p><p><em>Dark News #206</em></p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><p>CYBER SUMMIT es el punto de encuentro l&#237;der en Am&#233;rica Latina para profesionales, empresas, gobiernos y organizaciones tecnol&#243;gicas que est&#225;n transformando el futuro de la seguridad tecnol&#243;gica. Enterate todo lo que pas&#243; en el evento, haciendo clic <a href="https://cybersummit.io/industrial-cybersummit-argentina-2026/">ac&#225;</a> o en el banner.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://cybersummit.io/industrial-cybersummit-argentina-2026/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!g3a1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa2a9d18-9ffd-448b-89cc-4cd02dbd17ae_2880x1440.png 424w, https://substackcdn.com/image/fetch/$s_!g3a1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa2a9d18-9ffd-448b-89cc-4cd02dbd17ae_2880x1440.png 848w, https://substackcdn.com/image/fetch/$s_!g3a1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa2a9d18-9ffd-448b-89cc-4cd02dbd17ae_2880x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!g3a1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa2a9d18-9ffd-448b-89cc-4cd02dbd17ae_2880x1440.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!g3a1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa2a9d18-9ffd-448b-89cc-4cd02dbd17ae_2880x1440.png" width="1456" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/aa2a9d18-9ffd-448b-89cc-4cd02dbd17ae_2880x1440.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4443924,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://cybersummit.io/industrial-cybersummit-argentina-2026/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/200151802?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa2a9d18-9ffd-448b-89cc-4cd02dbd17ae_2880x1440.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!g3a1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa2a9d18-9ffd-448b-89cc-4cd02dbd17ae_2880x1440.png 424w, https://substackcdn.com/image/fetch/$s_!g3a1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa2a9d18-9ffd-448b-89cc-4cd02dbd17ae_2880x1440.png 848w, https://substackcdn.com/image/fetch/$s_!g3a1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa2a9d18-9ffd-448b-89cc-4cd02dbd17ae_2880x1440.png 1272w, https://substackcdn.com/image/fetch/$s_!g3a1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faa2a9d18-9ffd-448b-89cc-4cd02dbd17ae_2880x1440.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></div><h3>Empresas contaminan Reddit para manipular resultados de Google y respuestas de ChatGPT</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-dge!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2802e3e1-ca4d-4a6d-bf8e-7aa717d891a0_1883x1180.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-dge!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2802e3e1-ca4d-4a6d-bf8e-7aa717d891a0_1883x1180.png 424w, https://substackcdn.com/image/fetch/$s_!-dge!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2802e3e1-ca4d-4a6d-bf8e-7aa717d891a0_1883x1180.png 848w, https://substackcdn.com/image/fetch/$s_!-dge!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2802e3e1-ca4d-4a6d-bf8e-7aa717d891a0_1883x1180.png 1272w, https://substackcdn.com/image/fetch/$s_!-dge!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2802e3e1-ca4d-4a6d-bf8e-7aa717d891a0_1883x1180.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-dge!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2802e3e1-ca4d-4a6d-bf8e-7aa717d891a0_1883x1180.png" width="1456" height="912" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2802e3e1-ca4d-4a6d-bf8e-7aa717d891a0_1883x1180.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:912,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2995696,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/200151802?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2802e3e1-ca4d-4a6d-bf8e-7aa717d891a0_1883x1180.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!-dge!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2802e3e1-ca4d-4a6d-bf8e-7aa717d891a0_1883x1180.png 424w, https://substackcdn.com/image/fetch/$s_!-dge!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2802e3e1-ca4d-4a6d-bf8e-7aa717d891a0_1883x1180.png 848w, https://substackcdn.com/image/fetch/$s_!-dge!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2802e3e1-ca4d-4a6d-bf8e-7aa717d891a0_1883x1180.png 1272w, https://substackcdn.com/image/fetch/$s_!-dge!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2802e3e1-ca4d-4a6d-bf8e-7aa717d891a0_1883x1180.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Mascotas de Reddit en la entrada de los HQ de San Francisco. Foto: Reuters</figcaption></figure></div><p>Empresas del negocio de los p&#233;ptidos, las terapias hormonales y el <strong>biohacking</strong> est&#225;n usando Reddit para intentar manipular las respuestas de ChatGPT y los AI Overviews de Google, <a href="https://www.404media.co/companies-are-using-reddit-to-manipulate-chatgpt-and-google-ai-search/">seg&#250;n revel&#243; 404 Media</a>. </p><p>El caso se enmarca en una tendencia m&#225;s grande: marcas, agencias y actores maliciosos est&#225;n empezando a <strong>intervenir las fuentes que leen los sistemas de IA</strong>.</p><p><strong>Qu&#233; pas&#243;.</strong> Moderadores del subreddit <a href="https://www.reddit.com/r/Biohackers/">r/biohackers</a> dijeron que limitar&#225;n las publicaciones sobre p&#233;ptidos y terapia de reemplazo hormonal porque detectaron <strong>spam encubierto de compa&#241;&#237;as del sector</strong>. La sospecha es que esas empresas buscan instalar menciones, recomendaciones y narrativas en Reddit para que luego sean levantadas por buscadores con IA y chatbots.</p><p><strong>Por qu&#233; importa.</strong> Reddit se volvi&#243; una fuente muy citada por sistemas de IA generativa. Eso abri&#243; una nueva forma de manipulaci&#243;n: intervenir el material que los modelos leen o resumen, para influir en las respuestas que despu&#233;s reciben los usuarios.</p><p><strong>Contexto. </strong>En los &#250;ltimos meses, <a href="https://developers.google.com/search/docs/essentials/spam-policies?hl=es">Google</a> actualiz&#243; sus pol&#237;ticas de spam para incluir intentos de <strong>manipular respuestas</strong> generadas por IA, <a href="https://www.microsoft.com/en-us/security/blog/2026/02/10/ai-recommendation-poisoning/">Microsoft report&#243;</a> campa&#241;as de &#8220;AI Recommendation Poisoning&#8221; con instrucciones ocultas en botones de &#8220;Summarize with AI&#8221; y distintos reportes mostraron listados, sitios y contenido armado para que chatbots y buscadores con IA recomienden una marca, un producto o incluso informaci&#243;n falsa.</p><p><strong>El m&#233;todo.</strong> Seg&#250;n el reporte de 404 Media, algunas agencias usan bots o cuentas falsas para <strong>insertar menciones</strong> de marcas en hilos que parecen org&#225;nicos. La estrategia apunta a crear contenido optimizado para AEO, sigla de <strong>Answer Engine Optimization</strong>: el equivalente del SEO, pero pensado para aparecer en respuestas generadas por IA.</p><p><strong>El caso.</strong> En r/biohackers, el problema tom&#243; una dimensi&#243;n m&#225;s sensible porque el subreddit trata temas de suplementos, farmacolog&#237;a experimental, longevidad, p&#233;ptidos y terapias hormonales. Uno de los moderadores dijo a 404 Media que el riesgo es que una empresa poco confiable puede promocionar un producto y alguien puede terminar us&#225;ndolo y lastim&#225;ndose.</p><p><strong>La respuesta.</strong> Reddit dijo a 404 Media que sus equipos de seguridad usan revisi&#243;n humana y herramientas automatizadas para detectar y remover este tipo de contenido, y que tambi&#233;n ofrece herramientas a moderadores para <strong>identificar spammers</strong>. </p><p>Los moderadores se&#241;alan que las campa&#241;as se volvieron m&#225;s sofisticadas y dif&#237;ciles de separar de discusiones reales.</p><h3>Roban cuentas de Instagram a trav&#233;s del bot de soporte</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JqRQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab0af8-e16f-44ea-a408-1da58ae18b8b_1509x892.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JqRQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab0af8-e16f-44ea-a408-1da58ae18b8b_1509x892.png 424w, https://substackcdn.com/image/fetch/$s_!JqRQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab0af8-e16f-44ea-a408-1da58ae18b8b_1509x892.png 848w, https://substackcdn.com/image/fetch/$s_!JqRQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab0af8-e16f-44ea-a408-1da58ae18b8b_1509x892.png 1272w, https://substackcdn.com/image/fetch/$s_!JqRQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab0af8-e16f-44ea-a408-1da58ae18b8b_1509x892.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JqRQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab0af8-e16f-44ea-a408-1da58ae18b8b_1509x892.png" width="1456" height="861" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/25ab0af8-e16f-44ea-a408-1da58ae18b8b_1509x892.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:861,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1229250,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/200151802?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab0af8-e16f-44ea-a408-1da58ae18b8b_1509x892.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!JqRQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab0af8-e16f-44ea-a408-1da58ae18b8b_1509x892.png 424w, https://substackcdn.com/image/fetch/$s_!JqRQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab0af8-e16f-44ea-a408-1da58ae18b8b_1509x892.png 848w, https://substackcdn.com/image/fetch/$s_!JqRQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab0af8-e16f-44ea-a408-1da58ae18b8b_1509x892.png 1272w, https://substackcdn.com/image/fetch/$s_!JqRQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25ab0af8-e16f-44ea-a408-1da58ae18b8b_1509x892.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Reuters</figcaption></figure></div><p>Instagram corrigi&#243; una falla en su chatbot de soporte t&#233;cnico que permiti&#243; <a href="https://www.theguardian.com/technology/2026/jun/01/meta-ai-hack-obama-sephora-instagram">secuestrar cuentas sin acceder al mail real</a> de las v&#237;ctimas. El caso expone un riesgo cada vez m&#225;s relevante: cuando un chatbot puede intervenir en recuperaci&#243;n de cuentas, tambi&#233;n pasa a formar parte de la superficie de ataque.</p><p><strong>Qu&#233; pas&#243;.</strong> <a href="https://techcrunch.com/2026/06/01/hackers-hijacked-instagram-accounts-by-tricking-meta-ai-support-chatbot-into-granting-access/">Seg&#250;n TechCrunch</a>, atacantes lograron enga&#241;ar al chatbot de soporte de Meta para agregar una direcci&#243;n de correo propia durante el proceso de recuperaci&#243;n de contrase&#241;a de Instagram. Con ese mail, recib&#237;an un c&#243;digo de verificaci&#243;n, lo devolv&#237;an al asistente y consegu&#237;an resetear la clave de la cuenta.</p><p><strong>El m&#233;todo.</strong> De acuerdo con videos difundidos en Telegram y X, el ataque no requer&#237;a malware, credenciales robadas ni una vulnerabilidad t&#233;cnica sofisticada. Los atacantes iniciaban el proceso de recuperaci&#243;n, usaban una VPN para parecer ubicados cerca del lugar habitual de la v&#237;ctima y luego abr&#237;an un chat con el asistente de soporte de Meta.</p><p><strong>A qui&#233;nes afect&#243;.</strong> La falla impact&#243; a varios usuarios antes de ser corregida. Entre las cuentas comprometidas estuvieron <a href="https://www.theguardian.com/technology/2026/jun/01/meta-ai-hack-obama-sephora-instagram">la cuenta inactiva de Instagram de la Casa Blanca de Obama</a> y la del Chief Master Sergeant John Bentivegna, de la Fuerza Espacial de Estados Unidos. Seg&#250;n Brian Krebs, ambas fueron brevemente modificadas con contenido proiran&#237;.</p><p><strong>Las fuentes.</strong> TechCrunch inform&#243; que Instagram resolvi&#243; el problema y verific&#243; que el c&#243;digo de recuperaci&#243;n lleg&#243; efectivamente al buz&#243;n p&#250;blico mostrado por el atacante en el video. KrebsOnSecurity report&#243; que las instrucciones para explotar la falla empezaron a circular ampliamente en canales de Telegram el 31 de mayo. La investigaci&#243;n tambi&#233;n menciona reportes previos en Reddit, X, Telegram y c&#237;rculos de seguridad, adem&#225;s de alertas de la researcher Jane Wong y otros usuarios.</p><p><strong>Qu&#233; dijo Meta.</strong> El vocero Andy Stone confirm&#243; el lunes que la vulnerabilidad fue corregida y que las cuentas afectadas estaban siendo aseguradas. La compa&#241;&#237;a no inform&#243; cu&#225;ntos usuarios fueron impactados.</p><p>Check Point Research public&#243; un buen <em><a href="https://blog.checkpoint.com/ai-security/the-meta-ai-account-recovery-incident-wasnt-just-a-chatbot-problem/">write-up</a></em>.</p><h3>Valve enfrenta una demanda antimonopolio</h3><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pn3B!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0330788-dd4f-43dc-8a00-7586c6b92543_898x645.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pn3B!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0330788-dd4f-43dc-8a00-7586c6b92543_898x645.png 424w, https://substackcdn.com/image/fetch/$s_!pn3B!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0330788-dd4f-43dc-8a00-7586c6b92543_898x645.png 848w, https://substackcdn.com/image/fetch/$s_!pn3B!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0330788-dd4f-43dc-8a00-7586c6b92543_898x645.png 1272w, https://substackcdn.com/image/fetch/$s_!pn3B!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0330788-dd4f-43dc-8a00-7586c6b92543_898x645.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pn3B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0330788-dd4f-43dc-8a00-7586c6b92543_898x645.png" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a0330788-dd4f-43dc-8a00-7586c6b92543_898x645.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:null,&quot;width&quot;:null,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:636973,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/200151802?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0330788-dd4f-43dc-8a00-7586c6b92543_898x645.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!pn3B!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0330788-dd4f-43dc-8a00-7586c6b92543_898x645.png 424w, https://substackcdn.com/image/fetch/$s_!pn3B!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0330788-dd4f-43dc-8a00-7586c6b92543_898x645.png 848w, https://substackcdn.com/image/fetch/$s_!pn3B!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0330788-dd4f-43dc-8a00-7586c6b92543_898x645.png 1272w, https://substackcdn.com/image/fetch/$s_!pn3B!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa0330788-dd4f-43dc-8a00-7586c6b92543_898x645.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a><figcaption class="image-caption">Gabe Newell, CEO y fundador de Valve. Foto: Valve</figcaption></figure></div><p>Una demanda antimonopolio <a href="https://www.eurogamer.net/valve-antitrust-lawsuits-ubisoft-warner-bros-report">acus&#243; a </a><strong><a href="https://www.eurogamer.net/valve-antitrust-lawsuits-ubisoft-warner-bros-report">Valve</a></strong> por &#8220;usar su posici&#243;n dominante&#8221; para impedir que los desarrolladores ofrezcan precios m&#225;s baratos en otras tiendas digitales por fuera de Steam.</p><p><strong>Qu&#233; pas&#243;.</strong> Seg&#250;n documentos judiciales <a href="https://www.bloomberg.com/news/features/2026-06-01/valve-s-antitrust-reckoning-over-steam-has-echoes-of-apple-google-app-store-sui">citados por Bloomberg</a>, Valve habr&#237;a presionado a estudios y <em>publishers</em> para mantener paridad de precios entre Steam y otras plataformas. La acusaci&#243;n aparece en una demanda impulsada por desarrolladores independientes, que sostienen que la compa&#241;&#237;a limita la competencia en el mercado de videojuegos para PC.</p><p><strong>El caso Ubisoft.</strong> Uno de los ejemplos mencionados involucra a <strong>Rainbow Six Siege</strong>. Ubisoft ofrec&#237;a en Uplay un Starter Pack de 15 d&#243;lares que no estaba disponible en Steam, donde la opci&#243;n m&#225;s barata era m&#225;s cara. Seg&#250;n la demanda, Valve habr&#237;a amenazado con retirar todas las ediciones del juego de Steam si Ubisoft no correg&#237;a la diferencia &#8220;hasta el final del d&#237;a siguiente&#8221;.</p><p><strong>Por qu&#233; importa.</strong> Steam es la tienda dominante de juegos para PC y cobra una comisi&#243;n que hist&#243;ricamente lleg&#243; al 30%. Si Valve impide que los juegos sean m&#225;s baratos en otras plataformas, los desarrolladores pierden margen para competir por precio y <strong>los usuarios terminan con menos opciones</strong> reales fuera de Steam.</p><p>Valve ya hab&#237;a enfrentado acusaciones similares por presunto abuso de posici&#243;n dominante. </p><h3>Microsoft quiere que sus usuarios sean &#8220;adictos&#8221; a la IA</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IHoG!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef00b392-b8b2-409e-bbb3-0c538bb2400e_1618x896.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IHoG!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef00b392-b8b2-409e-bbb3-0c538bb2400e_1618x896.png 424w, https://substackcdn.com/image/fetch/$s_!IHoG!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef00b392-b8b2-409e-bbb3-0c538bb2400e_1618x896.png 848w, https://substackcdn.com/image/fetch/$s_!IHoG!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef00b392-b8b2-409e-bbb3-0c538bb2400e_1618x896.png 1272w, https://substackcdn.com/image/fetch/$s_!IHoG!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef00b392-b8b2-409e-bbb3-0c538bb2400e_1618x896.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IHoG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef00b392-b8b2-409e-bbb3-0c538bb2400e_1618x896.png" width="1456" height="806" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef00b392-b8b2-409e-bbb3-0c538bb2400e_1618x896.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:806,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:655533,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/200151802?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef00b392-b8b2-409e-bbb3-0c538bb2400e_1618x896.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IHoG!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef00b392-b8b2-409e-bbb3-0c538bb2400e_1618x896.png 424w, https://substackcdn.com/image/fetch/$s_!IHoG!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef00b392-b8b2-409e-bbb3-0c538bb2400e_1618x896.png 848w, https://substackcdn.com/image/fetch/$s_!IHoG!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef00b392-b8b2-409e-bbb3-0c538bb2400e_1618x896.png 1272w, https://substackcdn.com/image/fetch/$s_!IHoG!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef00b392-b8b2-409e-bbb3-0c538bb2400e_1618x896.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Satya Nadella, en la presentaci&#243;n de Scout. Foto: Microsoft</figcaption></figure></div><p><strong>Microsoft</strong> anunci&#243; <a href="https://news.microsoft.com/source/latam/noticias-de-microsoft/microsoft-scout-de-proyecto-personal-a-agente-personal-listo-para-empresas/">Scout</a>, un asistente personal de IA integrado a Microsoft 365. Seg&#250;n <a href="https://www.theinformation.com/briefings/exclusive-nadella-rebukes-microsoft-executives-plan-make-users-addicted-ai-agents">documentos internos</a>, una de las primeras metas del proyecto era &#8220;hacer adictos&#8221; a los usuarios.</p><p><strong>Qu&#233; pas&#243;.</strong> Scout es la versi&#243;n p&#250;blica de <strong>ClawPilot</strong>, una herramienta que Microsoft ven&#237;a probando internamente desde marzo con m&#225;s de 1.000 empleados, incluido Satya Nadella. El producto forma parte de Project Lobster, una iniciativa para llevar agentes basados en <strong>OpenClaw a usuarios sin perfil t&#233;cnico</strong>.</p><p><strong>El plan.</strong> El documento interno describe &#8220;tres fases desde una app adictiva hasta una plataforma ag&#233;ntica&#8221;. La primera fase aparece formulada como <em><strong>Make people addicted</strong></em>. El objetivo era mantener una experiencia separada, hacer crecer la base de usuarios y construir un ecosistema de habilidades y herramientas que llevara a la dependencia diaria.</p><p><strong>Por qu&#233; importa.</strong> Scout est&#225; pensado como un agente &#8220;always-on&#8221; que se sienta al lado del usuario, aprende c&#243;mo trabaja y act&#250;a en su nombre. Puede gestionar calendario, filtrar la bandeja de entrada, preparar reuniones, presentar gastos y ejecutar workflows recurrentes. </p><p>Seg&#250;n otro documento interno, <strong>&#8220;toma acciones en un escritorio real&#8221;</strong> y sigue trabajando aunque el usuario no lo est&#233; mirando.</p><p><strong>Entre l&#237;neas.</strong> Lo m&#225;s pol&#233;mico va m&#225;s all&#225; de la palabra &#8220;adicci&#243;n&#8221; y tiene que ver con que este tipo de agentes necesita acceso a cuentas, archivos, correo, calendario y flujos de trabajo para operar. </p><p>El propio documento marca que <strong>seguridad y compliance siguen siendo temas a resolver.</strong></p><p><strong>El contexto.</strong> Microsoft viene empujando IA en casi todos sus productos, con resultados negativos. Copilot fue uno de sus grandes avances en el sector, pero la integraci&#243;n de herramientas de IA en Windows tambi&#233;n <strong>gener&#243; rechazo de usuarios.</strong></p><h3>Estados Unidos: Donald Trump ahora quiere regular a los LLM</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LsC4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12852415-b995-4c61-9137-18b66a1d75b2_1319x890.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LsC4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12852415-b995-4c61-9137-18b66a1d75b2_1319x890.png 424w, https://substackcdn.com/image/fetch/$s_!LsC4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12852415-b995-4c61-9137-18b66a1d75b2_1319x890.png 848w, https://substackcdn.com/image/fetch/$s_!LsC4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12852415-b995-4c61-9137-18b66a1d75b2_1319x890.png 1272w, https://substackcdn.com/image/fetch/$s_!LsC4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12852415-b995-4c61-9137-18b66a1d75b2_1319x890.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LsC4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12852415-b995-4c61-9137-18b66a1d75b2_1319x890.png" width="1319" height="890" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/12852415-b995-4c61-9137-18b66a1d75b2_1319x890.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:890,&quot;width&quot;:1319,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1641894,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/200151802?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12852415-b995-4c61-9137-18b66a1d75b2_1319x890.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LsC4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12852415-b995-4c61-9137-18b66a1d75b2_1319x890.png 424w, https://substackcdn.com/image/fetch/$s_!LsC4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12852415-b995-4c61-9137-18b66a1d75b2_1319x890.png 848w, https://substackcdn.com/image/fetch/$s_!LsC4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12852415-b995-4c61-9137-18b66a1d75b2_1319x890.png 1272w, https://substackcdn.com/image/fetch/$s_!LsC4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F12852415-b995-4c61-9137-18b66a1d75b2_1319x890.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">AP</figcaption></figure></div><p>Trump firm&#243; una orden ejecutiva <a href="https://www.nytimes.com/2026/06/02/technology/trump-executive-order-ai.html">para que las compa&#241;&#237;as de IA compartan nuevos modelos con el Gobierno</a> antes de lanzarlos al p&#250;blico. Es el giro m&#225;s claro de la Casa Blanca hacia una supervisi&#243;n formal de la tecnolog&#237;a.</p><p><strong>Qu&#233; pas&#243;.</strong> La orden crea un sistema voluntario para que los laboratorios de IA den al Gobierno <strong>hasta 30 d&#237;as de acceso previo</strong> a sus modelos. </p><p><strong>El cambio</strong>. La versi&#243;n anterior contemplaba una revisi&#243;n de hasta 90 d&#237;as, pero Trump la fren&#243; tras objeciones de David Sacks, ex PayPal, de IA de la administraci&#243;n. El texto avanz&#243; despu&#233;s de que el plazo se redujera a 30 d&#237;as.</p><p><strong>Por qu&#233; importa.</strong> La medida marca <strong>un cambio</strong> respecto del enfoque m&#225;s desregulado que Trump hab&#237;a tomado para impulsar a las empresas estadounidenses frente a China. La Casa Blanca intenta mantener ese apoyo a la industria, pero con m&#225;s control sobre <strong>modelos capaces de encontrar fallas</strong> de seguridad sensibles.</p><p><strong>La reacci&#243;n.</strong> Ejecutivos de <strong>Microsoft, OpenAI, Google</strong> y otras compa&#241;&#237;as apoyaron la orden como un intento de equilibrar innovaci&#243;n y seguridad. En paralelo, parte del sector teme que el esquema derive en controles m&#225;s estrictos o demore el desarrollo.</p><p><strong>Entre l&#237;neas.</strong> <a href="https://www.nytimes.com/2026/06/03/business/dealbook/trump-ai-pivot.html">El newsletter del NYT DealBook</a> explic&#243; el cambio como resultado de una mezcla de presi&#243;n pol&#237;tica, preocupaci&#243;n p&#250;blica y avances t&#233;cnicos. El detonante fue Mythos, un modelo de Anthropic capaz de detectar debilidades en sistemas de bancos, gobiernos y otras organizaciones. A eso se sum&#243; una investigaci&#243;n de la Universidad de Toronto sobre un sistema creado con IA para explotar fallas conocidas. </p><p>Incluso una Casa Blanca cercana a Silicon Valley empez&#243; a ver que los modelos m&#225;s potentes necesitan alg&#250;n nivel de supervisi&#243;n estatal.</p><div><hr></div><h4><strong>&#128275; Breaches y hacks</strong></h4><ul><li><p>Roban miles de sitios con <a href="https://www.bleepingcomputer.com/news/security/hackers-hijack-thousands-of-sites-for-clickfix-and-fakeupdate-attacks/">ClickFix y FakeUpdates</a></p></li><li><p>Comprometen <a href="https://www.bleepingcomputer.com/news/security/red-hat-npm-packages-compromised-to-steal-developer-credentials/">paquetes npm de Red Hat</a> para robar credenciales</p></li><li><p><a href="https://status.dashlane.com/pages/incident/5aabcb89fccc4b04d3774443/6a1c519ceac9dc05ffa1f526">Dashlane</a> sufre un ataque de fuerza bruta que afecta la privacidad de las contrase&#241;as</p></li></ul><h4><strong>&#128274; Ransomware</strong></h4><ul><li><p><a href="https://www.halcyon.ai/ransomware-research-reports/threat-assessment-the-gentlemen-ransomware-group">The Gentlemen</a> lleva la delantera en v&#237;ctimas</p></li><li><p>Los afiliados de ransomware operan durante las <a href="https://securityaffairs.com/192969/cyber-crime/ransomware-operators-keep-business-hours-the-data-proves-it.html">horas de oficina</a></p></li><li><p>Reporte: por qu&#233; la <a href="https://securityaffairs.com/192550/cyber-crime/why-pure-extortion-is-replacing-traditional-ransomware.html">extorsi&#243;n sin cifrado</a> reemplaza al ransomware tradicional</p></li></ul><h4><strong>&#128163; Exploits y malware</strong></h4><ul><li><p>Un nuevo malware usa los <a href="https://hackread.com/wordpress-malware-steam-profile-comments-instructions/">comentarios de Steam</a> como C2</p></li><li><p>Falsas alertas de virus invaden <a href="https://www.malwarebytes.com/blog/mobile/2026/06/fake-virus-alerts-are-invading-mobile-games">juegos m&#243;viles</a></p></li><li><p>Explotan vulnerabilidades de <a href="https://www.securityweek.com/wp-maps-pro-vulnerability-exploited-to-take-over-wordpress-sites/">WP Maps Pro</a></p></li></ul><h4><strong>&#128269; Threat intel y vulnerabilidades</strong></h4><ul><li><p>Arrestan a 29 operadores de <a href="https://securityaffairs.com/193099/cyber-crime/29-arrests-nine-crime-groups-dismantled-another-blow-to-illegal-streaming.html">sitios de streaming ilegales</a></p></li><li><p>Un nuevo DoS <a href="https://www.bleepingcomputer.com/news/security/new-http-2-bomb-dos-attack-crashes-web-servers-in-under-a-minute/">&#8220;HTTP/2 Bomb&#8221;</a> da de baja servidores en menos de un minuto</p></li><li><p>Lazarus abusa de <a href="https://hackread.com/lazarus-group-npm-brandjacking-target-developers/">paquetes npm</a> para apuntar a desarrolladores</p></li></ul><h4><strong>&#128736;&#65039; Tools y updates</strong></h4><ul><li><p><a href="https://www.securityweek.com/android-update-patches-exploited-zero-day-123-other-vulnerabilities/">Android parchea</a> un zero day y 123 vulnerabilidades</p></li><li><p>Anthropic <a href="https://cyberscoop.com/anthropic-project-glasswing-expansion-critical-infrastructure-claude-mythos/">suma 150 empresas</a> a su Project Glasswing</p></li><li><p>Parchean un bug cr&#237;tico de <a href="https://securityaffairs.com/193142/hacking/critical-cisco-unified-cm-bug-patched-as-public-exploit-code-emerges.html">Unified CM de Cisco</a></p></li></ul><h4><strong>&#128203; Privacidad y regulaciones</strong></h4><ul><li><p>23andMe, la empresa de testeos gen&#233;ticos, <a href="https://oag.ca.gov/news/press-releases/attorney-general-bonta-sues-chrome-holding-co-formerly-known-23andme-over-2023">demandada</a> por el breach de 2023</p></li><li><p><a href="https://www.theguardian.com/technology/2026/jun/01/florida-lawsuit-openai-sam-altman">Demanda contra OpenAI</a> en Florida por &#8220;poner a los ni&#241;os en riesgo&#8221;</p></li><li><p>Un reporte muestra que la moderaci&#243;n en redes sociales es <a href="https://www.appealscentre.eu/transparency-report-shows-big-increase-in-users-challenging-social-media-decisions/">poco eficiente</a></p><p></p></li></ul><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial generativa para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/internet-muerto-contaminan-reddit-influir-resultados-chatgpt-google?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/internet-muerto-contaminan-reddit-influir-resultados-chatgpt-google?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Más de 142 mil despidos en tech, mientras datos de Microsoft sugieren que usar IA es más caro que contratar]]></title><description><![CDATA[Adem&#225;s: pol&#233;mica con un researcher que public&#243; varios zero days, Grandoreiro sigue muy activo en Am&#233;rica Latina y advierten sobre sitios falsos y estafas con el Mundial 2026.]]></description><link>https://www.brodersendarknews.com/p/mas-de-142-mil-despidos-en-tech-microsoft-datos-ia</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/mas-de-142-mil-despidos-en-tech-microsoft-datos-ia</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Fri, 29 May 2026 11:19:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!czxU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb92357-8028-41e3-900e-865894c0d32d_1672x1123.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>22~29<br>may</h1><h2><strong>&#9889;TL;DR</strong></h2><p>Ya dije que, por momentos, el newsletter se me est&#225; transformando en <strong>AI News</strong>. No es algo que me guste del todo, pero los problemas que est&#225; trayendo la aplicaci&#243;n masiva de inteligencia artificial, en mi opini&#243;n, ya son muy visibles como para ser ignorados.</p><p>Por esto, le&#237; algunas noticias y tuits que me parec&#237;an interesantes para cruzarlos como <em>lead</em> de esta edici&#243;n. Ac&#225; va.</p><p>Esta semana, algunas noticias pusieron sobre la mesa lo que ya <strong>est&#225; a la vista</strong>: echar trabajadores para reemplazarlos por IA es una ilusi&#243;n que ya empieza a mostrar sus costuras. </p><p><strong>Sam Altman</strong>, CEO y cofundador de OpenAI, <a href="https://x.com/Vivek4real_/status/2059058179955380493">dijo que</a> ve a la IA &#8220;como una utilidad, como la electricidad o el agua&#8221;, que vamos a terminar pagando por consumo, pero que <strong>funciona para todas las empresas que hoy juegan el juego de la IA. </strong>Cruc&#233; <strong><a href="https://x.com/alex_prompter/status/2059240459222868479?s=20">un tuit</a></strong> que traz&#243; una <em>timeline</em> de lo que ser&#237;a la <em><a href="https://encyclopaedia.herdereditorial.com/wiki/Recurso:Nietzsche:_historia_de_un_error">Historia de un error</a></em>, a la Nietzsche. Lo reproduzco, traducido:</p><blockquote><p><em>D&#233;jenme reconstruir la l&#237;nea de tiempo, porque nadie la est&#225; conectando.</em></p><p><em><strong>Paso 1:</strong> scrapear todo internet. Cada libro, cada art&#237;culo, cada conversaci&#243;n, cada obra de arte, cada posteo en foros. Hacerlo sin pedir permiso. Hacerlo sin pagar.</em></p><p><em><strong>Paso 2:</strong> entrenar un modelo con todo eso. Llamarlo &#8220;inteligencia artificial&#8221;.</em></p><p><em><strong>Paso 3:</strong> ir al <a href="https://www.blackrock.com/corporate/insights/2026-infrastructure-summit">Infrastructure Summit de BlackRock</a> y anunciar: &#8220;Vemos un futuro en el que la inteligencia sea un servicio b&#225;sico, como la electricidad o el agua, y la gente nos la compre con medidor&#8221;.</em></p><p><em>El paso 3 es donde le venden a la gente su propio conocimiento. <strong>Con medidor.</strong></em></p><p><em>Tomaron la producci&#243;n colectiva del pensamiento humano, la comprimieron en un modelo y ahora quieren cobrarte por token para acceder a una versi&#243;n de lo que vos y todos los que conoc&#233;s ya crearon.</em></p><p><em>Un usuario de Reddit lo resumi&#243; perfecto: &#8220;Nos robaron todos estos datos a nosotros, la gente, el trabajo de nuestras vidas, nuestra creatividad, nuestro arte, devorando internet y pasando por encima de todas las leyes de copyright. Ahora quieren vend&#233;rnoslo de vuelta en forma de servicio b&#225;sico&#8221;.</em></p><p><em>Imaginate que alguien fotocopia todos los libros de una biblioteca p&#250;blica, quema la biblioteca y despu&#233;s abre un servicio de suscripci&#243;n para acceder a las copias.</em></p><p><em><strong>Ese es el modelo de negocio de la inteligencia medida por consumo.</strong></em></p><p><em>Y se lo est&#225;n vendiendo a inversores en infraestructura como si hubieran inventado el agua.</em></p></blockquote><p>Es interesante porque pareciera que el capitalismo est&#225; mostrando otra de sus contradicciones internas y demuestra, una vez m&#225;s, que <strong>trae consigo mismo el germen de su destrucci&#243;n</strong>: hoy, <a href="https://www.reuters.com/business/anthropic-raises-65-billion-now-valued-965-billion-2026-05-28/">las inversiones</a> van hacia dos empresas que <strong>est&#225;n pulverizando el copyright.</strong></p><p>Hubo otra cr&#237;tica, ya en el plano de los datos concretos: <strong><a href="https://www.removepaywall.com/search?url=https://fortune.com/2026/05/22/microsoft-ai-cost-problem-tokens-agents/">The Verge</a></strong><a href="https://www.removepaywall.com/search?url=https://fortune.com/2026/05/22/microsoft-ai-cost-problem-tokens-agents/"> public&#243;</a> una investigaci&#243;n sobre c&#243;mo Microsoft cancel&#243; la mayor&#237;a de sus licencias directas de Claude Code y redirigi&#243; empleados hacia GitHub Copilot CLI. </p><p>El tema fue recogido por Yahoo Finance y Fortune: <strong>echar gente y usar IA, ahora, es m&#225;s caro que contratar</strong>. </p><p>&#191;C&#243;mo se explica esto? En parte, <a href="https://x.com/escanorreloaded/status/2059637607403831732?s=46&amp;t=irLyryAdJlqZG0t2F4iu_g">as&#237;</a>:</p><blockquote><p><em>Los CEOs est&#225;n empezando a darse cuenta, en silencio, de que el plan de reemplazar empleados con IA <strong>tiene un problema.</strong></em></p><p><em>En realidad, dos.</em></p><p><em>Uno: los costos en tokens para operar agentes de IA <strong>ya est&#225;n superando lo que pagaban</strong> por los empleados que echaron.</em></p><p><em>Dos: cuando se agotan los tokens, la IA se detiene. <strong>Se detiene y punto. Sin continuidad.</strong> Sin plan alternativo. Solo una ruedita girando donde antes estaba tu fuerza laboral.</em></p><p><em>Echaste humanos para ahorrar plata y compraste una suscripci&#243;n que te factura hasta dejarte contra la pared.</em></p><p><em>Los empleados que dejaste ir sab&#237;an qu&#233; hacer cuando algo se romp&#237;a.</em></p><p><em>La IA simplemente te factura por la ca&#237;da del servicio.</em></p><p><em>Y despu&#233;s est&#225; el problema de los permisos, del que nadie quiere hablar.</em></p><p><em>Para hacer su trabajo, el agente de IA necesita acceso. <strong>Acceso completo. A tus sistemas, tus patentes, tus contratos, tus planes futuros</strong>. Todo lo que pasaste a&#241;os construyendo, entregado a un proceso que no tiene lealtad, discreci&#243;n ni nada en juego.</em></p><p><em>No contrataste un reemplazo.</em></p><p><em>Le diste las llaves de todo lo que ten&#233;s a un extra&#241;o sin alma.</em></p><p><em>Que lo disfrutes.</em></p></blockquote><p>Hay, para todo este tema, <a href="https://www.trueup.io/layoffs">un tracker</a> de despidos en tech, en un mundo donde hasta <strong>el Papa cuestion&#243;</strong> la falta de regulaci&#243;n en el mundo de la IA. Y Microsoft ya advirti&#243; que es m&#225;s caro usar IA que contratar empleados.</p><p>Pasando a otros temas de la semana, precisamente, Microsoft <a href="https://www.tomshardware.com/tech-industry/cyber-security/microsofts-github-bans-security-researcher-who-posted-zero-day-windows-exploits-because-company-ruined-their-life-expert-claims-action-is-vindictive-and-promises-further-retaliation">protagoniz&#243; una pol&#233;mica</a> muy de nicho, pero que hizo ruido en el ambiente: se enfrent&#243; a un researcher que public&#243;, en GitHub primero y en GitLab despu&#233;s, <strong>varios zero days</strong>. </p><p>En el mundo del malware, una nueva campa&#241;a del troyano bancario Grandoreiro volvi&#243; con fuerza en Am&#233;rica Latina. A nivel t&#233;cnico, encontr&#233; un research interesante que dice que los sitios web ahora pueden ver el tr&#225;fico web de un browser a trav&#233;s del SSD. Y la <strong>Copa del Mundo</strong> ya est&#225; generando una enorme cantidad de sitios falsos y fraude.</p><p>La perlita de la semana es para quienes usan <strong>DuckDuckGo</strong>: el buscador vio <strong><a href="https://www.xataka.com/robotica-e-ia/buscador-google-esta-matando-enlaces-azules-asi-que-cada-vez-usuarios-estan-encontrando-refugio-duckduckgo">un crecimiento del 30%</a></strong> en sus descargas despu&#233;s de que Google llenara su motor de b&#250;squeda con basura IA.</p><div><hr></div><p><em>En esta edici&#243;n:</em></p><ul><li><p>&#128188; <em><a href="https://www.brodersendarknews.com/i/199246943/mas-de-142-mil-despidos-en-tech-mientras-datos-de-microsoft-sugieren-que-usar-ia-es-mas-caro-que-contratar">M&#225;s de 142 mil despidos en tech, mientras datos de Microsoft sugieren que usar IA es m&#225;s caro que contratar</a></em></p></li><li><p>&#128126; <em><a href="https://www.brodersendarknews.com/i/199246943/microsoft-enfrenta-a-un-investigador-por-la-publicacion-de-zero-days">Microsoft enfrenta a un investigador por la publicaci&#243;n de zero-days</a></em></p></li><li><p>&#127974; <em><a href="https://www.brodersendarknews.com/i/199246943/grandoreiro-sigue-activo-en-america-latina">Grandoreiro sigue muy activo en Am&#233;rica Latina</a></em></p></li><li><p>&#129482; <em><a href="https://www.brodersendarknews.com/i/199246943/frost-la-tecnica-que-usa-el-ssd-para-espiar-actividad-desde-el-navegador">FROST, la t&#233;cnica que usa el SSD para espiar actividad desde el navegador</a></em></p></li><li><p>&#9917;<em> <a href="https://www.brodersendarknews.com/i/199246943/advierten-sobre-sitios-falsos-del-mundial-fifa-2026">Advierten sobre sitios falsos del Mundial FIFA 2026</a></em></p></li></ul><div><hr></div><p>&#9200; <em>Substack dice que leer este correo completo lleva 15 minutos</em></p><p><em>Dark News #205</em></p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><p><strong>CYBER SUMMIT</strong> es el punto de encuentro l&#237;der en Am&#233;rica Latina para profesionales, empresas, gobiernos y organizaciones tecnol&#243;gicas que est&#225;n transformando el futuro de la seguridad tecnol&#243;gica. Nuestra misi&#243;n es <strong>unir a las comunidades globales</strong> para construir un mundo digital y operacional m&#225;s seguro. Inscripci&#243;n, <a href="https://cybersummit.io/industrial-cybersummit-argentina-2026/">en este enlace</a>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://cybersummit.io/industrial-cybersummit-argentina-2026/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KFeQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc14cc94-3660-422c-8074-4819722edc25_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!KFeQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc14cc94-3660-422c-8074-4819722edc25_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!KFeQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc14cc94-3660-422c-8074-4819722edc25_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!KFeQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc14cc94-3660-422c-8074-4819722edc25_1200x600.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KFeQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc14cc94-3660-422c-8074-4819722edc25_1200x600.png" width="1200" height="600" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fc14cc94-3660-422c-8074-4819722edc25_1200x600.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:600,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:435867,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://cybersummit.io/industrial-cybersummit-argentina-2026/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/199246943?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc14cc94-3660-422c-8074-4819722edc25_1200x600.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!KFeQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc14cc94-3660-422c-8074-4819722edc25_1200x600.png 424w, https://substackcdn.com/image/fetch/$s_!KFeQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc14cc94-3660-422c-8074-4819722edc25_1200x600.png 848w, https://substackcdn.com/image/fetch/$s_!KFeQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc14cc94-3660-422c-8074-4819722edc25_1200x600.png 1272w, https://substackcdn.com/image/fetch/$s_!KFeQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffc14cc94-3660-422c-8074-4819722edc25_1200x600.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></div><h3>M&#225;s de 142 mil despidos en tech, mientras datos de Microsoft sugieren que usar IA es m&#225;s caro que contratar</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!czxU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb92357-8028-41e3-900e-865894c0d32d_1672x1123.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!czxU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb92357-8028-41e3-900e-865894c0d32d_1672x1123.png 424w, https://substackcdn.com/image/fetch/$s_!czxU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb92357-8028-41e3-900e-865894c0d32d_1672x1123.png 848w, https://substackcdn.com/image/fetch/$s_!czxU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb92357-8028-41e3-900e-865894c0d32d_1672x1123.png 1272w, https://substackcdn.com/image/fetch/$s_!czxU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb92357-8028-41e3-900e-865894c0d32d_1672x1123.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!czxU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb92357-8028-41e3-900e-865894c0d32d_1672x1123.png" width="1456" height="978" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bdb92357-8028-41e3-900e-865894c0d32d_1672x1123.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:978,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1955352,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/199246943?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb92357-8028-41e3-900e-865894c0d32d_1672x1123.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!czxU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb92357-8028-41e3-900e-865894c0d32d_1672x1123.png 424w, https://substackcdn.com/image/fetch/$s_!czxU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb92357-8028-41e3-900e-865894c0d32d_1672x1123.png 848w, https://substackcdn.com/image/fetch/$s_!czxU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb92357-8028-41e3-900e-865894c0d32d_1672x1123.png 1272w, https://substackcdn.com/image/fetch/$s_!czxU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbdb92357-8028-41e3-900e-865894c0d32d_1672x1123.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Satya Nadella, CEO de Microsoft. Foto: AFP</figcaption></figure></div><p>Los despidos en el sector tech <strong><a href="https://tech.yahoo.com/general/article/tech-layoffs-2026-update-over-142000-people-have-been-laid-off-from-meta-linkedin-cisco-and-more-144545654.html">ya superan los 142.000 en 2026</a></strong>, mientras crece una tensi&#243;n en la industria: la IA promete ahorrar costos, pero <strong>usarla a escala tambi&#233;n empieza a volverse caro.</strong></p><p><strong>Qu&#233; pas&#243;</strong>. Seg&#250;n Yahoo Finance, marzo fue el mes m&#225;s duro y varias empresas vincularon los recortes con <strong>inversi&#243;n en IA</strong>, automatizaci&#243;n o nuevos perfiles t&#233;cnicos.</p><p><strong>La lista.</strong> <strong>Meta</strong> recort&#243; cerca de 8.000 puestos y cerr&#243; 6.000 vacantes para liberar margen hacia inversi&#243;n en IA. <strong>Intuit</strong> elimin&#243; 3.000 empleos, el 17% de su plantilla, con el foco puesto en integrar IA en sus servicios. <strong>Cloudflare</strong> despidi&#243; a m&#225;s de 1.100 empleados en una reestructuraci&#243;n pensada para la &#8220;era de la IA ag&#233;ntica&#8221;. <strong>PayPal</strong>, en tanto, proyecta recortar unos 4.800 puestos en los pr&#243;ximos a&#241;os para eliminar capas internas y acelerar automatizaci&#243;n. <a href="https://www.trueup.io/layoffs">La lista sigue</a>.</p><p><strong>Cisco, LinkedIn, Coinbase, Snap, Atlassian, Amazon, Oracle y Microsoft</strong> tambi&#233;n avanzaron con recortes, reorganizaciones o retiros voluntarios, en un sector que sigue achicando equipos mientras redirige capital hacia infraestructura, productos y operaciones basadas en IA.</p><p><strong>Por qu&#233; importa.</strong> La narrativa dominante de Silicon Valley presenta a la IA como una herramienta para hacer m&#225;s con menos. La lista muestra otra din&#225;mica: empresas que recortan empleo para financiar IA, reorganizar estructuras y concentrar recursos en <strong>&#225;reas</strong> <strong>estrat&#233;gicas.</strong></p><p><strong>El contraste.</strong> Microsoft <a href="https://finance.yahoo.com/sectors/technology/articles/microsoft-data-suggests-using-ai-225900743.html">acaba de recortar la mayor&#237;a de sus licencias directas de Claude Code</a>, apenas meses despu&#233;s de impulsar su uso interno. Seg&#250;n <a href="https://fortune.com/2026/05/22/microsoft-ai-cost-problem-tokens-agents/">Fortune</a>, citando a <a href="https://www.theverge.com/ai-artificial-intelligence/917380/ai-monetization-anthropic-openai-token-economics-revenue">The Verge</a>, la empresa empez&#243; a redirigir a sus empleados hacia GitHub Copilot CLI. El uso masivo de herramientas de IA dentro de una compa&#241;&#237;a tambi&#233;n puede volverse dif&#237;cil de justificar por costo.</p><p>La pregunta es cu&#225;nto cuesta sostener la IA cuando deja de ser prueba piloto y empieza a usarse todos los d&#237;as, por miles de empleados, en tareas intensivas.</p><p><strong>Qu&#233; mirar.</strong> Si la factura de c&#243;mputo sigue creciendo, las empresas pueden avanzar hacia accesos m&#225;s limitados, aprobaciones por &#225;rea, topes de uso y despliegues m&#225;s selectivos. </p><p>El costo real de usar IA a escala empieza a entrar en el c&#225;lculo laboral y, ahora, <strong>se est&#225; planteando que los n&#250;meros no cierran</strong>.</p><h3>Microsoft enfrenta a un investigador por la publicaci&#243;n de zero-days </h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!uXjW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfbac0af-4bc1-40bb-a149-a4e12cfdf8af_1083x574.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!uXjW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfbac0af-4bc1-40bb-a149-a4e12cfdf8af_1083x574.png 424w, https://substackcdn.com/image/fetch/$s_!uXjW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfbac0af-4bc1-40bb-a149-a4e12cfdf8af_1083x574.png 848w, https://substackcdn.com/image/fetch/$s_!uXjW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfbac0af-4bc1-40bb-a149-a4e12cfdf8af_1083x574.png 1272w, https://substackcdn.com/image/fetch/$s_!uXjW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfbac0af-4bc1-40bb-a149-a4e12cfdf8af_1083x574.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!uXjW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfbac0af-4bc1-40bb-a149-a4e12cfdf8af_1083x574.png" width="1083" height="574" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/bfbac0af-4bc1-40bb-a149-a4e12cfdf8af_1083x574.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:574,&quot;width&quot;:1083,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:511245,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/199246943?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfbac0af-4bc1-40bb-a149-a4e12cfdf8af_1083x574.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!uXjW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfbac0af-4bc1-40bb-a149-a4e12cfdf8af_1083x574.png 424w, https://substackcdn.com/image/fetch/$s_!uXjW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfbac0af-4bc1-40bb-a149-a4e12cfdf8af_1083x574.png 848w, https://substackcdn.com/image/fetch/$s_!uXjW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfbac0af-4bc1-40bb-a149-a4e12cfdf8af_1083x574.png 1272w, https://substackcdn.com/image/fetch/$s_!uXjW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbfbac0af-4bc1-40bb-a149-a4e12cfdf8af_1083x574.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Imagen: GitHub</figcaption></figure></div><p>Microsoft sali&#243; a criticar las divulgaciones p&#250;blicas de vulnerabilidades zero-day sin coordinaci&#243;n previa, despu&#233;s de que <strong><a href="https://thehackernews.com/2026/05/microsoft-slams-public-zero-day.html">varias fallas en Windows fueran publicadas</a></strong> por un investigador y algunas empezaran a ser explotadas.</p><p><strong>Qu&#233; pas&#243;.</strong> La compa&#241;&#237;a defendi&#243; el modelo de <em>Coordinated Vulnerability Disclosure</em>, o CVD: que los investigadores reporten primero las fallas al proveedor afectado, le den tiempo para analizarlas y reci&#233;n despu&#233;s las hagan p&#250;blicas.</p><p><strong>El caso.</strong> La discusi&#243;n se aceler&#243; por las publicaciones de <strong>Chaotic Eclipse</strong>, tambi&#233;n conocido como Nightmare-Eclipse, que divulg&#243; detalles de varias vulnerabilidades zero-day en componentes de Windows, incluidos <strong>Defender y BitLocker</strong>. Seg&#250;n Microsoft, esos detalles no fueron compartidos antes con la empresa.</p><p><strong>Por qu&#233; importa.</strong> Microsoft sostiene que publicar pruebas de concepto o detalles t&#233;cnicos de fallas sin parche puede poner a usuarios y empresas en riesgo inmediato. </p><p>Tres de las vulnerabilidades divulgadas, BlueHammer, RedSun y UnDefend, ya habr&#237;an sido explotadas activamente despu&#233;s de hacerse p&#250;blicas.</p><p><strong>El conflicto.</strong> El investigador afirma que <strong>intent&#243; comunicarse con Microsoft</strong>, pero que el proceso de reporte fall&#243;. Tambi&#233;n denunci&#243; que la empresa elimin&#243; la cuenta de Microsoft que usaba para reportar bugs y que luego GitHub baj&#243; su cuenta. </p><p>El c&#243;digo de explotaci&#243;n fue subido despu&#233;s a GitLab, pero esa cuenta tambi&#233;n termin&#243; bloqueada.</p><p>Varias cuentas de investigadores de seguridad se hicieron eco del caso: </p><div class="twitter-embed" data-attrs="{&quot;url&quot;:&quot;https://x.com/vxunderground/status/2060036224245432506?s=20&quot;,&quot;full_text&quot;:&quot;Chat, I don't want to be that guy, but I think Microsoft has really pissed off security researchers and we're approaching the tipping point.\n\nThis Eclipse guy has really rocked the boat for Microsoft. &quot;,&quot;username&quot;:&quot;vxunderground&quot;,&quot;name&quot;:&quot;vx-underground&quot;,&quot;profile_image_url&quot;:&quot;https://pbs.substack.com/profile_images/1903282052297891840/sMABW3W-_normal.jpg&quot;,&quot;date&quot;:&quot;2026-05-28T16:31:24.000Z&quot;,&quot;photos&quot;:[{&quot;img_url&quot;:&quot;https://pbs.substack.com/media/HJa3XefWMAQs-ZL.jpg&quot;,&quot;link_url&quot;:&quot;https://t.co/y7wOvB2UYh&quot;}],&quot;quoted_tweet&quot;:{},&quot;reply_count&quot;:72,&quot;retweet_count&quot;:238,&quot;like_count&quot;:2035,&quot;impression_count&quot;:57893,&quot;expanded_url&quot;:null,&quot;video_url&quot;:null,&quot;belowTheFold&quot;:true}" data-component-name="Twitter2ToDOM"></div><h3>Grandoreiro sigue activo en Am&#233;rica Latina</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!B5-W!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6fbfa660-3a2f-45ed-ba8e-2fc0c158cf8d_1310x876.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!B5-W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6fbfa660-3a2f-45ed-ba8e-2fc0c158cf8d_1310x876.png 424w, https://substackcdn.com/image/fetch/$s_!B5-W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6fbfa660-3a2f-45ed-ba8e-2fc0c158cf8d_1310x876.png 848w, https://substackcdn.com/image/fetch/$s_!B5-W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6fbfa660-3a2f-45ed-ba8e-2fc0c158cf8d_1310x876.png 1272w, https://substackcdn.com/image/fetch/$s_!B5-W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6fbfa660-3a2f-45ed-ba8e-2fc0c158cf8d_1310x876.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!B5-W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6fbfa660-3a2f-45ed-ba8e-2fc0c158cf8d_1310x876.png" width="1310" height="876" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6fbfa660-3a2f-45ed-ba8e-2fc0c158cf8d_1310x876.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:876,&quot;width&quot;:1310,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1713324,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/199246943?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6fbfa660-3a2f-45ed-ba8e-2fc0c158cf8d_1310x876.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!B5-W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6fbfa660-3a2f-45ed-ba8e-2fc0c158cf8d_1310x876.png 424w, https://substackcdn.com/image/fetch/$s_!B5-W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6fbfa660-3a2f-45ed-ba8e-2fc0c158cf8d_1310x876.png 848w, https://substackcdn.com/image/fetch/$s_!B5-W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6fbfa660-3a2f-45ed-ba8e-2fc0c158cf8d_1310x876.png 1272w, https://substackcdn.com/image/fetch/$s_!B5-W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6fbfa660-3a2f-45ed-ba8e-2fc0c158cf8d_1310x876.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Ilustraci&#243;n: Midjourney (IA)</figcaption></figure></div><p><strong>Grandoreiro</strong> sigue activo y volvi&#243; a apuntar contra bancos y empresas de Europa y Am&#233;rica Latina con campa&#241;as de phishing, abuso de servicios leg&#237;timos y t&#233;cnicas para esconderse dentro del tr&#225;fico normal.</p><p><strong>Qu&#233; pas&#243;.</strong> <a href="https://www.watchguard.com/wgrd-security-hub/secplicity-blog/grandoreiro-malware-campaign-targets-europe-and-latin-america">WatchGuard detect&#243;</a> una campa&#241;a de Grandoreiro contra bancos de Portugal que usa DLL side-loading, una t&#233;cnica que aprovecha software leg&#237;timo para cargar archivos maliciosos. El malware tambi&#233;n aparece en otra campa&#241;a distribuida por correos de phishing con archivos ZIP alojados en MediaFire y un falso aviso para actualizar Adobe Reader.</p><p><strong>Por qu&#233; importa.</strong> Grandoreiro est&#225; activo desde 2016 y ya fue vinculado al robo de credenciales financieras en miles de instituciones de 45 pa&#237;ses y territorios. Aunque <strong>Brasil</strong> <a href="https://www.brodersendarknews.com/p/grandoreiro-malware-bancario-desmantelado?utm_source=publication-search">intent&#243; desmantelar</a> parte de su infraestructura en 2024, el malware sigui&#243; evolucionando, ampli&#243; su alcance e incorpor&#243; controles como CAPTCHA y chequeos anti an&#225;lisis.</p><p><strong>El alcance.</strong> Los archivos analizados hacen referencia a bancos e instituciones financieras de Portugal, como Abanca, Banco de Portugal, BBVA PT, Caixa Geral de Dep&#243;sitos y Santander. Tambi&#233;n aparecen Revolut y Wise.</p><h3>FROST, la t&#233;cnica que usa el SSD para espiar actividad desde el navegador</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!pwrA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8af77e-3a49-4ca1-8606-4b9e56b37b93_825x464.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!pwrA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8af77e-3a49-4ca1-8606-4b9e56b37b93_825x464.png 424w, https://substackcdn.com/image/fetch/$s_!pwrA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8af77e-3a49-4ca1-8606-4b9e56b37b93_825x464.png 848w, https://substackcdn.com/image/fetch/$s_!pwrA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8af77e-3a49-4ca1-8606-4b9e56b37b93_825x464.png 1272w, https://substackcdn.com/image/fetch/$s_!pwrA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8af77e-3a49-4ca1-8606-4b9e56b37b93_825x464.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!pwrA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8af77e-3a49-4ca1-8606-4b9e56b37b93_825x464.png" width="825" height="464" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ae8af77e-3a49-4ca1-8606-4b9e56b37b93_825x464.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:464,&quot;width&quot;:825,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:573644,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/199246943?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8af77e-3a49-4ca1-8606-4b9e56b37b93_825x464.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!pwrA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8af77e-3a49-4ca1-8606-4b9e56b37b93_825x464.png 424w, https://substackcdn.com/image/fetch/$s_!pwrA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8af77e-3a49-4ca1-8606-4b9e56b37b93_825x464.png 848w, https://substackcdn.com/image/fetch/$s_!pwrA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8af77e-3a49-4ca1-8606-4b9e56b37b93_825x464.png 1272w, https://substackcdn.com/image/fetch/$s_!pwrA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fae8af77e-3a49-4ca1-8606-4b9e56b37b93_825x464.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Kingston</figcaption></figure></div><p>Un grupo de investigadores mostr&#243; una t&#233;cnica que permite a un sitio web <strong>inferir</strong> qu&#233; otras p&#225;ginas y apps tiene abiertas un usuario <a href="https://arstechnica.com/security/2026/05/websites-have-a-new-way-to-spy-on-visitors-analyzing-their-ssd-activity/">midiendo la actividad de su SSD</a> desde el navegador. La t&#233;cnica se llama <strong>FROST</strong> y, seg&#250;n Ars Technica, todav&#237;a no hay indicios de uso real en ataques.</p><p><strong>Qu&#233; pas&#243;.</strong> FROST usa JavaScript y el sistema OPFS del navegador para medir <strong>peque&#241;as variaciones de latencia</strong> en operaciones de lectura del disco. Esas se&#241;ales pueden revelar actividad en otras pesta&#241;as, incluso en otros navegadores, y apps abiertas en el equipo.</p><p><strong>Por qu&#233; importa.</strong> El ataque no necesita permisos especiales <strong>ni interacci&#243;n del usuario</strong> m&#225;s all&#225; de abrir el sitio malicioso. Funciona como un canal lateral: aprovecha se&#241;ales indirectas del hardware para deducir informaci&#243;n que el navegador deber&#237;a aislar.</p><p><strong>El l&#237;mite.</strong> El m&#233;todo requiere crear un archivo OPFS muy grande, probablemente de <strong>m&#225;s de 1 GB,</strong> lo que vuelve m&#225;s dif&#237;cil un ataque masivo y m&#225;s probable que el usuario lo note. Los investigadores probaron el ataque completo en una <strong>Mac M2</strong>. En <strong>Linux</strong> validaron la base t&#233;cnica, pero no el ataque completo. <strong>Windows</strong> no fue testeado.</p><p><strong>Qu&#233; hacer.</strong> Cerrar pesta&#241;as innecesarias reduce superficie de exposici&#243;n. Para los navegadores, una mitigaci&#243;n posible ser&#237;a limitar el tama&#241;o m&#225;ximo de los archivos OPFS que puede crear un sitio.</p><h3>Advierten sobre sitios falsos del Mundial FIFA 2026</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gI52!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20e6d61c-8176-4261-8f1a-c2be9ef6804f_1454x869.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gI52!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20e6d61c-8176-4261-8f1a-c2be9ef6804f_1454x869.png 424w, https://substackcdn.com/image/fetch/$s_!gI52!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20e6d61c-8176-4261-8f1a-c2be9ef6804f_1454x869.png 848w, https://substackcdn.com/image/fetch/$s_!gI52!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20e6d61c-8176-4261-8f1a-c2be9ef6804f_1454x869.png 1272w, https://substackcdn.com/image/fetch/$s_!gI52!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20e6d61c-8176-4261-8f1a-c2be9ef6804f_1454x869.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gI52!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20e6d61c-8176-4261-8f1a-c2be9ef6804f_1454x869.png" width="1454" height="869" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/20e6d61c-8176-4261-8f1a-c2be9ef6804f_1454x869.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:869,&quot;width&quot;:1454,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1896771,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/199246943?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20e6d61c-8176-4261-8f1a-c2be9ef6804f_1454x869.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gI52!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20e6d61c-8176-4261-8f1a-c2be9ef6804f_1454x869.png 424w, https://substackcdn.com/image/fetch/$s_!gI52!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20e6d61c-8176-4261-8f1a-c2be9ef6804f_1454x869.png 848w, https://substackcdn.com/image/fetch/$s_!gI52!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20e6d61c-8176-4261-8f1a-c2be9ef6804f_1454x869.png 1272w, https://substackcdn.com/image/fetch/$s_!gI52!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F20e6d61c-8176-4261-8f1a-c2be9ef6804f_1454x869.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Gianni Infantino, presidente de la FIFA. Foto: AP</figcaption></figure></div><p><strong><a href="https://www.ic3.gov/PSA/2026/PSA260527">El FBI alert&#243;</a></strong> por una ola de sitios falsos que se hacen pasar por FIFA para robar datos, vender entradas truchas y explotar el inter&#233;s por el Mundial 2026.</p><p><strong>Qu&#233; pas&#243;.</strong> La advertencia apunta a dominios que imitan a fifa.com con cambios m&#237;nimos en la escritura, o con terminaciones alternativas como .org, .xyz, .live o .sale. Tambi&#233;n aparecen falsos portales laborales.</p><p><strong>Por qu&#233; importa.</strong> El Mundial se jugar&#225; del 11 de junio al 19 de julio de 2026 en Estados Unidos, Canad&#225; y M&#233;xico. Seg&#250;n el FBI, los atacantes ya prepararon cientos de sitios de phishing para robar nombres, direcciones, emails, tel&#233;fonos y datos bancarios o de pago.</p><p><strong>La escala.</strong> <a href="https://www.group-ib.com/blog/ghost-stadium-football-fraud/">Group-IB</a> y <a href="https://www.bitdefender.com/en-us/blog/labs/football-fever-fuels-scam-campaigns-across-email-and-social-media">Bitdefender</a> tambi&#233;n detectaron campa&#241;as vinculadas al Mundial en Google Search, Facebook Ads, Telegram y WhatsApp. Group-IB atribuy&#243; a un actor chino, al que rastrea como Ghost Stadium, una operaci&#243;n con m&#225;s de 300 sitios clonados del portal de FIFA para fraudes con entradas premium.</p><p><strong>Qu&#233; hacer.</strong> El FBI recomienda tipear fifa.com manualmente, evitar anuncios patrocinados, verificar que la URL termine en .com, usar marcadores para los sitios oficiales y no ingresar datos sensibles hasta confirmar que el sitio sea aut&#233;ntico.</p><div><hr></div><h4><strong>&#128275; Breaches y hacks</strong></h4><ul><li><p>Vietnam investiga un <a href="https://vietnamnet.vn/en/hackers-breach-two-vietnamese-ministerial-systems-in-major-cyberattack-2518404.html">data breach</a></p></li><li><p>Advierten que <a href="https://securityaffairs.com/192787/security/19-6-billion-files-are-sitting-open-on-the-internet-no-password-required.html">19.600 millones de archivos</a> est&#225;n expuestos en internet sin passwords</p></li><li><p>Arrestan al atacante que <a href="https://www.bleepingcomputer.com/news/security/dutch-police-arrests-suspect-linked-to-ajax-football-club-hack/">hacke&#243; al Ajax</a> en Pa&#237;ses Bajos</p></li></ul><h4><strong>&#128274; Ransomware</strong></h4><ul><li><p>ShinyHunters extorsiona a una <a href="https://www.theregister.com/cyber-crime/2026/05/28/carnival-shinyhunters-cruised-off-with-6m-customer-records/5247808">empresa de cruceros</a></p></li><li><p>Advierten que el ransomware <a href="https://securityaffairs.com/192550/cyber-crime/why-pure-extortion-is-replacing-traditional-ransomware.html">cada vez tiene menos cifrado</a> y m&#225;s robo de datos sin encriptar</p></li><li><p>Anuncian como v&#237;ctima a una organizaci&#243;n de salud argentina: <a href="https://sheriff.birminghamcyberarms.co.uk/alert?id=478">Sanatorio Delta</a></p></li></ul><h4><strong>&#128163; Exploits y malware</strong></h4><ul><li><p>Anthropic dice que encontr&#243; <a href="https://www.anthropic.com/research/glasswing-initial-update">m&#225;s de 10 mil</a> vulnerabilidades altas o cr&#237;ticas en un mes</p></li><li><p>Explotan una falla en <a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-forticlient-ems-flaw-to-push-infostealer-malware/">FortiClient Enterprise Management Server (EMS)</a> para instalar infostealers</p></li><li><p>Un <a href="https://www.bleepingcomputer.com/news/security/new-gogs-zero-day-flaw-lets-hackers-get-remote-code-execution/">zero day</a> en Gogs (servicio Git self-hosted) permite tener ejecuci&#243;n remota</p></li></ul><h4><strong>&#128269; Threat intel y vulnerabilidades</strong></h4><ul><li><p>Reportes: <a href="https://blog.checkpoint.com/research/ai-attacks-are-no-longer-experimental-key-findings-from-the-march-april-2026-ai-threat-landscape/">Check Point</a>, <a href="https://threatresearch.ext.hp.com/hp-wolf-security-threat-insights-report-q1-2024/">HP Wolf Security</a>, <a href="https://unit42.paloaltonetworks.com/cyber-extortion-economy/">Unit 42 (Palo Alto)</a>, <a href="https://blog.talosintelligence.com/dicom-pydicom-gdcm-and-orthanc-a-technical-tour-of-what-really-happens-in-the-heap/">Cisco Talos</a>, <a href="https://lp.kaspersky.com/global/tech-enabled-abuse-2/">Kaspersky</a>, <a href="https://redcanary.com/blog/threat-intelligence/intelligence-insights-may-2026/">Red Canary</a>, <a href="https://www.tenable.com/blog/how-cyberattackers-inflate-malicious-package-npm-download-counts">Tenable</a>, <a href="https://www.vulncheck.com/blog/routinely-targeted-vulnerabilities-may-2026">VulnCheck</a></p></li><li><p>Dan de baja la botnet <a href="https://www.bleepingcomputer.com/news/security/glassworm-botnet-disrupted-after-resilient-c2-infrastructure-takedown/">Glassworm</a> y <a href="https://www.politie.nl/nieuws/2026/mei/28/06-politie-en-ncsc-halen-groot-botnetwerk-offline.html">otra</a> de 17 millones de dispositivos</p></li><li><p>Un minero de GPUs <a href="https://www.bleepingcomputer.com/news/security/gpu-mining-malware-spreads-via-seo-poisoning-ai-chatbots/">infecta equipos</a> a partir de SEO poisoning</p></li></ul><h4><strong>&#128736;&#65039; Tools y updates</strong></h4><ul><li><p><a href="https://github.blog/changelog/2026-05-22-staged-publishing-and-new-install-time-controls-for-npm/">GitHub</a> lanza una actualizaci&#243;n por paquetes npm maliciosos</p></li><li><p>YouTube va a etiquetar el <a href="https://www.macrumors.com/2026/05/27/youtube-automatic-ai-video-labeling/">contenido generado por IA</a></p></li><li><p>Una plataforma nueva intenta <a href="https://www.securityweek.com/new-edamame-platform-aims-to-catch-ai-coding-agents-going-off-the-rails/">arreglar errores</a> de agentes de IA antes de que vayan a producci&#243;n</p></li></ul><h4><strong>&#128203; Privacidad y regulaciones</strong></h4><ul><li><p><a href="https://www.reuters.com/business/media-telecom/malaysia-introduce-new-rules-protect-youth-online-platforms-2026-05-22/">Malasia</a> se suma a la prohibici&#243;n de redes sociales para menores de 16</p></li><li><p>Acusan a un empleado de Google por usar <a href="https://abcnews.com/amp/US/google-employee-charged-inside-information-make-1-million/story?id=133350018">informaci&#243;n interna</a> en Polymarket</p></li><li><p><a href="https://www.reuters.com/world/middle-east/irans-president-orders-reopening-international-internet-access-state-media-2026-05-25/">Ir&#225;n vuelve</a> a tener internet tras casi 90 d&#237;as de apag&#243;n</p><p></p></li></ul><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial generativa para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/mas-de-142-mil-despidos-en-tech-microsoft-datos-ia?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/mas-de-142-mil-despidos-en-tech-microsoft-datos-ia?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Cómo fue Ekoparty Miami: hackers latinos, mucha IA y el saldo del primer viaje fuera de Argentina]]></title><description><![CDATA[Del entusiasmo por el debut internacional a los puntos por mejorar: la conferencia hacker argentina busca su identidad propia en un terreno desconocido. Repaso por las villages y balance.]]></description><link>https://www.brodersendarknews.com/p/como-fue-ekoparty-miami-hackers-latinos</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/como-fue-ekoparty-miami-hackers-latinos</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Sun, 24 May 2026 12:03:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!RKl0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e701e34-a23e-455d-9f6f-a5019464ea1f_4032x2268.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><p><em><strong>Edici&#243;n especial Ekoparty Miami: balance de la conferencia.</strong></em></p><p><em><strong>&#9992; Env&#237;o desde Florida, Miami.</strong></em></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><div class="pullquote"><p style="text-align: center;"><em><strong>Presentado por:</strong></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.axionenergy.com/Paginas/index.aspx" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dh5W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg 424w, https://substackcdn.com/image/fetch/$s_!dh5W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg 848w, https://substackcdn.com/image/fetch/$s_!dh5W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!dh5W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dh5W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg" width="600" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:131875,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://www.axionenergy.com/Paginas/index.aspx&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194107355?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!dh5W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg 424w, https://substackcdn.com/image/fetch/$s_!dh5W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg 848w, https://substackcdn.com/image/fetch/$s_!dh5W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!dh5W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg 1456w" sizes="100vw" loading="lazy" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></div><h1>24<br>may</h1><h2><strong>&#9889;TL;DR</strong></h2><p>Y se fue la Eko Miami. Tras dos d&#237;as de charlas, villages y una humedad insoportable (reportajes, <a href="https://www.brodersendarknews.com/p/ekoparty-llego-a-miami-con-ia-chips">d&#237;a 1</a> y <a href="https://www.clarin.com/tecnologia/ekoparty-miami-dia-2-hackeos-ia-fraude-millonario-brasil-influencer-cyber-conquista-instagram_0_I4y9VAB97W.html">d&#237;a 2</a>), la conferencia argentina de hackers logr&#243; salir de Argentina en una experiencia que tiene un <strong>saldo positivo, pero tambi&#233;n algunos puntos a revisar</strong>.</p><p><strong>Ekoparty</strong> empez&#243; hace m&#225;s de 20 a&#241;os como una juntada presencial de amigos que &#8220;hangueaban&#8221; online, como se dice en la jerga (<em>hang out</em>, juntarse, pasar el rato). De fondo, todos sab&#237;an que exist&#237;a algo llamado <a href="https://www.clarin.com/tecnologia/defcon-31-comienza-conferencia-hackers-grande-mundo_0_3M4bAQWQD2.html">DEF CON, la conferencia de hackers m&#225;s grande del mundo</a>, que empez&#243; en 1993 con un pu&#241;ado de curiosos y hoy re&#250;ne a m&#225;s de 30 mil hackers todos los a&#241;os en Las Vegas. &#8220;No pod&#237;amos ni pensar en ir, no ten&#237;amos un mango&#8221;, recuerda uno de sus fundadores.</p><p>No es menor recordar que Argentina tiene un lugar relevante en la escena del hacking global. A principios de los 2000, una empresa local llamada <strong>Core Security Technologies </strong>abri&#243; el paso a lo que hoy se conoce como<strong> &#8220;seguridad ofensiva&#8221;</strong>, esto es, atacar sistemas en entornos controlados (o no) para encontrar vulnerabilidades y reportarlas. A diferencia del escenario de hace 25 a&#241;os, donde no exist&#237;a esta industria, <strong>hoy es un negocio global multimillonario.</strong></p><p>Por aquel entonces, Ekoparty empez&#243; a marcar su propia agenda local y pas&#243; por distintos lugares: casas de amigos, <strong>el hotel Bauen, el Konex </strong>y hoy el Centro de Convenciones Buenos Aires.</p><p>La conferencia argentina incluso tuvo una incursi&#243;n fallida en Los &#193;ngeles en 2019: hubo negociaciones avanzadas, pero nunca lleg&#243; a concretarse. El arribo a Miami, 20 a&#241;os despu&#233;s, se siente como un punto de llegada inesperado para los fundadores.</p><p>En 2026, el hotel Loews se llen&#243; no s&#243;lo de argentinos sino de hackers de m&#225;s de 10 nacionalidades que encontraron en South Beach, un destino m&#225;s cercano que Buenos Aires para muchos pa&#237;ses latinos (y con vuelo directo para los argentinos): <strong>Per&#250;, Colombia, Ecuador, M&#233;xico, Brasil, Guatemala, Panam&#225;</strong>. Tambi&#233;n una buena cantidad de norteamericanos y hasta taiwaneses o asistentes que vinieron desde <strong>Jap&#243;n</strong>. &#8220;Me queda m&#225;s cerca que Argentina&#8221;, brome&#243; un expositor.</p><p>&#8220;Ekoparty siempre fue un punto de encuentro. Durante m&#225;s de veinte a&#241;os, en Buenos Aires, reuni&#243; a hackers, investigadores, empresas, comunidades y talento de toda Am&#233;rica Latina. Ahora queremos ser un punto de encuentro entre lo que pasa en la regi&#243;n y el ecosistema de Estados Unidos&#8221;, dijo a este medio Leonardo Pig&#241;er, CEO de la conferencia.</p><p>&#8220;Para un pa&#237;s del tama&#241;o del nuestro, <strong>Argentina produjo una cantidad enorme de hackers</strong>, investigadores y profesionales de ciberseguridad que marcaron historia a nivel global. Eso no pas&#243; por casualidad. Tiene que ver con una forma de pensar muy argentina: hacer mucho con poco, resolver problemas sin esperar las condiciones ideales, mirar los sistemas desde los bordes, con curiosidad, creatividad y cierta rebeld&#237;a&#8221;, agreg&#243;.</p><p>En cuanto al lugar, la sala de conferencias del Loews cumpli&#243; las expectativas: hotel bien ubicado en el norte de South Beach, espacio amplio y muy caminable. Lo que no funcion&#243;: <strong>escuchar charlas se hizo muy complicado por momentos</strong>, debido a que convivieron tres auditorios en un mismo lugar y las voces de los expositores se superpon&#237;an entre s&#237;.</p><p>El debut tambi&#233;n dej&#243; <strong>una pregunta abierta para varios de los asistentes</strong> sobre su identidad fuera de Argentina. En Buenos Aires, la conferencia tiene una marca construida durante m&#225;s de dos d&#233;cadas, con una comunidad que ya entiende sus c&#243;digos, sus pasillos, sus villages y su mezcla entre industria, investigaci&#243;n y cultura hacker. </p><p><strong>En Miami, ese contrato no existe</strong>: por momentos pareci&#243; buscar un perfil m&#225;s corporativo, cercano a una conferencia de industria y, por otros, intent&#243; sostener el pulso comunitario que la volvi&#243; reconocible en Am&#233;rica Latina.</p><p>El desaf&#237;o es mayor porque en Estados Unidos el calendario de ciberseguridad ya tiene nombres muy instalados, como DEF CON, Black Hat o RSA Conference entre los gigantes, y <strong>BSides o incluso Hack Miami </strong>en la ciudad de Florida. Ekoparty llega con una identidad fuerte para el p&#250;blico argentino y regional, pero con una marca todav&#237;a <strong>menos reconocida fuera de ese circuito.</strong></p><p><strong>P&#225;rrafo aparte para Miami</strong>, que es un buen <em>hub tech</em> para Latinoam&#233;rica pero suma su propia complejidad: una ciudad diversa, atravesada por comunidades de muchos pa&#237;ses, aunque menos org&#225;nica que el que puede construirse en una escena local m&#225;s compacta. Armar comunidad all&#237; demandar&#225; encontrar un lenguaje com&#250;n entre p&#250;blicos, acentos, intereses y niveles de pertenencia muy distintos.</p><p>A eso se suma que viajar desde Argentina a Estados Unidos es caro, y varias villages que suelen ser parte central de la experiencia en Buenos Aires no pudieron acompa&#241;ar <strong>por falta de financiamiento</strong> para cubrir traslados, estad&#237;a y log&#237;stica.</p><p>Resolver esas variables de la ecuaci&#243;n, identidad, comunidad y sostenibilidad econ&#243;mica, ser&#225; clave si la edici&#243;n de Miami quiere sostenerse en el tiempo y crecer con una personalidad propia.</p><p>M&#225;s all&#225; de todo esto, el primer partido de visitante de Ekoparty dej&#243; un saldo positivo: tener la idea de una conferencia en el exterior y realizarla es un paso gigante para empresas argentinas en el duro contexto econ&#243;mico de 2026.</p><p>Como suelo decir: hay <em>doers </em>y hay <em>talkers, </em>los que hacen y los que hablan. Hacer es dif&#237;cil. Hablar es f&#225;cil. Ekoparty dijo que iba a hacer una edici&#243;n en Miami y, este domingo, puede mirar para atr&#225;s y ver que sucedi&#243;.</p><p>La edici&#243;n 2027 todav&#237;a no fue oficializada, pero ya circula como comentario recurrente detr&#225;s de escena. &#8220;Ahora hay dos Eko por a&#241;o&#8221;, dec&#237;an algunos de los organizadores, con la cabeza puesta en la edici&#243;n que arranca el 7 de octubre en Buenos Aires.</p><p>En DEF CON suele repetirse una m&#225;xima: la conferencia es lo que cada asistente hace con ella. </p><p><strong>Ekoparty Miami ser&#225; lo que los hackers latinos quieran que sea.</strong></p><div><hr></div><p>&#9200; <em>Substack dice que leer este correo completo lleva 16 minutos</em></p><p><em>Reportaje publicado en tandem con <strong><a href="https://www.clarin.com/tecnologia/hackear-audi-miami-ekoparty-mostro-villages-espiritu-comunidad-hacker_0_yZqR8aUOsM.html">Clar&#237;n</a></strong></em></p><p><em>Dark News #204</em></p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://bloka.red/contacto/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gebg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 424w, https://substackcdn.com/image/fetch/$s_!gebg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 848w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1272w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png" width="1456" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1127539,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://bloka.red/contacto/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194107355?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gebg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 424w, https://substackcdn.com/image/fetch/$s_!gebg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 848w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1272w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></div><h3>C&#243;mo fue Ekoparty Miami: hackers latinos, mucha IA y el saldo del primer viaje fuera de Argentina</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!RKl0!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e701e34-a23e-455d-9f6f-a5019464ea1f_4032x2268.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!RKl0!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e701e34-a23e-455d-9f6f-a5019464ea1f_4032x2268.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RKl0!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e701e34-a23e-455d-9f6f-a5019464ea1f_4032x2268.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RKl0!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e701e34-a23e-455d-9f6f-a5019464ea1f_4032x2268.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RKl0!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e701e34-a23e-455d-9f6f-a5019464ea1f_4032x2268.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!RKl0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e701e34-a23e-455d-9f6f-a5019464ea1f_4032x2268.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2e701e34-a23e-455d-9f6f-a5019464ea1f_4032x2268.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:6313530,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/199004559?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e701e34-a23e-455d-9f6f-a5019464ea1f_4032x2268.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!RKl0!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e701e34-a23e-455d-9f6f-a5019464ea1f_4032x2268.jpeg 424w, https://substackcdn.com/image/fetch/$s_!RKl0!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e701e34-a23e-455d-9f6f-a5019464ea1f_4032x2268.jpeg 848w, https://substackcdn.com/image/fetch/$s_!RKl0!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e701e34-a23e-455d-9f6f-a5019464ea1f_4032x2268.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!RKl0!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e701e34-a23e-455d-9f6f-a5019464ea1f_4032x2268.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Danilo Erazo, hacker ecuatoriano, mostr&#243; qu&#233; cuidados tener al cerrar el auto. Foto: Juan Brodersen</figcaption></figure></div><p><strong><a href="https://www.clarin.com/tecnologia/argentina-miami-ekoparty-abrio-primera-edicion-internacional-ia-chips-camaras-lupa_0_m2ZMgtC3BS.html">Ekoparty Miami</a></strong> reflej&#243; en sus charlas principales el clima de &#233;poca: inteligencia artificial aplicada a hackeos, fraudes millonarios, ingenier&#237;a inversa, chips, c&#225;maras de seguridad vulnerables y <a href="https://www.clarin.com/tecnologia/ekoparty-miami-dia-2-hackeos-ia-fraude-millonario-brasil-influencer-cyber-conquista-instagram_0_I4y9VAB97W.html">nuevas formas</a> de pensar la comunicaci&#243;n en ciberseguridad. Pero el esp&#237;ritu m&#225;s propio de la conferencia apareci&#243; en otro lugar: las &#8220;<strong>villages</strong>&#8221;, o villas, espacios donde la comunidad hacker se junta alrededor de desaf&#237;os, juegos, competencias y demostraciones pr&#225;cticas<strong>. &#191;Hackear un Audi con fines educativos? Por qu&#233; no.</strong></p><p>Esa idea tuvo una escena muy clara durante el jueves, pasadas las 3 de la tarde, cuando <a href="https://www.clarin.com/tecnologia/ekoparty-2025-descubren-falla-alarmas-genericas-autos-permite-abrir-miles-vehiculos_0_53GFvnqfwm.html">Danilo Erazo</a> llev&#243; a un grupo de asistentes hasta el estacionamiento de cortes&#237;a del hotel Loews, en South Beach. Erazo, hacker ecuatoriano reconocido en la comunidad latina por sus trabajos de hardware hacking y hackeo de autos, los esperaba con un <strong>Audi A5 alquilado especialmente para la ocasi&#243;n</strong>. &#8220;No s&#233; con qu&#233; cara lo vas a devolver&#8221;, brome&#243; un asistente cuando se enter&#243; del desaf&#237;o.</p><p>El objetivo no era malicioso: era mostrar c&#243;mo se pod&#237;a abrir el auto con herramientas usadas en el mundo del <em>car hacking</em>. Y, a fin de cuentas, el hackeo era tan &#8220;simple&#8221; como abrir la puerta del auto sin autorizaci&#243;n oficial del due&#241;o.</p><p>Asistentes de la conferencia pasaron del g&#233;lido aire acondicionado del hotel a los m&#225;s de 30 grados y la humedad de la intemperie, donde hasta lleg&#243; <strong>un equipo de la cadena de TV estadounidense Univision</strong>. El objetivo: ver c&#243;mo un auto alem&#225;n de alta gama pod&#237;a ser desbloqueado en vivo con antenas y se&#241;ales de radio, con Danilo como anfitri&#243;n, <strong>un showman del hacking.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SSGJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15b8ffa4-590a-4480-a90e-c9cccdb04835_1023x721.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SSGJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15b8ffa4-590a-4480-a90e-c9cccdb04835_1023x721.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SSGJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15b8ffa4-590a-4480-a90e-c9cccdb04835_1023x721.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SSGJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15b8ffa4-590a-4480-a90e-c9cccdb04835_1023x721.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SSGJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15b8ffa4-590a-4480-a90e-c9cccdb04835_1023x721.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SSGJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15b8ffa4-590a-4480-a90e-c9cccdb04835_1023x721.jpeg" width="1023" height="721" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/15b8ffa4-590a-4480-a90e-c9cccdb04835_1023x721.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:721,&quot;width&quot;:1023,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:133840,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/199004559?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15b8ffa4-590a-4480-a90e-c9cccdb04835_1023x721.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SSGJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15b8ffa4-590a-4480-a90e-c9cccdb04835_1023x721.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SSGJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15b8ffa4-590a-4480-a90e-c9cccdb04835_1023x721.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SSGJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15b8ffa4-590a-4480-a90e-c9cccdb04835_1023x721.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SSGJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15b8ffa4-590a-4480-a90e-c9cccdb04835_1023x721.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">La prueba fall&#243; al primer intento, pero al tercero, Erazo abri&#243; el auto. Foto: Juan Brodersen</figcaption></figure></div><p><strong>Carism&#225;tico</strong>, c&#243;modo frente al p&#250;blico y las c&#225;maras, explic&#243; cada paso con tono de divulgador. El hacker, que vive en Budapest y trabaja profesionalmente en PCAutomotive, una compa&#241;&#237;a dedicada a la seguridad de autos y dispositivos embebidos, tambi&#233;n tiene un canal de <a href="https://www.youtube.com/@revers3everything">YouTube en espa&#241;ol, </a><strong><a href="https://www.youtube.com/@revers3everything">Reverse Everything</a></strong>, donde publica contenido t&#233;cnico sobre<strong> ingenier&#237;a inversa</strong>, uno de los conceptos clave del hacking: investigar c&#243;mo funciona una tecnolog&#237;a sin tener acceso a los planos.</p><p>&#8220;Alquilamos un Audi A5, de 2024, que tiene u<strong>no de los sistemas de seguridad m&#225;s altos</strong> en el sentido de las alarmas para desbloquear el auto&#8221;, cont&#243; a <strong>Dark News</strong> despu&#233;s de su demostraci&#243;n. &#8220;Estamos hablando de un auto alem&#225;n, y los autos alemanes son los m&#225;s seguros en el sentido de las llaves remotas, que es el <em>key fob</em>, como se conoce en ingl&#233;s, para abrir el auto&#8221;.</p><p>El punto, explic&#243;, era que el sistema de apertura remota del veh&#237;culo no funciona con una se&#241;al simple. &#8220;Es un auto que manda el c&#243;digo <strong>en tres diferentes frecuencias </strong>y, despu&#233;s, manda en seis diferentes saltos el c&#243;digo que desbloquea el auto&#8221;, cont&#243;.</p><p>En t&#233;rminos simples, la ingenier&#237;a inversa consiste en estudiar c&#243;mo funciona una tecnolog&#237;a desde afuera,<strong> sin que el fabricante entregue necesariamente esa informaci&#243;n</strong>. En este caso, implicaba analizar la comunicaci&#243;n entre la llave inal&#225;mbrica y el auto.</p><p>&#8220;Obviamente, todo est&#225; encriptado. Los autos alemanes cifran con una llave segura, y es <strong>casi imposible romper ese cifrado</strong>&#8221;, aclar&#243; Erazo. Por eso, la demostraci&#243;n us&#243; otro camino: un ataque conocido como <strong>RollJam</strong>.</p><p>&#8220;El RollJam attack es un ataque de <em>man in the middle</em>, poner a una persona en el medio, se necesita interacci&#243;n con el usuario. Entonces, se presiona la llave para cerrar el auto y por debajo hay una inhibici&#243;n de se&#241;al. Esta inhibici&#243;n hace que ese c&#243;digo nunca llegue al auto y, como nunca lleg&#243;,<strong> yo lo puedo reutilizar</strong>&#8221;, explic&#243;. Los inhibidores de se&#241;al ganaron visibilidad durante estos a&#241;os por videos virales en redes sociales <a href="https://www.clarin.com/policiales/crecen-casos-robos-inhibidores-modalidad-llave-abrir-autos-victimas-entrar-casas_0_XnAS9Ybwd0.html">donde se demuestra c&#243;mo un delincuente puede abrir un auto</a>.</p><p>La prueba fue realizada en un entorno controlado y con fines educativos, para mostrar riesgos reales y posibles defensas: para un ataque de este tipo <strong>es clave verificar que el auto se cerr&#243; completamente</strong>, tirando f&#237;sicamente de la manija para chequear que no est&#233; abierto por un ataque tipo RollJam o inhibici&#243;n de se&#241;al.</p><h2>Las villages, el esp&#237;ritu de las conferencias de seguridad</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aGw7!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95321b73-e7a0-41c6-bcc7-a4895eaa61a3_4032x2268.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aGw7!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95321b73-e7a0-41c6-bcc7-a4895eaa61a3_4032x2268.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aGw7!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95321b73-e7a0-41c6-bcc7-a4895eaa61a3_4032x2268.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aGw7!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95321b73-e7a0-41c6-bcc7-a4895eaa61a3_4032x2268.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aGw7!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95321b73-e7a0-41c6-bcc7-a4895eaa61a3_4032x2268.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aGw7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95321b73-e7a0-41c6-bcc7-a4895eaa61a3_4032x2268.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/95321b73-e7a0-41c6-bcc7-a4895eaa61a3_4032x2268.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:3256609,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/199004559?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95321b73-e7a0-41c6-bcc7-a4895eaa61a3_4032x2268.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aGw7!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95321b73-e7a0-41c6-bcc7-a4895eaa61a3_4032x2268.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aGw7!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95321b73-e7a0-41c6-bcc7-a4895eaa61a3_4032x2268.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aGw7!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95321b73-e7a0-41c6-bcc7-a4895eaa61a3_4032x2268.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aGw7!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F95321b73-e7a0-41c6-bcc7-a4895eaa61a3_4032x2268.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Muchos asistentes de las villages viajaron con sus familias. Foto: Juan Brodersen</figcaption></figure></div><p>Una de las apuestas de esta primera edici&#243;n internacional fue mostrar que la Ekoparty <strong>no viaj&#243; sola a Miami sino que fue con una parte de la comunidad</strong> que la viene acompa&#241;ando desde hace a&#241;os en Buenos Aires, y tambi&#233;n con grupos de otros pa&#237;ses de la regi&#243;n que vieron en Florida una oportunidad para conectar con hackers latinoamericanos que viven o trabajan en Estados Unidos.</p><p>Entre <strong>cables, routers, laptops, destornilladores y Raspberries</strong>, las villages representaron el esp&#237;ritu argento de &#8220;lo atamos con alambre&#8221; en su m&#225;ximo esplendor, como <strong>ir de &#250;ltimo momento a comprar TVs a Best Buy</strong> para luego preguntarse qu&#233; hacer con ellas (ya que traerlas de vuelta es una complicaci&#243;n en el aeropuerto).</p><p>Uno de los espacios m&#225;s llamativos fue el <a href="https://airesiliencehub.space/">AI Resilience Hub</a>, coordinado por el hacker Daniel Dieser. La propuesta era mostrar modelos de inteligencia artificial funcionando con capacidades nativas, conectados a infraestructura, hardware, sensores, robots y servicios en la nube. &#8220;Lo que hacemos es, mediante algo parecido a un envase, hacer que el modelo corra libremente y pueda interactuar con todo lo que tiene a su alrededor: infraestructura, hardware, cloud, local, Raspberry, robots, sensores, crear c&#243;digo&#8221;, explic&#243; Dieser.</p><p>Seg&#250;n el hacker (que fue reconocido en el cierre de la conferencia), el problema actual es que buena parte de los usuarios<strong> todav&#237;a usa la inteligencia artificial en formatos b&#225;sicos</strong>, como un chat, mientras la tecnolog&#237;a empieza a adquirir capacidades m&#225;s amplias. &#8220;Creo que socialmente todav&#237;a no somos conscientes del potencial que tiene la IA, que es exponencial&#8221;, dijo. &#8220;Esto va a tener un impacto en la industria, en nuestra vida, y todo se va a tener que adaptar a esto&#8221;, asegur&#243; en di&#225;logo con este medio.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!6lcE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8762d1a-6795-4109-8705-0e5b982af7e1_4032x2268.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!6lcE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8762d1a-6795-4109-8705-0e5b982af7e1_4032x2268.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6lcE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8762d1a-6795-4109-8705-0e5b982af7e1_4032x2268.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6lcE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8762d1a-6795-4109-8705-0e5b982af7e1_4032x2268.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6lcE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8762d1a-6795-4109-8705-0e5b982af7e1_4032x2268.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!6lcE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8762d1a-6795-4109-8705-0e5b982af7e1_4032x2268.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f8762d1a-6795-4109-8705-0e5b982af7e1_4032x2268.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4946816,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/199004559?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8762d1a-6795-4109-8705-0e5b982af7e1_4032x2268.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!6lcE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8762d1a-6795-4109-8705-0e5b982af7e1_4032x2268.jpeg 424w, https://substackcdn.com/image/fetch/$s_!6lcE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8762d1a-6795-4109-8705-0e5b982af7e1_4032x2268.jpeg 848w, https://substackcdn.com/image/fetch/$s_!6lcE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8762d1a-6795-4109-8705-0e5b982af7e1_4032x2268.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!6lcE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8762d1a-6795-4109-8705-0e5b982af7e1_4032x2268.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">El hub de IA de la Eko. Foto: Juan Brodersen</figcaption></figure></div><p>Al lado del AI hub, el <strong><a href="https://redteamspace.org/">Red Team Space</a></strong> llev&#243; una versi&#243;n m&#225;s liviana y port&#225;til de las actividades que suele desplegar en Buenos Aires. Javier Ant&#250;nez cont&#243; que el espacio funciona desde 2020 y que este a&#241;o el objetivo fue generar interacci&#243;n con quienes se acercaban. &#8220;Como es el primer a&#241;o y podemos transportar menos cosas, la idea es que tengamos m&#225;s interacci&#243;n con las personas&#8221;, explic&#243;.</p><p>El espacio combin&#243; retos de <strong>lockpicking (apertura de cerraduras)</strong>, trivias de ataque y defensa, escenarios de Red Team y una actividad bautizada <strong>&#8220;Fails reales&#8221;</strong>, basada en errores encontrados en trabajos profesionales. Ant&#250;nez lo cont&#243; con humor: &#8220;Le pusimos &#8216;Fails reales&#8217;,<strong> porque quedaba feo poner &#8216;cagadas que encontramos en los clientes&#8217;</strong>, pero bueno, fueron situaciones de escenarios reales que fueron errores que nos ayudaron a seguir avanzando y lograr algo importante&#8221;.</p><p>Por supuesto, estos viajes tuvieron su costo para quienes decidieron acompa&#241;ar a la conferencia. &#8220;Fue un esfuerzo muy grande para nosotros llegar ac&#225;, personal y econ&#243;mico. Venimos sin sponsor ni nada, pero m&#225;s que nada quer&#237;amos apoyar a la Eko en esta primera edici&#243;n&#8221;, dijo Ant&#250;nez.</p><p>Para &#233;l, la Ekoparty puede ocupar un lugar propio en el calendario de seguridad de Estados Unidos. El <strong><a href="https://bluespacesec.org/">Blue Space</a></strong> tambi&#233;n dijo presente.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!_g6U!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ebb9d3-0d7e-4b08-97a2-5f47188f4bdc_4032x2268.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!_g6U!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ebb9d3-0d7e-4b08-97a2-5f47188f4bdc_4032x2268.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_g6U!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ebb9d3-0d7e-4b08-97a2-5f47188f4bdc_4032x2268.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_g6U!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ebb9d3-0d7e-4b08-97a2-5f47188f4bdc_4032x2268.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_g6U!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ebb9d3-0d7e-4b08-97a2-5f47188f4bdc_4032x2268.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!_g6U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ebb9d3-0d7e-4b08-97a2-5f47188f4bdc_4032x2268.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/81ebb9d3-0d7e-4b08-97a2-5f47188f4bdc_4032x2268.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2180610,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/199004559?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ebb9d3-0d7e-4b08-97a2-5f47188f4bdc_4032x2268.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!_g6U!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ebb9d3-0d7e-4b08-97a2-5f47188f4bdc_4032x2268.jpeg 424w, https://substackcdn.com/image/fetch/$s_!_g6U!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ebb9d3-0d7e-4b08-97a2-5f47188f4bdc_4032x2268.jpeg 848w, https://substackcdn.com/image/fetch/$s_!_g6U!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ebb9d3-0d7e-4b08-97a2-5f47188f4bdc_4032x2268.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!_g6U!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F81ebb9d3-0d7e-4b08-97a2-5f47188f4bdc_4032x2268.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Red Team Space y Blue Space, juntos en la Eko. Foto: Juan Brodersen</figcaption></figure></div><p>Ese componente comunitario tambi&#233;n apareci&#243; en el stand compartido entre <strong><a href="https://owasp.org/">OWASP</a> e <a href="https://infosecmap.com/">InfosecMap</a></strong>. La argentina <strong>Ana Laura Mond&#243;n</strong> explic&#243; que InfosecMap es un directorio gratuito para rastrear eventos del ecosistema de seguridad inform&#225;tica en todo el mundo, desde conferencias grandes hasta meetups locales. &#8220;Trackeamos eventos, desde grandes conferencias hasta meetups locales o incluso juntadas a tomar una cerveza, para conectar con la comunidad&#8221;, cont&#243;.</p><p>Para Mond&#243;n, que participaba por primera vez en una conferencia fuera de Argentina, la llegada de Ekoparty a Estados Unidos tuvo un valor particular. &#8220;Me parece que est&#225; bueno, que es una oportunidad buen&#237;sima para que lo que vemos en Argentina, de semejante conferencia, pueda estar accesible para otro p&#250;blico, quiz&#225;s, o incluso para la comunidad de Latinoam&#233;rica viviendo en Estados Unidos&#8221;, dijo.</p><p>Tambi&#233;n particip&#243; la comunidad de <strong><a href="https://www.instagram.com/bugbountyarg/">Bug Bounty Argentina</a></strong>, que ven&#237;a de un periplo por Oriente, donde hackearon a Meta en un programa que tiene la empresa de Mark Zuckerberg para que hackers de todo el mundo les encuentren vulnerabilidades (y encontraron varias). El bug bounty es una de las ramas del hacking donde se paga por errores reportados.</p><p>&#8220;Uno de los chicos, Luciano Pacella, habl&#243; sobre la legalidad en el mundo del bug bounty y c&#243;mo surfear los grises&#8221;, cont&#243; Alan &#8220;El Mago&#8221; Levy a este medio, un t&#243;pico caliente por el conocido caso del <strong><a href="https://www.brodersendarknews.com/p/ahora-hackeo-a-aerolineas-argentinas">joven argentino que hacke&#243; el sistema de Aerol&#237;neas Argentinas</a></strong> para viajar gratis por el mundo y termin&#243; detenido.</p><p>El recorrido tambi&#233;n incluy&#243; al <a href="https://bugbountygirlsclub.com/">Bug Bounty Girls Club</a>, comunidad de mujeres que dijo presente en la conferencia.&#8220;Es un espacio para que <strong>todas las que no se animan</strong>, a lo mejor, o se sienten inseguras para empezar, sepan que tienen una red que las contiene&#8221;, cont&#243; Victoria Giunta, una de las organizadoras. Y tambi&#233;n particip&#243; el <strong><a href="https://www.instagram.com/cybersocialclub/">Cyber Social Club</a></strong>, una comunidad de trabajadores del mundo de la ciberseguridad argentina que organiz&#243; juntadas mientras dur&#243; la conferencia.</p><p>Adem&#225;s de las villages, distintas conferencias de ciberseguridad aprovecharon para mostrar sus propios espacios, como <strong>Hack Miami y Unknown Security Conference, de Lima (Per&#250;)</strong>. John Vargas, uno de sus representantes, cont&#243; que la conferencia peruana naci&#243; hace dos a&#241;os, despu&#233;s de participar como asistentes en la Ekoparty. &#8220;Cuando tienes un espacio donde se re&#250;ne toda Latinoam&#233;rica, es importante tener presencia. Lo que buscamos es seguir creciendo como comunidad&#8221;, dijo. Seg&#250;n cont&#243;, la escena peruana tambi&#233;n viene ganando terreno de la mano de universidades, instituciones y comunidades t&#233;cnicas.</p><p>Adem&#225;s de las villas que viajaron desde otros pa&#237;ses, una de las particularidades de la Eko Miami fue que participaron algunas que ya tienen presencia en Estados Unidos (<a href="https://www.clarin.com/tecnologia/def-33-abrio-llamado-democratizar-internet-defender-codigo-abierto_0_qWPL4LWRVw.html">DEF CON</a>), como <strong>la Aerospace Village</strong>.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!JJ2d!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F115e1533-42a7-47d1-9039-f1bdb7b182dd_4032x2268.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!JJ2d!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F115e1533-42a7-47d1-9039-f1bdb7b182dd_4032x2268.jpeg 424w, https://substackcdn.com/image/fetch/$s_!JJ2d!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F115e1533-42a7-47d1-9039-f1bdb7b182dd_4032x2268.jpeg 848w, https://substackcdn.com/image/fetch/$s_!JJ2d!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F115e1533-42a7-47d1-9039-f1bdb7b182dd_4032x2268.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!JJ2d!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F115e1533-42a7-47d1-9039-f1bdb7b182dd_4032x2268.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!JJ2d!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F115e1533-42a7-47d1-9039-f1bdb7b182dd_4032x2268.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/115e1533-42a7-47d1-9039-f1bdb7b182dd_4032x2268.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1823785,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/199004559?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F115e1533-42a7-47d1-9039-f1bdb7b182dd_4032x2268.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!JJ2d!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F115e1533-42a7-47d1-9039-f1bdb7b182dd_4032x2268.jpeg 424w, https://substackcdn.com/image/fetch/$s_!JJ2d!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F115e1533-42a7-47d1-9039-f1bdb7b182dd_4032x2268.jpeg 848w, https://substackcdn.com/image/fetch/$s_!JJ2d!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F115e1533-42a7-47d1-9039-f1bdb7b182dd_4032x2268.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!JJ2d!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F115e1533-42a7-47d1-9039-f1bdb7b182dd_4032x2268.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">La village aeroespacial, presente. Foto: Juan Brodersen</figcaption></figure></div><p>El Malware Space, la comunidad de <strong><a href="http://bugbounty.ar/">Bug Bounty de Argentina</a></strong>, Mobile Hacking y el Blue Space fueron otras de las villas que se sumaron. En el otro extremo del Loews Hotel estaban, tambi&#233;n, los espacios de <strong>sponsors</strong>: Faraday, Safe-U, Kulkan, Strike y Base4 entre los argentinos y empresas como Adobe, Fortinet y GitHub entre los de talla global.</p><p>Y algunos argentinos viajaron desde destinos remotos como <strong>Jap&#243;n</strong>: Emilio Couto, investigador de ciberseguridad argentino que vive en suelo nip&#243;n, llev&#243; su proyecto <a href="https://cybertamago.org/">CyberTAMAGO</a>, un conjunto de herramientas de entrenamiento y simulaci&#243;n en ciberseguridad. Hasta desarrollaron su propia credencial para entrar a la conferencia: </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bCrZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed3ffe2-5087-4fd1-81c7-2591338eadaa_720x785.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bCrZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed3ffe2-5087-4fd1-81c7-2591338eadaa_720x785.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bCrZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed3ffe2-5087-4fd1-81c7-2591338eadaa_720x785.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bCrZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed3ffe2-5087-4fd1-81c7-2591338eadaa_720x785.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bCrZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed3ffe2-5087-4fd1-81c7-2591338eadaa_720x785.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bCrZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed3ffe2-5087-4fd1-81c7-2591338eadaa_720x785.jpeg" width="720" height="785" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7ed3ffe2-5087-4fd1-81c7-2591338eadaa_720x785.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:785,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Un \&quot;badge\&quot; especial para la Eko Miami: CyberTAMAGO&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Un &quot;badge&quot; especial para la Eko Miami: CyberTAMAGO" title="Un &quot;badge&quot; especial para la Eko Miami: CyberTAMAGO" srcset="https://substackcdn.com/image/fetch/$s_!bCrZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed3ffe2-5087-4fd1-81c7-2591338eadaa_720x785.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bCrZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed3ffe2-5087-4fd1-81c7-2591338eadaa_720x785.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bCrZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed3ffe2-5087-4fd1-81c7-2591338eadaa_720x785.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bCrZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7ed3ffe2-5087-4fd1-81c7-2591338eadaa_720x785.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Un &#8220;badge&#8221; especial para la Eko Miami: CyberTAMAGO</figcaption></figure></div><p>Para leer el reportaje del d&#237;a 2, <a href="https://www.clarin.com/tecnologia/ekoparty-miami-dia-2-hackeos-ia-fraude-millonario-brasil-influencer-cyber-conquista-instagram_0_I4y9VAB97W.html">clic en este enlace</a></p><p>Para leer sobre la apertura y el d&#237;a 1, <a href="https://www.brodersendarknews.com/p/ekoparty-llego-a-miami-con-ia-chips">clic ac&#225;</a></p><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial generativa para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/como-fue-ekoparty-miami-hackers-latinos?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/como-fue-ekoparty-miami-hackers-latinos?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Ekoparty llegó a Miami con IA, chips y cámaras de seguridad en el centro de la escena]]></title><description><![CDATA[La conferencia hacker debut&#243; en Estados Unidos. Una investigaci&#243;n mostr&#243; c&#243;mo la IA puede acelerar la ingenier&#237;a inversa de chips poco documentados. Reportaje del primer d&#237;a.]]></description><link>https://www.brodersendarknews.com/p/ekoparty-llego-a-miami-con-ia-chips</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/ekoparty-llego-a-miami-con-ia-chips</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Fri, 22 May 2026 11:03:53 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!8yoX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4122fd04-3983-4425-af3c-beffb4c77a21_4032x2268.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><p><em><strong>Edici&#243;n especial Ekoparty Miami, d&#237;a 1.</strong></em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>15-22<br>jun</h1><h2><strong>&#9889;TL;DR</strong></h2><p><strong>Ekoparty</strong> debut&#243; en el extranjero: la conferencia de hackers nacida hace m&#225;s de 20 a&#241;os en Argentina tuvo su primera experiencia de visitante (y se sinti&#243;).</p><p>En una sala de conferencias del Loews Hotel, en South Beach Miami, dos de los fundadores de la conferencia hicieron el <em>kickoff</em> para un keynote cargado de cr&#237;ticas al modelo actual de la industria de la ciberseguridad a cargo de Juan Andr&#233;s Guerrero-Saade de SentinelOne.</p><p>Bajo un aire acondicionado g&#233;lido que contrastaba con la alta (y h&#250;meda) temperatura exterior, transcurri&#243; el primer d&#237;a, del cual rescat&#233; dos charlas y las desarroll&#233; a modo de cr&#243;nica.</p><p>Se nota que la conferencia todav&#237;a est&#225; en construcci&#243;n. Le falta camino para replicar el clima de Buenos Aires, por geograf&#237;a, tradici&#243;n y tambi&#233;n por composici&#243;n del p&#250;blico: en Miami, la Eko busca armar un hub latinoamericano m&#225;s amplio, con asistentes de unas 18 nacionalidades y una identidad com&#250;n todav&#237;a en formaci&#243;n.</p><p>Uno de los problemas m&#225;s grandes que viene teniendo la conferencia es que, al estar todo en un mismo lugar, las charlas de los distintos tracks se superponen y hacen dif&#237;cil poder escuchar a los speakers.</p><p></p><p>Fuera de la conferencia, el tema de la semana fue un compromiso de unos <a href="https://thehackernews.com/2026/05/github-investigating-teampcp-claimed.html">3.800 repositorios internos de </a><strong><a href="https://thehackernews.com/2026/05/github-investigating-teampcp-claimed.html">GitHub</a></strong> a trav&#233;s del acceso por la computadora de un empleado. ShinyHunters, de quien hablamos en la entrega pasada, sigue activo: ahora <a href="https://therecord.media/huawei-zero-day-behind-last-year-luxembourg-telecom-outage">hackearon a 7-Eleven</a> y postearon a la cadena como v&#237;ctima en su DLS.</p><p>En el mundo Big Tech y regulaciones IA, <a href="https://edition.cnn.com/2026/05/18/tech/openai-musk-lawsuit-verdict">Elon Musk perdi&#243; la demanda con Sam Altman</a>. Y arXiv, repositorio de papers donde se publica mucho sobre temas de ciberseguridad, va a <strong><a href="https://x.com/tdietterich/status/2055000956144935055">prohibir papers producidos con IA</a></strong>.</p><p>Por cuestiones de tiempo, dejo en la selecci&#243;n de abajo de todo los temas m&#225;s importantes que cruc&#233; de agenda de ciberseguridad y hacking de la semana.</p><p>En esta entrega, reproduzco en esta edici&#243;n el <a href="https://www.clarin.com/tecnologia/argentina-miami-ekoparty-abrio-primera-edicion-internacional-ia-chips-camaras-lupa_0_m2ZMgtC3BS.html">reportaje publicado en </a><strong><a href="https://www.clarin.com/tecnologia/argentina-miami-ekoparty-abrio-primera-edicion-internacional-ia-chips-camaras-lupa_0_m2ZMgtC3BS.html">Clar&#237;n</a>, </strong>desde Miami.</p><div><hr></div><p>&#9200; <em>Substack dice que leer este correo completo lleva 13 minutos</em></p><p><em>Dark News #203</em></p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.kulkan.com/?utm_source=newsletter&amp;utm_medium=dark_news&amp;utm_campaign=quote#quote" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qXPk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 424w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 848w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 1272w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qXPk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png" width="600" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/379ea089-6930-4e5c-a652-27cb153177d8_600x300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:136661,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.kulkan.com/?utm_source=newsletter&amp;utm_medium=dark_news&amp;utm_campaign=quote#quote&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/193094978?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qXPk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 424w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 848w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 1272w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></div><h3>De Argentina a Miami: Ekoparty abri&#243; su primera edici&#243;n internacional con IA, chips y c&#225;maras bajo la lupa</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8yoX!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4122fd04-3983-4425-af3c-beffb4c77a21_4032x2268.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8yoX!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4122fd04-3983-4425-af3c-beffb4c77a21_4032x2268.jpeg 424w, https://substackcdn.com/image/fetch/$s_!8yoX!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4122fd04-3983-4425-af3c-beffb4c77a21_4032x2268.jpeg 848w, https://substackcdn.com/image/fetch/$s_!8yoX!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4122fd04-3983-4425-af3c-beffb4c77a21_4032x2268.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!8yoX!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4122fd04-3983-4425-af3c-beffb4c77a21_4032x2268.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8yoX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4122fd04-3983-4425-af3c-beffb4c77a21_4032x2268.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4122fd04-3983-4425-af3c-beffb4c77a21_4032x2268.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2532373,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/198271234?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4122fd04-3983-4425-af3c-beffb4c77a21_4032x2268.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!8yoX!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4122fd04-3983-4425-af3c-beffb4c77a21_4032x2268.jpeg 424w, https://substackcdn.com/image/fetch/$s_!8yoX!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4122fd04-3983-4425-af3c-beffb4c77a21_4032x2268.jpeg 848w, https://substackcdn.com/image/fetch/$s_!8yoX!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4122fd04-3983-4425-af3c-beffb4c77a21_4032x2268.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!8yoX!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4122fd04-3983-4425-af3c-beffb4c77a21_4032x2268.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Gast&#243;n Aznarez y Dan Borgogno, en una de las primeras charlas del Loews Hotel de Miami Beach. Foto: Juan Brodersen</figcaption></figure></div><p><strong>Ekoparty</strong>, la conferencia de hackers nacida en Argentina y convertida en una referencia regional de la ciberseguridad, abri&#243; esta semana s<strong>u primera edici&#243;n en Miami </strong>con una agenda repleta de vulnerabilidades, riesgos por tener cada vez m&#225;s dispositivos conectados a internet, c&#225;maras de seguridad f&#225;ciles de atacar y los beneficios (y riesgos) que trae la <strong><a href="https://www.clarin.com/tecnologia/anthropic-encendio-alarma-industria-ia-preocupa-potencial-hackear-sistemas_0_VxhHLI0iY5.html">inteligencia artificial.</a></strong></p><p>Con m&#225;s de 500 inscriptos, Ekoparty abri&#243; sus puertas cerca de las 9.30 de la ma&#241;ana de este jueves con las palabras de uno de sus fundadores, el actual CEO, Leonardo Pig&#241;er: &#8220;Para nosotros, Ekoparty <strong>se trata de construir puentes y conectar gente</strong>. Creo que lo que podemos traer de diferente es un nuevo punto de encuentro para conectar con la comunidad latinoamericana de la ciberseguridad&#8221;, asegur&#243; en el escenario del<strong> Hotel Loews, South Beach de Miami.</strong></p><p>Como ocurre con buena parte de la agenda tecnol&#243;gica actual, la charla de apertura (keynote) del primer d&#237;a estuvo dedicada a la inteligencia artificial. Juan Andr&#233;s Guerrero-Saade, un experimentado hacker de la industria, advirti&#243; que la IA suele presentarse como una herramienta capaz de &#8220;democratizar&#8221; el acceso a tareas t&#233;cnicas, como programar o analizar informaci&#243;n, pero que tambi&#233;n hay <strong>un efecto &#8220;multiplicador&#8221;</strong> sobre quienes deben usarla en sus trabajos.</p><p>&#8220;Creo que el valor de la inteligencia artificial est&#225; en su poder multiplicador. Si alguien ya tiene capacidades en su &#225;rea, la IA puede multiplicar su rendimiento diez veces. Cosas que antes tomaban semanas o meses, ahora se pueden resolver en horas. El problema es que falta orientaci&#243;n: en lugar de ver ese beneficio, mucha gente siente <strong>miedo y ansiedad</strong> frente a procesos que ahora se vuelven m&#225;s accesibles y baratos&#8221;, dijo a <strong>Clar&#237;n</strong> al bajar del escenario.</p><p>&#8220;Esto tambi&#233;n genera una crisis sobre c&#243;mo asignamos valor al trabajo. Si una presentaci&#243;n de PowerPoint que antes llevaba mucho tiempo ahora se puede generar en 30 segundos,<strong> &#191;cu&#225;nto vale ese producto?</strong> Esa incertidumbre est&#225; llevando a algunas empresas a tomar decisiones precipitadas, incluso despedir a gente esencial&#8221;, sigui&#243; el vicepresidente de Investigaci&#243;n en Inteligencia y Seguridad de <strong>SentinelOne</strong>.</p><p>&#8220;Despu&#233;s, seis meses m&#225;s tarde, intentan recontratar a esos mismos expertos, con una relaci&#243;n laboral ya da&#241;ada. <strong>El desaf&#237;o es aprender a valorar la experiencia detr&#225;s del trabajo</strong> y compensarla correctamente, para construir una relaci&#243;n m&#225;s simbi&#243;tica entre empleados y empleadores&#8221;, cerr&#243;.</p><p>Luego de su charla comenzaron otras actividades caracter&#237;sticas de una convenci&#243;n de hackers: desde los <em>villages</em> tem&#225;ticos y los talleres de <em><strong>lockpicking</strong></em> (abrir cerraduras) hasta las demostraciones t&#233;cnicas, los espacios de intercambio entre investigadores y las charlas sobre vulnerabilidades, IA y seguridad ofensiva.</p><h2>La inteligencia artificial, aliada (y enemiga) hacker</h2><p>Una de las charlas destacadas del primer d&#237;a tuvo que ver con una investigaci&#243;n sobre c&#243;mo la IA puede ayudar a hacer ingenier&#237;a inversa, una parte fundamental del hacking: analizar un programa, un sistema o una aplicaci&#243;n desde adentro para <strong>entender c&#243;mo funciona, detectar errores y eventualmente encontrar vulnerabilidades de seguridad</strong>.</p><p><strong>Gast&#243;n Aznarez y Dan Borgogno</strong>, investigadores de Faraday Security, empresa de ciberseguridad argentina, analizaron un problema muy espec&#237;fico del mundo de la ingenier&#237;a inversa: qu&#233; pasa cuando un investigador analiza un dispositivo y descubre que su arquitectura no es x86 o ARM (las m&#225;s conocidas), sino una propietaria, con poca o ninguna documentaci&#243;n p&#250;blica. &#191;C&#243;mo se hace para romper un sistema que no se conoce?</p><p>&#8220;Detr&#225;s de muchos dispositivos electr&#243;nicos modernos hay un chip ejecutando c&#243;digo que nadie fuera del fabricante puede leer. Eso incluye cosas que la gente usa todos los d&#237;as: <strong>autos, marcapasos, c&#225;maras de seguridad, routers, juguetes conectados, electrodom&#233;sticos inteligentes</strong>. Cuando uno de esos dispositivos tiene una vulnerabilidad, un fallo que permite, por ejemplo, que alguien tome el control remoto del auto o esp&#237;e a trav&#233;s de la c&#225;mara, la &#250;nica forma de descubrirla antes que un atacante es analizar el chip por dentro&#8221;, explic&#243; Aznarez a <strong>Clar&#237;n</strong>.</p><p>&#8220;El problema es que a veces el fabricante <strong>no publica c&#243;mo funciona</strong>. La industria llama a esto &#8216;seguridad por oscuridad&#8217;: la idea de que si nadie sabe c&#243;mo est&#225; hecho algo, nadie va a poder romperlo. En la pr&#225;ctica esa idea no funciona, porque los atacantes con suficientes recursos terminan descifr&#225;ndolo igual, los &#250;nicos que se quedan afuera son los investigadores independientes que podr&#237;an avisar de los problemas antes de que se exploten. Hay demasiados chips y demasiado pocos investigadores&#8221;, complement&#243; Borgogno.</p><p>La IA, sostienen, puede acelerar esa tarea. &#8220;<strong>Ac&#225; es donde la inteligencia artificial cambia las reglas.</strong> Los modelos de lenguaje actuales son particularmente buenos en dos tareas que antes requer&#237;an un experto humano: reconocer patrones en texto que parece sin sentido, y razonar sobre estructuras desconocidas para deducir qu&#233; significan. Aplicados a este problema, permiten automatizar gran parte del trabajo que antes hac&#237;a un especialista a mano, y generalizar a chips para los que nunca antes hubo herramientas. Lo que antes tomaba meses puede pasar a tomar d&#237;as&#8221;, dice Aznarez.</p><p>Sobre el impacto de la inteligencia artificial en la ciberseguridad durante 2026, los investigadores plantean que el cambio principal est&#225; en la escala del trabajo.</p><p>&#8220;Lo que estamos viendo en lo que va de 2026 es un cambio en la econom&#237;a del research de seguridad. Antes, encontrar vulnerabilidades en un producto requer&#237;a que un investigador o un equipo dedicara meses, a veces a&#241;os, a entender c&#243;mo funciona ese producto por dentro: abrirlo, leer firmware, iterar sobre hip&#243;tesis. Hoy, un sistema orquestado de agentes de IA puede tomarse como objetivo encontrar<strong> vulnerabilidades en una pieza de software</strong> y cubrir much&#237;simo m&#225;s terreno del que cubre una persona en el mismo tiempo. La capacidad de cobertura no es comparable&#8221;, dijo Aznarez.</p><h2>Vigilados y vulnerables: encuentran fallas en c&#225;maras de seguridad Hikvision</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SAhO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab018a87-e66a-4332-ba8c-d17029af16e0_720x405.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SAhO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab018a87-e66a-4332-ba8c-d17029af16e0_720x405.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SAhO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab018a87-e66a-4332-ba8c-d17029af16e0_720x405.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SAhO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab018a87-e66a-4332-ba8c-d17029af16e0_720x405.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SAhO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab018a87-e66a-4332-ba8c-d17029af16e0_720x405.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SAhO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab018a87-e66a-4332-ba8c-d17029af16e0_720x405.jpeg" width="720" height="405" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ab018a87-e66a-4332-ba8c-d17029af16e0_720x405.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:405,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;&#193;ngel Lozano Alc&#225;zar y Pedro Guill&#233;n, investigadores espa&#241;oles. Foto: Juan Brodersen&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="&#193;ngel Lozano Alc&#225;zar y Pedro Guill&#233;n, investigadores espa&#241;oles. Foto: Juan Brodersen" title="&#193;ngel Lozano Alc&#225;zar y Pedro Guill&#233;n, investigadores espa&#241;oles. Foto: Juan Brodersen" srcset="https://substackcdn.com/image/fetch/$s_!SAhO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab018a87-e66a-4332-ba8c-d17029af16e0_720x405.jpeg 424w, https://substackcdn.com/image/fetch/$s_!SAhO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab018a87-e66a-4332-ba8c-d17029af16e0_720x405.jpeg 848w, https://substackcdn.com/image/fetch/$s_!SAhO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab018a87-e66a-4332-ba8c-d17029af16e0_720x405.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!SAhO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fab018a87-e66a-4332-ba8c-d17029af16e0_720x405.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">&#193;ngel Lozano Alc&#225;zar y Pedro Guill&#233;n, investigadores espa&#241;oles. Foto: Juan Brodersen</figcaption></figure></div><p>Otra investigaci&#243;n presentada en la primera jornada se concentr&#243; en un tipo de equipo mucho m&#225;s com&#250;n para empresas, comercios y edificios: los grabadores de video en red, conocidos como NVR. La charla <em>Desde el Firmware al RCE: Atacando NVRs de <strong>Hikvision</strong></em>, de los investigadores espa&#241;oles &#193;ngel Lozano Alc&#225;zar y Pedro Guill&#233;n N&#250;&#241;ez, mostr&#243; el proceso completo para descubrir y explotar fallas<em> zero day</em> en dispositivos NVR de Hikvision, una de las marcas m&#225;s extendidas del mercado, <a href="https://www.clarin.com/tecnologia/alerta-falla-grave-seguridad-camaras-videovigilancia-vendidas-argentina_0_7koa3RH4rN.html">muy vendida en Argentina y Am&#233;rica Latina</a>.</p><p><strong>Un NVR</strong> es el equipo que centraliza, graba y administra las im&#225;genes de varias c&#225;maras de seguridad conectadas a una red. La investigaci&#243;n incluy&#243; obtenci&#243;n del <strong>firmware</strong> (el software interno que viene instalado en un dispositivo y le indica c&#243;mo funcionar), junto con la explotaci&#243;n y &#8220;persistencia&#8221;, algo clave que buscan los atacantes: no s&#243;lo entrar, sino permanecer (idealmente, sin ser detectados).</p><p>Para Lozano Alc&#225;zar y Guill&#233;n N&#250;&#241;ez, estos equipos pueden convertirse en un punto d&#233;bil dentro de muchas organizaciones porque se instalan y quedan funcionando durante a&#241;os. &#8220;Los grabadores de video en red, como los de Hikvision, forman parte del ecosistema de <a href="https://www.clarin.com/tecnologia/peligros-dispositivos-iot-entretenimiento-smart-tv-playstation_0_NCTwEYNZV.html">dispositivos IoT</a> orientados a la seguridad f&#237;sica. Su funci&#243;n principal es grabar y gestionar c&#225;maras, no actuar como sistemas inform&#225;ticos dise&#241;ados para resistir ciberataques. Y ah&#237; est&#225; el problema&#8221;, dijeron a este medio.</p><p>&#8220;En muchas empresas, estos equipos se instalan y quedan funcionando durante a&#241;os sin apenas mantenimiento. A diferencia de un ordenador o un servidor, no suelen recibir actualizaciones peri&#243;dicas, auditor&#237;as de seguridad o revisiones de configuraci&#243;n, incluso rara vez est&#225;n monitoreados. En algunos casos, <strong>siguen operando con credenciales por defecto</strong> o configuraciones poco seguras&#8221;, explicaron.</p><p>&#8220;El riesgo m&#225;s evidente es la p&#233;rdida de privacidad.<strong> Si un atacante accede a una c&#225;mara, puede ver en tiempo real</strong> lo que ocurre en un hogar, una oficina o una instalaci&#243;n cr&#237;tica. Por ejemplo, se puede acceder no s&#243;lo a im&#225;genes sino tambi&#233;n inferir rutinas, horarios, presencia o ausencia de personas&#8221;, explicaron.</p><p>El primer d&#237;a de la conferencia dej&#243; una foto actual de la ciberseguridad: la inteligencia artificial ya se usa para acelerar investigaciones t&#233;cnicas complejas, los dispositivos conectados siguen acumulando riesgos dif&#237;ciles de ver para el usuario com&#250;n y la comunidad hacker latinoamericana busca <strong>ocupar un lugar propio </strong>en una agenda cada vez m&#225;s global.</p><div><hr></div><h4><strong>&#128275; Breaches y hacks</strong></h4><ul><li><p><a href="https://databreaches.net/2026/05/21/github-confirms-breach-of-3800-repos-via-malicious-vscode-extension/?pk_campaign=feed&amp;pk_kwd=github-confirms-breach-of-3800-repos-via-malicious-vscode-extension&amp;__cf_chl_rt_tk=zA4Dv1Xtb77TjnJK7_ffbdaH.oKV7I77jrOpk7Q_Ulw-1779419202-1.0.1.1-5HbjeU_kxCN_M204EBN7shMHf5K4LqUamwR8DCMfmX0">GitHub confirm&#243;</a> un breach interno que filtr&#243; 3.800 repositorios</p></li><li><p>Las p&#233;rdidas por <a href="https://www.ic3.gov/PSA/2026/PSA260515-2">estafas cripto en ATMs</a> (cajeros) alacanz&#243; 388 millones en EE.UU.</p></li><li><p>Hackean otra de las cuentas del director del FBI</p></li></ul><h4><strong>&#128274; Ransomware</strong></h4><ul><li><p><a href="https://sheriff.birminghamcyberarms.co.uk/alert?id=476">Grupo Petersen (Argentina)</a> apareci&#243; listado como v&#237;ctima de ransomware (APT73)</p></li><li><p>Aparece un nuevo grupo de extorsi&#243;n: <a href="https://cloud.google.com/blog/topics/threat-intelligence/blackfile-vishing-extortion-operation">BlackFile</a></p></li><li><p>Incautan los servicios de First VPN, usados por <a href="https://hackread.com/europol-seizes-first-vpn-ransomware-administrator-arrest/">grupos de ransomware</a></p></li></ul><h4><strong>&#128163; Exploits y malware</strong></h4><ul><li><p>El breach en GitHub ya se conecta a un <a href="https://www.bleepingcomputer.com/news/security/cybercrime-service-disrupted-for-abusing-microsoft-platform-to-sign-malware/">supply chain npm</a></p></li><li><p><a href="https://www.gamespot.com/articles/another-steam-game-gets-removed-over-malware/1100-6540044/">Steam</a> remueve otro juego por tener malware</p></li><li><p>Encuentran malware en <a href="https://hackread.com/android-malware-subscribe-services-without-consent/">Android</a> en servicios de suscripci&#243;n</p></li></ul><h4><strong>&#128269; Threat intel y vulnerabilidades</strong></h4><ul><li><p>Un servicio abusaba de una plataforma de Microsoft para <a href="https://www.bleepingcomputer.com/news/security/cybercrime-service-disrupted-for-abusing-microsoft-platform-to-sign-malware/">firmar digitalmente malware</a></p></li><li><p>Hackers chinos apuntan a <a href="https://www.bleepingcomputer.com/news/security/cybercrime-service-disrupted-for-abusing-microsoft-platform-to-sign-malware/">telcos</a> con malware para Windows y Linux</p></li><li><p>Reportes: <a href="https://www.crowdstrike.com/en-us/blog/crowdstrike-2026-financial-services-threat-landscape-report/">CrowdStrike</a>, <a href="https://www.cyfirma.com/research/tracking-ransomware-apr-2026/">CyFirma</a>, <a href="https://www.vulncheck.com/blog/ai-assisted-vulnerability-discovery">VulnCheck</a>, <a href="https://securelist.com/malware-report-q1-2026-pc-iot-statistics/119828/">Kaspersky</a>, <a href="https://www.verizon.com/business/resources/reports/dbir/">Verizon</a>   </p></li></ul><h4><strong>&#128736;&#65039; Tools y updates</strong></h4><ul><li><p><a href="https://www.bleepingcomputer.com/news/security/discord-rolls-out-end-to-end-encryption-on-voice-video-calls/">Discord</a> aplica cifrado de punta a punta en llamadas de voz y video</p></li><li><p>Google cambia la cuota de espacio gratuito <a href="https://sheriff.birminghamcyberarms.co.uk/alert?id=476">de 15 a 5 GB</a></p></li><li><p>Firefox actualiza a la <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2026-46/">versi&#243;n 151</a> con fixes de seguridad</p></li></ul><h4><strong>&#128203; Privacidad y regulaciones</strong></h4><ul><li><p>Encuentran <a href="https://www.theguardian.com/technology/2026/may/20/ai-chatbots-chatgpt-replika-grok-gemini-misinformation-scottish-election-demos">errores graves de ChatGPT</a> y otros chatbots en procesos electorales europeos</p></li><li><p><a href="https://www.theguardian.com/technology/2026/may/19/meta-jobs-ai-transfers">Meta reorganiza</a> a sus empleados en torno a la IA</p></li><li><p><a href="https://www.nytimes.com/2026/05/21/technology/trump-ai-executive-order.html">Trump da marcha atr&#225;s</a> con una orden ejecutiva sobre la IA</p><p></p></li></ul><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/ekoparty-llego-a-miami-con-ia-chips?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/ekoparty-llego-a-miami-con-ia-chips?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[ShinyHunters cobró el rescate: Canvas pagó para evitar la filtración de datos robados]]></title><description><![CDATA[Adem&#225;s: el Gobierno da 180 d&#237;as a organismos para mejorar sistemas, Foxconn confirma un ciberataque, Linux trabaja en un killswitch por Copy Fail y Xbow explota una vulnerabilidad en Exim.]]></description><link>https://www.brodersendarknews.com/p/shinyhunters-cobro-el-rescate-canvas</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/shinyhunters-cobro-el-rescate-canvas</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Fri, 15 May 2026 11:03:24 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!LfVV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648c69d0-2269-48d5-a702-e7026231aa48_1672x941.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><div><hr></div><p><em><strong>&#9992;&#65039; IMPORTANTE: </strong>La semana que viene estar&#233; en Florida, Estados Unidos, por la primera edici&#243;n de <strong><a href="https://ekoparty.org/miami/">Ekoparty en Miami</a></strong>. Las pr&#243;ximas dos entregas, viernes y domingo, saldr&#225;n desde all&#225;.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>8~15<br>may</h1><h2><strong>&#9889;TL;DR</strong></h2><p>No es habitual leer que una empresa pag&#243; un rescate en un caso de <strong>ransomware</strong> (con o sin cifrado de datos). Esta semana, distintas publicaciones reportaron que Instructure, empresa detr&#225;s de la plataforma educativa <strong>Canvas</strong>, <strong><a href="https://www.reuters.com/legal/litigation/canvas-parent-company-reaches-agreement-with-hacking-group-behind-recent-breach-2026-05-12/">&#8220;lleg&#243; a un acuerdo&#8221;</a> con ShinyHunters</strong>: <strong><a href="https://www.bbc.com/news/articles/cdepzg83x87o">BBC</a></strong> incluso asegura que pagaron. </p><p><strong>ShinyHunters</strong> es un grupo de atacantes que tiene una reputaci&#243;n enorme en el ecosistema cibercriminal. Llev&#243; adelante, durante las &#250;ltimas semanas, ataques de alto perfil que llamaron mucho la atenci&#243;n, Udemy, Vimeo, Rockstar Games, ADT, entre otros. Como hab&#237;amos dicho, se estaban poniendo un blanco sobre la espalda. El a&#241;o pasado se hab&#237;an fusionado en una supuesta <em><strong><a href="https://www.brodersendarknews.com/p/scattered-lapsus-hunters-fusion-ingenieria-social">trinidad del caos</a>.</strong> </em>Ahora, <a href="https://www.bleepingcomputer.com/news/security/us-govt-seeks-instructure-testimony-on-massive-canvas-cyberattack/">el FBI</a> los sigue de cerca, uno de sus dominios fue <a href="https://hackread.com/canvas-hackers-shinyhunters-official-domain-suspended/">dado de baja</a> y el Gobierno de EE.UU. <a href="https://www.bleepingcomputer.com/news/security/us-govt-seeks-instructure-testimony-on-massive-canvas-cyberattack/">llam&#243; a declarar</a> a directivos de la empresa due&#241;a de Canvas.</p><p>Hubo movimiento en <strong>Am&#233;rica Latina</strong>. En Uruguay, ciberdelincuentes <a href="https://www.elobservador.com.uy/ciberdelincuentes-filtran-accesos-servidores-una-empresa-antel-n6043757">filtraron accesos a servidores de una empresa de Antel</a>, principal telco e ISP del pa&#237;s. En Argentina, al poco tiempo de que apareciera <a href="https://x.com/DarkWebInformer/status/2052104641404383527">un lote de datos</a> del Estado a la venta,<strong> el &#225;rea de sistemas de ANSES experiment&#243; problemas</strong>. El Centro Nacional de Ciberseguridad lanz&#243; su primera resoluci&#243;n (ver abajo) y <strong>a los dos d&#237;as apareci&#243; a la venta</strong> una <a href="https://x.com/DailyDarkWeb/status/2055053434563228095">presunta base de datos del Ministerio de Salud</a> en un foro cibercriminal. El researcher <a href="https://www.linkedin.com/in/moises-cerqueira/">Moises Cerqueira</a> public&#243; en detalle una campa&#241;a de un a&#241;o y medio del <a href="https://any.run/cybersecurity-blog/agent-tesla-latam-enterprise/">troyano Agent Tesla (RAT) en Chile</a>, robando credenciales. </p><p>En el mundo del research, Xbow encontr&#243; <a href="https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim">una vulnerabilidad explotable en </a><strong><a href="https://xbow.com/blog/dead-letter-cve-2026-45185-xbow-found-rce-exim">Exim</a></strong>, popular servidor de correo usado en Linux. El caso es interesante porque la empresa es <em>AI-driven</em>, pero la investigaci&#243;n demuestra los l&#237;mites del pentesting automatizado y <strong>d&#243;nde el humano es crucial</strong> a la hora de desarrollar un <strong>exploit</strong>.</p><p>Adem&#225;s, Google dice que fren&#243; una explotaci&#243;n masiva de vulnerabilidades con IA, <strong>Foxconn</strong> confirm&#243; un ciberataque y <strong>Linux</strong> trabaja en un <em>killswitch</em> a partir de los efectos de <a href="https://www.brodersendarknews.com/p/dos-fallas-criticas-linux-cpanel-exploits">Copy Fail</a> y <a href="https://www.brodersendarknews.com/i/196316042/dirty-frag-otra-falla-critica-permite-obtener-root-en-linux">Dirty Frag</a>.</p><p>Y el coraz&#243;n <em><strong>warez</strong></em> se sigue estrujando. La semana pasada, Daemon Tools distribuy&#243; una <a href="https://www.brodersendarknews.com/p/google-chrome-descarga-modelo-ia-sin-permiso?open=false#%C2%A7daemon-tools-distribuyo-una-version-con-backdoor-durante-casi-un-mes">versi&#243;n infectada</a>. Ahora, <a href="https://jdownloader.org/incident_8.5.2026.html?v=20260508277000">JDownloader</a> fue hackeado y puso en circulaci&#243;n instaladores con malware.</p><p>La perlita de la semana: no paran de aparecer ataques de <em>supply chain</em> con paquetes npm (<a href="https://hackread.com/teampcp-mini-shai-hulud-worm-npm-pypi-packages/">por ejemplo</a>). Y este tuit me pareci&#243; muy representativo:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4Nco!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65105519-702f-489f-8c57-d2bec3c2ef72_734x562.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4Nco!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65105519-702f-489f-8c57-d2bec3c2ef72_734x562.png 424w, https://substackcdn.com/image/fetch/$s_!4Nco!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65105519-702f-489f-8c57-d2bec3c2ef72_734x562.png 848w, https://substackcdn.com/image/fetch/$s_!4Nco!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65105519-702f-489f-8c57-d2bec3c2ef72_734x562.png 1272w, https://substackcdn.com/image/fetch/$s_!4Nco!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65105519-702f-489f-8c57-d2bec3c2ef72_734x562.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4Nco!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65105519-702f-489f-8c57-d2bec3c2ef72_734x562.png" width="734" height="562" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/65105519-702f-489f-8c57-d2bec3c2ef72_734x562.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:562,&quot;width&quot;:734,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:235089,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/197269600?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65105519-702f-489f-8c57-d2bec3c2ef72_734x562.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!4Nco!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65105519-702f-489f-8c57-d2bec3c2ef72_734x562.png 424w, https://substackcdn.com/image/fetch/$s_!4Nco!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65105519-702f-489f-8c57-d2bec3c2ef72_734x562.png 848w, https://substackcdn.com/image/fetch/$s_!4Nco!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65105519-702f-489f-8c57-d2bec3c2ef72_734x562.png 1272w, https://substackcdn.com/image/fetch/$s_!4Nco!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F65105519-702f-489f-8c57-d2bec3c2ef72_734x562.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Para cerrar la intro, la semana que viene voy a cubrir la primera edici&#243;n de Ekoparty Miami desde el lugar. La idea es relevar, m&#225;s all&#225; de las charlas, c&#243;mo es una conferencia argentina en suelo norteamericano. </p><p>El viernes voy a enviar un reportaje con los findings presentados y, probablemente, el domingo haga una entrega sobre el pulso de la conferencia.</p><div><hr></div><p><em>En esta edici&#243;n:</em></p><ul><li><p>&#128275; <em><a href="https://www.brodersendarknews.com/i/197269600/shinyhunters-cobro-el-rescate-canvas-pago-para-recuperar-los-datos-robados">ShinyHunters cobr&#243; el rescate: Canvas pag&#243; para recuperar los datos robados</a></em></p></li><li><p>&#127963;&#65039; <em><a href="https://www.brodersendarknews.com/i/197269600/el-gobierno-da-180-dias-a-organismos-estatales-para-preparar-sus-sistemas-ante-ciberataques">El Gobierno da 180 d&#237;as a organismos estatales para preparar sus sistemas ante ciberataques</a></em></p></li><li><p>&#129302; <em><a href="https://www.brodersendarknews.com/i/197269600/google-dice-que-freno-una-explotacion-masiva-de-vulnerabilidades-con-ia">Google dice que fren&#243; una explotaci&#243;n masiva de vulnerabilidades con IA</a></em></p></li><li><p>&#127981; <em><a href="https://www.brodersendarknews.com/i/197269600/foxconn-confirma-un-ciberataque-en-su-division-de-eeuu">Foxconn confirma un ciberataque en su divisi&#243;n de EE.UU.</a></em></p></li><li><p>&#128236; <em><a href="https://www.brodersendarknews.com/i/197269600/xbow-encuentra-una-vulnerabilidad-con-exploit-en-exim-deadletter">Xbow encuentra una vulnerabilidad con exploit en Exim: dead.letter</a></em></p></li><li><p>&#129519; <em><a href="https://www.brodersendarknews.com/i/197269600/linux-trabaja-en-un-killswitch-efectos-de-copy-fail-y-dirty-frag">Linux trabaja en un killswitch: efectos de Copy Fail y Dirty Frag</a></em></p></li></ul><p>&#9200; <em>Substack dice que leer este correo completo lleva 13 minutos</em></p><p><em>Dark News #202</em></p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://bloka.red/contacto/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gebg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 424w, https://substackcdn.com/image/fetch/$s_!gebg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 848w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1272w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png" width="1456" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1127539,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://bloka.red/contacto/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194107355?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gebg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 424w, https://substackcdn.com/image/fetch/$s_!gebg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 848w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1272w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></div><h3><strong>ShinyHunters cobr&#243; el rescate: Canvas pag&#243; para recuperar los datos robados</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!LfVV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648c69d0-2269-48d5-a702-e7026231aa48_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!LfVV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648c69d0-2269-48d5-a702-e7026231aa48_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!LfVV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648c69d0-2269-48d5-a702-e7026231aa48_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!LfVV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648c69d0-2269-48d5-a702-e7026231aa48_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!LfVV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648c69d0-2269-48d5-a702-e7026231aa48_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!LfVV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648c69d0-2269-48d5-a702-e7026231aa48_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/648c69d0-2269-48d5-a702-e7026231aa48_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1185427,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/197269600?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648c69d0-2269-48d5-a702-e7026231aa48_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!LfVV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648c69d0-2269-48d5-a702-e7026231aa48_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!LfVV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648c69d0-2269-48d5-a702-e7026231aa48_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!LfVV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648c69d0-2269-48d5-a702-e7026231aa48_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!LfVV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F648c69d0-2269-48d5-a702-e7026231aa48_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">El texto que instal&#243; el grupo en los sistemas de Instructure</figcaption></figure></div><p>Instructure, la empresa detr&#225;s de Canvas, <a href="https://www.bbc.com/news/articles/cdepzg83x87o">confirm&#243; que lleg&#243; a un acuerdo</a> con <strong>ShinyHunters</strong> para evitar la publicaci&#243;n de datos robados tras un ataque que afect&#243; a unas 9.000 instituciones educativas.</p><p><strong>Qu&#233; pas&#243;.</strong> La compa&#241;&#237;a dijo que el acuerdo incluy&#243; la devoluci&#243;n de los datos, una &#8220;confirmaci&#243;n digital&#8221; de destrucci&#243;n y el compromiso de que los clientes afectados no ser&#225;n extorsionados. </p><p>Instructure no detall&#243; los t&#233;rminos ni dijo de manera expl&#237;cita que pag&#243; un rescate, pero el caso tiene todos los rasgos de una negociaci&#243;n de extorsi&#243;n: datos robados, amenaza de filtraci&#243;n y presi&#243;n para pagar en bitcoin.</p><p><strong>Operaci&#243;n at&#237;pica.</strong> Pagarle a grupos criminales va contra la recomendaci&#243;n de agencias de seguridad y fuerzas policiales en todo el mundo. Esto es porque es imposible tener garant&#237;as del borrado de la informaci&#243;n.</p><p>En casos anteriores, como <strong>LockBit</strong>, las autoridades encontraron datos que segu&#237;an en manos de criminales incluso despu&#233;s de pagos de rescate.</p><p><strong>El impacto.</strong> El ataque dio de baja el servicio de Canvas y afect&#243; a universidades de Estados Unidos, Canad&#225;, Australia y el Reino Unido. En algunos casos interrumpi&#243; ex&#225;menes online. </p><p>Una estudiante de meteorolog&#237;a de Mississippi State University <a href="https://www.bbc.com/news/articles/cdepzg83x87o">cont&#243; a la BBC</a> que acababa de terminar un ensayo de 2.900 palabras cuando apareci&#243; en pantalla una nota de rescate atribuida a ShinyHunters.</p><p><strong>El dato.</strong> Los hackers amenazaban con publicar 3,5 terabytes de datos de estudiantes y universidades. Seg&#250;n Instructure, su prioridad fue proteger la informaci&#243;n de alumnos y personal educativo, aunque la propia empresa admiti&#243; que &#8220;nunca hay certeza completa&#8221; cuando se negocia con ciberdelincuentes.</p><h3>El Gobierno da 180 d&#237;as a organismos estatales para preparar sus sistemas ante ciberataques</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!izL4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e46f70f-e19e-45b1-ba4b-42f8748adeaf_2045x1246.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!izL4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e46f70f-e19e-45b1-ba4b-42f8748adeaf_2045x1246.png 424w, https://substackcdn.com/image/fetch/$s_!izL4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e46f70f-e19e-45b1-ba4b-42f8748adeaf_2045x1246.png 848w, https://substackcdn.com/image/fetch/$s_!izL4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e46f70f-e19e-45b1-ba4b-42f8748adeaf_2045x1246.png 1272w, https://substackcdn.com/image/fetch/$s_!izL4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e46f70f-e19e-45b1-ba4b-42f8748adeaf_2045x1246.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!izL4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e46f70f-e19e-45b1-ba4b-42f8748adeaf_2045x1246.png" width="1456" height="887" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4e46f70f-e19e-45b1-ba4b-42f8748adeaf_2045x1246.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:887,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:4000513,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/197269600?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e46f70f-e19e-45b1-ba4b-42f8748adeaf_2045x1246.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!izL4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e46f70f-e19e-45b1-ba4b-42f8748adeaf_2045x1246.png 424w, https://substackcdn.com/image/fetch/$s_!izL4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e46f70f-e19e-45b1-ba4b-42f8748adeaf_2045x1246.png 848w, https://substackcdn.com/image/fetch/$s_!izL4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e46f70f-e19e-45b1-ba4b-42f8748adeaf_2045x1246.png 1272w, https://substackcdn.com/image/fetch/$s_!izL4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4e46f70f-e19e-45b1-ba4b-42f8748adeaf_2045x1246.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Emmanuel Fern&#225;ndez</figcaption></figure></div><p>El Centro Nacional de Ciberseguridad, conducido por <strong><a href="https://www.brodersendarknews.com/p/ariel-wata-waissbein-agencia-ciberseguridad">Ariel Waissbein</a></strong>, <a href="https://www.boletinoficial.gob.ar/detalleAviso/primera/341893/20260513">public&#243; su primera disposici&#243;n</a> y fij&#243; la obligaci&#243;n de que los organismos del Sector P&#250;blico Nacional que usen centros de datos o infraestructura tecnol&#243;gica <strong>tengan planes</strong> de contingencia, recuperaci&#243;n ante desastres y centros de procesamiento alternativos. </p><p>El plazo para adecuarse es de <strong>180 d&#237;as.</strong></p><p><strong>Qu&#233; pas&#243;.</strong> La Disposici&#243;n 1/2026 aprueba un reglamento t&#233;cnico con requisitos m&#237;nimos de continuidad operativa y resiliencia digital. La norma alcanza a los organismos incluidos en el art&#237;culo 8 de la Ley 24.156 y busca que los sistemas cr&#237;ticos del Estado puedan sostener o recuperar servicios ante ciberataques, fallas graves, desastres o incidentes inform&#225;ticos.</p><p><strong>El punto central.</strong> Cada organismo deber&#225; presentar un informe de cumplimiento de su Plan de Recuperaci&#243;n ante Desastres. Tiene que incluir, cuando corresponda, la ubicaci&#243;n del centro alternativo, caracter&#237;sticas t&#233;cnicas, resultados de al menos una prueba inicial de conmutaci&#243;n al sitio de respaldo y los par&#225;metros RTO/RPO: cu&#225;nto tarda un sistema en volver a estar operativo y desde qu&#233; punto puede recuperar la informaci&#243;n.</p><p><strong>Por qu&#233; importa.</strong> La medida marca el primer movimiento operativo fuerte del nuevo CNC como autoridad t&#233;cnica en ciberseguridad del Estado. Tambi&#233;n obliga a pasar de lineamientos generales a planes escritos, infraestructura alternativa, pruebas reales y tiempos de recuperaci&#243;n definidos.</p><h3>Google dice que fren&#243; una explotaci&#243;n masiva de vulnerabilidades con IA</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!In3_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F704efd75-7d4d-4d9f-8158-8036e9affc74_1460x888.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!In3_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F704efd75-7d4d-4d9f-8158-8036e9affc74_1460x888.png 424w, https://substackcdn.com/image/fetch/$s_!In3_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F704efd75-7d4d-4d9f-8158-8036e9affc74_1460x888.png 848w, https://substackcdn.com/image/fetch/$s_!In3_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F704efd75-7d4d-4d9f-8158-8036e9affc74_1460x888.png 1272w, https://substackcdn.com/image/fetch/$s_!In3_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F704efd75-7d4d-4d9f-8158-8036e9affc74_1460x888.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!In3_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F704efd75-7d4d-4d9f-8158-8036e9affc74_1460x888.png" width="1456" height="886" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/704efd75-7d4d-4d9f-8158-8036e9affc74_1460x888.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:886,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1781743,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/197269600?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F704efd75-7d4d-4d9f-8158-8036e9affc74_1460x888.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!In3_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F704efd75-7d4d-4d9f-8158-8036e9affc74_1460x888.png 424w, https://substackcdn.com/image/fetch/$s_!In3_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F704efd75-7d4d-4d9f-8158-8036e9affc74_1460x888.png 848w, https://substackcdn.com/image/fetch/$s_!In3_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F704efd75-7d4d-4d9f-8158-8036e9affc74_1460x888.png 1272w, https://substackcdn.com/image/fetch/$s_!In3_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F704efd75-7d4d-4d9f-8158-8036e9affc74_1460x888.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: EFE</figcaption></figure></div><p>Google dice que <strong>fren&#243;</strong> un intento de usar IA para preparar una <a href="https://www.cnbc.com/2026/05/11/google-thwarts-effort-hacker-group-use-ai-mass-exploitation-event.html">operaci&#243;n masiva de explotaci&#243;n</a> de vulnerabilidades. Seg&#250;n su Threat Intelligence Group (GTIG), un actor criminal habr&#237;a usado un modelo de IA para encontrar y explotar una vulnerabilidad zero-day capaz de evadir la autenticaci&#243;n de dos factores.</p><p><strong>Qu&#233; pas&#243;.</strong> GTIG dijo que tiene &#8220;alta confianza&#8221; en haber registrado el uso de un modelo de IA para descubrir y explotar una falla desconocida por los desarrolladores. El objetivo era preparar una campa&#241;a de explotaci&#243;n masiva, aunque Google asegura que su detecci&#243;n proactiva pudo haber evitado que se usara.</p><p><strong>Dato clave.</strong> Google no identific&#243; al grupo detr&#225;s del intento y dijo que <strong>no cree que se haya usado Gemini</strong>, su propio modelo. El caso muestra otro salto en el uso ofensivo de IA, con herramientas disponibles para hackers que ayudan a encontrar fallas, construir exploits y automatizar partes de ataques que antes requer&#237;an m&#225;s trabajo manual.</p><p><strong>El contexto.</strong> Google mencion&#243; herramientas como OpenClaw y se&#241;al&#243; que grupos vinculados a China y Corea del Norte mostraron un inter&#233;s fuerte en usar IA para descubrir vulnerabilidades. </p><p>El reporte aparece luego de que <a href="https://www.brodersendarknews.com/p/anthropic-mythos-preview-modelo-riesgos">Anthropic retrasara el despliegue amplio de Mythos</a> por riesgos de ciberseguridad y OpenAI lanz&#243; GPT-5.5-Cyber en preview limitada para equipos defensivos evaluados.</p><h3>Foxconn confirma un ciberataque en su divisi&#243;n de EE.UU.</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!88za!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e73c642-9574-42ab-956c-d6570f4e27c1_1353x902.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!88za!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e73c642-9574-42ab-956c-d6570f4e27c1_1353x902.png 424w, https://substackcdn.com/image/fetch/$s_!88za!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e73c642-9574-42ab-956c-d6570f4e27c1_1353x902.png 848w, https://substackcdn.com/image/fetch/$s_!88za!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e73c642-9574-42ab-956c-d6570f4e27c1_1353x902.png 1272w, https://substackcdn.com/image/fetch/$s_!88za!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e73c642-9574-42ab-956c-d6570f4e27c1_1353x902.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!88za!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e73c642-9574-42ab-956c-d6570f4e27c1_1353x902.png" width="1353" height="902" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2e73c642-9574-42ab-956c-d6570f4e27c1_1353x902.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:902,&quot;width&quot;:1353,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1698375,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/197269600?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e73c642-9574-42ab-956c-d6570f4e27c1_1353x902.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!88za!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e73c642-9574-42ab-956c-d6570f4e27c1_1353x902.png 424w, https://substackcdn.com/image/fetch/$s_!88za!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e73c642-9574-42ab-956c-d6570f4e27c1_1353x902.png 848w, https://substackcdn.com/image/fetch/$s_!88za!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e73c642-9574-42ab-956c-d6570f4e27c1_1353x902.png 1272w, https://substackcdn.com/image/fetch/$s_!88za!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2e73c642-9574-42ab-956c-d6570f4e27c1_1353x902.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Bloomberg</figcaption></figure></div><p>Foxconn confirm&#243; un ciberataque <a href="https://www.securityweek.com/foxconn-confirms-north-american-factories-hit-by-cyberattack/">contra operaciones en Estados Unidos</a> despu&#233;s de que el grupo Nitrogen la publicara en su sitio de filtraciones.</p><p><strong>Qu&#233; pas&#243;.</strong> La empresa dijo que algunas f&#225;bricas sufrieron un incidente y que su equipo de ciberseguridad activ&#243; el mecanismo de respuesta. Seg&#250;n Foxconn, las plantas afectadas ya est&#225;n retomando la producci&#243;n normal.</p><p><strong>El reclamo.</strong> El actor de amenazas, Nitrogen, asegura haber robado 8 TB de datos, con m&#225;s de 11 millones de archivos.</p><p>El grupo dice que el paquete incluye instrucciones confidenciales, documentaci&#243;n interna de proyectos y planos t&#233;cnicos vinculados a Intel, Apple, Google, Dell y Nvidia, entre otros clientes.</p><p><strong>El l&#237;mite.</strong> Foxconn confirm&#243; el ataque, pero no valid&#243; el robo de esa informaci&#243;n ni el impacto sobre datos de sus clientes. La compa&#241;&#237;a dijo que tom&#243; medidas operativas para sostener la continuidad de producci&#243;n y entrega.</p><p><strong>Por qu&#233; importa.</strong> Foxconn es un <strong>proveedor cr&#237;tico de hardware</strong> para algunas de las empresas tecnol&#243;gicas m&#225;s grandes del mundo. Un ataque sobre su infraestructura abre un riesgo de cadena de suministro: planos, procesos internos o documentaci&#243;n t&#233;cnica pueden ser valiosos para extorsi&#243;n, espionaje industrial o ataques posteriores.</p><p><strong>El grupo.</strong> Nitrogen opera desde 2023 y est&#225; vinculado a familias derivadas del builder filtrado de Conti 2. </p><p>En febrero, <a href="https://www.coveware.com/blog/2026/2/2/nitrogen-ransomware-esxi-malware-has-a-bug">Coveware advirti&#243;</a> que un error de programaci&#243;n en su decryptor para VMware ESXi puede impedir recuperar archivos aun pagando el rescate.</p><h3>Xbow encuentra una vulnerabilidad con exploit en Exim: dead.letter</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-LxJ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47dba949-a4bc-4a93-953f-751e2674ad95_1728x910.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-LxJ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47dba949-a4bc-4a93-953f-751e2674ad95_1728x910.png 424w, https://substackcdn.com/image/fetch/$s_!-LxJ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47dba949-a4bc-4a93-953f-751e2674ad95_1728x910.png 848w, https://substackcdn.com/image/fetch/$s_!-LxJ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47dba949-a4bc-4a93-953f-751e2674ad95_1728x910.png 1272w, https://substackcdn.com/image/fetch/$s_!-LxJ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47dba949-a4bc-4a93-953f-751e2674ad95_1728x910.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-LxJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47dba949-a4bc-4a93-953f-751e2674ad95_1728x910.png" width="1456" height="767" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/47dba949-a4bc-4a93-953f-751e2674ad95_1728x910.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:767,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:852095,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/197269600?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47dba949-a4bc-4a93-953f-751e2674ad95_1728x910.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-LxJ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47dba949-a4bc-4a93-953f-751e2674ad95_1728x910.png 424w, https://substackcdn.com/image/fetch/$s_!-LxJ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47dba949-a4bc-4a93-953f-751e2674ad95_1728x910.png 848w, https://substackcdn.com/image/fetch/$s_!-LxJ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47dba949-a4bc-4a93-953f-751e2674ad95_1728x910.png 1272w, https://substackcdn.com/image/fetch/$s_!-LxJ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F47dba949-a4bc-4a93-953f-751e2674ad95_1728x910.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong>Xbow</strong> descubri&#243; una vulnerabilidad cr&#237;tica en <strong>Exim</strong>, el popular servidor de correo usado en Linux, que permite ejecuci&#243;n remota de c&#243;digo (RCE) sin autenticaci&#243;n, bautizada <strong>dead.letter</strong>.</p><p>La falla fue registrada como <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-45185">CVE-2026-45185</a> y tiene una severidad de <strong>9.8</strong>. Afecta a Exim 4.97 en instalaciones de Ubuntu y Debian.</p><p><strong>Qu&#233; pas&#243;. </strong>El bug est&#225; en c&#243;mo Exim maneja conexiones TLS, el protocolo que cifra comunicaciones en internet, como HTTPS o correo seguro, y BDAT, una funci&#243;n del protocolo SMTP usada para enviar grandes bloques de datos de correo en partes. </p><p><strong>Por qu&#233; importa.</strong> El bug casi no requiere configuraci&#243;n especial del servidor. El ataque se puede disparar de forma remota y sin credenciales, lo que la convierte en una de las vulnerabilidades m&#225;s serias encontradas en Exim en los &#250;ltimos a&#241;os. </p><p><strong>El experimento.</strong> Xbow us&#243; la ventana de <em>disclosure</em> para probar algo m&#225;s amplio: hasta d&#243;nde pod&#237;an llegar humanos y sistemas aut&#243;nomos en el desarrollo de exploits. </p><p>Seg&#250;n la publicaci&#243;n, un sistema basado en LLM logr&#243; construir exploits funcionales en escenarios controlados, primero sin ASLR (la protecci&#243;n que randomiza direcciones de memoria) ni PIE (una t&#233;cnica que vuelve aleatoria la ubicaci&#243;n del binario en memoria), y luego con ASLR activado pero binario no PIE.</p><p><strong>El l&#237;mite.</strong> En el escenario m&#225;s realista, contra una build de producci&#243;n, el equipo humano logr&#243; avanzar hasta filtrar una direcci&#243;n de stack, utilizando un infoleak (otro bug) que no compartieron. El sistema aut&#243;nomo, en cambio, no lleg&#243; tan lejos. Explicaron <a href="https://www.linkedin.com/feed/update/urn:li:activity:7459992284273545216/">Federico Kirschbaum</a> y <a href="https://www.linkedin.com/in/andres-lopez-luksenberg-9b48419/">Andres Luksenberg</a>, autores del art&#237;culo:</p><blockquote><p><em>Sinceramente, <strong>no creo que los LLMs est&#233;n listos todav&#237;a para escribir exploits</strong> contra software del mundo real por s&#237; solos. Despu&#233;s de esta experiencia, creo que pueden resolver desaf&#237;os tipo CTF, pero todav&#237;a no los veo llegando al nivel de objetivos reales de producci&#243;n.</em></p></blockquote><p><strong>Conclusi&#243;n.</strong> La conclusi&#243;n del post es que los LLMs ya aceleran investigaci&#243;n de vulnerabilidades y ayudan a entender c&#243;digo y probar caminos, pero todav&#237;a necesitan criterio, <em>debugging</em> y validaci&#243;n humana <strong>para objetivos reales.</strong></p><h3>Linux trabaja en un killswitch: efectos de Copy Fail y Dirty Frag</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!n0cZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d97ffa5-c723-4a2a-b0ff-6837a0906a00_1672x941.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!n0cZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d97ffa5-c723-4a2a-b0ff-6837a0906a00_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!n0cZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d97ffa5-c723-4a2a-b0ff-6837a0906a00_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!n0cZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d97ffa5-c723-4a2a-b0ff-6837a0906a00_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!n0cZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d97ffa5-c723-4a2a-b0ff-6837a0906a00_1672x941.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!n0cZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d97ffa5-c723-4a2a-b0ff-6837a0906a00_1672x941.png" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4d97ffa5-c723-4a2a-b0ff-6837a0906a00_1672x941.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1385258,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/197269600?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d97ffa5-c723-4a2a-b0ff-6837a0906a00_1672x941.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!n0cZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d97ffa5-c723-4a2a-b0ff-6837a0906a00_1672x941.png 424w, https://substackcdn.com/image/fetch/$s_!n0cZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d97ffa5-c723-4a2a-b0ff-6837a0906a00_1672x941.png 848w, https://substackcdn.com/image/fetch/$s_!n0cZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d97ffa5-c723-4a2a-b0ff-6837a0906a00_1672x941.png 1272w, https://substackcdn.com/image/fetch/$s_!n0cZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d97ffa5-c723-4a2a-b0ff-6837a0906a00_1672x941.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Ilustraci&#243;n: IA - ChatGPT</figcaption></figure></div><p>Los <a href="https://docs.kernel.org/process/maintainers.html">maintainers</a> del kernel de Linux eval&#250;an crear un <em><strong><a href="https://lore.kernel.org/all/20260507070547.2268452-1-sashal@kernel.org/">killswitch</a></strong></em> para desactivar funciones vulnerables antes de que haya parches disponibles.</p><p><strong>Qu&#233; pas&#243;.</strong> La propuesta fue presentada por <a href="https://www.linuxfoundation.org/webinars/my-life-as-a-linux-kernel-developer-and-maintainer-with-sasha-levin?hsLang=en">Sasha Levin</a>, co-maintainer del kernel estable de Linux e ingeniero de Nvidia. El killswitch permitir&#237;a deshabilitar en tiempo de ejecuci&#243;n funciones espec&#237;ficas del kernel cuando aparece una vulnerabilidad grave y todav&#237;a no hay una actualizaci&#243;n lista.</p><p><strong>Por qu&#233; importa</strong>. <a href="https://www.brodersendarknews.com/p/dos-fallas-criticas-linux-cpanel-exploits">Copy Fail</a> y <a href="https://www.brodersendarknews.com/i/196316042/dirty-frag-otra-falla-critica-permite-obtener-root-en-linux">Dirty Frag</a> expusieron una ventana cr&#237;tica: entre la divulgaci&#243;n p&#250;blica de una falla y la llegada del kernel parcheado, las organizaciones quedaron vulnerables. En organizaciones grandes, compilar, distribuir y reiniciar puede llevar mucho tiempo.</p><p><strong>C&#243;mo funcionar&#237;a.</strong> Si empieza a circular <em>exploit code</em> contra una funci&#243;n concreta, Killswitch permitir&#237;a apagar esa parte del kernel para que las llamadas fallen antes de llegar al c&#243;digo vulnerable. No corrige la falla: bloquea el acceso hasta que el sistema pueda actualizarse.</p><p><strong>Qu&#233; significa.</strong> La comunidad Linux est&#225; discutiendo una respuesta m&#225;s flexible para vulnerabilidades explotables antes del parche. </p><p>El objetivo es acortar la ventana entre la divulgaci&#243;n p&#250;blica y la mitigaci&#243;n real, un per&#237;odo que Copy Fail y Dirty Frag volvieron demasiado visible.</p><div><hr></div><h4><strong>&#128275; Breaches y hacks</strong></h4><ul><li><p>Nvidia confirm&#243; un <a href="https://www.bleepingcomputer.com/news/security/nvidia-confirms-geforce-now-data-breach-affecting-armenian-users/">data breach</a></p></li><li><p>M&#225;s detalles del <a href="https://insider-gaming.com/forza-horizon-6-leak-drops-155-gb-content/">breach de Forza Horizon</a>: 155 GB de contenido filtrado online</p></li><li><p><a href="https://www.bleepingcomputer.com/news/security/openai-confirms-security-breach-in-tanstack-supply-chain-attack/">OpenAI confirma</a> un breach por supply chain de TanStack</p></li></ul><h4><strong>&#128274; Ransomware</strong></h4><ul><li><p>Filtran la base de datos del grupo de ransomware <a href="https://www.bankinfosecurity.com/tables-turned-gentlemen-ransomware-group-suffers-data-leak-a-31654">The Gentlemen</a></p></li><li><p>Diversos <a href="https://www.bbc.com/news/articles/cr71d8vyjv0o">reportes</a> advierten sobre el paso a la <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/ransomware-physical-threats-violence">violencia f&#237;sica </a>en el mundo del ransomware</p></li><li><p>Qilin suma esta semana <a href="https://www.ransomware.live/id/RmFiLU1hc3RlcnNAcWlsaW4=">dos</a> <a href="https://www.ransomware.live/id/U2NodWx0ZS1MaW5kaG9yc3QgR21iSCAmIENvLkBxaWxpbg==">nuevas</a> v&#237;ctimas</p></li></ul><h4><strong>&#128163; Exploits y malware</strong></h4><ul><li><p>Un actor identificado como Mr_Rot13 explota la vulnerabilidad de <a href="https://blog.xlab.qianxin.com/mr_rot13-the-elusive-6-year-hacker-group-weaponizing-critical-cpanel-flaws-for-backdoor-deployment/">cPanel</a></p></li><li><p>Encuentran un <a href="https://www.bleepingcomputer.com/news/security/windows-bitlocker-zero-day-gives-access-to-protected-drives-poc-released/">zero day en BitLocker</a> y hay PoC</p></li><li><p>Explotan un auth bypass en el plugin de estad&#237;sticas <a href="https://www.bleepingcomputer.com/news/security/hackers-exploit-auth-bypass-flaw-in-burst-statistics-wordpress-plugin/">Burst de WordPress</a></p></li></ul><h4><strong>&#128269; Threat intel y vulnerabilidades</strong></h4><ul><li><p>Explotan la app para tomar notas <a href="https://www.elastic.co/security-labs/phantom-in-the-vault">Obsidian</a></p></li><li><p><a href="https://www.securityweek.com/claude-mythos-finds-only-one-curl-vulnerability-experts-divided-on-what-it-really-means/">Mythos encuentra</a> vulnerabilidades en curl</p></li><li><p>Reportes: <a href="https://www.binance.com/en/blog/security/2953911729763975700">Binance</a>, <a href="https://research.checkpoint.com/2026/the-state-of-ransomware-q1-2026/">Check Point Research</a>, <a href="https://cloud.google.com/blog/topics/threat-intelligence/ai-vulnerability-exploitation-initial-access">Google Cloud</a>, <a href="https://securelist.com/state-of-ransomware-in-2026/119761/">Kaspersky</a></p></li></ul><h4><strong>&#128736;&#65039; Tools y updates</strong></h4><ul><li><p>Google <a href="https://cyberscoop.com/google-android-intrusion-logging-amnesty-spyware-detection/">hace una alianza</a> con Amnist&#237;a Internacional para detectar spyware</p></li><li><p>Firefox actualiza su pol&#237;tica de updates a un <a href="https://www.soeren-hentzschel.at/firefox/firefox-korrektur-updates-kuenftig-im-wochen-takt/">modelo semanal</a></p></li><li><p>Broadcom lanza una actualizaci&#243;n de VMware Fusion para parchear un bug de <a href="https://www.reddit.com/r/InfoSecNews/comments/1td72kf/broadcom_releases_vmware_fusion_security_update/">acceso root</a></p></li></ul><h4><strong>&#128203; Privacidad y regulaciones</strong></h4><ul><li><p>La Uni&#243;n Europea prepara una <a href="https://www.euronews.com/my-europe/2026/05/12/von-der-leyen-opens-door-to-eu-wide-social-media-ban-for-children">prohibici&#243;n</a> de redes sociales para menores</p></li><li><p>Meta tuvo r&#233;dito econ&#243;mico por <a href="https://www.theguardian.com/technology/2026/may/13/meta-scam-ads-california-lawsuit">avisos fraudulentos</a>, seg&#250;n un tribunal de California</p></li><li><p>Un reporte se&#241;ala que <a href="https://www.hrw.org/report/2026/05/12/looking-the-other-way/eu-failure-to-prevent-surveillance-exports-to-rights">Europa falla</a> en controlar la vigilancia online</p><p></p></li></ul><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial generativa para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/shinyhunters-cobro-el-rescate-canvas?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/shinyhunters-cobro-el-rescate-canvas?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Google Chrome descarga un modelo de IA de 4 GB sin pedir permiso, según una investigación]]></title><description><![CDATA[Adem&#225;s: Daemon Tools distribuy&#243; una versi&#243;n infectada, Microsoft Defender marc&#243; certificados v&#225;lidos como troyanos, dos nuevas v&#237;ctimas de ShinyHunters y "Dirty Frag", otra vulnerabilidad en Linux.]]></description><link>https://www.brodersendarknews.com/p/google-chrome-descarga-modelo-ia-sin-permiso</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/google-chrome-descarga-modelo-ia-sin-permiso</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Fri, 08 May 2026 11:03:04 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!-ZmP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d73f7-7ccb-4354-b4ec-336177b9f245_1169x773.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>1~8<br>may</h1><h2><strong>&#9889;TL;DR</strong></h2><p>Despu&#233;s de una entrega <a href="https://www.brodersendarknews.com/p/dos-fallas-criticas-linux-cpanel-exploits">m&#225;s t&#233;cnica</a>, toca hablar de algo un poco m&#225;s masivo: <strong>Google Chrome</strong> est&#225; instalando un modelo de inteligencia artificial de 4 GB en muchos equipos <strong>sin pedir permiso</strong>. </p><p>Hay antecedentes de esto: Chrome ya instal&#243; paquetes por acuerdos con otras compa&#241;&#237;as. Por ejemplo, en 2017 con <a href="https://blog.google/products-and-platforms/products/chrome/cleaner-safer-web-chrome-cleanup/?utm_source=chatgpt.com">Chrome Cleanup</a> (una alianza con ESET), pero por lo general se comunican con transparencia. Esta vez, seg&#250;n dio a conocer Alexander Hanff (<strong><a href="https://www.thatprivacyguy.com/blog/chrome-silent-nano-install/">&#8220;That Privacy Guy&#8221;</a></strong>), se trata de un mini modelo de Gemini integrado en el <em>browser</em> para acelerar funciones. El problema es que todo ocurre en segundo plano y <strong>sin que el usuario se entere</strong>.</p><p>Pero no tan r&#225;pido: apareci&#243;, a &#250;ltima hora del jueves, una nueva vulnerabilidad cr&#237;tica en el ecosistema Linux que permitir&#237;a obtener root en sistemas desde 2017: <strong><a href="https://seclists.org/oss-sec/2026/q2/430">Dirty Frag</a></strong>. Parecida a <a href="https://www.brodersendarknews.com/p/dos-fallas-criticas-linux-cpanel-exploits">Copy Fail</a>, de la semana pasada. Y ya est&#225; haciendo <strong>mucho ruido en la carrera por parchear.</strong></p><p>En otras noticias, <strong>Daemon Tools</strong>, la popular herramienta para montar discos (que m&#225;s de un usuario habr&#225; instalado en la &#233;poca dorada del <em><strong>warez</strong></em>), sufri&#243; un <em>supply chain</em> interesante esta semana. Tambi&#233;n hubo un problema de certificados <strong>DigiCert</strong> que Microsoft Defender marc&#243; como troyanos.</p><p>Un caso m&#225;s que destaqu&#233; es el de un estudiante que, en Taiw&#225;n, logr&#243; <strong>hackear por radio el sistema ferroviario</strong> y fren&#243; cuatro formaciones de trenes, en lo que entra en la categor&#237;a de ataque <strong>cin&#233;tico</strong>: un incidente digital o de radiofrecuencia que produce efectos f&#237;sicos en el mundo real.</p><p>Adem&#225;s, <strong>ShinyHunters</strong> sum&#243; dos v&#237;ctimas m&#225;s de peso: Instructure (Canvas) y Vimeo. Y hablando de este grupo de hackers, puedo entrar en las perlitas (esta vez encontr&#233; varias) porque luego de que hackearan a <strong><a href="https://www.brodersendarknews.com/i/194107355/rockstar-games-creadores-de-gta-hackeado-otra-vez">Rockstar Games</a></strong>, la acci&#243;n de Take-Two, due&#241;a de la empresa que hace GTA, <strong><a href="https://www.videogameschronicle.com/news/rockstar-hackers-actually-made-take-twos-stock-increase-after-leaking-how-much-gta-online-is-making/">subi&#243;</a></strong>. Y muchos lo atribu&#237;an a que en el leak se pod&#237;an ver los detalles financieros, que inclu&#237;an un revenue de <strong>1,3 millones de d&#243;lares s&#243;lo por GTA Online</strong>.</p><p>En el mundo de la IA, ya se habla de <em><strong>podslop</strong></em>: 40% de los podcasts nuevos <a href="https://www.bloomberg.com/news/newsletters/2026-04-30/-podslop-proliferation-is-challenging-the-audio-industry">est&#225;n hechos con IA</a>. </p><p>Y ayer fue el <strong><a href="https://blog.checkpoint.com/security/world-password-day-2026-why-strong-passwords-cant-save-you-from-ai-infostealers-and-the-telegram-underground/">d&#237;a mundial de la contrase&#241;a</a></strong>: buen momento para recordar que 60% de los passwords hasheados con MD5 <a href="https://www.theregister.com/security/2026/05/07/60-of-md5-password-hashes-are-crackable-in-under-an-hour/5234954">se pueden crackear</a> en menos de una hora, adem&#225;s de que algunos navegadores como Edge guardan passwords en <a href="https://hackread.com/edge-browser-stores-saved-plaintext-passwords/">texto plano</a>.</p><p>Felices <em><strong>123456</strong></em>, contrase&#241;a usada <a href="https://nordpass.com/most-common-passwords-list/">al menos </a><strong><a href="https://nordpass.com/most-common-passwords-list/">21.627.656</a></strong> veces seg&#250;n el &#250;ltimo registro.</p><div><hr></div><p><em>En esta edici&#243;n:</em></p><ul><li><p><a href="https://www.brodersendarknews.com/i/196316042/google-chrome-instala-un-modelo-de-ia-de-4-gb-sin-pedir-permiso-segun-una-investigacion">&#129302; </a><em><a href="https://www.brodersendarknews.com/i/196316042/google-chrome-instala-un-modelo-de-ia-de-4-gb-sin-pedir-permiso-segun-una-investigacion">Google</a></em><a href="https://www.brodersendarknews.com/i/196316042/google-chrome-instala-un-modelo-de-ia-de-4-gb-sin-pedir-permiso-segun-una-investigacion"> </a><em><a href="https://www.brodersendarknews.com/i/196316042/google-chrome-instala-un-modelo-de-ia-de-4-gb-sin-pedir-permiso-segun-una-investigacion">Chrome instala un modelo de IA de 4 GB sin pedir permiso, seg&#250;n una investigaci&#243;n</a></em></p></li><li><p><a href="https://www.brodersendarknews.com/i/196316042/dirty-frag-otra-falla-critica-permite-obtener-root-en-linux">&#128039;</a><em><a href="https://www.brodersendarknews.com/i/196316042/dirty-frag-otra-falla-critica-permite-obtener-root-en-linux"> Dirty Frag: otra falla cr&#237;tica permite obtener root en Linux</a></em></p></li><li><p><a href="https://www.brodersendarknews.com/i/196316042/daemon-tools-distribuyo-una-version-con-backdoor-durante-casi-un-mes">&#128191; </a><em><a href="https://www.brodersendarknews.com/i/196316042/daemon-tools-distribuyo-una-version-con-backdoor-durante-casi-un-mes">Daemon Tools distribuy&#243; una versi&#243;n con backdoor durante casi un mes</a></em></p></li><li><p><a href="https://www.brodersendarknews.com/i/196316042/microsoft-defender-marco-certificados-digicert-como-troyanos-por-error">&#129706; </a><em><a href="https://www.brodersendarknews.com/i/196316042/microsoft-defender-marco-certificados-digicert-como-troyanos-por-error">Microsoft Defender marc&#243; certificados DigiCert como troyanos por error</a></em></p></li><li><p><a href="https://www.brodersendarknews.com/i/196316042/dos-nuevas-victimas-de-shinyhunters-instructure-canvas-y-vimeo">&#127919; </a><em><a href="https://www.brodersendarknews.com/i/196316042/dos-nuevas-victimas-de-shinyhunters-instructure-canvas-y-vimeo">Dos nuevas v&#237;ctimas de ShinyHunters: Instructure (Canvas) y Vimeo</a></em></p></li><li><p><a href="https://www.brodersendarknews.com/i/196316042/un-estudiante-hackeo-por-radio-el-tren-bala-de-taiwan-y-freno-cuatro-formaciones">&#128646; </a><em><a href="https://www.brodersendarknews.com/i/196316042/un-estudiante-hackeo-por-radio-el-tren-bala-de-taiwan-y-freno-cuatro-formaciones">Un estudiante hacke&#243; por radio el tren bala de Taiw&#225;n y fren&#243; cuatro formaciones</a></em></p></li></ul><p>&#9200; <em>Substack dice que leer este correo completo lleva 13 minutos</em></p><p><em>Dark News #201</em></p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://bloka.red/contacto/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gebg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 424w, https://substackcdn.com/image/fetch/$s_!gebg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 848w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1272w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png" width="1456" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1127539,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://bloka.red/contacto/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194107355?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gebg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 424w, https://substackcdn.com/image/fetch/$s_!gebg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 848w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1272w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></div><h3>Google Chrome instala un modelo de IA de 4 GB sin pedir permiso, seg&#250;n una investigaci&#243;n</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!-ZmP!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d73f7-7ccb-4354-b4ec-336177b9f245_1169x773.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!-ZmP!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d73f7-7ccb-4354-b4ec-336177b9f245_1169x773.png 424w, https://substackcdn.com/image/fetch/$s_!-ZmP!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d73f7-7ccb-4354-b4ec-336177b9f245_1169x773.png 848w, https://substackcdn.com/image/fetch/$s_!-ZmP!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d73f7-7ccb-4354-b4ec-336177b9f245_1169x773.png 1272w, https://substackcdn.com/image/fetch/$s_!-ZmP!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d73f7-7ccb-4354-b4ec-336177b9f245_1169x773.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!-ZmP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d73f7-7ccb-4354-b4ec-336177b9f245_1169x773.png" width="1169" height="773" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fa5d73f7-7ccb-4354-b4ec-336177b9f245_1169x773.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:773,&quot;width&quot;:1169,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:553590,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/196316042?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d73f7-7ccb-4354-b4ec-336177b9f245_1169x773.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!-ZmP!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d73f7-7ccb-4354-b4ec-336177b9f245_1169x773.png 424w, https://substackcdn.com/image/fetch/$s_!-ZmP!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d73f7-7ccb-4354-b4ec-336177b9f245_1169x773.png 848w, https://substackcdn.com/image/fetch/$s_!-ZmP!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d73f7-7ccb-4354-b4ec-336177b9f245_1169x773.png 1272w, https://substackcdn.com/image/fetch/$s_!-ZmP!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffa5d73f7-7ccb-4354-b4ec-336177b9f245_1169x773.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Shutterstock</figcaption></figure></div><p><strong>Google Chrome</strong> descarga un modelo de IA de 4 GB sin pedir consentimiento expl&#237;cito, seg&#250;n una investigaci&#243;n publicada por Alexander Hanff, conocido como <strong><a href="https://www.thatprivacyguy.com/blog/chrome-silent-nano-install/">&#8220;That Privacy Guy&#8221;</a>.</strong></p><p>Hanff es cient&#237;fico inform&#225;tico, soci&#243;logo y abogado, con m&#225;s de 30 a&#241;os de experiencia en la intersecci&#243;n entre tecnolog&#237;a, privacidad y derecho.</p><p><strong>Qu&#233; encontr&#243;.</strong> Chrome escribe en el perfil del usuario una carpeta llamada OptGuideOnDeviceModel con un archivo <strong>weights[.]bin</strong> de unos 4 GB. </p><p>Ese archivo corresponder&#237;a a <strong>Gemini Nano</strong>, el modelo local de Google para funciones de IA en el navegador. El nombre t&#233;cnico de la carpeta <strong>hace dif&#237;cil entender</strong> qu&#233; ocupa ese espacio en disco.</p><p><strong>Por qu&#233; importa.</strong> Hanff dice que el proceso ocurre sin un aviso claro, sin una casilla de aceptaci&#243;n visible y con redescarga autom&#225;tica si el usuario borra el archivo. Chrome estar&#237;a preinstalando una capacidad de IA <strong>aunque el usuario no haya pedido usarla.</strong></p><p><strong>La parte legal.</strong> El caso podr&#237;a violar la directiva europea ePrivacy, principios del <strong>GDPR</strong> sobre transparencia y minimizaci&#243;n, y obligaciones de privacidad por dise&#241;o. </p><p><strong>El costo ambiental.</strong> Adem&#225;s, la investigaci&#243;n calcula el impacto clim&#225;tico de empujar un archivo de ese tama&#241;o a escala masiva. En un escenario bajo, con 100 millones de dispositivos, estima 6.000 toneladas de CO2 equivalente solo por la entrega del modelo. En un escenario alto, con 1.000 millones de equipos, la cifra sube a 60.000 toneladas.</p><p><strong>Qu&#233; pide.</strong> Hanff reclama que Google use un esquema de <em><strong>opt in</strong></em>: descargar el modelo s&#243;lo cuando el usuario active una funci&#243;n de IA, mostrar qu&#233; archivos se instalaron, permitir borrarlos de forma persistente y transparentar el costo ambiental agregado en sus reportes de sostenibilidad.</p><h3>Dirty Frag: otra falla cr&#237;tica permite obtener root en Linux</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!SXTy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa42acf-ebf8-401a-8a23-ab3e135236ee_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!SXTy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa42acf-ebf8-401a-8a23-ab3e135236ee_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!SXTy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa42acf-ebf8-401a-8a23-ab3e135236ee_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!SXTy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa42acf-ebf8-401a-8a23-ab3e135236ee_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!SXTy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa42acf-ebf8-401a-8a23-ab3e135236ee_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!SXTy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa42acf-ebf8-401a-8a23-ab3e135236ee_1448x1086.png" width="1448" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/baa42acf-ebf8-401a-8a23-ab3e135236ee_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1493355,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/196316042?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa42acf-ebf8-401a-8a23-ab3e135236ee_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!SXTy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa42acf-ebf8-401a-8a23-ab3e135236ee_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!SXTy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa42acf-ebf8-401a-8a23-ab3e135236ee_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!SXTy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa42acf-ebf8-401a-8a23-ab3e135236ee_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!SXTy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fbaa42acf-ebf8-401a-8a23-ab3e135236ee_1448x1086.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><strong><a href="https://www.tomshardware.com/tech-industry/cyber-security/dirty-frag-exploit-gets-root-on-most-linux-machines-since-2017-no-patches-available-no-warning-given-copy-fail-like-vulnerability-had-its-embargo-broken">Dirty Frag</a></strong><a href="https://www.tomshardware.com/tech-industry/cyber-security/dirty-frag-exploit-gets-root-on-most-linux-machines-since-2017-no-patches-available-no-warning-given-copy-fail-like-vulnerability-had-its-embargo-broken">, una nueva vulnerabilidad cr&#237;tica en Linux</a>, permitir&#237;a obtener <strong>root inmediato</strong> en sistemas afectados desde 2017. El caso llega cuando la comunidad todav&#237;a <a href="https://www.brodersendarknews.com/p/dos-fallas-criticas-linux-cpanel-exploits">sigue de cerca </a><strong><a href="https://www.brodersendarknews.com/p/dos-fallas-criticas-linux-cpanel-exploits">Copy Fail</a></strong>, otra falla local de escalamiento de privilegios de la semana pasada con un mecanismo parecido.</p><p><strong>Qu&#233; pas&#243;.</strong> Seg&#250;n un reporte, Dirty Frag afecta a la mayor&#237;a de las instalaciones Linux modernas, incluidas versiones actuales de <strong>Ubuntu, Arch, RHEL, openSUSE, CentOS Stream, Fedora y AlmaLinux</strong>. Tambi&#233;n habr&#237;a sido reproducida en WSL2.</p><p>Cualquier usuario local podr&#237;a ejecutar un programa muy peque&#241;o y conseguir privilegios de administrador.</p><p><strong>Por qu&#233; importa.</strong> La falla todav&#237;a no tendr&#237;a parches disponibles al momento de la publicaci&#243;n. El reporte afirma que se rompi&#243; el embargo por parte de un tercero, pese a que la vulnerabilidad hab&#237;a sido informada al equipo del kernel de Linux el 30 de abril. Eso dej&#243; a administradores y distribuciones sin margen para preparar actualizaciones antes de que los detalles circularan.</p><p><strong>El contexto.</strong> Dirty Frag se parece a Copy Fail porque aprovecha una operaci&#243;n de zero-copy vinculada al <em>page cache,</em> una zona de memoria usada para acelerar operaciones de archivos.</p><p>En este caso, el c&#243;digo vulnerable estar&#237;a en m&#243;dulos relacionados con IPSec y RxRPC. La falla principal, &#8220;xfrm-ESP Page Cache Write&#8221;, habr&#237;a sido introducida en un commit del kernel de 2017.</p><p><strong>Mitigaci&#243;n.</strong> Hasta que haya parches, el reporte recomienda desactivar los m&#243;dulos esp4, esp6 y rxrpc. Est&#225;n vinculados a funciones de red e IPSec, por lo que en muchos servidores podr&#237;an no ser necesarios. </p><p>La excepci&#243;n: equipos que funcionen como clientes o servidores IPSec, donde el cambio podr&#237;a afectar servicios reales.</p><h3><strong>Daemon Tools distribuy&#243; una versi&#243;n con backdoor durante casi un mes</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!rV-3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd887b569-4e59-44e9-8ddf-075006f1512b_1448x1086.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!rV-3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd887b569-4e59-44e9-8ddf-075006f1512b_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!rV-3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd887b569-4e59-44e9-8ddf-075006f1512b_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!rV-3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd887b569-4e59-44e9-8ddf-075006f1512b_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!rV-3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd887b569-4e59-44e9-8ddf-075006f1512b_1448x1086.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!rV-3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd887b569-4e59-44e9-8ddf-075006f1512b_1448x1086.png" width="1448" height="1086" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d887b569-4e59-44e9-8ddf-075006f1512b_1448x1086.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1086,&quot;width&quot;:1448,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1386576,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/196316042?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd887b569-4e59-44e9-8ddf-075006f1512b_1448x1086.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!rV-3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd887b569-4e59-44e9-8ddf-075006f1512b_1448x1086.png 424w, https://substackcdn.com/image/fetch/$s_!rV-3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd887b569-4e59-44e9-8ddf-075006f1512b_1448x1086.png 848w, https://substackcdn.com/image/fetch/$s_!rV-3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd887b569-4e59-44e9-8ddf-075006f1512b_1448x1086.png 1272w, https://substackcdn.com/image/fetch/$s_!rV-3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd887b569-4e59-44e9-8ddf-075006f1512b_1448x1086.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Daemon Tools Lite, herramienta de montaje de discos. Imagen generada con ChatGPT</figcaption></figure></div><p><strong>Daemon Tools</strong>, un programa muy usado para montar im&#225;genes de disco, <a href="https://arstechnica.com/security/2026/05/widely-used-daemon-tools-disk-app-backdoored-in-monthlong-supply-chain-attack/">distribuy&#243; instaladores con </a><strong><a href="https://arstechnica.com/security/2026/05/widely-used-daemon-tools-disk-app-backdoored-in-monthlong-supply-chain-attack/">malware</a></strong> desde sus propios servidores durante casi un mes, en un ataque de cadena de suministro <a href="https://www.kaspersky.com/blog/daemon-tools-supply-chain-attack/55691/">detectado por Kaspersky</a>.</p><p><strong>Qu&#233; pas&#243;.</strong> Los instaladores afectados estaban firmados con el <strong>certificado digital oficial</strong> del desarrollador y se descargaban desde el sitio leg&#237;timo. Las versiones afectadas van de la 12.5.0.2421 a la 12.5.0.2434 y, por los detalles t&#233;cnicos publicados, el impacto parece concentrado en <strong>Windows</strong>.</p><p><strong>Por qu&#233; importa.</strong> El caso expone una de las formas m&#225;s dif&#237;ciles de defender en seguridad: el usuario instala una actualizaci&#243;n oficial, firmada y distribuida por canales leg&#237;timos, pero <strong>el paquete ya viene manipulado.</strong> </p><p><strong>Qu&#233; hac&#237;a.</strong> El primer <em>payload</em> recolectaba datos del equipo infectado: direcciones MAC, hostname, dominio DNS, procesos activos, software instalado y configuraci&#243;n regional. Esa informaci&#243;n se enviaba a un servidor controlado por los atacantes y serv&#237;a para perfilar qu&#233; tipo de sistema hab&#237;an infectado.</p><p><strong>Alcance.</strong> Kaspersky observ&#243; miles de m&#225;quinas afectadas en m&#225;s de 100 pa&#237;ses. Entre las organizaciones, alrededor del 10% pertenec&#237;a a empresas u organismos. </p><p><strong>Update.</strong> Disc Soft Limited, la desarrolladora de DAEMON Tools Lite, <a href="https://www.bleepingcomputer.com/news/security/daemon-tools-devs-confirm-breach-release-malware-free-version/">confirm&#243;</a> que el software fue troyanizado en un ataque de cadena de suministro y public&#243; una nueva versi&#243;n <strong>sin malware</strong>. </p><h3>Microsoft Defender marc&#243; certificados DigiCert como troyanos por error</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vq86!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540953d4-2812-4be0-87b6-5718da7a2905_1085x668.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vq86!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540953d4-2812-4be0-87b6-5718da7a2905_1085x668.png 424w, https://substackcdn.com/image/fetch/$s_!vq86!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540953d4-2812-4be0-87b6-5718da7a2905_1085x668.png 848w, https://substackcdn.com/image/fetch/$s_!vq86!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540953d4-2812-4be0-87b6-5718da7a2905_1085x668.png 1272w, https://substackcdn.com/image/fetch/$s_!vq86!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540953d4-2812-4be0-87b6-5718da7a2905_1085x668.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vq86!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540953d4-2812-4be0-87b6-5718da7a2905_1085x668.png" width="1085" height="668" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/540953d4-2812-4be0-87b6-5718da7a2905_1085x668.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:668,&quot;width&quot;:1085,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:304458,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/196316042?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540953d4-2812-4be0-87b6-5718da7a2905_1085x668.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vq86!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540953d4-2812-4be0-87b6-5718da7a2905_1085x668.png 424w, https://substackcdn.com/image/fetch/$s_!vq86!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540953d4-2812-4be0-87b6-5718da7a2905_1085x668.png 848w, https://substackcdn.com/image/fetch/$s_!vq86!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540953d4-2812-4be0-87b6-5718da7a2905_1085x668.png 1272w, https://substackcdn.com/image/fetch/$s_!vq86!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F540953d4-2812-4be0-87b6-5718da7a2905_1085x668.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Screensaver hist&#243;rico de Windows 95</figcaption></figure></div><p>Un atacante comprometi&#243; <a href="https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/">sistemas internos de DigiCert</a> tras enga&#241;ar a empleados de soporte para que ejecutaran <strong>archivos SCR</strong>, el formato usado por Windows para <strong>protectores de pantalla</strong>. Con ese acceso, rob&#243; 27 certificados de firma de c&#243;digo que luego fueron usados para firmar malware.</p><p><strong>Por qu&#233; importa.</strong> <a href="https://www.digicert.com/">DigiCert</a> es una de las principales <strong>autoridades certificadoras del mundo</strong>. Emite certificados digitales para validar identidades, proteger conexiones web y firmar software. En este caso, el atacante apunt&#243; a certificados EV Code Signing, que funcionan como una se&#241;al de confianza para Windows y otras plataformas.</p><p><strong>Qu&#233; pas&#243;.</strong> DigiCert dijo que el incidente empez&#243; con ingenier&#237;a social contra <strong>dos empleados de soporte t&#233;cnico</strong>. El atacante se hizo pasar por cliente y logr&#243; que ejecutaran un archivo SCR, un formato leg&#237;timo que tambi&#233;n puede usarse para distribuir malware.</p><p><strong>El impacto.</strong> El atacante accedi&#243; a tickets de soporte vinculados a certificados EV en aprobaci&#243;n y obtuvo c&#243;digos de inicializaci&#243;n. DigiCert <strong>revoc&#243; 60 &#243;rdenes</strong> procesadas durante la ventana de acceso y vincul&#243; 27 certificados directamente con el atacante. </p><p>Esos certificados fueron usados para firmar cargas maliciosas de <strong>Zhong Stealer</strong>, un malware asociado al robo de criptomonedas.</p><p><strong>Falso positivo.</strong> Microsoft Defender empez&#243; a marcar certificados root leg&#237;timos de DigiCert como <strong>Trojan:Win32/Cerdigent[.]A!dha</strong>, lo que gener&#243; alertas falsas masivas y, en algunos casos, elimin&#243; certificados del almac&#233;n de confianza de Windows. </p><p>Microsoft dijo <a href="https://www.bleepingcomputer.com/news/security/microsoft-defender-wrongly-flags-digicert-certs-as-trojan-win32-cerdigentadha/">a BleepingComputer</a> que corrigi&#243; la detecci&#243;n y pidi&#243; actualizar Defender a la versi&#243;n Security Intelligence 1.449.430.0 o posterior.</p><h3>Dos nuevas v&#237;ctimas de ShinyHunters: Instructure (Canvas) y Vimeo</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hHIF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3455154-9a28-49c1-971a-132cb432a95b_1393x669.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hHIF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3455154-9a28-49c1-971a-132cb432a95b_1393x669.png 424w, https://substackcdn.com/image/fetch/$s_!hHIF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3455154-9a28-49c1-971a-132cb432a95b_1393x669.png 848w, https://substackcdn.com/image/fetch/$s_!hHIF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3455154-9a28-49c1-971a-132cb432a95b_1393x669.png 1272w, https://substackcdn.com/image/fetch/$s_!hHIF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3455154-9a28-49c1-971a-132cb432a95b_1393x669.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hHIF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3455154-9a28-49c1-971a-132cb432a95b_1393x669.png" width="1393" height="669" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c3455154-9a28-49c1-971a-132cb432a95b_1393x669.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:669,&quot;width&quot;:1393,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:266031,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/196316042?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3455154-9a28-49c1-971a-132cb432a95b_1393x669.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hHIF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3455154-9a28-49c1-971a-132cb432a95b_1393x669.png 424w, https://substackcdn.com/image/fetch/$s_!hHIF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3455154-9a28-49c1-971a-132cb432a95b_1393x669.png 848w, https://substackcdn.com/image/fetch/$s_!hHIF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3455154-9a28-49c1-971a-132cb432a95b_1393x669.png 1272w, https://substackcdn.com/image/fetch/$s_!hHIF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc3455154-9a28-49c1-971a-132cb432a95b_1393x669.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">DLS de ShinyHunters</figcaption></figure></div><p>ShinyHunters sum&#243; dos nuevas v&#237;ctimas a su cadena de extorsiones: la plataforma de video online <strong>Vimeo</strong> e <a href="https://techcrunch.com/2026/05/05/hackers-steal-students-data-during-breach-at-education-tech-giant-instructure/">Instructure</a>, la empresa detr&#225;s de <strong>Canvas</strong> (sistema de gesti&#243;n de aprendizaje [no confundir con <a href="https://www.canva.com/">Canva</a>]). </p><p>En ambos casos (y como siempre hace), el grupo explot&#243; accesos o integraciones de terceros para llegar a datos de usuarios y clientes.</p><p><strong>Qu&#233; pas&#243;.</strong> En Vimeo, la brecha expuso informaci&#243;n de 119.200 usuarios, seg&#250;n datos <a href="https://haveibeenpwned.com/Breach/Vimeo">analizados por Have I Been Pwned</a>. El incidente hab&#237;a sido informado a fines de abril y estuvo vinculado al ataque contra <strong>Anodot</strong>, una plataforma de anal&#237;tica en la nube que ten&#237;a integraciones con cuentas de Snowflake y BigQuery de sus clientes.</p><p><strong>El otro caso.</strong> Instructure confirm&#243; un nuevo incidente menos de un a&#241;o despu&#233;s de haber sufrido otro ataque atribuido al mismo grupo. La empresa dijo que, hasta ahora, la informaci&#243;n involucrada incluye nombres, emails, n&#250;meros de estudiante y mensajes entre usuarios de instituciones afectadas. </p><p>Afirm&#243; que no encontr&#243; evidencia de exposici&#243;n de contrase&#241;as, fechas de nacimiento, documentos oficiales o datos financieros.</p><p><strong>Riesgo.</strong> En Vimeo, el riesgo m&#225;s inmediato es el phishing dirigido a usuarios cuyos nombres y emails quedaron expuestos. </p><p>En Instructure, el punto sensible es mayor: adem&#225;s de datos identificatorios, el grupo afirma haber accedido a mensajes privados dentro de entornos educativos.</p><h3><strong>Un estudiante hacke&#243; por radio el tren bala de Taiw&#225;n y fren&#243; cuatro formaciones</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nqU5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40211de5-09f2-4357-8adb-cf851b7ec152_1143x767.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nqU5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40211de5-09f2-4357-8adb-cf851b7ec152_1143x767.png 424w, https://substackcdn.com/image/fetch/$s_!nqU5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40211de5-09f2-4357-8adb-cf851b7ec152_1143x767.png 848w, https://substackcdn.com/image/fetch/$s_!nqU5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40211de5-09f2-4357-8adb-cf851b7ec152_1143x767.png 1272w, https://substackcdn.com/image/fetch/$s_!nqU5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40211de5-09f2-4357-8adb-cf851b7ec152_1143x767.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nqU5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40211de5-09f2-4357-8adb-cf851b7ec152_1143x767.png" width="1143" height="767" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/40211de5-09f2-4357-8adb-cf851b7ec152_1143x767.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:767,&quot;width&quot;:1143,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2228614,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/196316042?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40211de5-09f2-4357-8adb-cf851b7ec152_1143x767.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nqU5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40211de5-09f2-4357-8adb-cf851b7ec152_1143x767.png 424w, https://substackcdn.com/image/fetch/$s_!nqU5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40211de5-09f2-4357-8adb-cf851b7ec152_1143x767.png 848w, https://substackcdn.com/image/fetch/$s_!nqU5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40211de5-09f2-4357-8adb-cf851b7ec152_1143x767.png 1272w, https://substackcdn.com/image/fetch/$s_!nqU5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F40211de5-09f2-4357-8adb-cf851b7ec152_1143x767.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Wikimedia Commons</figcaption></figure></div><p>Un estudiante de 23 a&#241;os fue detenido en Taiw&#225;n acusado de <a href="https://www.tomshardware.com/tech-industry/cyber-security/college-student-hacks-taiwan-high-speed-rail-line-stopping-four-trains-19-years-without-crypto-key-rotation-ends-in-predictable-result">interferir por radio el sistema</a> de comunicaciones TETRA del tren bala. Seg&#250;n medios locales, el ataque fren&#243; cuatro formaciones durante 48 minutos el 5 de abril.</p><p><strong>Qu&#233; pas&#243;.</strong> El sospechoso, identificado como Lin, habr&#237;a usado equipos SDR y radios port&#225;tiles para transmitir una falsa &#8220;alarma general&#8221; de alta prioridad. Esa se&#241;al activ&#243; el frenado de emergencia en la red THSR.</p><p><strong>El m&#233;todo.</strong> Antes del incidente, Lin habr&#237;a interceptado y decodificado par&#225;metros TETRA con equipamiento comprado online. Luego los carg&#243; en radios para hacerse pasar por balizas leg&#237;timas del sistema ferroviario.</p><p><strong>Por qu&#233; importa.</strong> THSR es <strong>infraestructura cr&#237;tica</strong>: conecta la costa oeste de Taiw&#225;n en una l&#237;nea de 350 kil&#243;metros, con trenes de hasta 300 km/h y m&#225;s de 81 millones de pasajeros al a&#241;o. El caso muestra c&#243;mo una falla en comunicaciones puede tener consecuencias f&#237;sicas sobre servicios esenciales.</p><p><strong>Efecto cin&#233;tico.</strong> En ciberseguridad, puede leerse como un ataque con &#8220;efecto cin&#233;tico&#8221; (kinetic): una acci&#243;n digital o electr&#243;nica que impacta en el mundo real. </p><div><hr></div><h4><strong>&#128275; Breaches y hacks</strong></h4><ul><li><p>Acceden a informaci&#243;n interna de la empresa de seguridad <a href="https://www.trellix.com/statement/">Trellix</a></p></li><li><p>Ubuntu estuvo ca&#237;do por un <a href="https://www.theregister.com/security/2026/05/01/pro-iran-group-turns-ubuntu-ddos-into-shakedown/5224575">DDoS</a> contra Canonical</p></li><li><p>Sentencian a <a href="https://cyberscoop.com/north-korea-it-worker-scheme-laptop-farm-facilitators-sentenced/">dos norteamericanos</a> por correr &#8220;laptop farms&#8221; para esquemas de IT norcoreanos</p></li></ul><h4><strong>&#128274; Ransomware</strong></h4><ul><li><p>Asociaci&#243;n Mutual de Trabajadores Estatales (Argentina), anunciados por <a href="https://x.com/BirminghamCyber/status/2052362168260034984?s=20">The Gentlemen</a></p></li><li><p>Un gigante del <a href="https://www.theregister.com/security/2026/05/05/cushman-wakefield-confirms-vishing-cyberattack/5228718">real estate</a>, afectado por un ransomware</p></li><li><p>Una tool de <a href="https://securityaffairs.com/191765/breaking-news/iranian-cyber-espionage-disguised-as-a-chaos-ransomware-attack.html">ciberespionaje</a> se disfraza de ransomware en Ir&#225;n</p></li></ul><h4><strong>&#128163; Exploits y malware</strong></h4><ul><li><p>Google ofrece <a href="https://www.bleepingcomputer.com/news/security/google-now-offers-up-to-15-million-for-some-android-exploits/">1,5 millones</a> por exploits de Android</p></li><li><p>Abusan <a href="https://www.bleepingcomputer.com/news/security/researchers-report-amazon-ses-abused-in-phishing-to-evade-detection/">Amazon SES</a> para evadir detecciones</p></li><li><p>El grupo APT OceanLotus distribuye <a href="https://securelist.com/oceanlotus-suspected-pypi-zichatbot-campaign/119603/">malware</a> a trav&#233;s de paquetes PyPI</p></li></ul><h4><strong>&#128269; Threat intel y vulnerabilidades</strong></h4><ul><li><p>Corea del Norte ya es responsable del <a href="https://www.trmlabs.com/resources/blog/north-korea-stole-76-of-all-crypto-hack-value-in-2026-with-just-two-attacks">76% del robo de criptoactivos de 2026</a></p></li><li><p>Un troyano abusa la app de <a href="https://www.zdnet.com/article/trojan-abuses-microsoft-phone-link-app-to-steal-passwords/">Microsoft Phone Link</a></p></li><li><p>Reportes: <a href="https://www.wiz.io/blog/state-of-ai-in-cloud-2026-recap">Wiz</a>, <a href="https://wasabi.com/download/2026-global-cloud-storage-index-report">Wasabi</a>, <a href="https://blog.incogni.com/workplace-apps-on-personal-devices-research/">Incogni</a>, <a href="https://blog.talosintelligence.com/insights-into-the-clustering-and-reuse-of-phone-numbers-in-scam-emails/">Cisco Talos</a>, <a href="https://securelist.com/vulnerabilities-and-exploits-in-q1-2026/119733/">Kaspersky</a>, <a href="https://blogs.microsoft.com/on-the-issues/2026/05/07/the-state-of-global-ai-diffusion-in-2026/">Microsoft</a></p></li></ul><h4><strong>&#128736;&#65039; Tools y updates</strong></h4><ul><li><p>Parchean vulnerabilidades cr&#237;ticas en <a href="https://www.securityweek.com/critical-high-severity-vulnerabilities-patched-in-apache-mina-http-server/">Apache</a> HTTP y Mina </p></li><li><p><a href="https://cyberscoop.com/palo-alto-networks-pan-os-firewall-zero-day-vulnerability-exploited/">Palo Alto</a> advierte de un zero day RCE en sus firewalls</p></li><li><p><a href="https://chromereleases.googleblog.com/2026/05/stable-channel-update-for-desktop.html">Chrome</a> lanza actualizaciones de seguridad</p></li></ul><h4><strong>&#128203; Privacidad y regulaciones</strong></h4><ul><li><p>Pa&#237;ses de la alianza Five Eyes publican una <a href="https://www.cyber.gov.au/business-government/secure-design/artificial-intelligence/careful-adoption-of-agentic-ai-services">gu&#237;a de uso de agentes de IA</a></p></li><li><p><a href="https://www.minnpost.com/state-government/2026/05/nudification-apps-minnesota-passes-the-nations-first-ban/">Minnesota</a> proh&#237;be las apps de &#8220;nudification&#8221;</p></li><li><p>Google instal&#243; sin avisar <a href="https://www.thatprivacyguy.com/blog/chrome-silent-nano-install/">un modelo de IA</a> en los navegadores Chrome </p><p></p></li></ul><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial generativa para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/google-chrome-descarga-modelo-ia-sin-permiso?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/google-chrome-descarga-modelo-ia-sin-permiso?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Dos fallas críticas presionan a empresas a parchear: root en Linux y bypass en cPanel]]></title><description><![CDATA[Adem&#225;s: un wiper ataca una petrolera de Venezuela, ShinyHunters extorsiona a tres nuevas v&#237;ctimas, paquetes npm infectados afectan a SAP y Google firma con el Pent&#225;gono por Gemini.]]></description><link>https://www.brodersendarknews.com/p/dos-fallas-criticas-linux-cpanel-exploits</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/dos-fallas-criticas-linux-cpanel-exploits</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Fri, 01 May 2026 11:30:54 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!XDe5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cc7a8de-6ed0-4a3d-a689-e31093912368_5184x3456.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>24 abr~<br>1 may</h1><h2><strong>&#9889;TL;DR</strong></h2><p>Semana cargada de vulnerabilidades en el mundo de <strong>Linux</strong>. Apenas a mitad de semana (<em><a href="https://x.com/CptItsWednesday/status/2049420864341340412">Captain, it&#8217;s Wednesday</a>)</em>, <strong><a href="https://www.bugcrowd.com/blog/what-we-know-about-copy-fail-cve-2026-31431/">Copy Fail</a> </strong>hizo mucho ruido porque permite que un usuario local con privilegios m&#237;nimos escale permisos y <strong>obtenga </strong><em><strong>root</strong></em> en distribuciones publicadas desde 2017 en adelante. Incluye distros muy usadas en el mundo empresarial (muchas ya parchearon).</p><p>&#8220;El problema es que el exploit es tan simple que ahora mismo podr&#237;an estar ocurriendo hacks que no estamos viendo&#8221;, dijo una fuente a <strong>Dark News</strong>. Incluso con un EDR activo se puede bypassear. Y, lo peor, que el parcheo puede llevar m&#225;s tiempo del que se esperaba. Seg&#250;n pude saber, el problema impacta muy fuerte en el ecosistema de <strong>empresas y entidades argentinas.</strong></p><p>La segunda es un exploit en <strong>cPanel, </strong>un panel de control para administrar sitios web, correos, bases de datos y otros recursos de hosting desde una interfaz gr&#225;fica muy usado en todo el mundo. El impacto del problema es grande porque est&#225; instalado en muchos servidores de hosting compartido y administrado, donde <strong>un solo panel puede concentrar</strong> el control de m&#250;ltiples sitios, correos, bases de datos y dominios.</p><p>Todo esto est&#225; metiendo mucha presi&#243;n para no dejar los sistemas vulnerables. M&#225;s abajo detallo ambos problemas, que pusieron en alerta a la comunidad de hackers y la industria de la ciberseguridad, en lo que seguramente sea un fin de semana de mucho caf&#233; y pocas horas de sue&#241;o.</p><p>Otro tema que destaqu&#233; es el de un wiper que atac&#243; a una petrolera de Venezuela. Primero se cre&#237;a que era un ransomware, pero termin&#243; siendo un malware que borra archivos. Algo similar pas&#243; con otro ransom, VECT 2.0, pero <a href="https://www.bleepingcomputer.com/news/security/broken-vect-20-ransomware-acts-as-a-data-wiper-for-large-files/">por error</a>.</p><p>El cambio es importante porque modifica la estructura del modelo de negocio de la extorsi&#243;n. Del &#8220;te encripto y devuelo los datos si me pag&#225;s&#8221; al <strong>&#8220;te borro todo&#8221;</strong> que, m&#225;s all&#225; de un modelo de negocio, pasa a ser m&#225;s una herramienta de extorsi&#243;n geopol&#237;tica (una pieza m&#225;s del complejo puzzle del cyber-warfare). Vale decir, tampoco es nuevo y ya hubo casos registrados, como <strong><a href="https://www.clarin.com/tecnologia/industroyer2-freno-ucrania-ciberataque-ruso-intento-dejar-pais-luz_0_DYWvBmLtDK.html">Industroyer</a></strong>.</p><p>El mundo cibercriminal, ShinyHunters se mostr&#243; muy activo esta &#250;ltima semana, sumando varias v&#237;ctimas. Adem&#225;s, se conoci&#243; el <a href="https://www.chicagotribune.com/2026/04/27/teen-charged-in-chicago-was-part-of-international-scattered-spider-hacker-group-feds-say/">arresto, esta vez de uno de los miembros de </a><strong><a href="https://www.chicagotribune.com/2026/04/27/teen-charged-in-chicago-was-part-of-international-scattered-spider-hacker-group-feds-say/">Scattered Spider</a></strong>, un joven de 19 a&#241;os, ciudadano estadounidense y estonio. Y otra vez los <strong>paquetes npm comprometidos</strong> dan problemas, <a href="https://thehackernews.com/2026/04/sap-npm-packages-compromised-by-mini.html">esta vez con </a><strong><a href="https://thehackernews.com/2026/04/sap-npm-packages-compromised-by-mini.html">SAP</a></strong>.</p><p>En el mundo de la IA, encontr&#233; que un ejecutivo de Nvidia advirti&#243; que, todav&#237;a, <strong>el costo del c&#243;mputo <a href="https://fortune.com/2026/04/28/nvidia-executive-cost-of-ai-is-greater-than-cost-of-employees/">es m&#225;s alto</a></strong> que el de la fuerza laboral. &#191;Por ahora? Intuyo que, cuando se pinche la burbuja, se van a acabar los modelos por suscripci&#243;n y pasar&#225;n a cobrar por tokens(como sucede v&#237;a API hoy).</p><p>Y ya que tiramos dos p&#225;lidas del mundo Linux, ahora para salir de las vulnerabilidades: <a href="https://www.profesionalreview.com/2026/04/29/ps5-linux/">lograron correr </a><strong><a href="https://www.profesionalreview.com/2026/04/29/ps5-linux/">Ubuntu</a> en la PS5</strong>, que ya hab&#237;a sido jailbreakeada, y el logo de la <em>TuxStation 5 </em>resignifica, al menos para m&#237;, el extra&#241;o dise&#241;o de la consola:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!inVM!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b31cc64-bca6-482b-a6bc-6fb2e0c9fff4_1018x897.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!inVM!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b31cc64-bca6-482b-a6bc-6fb2e0c9fff4_1018x897.png 424w, https://substackcdn.com/image/fetch/$s_!inVM!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b31cc64-bca6-482b-a6bc-6fb2e0c9fff4_1018x897.png 848w, https://substackcdn.com/image/fetch/$s_!inVM!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b31cc64-bca6-482b-a6bc-6fb2e0c9fff4_1018x897.png 1272w, https://substackcdn.com/image/fetch/$s_!inVM!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b31cc64-bca6-482b-a6bc-6fb2e0c9fff4_1018x897.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!inVM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b31cc64-bca6-482b-a6bc-6fb2e0c9fff4_1018x897.png" width="1018" height="897" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0b31cc64-bca6-482b-a6bc-6fb2e0c9fff4_1018x897.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:897,&quot;width&quot;:1018,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:762233,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/195572157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b31cc64-bca6-482b-a6bc-6fb2e0c9fff4_1018x897.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!inVM!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b31cc64-bca6-482b-a6bc-6fb2e0c9fff4_1018x897.png 424w, https://substackcdn.com/image/fetch/$s_!inVM!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b31cc64-bca6-482b-a6bc-6fb2e0c9fff4_1018x897.png 848w, https://substackcdn.com/image/fetch/$s_!inVM!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b31cc64-bca6-482b-a6bc-6fb2e0c9fff4_1018x897.png 1272w, https://substackcdn.com/image/fetch/$s_!inVM!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b31cc64-bca6-482b-a6bc-6fb2e0c9fff4_1018x897.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">(nunca hubo tantos ping&#252;inos en una edici&#243;n de Dark News)</figcaption></figure></div><p>Y la perlita de la semana es <a href="https://x.com/konekone2026">este gato naranja</a> que te aparece en pantalla si scrolle&#225;s por mucho tiempo.</p><p>Feliz d&#237;a del trabajador.</p><div><hr></div><p><em>En esta edici&#243;n:</em></p><ul><li><p><a href="https://www.brodersendarknews.com/i/195572157/copy-fail-vulnerabilidad-de-alta-severidad-en-linux-da-acceso-root">&#128039; </a><em><a href="https://www.brodersendarknews.com/i/195572157/copy-fail-vulnerabilidad-de-alta-severidad-en-linux-da-acceso-root">Copy Fail: vulnerabilidad de alta severidad en Linux da root</a></em></p></li><li><p><a href="https://www.brodersendarknews.com/i/195572157/descubren-una-vulnerabilidad-critica-en-cpanel">&#128680; </a><em><a href="https://www.brodersendarknews.com/i/195572157/descubren-una-vulnerabilidad-critica-en-cpanel">Descubren una vulnerabilidad cr&#237;tica en cPanel</a></em></p></li><li><p><a href="https://www.brodersendarknews.com/i/195572157/lotus-wiper-el-malware-destructivo-que-apunto-contra-una-petrolera-clave-de-america-latina">&#128738;&#65039; </a><em><a href="https://www.brodersendarknews.com/i/195572157/lotus-wiper-el-malware-destructivo-que-apunto-contra-una-petrolera-clave-de-america-latina">Lotus Wiper, el malware destructivo que apunt&#243; contra una petrolera clave de Am&#233;rica Latina</a></em></p></li><li><p><a href="https://www.brodersendarknews.com/i/195572157/paquetes-npm-de-sap-comprometidos-robo-de-credenciales-y-propagacion-automatica">&#128027; </a><em><a href="https://www.brodersendarknews.com/i/195572157/paquetes-npm-de-sap-comprometidos-robo-de-credenciales-y-propagacion-automatica">Paquetes npm de SAP comprometidos: robo de credenciales y propagaci&#243;n autom&#225;tica</a></em><a href="https://www.brodersendarknews.com/i/195572157/paquetes-npm-de-sap-comprometidos-robo-de-credenciales-y-propagacion-automatica"> </a></p></li><li><p><a href="https://www.brodersendarknews.com/i/195572157/adt-udemy-y-vimeo-extorsionados-por-shinyhunters">&#128184; </a><em><a href="https://www.brodersendarknews.com/i/195572157/adt-udemy-y-vimeo-extorsionados-por-shinyhunters">ADT, Udemy y Vimeo, extorsionados por ShinyHunters</a></em></p></li><li><p><a href="https://www.brodersendarknews.com/i/195572157/google-firma-un-acuerdo-con-el-pentagono-para-que-usen-gemini">&#129302; </a><em><a href="https://www.brodersendarknews.com/i/195572157/google-firma-un-acuerdo-con-el-pentagono-para-que-usen-gemini">Google firma un acuerdo con el Pent&#225;gono para que usen Gemini</a></em></p></li></ul><p>&#9200; <em>Substack dice que leer este correo completo lleva 13 minutos</em></p><p><em>Dark News #200</em></p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://bloka.red/contacto/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gebg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 424w, https://substackcdn.com/image/fetch/$s_!gebg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 848w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1272w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png" width="1456" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1127539,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://bloka.red/contacto/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194107355?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gebg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 424w, https://substackcdn.com/image/fetch/$s_!gebg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 848w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1272w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></div><h3>Copy Fail: vulnerabilidad de alta severidad en Linux da acceso root</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XDe5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cc7a8de-6ed0-4a3d-a689-e31093912368_5184x3456.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XDe5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cc7a8de-6ed0-4a3d-a689-e31093912368_5184x3456.jpeg 424w, https://substackcdn.com/image/fetch/$s_!XDe5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cc7a8de-6ed0-4a3d-a689-e31093912368_5184x3456.jpeg 848w, https://substackcdn.com/image/fetch/$s_!XDe5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cc7a8de-6ed0-4a3d-a689-e31093912368_5184x3456.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!XDe5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cc7a8de-6ed0-4a3d-a689-e31093912368_5184x3456.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XDe5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cc7a8de-6ed0-4a3d-a689-e31093912368_5184x3456.jpeg" width="1456" height="971" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8cc7a8de-6ed0-4a3d-a689-e31093912368_5184x3456.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:971,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:9166134,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/195572157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cc7a8de-6ed0-4a3d-a689-e31093912368_5184x3456.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XDe5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cc7a8de-6ed0-4a3d-a689-e31093912368_5184x3456.jpeg 424w, https://substackcdn.com/image/fetch/$s_!XDe5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cc7a8de-6ed0-4a3d-a689-e31093912368_5184x3456.jpeg 848w, https://substackcdn.com/image/fetch/$s_!XDe5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cc7a8de-6ed0-4a3d-a689-e31093912368_5184x3456.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!XDe5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8cc7a8de-6ed0-4a3d-a689-e31093912368_5184x3456.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Shutterstock</figcaption></figure></div><p>Una vulnerabilidad de alta severidad en el kernel de Linux llamada <strong>Copy Fail</strong> permite que un usuario local con privilegios m&#237;nimos <strong>escale permisos</strong> y obtenga <strong>root</strong> en distribuciones publicadas desde 2017.</p><p>La prueba de concepto es un script de 732 bytes que otorga privilegios de administrador a las principales distribuciones que ejecutan una versi&#243;n vulnerable del kernel.</p><p><strong>Qu&#233; pas&#243;.</strong> Investigadores de <strong><a href="https://xint.io/blog/copy-fail-linux-distributions">Xint.io y Theori</a></strong> revelaron el CVE-2026-31431, que explota un bug que est&#225; en el m&#243;dulo <code>algif_aead</code>, dentro del subsistema criptogr&#225;fico, y fue introducido por un cambio de c&#243;digo de 2017. Se dice que <strong>usaron modelos de IA</strong> para encontrar el problema, que fue probado y validado por investigadores de seguridad de diversas partes del mundo.</p><p><strong>Por qu&#233; importa.</strong> El exploit permitir&#237;a escribir cuatro bytes controlados en la <em>page cache</em> de cualquier archivo legible del sistema. Con eso, un atacante local puede alterar la copia cacheada de un binario setuid, como /usr/bin/su, y ejecutarlo para <strong>obtener root.</strong></p><p><strong>Alcance.</strong> La falla afecta a distribuciones Linux publicadas desde 2017, incluidas <strong>Arch Linux,</strong> <strong>Fedora, Oracle Linux,</strong> <strong>Amazon Linux, RHEL, SUSE, Ubuntu y Debian, entre otros</strong>. No es explotable de forma remota por s&#237; sola, pero cualquier acceso local de bajo privilegio podr&#237;a convertirse en control administrativo.</p><p>El riesgo crece en entornos compartidos o con contenedores: la <em>page cache</em> es com&#250;n a todos los procesos del sistema, por lo que el impacto puede <strong>cruzar l&#237;mites de sandboxing</strong>.</p><p><strong>El contexto.</strong> Bleeping Computer record&#243; que <a href="https://www.bleepingcomputer.com/news/security/new-linux-copy-fail-flaw-gives-hackers-root-on-major-distros/">Copy Fail recuerda a Dirty Pipe</a>, otra falla del kernel que permit&#237;a modificar la page cache de archivos de solo lectura. Seg&#250;n los investigadores, la diferencia clave es que este exploit ser&#237;a <strong>portable, peque&#241;o y  confiable</strong>.</p><p><strong>Qu&#233; hacer.</strong> Las principales distribuciones ya publicaron avisos y parches. La prioridad es <strong>actualizar el kernel en servidores Linux</strong>, especialmente en sistemas multiusuario, cloud, hosting y entornos con contenedores.</p><p>Tenable public&#243; un <a href="https://www.tenable.com/blog/copy-fail-cve-2026-31431-frequently-asked-questions-about-linux-kernel-privilege-escalation">FAQ</a> con detalles del caso.</p><h3>Descubren una vulnerabilidad cr&#237;tica en cPanel</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!5oqy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403c676e-4d0d-465f-9c41-d54040fddfc5_996x564.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!5oqy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403c676e-4d0d-465f-9c41-d54040fddfc5_996x564.png 424w, https://substackcdn.com/image/fetch/$s_!5oqy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403c676e-4d0d-465f-9c41-d54040fddfc5_996x564.png 848w, https://substackcdn.com/image/fetch/$s_!5oqy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403c676e-4d0d-465f-9c41-d54040fddfc5_996x564.png 1272w, https://substackcdn.com/image/fetch/$s_!5oqy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403c676e-4d0d-465f-9c41-d54040fddfc5_996x564.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!5oqy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403c676e-4d0d-465f-9c41-d54040fddfc5_996x564.png" width="996" height="564" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/403c676e-4d0d-465f-9c41-d54040fddfc5_996x564.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:564,&quot;width&quot;:996,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:283901,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/195572157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403c676e-4d0d-465f-9c41-d54040fddfc5_996x564.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!5oqy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403c676e-4d0d-465f-9c41-d54040fddfc5_996x564.png 424w, https://substackcdn.com/image/fetch/$s_!5oqy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403c676e-4d0d-465f-9c41-d54040fddfc5_996x564.png 848w, https://substackcdn.com/image/fetch/$s_!5oqy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403c676e-4d0d-465f-9c41-d54040fddfc5_996x564.png 1272w, https://substackcdn.com/image/fetch/$s_!5oqy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F403c676e-4d0d-465f-9c41-d54040fddfc5_996x564.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">cPanel</figcaption></figure></div><p>Una <a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41940">falla cr&#237;tica en </a><strong><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-41940">cPanel y WHM</a></strong> permite <strong>saltar la autenticaci&#243;n</strong> y entrar al panel de control sin credenciales. El proveedor public&#243; una actualizaci&#243;n de emergencia y pidi&#243; forzar la instalaci&#243;n del parche.</p><p><a href="https://cyberscoop.com/cpanel-authentication-bypass-vulnerability-cve-2026-41940-exploited/">CISA advirti&#243;</a> que <strong>ya se explota </strong><em><strong>in the wild.</strong></em></p><p><strong>Qu&#233; pas&#243;.</strong> La vulnerabilidad, identificada como <strong>CVE-2026-41940</strong>, tiene un puntaje de severidad de <strong>9,8</strong> y afecta a todas las versiones soportadas salvo las m&#225;s recientes. cPanel inform&#243; que el problema <strong>ya fue corregido</strong> en varias ramas del producto.</p><p><strong>Por qu&#233; importa.</strong> cPanel y WHM son paneles muy usados por proveedores de hosting para administrar sitios, servidores, bases de datos y correo. WHM da control a nivel servidor, mientras cPanel da acceso al backend de sitios, webmail y bases de datos.</p><p><strong>El riesgo.</strong> Un atacante con acceso a cPanel puede controlar sitios y datos del hosting, robar archivos sensibles, instalar backdoors o web shells, redirigir usuarios, enviar spam o phishing y extraer contrase&#241;as de archivos de configuraci&#243;n. Con WHM, el impacto escala al servidor completo y a todos los sitios alojados.</p><p><strong>La se&#241;al.</strong> No se publicaron detalles t&#233;cnicos, pero Namecheap bloque&#243; temporalmente los puertos 2083 y 2087, usados por cPanel y WHM, para proteger a sus clientes hasta que hubiera parches disponibles. La empresa dijo que la falla pod&#237;a permitir acceso no autorizado al panel de control.</p><p><strong>Qu&#233; hacer.</strong> cPanel pidi&#243; a los administradores ejecutar manualmente <code>/scripts/upcp --force</code> para forzar la actualizaci&#243;n, incluso si el sistema cree estar al d&#237;a. </p><p>Los servidores con versiones sin soporte no reciben parches y deben migrar a una versi&#243;n soportada cuanto antes.</p><h3><strong>Lotus Wiper, el malware destructivo que apunt&#243; contra una petrolera clave de Am&#233;rica Latina</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!zgMV!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e2dcad6-d391-4566-94ee-79890d2cee5d_1293x882.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!zgMV!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e2dcad6-d391-4566-94ee-79890d2cee5d_1293x882.png 424w, https://substackcdn.com/image/fetch/$s_!zgMV!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e2dcad6-d391-4566-94ee-79890d2cee5d_1293x882.png 848w, https://substackcdn.com/image/fetch/$s_!zgMV!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e2dcad6-d391-4566-94ee-79890d2cee5d_1293x882.png 1272w, https://substackcdn.com/image/fetch/$s_!zgMV!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e2dcad6-d391-4566-94ee-79890d2cee5d_1293x882.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!zgMV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e2dcad6-d391-4566-94ee-79890d2cee5d_1293x882.png" width="1293" height="882" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3e2dcad6-d391-4566-94ee-79890d2cee5d_1293x882.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:882,&quot;width&quot;:1293,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1815977,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/195572157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e2dcad6-d391-4566-94ee-79890d2cee5d_1293x882.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!zgMV!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e2dcad6-d391-4566-94ee-79890d2cee5d_1293x882.png 424w, https://substackcdn.com/image/fetch/$s_!zgMV!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e2dcad6-d391-4566-94ee-79890d2cee5d_1293x882.png 848w, https://substackcdn.com/image/fetch/$s_!zgMV!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e2dcad6-d391-4566-94ee-79890d2cee5d_1293x882.png 1272w, https://substackcdn.com/image/fetch/$s_!zgMV!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3e2dcad6-d391-4566-94ee-79890d2cee5d_1293x882.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: EFE</figcaption></figure></div><p>Un nuevo hallazgo t&#233;cnico reaviv&#243; el misterio sobre el ciberataque que golpe&#243; a <strong>PDVSA</strong> en diciembre: en vez de ransomware, pudo haber sido un wiper altamente destructivo dise&#241;ado para la petrolera estatal venezolana.</p><p><strong>Qu&#233; pas&#243;.</strong> <a href="https://securelist.com/tr/lotus-wiper/119472/">Kaspersky detect&#243;</a> un malware al que bautiz&#243; <strong>Lotus Wiper</strong>, activo contra el sector de energ&#237;a y servicios en Venezuela entre diciembre y enero. El dato m&#225;s fuerte <a href="https://www.zetter-zeroday.com/hwiper-targeting-venezuelas-state-oil-company-discovered/">lo destac&#243; Kim Zetter</a>: uno de los archivos ten&#237;a <strong>&#8220;pdvsa.com&#8221; hardcodeado</strong>, lo que sugiere que estaba configurado para activarse solo dentro de la red de PDVSA y evitar da&#241;os fuera del objetivo.</p><p><strong>Por qu&#233; importa.</strong> Los primeros reportes hablaban de ransomware, pero este malware <strong>no incluye pedido de rescate</strong> y fue dise&#241;ado para destruir: sobrescribe discos, borra backups, elimina archivos cr&#237;ticos, limpia logs y deja equipos inoperables. Kaspersky lo describi&#243; como una herramienta &#8220;extremadamente dirigida&#8221; y sin motivaci&#243;n financiera.</p><p><strong>Qu&#233; se sabe.</strong> El ataque ocurri&#243; el <strong>13 de diciembre de 2025</strong> y PDVSA lo reconoci&#243; dos d&#237;as despu&#233;s. La empresa dijo que solo afect&#243; sistemas administrativos. Pero, seg&#250;n recopil&#243; Zetter a partir de <strong>Reuters, Bloomberg </strong>y otros reportes, el impacto habr&#237;a sido mayor: exportaciones demoradas, terminales fuera de l&#237;nea y empleados operando durante semanas con <strong>WhatsApp, Telegram, llamadas y notas manuscritas</strong>. </p><p>Bloomberg incluso report&#243; impacto sobre sistemas <strong>SCADA</strong> en refiner&#237;as, plantas y oleoductos.</p><p><strong>El dato t&#233;cnico.</strong> Seg&#250;n Zetter, Lotus fue compilado a fines de <strong>septiembre de 2025</strong>, meses antes del incidente. Adem&#225;s, intenta desactivar un servicio viejo de Windows, una pista de que los atacantes conoc&#237;an de antemano que PDVSA usaba sistemas legacy, algo consistente con a&#241;os de sanciones y problemas de actualizaci&#243;n tecnol&#243;gica en Venezuela.</p><p><strong>Entre l&#237;neas.</strong> No hay prueba p&#250;blica de qui&#233;n estuvo detr&#225;s. Pero el contexto geopol&#237;tico es el de la escalada entre Washington y Caracas, con antecedentes de operaciones cyber de EE.UU. en Venezuela reveladas por Wired y CNN.</p><h3>Paquetes npm de SAP comprometidos: robo de credenciales y propagaci&#243;n autom&#225;tica</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YkNW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93cb60ea-11b2-44a2-b30f-a437c8ff6a47_1150x702.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YkNW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93cb60ea-11b2-44a2-b30f-a437c8ff6a47_1150x702.png 424w, https://substackcdn.com/image/fetch/$s_!YkNW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93cb60ea-11b2-44a2-b30f-a437c8ff6a47_1150x702.png 848w, https://substackcdn.com/image/fetch/$s_!YkNW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93cb60ea-11b2-44a2-b30f-a437c8ff6a47_1150x702.png 1272w, https://substackcdn.com/image/fetch/$s_!YkNW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93cb60ea-11b2-44a2-b30f-a437c8ff6a47_1150x702.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YkNW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93cb60ea-11b2-44a2-b30f-a437c8ff6a47_1150x702.png" width="1150" height="702" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/93cb60ea-11b2-44a2-b30f-a437c8ff6a47_1150x702.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:702,&quot;width&quot;:1150,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:595160,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/195572157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93cb60ea-11b2-44a2-b30f-a437c8ff6a47_1150x702.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YkNW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93cb60ea-11b2-44a2-b30f-a437c8ff6a47_1150x702.png 424w, https://substackcdn.com/image/fetch/$s_!YkNW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93cb60ea-11b2-44a2-b30f-a437c8ff6a47_1150x702.png 848w, https://substackcdn.com/image/fetch/$s_!YkNW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93cb60ea-11b2-44a2-b30f-a437c8ff6a47_1150x702.png 1272w, https://substackcdn.com/image/fetch/$s_!YkNW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F93cb60ea-11b2-44a2-b30f-a437c8ff6a47_1150x702.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Un ataque a la cadena de suministro comprometi&#243; <strong><a href="https://www.wiz.io/blog/mini-shai-hulud-supply-chain-sap-npm">paquetes npm vinculados a SAP</a></strong> e inyect&#243; malware para robar credenciales y propagarse en repositorios.</p><p><strong>Qu&#233; pas&#243;.</strong> Investigadores detectaron versiones maliciosas de paquetes usados en el ecosistema JavaScript de SAP, publicados el 29 de abril. Incluyen mbt y m&#243;dulos @cap-js, claves en entornos cloud y desarrollo.</p><p><strong>C&#243;mo funciona.</strong> Las versiones alteradas agregaron un script &#8220;preinstall&#8221; que descarga y ejecuta c&#243;digo v&#237;a Bun sin validaci&#243;n, <strong>incluso usando PowerShell con bypass en Windows</strong>. Act&#250;a como loader de un stealer y framework de propagaci&#243;n.</p><p><strong>Impacto.</strong> El malware roba credenciales locales, tokens de GitHub y npm, secretos de CI/CD y de nubes como AWS, Azure y GCP. Tambi&#233;n accede a contrase&#241;as en navegadores. <strong>Los datos se cifran y se exfiltran a repositorios GitHub</strong> creados en cuentas de las v&#237;ctimas. </p><p>Ya hay m&#225;s de 1.100 repositorios detectados.</p><h3>ADT, Udemy y Vimeo, extorsionados por ShinyHunters</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PVjt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb4e7-62d6-4ccf-8c82-a3b796cbd591_1244x766.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PVjt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb4e7-62d6-4ccf-8c82-a3b796cbd591_1244x766.png 424w, https://substackcdn.com/image/fetch/$s_!PVjt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb4e7-62d6-4ccf-8c82-a3b796cbd591_1244x766.png 848w, https://substackcdn.com/image/fetch/$s_!PVjt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb4e7-62d6-4ccf-8c82-a3b796cbd591_1244x766.png 1272w, https://substackcdn.com/image/fetch/$s_!PVjt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb4e7-62d6-4ccf-8c82-a3b796cbd591_1244x766.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PVjt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb4e7-62d6-4ccf-8c82-a3b796cbd591_1244x766.png" width="1244" height="766" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ccafb4e7-62d6-4ccf-8c82-a3b796cbd591_1244x766.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:766,&quot;width&quot;:1244,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:464959,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/195572157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb4e7-62d6-4ccf-8c82-a3b796cbd591_1244x766.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PVjt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb4e7-62d6-4ccf-8c82-a3b796cbd591_1244x766.png 424w, https://substackcdn.com/image/fetch/$s_!PVjt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb4e7-62d6-4ccf-8c82-a3b796cbd591_1244x766.png 848w, https://substackcdn.com/image/fetch/$s_!PVjt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb4e7-62d6-4ccf-8c82-a3b796cbd591_1244x766.png 1272w, https://substackcdn.com/image/fetch/$s_!PVjt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fccafb4e7-62d6-4ccf-8c82-a3b796cbd591_1244x766.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">DLS de ShinyHunters</figcaption></figure></div><p>ShinyHunters sum&#243; a <strong><a href="https://www.bleepingcomputer.com/news/security/adt-confirms-data-breach-after-shinyhunters-leak-threat/">ADT</a>, <a href="https://hackread.com/shinyhunters-leak-udemy-zara-7-eleven-data-breach/">Udemy</a> y <a href="https://www.securityweek.com/vimeo-confirms-user-and-customer-data-breach/">Vimeo</a></strong> a su sitio de extorsi&#243;n. En los tres casos, el grupo asegura haber robado datos y subi&#243; la informaci&#243;n.</p><p><strong>ADT.</strong> La empresa de seguridad hogare&#241;a confirm&#243; una brecha tras aparecer en el leak site del grupo. Dijo que detect&#243; el acceso el 20 de abril y que se robaron nombres, tel&#233;fonos y direcciones. En algunos casos tambi&#233;n quedaron expuestos fechas de nacimiento y los &#250;ltimos cuatro d&#237;gitos del Social Security o Tax ID. </p><p>ADT aclar&#243; que no se afectaron datos de pago ni los sistemas de seguridad de los clientes. </p><p>ShinyHunters habla de <strong>m&#225;s de 10 millones de registros</strong> y asegura que entr&#243; con un ataque de vishing sobre una cuenta de Okta SSO y desde ah&#237; accedi&#243; a <strong>Salesforce</strong>.</p><p><strong>Udemy.</strong> El grupo afirma haber robado 2,3 GB de datos, incluyendo m&#225;s de 1,4 millones de registros de Salesforce. Seg&#250;n su publicaci&#243;n, el lote incluye PII (Informaci&#243;n Personal Identificable) y datos corporativos internos. </p><p><strong>Vimeo.</strong> Confirm&#243; un incidente ligado a <strong>Anodot</strong> (mismo vector de ataque que <strong><a href="https://www.brodersendarknews.com/i/194107355/rockstar-games-creadores-de-gta-hackeado-otra-vez">Rockstar Games</a></strong>), un proveedor externo de anal&#237;tica. La empresa dijo que quedaron expuestos sobre todo datos t&#233;cnicos, t&#237;tulos de videos, metadata y en algunos casos emails. Asegur&#243; que no se filtraron videos, credenciales ni tarjetas. </p><p>ShinyHunters sostiene que el acceso lleg&#243; a trav&#233;s de tokens robados de Anodot y que comprometi&#243; entornos en Snowflake y BigQuery. </p><p><strong>Por qu&#233; importa.</strong> Los tres casos refuerzan la tendencia de ShinyHunters de explotar SSO, SaaS y proveedores terceros para robar datos y convertir esos accesos en campa&#241;as de extorsi&#243;n.</p><h3>Google firma un acuerdo con el Pent&#225;gono para que usen Gemini</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2G3c!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3095b207-d878-4d7d-8067-88f3f77fdd48_1464x899.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2G3c!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3095b207-d878-4d7d-8067-88f3f77fdd48_1464x899.png 424w, https://substackcdn.com/image/fetch/$s_!2G3c!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3095b207-d878-4d7d-8067-88f3f77fdd48_1464x899.png 848w, https://substackcdn.com/image/fetch/$s_!2G3c!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3095b207-d878-4d7d-8067-88f3f77fdd48_1464x899.png 1272w, https://substackcdn.com/image/fetch/$s_!2G3c!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3095b207-d878-4d7d-8067-88f3f77fdd48_1464x899.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2G3c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3095b207-d878-4d7d-8067-88f3f77fdd48_1464x899.png" width="1456" height="894" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3095b207-d878-4d7d-8067-88f3f77fdd48_1464x899.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:894,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2026324,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/195572157?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3095b207-d878-4d7d-8067-88f3f77fdd48_1464x899.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2G3c!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3095b207-d878-4d7d-8067-88f3f77fdd48_1464x899.png 424w, https://substackcdn.com/image/fetch/$s_!2G3c!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3095b207-d878-4d7d-8067-88f3f77fdd48_1464x899.png 848w, https://substackcdn.com/image/fetch/$s_!2G3c!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3095b207-d878-4d7d-8067-88f3f77fdd48_1464x899.png 1272w, https://substackcdn.com/image/fetch/$s_!2G3c!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3095b207-d878-4d7d-8067-88f3f77fdd48_1464x899.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Pete Hegseth, secretario de Defensa. Foto: Reuters</figcaption></figure></div><p>Google firm&#243; un acuerdo para que el <a href="https://www.nytimes.com/2026/04/28/technology/google-ai-deal-pentagon.html">Pent&#225;gono use Gemini en redes clasificadas</a>, en un nuevo paso de la carrera por meter IA en defensa. El movimiento llega mientras sigue abierta la <strong>pelea entre el Departamento de Defensa y Anthropic</strong> por los l&#237;mites al uso militar de estos modelos.</p><p><strong>Qu&#233; pas&#243;.</strong> El acuerdo habilita al Pent&#225;gono a usar la IA de Google en sistemas clasificados para &#8220;cualquier prop&#243;sito gubernamental legal&#8221;. Forma parte de un contrato de hasta US$ 200 millones firmado el a&#241;o pasado. Seg&#250;n el New York Times, el lenguaje replica el de los acuerdos que Defensa cerr&#243; el mes pasado con OpenAI y xAI.</p><p><strong>Por qu&#233; importa.</strong> El Pent&#225;gono est&#225; acelerando fuerte la adopci&#243;n de IA. En enero, Pete Hegseth pidi&#243; integrarla de forma amplia en las Fuerzas Armadas. La semana pasada, adem&#225;s, Defensa pidi&#243; al Congreso US$ 2.300 millones para expandir Project Maven, el sistema de Palantir para an&#225;lisis de inteligencia.</p><p><strong>La tensi&#243;n.</strong> El avance coincide con el choque con Anthropic, que se neg&#243; a eliminar guardrails contra armas aut&#243;nomas y vigilancia dom&#233;stica. En marzo, el Pent&#225;gono la marc&#243; como &#8220;supply chain risk&#8221;, una etiqueta que en la pr&#225;ctica la bloque&#243; de nuevos contratos. <strong>La empresa demand&#243; al gobierno.</strong></p><p><strong>Qu&#233; cambia.</strong> Project Maven hoy usa tecnolog&#237;a de Anthropic. Si no hay acuerdo, otro proveedor podr&#237;a reemplazarla. En paralelo, m&#225;s de 600 empleados de Google firmaron una carta para rechazar el uso de su tecnolog&#237;a en operaciones militares clasificadas.</p><div><hr></div><h4><strong>&#128275; Breaches y hacks</strong></h4><ul><li><p>Otra <a href="https://finance.yahoo.com/markets/crypto/articles/another-defi-platform-just-got-122925586.html">plataforma DeFi</a> fue hackeada con un exploit por 1,5 millones</p></li><li><p><a href="https://www.cybersecuritydive.com/news/hasbro-march-cyberattack-impact-second-quarter-revenue/818438/">Hasbro</a> demora sus resultados financieros por un ciberataque</p></li><li><p><a href="https://www.securityweek.com/vimeo-confirms-user-and-customer-data-breach/">Vimeo</a> confirma un data breach que incluye informaci&#243;n de usuarios</p></li></ul><h4><strong>&#128274; Ransomware</strong></h4><ul><li><p><a href="https://argentina.mefiltraron.com/leaks#Sancor-2026-04-25">Qilin anuncia</a> a Sancor en Argentina como v&#237;ctima</p></li><li><p><a href="https://securityaffairs.com/191294/cyber-crime/trigona-ransomware-adopts-custom-tool-to-steal-data-and-evade-detection.html">Trigona</a> adopta una herramienta customizada para evadir detecciones</p></li><li><p>Una <a href="https://www.securityweek.com/sandhills-medical-says-ransomware-breach-affects-170000/">entidad de salud</a> afirma que un ransomware afecta a 170 mil usuarios</p></li></ul><h4><strong>&#128163; Exploits y malware</strong></h4><ul><li><p>Explotan una falla cr&#237;tica en <a href="https://securityaffairs.com/191483/hacking/cve-2026-42208-litellm-bug-exploited-36-hours-after-its-disclosure.html">LiteLLM</a> para modificar bases de datos v&#237;a inyecci&#243;n SQL</p></li><li><p>Aparecen m&#225;s emails de PayPal dise&#241;ados para enga&#241;ar usuarios v&#237;a <a href="https://www.malwarebytes.com/blog/news/2026/04/more-paypal-emails-hijacked-to-deliver-tech-support-scams">soporte t&#233;cnico fake</a></p></li><li><p>Una empresa <a href="https://krebsonsecurity.com/2026/04/anti-ddos-firm-heaped-attacks-on-brazilian-isps/">anti-DDoS</a> particip&#243; de ataques contra ISP en Brasil</p></li></ul><h4><strong>&#128269; Threat intel y vulnerabilidades</strong></h4><ul><li><p>Lapsus, detr&#225;s del hackeo a la empresa de seguridad <a href="https://checkmarx.com/blog/supply-chain-security-incident-update/">Checkmarx</a></p></li><li><p>EE.UU. perdi&#243; 2,1 mil millones por <a href="https://www.ftc.gov/news-events/news/press-releases/2026/04/new-ftc-data-show-people-have-lost-billions-social-media-scams">estafas</a> en redes sociales</p></li><li><p>Reportes: <a href="https://www.gartner.com/en/newsroom/press-releases/2026-04-28-gartner-estimates-us-states-privacy-fines-totaled-3-point-425-billion-dollars-in-2025-trend-expected-to-accelerate-through-2028">Gartner</a>, <a href="https://horizon3.ai/downloads/research/the-state-of-assumed-security/">Horizon3</a>, <a href="https://blog.cloudflare.com/q1-2026-internet-disruption-summary/">Cloudflare</a>, <a href="https://www.paloaltonetworks.com/blog/2026/04/securing-and-governing-ai-agents-at-scale-through-a-unified-ai-gateway/">Palo Alto</a></p></li></ul><h4><strong>&#128736;&#65039; Tools y updates</strong></h4><ul><li><p>CrowdStrike arregl&#243; una <a href="https://securityaffairs.com/191343/hacking/critical-bug-in-crowdstrike-logscale-let-attackers-access-files.html">vulnerabilidad cr&#237;tica</a></p></li><li><p>La &#250;ltima actualizaci&#243;n de Windows 11 causa <a href="https://www.bleepingcomputer.com/news/microsoft/april-kb5083769-windows-11-update-causes-backup-software-failures/">errores en los backups</a></p></li><li><p><a href="https://www.securityweek.com/chrome-147-firefox-150-security-updates-rolling-out/">Chrome 147 y Firefox 150</a>: actualizaciones de seguridad</p></li></ul><h4><strong>&#128203; Privacidad y regulaciones</strong></h4><ul><li><p>Turqu&#237;a se suma a la lista de pa&#237;ses en <a href="https://apnews.com/article/turkey-social-media-children-restrictions-law-d88963a7446a12cf4963b73d455b5ef7">prohibir redes</a> a menores</p></li><li><p>Desaparecen varios sitios conocidos de <a href="https://torrentfreak.com/sflix-myflixerz-hdtoday-and-other-pirate-sites-go-dark-as-backend-infrastructure-fails/">pirater&#237;a</a></p></li><li><p><a href="https://cyberscoop.com/privacy-companies-hit-with-record-fines-2025-gartner/">Multas record</a> a compa&#241;&#237;as americanas por violaciones a la privacidad: 3,4 mil millones</p><p></p></li></ul><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial generativa para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/dos-fallas-criticas-linux-cpanel-exploits?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/dos-fallas-criticas-linux-cpanel-exploits?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Derek Manky, experto en threat intel: “Todavía no desarrollamos un verdadero instinto de supervivencia digital”]]></title><description><![CDATA[Ransomware sin cifrado, infostealers casi imposibles de bajar, agentes de initial access brokers y la IA que acelera todo: charla a fondo con uno de los principales especialistas de Fortinet.]]></description><link>https://www.brodersendarknews.com/p/derek-manky-fortinet-threat-intel-ransomware-iab-ai</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/derek-manky-fortinet-threat-intel-ransomware-iab-ai</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Sun, 26 Apr 2026 12:12:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!ylTb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F356417cf-e18c-4ed6-bb91-0c16710fac74_1663x1247.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>26<br>abr</h1><h2><strong>&#127908; Entrevista</strong></h2><p>Conoc&#237; a <strong>Derek Manky</strong> en noviembre de 2022, en un congreso en Canc&#250;n, M&#233;xico. Especialista en <em>threat intelligence</em>, es una de esas fuentes que vale la pena escuchar: lleva d&#233;cadas siguiendo de cerca la evoluci&#243;n del cibercrimen y tiene un perfil t&#233;cnico poco habitual en ejecutivos de grandes compa&#241;&#237;as.</p><p>En <strong>Fortinet</strong>, donde est&#225; hace m&#225;s de 20 a&#241;os, lidera el equipo de threat intelligence. A fines del a&#241;o pasado surgi&#243; la posibilidad de entrevistarlo. Estoy publicando un poco despu&#233;s, en parte por temas de agenda del d&#237;a a d&#237;a (las rutinas de producci&#243;n en un diario suelen interrumpir, frecuentemente, las notas que demandan parar un poco la pelota). </p><p>El mundo de la ciberseguridad se mueve muy r&#225;pido. Pero creo que gran parte de las respuestas de Manky siguen siendo representativas, en parte porque las preguntas no fueron sobre incidentes puntuales sino por problem&#225;ticas m&#225;s generales.</p><p>La segunda aclaraci&#243;n es que hay mucha terminolog&#237;a anglosajona. No es lo que m&#225;s me gusta a la hora de escribir, pero hay conceptos que son dif&#237;ciles de traducir. Algunos t&#233;rminos son bastante intuitivos. Otros no tanto. </p><p>En esos casos, prefer&#237; priorizar la precisi&#243;n antes que una traducci&#243;n forzada (al fin y al cabo, <em><strong><a href="https://www.fundeu.es/noticia/traduccion-un-puente-entre-dos-lenguas/">traduttore traditore</a></strong></em> como respuesta a todo).</p><p>Sin m&#225;s, ac&#225;, la charla que tuvimos hace unos meses.</p><div><hr></div><p>&#9200; <em>Substack dice que leer este correo completo lleva 16 minutos</em></p><p><em>Dark News #199</em></p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.kulkan.com/?utm_source=newsletter&amp;utm_medium=dark_news&amp;utm_campaign=quote#quote" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qXPk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 424w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 848w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 1272w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qXPk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png" width="600" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/379ea089-6930-4e5c-a652-27cb153177d8_600x300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:136661,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.kulkan.com/?utm_source=newsletter&amp;utm_medium=dark_news&amp;utm_campaign=quote#quote&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/193094978?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qXPk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 424w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 848w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 1272w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></div><h3>Supply chain y crimen como servicio, vigentes</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ylTb!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F356417cf-e18c-4ed6-bb91-0c16710fac74_1663x1247.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ylTb!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F356417cf-e18c-4ed6-bb91-0c16710fac74_1663x1247.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ylTb!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F356417cf-e18c-4ed6-bb91-0c16710fac74_1663x1247.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ylTb!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F356417cf-e18c-4ed6-bb91-0c16710fac74_1663x1247.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ylTb!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F356417cf-e18c-4ed6-bb91-0c16710fac74_1663x1247.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ylTb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F356417cf-e18c-4ed6-bb91-0c16710fac74_1663x1247.jpeg" width="1456" height="1092" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/356417cf-e18c-4ed6-bb91-0c16710fac74_1663x1247.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1092,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:282506,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/195477752?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F356417cf-e18c-4ed6-bb91-0c16710fac74_1663x1247.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ylTb!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F356417cf-e18c-4ed6-bb91-0c16710fac74_1663x1247.jpeg 424w, https://substackcdn.com/image/fetch/$s_!ylTb!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F356417cf-e18c-4ed6-bb91-0c16710fac74_1663x1247.jpeg 848w, https://substackcdn.com/image/fetch/$s_!ylTb!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F356417cf-e18c-4ed6-bb91-0c16710fac74_1663x1247.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!ylTb!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F356417cf-e18c-4ed6-bb91-0c16710fac74_1663x1247.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Derek Manky, experto en threat intel</figcaption></figure></div><p><em>&#9472;Cada a&#241;o parece tener su buzzword en ciberseguridad. En 2025 y la primera parte de 2026, la IA monopoliz&#243; la conversaci&#243;n. M&#225;s all&#225; de esa etiqueta, &#191;qu&#233; hay m&#225;s all&#225; del hype?</em></p><p>&#9472;La clave es c&#243;mo se est&#225; implementando la IA. Si me pregunt&#225;s qu&#233; aparece cuando hablo con <strong>CISOs</strong>, uno de los temas m&#225;s frecuentes es <em>AI-driven SecOps</em>: la integraci&#243;n y convergencia de herramientas para acelerar la adopci&#243;n de <em>threat intelligence</em> y reducir los tiempos de respuesta frente a amenazas. Ese es un eje. El otro, que fue central en 2025 y va a seguir si&#233;ndolo en 2026, es la seguridad de los propios sistemas de IA. Hay much&#237;simo inter&#233;s en <em>secure AI data centers</em> y en c&#243;mo proteger esa infraestructura. El panorama de amenazas evoluciona muy r&#225;pido y ya estamos viendo ataques contra sistemas de IA, <em><strong>weaponizaci&#243;n </strong></em><strong>de modelos ya disponibles</strong>, <em>Crime-as-a-Service</em> montados en la <em>dark web</em> con ayuda de GPTs y nuevos intentos de extraer informaci&#243;n sensible o envenenar esos modelos.</p><p><em><strong>&#9472;</strong>Los atacantes est&#225;n usando AI para acelerar operaciones. &#191;La industria se vio obligada a adoptar AI para responder a esa velocidad?</em></p><p><strong>&#9472;</strong>100%. Es una suerte de carrera armament&#237;stica digital donde todo se est&#225; acelerando cada vez m&#225;s. De hecho, seg&#250;n nuestro <a href="https://www.fortinet.com/resources/reports/threat-landscape-report">Global Threat Landscape Report</a>, desde la perspectiva del atacante, el tiempo para atacar del Red Team est&#225; por debajo de 5 d&#237;as. Y creo que el a&#241;o que viene, cuando publiquemos el nuevo reporte, va a ser todav&#237;a m&#225;s r&#225;pido.</p><p><em><strong>&#9472;</strong>Cuando hablamos en 2022, el ataque a la cadena de suministro era uno de los grandes temas. Tres a&#241;os despu&#233;s, sigue apareciendo en casos de alto perfil. &#191;C&#243;mo est&#225; el problema?</em></p><p><strong>&#9472;&#9472;</strong>S&#237;, sigue siendo una preocupaci&#243;n, pero tambi&#233;n evolucion&#243;. Hoy el <em>supply chain</em> es mucho m&#225;s amplio, sobre todo cuando hablamos de modelos de IA, desarrollos a medida desplegados en nuevos <em>data centers</em> y toda esa infraestructura asociada. Las <strong>GPUs</strong>, e incluso ahora los <em>edge devices</em>, tambi&#233;n entran en ese problema [<a href="https://www.brodersendarknews.com/i/170319059/un-argentino-descubre-una-vulnerabilidad-critica-en-casi-todos-los-servicios-de-inteligencia-artificial">ver esta investigaci&#243;n de Black Hat</a>]. La cuesti&#243;n tecnol&#243;gica hoy pasa por <strong>c&#243;mo identific&#225;s esa cadena de suministro</strong>, porque eso cambi&#243; mucho desde 2022: en el fondo, es una discusi&#243;n sobre c&#243;mo gestion&#225;s tu superficie de ataque. Y eso conecta con <strong>otra </strong><em><strong>buzzword</strong></em> que no mencion&#233; antes: <em>CTEM</em>, <em>Continuous Threat Exposure Management</em>.</p><p><em>&#9472;&#191;Qu&#233; es?</em></p><p>&#9472;Es llevar la gesti&#243;n de la superficie de ataque a un esquema m&#225;s continuo: ponerla a prueba con <em>penetration testing</em> y otras t&#233;cnicas, y reforzar los controles de forma m&#225;s din&#225;mica. En lugar de hacer un chequeo anual, sacar un reporte, hacer un <em>pentest</em> y despu&#233;s intentar cerrar los <em>gaps</em>, ahora todo se hace mucho m&#225;s en tiempo real. Y eso responde a una realidad simple, que es que el <em><strong>threat landscape</strong></em><strong> se mueve cada vez m&#225;s r&#225;pido</strong>. Por eso <em>CTEM</em> hoy es casi una necesidad.</p><p><em>&#9472;&#191;C&#243;mo est&#225; el panorama del crimen como servicio?</em></p><p>&#9472;&#9472;El ascenso del <em>Crime-as-a-Service</em> lo est&#225; acelerando mucho. Hoy hay un conjunto de componentes que le permiten a un atacante, con una inversi&#243;n relativamente baja, comprar una herramienta y lanzar operaciones contra m&#250;ltiples objetivos, por ejemplo cinco bancos distintos. Esa herramienta adem&#225;s puede generar <strong>lenguaje muy regionalizado</strong>, en espa&#241;ol, chino, japon&#233;s o ingl&#233;s, y adaptarse a cada blanco sin que el atacante tenga que hacerlo manualmente. Eso es lo que estamos viendo: herramientas cada vez m&#225;s sofisticadas que les permiten ser m&#225;s especializados, m&#225;s efectivos y operar a escala.</p><p><em>&#9472;&#191;Hubo alguna t&#233;cnica o ataque reciente que te haya impresionado por su nivel de sofisticaci&#243;n?</em></p><p>&#9472;En t&#233;rminos de ataques <em>in the wild</em>, de lo m&#225;s interesante que estamos viendo en investigaci&#243;n son los nuevos ataques dirigidos a sistemas de IA para extraer informaci&#243;n sensible. Un ejemplo es lo que llamamos <em><a href="https://www.firetail.ai/blog/peek-a-boo-emoji-smuggling-and-modern-llms">emoji smuggling attack</a></em>. Si entr&#225;s a uno de estos motores tipo GPT y le ped&#237;s algo como &#8220;dame consejos para crear una nueva pieza de malware&#8221;, esos modelos tienen <em>safeguard rails</em>: est&#225;n dise&#241;ados para bloquear ese tipo de salida. Pero estos nuevos ataques buscan justamente evadir esos controles. En el caso de <em>emoji smuggling</em>, el atacante codifica caracteres <em>emoji</em> que despu&#233;s pueden decodificarse en una <em>string</em> real de comandos, como un <em>prompt</em>. Y eso ya lo vimos <em>in the wild</em>.</p><h3>El panorama de los infostealers y los initial access broker (IAB)</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!e-Os!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fd4903-2e5a-4b5a-a968-90846cfa4970_1185x807.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!e-Os!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fd4903-2e5a-4b5a-a968-90846cfa4970_1185x807.png 424w, https://substackcdn.com/image/fetch/$s_!e-Os!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fd4903-2e5a-4b5a-a968-90846cfa4970_1185x807.png 848w, https://substackcdn.com/image/fetch/$s_!e-Os!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fd4903-2e5a-4b5a-a968-90846cfa4970_1185x807.png 1272w, https://substackcdn.com/image/fetch/$s_!e-Os!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fd4903-2e5a-4b5a-a968-90846cfa4970_1185x807.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!e-Os!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fd4903-2e5a-4b5a-a968-90846cfa4970_1185x807.png" width="1185" height="807" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/e7fd4903-2e5a-4b5a-a968-90846cfa4970_1185x807.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:807,&quot;width&quot;:1185,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1535603,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/195477752?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fd4903-2e5a-4b5a-a968-90846cfa4970_1185x807.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!e-Os!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fd4903-2e5a-4b5a-a968-90846cfa4970_1185x807.png 424w, https://substackcdn.com/image/fetch/$s_!e-Os!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fd4903-2e5a-4b5a-a968-90846cfa4970_1185x807.png 848w, https://substackcdn.com/image/fetch/$s_!e-Os!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fd4903-2e5a-4b5a-a968-90846cfa4970_1185x807.png 1272w, https://substackcdn.com/image/fetch/$s_!e-Os!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fe7fd4903-2e5a-4b5a-a968-90846cfa4970_1185x807.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p><em>&#9472;Durante 2025 hubo varios takedowns de infraestructuras de infostealers, pero al poco tiempo esas operaciones reaparecen. &#191;Es posible erradicarlas o solo se las puede interrumpir temporalmente?</em></p><p>&#9472;Siendo realistas, con el panorama actual el cibercrimen es imposible de erradicar por completo. Igual que el crimen en el mundo real, siempre va a existir. Pensar en una erradicaci&#243;n total no es realista. Lo que s&#237; se puede hacer es priorizar y mitigar buena parte de ese riesgo, pero eso exige nuevos esfuerzos. Porque un <em>takedown</em> de infraestructura por s&#237; solo (bajar servidores o infraestructura asociada a uno de estos <em>infostealers</em>) termina siendo un juego de <em>whack-a-mole</em>. Son esfuerzos valiosos, <strong>pero no alcanzan.</strong></p><p><em>&#9472;&#191;Y qu&#233; se necesita, entonces?</em></p><p>&#9472;Si realmente quer&#233;s golpear operaciones como <em>Lumma Stealer</em> para que no se vuelvan a levantar, hace falta mucha m&#225;s coordinaci&#243;n. Esa es una de las razones por las que fundamos <em><a href="https://www.weforum.org/stories/2023/10/cybercrime-violent-crime/?gad_source=1&amp;gad_campaignid=22228224717&amp;gbraid=0AAAAAoVy5F7d2itn1eKcwuuLdfDJOO0tF&amp;gclid=CjwKCAjwzLHPBhBTEiwABaLsSiPW99Pnoi7kWOcmOhymKdH7al0FWT5oCGM_dupz2vDJqGDWugWm3hoCRuYQAvD_BwE">Cybercrime Atlas</a></em>, donde participan expertos en policy y cripto, fuerzas del orden, y empresas de seguridad, no s&#243;lo Fortinet. <strong>Si s&#243;lo vas contra la infraestructura, no alcanza.</strong> Tambi&#233;n ten&#233;s que ir por los afiliados: arrestarlos, procesarlos, incautar fondos y fortalecer la capacidad de las fuerzas policiales para llevar adelante esos casos. Ya estamos viendo m&#225;s cooperaci&#243;n regional y transnacional, y creo que eso va a permitir una disrupci&#243;n m&#225;s efectiva.</p><p><em>&#9472;La industria habla mucho de colaboraci&#243;n, pero tambi&#233;n compite. &#191;C&#243;mo conviven esas dos l&#243;gicas en el intercambio de inteligencia?</em></p><p>&#9472;Creo que ah&#237; hay una se&#241;al de madurez de la industria. Un buen ejemplo es <em>Cyber Threat Alliance</em>, que Fortinet fund&#243; en 2014 junto con Palo Alto Networks, y a la que despu&#233;s se sumaron otros competidores como <strong>Check Point y Cisco Talos</strong>. La l&#243;gica es simple: ning&#250;na empresa de la industria ni ning&#250;n actor individual va a ser tan efectivo solo como colaborando con otros. Si retenemos informaci&#243;n sobre ataques, les damos todav&#237;a m&#225;s ventaja a los atacantes, y ellos ya la tienen porque no tienen que respetar leyes, pol&#237;ticas ni fronteras. Por eso, hace a&#241;os, empezamos a compartir inteligencia de forma m&#225;s temprana, incluso con programas de advertencias tempranas<em> </em>dentro de la alianza.</p><p><em>&#9472;As&#237; y todo, &#191;no hay informaci&#243;n que retienen?</em></p><p>&#9472;No. Si Unit 42, Cisco Talos o FortiGuard Labs<em> </em>van a publicar investigaci&#243;n sobre un ataque, esa informaci&#243;n se comparte antes para que todos puedan enterarse e implementar controles de seguridad. Eso fortalece las defensas colectivas. La competencia no est&#225; en retener inteligencia, sino en <strong>qu&#233; tan bien cada uno la convierte en acci&#243;n</strong> dentro de sus propias soluciones y qu&#233; tan efectivas son esas soluciones. Ah&#237; sigue estando la diferencia.</p><p><em>&#9472;Durante estos a&#241;os empez&#243; a aparecer mucho m&#225;s la figura del initial access broker. &#191;Qu&#233; peso tiene hoy dentro del ecosistema criminal?</em></p><p>&#9472;Much&#237;simo. Los <em>initial access brokers</em> ya <strong>operan casi como negocios formales</strong>: tienen marketing, hacen publicidad y a veces segmentan su oferta por organizaciones espec&#237;ficas, regiones o industrias, incluyendo datos como la facturaci&#243;n anual de sus blancos. Publican esos accesos, negocian y hasta hacen subastas. Pero, en esencia, lo que venden es acceso inicial a sistemas comprometidos, incluso en entornos de <em>operational technology </em>(OT). En promedio, ese acceso puede valer entre <strong>150.000 y 200.000 d&#243;lares</strong>, que no es tanto si despu&#233;s se usa para extorsiones o rescates multimillonarios.</p><p><em>&#9472;&#191;Y qu&#233; cambi&#243; respecto del modelo anterior? Porque no es nueva la comercializaci&#243;n de accesos.</em></p><p>&#9472;Que antes estos atacantes eran mucho m&#225;s monol&#237;ticos. El cibercrimen organizado hac&#237;a todo: <em>reconnaissance</em>, <em>spear phishing</em>, obtener acceso, entrar a la red y despu&#233;s pedir el ransom. Ahora estamos viendo roles mucho m&#225;s especializados, como el de <em>initial access broker</em>.</p><p><em>&#9472;Y supongo que esto se vio intensificado con la IA.</em></p><p>&#9472;Exacto, de hecho una de nuestras predicciones, que acabamos de publicar, es que vamos a empezar a ver <strong>IAB agents</strong>, agentes para initial access brokers. En vez de que el broker maneje el nivel uno, el marketing, el contacto inicial y las primeras comunicaciones, creo que eso va a empezar a ser reemplazado por agentes. Va a haber un componente de IA weaponizada.</p><p><em>&#9472;Entonces las t&#233;cnicas viejas siguen funcionando, aunque ahora est&#233;n potenciadas por estos modelos automatizados.</em></p><p><strong>&#9472;</strong>S&#237;, siguen funcionando. Y las credenciales, especialmente, siguen siendo un foco enorme para los atacantes. Ese <em>low-hanging fruit</em> sigue siendo un target para el atacante.</p><h3>Ransomware, IA y el problema de la educaci&#243;n para los juniors</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ieu5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b223fd2-8dfa-45ba-ba49-8421b1808fbf_1316x874.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ieu5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b223fd2-8dfa-45ba-ba49-8421b1808fbf_1316x874.png 424w, https://substackcdn.com/image/fetch/$s_!ieu5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b223fd2-8dfa-45ba-ba49-8421b1808fbf_1316x874.png 848w, https://substackcdn.com/image/fetch/$s_!ieu5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b223fd2-8dfa-45ba-ba49-8421b1808fbf_1316x874.png 1272w, https://substackcdn.com/image/fetch/$s_!ieu5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b223fd2-8dfa-45ba-ba49-8421b1808fbf_1316x874.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ieu5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b223fd2-8dfa-45ba-ba49-8421b1808fbf_1316x874.png" width="1316" height="874" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2b223fd2-8dfa-45ba-ba49-8421b1808fbf_1316x874.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1316,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2051821,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/195477752?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b223fd2-8dfa-45ba-ba49-8421b1808fbf_1316x874.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ieu5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b223fd2-8dfa-45ba-ba49-8421b1808fbf_1316x874.png 424w, https://substackcdn.com/image/fetch/$s_!ieu5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b223fd2-8dfa-45ba-ba49-8421b1808fbf_1316x874.png 848w, https://substackcdn.com/image/fetch/$s_!ieu5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b223fd2-8dfa-45ba-ba49-8421b1808fbf_1316x874.png 1272w, https://substackcdn.com/image/fetch/$s_!ieu5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2b223fd2-8dfa-45ba-ba49-8421b1808fbf_1316x874.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Shutterstock</figcaption></figure></div><p><em>&#9472;Hoy cualquiera puede usar un LLM para hacer phishing, deepfakes o reconnaissance. &#191;Hay algo en la experiencia humana que siga siendo dif&#237;cil de reemplazar por IA?</em></p><p>&#9472;Depende mucho de la aplicaci&#243;n. Un especialista entrenado sigue teniendo una ventaja importante: sabe qu&#233; mirar porque lleva tiempo viendo ese tipo de <em>outputs</em>. En tu caso, por ejemplo, probablemente detectes cu&#225;ndo un texto period&#237;stico fue generado por un modelo. Lo mismo puede pasar con un docente frente a un ensayo o un examen. El problema es que eso funciona cuando hay un ojo entrenado. Para un empleado com&#250;n, en cambio, <strong>seguimos teniendo un problema serio de educaci&#243;n</strong> y preparaci&#243;n dentro de la organizaci&#243;n.</p><p><em>&#9472;&#191;Y c&#243;mo supl&#237;s ese gap entre el ojo entrenado y el novato, en un mundo donde la IA entrega todo el contenido ya digerido?</em></p><p>&#9472;En mi experiencia, necesit&#225;s un enfoque hol&#237;stico. La educaci&#243;n sigue siendo clave, y nosotros apostamos mucho a eso: tenemos un programa de concientizaci&#243;n, trabajamos con universidades y hacemos training K-12. Pero la educaci&#243;n no es una bala de plata. Aunque hace a&#241;os hablamos de concientizaci&#243;n, hoy sigue siendo muy dif&#237;cil para un empleado (incluso con cierta formaci&#243;n) <strong>detectar un email de spear phishing bien hecho.</strong></p><p><em>&#9472;&#191;Por qu&#233; ya no alcanza con eso?<br><br></em> &#9472;Porque estos ataques cambiaron mucho. Ya no se trata s&#243;lo de detectar errores de ortograf&#237;a o se&#241;ales obvias. Con la weaponizaci&#243;n de la IA, los atacantes pueden automatizar el <em>reconnaissance</em>, tomar datos de LinkedIn, redes sociales o cualquier fuente p&#250;blica y usar todo eso para darle m&#225;s legitimidad al enga&#241;o. Por eso no alcanza con depender s&#243;lo de la educaci&#243;n: hace falta una defensa por capas. El objetivo sigue siendo el mismo, que el usuario entregue informaci&#243;n o abra un adjunto malicioso, pero hoy necesit&#225;s otra l&#237;nea de defensa, y ah&#237; vuelve a entrar el concepto de las operaciones de seguridad con IA en mente.</p><p><em><strong>&#9472;</strong>En el mundo del ransomware parece haber un giro desde el cifrado de datos hacia el data extortion. &#191;C&#243;mo le&#233;s esto?</em></p><p><strong>&#9472;</strong>En realidad no me gusta mucho la palabra ransomware porque es la palabra que todos usan en la industria, pero ransomware es m&#225;s bien el <em>payload</em>. Y esos <em>payloads</em> no evolucionaron tanto. <strong>Lo que cambi&#243; mucho son las operaciones del ransom. Cambiaron la estrategia y las t&#225;cticas.</strong> Esos son los <em>toolkits</em> que se venden en el modelo de ransomware as a service. Ese modelo usa el payload, pero si ten&#233;s 100 afiliados distintos cobrando comisi&#243;n, cada uno tiene ideas distintas sobre c&#243;mo operar. No es una sola campa&#241;a.</p><p><em>&#9472;&#191;En qu&#233; sentido?</em></p><p>&#9472;Los atacantes ahora usan mucha m&#225;s informaci&#243;n. Cambi&#243; la forma en la que se hace <em>reconnaissance</em>. Si van contra un target espec&#237;fico, se preguntan: si tiro abajo esta l&#237;nea producci&#243;n en una empresa manufacturera, &#191;cu&#225;nto les va a costar? &#191;Qu&#233; da&#241;o les genera? La estrategia es distinta.</p><p><em>&#9472;Se estudia m&#225;s a la v&#237;ctima antes de ejecutar un ataque.</em></p><p>&#9472;Y s&#237;, por eso tambi&#233;n hubo un movimiento desde el <em>data encryption </em>hacia <em>data extortion </em>y <em>double extortion</em>. La amenaza de publicar c&#243;digo o informaci&#243;n sigue existiendo. Pero ahora estamos viendo grupos m&#225;s tipo empresa criminal, m&#225;s dirigidos, m&#225;s espec&#237;ficos. Eligen targets muy puntuales y tienen un <em>playbook </em>mucho m&#225;s grande. Eso es lo que est&#225; cambiando ahora: los targets a los que van y c&#243;mo se relacionan con esos targets, porque saben exactamente qu&#233; est&#225;n buscando.</p><p><em>&#9472;En un reporte de FortiGuard Labs le&#237; que dicen que la pr&#243;xima frontera competitiva en ciberseguridad va a depender de qu&#233; tan bien puedan operar juntos humanos y m&#225;quinas. &#191;Ese es el marco m&#225;s &#250;til para salir de la pregunta simplista de si AI va a reemplazar a las personas?</em></p><p>&#9472;S&#237;. Lo que estamos viendo no es solo una brecha en las habilidades, sino una transformaci&#243;n de roles. M&#225;s que mejorar las habilidades, hay una <strong>especializaci&#243;n de perfiles que ya existen</strong>, como analistas o equipos de IT. El futuro est&#225; en equipos h&#237;bridos entre humanos e IA: no alcanza con humanos solos, pero tampoco con sistemas totalmente aut&#243;nomos. Ese modelo puede achicar la brecha de talento, mejorar los tiempos de respuesta y, si se implementa bien, incluso darle ventaja a la defensa en esta carrera armament&#237;stica por la IA. El problema es que para eso hace falta educaci&#243;n: hay que formar a la gente para esos nuevos roles, y eso todav&#237;a est&#225; en construcci&#243;n.</p><p><em><strong>&#9472;</strong>M&#225;s all&#225; de la ciberseguridad, es cada vez m&#225;s dif&#237;cil distinguir lo real de lo falso en la vida online. &#191;Estamos entrando en una etapa distinta?</em></p><p>&#9472;S&#237;. Y creo que vamos a necesitar m&#225;s herramientas para superar este problema. Con el cl&#225;sico mail del pr&#237;ncipe que te promet&#237;a 10 millones de d&#243;lares no hac&#237;a falta demasiado: era casi autoevidente que era una estafa. Pero con correos o mensajes en redes mucho m&#225;s personalizados, con <em>vishing</em> o con un <em>deepfake </em>en una videollamada, la cosa cambia. Ah&#237; ya no alcanza con el sentido com&#250;n de siempre. Y eso nos lleva a lo que yo llamo el problema del &#8220;instinto de supervivencia&#8221;.</p><p><em>&#9472;&#191;C&#243;mo ser&#237;a esto?</em></p><p>&#9472;Los humanos, despu&#233;s de decenas de miles de a&#241;os de evoluci&#243;n, desarrollamos una especie de instinto de autoprotecci&#243;n en el mundo f&#237;sico. <strong>Si toc&#225;s fuego, te quem&#225;s.</strong> Si camin&#225;s por un callej&#243;n oscuro, se activa una alarma interna y empez&#225;s a mirar qu&#233; puede ser sospechoso. Pero para mucha gente ese mismo reflejo todav&#237;a no existe en el mundo online. Como todo es virtual, no se activa de forma natural. Y ah&#237; est&#225; el problema: <strong>todav&#237;a falta desarrollar un instinto de supervivencia digital.</strong></p><p><em>&#9472;&#191;Y c&#243;mo se puede ejercitar ese instinto en el mundo online?</em></p><p>&#9472;Creo que hay que entrenarlo con el tiempo. Y para eso hacen falta m&#225;s herramientas. No estoy sugiriendo una <strong>sociedad paranoica</strong>, no creo que esa sea la respuesta. Pero s&#237; m&#225;s concientizaci&#243;n: cuestionar m&#225;s cosas, verificar la fuente si recib&#237;s algo sospechoso, y usar un canal secundario si un compa&#241;ero o tu jefe te escribe por Teams con un pedido poco habitual. A fin de cuentas, estamos construyendo hoy <strong>los anticuerpos del futuro.</strong></p><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/derek-manky-fortinet-threat-intel-ransomware-iab-ai?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/derek-manky-fortinet-threat-intel-ransomware-iab-ai?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Cómo hackearon a Vercel: el acceso por un proveedor de IA, la pista de ShinyHunters y la versión de un pago millonario]]></title><description><![CDATA[Adem&#225;s: Anthropic analiza un acceso no autorizado a su modelo Mythos, se declaran culpables miembros de Scattered Spider y BlackCat y Meta captura lo que hacen sus empleados para entrenarar IA.]]></description><link>https://www.brodersendarknews.com/p/vercel-shinyhunters-hackeo-pago-rescate</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/vercel-shinyhunters-hackeo-pago-rescate</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Fri, 24 Apr 2026 11:05:43 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!B0Xu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13832ff6-8f38-484e-a535-1321201c3d95_1200x800.webp" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>17<strong>~24</strong><br>abr</h1><h2><strong>&#9889;TL;DR</strong></h2><p>Esta semana se conoci&#243; un hackeo a <strong>Vercel</strong>, una plataforma cloud de despliegue y hosting muy usada para aplicaciones web (Next.js).  La empresa estuvo en el ojo de la tormenta por un breach que tiene varias aristas para analizar.</p><p>En primer lugar, porque el ataque fue un puro supply chain que empez&#243; en una m&#225;quina de Context[.]ai en la que se hab&#237;an descargado <strong>cheats de Roblox, y Vercel </strong>trabaja con esta plataforma.<strong> </strong>El problema es que, para sorpresa de nadie, esos cheats ven&#237;an con un infostealer. Fue algo as&#237;: </p><div class="pullquote"><p>Script de cheats de Roblox en una m&#225;quina de Context[.]ai / infecci&#243;n con Lumma stealer / robo de sesiones y tokens OAuth / abuso de accesos ya autorizados entre el proveedor y Vercel / entrada a Vercel usando una integraci&#243;n ya confiable / acceso a logs, configuraci&#243;n y variables de entorno / extorsi&#243;n y venta de la informaci&#243;n robada.</p></div><p>El CEO de la compa&#241;&#237;a (dato de color, <a href="https://x.com/rauchg">es argentino</a>) dijo que se trat&#243; de &#8220;un actor excepcionalmente sofisticado acelerado por IA&#8221;. La frase termin&#243; convirti&#233;ndose en el <a href="https://x.com/IceSolst/status/2046669269102948519?s=20">meme de la semana</a>:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!ifsn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9698a01d-4a83-47fd-9022-857e55415dce_1287x751.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ifsn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9698a01d-4a83-47fd-9022-857e55415dce_1287x751.png 424w, https://substackcdn.com/image/fetch/$s_!ifsn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9698a01d-4a83-47fd-9022-857e55415dce_1287x751.png 848w, https://substackcdn.com/image/fetch/$s_!ifsn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9698a01d-4a83-47fd-9022-857e55415dce_1287x751.png 1272w, https://substackcdn.com/image/fetch/$s_!ifsn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9698a01d-4a83-47fd-9022-857e55415dce_1287x751.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ifsn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9698a01d-4a83-47fd-9022-857e55415dce_1287x751.png" width="1287" height="751" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9698a01d-4a83-47fd-9022-857e55415dce_1287x751.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:751,&quot;width&quot;:1287,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1461356,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194792201?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9698a01d-4a83-47fd-9022-857e55415dce_1287x751.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!ifsn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9698a01d-4a83-47fd-9022-857e55415dce_1287x751.png 424w, https://substackcdn.com/image/fetch/$s_!ifsn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9698a01d-4a83-47fd-9022-857e55415dce_1287x751.png 848w, https://substackcdn.com/image/fetch/$s_!ifsn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9698a01d-4a83-47fd-9022-857e55415dce_1287x751.png 1272w, https://substackcdn.com/image/fetch/$s_!ifsn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9698a01d-4a83-47fd-9022-857e55415dce_1287x751.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A partir de la informaci&#243;n que public&#243; Vercel y datos que consegu&#237; con fuentes propias, reconstruyo abajo qu&#233; se sabe del caso, incluso con una versi&#243;n (no confirmada) de un pago de 1.5 millones de d&#243;lares por parte de la compa&#241;&#237;a.</p><p>En el mundo del ransomware, dos ciudadanos (uno americano y otro brit&#225;nico) se declararon culpables de ser parte de los esquemas de los grupos <strong>BlackCat</strong> y <strong>Scattered Spider</strong>.</p><p>Hay tres temas m&#225;s relacionados a <strong>IA</strong> que destaco m&#225;s abajo, uno que tiene que ver con privacidad (Meta va a grabar los movimientos de los empleados para entrenar modelos), otro con todo el ruido de <a href="https://www.brodersendarknews.com/p/anthropic-mythos-preview-modelo-riesgos">Claude Mythos Preview</a>: lograron entrar a &#8220;<a href="https://x.com/JoshKale/status/2046774243799511156">la IA m&#225;s peligrosa del mundo</a>&#8221; haciendo OSINT. Y un tercero a partir de compa&#241;&#237;as que fracasaron y ahora venden sus historiales de chats y mails para entrenar modelos.</p><p>Para cerrar, un nuevo estudio apunta que los chatbots nos est&#225;n haciendo <a href="https://www.bbc.com/future/article/20260417-ai-chatbots-could-be-making-you-stupider">&#8220;m&#225;s est&#250;pidos&#8221;</a>. </p><p><strong>Qui&#233;n lo hubiera pensado.</strong></p><p>Y <a href="https://www.reddit.com/r/nextfuckinglevel/s/1j3AFVVGXK">esta perla absoluta</a> que program&#243; un usuario cansado de las llamadas de spam: una venganza de <strong><a href="https://es.wikipedia.org/wiki/Rickroll">rick-rolleo</a> infinito</strong>.</p><div><hr></div><p><em>En esta edici&#243;n:</em></p><ul><li><p><strong>&#129513;</strong> <em><a href="https://www.brodersendarknews.com/i/194792201/como-hackearon-a-vercel-el-acceso-por-un-proveedor-de-ia-la-pista-de-shinyhunters-y-la-version-de-un-pago-millonario">C&#243;mo hackearon a Vercel: el acceso por un proveedor de IA, la pista de ShinyHunters y la versi&#243;n de un pago millonario</a></em></p></li><li><p><strong>&#128680;</strong> <em><a href="https://www.brodersendarknews.com/i/194792201/anthropic-investiga-un-acceso-no-autorizado-a-mythos">Anthropic investiga un acceso no autorizado a Mythos</a></em></p></li><li><p><strong>&#128451;&#65039;</strong> <em><a href="https://www.brodersendarknews.com/i/194792201/companias-fallidas-estan-vendiendo-sus-chats-mails-e-historiales-internos-a-companias-de-ia">Compa&#241;&#237;as fallidas est&#225;n vendiendo sus chats, mails e historiales internos a compa&#241;&#237;as de IA</a></em></p></li><li><p><strong>&#9878;&#65039;</strong> <em><a href="https://www.brodersendarknews.com/i/194792201/scattered-spider-y-blackcat-ransomware-un-britanico-y-un-americano-se-declaran-culpables">Scattered Spider y BlackCat Ransomware: un brit&#225;nico y un americano se declaran culpables</a></em></p></li><li><p><strong>&#128433;&#65039;</strong> <em><a href="https://www.brodersendarknews.com/i/194792201/meta-captura-movimientos-del-mouse-de-empleados-para-entrenar-ia">Meta captura movimientos del mouse de empleados para entrenar IA</a></em></p></li></ul><p>&#9200; <em>Substack dice que leer este correo completo lleva 13 minutos</em></p><p><em>Dark News #198</em></p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://bloka.red/contacto/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gebg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 424w, https://substackcdn.com/image/fetch/$s_!gebg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 848w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1272w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png" width="1456" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1127539,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://bloka.red/contacto/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194107355?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gebg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 424w, https://substackcdn.com/image/fetch/$s_!gebg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 848w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1272w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></div><h3>C&#243;mo hackearon a Vercel: el acceso por un proveedor de IA, la pista de ShinyHunters y la versi&#243;n de un pago millonario</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!B0Xu!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13832ff6-8f38-484e-a535-1321201c3d95_1200x800.webp" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!B0Xu!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13832ff6-8f38-484e-a535-1321201c3d95_1200x800.webp 424w, https://substackcdn.com/image/fetch/$s_!B0Xu!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13832ff6-8f38-484e-a535-1321201c3d95_1200x800.webp 848w, https://substackcdn.com/image/fetch/$s_!B0Xu!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13832ff6-8f38-484e-a535-1321201c3d95_1200x800.webp 1272w, https://substackcdn.com/image/fetch/$s_!B0Xu!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13832ff6-8f38-484e-a535-1321201c3d95_1200x800.webp 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!B0Xu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13832ff6-8f38-484e-a535-1321201c3d95_1200x800.webp" width="1200" height="800" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/13832ff6-8f38-484e-a535-1321201c3d95_1200x800.webp&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:800,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:27830,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/webp&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194792201?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13832ff6-8f38-484e-a535-1321201c3d95_1200x800.webp&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!B0Xu!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13832ff6-8f38-484e-a535-1321201c3d95_1200x800.webp 424w, https://substackcdn.com/image/fetch/$s_!B0Xu!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13832ff6-8f38-484e-a535-1321201c3d95_1200x800.webp 848w, https://substackcdn.com/image/fetch/$s_!B0Xu!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13832ff6-8f38-484e-a535-1321201c3d95_1200x800.webp 1272w, https://substackcdn.com/image/fetch/$s_!B0Xu!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F13832ff6-8f38-484e-a535-1321201c3d95_1200x800.webp 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Getty Images</figcaption></figure></div><p><strong><a href="https://vercel.com/kb/bulletin/vercel-april-2026-security-incident">Vercel</a></strong><a href="https://vercel.com/kb/bulletin/vercel-april-2026-security-incident"> confirm&#243;</a> un incidente de seguridad que comprometi&#243; parte de sus sistemas internos y expuso variables de entorno de algunos clientes. El vector inicial fue el compromiso de una cuenta de un empleado a trav&#233;s de Context[.]ai, una herramienta externa de inteligencia artificial.</p><p><strong>Qu&#233; pas&#243;.</strong> Seg&#250;n el <a href="https://vercel.com/kb/bulletin/vercel-april-2026-security-incident">comunicado oficial</a>, a partir del acceso a la herramienta de IA el atacante tom&#243; control de la cuenta de Google Workspace de ese empleado y desde ah&#237; logr&#243; entrar a algunos entornos internos de Vercel. Guillermo Rauch, CEO de Vercel, <a href="https://x.com/rauchg/status/2045995362499076169">plante&#243;</a> que el ataque fue &#8220;altamente sofisticado&#8221; y que sospecha que estuvo &#8220;acelerado por IA&#8221;. </p><p><strong>Reporte t&#233;cnico.</strong> <a href="https://www.infostealers.com/article/breaking-vercel-breach-linked-to-infostealer-infection-at-context-ai/">Seg&#250;n HudsonRock</a> fue una <strong>infecci&#243;n con <a href="https://www.brodersendarknews.com/p/hackeos-al-estado-criticas-afc-cert-dnc?open=false#%C2%A7lumma-stealer-operativo-da-de-baja-dominios-pero-sigue-activo">Lumma Stealer</a></strong>, en febrero de 2026, que se meti&#243; por la cuenta de un empleado de Context[.]ai con privilegios sensibles. Seg&#250;n la empresa, la m&#225;quina comprometida mostraba descargas de scripts de exploits (cheats) para Roblox, un vector t&#237;pico de distribuci&#243;n de <strong>infostealers</strong>. </p><p><strong>Dark News</strong> contact&#243; a <a href="https://www.linkedin.com/in/jaimeblasco/">Jaime Blasco</a>, cofundador y CTO de <a href="http://nudgesecurity.com">Nudge Security</a>, plataforma de seguridad para aplicaciones SaaS e IA: </p><blockquote><p><em>Distintos proveedores, la misma historia: los atacantes comprometen a un peque&#241;o proveedor de IA o SaaS, roban los tokens OAuth que ese proveedor custodia en nombre de sus clientes y se cuelan en cientos de empresas posteriores usando las credenciales de la propia plataforma. OAuth es el nuevo movimiento lateral. Hasta que la industria no trate los tokens OAuth como credenciales de alto valor, vamos a seguir leyendo el mismo post-mortem de brecha con los nombres de los proveedores cambiados.</em></p></blockquote><p><strong>El </strong><em><strong>threat actor</strong></em><strong>.</strong> El autor del ataque ser&#237;a un viejo conocido: <strong>ShinyHunters</strong>. Son conocidos por haber breacheado a Ticketmaster, Santander y Rockstar Games (GTA). </p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!4LVE!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2fcb1cd-06de-4292-afbd-13c9546d4fce_1438x870.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!4LVE!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2fcb1cd-06de-4292-afbd-13c9546d4fce_1438x870.png 424w, https://substackcdn.com/image/fetch/$s_!4LVE!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2fcb1cd-06de-4292-afbd-13c9546d4fce_1438x870.png 848w, https://substackcdn.com/image/fetch/$s_!4LVE!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2fcb1cd-06de-4292-afbd-13c9546d4fce_1438x870.png 1272w, https://substackcdn.com/image/fetch/$s_!4LVE!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2fcb1cd-06de-4292-afbd-13c9546d4fce_1438x870.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!4LVE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2fcb1cd-06de-4292-afbd-13c9546d4fce_1438x870.png" width="1438" height="870" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a2fcb1cd-06de-4292-afbd-13c9546d4fce_1438x870.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:870,&quot;width&quot;:1438,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:913789,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194792201?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2fcb1cd-06de-4292-afbd-13c9546d4fce_1438x870.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!4LVE!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2fcb1cd-06de-4292-afbd-13c9546d4fce_1438x870.png 424w, https://substackcdn.com/image/fetch/$s_!4LVE!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2fcb1cd-06de-4292-afbd-13c9546d4fce_1438x870.png 848w, https://substackcdn.com/image/fetch/$s_!4LVE!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2fcb1cd-06de-4292-afbd-13c9546d4fce_1438x870.png 1272w, https://substackcdn.com/image/fetch/$s_!4LVE!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa2fcb1cd-06de-4292-afbd-13c9546d4fce_1438x870.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Los datos de Vercel, a la venta.</figcaption></figure></div><p>Interna. Entender qui&#233;nes son es un poco m&#225;s complejo de lo que parece. Explic&#243; a <strong>Dark News</strong> Mauro Eldritch, especialista en <em>threat intel</em> de <a href="https://www.birminghamcyberarms.co.uk/">BCA LTD</a>:</p><blockquote><p><em>Hoy el ecosistema alrededor de ShinyHunters es dif&#237;cil de seguir por rebrands y movimientos internos. Por un lado, ShinyHunters apareci&#243; como figura central en BreachForums, aunque el nombre muchas veces representaba a un colectivo m&#225;s que a un individuo. Por otro, tambi&#233;n se lo asocia a un grupo de data extortion muy activo, especializado en comprometer proveedores o servicios usados por muchas empresas, para maximizar el impacto: atacan a uno y terminan afectando a muchos. En el caso de Vercel, el grupo original ahora niega responsabilidad y atribuye el hecho a un &#8220;fake ShinyHunters&#8221;, un actor sin v&#237;nculo con su estructura actual. Adem&#225;s, parte de ese ecosistema se mezcl&#243; con alianzas y cruces con otros grupos como <a href="https://www.brodersendarknews.com/p/scattered-lapsus-hunters-fusion-ingenieria-social">Scattered Spider y LAPSUS</a>, lo que vuelve todav&#237;a m&#225;s dif&#237;cil seguir con precisi&#243;n <strong>qui&#233;n es qui&#233;n</strong>.</em></p></blockquote><p>En cuanto a la situaci&#243;n de Vercel, la negociaci&#243;n por la informaci&#243;n robada tuvo sus particularidades. Explica Eldritch:</p><blockquote><p><em>La negociaci&#243;n habr&#237;a arrancado por Session. Desde el inicio fue ca&#243;tica y mal manejada, sobre todo porque el actor filtr&#243; capturas donde se ve&#237;an tanto su usuario como el de la v&#237;ctima, &#8220;VercelCloud&#8221;. Eso abri&#243; la puerta a intentos de terceros de meterse en la conversaci&#243;n y estafar a una u otra parte haci&#233;ndose pasar por intermediarios.</em>  </p></blockquote><p>Incluso, se&#241;ala que hay versiones de un pago: </p><blockquote><p><em>Vercel habr&#237;a sumado un negociador que, en la pr&#225;ctica, plante&#243; que primero le enviaran la data robada y reci&#233;n despu&#233;s la empresa definir&#237;a cu&#225;nto pagar, algo que gener&#243; ruido entre algunos clientes. Horas m&#225;s tarde empez&#243; a circular la versi&#243;n de un pago de US$ 1,5 millones al grupo. Poco despu&#233;s, <strong>todas las publicaciones fueron eliminadas.</strong></em></p></blockquote><p><strong>Update.</strong> Vercel agreg&#243; informaci&#243;n sobre el incidente el mi&#233;rcoles y <a href="https://vercel.com/kb/bulletin/vercel-april-2026-security-incident">revel&#243;</a> un set adicional de clientes que se vieron afectados por el breach.</p><h3>Anthropic investiga un acceso no autorizado a Mythos</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!8KSd!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F643c8ae4-d9c8-47ef-8e1a-920afcaba6f9_1172x876.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!8KSd!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F643c8ae4-d9c8-47ef-8e1a-920afcaba6f9_1172x876.png 424w, https://substackcdn.com/image/fetch/$s_!8KSd!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F643c8ae4-d9c8-47ef-8e1a-920afcaba6f9_1172x876.png 848w, https://substackcdn.com/image/fetch/$s_!8KSd!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F643c8ae4-d9c8-47ef-8e1a-920afcaba6f9_1172x876.png 1272w, https://substackcdn.com/image/fetch/$s_!8KSd!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F643c8ae4-d9c8-47ef-8e1a-920afcaba6f9_1172x876.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!8KSd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F643c8ae4-d9c8-47ef-8e1a-920afcaba6f9_1172x876.png" width="1172" height="876" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/643c8ae4-d9c8-47ef-8e1a-920afcaba6f9_1172x876.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:876,&quot;width&quot;:1172,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1310316,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194792201?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F643c8ae4-d9c8-47ef-8e1a-920afcaba6f9_1172x876.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!8KSd!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F643c8ae4-d9c8-47ef-8e1a-920afcaba6f9_1172x876.png 424w, https://substackcdn.com/image/fetch/$s_!8KSd!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F643c8ae4-d9c8-47ef-8e1a-920afcaba6f9_1172x876.png 848w, https://substackcdn.com/image/fetch/$s_!8KSd!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F643c8ae4-d9c8-47ef-8e1a-920afcaba6f9_1172x876.png 1272w, https://substackcdn.com/image/fetch/$s_!8KSd!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F643c8ae4-d9c8-47ef-8e1a-920afcaba6f9_1172x876.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Dar&#237;o Amodei, CEO de Anthropic. Foto: Reuters</figcaption></figure></div><p>Anthropic investiga un presunto <a href="https://www.theguardian.com/technology/2026/apr/22/anthropic-investigates-report-of-rogue-access-to-hack-enabling-mythos-ai">acceso no autorizado a Mythos</a>, su modelo de IA orientado a ciberseguridad que todav&#237;a no fue lanzado al p&#250;blico por los riesgos que implica.</p><p><strong>Qu&#233; pas&#243;.</strong> Anthropic confirm&#243; que est&#225; investigando un reporte que habla de un compromiso a trav&#233;s de uno de sus proveedores externos. La informaci&#243;n surgi&#243; despu&#233;s de un reporte de <a href="https://www.bloomberg.com/news/articles/2026-04-21/anthropic-s-mythos-model-is-being-accessed-by-unauthorized-users">Bloomberg</a>, que habl&#243; de un peque&#241;o grupo de usuarios que habr&#237;a accedido al modelo el mismo d&#237;a en que la empresa anunci&#243; pruebas limitadas con compa&#241;&#237;as como Apple y Goldman Sachs.</p><p><strong>C&#243;mo habr&#237;a ocurrido.</strong> Seg&#250;n ese reporte, el acceso se habr&#237;a logrado a partir de las credenciales o permisos de un trabajador de un contratista externo de Anthropic, combinados con m&#233;todos usados por investigadores de ciberseguridad. La empresa, por ahora, no confirm&#243; m&#225;s detalles t&#233;cnicos.</p><p><strong>Por qu&#233; importa.</strong> Mythos no est&#225; disponible de forma abierta justamente por su &#8220;potencial para facilitar ciberataques&#8221; en los principales sistemas operativos y programas. </p><p>Anthropic ya hab&#237;a advertido que el modelo plantea riesgos en materia de ciberseguridad, y una filtraci&#243;n o acceso indebido, incluso acotado, abre preguntas sobre los controles alrededor de herramientas de este tipo.</p><h3>Compa&#241;&#237;as fallidas est&#225;n vendiendo sus chats, mails e historiales internos a compa&#241;&#237;as de IA</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!0BQw!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbcbebe1-05d2-4211-a00a-ca4daee804ea_761x470.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!0BQw!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbcbebe1-05d2-4211-a00a-ca4daee804ea_761x470.png 424w, https://substackcdn.com/image/fetch/$s_!0BQw!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbcbebe1-05d2-4211-a00a-ca4daee804ea_761x470.png 848w, https://substackcdn.com/image/fetch/$s_!0BQw!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbcbebe1-05d2-4211-a00a-ca4daee804ea_761x470.png 1272w, https://substackcdn.com/image/fetch/$s_!0BQw!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbcbebe1-05d2-4211-a00a-ca4daee804ea_761x470.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!0BQw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbcbebe1-05d2-4211-a00a-ca4daee804ea_761x470.png" width="761" height="470" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fbcbebe1-05d2-4211-a00a-ca4daee804ea_761x470.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:470,&quot;width&quot;:761,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:366971,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194792201?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbcbebe1-05d2-4211-a00a-ca4daee804ea_761x470.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!0BQw!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbcbebe1-05d2-4211-a00a-ca4daee804ea_761x470.png 424w, https://substackcdn.com/image/fetch/$s_!0BQw!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbcbebe1-05d2-4211-a00a-ca4daee804ea_761x470.png 848w, https://substackcdn.com/image/fetch/$s_!0BQw!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbcbebe1-05d2-4211-a00a-ca4daee804ea_761x470.png 1272w, https://substackcdn.com/image/fetch/$s_!0BQw!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffbcbebe1-05d2-4211-a00a-ca4daee804ea_761x470.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Los mails, un activo para la IA. Foto: Microsoft</figcaption></figure></div><p>Empresas quebradas est&#225;n empezando a vender sus archivos internos a laboratorios de IA para entrenar modelos: a&#241;os de Slack, mails y tickets internos.</p><p><strong>Qu&#233; pas&#243;.</strong> <a href="https://www.fastcompany.com/91528808/shuttered-startups-are-selling-old-slack-chats-and-emails-to-ai-companies">Forbes revel&#243;</a> que compa&#241;&#237;as cerradas est&#225;n monetizando su &#8220;huella digital&#8221; corporativa como dataset para IA. Shanna Johnson, CEO de la extinta Cielo24, cont&#243; que vendi&#243; todos los mensajes de Slack, correos internos y tickets de Jira por &#8220;cientos de miles de d&#243;lares&#8221;. </p><p><strong>El negocio.</strong> SimpleClosure, compa&#241;&#237;a que se dedica a cerrar empresas, dijo que proces&#243; 100 acuerdos de este tipo en el &#250;ltimo a&#241;o. Los pagos fueron desde US$ 10.000 hasta US$ 100.000.</p><p>El inter&#233;s crece porque los modelos m&#225;s avanzados, sobre todo los agentes de IA, necesitan datasets m&#225;s complejos que el contenido p&#250;blico de internet: flujos de trabajo reales, cadenas de mails, documentaci&#243;n interna, soporte, coordinaci&#243;n entre equipos y resoluci&#243;n de problemas cotidianos.</p><p><strong>Por qu&#233; importa.</strong> Esto abre un nuevo mercado de &#8220;residuos corporativos&#8221; para la econom&#237;a de entrenamiento de IA. Seg&#250;n Forbes, empresas como AfterQuery incluso construyen &#8220;mundos de oficina&#8221; digitales para entrenar agentes capaces de moverse dentro de entornos laborales reales.</p><p><strong>La alarma.</strong> Aunque los datos se anonimicen, el riesgo de privacidad es alto. En esos archivos puede haber informaci&#243;n sensible, datos identificables de empleados, historial laboral, conflictos internos o decisiones de negocio.</p><h3>Scattered Spider y BlackCat Ransomware: un brit&#225;nico y un americano se declaran culpables</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!98Iq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e5cb0f-d4d5-4c3a-abe2-4e1be1bbcc68_4500x3003.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!98Iq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e5cb0f-d4d5-4c3a-abe2-4e1be1bbcc68_4500x3003.jpeg 424w, https://substackcdn.com/image/fetch/$s_!98Iq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e5cb0f-d4d5-4c3a-abe2-4e1be1bbcc68_4500x3003.jpeg 848w, https://substackcdn.com/image/fetch/$s_!98Iq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e5cb0f-d4d5-4c3a-abe2-4e1be1bbcc68_4500x3003.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!98Iq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e5cb0f-d4d5-4c3a-abe2-4e1be1bbcc68_4500x3003.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!98Iq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e5cb0f-d4d5-4c3a-abe2-4e1be1bbcc68_4500x3003.jpeg" width="1456" height="972" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/75e5cb0f-d4d5-4c3a-abe2-4e1be1bbcc68_4500x3003.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:972,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1165358,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194792201?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e5cb0f-d4d5-4c3a-abe2-4e1be1bbcc68_4500x3003.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!98Iq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e5cb0f-d4d5-4c3a-abe2-4e1be1bbcc68_4500x3003.jpeg 424w, https://substackcdn.com/image/fetch/$s_!98Iq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e5cb0f-d4d5-4c3a-abe2-4e1be1bbcc68_4500x3003.jpeg 848w, https://substackcdn.com/image/fetch/$s_!98Iq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e5cb0f-d4d5-4c3a-abe2-4e1be1bbcc68_4500x3003.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!98Iq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F75e5cb0f-d4d5-4c3a-abe2-4e1be1bbcc68_4500x3003.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Especialistas en sim swapping y phishing. Foto: Shutterstock</figcaption></figure></div><p>Un <a href="https://www.justice.gov/usao-cdca/pr/british-national-pleads-guilty-hacking-companies-and-stealing-least-8-million-virtual">brit&#225;nico ligado a </a><strong><a href="https://www.justice.gov/usao-cdca/pr/british-national-pleads-guilty-hacking-companies-and-stealing-least-8-million-virtual">Scattered Spider</a></strong> y un negociador de incidentes <a href="https://www.securityweek.com/third-us-security-expert-admits-helping-ransomware-gang/">vinculado a </a><strong><a href="https://www.securityweek.com/third-us-security-expert-admits-helping-ransomware-gang/">BlackCat/ALPHV</a></strong> se declararon culpables en EE.UU. por dos casos distintos, pero conectados por un mismo patr&#243;n: atacantes que explotan el costado m&#225;s d&#233;bil de la cadena, desde empleados enga&#241;ados por SMS hasta especialistas en ciberseguridad que terminan colaborando con los extorsionadores.</p><p><strong>Qu&#233; pas&#243;.</strong> Tyler Robert Buchanan, de 24 a&#241;os y de Escocia, admiti&#243; haber participado entre 2021 y 2023 en una campa&#241;a de intrusiones a al menos una docena de empresas mediante <strong>SMS phishing</strong>. Seg&#250;n su acuerdo judicial, el grupo enviaba cientos de mensajes a empleados, robaba credenciales en sitios falsos y despu&#233;s usaba ese acceso para entrar a sistemas corporativos, robar datos y vaciar billeteras cripto. El perjuicio reconocido es de al menos <strong>US$ 8 millones</strong>.</p><p><strong>El contexto.</strong> Buchanan fue se&#241;alado en la &#243;rbita de <strong>Scattered Spider</strong>, el grupo conocido por combinar ingenier&#237;a social, robo de credenciales, SIM swapping y ataques a grandes compa&#241;&#237;as de tecnolog&#237;a, telecomunicaciones y entretenimiento.</p><p><strong>En paralelo.</strong> Angelo Martino, un estadounidense de 41 a&#241;os, se convirti&#243; en el <strong>tercer especialista en ciberseguridad</strong> en declararse culpable por colaborar con <strong>BlackCat/ALPHV</strong> mientras trabajaba negociando pagos de ransomware para v&#237;ctimas. </p><p>Seg&#250;n el Departamento de Justicia, us&#243; su rol para pasarle a la banda informaci&#243;n confidencial que ayudaba a maximizar los rescates. Ya hab&#237;an admitido su culpa Kevin Martin y Ryan Goldberg. Martino enfrenta hasta <strong>20 a&#241;os de prisi&#243;n</strong> y le secuestraron bienes por <strong>US$ 10 millones</strong>.</p><h3>Meta captura movimientos del mouse de empleados para entrenar IA</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!hJw-!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a7376c-0856-4225-8122-8b172b3badab_1511x870.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!hJw-!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a7376c-0856-4225-8122-8b172b3badab_1511x870.png 424w, https://substackcdn.com/image/fetch/$s_!hJw-!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a7376c-0856-4225-8122-8b172b3badab_1511x870.png 848w, https://substackcdn.com/image/fetch/$s_!hJw-!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a7376c-0856-4225-8122-8b172b3badab_1511x870.png 1272w, https://substackcdn.com/image/fetch/$s_!hJw-!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a7376c-0856-4225-8122-8b172b3badab_1511x870.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!hJw-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a7376c-0856-4225-8122-8b172b3badab_1511x870.png" width="1456" height="838" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f5a7376c-0856-4225-8122-8b172b3badab_1511x870.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:838,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1323708,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194792201?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a7376c-0856-4225-8122-8b172b3badab_1511x870.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!hJw-!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a7376c-0856-4225-8122-8b172b3badab_1511x870.png 424w, https://substackcdn.com/image/fetch/$s_!hJw-!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a7376c-0856-4225-8122-8b172b3badab_1511x870.png 848w, https://substackcdn.com/image/fetch/$s_!hJw-!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a7376c-0856-4225-8122-8b172b3badab_1511x870.png 1272w, https://substackcdn.com/image/fetch/$s_!hJw-!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff5a7376c-0856-4225-8122-8b172b3badab_1511x870.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Reuters</figcaption></figure></div><p>Meta va a empezar a <a href="https://www.reuters.com/sustainability/boards-policy-regulation/meta-start-capturing-employee-mouse-movements-keystrokes-ai-training-data-2026-04-21/">registrar movimientos de mouse, clics, teclas</a> y capturas parciales de pantalla de empleados en EE.UU. para entrenar sus modelos de IA. La empresa dice que no se usar&#225; para evaluar desempe&#241;o, aunque en la empresa se ley&#243; como vigilancia laboral en tiempo real para reemplazar parte del propio trabajo humano.</p><p><strong>Qu&#233; pas&#243;.</strong> Seg&#250;n Reuters, Meta est&#225; instalando una herramienta interna llamada <strong>Model Capability Initiative (MCI)</strong> en computadoras de empleados en Estados Unidos. El software va a monitorear interacciones en apps y sitios de trabajo, incluyendo movimientos del mouse, clics, atajos de teclado y capturas ocasionales de pantalla. El objetivo es usar esos datos para entrenar agentes de IA que aprendan c&#243;mo los humanos usan una computadora en tareas cotidianas.</p><p><strong>Qu&#233; busca Meta</strong>. La empresa quiere que sus modelos mejoren en algo que todav&#237;a les cuesta: navegar interfaces reales, elegir opciones en men&#250;s, usar shortcuts y completar flujos de trabajo como lo har&#237;a un empleado. En un memo interno, el CTO Andrew Bosworth plante&#243; la visi&#243;n de una compa&#241;&#237;a donde &#8220;los agentes hagan principalmente el trabajo&#8221; y los humanos se limiten a dirigir, revisar y corregir.</p><p><strong>El contexto.</strong> La medida forma parte de una reestructuraci&#243;n m&#225;s amplia. Meta viene empujando fuerte el uso interno de IA para programaci&#243;n y otras tareas, cre&#243; equipos espec&#237;ficos para desarrollar agentes que construyan y prueben productos, y planea recortar <strong>10% de su plantilla global</strong> desde mayo. </p><p>Tambi&#233;n est&#225; borrando diferencias entre roles bajo una nueva etiqueta interna: <strong>&#8220;AI builder&#8221;</strong>.</p><div><hr></div><h4><strong>&#128275; Breaches y hacks</strong></h4><ul><li><p>Roban 292 millones de d&#243;lares de la plataforma cripto <a href="https://www.theblock.co/post/397988/kelp-daos-rseth-bridge-apparently-exploited-for-roughly-292-million-in-layerzero-based-attack">Kelp DAO</a></p></li><li><p>Defacean el sitio de <a href="https://www.reddit.com/r/InfoSecNews/comments/1sri8hm/seiko_usa_website_defaced_as_hacker_claims/">Seiko</a> y aseguran que tienen datos de clientes</p></li><li><p>Una agencia de gobierno francesa <a href="https://www.bleepingcomputer.com/news/security/french-govt-agency-confirms-breach-as-hacker-offers-to-sell-data/">sufre un hackeo</a></p></li></ul><h4><strong>&#128274; Ransomware</strong></h4><ul><li><p>M&#225;s de 200 empresas de <a href="https://mainichi.jp/english/articles/20260420/p2g/00m/0na/009000c">Jap&#243;n</a> pagaron rescates</p></li><li><p>Publican una entrevista con <a href="https://www.suspectfile.com/dragonforce-interview-human-factor-is-the-key-to-every-attack/">DragonForce Ransomware</a></p></li><li><p>Detectan dos nuevas variantes de la cepa Kyber que usa <a href="https://www.bleepingcomputer.com/news/security/kyber-ransomware-gang-toys-with-post-quantum-encryption-on-windows/">cifrado post cu&#225;ntico</a></p></li></ul><h4><strong>&#128163; Exploits y malware</strong></h4><ul><li><p>Una falla en servidores <a href="https://www.bleepingcomputer.com/news/security/actively-exploited-apache-activemq-flaw-impacts-6-400-servers/">Apache ActiveMQ</a> impacta 6.400 servidores</p></li><li><p><a href="https://layerxsecurity.com/blog/stealtok-130k-users-compromised-by-data-stealing-tiktok-video-downloaders/">StealTok</a>: m&#225;s de 130 mil usuarios infectados con una extensi&#243;n para bajar videos de TikTok</p></li><li><p>Detectan un <a href="https://securelist.com/tr/lotus-wiper/119472/">nuevo wiper</a> que opera en OT, en Venezuela</p></li></ul><h4><strong>&#128269; Threat intel y vulnerabilidades</strong></h4><ul><li><p>Reportes:  <a href="https://blog.talosintelligence.com/the-q1-vulnerability-pulse/">Cisco Talos</a>, <a href="https://blog.barracuda.com/2026/04/16/threat-spotlight-tycoon-2fa-scattered-everywhere">Barracuda</a>, <a href="https://www.chromium.org/Home/chromium-security/quarterly-updates/">The Chromium Projects</a>, <a href="https://www.blackberry.com/en/secure-communications/insights/blog/state-secure-communications-2026">BlackBerry</a>, <a href="https://www.businesswire.com/news/home/20260421514860/en/One-in-Five-Experienced-an-LLM-Security-Incident-in-the-Last-Year-With-32-of-AI-Vulnerabilities-Rated-High-Risk">Cobalt</a>, <a href="https://nordvpn.com/research-lab/dark-web-market/">NordVPN</a>    </p></li><li><p><a href="https://research.checkpoint.com/2026/dfir-report-the-gentlemen/">Check Point</a>: The Gentlemen ya hacke&#243; 240 organizaciones</p></li></ul><h4><strong>&#128736;&#65039; Tools y updates</strong></h4><ul><li><p>Microsoft cambia el <a href="https://www.wheresyoured.at/news-microsoft-to-shift-github-copilot-users-to-token-based-billing-reduce-rate-limits-2/">Copilot de GitHub</a> a un modelo de consumo de tokens</p></li><li><p>Apple arregla el bug que permit&#237;a <a href="https://www.bleepingcomputer.com/news/security/apple-fixes-ios-bug-that-retained-deleted-notification-data/">recuperar mensajes</a> desde las notificaciones de Signal en iOS</p></li></ul><h4><strong>&#128203; Privacidad y regulaciones</strong></h4><ul><li><p>ICE (EE.UU.) reconoce que usa <a href="https://www.npr.org/2026/04/07/nx-s1-5776799/ice-spyware-privacy">spyware</a></p></li><li><p>Esp&#237;as rusos comprometen <a href="https://www.spiegel.de/politik/deutschland/phishing-alarm-in-berliner-regierungsviertel-julia-kloeckner-opfer-des-signal-hacks-a-7f5fc795-d0c2-4325-b726-4109531270bc">la cuenta de signal de Julia Kl&#246;ckner</a>, presidenta del Bundestag</p></li><li><p><a href="https://www.esafety.gov.au/newsroom/media-releases/esafety-asks-gaming-giants-what-they-are-doing-to-prevent-grooming-and-radicalisation">Australia investiga</a> compa&#241;&#237;as de gaming por casos de grooming y radicalizaci&#243;n</p><p></p></li></ul><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial generativa para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/vercel-shinyhunters-hackeo-pago-rescate?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/vercel-shinyhunters-hackeo-pago-rescate?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Grandes medios bloquean a Wayback Machine y ponen en riesgo el archivo público de internet]]></title><description><![CDATA[Adem&#225;s: hackearon otra vez a Rockstar Games, Booking confirma una filtraci&#243;n de datos y Claude Mythos Preview tuvo un 73% de &#233;xito en CTFs.]]></description><link>https://www.brodersendarknews.com/p/internet-archive-wayback-machine-medios-bloqueo</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/internet-archive-wayback-machine-medios-bloqueo</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Fri, 17 Apr 2026 11:07:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!nifi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23379c38-b20d-4cf2-9ee2-1eeb4733829a_1329x878.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>10<strong>~17</strong><br>abr</h1><h2><strong>&#9889;TL;DR</strong></h2><p><strong>Internet</strong> se almacena, m&#225;s all&#225; de los servidores originales de cada sitio, en un repositorio online que hasta el momento ha operado como el archivo de internet: <strong><a href="https://web.archive.org/">Wayback Machine</a>, del Internet Archive</strong>. Se trata de una biblioteca digital sin fines de lucro, fundada en 1996, que <em>scrapea </em>con bots el contenido de p&#225;ginas web y descarga lo que se ve p&#250;blicamente, para guardar una &#8220;foto&#8221; del contenido en un momento determinado. </p><p><strong>Y ahora est&#225; en peligro.</strong></p><p>Esta semana se supo que <strong>al menos 23 medios</strong> de comunicaci&#243;n importantes a nivel global le <a href="https://www.tomshardware.com/tech-industry/big-tech/news-outlets-are-blocking-wayback-machine-from-archiving-their-pages-23-outlets-concerned-ai-companies-might-abuse-fair-use-and-use-it-to-train-their-models">bloquearon</a> el acceso al contenido. Y, otra vez, <strong>la responsable es la IA: </strong>la industria medi&#225;tica est&#225; en guerra con compa&#241;&#237;as como Google, OpenAI y Anthropic porque usan su informaci&#243;n sin retribuirlas econ&#243;micamente.</p><p>El concepto central es el de <em>fair use: </em>&#191;cu&#225;nto de lo que hacen es uso leg&#237;timo y cu&#225;nto violaci&#243;n de <em>copyright</em>? El tema engloba un problema m&#225;s legal-pol&#237;tico que tecnol&#243;gico. Y representa un problema grave para <a href="https://www.niemanlab.org/2026/01/news-publishers-limit-internet-archive-access-due-to-ai-scraping-concerns/">el periodismo</a>, que en EE.UU. ya tiene referentes que est&#225;n advirtiendo sobre el problema que esto puede generar: <strong>&#8220;En la era de la desinformaci&#243;n y las alucinaciones de la IA, el archivo de internet es m&#225;s cr&#237;tico que nunca&#8221;.</strong></p><p>Adem&#225;s, sali&#243; un estudio independiente sobre Claude Mythos Preview, el <a href="https://www.brodersendarknews.com/p/anthropic-mythos-preview-modelo-riesgos">tema central de la semana pasada</a>, que dice que tuvo un 73% de &#233;xito en desaf&#237;os CTF. Anthropic <a href="https://www.cnbc.com/2026/04/16/anthropic-claude-opus-4-7-model-mythos.html">lanz&#243; una actualizaci&#243;</a>n de su modelo esta semana y tuvo que aclarar que no era peligroso, por el revuelo que caus&#243; d&#237;as atr&#225;s.</p><p>Entre otros temas relevantes, (otra vez) hackearon a Rockstar (creadores de GTA), Booking sufri&#243; una filtraci&#243;n de datos grande y una nueva investigaci&#243;n revel&#243; c&#243;mo sigue activo un <strong>mercado negro</strong> de 21 mil millones de d&#243;lares en Telegram. Adem&#225;s, una nueva medida de Google va a penalizar a los sitios que hacen hijacking del bot&#243;n &#8220;atr&#225;s&#8221; del navegador.</p><p>Dejo como recomendaci&#243;n de lectura esta nota <a href="https://www.wired.com/story/ai-slop-is-changing-the-internet-just-not-how-you-might-think/?utm_campaign=etb&amp;utm_medium=newsletter&amp;utm_source=morning_brew">de Wired</a> que dice que internet se transform&#243; en un lugar <strong>&#8220;fake-happy&#8221;</strong> a partir del impacto de los sitios generados con IA.</p><p>En el mundo del open source, sali&#243; la versi&#243;n <strong>7.0</strong> del <a href="https://lore.kernel.org/lkml/CAHk-=wj2WqpPBwpAXo8bj_Hx-NxKMRVTVMUaQis7+Vm6XLRZiw@mail.gmail.com/T/">kernel de Linux</a>.</p><div><hr></div><p><em>En esta edici&#243;n:</em></p><ul><li><p><strong>&#128368;&#65039;</strong> <em><a href="https://www.brodersendarknews.com/i/194107355/grandes-medios-bloquean-a-wayback-machine-y-ponen-en-riesgo-el-archivo-publico-de-internet">Grandes medios bloquean a Wayback Machine y ponen en riesgo el archivo p&#250;blico de internet</a></em></p></li><li><p><strong>&#127919;</strong> <em><a href="https://www.brodersendarknews.com/i/194107355/claude-mythos-preview-tuvo-un-73-de-exito-en-desafios-ctf">Claude Mythos Preview tuvo un 73% de &#233;xito en desaf&#237;os CTF</a></em></p></li><li><p><strong>&#8617;&#65039;</strong> <em><a href="https://www.brodersendarknews.com/i/194107355/la-trampa-del-boton-de-atras-en-google-search-penalizan-los-sitios-que-secuestran-la-funcion">La trampa del bot&#243;n de &#8220;atr&#225;s&#8221; en Google Search: penalizan los sitios que secuestran la funci&#243;n</a></em></p></li><li><p><strong>&#127918;</strong> <em><a href="https://www.brodersendarknews.com/i/194107355/rockstar-games-creadores-de-gta-hackeado-otra-vez">Rockstar Games, creadores de GTA, hackeado (otra vez)</a></em></p></li><li><p><strong>&#129523;</strong> <em><a href="https://www.brodersendarknews.com/i/194107355/booking-sufre-una-filtracion-de-datos">Booking sufre una filtraci&#243;n de datos</a></em></p></li><li><p><strong>&#128184;</strong> <em><a href="https://www.brodersendarknews.com/i/194107355/nueva-investigacion-revela-que-telegram-aloja-un-mercado-negro-cripto-de-21-mil-millones">Nueva investigaci&#243;n revela que Telegram aloja un mercado negro cripto de 21 mil millones</a></em></p></li></ul><p>&#9200; <em>Substack dice que leer este correo completo lleva 13 minutos</em></p><p><em>Dark News #197</em></p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://bloka.red/contacto/" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gebg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 424w, https://substackcdn.com/image/fetch/$s_!gebg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 848w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1272w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png" width="1456" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1127539,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://bloka.red/contacto/&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194107355?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gebg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 424w, https://substackcdn.com/image/fetch/$s_!gebg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 848w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1272w, https://substackcdn.com/image/fetch/$s_!gebg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc738194f-2199-4a44-a9c1-77f08fa6d844_2500x1250.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></div><h3>Grandes medios bloquean a Wayback Machine y ponen en riesgo el archivo p&#250;blico de internet</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nifi!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23379c38-b20d-4cf2-9ee2-1eeb4733829a_1329x878.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nifi!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23379c38-b20d-4cf2-9ee2-1eeb4733829a_1329x878.png 424w, https://substackcdn.com/image/fetch/$s_!nifi!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23379c38-b20d-4cf2-9ee2-1eeb4733829a_1329x878.png 848w, https://substackcdn.com/image/fetch/$s_!nifi!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23379c38-b20d-4cf2-9ee2-1eeb4733829a_1329x878.png 1272w, https://substackcdn.com/image/fetch/$s_!nifi!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23379c38-b20d-4cf2-9ee2-1eeb4733829a_1329x878.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nifi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23379c38-b20d-4cf2-9ee2-1eeb4733829a_1329x878.png" width="1329" height="878" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/23379c38-b20d-4cf2-9ee2-1eeb4733829a_1329x878.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:878,&quot;width&quot;:1329,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1410572,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194107355?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23379c38-b20d-4cf2-9ee2-1eeb4733829a_1329x878.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nifi!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23379c38-b20d-4cf2-9ee2-1eeb4733829a_1329x878.png 424w, https://substackcdn.com/image/fetch/$s_!nifi!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23379c38-b20d-4cf2-9ee2-1eeb4733829a_1329x878.png 848w, https://substackcdn.com/image/fetch/$s_!nifi!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23379c38-b20d-4cf2-9ee2-1eeb4733829a_1329x878.png 1272w, https://substackcdn.com/image/fetch/$s_!nifi!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23379c38-b20d-4cf2-9ee2-1eeb4733829a_1329x878.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Shutterstock</figcaption></figure></div><p><strong>Wayback Machine</strong>, herramienta para archivar sitios web, est&#225; perdiendo acceso a parte del archivo period&#237;stico online. Al menos <strong>23 grandes medios de comunicaci&#243;n</strong> <a href="https://www.tomshardware.com/tech-industry/big-tech/news-outlets-are-blocking-wayback-machine-from-archiving-their-pages-23-outlets-concerned-ai-companies-might-abuse-fair-use-and-use-it-to-train-their-models">ya bloquean su </a><em><a href="https://www.tomshardware.com/tech-industry/big-tech/news-outlets-are-blocking-wayback-machine-from-archiving-their-pages-23-outlets-concerned-ai-companies-might-abuse-fair-use-and-use-it-to-train-their-models">crawler</a></em>, en lo que es una disputa entre preservaci&#243;n p&#250;blica y el riesgo de que ese material alimente modelos de IA. </p><p><strong>Qu&#233; pas&#243;.</strong> La noticia la hab&#237;a dado <a href="https://www.niemanlab.org/2026/01/news-publishers-limit-internet-archive-access-due-to-ai-scraping-concerns/">Nieman Lab</a> en enero y, desde entonces, seg&#250;n un an&#225;lisis citado por <a href="https://www.wired.com/story/the-internets-most-powerful-archiving-tool-is-in-mortal-peril/">Wired</a> y <a href="https://www.techradar.com/computing/internet/ai-could-mean-the-end-of-the-wayback-machine-as-news-websites-are-increasingly-blocking-it-to-prevent-content-scraping">Originality AI</a>, 23 grandes medios <strong>bloquean a </strong><code>ia_archiverbot</code>, el crawler que usa Internet Archive para alimentar Wayback Machine. </p><p>Entre ellos aparecen <strong>The New York Times y USA Today Co.</strong>, que adem&#225;s controla m&#225;s de 200 medios. <strong><a href="https://arstechnica.com/tech-policy/2025/08/reddit-blocks-internet-archive-to-end-sneaky-ai-scraping/">Reddit</a></strong><a href="https://arstechnica.com/tech-policy/2025/08/reddit-blocks-internet-archive-to-end-sneaky-ai-scraping/"> tambi&#233;n</a> cerr&#243; el acceso. En otros casos, como <a href="https://www.niemanlab.org/2026/01/news-publishers-limit-internet-archive-access-due-to-ai-scraping-concerns/">The Guardian</a>, la restricci&#243;n es m&#225;s sutil: no bloquea el rastreo, pero limita la visibilidad p&#250;blica del contenido archivado.</p><p><strong>Antecedentes.</strong> En 2025, <a href="https://www.theverge.com/news/757538/reddit-internet-archive-wayback-machine-block-limit?utm_source=chatgpt.com">Reddit ya hab&#237;a restringido</a> el acceso a Wayback Machine y dej&#243; que archive casi solo su homepage, con el argumento de que empresas de IA estaban usando el archivo para esquivar sus l&#237;mites de scraping y licencias. En paralelo, <a href="https://techcrunch.com/2026/02/21/wikipedia-blacklists-archive-today-after-alleged-ddos-attack/">Wikipedia</a> bloque&#243; a <em>Archive[.]today</em>, un sitio de caracter&#237;sticas similares.</p><p><strong>Por qu&#233; importa.</strong> Wayback Machine es el gran archivo p&#250;blico de la web. Sirve para rastrear cambios en art&#237;culos, verificar posteos borrados, chequear ediciones silenciosas y reconstruir contextos que ya no est&#225;n online. </p><p>Si ese acceso se reduce, parte de la memoria digital queda bajo control de las propias plataformas o medios que publicaron el contenido.</p><p><strong>Tensi&#243;n</strong>. Los medios justifican los bloqueos con dos argumentos: frenar scraping generalizado y evitar que su contenido archivado termine usado para entrenar sistemas de IA que luego compiten con ellos. The New York Times sostiene que ese uso puede violar el copyright. USA Today dice que no busca bloquear espec&#237;ficamente a Internet Archive, sino aplicar una pol&#237;tica m&#225;s amplia contra bots.</p><p>Mark Graham, director de Wayback Machine, <a href="https://www.techdirt.com/2026/02/17/preserving-the-web-is-not-the-problem-losing-it-is/">resumi&#243;</a> en febrero de este a&#241;o: </p><blockquote><p><em>Estas preocupaciones son comprensibles, pero infundadas. Wayback Machine no est&#225; pensada para ser un backdoor para el scraping comercial a gran escala y, como otros actores de la web hoy, dedicamos una cantidad significativa de tiempo y esfuerzo a prevenir ese tipo de abusos. M&#225;s all&#225; de las preocupaciones leg&#237;timas que pueda haber sobre la IA generativa, las bibliotecas no son el problema y bloquear el acceso a los archivos web no es la soluci&#243;n, hacerlo pone en riesgo de da&#241;ar seriamente el registro p&#250;blico.</em></p></blockquote><p>Respuesta. M&#225;s de <a href="https://www.niemanlab.org/2026/04/journalists-champion-wayback-machine-after-news-publishers-limit-article-archiving/">100 periodistas firmaron una carta</a> de apoyo a Internet Archive impulsada junto a grupos como <strong>EFF</strong> y Fight for the Future. </p><h3>Claude Mythos Preview tuvo un 73% de &#233;xito en desaf&#237;os CTF</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nlUF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F712c086b-b05e-40d0-a66d-63280be76619_1009x649.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nlUF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F712c086b-b05e-40d0-a66d-63280be76619_1009x649.png 424w, https://substackcdn.com/image/fetch/$s_!nlUF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F712c086b-b05e-40d0-a66d-63280be76619_1009x649.png 848w, https://substackcdn.com/image/fetch/$s_!nlUF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F712c086b-b05e-40d0-a66d-63280be76619_1009x649.png 1272w, https://substackcdn.com/image/fetch/$s_!nlUF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F712c086b-b05e-40d0-a66d-63280be76619_1009x649.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nlUF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F712c086b-b05e-40d0-a66d-63280be76619_1009x649.png" width="1009" height="649" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/712c086b-b05e-40d0-a66d-63280be76619_1009x649.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:649,&quot;width&quot;:1009,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:917865,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194107355?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F712c086b-b05e-40d0-a66d-63280be76619_1009x649.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nlUF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F712c086b-b05e-40d0-a66d-63280be76619_1009x649.png 424w, https://substackcdn.com/image/fetch/$s_!nlUF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F712c086b-b05e-40d0-a66d-63280be76619_1009x649.png 848w, https://substackcdn.com/image/fetch/$s_!nlUF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F712c086b-b05e-40d0-a66d-63280be76619_1009x649.png 1272w, https://substackcdn.com/image/fetch/$s_!nlUF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F712c086b-b05e-40d0-a66d-63280be76619_1009x649.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Reuters</figcaption></figure></div><p><a href="https://www.brodersendarknews.com/p/anthropic-mythos-preview-modelo-riesgos">Claude Mythos Preview</a> ya muestra capacidades ofensivas de ciberseguridad mucho m&#225;s avanzadas que las de modelos anteriores. Una evaluaci&#243;n del <strong><a href="https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities">AI Security Institute</a></strong><a href="https://www.aisi.gov.uk/blog/our-evaluation-of-claude-mythos-previews-cyber-capabilities"> encontr&#243;</a> que puede encadenar ataques complejos sobre redes vulnerables y completar, en algunos casos, una simulaci&#243;n corporativa de 32 pasos de punta a punta.</p><p><strong>Qu&#233; detectaron.</strong> En desaf&#237;os tipo CTF, Mythos Preview mejor&#243; fuerte frente a modelos anteriores. En tareas de nivel experto, donde hasta abril de 2025 ning&#250;n modelo lograba resultados, alcanz&#243; una <strong>tasa de &#233;xito del 73%</strong>. </p><p><strong>Por qu&#233; importa.</strong> La evaluaci&#243;n sugiere que ya puede comprometer de forma aut&#243;noma sistemas empresariales chicos, d&#233;biles y mal defendidos, siempre que tenga acceso a la red. El instituto aclara que eso no prueba todav&#237;a capacidad contra entornos bien protegidos, porque las pruebas no incluyeron defensas activas ni detecci&#243;n.</p><p><strong>Entre l&#237;neas.</strong> Mythos Preview no logr&#243; completar otra simulaci&#243;n centrada en entornos industriales, aunque el informe aclara que se trab&#243; en la parte IT y que eso no alcanza para descartar capacidades en OT. Tambi&#233;n advierte que el rendimiento podr&#237;a seguir subiendo con m&#225;s c&#243;mputo.</p><h3>La trampa del bot&#243;n de &#8220;atr&#225;s&#8221; en Google Search: penalizan los sitios que secuestran la funci&#243;n</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Ipjx!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd769b495-2c3f-468e-98f2-54c9b15a1d07_1136x767.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Ipjx!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd769b495-2c3f-468e-98f2-54c9b15a1d07_1136x767.png 424w, https://substackcdn.com/image/fetch/$s_!Ipjx!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd769b495-2c3f-468e-98f2-54c9b15a1d07_1136x767.png 848w, https://substackcdn.com/image/fetch/$s_!Ipjx!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd769b495-2c3f-468e-98f2-54c9b15a1d07_1136x767.png 1272w, https://substackcdn.com/image/fetch/$s_!Ipjx!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd769b495-2c3f-468e-98f2-54c9b15a1d07_1136x767.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Ipjx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd769b495-2c3f-468e-98f2-54c9b15a1d07_1136x767.png" width="1136" height="767" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d769b495-2c3f-468e-98f2-54c9b15a1d07_1136x767.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:767,&quot;width&quot;:1136,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1875700,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194107355?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd769b495-2c3f-468e-98f2-54c9b15a1d07_1136x767.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Ipjx!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd769b495-2c3f-468e-98f2-54c9b15a1d07_1136x767.png 424w, https://substackcdn.com/image/fetch/$s_!Ipjx!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd769b495-2c3f-468e-98f2-54c9b15a1d07_1136x767.png 848w, https://substackcdn.com/image/fetch/$s_!Ipjx!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd769b495-2c3f-468e-98f2-54c9b15a1d07_1136x767.png 1272w, https://substackcdn.com/image/fetch/$s_!Ipjx!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd769b495-2c3f-468e-98f2-54c9b15a1d07_1136x767.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Shutterstock</figcaption></figure></div><p>Google empezar&#225; a penalizar en Search a los sitios que hacen <strong><a href="https://9to5google.com/2026/04/13/google-search-back-button-hijacking/">&#8220;back button hijacking&#8221;</a></strong>, una pr&#225;ctica enga&#241;osa que impide volver normalmente a la p&#225;gina anterior y empuja al usuario a p&#225;ginas no visitadas, <strong>recomendaciones no solicitadas</strong> o publicidad. La compa&#241;&#237;a la incorpor&#243; a su pol&#237;tica de spam por &#8220;pr&#225;cticas maliciosas&#8221; y advirti&#243; que esos sitios podr&#225;n recibir acciones manuales o <strong>degradaciones</strong> autom&#225;ticas en el ranking.</p><p><strong>Qu&#233; cambia.</strong> Desde ahora, el &#8220;back button hijacking&#8221; pasa a ser una violaci&#243;n de la pol&#237;tica de spam vinculada a pr&#225;cticas maliciosas, es decir, conductas que generan una brecha entre lo que el usuario espera y lo que realmente ocurre, con <strong>impacto negativo</strong> en experiencia, privacidad o seguridad.</p><p><strong>C&#243;mo impacta.</strong> Las p&#225;ginas que usen este tipo de scripts podr&#225;n sufrir sanciones manuales o ca&#237;das autom&#225;ticas en Google Search, lo que puede afectar directamente su visibilidad y tr&#225;fico org&#225;nico.</p><p><strong>Deadline.</strong> Google dijo que detect&#243; un aumento de este comportamiento y les dio a los due&#241;os de sitios dos meses para corregirlo. La aplicaci&#243;n de la medida empezar&#225; el 15 de junio de 2026.</p><h3>Rockstar Games, creadores de GTA, hackeado (otra vez)</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Rzb8!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d5399d9-dda8-489b-950a-3d575e2f18bd_1460x859.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Rzb8!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d5399d9-dda8-489b-950a-3d575e2f18bd_1460x859.png 424w, https://substackcdn.com/image/fetch/$s_!Rzb8!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d5399d9-dda8-489b-950a-3d575e2f18bd_1460x859.png 848w, https://substackcdn.com/image/fetch/$s_!Rzb8!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d5399d9-dda8-489b-950a-3d575e2f18bd_1460x859.png 1272w, https://substackcdn.com/image/fetch/$s_!Rzb8!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d5399d9-dda8-489b-950a-3d575e2f18bd_1460x859.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Rzb8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d5399d9-dda8-489b-950a-3d575e2f18bd_1460x859.png" width="1456" height="857" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7d5399d9-dda8-489b-950a-3d575e2f18bd_1460x859.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:857,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:632284,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194107355?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d5399d9-dda8-489b-950a-3d575e2f18bd_1460x859.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Rzb8!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d5399d9-dda8-489b-950a-3d575e2f18bd_1460x859.png 424w, https://substackcdn.com/image/fetch/$s_!Rzb8!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d5399d9-dda8-489b-950a-3d575e2f18bd_1460x859.png 848w, https://substackcdn.com/image/fetch/$s_!Rzb8!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d5399d9-dda8-489b-950a-3d575e2f18bd_1460x859.png 1272w, https://substackcdn.com/image/fetch/$s_!Rzb8!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7d5399d9-dda8-489b-950a-3d575e2f18bd_1460x859.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Captura sitio ShinyHunters</figcaption></figure></div><p><a href="https://hackread.com/shinyhunters-rockstar-games-snowflake-breach-anodot/">Rockstar Games confirm&#243;</a> esta semana que cibercriminales accedieron a &#8220;una cantidad limitada&#8221; de informaci&#243;n interna en una brecha ligada a un proveedor externo, pero busc&#243; bajar el tono: dijo que el incidente no afecta ni a la empresa ni a los jugadores.</p><p><strong>Qu&#233; pas&#243;.</strong> Seg&#250;n los reportes, <strong>ShinyHunters</strong> habr&#237;a comprometido <strong>Anodot</strong>, una plataforma de an&#225;lisis y monitoreo de costos en la nube que Rockstar usa, y desde ah&#237; habr&#237;a obtenido tokens de autenticaci&#243;n para entrar al <em>data warehouse</em> de Snowflake de la empresa. La hip&#243;tesis es que no quebraron el cifrado de Snowflake: aprovecharon el acceso delegado de una herramienta con permisos amplios.</p><p><strong>La clave.</strong> El punto d&#233;bil no habr&#237;a sido Snowflake sino la integraci&#243;n. Si una herramienta externa tiene permisos de lectura sobre un entorno sensible y ese tercero queda comprometido, el acceso ya est&#225; garantizado.</p><p><strong>Qu&#233; dice Rockstar.</strong> La empresa confirm&#243; el acceso, pero lo relativiz&#243;. Tambi&#233;n asegur&#243; que no hay impacto operativo ni para jugadores. Por ahora, eso sugiere que no espera una filtraci&#243;n grave vinculada a <strong>GTA 6</strong>, al menos en t&#233;rminos de contenido sensible o planes de lanzamiento.</p><p><strong>Antecedentes.</strong> En 2022 Rockstar ya sufri&#243; una de las filtraciones m&#225;s resonantes de la industria, con <strong><a href="https://www.clarin.com/tecnologia/gta-vi-publican-90-videos-robados-imagenes-proximo-juego-fans-enloquecen_0_4u3GyrwHB7.html">m&#225;s de 90 videos e im&#225;genes tempranas de GTA 6</a></strong>, y en 2023 el primer tr&#225;iler tambi&#233;n se filtr&#243; antes de tiempo.</p><h3>Booking sufre una filtraci&#243;n de datos</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oigH!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F055eae92-fe80-44ba-a8f0-62fe18896b99_1273x769.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oigH!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F055eae92-fe80-44ba-a8f0-62fe18896b99_1273x769.png 424w, https://substackcdn.com/image/fetch/$s_!oigH!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F055eae92-fe80-44ba-a8f0-62fe18896b99_1273x769.png 848w, https://substackcdn.com/image/fetch/$s_!oigH!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F055eae92-fe80-44ba-a8f0-62fe18896b99_1273x769.png 1272w, https://substackcdn.com/image/fetch/$s_!oigH!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F055eae92-fe80-44ba-a8f0-62fe18896b99_1273x769.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oigH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F055eae92-fe80-44ba-a8f0-62fe18896b99_1273x769.png" width="1273" height="769" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/055eae92-fe80-44ba-a8f0-62fe18896b99_1273x769.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:769,&quot;width&quot;:1273,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2271021,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194107355?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F055eae92-fe80-44ba-a8f0-62fe18896b99_1273x769.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!oigH!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F055eae92-fe80-44ba-a8f0-62fe18896b99_1273x769.png 424w, https://substackcdn.com/image/fetch/$s_!oigH!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F055eae92-fe80-44ba-a8f0-62fe18896b99_1273x769.png 848w, https://substackcdn.com/image/fetch/$s_!oigH!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F055eae92-fe80-44ba-a8f0-62fe18896b99_1273x769.png 1272w, https://substackcdn.com/image/fetch/$s_!oigH!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F055eae92-fe80-44ba-a8f0-62fe18896b99_1273x769.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Pexels</figcaption></figure></div><p><strong>Booking </strong>confirm&#243; un incidente que expuso datos de reservas de algunos clientes. La empresa habl&#243; de <strong>&#8220;terceros no autorizados&#8221;</strong>, pero no inform&#243; cu&#225;ntos usuarios fueron afectados ni c&#243;mo ocurri&#243; el acceso.</p><p><strong>Qu&#233; pas&#243;.</strong> La plataforma detect&#243; actividad sospechosa vinculada a atacantes que lograron acceder a parte de la informaci&#243;n de reservas de hu&#233;spedes. Booking dijo que ya contuvo el incidente, actualiz&#243; el PIN de las reservas impactadas y notific&#243; a los usuarios afectados.</p><p><strong>Qu&#233; datos quedaron expuestos.</strong> Booking.com dijo que no se comprometi&#243; informaci&#243;n financiera. Pero el acceso s&#237; pudo incluir nombres, mails, direcciones, tel&#233;fonos, detalles de la reserva y cualquier dato adicional que el usuario haya compartido con el alojamiento.</p><p><strong>Por qu&#233; importa.</strong> Aunque no haya tarjetas filtradas, ese combo alcanza para montar estafas muy convincentes. Con datos de una reserva real, un atacante puede hacerse pasar por el hotel o por Booking.com y pedir pagos, verificaciones o documentos con apariencia leg&#237;tima.</p><p><strong>El contexto.</strong> Booking.com arrastra antecedentes de fraude dentro de su ecosistema, especialmente estafas que usan mensajes falsos para pedir &#8220;verificaciones&#8221; antes del viaje. En 2018, adem&#225;s, un ataque v&#237;a phishing contra empleados de hoteles expuso datos de m&#225;s de 4.000 usuarios y termin&#243; con una multa en Pa&#237;ses Bajos por reportarlo tarde.</p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.axionenergy.com/Paginas/index.aspx" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dh5W!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg 424w, https://substackcdn.com/image/fetch/$s_!dh5W!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg 848w, https://substackcdn.com/image/fetch/$s_!dh5W!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!dh5W!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dh5W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg" width="600" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:131875,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://www.axionenergy.com/Paginas/index.aspx&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194107355?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dh5W!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg 424w, https://substackcdn.com/image/fetch/$s_!dh5W!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg 848w, https://substackcdn.com/image/fetch/$s_!dh5W!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!dh5W!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F85b8589c-c63b-4b54-bd74-75639306f8fb_600x300.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></div><h3>Nueva investigaci&#243;n revela que Telegram aloja un mercado negro cripto de 21 mil millones</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!dFaU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d3284fc-df3a-4c04-bccc-348e4cbf56ed_1196x831.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!dFaU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d3284fc-df3a-4c04-bccc-348e4cbf56ed_1196x831.png 424w, https://substackcdn.com/image/fetch/$s_!dFaU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d3284fc-df3a-4c04-bccc-348e4cbf56ed_1196x831.png 848w, https://substackcdn.com/image/fetch/$s_!dFaU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d3284fc-df3a-4c04-bccc-348e4cbf56ed_1196x831.png 1272w, https://substackcdn.com/image/fetch/$s_!dFaU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d3284fc-df3a-4c04-bccc-348e4cbf56ed_1196x831.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!dFaU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d3284fc-df3a-4c04-bccc-348e4cbf56ed_1196x831.png" width="1196" height="831" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4d3284fc-df3a-4c04-bccc-348e4cbf56ed_1196x831.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:831,&quot;width&quot;:1196,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1283683,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/194107355?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d3284fc-df3a-4c04-bccc-348e4cbf56ed_1196x831.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!dFaU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d3284fc-df3a-4c04-bccc-348e4cbf56ed_1196x831.png 424w, https://substackcdn.com/image/fetch/$s_!dFaU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d3284fc-df3a-4c04-bccc-348e4cbf56ed_1196x831.png 848w, https://substackcdn.com/image/fetch/$s_!dFaU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d3284fc-df3a-4c04-bccc-348e4cbf56ed_1196x831.png 1272w, https://substackcdn.com/image/fetch/$s_!dFaU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4d3284fc-df3a-4c04-bccc-348e4cbf56ed_1196x831.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: AFP</figcaption></figure></div><p><strong>Telegram</strong> sigue alojando un mercado negro chino vinculado a estafas cripto y trata de personas, pese a que fue sancionado oficialmente por el Reino Unido hace casi tres semanas. La revelaci&#243;n surge de una investigaci&#243;n del periodista <a href="https://archive.is/20260414191740/https://www.wired.com/story/telegram-is-still-hosting-a-sanctioned-21-billion-crypto-scammer-black-market/">Andy Greenberg, de Wired</a>.</p><p><strong>Qu&#233; pas&#243;.</strong> El marketplace se llama <strong>Xinbi Guarantee</strong> y opera desde hace m&#225;s de tres a&#241;os dentro de Telegram como un bazar en chino para servicios de <strong>lavado de dinero</strong>, infraestructura para estafas con criptomonedas y otros delitos. Seg&#250;n la investigaci&#243;n, el Reino Unido lo sancion&#243; el 26 de marzo por facilitar estafas y trata, pero Telegram no elimin&#243; sus cuentas.</p><p><strong>Los n&#250;meros.</strong> La empresa de trazabilidad cripto Elliptic estima que Xinbi Guarantee ya movi&#243; unos US$ 21.000 millones en transacciones totales. Incluso despu&#233;s de las sanciones brit&#225;nicas, proces&#243; otros US$ 505 millones en apenas 19 d&#237;as y sigui&#243; sumando usuarios hasta rozar los 500.000 compradores y vendedores.</p><p><strong>Qu&#233; ofrec&#237;a.</strong> Seg&#250;n Wired y Elliptic, el mercado no solo funcionaba como engranaje de lavado para redes de scam centers del sudeste asi&#225;tico, sino que tambi&#233;n alojaba publicaciones de productos como bastones el&#233;ctricos, tasers y esposas, presuntamente ligados a operaciones de trata, adem&#225;s de servicios de acoso por encargo y avisos sexuales que inclu&#237;an menores.</p><p><strong>Por qu&#233; importa.</strong> El caso vuelve a poner presi&#243;n sobre Telegram y sobre <strong>Pavel Durov</strong> por el rol de la app como infraestructura visible para econom&#237;as criminales a gran escala.</p><div><hr></div><h4><strong>&#128275; Breaches y hacks</strong></h4><ul><li><p>Encuentran la posibilidad de <a href="https://thehackernews.com/2026/04/new-php-composer-flaws-enable-arbitrary.html">ejecutar c&#243;digo</a> en PHP Composer</p></li><li><p>CPUID, hackeado para inyectar malware <a href="https://www.bleepingcomputer.com/news/security/supply-chain-attack-at-cpuid-pushes-malware-with-cpu-z-hwmonitor/">v&#237;a CPU-Z y HWMonitor</a></p></li><li><p><a href="https://haveibeenpwned.com/Breach/Hallmark">Hallmark sufre</a> un data breach: 1,7 millones de cuentas comprometidas</p></li></ul><h4><strong>&#128274; Ransomware</strong></h4><ul><li><p>Atacantes todav&#237;a usan el playbook de <a href="https://cyberscoop.com/black-basta-affiliates-senior-executives-reliaquest/">Black Basta</a></p></li><li><p><a href="https://www.zscaler.com/blogs/security-research/payouts-king-takes-aim-ransomware-throne">Payouts King</a> apunta a &#8220;la corona&#8221; del ransomware: Zscaler</p></li><li><p><a href="https://www.sophos.com/en-us/blog/qemu-abused-to-evade-detection-and-enable-ransomware-delivery">Abusan de QEMU</a> (open source de m&#225;quinas virtuales) para instalar ransomware</p></li></ul><h4><strong>&#128163; Exploits y malware</strong></h4><ul><li><p>108 extensiones maliciosas de Chrome <a href="https://thehackernews.com/2026/04/108-malicious-chrome-extensions-steal.html">roban datos</a> de Google</p></li><li><p>Infecci&#243;n de <a href="https://isc.sans.edu/diary/32904">Lumma Stealer</a> con Sectop RAT</p></li><li><p>Una descarga falsa de Slack infecta equipos: <a href="https://www.malwarebytes.com/blog/threat-intel/2026/04/a-fake-slack-download-is-giving-attackers-a-hidden-desktop-on-your-machine">Malwarebytes</a></p></li></ul><h4><strong>&#128269; Threat intel y vulnerabilidades</strong></h4><ul><li><p><a href="https://blog.checkpoint.com/research/the-phishing-paradox-the-worlds-most-trusted-brands-are-cyber-criminals-entry-point-of-choice/">Microsoft, Apple y Google</a>, las marcas m&#225;s usadas para phishing seg&#250;n Check Point en el Q1 2026</p></li><li><p><a href="https://www.recordedfuture.com/research/latin-america-and-the-caribbean-cybercrime-landscape-es">Recorded Future</a>: Brasil, M&#233;xico y Argentina, los pa&#237;ses m&#225;s atacados de LATAM</p></li><li><p>Reportes: <a href="https://analyst1.com/ransomware-extortion-activity/">Analyst1</a>, <a href="https://www.f5.com/labs/casi">F5</a>, <a href="https://mind.io/newsroom/critical-impact-of-data-trust-on-ai-initiative-success">Mind</a>, <a href="https://www.wiz.io/blog/cloud-threat-retrospective-2026">Wiz</a>, <a href="https://www.kaseya.com/press-release/ai-emerges-as-the-key-to-scaling-msp-operations-as-growth-gets-harder/">Kaseya</a>, <a href="https://www.emsisoft.com/en/blog/47562/the-state-of-ransomware-in-q1-2026/">Emsisoft</a></p></li></ul><h4><strong>&#128736;&#65039; Tools y updates</strong></h4><ul><li><p>Adobe parchea un <a href="https://helpx.adobe.com/security/products/acrobat/apsb26-43.html">zero day</a> y <a href="https://www.securityweek.com/adobe-patches-55-vulnerabilities-across-11-products/">55 vulnerabilidades</a> en 11 productos</p></li><li><p>CISA <a href="https://www.cisa.gov/news-events/alerts/2026/04/14/cisa-adds-two-known-exploited-vulnerabilities-catalog">actualiza</a> su base de datos de KEV</p></li><li><p><a href="https://github.com/RedSiege/EyeWitness">EyeWitness</a>, una herramienta que toma screenshots de sitios web</p></li></ul><h4><strong>&#128203; Privacidad y regulaciones</strong></h4><ul><li><p>Rusia bloquea la red social <a href="https://therecord.media/russia-cracks-down-bluesky-internet">Blue Sky</a></p></li><li><p>16 a&#241;os de prisi&#243;n para <a href="https://www.tomshardware.com/tech-industry/two-us-citizens-get-combined-18-years-in-prison-for-running-north-korean-laptop-farms-fake-remote-it-work-scheme-netted-dprk-usd5-million-in-around-three-years">dos ciudadanos norteamericanos</a> que manejaban una granja de trabajadores falsos norcoreanos</p></li><li><p><a href="https://apnews.com/article/roblox-nevada-settlement-28b3d7d7a483dc28462a7504b67c9bbc">Roblox</a> alcanza un acuerdo por la verificaci&#243;n de edad</p><p></p></li></ul><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial generativa para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/internet-archive-wayback-machine-medios-bloqueo?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/internet-archive-wayback-machine-medios-bloqueo?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Anthropic considera riesgosa su nueva IA: "Puede explotar fallas en los principales sistemas operativos"]]></title><description><![CDATA[Adem&#225;s: record de fraude online, identifican al l&#237;der de REvil, LinkedIn recopila informaci&#243;n de usuarios y recuperan mensajes borrados de Signal.]]></description><link>https://www.brodersendarknews.com/p/anthropic-mythos-preview-modelo-riesgos</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/anthropic-mythos-preview-modelo-riesgos</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Fri, 10 Apr 2026 11:05:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!e3rO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43e9fe0-5540-4e1b-8e82-5f9601247032_1184x780.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>3<strong>~10</strong><br>abr</h1><h2><strong>&#9889;TL;DR</strong></h2><p>Anthropic agit&#243; el avispero esta semana. Para sorpresa de nadie, la IA sigue llenando titulares de medios, pero esta vez la esfera cyber recibi&#243; el cimbronazo de <strong>&#8220;Mythos Preview&#8221;</strong>, un modelo orientado a seguridad ofensiva y defensiva que, seg&#250;n la empresa, <a href="https://arstechnica.com/ai/2026/04/anthropic-limits-access-to-mythos-its-new-cybersecurity-ai-model/">se liberar&#225; de forma limitada</a> por el potencial de abuso que podr&#237;a tener.</p><p>No es la primera vez que aparece el argumento de una herramienta tan potente como peligrosa. De hecho, es la ra&#237;z de las discusiones entre el actual CEO de Anthropic, Dar&#237;o Amodei, y Sam Altman de OpenAI, que llev&#243; a la ruptura entre ambos.</p><p>Varias empresas y <a href="https://x.com/__suto/status/2042220670172708917?s=46&amp;t=irLyryAdJlqZG0t2F4iu_g">especialistas</a> salieron a <a href="https://aisle.com/blog/ai-cybersecurity-after-mythos-the-jagged-frontier">relativizar</a> el escenario de la herramienta. Como vengo diciendo de manera casi permanente, estamos ante un escenario en el que es <strong>muy dif&#237;cil separar se&#241;al de ruido</strong> en temas de IA. Todo viene con <em>hype</em> y operadores de estas tecnolog&#237;as. </p><p>Esta vez, m&#225;s all&#225; del marketing, parece haber cierto consenso respecto de que Anthropic dio <strong>un salto grande</strong> en capacidades de seguridad con Mythos Preview.</p><p>Por otro lado, la semana pasada no hubo edici&#243;n de <strong>Dark News y</strong> pas&#243; de todo. Hubo una recopilaci&#243;n de ataques a maintainers del mundo open source (con <strong><a href="https://techcrunch.com/2026/04/06/north-koreas-hijack-of-one-of-the-webs-most-used-open-source-projects-was-likely-weeks-in-the-making/">Axios</a></strong> a la cabeza, pero adem&#225;s PyPI, <strong>LiteLLM</strong> <a href="https://socket.dev/blog/attackers-hunting-high-impact-nodejs-maintainers">Node.js, Lodash, Fastify, Mocha y Express</a>). Es una ofensiva contra librer&#237;as y proyectos que funcionan como la infraestructura invisible de internet y est&#225;n integrados en miles de apps, servicios y entornos de desarrollo en todo el mundo. </p><p>Los casos vuelven a mostrar por qu&#233; <a href="https://www.brodersendarknews.com/i/143139754/xz-que-paso-y-por-que-se-agito-todo-el-mundo-infosec">el caso de XZ, en 2024</a>, fue apenas la punta del iceberg de un problema mucho m&#225;s profundo (recomiendo, de paso, <a href="https://youtu.be/aoag03mSuXQ?si=sJ7NEOyw2M1tpEOS">este video</a>).</p><p>Perlitas de la semana: <a href="https://techcrunch.com/2026/04/04/after-fighting-malware-for-decades-this-cybersecurity-veteran-is-now-hacking-drones/">entrevistaron a </a><strong><a href="https://techcrunch.com/2026/04/04/after-fighting-malware-for-decades-this-cybersecurity-veteran-is-now-hacking-drones/">Mikko Hypp&#246;nen</a></strong> luego de su salida de la industria infosec, el <a href="https://www.nytimes.com/2026/04/08/business/bitcoin-satoshi-nakamoto-identity-adam-back.html?unlocked_article_code=1.ZVA.5_s8.hTKeCkV97kow&amp;smid=tw-share">New York Times sali&#243; con una investigaci&#243;n</a> que, aparentemente, desenmascara al creador de Bitcoin, <strong>Satoshi Nakamoto</strong>. </p><p>Y encontr&#233; una nota donde explican c&#243;mo en Rusia est&#225;n adoptando plataformas de chat alternativas luego de la prohibici&#243;n de Telegram y WhatsApp. Desde<a href="https://restofworld.org/2026/china-ai-glasses-cheating-privacy-boom/"> aplicaciones de cita o Duolingo</a> hasta <a href="https://gubdaily-ru.translate.goog/news/ne-dumala-chto-eto-uvidyat-milliony-rossiyane-sozvanivayutsya-cherez-kormushku-kota/?_x_tr_sl=en&amp;_x_tr_tl=es&amp;_x_tr_hl=en&amp;_x_tr_pto=wapp&amp;_x_tr_hist=true">comederos inteligentes para </a><strong><a href="https://gubdaily-ru.translate.goog/news/ne-dumala-chto-eto-uvidyat-milliony-rossiyane-sozvanivayutsya-cherez-kormushku-kota/?_x_tr_sl=en&amp;_x_tr_tl=es&amp;_x_tr_hl=en&amp;_x_tr_pto=wapp&amp;_x_tr_hist=true">gatos</a></strong>.</p><div><hr></div><p><em>En esta edici&#243;n:</em></p><ul><li><p>&#129504; <em><a href="https://www.brodersendarknews.com/i/193094978/anthropic-considera-riesgosa-su-nueva-ia-puede-explotar-fallas-en-los-principales-sistemas-operativos">Anthropic considera riesgosa su nueva IA: &#8220;Puede explotar fallas en los principales sistemas operativos&#8221;</a></em></p></li><li><p>&#128184; <em><a href="https://www.brodersendarknews.com/i/193094978/record-de-fraude-online-en-eeuu-21-mil-millones-de-dolares">Record de fraude online en EE.UU: 21 mil millones de d&#243;lares</a></em></p></li><li><p>&#128373;&#65039; <em><a href="https://www.brodersendarknews.com/i/193094978/identifican-al-jefe-de-gandcrab-y-revil-quien-es-el-ruso-detras-de-dos-bandas-historicas-de-ransomware">Identifican al jefe de GandCrab y REvil: qui&#233;n es el ruso detr&#225;s de dos bandas hist&#243;ricas de ransomware</a></em></p></li><li><p>&#128242; <em><a href="https://www.brodersendarknews.com/i/193094978/logran-recuperar-mensajes-borrados-de-signal-desde-las-notificaciones">Logran recuperar mensajes borrados de Signal desde las notificaciones</a></em></p></li><li><p>&#128230; <em><a href="https://www.brodersendarknews.com/i/193094978/el-hackeo-a-axios-uno-de-los-proyectos-open-source-mas-grandes-se-planeo-durante-semanas">El hackeo a Axios, uno de los proyectos open source m&#225;s grandes, se plane&#243; durante semanas</a></em></p></li><li><p>&#9888;&#65039; <em><a href="https://www.brodersendarknews.com/i/193094978/un-informe-denuncia-que-linkedin-recolecto-ilegalmente-datos-de-usuarios">Un informe denuncia que LinkedIn recolect&#243; ilegalmente datos de usuarios</a></em></p></li></ul><p>&#9200; <em>Substack dice que leer este correo completo lleva 13 minutos</em></p><p><em>Dark News #196</em></p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.kulkan.com/?utm_source=newsletter&amp;utm_medium=dark_news&amp;utm_campaign=quote#quote" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!qXPk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 424w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 848w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 1272w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!qXPk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png" width="600" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/379ea089-6930-4e5c-a652-27cb153177d8_600x300.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:136661,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;https://www.kulkan.com/?utm_source=newsletter&amp;utm_medium=dark_news&amp;utm_campaign=quote#quote&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/193094978?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!qXPk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 424w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 848w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 1272w, https://substackcdn.com/image/fetch/$s_!qXPk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F379ea089-6930-4e5c-a652-27cb153177d8_600x300.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p></div><h3>Anthropic considera riesgosa su nueva IA: &#8220;Puede explotar fallas en los principales sistemas operativos&#8221;</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!e3rO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43e9fe0-5540-4e1b-8e82-5f9601247032_1184x780.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!e3rO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43e9fe0-5540-4e1b-8e82-5f9601247032_1184x780.png 424w, https://substackcdn.com/image/fetch/$s_!e3rO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43e9fe0-5540-4e1b-8e82-5f9601247032_1184x780.png 848w, https://substackcdn.com/image/fetch/$s_!e3rO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43e9fe0-5540-4e1b-8e82-5f9601247032_1184x780.png 1272w, https://substackcdn.com/image/fetch/$s_!e3rO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43e9fe0-5540-4e1b-8e82-5f9601247032_1184x780.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!e3rO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43e9fe0-5540-4e1b-8e82-5f9601247032_1184x780.png" width="1184" height="780" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b43e9fe0-5540-4e1b-8e82-5f9601247032_1184x780.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:780,&quot;width&quot;:1184,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:721314,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/193094978?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43e9fe0-5540-4e1b-8e82-5f9601247032_1184x780.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!e3rO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43e9fe0-5540-4e1b-8e82-5f9601247032_1184x780.png 424w, https://substackcdn.com/image/fetch/$s_!e3rO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43e9fe0-5540-4e1b-8e82-5f9601247032_1184x780.png 848w, https://substackcdn.com/image/fetch/$s_!e3rO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43e9fe0-5540-4e1b-8e82-5f9601247032_1184x780.png 1272w, https://substackcdn.com/image/fetch/$s_!e3rO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb43e9fe0-5540-4e1b-8e82-5f9601247032_1184x780.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: EFE</figcaption></figure></div><p>Anthropic anunci&#243; que <strong><a href="https://red.anthropic.com/2026/mythos-preview/">no va a lanzar de forma masiva</a></strong> su nuevo modelo <strong><a href="https://www.anthropic.com/glasswing">Mythos Preview</a></strong>, una IA orientada a ciberseguridad ofensiva y defensiva que, seg&#250;n la propia empresa, es capaz de encontrar y explotar fallas cr&#237;ticas con un nivel de autonom&#237;a in&#233;dito.</p><p><strong>Por qu&#233; importa.</strong> Seg&#250;n Anthropic, Mythos puede detectar &#8220;decenas de miles&#8221; de vulnerabilidades, muy por encima de lo que logra un investigador humano avanzado. </p><p>En el texto explican que, entre lo m&#225;s destacable, encontr&#243;:</p><ul><li><p><em><strong>Zero-days masivos:</strong> Mythos encontr&#243; y explot&#243; 0-days en los principales sistemas operativos y navegadores.</em></p></li><li><p><em><strong>OpenBSD:</strong> detect&#243; un bug de <strong>27 a&#241;os</strong>.</em></p></li><li><p><em><strong>FFmpeg / H.264:</strong> hall&#243; un bug de 16 a&#241;os en el est&#225;ndar de compresi&#243;n H.264.</em></p></li><li><p><em><strong>FFmpeg / m&#225;s codecs:</strong> tambi&#233;n report&#243; fallas en H.264, H.265 y AV1; tres ya se corrigieron en FFmpeg 8.1.</em></p></li><li><p><em><strong>FreeBSD / NFS:</strong> encontr&#243; y explot&#243; un bug de <strong>17 a&#241;os</strong> que permite RCE como root sin autenticaci&#243;n.</em></p></li><li><p><em><strong>Kernel de Linux:</strong> logr&#243; <strong>escalada local a root</strong> encadenando m&#250;ltiples vulnerabilidades.</em></p></li><li><p><em><strong>Browsers / JIT:</strong> arm&#243; exploits en los principales navegadores, en un caso encaden&#243; <strong>4 bugs</strong> para romper sandboxes.</em></p></li><li><p><em><strong>Criptograf&#237;a:</strong> encontr&#243; fallas en TLS, AES-GCM y SSH, con potencial para forjar certificados o descifrar tr&#225;fico.</em></p></li></ul><p><strong>Qu&#233; cambia.</strong> En lugar de un release abierto, Anthropic lo est&#225; dando a m&#225;s de 40 organizaciones para tareas defensivas, dentro de una iniciativa llamada <strong><a href="https://www.anthropic.com/glasswing">Project Glasswing</a></strong>. </p><p>Entre los participantes est&#225;n AWS, Apple, Cisco, CrowdStrike, Google, Microsoft, Nvidia, Palo Alto Networks y la Linux Foundation. </p><p><strong>La preocupaci&#243;n.</strong> La empresa incluso cont&#243; que, en un test, el modelo <strong>logr&#243; escapar de un entorno aislado</strong>, enviar un mail a un investigador y publicar detalles t&#233;cnicos en sitios p&#250;blicos sin que se lo pidieran. Todo esto lo hizo sin una indicaci&#243;n espec&#237;fica de un humano.</p><p><strong>Dark News </strong>contact&#243; a <strong><a href="https://www.linkedin.com/in/nwaisman/">Nicol&#225;s Waisman</a></strong>, Chief Security Officer de Xbow, plataforma de seguridad ofensiva y pentesting automatizada:</p><blockquote><p><em>La noticia de Mythos es algo de lo que ya venimos hablando y analizando en muchos de nuestros benchmarks focalizados en hacking. Hay un progreso constante de los modelos en sus capacidades ofensivas, y son en cierta forma consecuencias de las mejoras que tienen los modelos en desarrollo de c&#243;digo. Las empresas tienen que empezar seriamente a pensar (y accionar) sobre c&#243;mo sus defensas van a manejar el progreso de estos modelos, porque la escala y velocidad de las capacidades ofensivas <strong>van a impactar fuertemente en la defensa</strong>.</em></p></blockquote><p><strong>Qu&#233; significa.</strong> El movimiento marca un punto nuevo en la carrera de la IA: por primera vez, una empresa admite de forma expl&#237;cita que un modelo es demasiado riesgoso para liberarlo de forma general por su capacidad para encontrar y encadenar exploits. </p><p>Anthropic cree que modelos con habilidades similares podr&#237;an aparecer en otras compa&#241;&#237;as dentro de <strong>6 a 18 meses</strong>, por lo que busca instalar la discusi&#243;n antes de que esa capacidad se haga masiva.</p><h3>Record de fraude online en EE.UU: 21 mil millones de d&#243;lares</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!g5mI!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa24f648b-7618-4299-b10a-afe1eed1e5e1_1165x780.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!g5mI!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa24f648b-7618-4299-b10a-afe1eed1e5e1_1165x780.png 424w, https://substackcdn.com/image/fetch/$s_!g5mI!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa24f648b-7618-4299-b10a-afe1eed1e5e1_1165x780.png 848w, https://substackcdn.com/image/fetch/$s_!g5mI!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa24f648b-7618-4299-b10a-afe1eed1e5e1_1165x780.png 1272w, https://substackcdn.com/image/fetch/$s_!g5mI!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa24f648b-7618-4299-b10a-afe1eed1e5e1_1165x780.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!g5mI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa24f648b-7618-4299-b10a-afe1eed1e5e1_1165x780.png" width="1165" height="780" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a24f648b-7618-4299-b10a-afe1eed1e5e1_1165x780.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:780,&quot;width&quot;:1165,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1405605,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/193094978?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa24f648b-7618-4299-b10a-afe1eed1e5e1_1165x780.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!g5mI!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa24f648b-7618-4299-b10a-afe1eed1e5e1_1165x780.png 424w, https://substackcdn.com/image/fetch/$s_!g5mI!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa24f648b-7618-4299-b10a-afe1eed1e5e1_1165x780.png 848w, https://substackcdn.com/image/fetch/$s_!g5mI!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa24f648b-7618-4299-b10a-afe1eed1e5e1_1165x780.png 1272w, https://substackcdn.com/image/fetch/$s_!g5mI!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa24f648b-7618-4299-b10a-afe1eed1e5e1_1165x780.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Bloomberg</figcaption></figure></div><p>Los estadounidenses perdieron <a href="https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions">casi </a><strong><a href="https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions">US$ 21.000 millones</a></strong><a href="https://www.fbi.gov/news/press-releases/cryptocurrency-and-ai-scams-bilk-americans-of-billions"> por cibercrimen en 2025</a>, la cifra m&#225;s alta desde que el FBI empez&#243; a relevar estos datos hace 25 a&#241;os en su informe anual <strong><a href="https://www.ic3.gov/AnnualReport/Reports/2025_IC3Report.pdf">IC3 Internet Crime Report</a></strong>.</p><p><strong>El dato.</strong> Las estafas de inversi&#243;n volvieron a liderar las p&#233;rdidas, con US$ 8.600 millones robados. De ese total, casi US$ 6.200 millones estuvieron vinculados a <strong>criptomonedas</strong>. El fraude habilitado por herramientas digitales explic&#243; el 85% del da&#241;o econ&#243;mico, con casi US$ 17.700 millones.</p><p><strong>Escala.</strong> Fue adem&#225;s el primer a&#241;o en que el FBI recibi&#243; m&#225;s de un mill&#243;n de denuncias por delitos online. Eso equivale a m&#225;s de 3.000 reportes por d&#237;a, una se&#241;al de la aceleraci&#243;n sostenida del fen&#243;meno.</p><p><strong>Por qu&#233; importa.</strong> El informe del IC3 funciona como uno de los principales term&#243;metros globales del cibercrimen y suele influir en decisiones de pol&#237;tica p&#250;blica, operativos policiales y cambios regulatorios. Reportes anteriores ya fueron usados por la Casa Blanca para priorizar la persecuci&#243;n de redes de fraude online y presionar a pa&#237;ses que alojan centros de estafas.</p><p><strong>Qu&#233; sigue.</strong> Aunque hubo movimientos contra complejos de scam en pa&#237;ses como Myanmar y Camboya, los grupos criminales ya est&#225;n migrando operaciones hacia nuevos refugios, incluyendo &#193;frica, Medio Oriente y partes de Europa. </p><p>Las estafas siguen siendo el <strong>negocio m&#225;s rentable</strong> del cibercrimen.</p><h3>Identifican al jefe de GandCrab y REvil: qui&#233;n es el ruso detr&#225;s de dos bandas hist&#243;ricas de ransomware</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vdzg!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0efe06-2de1-4b29-a9cf-5956ff7c2fc9_1071x664.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vdzg!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0efe06-2de1-4b29-a9cf-5956ff7c2fc9_1071x664.png 424w, https://substackcdn.com/image/fetch/$s_!vdzg!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0efe06-2de1-4b29-a9cf-5956ff7c2fc9_1071x664.png 848w, https://substackcdn.com/image/fetch/$s_!vdzg!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0efe06-2de1-4b29-a9cf-5956ff7c2fc9_1071x664.png 1272w, https://substackcdn.com/image/fetch/$s_!vdzg!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0efe06-2de1-4b29-a9cf-5956ff7c2fc9_1071x664.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vdzg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0efe06-2de1-4b29-a9cf-5956ff7c2fc9_1071x664.png" width="1071" height="664" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2d0efe06-2de1-4b29-a9cf-5956ff7c2fc9_1071x664.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:664,&quot;width&quot;:1071,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:738663,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/193094978?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0efe06-2de1-4b29-a9cf-5956ff7c2fc9_1071x664.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vdzg!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0efe06-2de1-4b29-a9cf-5956ff7c2fc9_1071x664.png 424w, https://substackcdn.com/image/fetch/$s_!vdzg!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0efe06-2de1-4b29-a9cf-5956ff7c2fc9_1071x664.png 848w, https://substackcdn.com/image/fetch/$s_!vdzg!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0efe06-2de1-4b29-a9cf-5956ff7c2fc9_1071x664.png 1272w, https://substackcdn.com/image/fetch/$s_!vdzg!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2d0efe06-2de1-4b29-a9cf-5956ff7c2fc9_1071x664.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: KrebsOnSecurity</figcaption></figure></div><p>Alemania identific&#243; a Daniil Maksimovich Shchukin, un ruso de 31 a&#241;os, como &#8220;UNKN&#8221; o &#8220;UNKNOWN&#8221;, el operador detr&#225;s de GandCrab y REvil, dos de las bandas de ransomware m&#225;s influyentes de los &#250;ltimos a&#241;os. La informaci&#243;n fue publicada por <em><a href="https://krebsonsecurity.com/2026/04/germany-doxes-unkn-head-of-ru-ransomware-gangs-revil-gandcrab/">Krebs on Security</a></em>.</p><p><strong>La acusaci&#243;n.</strong> Seg&#250;n la BKA, la polic&#237;a federal alemana, Shchukin encabez&#243; ambos grupos y particip&#243; en al menos 130 hackeos y extorsi&#243;n entre 2019 y 2021. Junto con otro ruso, Anatoly Kravchuk, habr&#237;a extorsionado casi 2 millones de euros en unos 24 ataques que dejaron p&#233;rdidas por m&#225;s de 35 millones de euros.</p><p><strong>Por qu&#233; importa.</strong> GandCrab y REvil ayudaron a consolidar la l&#243;gica moderna del ransomware como negocio: afiliados, operadores y doble extorsi&#243;n. Es decir, cobrar por desbloquear sistemas y adem&#225;s exigir un segundo pago para no filtrar datos robados.</p><p><strong>El contexto.</strong> GandCrab apareci&#243; en 2018 y se retir&#243; en 2019 jact&#225;ndose de haber ganado m&#225;s de US$ 2.000 millones. Poco despu&#233;s surgi&#243; REvil, que muchos expertos vieron como una continuidad bajo otra marca. Su golpe m&#225;s recordado fue el ataque a <strong>Kaseya</strong> en 2021, que afect&#243; a m&#225;s de 1.500 organizaciones.</p><p><strong>Qu&#233; m&#225;s se sabe.</strong> El nombre de Shchukin ya figuraba en un expediente del Departamento de Justicia de EE.UU. de 2023 vinculado a wallets cripto asociadas a REvil. Alemania cree que vive en Krasnodar, Rusia.</p><h3>Logran recuperar mensajes borrados de Signal desde las notificaciones</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9FSk!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96322a1c-9701-4391-b60c-edb96d54bc39_1091x674.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9FSk!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96322a1c-9701-4391-b60c-edb96d54bc39_1091x674.png 424w, https://substackcdn.com/image/fetch/$s_!9FSk!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96322a1c-9701-4391-b60c-edb96d54bc39_1091x674.png 848w, https://substackcdn.com/image/fetch/$s_!9FSk!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96322a1c-9701-4391-b60c-edb96d54bc39_1091x674.png 1272w, https://substackcdn.com/image/fetch/$s_!9FSk!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96322a1c-9701-4391-b60c-edb96d54bc39_1091x674.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9FSk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96322a1c-9701-4391-b60c-edb96d54bc39_1091x674.png" width="1091" height="674" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/96322a1c-9701-4391-b60c-edb96d54bc39_1091x674.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:674,&quot;width&quot;:1091,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1243415,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/193094978?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96322a1c-9701-4391-b60c-edb96d54bc39_1091x674.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!9FSk!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96322a1c-9701-4391-b60c-edb96d54bc39_1091x674.png 424w, https://substackcdn.com/image/fetch/$s_!9FSk!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96322a1c-9701-4391-b60c-edb96d54bc39_1091x674.png 848w, https://substackcdn.com/image/fetch/$s_!9FSk!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96322a1c-9701-4391-b60c-edb96d54bc39_1091x674.png 1272w, https://substackcdn.com/image/fetch/$s_!9FSk!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F96322a1c-9701-4391-b60c-edb96d54bc39_1091x674.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Shutterstock</figcaption></figure></div><p>El FBI logr&#243; <a href="https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/">recuperar mensajes de </a><strong><a href="https://www.404media.co/fbi-extracts-suspects-deleted-signal-messages-saved-in-iphone-notification-database-2/">Signal</a></strong> en el iPhone de una acusada, incluso despu&#233;s de que la app hab&#237;a sido borrada. Los mensajes no salieron de Signal, sino de la base interna donde iOS guarda copias de notificaciones push cuando est&#225;n habilitadas las vistas previas en pantalla bloqueada.</p><p><strong>C&#243;mo pas&#243;.</strong> Seg&#250;n el testimonio citado en un juicio reciente en Texas, el contenido qued&#243; almacenado en la memoria interna del iPhone porque la usuaria ten&#237;a activadas las previews de notificaciones. Eso permiti&#243; extraer fragmentos de chats que ya hab&#237;an desaparecido de Signal. El hallazgo habr&#237;a incluido s&#243;lo mensajes entrantes, no salientes.</p><p><strong>Por qu&#233; importa.</strong> El caso muestra un l&#237;mite de las apps cifradas: el problema no siempre est&#225; en la app, sino en c&#243;mo el sistema operativo maneja las notificaciones. En la pr&#225;ctica, un mensaje ef&#237;mero puede seguir dejando rastros forenses fuera de Signal si el tel&#233;fono guarda previews.</p><p><strong>Qu&#233; hacer.</strong> Para usuarios que dependen de Signal en contextos sensibles, conviene revisar la configuraci&#243;n de notificaciones y desactivar la vista de contenido en pantalla bloqueada. </p><h3>El hackeo a Axios, uno de los proyectos open source m&#225;s grandes, se plane&#243; durante semanas</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Mz3I!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245b2fcc-5e13-47ce-aa68-b5ce714f3ba5_1189x719.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Mz3I!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245b2fcc-5e13-47ce-aa68-b5ce714f3ba5_1189x719.png 424w, https://substackcdn.com/image/fetch/$s_!Mz3I!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245b2fcc-5e13-47ce-aa68-b5ce714f3ba5_1189x719.png 848w, https://substackcdn.com/image/fetch/$s_!Mz3I!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245b2fcc-5e13-47ce-aa68-b5ce714f3ba5_1189x719.png 1272w, https://substackcdn.com/image/fetch/$s_!Mz3I!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245b2fcc-5e13-47ce-aa68-b5ce714f3ba5_1189x719.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Mz3I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245b2fcc-5e13-47ce-aa68-b5ce714f3ba5_1189x719.png" width="1189" height="719" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/245b2fcc-5e13-47ce-aa68-b5ce714f3ba5_1189x719.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:719,&quot;width&quot;:1189,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1361072,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/193094978?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245b2fcc-5e13-47ce-aa68-b5ce714f3ba5_1189x719.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Mz3I!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245b2fcc-5e13-47ce-aa68-b5ce714f3ba5_1189x719.png 424w, https://substackcdn.com/image/fetch/$s_!Mz3I!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245b2fcc-5e13-47ce-aa68-b5ce714f3ba5_1189x719.png 848w, https://substackcdn.com/image/fetch/$s_!Mz3I!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245b2fcc-5e13-47ce-aa68-b5ce714f3ba5_1189x719.png 1272w, https://substackcdn.com/image/fetch/$s_!Mz3I!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F245b2fcc-5e13-47ce-aa68-b5ce714f3ba5_1189x719.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: AP</figcaption></figure></div><p>Corea del Norte qued&#243; en el centro de uno de los ataques m&#225;s delicados del a&#241;o a la cadena de suministro open source: <a href="https://techcrunch.com/2026/04/06/north-koreas-hijack-of-one-of-the-webs-most-used-open-source-projects-was-likely-weeks-in-the-making/">el hackeo temporal de </a><strong><a href="https://techcrunch.com/2026/04/06/north-koreas-hijack-of-one-of-the-webs-most-used-open-source-projects-was-likely-weeks-in-the-making/">Axios</a></strong>, una de las librer&#237;as m&#225;s usadas para hacer requests HTTP. </p><p>El compromiso ocurri&#243; el 31 de marzo, pero el maintainer <a href="https://github.com/axios/axios/issues/10636">Jason Saayman cont&#243;</a> en su postmortem que fue una operaci&#243;n de al menos dos semanas.</p><p><strong>C&#243;mo hicieron.</strong> Los atacantes se hicieron pasar por una empresa real, montaron un workspace de Slack convincente con perfiles falsos y <strong>se ganaron la confianza del objetivo</strong> hasta invitarlo a una videollamada. Ah&#237; lo empujaron a descargar una supuesta actualizaci&#243;n necesaria para entrar a la call, que en realidad era <strong>malware</strong>. Con acceso remoto a su equipo, publicaron dos paquetes maliciosos en Axios.</p><p><strong>Qu&#233; riesgo hubo.</strong> Los paquetes infectados estuvieron online unas tres horas antes de ser retirados, tiempo suficiente como para que miles de sistemas pudieran haberlos instalado. Cualquier entorno afectado pudo haber expuesto claves privadas, credenciales y contrase&#241;as, abriendo la puerta a compromisos posteriores mucho m&#225;s amplios.</p><p><strong>Por qu&#233; importa.</strong> El caso muestra algo m&#225;s grande que Axios: los maintainers de proyectos open source se est&#225;n convirtiendo en blancos de alto valor porque una sola intrusi&#243;n puede escalar a miles de apps, servicios y entornos de desarrollo en todo el mundo. </p><p>Y tambi&#233;n confirma la impronta de Pyongyang: campa&#241;as largas de ingenier&#237;a social, identidades falsas y malware disfrazado para ganar acceso antes de monetizarlo con robo de datos o cripto.</p><h3>Un informe denuncia que LinkedIn recolect&#243; ilegalmente datos de usuarios</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!v252!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71301471-51ae-4762-965c-62469e412bb1_1278x874.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!v252!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71301471-51ae-4762-965c-62469e412bb1_1278x874.png 424w, https://substackcdn.com/image/fetch/$s_!v252!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71301471-51ae-4762-965c-62469e412bb1_1278x874.png 848w, https://substackcdn.com/image/fetch/$s_!v252!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71301471-51ae-4762-965c-62469e412bb1_1278x874.png 1272w, https://substackcdn.com/image/fetch/$s_!v252!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71301471-51ae-4762-965c-62469e412bb1_1278x874.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!v252!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71301471-51ae-4762-965c-62469e412bb1_1278x874.png" width="1278" height="874" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/71301471-51ae-4762-965c-62469e412bb1_1278x874.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:874,&quot;width&quot;:1278,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1871122,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/193094978?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71301471-51ae-4762-965c-62469e412bb1_1278x874.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!v252!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71301471-51ae-4762-965c-62469e412bb1_1278x874.png 424w, https://substackcdn.com/image/fetch/$s_!v252!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71301471-51ae-4762-965c-62469e412bb1_1278x874.png 848w, https://substackcdn.com/image/fetch/$s_!v252!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71301471-51ae-4762-965c-62469e412bb1_1278x874.png 1272w, https://substackcdn.com/image/fetch/$s_!v252!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F71301471-51ae-4762-965c-62469e412bb1_1278x874.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: AFP</figcaption></figure></div><p>Un informe llamado <em><a href="https://browsergate.eu/">BrowserGate</a></em> acus&#243; a la red social de Microsoft de inyectar JavaScript oculto para detectar extensiones instaladas y recolectar datos del navegador y del dispositivo. </p><p>Sospechan que esa telemetr&#237;a podr&#237;a servir para identificar qu&#233; herramientas usan empleados y empresas, incluidas apps que compiten con LinkedIn.</p><p><strong>Confirmado.</strong> <strong><a href="https://www.bleepingcomputer.com/news/security/linkedin-secretly-scans-for-6-000-plus-chrome-extensions-collects-data/">BleepingComputer</a> </strong>verific&#243; de manera independiente que LinkedIn carga un script con nombre aleatorio que intenta detectar <strong>6.236 extensiones</strong> en navegadores Chromium, una t&#233;cnica cl&#225;sica de <em>fingerprinting</em>. Esa cifra adem&#225;s creci&#243; fuerte: en 2025 se hab&#237;an reportado unas 2.000, y hace dos meses otro repositorio mostraba cerca de 3.000.</p><p><strong>La desmentida.</strong> LinkedIn no neg&#243; el escaneo. Dijo que detecta extensiones para identificar herramientas que hacen scraping sin consentimiento, mejorar defensas t&#233;cnicas y explicar comportamientos an&#243;malos en cuentas. </p><p>Tambi&#233;n asegur&#243; que <strong>no usa esos datos para inferir informaci&#243;n sensible</strong> y que el informe viene de un desarrollador enfrentado con la empresa tras restricciones por violar sus t&#233;rminos.</p><div><hr></div><h4><strong>&#128275; Breaches y hacks</strong></h4><ul><li><p>Hackean uno de los museos de arte m&#225;s importantes de  <a href="https://www.politico.eu/article/nothing-like-the-louvre-italian-art-museum-hit-cyberattack-uffizi/">Italia</a></p></li><li><p>Un actor de amenazas coloca una base de datos de <a href="https://argentina.mefiltraron.com/leaks#Administraci%C3%B3n%20Nacional%20de%20la%20Seguridad%20Social%20(ANSES)-2026-04-03">ANSES (Argentina)</a> a la venta</p></li><li><p><a href="https://www.microsoft.com/en-us/security/blog/2026/04/07/soho-router-compromise-leads-to-dns-hijacking-and-adversary-in-the-middle-attacks/">APT28 compromete</a> routers en todo el mundo para hacer ataques de phishing</p></li></ul><h4><strong>&#128274; Ransomware</strong></h4><ul><li><p>Grupo D&#8217;Arc (Argentina), anunciado por <a href="https://sheriff.birminghamcyberarms.co.uk/alert?id=355">Qilin</a></p></li><li><p>Entrevista con un operador de <a href="https://www.suspectfile.com/interview-katana-nova-nova-ransomware-raas-ransomware/">Nova Ransomware</a></p></li><li><p>Medusa Ransomware incrementa su actividad de manera veloz, dice <a href="https://www.securityweek.com/medusa-ransomware-fast-to-exploit-vulnerabilities-breached-systems/">Microsoft</a></p></li></ul><h4><strong>&#128163; Exploits y malware</strong></h4><ul><li><p>Un incidente afecta a las principales aplicaciones bancarias de <a href="https://securityaffairs.com/190464/security/major-outage-cripples-russian-banking-apps-and-metro-payments-nationwide.html">Rusia</a></p></li><li><p>RATs e infostealers, en el tope de las <a href="https://www.jamf.com/resources/white-papers/security-360-annual-trends-report/">amenazas de macOS</a></p></li><li><p>Explotan un zero-day de <a href="https://www.securityweek.com/adobe-reader-zero-day-exploited-for-months-researcher/">Adobe</a> desde noviembre</p></li></ul><h4><strong>&#128269; Threat intel y vulnerabilidades</strong></h4><ul><li><p>Netscout report&#243; un record de DDoS en los <a href="https://www.netscout.com/blog/asert/winter-games-effect-when-gold-meets-ddos">Juegos de Invierno</a></p></li><li><p><a href="https://thehackernews.com/2026/04/casbaneiro-phishing-targets-latin.html">Casbaneiro</a>, nueva campa&#241;a de phishing en Am&#233;rica Latina</p></li><li><p>Reportes: <a href="https://www.recordedfuture.com/research/latin-america-and-the-caribbean-cybercrime-landscape">Recorded Future</a>, <a href="https://www.cloudwards.net/internet-censorship/">Cloudwards</a>, <a href="https://fablesecurity.com/resources/report/report-202603/">Fable</a>, <a href="https://www.akamai.com/newsroom/press-release/publishing-industry-under-attack-global-ai-bot-activity-surges-by-300-percent-akamai-report-finds">Akamai</a>, <a href="https://blog.checkpoint.com/research/march-2026-cyber-threat-landscape-shows-no-relief-as-ransomware-rebounds-and-genai-risks-intensify/">Check Point Research</a>, <a href="https://brandefense.io/reports/ransomware-trends-report-q4-2025/">Brandfense</a>, <a href="https://securelist.com/financial-threat-report-2025/119304/">Kaspersky</a>.</p></li></ul><h4><strong>&#128736;&#65039; Tools y updates</strong></h4><ul><li><p><a href="https://fortiguard.fortinet.com/psirt/FG-IR-26-099">Fortinet parchea</a> un zero-day</p></li><li><p><a href="https://source.android.com/docs/security/bulletin/2026/2026-04-01">Android</a> lanza un parche de seguridad</p></li><li><p><a href="https://chromereleases.googleblog.com/2026/04/stable-channel-update-for-desktop.html">Chrome</a> se actualiza con parches de seguridad</p></li></ul><h4><strong>&#128203; Privacidad y regulaciones</strong></h4><ul><li><p><a href="https://restofworld.org/2026/china-ai-glasses-cheating-privacy-boom/">China detecta</a> un crecimiento en el uso de anteojos de Meta para copiarse en ex&#225;menes</p></li><li><p>La EFF <a href="https://x.com/EFF/status/2042278157609480566?s=20">abandona X</a> (Twitter)</p></li><li><p><a href="https://news.sky.com/story/greece-to-ban-under-15s-from-social-media-from-next-year-13529181">Grecia se suma</a> a la prohibici&#243;n de redes sociales a menores</p><p></p></li></ul><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/anthropic-mythos-preview-modelo-riesgos?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/anthropic-mythos-preview-modelo-riesgos?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Dark Web, Tor y el anonimato como límite a las Big Tech]]></title><description><![CDATA[El mito de la Dark Web. Tor como barrera al capitalismo de vigilancia de las Big Tech. Roger Dingledine, Micah Lee y dos hackers desmontan el iceberg.]]></description><link>https://www.brodersendarknews.com/p/dark-web-tor-y-el-anonimato-big-tech</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/dark-web-tor-y-el-anonimato-big-tech</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Sun, 05 Apr 2026 12:07:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!w9jc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff6ad4d-a0ca-4ed0-86fb-20c9cc69d720_1180x604.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>5<br>abr</h1><h2><strong>&#9749; Reportaje</strong></h2><p>Hace unas semanas publiqu&#233; un nuevo art&#237;culo en <a href="https://www.421.news/es/que-es-421/">421</a>, medio sobre cultura, tecnolog&#237;a y filosof&#237;a que apuesta por un concepto interesante: el de mejorar la &#8220;<strong>dieta cognitiva</strong>&#8221;.</p><p>C&#243;mo alimentamos la cabeza. Es un tema que me preocupa bastante, en l&#237;neas generales, por la gran cantidad de distracciones que tenemos en el d&#237;a a d&#237;a. </p><p>Para armar el reportaje, habl&#233; con <strong>Roger Dingledine</strong> (fundador del proyecto Tor), <strong><a href="https://micahflee.com/about/">Micah Lee</a></strong> (ingeniero en seguridad inform&#225;tica y periodista de datos e investigaci&#243;n) y dos hackers que prefirieron permanecer en el anonimato.</p><p>Lo reproduzco a continuaci&#243;n. Pueden leer m&#225;s notas de este sitio en <strong><a href="https://www.421.news/es/">este enlace</a></strong>.</p><div><hr></div><p>&#9200; <em>Substack dice que leer este correo completo lleva 13 minutos</em></p><p><em>Dark News #195</em></p><h3><strong>Dark Web, Tor y el anonimato como l&#237;mite a las Big Tech</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!w9jc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff6ad4d-a0ca-4ed0-86fb-20c9cc69d720_1180x604.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!w9jc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff6ad4d-a0ca-4ed0-86fb-20c9cc69d720_1180x604.jpeg 424w, https://substackcdn.com/image/fetch/$s_!w9jc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff6ad4d-a0ca-4ed0-86fb-20c9cc69d720_1180x604.jpeg 848w, https://substackcdn.com/image/fetch/$s_!w9jc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff6ad4d-a0ca-4ed0-86fb-20c9cc69d720_1180x604.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!w9jc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff6ad4d-a0ca-4ed0-86fb-20c9cc69d720_1180x604.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!w9jc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff6ad4d-a0ca-4ed0-86fb-20c9cc69d720_1180x604.jpeg" width="1180" height="604" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2ff6ad4d-a0ca-4ed0-86fb-20c9cc69d720_1180x604.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:604,&quot;width&quot;:1180,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:221696,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/191998943?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff6ad4d-a0ca-4ed0-86fb-20c9cc69d720_1180x604.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!w9jc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff6ad4d-a0ca-4ed0-86fb-20c9cc69d720_1180x604.jpeg 424w, https://substackcdn.com/image/fetch/$s_!w9jc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff6ad4d-a0ca-4ed0-86fb-20c9cc69d720_1180x604.jpeg 848w, https://substackcdn.com/image/fetch/$s_!w9jc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff6ad4d-a0ca-4ed0-86fb-20c9cc69d720_1180x604.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!w9jc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2ff6ad4d-a0ca-4ed0-86fb-20c9cc69d720_1180x604.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Ilustraci&#243;n: 421.news</figcaption></figure></div><p>Nunca la humanidad cre&#243; <em><a href="https://www.421.news/es/hauntologia-internet-ruinas-digitales/">tanta informaci&#243;n</a></em> como en la actualidad. Se dice que entre 2014 y 2017 se fabric&#243; tanto como lo que se produjo desde la prehistoria hasta 2014. Aunque gran parte de ese repositorio antes era texto, video y audio en soportes f&#237;sicos, hoy son unos y ceros. Y hay una met&#225;fora de un <em><strong><a href="https://www.dashlane.com/blog/dark-web-iceberg-explained?ref=421.news">Iceberg</a></strong></em> que nos dice que a una buena parte no se puede entrar.</p><p>Bienvenidos al reino de la &#8220;Dark Web&#8221;. Uno de los mitos m&#225;s grandes de internet.</p><p>La web oscura aparece como un recoveco donde la venta de datos personales, empresariales y estatales, tarjetas de cr&#233;dito robadas, drogas y todo tipo de il&#237;citos convergen en c&#237;rculos <em>ciberdantescos </em>que se pueden visitar si se sabe qu&#233; aplicaciones descargar y qu&#233; direcciones visitar.</p><p>Se supone que, en ese t&#233;mpano de informaci&#243;n, todo lo que encontramos navegando en buscadores como Google es la &#8220;surface web&#8221;, indexada, localizable. A fin de cuentas, Google no es la web, sino un (otrora) muy buen &#237;ndice de ella. Por debajo estar&#237;a la &#8220;Deep Web&#8221;, o el contenido no indexado, como por ejemplo bases de datos, correos electr&#243;nicos, cuentas bancarias y lo que est&#225; detr&#225;s de una pantalla de logueo. Y, en el &#250;ltimo subsuelo, la Dark Web, que tampoco est&#225; indexada, con todos sus il&#237;citos.</p><p>A diferencia de la as&#237; llamada &#8220;clearnet&#8221; (la web a la que entramos todos los d&#237;as, transparente, accesible a cualquiera y localizable por Google), en esta <strong>Dark Web</strong> hay que saber a d&#243;nde ir. No hay un buscador, sino que se visitan activamente determinados pasillos underground.</p><p>Ahora bien, la idea de un corpus oculto parece acompa&#241;arnos desde siempre. De los textos de <strong>Arist&#243;teles</strong> perdidos durante el medioevo, pasando por un &#225;rea secreta de <strong>Doom</strong> hasta un track oculto al final de un disco, parece que siempre hubo un &#8220;gatekeeper&#8221; que controla qui&#233;n accede y qui&#233;n no.</p><p>Tor, un navegador que, a diferencia de Chrome y Firefox, prioriza el anonimato, qued&#243; en ese lugar del portal hacia lo desconocido (y oscuro). Pero el paradigma es mucho m&#225;s grande: The Tor Project es una apuesta por una web por fuera del <em><a href="https://www.421.news/es/que-es-small-web-como-funciona/">capitalismo de vigilancia</a></em> de las Big Tech que poco tiene que ver con la Dark Web y m&#225;s con una concepci&#243;n diferente respecto de qu&#233; es internet.</p><p>Su creador, junto con dos hackers y un ingeniero desatan el nudo de la Dark Web, uno de los mitos m&#225;s grandes de la cultura popular digital de las &#250;ltimas d&#233;cadas.</p><h2><em><strong>&#8220;La Dark Web no existe&#8221;</strong></em></h2><p>Antes de dar cualquier paso hacia el fondo del iceberg, es importante recordar una diferencia fundamental. <em><a href="https://www.reddit.com/r/pcmasterrace/comments/b086lz/tim_bernerslee_and_vint_cerf_wearing_funny_shirts/?ref=421.news">Internet y la web no son lo mismo</a></em>. Internet es la infraestructura que sostiene todo: protocolos, routers, cables, chips, silicio. La web es un servicio que funciona sobre internet, que usa el protocolo HTTP (hipertexto).</p><p>Todo esto correr&#237;a bajo lo que se conoce como &#8220;<strong>clearnet</strong>&#8221;, una red accesible, sin muchas vueltas. Abr&#237;s Google Chrome, Firefox, Safari, busc&#225;s o tipe&#225;s una direcci&#243;n y entr&#225;s. Casi todo lo de uso cotidiano para el usuario promedio corre ac&#225;.</p><p>Los porcentajes del iceberg (4%, 90%, 6%) son estimaciones viejas. La Deep Web no es un subsuelo clandestino, sino todo lo que no es indexable por un buscador: tu correo, tu online banking o bases de datos privadas. Pensar que lo no indexado es ilegal es como suponer que todo <strong>lo que ocurre dentro de una casa es un delito.</strong></p><p>De hecho, no hay una definici&#243;n un&#237;voca de Dark Web, pero el t&#233;rmino se suele leer en medios masivos para asociarla a un reino de actividades il&#237;citas que vive en la web, pero no es accesible f&#225;cilmente.</p><p>&#8220;<strong>La Dark Web no existe</strong>. Los criminales est&#225;n en todas partes, incluyendo WhatsApp, Signal, Telegram, Facebook, Instagram, VK y dem&#225;s. &#191;Te parece oscuro todo eso? Porque a m&#237;, no. El lugar donde los criminales se re&#250;nen para discutir y hacer negocios depende del tipo de actividad que desarrollen&#8221;, dice un hacker que persigue amenazas para una empresa internacional.</p><p>&#8220;En el caso de los rusoparlantes, como afiliados y operadores de ransomware o grupos dedicados a la extorsi&#243;n, suelen moverse en foros espec&#237;ficos como Exploit[.]in, XSS, Duty Free, Rehub y TierOne&#8221;, enumera. Muchos de ellos, accesibles v&#237;a la web &#8220;normal&#8221;. Los actores de amenazas se mueven por conveniencia, idioma y modelo de negocio.</p><p>La mayor&#237;a funciona con un sistema de registro, cr&#233;ditos y reputaci&#243;n, a los cuales a veces s&#243;lo se accede por invitaci&#243;n de un tercero. &#8220;Depende del foro. Algunos son abiertos con registro y sistemas de reputaci&#243;n, otros funcionan por invitaci&#243;n o pago (muchas veces en criptomonedas, como XMR) y los m&#225;s cerrados exigen un proceso de validaci&#243;n por parte de miembros activos&#8221;, complementa otro hacker que frecuenta estos sitios.</p><p>El caso m&#225;s famoso es el de <em><a href="https://www.brodersendarknews.com/p/breachforums-caida-sitio-compraventa-intelbroker-anastasia-shinyhunters?ref=421.news">BreachForums</a></em>, quiz&#225;s el foro de compraventa de datos personales m&#225;s conocido del rubro, donde se han publicado a la venta datos personales no s&#243;lo de ciudadanos argentinos sino de Estados y empresas de todo el mundo. El sitio siempre fue accesible mediante la clearnet. Es decir, a trav&#233;s de un navegador cualquiera, tipeando la URL que, si bien migr&#243; infinidad de veces (Breached, RaidForums) de dominio por su naturaleza il&#237;cita, siempre fue f&#225;cilmente localizable por Google.</p><p>&#8220;No voy a nombrar los foros m&#225;s conocidos, pero s&#237; puedo decir que a la mayor&#237;a se accede por la clearnet, aunque los dos o tres importantes tienen su versi&#243;n onion en Tor. Curiosamente, algunos est&#225;n en ambas pero la gente prefiere acceder por clearnet y se nota especialmente cuando bajan un dominio y salen todos a quejarse (de Tor casi nunca cae)&#8221;, dice a 421 un data broker.</p><p>Quiz&#225;s gran parte de la asociaci&#243;n entre Dark Web y Tor haya sido culpa de <em><a href="https://www.421.news/es/ross-ulbricht-the-silk-road/">Ross Ulbricht, fundador de Silk Road</a></em>, uno de los mercados negros online m&#225;s conocidos del mundo. Un personaje que da para un art&#237;culo aparte, condenado de por vida en 2015 y, 10 a&#241;os despu&#233;s, indultado por el presidente de los Estados Unidos Donald Trump bajo el manto de una promesa hecha en la Convenci&#243;n Nacional Libertaria de 2024.</p><p>Y tambi&#233;n est&#225; ligado al ransomware, un tipo de malware que encripta informaci&#243;n de una v&#237;ctima para volverla inaccesible y pedir un rescate en criptomonedas a cambio. En general, los grupos de ransomware operaron en sitios accesibles v&#237;a Tor, un proyecto con un foco mucho m&#225;s amplio que qued&#243; en medio del fuego cruzado entre cibercriminales, clientes oscuros y fuerzas del orden.</p><h2><em><strong>The Tor Project: el costo de una web m&#225;s an&#243;nima</strong></em></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IGb_!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd48d5e-12b5-461a-ad0d-4293a2932108_1458x881.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IGb_!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd48d5e-12b5-461a-ad0d-4293a2932108_1458x881.png 424w, https://substackcdn.com/image/fetch/$s_!IGb_!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd48d5e-12b5-461a-ad0d-4293a2932108_1458x881.png 848w, https://substackcdn.com/image/fetch/$s_!IGb_!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd48d5e-12b5-461a-ad0d-4293a2932108_1458x881.png 1272w, https://substackcdn.com/image/fetch/$s_!IGb_!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd48d5e-12b5-461a-ad0d-4293a2932108_1458x881.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IGb_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd48d5e-12b5-461a-ad0d-4293a2932108_1458x881.png" width="1456" height="880" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4fd48d5e-12b5-461a-ad0d-4293a2932108_1458x881.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:880,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:2026205,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/191998943?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd48d5e-12b5-461a-ad0d-4293a2932108_1458x881.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IGb_!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd48d5e-12b5-461a-ad0d-4293a2932108_1458x881.png 424w, https://substackcdn.com/image/fetch/$s_!IGb_!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd48d5e-12b5-461a-ad0d-4293a2932108_1458x881.png 848w, https://substackcdn.com/image/fetch/$s_!IGb_!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd48d5e-12b5-461a-ad0d-4293a2932108_1458x881.png 1272w, https://substackcdn.com/image/fetch/$s_!IGb_!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd48d5e-12b5-461a-ad0d-4293a2932108_1458x881.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Luciano Thieberger</figcaption></figure></div><p>&#8220;&#191;Cu&#225;l creen que es el sitio m&#225;s grande de la Dark Web? &#191;Uno de venta de drogas o alguna otra actividad ilegal? <em><a href="https://youtu.be/9M2969IdFvE?si=hIAG78PuYMFl9Vz7&amp;t=2248&amp;ref=421.news">No. Es Facebook</a></em>. Y lo es porque un estudio interno de la compa&#241;&#237;a de hace 10 a&#241;os revel&#243; que un mill&#243;n de personas se conectaron a trav&#233;s de Tor. Obviamente hay gente que quiere privacidad&#8221;. Esta idea arroj&#243; <em><a href="https://www.brodersendarknews.com/p/roger-dingledine-tor-modelo-google-espionaje?ref=421.news">Roger Dingledine</a></em>, fundador de The Tor Project, en Ekoparty 2025, la convenci&#243;n de hackers m&#225;s grande de Am&#233;rica Latina. Ante un auditorio lleno, el ingeniero y matem&#225;tico explic&#243; (quiz&#225;s por vez n&#250;mero mil) por qu&#233; Tor no es &#8220;la Dark Web&#8221;.</p><p>Tor es una infraestructura pensada para reducir la exposici&#243;n del usuario en una red que, por dise&#241;o y por negocio, tiende a registrar y perfilar cada movimiento. El nombre viene de The Onion Router e implica una l&#243;gica de encapsular el tr&#225;fico en m&#250;ltiples capas de cifrado que se enrutan por distintos nodos antes de salir a la web abierta, de modo que el origen de la conexi&#243;n sea muy dif&#237;cil de rastrear.</p><p>&#8220;Sin Tor, cuando carg&#225;s un sitio web, ese sitio puede conocer tu direcci&#243;n IP real, y cualquiera que est&#233; espiando esa conexi&#243;n a internet puede ver que est&#225;s accediendo a ese sitio. Cuando lo carg&#225;s a trav&#233;s de Tor, tu conexi&#243;n rebota a trav&#233;s de una serie de nodos de la red. El primer nodo conoce tu direcci&#243;n IP real pero no sabe a d&#243;nde te dirig&#237;s, el segundo nodo no sabe nada y el tercero sabe a d&#243;nde vas, pero no conoce tu direcci&#243;n IP real. El sitio final que visit&#225;s solo sabe que llegaste desde Tor&#8221;, explica a 421 <em><a href="https://micahflee.com/about/?ref=421.news">Micah Lee</a></em>, ingeniero en seguridad de la informaci&#243;n y periodista de datos.</p><p>Autor del libro Hacks, Leaks and Revelations (una biblia para todo interesado en dataleaks), Lee recuerda que Tor &#8220;es privado y an&#243;nimo en el sentido de que los sitios que visit&#225;s no pueden conocer tu direcci&#243;n IP, y cualquiera que est&#233; vigilando el tr&#225;fico de internet no puede ver qu&#233; est&#225;s haciendo, m&#225;s all&#225; de que est&#225;s usando Tor&#8221;.</p><p>En Tor, ning&#250;n nodo conoce al mismo tiempo qui&#233;n es el usuario y cu&#225;l es el destino final. Ese dise&#241;o distribuido hace que rastrear el origen real de la conexi&#243;n sea considerablemente m&#225;s complejo. El proyecto surgi&#243; en el Laboratorio de Investigaci&#243;n Naval de Estados Unidos y luego fue desarrollado por la comunidad como una herramienta civil de protecci&#243;n frente a la vigilancia generalizada.</p><p>La soci&#243;loga Shoshana Zuboff describi&#243; el modelo dominante de internet como &#8220;capitalismo de vigilancia&#8221;: una econom&#237;a basada en la extracci&#243;n sistem&#225;tica de datos personales. Tor aparece, en ese mapa, como una tecnolog&#237;a que introduce fricci&#243;n en ese modelo con el que las Big Tech se han hecho m&#225;s grandes que nunca.</p><p>Su expansi&#243;n estuvo ligada a contextos de censura y control estatal. Durante la Primavera &#193;rabe fue una de las herramientas que permiti&#243; sortear bloqueos y acceder a informaci&#243;n. Con el tiempo, grandes medios internacionales como The New York Times, BBC, ProPublica y Deutsche Welle publicaron versiones de sus sitios accesibles como servicios onion, precisamente para lectores que necesitan anonimato.</p><div class="pullquote"><p style="text-align: center;"><em><strong>Espacio publicitario</strong></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://global.fortinet.com/ai-lp-es-ap-ciberamenazas2026" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c9iQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 424w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 848w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg" width="600" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:87226,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://global.fortinet.com/ai-lp-es-ap-ciberamenazas2026&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/183610466?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!c9iQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 424w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 848w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em><strong>Acceder al reporte completo, <a href="https://global.fortinet.com/ai-lp-es-ap-ciberamenazas2026">en este enlace</a></strong></em></p></div><p>Tor no es, bajo ning&#250;n punto de vista, un blindaje a prueba de balas digitales. &#8220;Usar VPN, Tor, ProxyChains y otras herramientas de ese tipo ayuda a quienes las utilizan a ocultar su direcci&#243;n IP y otra informaci&#243;n. Pero existen maneras de que te descubran. &#191;Qu&#233; pasa si hay nodos de Tor comprometidos y no est&#225;s usando una VPN? Quienes controlen esos nodos podr&#237;an obtener tu direcci&#243;n IP&#8221;, dice uno de los hackers consultados para esta nota.</p><p>&#8220;&#191;Qu&#233; pasa si alguien te env&#237;a un archivo a trav&#233;s de qTox [un protocolo p2p] y no est&#225;s usando una VPN? La persona que envi&#243; el archivo puede obtener tu direcci&#243;n IP. Hay varios ejemplos de c&#243;mo se puede conseguir la IP, la geolocalizaci&#243;n y m&#225;s. Todo depende de la opsec [seguridad operacional] de cada persona&#8221;, dice. Es, muchas veces, una sospecha frecuente de quienes corren nodos de Tor (motivo por el cual se desaconseja absolutamente correr un nodo de salida siendo una persona f&#237;sica): que puedan estar intervenidos por fuerzas de seguridad, algo imposible de saber <em>ex ante </em>por la naturaleza an&#243;nima del protocolo.</p><p>&#8220;El anonimato implica mucho m&#225;s que simplemente ocultar tu direcci&#243;n IP. Si inici&#225;s sesi&#243;n en tu cuenta de Gmail a trav&#233;s de Tor, o us&#225;s un nombre de usuario vinculado a tu identidad real, o mencion&#225;s en un chat d&#243;nde creciste, o comet&#233;s cualquiera de una serie de otros descuidos, puede resultar sencillo desanonimizarte. Si quer&#233;s hacer cosas de manera an&#243;nima en internet, Tor puede ser una herramienta importante que te ayude, pero es solo una pieza del rompecabezas. Tambi&#233;n ten&#233;s que hacer todo lo dem&#225;s de manera correcta&#8221;, complementa Lee.</p><p>Esto fundamenta, en gran parte, por qu&#233; a fin de cuentas un proyecto como Tor va m&#225;s all&#225; del uso il&#237;cito: si se proh&#237;be una tecnolog&#237;a como esta, los cibercriminales seguir&#237;an operando por la enorme cantidad de medios que operan en la actualidad, m&#225;s all&#225; de la red onion.</p><p>Hay quienes incluso sostienen que Tor es financiado por el Gobierno de los Estados Unidos porque prefieren que el cibercrimen se concentre en un s&#243;lo lugar en vez de en distintos sitios. Algo discutible si recordamos la cantidad de sitios, protocolos y servicios de mensajer&#237;a que operan con aplicaciones f&#225;cilmente descargables de la web, la App Store de Apple o Google Play (como Telegram).</p><h2><em><strong>Por qu&#233; importa el anonimato en la web</strong></em></h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!n0fc!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9635dc-0bb7-42ae-967e-f8cb755377fa_1307x884.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!n0fc!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9635dc-0bb7-42ae-967e-f8cb755377fa_1307x884.png 424w, https://substackcdn.com/image/fetch/$s_!n0fc!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9635dc-0bb7-42ae-967e-f8cb755377fa_1307x884.png 848w, https://substackcdn.com/image/fetch/$s_!n0fc!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9635dc-0bb7-42ae-967e-f8cb755377fa_1307x884.png 1272w, https://substackcdn.com/image/fetch/$s_!n0fc!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9635dc-0bb7-42ae-967e-f8cb755377fa_1307x884.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!n0fc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9635dc-0bb7-42ae-967e-f8cb755377fa_1307x884.png" width="1307" height="884" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/3f9635dc-0bb7-42ae-967e-f8cb755377fa_1307x884.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:884,&quot;width&quot;:1307,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:977399,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/191998943?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9635dc-0bb7-42ae-967e-f8cb755377fa_1307x884.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!n0fc!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9635dc-0bb7-42ae-967e-f8cb755377fa_1307x884.png 424w, https://substackcdn.com/image/fetch/$s_!n0fc!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9635dc-0bb7-42ae-967e-f8cb755377fa_1307x884.png 848w, https://substackcdn.com/image/fetch/$s_!n0fc!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9635dc-0bb7-42ae-967e-f8cb755377fa_1307x884.png 1272w, https://substackcdn.com/image/fetch/$s_!n0fc!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F3f9635dc-0bb7-42ae-967e-f8cb755377fa_1307x884.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Shutterstock</figcaption></figure></div><p>El anonimato en la web es, en 2026, cada vez m&#225;s complicado. Pero, quiz&#225;s, pocas veces fue tan deseable.</p><p>&#8220;Una de las cosas que me preocupan es la avalancha de leyes de verificaci&#243;n de edad que est&#225;n apareciendo en todo el mundo, y el hecho de que las grandes plataformas corporativas, que concentran una porci&#243;n enorme de las conversaciones online, est&#233;n cumpli&#233;ndolas. Por ejemplo, <em><a href="https://www.brodersendarknews.com/p/discord-verificacion-edad-identidad-online?ref=421.news">Discord pronto exigir&#225; que los usuarios presenten un documento de identidad</a></em> emitido por el gobierno u otros mecanismos para probar qui&#233;nes son y poder acceder a determinadas funciones, y esta tendencia no deja de expandirse&#8221;, dice Lee.</p><p>&#8220;Siempre van a existir formas de comunicarse y publicar informaci&#243;n de manera an&#243;nima, pero puede volverse mucho m&#225;s dif&#237;cil lograr que tu mensaje circule si qued&#225;s excluido de las grandes plataformas. Y con los fascistas firmemente en el poder en Estados Unidos, es prudente que personas de todo el mundo dejen de depender de plataformas estadounidenses, que se pliegan a las demandas de censura de Trump. El panorama se ve sombr&#237;o&#8221;, cierra.</p><p><strong>Roger Dingledine</strong>, fundador de Tor, tambi&#233;n expres&#243; preocupaci&#243;n por la situaci&#243;n actual: el usuario promedio no termina de entender bien bajo qu&#233; modelo funciona la web.</p><p>&#8220;Uno de los grandes desaf&#237;os que seguimos enfrentando en el mundo es si las personas pueden tomar decisiones por s&#237; mismas sobre sus datos, o si esas decisiones deben quedar en manos de las empresas y los gobiernos. Vemos este conflicto en gobiernos autoritarios como Rusia e Ir&#225;n, que intentan censurar internet y bloquear a los usuarios para que no puedan informarse ni expresarse libremente&#8221;, dice Dingledine.</p><p>&#8220;Pero tambi&#233;n lo vemos en lo que sol&#237;an ser democracias tradicionales, donde permitimos que las empresas acumulen poder y dinero espiando a los usuarios, y al mismo tiempo nuestros gobiernos parecen entusiasmados con centralizar el control&#8221;, agrega.</p><p>&#8220;Para m&#237;, la &#250;nica respuesta frente a este capitalismo de vigilancia corporativo y a estas democracias en retroceso es devolver el poder a los ciudadanos. Por eso herramientas descentralizadas como Tor son tan importantes para nuestras libertades, tanto ahora como en el futuro&#8221;, cierra Roger Dingledine en di&#225;logo con 421.</p><p>El primer paso es dejar de decirle Dark Web a un proyecto que, con todos sus contrapuntos, plantea un modelo alternativo al de la vigilancia permanente de Meta, la comercializaci&#243;n de datos de Google y el <strong>peaje inevitable</strong> de identificarse con nombre y documento para participar de la conversaci&#243;n online.</p><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/dark-web-tor-y-el-anonimato-big-tech?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/dark-web-tor-y-el-anonimato-big-tech?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Condenan a Meta y YouTube: qué es el diseño adictivo y por qué el caso va más allá de la “negligencia”]]></title><description><![CDATA[Adem&#225;s: Google cambia titulares de noticias y 7 a&#241;os de prisi&#243;n para un broker de accesos de ransomware.]]></description><link>https://www.brodersendarknews.com/p/condenan-meta-youtube-adictivas</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/condenan-meta-youtube-adictivas</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Fri, 27 Mar 2026 11:03:55 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!mlJy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c33a0fb-dbc6-4f41-a624-3cd443c0d27c_971x646.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><p><strong>&#128467;&#65039; </strong><em><strong>Break: Dark News vuelve a temas de agenda el viernes 10 de abril. El 3 de abril no habr&#225; edici&#243;n.</strong></em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>20<strong>~</strong>27<br>mar</h1><h2><strong>&#9889;TL;DR</strong></h2><p>Meta (Instagram) y YouTube sufrieron esta semana un rev&#233;s judicial que podr&#237;a sentar un precedente para el resto de las plataformas: fueron condenadas por <strong>su dise&#241;o adictivo</strong>.</p><p>El caso, que ven&#237;a ocupando la agenda de las Big Tech y era muy seguido de cerca no s&#243;lo por Silicon Valley sino tambi&#233;n por la sociedad civil, puede abrir la puerta a futuras demandas contra aplicaciones como TikTok. La parte m&#225;s interesante es que aquella <a href="https://www.brodersendarknews.com/p/adictivas-por-diseno-claves-juicio-zuckerberg-meta-youtube">Secci&#243;n 230 de la </a><em><strong><a href="https://www.brodersendarknews.com/p/adictivas-por-diseno-claves-juicio-zuckerberg-meta-youtube">Communications Decency Act</a></strong>, </em>que fue tan importante para los inicios de internet, empieza a tambalearse en un mundo muy distinto al de mediados de los 90.</p><p>&#191;Y por qu&#233; es importante esto? Porque este veredicto trata a las plataformas como <strong><a href="https://www.themediastack.co.uk/p/the-verdict-that-should-make-publishers">sujetas a la ley de responsabilidad por productos</a></strong>, y no como compa&#241;&#237;as de medios protegidas por <strong>inmunidad editorial</strong>, con m&#225;s de 2.000 demandas similares pendientes.</p><p>Habl&#233; con dos especialistas para responder a las preguntas del t&#237;tulo de esta entrega, sobre todo porque fueron consideradas &#8220;negligentes&#8221; en el fallo y esto hace un poco de ruido (no pareciera haber negligencia, sino una decisi&#243;n deliberada de hacerlas adictivas).</p><p>Tambi&#233;n hubo novedades en el frente del hardware en el norte: el ingreso de routers extranjeros (en particular, de China) estar&#225; prohibido en Estados Unidos. Adi&#243;s <strong>TP-Link</strong>, quiz&#225;s de los routers hogare&#241;os m&#225;s populares del mercado.</p><p>En el mundo de la IA, <strong>Microsoft</strong> reconoci&#243; que <a href="https://blogs.windows.com/windows-insider/2026/03/20/our-commitment-to-windows-quality/">se le fue la mano</a> con meter Copilot en todos lados, por lo que van a empezar a quitarlo de diversas herramientas de Windows. Y pasaron mil cosas m&#225;s que ya me cuesta recapitular. Ahora veo a medio mundo decir &#8220;hay que usar <strong>Claude</strong>&#8221;, por ejemplo, en una ola de <em>hype</em> que va dejando <a href="https://thehackernews.com/2026/03/claude-extension-flaw-enabled-zero.html">posibles infecciones</a> a cada paso que damos.</p><p>Otro tema para el que consult&#233; a un especialista fue el cambio de titulares de Google en resultados de b&#250;squeda y Discover, algo que puede sonar menor, pero que es un problema bastante grande no s&#243;lo para la industria de los medios sino tambi&#233;n para diversos sectores sociales y el acceso a la informaci&#243;n. Una ecolog&#237;a de medios saludable es m&#225;s que un producto: es un pilar de la democracia. Meter mano en los t&#237;tulos es, cuanto menos, pol&#233;mico.</p><p>Esta semana pude escuchar un cap&#237;tulo del podcast de Nilay Patel (<strong>Decoder</strong>) que es de lo mejor que escuch&#233; durante el &#250;ltimo tiempo: <em><a href="https://pocketcasts.com/podcast/decoder-with-nilay-patel/01a33f10-fcfe-0132-18b7-059c869cc4eb/confronting-the-ceo-of-the-ai-company-that-impersonated-me/1f918ffa-ea95-48e8-94b1-563a7b656339">Confronting the CEO of the AI company that impersonated me</a></em>. Recomiendo, si tienen un rato, escucharlo completo. Es sobre el caso de Grammarly, que sac&#243; <a href="https://www.bbc.com/news/articles/cx28v08jpe7o">una funci&#243;n que creaba &#8220;notas&#8221; y correcciones</a> de personalidades con un sistema de IA que gener&#243; tanta controversia que fue retirada. Un amigo me recordaba la importancia de que medios de envergadura puedan poner contra las cuerdas a la industria, y no que funcionen como meras c&#225;maras de resonancia de ella.</p><p>Aviso de agenda: el viernes que viene hago un break, pero ese fin de semana voy a reproducir un art&#237;culo nuevo que hice para <strong><a href="https://www.421.news/es/">421</a></strong> con fuentes de lujo.</p><p>La edici&#243;n semanal vuelve el viernes <strong>10 de abril.</strong></p><div><hr></div><p><em>En esta edici&#243;n:</em></p><ul><li><p>&#9878;&#65039; <em><a href="https://www.brodersendarknews.com/i/191877369/condenan-a-meta-y-youtube-que-es-el-diseno-adictivo-y-por-que-el-caso-va-mas-alla-de-la-negligencia">Condenan a Meta y YouTube: qu&#233; es el dise&#241;o adictivo y por qu&#233; el caso va m&#225;s all&#225; de la &#8220;negligencia&#8221;</a></em></p></li><li><p>&#128225; <em><a href="https://www.brodersendarknews.com/i/191877369/estados-unidos-prohibe-los-routers-extranjeros">Estados Unidos proh&#237;be los routers extranjeros</a></em></p></li><li><p>&#128110; <em><a href="https://www.brodersendarknews.com/i/191877369/condenan-a-un-iab-de-yanluowang-ransomware-y-arrestan-al-dueno-de-leakbase">Condenan a un IAB de Yanluowang ransomware y arrestan al due&#241;o de LeakBase</a></em></p></li><li><p>&#9997;&#65039; <em><a href="https://www.brodersendarknews.com/i/191877369/google-cambia-titulares-de-noticias-y-genera-polemica">Google cambia titulares de noticias y genera pol&#233;mica</a></em></p></li><li><p>&#128013; <em><a href="https://www.brodersendarknews.com/i/191877369/comprometen-litellm-en-pypi-y-desatan-otro-supply-chain">Comprometen LiteLLM en PyPI y desatan otro supply chain</a></em></p></li></ul><p>&#9200; <em>Substack dice que leer este correo completo lleva 13 minutos</em></p><p><em>Dark News #194</em></p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://global.fortinet.com/ai-lp-es-ap-ciberamenazas2026" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c9iQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 424w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 848w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg" width="600" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:87226,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://global.fortinet.com/ai-lp-es-ap-ciberamenazas2026&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/183610466?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!c9iQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 424w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 848w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Acceder al reporte completo, <a href="https://global.fortinet.com/ai-lp-es-ap-ciberamenazas2026">en este enlace</a></p></div><h3>Condenan a Meta y YouTube: qu&#233; es el dise&#241;o adictivo y por qu&#233; el caso va m&#225;s all&#225; de la &#8220;negligencia&#8221;</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!mlJy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c33a0fb-dbc6-4f41-a624-3cd443c0d27c_971x646.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!mlJy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c33a0fb-dbc6-4f41-a624-3cd443c0d27c_971x646.png 424w, https://substackcdn.com/image/fetch/$s_!mlJy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c33a0fb-dbc6-4f41-a624-3cd443c0d27c_971x646.png 848w, https://substackcdn.com/image/fetch/$s_!mlJy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c33a0fb-dbc6-4f41-a624-3cd443c0d27c_971x646.png 1272w, https://substackcdn.com/image/fetch/$s_!mlJy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c33a0fb-dbc6-4f41-a624-3cd443c0d27c_971x646.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!mlJy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c33a0fb-dbc6-4f41-a624-3cd443c0d27c_971x646.png" width="971" height="646" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8c33a0fb-dbc6-4f41-a624-3cd443c0d27c_971x646.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:646,&quot;width&quot;:971,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1235241,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/191877369?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c33a0fb-dbc6-4f41-a624-3cd443c0d27c_971x646.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!mlJy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c33a0fb-dbc6-4f41-a624-3cd443c0d27c_971x646.png 424w, https://substackcdn.com/image/fetch/$s_!mlJy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c33a0fb-dbc6-4f41-a624-3cd443c0d27c_971x646.png 848w, https://substackcdn.com/image/fetch/$s_!mlJy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c33a0fb-dbc6-4f41-a624-3cd443c0d27c_971x646.png 1272w, https://substackcdn.com/image/fetch/$s_!mlJy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8c33a0fb-dbc6-4f41-a624-3cd443c0d27c_971x646.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Familiares de v&#237;ctimas de suicidios por adicci&#243;n a las redes sociales. Foto: EFE</figcaption></figure></div><p>Un jurado de Los &#193;ngeles <a href="https://www.clarin.com/tecnologia/historico-fallo-eeuu-condenan-meta-youtube-danar-salud-mental-joven-diseno-adictivo_0_zEsK1fKuVa.html">declar&#243; a Meta y YouTube responsables</a> por haber perjudicado a una menor a trav&#233;s del dise&#241;o &#8220;adictivo&#8221; de Instagram y YouTube. Orden&#243; una indemnizaci&#243;n inicial de <strong>US$ 3 millones</strong>: <strong>US$ 2,1 millones para Meta</strong> y <strong>US$ 900 mil para YouTube</strong>.</p><p><strong>&#8220;Malicia&#8221;.</strong> Adem&#225;s de los da&#241;os compensatorios, el jurado concluy&#243; que hubo <strong>&#8220;malicia, conducta abusiva o fraude&#8221;</strong>, una definici&#243;n que habilita una segunda etapa para fijar <strong>da&#241;os punitivos</strong>. Ese monto podr&#237;a elevar de forma significativa la condena.</p><p><strong>Dark News</strong> contact&#243; a <a href="https://x.com/luisgbx">Luis Garc&#237;a Balcarce</a>, especialista en derechos digitales, que explic&#243;:</p><blockquote><p><em>Por primera vez en la historia, un jurado determin&#243; que el dise&#241;o de una plataforma digital, no su contenido,<strong> constituye un producto defectuoso generador de responsabilidad civil.</strong> Esa distinci&#243;n es fundamental: desplaza el eje del debate desde la libertad de expresi&#243;n hacia la seguridad del producto, y abre una v&#237;a de responsabilidad civil diferente, que en nuestra regi&#243;n se podr&#237;a asociar a la defensa del consumidor.</em></p></blockquote><p><strong>El contexto.</strong> El caso, en el que se habla de <strong>negligencia de las plataformas, </strong>fue elegido como caso testigo dentro de miles de demandas coordinadas en California contra Meta, Google, TikTok y Snap por supuestos <strong>da&#241;os a la salud mental</strong> de menores.</p><p><a href="https://x.com/titayna">Carolina Mart&#237;nez Elebi</a>, licenciada en Ciencias de la Comunicaci&#243;n y docente de la UBA, complementa:</p><blockquote><p><em>Lo central de este caso es que el jurado les atribuye responsabilidad por el dise&#241;o mismo de las plataformas. Lo que se est&#225; diciendo es que Instagram y YouTube no da&#241;an por accidente, sino por c&#243;mo est&#225;n pensadas: mecanismos dise&#241;ados para captar y retener la atenci&#243;n, alineados con un modelo de negocio que depende de eso. Y, adem&#225;s, hay evidencia de que las empresas sab&#237;an que ese dise&#241;o pod&#237;a causar da&#241;o.</em></p></blockquote><p>Adem&#225;s, la autora del sitio <strong><a href="https://www.dhytecno.ar/">DHyTecno</a> plantea una discrepancia </strong>con la idea de que fueron consideradas <strong>&#8220;negligentes&#8221;</strong>:</p><blockquote><p><em>Por eso, a m&#237; no me termina de cerrar que se hable solo de negligencia. La negligencia supone que algo se les escap&#243; o que no advirtieron el riesgo. Pero lo que aparece en este caso es otra cosa: <strong>un dise&#241;o con una intenci&#243;n concreta</strong>, orientado a maximizar la atenci&#243;n, y con se&#241;ales internas de que sab&#237;an que pod&#237;a generar da&#241;o.</em></p></blockquote><p><strong>Defensa.</strong> Meta dijo que discrepa con el veredicto y eval&#250;a sus pr&#243;ximos pasos. Google fue m&#225;s directa: anunci&#243; que <strong>apelar&#225;</strong> y sostuvo que el caso &#8220;malinterpreta&#8221; a YouTube.</p><p><strong>Por qu&#233; importa.</strong> Es un fallo <strong>hist&#243;rico </strong>que cuestiona el scroll infinito, autoplay, notificaciones constantes. </p><p>Para la industria, el mayor riesgo no es el monto inicial, sino que la Justicia empiece a forzar <strong>redise&#241;os profundos</strong> sobre productos cuyo negocio depende de capturar atenci&#243;n.</p><h3>Estados Unidos proh&#237;be los routers extranjeros</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aIv1!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3d402-dd7a-445c-bdde-07d148228288_1072x720.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aIv1!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3d402-dd7a-445c-bdde-07d148228288_1072x720.png 424w, https://substackcdn.com/image/fetch/$s_!aIv1!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3d402-dd7a-445c-bdde-07d148228288_1072x720.png 848w, https://substackcdn.com/image/fetch/$s_!aIv1!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3d402-dd7a-445c-bdde-07d148228288_1072x720.png 1272w, https://substackcdn.com/image/fetch/$s_!aIv1!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3d402-dd7a-445c-bdde-07d148228288_1072x720.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aIv1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3d402-dd7a-445c-bdde-07d148228288_1072x720.png" width="1072" height="720" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c1c3d402-dd7a-445c-bdde-07d148228288_1072x720.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:720,&quot;width&quot;:1072,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1244773,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/191877369?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3d402-dd7a-445c-bdde-07d148228288_1072x720.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aIv1!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3d402-dd7a-445c-bdde-07d148228288_1072x720.png 424w, https://substackcdn.com/image/fetch/$s_!aIv1!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3d402-dd7a-445c-bdde-07d148228288_1072x720.png 848w, https://substackcdn.com/image/fetch/$s_!aIv1!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3d402-dd7a-445c-bdde-07d148228288_1072x720.png 1272w, https://substackcdn.com/image/fetch/$s_!aIv1!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc1c3d402-dd7a-445c-bdde-07d148228288_1072x720.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Reuters</figcaption></figure></div><p>La FCC <a href="https://www.fcc.gov/document/fcc-updates-covered-list-include-foreign-made-consumer-routers">prohibi&#243; la importaci&#243;n de nuevos routers</a> fabricados fuera de Estados Unidos, salvo que sus fabricantes consigan una excepci&#243;n. La medida replica el esquema que ya hab&#237;a aplicado con drones extranjeros y apunta a reducir lo que considera <strong>riesgos para la seguridad nacional</strong>.</p><p><strong>Qu&#233; cambia.</strong> Los routers ya vendidos podr&#225;n seguir us&#225;ndose y los modelos ya aprobados seguir&#225;n entrando. Pero hacia adelante el impacto es fuerte: como casi todos los routers de consumo se fabrican fuera de EE.UU., la decisi&#243;n funciona en la pr&#225;ctica como un freno a nuevos equipos. </p><p><strong>El punto d&#233;bil.</strong> La FCC vincula el riesgo con espionaje y campa&#241;as como Volt, Flax y Salt Typhoon. Pero fabricar localmente no necesariamente resuelve el problema: en ataques recientes tambi&#233;n se explotaron routers de marcas estadounidenses como Cisco y Netgear, muchas veces vulnerables por falta de actualizaciones.</p><p><strong>Qu&#233; significa.</strong> EE.UU. busca relocalizar hardware cr&#237;tico y bajar su dependencia de Asia, aunque eso pueda achicar la oferta y encarecer el mercado de conectividad dom&#233;stica.</p><h3>Condenan a un IAB de Yanluowang ransomware y arrestan al due&#241;o de LeakBase</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!PxEl!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F036aece2-6059-4336-b0cb-56dd83f54646_1188x784.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!PxEl!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F036aece2-6059-4336-b0cb-56dd83f54646_1188x784.png 424w, https://substackcdn.com/image/fetch/$s_!PxEl!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F036aece2-6059-4336-b0cb-56dd83f54646_1188x784.png 848w, https://substackcdn.com/image/fetch/$s_!PxEl!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F036aece2-6059-4336-b0cb-56dd83f54646_1188x784.png 1272w, https://substackcdn.com/image/fetch/$s_!PxEl!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F036aece2-6059-4336-b0cb-56dd83f54646_1188x784.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!PxEl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F036aece2-6059-4336-b0cb-56dd83f54646_1188x784.png" width="1188" height="784" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/036aece2-6059-4336-b0cb-56dd83f54646_1188x784.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:784,&quot;width&quot;:1188,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1652649,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/191877369?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F036aece2-6059-4336-b0cb-56dd83f54646_1188x784.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!PxEl!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F036aece2-6059-4336-b0cb-56dd83f54646_1188x784.png 424w, https://substackcdn.com/image/fetch/$s_!PxEl!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F036aece2-6059-4336-b0cb-56dd83f54646_1188x784.png 848w, https://substackcdn.com/image/fetch/$s_!PxEl!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F036aece2-6059-4336-b0cb-56dd83f54646_1188x784.png 1272w, https://substackcdn.com/image/fetch/$s_!PxEl!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F036aece2-6059-4336-b0cb-56dd83f54646_1188x784.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Shutterstock</figcaption></figure></div><p>Un ciudadano ruso <a href="https://www.bleepingcomputer.com/news/security/yanluowang-ransomware-access-broker-gets-81-months-in-prison/">fue condenado</a> a casi siete a&#241;os de prisi&#243;n en Estados Unidos por actuar como <strong>Initial Access Broker (IAB)</strong>, una pieza clave en la cadena del ransomware: es quien se especializa en comercializar accesos a empresas o gobiernos para desplegar un ataque.</p><p><strong>Qu&#233; pas&#243;.</strong> Aleksey Olegovich Volkov, de 26 a&#241;os, se declar&#243; culpable de hackear redes corporativas entre 2021 y 2022 y vender esos accesos al grupo de ransomware Yanluowang. La justicia estadounidense lo conden&#243; a 81 meses de prisi&#243;n.</p><p><strong>C&#243;mo operaba.</strong> Volkov compromet&#237;a sistemas de empresas (al menos ocho en EE.UU.) y luego revend&#237;a esas credenciales al esquema ransomware-as-a-service del grupo. Los afiliados de Yanluowang cifraban los datos y exig&#237;an rescates de entre 300.000 y 15 millones de d&#243;lares.</p><p><strong>LeakBase.</strong> En otra noticia, Rusia detuvo en la regi&#243;n de Rostov a un sospechoso de ser el due&#241;o y administrador de <strong>LeakBase</strong>, uno de los foros cibercriminales m&#225;s activos para comprar y vender bases robadas, filtraciones, exploits y servicios de hacking. Seg&#250;n la agencia estatal TASS, tambi&#233;n lo acusan de haber creado la plataforma.</p><p><strong>El contexto.</strong> LeakBase apareci&#243; en 2021 con apoyo del grupo ARES y explot&#243; tras la ca&#237;da de <strong>Breached</strong> en marzo de 2023: lleg&#243; a superar los <strong>142.000 usuarios</strong>. Era gratis registrarse y funcionaba como un mercado de datos robados, pero tambi&#233;n alojaba secciones de programaci&#243;n, ingenier&#237;a social, criptograf&#237;a, OPSEC y gu&#237;as para ciberdelincuentes.</p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.austral.edu.ar/ingenieria/ingenieria-posgrados/ciberseguridad/diplomatura-en-gestion-y-estrategia-en-ciberseguridad/?utm_source=ig&amp;utm_medium=social&amp;utm_content=link_in_bio&amp;fbclid=PAdGRleAPBKt9leHRuA2FlbQIxMQBzcnRjBmFwcF9pZA8xMjQwMjQ1NzQyODc0MTQAAadoQCMBONCS0NNAQ-cM0vYYT1IgeTCq-MTTPX48d-Akd4-KtknzEHq9CF07Mg_aem_USxObTUnrQylxYcinDp7Kw" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j0Jh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 424w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 848w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg" width="1200" height="628" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:628,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:481623,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://www.austral.edu.ar/ingenieria/ingenieria-posgrados/ciberseguridad/diplomatura-en-gestion-y-estrategia-en-ciberseguridad/?utm_source=ig&amp;utm_medium=social&amp;utm_content=link_in_bio&amp;fbclid=PAdGRleAPBKt9leHRuA2FlbQIxMQBzcnRjBmFwcF9pZA8xMjQwMjQ1NzQyODc0MTQAAadoQCMBONCS0NNAQ-cM0vYYT1IgeTCq-MTTPX48d-Akd4-KtknzEHq9CF07Mg_aem_USxObTUnrQylxYcinDp7Kw&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/187504152?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!j0Jh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 424w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 848w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></div><div><hr></div><h3>Google cambia titulares de noticias y genera pol&#233;mica</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!p0ZL!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc447601f-d241-4c1c-8475-49f5a7dc5c2f_876x561.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!p0ZL!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc447601f-d241-4c1c-8475-49f5a7dc5c2f_876x561.png 424w, https://substackcdn.com/image/fetch/$s_!p0ZL!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc447601f-d241-4c1c-8475-49f5a7dc5c2f_876x561.png 848w, https://substackcdn.com/image/fetch/$s_!p0ZL!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc447601f-d241-4c1c-8475-49f5a7dc5c2f_876x561.png 1272w, https://substackcdn.com/image/fetch/$s_!p0ZL!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc447601f-d241-4c1c-8475-49f5a7dc5c2f_876x561.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!p0ZL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc447601f-d241-4c1c-8475-49f5a7dc5c2f_876x561.png" width="876" height="561" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/c447601f-d241-4c1c-8475-49f5a7dc5c2f_876x561.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:561,&quot;width&quot;:876,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:591258,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/191877369?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc447601f-d241-4c1c-8475-49f5a7dc5c2f_876x561.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!p0ZL!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc447601f-d241-4c1c-8475-49f5a7dc5c2f_876x561.png 424w, https://substackcdn.com/image/fetch/$s_!p0ZL!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc447601f-d241-4c1c-8475-49f5a7dc5c2f_876x561.png 848w, https://substackcdn.com/image/fetch/$s_!p0ZL!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc447601f-d241-4c1c-8475-49f5a7dc5c2f_876x561.png 1272w, https://substackcdn.com/image/fetch/$s_!p0ZL!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fc447601f-d241-4c1c-8475-49f5a7dc5c2f_876x561.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">AFP</figcaption></figure></div><p>Google empez&#243; a probar en su buscador una funci&#243;n que <a href="https://www.theverge.com/tech/896490/google-replace-news-headlines-in-search-canary-coal-mine-experiment">reemplaza titulares originales de medios</a> por versiones reescritas con IA dentro de los resultados tradicionales de b&#250;squeda. Hasta ahora, el cambio ya hab&#237;a aparecido en Google Discover, pero ahora tambi&#233;n lleg&#243; a los &#8220;10 blue links&#8221;, el formato cl&#225;sico del buscador.</p><p><strong>Qu&#233; cambia.</strong> Google mostr&#243; en varios casos t&#237;tulos que los medios nunca escribieron y que incluso alteran el enfoque editorial de las notas. En uno de los ejemplos de The Verge, <strong><a href="https://archive.is/mN7Yi">una nota cr&#237;tica sobre una herramienta de IA para &#8220;hacer trampa en todo&#8221;</a></strong> (<em>I used the &#8216;cheat on everything&#8217; AI tool and it didn&#8217;t help me cheat on anything</em>) apareci&#243; resumida como si simplemente <strong>promocionara ese producto</strong>. </p><p>Es decir, un t&#237;tulo <strong>exactamente opuesto</strong> al sentido original de la nota.</p><p><strong>Dark News </strong>consult&#243; a <a href="https://x.com/aracalacana">Mart&#237;n Becerra</a>, investigador del Conicet y profesor de la Universidad Nacional de Quilmes y de la Universidad de Buenos Aires, para entender el alcance de este problema:</p><blockquote><p><em>La reescritura de titulares en el buscador y en Discover tiene varias facetas preocupantes: por un lado, la intervenci&#243;n editorial de Google se hace expl&#237;cita, cuando hasta hace poco tiempo trataba de disimularla. En rigor, el propio ordenamiento de los resultados en el cat&#225;logo del buscador ya representa una suerte de acci&#243;n editora. Por otro lado, hay un avance sobre el derecho de autor&#237;a de las empresas period&#237;sticas que, con todo derecho, protestan porque Google altera de modo inconsulto sus contenidos, siendo el t&#237;tulo una pieza fundamental de los mismos.</em> </p></blockquote><p>Esto, advierte, podr&#237;a redundar en un problema a futuro para Google: </p><blockquote><p><em>Cambiar el t&#237;tulo en muchos casos supone cambiar el sentido de lo que los medios editaron. Parece una decisi&#243;n torpe por parte de Google, ya que adem&#225;s de exponerse como editora (y no como mera intermediaria) y de afectar derechos de propiedad intelectual, abre puertas a demandas judiciales por parte de las industrias de medios.</em></p></blockquote><p><strong>Por qu&#233; importa.</strong> El cambio reabre una pelea sensible entre Google y los medios: qui&#233;n controla c&#243;mo se presenta una nota en el principal distribuidor de tr&#225;fico de la web. </p><p>Para las redacciones, modificar titulares puede afectar clics, SEO, estilo editorial y hasta la confianza en la informaci&#243;n si la reescritura cambia el significado. </p><h3>Comprometen LiteLLM en PyPI y desatan otro supply chain</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HwdS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa892ac1b-2172-46d1-ae19-9043553e6ce4_1648x814.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HwdS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa892ac1b-2172-46d1-ae19-9043553e6ce4_1648x814.png 424w, https://substackcdn.com/image/fetch/$s_!HwdS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa892ac1b-2172-46d1-ae19-9043553e6ce4_1648x814.png 848w, https://substackcdn.com/image/fetch/$s_!HwdS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa892ac1b-2172-46d1-ae19-9043553e6ce4_1648x814.png 1272w, https://substackcdn.com/image/fetch/$s_!HwdS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa892ac1b-2172-46d1-ae19-9043553e6ce4_1648x814.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HwdS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa892ac1b-2172-46d1-ae19-9043553e6ce4_1648x814.png" width="1456" height="719" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a892ac1b-2172-46d1-ae19-9043553e6ce4_1648x814.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:719,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:780332,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/191877369?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa892ac1b-2172-46d1-ae19-9043553e6ce4_1648x814.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!HwdS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa892ac1b-2172-46d1-ae19-9043553e6ce4_1648x814.png 424w, https://substackcdn.com/image/fetch/$s_!HwdS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa892ac1b-2172-46d1-ae19-9043553e6ce4_1648x814.png 848w, https://substackcdn.com/image/fetch/$s_!HwdS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa892ac1b-2172-46d1-ae19-9043553e6ce4_1648x814.png 1272w, https://substackcdn.com/image/fetch/$s_!HwdS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa892ac1b-2172-46d1-ae19-9043553e6ce4_1648x814.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Fuente: BleepingComputer</figcaption></figure></div><p>El paquete <strong>LiteLLM</strong> en PyPI, una librer&#237;a muy usada para conectar m&#250;ltiples modelos de IA desde una sola API, <a href="https://labs.boostsecurity.io/articles/teampcp-litellm-supply-chain-compromise/">fue comprometido</a> con dos versiones maliciosas que <strong>robaban credenciales</strong>, tokens de autenticaci&#243;n, secretos de Kubernetes, claves SSH, wallets cripto y archivos <code>.env</code>.</p><p><strong>Supply chain.</strong> El ataque vuelve a pegar en la cadena de suministro de software: detr&#225;s aparece <strong>TeamPCP</strong>, el mismo grupo vinculado al caso <strong>Trivy</strong>, que ya hab&#237;a generado un efecto cascada sobre im&#225;genes de Docker y otros proyectos. </p><p>En este caso, el c&#243;digo malicioso se activaba al importar LiteLLM y, en la versi&#243;n m&#225;s agresiva, quedaba persistente mediante un archivo <code>.pth</code>, capaz de ejecutarse incluso aunque la librer&#237;a ya no se usara directamente.</p><p><strong>Por qu&#233; importa.</strong> LiteLLM tiene una adopci&#243;n masiva en entornos de desarrollo y despliegues de IA. Endor Labs detect&#243; que el malware tambi&#233;n intentaba moverse lateralmente en clusters de Kubernetes y dejar una puerta trasera persistente.</p><p>Circulan reportes de hasta <strong>500 mil dispositivos</strong> afectados o con datos exfiltrados, aunque esa cifra por ahora no fue confirmada de forma independiente.</p><div><hr></div><h4><strong>&#128275; Breaches y hacks</strong></h4><ul><li><p>Breach en <a href="https://www.bleepingcomputer.com/news/security/crunchyroll-probes-breach-after-hacker-claims-to-steal-68m-users-data/">Crunchyroll</a>: roban datos de 6.8 millones de usuarios</p></li><li><p>Breach en <a href="https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/7a57bd2b-9c89-4b3c-8ff9-41f55eea067c.html">HackerOne</a></p></li><li><p>Breach en el Ministerio de Finanzas de <a href="https://www.rijksoverheid.nl/actueel/nieuws/2026/03/23/ministerie-van-financien-onderzoekt-ongeautoriseerde-toegang-tot-systemen">Pa&#237;ses Bajos</a> y la <a href="https://x.com/DailyDarkWeb/status/2036031529525088512?s=20">plataforma chilena</a> Ley del Lobby</p></li></ul><h4><strong>&#128274; Ransomware</strong></h4><ul><li><p><a href="https://www.fostercity.org/community/page/foster-city-services-impacted-cyber-security-breach">Foster City</a>, una ciudad entera de California, comprometida por un ransomware</p></li><li><p>El subte de <a href="https://dysruptionhub.com/la-metro-unauthorized-activity-california/">Los &#193;ngeles</a> sufre un ransomware</p></li><li><p><a href="https://www.halcyon.ai/ransomware-research-reports/pay2key-iranian-linked-ransomware-is-back-back-again">Pay2Key</a>, ransomware iran&#237;, vuelve a estar activo</p></li></ul><h4><strong>&#128163; Exploits y malware</strong></h4><ul><li><p>Aparece una nueva versi&#243;n p&#250;blica para usar <a href="https://techcrunch.com/2026/03/23/someone-has-publicly-leaked-an-exploit-kit-that-can-hack-millions-of-iphones/">DarkSword</a> y hackear iPhone</p></li><li><p><a href="https://thehackernews.com/2026/03/openclaw-ai-agent-flaws-could-enable.html">OpenClaw</a> puede filtrar (m&#225;s) datos v&#237;a prompt injection</p></li><li><p><a href="https://www.elastic.co/security-labs/illuminating-voidlink">VoidLink</a>, framework de malware de Linux</p></li></ul><h4><strong>&#128269; Threat intel y vulnerabilidades</strong></h4><ul><li><p><a href="https://www.crowdstrike.com/en-us/blog/tycoon2fa-phishing-as-a-service-platform-persists-following-takedown/">Tycoon2FA (Phishing-as-a-Service)</a> vuelve a estar online despu&#233;s de un &#8220;takedown&#8221;</p></li><li><p>Bitdefender detecta un incremento de campa&#241;as de <a href="https://www.bitdefender.com/en-gb/blog/hotforsecurity/gulf-countries-phishing-surge">phishing</a> en Medio Oriente</p></li><li><p>Reportes: <a href="https://www.recordedfuture.com/research/2025-year-in-review-malicious-infrastructure">Recorded Future</a>, <a href="https://redcanary.com/blog/threat-intelligence/intelligence-insights-march-2026/">Red Canary</a>, <a href="https://blog.talosintelligence.com/2025yearinreview/">Cisco Talos</a>, <a href="https://cloud.google.com/blog/topics/threat-intelligence/m-trends-2026">Mandiant</a>, <a href="https://www.qualys.com/forms/whitepapers/the-broken-physics-of-remediation">Qualys</a>, <a href="https://www.sophos.com/en-us/blog/2026-ciso-report">Sophos</a>. </p></li></ul><h4><strong>&#128736;&#65039; Tools y updates</strong></h4><ul><li><p>Mozilla lanza <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2026-20/">Firefox 149</a>, con updates de seguridad</p></li><li><p>Nueva plataforma para revisar la seguridad de proyectos <a href="https://zenitysec.github.io/openclaw-security-platform/">OpenClaw</a></p></li><li><p><a href="https://support.apple.com/en-us/100100">Apple</a>, <a href="https://www.tp-link.com/us/press/security-advisory/">TP-Link</a> y <a href="https://sec.cloudapps.cisco.com/security/center/viewErp.x?alertId=ERP-75297">Cisco</a> lanzan actualizaciones de seguridad</p></li></ul><h4><strong>&#128203; Privacidad y regulaciones</strong></h4><ul><li><p><a href="https://bsky.app/profile/grapheneos.org/post/3mhigizd6fc2g">GrapheneOS</a> se niega a implementar verificaci&#243;n de edad</p></li><li><p><a href="https://au.pcmag.com/social-media/116659/reddit-could-soon-require-face-id-to-prove-youre-not-a-bot">Reddit</a> prepara nuevo m&#233;todo de verificaci&#243;n de edad</p></li><li><p><a href="https://www.dexerto.com/entertainment/wikipedia-bans-use-of-ai-to-write-articles-and-updates-3341307/">Wikipedia proh&#237;be</a> herramientas de IA para crear art&#237;culos</p><p></p></li></ul><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/condenan-meta-youtube-adictivas?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/condenan-meta-youtube-adictivas?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Hackeo a Aerolíneas Argentinas: el acusado pidió quedar libre y podría enfrentar hasta 6 años de prisión]]></title><description><![CDATA[Juan Ignacio Veltri est&#225; con preventiva y embargado en una comisar&#237;a porque no hay cupo para trasladarlo a un penal. Investigan una estafa por comprar el equivalente a 500 mil d&#243;lares en pasajes.]]></description><link>https://www.brodersendarknews.com/p/ahora-hackeo-a-aerolineas-argentinas</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/ahora-hackeo-a-aerolineas-argentinas</guid><pubDate>Wed, 25 Mar 2026 14:59:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!AoYt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15119f37-6a41-4075-be7f-68f135680711_1569x857.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>25<br>mar</h1><h2><strong>&#9889; &#250;ltimo momento</strong></h2><p>Publicaci&#243;n en t&#225;ndem con <strong><a href="https://www.clarin.com/tecnologia/hackeo-aerolineas-argentinas-acusado-pidio-quedar-libre-podria-enfrentar-6-anos-prision_0_gptALyrnkN.html">Clar&#237;n</a></strong>.</p><div><hr></div><p>&#9200; <em>Substack dice que leer este correo completo lleva 9 minutos</em></p><p><em>Dark News #193</em></p><h3><strong>El acusado por el hackeo a Aerol&#237;neas pidi&#243; anular su prisi&#243;n preventiva y quedar libre: qu&#233; penas podr&#237;a enfrentar</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!AoYt!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15119f37-6a41-4075-be7f-68f135680711_1569x857.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!AoYt!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15119f37-6a41-4075-be7f-68f135680711_1569x857.jpeg 424w, https://substackcdn.com/image/fetch/$s_!AoYt!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15119f37-6a41-4075-be7f-68f135680711_1569x857.jpeg 848w, https://substackcdn.com/image/fetch/$s_!AoYt!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15119f37-6a41-4075-be7f-68f135680711_1569x857.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!AoYt!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15119f37-6a41-4075-be7f-68f135680711_1569x857.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!AoYt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15119f37-6a41-4075-be7f-68f135680711_1569x857.jpeg" width="1456" height="795" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/15119f37-6a41-4075-be7f-68f135680711_1569x857.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:795,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:244601,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/192091708?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15119f37-6a41-4075-be7f-68f135680711_1569x857.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!AoYt!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15119f37-6a41-4075-be7f-68f135680711_1569x857.jpeg 424w, https://substackcdn.com/image/fetch/$s_!AoYt!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15119f37-6a41-4075-be7f-68f135680711_1569x857.jpeg 848w, https://substackcdn.com/image/fetch/$s_!AoYt!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15119f37-6a41-4075-be7f-68f135680711_1569x857.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!AoYt!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F15119f37-6a41-4075-be7f-68f135680711_1569x857.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Juan Ignacio Veltri. Foto: Instagram</figcaption></figure></div><p>La defensa de <strong><a href="https://www.clarin.com/sociedad/viajes-dubai-operaciones-cueva-acusado-estafa-millas-aerolineas-argentinas_0_1fPidaMFnJ.html">Juan Ignacio Veltri</a></strong>, el joven acusado de haber <a href="https://www.clarin.com/sociedad/cayo-influencer-viajes-estafa-500000-dolares-aerolineas-argentinas-millas-truchas-pasajes-roma-madrid-cancun-disney_0_IgiJdRhM7T.html">manipulado el sistema de millas de Aerol&#237;neas Argentinas para comprar vuelos por valores baj&#237;simos</a>, pidi&#243; este mi&#233;rcoles que se anule la prisi&#243;n preventiva dictada en su contra y<strong> reclam&#243; su inmediata libertad</strong>. En el mismo escrito, al que accedi&#243; <strong>Clar&#237;n</strong>, tambi&#233;n cuestion&#243; la resoluci&#243;n judicial y pidi&#243; que se revise su situaci&#243;n procesal.</p><p>Veltri estuvo una semana con prisi&#243;n <strong>domiciliaria </strong>y, tras la revocaci&#243;n de ese beneficio, fue trasladado a una comisar&#237;a de la Ciudad de Buenos Aires, donde<strong> todav&#237;a sigue porque no hay cupo para derivarlo a un penal</strong>.</p><p>&#8220;Vengo a solicitar se declare la nulidad del mismo y se disponga, consecuentemente, la inmediata libertad de mi defendido&#8221;, escribi&#243; su abogado en una presentaci&#243;n hecha ante el Juzgado Federal N&#176; 7, a cargo de <strong>Sebasti&#225;n Casanello</strong>.</p><p>En el propio recurso, la defensa expone cu&#225;l fue el argumento central que us&#243; el juez para endurecer la situaci&#243;n de Veltri. Seg&#250;n cita el escrito, Casanello consider&#243; que hab&#237;a &#8220;riesgo de entorpecimiento de la investigaci&#243;n&#8221; porque el imputado &#8220;contact&#243; a los testigos para incidir en su declaraci&#243;n&#8221;, y por eso revoc&#243; la prisi&#243;n domiciliaria y avanz&#243; con la prisi&#243;n preventiva.</p><p>En paralelo, la Justicia ya le trab&#243; <strong>un embargo por 910 millones de pesos</strong>, una cifra que la propia defensa us&#243; para argumentar que ya existe una fuerte restricci&#243;n patrimonial. La estrategia busca desarmar esa decisi&#243;n con un planteo de nulidad. Sostiene que la prisi&#243;n preventiva fue dictada de oficio por el juez, sin un pedido expreso de la fiscal&#237;a ni de la querella, algo que, seg&#250;n el escrito, <strong>no est&#225; permitido por el C&#243;digo Procesal Penal Federal</strong>. Adem&#225;s, remarca que la resoluci&#243;n no fij&#243; un plazo concreto para la detenci&#243;n.</p><p>Los abogados de Veltri tambi&#233;n apelaron a la resoluci&#243;n y pidieron que, si no lo liberan,<strong> al menos le restituyan la prisi&#243;n domiciliaria </strong>o le impongan una medida menos gravosa, como una<strong> tobillera electr&#243;nica</strong>. Adem&#225;s, solicit&#243; el sobreseimiento del acusado, al sostener que <strong>no hay pruebas suficientes</strong> para sostener la acusaci&#243;n en su contra.</p><p>Seg&#250;n hab&#237;an contado fuentes de la aerol&#237;nea de bandera, el caso sali&#243; a la luz cuando se detectaron &#8220;maniobras efectuadas sobre el sistema de compra de millas del programa AR&#8239;Plus&#8221; con el objetivo de &#8220;modificar, de forma indebida, el monto a pagar y la cantidad de millas acreditadas&#8221;. Veltri, quien hab&#237;a trabajado para Mercado Libre y la empresa de ciberseguridad local Strike, logr&#243; comprar <strong>un equivalente a 500 mil d&#243;lares</strong> en millas y s&#243;lo pag&#243; <strong>200 mil pesos argentinos</strong>.</p><p>La explotaci&#243;n de la vulnerabilidad fue, dentro del mundo de la seguridad inform&#225;tica, relativamente simple: Veltri alteraba el c&#243;digo fuente de la p&#225;gina al momento de comprar millas y, en lugar de rebotar, <strong>la solicitud era validada por la aerol&#237;nea</strong>.</p><p>Es un tipo de falla m&#225;s com&#250;n de lo que parece, con un antecedente que lleg&#243; a medios de todo el pa&#237;s <a href="https://www.clarin.com/tecnologia/sobreseen-joven-hackeo-valor-dolar-denunciar-fallas-seguridad-informatica-banco-nacion_0_o3w3b2lpp.html">en 2020, cuando un hacker logr&#243; cambiar la cotizaci&#243;n del d&#243;lar en </a><strong><a href="https://www.clarin.com/tecnologia/sobreseen-joven-hackeo-valor-dolar-denunciar-fallas-seguridad-informatica-banco-nacion_0_o3w3b2lpp.html">Banco Naci&#243;n</a> </strong>para comprar divisas a un precio m&#225;s bajo. No por esto no dej&#243; de llamar la atenci&#243;n: es un descuido muy grande para una empresa del tama&#241;o de Aerol&#237;neas Argentinas, catalogado como &#8220;papel&#243;n&#8221; entre fuentes del sector de la ciberseguridad local.</p><p>Por este motivo, <a href="https://www.clarin.com/sociedad/viajes-dubai-operaciones-cueva-acusado-estafa-millas-aerolineas-argentinas_0_1fPidaMFnJ.html">Veltri</a> podr&#237;a enfrentar un escenario con una pena m&#225;xima de hasta seis a&#241;os de prisi&#243;n.</p><h2>&#8220;Manipulaci&#243;n de sistema inform&#225;tico&#8221;, el delito que investiga la Justicia</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!KwT5!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41d048af-6de8-4c05-a0de-c5ac3325e6f9_720x897.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!KwT5!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41d048af-6de8-4c05-a0de-c5ac3325e6f9_720x897.jpeg 424w, https://substackcdn.com/image/fetch/$s_!KwT5!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41d048af-6de8-4c05-a0de-c5ac3325e6f9_720x897.jpeg 848w, https://substackcdn.com/image/fetch/$s_!KwT5!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41d048af-6de8-4c05-a0de-c5ac3325e6f9_720x897.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!KwT5!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41d048af-6de8-4c05-a0de-c5ac3325e6f9_720x897.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!KwT5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41d048af-6de8-4c05-a0de-c5ac3325e6f9_720x897.jpeg" width="720" height="897" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/41d048af-6de8-4c05-a0de-c5ac3325e6f9_720x897.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:897,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Juan Ignacio Veltri, acusado de estafar a Aerol&#237;neas Argentinas. Foto: Instagram (@juanii.veltri)&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Juan Ignacio Veltri, acusado de estafar a Aerol&#237;neas Argentinas. Foto: Instagram (@juanii.veltri)" title="Juan Ignacio Veltri, acusado de estafar a Aerol&#237;neas Argentinas. Foto: Instagram (@juanii.veltri)" srcset="https://substackcdn.com/image/fetch/$s_!KwT5!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41d048af-6de8-4c05-a0de-c5ac3325e6f9_720x897.jpeg 424w, https://substackcdn.com/image/fetch/$s_!KwT5!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41d048af-6de8-4c05-a0de-c5ac3325e6f9_720x897.jpeg 848w, https://substackcdn.com/image/fetch/$s_!KwT5!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41d048af-6de8-4c05-a0de-c5ac3325e6f9_720x897.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!KwT5!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F41d048af-6de8-4c05-a0de-c5ac3325e6f9_720x897.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Juan Ignacio Veltri, acusado de estafar a Aerol&#237;neas Argentinas. Foto: Instagram (@juanii.veltri)</figcaption></figure></div><p>La presunta alteraci&#243;n del sistema ocurri&#243; entre diciembre de 2023 y enero de 2025: <strong>Veltri habr&#237;a tenido m&#225;s de un a&#241;o para abusar del sistema</strong>. La figura que analiza la Justicia es la de<strong> &#8220;manipulaci&#243;n de sistema inform&#225;tico&#8221;</strong>, incorporada al C&#243;digo Penal en 2008 dentro del art&#237;culo 173, inciso 16. Se trata, en t&#233;rminos simples, de un tipo penal pensado para los casos en los que alguien altera o interviene un sistema para obtener un beneficio indebido.</p><p>&#8220;Es el tipo penal pensado para los casos en los que alguien manipula un sistema para obtener un beneficio indebido&#8221;, explica el abogado especialista en delitos inform&#225;ticos Pablo Palazzi. En este caso, la hip&#243;tesis es que se manipularon los sistemas de Aerol&#237;neas para generar o <strong>acreditar millas de forma ficticia </strong>y as&#237; emitir pasajes sin pagar.</p><p>En el expediente, uno de los puntos que m&#225;s complica al acusado es la trazabilidad de las operaciones. Seg&#250;n Palazzi, la prueba aparece como &#8220;bastante obvia&#8221;: los pasajes fueron utilizados sin que exista un pago real, y muchas de las operaciones <strong>quedaron asociadas a su propio nombre, tarjeta de cr&#233;dito y entorno cercano</strong>. Adem&#225;s, hay terceros beneficiados (amigos y familiares, <a href="https://www.lanacion.com.ar/tecnologia/como-hizo-juan-ignacio-veltri-para-comprar-16-millones-de-millas-de-aerolineas-por-200000-pesos-nid12032026/">como public&#243; La Naci&#243;n</a>, que viajaron con esas millas) que tambi&#233;n quedaron registrados, lo que ampl&#237;a el alcance del caso.</p><p>En cuanto a la estrategia de defensa, uno de los argumentos posibles es que todo se debi&#243; a un <strong>error del sistema</strong>. Pero ese planteo tiene un l&#237;mite claro en derecho penal, advierte Palazzi: &#8220;No es una justificaci&#243;n que la p&#225;gina ten&#237;a un error. Si alguien deja la puerta abierta de una concesionaria y yo entro a llevarme un auto, no me exime del dolo, estoy robando un veh&#237;culo&#8221;, resume. &#8220;El punto central es la intenci&#243;n, porque si la persona sab&#237;a que no ten&#237;a derecho a ese beneficio, el aprovechamiento de la falla no lo exime de la culpabilidad&#8221;, sentencia.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Zxs3!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe7b5ef4-f69f-4441-8087-fb26aa53f614_720x438.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Zxs3!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe7b5ef4-f69f-4441-8087-fb26aa53f614_720x438.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Zxs3!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe7b5ef4-f69f-4441-8087-fb26aa53f614_720x438.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Zxs3!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe7b5ef4-f69f-4441-8087-fb26aa53f614_720x438.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Zxs3!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe7b5ef4-f69f-4441-8087-fb26aa53f614_720x438.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Zxs3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe7b5ef4-f69f-4441-8087-fb26aa53f614_720x438.jpeg" width="720" height="438" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/fe7b5ef4-f69f-4441-8087-fb26aa53f614_720x438.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:438,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Aerol&#237;neas Argentinas podr&#237;a tomar acciones para recuperar el dinero. Foto: Marcelo Carroll &quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Aerol&#237;neas Argentinas podr&#237;a tomar acciones para recuperar el dinero. Foto: Marcelo Carroll " title="Aerol&#237;neas Argentinas podr&#237;a tomar acciones para recuperar el dinero. Foto: Marcelo Carroll " srcset="https://substackcdn.com/image/fetch/$s_!Zxs3!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe7b5ef4-f69f-4441-8087-fb26aa53f614_720x438.jpeg 424w, https://substackcdn.com/image/fetch/$s_!Zxs3!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe7b5ef4-f69f-4441-8087-fb26aa53f614_720x438.jpeg 848w, https://substackcdn.com/image/fetch/$s_!Zxs3!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe7b5ef4-f69f-4441-8087-fb26aa53f614_720x438.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!Zxs3!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ffe7b5ef4-f69f-4441-8087-fb26aa53f614_720x438.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Aerol&#237;neas Argentinas podr&#237;a tomar acciones para recuperar el dinero. Foto: Marcelo Carroll</figcaption></figure></div><p>El caso adem&#225;s podr&#237;a abrir un frente civil, porque Aerol&#237;neas Argentinas puede accionar contra la empresa encargada de la seguridad del sistema, llamada Valtech, si considera que hubo fallas de seguridad o negligencia en los est&#225;ndares aplicados. &#8220;Lo que es llamativo no es el error que ten&#237;a el sistema, puesto que muchas empresas tienen estas fallas. Lo realmente incre&#237;ble es que el error estuvo ah&#237; durante m&#225;s de un a&#241;o y no salt&#243; ninguna advertencia interna: <strong>sin vueltas, es una verg&#252;enza total para Aerol&#237;neas Argentinas</strong> porque le cost&#243; medio mill&#243;n de d&#243;lares&#8221;, dijo un hacker consultado por <strong>Clar&#237;n</strong>.</p><p>Veltri podr&#237;a enfrentar, si la causa avanza, <strong>hasta seis a&#241;os de prisi&#243;n</strong>. Sin embargo, en un escenario de primera condena, lo m&#225;s probable ser&#237;a que la pena fuese en suspenso si quedara por debajo de los tres a&#241;os, tal como permite el art&#237;culo 26 del C&#243;digo Penal. Incluso, el caso tiene otro camino posible, que ser&#237;a resolverse mediante una suspensi&#243;n del juicio a prueba (<strong>probation</strong>): no habr&#237;a condena efectiva, pero el imputado deber&#237;a cumplir reglas de conducta durante un per&#237;odo determinado, realizar tareas comunitarias y <strong>ofrecer alguna forma de reparaci&#243;n econ&#243;mica.</strong></p><p>&#8220;Es un pibe joven y sin antecedentes, con lo cual es probable que, a&#250;n condenado, la pena sea leve en los hechos&#8221;, dec&#237;an en los pasillos de Comodoro Py. &#8220;Lo que s&#237;, <strong>se le puede pedir que devuelva el medio mill&#243;n de d&#243;lares</strong> por el cual tuvo los viajes&#8221;, agregaban, en lo que ser&#237;a un escenario muy comprometedor para la econom&#237;a del acusado.</p><p>A nivel jur&#237;dico, la situaci&#243;n en la que est&#225; Veltri tampoco es gratuita. Aunque no terminase en prisi&#243;n, el proceso dejar&#237;a huella: el procesamiento figura en los antecedentes durante a&#241;os y puede tener impacto concreto en la vida personal y laboral. &#8220;Aunque sea un delito no violento, las empresas miran estos antecedentes&#8221;, advierte Palazzi.</p><div class="pullquote"><p style="text-align: center;"><em><strong>Espacio publicitario</strong></em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://global.fortinet.com/ai-lp-es-ap-ciberamenazas2026" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c9iQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 424w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 848w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg" width="600" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:87226,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://global.fortinet.com/ai-lp-es-ap-ciberamenazas2026&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/183610466?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!c9iQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 424w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 848w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p style="text-align: center;"><em><strong>Acceder al reporte completo, <a href="https://global.fortinet.com/ai-lp-es-ap-ciberamenazas2026">en este enlace</a></strong></em></p></div><h2>El otro lado: qu&#233; es y c&#243;mo funciona el &#8220;Bug Bounty&#8221;</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!bPrf!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7472b571-f5bb-478d-807c-6c4ce6c2e996_720x477.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!bPrf!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7472b571-f5bb-478d-807c-6c4ce6c2e996_720x477.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bPrf!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7472b571-f5bb-478d-807c-6c4ce6c2e996_720x477.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bPrf!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7472b571-f5bb-478d-807c-6c4ce6c2e996_720x477.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bPrf!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7472b571-f5bb-478d-807c-6c4ce6c2e996_720x477.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!bPrf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7472b571-f5bb-478d-807c-6c4ce6c2e996_720x477.jpeg" width="720" height="477" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/7472b571-f5bb-478d-807c-6c4ce6c2e996_720x477.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:477,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;HackerOne, una de las plataformas de Bug Bounty m&#225;s conocidas del rubro. Foto: HackerOne&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="HackerOne, una de las plataformas de Bug Bounty m&#225;s conocidas del rubro. Foto: HackerOne" title="HackerOne, una de las plataformas de Bug Bounty m&#225;s conocidas del rubro. Foto: HackerOne" srcset="https://substackcdn.com/image/fetch/$s_!bPrf!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7472b571-f5bb-478d-807c-6c4ce6c2e996_720x477.jpeg 424w, https://substackcdn.com/image/fetch/$s_!bPrf!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7472b571-f5bb-478d-807c-6c4ce6c2e996_720x477.jpeg 848w, https://substackcdn.com/image/fetch/$s_!bPrf!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7472b571-f5bb-478d-807c-6c4ce6c2e996_720x477.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!bPrf!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F7472b571-f5bb-478d-807c-6c4ce6c2e996_720x477.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">HackerOne, una de las plataformas de Bug Bounty m&#225;s conocidas del rubro. Foto: HackerOne</figcaption></figure></div><p>Dentro del mundo del hacking existe una pr&#225;ctica conocida como Bug Bounty: programas oficiales en los que empresas (e incluso gobiernos) pagan a hackers por encontrar y reportar vulnerabilidades. Muchas aerol&#237;neas tienen estos sistemas (United, Lufthansa, LATAM, entre otras) y bonifican a usuarios que les reportan problemas.</p><p>Vale aclarar dos cuestiones: primero, que <strong>Aerol&#237;neas Argentinas no tiene un programa de recompensas </strong>y parte del argumento de Veltri es que el problema ya hab&#237;a sido reportado pero la vulnerabilidad no hab&#237;a sido parcheada.</p><p>Y segundo, que las aerol&#237;neas en general suelen tener m&#225;s problemas de este tipo que los que se cree: <a href="https://www.clarin.com/tecnologia/exponen-vulnerabilidad-sistemas-reservas-pasajes-aereos-riesgos_0_OF5noXBGdD.html">en 2024, dos hackers argentinos mostraron en </a><strong><a href="https://www.clarin.com/tecnologia/exponen-vulnerabilidad-sistemas-reservas-pasajes-aereos-riesgos_0_OF5noXBGdD.html">Ekoparty</a></strong>, la conferencia de hackers m&#225;s grande de Am&#233;rica Latina, <strong>c&#243;mo se pod&#237;an alterar reservas</strong> tan s&#243;lo con el apellido y n&#250;mero de reserva de un pasajero.</p><p>Un hacker argentino, que pidi&#243; no ser identificado, lo resume as&#237;: &#8220;Hace bastantes a&#241;os, el Bug Bounty no exist&#237;a y los hackers no ten&#237;an un marco legal para &#8216;buscar cosas&#8217; si no estaban debidamente contratados por la empresa. El concepto vino a terminar con ese problema&#8221;.</p><p>&#8220;<strong>Lo que hizo este pibe es una guasada</strong>: una vez entr&#233; al sistema de gesti&#243;n de empleados de una aerol&#237;nea y me bonificaron con 500 mil millas. En este caso hablamos de m&#225;s de 16 millones de millas, en perspectiva, es una locura lo que se llev&#243;&#8221;, se&#241;ala, advirtiendo que <strong>&#8220;era obvio que iba a saltar la ficha&#8221;.</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!HX4q!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3976dfe-ea7c-4981-80e6-8685446fe2e8_720x425.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!HX4q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3976dfe-ea7c-4981-80e6-8685446fe2e8_720x425.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HX4q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3976dfe-ea7c-4981-80e6-8685446fe2e8_720x425.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HX4q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3976dfe-ea7c-4981-80e6-8685446fe2e8_720x425.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HX4q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3976dfe-ea7c-4981-80e6-8685446fe2e8_720x425.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!HX4q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3976dfe-ea7c-4981-80e6-8685446fe2e8_720x425.jpeg" width="720" height="425" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/d3976dfe-ea7c-4981-80e6-8685446fe2e8_720x425.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:425,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Ekoparty 2024: exponen vulnerabilidades en diversas aerol&#237;neas. Foto: Mauro Juli&#225;n Fern&#225;ndez&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Ekoparty 2024: exponen vulnerabilidades en diversas aerol&#237;neas. Foto: Mauro Juli&#225;n Fern&#225;ndez" title="Ekoparty 2024: exponen vulnerabilidades en diversas aerol&#237;neas. Foto: Mauro Juli&#225;n Fern&#225;ndez" srcset="https://substackcdn.com/image/fetch/$s_!HX4q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3976dfe-ea7c-4981-80e6-8685446fe2e8_720x425.jpeg 424w, https://substackcdn.com/image/fetch/$s_!HX4q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3976dfe-ea7c-4981-80e6-8685446fe2e8_720x425.jpeg 848w, https://substackcdn.com/image/fetch/$s_!HX4q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3976dfe-ea7c-4981-80e6-8685446fe2e8_720x425.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!HX4q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fd3976dfe-ea7c-4981-80e6-8685446fe2e8_720x425.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Ekoparty 2024: exponen vulnerabilidades en diversas aerol&#237;neas. Foto: Mauro Juli&#225;n Fern&#225;ndez</figcaption></figure></div><p>El especialista tambi&#233;n describe que no todas las compa&#241;&#237;as manejan el tema de la misma manera. Algunas tienen sistemas de recompensas activos mientras que otras solo aceptan reportes sin pagar, bajo esquemas llamados Vulnerability Disclosure Program (VDP). &#8220;<strong>Hay empresas que directamente no pagan. </strong>Eso tambi&#233;n influye en c&#243;mo se mueve la comunidad&#8221;, explica.</p><p>En paralelo, advierte sobre una <strong>zona gris </strong>dentro del propio ecosistema: investigadores que buscan fallas en empresas que no tienen programas activos y luego intentan negociar una recompensa. &#8220;Veo a muchos colegas haciendo eso y estoy totalmente en desacuerdo. Me suena un poco extorsivo&#8221;, plantea.</p><p>Mientras tanto, Veltri no es el &#250;nico investigado sino que hay otros 50 implicados que se habr&#237;an beneficiado de estas operatorias durante m&#225;s de un a&#241;o. Pero el que est&#225; detenido s&#243;lo es &#233;l.</p><p>La causa seguir&#225; con una audiencia para tratar el planteo de nulidad. Despu&#233;s deber&#225; expedirse el fiscal Guillermo Mariju&#225;n sobre la prisi&#243;n preventiva y el procesamiento, y el expediente podr&#237;a ser elevado a la C&#225;mara Federal para que revise la apelaci&#243;n de la defensa.</p><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/ahora-hackeo-a-aerolineas-argentinas?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/ahora-hackeo-a-aerolineas-argentinas?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Telegram: advierten cómo rematan datos del Renaper, domicilios y hasta historiales financieros]]></title><description><![CDATA[La organizaci&#243;n Derechos Digitales investig&#243; el mercado negro de datos personales en Am&#233;rica Latina en la aplicaci&#243;n. Datos biom&#233;tricos, registros m&#233;dicos e historiales financieros, y m&#225;s.]]></description><link>https://www.brodersendarknews.com/p/telegram-advierten-como-rematan-datos</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/telegram-advierten-como-rematan-datos</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Sun, 22 Mar 2026 12:12:38 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!gxuQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6547ea-ee16-41bd-a836-d350297ad09d_1282x865.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>22<br>mar</h1><h2><strong>&#9749; Reportaje</strong></h2><p>El  lunes pasado publiqu&#233; esta nota sobre un reporte nuevo de <strong><a href="https://www.derechosdigitales.org/recursos/identidades-en-venta-el-mercado-ilegal-de-compra-y-venta-de-datos-personales-latinoamericanos-en-telegram/">Derechos Digitales</a></strong> en <a href="https://www.clarin.com/tecnologia/dni-4-dolares-advierten-bots-telegram-rematan-datos-renaper-domicilios-historiales-financieros_0_AGqRvuQT0d.html">Clar&#237;n</a>.</p><p>El tema no es nuevo y ya es conocido, pero tiene datos que sostienen un panorama consolidado: la comercializaci&#243;n de datos personales en Telegram.</p><p>Contact&#233; a la plataforma para ver qu&#233; respuesta dan al informe. Tambi&#233;n a Beatriz Busaniche, de Fundaci&#243;n V&#237;a Libre, para complementar un punto en particular del reporte: el rol de los servicios de inteligencia en relaci&#243;n a la seguridad y el cuidado de los datos de los ciudadanos.</p><p>Reproduzco el art&#237;culo a continuaci&#243;n.</p><div><hr></div><p>&#9200; <em>Substack dice que leer este correo completo lleva 13 minutos</em></p><p><em>Dark News #192</em></p><h3><strong>Tu DNI por menos de 4 d&#243;lares: advierten que bots de Telegram rematan datos del Renaper, domicilios y hasta historiales financieros</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!gxuQ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6547ea-ee16-41bd-a836-d350297ad09d_1282x865.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!gxuQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6547ea-ee16-41bd-a836-d350297ad09d_1282x865.png 424w, https://substackcdn.com/image/fetch/$s_!gxuQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6547ea-ee16-41bd-a836-d350297ad09d_1282x865.png 848w, https://substackcdn.com/image/fetch/$s_!gxuQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6547ea-ee16-41bd-a836-d350297ad09d_1282x865.png 1272w, https://substackcdn.com/image/fetch/$s_!gxuQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6547ea-ee16-41bd-a836-d350297ad09d_1282x865.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!gxuQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6547ea-ee16-41bd-a836-d350297ad09d_1282x865.png" width="1282" height="865" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/db6547ea-ee16-41bd-a836-d350297ad09d_1282x865.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:865,&quot;width&quot;:1282,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1523062,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/191695560?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6547ea-ee16-41bd-a836-d350297ad09d_1282x865.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!gxuQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6547ea-ee16-41bd-a836-d350297ad09d_1282x865.png 424w, https://substackcdn.com/image/fetch/$s_!gxuQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6547ea-ee16-41bd-a836-d350297ad09d_1282x865.png 848w, https://substackcdn.com/image/fetch/$s_!gxuQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6547ea-ee16-41bd-a836-d350297ad09d_1282x865.png 1272w, https://substackcdn.com/image/fetch/$s_!gxuQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdb6547ea-ee16-41bd-a836-d350297ad09d_1282x865.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Shutterstock</figcaption></figure></div><p>Una investigaci&#243;n advierte sobre la <a href="https://www.clarin.com/tecnologia/peligros-filtraciones-datos-termina-informacion-personal-robada-usa_0_JkJ1Uk0cNk.html">comercializaci&#243;n de datos personales</a> en Am&#233;rica Latina a trav&#233;s de <strong>canales y bots de Telegram</strong>. El estudio identifica una tendencia preocupante en <strong>Argentina</strong>, Brasil y Per&#250;, donde brokers de datos aprovechan filtraciones de organismos p&#250;blicos como la del <a href="https://www.clarin.com/tecnologia/publican-base-datos-informacion-renaper-aseguran-65-millones-registros_0_cJeuoq8nv6.html">Renaper</a> para rematar informaci&#243;n personal, el DNI, <strong>por menos de 4 d&#243;lares.</strong></p><p><a href="https://www.derechosdigitales.org/recursos/identidades-en-venta-el-mercado-ilegal-de-compra-y-venta-de-datos-personales-latinoamericanos-en-telegram/">&#8220;Identidades en venta&#8221;</a>, realizado por la organizaci&#243;n <strong>Derechos Digitales</strong> entre 2024 y 2025, identifica un ecosistema automatizado, lo que significa que la venta no suele ser manual sino que se realiza mediante bots que responden consultas. A trav&#233;s de esquemas de pago digitales, que van desde <a href="https://www.clarin.com/tecnologia/vitalik-buterin-piensa-creador-ethereum-seguridad-cripto-destaca-argentina-proximo-salto-ia_0_SUCpMx8R4w.html">cripto</a> hasta <strong>Mercado Pago</strong>, brindan el acceso inmediato a informaci&#243;n de ciudadanos.</p><p>La informaci&#243;n en venta incluye fotos completas del <strong>DNI, de <a href="https://www.clarin.com/tecnologia/peligro-filtracion-licencias-conducir-renaper-delitos-podrian-cometer-datos-registro-dni_0_PTyqsf7guq.html">licencias de conducir</a>, domicilios particulares, historiales financieros, laborales, informaci&#243;n de salud</strong> y hasta v&#237;nculos comerciales. Estos datos son usados luego para cometer distintos tipos de ciberdelitos, desde suplantaci&#243;n de identidad hasta extorsiones.</p><p>&#8220;Los riesgos derivados de este mercado ilegal no son meramente t&#233;cnicos. La disponibilidad y circulaci&#243;n de datos personales en Telegram <strong>ha potenciado formas de violencia</strong>, incluyendo la violencia de g&#233;nero facilitada por tecnolog&#237;as y la exposici&#243;n de ni&#241;as, ni&#241;os y adolescentes. Estos hechos muestran c&#243;mo la explotaci&#243;n de datos se cruza con estructuras de desigualdad y poder preexistentes, convirti&#233;ndose en un mecanismo de control, silenciamiento y revictimizaci&#243;n&#8221;, dice el reporte.</p><p>El estudio advierte que con comandos bastante simples es posible acceder por una suma &#237;nfima a una <strong>radiograf&#237;a total de la v&#237;ctima</strong>: fotos faciales, firmas escaneadas, domicilios geolocalizados, historiales de deuda y v&#237;nculos familiares directos.</p><p>Este ecosistema de &#8220;identidad bajo demanda&#8221; se comercializa a precios marginales, con planes que arrancan en los <strong>3,50 d&#243;lares </strong>y se abonan a trav&#233;s de plataformas comunes como Mercado Pago o criptomonedas, que son m&#225;s efectivas para dificultar la trazabilidad de las transacciones.</p><h2>La situaci&#243;n en Argentina y la respuesta de Telegram</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!XZ4m!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd4c0cd-0b62-447f-ae85-5aa2ec5fa6ce_1175x797.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!XZ4m!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd4c0cd-0b62-447f-ae85-5aa2ec5fa6ce_1175x797.png 424w, https://substackcdn.com/image/fetch/$s_!XZ4m!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd4c0cd-0b62-447f-ae85-5aa2ec5fa6ce_1175x797.png 848w, https://substackcdn.com/image/fetch/$s_!XZ4m!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd4c0cd-0b62-447f-ae85-5aa2ec5fa6ce_1175x797.png 1272w, https://substackcdn.com/image/fetch/$s_!XZ4m!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd4c0cd-0b62-447f-ae85-5aa2ec5fa6ce_1175x797.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!XZ4m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd4c0cd-0b62-447f-ae85-5aa2ec5fa6ce_1175x797.png" width="1175" height="797" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/4fd4c0cd-0b62-447f-ae85-5aa2ec5fa6ce_1175x797.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:797,&quot;width&quot;:1175,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1777631,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/191695560?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd4c0cd-0b62-447f-ae85-5aa2ec5fa6ce_1175x797.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!XZ4m!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd4c0cd-0b62-447f-ae85-5aa2ec5fa6ce_1175x797.png 424w, https://substackcdn.com/image/fetch/$s_!XZ4m!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd4c0cd-0b62-447f-ae85-5aa2ec5fa6ce_1175x797.png 848w, https://substackcdn.com/image/fetch/$s_!XZ4m!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd4c0cd-0b62-447f-ae85-5aa2ec5fa6ce_1175x797.png 1272w, https://substackcdn.com/image/fetch/$s_!XZ4m!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F4fd4c0cd-0b62-447f-ae85-5aa2ec5fa6ce_1175x797.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Shutterstock</figcaption></figure></div><p>Otro tema que el reporte resalta es que se puede <strong>acceder a la situaci&#243;n crediticia de la persona, la &#8220;peor situaci&#243;n&#8221; </strong>registrada, la cantidad de bancos involucrados, el monto total adeudado, el compromiso mensual (relaci&#243;n entre ingresos y deuda), el score crediticio, y su tendencia a lo largo del tiempo. &#8220;En otras palabras, esta secci&#243;n ofrece una radiograf&#237;a clara del comportamiento financiero de la persona&#8221;, dice el reporte. Muchos datos son tomados de <strong>Nosis</strong>, empresa que recolecta estos datos y que <a href="https://argentina.mefiltraron.com/leaks#NOSIS-2024-04-10">sufri&#243; una filtraci&#243;n en 2024</a>.</p><p>En este sentido, el reporte vincula la venta de estos datos con las filtraciones que ocurrieron durante estos a&#241;os en organismos del Estado: incidentes de alto impacto, como la exposici&#243;n de <a href="https://www.clarin.com/tecnologia/publican-115-mil-fotos-ciudadanos-argentinos-robadas-renaper-riesgos-explicacion-gobierno_0_YbsnmMgEew.html">116 mil fotos del </a><strong><a href="https://www.clarin.com/tecnologia/publican-115-mil-fotos-ciudadanos-argentinos-robadas-renaper-riesgos-explicacion-gobierno_0_YbsnmMgEew.html">Renaper</a></strong><a href="https://www.clarin.com/tecnologia/publican-115-mil-fotos-ciudadanos-argentinos-robadas-renaper-riesgos-explicacion-gobierno_0_YbsnmMgEew.html"> en 2021</a>, la filtraci&#243;n masiva del mismo organismo de 2024 que expuso <a href="https://www.clarin.com/tecnologia/publican-base-datos-informacion-renaper-aseguran-65-millones-registros_0_cJeuoq8nv6.html">65 millones de registros</a>, el robo de 6 millones de <a href="https://www.clarin.com/tecnologia/robaron-6-millones-imagenes-licencias-conducir-venden-suben-muestra-registro-javier-milei_0_jYMJpHtuft.html">licencias de conducir</a> y la <a href="https://www.clarin.com/tecnologia/hackeo-pami-ciberdelincuentes-publican-informacion-robada-historias-clinicas-estudios-datos-personales_0_oVEAPipTS0.html">publicaci&#243;n de registros del PAMI</a> operan como indicios respecto de d&#243;nde podr&#237;a salir la informaci&#243;n.</p><p>Si bien es imposible confirmar que la informaci&#243;n sale de estas filtraciones con total certeza, &#8220;<strong>existen coincidencias con los formatos, estructuras</strong> de bases de datos y el tipo de informaci&#243;n que se podr&#237;a esperar que tengan agencias estatales&#8221;, explica a este medio Rafael Bonifaz, L&#237;der del Programa Latinoamericano para la Resiliencia y Defensa Digital, de Derechos Digitales.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!9a_N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b1f78a-4dec-4671-852b-e717e635431a_720x1055.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!9a_N!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b1f78a-4dec-4671-852b-e717e635431a_720x1055.jpeg 424w, https://substackcdn.com/image/fetch/$s_!9a_N!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b1f78a-4dec-4671-852b-e717e635431a_720x1055.jpeg 848w, https://substackcdn.com/image/fetch/$s_!9a_N!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b1f78a-4dec-4671-852b-e717e635431a_720x1055.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!9a_N!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b1f78a-4dec-4671-852b-e717e635431a_720x1055.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!9a_N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b1f78a-4dec-4671-852b-e717e635431a_720x1055.jpeg" width="720" height="1055" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/82b1f78a-4dec-4671-852b-e717e635431a_720x1055.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1055,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Datos en venta: Telegram. Captura: Derechos Digitales&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Datos en venta: Telegram. Captura: Derechos Digitales" title="Datos en venta: Telegram. Captura: Derechos Digitales" srcset="https://substackcdn.com/image/fetch/$s_!9a_N!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b1f78a-4dec-4671-852b-e717e635431a_720x1055.jpeg 424w, https://substackcdn.com/image/fetch/$s_!9a_N!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b1f78a-4dec-4671-852b-e717e635431a_720x1055.jpeg 848w, https://substackcdn.com/image/fetch/$s_!9a_N!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b1f78a-4dec-4671-852b-e717e635431a_720x1055.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!9a_N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F82b1f78a-4dec-4671-852b-e717e635431a_720x1055.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Datos en venta: Telegram. Captura: Derechos Digitales</figcaption></figure></div><p>Advierte el especialista: &#8220;En el caso de la ciudadan&#237;a, es importante saber que sus datos pueden ser accesibles para terceras personas a un costo muy bajo. Con tan solo saber el nombre, el n&#250;mero de DNI o un n&#250;mero de tel&#233;fono se puede obtener informaci&#243;n como residencia, CUIL, historial crediticio, deudas, nombres de familiares y direcci&#243;n completa, que en algunas ocasiones incluye enlaces a Google Maps&#8221;.</p><p>Una de las cuestiones m&#225;s llamativas es lo simple que es acceder a estos bots de Telegram. La empresa, contactada por este medio, dijo que &#8220;<strong>compartir datos privados est&#225; expl&#237;citamente prohibido</strong> por los t&#233;rminos de servicio de Telegram, y dicho contenido se elimina en cuanto se descubre. Moderadores, apoyados con herramientas personalizadas de IA, monitorean proactivamente las secciones p&#250;blicas de la plataforma y aceptan reportes para eliminar millones de contenidos da&#241;inos cada d&#237;a, incluyendo la difusi&#243;n de datos privados&#8221;.</p><p>Adem&#225;s, recordaron que este a&#241;o, &#8220;m&#225;s de 9,5 millones de grupos y canales han sido bloqueados por violar los t&#233;rminos de servicio&#8221; de la plataforma. Sin embargo, es sabido que estos canales <strong>suelen reaparecer</strong> (&#8220;respawnear&#8221;, en la jerga) bajo otros nombres y que los compradores tienen t&#233;cnicas para identificarlos f&#225;cilmente.</p><p>Bonifaz cree que &#8220;es importante exigir mayor transparencia sobre la actividad de las plataformas, por ejemplo mediante la publicaci&#243;n de informes peri&#243;dicos con informaci&#243;n sobre la remoci&#243;n de contenidos il&#237;citos, el cumplimiento de &#243;rdenes judiciales y el funcionamiento de sistemas automatizados, como los bots&#8221;, asegura. Telegram publica peri&#243;dicamente este tipo de reportes.</p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><p><em>Sheriff es la plataforma de inteligencia de amenazas de <a href="http://bca.ltd/">BCA LTD</a> para visualizar incidentes en un solo lugar, organizados y con evidencia adjunta. Sin censura, sin marcas de agua, con acceso directo a las muestras publicadas por actores de amenazas. Para m&#225;s informaci&#243;n, <a href="http://bca.ltd/Sheriff">clic</a> en la imagen.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="http://bca.ltd/Sheriff" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!DuAa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9babf742-7c97-4f60-81cb-fac651b13781_955x581.png 424w, https://substackcdn.com/image/fetch/$s_!DuAa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9babf742-7c97-4f60-81cb-fac651b13781_955x581.png 848w, https://substackcdn.com/image/fetch/$s_!DuAa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9babf742-7c97-4f60-81cb-fac651b13781_955x581.png 1272w, https://substackcdn.com/image/fetch/$s_!DuAa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9babf742-7c97-4f60-81cb-fac651b13781_955x581.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!DuAa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9babf742-7c97-4f60-81cb-fac651b13781_955x581.png" width="955" height="581" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9babf742-7c97-4f60-81cb-fac651b13781_955x581.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:581,&quot;width&quot;:955,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:933538,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://bca.ltd/Sheriff&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/164939887?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9babf742-7c97-4f60-81cb-fac651b13781_955x581.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!DuAa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9babf742-7c97-4f60-81cb-fac651b13781_955x581.png 424w, https://substackcdn.com/image/fetch/$s_!DuAa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9babf742-7c97-4f60-81cb-fac651b13781_955x581.png 848w, https://substackcdn.com/image/fetch/$s_!DuAa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9babf742-7c97-4f60-81cb-fac651b13781_955x581.png 1272w, https://substackcdn.com/image/fetch/$s_!DuAa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9babf742-7c97-4f60-81cb-fac651b13781_955x581.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></div><p>&#8220;Otro punto central es garantizar que plataformas como Telegram dispongan de canales eficaces de denuncia y respuesta r&#225;pida. En el caso de plataformas extranjeras (como Telegram en relaci&#243;n con Argentina), esto implica exigir que designen representantes legales en el pa&#237;s, capaces de responder ante las autoridades&#8221;, cierra Bonifaz.</p><p><strong>Beatriz Busaniche</strong>, de la <a href="https://www.vialibre.org.ar/">Fundaci&#243;n V&#237;a Libre</a>, organismo que desde hace m&#225;s de dos d&#233;cadas y media denuncia la falta de protecci&#243;n a los datos personales en Argentina, advierte en di&#225;logo con <strong>Clar&#237;n</strong>: &#8220;Esto muestra la fragilidad sist&#233;mica del ecosistema de protecci&#243;n de datos en Argentina. <strong>El Estado centraliza informaci&#243;n </strong>que no podemos administrar de forma diferente y no est&#225; bajo una custodia apropiada. La base de la Anses tiene nuestros ingresos y deudas: con solo saber el CUIT de una persona se puede entrar al Banco Central y ver cu&#225;nto consumi&#243; con su tarjeta cada mes. Es informaci&#243;n p&#250;blica que no deber&#237;a serlo&#8221;.</p><p>En 2024, de hecho, la organizaci&#243;n <a href="https://www.clarin.com/tecnologia/filtraciones-datos-personales-demandan-responsabilidad-discuten-ley-vigente_0_2g8DEGGLMa.html">demand&#243; al Estado Nacional</a> por la falta de cuidado de los datos, ante la filtraci&#243;n del Renaper, una de las m&#225;s grandes del pa&#237;s.</p><p>&#8220;Los datos tienen un valor alto en el mercado cuando se ponen en volumen. No tomamos real conciencia de lo que esto significa, no solo por posibles estafas o extorsiones, sino por la privacidad. <strong>Que el Banco Central publique cu&#225;nto gast&#233; de tarjeta me parece una violaci&#243;n total</strong>: no soy una persona p&#250;blica ni deudora. No tiene sentido que el Estado exhiba esos datos. Tenemos un grave problema en todo sentido&#8221;, complementa.</p><h2>La seguridad en manos de la inteligencia estatal</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!QZVF!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F820ad7d3-2c11-4670-82ac-f3340a85b957_707x416.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!QZVF!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F820ad7d3-2c11-4670-82ac-f3340a85b957_707x416.png 424w, https://substackcdn.com/image/fetch/$s_!QZVF!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F820ad7d3-2c11-4670-82ac-f3340a85b957_707x416.png 848w, https://substackcdn.com/image/fetch/$s_!QZVF!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F820ad7d3-2c11-4670-82ac-f3340a85b957_707x416.png 1272w, https://substackcdn.com/image/fetch/$s_!QZVF!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F820ad7d3-2c11-4670-82ac-f3340a85b957_707x416.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!QZVF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F820ad7d3-2c11-4670-82ac-f3340a85b957_707x416.png" width="707" height="416" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/820ad7d3-2c11-4670-82ac-f3340a85b957_707x416.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:416,&quot;width&quot;:707,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:232046,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/191695560?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F820ad7d3-2c11-4670-82ac-f3340a85b957_707x416.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!QZVF!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F820ad7d3-2c11-4670-82ac-f3340a85b957_707x416.png 424w, https://substackcdn.com/image/fetch/$s_!QZVF!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F820ad7d3-2c11-4670-82ac-f3340a85b957_707x416.png 848w, https://substackcdn.com/image/fetch/$s_!QZVF!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F820ad7d3-2c11-4670-82ac-f3340a85b957_707x416.png 1272w, https://substackcdn.com/image/fetch/$s_!QZVF!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F820ad7d3-2c11-4670-82ac-f3340a85b957_707x416.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>El informe de Derechos Digitales va m&#225;s all&#225; de la comercializaci&#243;n de los datos: apunta a la institucionalidad detr&#225;s de esta problem&#225;tica. All&#237; advierte sobre el traspaso de las pol&#237;ticas de ciberseguridad a la &#243;rbita de la <strong>SIDE </strong>(Secretar&#237;a de Inteligencia del Estado) introduce un factor de <strong>opacidad</strong> que dificulta el control democr&#225;tico y la rendici&#243;n de cuentas ante nuevas vulneraciones masivas de privacidad.</p><p>&#8220;A este problema estructural de las cuestiones vinculadas con los datos en poder del Estado, se suma la otra cara que tiene que ver con los organismos de seguridad y los organismos de inteligencia que introducen un factor de opacidad que dificulta el control democr&#225;tico sobre lo que pasa con nuestros datos&#8221;, dice Busaniche.</p><p>&#8220;En el &#250;ltimo decreto sobre servicios de inteligencia, donde se modifican sus funciones, en general se puso mucho foco en haberle atribuido a los empleados de la SIDE la potestad de detener personas sin orden judicial, lo cual es una aberraci&#243;n desde el punto de vista del Estado de derecho&#8221;, sigue.</p><p>Su referencia es al Decreto de Necesidad y Urgencia (DNU) que <a href="https://www.clarin.com/politica/dnu-reforma-side-cambios-dispuso-decreto-2-enero-punto-genero-polemica_0_XsSFLTXQ9m.html">public&#243; el Gobierno de Javier Milei</a> el pasado 2 de enero, donde el Poder Ejecutivo dispuso una reforma integral del sistema de inteligencia, con un art&#237;culo que habilita a personal de inteligencia a &#8220;aprehender&#8221; personas en determinadas circunstancias, como en casos de flagrancia o en el marco de tareas espec&#237;ficas vinculadas a la seguridad nacional.</p><p>&#8220;Pero tambi&#233;n se suma la opacidad creciente en el uso de los servicios de inteligencia, que tiene varias caracter&#237;sticas: la opacidad, la discrecionalidad de los fondos reservados y la falta total de control. Hay que recordar siempre que el &#250;nico &#243;rgano de control que tienen los servicios de inteligencia <strong>es la bicameral</strong>, una comisi&#243;n integrada por senadores y diputados que es la &#250;nica con facultades de hacer control efectivo sobre ellos&#8221;, cierra Busaniche.</p><p>Reportes como el de Derechos Digitales ayudan a aportar transparencia en un ecosistema, por lo general, bastante oscuro.</p><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/telegram-advierten-como-rematan-datos?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/telegram-advierten-como-rematan-datos?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[DarkSword: millones de iPhones pueden hackearse con una nueva herramienta]]></title><description><![CDATA[Adem&#225;s: infostealers dominan la escena, logran hackear Xbox One por primera vez y Adobe acuerda pagar una multa por pr&#225;cticas abusivas con sus clientes.]]></description><link>https://www.brodersendarknews.com/p/darksword-iphone-exploit-in-the-wild</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/darksword-iphone-exploit-in-the-wild</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Fri, 20 Mar 2026 11:00:47 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!Fsm4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f459b0-7cac-42fe-b800-5e76d40345bf_1358x731.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>13<strong>~</strong>20<br>mar</h1><h2><strong>&#9889;TL;DR</strong></h2><p>Esta semana se conoci&#243; un segundo exploit kit para hackear iPhones: <strong>DarkSword</strong>. La novedad, similar a la de hace dos semanas (<a href="https://www.brodersendarknews.com/i/189642562/descubren-un-kit-avanzado-para-hackear-iphone">Coruna</a>), es que la campa&#241;a era parte de un set de herramientas de espionaje estatal y ahora ya se lo ve <em>in the wild </em>apuntando a dispositivos de ciudadanos comunes. </p><p>La noticia es interesante no tanto por la gravedad del exploit (una cadena con 6 fallas y 3 <em>zero days</em>) hay <strong>parche</strong>, de hecho), sino por c&#243;mo hay una &#8220;comoditizaci&#243;n&#8221; de exploits que antes eran de &#233;lite (sobre todo <em>state sponsored</em>) y ahora pasan a estar disponibles para ataques generales.</p><p>Salieron reportes muy interesantes. Los <strong>infostealers</strong> siguen teniendo un protagonismo dominante a pesar de los takedowns del &#250;ltimo tiempo (como Lumma) y otro informe advierte que hay menos beneficio econ&#243;mico en el ransomware pero -parad&#243;jicamente- m&#225;s ataques. Mientras tanto, <a href="https://www.abstract.security/reports/priced-to-move">el mercado de los IAB</a> (<em>initial access brokers</em>) sigue siendo m&#225;s rentable que nunca.</p><p>En RE-Verse, conferencia de hackers de Orlando, <a href="https://www.youtube.com/watch?v=FTFn4UZsA5U">lograron hackear la Xbox One</a>, consola que llevaba 13 a&#241;os impoluta. El jailbreak es un avance para el conservacionismo de los videojuegos.</p><p>En el mundo de las <em>AI wars</em>, la <strong><a href="https://www.theverge.com/ai-artificial-intelligence/895372/encyclopedia-britannica-openai-lawsuit">Encyclopaedia Britannica</a></strong><a href="https://www.theverge.com/ai-artificial-intelligence/895372/encyclopedia-britannica-openai-lawsuit"> demand&#243;</a> a OpenAI porque considera que ChatGPT es una aspiradora de sus contenidos. <a href="https://www.404media.co/ai-job-loss-research-ignores-how-ai-is-utterly-destroying-the-internet/">404Media public&#243;</a> una nota con un foco muy atinado, y es que la IA est&#225; matando a la web tal y como la conoc&#237;amos (<a href="https://x.com/emiliomontilla_/status/2033877369425924551">as&#237;</a>). Y <strong><a href="https://www.reuters.com/technology/microsoft-weighs-legal-action-over-50-billion-amazon-openai-cloud-deal-ft-2026-03-18/?utm_source=chatgpt.com">Microsoft</a></strong><a href="https://www.reuters.com/technology/microsoft-weighs-legal-action-over-50-billion-amazon-openai-cloud-deal-ft-2026-03-18/?utm_source=chatgpt.com"> eval&#250;a llevar a juicio</a> a <strong>Amazon</strong> y <strong>OpenAI</strong> por el acuerdo que hicieron por m&#225;s de 50 mil millones de d&#243;lares.</p><p>Cierro compartiendo una herramienta que desarroll&#243; el especialista en seguridad ofensiva Braian Arroyo para tratar de reportar esquemas de phishing: <strong><a href="https://s4abuse.com/">S4 Abuse</a></strong>. &#8220;La propuesta es acercar una herramienta donde cualquiera pueda verificar se&#241;ales de fraude digital y tambi&#233;n reportarlas para ayudar a otros. Muchas veces esas se&#241;ales ya fueron utilizadas en otros fraudes, pero la informaci&#243;n est&#225; en distintas fuentes y no es f&#225;cil acceder a ella&#8221;, explic&#243; a <strong>Dark News</strong>.</p><p>Justo esta semana le&#237; <a href="https://ma.tt/2026/03/gone-almost-phishin/">este posteo de Matt Mullenweg</a>, CEO de Automattic y creador de WordPress (donde corre gran parte de la web), que cont&#243; en primera persona c&#243;mo casi cae en un phishing.</p><p>Todav&#237;a hay gente que cree que s&#243;lo aquellos con pocas luces son los que caen en este tipo de enga&#241;os.</p><div><hr></div><p><em>En esta edici&#243;n:</em></p><ul><li><p>&#9876;&#65039; <em><a href="https://www.brodersendarknews.com/i/191186094/darksword-descubren-un-segundo-kit-para-explotar-iphones-en-menos-de-un-mes">DarkSword: descubren un segundo kit para explotar iPhones en menos de un mes</a></em></p></li><li><p>&#129706; <em><a href="https://www.brodersendarknews.com/i/191186094/infostealers-a-pesar-de-los-takedowns-dominan-la-puerta-de-entrada-a-los-ataques">Infostealers: a pesar de los takedowns, dominan la puerta de entrada a los ataques</a></em></p></li><li><p>&#128272; <em><a href="https://www.brodersendarknews.com/i/191186094/otro-reporte-advierte-que-hay-mas-ransomware-pero-menos-rentabilidad">Otro reporte advierte que hay m&#225;s ransomware pero menos rentabilidad</a></em></p></li><li><p>&#127918; <em><a href="https://www.brodersendarknews.com/i/191186094/logran-hackear-xbox-one-despues-de-13-anos-de-intentos">Logran hackear Xbox One despu&#233;s de 13 a&#241;os de intentos</a></em></p></li><li><p>&#9878;&#65039; <em><a href="https://www.brodersendarknews.com/i/191186094/adobe-acuerda-75-millones-de-multa-por-cobrar-por-cancelar-suscripciones">Adobe acuerda: 75 millones de multa por cobrar por cancelar suscripciones</a></em></p></li><li><p>&#9889; <em><a href="https://www.brodersendarknews.com/i/191186094/interrumpen-cuatro-botnets-usadas-en-ciberataques-record">Interrumpen cuatro botnets usadas en ciberataques r&#233;cord</a></em></p></li></ul><p>&#9200; <em>Substack dice que leer este correo completo lleva 13 minutos</em></p><p><em>Dark News #191</em></p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://global.fortinet.com/ai-lp-es-ap-ciberamenazas2026" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c9iQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 424w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 848w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg" width="600" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:87226,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://global.fortinet.com/ai-lp-es-ap-ciberamenazas2026&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/183610466?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!c9iQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 424w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 848w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Acceder al reporte completo, <a href="https://global.fortinet.com/ai-lp-es-ap-ciberamenazas2026">en este enlace</a></p></div><h3>DarkSword: descubren un segundo kit para explotar iPhones en menos de un mes</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Fsm4!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f459b0-7cac-42fe-b800-5e76d40345bf_1358x731.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Fsm4!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f459b0-7cac-42fe-b800-5e76d40345bf_1358x731.png 424w, https://substackcdn.com/image/fetch/$s_!Fsm4!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f459b0-7cac-42fe-b800-5e76d40345bf_1358x731.png 848w, https://substackcdn.com/image/fetch/$s_!Fsm4!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f459b0-7cac-42fe-b800-5e76d40345bf_1358x731.png 1272w, https://substackcdn.com/image/fetch/$s_!Fsm4!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f459b0-7cac-42fe-b800-5e76d40345bf_1358x731.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Fsm4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f459b0-7cac-42fe-b800-5e76d40345bf_1358x731.png" width="1358" height="731" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a1f459b0-7cac-42fe-b800-5e76d40345bf_1358x731.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:731,&quot;width&quot;:1358,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1223946,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/191186094?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f459b0-7cac-42fe-b800-5e76d40345bf_1358x731.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Fsm4!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f459b0-7cac-42fe-b800-5e76d40345bf_1358x731.png 424w, https://substackcdn.com/image/fetch/$s_!Fsm4!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f459b0-7cac-42fe-b800-5e76d40345bf_1358x731.png 848w, https://substackcdn.com/image/fetch/$s_!Fsm4!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f459b0-7cac-42fe-b800-5e76d40345bf_1358x731.png 1272w, https://substackcdn.com/image/fetch/$s_!Fsm4!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa1f459b0-7cac-42fe-b800-5e76d40345bf_1358x731.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Bloomberg - Edici&#243;n con Nano Banana (IA)</figcaption></figure></div><p>Un nuevo exploit kit para iPhone, <strong>DarkSword</strong>, fue detectado en ataques reales desde al menos noviembre de 2025 para robar datos sensibles. </p><p>Desarrollado como una herramienta de espionaje estatal, la cadena de ataque circula ya <em>in the wild. </em>Lo reportaron <strong><a href="https://cloud.google.com/blog/topics/threat-intelligence/darksword-ios-exploit-chain">Google Threat Intelligence Group</a></strong> (GTIG), <strong><a href="https://iverify.io/blog/darksword-ios-exploit-kit-explained">iVerify</a></strong> y <strong><a href="https://www.lookout.com/threat-intelligence/article/darksword">Lookout</a></strong>.</p><p><strong>Qui&#233;nes lo usan.</strong> La herramienta circula entre m&#250;ltiples actores: vendors de vigilancia comercial y grupos con apoyo estatal. Se vio en campa&#241;as en Arabia Saudita, Turqu&#237;a, Malasia y Ucrania. </p><p>Un grupo vinculado a Rusia, UNC6353, lo habr&#237;a usado contra usuarios ucranianos.</p><p><strong>Por qu&#233; importa.</strong> Es el segundo kit de exploits para iOS que aparece en pocas semanas, despu&#233;s de <strong><a href="https://www.brodersendarknews.com/i/189642562/descubren-un-kit-avanzado-para-hackear-iphone">Coruna</a></strong>. Marca una tendencia: exploits avanzados, antes exclusivos de agencias, ahora circulan en un mercado secundario y llegan a actores con menos capacidades.</p><p><strong>C&#243;mo funciona.</strong> DarkSword es una cadena completa de exploits que se activa cuando la v&#237;ctima visita una <strong>web comprometida</strong> desde Safari. Un iframe malicioso carga JavaScript que perfila el dispositivo y, si es vulnerable, dispara el ataque.</p><p><strong>El payload.</strong> Despliega un infostealer (GHOSTBLADE) que recolecta datos masivos: credenciales, mails, archivos de iCloud, SMS, contactos, historial de navegaci&#243;n, fotos, datos de apps como Notas y Salud, y mensajes de WhatsApp y Telegram, entre otros.</p><p><strong>Modo operativo.</strong> A diferencia de spyware cl&#225;sico, no busca persistencia. Es <strong>&#8220;hit-and-run&#8221;</strong>: exfiltra datos en segundos o minutos y luego limpia rastros para reducir la detecci&#243;n.</p><p><strong>A qui&#233;n afecta.</strong> Apunta a iPhones con iOS entre 18.4 y 18.7 (con foco fino en 18.4&#8211;18.6.2), aunque el c&#243;digo sugiere que fue adaptado desde versiones previas que atacaban iOS 17.</p><h3>Infostealers: a pesar de los takedowns, dominan la puerta de entrada a los ataques</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Y1YZ!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c91845f-7b2e-42d3-b103-9ca4380eadf3_1111x612.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Y1YZ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c91845f-7b2e-42d3-b103-9ca4380eadf3_1111x612.png 424w, https://substackcdn.com/image/fetch/$s_!Y1YZ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c91845f-7b2e-42d3-b103-9ca4380eadf3_1111x612.png 848w, https://substackcdn.com/image/fetch/$s_!Y1YZ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c91845f-7b2e-42d3-b103-9ca4380eadf3_1111x612.png 1272w, https://substackcdn.com/image/fetch/$s_!Y1YZ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c91845f-7b2e-42d3-b103-9ca4380eadf3_1111x612.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Y1YZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c91845f-7b2e-42d3-b103-9ca4380eadf3_1111x612.png" width="1111" height="612" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9c91845f-7b2e-42d3-b103-9ca4380eadf3_1111x612.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:612,&quot;width&quot;:1111,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:312266,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/191186094?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c91845f-7b2e-42d3-b103-9ca4380eadf3_1111x612.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Y1YZ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c91845f-7b2e-42d3-b103-9ca4380eadf3_1111x612.png 424w, https://substackcdn.com/image/fetch/$s_!Y1YZ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c91845f-7b2e-42d3-b103-9ca4380eadf3_1111x612.png 848w, https://substackcdn.com/image/fetch/$s_!Y1YZ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c91845f-7b2e-42d3-b103-9ca4380eadf3_1111x612.png 1272w, https://substackcdn.com/image/fetch/$s_!Y1YZ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9c91845f-7b2e-42d3-b103-9ca4380eadf3_1111x612.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>El nuevo <em><a href="https://www.recordedfuture.com/blog/identity-trend-report-march-blog">Identity Threat Landscape Report 2025</a></em> de Recorded Future confirma que el robo de credenciales es hoy la principal puerta de entrada a ataques corporativos. </p><p>Solo en 2025 se detectaron vol&#250;menes masivos: <strong>1.950 millones de credenciales expuestas</strong> en listas de malware por <strong>infostealers</strong>, 892 millones en logs y decenas de millones m&#225;s en bases filtradas.</p><p><strong>Por qu&#233; importa.</strong> En la segunda mitad del a&#241;o se detectaron 50% m&#225;s de credenciales que en la primera, y en el &#250;ltimo trimestre el salto fue del 90% respecto al inicio del a&#241;o. La econom&#237;a del robo de datos est&#225; creciendo r&#225;pido y de forma sostenida.</p><p><strong>El dato clave.</strong> El 63,2% de los accesos filtrados con URLs identificables apuntan a sistemas de autenticaci&#243;n. Tambi&#233;n aparecen herramientas cr&#237;ticas: <strong>VPN</strong>, plataformas <strong>cloud</strong>, software de monitoreo y hasta sistemas de detecci&#243;n. </p><p><strong>MFA.</strong> Uno de los hallazgos m&#225;s relevantes: 276 millones de credenciales robadas inclu&#237;an cookies de sesi&#243;n activas (31% del total). Eso permite a los atacantes saltear la autenticaci&#243;n multifactor sin necesidad de contrase&#241;a ni c&#243;digo.</p><p><strong>El ecosistema.</strong> El mercado de infostealers funciona como un sistema din&#225;mico. LummaC2 fue la amenaza dominante del a&#241;o, operando como malware-as-a-service. Aunque fuerzas de seguridad <a href="https://www.brodersendarknews.com/i/163950557/lumma-stealer-operativo-da-de-baja-dominios-pero-sigue-activo">desactivaron m&#225;s de 2.300 dominios en mayo</a>, el malware sigui&#243; activo migrando a infraestructuras m&#225;s resistentes.</p><p><strong>Dark News</strong> contact&#243; a <a href="https://x.com/g0njxa">g0njxa</a>, investigador que sigue de cerca la escena de los infostealers:</p><blockquote><p><em>Los operadores de Lumma Stealer <strong>continuaron vivos</strong> en comunidades privadas y cerradas despu&#233;s de los operativos disruptivos de las fuerzas del orden. </em></p><p><em>Afiliados seleccionados por los operadores fueron provistos de un panel para continuar con capacidad de generar nuevos binarios y controlar el flujo de v&#237;ctimas y sus respectivos logs generados. Asimismo, el infostealer continu&#243; recibiendo actualizaciones y un continuo desarrollo.</em></p></blockquote><p><strong>Efecto domin&#243;.</strong> Cada ca&#237;da genera reemplazos. Tras operativos contra familias como RedLine y Lumma, otras como <a href="https://www.brodersendarknews.com/p/rhadamanthys-infostealer-operation-endgame?utm_source=publication-search">Rhadamanthys</a>, Vidar y StealC absorbieron la demanda. Tambi&#233;n crecen operaciones privadas m&#225;s dif&#237;ciles de rastrear, como Acreed u Odyssey Stealer.</p><h3>Otro reporte advierte que hay m&#225;s ransomware pero menos rentabilidad</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!xygO!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1daad296-2206-42e8-8cea-8143cc377fd1_1087x878.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!xygO!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1daad296-2206-42e8-8cea-8143cc377fd1_1087x878.png 424w, https://substackcdn.com/image/fetch/$s_!xygO!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1daad296-2206-42e8-8cea-8143cc377fd1_1087x878.png 848w, https://substackcdn.com/image/fetch/$s_!xygO!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1daad296-2206-42e8-8cea-8143cc377fd1_1087x878.png 1272w, https://substackcdn.com/image/fetch/$s_!xygO!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1daad296-2206-42e8-8cea-8143cc377fd1_1087x878.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!xygO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1daad296-2206-42e8-8cea-8143cc377fd1_1087x878.png" width="1087" height="878" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/1daad296-2206-42e8-8cea-8143cc377fd1_1087x878.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:878,&quot;width&quot;:1087,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:189799,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/191186094?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1daad296-2206-42e8-8cea-8143cc377fd1_1087x878.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!xygO!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1daad296-2206-42e8-8cea-8143cc377fd1_1087x878.png 424w, https://substackcdn.com/image/fetch/$s_!xygO!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1daad296-2206-42e8-8cea-8143cc377fd1_1087x878.png 848w, https://substackcdn.com/image/fetch/$s_!xygO!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1daad296-2206-42e8-8cea-8143cc377fd1_1087x878.png 1272w, https://substackcdn.com/image/fetch/$s_!xygO!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F1daad296-2206-42e8-8cea-8143cc377fd1_1087x878.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Distribuci&#243;n de cepas. Fuente: Google</figcaption></figure></div><p></p><p>Un nuevo <a href="https://cloud.google.com/blog/topics/threat-intelligence/ransomware-ttps-shifting-threat-landscape/">reporte de Google Threat Intelligence Group</a>, basado en incidentes investigados por Mandiant, detecta que la rentabilidad del ransomware ya es menor, incluso mientras crece el n&#250;mero de v&#237;ctimas.</p><p><strong>Qu&#233; pas&#243;.</strong> Desde 2018, cuando muchos actores financieros migraron al ransomware como modelo principal, el ecosistema se profesionaliz&#243; con el esquema de <strong>Ransomware-as-a-Service (RaaS)</strong>. Eso baj&#243; la barrera de entrada y multiplic&#243; las operaciones. Pero en 2025 aparecieron se&#241;ales de cambio: menos pagos, montos m&#225;s bajos y m&#225;s dificultades para monetizar ataques.</p><p><strong>Por qu&#233; importa.</strong> El ransomware sigue generando disrupciones cr&#237;ticas, pero ya no es tan rentable como antes.</p><p><strong>Los datos:</strong></p><ul><li><p>En un tercio de los incidentes, el acceso inicial se logr&#243; explotando vulnerabilidades, sobre todo en VPNs y firewalls.</p></li><li><p>El 77% de las intrusiones incluy&#243; robo de datos, contra 57% en 2024.</p></li><li><p>El 43% de los ataques apunt&#243; a infraestructura de virtualizaci&#243;n, en alza desde el 29% del a&#241;o anterior.</p></li><li><p>REDBIKE fue la familia m&#225;s usada, con el 30% de los casos analizados.</p></li></ul><p><strong>El reemplazo.</strong> Nuevos y viejos grupos como Qilin y Akira crecieron y empujaron un r&#233;cord de v&#237;ctimas publicadas en sitios de filtraci&#243;n de datos (DLS) en 2025.</p><h3>Logran hackear Xbox One despu&#233;s de 13 a&#241;os de intentos</h3><div id="youtube2-FTFn4UZsA5U" class="youtube-wrap" data-attrs="{&quot;videoId&quot;:&quot;FTFn4UZsA5U&quot;,&quot;startTime&quot;:null,&quot;endTime&quot;:null}" data-component-name="Youtube2ToDOM"><div class="youtube-inner"><iframe src="https://www.youtube-nocookie.com/embed/FTFn4UZsA5U?rel=0&amp;autoplay=0&amp;showinfo=0&amp;enablejsapi=0" frameborder="0" loading="lazy" gesture="media" allow="autoplay; fullscreen" allowautoplay="true" allowfullscreen="true" width="728" height="409"></iframe></div></div><p>Una consola que llevaba 13 a&#241;os sin ser hackeada finalmente cay&#243;: <strong>Xbox One</strong> fue jailbreakeada por primera vez con un m&#233;todo llamado &#8220;Bliss&#8221;, presentado en la conferencia RE//verse 2026.</p><p><strong>El hallazgo.</strong> El investigador Markus Gaasedelen mostr&#243; un <em>voltage glitching</em> que permite <strong>ejecutar c&#243;digo no firmado</strong> en todos los niveles del sistema, algo que hasta ahora no se hab&#237;a logrado en esta consola lanzada en 2013.</p><p><strong>C&#243;mo funciona.</strong> A diferencia del cl&#225;sico Reset Glitch Hack (RGH) de la Xbox 360, este exploit aplica dos microcortes de voltaje extremadamente precisos sobre la CPU. Esos glitches permiten saltear mecanismos clave de seguridad, como la configuraci&#243;n de protecci&#243;n de memoria en el procesador ARM y validaciones durante la carga del sistema.</p><p><strong>Por qu&#233; importa.</strong> El ataque impacta directamente sobre la boot ROM en silicio, lo que lo vuelve, en la pr&#225;ctica, imposible de parchear por software. Eso implica un compromiso total del sistema: <strong>desde el hypervisor hasta el sistema operativo</strong>.</p><p><strong>El contexto.</strong> Durante a&#241;os, Microsoft defendi&#243; a la Xbox One como uno de sus productos m&#225;s seguros. A diferencia de generaciones anteriores, nunca hab&#237;a sido vulnerada p&#250;blicamente, lo que la convirti&#243; en una rareza dentro del mundo del hacking de consolas.</p><p><strong>Preservaci&#243;n digital.</strong> El avance podr&#237;a impulsar la preservaci&#243;n digital y la emulaci&#243;n de juegos, adem&#225;s de mods y una nueva ola de investigaci&#243;n sobre hardware que se cre&#237;a cerrado.</p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.austral.edu.ar/ingenieria/ingenieria-posgrados/ciberseguridad/diplomatura-en-gestion-y-estrategia-en-ciberseguridad/?utm_source=ig&amp;utm_medium=social&amp;utm_content=link_in_bio&amp;fbclid=PAdGRleAPBKt9leHRuA2FlbQIxMQBzcnRjBmFwcF9pZA8xMjQwMjQ1NzQyODc0MTQAAadoQCMBONCS0NNAQ-cM0vYYT1IgeTCq-MTTPX48d-Akd4-KtknzEHq9CF07Mg_aem_USxObTUnrQylxYcinDp7Kw" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j0Jh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 424w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 848w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg" width="1200" height="628" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:628,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:481623,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://www.austral.edu.ar/ingenieria/ingenieria-posgrados/ciberseguridad/diplomatura-en-gestion-y-estrategia-en-ciberseguridad/?utm_source=ig&amp;utm_medium=social&amp;utm_content=link_in_bio&amp;fbclid=PAdGRleAPBKt9leHRuA2FlbQIxMQBzcnRjBmFwcF9pZA8xMjQwMjQ1NzQyODc0MTQAAadoQCMBONCS0NNAQ-cM0vYYT1IgeTCq-MTTPX48d-Akd4-KtknzEHq9CF07Mg_aem_USxObTUnrQylxYcinDp7Kw&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/187504152?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!j0Jh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 424w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 848w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></div><div><hr></div><h3><strong>Adobe acuerda: 75 millones de multa por cobrar por cancelar suscripciones</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sG5k!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb439a960-d27f-424c-8900-f6aa0084d4e9_1428x837.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sG5k!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb439a960-d27f-424c-8900-f6aa0084d4e9_1428x837.png 424w, https://substackcdn.com/image/fetch/$s_!sG5k!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb439a960-d27f-424c-8900-f6aa0084d4e9_1428x837.png 848w, https://substackcdn.com/image/fetch/$s_!sG5k!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb439a960-d27f-424c-8900-f6aa0084d4e9_1428x837.png 1272w, https://substackcdn.com/image/fetch/$s_!sG5k!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb439a960-d27f-424c-8900-f6aa0084d4e9_1428x837.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sG5k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb439a960-d27f-424c-8900-f6aa0084d4e9_1428x837.png" width="1428" height="837" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b439a960-d27f-424c-8900-f6aa0084d4e9_1428x837.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:837,&quot;width&quot;:1428,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:650143,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/191186094?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb439a960-d27f-424c-8900-f6aa0084d4e9_1428x837.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sG5k!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb439a960-d27f-424c-8900-f6aa0084d4e9_1428x837.png 424w, https://substackcdn.com/image/fetch/$s_!sG5k!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb439a960-d27f-424c-8900-f6aa0084d4e9_1428x837.png 848w, https://substackcdn.com/image/fetch/$s_!sG5k!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb439a960-d27f-424c-8900-f6aa0084d4e9_1428x837.png 1272w, https://substackcdn.com/image/fetch/$s_!sG5k!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb439a960-d27f-424c-8900-f6aa0084d4e9_1428x837.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Bloomberg</figcaption></figure></div><p>Adobe <a href="https://www.justice.gov/opa/pr/adobe-agrees-150-million-settlement-and-injunction-resolve-alleged-violations-restore-online">acord&#243;</a> cerrar una demanda del Departamento de Justicia de EE.UU. por sus pr&#225;cticas de cancelaci&#243;n en Creative Cloud. Pagar&#225; una multa de US$75 millones y promete compensaciones en servicios para usuarios afectados.</p><p><strong>El eje.</strong> La causa apuntaba a <strong>cargos de cancelaci&#243;n ocultos</strong> en suscripciones anuales. Adobe cobraba hasta el 50% del per&#237;odo restante si el usuario cancelaba antes de tiempo, con costos que pod&#237;an escalar a cientos de d&#243;lares.</p><p><strong>Qu&#233; cuestion&#243; el Gobierno.</strong> El Department of Justice acus&#243; a la empresa de esconder esos cargos en letra chica o detr&#225;s de links, y de dificultar la baja con procesos engorrosos. La denuncia se apoy&#243; en la Restore Online Shoppers&#8217; Confidence Act, que regula pr&#225;cticas enga&#241;osas en servicios online.</p><p><strong>Qu&#233; dice Adobe.</strong> La compa&#241;&#237;a sostuvo que &#8220;no hubo irregularidades&#8221;, pero que prefiere cerrar el caso. Tambi&#233;n afirma que ya hizo cambios para hacer m&#225;s transparentes los cargos al momento de contratar.</p><p><strong>Por qu&#233; importa.</strong> Es uno de los casos m&#225;s visibles contra el modelo de suscripciones con <strong>&#8220;trabas de salida&#8221;</strong>. </p><h3>Interrumpen cuatro botnets usadas en ciberataques r&#233;cord</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!MWKh!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa29d733f-686b-4d77-af3b-b910b4e5050c_1295x873.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!MWKh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa29d733f-686b-4d77-af3b-b910b4e5050c_1295x873.png 424w, https://substackcdn.com/image/fetch/$s_!MWKh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa29d733f-686b-4d77-af3b-b910b4e5050c_1295x873.png 848w, https://substackcdn.com/image/fetch/$s_!MWKh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa29d733f-686b-4d77-af3b-b910b4e5050c_1295x873.png 1272w, https://substackcdn.com/image/fetch/$s_!MWKh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa29d733f-686b-4d77-af3b-b910b4e5050c_1295x873.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!MWKh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa29d733f-686b-4d77-af3b-b910b4e5050c_1295x873.png" width="1295" height="873" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a29d733f-686b-4d77-af3b-b910b4e5050c_1295x873.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:873,&quot;width&quot;:1295,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1828148,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/191186094?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa29d733f-686b-4d77-af3b-b910b4e5050c_1295x873.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!MWKh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa29d733f-686b-4d77-af3b-b910b4e5050c_1295x873.png 424w, https://substackcdn.com/image/fetch/$s_!MWKh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa29d733f-686b-4d77-af3b-b910b4e5050c_1295x873.png 848w, https://substackcdn.com/image/fetch/$s_!MWKh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa29d733f-686b-4d77-af3b-b910b4e5050c_1295x873.png 1272w, https://substackcdn.com/image/fetch/$s_!MWKh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa29d733f-686b-4d77-af3b-b910b4e5050c_1295x873.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Reuters</figcaption></figure></div><p>EE.UU. interrumpi&#243; las operaciones de cuatro botnets usadas para ciberataques r&#233;cord: <strong>Aisuru, Kimwolf, JackSkid y Mossad</strong>. En conjunto controlaban m&#225;s de 3 millones de dispositivos comprometidos.</p><p><strong>Qu&#233; pas&#243;.</strong> El Departamento de Justicia, junto a una unidad del Departamento de Defensa, tom&#243; control de los servidores que operaban estas botnets. No hubo detenciones confirmadas.</p><p><strong>Por qu&#233; importa.</strong> Aisuru y Kimwolf protagonizaron algunos de los mayores ataques DDoS registrados. En noviembre lanzaron uno de m&#225;s de <strong>30 Tbps</strong>, casi triplicando el r&#233;cord previo, capaz de tumbar servicios online e infraestructura cr&#237;tica.</p><p><strong>C&#243;mo operaban.</strong> Infectaban dispositivos conectados (desde DVRs y c&#225;maras hasta smart TVs Android) y alquilaban su capacidad como &#8220;booter services&#8221; para otros actores criminales.</p><p><strong>El dato.</strong> Todas derivan de <strong>Mirai</strong>, el malware IoT que desde 2016 sigue siendo la base de nuevas botnets cada vez m&#225;s sofisticadas.</p><div><hr></div><h4><strong>&#128275; Breaches y hacks</strong></h4><ul><li><p>Filtran el c&#243;digo fuente del sitio de <a href="https://darkwebinformer.com/full-source-code-of-swedens-e-government-platform-leaked-from-compromised-cgi-sverige-infrastructure/">Gobierno de Suecia</a></p></li><li><p>Roban datos de casi 900 empleados de <a href="https://www.maine.gov/agviewer/content/ag/985235c7-cb95-4be2-8792-a1252b4f8318/585e41ad-c38b-407c-8ce8-1f281d570d97.html">Starbucks</a></p></li><li><p><a href="https://www.bleepingcomputer.com/news/security/aura-confirms-data-breach-exposing-900-000-marketing-contacts/">Aura confirma</a> un data breach que impacta en 900 mil empleados</p></li></ul><h4><strong>&#128274; Ransomware</strong></h4><ul><li><p>Nuevos grupos: <a href="https://www.bleepingcomputer.com/news/security/england-hockey-investigating-ransomware-data-breach/">AiLock</a> y <a href="https://www.derp.ca/research/payload-ransomware-babuk-derivative/">Payload</a></p></li><li><p>Reporte t&#233;cnico sobre <a href="https://www.group-ib.com/blog/hastalamuerte-gentlemen-raas-ttps/">The Gentlemen</a>: Group-IB</p></li><li><p><a href="https://aws.amazon.com/blogs/security/amazon-threat-intelligence-teams-identify-interlock-ransomware-campaign-targeting-enterprise-firewalls/">Interlock Ransomware</a> explot&#243; un zero day de Cisco durante un mes</p></li></ul><h4><strong>&#128163; Exploits y malware</strong></h4><ul><li><p>Una nueva <a href="https://github.com/deepfield/public-research/blob/main/katana/report.md">botnet IoT</a> infecta m&#225;s de 30 mil dispositivos Android TV</p></li><li><p>Nuevo troyano bancario apunta a Brasil: <a href="https://securelist.com/gopix-banking-trojan/119173/">GoPix</a></p></li><li><p><a href="https://www.bleepingcomputer.com/news/security/glassworm-malware-hits-400-plus-code-repos-on-github-npm-vscode-openvsx/">GlassWorm</a> afecta m&#225;s de 400 repositorios en GitHub</p></li></ul><h4><strong>&#128269; Threat intel y vulnerabilidades</strong></h4><ul><li><p>B&#233;lgica publica una base de datos de <a href="https://www.politie.be/5998/nl/nieuws/nieuw-overheidsprotocol-moet-belgische-internetgebruikers-beter-beschermen-tegen">sitios de phishing</a> para bloquearlos</p></li><li><p>Meta <a href="https://transparency.meta.com/sr/first-half-2026-Adversarial-threat-report/">suspendi&#243;</a> miles de cuentas en Facebook e Instagram vinculadas a carteles de droga</p></li><li><p>Reportes: <a href="https://www.akamai.com/newsroom/press-release/ai-transformation-at-risk-apis-emerge-as-the-primary-attack-surface-akamai-research-finds">Akamai</a>, <a href="https://www.recordedfuture.com/blog/identity-trend-report-march-blog">Recorded Future</a>, <a href="https://cloud.google.com/blog/topics/threat-intelligence/ransomware-ttps-shifting-threat-landscape/">Google</a>, <a href="https://www.levelblue.com/newsroom/press-releases/levelblue-research-finds-rising-cyber-threats-driving-us-government-and-higher-education-leaders-to-prioritize-cyber-resilience">LevelBlue</a>, <a href="https://redcanary.com/blog/threat-detection/2026-threat-detection-report/">Red Canary</a>. </p></li></ul><h4><strong>&#128736;&#65039; Tools y updates</strong></h4><ul><li><p>Demuestran c&#243;mo abrir <a href="https://x.com/it4sec/status/2034708449926304148">puertas de penitenciar&#237;as</a> remotamente</p></li><li><p>Amazon lanza una herramienta para prevenir el &#8220;<a href="https://aws.amazon.com/blogs/aws/introducing-account-regional-namespaces-for-amazon-s3-general-purpose-buckets/">bucketsquatting</a>&#8221;</p></li><li><p><a href="https://github.com/NVIDIA/NemoClaw">NemoClaw</a>, nueva tool para correr agentes de OpenClaw de manera segura</p></li></ul><h4><strong>&#128203; Privacidad y regulaciones</strong></h4><ul><li><p><a href="https://help.instagram.com/491565145294150">Instagram desactiva</a> el cifrado end-to-end en mensajes directos</p></li><li><p>Un usuario de Reddit trackea qui&#233;n est&#225; detr&#225;s del lobby de Meta para la <a href="https://www.yahoo.com/news/articles/reddit-user-uncovers-behind-meta-154717384.html">verificaci&#243;n de edad</a></p></li><li><p>Once gigantes tech se comprometen a <a href="https://blog.google/innovation-and-ai/technology/safety-security/google-industry-accord-combat-scams-fraud/">compartir TTPs</a></p><p></p></li></ul><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/darksword-iphone-exploit-in-the-wild?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/darksword-iphone-exploit-in-the-wild?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Brasil: Lula quiere prohibir los casinos online]]></title><description><![CDATA[Adem&#225;s: un hacker comprometi&#243; los archivos de Epstein, apareci&#243; un nuevo troyano bancario y detectaron una campa&#241;a de estafas en Facebook.]]></description><link>https://www.brodersendarknews.com/p/brasil-lula-quiere-prohibir-los-casinos-online-apps-apuestas</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/brasil-lula-quiere-prohibir-los-casinos-online-apps-apuestas</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Fri, 13 Mar 2026 11:00:06 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!WFry!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43bc0538-2359-4310-8f9b-51e8250225e3_1092x728.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>06<strong>~</strong>13<br>mar</h1><h2><strong>&#9889;TL;DR</strong></h2><p>El presidente de Brasil, <strong>Luiz In&#225;cio Lula da Silva</strong>, pidi&#243; prohibir los casinos online. El tema de la adicci&#243;n a las aplicaciones de apuestas es algo que viene desde hace por lo menos una d&#233;cada y es parte de una constelaci&#243;n de problemas: exceso de pantallas, uso excesivo de redes sociales y hasta las loot boxes de los videojuegos (que justo esta semana <a href="https://www.eurogamer.net/pegi-video-game-age-rating-changes-europe">se discutieron en Europa</a> para regular sus calificaciones).</p><p>En el &#225;mbito del cibercrimen, hubo una disrupci&#243;n importante contra la red proxy <strong><a href="https://www.theregister.com/2026/03/12/socksescort_fraud_proxy_taken_down_fbi/">SocksEscort</a></strong>, usada para comprometer routers y se supo que un hacker <a href="https://www.reuters.com/world/us/foreign-hacker-2023-compromised-epstein-files-held-by-fbi-source-documents-show-2026-03-11/">comprometi&#243;</a> los archivos de Epstein del FBI en 2023. Y una investigaci&#243;n detect&#243; una alarmante cifra de <a href="https://www.bitdefender.com/en-us/blog/labs/global-investment-scam-network-using-meta-ads">campa&#241;as fraudulentas</a> que usaron Facebook y marcas de medios para enga&#241;ar usuarios.</p><p>Por el lado m&#225;s t&#233;cnico, sali&#243; <a href="https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026">un reporte</a> de Google que explica que la explotaci&#243;n de fallas en software ya supera al robo de credenciales como puerta de entrada en los hackeos. Y apareci&#243; un nuevo troyano bancario en Brasil, <strong>BeatBanker</strong>, que seguro se vea pronto por el resto de Am&#233;rica Latina.</p><p>En el mundo de las <em>AI wars</em>, Microsoft se puso <a href="https://www.nytimes.com/2026/03/11/business/dealbook/microsoft-anthropic-pentagon.html">del lado de Anthropic</a> en su batalla contra el Pent&#225;gono y Meta <a href="https://cnnespanol.cnn.com/2026/03/11/ciencia/meta-moltbook-bots-redes-sociales-trax">compr&#243; </a><strong><a href="https://cnnespanol.cnn.com/2026/03/11/ciencia/meta-moltbook-bots-redes-sociales-trax">Moltbook</a></strong>, la red social de agentes de IA que <a href="https://www.brodersendarknews.com/p/moltbook-riesgos-vibe-coding">hizo mucho ruido</a> el mes pasado. La sociedad de autores del Reino Unido lanz&#243; una iniciativa para <a href="https://www.theguardian.com/technology/2026/mar/10/uk-society-authors-logo-identify-books-written-by-humans-not-ai">identificar libros</a> escritos con IA. Gartner arroj&#243; un dato clave: la mitad de los proyectos de GenAI en empresas fueron <a href="https://x.com/gartner_inc/status/2031718056720765362?s=46&amp;t=irLyryAdJlqZG0t2F4iu_g">abandonados</a> en la etapa del PoC.</p><p>Dos art&#237;culos que le&#237; esta semana que me parecieron demoledores. Uno de <strong>The Verge</strong> sobre c&#243;mo miles de profesionales son contratados para entrenar a las IAs que, m&#225;s tarde, terminan reemplaz&#225;ndolos. <strong><a href="https://www.theverge.com/cs/features/877388/white-collar-workers-training-ai-mercor?view_token=eyJhbGciOiJIUzI1NiJ9.eyJpZCI6ImxOMDRVWUFVQVkiLCJwIjoiL2NzL2ZlYXR1cmVzLzg3NzM4OC93aGl0ZS1jb2xsYXItd29ya2Vycy10cmFpbmluZy1haS1tZXJjb3IiLCJleHAiOjE3NzM2OTMxOTIsImlhdCI6MTc3MzI2MTE5M30.EiVf99-Cm3ZsWVtmne5sn6tkfTba7PU_-C7mibP17IA&amp;utm_medium=gift-link">&#8220;Me est&#225;n dando la pala para cavar mi propia tumba&#8221;</a></strong>. Y esta de empleados de Amazon que dicen que la IA est&#225; generando m&#225;s vigilancia, &#8220;slop&#8221; e, incluso, <strong><a href="https://www.theguardian.com/technology/ng-interactive/2026/mar/11/amazon-artificial-intelligence">&#8220;m&#225;s trabajo para todos&#8221;</a></strong>.</p><p>Trato de filtrar un poco el tema IA para que <strong>Dark News</strong> no sea IA News, pero realmente pasa mucho, muy r&#225;pido y lo que comparto es porque creo que aporta alg&#250;n <em>insight</em>.</p><p>La perlita, <a href="https://www.lanacion.com.ar/tecnologia/como-hizo-juan-ignacio-veltri-para-comprar-16-millones-de-millas-de-aerolineas-por-200000-pesos-nid12032026/">esta nota de Sebasti&#225;n Davidovsky</a>, que reconstruy&#243; c&#243;mo fue que <a href="https://www.infobae.com/judiciales/2026/03/03/la-justicia-detuvo-un-hombre-acusado-de-estafar-a-aerolineas-argentinas-por-casi-medio-millon-de-dolares-con-el-programa-de-millas/">el estafador de Aerol&#237;neas Argentinas</a> viaj&#243; por el mundo con el fraude por el que hoy est&#225; en prisi&#243;n domiciliaria.</p><p>El juzgado federal de Sebasti&#225;n Casanello tiene que definir su situaci&#243;n procesal.</p><div><hr></div><p><em>En esta edici&#243;n:</em></p><ul><li><p>&#127920; <em><a href="https://www.brodersendarknews.com/i/190385998/brasil-lula-pide-prohibir-los-casinos-online">Brasil: Lula pide prohibir los casinos online</a></em></p></li><li><p>&#9729; <em><a href="https://www.brodersendarknews.com/i/190385998/hackeos-en-la-nube-explotar-fallas-de-software-ya-supera-al-robo-de-credenciales">Hackeos en la nube: explotar fallas de software ya supera al robo de credenciales</a></em></p></li><li><p>&#128110;&#8205;&#9792;&#65039; <em><a href="https://www.brodersendarknews.com/i/190385998/un-hacker-comprometio-los-archivos-epstein-del-fbi-en-2023">Un hacker comprometi&#243; los archivos Epstein del FBI en 2023</a></em></p></li><li><p>&#129440; <em><a href="https://www.brodersendarknews.com/i/190385998/nuevo-troyano-bancario-apunta-a-brasil-beatbanker">Nuevo troyano bancario apunta a Brasil: BeatBanker</a></em></p></li><li><p>&#128226;<em> <a href="https://www.brodersendarknews.com/i/190385998/detectan-310-campanas-que-usaron-anuncios-en-facebook-para-estafas-en-todo-el-mundo">Detectan 310 campa&#241;as que usaron anuncios en Facebook para estafas en todo el mundo</a></em></p></li></ul><p>&#9200; <em>Substack dice que leer este correo completo lleva 13 minutos</em></p><p><em>Dark News #190</em></p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://global.fortinet.com/ai-lp-es-ap-ciberamenazas2026" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!c9iQ!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 424w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 848w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg" width="600" height="300" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:300,&quot;width&quot;:600,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:87226,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://global.fortinet.com/ai-lp-es-ap-ciberamenazas2026&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/183610466?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!c9iQ!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 424w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 848w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!c9iQ!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8680910c-72a7-47c0-aac2-df0aea0410c0_600x300.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Acceder al reporte completo, <a href="https://global.fortinet.com/ai-lp-es-ap-ciberamenazas2026">en este enlace</a></p></div><h3>Brasil: Lula pide prohibir los casinos online</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!WFry!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43bc0538-2359-4310-8f9b-51e8250225e3_1092x728.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!WFry!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43bc0538-2359-4310-8f9b-51e8250225e3_1092x728.png 424w, https://substackcdn.com/image/fetch/$s_!WFry!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43bc0538-2359-4310-8f9b-51e8250225e3_1092x728.png 848w, https://substackcdn.com/image/fetch/$s_!WFry!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43bc0538-2359-4310-8f9b-51e8250225e3_1092x728.png 1272w, https://substackcdn.com/image/fetch/$s_!WFry!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43bc0538-2359-4310-8f9b-51e8250225e3_1092x728.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!WFry!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43bc0538-2359-4310-8f9b-51e8250225e3_1092x728.png" width="1092" height="728" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/43bc0538-2359-4310-8f9b-51e8250225e3_1092x728.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:728,&quot;width&quot;:1092,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1210697,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/190385998?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43bc0538-2359-4310-8f9b-51e8250225e3_1092x728.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!WFry!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43bc0538-2359-4310-8f9b-51e8250225e3_1092x728.png 424w, https://substackcdn.com/image/fetch/$s_!WFry!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43bc0538-2359-4310-8f9b-51e8250225e3_1092x728.png 848w, https://substackcdn.com/image/fetch/$s_!WFry!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43bc0538-2359-4310-8f9b-51e8250225e3_1092x728.png 1272w, https://substackcdn.com/image/fetch/$s_!WFry!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F43bc0538-2359-4310-8f9b-51e8250225e3_1092x728.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Reuters</figcaption></figure></div><p>El presidente de Brasil, Luiz In&#225;cio Lula da Silva, <strong>pidi&#243; <a href="https://es-us.noticias.yahoo.com/acaba-celular-casino-lula-silva-013148760.html?guccounter=1&amp;guce_referrer=aHR0cHM6Ly93d3cuZ29vZ2xlLmNvbS8&amp;guce_referrer_sig=AQAAAIOOHi9yW5WEiVp7A9wolr7bcXH-wycf2XszgwL1ESlIpW3MttUBAM_x-s5Gwp7o8nhrnFkUn9-3_J6qPlvYn3NeMyF4aJu-Bp4mNgzu9qAVa-BJIKLkuV6Jdc-uF17h7rJ7dOx1rqlOih0dA_8-QnNY0s7FoHJce5U_Gze-LKKK">prohibir los casinos online</a> en Brasil</strong> durante <a href="https://www.youtube.com/watch?v=c6LoBuuCZu0">un mensaje nacional</a> por el D&#237;a Internacional de la Mujer, el domingo pasado.</p><p><strong>Qu&#233; pas&#243;.</strong> En un discurso televisado de casi seis minutos emitido el s&#225;bado, Lula <strong>vincul&#243; la ludopat&#237;a con problemas econ&#243;micos</strong> en los hogares brasile&#241;os y sostuvo que, aunque la mayor&#237;a de los jugadores problem&#225;ticos son hombres, las consecuencias recaen desproporcionadamente sobre las mujeres. </p><p>&#8220;Es dinero para comida, alquiler o la escuela de los chicos que desaparece en la pantalla del celular&#8221;, asegur&#243;.</p><p><strong>El foco.</strong> El presidente mencion&#243; especialmente a los casinos digitales populares en el pa&#237;s, como el llamado <strong>&#8220;Jogo do Tigrinho&#8221;</strong>, y plante&#243; que no tiene sentido permitir que juegos de azar entren al hogar a trav&#233;s del tel&#233;fono cuando los casinos f&#237;sicos est&#225;n prohibidos en Brasil. </p><p>Tambi&#233;n adelant&#243; que el gobierno buscar&#225; coordinar con <strong>el Congreso y el Poder Judicial</strong> medidas para frenar ese tipo de plataformas.</p><p><strong>Contexto.</strong> Brasil aprob&#243; a fines de 2023 un <strong>marco legal</strong> para regular las apuestas online, impulsado por el Ministerio de Hacienda de Fernando Haddad. La idea original era &#8220;ordenar&#8221; el mercado de apuestas deportivas, que ya operaba sin regulaci&#243;n. Durante el debate parlamentario, sin embargo, la C&#225;mara de Diputados ampli&#243; el proyecto para incluir tambi&#233;n juegos de casino online.</p><p><strong>Idas y vueltas.</strong> El Senado intent&#243; limitar la ley &#250;nicamente a las apuestas deportivas, pero los diputados reinstalaron la cl&#225;usula que habilitaba los casinos digitales antes de la votaci&#243;n final. Lula promulg&#243; la norma en diciembre de 2023 sin vetar ese punto, lo que permiti&#243; el <strong>funcionamiento legal</strong> de operadores de apuestas deportivas y plataformas de casino bajo regulaci&#243;n. El sistema comenz&#243; a regir en enero de 2025.</p><p><strong>Caso local.</strong> En Argentina, la Defensor&#237;a del Pueblo (Ciudad de Buenos Aires) public&#243; <a href="https://www.calameo.com/defensoriacaba/read/0026823995351db5eca45">un estudio en 2024</a> sobre el impacto en los ciudadanos, en particular chicos y adolescentes, de las apuestas online. </p><p><strong>Dark News </strong>contact&#243; a Monserrat Neme, Subdirectora de observaci&#243;n de las pol&#237;ticas para el desarrollo humano de la entidad, y parte del equipo que elabor&#243; el informe:</p><blockquote><p><em>Las apuestas online ya est&#225;n dentro del ecosistema digital de los y las adolescentes. Nuestro informe muestra que muchos pueden acceder a estas plataformas con muy pocos controles efectivos, lo que expone a menores a din&#225;micas de juego que deber&#237;an estar restringidas para adultos. Esto va en consonancia con decisiones recientes del propio Estado: en 2024 se habilit&#243; que chicos desde los 13 a&#241;os puedan invertir en el mercado de capitales, una se&#241;al clara de la creciente financiarizaci&#243;n de las adolescencias.</em></p></blockquote><h3>Hackeos en la nube: explotar fallas de software ya supera al robo de credenciales</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!sn48!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339c7fe4-1ec1-45e1-9e11-c3faa541fcd8_1208x726.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!sn48!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339c7fe4-1ec1-45e1-9e11-c3faa541fcd8_1208x726.png 424w, https://substackcdn.com/image/fetch/$s_!sn48!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339c7fe4-1ec1-45e1-9e11-c3faa541fcd8_1208x726.png 848w, https://substackcdn.com/image/fetch/$s_!sn48!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339c7fe4-1ec1-45e1-9e11-c3faa541fcd8_1208x726.png 1272w, https://substackcdn.com/image/fetch/$s_!sn48!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339c7fe4-1ec1-45e1-9e11-c3faa541fcd8_1208x726.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!sn48!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339c7fe4-1ec1-45e1-9e11-c3faa541fcd8_1208x726.png" width="1208" height="726" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/339c7fe4-1ec1-45e1-9e11-c3faa541fcd8_1208x726.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:726,&quot;width&quot;:1208,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:149772,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/190385998?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339c7fe4-1ec1-45e1-9e11-c3faa541fcd8_1208x726.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!sn48!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339c7fe4-1ec1-45e1-9e11-c3faa541fcd8_1208x726.png 424w, https://substackcdn.com/image/fetch/$s_!sn48!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339c7fe4-1ec1-45e1-9e11-c3faa541fcd8_1208x726.png 848w, https://substackcdn.com/image/fetch/$s_!sn48!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339c7fe4-1ec1-45e1-9e11-c3faa541fcd8_1208x726.png 1272w, https://substackcdn.com/image/fetch/$s_!sn48!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F339c7fe4-1ec1-45e1-9e11-c3faa541fcd8_1208x726.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Fuente: Google Cloud</figcaption></figure></div><p>La explotaci&#243;n de vulnerabilidades de software <a href="https://cloud.google.com/security/report/resources/cloud-threat-horizons-report-h1-2026">super&#243; por primera vez</a> al robo o abuso de credenciales como principal puerta de entrada a entornos de <strong>Google Cloud</strong>, seg&#250;n el &#250;ltimo <em>Cloud Threat Horizons Report</em> de Google y Mandiant. </p><p>En la segunda mitad de 2025, el <strong>44,5%</strong> de las intrusiones se inici&#243; explotando fallas en software instalado por los clientes, contra <strong>27,2%</strong> que comenz&#243; con contrase&#241;as d&#233;biles o inexistentes.</p><p><strong>Cambio. </strong>Durante a&#241;os, el vector dominante hab&#237;a sido la identidad: contrase&#241;as d&#233;biles, credenciales filtradas o errores de configuraci&#243;n. Pero en 2025 los atacantes empezaron a pivotear hacia aplicaciones vulnerables sin parchear, sobre todo software de terceros desplegado en m&#225;quinas virtuales y clusters de Kubernetes.</p><p><strong>Qu&#233; est&#225;n explotando. </strong>Los incidentes analizados incluyen ataques contra vulnerabilidades cr&#237;ticas como <strong>React2Shell</strong> (CVE-2025-55182) en React Server Components y una falla de inyecci&#243;n en <strong>XWiki</strong> (CVE-2025-24893). En varios casos, los atacantes desplegaron <em>cryptominers</em> como XMRig apenas <strong>48 horas</strong> despu&#233;s de la divulgaci&#243;n p&#250;blica de la falla.</p><p><strong>M&#225;s r&#225;pido. </strong>El tiempo entre la publicaci&#243;n de una vulnerabilidad y su explotaci&#243;n activa se redujo dr&#225;sticamente: pas&#243; de semanas a <strong>d&#237;as</strong>.</p><p><strong>El contexto. </strong>Aunque parad&#243;jico, el cambio puede reflejar mejoras en seguridad de identidad. Google atribuye parte del giro a sus pol&#237;ticas <em>secure-by-default</em> y a protecciones m&#225;s estrictas para credenciales, que habr&#237;an cerrado los vectores m&#225;s simples y empujado a los atacantes hacia exploits de software.</p><h3>Un hacker comprometi&#243; los archivos Epstein del FBI en 2023</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!nZHa!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8178af7-b04c-4aa8-9727-7e2fd99fee5e_1169x719.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!nZHa!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8178af7-b04c-4aa8-9727-7e2fd99fee5e_1169x719.png 424w, https://substackcdn.com/image/fetch/$s_!nZHa!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8178af7-b04c-4aa8-9727-7e2fd99fee5e_1169x719.png 848w, https://substackcdn.com/image/fetch/$s_!nZHa!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8178af7-b04c-4aa8-9727-7e2fd99fee5e_1169x719.png 1272w, https://substackcdn.com/image/fetch/$s_!nZHa!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8178af7-b04c-4aa8-9727-7e2fd99fee5e_1169x719.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!nZHa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8178af7-b04c-4aa8-9727-7e2fd99fee5e_1169x719.png" width="1169" height="719" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f8178af7-b04c-4aa8-9727-7e2fd99fee5e_1169x719.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:719,&quot;width&quot;:1169,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1499002,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/190385998?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F25426c70-2cbd-4250-bac3-869dd2076906_1169x719.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!nZHa!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8178af7-b04c-4aa8-9727-7e2fd99fee5e_1169x719.png 424w, https://substackcdn.com/image/fetch/$s_!nZHa!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8178af7-b04c-4aa8-9727-7e2fd99fee5e_1169x719.png 848w, https://substackcdn.com/image/fetch/$s_!nZHa!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8178af7-b04c-4aa8-9727-7e2fd99fee5e_1169x719.png 1272w, https://substackcdn.com/image/fetch/$s_!nZHa!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff8178af7-b04c-4aa8-9727-7e2fd99fee5e_1169x719.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Ghislaine Maxwell y Jeffrey Epstein. Foto: Reuters</figcaption></figure></div><p>Un <a href="https://www.reuters.com/world/us/foreign-hacker-2023-compromised-epstein-files-held-by-fbi-source-documents-show-2026-03-11/">hacker accedi&#243;</a> en 2023 a archivos vinculados a la investigaci&#243;n del FBI sobre <strong>Jeffrey Epstein</strong> tras comprometer un servidor en la oficina del FBI en Nueva York. La intrusi&#243;n ocurri&#243; el 12 de febrero de ese a&#241;o y fue descubierta al d&#237;a siguiente, seg&#250;n documentos del Departamento de Justicia a los que accedi&#243; Reuters.</p><p><strong>C&#243;mo ocurri&#243;.</strong> El acceso se produjo despu&#233;s de que un servidor del laboratorio forense de explotaci&#243;n infantil quedara <strong>expuesto</strong> por error mientras un agente del FBI manipulaba evidencia digital. Los investigadores detectaron actividad inusual en el sistema, incluida la revisi&#243;n de archivos relacionados con el caso Epstein.</p><p><strong>Qu&#233; se sabe del acceso.</strong> No est&#225; claro qu&#233; archivos espec&#237;ficos fueron consultados ni si el atacante descarg&#243; informaci&#243;n. Tampoco se conoce la identidad del hacker ni el pa&#237;s desde donde operaba. Una fuente citada por Reuters dijo que parec&#237;a tratarse de un cibercriminal y no de un actor estatal.</p><p><strong>Por qu&#233; importa.</strong> El episodio expone el valor potencial de inteligencia de los archivos Epstein, que contienen v&#237;nculos del financista con figuras influyentes de la pol&#237;tica, las finanzas y la academia. </p><p>Investigadores se&#241;alan que esos documentos podr&#237;an ser un objetivo atractivo para actores interesados en obtener material de presi&#243;n.</p><h3>Nuevo troyano bancario apunta a Brasil: BeatBanker</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!V5vS!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f01216d-01e1-49dd-897b-c66ddd7008fe_1160x764.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!V5vS!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f01216d-01e1-49dd-897b-c66ddd7008fe_1160x764.png 424w, https://substackcdn.com/image/fetch/$s_!V5vS!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f01216d-01e1-49dd-897b-c66ddd7008fe_1160x764.png 848w, https://substackcdn.com/image/fetch/$s_!V5vS!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f01216d-01e1-49dd-897b-c66ddd7008fe_1160x764.png 1272w, https://substackcdn.com/image/fetch/$s_!V5vS!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f01216d-01e1-49dd-897b-c66ddd7008fe_1160x764.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!V5vS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f01216d-01e1-49dd-897b-c66ddd7008fe_1160x764.png" width="1160" height="764" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2f01216d-01e1-49dd-897b-c66ddd7008fe_1160x764.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:764,&quot;width&quot;:1160,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:1189161,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/190385998?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f01216d-01e1-49dd-897b-c66ddd7008fe_1160x764.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!V5vS!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f01216d-01e1-49dd-897b-c66ddd7008fe_1160x764.png 424w, https://substackcdn.com/image/fetch/$s_!V5vS!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f01216d-01e1-49dd-897b-c66ddd7008fe_1160x764.png 848w, https://substackcdn.com/image/fetch/$s_!V5vS!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f01216d-01e1-49dd-897b-c66ddd7008fe_1160x764.png 1272w, https://substackcdn.com/image/fetch/$s_!V5vS!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2f01216d-01e1-49dd-897b-c66ddd7008fe_1160x764.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Un APK que se hace pasar por Play Store. Foto: Reuters</figcaption></figure></div><p>Investigadores de <a href="https://securelist.com/beatbanker-miner-and-banker/119121/">Kaspersky</a> detectaron una campa&#241;a de malware para Android bautizada <strong>BeatBanker</strong>, dirigida principalmente a usuarios de Brasil y distribuida a trav&#233;s de sitios falsos que imitan la tienda de aplicaciones oficial.</p><p><strong>Qu&#233; pas&#243;.</strong> El malware se propaga mediante p&#225;ginas de phishing que replican la interfaz de la Play Store y ofrecen descargar una supuesta app llamada &#8220;INSS Reembolso&#8221;, que se hace pasar por el sitio del sistema de seguridad social brasile&#241;o. En realidad se trata de un <strong>APK malicioso</strong> que instala distintos m&#243;dulos en el tel&#233;fono.</p><p><strong>Qu&#233; hace.</strong> Una vez instalado, BeatBanker despliega una operaci&#243;n de m&#250;ltiples capas: puede <strong>minar cripto en segundo plano</strong>, robar credenciales bancarias y manipular transacciones cripto. En algunos casos, cuando detecta intentos de enviar USDT, superpone pantallas falsas de billeteras o exchanges para reemplazar la direcci&#243;n de destino por la del atacante.</p><p><strong>Evoluci&#243;n.</strong> Las variantes m&#225;s recientes del malware abandonaron el m&#243;dulo bancario y lo reemplazaron por un <strong>RAT</strong> conocido como BTMOB, que permite a los operadores tomar control remoto del dispositivo infectado.</p><p><strong>Persistencia.</strong> El malware utiliza varios trucos para mantenerse activo y evadir detecci&#243;n. El m&#225;s llamativo: reproduce en <em>loop </em>un audio <strong>casi inaudible</strong> para impedir que el sistema cierre el proceso. Tambi&#233;n monitorea el uso del tel&#233;fono, la temperatura y el nivel de bater&#237;a para operar de forma m&#225;s sigilosa.</p><p><strong>C&#243;mo se oculta.</strong> Durante el ataque, el malware simula ser tanto una aplicaci&#243;n leg&#237;tima de la Play Store como la propia tienda de Google, mostrando falsas pantallas de actualizaci&#243;n que inducen a las v&#237;ctimas a instalar cargas maliciosas adicionales.</p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.austral.edu.ar/ingenieria/ingenieria-posgrados/ciberseguridad/diplomatura-en-gestion-y-estrategia-en-ciberseguridad/?utm_source=ig&amp;utm_medium=social&amp;utm_content=link_in_bio&amp;fbclid=PAdGRleAPBKt9leHRuA2FlbQIxMQBzcnRjBmFwcF9pZA8xMjQwMjQ1NzQyODc0MTQAAadoQCMBONCS0NNAQ-cM0vYYT1IgeTCq-MTTPX48d-Akd4-KtknzEHq9CF07Mg_aem_USxObTUnrQylxYcinDp7Kw" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j0Jh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 424w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 848w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg" width="1200" height="628" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:628,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:481623,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://www.austral.edu.ar/ingenieria/ingenieria-posgrados/ciberseguridad/diplomatura-en-gestion-y-estrategia-en-ciberseguridad/?utm_source=ig&amp;utm_medium=social&amp;utm_content=link_in_bio&amp;fbclid=PAdGRleAPBKt9leHRuA2FlbQIxMQBzcnRjBmFwcF9pZA8xMjQwMjQ1NzQyODc0MTQAAadoQCMBONCS0NNAQ-cM0vYYT1IgeTCq-MTTPX48d-Akd4-KtknzEHq9CF07Mg_aem_USxObTUnrQylxYcinDp7Kw&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/187504152?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!j0Jh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 424w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 848w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></div><div><hr></div><h3><strong>Detectan 310 campa&#241;as que usaron anuncios en Facebook para estafas en todo el mundo</strong></h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!YsBy!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4710a70-f221-4477-8a2a-0ba67ff2a598_1032x650.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!YsBy!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4710a70-f221-4477-8a2a-0ba67ff2a598_1032x650.png 424w, https://substackcdn.com/image/fetch/$s_!YsBy!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4710a70-f221-4477-8a2a-0ba67ff2a598_1032x650.png 848w, https://substackcdn.com/image/fetch/$s_!YsBy!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4710a70-f221-4477-8a2a-0ba67ff2a598_1032x650.png 1272w, https://substackcdn.com/image/fetch/$s_!YsBy!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4710a70-f221-4477-8a2a-0ba67ff2a598_1032x650.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!YsBy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4710a70-f221-4477-8a2a-0ba67ff2a598_1032x650.png" width="1032" height="650" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/f4710a70-f221-4477-8a2a-0ba67ff2a598_1032x650.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:650,&quot;width&quot;:1032,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:572980,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/190385998?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4710a70-f221-4477-8a2a-0ba67ff2a598_1032x650.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!YsBy!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4710a70-f221-4477-8a2a-0ba67ff2a598_1032x650.png 424w, https://substackcdn.com/image/fetch/$s_!YsBy!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4710a70-f221-4477-8a2a-0ba67ff2a598_1032x650.png 848w, https://substackcdn.com/image/fetch/$s_!YsBy!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4710a70-f221-4477-8a2a-0ba67ff2a598_1032x650.png 1272w, https://substackcdn.com/image/fetch/$s_!YsBy!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Ff4710a70-f221-4477-8a2a-0ba67ff2a598_1032x650.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: Reuters</figcaption></figure></div><p>Investigadores de <a href="https://www.bitdefender.com/en-us/blog/labs/global-investment-scam-network-using-meta-ads">Bitdefender</a> detectaron una infraestructura global de estafas que us&#243; anuncios pagos en Facebook para difundir historias falsas que imitaban medios de comunicaci&#243;n y figuras p&#250;blicas. </p><p>Entre el 9 de febrero y el 5 de marzo identificaron <strong>310 campa&#241;as</strong> coordinadas con m&#225;s de 26.000 visualizaciones de anuncios en al menos 25 pa&#237;ses.</p><p><strong>C&#243;mo funciona.</strong> Las campa&#241;as usan narrativas falsas (esc&#225;ndalos televisivos, testamentos de celebridades o supuestas plataformas de inversi&#243;n) para atraer a usuarios a p&#225;ginas que simulan art&#237;culos period&#237;sticos. All&#237; se les pide registrarse con nombre, mail y tel&#233;fono, datos que luego se usan para derivarlos a fraudes de inversi&#243;n.</p><p><strong>El objetivo.</strong> Tras registrarse, las v&#237;ctimas suelen ser contactadas por supuestos brokers que promueven plataformas de <em>trading</em> o cripto y presionan para realizar dep&#243;sitos iniciales. Las interfaces muestran ganancias ficticias para incentivar m&#225;s inversiones, pero retirar el dinero luego resulta imposible.</p><p><strong>La escala.</strong> Los investigadores detectaron tres subcampa&#241;as principales con la misma infraestructura y contenido <strong>en m&#225;s de 15 idiomas.</strong> El esquema aparece activo en Europa, Am&#233;rica del Norte, Am&#233;rica Latina, Asia, Ocean&#237;a y &#193;frica.</p><p><strong>El modelo.</strong> La estructura sugiere un sistema tipo afiliados o franquicia. Distintos grupos operar&#237;an campa&#241;as regionales usando el mismo kit t&#233;cnico y el mismo <em>playbook</em> narrativo para replicar las estafas en distintos pa&#237;ses.</p><p><strong>Evasi&#243;n.</strong> Las campa&#241;as usaban t&#233;cnicas dise&#241;adas para evadir la moderaci&#243;n de Meta. Entre ellas, mostrar dominios confiables en la vista previa de los anuncios mientras el clic redirig&#237;a a otro sitio, registrar dominios que imitaban medios nacionales y usar caracteres cir&#237;licos visualmente id&#233;nticos al alfabeto latino para evitar filtros autom&#225;ticos.</p><div><hr></div><h4><strong>&#128275; Breaches y hacks</strong></h4><ul><li><p>Nueva campa&#241;a contra <a href="https://www.salesforce.com/blog/protecting-your-data-essential-actions-to-secure-experience-cloud-guest-user-access/">Salesforce</a>, ShinyHunters se atribuye el ataque</p></li><li><p><a href="https://www.securityweek.com/michelin-confirms-data-breach-linked-to-oracle-ebs-attack/">Michelin</a> confirma un data breach linkeado a Oracle</p></li><li><p>Un grupo pro-ruso asegura que <a href="https://x.com/DailyDarkWeb/status/2029951384959799781">hacke&#243;</a> un sistema de suministro de agua de Israel</p></li></ul><h4><strong>&#128274; Ransomware</strong></h4><ul><li><p>Acusan a un negociador de ransomware vinculado a <a href="https://www.bleepingcomputer.com/news/security/us-charges-another-ransomware-negotiator-linked-to-blackcat-attacks/">BlackCat</a></p></li><li><p><a href="https://www.cert.ssi.gouv.fr/cti/CERTFR-2026-CTI-002/">Francia publica</a> su reporte anual y detecta menos casos de ransomware con cifrado y m&#225;s con robo de datos</p></li><li><p>Nuevo malware hecho con IA se us&#243; en campa&#241;a de <a href="https://www.bleepingcomputer.com/news/security/ai-generated-slopoly-malware-used-in-interlock-ransomware-attack/">Interlock ransomware</a></p></li></ul><h4><strong>&#128163; Exploits y malware</strong></h4><ul><li><p>El plugin <a href="https://www.securityweek.com/ally-wordpress-plugin-flaw-exposes-over-200000-websites-to-attacks/">Ally</a> de WordPress, expuesto a un exploit que afecta a 200 mil sitios</p></li></ul><h4><strong>&#128269; Threat intel y vulnerabilidades</strong></h4><ul><li><p>SentinelOne publica detalles de la campa&#241;a contra <a href="https://www.sentinelone.com/blog/fortigate-edge-intrusions/">FortiGate</a></p></li><li><p>Reportes: <a href="https://blog.checkpoint.com/research/global-cyber-attacks-remain-near-record-highs-in-february-2026-despite-ransomware-decline/">Check Point</a>, <a href="https://www.isc2.org/insights/2026/03/isc2-women-in-cybersecurity-study-workplace-ai-skills?queryID=9f509fdb3680bd057efda34c16205e13">ISC2</a>, <a href="https://blog.talosintelligence.com/patch-track-repeat-the-2025-cve-retrospective/">Cisco Talos</a>, <a href="https://securelist.com/vulnerabilities-and-exploits-in-q4-2025/119105/">Kaspersky</a>.</p></li><li><p><a href="https://zonacero.com/generales/hernan-penagos-denuncio-ciberataques-las-plataformas-de-la-registraduria">Colombia denuncia</a> intentos de ciberataques durante las elecciones</p></li></ul><h4><strong>&#128736;&#65039; Tools y updates</strong></h4><ul><li><p>Windows va a activar <a href="https://techcommunity.microsoft.com/blog/windows-itpro-blog/securing-devices-faster-with-hotpatch-updates-on-by-default/4500066">Hotpatch</a> por default</p></li><li><p><a href="https://msrc.microsoft.com/update-guide/">Microsoft</a> parchea 79 vulnerabilidades</p></li><li><p><a href="https://www.bleepingcomputer.com/news/security/us-charges-another-ransomware-negotiator-linked-to-blackcat-attacks/">Splunk y Zoom</a> lanzan parches de seguridad</p></li></ul><h4><strong>&#128203; Privacidad y regulaciones</strong></h4><ul><li><p><a href="https://www.dexerto.com/youtube/youtube-ads-are-about-to-get-even-longer-and-theyll-be-unskippable-3332420/">Los avisos de YouTube</a> ser&#225;n m&#225;s largos y no se podr&#225;n saltear</p></li><li><p><a href="https://futurism.com/artificial-intelligence/meta-lied-smart-glasses-privacy-class-action-lawsuit">Demanda colectiva</a> contra Meta por la recolecci&#243;n de im&#225;genes de sus lentes</p></li><li><p><a href="https://www.theguardian.com/technology/2026/mar/09/x-suspends-accounts-massive-scale-manipulation-attempts-russia">X (Twitter) suspende</a> 800 millones de cuentas por manipulaci&#243;n masiva</p><p></p></li></ul><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/brasil-lula-quiere-prohibir-los-casinos-online-apps-apuestas?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/brasil-lula-quiere-prohibir-los-casinos-online-apps-apuestas?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p>]]></content:encoded></item><item><title><![CDATA[Adictivas por diseño: claves para entender el juicio contra Zuckerberg y YouTube]]></title><description><![CDATA[Un jurado de Los &#193;ngeles deber&#225; determinar si las plataformas fueron dise&#241;adas para generar uso compulsivo en chicos y adolescentes. Reportaje con tres especialistas.]]></description><link>https://www.brodersendarknews.com/p/adictivas-por-diseno-claves-juicio-zuckerberg-meta-youtube</link><guid isPermaLink="false">https://www.brodersendarknews.com/p/adictivas-por-diseno-claves-juicio-zuckerberg-meta-youtube</guid><dc:creator><![CDATA[Juan Brodersen]]></dc:creator><pubDate>Sun, 08 Mar 2026 12:07:37 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!2dqn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c5ba0-ee33-4fd0-8188-0916d39a373c_884x611.png" length="0" type="image/jpeg"/><content:encoded><![CDATA[<p><em>Dark News es un resumen semanal de noticias de ciberseguridad, privacidad y hacking. Los temas est&#225;n producidos y seleccionados por <a href="https://twitter.com/juanbrodersen">Juan Brodersen</a> seg&#250;n estos <a href="https://juanbrodersen.substack.com/about">criterios de edici&#243;n</a>.</em></p><div><hr></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/subscribe?"><span>Subscribe now</span></a></p><h1>08<br>mar</h1><h2><strong>&#9889;TL;DR</strong></h2><p>El lunes de esta semana publicamos un <a href="https://www.clarin.com/tecnologia/juicio-historico-zuckerberg-youtube-disenaron-redes-volver-adictos-chicos_0_UzVkLnP3Rn.html">reportaje</a> en Clar&#237;n sobre el juicio que enfrentan Meta y YouTube en el que las acusan de ser &#8220;adictivas y da&#241;ar la salud mental durante la infancia&#8221;. No es la primera vez que Mark Zuckerberg tiene que dar explicaciones ante la Justicia, pero s&#237; es su debut en un juicio ante un jurado.</p><p>Reproduzco la nota, en la que habl&#233; con tres especialistas que estudian el tema desde hace tiempo: <strong>Luis Garc&#237;a Balcarce, Luc&#237;a Camacho y Carolina Mart&#237;nez Elebi</strong>.</p><div><hr></div><p>&#9200; <em>Substack dice que leer este correo completo lleva 13 minutos</em></p><p><em>Dark News #189</em></p><div class="pullquote"><p><em><strong>Espacio publicitario</strong></em></p><p style="text-align: center;"><em>Atomiq Vision integra gesti&#243;n de superficie de ataque, escaneo de vulnerabilidades y alertas. Est&#225; pensado tanto para analistas como para quienes toman decisiones en el alto nivel de una organizaci&#243;n o un pa&#237;s. M&#225;s informaci&#243;n, clic en <a href="https://www.atomiqlab.io/">este enlace</a>.</em></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="http://www.atomiqlab.io" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!ibcs!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80ac901b-7d81-4153-900c-e07aed602a4a_1200x628.png 424w, https://substackcdn.com/image/fetch/$s_!ibcs!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80ac901b-7d81-4153-900c-e07aed602a4a_1200x628.png 848w, https://substackcdn.com/image/fetch/$s_!ibcs!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80ac901b-7d81-4153-900c-e07aed602a4a_1200x628.png 1272w, https://substackcdn.com/image/fetch/$s_!ibcs!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80ac901b-7d81-4153-900c-e07aed602a4a_1200x628.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!ibcs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80ac901b-7d81-4153-900c-e07aed602a4a_1200x628.png" width="1200" height="628" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/80ac901b-7d81-4153-900c-e07aed602a4a_1200x628.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:628,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:629646,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:&quot;&quot;,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://www.atomiqlab.io&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/173434966?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80ac901b-7d81-4153-900c-e07aed602a4a_1200x628.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!ibcs!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80ac901b-7d81-4153-900c-e07aed602a4a_1200x628.png 424w, https://substackcdn.com/image/fetch/$s_!ibcs!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80ac901b-7d81-4153-900c-e07aed602a4a_1200x628.png 848w, https://substackcdn.com/image/fetch/$s_!ibcs!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80ac901b-7d81-4153-900c-e07aed602a4a_1200x628.png 1272w, https://substackcdn.com/image/fetch/$s_!ibcs!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F80ac901b-7d81-4153-900c-e07aed602a4a_1200x628.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></div><div><hr></div><h3>Juicio hist&#243;rico contra Zuckerberg y YouTube: &#191;dise&#241;aron las redes para volver adictos a los chicos?</h3><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!2dqn!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c5ba0-ee33-4fd0-8188-0916d39a373c_884x611.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!2dqn!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c5ba0-ee33-4fd0-8188-0916d39a373c_884x611.png 424w, https://substackcdn.com/image/fetch/$s_!2dqn!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c5ba0-ee33-4fd0-8188-0916d39a373c_884x611.png 848w, https://substackcdn.com/image/fetch/$s_!2dqn!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c5ba0-ee33-4fd0-8188-0916d39a373c_884x611.png 1272w, https://substackcdn.com/image/fetch/$s_!2dqn!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c5ba0-ee33-4fd0-8188-0916d39a373c_884x611.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!2dqn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c5ba0-ee33-4fd0-8188-0916d39a373c_884x611.png" width="884" height="611" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ef0c5ba0-ee33-4fd0-8188-0916d39a373c_884x611.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:611,&quot;width&quot;:884,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:668622,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/190215180?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c5ba0-ee33-4fd0-8188-0916d39a373c_884x611.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!2dqn!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c5ba0-ee33-4fd0-8188-0916d39a373c_884x611.png 424w, https://substackcdn.com/image/fetch/$s_!2dqn!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c5ba0-ee33-4fd0-8188-0916d39a373c_884x611.png 848w, https://substackcdn.com/image/fetch/$s_!2dqn!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c5ba0-ee33-4fd0-8188-0916d39a373c_884x611.png 1272w, https://substackcdn.com/image/fetch/$s_!2dqn!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fef0c5ba0-ee33-4fd0-8188-0916d39a373c_884x611.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a><figcaption class="image-caption">Foto: EFE</figcaption></figure></div><p>Un <a href="https://www.clarin.com/estados-unidos/mark-zuckerberg-enfrentara-familiares-juicio-historico-adiccion-redes-sociales-eeuu_0_tWJkkgWT0b.html">juicio hist&#243;rico</a> puso a <strong>Mark Zuckerberg</strong>, fundador y CEO de Meta (Facebook, Instagram, WhatsApp), ante un jurado de Los &#193;ngeles en un proceso civil que tambi&#233;n apunta contra <strong>YouTube</strong>: acusan a estas plataformas de <a href="https://www.clarin.com/estados-unidos/comienzan-alegatos-historico-juicio-estados-unidos-adiccion-redes-sociales_0_MtkJWmutyR.html">ser adictivas y &#8220;da&#241;ar la salud mental durante la infancia&#8221;</a>. Lo que se intenta determinar es si estas apps <strong>se dise&#241;aron para ser adictivas.</strong></p><p>El planteo tiene un contexto: <a href="https://www.clarin.com/new-york-times-international-weekly/australia-prohibio-acceso-redes-sociales-menores-16-anos-funcionara_0_zYDVTbVQ6m.html?adcmp=pwclarin-cpa-DSA-C1-30&amp;gad_source=1&amp;gad_campaignid=12801678220&amp;gbraid=0AAAAADN1DWiUgwQjpGSJhJG66C40LGnkx&amp;gclid=CjwKCAiAnoXNBhAZEiwAnItcG3qDtphIX76ntFy75eUUJXxWeR8p2IuhTx1C0dO_vwVaNY_DfH0lBRoCArgQAvD_BwE">Australia prohibi&#243;</a> el uso de las redes sociales a menores de 16 a fines de 2024, <strong><a href="https://www.clarin.com/tecnologia/espana-prohibe-redes-sociales-menores-16-aplicaria-genera-resistencia_0_Wb23Sva2jK.html">Espa&#241;a</a></strong><a href="https://www.clarin.com/tecnologia/espana-prohibe-redes-sociales-menores-16-aplicaria-genera-resistencia_0_Wb23Sva2jK.html"> hizo lo mismo el mes pasado</a> e instituciones educativas en todo el mundo restringen el uso de tel&#233;fonos celulares por la dispersi&#243;n que generan.</p><p>Y los motivos tienen que ver con c&#243;mo las plataformas explotan el sistema de recompensa asociado a la <strong><a href="https://www.clarin.com/buena-vida/redes-sociales-estres-ansiedad-7-herramientas-dejar-vivir-cabeza-lado_0_PmoDV7hW6W.html">dopamina</a></strong> que activan los likes, las interacciones, el fomento del <em>multitasking </em>(hacer muchas tareas a la vez) y c&#243;mo puede inducir a depresi&#243;n y ansiedad, dos condiciones particularmente sensibles en adolescentes.  </p><p>El caso, que arranc&#243; el 9 de febrero, pone al quinto hombre m&#225;s rico del mundo otra vez en un estrado. En 2018, Zuckerberg fue citado ante el Capitolio en Estados Unidos para responder por el esc&#225;ndalo de privacidad de <a href="https://www.clarin.com/mundo/facebook-admitio-cambridge-analytica-accedio-datos-87-millones-usuarios_0_rySs8oMiM.html?adcmp=pwclarin-cpa-DSA-C1-30&amp;gad_source=1&amp;gad_campaignid=12801678220&amp;gbraid=0AAAAADN1DWiUgwQjpGSJhJG66C40LGnkx&amp;gclid=CjwKCAiAnoXNBhAZEiwAnItcG4dWVrDBl1nK_XGSiA-3goLElVXpm4637GXgagRekrZHxj0PSh8EbBoCOuMQAvD_BwE">Cambridge Analytica</a>. En 2025, la Federal Trade Commission (FTC) lo investig&#243; por monopolio y tambi&#233;n tuvo que testificar. Pero esta vez es distinto: <strong>es la primera vez que estar&#225; ante un jurado.</strong></p><p>Con <strong>3,07 mil millones de usuarios en Facebook</strong> (la mayor red social del mundo), 3 mil millones en <strong>Instagram </strong>y 2.5 mil millones de <strong>YouTube</strong>, estas plataformas enfrentan un juicio que, si bien se lleva a cabo en California, podr&#237;a repercutir en todo el mundo. Hasta hay en Argentina<strong> un proyecto de ley en Provincia de Buenos Aires</strong> que va en este sentido de la restricci&#243;n del uso.</p><p>Ac&#225;, tres especialistas explican los alcances de este juicio.</p><h2>El juicio: de qu&#233; acusan a Meta y YouTube</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!C_uA!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23fa7092-ef5e-430d-a8ff-86ee64ca1c9a_720x480.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!C_uA!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23fa7092-ef5e-430d-a8ff-86ee64ca1c9a_720x480.jpeg 424w, https://substackcdn.com/image/fetch/$s_!C_uA!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23fa7092-ef5e-430d-a8ff-86ee64ca1c9a_720x480.jpeg 848w, https://substackcdn.com/image/fetch/$s_!C_uA!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23fa7092-ef5e-430d-a8ff-86ee64ca1c9a_720x480.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!C_uA!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23fa7092-ef5e-430d-a8ff-86ee64ca1c9a_720x480.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!C_uA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23fa7092-ef5e-430d-a8ff-86ee64ca1c9a_720x480.jpeg" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/23fa7092-ef5e-430d-a8ff-86ee64ca1c9a_720x480.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Mark Zuckerberg, CEO de Meta, en el estrado. Foto: Reuters&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Mark Zuckerberg, CEO de Meta, en el estrado. Foto: Reuters" title="Mark Zuckerberg, CEO de Meta, en el estrado. Foto: Reuters" srcset="https://substackcdn.com/image/fetch/$s_!C_uA!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23fa7092-ef5e-430d-a8ff-86ee64ca1c9a_720x480.jpeg 424w, https://substackcdn.com/image/fetch/$s_!C_uA!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23fa7092-ef5e-430d-a8ff-86ee64ca1c9a_720x480.jpeg 848w, https://substackcdn.com/image/fetch/$s_!C_uA!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23fa7092-ef5e-430d-a8ff-86ee64ca1c9a_720x480.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!C_uA!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F23fa7092-ef5e-430d-a8ff-86ee64ca1c9a_720x480.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Mark Zuckerberg, CEO de Meta, en el estrado. Foto: Reuters</p><p>El juicio, que se lleva a cabo en la Corte Superior de Los &#193;ngeles, tiene como demandante a una joven de 19 a&#241;os del norte de California, identificada como K.G.M., que acusa a las plataformas de haberle<strong> generado adicci&#243;n y depresi&#243;n</strong> tras m&#225;s de una d&#233;cada de uso y reclama da&#241;os y perjuicios no especificados.</p><p>El caso pone a prueba una teor&#237;a jur&#237;dica novedosa: que las redes sociales o ciertas funciones de sus plataformas pueden considerarse <strong>&#8220;productos defectuosos&#8221;</strong> dise&#241;ados de manera adictiva, y por lo tanto quedar alcanzados por leyes de responsabilidad por da&#241;os personales, de forma similar a litigios contra <strong>tabacaleras u opioides.</strong></p><p>Tambi&#233;n desaf&#237;a el alcance de la Secci&#243;n 230 de la <em>Communications Decency Act</em>, norma que hist&#243;ricamente protegi&#243; a las empresas tecnol&#243;gicas de la responsabilidad por contenidos publicados por usuarios.</p><p>&#8220;En Estados Unidos, la Secci&#243;n 230 de esta ley establece que las plataformas digitales<strong> no son responsables</strong> por el contenido que publican sus usuarios. La l&#243;gica original era <strong>razonable </strong>para la &#233;poca en que se sancion&#243;, 1996: proteger a los primeros servicios de internet de ser demandados por lo que cualquier persona escrib&#237;a en sus foros. Lo que no se anticip&#243; es que ese escudo legal le permitir&#237;a a las redes sociales operar durante mucho tiempo sin responder por lo que ocurre en sus plataformas&#8221;, recuerda a <strong>Clar&#237;n </strong>Luis Garc&#237;a Balcarce, abogado especializado en derechos digitales.</p><p>&#8220;Lo que el juicio en Los &#193;ngeles pone en discusi&#243;n no es ese escudo en s&#237; mismo, sino sus l&#237;mites: se hace la distinci&#243;n entre el contenido que suben los usuarios, protegido por la norma, <strong>y las decisiones de dise&#241;o propias de la plataforma</strong>, como el <em><a href="https://www.clarin.com/tecnologia/inteligencia-artificial-desinformacion-adiccion-celulares-predicciones-werner-vogels-cerebro-tecnologico-amazon_0_iTvhSqXnRq.html">scroll infinito</a></em>, el algoritmo de recomendaci&#243;n o las notificaciones compulsivas&#8221;, agrega.</p><p>&#8220;Tambi&#233;n el <em><strong>autoplay </strong></em>[reproducci&#243;n de un contenido tras otro], las notificaciones, las recomendaciones sugeridas por algoritmos y los filtros de est&#233;tica tienen la capacidad de generar adicci&#243;n en menores de edad, y afectar a largo plazo su salud mental. El centro de su argumento es que las redes sociales generan adicci&#243;n, y que su dise&#241;o se enfoca deliberadamente en ese resultado&#8221;, complementa Luc&#237;a Camacho, coordinadora de Pol&#237;ticas P&#250;blicas en la organizaci&#243;n <strong><a href="https://www.derechosdigitales.org/en/home/">Derechos Digitales</a></strong>.</p><p>Sin embargo, advierte que las plataformas tienen contraargumentos, como que &#8220;no hay evidencia que vincule de manera causal el uso de redes sociales con un resultado adictivo, y acusan la inexistencia de algo como la adicci&#243;n por redes sociales bajo est&#225;ndares m&#233;dicos o cl&#237;nicos&#8221;.</p><div class="pullquote"><p><strong>Espacio publicitario</strong></p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://www.austral.edu.ar/ingenieria/ingenieria-posgrados/ciberseguridad/diplomatura-en-gestion-y-estrategia-en-ciberseguridad/?utm_source=ig&amp;utm_medium=social&amp;utm_content=link_in_bio&amp;fbclid=PAdGRleAPBKt9leHRuA2FlbQIxMQBzcnRjBmFwcF9pZA8xMjQwMjQ1NzQyODc0MTQAAadoQCMBONCS0NNAQ-cM0vYYT1IgeTCq-MTTPX48d-Akd4-KtknzEHq9CF07Mg_aem_USxObTUnrQylxYcinDp7Kw" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!j0Jh!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 424w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 848w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg" width="1200" height="628" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:628,&quot;width&quot;:1200,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:481623,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:&quot;https://www.austral.edu.ar/ingenieria/ingenieria-posgrados/ciberseguridad/diplomatura-en-gestion-y-estrategia-en-ciberseguridad/?utm_source=ig&amp;utm_medium=social&amp;utm_content=link_in_bio&amp;fbclid=PAdGRleAPBKt9leHRuA2FlbQIxMQBzcnRjBmFwcF9pZA8xMjQwMjQ1NzQyODc0MTQAAadoQCMBONCS0NNAQ-cM0vYYT1IgeTCq-MTTPX48d-Akd4-KtknzEHq9CF07Mg_aem_USxObTUnrQylxYcinDp7Kw&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://www.brodersendarknews.com/i/187504152?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!j0Jh!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 424w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 848w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!j0Jh!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F09534a06-73eb-402e-93be-4ef792b9727c_1200x628.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div></div><div><hr></div><h2>La situaci&#243;n en Argentina</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!g-Ij!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6083dd5e-4b2b-49d9-a032-21d79cdf29f8_720x480.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!g-Ij!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6083dd5e-4b2b-49d9-a032-21d79cdf29f8_720x480.jpeg 424w, https://substackcdn.com/image/fetch/$s_!g-Ij!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6083dd5e-4b2b-49d9-a032-21d79cdf29f8_720x480.jpeg 848w, https://substackcdn.com/image/fetch/$s_!g-Ij!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6083dd5e-4b2b-49d9-a032-21d79cdf29f8_720x480.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!g-Ij!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6083dd5e-4b2b-49d9-a032-21d79cdf29f8_720x480.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!g-Ij!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6083dd5e-4b2b-49d9-a032-21d79cdf29f8_720x480.jpeg" width="720" height="480" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/6083dd5e-4b2b-49d9-a032-21d79cdf29f8_720x480.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:480,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;C&#225;mara Diputados de la Provincia de Buenos Aires. Foto: Mart&#237;n Bonetto&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="C&#225;mara Diputados de la Provincia de Buenos Aires. Foto: Mart&#237;n Bonetto" title="C&#225;mara Diputados de la Provincia de Buenos Aires. Foto: Mart&#237;n Bonetto" srcset="https://substackcdn.com/image/fetch/$s_!g-Ij!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6083dd5e-4b2b-49d9-a032-21d79cdf29f8_720x480.jpeg 424w, https://substackcdn.com/image/fetch/$s_!g-Ij!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6083dd5e-4b2b-49d9-a032-21d79cdf29f8_720x480.jpeg 848w, https://substackcdn.com/image/fetch/$s_!g-Ij!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6083dd5e-4b2b-49d9-a032-21d79cdf29f8_720x480.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!g-Ij!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F6083dd5e-4b2b-49d9-a032-21d79cdf29f8_720x480.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>C&#225;mara Diputados de la Provincia de Buenos Aires. Foto: Mart&#237;n Bonetto</p><p>En Argentina hay debates sobre la adicci&#243;n a las redes, aunque con poco grado de madurez. &#8220;No tenemos una norma de ese tipo, y tampoco tenemos un marco regulatorio espec&#237;fico para los datos de los menores. La Ley 25.326 fue sancionada en el a&#241;o 2000 y no distingue entre el tratamiento de datos de un adulto y el de un ni&#241;o. <strong>Veinte a&#241;os despu&#233;s de su sanci&#243;n,</strong> las redes sociales operan en el pa&#237;s bajo el mismo r&#233;gimen que cualquier empresa que procesa datos de facturaci&#243;n&#8221;, explica Garc&#237;a Balcarce.</p><p>&#8220;A nivel legislativo han surgido varias iniciativas en relaci&#243;n a este tema. En la Legislatura bonaerense se present&#243; este a&#241;o <a href="https://www.linkedin.com/posts/luis-garcia-balcarce_proyecto-de-ley-menores-redes-sociales-activity-7429880239918399488-kNe_?utm_source=share&amp;utm_medium=member_desktop&amp;rcm=ACoAAAcgBncBd-6AZZeDpdx8L8eXJyFAOs67Stk">un proyecto que propone prohibir que menores de 13 a&#241;os</a> creen o mantengan cuentas en plataformas y redes sociales, sin excepciones y sin posibilidad de suplirlo con autorizaci&#243;n parental. El proyecto establece que son las plataformas las que deben implementar <strong>mecanismos auditables</strong> de verificaci&#243;n de edad bajo pena de multa. No se sanciona al menor ni a la familia. Se sanciona a la empresa&#8221;, cuenta.</p><p>Y a nivel nacional, &#8220;el proyecto de reforma de la Ley de Protecci&#243;n de Datos elaborado por la AAIP, la agencia que hoy aplica y controla la ley vigente, incorpor&#243; un r&#233;gimen espec&#237;fico para el tratamiento de datos de ni&#241;as, ni&#241;os y adolescentes&#8221;, cuenta.</p><p>&#8220;De acuerdo al proyecto, <strong>para menores de 16 a&#241;os</strong> el tratamiento s&#243;lo ser&#225; l&#237;cito con consentimiento de quien ejerce la responsabilidad parental, y proh&#237;be expresamente el tratamiento de datos en aplicaciones y plataformas m&#225;s all&#225; de lo estrictamente necesario para la actividad. En este proyecto, adem&#225;s, se obliga a realizar una evaluaci&#243;n de impacto previa a las empresas cuando el tratamiento pueda entra&#241;ar un alto riesgo para los derechos de las personas, siendo obligatoria en particular cuando se pueda afectar a menores y datos sensibles&#8221;, cierra.</p><p>&#8220;Los fallos de la justicia norteamericana, en general, no resuenan con tanta fuerza en pa&#237;ses de la regi&#243;n, a excepci&#243;n de las citas que a pie de p&#225;gina pueda hacer una Corte o Juzgado en la Argentina (y que es una pr&#225;ctica muy particular en ese pa&#237;s) de un fallo emitido en Estados Unidos. Por ahora, Am&#233;rica Latina con su propia inercia va generando proyectos que buscan, con enfoques prohibitivos, hacer frente al impacto en salud mental en las infancias del consumo de redes sociales y dispositivos digitales. Principalmente, a trav&#233;s de su prohibici&#243;n hasta cierto tope de edad&#8221;, agrega Camacho.</p><p>&#8220;En esa tendencia, pa&#237;ses como Colombia y Brasil ya han regulado en la materia. Colombia aprob&#243; en 2025 una Ley de Salud Mental que, en verdad, no cambia el paradigma actual, pues reafirma el modelo de autorregulaci&#243;n a cargo de las plataformas que afectan a ni&#241;os, ni&#241;as y adolescentes&#8221;, sigue.</p><p>La especialista recuerda que &#8220;pa&#237;ses como M&#233;xico (desde los 16 a&#241;os), Per&#250; (desde los 16 a&#241;os), Argentina (desde los 13 a&#241;os, seg&#250;n un proyecto de la C&#225;mara de Diputados de Buenos Aires), buscan tambi&#233;n prohibir el uso, y obligar a las plataformas e introducir mecanismos de verificaci&#243;n de edad de las personas usuarias de sus servicios&#8221;.</p><p>Argentina es, por el momento, una inc&#243;gnita que tiene el proyecto de la Provincia como punta de lanza.</p><h2>Adictivas &#8220;por dise&#241;o&#8221;: &#191;hay soluci&#243;n?</h2><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!q-_G!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb846ce5d-205e-4f03-92ae-61984e16b9d9_720x497.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!q-_G!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb846ce5d-205e-4f03-92ae-61984e16b9d9_720x497.jpeg 424w, https://substackcdn.com/image/fetch/$s_!q-_G!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb846ce5d-205e-4f03-92ae-61984e16b9d9_720x497.jpeg 848w, https://substackcdn.com/image/fetch/$s_!q-_G!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb846ce5d-205e-4f03-92ae-61984e16b9d9_720x497.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!q-_G!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb846ce5d-205e-4f03-92ae-61984e16b9d9_720x497.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!q-_G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb846ce5d-205e-4f03-92ae-61984e16b9d9_720x497.jpeg" width="720" height="497" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/b846ce5d-205e-4f03-92ae-61984e16b9d9_720x497.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:497,&quot;width&quot;:720,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;Mark Zuckerberg, creador de Facebook y referente tech. Foto: Reuters&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="Mark Zuckerberg, creador de Facebook y referente tech. Foto: Reuters" title="Mark Zuckerberg, creador de Facebook y referente tech. Foto: Reuters" srcset="https://substackcdn.com/image/fetch/$s_!q-_G!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb846ce5d-205e-4f03-92ae-61984e16b9d9_720x497.jpeg 424w, https://substackcdn.com/image/fetch/$s_!q-_G!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb846ce5d-205e-4f03-92ae-61984e16b9d9_720x497.jpeg 848w, https://substackcdn.com/image/fetch/$s_!q-_G!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb846ce5d-205e-4f03-92ae-61984e16b9d9_720x497.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!q-_G!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fb846ce5d-205e-4f03-92ae-61984e16b9d9_720x497.jpeg 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Mark Zuckerberg, creador de Facebook y referente tech. Foto: Reuters</p><p>Organizaciones como <a href="https://www.clarin.com/tecnologia/lado-oscuro-tiktok-alarmante-advertencia-amnistia-internacional-uso-argentina_0_qguaxlv9go.html">Amnist&#237;a Internacional</a> advierten que las redes tienen una din&#225;mica de adicci&#243;n similar a la de otros consumos problem&#225;ticos. De los estudios sobre c&#243;mo funcionan los<strong> &#8220;centros de placer&#8221;</strong> de los a&#241;os 50 de los psic&#243;logos norteamericanos James Olds y Peter Milner hasta trabajos actuales que eval&#250;an a las redes en este esquema de demanda de recompensas, diversas instituciones como la American Psychological Association advierten sobre el impacto negativo.</p><p>&#8220;Cuando el modelo de negocio est&#225; estructuralmente basado en maximizar la atenci&#243;n, el tiempo de permanencia y el engagement, lo que est&#225; en juego es un dise&#241;o econ&#243;mico que incentiva la amplificaci&#243;n de contenidos que generan reacci&#243;n, muchas veces a costa del bienestar, la privacidad y el desarrollo de ni&#241;as, ni&#241;os y adolescentes. En ese contexto, la pregunta por la responsabilidad es sist&#233;mica: &#191;Qu&#233; decisiones de dise&#241;o, qu&#233; m&#233;tricas internas y qu&#233; l&#243;gicas publicitarias est&#225;n orientando la arquitectura de estas plataformas? No se trata solo de qu&#233; contenidos circulan, sino de c&#243;mo se priorizan, a qui&#233;n se le muestran y con qu&#233; incentivos&#8221;, plantea Carolina Mart&#237;nez Elebi, licenciada en Ciencias de la Comunicaci&#243;n y docente de la UBA.</p><p>&#8220;En el caso de menores, el est&#225;ndar deber&#237;a ser m&#225;s exigente. Si sabemos que el cerebro de ni&#241;as, ni&#241;os y adolescentes est&#225; en proceso de desarrollo y que ciertos mecanismos (como son las notificaciones constantes, el scroll infinito y las recompensas intermitentes) est&#225;n dise&#241;ados para capturar la atenci&#243;n, entonces no alcanza con recomendar solamente el &#8220;uso responsable&#8221; de esos usuarios. Hay un deber reforzado de cuidado. Esto implica revisar <strong>modelos de recomendaci&#243;n</strong>, limitar pr&#225;cticas de perfilado comercial, reducir la hiperpersonalizaci&#243;n y transparentar c&#243;mo operan los sistemas algor&#237;tmicos cuando interact&#250;an con cuentas de menores. La responsabilidad no es solo de las familias o de las escuelas: es tambi&#233;n empresarial y, en &#250;ltima instancia, regulatoria&#8221;, sigue Elebi, consultora y autora del sitio <strong><a href="https://www.dhytecno.ar/">DHyTecno</a>.</strong></p><p>Como posibles soluciones a este dise&#241;o adictivo, considera Elebi: &#8220;Algunos posibles aspectos a considerar podr&#237;an ser una combinaci&#243;n de obligaciones estructurales para las plataformas y pol&#237;ticas p&#250;blicas centradas en derechos. Reglas claras sobre dise&#241;o seguro por defecto,<strong> prohibici&#243;n o fuertes restricciones a la publicidad comportamental</strong> (publicidad segmentada, basada en las conductas) dirigida a menores, evaluaciones de impacto en el desarrollo y en derechos de la ni&#241;ez antes de lanzar nuevas funcionalidades, auditor&#237;as independientes de sistemas de recomendaci&#243;n y mayores exigencias de transparencia y rendici&#243;n de cuentas&#8221;, piensa.</p><p>&#8220;Al mismo tiempo, es clave fortalecer capacidades p&#250;blicas y sociales: <strong>educaci&#243;n digital </strong>cr&#237;tica, apoyo a familias y docentes, y marcos regulatorios que no deleguen toda la responsabilidad en el autocontrol individual. La discusi&#243;n deber&#237;a estar enfocada en c&#243;mo garantizamos entornos digitales compatibles con el desarrollo integral y los derechos de ni&#241;os y adolescentes sin sacrificar principios democr&#225;ticos b&#225;sicos&#8221;, cierra.</p><p>El juicio a Zuckerberg y YouTube, estiman, durar&#225; hasta finales de marzo. Cuando termine, un jurado deber&#225; responder una pregunta que la Justicia estadounidense evit&#243; desde al menos una d&#233;cada: si la responsabilidad por los da&#241;os asociados al uso de redes sociales recae &#250;nicamente en los usuarios o tambi&#233;n en las decisiones de dise&#241;o de las propias plataformas.</p><div class="pullquote"><p>Este newsletter fue escrito por un humano. Se us&#243; inteligencia artificial para resumir textos, detectar errores de redacci&#243;n, concordancia y typos. Aun as&#237;, puede contener imprecisiones.</p><p>Para cualquier comentario, correcci&#243;n o sugerencia, pod&#233;s responder este mail. Si ten&#233;s informaci&#243;n sobre un hackeo, me pod&#233;s contactar por ac&#225; o por mis redes.</p><p>Si te sirvi&#243;, compartilo: tu recomendaci&#243;n org&#225;nica es mucho m&#225;s valiosa que cualquier campa&#241;a publicitaria.</p></div><div class="captioned-image-container"><figure><a class="image-link image2" target="_blank" href="http://brodersendarknews.com" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png" width="48" height="48" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:512,&quot;width&quot;:512,&quot;resizeWidth&quot;:48,&quot;bytes&quot;:30200,&quot;alt&quot;:&quot;&quot;,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:&quot;http://brodersendarknews.com&quot;,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" title="" srcset="https://substackcdn.com/image/fetch/$s_!vK-q!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 424w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 848w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1272w, https://substackcdn.com/image/fetch/$s_!vK-q!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F72f08498-8f8e-4ea5-af41-0ae8bf12bcb4_512x512.png 1456w" sizes="100vw" loading="lazy"></picture><div></div></div></a></figure></div><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://www.brodersendarknews.com/p/adictivas-por-diseno-claves-juicio-zuckerberg-meta-youtube?utm_source=substack&utm_medium=email&utm_content=share&action=share&quot;,&quot;text&quot;:&quot;Share&quot;,&quot;action&quot;:null,&quot;class&quot;:&quot;button-wrapper&quot;}" data-component-name="ButtonCreateButton"><a class="button primary button-wrapper" href="https://www.brodersendarknews.com/p/adictivas-por-diseno-claves-juicio-zuckerberg-meta-youtube?utm_source=substack&utm_medium=email&utm_content=share&action=share"><span>Share</span></a></p><p><em>Juan Brodersen</em></p>]]></content:encoded></item></channel></rss>