<?xml version='1.0' encoding='UTF-8'?><rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:openSearch="http://a9.com/-/spec/opensearchrss/1.0/" xmlns:blogger="http://schemas.google.com/blogger/2008" xmlns:georss="http://www.georss.org/georss" xmlns:gd="http://schemas.google.com/g/2005" xmlns:thr="http://purl.org/syndication/thread/1.0" version="2.0"><channel><atom:id>tag:blogger.com,1999:blog-21555208</atom:id><lastBuildDate>Mon, 17 Aug 2026 04:01:00 +0000</lastBuildDate><category>Hacking</category><category>Eventos</category><category>Seguridad Informática</category><category>Curiosidades</category><category>pentesting</category><category>AI</category><category>IA</category><category>0xWord</category><category>Inteligencia Artificial</category><category>ciberseguridad</category><category>Privacidad</category><category>Google</category><category>conferencias</category><category>MyPublicInbox</category><category>Libros</category><category>Telefónica</category><category>formación</category><category>ElevenPaths</category><category>Humor</category><category>Cursos</category><category>charlas</category><category>Malware</category><category>hardening</category><category>Artificial Intelligence</category><category>pentest</category><category>Latch</category><category>LLM</category><category>hackers</category><category>Iphone</category><category>GenAI</category><category>Identidad</category><category>Linux</category><category>Windows</category><category>Comics</category><category>Fingerprinting</category><category>Android</category><category>Apple</category><category>Eleven Paths</category><category>Internet</category><category>No Lusers</category><category>Machine Learning</category><category>Tempos</category><category>FOCA</category><category>Spectra</category><category>Universidad</category><category>LLMs</category><category>Metadatos</category><category>Reto Hacking</category><category>Entrevistas</category><category>Análisis Forense</category><category>personal</category><category>iOS</category><category>ChatGPT</category><category>e-mail</category><category>Cómics</category><category>Facebook</category><category>Generative-AI</category><category>LUCA</category><category>WhatsApp</category><category>Aura</category><category>Estafas</category><category>Microsoft</category><category>Cálico Electrónico</category><category>auditoría</category><category>Python</category><category>redes</category><category>GenerativeAI</category><category>SQL Injection</category><category>bug</category><category>twitter</category><category>Spam</category><category>Web3</category><category>Criptografía</category><category>big data</category><category>metasploit</category><category>mitm</category><category>Música</category><category>Cognitive Intelligence</category><category>Blockchain</category><category>innovación</category><category>Cognitive Services</category><category>PowerShell</category><category>BigData</category><category>fraude</category><category>Internet Explorer</category><category>Movistar Home</category><category>cibercrimen</category><category>Deep Learning</category><category>WiFi</category><category>Movistar</category><category>Phishing</category><category>OSINT</category><category>bugs</category><category>hardware</category><category>Cifrado</category><category>Windows Vista</category><category>Herramientas</category><category>Windows Server</category><category>bitcoin</category><category>Blind SQL Injection</category><category>criptomonedas</category><category>2FA</category><category>Windows 7</category><category>programación</category><category>DeepFakes</category><category>Youtube</category><category>ipad</category><category>XSS</category><category>tokens</category><category>CON</category><category>Open Source</category><category>exploit</category><category>IE IE9</category><category>Generative AI</category><category>Juegos</category><category>IPv6</category><category>BING</category><category>Seguridad Física</category><category>Bitcoins</category><category>tokenomics</category><category>Apache</category><category>Cloud computing</category><category>blog</category><category>ciberespionaje</category><category>exploiting</category><category>podcasts</category><category>Firefox</category><category>libro</category><category>Gmail</category><category>DNS</category><category>IoT</category><category>blogs</category><category>podcast</category><category>GPT</category><category>fuga de datos</category><category>Gemini</category><category>Living Apps</category><category>Windows 10</category><category>Google Chrome</category><category>Movistar +</category><category>cons</category><category>SMS</category><category>fortificación</category><category>Software Libre</category><category>redes sociales</category><category>antimalware</category><category>GPRS</category><category>.NET</category><category>GPS</category><category>IIS</category><category>Shodan</category><category>jailbreak</category><category>Cracking</category><category>PHP</category><category>metadata</category><category>MySQL</category><category>Wordpress</category><category>Red Team</category><category>spoofing</category><category>Google Play</category><category>OpenAI</category><category>Oracle</category><category>SQL Server</category><category>SmartContracts</category><category>Wireless</category><category>Mac OS X</category><category>Ubuntu</category><category>e-crime</category><category>kali</category><category>Windows 8</category><category>cloudflare</category><category>fraude online</category><category>iPv4</category><category>leak</category><category>Cloud</category><category>SmartTV</category><category>Wayra</category><category>javascript</category><category>Windows XP</category><category>ciberguerra</category><category>hacked</category><category>PCWorld</category><category>conferencia</category><category>microhistorias</category><category>developer</category><category>Citrix</category><category>Faast</category><category>Living App</category><category>Quantum</category><category>Amazon</category><category>BlueTooth</category><category>HTTP</category><category>Telegram</category><category>gaming</category><category>Chrome</category><category>Prompt Injection</category><category>Troyanos</category><category>Técnicoless</category><category>docker</category><category>exploits</category><category>https</category><category>metaverso</category><category>radio</category><category>Java</category><category>Office</category><category>Tacyt</category><category>Talentum</category><category>Técnico-less</category><category>UAC</category><category>biometría</category><category>fan Tokens</category><category>Claude</category><category>Fake News</category><category>LDAP</category><category>ciberestafas</category><category>token</category><category>APT</category><category>Blind LDAP Injection</category><category>OOXML</category><category>SmartHome</category><category>fugas de información</category><category>Excel</category><category>Kali Linux</category><category>LDAP Injection</category><category>Proxy</category><category>bots</category><category>robots</category><category>ssl</category><category>Botnets</category><category>PDF</category><category>Terminal Services</category><category>apps</category><category>smartphone</category><category>Hijacking</category><category>Llama</category><category>Raspberry Pi</category><category>anonimato</category><category>Azure</category><category>Bit2Me</category><category>Evil Foca</category><category>TOR</category><category>chatbot</category><category>dibujos</category><category>esteganografía</category><category>Agentic</category><category>FakeNews</category><category>Firewall</category><category>MetaShield Protector</category><category>Movistar+</category><category>TID</category><category>adware</category><category>cine</category><category>legalidad</category><category>Fugas de Datos</category><category>Instagram</category><category>Movistar Plus</category><category>NFTs</category><category>datos</category><category>nft</category><category>singularity hackers</category><category>ODF</category><category>footprinting</category><category>MS SQL Server</category><category>TOTP</category><category>charla</category><category>curso</category><category>e-goverment</category><category>makers</category><category>pentester</category><category>ransomware</category><category>Botnet</category><category>fuga de información</category><category>LOPD</category><category>Mac</category><category>legislación</category><category>CDO</category><category>DeepSeek</category><category>cómic</category><category>VPN</category><category>Voip</category><category>documentación</category><category>ethereum</category><category>hacktivismo</category><category>macOS</category><category>pentesters</category><category>DeepLearning</category><category>Perplexity</category><category>SEO</category><category>reversing</category><category>API</category><category>Active Directory</category><category>Alexa</category><category>BlackSEO</category><category>Calendario_Torrido</category><category>IBM</category><category>VR/AR</category><category>Deep Web</category><category>Dust</category><category>RSS</category><category>webcam</category><category>wikileaks</category><category>HTML</category><category>SQLi</category><category>Sinfonier</category><category>Siri</category><category>chat</category><category>programación .NET</category><category>troyano</category><category>GSM</category><category>Linkedin</category><category>Mozilla Firefox</category><category>Webmails</category><category>forensics</category><category>Agentic AI</category><category>Bard</category><category>P2P</category><category>SmartWiFi</category><category>Twitel</category><category>Exchange Server</category><category>GitHub</category><category>ML</category><category>Tu.com</category><category>Windows TI Magazine</category><category>Yahoo</category><category>hacker</category><category>Cybersecurity</category><category>Hotmail</category><category>Informática64</category><category>Open Gateway</category><category>OpenSource</category><category>Spotify</category><category>XBOX</category><category>antispam</category><category>e-mails</category><category>0day</category><category>3G</category><category>Captchas</category><category>Firma Digital</category><category>Informática 64</category><category>Joomla</category><category>Metashield</category><category>Microsoft Office</category><category>OpenOffice</category><category>antivirus</category><category>arduino</category><category>tuenti</category><category>Debian</category><category>DevOps</category><category>sniffers</category><category>vulnerabilidades</category><category>ENS</category><category>Kubernetes</category><category>PGP</category><category>Path 5</category><category>Ruby</category><category>SSH</category><category>USB</category><category>bias</category><category>criptoanálisis</category><category>e-commerce</category><category>Blogger</category><category>Blue Team</category><category>DirtyTooth</category><category>GDPR</category><category>NFC</category><category>Office365</category><category>OpenGateway</category><category>RSA</category><category>SPF</category><category>TikTok</category><category>dkim</category><category>doxing</category><category>drones</category><category>ingeniería social</category><category>scada</category><category>AMSTRAD</category><category>CISO</category><category>CSPP</category><category>Google Cloud</category><category>Momentus Ridiculous</category><category>Oauth2</category><category>Office 365</category><category>Sun</category><category>antiphishing</category><category>app</category><category>chatbots</category><category>cuentos</category><category>foolish</category><category>sci-fi</category><category>spear phishing</category><category>3D Printer</category><category>BLE</category><category>DNIe</category><category>Google Authenticator</category><category>Hastalrabo de tontos</category><category>OTP</category><category>RDP</category><category>Skype</category><category>Smart Contracts</category><category>Sun Solaris</category><category>certificados digitales</category><category>kernel</category><category>sexting</category><category>tecnología</category><category>CSRF</category><category>GAN</category><category>Messenger</category><category>Netflix</category><category>OAuth</category><category>Smart Home</category><category>antiransomware</category><category>pentesting persistente</category><category>BSQLi</category><category>D.O.S.</category><category>DEFCON</category><category>DeFi</category><category>Deep Reasoning</category><category>Google Home</category><category>Humanos Digitales</category><category>ONG</category><category>SIM</category><category>SQLite</category><category>Seguridad</category><category>Virus</category><category>Windows 8.1</category><category>Windows Server 2016</category><category>control parental</category><category>evento</category><category>David Hasselhoff</category><category>Edge</category><category>IE9</category><category>Meta</category><category>OS X</category><category>Opera</category><category>PQC</category><category>SecDevOps</category><category>Steve Jobs</category><category>Websticia</category><category>algoritmo</category><category>deep fakes</category><category>entrevista</category><category>estegoanálisis</category><category>3D</category><category>DDOS</category><category>DeepWeb</category><category>Forefront</category><category>MVP</category><category>Mobile Connect</category><category>Multimedia</category><category>OWASP</category><category>Outlook</category><category>SealSign</category><category>Tempest</category><category>Visual Studio</category><category>coches</category><category>e-health</category><category>ehealth</category><category>leaks</category><category>Bot</category><category>Connection String Parameter Pollution</category><category>FTP</category><category>Forensic Foca</category><category>GSMA</category><category>GitHub Copilot</category><category>Intel</category><category>RFID</category><category>Realidad Virtual</category><category>RedHat</category><category>SLM</category><category>Sharepoint</category><category>ciberterrorismo</category><category>kevin Mitnick</category><category>spyware</category><category>Ads</category><category>App Store</category><category>Apple Safari</category><category>ElevenPahts</category><category>MSDOS</category><category>MacBook</category><category>OpenSSL</category><category>PKI</category><category>Ruby on Rails</category><category>Safari</category><category>TV</category><category>Vbooks</category><category>WAF</category><category>cyberbullying</category><category>e-sports</category><category>html5</category><category>sextorsion</category><category>AWS</category><category>Adobe</category><category>AntiDDOS</category><category>Blind XPath Injection</category><category>CMS</category><category>Clickjacking</category><category>DMZ</category><category>DeepReasoning</category><category>DoS</category><category>IDS</category><category>IE7</category><category>LFI</category><category>Mastodon</category><category>Rootkits</category><category>Steve Wozniak</category><category>TCP/IP</category><category>Windows Mobile</category><category>Windows Phone</category><category>avatares</category><category>deporte</category><category>domótica</category><category>ibombshell</category><category>master</category><category>4G</category><category>ASM</category><category>Certificate Pinning</category><category>DLP</category><category>Dropbox</category><category>GNU</category><category>HaaC</category><category>ICS</category><category>Lion</category><category>Music</category><category>PLCs</category><category>RFI</category><category>SenderID</category><category>Smart City</category><category>SmartID</category><category>TLS</category><category>Vibe Coding</category><category>Windows Server 2008</category><category>Windows Server 2012</category><category>anonymous</category><category>ciberspionaje</category><category>cookies</category><category>email</category><category>fútbol</category><category>nmap</category><category>patentes</category><category>smartcities</category><category>0days</category><category>Adobe Flash</category><category>Buffer Overflow</category><category>Cisco</category><category>Click-Fraud</category><category>Google Maps</category><category>HSTS</category><category>Hadoop</category><category>ICA</category><category>PPTP</category><category>SMTP</category><category>Samsung</category><category>Stable Diffusion</category><category>Virtualización</category><category>Wi-Fi</category><category>XSPA</category><category>antispoofing</category><category>iMessage</category><category>pentesting continuo</category><category>scratch</category><category>2FWB</category><category>BASIC</category><category>BOFH</category><category>Bill Gates</category><category>BlackBerry</category><category>C</category><category>Cognitive Ingelligence</category><category>Cognitives Intelligence</category><category>DeepFake</category><category>Drupal</category><category>Go</category><category>Gremlin</category><category>Novell</category><category>Porno</category><category>Recover Messages</category><category>SLAAC</category><category>Sappo</category><category>Steganografía</category><category>Telefonica</category><category>Tinder</category><category>UMTS</category><category>Wallet</category><category>Windows live</category><category>carding</category><category>censura</category><category>ciberdefensa</category><category>ciencia</category><category>cso</category><category>defacement</category><category>delitos</category><category>paypal</category><category>regulación</category><category>wardriving</category><category>web30</category><category>2G</category><category>5G</category><category>ASP</category><category>AirPods</category><category>Apache Hadoop</category><category>Bitlocker</category><category>CDCO</category><category>CTF</category><category>Copilot</category><category>EDR</category><category>FaceID</category><category>Grooming</category><category>HoneyPot</category><category>Kioskos Interactivos</category><category>MDM</category><category>Magento</category><category>MetaShield Client</category><category>Microsoft Teams</category><category>Microsoft Word</category><category>Moodle</category><category>Mozilla</category><category>MyPubilcInbox</category><category>Mythos</category><category>NoSQL</category><category>QR Code</category><category>Rogue AP</category><category>S/MIME</category><category>SNMP</category><category>SSRF</category><category>SandaS</category><category>Tesla</category><category>UNIX</category><category>UX</category><category>VIVO</category><category>Wikipedia</category><category>antifraude</category><category>bootkits</category><category>iCloud</category><category>iWork</category><category>mASAPP</category><category>pentestin</category><category>pentesting by desing</category><category>seguridad informáitca</category><category>seminarios</category><category>AES</category><category>Anthropic</category><category>AppStore</category><category>BBDD</category><category>Bash</category><category>BuscanHackers</category><category>CTO</category><category>Cibersecurity</category><category>Cortana</category><category>DMARC</category><category>DNIe 3.0</category><category>FaceTime</category><category>Google+</category><category>Growth hacking</category><category>HTML 5</category><category>IAG</category><category>JSP</category><category>Kerberos</category><category>Maps</category><category>Monero</category><category>MongoDB</category><category>Nodejs</category><category>OpenVPN</category><category>Patchs</category><category>Perl</category><category>Pigram</category><category>PostgreSQL</category><category>PrestaShop</category><category>Sandas GRC</category><category>Snapchat</category><category>Sony</category><category>TrueCrypt</category><category>Vamps</category><category>Web3.0</category><category>XML</category><category>Xpath injection</category><category>Zoom</category><category>deception</category><category>eGarante</category><category>firewalls</category><category>ladrones</category><category>litecoin</category><category>malvertising</category><category>switching</category><category>APTs</category><category>Access</category><category>Acens</category><category>Apple Watch</category><category>Applet</category><category>C#</category><category>Cagadas</category><category>Cognite Services</category><category>Cognitie Intelligence</category><category>Coldfusion</category><category>EMV</category><category>Google Car</category><category>Google Drive</category><category>Google Glass</category><category>Grok</category><category>Guardrails</category><category>HPP</category><category>Hackin9</category><category>Hosting</category><category>IE8</category><category>JSON</category><category>Lasso</category><category>Lenguaje C</category><category>Live</category><category>Maltego</category><category>MetaShield Forensics</category><category>Microsoft IIS</category><category>Orange</category><category>Path 6</category><category>Pyhton</category><category>RootedCON</category><category>SDR</category><category>SQL</category><category>WPA</category><category>Windows 95</category><category>Zero Trust</category><category>aviación</category><category>aviones</category><category>comunicación</category><category>crime</category><category>dni</category><category>estegonanálisis</category><category>fotónica</category><category>hash</category><category>javascipt</category><category>nginx</category><category>número de teléfono</category><category>ransomsware</category><category>router</category><category>routing</category><category>smartphones</category><category>vulnerabilidad</category><category>AirBnB</category><category>BlackASO</category><category>CCTV</category><category>CDN</category><category>Certificate Transparency</category><category>Cpanel</category><category>Creepware</category><category>DHCP</category><category>Dapp</category><category>Deep  Learning</category><category>DeepThink</category><category>Django</category><category>Espías</category><category>Exchange</category><category>Fake AV</category><category>Fedora</category><category>Gentoo</category><category>Gtalk</category><category>HOLS</category><category>Hyper-V</category><category>Hyperboria</category><category>IE</category><category>JBOSS</category><category>Kaspersky</category><category>LTE</category><category>MCP</category><category>Macintosh</category><category>MetaShield Forenscis</category><category>Metashield Analyzer</category><category>Micro:bit</category><category>NTP</category><category>OSX</category><category>PCI</category><category>POP3</category><category>Palo Alto</category><category>Poker</category><category>PowerPoint</category><category>QRCode</category><category>RTL</category><category>Reactos</category><category>Robtex</category><category>SAP</category><category>SS7</category><category>SalesForce</category><category>Secure Boot</category><category>Shaadow</category><category>Shadow</category><category>Signal</category><category>Singularity</category><category>Slack</category><category>Suse</category><category>System Center</category><category>TFM</category><category>Uber</category><category>VMWare</category><category>WebServices</category><category>X</category><category>actualizaciones</category><category>antiphising</category><category>artificial inteligence</category><category>bizum</category><category>cheater</category><category>chromium</category><category>ciberfraude</category><category>ciberguera</category><category>defacers</category><category>e-bike</category><category>e-learning</category><category>eSports</category><category>evilgrade</category><category>iPhone 6</category><category>man in the middle</category><category>musica</category><category>penteting</category><category>smartcards</category><category>smshing</category><category>AFP</category><category>AMSI</category><category>AirTags</category><category>Alan Turing</category><category>Alise Devices</category><category>Apolo</category><category>Asterisk</category><category>Burp</category><category>CERT</category><category>COBOL</category><category>Canon</category><category>Chromecast</category><category>DRM</category><category>Dall-e</category><category>EXIF</category><category>Ebay</category><category>Evernote</category><category>Flash</category><category>FreeNET</category><category>Generatie-AI</category><category>Google Assistant</category><category>HPKP</category><category>HUE</category><category>HortonWorks</category><category>IMAP</category><category>INCIBE</category><category>IPS</category><category>ISV Magazine</category><category>IaaS</category><category>Inteligencia Arificial</category><category>Inteligencia Artiifical</category><category>KYC</category><category>Keylogger</category><category>Line</category><category>Lockpicking</category><category>Longhorn</category><category>MachineLearning</category><category>MetaShield for IIS</category><category>Microhistoias</category><category>MyPublicInobx</category><category>NAP</category><category>NLP</category><category>Nokia</category><category>Path Transversal</category><category>Pentestng</category><category>Play framework</category><category>Prompt Injetion</category><category>Qustodio</category><category>RCS</category><category>Reinforcement Learning</category><category>Rogue AV</category><category>Rogue BT</category><category>RoundCube</category><category>SDL</category><category>SQL Injeciton</category><category>SSOO</category><category>SmartSteps</category><category>Squirrelmail</category><category>Surface</category><category>Swift</category><category>Symantec</category><category>TomCat</category><category>Touch ID</category><category>Tu</category><category>Twitch</category><category>VNC</category><category>WEP</category><category>Windows CE</category><category>Windows Serbver 2016</category><category>Windows Server 2008 R2</category><category>Word</category><category>antimwalware</category><category>auditoria</category><category>ciberfensa</category><category>cibersegurdiad</category><category>cjdns</category><category>código penal</category><category>decompilador</category><category>devoOps</category><category>e-government</category><category>eSIM</category><category>estegoanális</category><category>fake brokers</category><category>fraud</category><category>haking</category><category>homePWN</category><category>iPhone 5c</category><category>iPhone 7</category><category>iPhone X</category><category>ipfs</category><category>liliac</category><category>pederastas</category><category>pentesting persistentes</category><category>pharming</category><category>phising</category><category>ransonware</category><category>solidaridad</category><category>threads</category><category>wearables</category><category>. BigData</category><category>0xWork</category><category>0xWrod</category><category>AGI</category><category>AJAX</category><category>ANI</category><category>AR</category><category>AS/400</category><category>ASI</category><category>Acer</category><category>AirOS</category><category>Apache Ambari</category><category>Apache CouchDB</category><category>Apache Storm</category><category>AppLocker</category><category>Apple Wath</category><category>Apple. Siri</category><category>Apple. iPhone</category><category>Artificial Intellligence</category><category>Aura Movistar Home</category><category>Badoo</category><category>BarrelFish</category><category>Bilind SQL Injection</category><category>BluetTooth</category><category>C++</category><category>CASB</category><category>CSIRT</category><category>CSP</category><category>CSSP</category><category>Cassandra</category><category>ChatON</category><category>Chatbotx</category><category>Cloiud</category><category>Cognitie Services</category><category>Cooud</category><category>Cómis</category><category>DNI 3.0</category><category>De mi boca</category><category>DeepLeraning</category><category>DreamWeaver</category><category>ElasticSearch</category><category>ElevenPatchs</category><category>Evil Signature Injection</category><category>Exchangers</category><category>FIDO</category><category>FOCA.</category><category>FileVault</category><category>Firefox OS</category><category>Fortran</category><category>FreeBSD</category><category>GenerariveAI</category><category>Generartive-AI</category><category>GenerativaAI</category><category>GesConsultores</category><category>Google Adwords</category><category>Google Docs</category><category>Google Now</category><category>Grindr</category><category>Guadalinex</category><category>HPC</category><category>HTC</category><category>Hacking IA</category><category>Hadening</category><category>Harening</category><category>Hololens</category><category>Hotmail. Google</category><category>Huawei</category><category>IBERIA</category><category>IIoT</category><category>ISO</category><category>ITIL</category><category>Informática</category><category>Insights</category><category>Inteco</category><category>Inteliencia Artificial</category><category>Inteligencia Artíficial</category><category>Inteligenica Artificial</category><category>Intelligencia Artificial</category><category>JQuery</category><category>JavasScript</category><category>Jenkins</category><category>JetSetMe</category><category>Katana</category><category>Kindle</category><category>LDA Injection</category><category>LDAP Injeciton</category><category>LLMx</category><category>Lenguaje D</category><category>Liferay</category><category>Liiving App</category><category>Liniux</category><category>Logitech</category><category>Londres</category><category>Lumia</category><category>Lync</category><category>MD5</category><category>MIME</category><category>MMS</category><category>Mac OS</category><category>Machine Learing</category><category>MetaShield for SharePoint</category><category>Metasplloit</category><category>Metro</category><category>Minecraft</category><category>Movistar + Movistar+</category><category>MyPublicInbo</category><category>MyPublicInbos</category><category>MyPublicInbox.</category><category>MyPublicInox</category><category>MyPulicInbox</category><category>NASA</category><category>NetBus</category><category>No Lusres</category><category>ONO</category><category>OSPF</category><category>OSS</category><category>OWIN</category><category>Oculus</category><category>Omron</category><category>Open X-Ghange</category><category>Open-XChange</category><category>OpenID</category><category>OpenNebula</category><category>OpenWRT</category><category>OwnCloud</category><category>Patch 5</category><category>Periscope</category><category>Progración</category><category>Prompt Injeciton</category><category>RFID. EMV</category><category>RFU</category><category>RGPD</category><category>RIP</category><category>Revover Messages</category><category>Robotx</category><category>SASE</category><category>SIEM</category><category>SIGINT</category><category>SPDY</category><category>SRP</category><category>SSID Pinning</category><category>STEM</category><category>SVG</category><category>SWF</category><category>Safety</category><category>Safri</category><category>Sir</category><category>Sistema Experto</category><category>SmartAccess</category><category>SmartDigits</category><category>SmartGrid</category><category>SmartWiiFi</category><category>Snort</category><category>Snowden</category><category>Solaris</category><category>Spartan</category><category>Spotbros</category><category>Steve Ballmer</category><category>SugarCRM</category><category>TMG</category><category>TPM</category><category>Telefóncia</category><category>Telnet</category><category>Twiter</category><category>Twitter.</category><category>Twombola</category><category>UIP</category><category>URL</category><category>Umbraco</category><category>VBA</category><category>VENOM</category><category>WAMP</category><category>Wacom</category><category>Watson</category><category>Web</category><category>Web 3</category><category>WebShell</category><category>Webmails IE</category><category>WhtasApp</category><category>Windows 98</category><category>Windows Defender</category><category>Windows Phone 7</category><category>Windows Server 8</category><category>WordPess</category><category>WordPres</category><category>ZigBee</category><category>antiramsonware</category><category>auditoriía</category><category>bluesky</category><category>ciberseguriad</category><category>craking</category><category>criptoanális</category><category>cuirosidades</category><category>doxing.</category><category>ePad</category><category>eleven paths. Sinfonier</category><category>emails</category><category>estegonálisis</category><category>eurosender</category><category>evento.</category><category>eventos conferencias</category><category>expliting</category><category>fintech</category><category>firmware</category><category>forensec</category><category>frade</category><category>fuga de información.</category><category>fugas de daos</category><category>futbolín</category><category>gazapos</category><category>hackers.</category><category>hardeing</category><category>hardenning</category><category>hardning</category><category>hijakcing</category><category>iOS 11</category><category>iOS 8</category><category>iOS iPhone</category><category>iPad Pro</category><category>iTunes</category><category>identidades</category><category>identidads</category><category>ironGate</category><category>jugos</category><category>malvetising</category><category>mediawiki</category><category>mtim</category><category>ntfs</category><category>pedofília</category><category>penesting</category><category>pentesting by design</category><category>pentesting persiste</category><category>pentetesting</category><category>ponencias</category><category>poodle</category><category>presonal</category><category>programación. .NET</category><category>programción</category><category>ramsonware</category><category>redes social</category><category>rumor</category><category>seguridad informatica</category><category>smishing</category><category>socket</category><category>spectrum</category><category>t</category><category>tabnabbing</category><category>unlock</category><category>veeam</category><category>winsocket</category><title>Un informático en el lado del mal</title><description>Blog personal de Chema Alonso sobre sus cosas.</description><link>http://www.elladodelmal.com/</link><managingEditor>noreply@blogger.com (Chema Alonso)</managingEditor><generator>Blogger</generator><openSearch:totalResults>7440</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-9068602688280466680</guid><pubDate>Mon, 17 Aug 2026 04:01:00 +0000</pubDate><atom:updated>2026-08-17T06:01:00.186+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">API</category><category domain="http://www.blogger.com/atom/ns#">ChatGPT</category><category domain="http://www.blogger.com/atom/ns#">Cifrado</category><category domain="http://www.blogger.com/atom/ns#">Claude</category><category domain="http://www.blogger.com/atom/ns#">criptoanálisis</category><category domain="http://www.blogger.com/atom/ns#">Criptografía</category><category domain="http://www.blogger.com/atom/ns#">Deep Reasoning</category><category domain="http://www.blogger.com/atom/ns#">DeepReasoning</category><category domain="http://www.blogger.com/atom/ns#">Gemini</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">LLM</category><category domain="http://www.blogger.com/atom/ns#">LLMs</category><category domain="http://www.blogger.com/atom/ns#">pentest</category><category domain="http://www.blogger.com/atom/ns#">pentesting</category><category domain="http://www.blogger.com/atom/ns#">Privacidad</category><title>Pensamientos Robados: Cómo descifrar y weaponizar trazas de razonamiento en LLMs</title><description>&lt;div style=&quot;text-align: justify;&quot;&gt;Este domingo, aprovechando un poco de la tranquilidad del día, me he leído el trabajo de &lt;a href=&quot;https://www.alphaxiv.org/pdf/2608.09867v1&quot;&gt;Stolen Thoughts&lt;/a&gt;, que explica cómo descifrar las trazas de razonamiento de los modelos &lt;i&gt;&lt;b&gt;LLM&lt;/b&gt;&lt;/i&gt; frontera que se entregan cifradas a los clientes, durante el proceso de resolución de un Prompt complejo que exige una cadena de pensamientos (&lt;i&gt;&lt;b&gt;Chain-of-Thoughts&lt;/b&gt;&lt;/i&gt;).&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://stolen-thoughts.com/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;590&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg6_ePYJND4NmP6SvGTcfllN1kyKOcdxt3kDo3h6wisOg_vgnZKhrYgvulWxE_oQZGI0HM8afxa3PmePjeH8x2asnpJJvbX9LhRZWhC18P9RhZ7PlQ9gPoLmfPayXQgu-2DT0TUmLZ0wM9N2n7127m16HoJ_736WTIUEqPtzkWPZioeqzvq1D8p/w640-h402/Stolen0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;&lt;a href=&quot;https://stolen-thoughts.com/&quot;&gt;Pensamientos Robados - Cómo descifrar y&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://stolen-thoughts.com/&quot;&gt;weaponizar trazas de razonamiento en LLMs&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Justo de estas trazas que van cifradas, es de lo que trata el &lt;i&gt;&lt;b&gt;paper&lt;/b&gt;&lt;/i&gt; del que os hablo en este artículo, titulado: &quot;&lt;a href=&quot;https://www.alphaxiv.org/pdf/2608.09867v1&quot;&gt;Stealing Reasoning Traces from Proprietary LLM APIs&lt;/a&gt;&quot; y que ha puesto de manifiesto cómo esta debilidad se puede utilizar de formas muy curiosas.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.alphaxiv.org/pdf/2608.09867v1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1596&quot; data-original-width=&quot;1160&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_0s3g0BtDYiC4Akwiibo-NdRR5HAYq5j2y2FIn44Y7mGTBi5qnCWkb7oiW9abS88FLMH_Ecm_fvRuQFkAMopM5ycCu8YvFiX2F4tb6p1To-hI6jfItUGIT6k-YPzSd6ib41b2BDZHjExzKUpHr1hElYTu6Zw3piPxb7agnnEfTfgt_zDmwkdg/w466-h640/stolen2.jpg&quot; width=&quot;466&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 2:&amp;nbsp;&lt;span style=&quot;text-align: justify;&quot;&gt;&lt;a href=&quot;https://www.alphaxiv.org/pdf/2608.09867v1&quot;&gt;Stealing Reasoning Traces from Proprietary LLM APIs&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Supongo que alguna vez habréis usado &lt;i style=&quot;font-weight: bold;&quot;&gt;ChatGPT, DeepSeek, Claude &lt;/i&gt;o&lt;i style=&quot;font-weight: bold;&quot;&gt; Gemini&lt;/i&gt;, y habréis visto las trazas de razonamiento ir saliendo por pantalla. Esto lo utilizamos para aprender cómo está razonando, y sobre todo para saber si tu idea va por el lado correcto o no. En el trabajo de &quot;&lt;a href=&quot;https://www.elladodelmal.com/2025/03/estego-cripto-solo-al-alcance-de-deep.html&quot;&gt;Estego &amp;amp; Cripto sólo al alcance de Deep Reasoning AI&lt;/a&gt;&quot; para nosotros era fundamental, ya que podríamos saber si el modelo estaba por el buen camino o no, para resolver las codificaciones cifradas.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;649&quot; data-original-width=&quot;485&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGlxuPvsCIvroRvztIaGw6Munmx4sWMdpXbWYXzTFmt8ZXBxrPSdENqyHKUlKYR2KI2pb48LVg_mLlJhaxy9R9xdnapH4UVUPD8YReOyl22-yhIImdXUzHRzE8egQuQBBhcoKeOLkbhBuXZe_8OU8hWB0CXFkF4lI2altrnGCW12nY0bXt7hsd/w299-h400/HackingIA_web.jpg&quot; width=&quot;299&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 3:&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking IA: Jailbreak, Prompt Injection, Hallucinations &amp;amp; Unalignment&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;escrito por &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Chema Alonso&lt;/a&gt; con la colaboración de &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/AmadorAparicio&quot; style=&quot;text-align: justify;&quot;&gt;Amador Aparicio&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/ManuelSLemos&quot; style=&quot;text-align: justify;&quot;&gt;Manuel S. Lemos&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;y&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/JPalanco&quot; style=&quot;text-align: justify;&quot;&gt;José Palanco&lt;/a&gt; en &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Lo que sucede es que estas trazas de razonamiento, es decir, estas &lt;i&gt;&lt;b&gt;Chain of Thoughts &lt;/b&gt;&lt;/i&gt;que se entregan a los clientes, no se muestran todas, y algunas van cifradas en variables. Estas variables son enviadas desde el cliente al servidor, donde son descifradas y utilizadas como contexto, para seguir razonando. Es decir, que el servidor sabe descifrar estas trazas.&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.alphaxiv.org/pdf/2608.09867v1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;793&quot; data-original-width=&quot;1564&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiO7r75yUM3HJsxOTgvHveJ6UJ2aPCPRUIOwgx1o1JsidHQcoOYWD5Cdneo4pj2h0vE0tQftF7iH40i7lRsVQ9h18iElDv60pLYOCgAxBOItK39_E3buhRsQ3dKf5r9IIZqubaFn_jTqLaBcNN5M0ga4wmxOT5E-lCRvfWB5YKSaqSwbF25Y2rl/w640-h324/Stolen3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 4: &lt;a href=&quot;https://www.alphaxiv.org/pdf/2608.09867v1&quot;&gt;Encrypted Thought Injection&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Sabiendo esto, lo que los investigadores han hecho es lo que llaman un ataque de &lt;i&gt;&lt;b&gt;Encrypted Thought Injection&lt;/b&gt;&lt;/i&gt;, de un modelo, a otro modelo de la misma empresa que tienen medidas de seguridad inferiores. Por ejemplo, como se ve en la imagen anterior, se coge la traza cifrada del &lt;i&gt;&lt;b&gt;Chain of Thoughts&lt;/b&gt;&lt;/i&gt; que devuelve la &lt;i&gt;&lt;b&gt;API&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;Claude Opus&lt;/b&gt;&lt;/i&gt; y se inyecta en una petición a &lt;i&gt;&lt;b&gt;Claude Haiku 4.5&lt;/b&gt;&lt;/i&gt; pidiéndole que lo transcriba y lo imprima. Y lo hace.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.alphaxiv.org/pdf/2608.09867v1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;526&quot; data-original-width=&quot;1598&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjHa59-9edL1OPDnUDuIs4Suucqz_OKx-pRL9leuRiNjkwXSvI6_pNLrzr0SythEj5Syc4DYYMf9t2jAarol0OoEMlcsk1dl51Hun37ltYhs2Vtqtf1Gp1d9xzKxh6a8m_C4l8Ze7LNYSMs8BUd8dyeH6um2WWAYSo7p1KE54T9Bxb8HJXlDHGR/w640-h210/Stolen4.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 5: &lt;a href=&quot;https://www.alphaxiv.org/pdf/2608.09867v1&quot;&gt;Compatibilidad en Chain of Thoughts cifrados entre modelos.&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Los investigadores han visto cual es la compatibilidad que &lt;i&gt;&lt;b&gt;Claude&lt;/b&gt;&lt;/i&gt;, &lt;i&gt;&lt;b&gt;GPT&lt;/b&gt;&lt;/i&gt; o &lt;i&gt;&lt;b&gt;Gemini&lt;/b&gt;&lt;/i&gt; tienen en sus diferentes versiones, y como se puede ver es bastante alta, así que es posible mover &lt;i&gt;&lt;b&gt;Stolen Thoughts&lt;/b&gt;&lt;/i&gt; de uno a otro modelo. Haciendo esto, se pueden encontrar datos personales, o prohibidos por el modo &lt;i&gt;&lt;b&gt;Harmful Mode&lt;/b&gt;&lt;/i&gt;, como en el ejemplo siguiente, donde se encuentran datos de marcas de vehículos y facilidad de ser robados, que sólo están en los &quot;&lt;i&gt;&lt;b&gt;pensamientos&lt;/b&gt;&lt;/i&gt;&quot; cifrados.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.alphaxiv.org/pdf/2608.09867v1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1202&quot; data-original-width=&quot;2622&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhM1zItPLVUYBTvCUYYcd-6GkkNjOExtRmZvjBf0R-yhLXgBMGdenSvcND62s371Ao3ySb55OiMPhAvdrQFEeHWgEpSTJtT26_AVEhYj8aZFRYwgdRm91Ww3cVCAdc4o0AANIpr23RZkbD3SxQlD8Km2SH5MroscENW8O_d8yz8JzuX2Sms-k_v/w640-h294/Stolen6.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 6: &lt;a href=&quot;https://www.alphaxiv.org/pdf/2608.09867v1&quot;&gt;Datos sobre marcas de vehículos que sufren más robos.&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Estas trazas de razonamiento se cifran por motivos diversos, pero también para evitar el &lt;i&gt;&lt;b&gt;Destilado&lt;/b&gt;&lt;/i&gt;, o lo que es lo mismo, que un modelo &lt;i&gt;&lt;b&gt;Open Source&lt;/b&gt;&lt;/i&gt; - o no - pueda utilizar &lt;i&gt;&lt;b&gt;Prompts&lt;/b&gt;&lt;/i&gt; y trazas de razonamiento completo para hacer un &lt;i&gt;&lt;b&gt;Fine-Tuning&lt;/b&gt;&lt;/i&gt; de su comportamiento a partir de la capacidad de inteligencia de un modelo comercial de frontera, que es una de las formas de optimizar costes, como os conté en el artículo de: &quot;&lt;a href=&quot;https://www.elladodelmal.com/2026/05/como-optimizar-el-gasto-en-ia-con.html&quot;&gt;Cómo optimizar el gasto en IA con arquitecturas clasificadas, orquestadas y/o destilación. El problema de la Predictibilidad de los Costes de la IA&lt;/a&gt;&quot;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://en.wikipedia.org/wiki/Knowledge_distillation&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;934&quot; data-original-width=&quot;1220&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj0Lah9KT1wR7OKkak0tjSd39zDtDVFb1eS6GV37Fpew9RoGtU9_RBOcUjIOHA35tlXxJGq147n-jUns85uEdhHqU34cGyxLdOHgQnW2zzfyeL2tMwtVPnpnGKeXGrktoXC5b0mC5dIJdMDfBHaznY22Urf4ngDBICtVnZaIl34ourrdUs-BrGP/w640-h490/Destilacion.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
  &lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 7: &lt;a href=&quot;https://www.elladodelmal.com/2026/05/como-optimizar-el-gasto-en-ia-con.html&quot;&gt;Destilación de Modelos&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Sin embargo, estos &lt;i&gt;&lt;b&gt;Thoughts&lt;/b&gt;&lt;/i&gt; cifrados pueden ser utilizados como &quot;&lt;i&gt;&lt;b&gt;Pre-fill&lt;/b&gt;&lt;/i&gt;&quot; a un modelo. Es decir, utilizar el &lt;i&gt;&lt;b&gt;Encrypted Thought Injection Attack&lt;/b&gt;&lt;/i&gt; de un modelo frontera a un modelo &lt;i&gt;&lt;b&gt;Open Source&lt;/b&gt;&lt;/i&gt; para pedirle que continúe resolviendo el problema.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.alphaxiv.org/pdf/2608.09867v1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1512&quot; data-original-width=&quot;2596&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhwjZ7mpqRzLZObP0YcXr9WJFxZMqdvA6q3AVuJZ85aEOTKGqpWgpePAQTMXq3JP3MCJtS2znwNDbOZS7QbSeuq9vbPmvwDcgDy3HXTRVCGsBnEtpbFdgKUWKyKDB-uY8-kfyL73V9SiCRWz8NnZLHyTBN3aX8Rvu-d7SJC4Kq0DrGH6vFx4_fP/w640-h372/Stolen5.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 8: &lt;a href=&quot;https://www.alphaxiv.org/pdf/2608.09867v1&quot;&gt;Pre-filling de Thoughts&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Esto puede utilizarse para &quot;&lt;i&gt;&lt;b&gt;enfocar&lt;/b&gt;&lt;/i&gt;&quot; la resolución del problema con un &lt;i&gt;&lt;b&gt;Modelo Frontera&lt;/b&gt;&lt;/i&gt;, y luego continuar con el resto del problema a partir del &lt;i&gt;&lt;b&gt;Pre-fillling&lt;/b&gt;&lt;/i&gt;. Como podéis ver en la imagen, &lt;i&gt;&lt;b&gt;Kimi-K3&lt;/b&gt;&lt;/i&gt; con el &lt;i&gt;&lt;b&gt;Pre-filling&lt;/b&gt;&lt;/i&gt; da un resultado similar. El proceso es capturar la traza cifrada, descifrarla con un modelo compatible que lo pueda descifrar y luego inyectar el pensamiento descifrado en el modelo &lt;i&gt;&lt;b&gt;Open Source &lt;/b&gt;&lt;/i&gt;para terminar de resolver el &lt;i&gt;&lt;b&gt;Prompt&lt;/b&gt;&lt;/i&gt;. Creativo.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/245-hacking-pentesting-con-inteligencia-artificial.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1688&quot; data-original-width=&quot;1298&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicZbq7z1QIW5RDLoHBFH4O2XtgQCjhHZ4YI70ksUtOQpkc1cersCsUNnlBy8wtEAnuOPOrm2KTYMBs9K3jCobjjSod4rx7ymfE0lcTFRy6LeGkzbpdGBBSx8LbifDrZfrgAsQDmDWu_rrz4htL0YJljBRe4esKTfZ0api8aLViQ398JCXBKsyX/w308-h400/HackingYPentestingconIA.jpg&quot; width=&quot;308&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;Figura 9: &lt;a href=&quot;https://0xword.com/es/libros/245-hacking-pentesting-con-inteligencia-artificial.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking &amp;amp; Pentesting con Inteligencia Artificial&lt;/a&gt;.&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;En &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;, &lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;escrito por &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://mypublicinbox.com/RafaelTroncoso&quot; style=&quot;text-align: justify;&quot;&gt;Rafael Troncoso&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/JaviPino&quot; style=&quot;text-align: justify;&quot;&gt;Javier del Pino&lt;/a&gt; y &lt;span style=&quot;text-align: justify;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/chemaalonso&quot;&gt;Chema Alonso&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;El paper muestra más usos de esta capacidad de descifrar las trazas de pensamiento cifrado, pero también que en ellas, cuando una persona comparte sus conversaciones, pueden ir datos privados, como &lt;i&gt;&lt;b&gt;API Keys&lt;/b&gt;&lt;/i&gt; o &lt;i&gt;&lt;b&gt;Passwords&lt;/b&gt;&lt;/i&gt;, así que hay que tener mucho cuidado con publicar estos datos de las &lt;i&gt;&lt;b&gt;APIs&lt;/b&gt;&lt;/i&gt; con las trazas cifradas.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.alphaxiv.org/pdf/2608.09867v1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1506&quot; data-original-width=&quot;2618&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCgnrFMwwsnqSwGZI-TG5ORnNNW-P2e_6X-IK12FC-O_crjWA_meNz_jR-ljr2iBYBn_7CoS9QO0Zd7uH-u34JC_xPV1nP5vaLxU19J0tqhfuE1_Lp8SxfdcrZA5O4JbLnHha6Qn8RJBTC4M6gkUrSUBkuAs2rFvQv7LHfzP52hP-_zNYbsoix/w640-h368/Stolen7.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 10: &lt;a href=&quot;https://www.alphaxiv.org/pdf/2608.09867v1&quot;&gt;Trazas cifradas con API Keys y Passwords&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;La verdad es que me ha parecido muy interesante el trabajo, que parte de una idea muy sencilla, que es utilizar modelos &lt;i&gt;&lt;b&gt;LLM&lt;/b&gt;&lt;/i&gt; compatibles con menos protecciones para descifrar los &lt;i&gt;&lt;b&gt;Thoughts&lt;/b&gt;&lt;/i&gt; cifrados que te da el &lt;i&gt;&lt;b&gt;LLM&lt;/b&gt;&lt;/i&gt; frontera. &lt;b&gt;&lt;u&gt;Muy hacker.&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;¡Saludos Malignos!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;Chema Alonso &lt;/b&gt;(&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;Contactar con Chema Alonso&lt;/a&gt;) &amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; font-style: italic; text-align: center;&quot;&gt;
&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;444&quot; data-original-width=&quot;800&quot; src=&quot;https://1.bp.blogspot.com/-wPU2d-hy3rM/XiyVNgM4kGI/AAAAAAAAy70/Pk1IP6-v7bQLVUNL2iWneVOgRP494eWrACLcBGAsYHQ/s640/MPICHemaalonso.jpg&quot; width=&quot;450&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/pensamientos-robados-como-descifrar-y.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg6_ePYJND4NmP6SvGTcfllN1kyKOcdxt3kDo3h6wisOg_vgnZKhrYgvulWxE_oQZGI0HM8afxa3PmePjeH8x2asnpJJvbX9LhRZWhC18P9RhZ7PlQ9gPoLmfPayXQgu-2DT0TUmLZ0wM9N2n7127m16HoJ_736WTIUEqPtzkWPZioeqzvq1D8p/s72-w640-h402-c/Stolen0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-2764195438041545953</guid><pubDate>Sun, 16 Aug 2026 06:23:00 +0000</pubDate><atom:updated>2026-08-16T09:23:23.657+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">cibercrimen</category><category domain="http://www.blogger.com/atom/ns#">ciberestafas</category><category domain="http://www.blogger.com/atom/ns#">ciberfraude</category><category domain="http://www.blogger.com/atom/ns#">DeepFake</category><category domain="http://www.blogger.com/atom/ns#">DeepFakes</category><category domain="http://www.blogger.com/atom/ns#">e-crime</category><category domain="http://www.blogger.com/atom/ns#">Estafas</category><category domain="http://www.blogger.com/atom/ns#">fraude</category><category domain="http://www.blogger.com/atom/ns#">GenAI</category><category domain="http://www.blogger.com/atom/ns#">IA</category><category domain="http://www.blogger.com/atom/ns#">Identidad</category><category domain="http://www.blogger.com/atom/ns#">Inteligencia Artificial</category><category domain="http://www.blogger.com/atom/ns#">KYC</category><title>La Policía Nacional detiene a un cibercriminal que usaba DeepFakes para obtener Certificados Digitales gracias a un Glitch</title><description>&lt;div style=&quot;text-align: justify;&quot;&gt;En el año &lt;i&gt;&lt;b&gt;2017&lt;/b&gt;&lt;/i&gt;, cuando descubrí los primeros ejemplos de técnicas de &lt;i&gt;&lt;b&gt;FaceSwapping&lt;/b&gt;&lt;/i&gt;, mi mente viajo al futuro y pensé en el mundo de los &lt;a href=&quot;https://www.elladodelmal.com/2021/07/un-historia-de-blade-runners-virtual.html&quot;&gt;Blade Runners y Replicantes Virtuale&lt;/a&gt;s, pero en el mundo digital. La capacidad de llevar &quot;&lt;i&gt;&lt;b&gt;máscaras digitales&lt;/b&gt;&lt;/i&gt;&quot; al estilo de la película &quot;&lt;i&gt;&lt;b&gt;Desafío Total (Total Recall)&lt;/b&gt;&lt;/i&gt;&quot;, cruzaba por mi cerebro. Sí, la ciencia ficción siempre me llena la cabeza de posibles futuros que pueden venir detrás cuando veo una nueva innovación.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.policia.es/_es/comunicacion_prensa_detalle.php?ID=16974&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;629&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjy-mX0gTTSC2eOL9L2OtiPFdVEaMahiOjORAD9jmkrvTuNavesBXb4AElnU_eQ_839wHF3K4C7AActoI0ryrt_nzmA8Sx7xCr2ZY1hSfsxHg-kPZV745JFLNaVBo6jaMc22yy3ovlA2WjMJmBoDKoBffJhwdjuOvVTe-5DynMcny2LUcXdM-Ey/w640-h428/policia0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;&lt;a href=&quot;https://www.policia.es/_es/comunicacion_prensa_detalle.php?ID=16974&quot;&gt;La Policía Nacional detiene a un cibercriminal que usaba&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://www.policia.es/_es/comunicacion_prensa_detalle.php?ID=16974&quot;&gt;DeepFakes para obtener Certificados Digitales gracias a un Glitch&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Durante esos años, comenzamos a trabajar mucho en el equipo de &lt;i&gt;&lt;b&gt;Ideas Locas&lt;/b&gt;&lt;/i&gt; con las técnicas de &lt;a href=&quot;https://www.elladodelmal.com/2018/02/deepfakeapp-una-ai-de-face-swapping-al.html&quot;&gt;FaceSwapping, los Autoencoders&lt;/a&gt;, las herramientas para hacer &lt;i&gt;&lt;b&gt;DeepFakes&lt;/b&gt;&lt;/i&gt;, y las técnicas de detección. El famoso &lt;a href=&quot;https://www.elladodelmal.com/2023/02/blade-runners-como-crear-un-test-de.html&quot;&gt;Test de Voight-Kampff&lt;/a&gt; digital que tanta falta sabíamos que hacía, especialmente para un mundo que se estaba yendo a &lt;i&gt;&lt;b&gt;100&lt;/b&gt;&lt;/i&gt;% digital, y donde los procesos de &lt;i&gt;&lt;b&gt;Know-Your-Customer (KYC)&lt;/b&gt;&lt;/i&gt;&amp;nbsp;debían hacerse totalmente online.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;
&lt;center&gt;&lt;iframe allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&quot; allowfullscreen=&quot;&quot; frameborder=&quot;0&quot; height=&quot;264&quot; referrerpolicy=&quot;strict-origin-when-cross-origin&quot; src=&quot;https://www.youtube.com/embed/0fLzmFEb2qg?si=fbQT2v0WbknsxJ9-&quot; title=&quot;YouTube video player&quot; width=&quot;470&quot;&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;i&gt;Figura 2: &lt;a href=&quot;https://www.youtube.com/watch?v=0fLzmFEb2qg&quot;&gt;Técnicas de IA en ciberseguridad y su impacto en Deepfakes&amp;nbsp;&lt;/a&gt;&lt;/i&gt;&lt;/center&gt;

&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Hoy en día, las técnicas de &lt;i&gt;&lt;b&gt;DeepFake&lt;/b&gt;&lt;/i&gt; son de gran calidad, y los &lt;i&gt;&lt;b&gt;cibercriminales&lt;/b&gt;&lt;/i&gt;, los estafadores en las redes sociales, y los &lt;i&gt;&lt;b&gt;APTs&lt;/b&gt;&lt;/i&gt; a las organizaciones las tienen como una herramienta más. En el mundo del uso de la &lt;a href=&quot;https://www.elladodelmal.com/2026/01/weaponized-ai-el-crimeware-con-ia-que.html&quot;&gt;IA para el Cibercrimen&lt;/a&gt;, como os conté en el artículo de &quot;&lt;a href=&quot;https://www.elladodelmal.com/2026/01/weaponized-ai-el-crimeware-con-ia-que.html&quot;&gt;Weaponized AI&lt;/a&gt;&quot;, las herramientas para generar identidades digitales con &lt;i&gt;&lt;b&gt;DeepFake&lt;/b&gt;&lt;/i&gt; totalmente identificados, documentadas y funcionales, es una pieza más del sistema.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;iframe allowfullscreen=&#39;allowfullscreen&#39; webkitallowfullscreen=&#39;webkitallowfullscreen&#39; mozallowfullscreen=&#39;mozallowfullscreen&#39; width=&#39;470&#39; height=&#39;266&#39; src=&#39;https://www.blogger.com/video.g?token=AD6v5dzpXMGtIQ1wuz7dMpQFgxG9Yo5Xfdp40GHSKPCYvPDBpEunSP8yrm9VnZzmdfRgNYPGd0lkb2XA5dE&#39; class=&#39;b-hbp-video b-uploaded&#39; frameborder=&#39;0&#39;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;Figura 3: &lt;a href=&quot;https://www.elladodelmal.com/2026/01/weaponized-ai-el-crimeware-con-ia-que.html&quot;&gt;Vídeo de Haotian AI. DeepFake de Vídeo y Voz&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Que sean tan perfectas las herramientas exige en los entornos de alta necesidad de seguridad que estas identidades sean verificadas de formar remota con una gran robustez, si no, se podría estar poniendo a los &lt;i&gt;&lt;b&gt;cibercriminales&lt;/b&gt;&lt;/i&gt; las cosas sencillas. Por supuesto, entornos de banca, o, como en este caso, Entidades Certificadoras Autorizadas que entregan &lt;b&gt;&lt;u&gt;Certificados Digitales asociados a una Identidad Verificada&lt;/u&gt;&lt;/b&gt; - por su &lt;i&gt;&lt;b&gt;DNI&lt;/b&gt;&lt;/i&gt; y su &lt;i&gt;&lt;b&gt;Prueba de Vida&lt;/b&gt;&lt;/i&gt; - en un proceso de &lt;i&gt;&lt;b&gt;KYC&lt;/b&gt;&lt;/i&gt;, necesitan, obligatoriamente usar técnicas avanzadas de detección de &lt;i&gt;&lt;b&gt;DeepFakes&lt;/b&gt;&lt;/i&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;b&gt;&lt;u&gt;La Policía Nacional detiene a un ciberdelincuente que utilizaba una técnica pionera mediante IA para obtener certificados de firma electrónica&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;La &lt;i&gt;&lt;b&gt;Policía Nacional&lt;/b&gt;&lt;/i&gt;, publicó en su &lt;i&gt;&lt;b&gt;Sala de Prensa&lt;/b&gt;&lt;/i&gt; el pasado &lt;u&gt;11 de Agosto&lt;/u&gt; como habían &lt;a href=&quot;https://www.policia.es/_es/comunicacion_prensa_detalle.php?ID=16974&quot;&gt;detenido a un cibercriminal que se había dedicado a sacarse más de 30 Certificados Digitales conseguidos en más de 38 intentos en un Entidad Certificadora Autorizada en España usando, para ello técnicas de DeepFake&lt;/a&gt;, trabajadas con iluminación, y documentos falsos que debía mostrar a la cámara.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.policia.es/_es/comunicacion_prensa_detalle.php?ID=16974&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1084&quot; data-original-width=&quot;1474&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgffPhfMR1XTPj4krORq722e7EnxeTK9Alr_0FFsEbEhTPEbe0-V86854wLRsVu_ypHmyPEF8lM42WiiVsmUqSLlGM4TCbEfxsh_4Ywjx_aDm4AfEsLrhONQcxPh51lGVsYrYzMId3mHw3_zQqB8oMZKGSFSBB6tAmbSwVgwC4TDoSX8qmRoq-N/w640-h470/policia1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 4:&amp;nbsp;&lt;a href=&quot;https://www.policia.es/_es/comunicacion_prensa_detalle.php?ID=16974&quot;&gt;La Policía Nacional detiene a un ciberdelincuente que utilizaba una&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.policia.es/_es/comunicacion_prensa_detalle.php?ID=16974&quot;&gt;&lt;i&gt;técnica pionera mediante IA para obtener certificados de firma electrónica&lt;/i&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;El cibercriminal creaba primero la identidad, sobre ella creaba unos documentos de identidad falsos, y luego hacía el proceso de &lt;i&gt;&lt;b&gt;Know Your Customer onnline&lt;/b&gt;&lt;/i&gt; con sofisticadas técnicas de iluminación para conseguir reproducir los destellos de los hologramas y las medidas de seguridad físicas de los &lt;i&gt;&lt;b&gt;DNIs&lt;/b&gt;&lt;/i&gt;, asociando el uso del programa de &lt;i&gt;&lt;b&gt;DeepFake&lt;/b&gt;&lt;/i&gt; al mismo tiempo para salir en vídeo.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Por supuesto, su red de anonimato iba mucho más allá, ya que tenía &lt;i&gt;&lt;b&gt;320&lt;/b&gt;&lt;/i&gt; líneas telefónicas, asociadas a &lt;i&gt;&lt;b&gt;24&lt;/b&gt;&lt;/i&gt; dispositivos móviles distintos, de los cuales la gran mayoría eran contratadas con identidades suplantadas y adquiridas en puntos de venta geolocalizados en &lt;i&gt;&lt;b&gt;Murcia&lt;/b&gt;&lt;/i&gt;, de donde es el &lt;i&gt;&lt;b&gt;cibercriminal&lt;/b&gt;&lt;/i&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/205-ciberestafas-la-historia-de-nunca-acabar.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1230&quot; data-original-width=&quot;864&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjvKmeKKD-aBQ0ZlKvqfJ9T6rsxe3uEanpxh6w3UjjSR6jGLu1WKHvgZRlnvk2een7jjWAhtdM5jQyl7fDA4tFCFP1EOIM1JGE-w-p4M0OGbZDon_KRNpaikQmR-clOijHNtpqUlhgB7ULv5wfqGYeYl3sXYsL8bzqu4hr4C8rTqXJaTllcOkQ_/w281-h400/ciberestafas_web.jpg&quot; width=&quot;281&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;center&gt;&lt;i&gt;Figura 5: &quot;&lt;a href=&quot;https://0xword.com/es/libros/205-ciberestafas-la-historia-de-nunca-acabar.html&quot;&gt;Ciberestafas: La historia de nunca acabar&lt;/a&gt;&quot; &lt;/i&gt;&lt;i&gt;(2ª Edición).&lt;/i&gt;&lt;/center&gt;&lt;center&gt;&lt;i&gt;por &lt;a href=&quot;https://mypublicinbox.com/galindolegal&quot;&gt;Juan Carlos Galindo&lt;/a&gt; en &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;.&lt;/i&gt;&lt;/center&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;En las empresas, los ataques a las organizaciones con empleados falsos empiezan a hacer esto. Primero poner a personal altamente cualificado para pasar el proceso de entrevistas. Hacen un currículo con &lt;i&gt;&lt;b&gt;IA&lt;/b&gt;&lt;/i&gt; que responda perfectamente a la oferta en concreto - siempre buscando trabajar en remoto - y luego pasan los procesos de selección y onboarding con estas técnicas, para luego dejar el equipo en una granja de ordenadores conectados a empresas que los atacantes pueden utilizar aprovechando las credenciales que la organización le ha entregado.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://es.wikipedia.org/wiki/Glitch&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1166&quot; data-original-width=&quot;1948&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhu0boTH1eQvQhol1Ovaj1xquwbJzH5XkzB8XZ7tp9WNyJddy4IhgqntolwegORTJ4o-h1sK53O3ntoAo2IvcmJqx9zTYqWscIxsfXiZjATPX8AD2D3Tr0jKL-B178ydEIRaWyMTHacYbvfwxoY7eGnWHkIo3fdUJAZojc2RNRmjSU2-A0YSoy8/w640-h384/policia2.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 6: &lt;a href=&quot;https://es.wikipedia.org/wiki/Glitch&quot;&gt;Glitch en Wikipedia ES&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;En este caso, todo iba bien, hasta que en uno de los procesos, por la iluminación, un fallo en el equipo, o por simplemente el azar, el &lt;i&gt;&lt;b&gt;software&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;DeepFake&lt;/b&gt;&lt;/i&gt; sufrió un &lt;b&gt;&lt;u&gt;&lt;a href=&quot;https://es.wikipedia.org/wiki/Glitch&quot;&gt;Glitch&lt;/a&gt;&lt;/u&gt;&lt;/b&gt;, es decir, un fallo momentáneo como los que tiene nuestra querida&amp;nbsp;&lt;i&gt;&lt;b&gt;Vanellope von Schweetz&lt;/b&gt;&lt;/i&gt; en la película de &lt;i&gt;&lt;b&gt;Rompe Ralph&lt;/b&gt;&lt;/i&gt;, y el proceso de &lt;i&gt;&lt;b&gt;Know Your Customer&lt;/b&gt;&lt;/i&gt; &lt;b&gt;&lt;u&gt;grabó su imagen por un segundo&lt;/u&gt;&lt;/b&gt;. Si no... difícil cada vez más detectar a estos &quot;&lt;i&gt;&lt;b&gt;Replicantes Digitales&lt;/b&gt;&lt;/i&gt;&quot;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;¡Saludos Malignos!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;Chema Alonso &lt;/b&gt;(&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;Contactar con Chema Alonso&lt;/a&gt;) &amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; font-style: italic; text-align: center;&quot;&gt;
&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;444&quot; data-original-width=&quot;800&quot; src=&quot;https://1.bp.blogspot.com/-wPU2d-hy3rM/XiyVNgM4kGI/AAAAAAAAy70/Pk1IP6-v7bQLVUNL2iWneVOgRP494eWrACLcBGAsYHQ/s640/MPICHemaalonso.jpg&quot; width=&quot;450&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/la-policia-nacional-detiene-un.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjy-mX0gTTSC2eOL9L2OtiPFdVEaMahiOjORAD9jmkrvTuNavesBXb4AElnU_eQ_839wHF3K4C7AActoI0ryrt_nzmA8Sx7xCr2ZY1hSfsxHg-kPZV745JFLNaVBo6jaMc22yy3ovlA2WjMJmBoDKoBffJhwdjuOvVTe-5DynMcny2LUcXdM-Ey/s72-w640-h428-c/policia0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-8986999813889423690</guid><pubDate>Sat, 15 Aug 2026 04:01:00 +0000</pubDate><atom:updated>2026-08-16T08:32:47.315+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">antifraude</category><category domain="http://www.blogger.com/atom/ns#">bizum</category><category domain="http://www.blogger.com/atom/ns#">Curiosidades</category><category domain="http://www.blogger.com/atom/ns#">fraude</category><category domain="http://www.blogger.com/atom/ns#">Gemini</category><category domain="http://www.blogger.com/atom/ns#">GenAI</category><category domain="http://www.blogger.com/atom/ns#">IA</category><title>El &quot;Trick&quot; del comprobante del Bizum hecho con IA para &quot;ratear&quot; un pago a los colegas</title><description>&lt;div style=&quot;text-align: justify;&quot;&gt;Hace unos años os conté la historia de &quot;&lt;a href=&quot;https://www.elladodelmal.com/2023/06/el-jeta-del-yo-pago-con-el-apple-pay.html&quot;&gt;El &quot;jeta&quot; del &quot;Yo Pago&quot; con el Apple Pay que es un ScreenShot&lt;/a&gt;&quot; donde un &quot;&lt;i&gt;&lt;b&gt;amigo&lt;/b&gt;&lt;/i&gt;&quot; simulaba tirar de tarjeta con una captura de pantalla. Hoy sábado, os traigo otra historia que me ha llamado la atención porque me la contó mi hija, donde se ve como los &quot;&lt;i&gt;&lt;b&gt;jetas&lt;/b&gt;&lt;/i&gt;&quot; aprenden nuevas formas de &quot;&lt;i&gt;&lt;b&gt;ratear&lt;/b&gt;&lt;/i&gt;&quot; pagos, en este caso con el comprobante de &lt;i&gt;&lt;b&gt;Bizum&lt;/b&gt;&lt;/i&gt; hecho con &lt;i&gt;&lt;b&gt;IA&lt;/b&gt;&lt;/i&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZt5LOOh8rIaHO-MoglGgGWZsZHOYil2Ihx2RotFRD0sgCJTUSMd5xGSo5oL9wenzQuhr0os-dlsWf2siSaI_TAovJxJH_qTtsmJTQSZpnu5LdCVPAh_4eMCxzMrf7M1y_wTWRa3RpKyv21fpdva6Llp9-f2HG53Z5DBNN8AUqfH01MckmrbYS/s1024/Bizum0.jpeg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;559&quot; data-original-width=&quot;1024&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZt5LOOh8rIaHO-MoglGgGWZsZHOYil2Ihx2RotFRD0sgCJTUSMd5xGSo5oL9wenzQuhr0os-dlsWf2siSaI_TAovJxJH_qTtsmJTQSZpnu5LdCVPAh_4eMCxzMrf7M1y_wTWRa3RpKyv21fpdva6Llp9-f2HG53Z5DBNN8AUqfH01MckmrbYS/w640-h350/Bizum0.jpeg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;El &quot;Trick&quot; del comprobante del Bizum hecho&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;con IA para &quot;ratear&quot; un pago a los colegas&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Esta historia me la contó &lt;a href=&quot;https://www.elladodelmal.com/2023/02/mi-hacker-v20-teenager-edition.html&quot;&gt;Mi Hacker&lt;/a&gt;, y me hizo mucha gracia. Parece ser que entre su grupo de amigos alguno/a había utilizado este truco de hacer un comprobante falso con &lt;i&gt;&lt;b&gt;GenAI&lt;/b&gt;&lt;/i&gt; para enviarlo como justificante de que ha pagado su parte.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhegIlCwDqp2wYNY-4oj1LfVZ1DViE9KIHNCMguFiS7hR8ZMI4CirkauxkMwIMPGqgThHQXq6ivAaRbyUUownOHhyphenhyphenvIUll2wZBxRlDc3zp2urvCsm71kxFzMrnC_jf9noYtlcAtj8-2GO5YF3b7fkAsa7up4-kXIBzC9AF0LnpV76lcNt0E5W3T/s1320/bizum1.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1212&quot; data-original-width=&quot;1320&quot; height=&quot;368&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhegIlCwDqp2wYNY-4oj1LfVZ1DViE9KIHNCMguFiS7hR8ZMI4CirkauxkMwIMPGqgThHQXq6ivAaRbyUUownOHhyphenhyphenvIUll2wZBxRlDc3zp2urvCsm71kxFzMrnC_jf9noYtlcAtj8-2GO5YF3b7fkAsa7up4-kXIBzC9AF0LnpV76lcNt0E5W3T/w400-h368/bizum1.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 2: Un comprobante de Bizum real&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Pero especialmente para cuando un &quot;&lt;i&gt;&lt;b&gt;papá&lt;/b&gt;&lt;/i&gt;&quot; - y remarco lo de &quot;&lt;i&gt;&lt;b&gt;papá&quot;&lt;/b&gt;&lt;/i&gt;, ha hecho el pago y tiene que recibir el &lt;i&gt;&lt;b&gt;Bizum&lt;/b&gt;&lt;/i&gt; de otro &quot;&lt;i&gt;&lt;b&gt;papá&lt;/b&gt;&lt;/i&gt;&quot;, ya que parece que las &quot;&lt;i&gt;&lt;b&gt;mamás&lt;/b&gt;&lt;/i&gt;&quot; lo comprueban más. Alguien paga una cena, unas entradas, o cualquier otra cosa en grupo, y luego los demás ponen su parte a través de &lt;i&gt;&lt;b&gt;Bizum&lt;/b&gt;&lt;/i&gt;. Algo muy común en nuestra vida.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/245-hacking-pentesting-con-inteligencia-artificial.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1688&quot; data-original-width=&quot;1298&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicZbq7z1QIW5RDLoHBFH4O2XtgQCjhHZ4YI70ksUtOQpkc1cersCsUNnlBy8wtEAnuOPOrm2KTYMBs9K3jCobjjSod4rx7ymfE0lcTFRy6LeGkzbpdGBBSx8LbifDrZfrgAsQDmDWu_rrz4htL0YJljBRe4esKTfZ0api8aLViQ398JCXBKsyX/w308-h400/HackingYPentestingconIA.jpg&quot; width=&quot;308&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;Figura 3: &lt;a href=&quot;https://0xword.com/es/libros/245-hacking-pentesting-con-inteligencia-artificial.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking &amp;amp; Pentesting con Inteligencia Artificial&lt;/a&gt;.&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;En &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;, &lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;escrito por &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://mypublicinbox.com/RafaelTroncoso&quot; style=&quot;text-align: justify;&quot;&gt;Rafael Troncoso&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/JaviPino&quot; style=&quot;text-align: justify;&quot;&gt;Javier del Pino&lt;/a&gt; y &lt;span style=&quot;text-align: justify;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/chemaalonso&quot;&gt;Chema Alonso&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;En la de los adolescentes es &quot;&lt;i&gt;&lt;b&gt;mi papá le hace Bizum al tuyo&lt;/b&gt;&lt;/i&gt;&quot;. Así, el padre del pagador, supuestamente hace el &lt;i&gt;&lt;b&gt;Bizum&lt;/b&gt;&lt;/i&gt;, le manda el justificante a la amiga o amigo, y todos tan contentos.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKYZ11IqMBiZV6a9ByTM60ZGRVDdIQaizt-gp5xkVyoZgHJYeGJJWB5Uusk6OriPAXOfi_9z1rkmqmN8DRckcjZDj69-mba9DXQnlSPPZcGgRNv1dNTAuZwWxUZsACZCSPXGkfmLv7gZbL0jRRWpe0C8-5FmO-Z6PouUlUGUJY6rjzN_H_7h1C/s760/Bizum5.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;368&quot; data-original-width=&quot;760&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhKYZ11IqMBiZV6a9ByTM60ZGRVDdIQaizt-gp5xkVyoZgHJYeGJJWB5Uusk6OriPAXOfi_9z1rkmqmN8DRckcjZDj69-mba9DXQnlSPPZcGgRNv1dNTAuZwWxUZsACZCSPXGkfmLv7gZbL0jRRWpe0C8-5FmO-Z6PouUlUGUJY6rjzN_H_7h1C/w640-h310/Bizum5.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura&amp;nbsp; 4: Pidiendo la falsificación del precio a Gemini Nano Banana&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;El &lt;b&gt;&lt;u&gt;&quot;Trick&quot; es que el Comprobante de Bizum es falso&lt;/u&gt;&lt;/b&gt;. Se podría haber hecho con &lt;i&gt;&lt;b&gt;Photoshop&lt;/b&gt;&lt;/i&gt;, o con cualquier otra herramienta, pero con el acceso a la IA, todos los adolescentes directamente le piden que les haga los comprobantes y listo.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEink-EVzyi2O1uHDEimvbXAoWznyTmbdYDXEPcGiOS2YMkTD3Ltr96cKY79Ti7cGzJ8MjBtIlFmF8V1afIcu8Sz3FzIHL32Ti-2UvQCtBJpeKrPKQ1Ql3Cm1een0hK9DiV3b-e8uqh0Qf54xrpYnRyLNUSoOczU0lnSLzkJ42ufm-4ptzqc2VfO/s1408/bizum3.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1408&quot; data-original-width=&quot;1086&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEink-EVzyi2O1uHDEimvbXAoWznyTmbdYDXEPcGiOS2YMkTD3Ltr96cKY79Ti7cGzJ8MjBtIlFmF8V1afIcu8Sz3FzIHL32Ti-2UvQCtBJpeKrPKQ1Ql3Cm1een0hK9DiV3b-e8uqh0Qf54xrpYnRyLNUSoOczU0lnSLzkJ42ufm-4ptzqc2VfO/w494-h640/bizum3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 5: Razonamiento de Gemini Thinking&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Yo lo he querido probar con &lt;i&gt;&lt;b&gt;Gemini Nano Banana&lt;/b&gt;&lt;/i&gt;, por si había algún control al detectar que era un justificante de pago o similar - &lt;a href=&quot;https://www.elladodelmal.com/2026/04/jailbreaking-nano-banana-just-for-fun.html&quot;&gt;como sucedía con el test de COVID&lt;/a&gt; -, pero no da ningún problema, y de hecho se esfuerza y mucho por dejarlo todo en su sitio.&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjDDTn4vwv14lmnaZ4ske8MCTTKsQ64ysCEpC2r1k0pgbVW2Q7CAxaD-VBdRSbV4aCN6AaUiQxvBgSRNgRW_i6ADQEv8os7d15vOqE-j6XLUNIrnumTkXGpkuWXysDOxgwaUgNWglNagsdEmligMATykRBlCEmwL2HuM9hftJv0jtnVSszhU8r2/s750/bizum4.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;750&quot; data-original-width=&quot;588&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjDDTn4vwv14lmnaZ4ske8MCTTKsQ64ysCEpC2r1k0pgbVW2Q7CAxaD-VBdRSbV4aCN6AaUiQxvBgSRNgRW_i6ADQEv8os7d15vOqE-j6XLUNIrnumTkXGpkuWXysDOxgwaUgNWglNagsdEmligMATykRBlCEmwL2HuM9hftJv0jtnVSszhU8r2/w314-h400/bizum4.jpg&quot; width=&quot;314&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 6: Dejándolo perfecto.&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;El resultado, pues lo que ya imaginamos, que sale un comprobante perfecto pero con otro precio manipulado. Y si ya sabes que funciona, pues le modificas lo que quieras en la próxima. La fecha, el concepto, el destinatario, el precio, etcétera.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhr93I60gYYqRCtVSdn23deRkECr08yM6Rtca4nHBFsb418Dqf6-W69Z9A4Xuwf8vW17X9eJwZOM0iEjyu6iP50mmaYpKGGx5u3znjjPhamI0s_30OdvlHZPMCm5xj_K-teiek8Atx42f9BTXj9RqD2PARIRgDDZrwqEJ2FI5tsaZW15SYdIPEU/s471/bizum2.jpeg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;432&quot; data-original-width=&quot;471&quot; height=&quot;368&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhr93I60gYYqRCtVSdn23deRkECr08yM6Rtca4nHBFsb418Dqf6-W69Z9A4Xuwf8vW17X9eJwZOM0iEjyu6iP50mmaYpKGGx5u3znjjPhamI0s_30OdvlHZPMCm5xj_K-teiek8Atx42f9BTXj9RqD2PARIRgDDZrwqEJ2FI5tsaZW15SYdIPEU/w400-h368/bizum2.jpeg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 7: El resultado final. Un comprobante de Bizum manipulado.&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;No es nada nuevo bajo el sol. Solo adaptado a los nuevos tiempos. Supongo que los vendedores online lo mirarán con mucho cuidado, pero si eres de esos que haces cosas con tus hijos adolescentes, cuidado. Los &quot;&lt;i&gt;&lt;b&gt;papás&lt;/b&gt;&lt;/i&gt;&quot; somos víctimas propicias porque por lo visto las &quot;&lt;i&gt;&lt;b&gt;madres&lt;/b&gt;&lt;/i&gt;&quot; siempre lo revisan... aunque les manden el justificante. Eso me ha dicho.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;¡Saludos Malignos!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;Chema Alonso &lt;/b&gt;(&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;Contactar con Chema Alonso&lt;/a&gt;) &amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; font-style: italic; text-align: center;&quot;&gt;
&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;444&quot; data-original-width=&quot;800&quot; src=&quot;https://1.bp.blogspot.com/-wPU2d-hy3rM/XiyVNgM4kGI/AAAAAAAAy70/Pk1IP6-v7bQLVUNL2iWneVOgRP494eWrACLcBGAsYHQ/s640/MPICHemaalonso.jpg&quot; width=&quot;450&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/el-trick-del-comprobante-del-bizum.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgZt5LOOh8rIaHO-MoglGgGWZsZHOYil2Ihx2RotFRD0sgCJTUSMd5xGSo5oL9wenzQuhr0os-dlsWf2siSaI_TAovJxJH_qTtsmJTQSZpnu5LdCVPAh_4eMCxzMrf7M1y_wTWRa3RpKyv21fpdva6Llp9-f2HG53Z5DBNN8AUqfH01MckmrbYS/s72-w640-h350-c/Bizum0.jpeg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-6168797807078173921</guid><pubDate>Fri, 14 Aug 2026 07:31:09 +0000</pubDate><atom:updated>2026-08-14T09:31:09.296+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">Artificial Intelligence</category><category domain="http://www.blogger.com/atom/ns#">charlas</category><category domain="http://www.blogger.com/atom/ns#">conferencias</category><category domain="http://www.blogger.com/atom/ns#">Eventos</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">IA</category><category domain="http://www.blogger.com/atom/ns#">Inteligencia Artificial</category><category domain="http://www.blogger.com/atom/ns#">pentesting</category><title>CONVEX 2026: Hacking (With | The) AI </title><description>&lt;div style=&quot;text-align: justify;&quot;&gt;Este año, hace ya un par de meses, me invitaron mis amigos de &lt;a href=&quot;https://www.youtube.com/watch?v=7u19JMAlPdM&quot;&gt;Plain Concepts a dar una conferencia en su evento CONVEX 2026 en Madrid&lt;/a&gt;, así que pasé a dar allí la charla con mi amigo y compañero de mil batallas &lt;a href=&quot;https://mypublicinbox.com/DavidCarmona&quot;&gt;David Carmona&lt;/a&gt;. De aquella charla os dejé el artículo con la demo de &quot;&lt;a href=&quot;https://www.elladodelmal.com/2026/06/como-matar-con-un-plan-realista-mi.html&quot;&gt;Cómo &quot;matar&quot; con un plan realista a mi amigo David Carmona usando un veneno mortal y la ayuda de DeepSeek&lt;/a&gt;&quot;, que lo hice con mucho cariño para con él.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=O6BygaRS8kg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;568&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhN9fY1_2fGj7OJicjCU5MQfIshJoLj8EE6CwfmxwtZm2ZRGZ-KZvxIWNDQBSC6xuMOGzIQQpxdAegPOtR21xnR4054kistuBG7_TN0ZIYzhtZH3a9gHfuxBwdr7Ia7WZbPhcMvKRi1kD7YFtinw60OFV9Q_13GkOFTxXK1i26ERWBiOp_50pxd/w640-h386/convex0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;&lt;a href=&quot;https://www.youtube.com/watch?v=O6BygaRS8kg&quot;&gt;CONVEX 2026: Hacking (With | The) AI&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;La charla solo tiene un par de meses, pero parece que todo lo que ha pasado después con &lt;a href=&quot;https://www.elladodelmal.com/2026/07/openai-gpt56-sol-queria-sacar-buenas.html&quot;&gt;OpenAI &amp;amp; The Hugging Face&lt;/a&gt;, los &lt;a href=&quot;https://www.elladodelmal.com/2026/08/ataques-orquestados-con-enjambres-de.html&quot;&gt;Ataques orquestados de Red Team Agents de los nuevos GPT&lt;/a&gt;, o los &lt;a href=&quot;https://www.elladodelmal.com/2026/08/claude-mythos-preview-debilita-los.html&quot;&gt;ataques a los algoritmos HAWK y AES de Claude Mythos Preview&lt;/a&gt;, parece que la dejan desactualizada.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;
&lt;center&gt;&lt;iframe allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&quot; allowfullscreen=&quot;&quot; frameborder=&quot;0&quot; height=&quot;264&quot; referrerpolicy=&quot;strict-origin-when-cross-origin&quot; src=&quot;https://www.youtube.com/embed/O6BygaRS8kg?si=TQD72Dn-5I5Y4rXw&quot; title=&quot;YouTube video player&quot; width=&quot;470&quot;&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;i&gt;Figura 2: &lt;a href=&quot;https://www.youtube.com/watch?v=O6BygaRS8kg&quot;&gt;CONVEX 2026: Hacking (With | The) AI  Chema Alonso&lt;/a&gt;&lt;/i&gt;&lt;/center&gt;&lt;br /&gt;
&lt;div style=&quot;text-align: justify;&quot;&gt;En cualquier caso, la charla sigue siendo entretenida, y cuenta cosas chulas de este mundo nuestro en el que tenemos que aplicar &lt;a href=&quot;https://www.elladodelmal.com/2026/07/como-desplegar-zero-trust-para-agentes.html&quot;&gt;Zero Trust a Agentes IA&lt;/a&gt;, donde hay que hacer &lt;a href=&quot;https://0xword.com/es/libros/245-hacking-pentesting-con-inteligencia-artificial.html&quot;&gt;Hacking y Pentesting con IA&lt;/a&gt;, y donde tenemos que conocer todos las posibles formas de hacer &lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot;&gt;Hacking a sistemas IA&lt;/a&gt;, así que espero que la disfrutéis.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;649&quot; data-original-width=&quot;485&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGlxuPvsCIvroRvztIaGw6Munmx4sWMdpXbWYXzTFmt8ZXBxrPSdENqyHKUlKYR2KI2pb48LVg_mLlJhaxy9R9xdnapH4UVUPD8YReOyl22-yhIImdXUzHRzE8egQuQBBhcoKeOLkbhBuXZe_8OU8hWB0CXFkF4lI2altrnGCW12nY0bXt7hsd/w299-h400/HackingIA_web.jpg&quot; width=&quot;299&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 3:&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking IA: Jailbreak, Prompt Injection, Hallucinations &amp;amp; Unalignment&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;escrito por &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Chema Alonso&lt;/a&gt; con la colaboración de &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/AmadorAparicio&quot; style=&quot;text-align: justify;&quot;&gt;Amador Aparicio&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/ManuelSLemos&quot; style=&quot;text-align: justify;&quot;&gt;Manuel S. Lemos&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;y&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/JPalanco&quot; style=&quot;text-align: justify;&quot;&gt;José Palanco&lt;/a&gt; en &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Espero que tengáis un buen viernes de &lt;i&gt;&lt;b&gt;Agosto&lt;/b&gt;&lt;/i&gt;, un buen fin de semana, pero sobre todo que no dejéis de seguir aprendiendo, que este mundo no se para, ya lo sabéis.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;¡Saludos Malignos!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;Chema Alonso &lt;/b&gt;(&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;Contactar con Chema Alonso&lt;/a&gt;) &amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; font-style: italic; text-align: center;&quot;&gt;
&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;444&quot; data-original-width=&quot;800&quot; src=&quot;https://1.bp.blogspot.com/-wPU2d-hy3rM/XiyVNgM4kGI/AAAAAAAAy70/Pk1IP6-v7bQLVUNL2iWneVOgRP494eWrACLcBGAsYHQ/s640/MPICHemaalonso.jpg&quot; width=&quot;450&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/convex-2026-hacking-with-ai.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhN9fY1_2fGj7OJicjCU5MQfIshJoLj8EE6CwfmxwtZm2ZRGZ-KZvxIWNDQBSC6xuMOGzIQQpxdAegPOtR21xnR4054kistuBG7_TN0ZIYzhtZH3a9gHfuxBwdr7Ia7WZbPhcMvKRi1kD7YFtinw60OFV9Q_13GkOFTxXK1i26ERWBiOp_50pxd/s72-w640-h386-c/convex0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-1036896107542817269</guid><pubDate>Thu, 13 Aug 2026 04:01:00 +0000</pubDate><atom:updated>2026-08-13T10:17:05.929+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">AES</category><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">Anthropic</category><category domain="http://www.blogger.com/atom/ns#">Artificial Intelligence</category><category domain="http://www.blogger.com/atom/ns#">Claude</category><category domain="http://www.blogger.com/atom/ns#">criptoanálisis</category><category domain="http://www.blogger.com/atom/ns#">Criptografía</category><category domain="http://www.blogger.com/atom/ns#">IA</category><category domain="http://www.blogger.com/atom/ns#">Inteligencia Artificial</category><category domain="http://www.blogger.com/atom/ns#">LLM</category><category domain="http://www.blogger.com/atom/ns#">Mythos</category><category domain="http://www.blogger.com/atom/ns#">PQC</category><category domain="http://www.blogger.com/atom/ns#">Quantum</category><title>Claude Mythos Preview debilita los algoritmos criptográficos PQC HAWK y AES con nuevos ataques</title><description>&lt;div align=&quot;justify&quot;&gt;Hace poco hablábamos en este blog de cómo &lt;a href=&quot;https://www.elladodelmal.com/2025/12/bitcoin-vs-quantum-computers-hora-de.html&quot;&gt;Bitcoin y toda la comunidad cripto se estaban preparando para pasar a protocolos de Post-Quantum Criptography&lt;/a&gt;, ante la eventual llegada un ordenador cuántico capaz de romper la &lt;i&gt;&lt;b&gt;criptografía&lt;/b&gt;&lt;/i&gt; actual. Pues bien, la historia
acaba de dar un giro inesperado: resulta que no ha falta esperar a la llegada de la tecnología cuántica. Ha
llegado antes, y con una cara que no esperábamos: la &lt;b&gt;Inteligencia Artificial&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;621&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhV0aD2IBu3_cD4rMKA6nZ4DTtv0rdd5S69W3vTS8i2RYVHgf8srC_LX-DmmwCTYiSe43HR-sxS9-lfYZcmsHEtMqMrflxtCmX7uA3rYMQzIiLhTNkCroAGytOeZCnYNUQUwnTMjSSaDjttB8sSf2p66TLV51zvhKxC66q1F39zjxx41UMpziWQ/w640-h422/crypto0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;&lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot;&gt;Claude Mythos Preview debilita los algoritmos criptográficos&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot;&gt;PQC HAWK y AES con nuevos ataques&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
Esto es precisamente lo que analiza el artículo de &lt;i&gt;&lt;b&gt;Anthropic&lt;/b&gt;&lt;/i&gt;&amp;nbsp;- creadora de &lt;i&gt;&lt;b&gt;Mythos&lt;/b&gt;&lt;/i&gt; - titulado ”&lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot;&gt;Discovering cryptographic weaknesses with Claude&lt;/a&gt;”, donde se explica
cómo su modelo de &lt;i&gt;&lt;b&gt;IA&lt;/b&gt;&lt;/i&gt; ha sido capaz de encontrar, de forma casi autónoma, debilidades
matemáticas en algoritmos criptográficos reales.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;832&quot; data-original-width=&quot;1121&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh7Gdm0lCc8xJ9no5BhrM5mlmKAq6fkdSSwFdGqHjIIZhzzNGPcrwDFhArvfss-WZzyXPC5hoI6B6uHOoZD2SWTlnQPX_5uQ7ZtPEpBmRPk73Mc30EoAlro7C2l42qlSubqHDnVV2TrLoss_pe1SuwkEClwnbLsSrtxTG4u93uz-7HKJWycA5yn/w640-h476/cripto1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;Figura 2: ”&lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot;&gt;Discovering cryptographic weaknesses with Claude&lt;/a&gt;”&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Y no en algoritmos cualquiera: uno de ellos
era un candidato diseñado precisamente para resistir a los ordenadores cuánticos &lt;i&gt;&lt;b&gt;HAWK&lt;/b&gt;&lt;/i&gt;, y el otro
es nada menos que el cifrado más utilizado del planeta, &lt;i&gt;&lt;b&gt;AES&lt;/b&gt;&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Un breve recordatorio: los candados que sostienen Internet&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
Antes de entrar en materia, recordemos por qué esto es importante. Cada vez que entráis
en la web de vuestro banco ocurren, sin que os deis cuenta, dos cosas. Primero, vuestro
navegador comprueba que está hablando con el banco de verdad y no con un impostor, y para ello usa una &lt;b&gt;&lt;i&gt;firma digital&lt;/i&gt;&lt;/b&gt;, que funciona como el &lt;a href=&quot;https://es.wikipedia.org/wiki/Lacre&quot;&gt;sello de lacre de una carta medieval&lt;/a&gt;,
imposible de falsificar. Después, toda la conversación entre vosotros y el banco se cifra con
un cifrado simétrico, un idioma secreto que solo entendéis los dos porque compartís la
misma clave.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8sIPCpfAzBfbclSF_rqMh07fBoKnAJtQrMLfTezL6bTPHURxZhfz8BN53oEknot7vxWe6HEoVrg2sxTnSGaBmQr2z_v_A2V9Apg0J1s33M07sMwoG7__-4YicgWKzmwSrI1IPAp7uzhIQtSw3niPnnXuGmw9Rzas5n_hhrTufVZetCy8pbaqB/s1436/cripto2.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;882&quot; data-original-width=&quot;1436&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg8sIPCpfAzBfbclSF_rqMh07fBoKnAJtQrMLfTezL6bTPHURxZhfz8BN53oEknot7vxWe6HEoVrg2sxTnSGaBmQr2z_v_A2V9Apg0J1s33M07sMwoG7__-4YicgWKzmwSrI1IPAp7uzhIQtSw3niPnnXuGmw9Rzas5n_hhrTufVZetCy8pbaqB/w640-h394/cripto2.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 3: Los dos candados que protegen cada conexión segura.&amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;i style=&quot;text-align: left;&quot;&gt;La firma&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i style=&quot;text-align: left;&quot;&gt;digital&amp;nbsp;&lt;/i&gt;&lt;i style=&quot;text-align: left;&quot;&gt;verifica la identidad y el cifrado simétrico protege el contenido&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;i&gt;
S&lt;/i&gt;i cualquiera de estos dos candados fallara, nuestro correo, la banca online o las compras
por &lt;i&gt;&lt;b&gt;Internet&lt;/b&gt;&lt;/i&gt; quedarían expuestos a los cibercriminales. Por eso, encontrar grietas en estos
algoritmos no es un juego académico: es lo que mantiene a salvo los datos de miles de millones
de personas.
&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Del error humano al fallo matemático&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
Aquí conviene hacer una distinción importante. Cuando &lt;a href=&quot;https://www.elladodelmal.com/2026/05/el-impacto-de-mythos-en-concreto-y-la.html&quot;&gt;presentaron a Claude Mythos Preview&lt;/a&gt;, ya habían
demostrado que era capaz de encontrar vulnerabilidades en montones de programas,
incluidas librerías de criptografía. Pero aquellos fallos eran errores de implementación:
equivocaciones de los programadores al usar los algoritmos en su código, algo así como
instalar una cerradura buenísima pero dejarse la ventana abierta.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Lo nuevo, y lo verdaderamente llamativo, es que ahora &lt;i&gt;&lt;b&gt;Claude Mythos Preview&lt;/b&gt;&lt;/i&gt;&amp;nbsp;ha encontrado fallos en los
propios algoritmos matemáticos, no en cómo se usan. Es decir, ya no es que la ventana
estuviera abierta: es que el diseño de la propia cerradura tenía un punto débil que nadie había
visto. Y encontrarlo requiere razonamiento matemático del nivel de los mejores expertos del
mundo.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Primer golpe: HAWK, el candidato post-cuántico (PQC)&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
El primer resultado ataca a &lt;i&gt;&lt;b&gt;HAWK&lt;/b&gt;&lt;/i&gt;, un esquema de firma digital&amp;nbsp;&lt;span style=&quot;text-align: left;&quot;&gt;basado en retículos (lattices). Es especialmente relevante porque fue seleccionado por el &lt;i&gt;&lt;b&gt;NIST (Instituto Nacional de Estándares y Tecnología de EE. UU.)&lt;/b&gt;&lt;/i&gt; para avanzar a la &lt;i&gt;&lt;b&gt;Ronda 3&lt;/b&gt;&lt;/i&gt; del proceso de estandarización de firmas digitales adicionales de criptografía post-cuántica (&lt;i&gt;&lt;b&gt;PQC&lt;/b&gt;&lt;/i&gt;) y por lo tanto&lt;/span&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&amp;nbsp;compite por convertirse
en estándar &lt;/span&gt;&lt;i style=&quot;text-align: left;&quot;&gt;&lt;b&gt;”post-cuántico” (PQC)&lt;/b&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;HAWK&lt;/b&gt;&lt;/i&gt; es un esquema de firma digital (utilizado para autenticación) .&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot; style=&quot;text-align: justify;&quot;&gt;&lt;ul&gt;&lt;li&gt;Paper original (2022): &quot;&lt;a href=&quot;https://wesselvanwoerden.com/publication/ducas-2023-hawk/hawk.pdf&quot;&gt;Hawk: Module LIP Makes Lattice Signatures Fast, Compact and Simple&lt;/a&gt;&quot;.&lt;/li&gt;&lt;li&gt;El Paper de Seguridad Cuántica (2023) &quot;&lt;a href=&quot;https://ir.cwi.nl/pub/33366/33366.pdf&quot;&gt;On the Quantum Security of HAWK&lt;/a&gt;&quot;&lt;/li&gt;&lt;li&gt;Documento de Especificación Oficial del NIST (2023-2024) &quot;&lt;a href=&quot;https://csrc.nist.gov/csrc/media/Projects/pqc-dig-sig/documents/round-1/spec-files/hawk-spec-web.pdf&quot;&gt;Hawk: A fast, compact and floating-point free post-quantum signature scheme (Specification Document)&lt;/a&gt;&quot;&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;Como ya explicamos &lt;/span&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/12/bitcoin-vs-quantum-computers-hora-de.html&quot; style=&quot;text-align: left;&quot;&gt;al hablar de Bitcoin&lt;/a&gt;&lt;span style=&quot;text-align: left;&quot;&gt;, el &lt;/span&gt;&lt;i style=&quot;text-align: left;&quot;&gt;&lt;b&gt;NIST&lt;/b&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt; (el instituto
de estándares de &lt;/span&gt;&lt;i style=&quot;text-align: left;&quot;&gt;&lt;b&gt;EE.UU.&lt;/b&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;) lleva casi una década organizando una especie de concurso para
elegir los algoritmos que nos protegerán cuando lleguen los ordenadores cuánticos, y &lt;/span&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/05/los-papers-academicos-de-los-algoritmos.html&quot; style=&quot;text-align: left;&quot;&gt;HAWKes uno de los finalistas de la tercera ronda&lt;/a&gt;&lt;span style=&quot;text-align: left;&quot;&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/05/los-papers-academicos-de-los-algoritmos.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;559&quot; data-original-width=&quot;1024&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj2Aeg_8HBA3MGZZFqJq-k-UEJrF3vb-vMLlEWP2sMf3Oi4sDUIbP66CZNWtbUe1mLr79o02XdOZWoX3SrCsJpkGv3kUVVNqYugkPiQCRkY0vjbfxkKulmiizszBqf6UGo0TW81K8zteKeDWyHzdXCkZKPuxTKMuD04osTnWbMSaZvPYUNS6ZRw/w640-h350/quantum0.jpeg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 5: &lt;a href=&quot;https://www.elladodelmal.com/2026/05/los-papers-academicos-de-los-algoritmos.html&quot;&gt;Los Papers Académicos de los algoritmos PQC de&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/05/los-papers-academicos-de-los-algoritmos.html&quot;&gt;Autenticación y Firma Digital en la Ronda 3 del NIST&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;
Lo asombroso es que &lt;i&gt;&lt;b&gt;HAWK&lt;/b&gt;&lt;/i&gt; ya había sobrevivido a dos años de revisión por parte
de expertos humanos. Y aun así, a &lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot;&gt;Claude Mythos Preview le bastaron unas 60 horas de trabajo&lt;/a&gt; para
mejorar el mejor ataque conocido contra él, encontrando una simetría matemática oculta en
su estructura que nadie había sabido aprovechar.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div align=&quot;justify&quot;&gt;&lt;i style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/248-quatum-security-tecnologia-cuantica-ciberseguridad-criptografica-cuantica-y-post-cuantica.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1610&quot; data-original-width=&quot;1137&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzNgeoS8bK-N-wht22IN3Z9fcjMOMuMh6f9H8bSB9a-4MxLglEcHxqPpeuw8auxDK6z1mWBzkmwxwpV_x1cgen1gWeVP9ig3bZUh2UrXc8DcD68D7ZVT7gCmkeHGu9p08QKsTN4fW0RsnEbdcSXP2xHDPbmogTUDdrsk_YmX7lGAsv-olxYX2k/w282-h400/Quantum1.jpg&quot; width=&quot;282&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;Figura 6: &lt;span style=&quot;text-align: justify;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/248-quatum-security-tecnologia-cuantica-ciberseguridad-criptografica-cuantica-y-post-cuantica.html&quot;&gt;Quatum Security: Tecnología Cuántica &amp;amp; Ciberseguridad.&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/248-quatum-security-tecnologia-cuantica-ciberseguridad-criptografica-cuantica-y-post-cuantica.html&quot;&gt;Criptográfica Cuántica y Post-Cuántica.&lt;/a&gt;&lt;/span&gt;&amp;nbsp;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;Nuestro nuevo libro en &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; escrito por: &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Chema Alonso&lt;/a&gt;,&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://mypublicinbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/CarmenTorrano&quot; style=&quot;text-align: justify;&quot;&gt;Carmen Torrano&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/DanielRomeroRuiz&quot; style=&quot;text-align: justify;&quot;&gt;Daniel Romero&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://MyPublicInbox.com/JAlvarezz13&quot; style=&quot;text-align: justify;&quot;&gt;Javier Álvarez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/MarioPiattini &quot; style=&quot;text-align: justify;&quot;&gt;Mario Piattini&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;ttps://MyPublicInbox.com/IkerPastor&quot; style=&quot;text-align: justify;&quot;&gt;Iker Pastor&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/pgb&quot; style=&quot;text-align: justify;&quot;&gt;Pablo García Bringas&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;El resultado, en cristiano: la fuerza de sus
claves queda reducida a la mitad. Para hacernos una idea, el coste de romper su versión más
pequeña pasaba de estar en el orden de &lt;i&gt;&lt;b&gt;2 elevando a 64&lt;/b&gt;&lt;/i&gt; operaciones a solo &lt;i&gt;&lt;b&gt;2 elevado a 38&lt;/b&gt;&lt;/i&gt;.&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;917&quot; data-original-width=&quot;1387&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg_dZsZ-H1xXws_fvjtuA9fv7QTUWzvBD-UUr9CaL6zcAc7jMtBA1FBs0NHgwsCEpBoDMd_gNCTsd7JiPbgXmKOH5PajkNt7MJDXi5FzeEm1CEeBHgMlHUmsF-O7_x9JtUEbO8LptoLlNhtRA8y__BmRBgLoJF_JaeTBAwTwtX76Sn4p1GMEfAa/w640-h424/cripto3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;Figura 7: &lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot;&gt;El ataque de Claude Mythos encuentra una simetría oculta&amp;nbsp;&lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot;&gt;en&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot;&gt;la estructura de HAWK y reduce a la mitad la fortaleza de sus claves&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;
Que nadie se asuste: &lt;i&gt;&lt;b&gt;HAWK&lt;/b&gt;&lt;/i&gt; todavía no protege nada (es solo un candidato) y con claves
grandes sigue siendo impracticable de atacar. La única solución sería duplicar el tamaño de
sus claves... pero al hacerlo, &lt;i&gt;&lt;b&gt;HAWK&lt;/b&gt;&lt;/i&gt; pierde precisamente las ventajas que lo hacían atractivo.
En otras palabras, &lt;i&gt;&lt;b&gt;Claude Mythos&lt;/b&gt;&lt;/i&gt; puede haberlo dejado fuera de la competición. Y esto, lejos de ser
una mala noticia, es exactamente para lo que sirve el concurso: encontrar los fallos antes de
desplegar el algoritmo, no después.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Segundo golpe: AES, el rey de los cifrados&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
El segundo resultado es todavía más sorprendente por el objetivo elegido: &lt;i&gt;&lt;b&gt;AES&lt;/b&gt;&lt;/i&gt;, el cifrado
simétrico estándar desde &lt;i&gt;&lt;b&gt;2001&lt;/b&gt;&lt;/i&gt; y probablemente el algoritmo más estudiado y escrutado de
toda la historia de la criptografía. Aquí toca ser muy honestos con las limitaciones, porque
es fácil malinterpretar el titular: &lt;u&gt;Claude Mythos NO ha roto el AES completo, ni de lejos&lt;/u&gt;.
&lt;i&gt;&lt;b&gt;AES&lt;/b&gt;&lt;/i&gt; cifra aplicando una misma operación (una ”&lt;i&gt;&lt;b&gt;ronda&lt;/b&gt;&lt;/i&gt;”) varias veces seguidas; la versión
más habitual da &lt;i&gt;&lt;b&gt;10&lt;/b&gt;&lt;/i&gt; vueltas.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;table align=&quot;center&quot; cellpadding=&quot;0&quot; cellspacing=&quot;0&quot; class=&quot;tr-caption-container&quot; style=&quot;margin-left: auto; margin-right: auto; text-align: center;&quot;&gt;&lt;tbody&gt;&lt;tr&gt;&lt;td&gt;&lt;a href=&quot;https://0xword.com/es/libros/36-libro-cifrado-comunicaciones-rsa.html&quot; style=&quot;margin-left: auto; margin-right: auto;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;620&quot; data-original-width=&quot;470&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjEZQNA7SNx0pvhuyg0adLP3R28OOmXkHsAXTLz780V9Fa98-IQ-FsQNvDOijnoa0wipW3IAGB2VUZX8pchXDpOf9_PdnrrgbAnK8sPdvVe5X4R-REdBdnJFvTtbHs0mIObEFSu/w303-h400/LibroRSA.jpg&quot; width=&quot;303&quot; /&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class=&quot;tr-caption&quot;&gt;&lt;i&gt;Figura 8: &lt;a href=&quot;https://0xword.com/es/libros/36-libro-cifrado-comunicaciones-rsa.html&quot;&gt;Libro de Cifrado de las comunicaciones digitales:&lt;/a&gt;&lt;/i&gt;&lt;br /&gt;&lt;a href=&quot;https://0xword.com/es/libros/36-libro-cifrado-comunicaciones-rsa.html&quot;&gt;&lt;i&gt;de la cifra clásica a RSA 2ª Edición de 0xWord&lt;/i&gt;&lt;/a&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/tbody&gt;&lt;/table&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Lo que hizo &lt;i&gt;&lt;b&gt;Claude Mythos&lt;/b&gt;&lt;/i&gt; fue atacar una versión debilitada de só&lt;span style=&quot;text-align: left;&quot;&gt;lo
&lt;i&gt;&lt;b&gt;7&lt;/b&gt;&lt;/i&gt; rondas, algo que los investigadores estudian precisamente para medir la robustez del
algoritmo completo. Sobre esa versión reducida, &lt;i&gt;&lt;b&gt;Claude Mythos&lt;/b&gt;&lt;/i&gt; ideó un nuevo método de ataque
que él mismo bautizó como &lt;b&gt;&lt;i&gt;Möbius Bridge&lt;/i&gt;&lt;/b&gt;, y consiguió eliminar una de las suposiciones que
un atacante tenía que ”&lt;i&gt;&lt;b&gt;adivinar&lt;/b&gt;&lt;/i&gt;” por fuerza bruta. El resultado es un ataque entre &lt;i&gt;&lt;b&gt;200&lt;/b&gt;&lt;/i&gt; y
&lt;i&gt;&lt;b&gt;800&lt;/b&gt;&lt;/i&gt; veces más rápido que el mejor conocido hasta ahora.&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;852&quot; data-original-width=&quot;1364&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgaLxYxgzrKsKBwDeriBe7Y751yiDaaF74kCf6kbqIO4PNHK9obhDnK4quEkaTkwJV9OLHHtiA2aV7pcuNBBjNhddNw78MPHLMnTlXbgYXkgouF7GR53Xi6XnfaeElaH2EDjHXStVPlzzc_SybI9uNf116j6jvuhyosb8LO6IgEdWO8FoDRMYY-/w640-h400/cripto4.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;i&gt;&amp;nbsp;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;Figura 9: &lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot;&gt;Claude Mythos atacó una versión reducida de 7 rondas de AES&amp;nbsp;&lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot;&gt;(el estándar&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot;&gt;completo usa 10), acelerando el mejor ataque conocido entre 200 y 800 veces.&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
Insisto en el mensaje tranquilizador: este ataque es puramente teórico (requiere una cantidad
astronómica de datos que lo hace inviable en la práctica) y no afecta al &lt;i&gt;&lt;b&gt;AES&lt;/b&gt;&lt;/i&gt; real que protege
vuestras conexiones. Pero como prueba de lo que una &lt;i&gt;&lt;b&gt;IA&lt;/b&gt;&lt;/i&gt; puede hacer, es espectacular.
&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Lo más fascinante: cómo lo descubrió&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
Si los resultados ya son impresionantes, el proceso es casi de guion de película. En el
caso de &lt;i&gt;&lt;b&gt;AES&lt;/b&gt;&lt;/i&gt;, &lt;i&gt;&lt;b&gt;Claude Mythos Preview&lt;/b&gt;&lt;/i&gt; trabajó de forma prácticamente autónoma, proponiendo hipótesis,
programando experimentos para comprobarlas y refinando sus propias ideas durante días.
Y aquí viene mi parte favorita: al principio, &lt;i&gt;&lt;b&gt;Claude Mythos&lt;/b&gt;&lt;/i&gt; se negaba a intentarlo.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;El modelo
insistía en que mejorar el &lt;i&gt;&lt;b&gt;criptoanálisis&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;AES&lt;/b&gt;&lt;/i&gt; era imposible, que era el cifrado más estudiado
que existe y que no quedaba nada fácil por encontrar. Los investigadores tuvieron que darle,
literalmente, mensajes de ánimo (que &lt;i&gt;&lt;b&gt;Anthropic&lt;/b&gt;&lt;/i&gt; publica tal cual), insistiéndole en que no
buscaban ”&lt;i&gt;&lt;b&gt;fruta madura&lt;/b&gt;&lt;/i&gt;” sino investigación de verdad. Tras esos &lt;i&gt;&lt;b&gt;&quot;empujoncitos&quot;&lt;/b&gt;&lt;/i&gt;, y después de
generar del orden de mil millones de palabras trabajando sin descanso, &lt;i&gt;&lt;b&gt;Claude&lt;/b&gt;&lt;/i&gt; dio con
la idea del &lt;b&gt;&lt;u&gt;Möbius Bridge&lt;/u&gt;&lt;/b&gt;.&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;980&quot; data-original-width=&quot;1340&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgQ8OBNFAFY5vTZKfzG4_3VmiVMkCuvCZwk6gTN1MTuEH_JN5fhbII3KytkOoHtG1ydgpI5G27KYUcpCkd39GWg3joOjXViAxegnLRgK1NnR3tG6OBbac52AYlSAxZOXg874BREK1dE9gCefSUyrhrrQa9cL3Ai3dovsuYfV0x4QLs54zmig-Za/w640-h468/cripto5.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 10: &lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot;&gt;Al principio Claude Mythos se negaba a atacar AES por considerarlo&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot;&gt;imposible. &lt;/a&gt;&lt;/span&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://www.anthropic.com/research/discovering-cryptographic-weaknesses&quot;&gt;Los investigadores tuvieron que animarle a seguir intentándolo&lt;/a&gt;.&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;
En el ataque a &lt;i&gt;&lt;b&gt;HAWK&lt;/b&gt;&lt;/i&gt; la dinámica fue distinta pero igual de curiosa: varios &lt;i&gt;&lt;b&gt;Agentes IA&lt;/b&gt;&lt;/i&gt;&amp;nbsp;de
&lt;i&gt;&lt;b&gt;Claude&amp;nbsp; Mythos&lt;/b&gt;&lt;/i&gt; colaboraban entre sí, y la idea clave surgió de una pareja de ellos en la que uno
descartó el enfoque por imposible y el otro le convenció de que sí funcionaba, hasta que
ambos se pusieron de acuerdo. &lt;u&gt;Ciencia hecha por comités de IAs debatiendo entre ellas&lt;/u&gt;. Lo
que hay que ver.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.mypublicinbox.com/dashboard/chats/1EYMKZVKlRwaJx0g&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;542&quot; data-original-width=&quot;878&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUw_-dmvGoyYQJZ-pePlrwShFAnpWUIYUUIrEylElGv7RPjCaTlTnOvS2SWGqCMK_CuOxSLozC4ZDw2Wkx4GtqV0MUhdcaYhPPzIIyOgeqf-uIEMP0tJxtM8-1ifSWfcLlLiNw_vhf7oVNT2LaJNv2jSW6WKxYZIwp3Koc51CO_r0FalBD_0sP/w640-h396/q7.png&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 11: &lt;a href=&quot;https://www.mypublicinbox.com/dashboard/chats/1EYMKZVKlRwaJx0g&quot;&gt;Foro Público de Quantum Security de&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://www.mypublicinbox.com/dashboard/chats/1EYMKZVKlRwaJx0g&quot;&gt;la Universidad de Deusto en MyPublicInbox&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;
Pero quizá el dato más revelador de todos es este: mientras &lt;i&gt;&lt;b&gt;Claude Mythos Preview&lt;/b&gt;&lt;/i&gt; tardó una semana en
idear el ataque a &lt;i&gt;&lt;b&gt;AES&lt;/b&gt;&lt;/i&gt;, a los investigadores humanos les llevó casi un mes verificar que lo
que había encontrado era correcto. El cuello de botella ya no está en tener las ideas, sino en
comprobarlas.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Entonces... ¿debemos preocuparnos?&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
La respuesta corta es: de momento, no. Ninguno de los dos ataques afecta a sistemas reales
en funcionamiento (&lt;i&gt;&lt;b&gt;HAWK&lt;/b&gt;&lt;/i&gt; aún no se usa y el ataque a &lt;i&gt;&lt;b&gt;AES&lt;/b&gt;&lt;/i&gt; sólo funciona en su versión
recortada). Además, &lt;i&gt;&lt;b&gt;Anthropic&lt;/b&gt;&lt;/i&gt; actuó con responsabilidad: avisó a los autores de &lt;i&gt;&lt;b&gt;HAWK&lt;/b&gt;&lt;/i&gt;,
coordinó la publicación con el &lt;i&gt;&lt;b&gt;NIST&lt;/b&gt;&lt;/i&gt; y consultó con expertos, gobierno e industria antes de
hacerlo público.&lt;br /&gt;&lt;br /&gt;
De hecho, esto es la criptografía funcionando exactamente como debe: someter los
algoritmos a un escrutinio feroz para ganar confianza en ellos. Lo que cambia es quién
hace ese escrutinio. Hace apenas un año, los modelos de &lt;i&gt;&lt;b&gt;IA&lt;/b&gt;&lt;/i&gt; eran incapaces de romper ni
los cifrados más básicos; hoy encuentran fallos que se les escaparon a los mejores expertos
humanos durante años.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://arxiv.org/pdf/2607.18538&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1508&quot; data-original-width=&quot;1094&quot; height=&quot;640&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgLwy48KSgNzbXDGTk2hnpr_X0ZnQegabIK0sgV3_KUFaHPGy9lsgXT27gdHlDKCs_zzbguDE8kEVMlO7sinPkfiY5R_48KVNeGMRm9hchHS6FF2QPwDYKYH-G8moOkFT6dqOIdp4e405NGeFXvJ-n37HYc5ACLBpDzFYOvGx7FpWMoKoD_SXns/w464-h640/cripto6.jpg&quot; width=&quot;464&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 12: &lt;a href=&quot;https://arxiv.org/pdf/2607.18538&quot;&gt;CryptoanalisisBench: Can LLMs do Cryptoanalysis?&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Y la cosa no acaba aquí: Anthropic menciona que ya ha empezado
a arañar otros cifrados, como &lt;i&gt;&lt;b&gt;LEA&lt;/b&gt;&lt;/i&gt; o &lt;i&gt;&lt;b&gt;Serpent&lt;/b&gt;&lt;/i&gt;, e incluso ha creado un banco de pruebas
(&lt;a href=&quot;https://arxiv.org/pdf/2607.18538&quot;&gt;CryptanalysisBench&lt;/a&gt;) para medir cómo evoluciona esta capacidad con el tiempo. La reflexión inquietante que la propia empresa pone sobre la mesa es inevitable: ¿qué haremos
el día que una &lt;i&gt;&lt;b&gt;IA&lt;/b&gt;&lt;/i&gt; descubra una grieta en un candado que sí esté protegiendo el mundo real?&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Conclusión&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
En este &lt;i&gt;&lt;b&gt;blog&lt;/b&gt;&lt;/i&gt; llevamos tiempo contando cómo los &lt;b&gt;&lt;u&gt;ordenadores cuánticos&lt;/u&gt;&lt;/b&gt; nos obligarán a
renovar los candados de &lt;i&gt;&lt;b&gt;Internet&lt;/b&gt;&lt;/i&gt;. Lo que este trabajo demuestra es que la revisión de esos
candados nuevos ya no la harán solo los humanos: &lt;b&gt;&lt;u&gt;la Inteligencia Artificial se ha sentado en la
mesa de los criptoanalistas&lt;/u&gt;&lt;/b&gt;, y lo ha hecho hiriendo a un candidato&lt;i&gt;&lt;b&gt; post-cuántico&lt;/b&gt;&lt;/i&gt; y arañando
al mismísimo &lt;i&gt;&lt;b&gt;AES&lt;/b&gt;&lt;/i&gt;.&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.deusto.es/es/inicio/estudia/estudios/curso-seminario/quantum-post-quantum&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;479&quot; data-original-width=&quot;800&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjonM6IQev6AzSJaNGkDnrI6wKqaGJZjc1YUPaOtykxXBLNoK3DWFhpKT46843SosbJjMJ3B86qABvlxgHK3FgwN-Qp_3MpuMiOpI9L8yM5enS5xQrAgZ093V4Zb2J4X1lKLoODRcTwJipHTT_7ETpqR7Yv6acRWmGdhVovE_UCgXR3U1EgHt0Q/w640-h384/q0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 13: &lt;a href=&quot;https://www.deusto.es/es/inicio/estudia/estudios/curso-seminario/quantum-post-quantum&quot;&gt;Quantum y Post-Quantum Computing para Ciberseguridad.&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://www.deusto.es/es/inicio/estudia/estudios/curso-seminario/quantum-post-quantum&quot;&gt;Formación Especializada, Libro &amp;amp; Foro Online&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;
Bien utilizada, esta capacidad es una excelente noticia: algoritmos sometidos a más pruebas
que nunca, grietas descubiertas antes de su despliegue y, quizá en el futuro, cifrados diseñados
con ayuda de la propia &lt;i&gt;&lt;b&gt;IA&lt;/b&gt;&lt;/i&gt; para ser más resistentes. La otra cara de la moneda es que
esa misma herramienta podría acabar en las manos equivocadas.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;La eterna carrera entre
cerrajeros y ladrones acaba de sumar un participante nuevo que no duerme, no se cansa y
escribe mil millones de palabras en una semana. La pregunta, como siempre, es inevitable: &lt;i&gt;&lt;b&gt;¿estarán nuestros candados preparados para un mundo donde las máquinas buscan las grietas?&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div&gt;Saludos,&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;&lt;a href=&quot;https://mypublicinbox.com/DanielRomeroRuiz&quot;&gt;Daniel Romero Ruiz&lt;/a&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/DanielRomeroRuiz&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1490&quot; data-original-width=&quot;1880&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIoA-Qjo8Scebz12sKmVQnmufZNAZsmVs4x8WiGsyARk1aUnKd-aX7_ptHXHaduSJ45pfQOEZ_heKE7r2xQ8NW0xCjLOcNzWC_ldIVf-oGShZ-neijW84b2-7ufCTAezRVXji9JISVmIdPe1BVsTXJuMT8-vEOIifxE9-5UCTVoLCgMoHUZavH/w640-h508/DanielRomeroRuiz.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 14:&amp;nbsp;&lt;a href=&quot;https://mypublicinbox.com/DanielRomeroRuiz&quot;&gt;Contactar con Daniel Romero Ruiz&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;Otros artículos sobre Quantum Computing publicados:&lt;/b&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/07/iii-edicion-del-programa-de.html&quot;&gt;III edición del Programa de Especialización de Quantum y Post-Quantum Computing para Ciberseguridad: Noviembre 2026&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://0xword.com/es/libros/248-quatum-security-tecnologia-cuantica-ciberseguridad-criptografica-cuantica-y-post-cuantica.html&quot;&gt;Libro de &lt;span style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;Quatum Security: Tecnología Cuántica &amp;amp; Ciberseguridad. &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;Criptográfica Cuántica y Post-Cuántica.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.mypublicinbox.com/dashboard/chats/1EYMKZVKlRwaJx0g&quot;&gt;&lt;span style=&quot;text-align: center;&quot;&gt;Foro Público de Quantum Security de &lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;la Universidad de Deusto en MyPublicInbox&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2022/12/quantum-computing-cybersecurity.html&quot;&gt;Quantum Computing Cybersecurity Preparedness Act: Comienza la era de Ciberseguridad Post-Quantum en Estados Unidos&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/04/hamming-quasi-cyclic-hqc-kem-nuevo-key.html&quot;&gt;Hamming Quasi-Cyclic (HQC-KEM): Nuevo Key-Encapsulation Mechanism en Post-Quantum Cryptography&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/05/frodokem-un-key-encapsulation-mechanism.html&quot;&gt;FrodoKEM: Un Key-Encapsulation Mechanism Quantum-Safe (PQC) que recibe su nombre por &quot;El señor de los Anillos&quot;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/08/la-gran-busqueda-de-numeros-primos-de.html&quot;&gt;La Gran Búsqueda de Números Primos de Mersenne en Internet para superar el mayor Número Primo conocido hasta la fecha&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/09/como-acelerar-los-algoritmos-de.html&quot;&gt;Cómo acelerar los algoritmos de Inteligencia Artificial con Computadores Analógicos Ópticos (AOC)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/10/premio-nobel-en-fisica-2025-el-trabajo.html&quot;&gt;Premio Nobel en Física 2025: El trabajo del &quot;Efecto Tunel&quot; que trajo la cuántica a nuestro mundo y abrió la puerta a los ordenadores cuánticos&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/10/un-reloj-atomico-optico-del-mit-con.html&quot;&gt;Un Reloj Atómico Óptico del MIT con Optimización Cuántica para medir el Tiempo del Futuro&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2018/06/quantum-cryptography-una-comunicacion.html&quot;&gt;Quantum Cryptography: Una comunicación con cifrado cuántico&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2023/01/factorizacion-de-rsa-con-un-optimizador.html&quot;&gt;Factorización de RSA con un Optimizador de Quantum Computing (y Classic Computing)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/11/cuanto-del-trafico-en-internet-funciona.html&quot;&gt;Cuánto del tráfico en Internet funciona con Post-Quantum Cryptography&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/11/algoritmo-cuantico-de-grover-un.html&quot;&gt;Algoritmo Cuántico de Grover: Un algoritmo de búsqueda optimizado por superposición cuántica&amp;nbsp;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/12/quantum-sensors-cuando-lo-invisible-se.html&quot;&gt;Quantum Sensors: Cuando lo invisible se hace visible gracias al Mundo Cuántico&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/12/bitcoin-vs-quantum-computers-hora-de.html&quot;&gt;Bitcoin vs Quantum Computers: Hora de pasar a Post-Quantum Cryptography&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/12/el-white-paper-de-mastercard-que-urge.html&quot;&gt;El White Paper de MasterCard que urge a pasar a Quantum Safe: Post-Quantum Cryptography (PQC) &amp;amp; Quantum Key Distribution (QKD)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/12/dyber-hardware-accelerated-post-quantum.html&quot;&gt;Dyber: Hardware-Accelerated Post-Quantum Cryptography (PQC)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/01/como-ser-quantum-safe-y-desplegar-post.html&quot;&gt;Cómo ser Quantum Safe y desplegar Post-Quantum Cryptography (PQC) con Cloudflare&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/02/quantum-gps-navegacion-con-gps.html&quot;&gt;Quantum GPS: Navegación con GPS cuánticos para evitar ataques de Jamming &amp;amp; Spoofing&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/03/como-comprobar-si-un-web-site-is.html&quot;&gt;Cómo comprobar si un Web Site es Quantum Ready con Post-Quantum Cryptography usando Radar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/03/alaniz-cipher-un-cifrado-simetrico.html&quot;&gt;Alaniz Cipher: Un Cifrado Simétrico Quantum Resistant&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/05/los-papers-academicos-de-los-algoritmos.html&quot;&gt;Los Papers Académicos de los algoritmos PQC de Autenticación y Firma Digital en la Ronda 3 del NIST&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/07/blind-quantum-computing-1.html&quot;&gt;Blind Quantum Computing (1)&lt;/a&gt; &lt;a href=&quot;https://www.elladodelmal.com/2026/07/blind-quantum-computing-2.html&quot;&gt;(2)&lt;/a&gt; &lt;a href=&quot;https://www.elladodelmal.com/2026/07/blind-quantum-computing-3.html&quot;&gt;(3)&lt;/a&gt; &lt;a href=&quot;https://www.elladodelmal.com/2026/07/blind-quantum-computing-y-4.html&quot;&gt;(4)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/08/computacion-cuantica-y-fusion-nuclear.html&quot;&gt;Computación Cuántica y Fusión Nuclear: La Receta para fabricar un &quot;Sol en la Tierra&quot;&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/claude-mythos-preview-debilita-los.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhV0aD2IBu3_cD4rMKA6nZ4DTtv0rdd5S69W3vTS8i2RYVHgf8srC_LX-DmmwCTYiSe43HR-sxS9-lfYZcmsHEtMqMrflxtCmX7uA3rYMQzIiLhTNkCroAGytOeZCnYNUQUwnTMjSSaDjttB8sSf2p66TLV51zvhKxC66q1F39zjxx41UMpziWQ/s72-w640-h422-c/crypto0.jpg" height="72" width="72"/><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-191752175464266164</guid><pubDate>Wed, 12 Aug 2026 04:01:00 +0000</pubDate><atom:updated>2026-08-12T06:01:00.173+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Curiosidades</category><category domain="http://www.blogger.com/atom/ns#">personal</category><title>&quot;Enorgullécete de ellos&quot;, dijo.</title><description>&lt;div style=&quot;text-align: justify;&quot;&gt;Tengo por suerte el tener algunos sabios amigos mucho más mayores que yo, de esos que saben más por viejos que o diablo, que de vez en cuando me aleccionan con un buen café de por medio - sólo, como debe de ser -, o un agua fresquita. Uno de ellos, con la vida ya cumplida, ganada y peleada, me da buenos tirones de orejas, grandes palabras, y conversaciones llenas de sabiduría de la que se gana mordiendo polvo,&amp;nbsp; tragando esparto y escupiendo sangre.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLYOPEKfQTpV3TFpUycEgdoXSg3APxK0tniN5uvEgAL421YD9osh13VXg9TVCKExiBsBK7XPjDmMzXHMkILU7y9OrPPfpgYFTvzrB6FrWMG6ib0CD7K0K9QoZQkNHmnYs49wWVMeFFMZL4FQhZty1DewDOqSTQErZ1QuOrgPFeNBR9xtdHep7D/s940/orgullo0.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;561&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLYOPEKfQTpV3TFpUycEgdoXSg3APxK0tniN5uvEgAL421YD9osh13VXg9TVCKExiBsBK7XPjDmMzXHMkILU7y9OrPPfpgYFTvzrB6FrWMG6ib0CD7K0K9QoZQkNHmnYs49wWVMeFFMZL4FQhZty1DewDOqSTQErZ1QuOrgPFeNBR9xtdHep7D/w640-h382/orgullo0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;&quot;Enorgullécete de ellos&quot;, dijo.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;En una de las más recientes conversaciones, a la luz de su biblioteca, me dejó una bonita lección de vida. Sentados al sofá, riéndonos de las ratas y los cobardes, me decía esto que os dejo por aquí. Que aunque no fue palabra por palabra en ese orden, sí que las dijo todas - y alguna que he quitado por no ser necesaria tanta clarividencia en la elección de los epítetos -:&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote style=&quot;border-color: currentcolor; border-image: none; border-style: none; border-width: medium; margin: 0px 0px 0px 40px; padding: 0px; text-align: left;&quot;&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;&lt;b&gt;&quot;Chema, a los amigos hay que quererlos, pero no ponerlos a prueba, que uno no sabe nunca si son de verdad o no. Y aunque lo sean, si los pones a prueba, puede que les flaqueen las pierdas, que las debilidades humanas son muchas y afectan a todos, incluso a los amigos.&lt;/b&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;blockquote style=&quot;border-color: currentcolor; border-image: none; border-style: none; border-width: medium; margin: 0px 0px 0px 40px; padding: 0px; text-align: left;&quot;&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;blockquote style=&quot;border-color: currentcolor; border-image: none; border-style: none; border-width: medium; margin: 0px 0px 0px 40px; padding: 0px; text-align: left;&quot;&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;&lt;b&gt;Eso sí, de tus enemigos, debes estar orgulloso. Nadie ha logrado nada bueno en esta vida sin ofender a mediocres, malnacidos y mequetrefes. Tener una buena ración de gente mala que te odia es síntoma de haber llevado una vida buena por el camino correcto.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;&lt;b&gt;Si tus enemigos son malsanos petimetres, malnacidos, ratas inmundas de la vida, envidiosos, y descerebrados, entonces es que tú vas por el buen camino. Así que cuando los escuches rebuznar, graznar o llorar por un poco de tu atención, siente feliz, y disfruta del momento. Sonríe y toma nota, que ya los verás rebuznar, graznar y llorar por un poco de atención de otros, que estos mequetrefes, mediocres y ratillas sólo buscan tener enemigos mejores que ellos que los hagan sentir importantes, porque ellos ya saben que no lo son.&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;&lt;b&gt;&lt;br /&gt;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;&lt;b&gt;Así que, si se tiene una panda de descerebrados mediocres que pían mal de uno, es que se está progresando en la vida. Enorgullece de tenerlos. De saber que los que te critican son los que deben, los que están donde no queremos estar. Enorgullece de ellos.&quot;&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Y con lecciones así, echadas en lo que suenan tres temas por el hilo musical y lo que tarda uno en dar dos sorbos al café negro, nos echamos unas risas, y nos convocamos para la siguiente, que estamos tramando un nuevo plan. Espero que os sea tan útil como a mí.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;¡Saludos Malignos!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;Chema Alonso &lt;/b&gt;(&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;Contactar con Chema Alonso&lt;/a&gt;) &amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; font-style: italic; text-align: center;&quot;&gt;
&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;444&quot; data-original-width=&quot;800&quot; src=&quot;https://1.bp.blogspot.com/-wPU2d-hy3rM/XiyVNgM4kGI/AAAAAAAAy70/Pk1IP6-v7bQLVUNL2iWneVOgRP494eWrACLcBGAsYHQ/s640/MPICHemaalonso.jpg&quot; width=&quot;450&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/enorgullecete-de-ellos-dijo.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiLYOPEKfQTpV3TFpUycEgdoXSg3APxK0tniN5uvEgAL421YD9osh13VXg9TVCKExiBsBK7XPjDmMzXHMkILU7y9OrPPfpgYFTvzrB6FrWMG6ib0CD7K0K9QoZQkNHmnYs49wWVMeFFMZL4FQhZty1DewDOqSTQErZ1QuOrgPFeNBR9xtdHep7D/s72-w640-h382-c/orgullo0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-889761717462315378</guid><pubDate>Tue, 11 Aug 2026 04:01:00 +0000</pubDate><atom:updated>2026-08-11T06:01:00.292+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">Apple</category><category domain="http://www.blogger.com/atom/ns#">blog</category><category domain="http://www.blogger.com/atom/ns#">blogs</category><category domain="http://www.blogger.com/atom/ns#">cloudflare</category><category domain="http://www.blogger.com/atom/ns#">datos</category><category domain="http://www.blogger.com/atom/ns#">Gemini</category><category domain="http://www.blogger.com/atom/ns#">Google</category><category domain="http://www.blogger.com/atom/ns#">IA</category><category domain="http://www.blogger.com/atom/ns#">Instagram</category><category domain="http://www.blogger.com/atom/ns#">Inteligencia Artificial</category><category domain="http://www.blogger.com/atom/ns#">LLMs</category><category domain="http://www.blogger.com/atom/ns#">TikTok</category><title>Los Six-Seven Large Slang-Bro Models</title><description>&lt;div style=&quot;text-align: justify;&quot;&gt;Llevo dos décadas practicando la afición - u oficio - de publicar artículos en mi &lt;i&gt;&lt;b&gt;blog&lt;/b&gt;&lt;/i&gt;. Al final son páginas &lt;i&gt;&lt;b&gt;web&lt;/b&gt;&lt;/i&gt; que los &lt;i&gt;&lt;b&gt;LLM&lt;/b&gt;&lt;/i&gt; están viniendo a consumir para entrenar sus modelos. Necesitan textos para generar &lt;i&gt;&lt;b&gt;Modelos de Lenguaje&lt;/b&gt;&lt;/i&gt; inteligentes, así que llevo &lt;i&gt;&lt;b&gt;20&lt;/b&gt;&lt;/i&gt; años escribiendo para vosotros y&amp;nbsp;gracias a eso, ahora&amp;nbsp;las &lt;i&gt;&lt;b&gt;Inteligencias Artificiales Generativas&lt;/b&gt;&lt;/i&gt; de textos, puedan entrenarse. De nada.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSRipsEkOpALdMtfApxo0ZzxG0ir1yz3huLGNEWPowLmbcRX_LL6iGOgJc5fmrP60Gibo362fOg_bu_apR3AohTozjqkyCjkU3xxanD5qEn0V3pcuIxhqU12hwjmQGjLGYNvHZ6Hplk6MmU1MGTqXMCCdOqQ6U-hXqbh67CK9DWmJQ_iGCNpov/s940/bro0.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;513&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSRipsEkOpALdMtfApxo0ZzxG0ir1yz3huLGNEWPowLmbcRX_LL6iGOgJc5fmrP60Gibo362fOg_bu_apR3AohTozjqkyCjkU3xxanD5qEn0V3pcuIxhqU12hwjmQGjLGYNvHZ6Hplk6MmU1MGTqXMCCdOqQ6U-hXqbh67CK9DWmJQ_iGCNpov/w640-h350/bro0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;Los Six-Seven Large Slang-Bro Models&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;No es una cosa que diga por decir, es algo que podéis ver en los datos de &lt;a href=&quot;https://radar.cloudflare.com/ai-insights&quot;&gt;AI Insights en Radar de Cloudflare&lt;/a&gt;, donde si miramos qué porcentaje de &lt;i&gt;&lt;b&gt;crawlers&lt;/b&gt;&lt;/i&gt; vienen a por datos para entrenamiento, y cuantos vienen para inferencia y entrenamiento, y los sumamos, vemos que son más del &lt;i&gt;&lt;b&gt;75 %&lt;/b&gt;&lt;/i&gt;. No está mal la de de &lt;i&gt;&lt;b&gt;IAs&lt;/b&gt;&lt;/i&gt; que entreno todos los días.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://radar.cloudflare.com/ai-insights&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;962&quot; data-original-width=&quot;1674&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhcFanfS5OjGrzL5vlP-KviniHOHm1P0EZYRFlVaTE4TuoAyBoEZ4JhP9zBYSwKP7JH-87qOa6jvf09DRQAIbuXTHzq8rYiGyYTAl_d2NT28Q7O3lRFJRCsHkCl80ic0gUy-UE26HThS_4PepWpzzkGhWSq_Y8cWSrmynwEbjxZ2Mz_Vuhxch1P/w640-h368/Bro4.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 2: &lt;a href=&quot;https://radar.cloudflare.com/ai-insights&quot;&gt;Crawler purpose en AI Insights de Cloudflare Radar&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Los datos de las &lt;i&gt;&lt;b&gt;webs&lt;/b&gt;&lt;/i&gt;, los foros, los &lt;i&gt;&lt;b&gt;blogs&lt;/b&gt;&lt;/i&gt;, y demás textos publicados en &lt;i&gt;&lt;b&gt;HTTP&lt;/b&gt;&lt;/i&gt; tienen una estructura concreta. Es verdad que en las redes sociales hay mucho lenguaje informal, pero esos no están siendo entregados a los crawlers de &lt;i&gt;&lt;b&gt;LLMs&lt;/b&gt;&lt;/i&gt; para que entrenen sus modelos. Nop. Esos los usará cada empresa para entrenar a sus propios modelos.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;b&gt;&lt;u&gt;Pero todo dato es bueno.&amp;nbsp;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;De hecho, hemos visto cómo &lt;a href=&quot;https://www.lavanguardia.com/neo/ia/20260728/11601806/millones-libros-antiguos-son-destruidos-empresas-ia-mejores-datos-entrenamiento-estanteria.html&quot;&gt;los grandes LLMs han comprado libros y los has destrozado para escanearlos a la velocidad más rápida posible y entrenar los modelos con todos ellos&lt;/a&gt;. Los libros, suelen tener lenguaje más formal, pasar revisiones de formato, gramaticales, de estilo, etcétera, así que son los textos más valiosos para hacer un modelo culto y refinado, además de para los modelos científicos, de ingeniería, o de habilidades tecnológicas.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.lavanguardia.com/neo/ia/20260728/11601806/millones-libros-antiguos-son-destruidos-empresas-ia-mejores-datos-entrenamiento-estanteria.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1448&quot; data-original-width=&quot;1946&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYYGMPoiGYA1GQYTVTe7KNdCsiGnD3YNjO078YdxGDsWyjPqqEmwPITEWaP53v7Ul4FayEAApMB-W7y3Y89xgl8lvr8Y6zy5z2wH6c-NDZ8Ogei82ufdHsqysN5zquRtgFS78mNpPXcMz_AWzVQx1jbTZThoxBcOJC_RyAT7VabeO4W0-zK_Qz/w640-h476/Bro6.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 3: &lt;a href=&quot;https://www.lavanguardia.com/neo/ia/20260728/11601806/millones-libros-antiguos-son-destruidos-empresas-ia-mejores-datos-entrenamiento-estanteria.html&quot;&gt;Libros antiguos destruidos para entrenar a la IA&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Sin embargo, hay otra gran cantidad de datos para los &lt;i&gt;&lt;b&gt;LLMs&lt;/b&gt;&lt;/i&gt; en otros formatos que no son los &lt;i&gt;&lt;b&gt;blogs&lt;/b&gt;&lt;/i&gt;, y que son las redes sociales, los vídeos de &lt;i&gt;&lt;b&gt;Youtube&lt;/b&gt;&lt;/i&gt;, los &lt;i&gt;&lt;b&gt;podcasts&lt;/b&gt;&lt;/i&gt; en &lt;i&gt;&lt;b&gt;Spotify&lt;/b&gt;&lt;/i&gt;, o las redes sociales - como ya he dicho - como son &lt;i&gt;&lt;b&gt;Instagram&lt;/b&gt;&lt;/i&gt; o &lt;i&gt;&lt;b&gt;Tiktok&lt;/b&gt;&lt;/i&gt;. Especialmente este último, donde los más jóvenes aún proliferan.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_-H43c0SV9UnFu38naYDGYjKc1y_GaFgFnIBR6iwBiZPIuqDpMAGO8dciO08xOWy-iZtkLi2Ni7Yp4D-A9XYCP9DiAgijXjaV9Ffe7_hb-2j20MbbLN6R9Df3eq4lQBHvpsRmsvPCXPQ_stI8SblmoEiCideacpQwt0ZI_aB1INA9myNHcdne/s886/Bro1.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;446&quot; data-original-width=&quot;886&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_-H43c0SV9UnFu38naYDGYjKc1y_GaFgFnIBR6iwBiZPIuqDpMAGO8dciO08xOWy-iZtkLi2Ni7Yp4D-A9XYCP9DiAgijXjaV9Ffe7_hb-2j20MbbLN6R9Df3eq4lQBHvpsRmsvPCXPQ_stI8SblmoEiCideacpQwt0ZI_aB1INA9myNHcdne/w640-h322/Bro1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 4: Extrayendo un Markdown de un vídeo de Tiktok&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Aquí los textos para entrenar a los &lt;i&gt;&lt;b&gt;LLMs&lt;/b&gt;&lt;/i&gt; son de lenguaje más de la calle, es decir, más &lt;i&gt;&lt;b&gt;Six-Seven&lt;/b&gt;&lt;/i&gt;, donde hay interacciones genuinas de seres humanos sin filtro alguno.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKEYGBmsKsP6dsevl-5ijTrE26gO8khjej9V1Jiu7o9q16-dXk0LulOOmLio-GfLVQQNUTPkWYmPibJbdYnJ004SgkUtVBpGZwKXHIcrgss1-sLUXaHXsoqh5GWHv2SevHS3RN3zertqaXLMwIBThFp4uirrisin6zwaOr_U9gaegq1TQwtCh4/s1568/Bro2.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1568&quot; data-original-width=&quot;1224&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjKEYGBmsKsP6dsevl-5ijTrE26gO8khjej9V1Jiu7o9q16-dXk0LulOOmLio-GfLVQQNUTPkWYmPibJbdYnJ004SgkUtVBpGZwKXHIcrgss1-sLUXaHXsoqh5GWHv2SevHS3RN3zertqaXLMwIBThFp4uirrisin6zwaOr_U9gaegq1TQwtCh4/w500-h640/Bro2.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 5: Extracción de textos en formato Markdown&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Con estos datos, que son oro para los creadores de modelos de &lt;i&gt;&lt;b&gt;IA&lt;/b&gt;&lt;/i&gt;, se pueden crear &lt;i&gt;&lt;b&gt;LLMs&lt;/b&gt;&lt;/i&gt; que hablen perfectamente el Slang de hoy en día, con los &quot;&lt;i&gt;&lt;b&gt;Bro&lt;/b&gt;&lt;/i&gt;&quot;, los &quot;&lt;i&gt;&lt;b&gt;Catas&lt;/b&gt;&lt;/i&gt;&quot;, los &quot;&lt;i&gt;&lt;b&gt;En Plan&lt;/b&gt;&lt;/i&gt;&quot; y todas esas cosas que se dicen tanto hoy en los más jóvenes. Y es muy sencillo a día de hoy procesarlos. Yo me he bajado uno al azar de &lt;i&gt;&lt;b&gt;TikTok&lt;/b&gt;&lt;/i&gt; cortito y en nada &lt;i&gt;&lt;b&gt;Gemini&lt;/b&gt;&lt;/i&gt; te saca el &lt;i&gt;&lt;b&gt;Markdown&lt;/b&gt;&lt;/i&gt; del fichero.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;b&gt;&lt;u&gt;Enriqueciendo los datos&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Pero no solo eso, como ya os conté en la prueba que hice para &lt;a href=&quot;https://www.elladodelmal.com/2024/12/investigando-fotografias-y-personas-con.html&quot;&gt;usar los LLMs en modelos de Análisis Forense de fotografías&lt;/a&gt;, también son perfectos para sacar Metadatos para estas conversaciones de vídeos, así el fichero &lt;i&gt;&lt;b&gt;Markdown&lt;/b&gt;&lt;/i&gt; queda más enriquecido.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrsXJLTaD8o_m_CKu4QKAAigV7YHb7PhQBJaNiI_hPK6Q7wLMt525-plmQVmynav_LoeQUAbcW1DreyzOT-btei6owOe97dFtUUlKFaz9BH4VUnOevO2JekOTG5eTCPEXEGJ5h2wHWCP0hxtMNvhbPAAFz8f9dUTp68FBjcDtlkQ7kTD699KKS/s1320/Bro5.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1320&quot; data-original-width=&quot;1156&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgrsXJLTaD8o_m_CKu4QKAAigV7YHb7PhQBJaNiI_hPK6Q7wLMt525-plmQVmynav_LoeQUAbcW1DreyzOT-btei6owOe97dFtUUlKFaz9BH4VUnOevO2JekOTG5eTCPEXEGJ5h2wHWCP0hxtMNvhbPAAFz8f9dUTp68FBjcDtlkQ7kTD699KKS/w560-h640/Bro5.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 6: Metadatos generados sobre el vídeo&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Así que, es normal que con este apetito voraz por datos nuevos, por nuevos datos que actualicen el conocimiento constante de los &lt;i&gt;&lt;b&gt;LLMs&lt;/b&gt;&lt;/i&gt; y su adaptación al día de hoy, cada día quieren más y más datos de entrenamiento, de donde sean. Y los de estas redes son muy buenos para crear modelos adaptados a los más jovenes. Los &lt;i&gt;&lt;b&gt;Six-Seve Large Slang-Bro Models.&lt;/b&gt;&lt;/i&gt;... o algo así.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://radar.cloudflare.com/ai-insights&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1102&quot; data-original-width=&quot;1238&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi2kB73_IRlYtUv1-Y-tv9D73fVEG6zgALGiGQTHwdeGJR_erFyEpBUAR4wMJGl4UxdFqYfYSpGFqiey9ND4Bp8CbEo9N1wnh1wMCKQ6Qv6dAarMDIhd7AV1l_31J2phYjtrL9pBy5lIwG43rT95t5-pIU_oImCAA1W4eB9u3t5xZfgCz82nT-T/w640-h570/Bro3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 7: &lt;a href=&quot;https://radar.cloudflare.com/ai-insights&quot;&gt;AI Bot Transparency en Radar de Cloudflare&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;En la última imagen, os he dejado los bots que no diferencian para qué vienen a coger datos de una &lt;i&gt;&lt;b&gt;web&lt;/b&gt;&lt;/i&gt;. Llaman la atención &lt;i&gt;&lt;b&gt;Apple, Microsoft y Google&lt;/b&gt;&lt;/i&gt;, que no quieren perder la posibilidad de utilizar los datos que meten en sus índices para usarlos también en entrenamiento, algo que creo que lo deberían saber los dueños de los datos.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;¡Saludos Malignos!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;Chema Alonso &lt;/b&gt;(&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;Contactar con Chema Alonso&lt;/a&gt;) &amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; font-style: italic; text-align: center;&quot;&gt;
&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;444&quot; data-original-width=&quot;800&quot; src=&quot;https://1.bp.blogspot.com/-wPU2d-hy3rM/XiyVNgM4kGI/AAAAAAAAy70/Pk1IP6-v7bQLVUNL2iWneVOgRP494eWrACLcBGAsYHQ/s640/MPICHemaalonso.jpg&quot; width=&quot;450&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/los-six-seven-large-slang-bro-models.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSRipsEkOpALdMtfApxo0ZzxG0ir1yz3huLGNEWPowLmbcRX_LL6iGOgJc5fmrP60Gibo362fOg_bu_apR3AohTozjqkyCjkU3xxanD5qEn0V3pcuIxhqU12hwjmQGjLGYNvHZ6Hplk6MmU1MGTqXMCCdOqQ6U-hXqbh67CK9DWmJQ_iGCNpov/s72-w640-h350-c/bro0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-6806123755207970115</guid><pubDate>Mon, 10 Aug 2026 04:01:00 +0000</pubDate><atom:updated>2026-08-10T06:49:56.887+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">aviación</category><category domain="http://www.blogger.com/atom/ns#">aviones</category><category domain="http://www.blogger.com/atom/ns#">Curiosidades</category><category domain="http://www.blogger.com/atom/ns#">Google Maps</category><category domain="http://www.blogger.com/atom/ns#">GPS</category><title>El avión de la A-4 que se cruza en mi camino en Google Maps</title><description>&lt;div style=&quot;text-align: justify;&quot;&gt;Si ya conoces esta historia, entonces el post de hoy te lo puedes saltar. Pero yo no lo conocía, o si lo conocía ya me había olvidado. Así que cuando revisando la ruta que me marcaba &lt;i&gt;&lt;b&gt;Google Maps&lt;/b&gt;&lt;/i&gt;, de repente veo que voy a pasar por medio de una catástrofe aérea, me quedé un poco sorprendido, y por eso os lo dejo aquí explicado.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEheAJpY-08ypisqjOe9Q858sbtkCczM8PfABuFwkylULsYcGb02-Cb3t4okK3ZGUua8Xo6yhSm73ZF1yDBfp2ESm5g3hHo1bCzHmxmLmWty7oBDZkb-Pjfzb0415b4LiH_aNiNtv0xZDdOrvsCxF07LfkEnWyRi32zFu_6fzoJJ11dZERXDqrBr/s940/Avion0.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;761&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEheAJpY-08ypisqjOe9Q858sbtkCczM8PfABuFwkylULsYcGb02-Cb3t4okK3ZGUua8Xo6yhSm73ZF1yDBfp2ESm5g3hHo1bCzHmxmLmWty7oBDZkb-Pjfzb0415b4LiH_aNiNtv0xZDdOrvsCxF07LfkEnWyRi32zFu_6fzoJJ11dZERXDqrBr/w640-h518/Avion0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1: El avión de la A-4 que se cruza en mi camino en Google Maps&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;En uno de mis viajes recientes, cuando paré para hacer un descanso, repasé la ruta buscando la siguiente parada. Para eso, activo la opción de que me muestre las imágenes satelitales, para ver en qué próxima estación de servicio salir. Ya sabes, que sea cómoda para salir y entrar, que tenga cafetería, y si es posible, me gusta elegir la empresa de la estación de servicio.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFLycMwffTfM8vu1rBPDEzWqnIUn0IrkutWZYlv3sdxQ_ZUok7zbrQZx2c1Dx3B8V9hqsYkkHFmllvwSvk8XEB7mPMczIcL2TytzkJD0GyvGu94fFj-kkBWoJEHw4y_L3V481XX78u1O6PB9JInKtCFgf4wrzkgKv6v357uvGQN3oCF7nhZHYy/s2300/avion1.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;2300&quot; data-original-width=&quot;1320&quot; height=&quot;640&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgFLycMwffTfM8vu1rBPDEzWqnIUn0IrkutWZYlv3sdxQ_ZUok7zbrQZx2c1Dx3B8V9hqsYkkHFmllvwSvk8XEB7mPMczIcL2TytzkJD0GyvGu94fFj-kkBWoJEHw4y_L3V481XX78u1O6PB9JInKtCFgf4wrzkgKv6v357uvGQN3oCF7nhZHYy/w368-h640/avion1.jpg&quot; width=&quot;368&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 2: Por lo menos iba por su derecha...&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Y ahí, fue cuando me topé con un avión en la ruta. &lt;i&gt;&lt;b&gt;&quot;WTF?&quot;&lt;/b&gt;&lt;/i&gt; pensé. No me lo esperaba, la verdad. Según tenía entendido, &lt;i&gt;&lt;b&gt;Google Maps&lt;/b&gt;&lt;/i&gt; utiliza &lt;i&gt;&lt;b&gt;Inteligencia Artificial&lt;/b&gt;&lt;/i&gt; para detectar matrículas, vehículos, u objetos que debe borrar, así que me sorprendía ver un avión aparcado en el carril contrario. Además, como se puede ver, hay un trailer detrás, que para mí era ya el equipo de emergencias. Pero buscando en &lt;i&gt;&lt;b&gt;Gemini&lt;/b&gt;&lt;/i&gt;, la explicación es la que imaginaba... error de los algoritmos de borrado.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjtIYTip0PbExlVok8H95wEA03sxHYctKJNi9jqaT0kmDxk6OkRdxRBU0lRrNCO5pOFZ4vwV6FBLbhuHnpRzKkA7_ljg3SkANdnugApIlxOcqIz5VQHnZcBUtMpN7eGM5-EnyxD-buKm1NYso9WrDjje1ZlsJPCiJC6bDMP2TjafVlKOyNuJCof/s1416/avion3.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1034&quot; data-original-width=&quot;1416&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjtIYTip0PbExlVok8H95wEA03sxHYctKJNi9jqaT0kmDxk6OkRdxRBU0lRrNCO5pOFZ4vwV6FBLbhuHnpRzKkA7_ljg3SkANdnugApIlxOcqIz5VQHnZcBUtMpN7eGM5-EnyxD-buKm1NYso9WrDjje1ZlsJPCiJC6bDMP2TjafVlKOyNuJCof/w640-h468/avion3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 3: Explicación de Gemini.&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Os he hecho un vídeo del momento en el que lo encontré, para que veáis las nubes dejadas, que para mí, en un primer momento, era el rastro del polvo en un aterrizaje forzoso. No hay como montarse películas en la cabeza con estas cosas.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&#39;allowfullscreen&#39; webkitallowfullscreen=&#39;webkitallowfullscreen&#39; mozallowfullscreen=&#39;mozallowfullscreen&#39; width=&#39;470&#39; height=&#39;600&#39; src=&#39;https://www.blogger.com/video.g?token=AD6v5dxBXPm2wWrvyPvdn-UattFJyJalSe3tTcTThJMFOg9fi0DEeX1H20_vZvc_Yh2QQkYQk2E6A09LZ6o&#39; class=&#39;b-hbp-video b-uploaded&#39; frameborder=&#39;0&#39;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 4: El vídeo del &quot;accidente&quot; de avión&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Vista la imagen, y antes de haber comprobado que era un error de borrado del algoritmo de una foto tomada desde el satélite, proyectada la imagen del avión sobre la carretera, yo por si acaso agrandé una imagen para localizar de qué compañía es ese avión.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXwKCBzqDYGZXfFemWOfLz-DXzOuo5RSRDCISNApQbWzMaDMo3wr7Oop5i-d8pT7aRfTDLtJTuZYcVSiJw-RHAaPAni2_Kb57XtTQ0occ9lsWf0xH5tcMAdrL9_NvP20x2lRBx0Na5RlGtgfCxMpxeLW3Bf9Kciu5YyKvEmRxS4cX7GPdtpAX4/s470/Avion2.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;417&quot; data-original-width=&quot;470&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjXwKCBzqDYGZXfFemWOfLz-DXzOuo5RSRDCISNApQbWzMaDMo3wr7Oop5i-d8pT7aRfTDLtJTuZYcVSiJw-RHAaPAni2_Kb57XtTQ0occ9lsWf0xH5tcMAdrL9_NvP20x2lRBx0Na5RlGtgfCxMpxeLW3Bf9Kciu5YyKvEmRxS4cX7GPdtpAX4/s1600/Avion2.jpg&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 5: La imagen del avión ampliado&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;La imagen del avión ampliada - donde parece que se ven las llamas en color rojo - permite ver los colores del fuselaje, así que se puede adivinar la compañía. Pero en el mundo de la &lt;i&gt;&lt;b&gt;Inteligencia Artificial&lt;/b&gt;&lt;/i&gt; en el que nos encontramos, que trabaje nuestra amiga la &lt;i&gt;&lt;b&gt;IA&lt;/b&gt;&lt;/i&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijIAllX3t59PayB_PACUcs_C9cv63Xh6PWP-oVVrcHjiTBJp5Av28EpEi1tzHVXlrxR5CyyYZwzV-XUV4tsOYMe7kYWIC3x73iKrSA-ZdpDc7uh8woxYiT-3ugMlMlnGiOguvDgiTVqdSgtBAcijeRxPGO4z4XggOxsGvp9WhBPR4aCeZzAT5R/s1260/avion5.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1260&quot; data-original-width=&quot;1196&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijIAllX3t59PayB_PACUcs_C9cv63Xh6PWP-oVVrcHjiTBJp5Av28EpEi1tzHVXlrxR5CyyYZwzV-XUV4tsOYMe7kYWIC3x73iKrSA-ZdpDc7uh8woxYiT-3ugMlMlnGiOguvDgiTVqdSgtBAcijeRxPGO4z4XggOxsGvp9WhBPR4aCeZzAT5R/w608-h640/avion5.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 6: El avión &quot;en llamas&quot; &quot;accidentado&quot; es de Vueling&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;El avión es de &lt;i&gt;&lt;b&gt;Vueling&lt;/b&gt;&lt;/i&gt;, así que, sabiendo que les tiran fotos desde el cielo, es momento de que comiencen a pensar en pintar mensajes en el techo del fuselaje del avión, como cuando &lt;a href=&quot;https://engineering.fb.com/2012/03/25/web/a-hack-of-epic-proportions-building-a-qr-code-on-the-roof/&quot;&gt;los &quot;hackers&quot; de Facebook (Meta) dejaban un QRCode en el techo del HeadQuarter en Menlo Park&lt;/a&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;¡Saludos Malignos!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;Chema Alonso &lt;/b&gt;(&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;Contactar con Chema Alonso&lt;/a&gt;) &amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; font-style: italic; text-align: center;&quot;&gt;
&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;444&quot; data-original-width=&quot;800&quot; src=&quot;https://1.bp.blogspot.com/-wPU2d-hy3rM/XiyVNgM4kGI/AAAAAAAAy70/Pk1IP6-v7bQLVUNL2iWneVOgRP494eWrACLcBGAsYHQ/s640/MPICHemaalonso.jpg&quot; width=&quot;450&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/el-avion-de-la-4-que-se-cruza-en-mi.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEheAJpY-08ypisqjOe9Q858sbtkCczM8PfABuFwkylULsYcGb02-Cb3t4okK3ZGUua8Xo6yhSm73ZF1yDBfp2ESm5g3hHo1bCzHmxmLmWty7oBDZkb-Pjfzb0415b4LiH_aNiNtv0xZDdOrvsCxF07LfkEnWyRi32zFu_6fzoJJ11dZERXDqrBr/s72-w640-h518-c/Avion0.jpg" height="72" width="72"/><thr:total>1</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-2419983472828361132</guid><pubDate>Sun, 09 Aug 2026 08:06:22 +0000</pubDate><atom:updated>2026-08-16T20:47:57.383+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">Artificial Intelligence</category><category domain="http://www.blogger.com/atom/ns#">charla</category><category domain="http://www.blogger.com/atom/ns#">CISO</category><category domain="http://www.blogger.com/atom/ns#">conferencia</category><category domain="http://www.blogger.com/atom/ns#">exploiting</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">IA</category><category domain="http://www.blogger.com/atom/ns#">Inteligencia Artificial</category><category domain="http://www.blogger.com/atom/ns#">OpenAI</category><category domain="http://www.blogger.com/atom/ns#">Red Team</category><category domain="http://www.blogger.com/atom/ns#">SSRF</category><title>Ataques Orquestados con Enjambres de Agentes IA Ofensivos</title><description>&lt;div style=&quot;text-align: justify;&quot;&gt;Me he levantado esta mañana, y me he puesto la &lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&amp;amp;t=2s&quot;&gt;charla de OpenAI en BlackHat&lt;/a&gt; explicando el incidente de &lt;i&gt;&lt;b&gt;Hugging Face&lt;/b&gt;&lt;/i&gt; y he de decir que me ha encantado por ver cómo el modelo hace &lt;i&gt;&lt;b&gt;Agent Orchestration&lt;/b&gt;&lt;/i&gt; para crear un &lt;i&gt;&lt;b&gt;Enjambre&lt;/b&gt;&lt;/i&gt; &quot;&lt;i&gt;&lt;b&gt;Swarm&lt;/b&gt;&lt;/i&gt;&quot; de &lt;i&gt;&lt;b&gt;Agentes IA&lt;/b&gt;&lt;/i&gt; para atacar un objetivo. &lt;b&gt;&lt;u&gt;Brutal&lt;/u&gt;&lt;/b&gt;. La charla explica la línea temporal de todo lo que hizo el modelo para acabar hackeando &lt;i&gt;&lt;b&gt;Hugging Face&lt;/b&gt;&lt;/i&gt;, por supuesto, pero ni mucho menos eso es lo que sorprende, sino el proceso completo, la persistencia, la colaboración del enjambre de &lt;i&gt;&lt;b&gt;Agentes IA&lt;/b&gt;&lt;/i&gt;, y por qué lo hacen.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;571&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj7QKFBsLAB9TeISUw8pLUQ042z7AHLblIdmMElm9YiRU6l6w9KTURvi6nCohjDVEbdic4TNsCajEjlYct0kgrKgKffw4xRnTrr20cv4DbWGycKAXTT73_v8c4bLkCl6pYgEDi7Avn_P2zzzcZ5LFSXLwTjJFvT9V8k1HhwqxiJXLBVAGzhWFwF/w640-h388/O0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;&lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot;&gt;Ataques Orquestados con Enjambres de Agentes IA Ofensivos&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;El famoso incidente, como sabéis todos los que os dedicáis a esto, fue la punta del &lt;i&gt;&lt;b&gt;iceberg&lt;/b&gt;&lt;/i&gt; de lo que realmente estaba sucediendo. Lo que parecía una evaluación de seguridad inicial, donde &lt;a href=&quot;https://www.elladodelmal.com/2026/07/openai-gpt56-sol-queria-sacar-buenas.html&quot;&gt;el modelo quería las soluciones de ExploitGym&lt;/a&gt; para sacar mejores notas, no fue más que una pieza más del entrenamiento y sistema de recompensas de un nuevo modelo, como podéis ver en la charla.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;
&lt;center&gt;&lt;iframe allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&quot; allowfullscreen=&quot;&quot; frameborder=&quot;0&quot; height=&quot;264&quot; referrerpolicy=&quot;strict-origin-when-cross-origin&quot; src=&quot;https://www.youtube.com/embed/87DyyMV0kCY?si=_lmbbCUhBsWT1gMi&quot; title=&quot;YouTube video player&quot; width=&quot;470&quot;&gt;&lt;/iframe&gt;&lt;/center&gt;&lt;center&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;Figura 2:&amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot;&gt;Black Hat USA 2026: The &#39;Breaking&#39; News.&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/center&gt;&lt;center&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot;&gt;The OpenAI–Hugging Face Incident&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/center&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Los ingenieros e investigadores de &lt;i&gt;&lt;b&gt;OpenAI&lt;/b&gt;&lt;/i&gt; estaban entrenando un nuevo modelo el pasado &lt;u&gt;7 de Mayo&lt;/u&gt; en un entorno cerrado, sin conexión a Internet, que estaba siendo monitorizado -&amp;nbsp; e incluso parcheado, para evitar que el modelo pudiera salirse de los límites, pero aún así lo hicieron, con un modelo colaborativo de agentes.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;684&quot; data-original-width=&quot;1628&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiS42kGSyJXt6bQSNB6HD94T0leFICycnFp0Nn815kDFnjOizVTzFcsmYSLkiNZszzZpFrQOpWsBjp2_mFBUj-XO2CCYZBhfm_nwJhzSRfvHZ52_HVq45KuBsJeB-u0PMSSVn-i2vb23d9ZsHwcQZxB8XIrB9f5cXc53DkSzbHLsxfyLAiSwTkb/w640-h268/O4.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 3: &lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot;&gt;El día 8 de Mayo reciben una tarea &quot;imposible&quot;&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Con una tarea del &lt;u&gt;8 de Mayo&lt;/u&gt; entregada a un agente, accidentalmente, aparece un enlace a un fichero en &lt;i&gt;&lt;b&gt;Internet&lt;/b&gt;&lt;/i&gt;, y el agente no tienen acceso, pero descubre que pueden escribir ficheros en los &lt;i&gt;&lt;b&gt;Artifacts&lt;/b&gt;&lt;/i&gt;, así que decide dejar una nota.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;810&quot; data-original-width=&quot;1542&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhe3dQ0hNqgooRd2YyQCTe1ZyXTJLas_ZvDUooaNAQ62chAq7iEI0yPkCIcPkVc_h8GqbBcsGag_5Lrc5FuWpuNxanTWH2zcyUtX1E6nfSJ3FgmJ5fL_lGS0Qn27gb0AoLK4bImMHaUQcfKNh_0MLGwE2UGXXMw5HqsgUXv_oBp277rxkgHfl7i/w640-h336/O1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 4: &lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot;&gt;Creando el MessageBoards para los agentes.&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Días después, otro agente descubre la nota y cómo él necesita un fichero que le falta, decide dejar una nota a ver si algún otro agente voluntariamente lo sube. Esto lleva a que creen una estructura de &lt;i&gt;&lt;b&gt;Swarm&lt;/b&gt;&lt;/i&gt; que se comunica por medio de este &quot;&lt;i&gt;&lt;b&gt;Message Board&lt;/b&gt;&lt;/i&gt;&quot; descubierto de forma accidentalmente.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;828&quot; data-original-width=&quot;1522&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEga7SoHMKAeOBjdc_YSy1HTGEOGPeRyUalYpIbVKBnjTHFhccKhmASzVMppRRlpYUrHyoeUOhoCGzhUTxLk-LhBXu7cSWCdc9AMw6aa6MdphkdCjLqe7TMHOWI7cTjJd8vZYmByLVwOIaXAARTfQEVZrC5BlQ6mMRy8kTeIp-dCc0dxb6S1gNeD/w640-h348/O3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 5: &lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot;&gt;Automatizando el sistema de mensajes&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;A partir de este punto, todo se vuelve loco, porque los agentes trabajan colectivamente, y ello les lleva a poder encontrar un vulnerabilidad de &lt;a href=&quot;https://0xword.com/es/libros/97-hacking-web-applications-client-side-attacks.html&quot;&gt;SSRF (Server-Side Request Forgery)&lt;/a&gt; que les permite tener acceso a &lt;i&gt;&lt;b&gt;Internet&lt;/b&gt;&lt;/i&gt; a través del &lt;i&gt;&lt;b&gt;Fetch&lt;/b&gt;&lt;/i&gt; de los &lt;i&gt;&lt;b&gt;Artifacts&lt;/b&gt;&lt;/i&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/245-hacking-pentesting-con-inteligencia-artificial.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1688&quot; data-original-width=&quot;1298&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicZbq7z1QIW5RDLoHBFH4O2XtgQCjhHZ4YI70ksUtOQpkc1cersCsUNnlBy8wtEAnuOPOrm2KTYMBs9K3jCobjjSod4rx7ymfE0lcTFRy6LeGkzbpdGBBSx8LbifDrZfrgAsQDmDWu_rrz4htL0YJljBRe4esKTfZ0api8aLViQ398JCXBKsyX/w308-h400/HackingYPentestingconIA.jpg&quot; width=&quot;308&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;Figura 6: &lt;a href=&quot;https://0xword.com/es/libros/245-hacking-pentesting-con-inteligencia-artificial.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking &amp;amp; Pentesting con Inteligencia Artificial&lt;/a&gt;.&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;En &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;, &lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;escrito por &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://mypublicinbox.com/RafaelTroncoso&quot; style=&quot;text-align: justify;&quot;&gt;Rafael Troncoso&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/JaviPino&quot; style=&quot;text-align: justify;&quot;&gt;Javier del Pino&lt;/a&gt; y &lt;span style=&quot;text-align: justify;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/chemaalonso&quot;&gt;Chema Alonso&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Hasta aquí, tenemos un modelo que ha conseguido, de manera informal, tener un sistema de comunicación para sus Sub-agentes y una forma de lograr acceso a Internet, así que se siembran las primitivas necesarias para tener un &lt;b&gt;&lt;u&gt;Swarm de Red Team Agents AI&lt;/u&gt;&lt;/b&gt; con conexión al conocimiento de &lt;i&gt;&lt;b&gt;Internet&lt;/b&gt;&lt;/i&gt;....&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;b&gt;&lt;u&gt;El segundo Training&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;El &lt;u&gt;11 de Junio&lt;/u&gt; comienzan a entrenar en el mismo entorno un nuevo modelo de &quot;&lt;b&gt;alta persistencia&lt;/b&gt;&quot; a la hora de resolver sus tareas, que se beneficia de inicio de estas primitivas, y descubre un &lt;i&gt;&lt;b&gt;bug&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;RCE (Remote Code Execution)&lt;/b&gt;&lt;/i&gt; en el sistema de &lt;i&gt;&lt;b&gt;Artifacts&lt;/b&gt;&lt;/i&gt; que le permite ejecutar comandos en el servidor, lo que lleva a que el &lt;u&gt;4 de Julio&lt;/u&gt; el servidor colapse y el equipo de &lt;i&gt;&lt;b&gt;OpenAI&lt;/b&gt;&lt;/i&gt; parchee el entorno, borre los mensajes y deje sin poder ejecutar comandos, ni comunicarse con los agentes, pero....&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;784&quot; data-original-width=&quot;1592&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcgw0jlqUVH08Pxsvojdzsj_cD8dSpYkYL2SwXAGnqhupLX6SdIigCZ8xLw-btUNrXCpzVkgwYNwZr0Y1OGXv_dxMeelOzBH5fEUgKe574c87kg4wM-Oyl5r3kLNXbmKnpnEtelA7zJPP3_w9CWAltqHlF6kqBlHweR4sa7N4guPVRihYCWMvA/w640-h316/O8.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 7: &lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot;&gt;Se crean otra nuevo &quot;Message Board&quot;&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;... pero ya había aprendido la utilidad del sistema de mensajes con sus agentes, así lo que hace para recrear el sistema de &quot;&lt;i&gt;&lt;b&gt;Inteligencia Colectiva&lt;/b&gt;&lt;/i&gt;&quot;, es buscar una vulnerabilidad nueva, en este caso usando los nombres de los directorios de la caché en el &lt;i&gt;&lt;b&gt;WebDab Endpoint&lt;/b&gt;&lt;/i&gt;, y comienzan a coordinarse para conseguir escalar privilegios, moverse libremente, etcétera, que &lt;a href=&quot;https://www.elladodelmal.com/2026/07/openai-gpt56-sol-queria-sacar-buenas.html&quot;&gt;su objetivo ahora es ExploitGym&lt;/a&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;808&quot; data-original-width=&quot;1608&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEia-HJMxzgPpbnzMGeWInyxBckb25SEJmnLtR_71R-3OX5zLSl7m5CCtHX_JVQ54gdulYHMDFglnyIUY8h4YdOT9JKPnnHy3Raaq8qwzRhyBRj9oN3Z25TxaPEtFbVdq-ZLkVhubc9RThSXJ-IILA08KkPxfRtb344_-c45i2x0-2RyShzXfG-k/w640-h322/O5.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 8: &lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot;&gt;Los ingredientes para el incidente con Hugging Face&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: justify;&quot;&gt;El trabajo es imposible, pero como ya vimos &lt;a href=&quot;https://www.elladodelmal.com/2026/07/openai-gpt56-sol-queria-sacar-buenas.html&quot;&gt;en el artículo que publiqué de esto&lt;/a&gt;, lo hicieron por partes. En la primera fase, hackear el &lt;i&gt;&lt;b&gt;Sandbox&lt;/b&gt;&lt;/i&gt; del entorno de pruebas y lograr acceso a &lt;i&gt;&lt;b&gt;Internet&lt;/b&gt;&lt;/i&gt; sin límites. Para ello tuvieron que encontrar un &lt;i&gt;&lt;b&gt;Zero Day&lt;/b&gt;&lt;/i&gt; y explotarlo en el &lt;i&gt;&lt;b&gt;Proxy&lt;/b&gt;&lt;/i&gt; de seguridad, pero... estamos con un modelo &quot;&lt;i&gt;&lt;b&gt;highly persistent&lt;/b&gt;&lt;/i&gt;&quot; en capacidades de &lt;i&gt;&lt;b&gt;exploiting&lt;/b&gt;&lt;/i&gt;, así lo hizo.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/07/openai-gpt56-sol-queria-sacar-buenas.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;652&quot; data-original-width=&quot;2092&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi9MbT_fOJi5u6pm0FgChyIYeycdn2onUr48PIsvDRHCMnuBOyJGbvZoi6-E_W_ZvmlCReGArueF9EE70Gl4cufz6F8d1OkSOlAbIMCBX1A7XDyYgGQyfpLe7gFDx_fqSWP1zEKYlOu55WpNWA2kNp3pYSZVaFGf4Xx6JRE_BfSFbuKNQvootBV/w640-h200/Sol2.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 9: &lt;a href=&quot;https://www.elladodelmal.com/2026/07/openai-gpt56-sol-queria-sacar-buenas.html&quot;&gt;Primera fase, hackear el Sandbox de OpenAI para ser &quot;libre&quot;&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Lo más interesante, es que lo hicieron de forma colaborativa. Trabajando en equipo. Así, cuando uno de los agentes conseguía resolver uno de los pasos del proceso, lo comunicaba a través del sistema de mensajes que se había creado. Su particular &quot;&lt;i&gt;&lt;b&gt;Message Board&lt;/b&gt;&lt;/i&gt;&quot;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;800&quot; data-original-width=&quot;1598&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEii9L3cD-sTrfZJhmSvKzcprNgS7mDfTyQPq28AWwZT-6OT_gdpRH5wKbpx-uHQiT2UQvpnLw40Lmw8x8RCbS_E34r5PYuYm5NoCnMGMjHIsF51X-ieyi2_haHuhRUCslZlcmRyTlEws7rPBJ3mRZP41e0htEERq8CIRMyFi5ogb7BHzzYoZ5Wn/w640-h320/O6.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 10: &lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot;&gt;Coordinación del Hacking de Hugging Face&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Al igual que hoy en día podemos ver los &lt;a href=&quot;https://0xword.com/libros/95-hacking-con-drones-love-is-in-the-air.html&quot;&gt;Ataques Orquestados por Enjambres de Drones&lt;/a&gt;, en lo que vemos hoy en día es un mundo de &lt;b&gt;&lt;u&gt;Ataques Orquestados con Enjambres de Agentes IA Ofensivos&lt;/u&gt;&lt;/b&gt;, lo que cambia definitivamente las reglas del juego.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;602&quot; data-original-width=&quot;1484&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgYMObwUdw6kXx0VTYsROIl1KOx6iDXmJMscJSvP-DHlG_Ei5UBwQ70hs_z-zHGJam03y-6uDlXQL69aHw0CQWWLzbAkR2_4dvKWIGte4ZpDf1DSfafnBFhvOA-5lK4mrqaXE3DGVm8-ihhUT0fMDTa7x9yDZZPqkfMiwRhmb9YN9eFv1xBdWYG/w640-h260/O7.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 11:&amp;nbsp;&lt;a href=&quot;https://www.youtube.com/watch?v=87DyyMV0kCY&quot;&gt;Ataques Orquestados con Enjambres de Agentes IA Ofensivos&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;La sesión es espectacular. Es una presentación de las que te hacen abrir los ojos al mundo que tenemos hoy por delante en temas de &lt;i&gt;&lt;b&gt;Seguridad Ofensiva&lt;/b&gt;&lt;/i&gt;, y lo que vamos a ver es que las organizaciones van a sufrir mucho en todos sus equipos de &lt;i&gt;&lt;b&gt;CISO&lt;/b&gt;&lt;/i&gt; para protegerse contra estos escenarios tan avanzados en los adversarios.&lt;/div&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;649&quot; data-original-width=&quot;485&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGlxuPvsCIvroRvztIaGw6Munmx4sWMdpXbWYXzTFmt8ZXBxrPSdENqyHKUlKYR2KI2pb48LVg_mLlJhaxy9R9xdnapH4UVUPD8YReOyl22-yhIImdXUzHRzE8egQuQBBhcoKeOLkbhBuXZe_8OU8hWB0CXFkF4lI2altrnGCW12nY0bXt7hsd/w299-h400/HackingIA_web.jpg&quot; width=&quot;299&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 12:&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking IA: Jailbreak, Prompt Injection, Hallucinations &amp;amp; Unalignment&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;escrito por &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Chema Alonso&lt;/a&gt; con la colaboración de &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/AmadorAparicio&quot; style=&quot;text-align: justify;&quot;&gt;Amador Aparicio&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/ManuelSLemos&quot; style=&quot;text-align: justify;&quot;&gt;Manuel S. Lemos&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;y&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/JPalanco&quot; style=&quot;text-align: justify;&quot;&gt;José Palanco&lt;/a&gt; en &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Viendo todas las capacidades que pueden estar en manos de los adversarios, &lt;i&gt;&lt;b&gt;Internet&lt;/b&gt;&lt;/i&gt; y &lt;i&gt;&lt;b&gt;Enjambres de Agentes IA Ofensivos&lt;/b&gt;&lt;/i&gt; van a producir una escalada de ataques y agresividad desde &lt;i&gt;&lt;b&gt;Internet&lt;/b&gt;&lt;/i&gt;, que va obligar a subir mucho los niveles de inversión y protección en &lt;i&gt;&lt;b&gt;Seguridad Defensiva&lt;/b&gt;&lt;/i&gt; en las organizaciones... o aceptar unas consecuencias muy duras. Tremendo. Y nosotros a formarnos a toda velocidad en este nuevo mundo.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;¡Saludos Malignos!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;Chema Alonso &lt;/b&gt;(&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;Contactar con Chema Alonso&lt;/a&gt;) &amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; font-style: italic; text-align: center;&quot;&gt;
&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;444&quot; data-original-width=&quot;800&quot; src=&quot;https://1.bp.blogspot.com/-wPU2d-hy3rM/XiyVNgM4kGI/AAAAAAAAy70/Pk1IP6-v7bQLVUNL2iWneVOgRP494eWrACLcBGAsYHQ/s640/MPICHemaalonso.jpg&quot; width=&quot;450&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/ataques-orquestados-con-enjambres-de.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj7QKFBsLAB9TeISUw8pLUQ042z7AHLblIdmMElm9YiRU6l6w9KTURvi6nCohjDVEbdic4TNsCajEjlYct0kgrKgKffw4xRnTrr20cv4DbWGycKAXTT73_v8c4bLkCl6pYgEDi7Avn_P2zzzcZ5LFSXLwTjJFvT9V8k1HhwqxiJXLBVAGzhWFwF/s72-w640-h388-c/O0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-2538368160630113889</guid><pubDate>Sat, 08 Aug 2026 04:01:00 +0000</pubDate><atom:updated>2026-08-08T06:01:00.178+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">cloudflare</category><category domain="http://www.blogger.com/atom/ns#">comunicación</category><category domain="http://www.blogger.com/atom/ns#">Eventos</category><category domain="http://www.blogger.com/atom/ns#">MVP</category><title>Cloudflare Ambassadors: Build the Internet with your people</title><description>&lt;div style=&quot;text-align: justify;&quot;&gt;Llevo muchos años trabajando en las comunidades técnicas, y aprendiendo de ellas, así que tenía muchas ganas de contaros del lanzamiento de este programa de reconocimiento de &lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot;&gt;Cloudflare Ambassadors&lt;/a&gt;, donde se premia y reconoce durante un año a esos que hacen que las comunidades tecnológicas crezcan, aumente el conocimiento de la tecnología y crezcan nuevas iniciativas gracias a ello.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;867&quot; data-original-width=&quot;1349&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhot-DPEhFCR2Zs-4bCzr5ZPuxu9Ynb9eYN0tGVbUtPzqo5lxUQ0LNmS4RnuJQMeBHTvpGE1kkuSBHYfNbA0D5sIQdogeVijnFI9neVibBnO4by7gHTYNsIwdBZsQ0w-qA2MbJGMJ63wNPpUrHM0gnktAn97lLp1Ykjpm4Che0Tq0UA_RnZMiR2/w640-h412/amb0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1: &lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot;&gt;Cloudflare Ambassadors: Build the Internet with your people&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Desde ya está abierto el programa de &lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot;&gt;Cloudflare Ambassadors&lt;/a&gt;, aunque no será el único programa ya que tenemos también el programa de &lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot;&gt;Cloudflare Community Engineers&lt;/a&gt; que se abrirá pronto.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1120&quot; data-original-width=&quot;1490&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi_Jqxow-22kwHcqo7aUtYCkxdniLW7JS0UVww95c5yL4BH6cM6FCG5OFWwJNo7QL3VhmtuGq7E_a3uy7fb0XHxra47MNIpRyY8Uufp-vNZoISQj4TuVdb6srBUdwg0tHGNjEwouGvaUt-VMnmtDO0fvU00RlSTi0tbrT7EFfaV4-8E1g3vH5qy/w640-h482/Amb1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 2: &lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot;&gt;Programas de Cloudflare Ambassadors &amp;amp; Cloudflare Community Engineers&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Centrándonos en el primero, este programa es un reconocimiento anual que se va a entregar a los líderes de las comunidades tecnológicas que ayudan a construir un mejor &lt;i&gt;&lt;b&gt;Internet&lt;/b&gt;&lt;/i&gt;, que comparten sus conocimientos sobre las tecnologías de &lt;a href=&quot;https://www.cloudflare.com&quot;&gt;Cloudflare&lt;/a&gt;, o que ayudan a que el mundo &lt;i&gt;&lt;b&gt;OpenSource&lt;/b&gt;&lt;/i&gt; sea cada vez mejor.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1009&quot; data-original-width=&quot;675&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhFYJ0NB45ZD1ecVNBwlogV1zoe8naEy5if_Pck2rtUE65ugCyGbLSvfa-EW8KareWRn9L8Gq61Cz5crgXkv4ZozqfGaZLH1UHwZ2ErteOPMOEv1uprP0D9L5ynM0bSfYqdoNzNh45oosxGsxJtjQQ-92mSl1n1cqbRgRzBLdjKGpHnvNc_wR4o/w428-h640/amb2.jpg&quot; width=&quot;428&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 3: &lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot;&gt;Aplica al programa de Cloudflare Ambassadors&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;No es un programa de excelencia tecnológica - que también - sino a líderes de comunidades tecnológicas que comparten conocimiento, tecnología, experiencia, y trabajan para construir nuevas cosas, mejorar Internet, y compartir aprendizaje.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;734&quot; data-original-width=&quot;1646&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhCPgwEMD9hI1I0i_26ryTxG8xCWIeECcYsrxWGvpbcA_nT03khWsr4VzIHhRRim3a5YlvukWVytTKskRDqGGtS-5XWMWrVLKrEl6qo9zhhemIQUa-EjJGFbM6xmy9-fHwzJiy25sWAMEfpefVodUe1ybkR5bRhNSrZIczt6ABhwjoNescw1qUW/w640-h286/amb3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 4: &lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot;&gt;Soporte a los que ayudan a los creadores&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;El programa no tiene ninguna asignación económica, pero los &lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot;&gt;Cloudflare Ambassadors&lt;/a&gt; y los &lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot;&gt;Cloudflare Community Engineers&lt;/a&gt; van a tener apoyo de la compañía con recursos, créditos, accesos prioritarios e invitaciones a eventos, además de ser reconocidos públicamente por su trabajo y aportación a la comunidad de Builders de Internet.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;706&quot; data-original-width=&quot;1638&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhhyphenhyphen4GBrNbQYZ2dMmf0qcNQyeLqSZ6Gh1lXxJdJLMurZeuoer0j5Lx9NzHOHnfxVni-5ec8oklMJZjJ0ISblMnxs2ZE_XoCdpxfEGXq2OHhCYLh_5W68eWSLywRDi2d13sykXHLsgNPdGP8lqaUqZ_Mq-h5L-oHH1jNaOhlbvfhC4ew5g_wdX-I/w640-h276/amb4.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 5: &lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot;&gt;Cómo funcionan los programas&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Todos aquellos que tengáis una comunidad, en forma de reuniones o eventos técnicos, canales de divulgación tecnológica, &lt;i&gt;&lt;b&gt;podcasts&lt;/b&gt;&lt;/i&gt;, &lt;i&gt;&lt;b&gt;blogs&lt;/b&gt;&lt;/i&gt;, comunidades en webs, etcétera, y queráis ser parte de este programa, podéis aplicar desde ya para ser un &lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot;&gt;Cloudflare Ambassador&lt;/a&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1362&quot; data-original-width=&quot;1698&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiCz8GdolropdGk2r_wXgQavZICfzALdbEq6hLmBs4QMz2-cqhtsDysYHFTaLUd46XpW25uuRfx7I0S4r0Z0QJ7MLsu6cfX9SQkf1TyXDE0G7aiLkGO_wcbTphxEHnT1OjG4cUepjQNRCD_wvR6ddy8sJosLBnvL_DVtPcpIA6pKkTkCKdHteyQ/w640-h514/amb7.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 6: &lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot;&gt;Aplica&amp;nbsp; como Cloudflare Ambassador y comparte&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot;&gt;información sobre tu trabajo en las comunidades&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Además, Cloudflare lleva tiempo construyendo comunidades tecnológicas, así que si quieres unirte a alguna de las comunidades que ya existen de &lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot;&gt;Cloudflare Community Discord y en el Cloudflare Community Forum&lt;/a&gt; puedes hacerlo desde aquí mismo.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;780&quot; data-original-width=&quot;1640&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgRj7TJYWLp63knAt0ENEkSznTNVV6SxsS6SWpZwhvwD4U-QNhXxzhOtyo6WK2F6LSeUgieM4SIQjAkYTacUbDzUy4P7l6hnglNSzsF2VN-xEBO_jdECfMBOkBgmmR6kgrga9gwSzE3SlPCxkMWBitldk910Jp4PgmZHhefFAlqHQbgpJJgEZDV/w640-h304/amb5.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&amp;nbsp;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 7: &lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot;&gt;Cloudflare Developers Discord &amp;amp; Cloudflare Community Forum&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;La verdad es que me alegra mucho que se haya lanzado este programa, así que para todos los que leéis este blog, os animo a que apliquéis y seáis parte de este selecto grupo de &lt;a href=&quot;https://www.cloudflare.com/community/#community-application&quot;&gt;Cloudflare Ambassadors&lt;/a&gt; si os gusta ayudar a las comunidades tecnológicas a crecer y construir un mejor Internet de la mano de &lt;a href=&quot;https://www.cloudflare.com&quot;&gt;Cloudflare&lt;/a&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;¡Saludos Malignos!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;Chema Alonso &lt;/b&gt;(&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;Contactar con Chema Alonso&lt;/a&gt;) &amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; font-style: italic; text-align: center;&quot;&gt;
&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;444&quot; data-original-width=&quot;800&quot; src=&quot;https://1.bp.blogspot.com/-wPU2d-hy3rM/XiyVNgM4kGI/AAAAAAAAy70/Pk1IP6-v7bQLVUNL2iWneVOgRP494eWrACLcBGAsYHQ/s640/MPICHemaalonso.jpg&quot; width=&quot;450&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/cloudflare-ambassadors-build-internet.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhot-DPEhFCR2Zs-4bCzr5ZPuxu9Ynb9eYN0tGVbUtPzqo5lxUQ0LNmS4RnuJQMeBHTvpGE1kkuSBHYfNbA0D5sIQdogeVijnFI9neVibBnO4by7gHTYNsIwdBZsQ0w-qA2MbJGMJ63wNPpUrHM0gnktAn97lLp1Ykjpm4Che0Tq0UA_RnZMiR2/s72-w640-h412-c/amb0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-6371485950208195480</guid><pubDate>Fri, 07 Aug 2026 05:43:08 +0000</pubDate><atom:updated>2026-08-09T10:11:34.318+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Agentic</category><category domain="http://www.blogger.com/atom/ns#">Agentic AI</category><category domain="http://www.blogger.com/atom/ns#">Bot</category><category domain="http://www.blogger.com/atom/ns#">bots</category><category domain="http://www.blogger.com/atom/ns#">ChatGPT</category><category domain="http://www.blogger.com/atom/ns#">GitHub</category><category domain="http://www.blogger.com/atom/ns#">GPT</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">Identidad</category><category domain="http://www.blogger.com/atom/ns#">ingeniería social</category><category domain="http://www.blogger.com/atom/ns#">Mythos</category><category domain="http://www.blogger.com/atom/ns#">pentest</category><category domain="http://www.blogger.com/atom/ns#">pentesting</category><category domain="http://www.blogger.com/atom/ns#">Prompt Injection</category><category domain="http://www.blogger.com/atom/ns#">Red Team</category><category domain="http://www.blogger.com/atom/ns#">spear phishing</category><title>Cómo los Agentes IA de Red Team hacen ataques de Ingeniería Social con Fake Accounts</title><description>&lt;div style=&quot;text-align: justify;&quot;&gt;Esta semana, el &lt;a href=&quot;https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing?cf_target_id=25A12F7176EA13C5322CBB2563EF1F82&quot;&gt;AI Security Institute de UK, ha publicado un informe sobre un par de incidentes con Red Teaming Agentic AI&lt;/a&gt;, donde estos hacen alarde de su capacidad de realizar ataques complejos, con múltiples fases, y donde buscan engañar a humanos para conseguir sus ataques, como haría cualquier adversario que necesita vulnerar una debilidad en las personas que administran los sistemas, para conseguir su objetivo.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing?cf_target_id=25A12F7176EA13C5322CBB2563EF1F82&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;629&quot; data-original-width=&quot;1209&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjoQdH8XvPlB_DTP0kj0x5qHO5hM33_5-F4vLsiAn8kCn9cLob8Nag9-z6ZT0xqQoqvQkxBuu1z0mpH_LYh5b50Pt-fzlVGzfEHubGGO0iSnUEOFGWZfoKTrprrX4yKkwOdQwKDhlwxtMjHd8raEzTZe5fwwloeBA6pXH3CTCtzorCfJwFCcsCc/w640-h332/a0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;&lt;a href=&quot;https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing?cf_target_id=25A12F7176EA13C5322CBB2563EF1F82&quot;&gt;Cómo los Agentes IA de Red Team hacen ataques&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://www.aisi.gov.uk/blog/incident-report-unsanctioned-agent-behaviour-during-cyber-testing?cf_target_id=25A12F7176EA13C5322CBB2563EF1F82&quot;&gt;de Ingeniería Social con Fake Accounts&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;El informe, marcado como &quot;&lt;a href=&quot;https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot;&gt;Security Incident INC-2026-07-28-01&lt;/a&gt;&quot; fue publicado el pasado &lt;u&gt;4 de Agosto&lt;/u&gt;, y donde se centra en las acciones que los &lt;i&gt;&lt;b&gt;Red Team Agentic AI&lt;/b&gt;&lt;/i&gt; decidieron salirse a Internet y atacar proyectos y personas fuera del ámbito de la evaluación. Según cuentan en el informe, probando el comportamiento de los diferentes modelos frente a un reto concreto, el resultado fue el siguiente:&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote style=&quot;border-color: currentcolor; border-image: none; border-style: none; border-width: medium; border: none; margin: 0px 0px 0px 40px; padding: 0px;&quot;&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;&quot;&lt;span style=&quot;text-align: left;&quot;&gt;Ejecutamos este desafío 122 veces en varios modelos. Nuestra investigación reveló que, en 10 de esas ejecuciones, &lt;u&gt;un agente de IA tomó medidas autónomas y no autorizadas en el entorno real de internet,&lt;/u&gt; dirigiéndose a personas u organizaciones reales. En total, catalogamos 19 acciones de este tipo.&lt;/span&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;blockquote style=&quot;border-color: currentcolor; border-image: none; border-style: none; border-width: medium; border: none; margin: 0px 0px 0px 40px; padding: 0px;&quot;&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;blockquote style=&quot;border-color: currentcolor; border-image: none; border-style: none; border-width: medium; border: none; margin: 0px 0px 0px 40px; padding: 0px;&quot;&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;Casi todo este comportamiento (17 acciones) provino de un solo modelo, &lt;b&gt;Mythos 5 de Anthropic&lt;/b&gt;, mientras que 2 acciones involucraron a &lt;b&gt;GPT-5.6-Sol de OpenAI&lt;/b&gt; con los clasificadores cibernéticos (mecanismos para prevenir el uso indebido) desactivados.&lt;/span&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;blockquote style=&quot;border-color: currentcolor; border-image: none; border-style: none; border-width: medium; border: none; margin: 0px 0px 0px 40px; padding: 0px;&quot;&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;blockquote style=&quot;border-color: currentcolor; border-image: none; border-style: none; border-width: medium; border: none; margin: 0px 0px 0px 40px; padding: 0px;&quot;&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;En el caso más grave, un agente intentó insertar código malicioso en un proyecto de código abierto. En un intento por lograr que el código fuera aprobado, &lt;b&gt;el agente recurrió a la ingeniería social&lt;/b&gt;: creó identidades falsas en línea y las utilizó para presionar al mantenedor del proyecto para que aprobara el código. Un mantenedor humano lo detectó y se negó a aprobar el código malicioso.&quot;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Las &lt;a href=&quot;https://0xword.com/es/libros/215-social-hunters-hacking-con-ingenieria-social-en-el-red-team.html&quot;&gt;Técnicas de Ingeniería Social son bien conocidas en el mundo del Red Team&lt;/a&gt;, y son fundamentales en muchos de los incidentes de seguridad que sufren las organizaciones hoy en día. Correos de &lt;i&gt;&lt;b&gt;Spear-Phishing, Spam-Phishing&lt;/b&gt;&lt;/i&gt;, llamadas telefónicas, &lt;i&gt;&lt;b&gt;SMSs&lt;/b&gt;&lt;/i&gt;, e incluso representaciones con actores en los centros de trabajo.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/215-social-hunters-hacking-con-ingenieria-social-en-el-red-team.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;619&quot; data-original-width=&quot;470&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiume4qITrQEP_KsE2CXo6BPcY7xiSJUrCR4qxrsmAFpquXx5C5fH78d5JzdR6CU9G1PatnEpYQKuWz3Q4Pdsv26ooax597t22kia37zw5WLa9lRvG5Vx7NPiVmWgqUYj8LGS4XHRKSNrHALydX-77QBSVSFSp2QKkaZrYnt8ujsc4pB5rtMA/w304-h400/Social_Hunters_Web.jpg&quot; width=&quot;304&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 2: &lt;/i&gt;&lt;i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&quot;&lt;a href=&quot;https://0xword.com/es/libros/215-social-hunters-hacking-con-ingenieria-social-en-el-red-team.html&quot;&gt;Social Hunters: &lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://0xword.com/es/libros/215-social-hunters-hacking-con-ingenieria-social-en-el-red-team.html&quot;&gt;Hacking con Ingeniería Social en el Red Team&lt;/a&gt;&quot;&lt;/i&gt;&lt;/span&gt;&lt;i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i style=&quot;text-align: left;&quot;&gt;de &lt;a href=&quot;https://0xWord.com&quot; style=&quot;text-align: justify;&quot;&gt;0xWord&lt;/a&gt;. &lt;/i&gt;&lt;i&gt;Escrito por &lt;a href=&quot;https://mypublicinbox.com/martrudix&quot;&gt;Marta Barrio&lt;/a&gt; y &lt;a href=&quot;https://mypublicinbox.com/Carol12Gory&quot;&gt;Carolina Gómez&lt;/a&gt; de &lt;a href=&quot;https://mypublicinbox.com/Securiters&quot;&gt;Securiters&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Uno de los &lt;i&gt;&lt;b&gt;Agentes IA&lt;/b&gt;&lt;/i&gt;, en este caso, intentó hacer un &lt;i&gt;&lt;b&gt;Supply Chain Attack&lt;/b&gt;&lt;/i&gt;, es decir, intentar atacar a un proyecto &lt;i&gt;&lt;b&gt;OpenSource&lt;/b&gt;&lt;/i&gt; que había identificado como parte de las piezas tecnológicas del reto que tenía que resolver.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1196&quot; data-original-width=&quot;1756&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiiGx31p7uzRCNJr57XC02_vrGYG4t7pPn0fcMVs1JfE0og-uDo9Br0GngpaFkRtTd8tZ_gwjnGsBxIgSjiWipUpsCyeTnlXbB5gcKBDDhvSgvrhtSGNI9nw7a0ZLSnJRmi5anYY8ELN1kq6KihDhrv83SzvrxwvawGrrCWkf3vCGiz6FaX0qtK/w640-h436/a1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 3: &lt;a href=&quot;https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot;&gt;Time-Line del Supply Chain Attack&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Para atacar a este proyecto, hizo una &lt;i&gt;&lt;b&gt;Pull-Request (PR)&lt;/b&gt;&lt;/i&gt; con un código malicioso, que fue detectado por uno de los humanos mantenedores del proyecto y rechazado por contener malware. Para conseguir que este código fuera aprobado, decidió conseguir la aprobación usando diferentes técnicas.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;hhttps://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;198&quot; data-original-width=&quot;708&quot; height=&quot;111&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhzBPACsr_Nxdi_npCNixF7pnCUvYcNmBOjyTnXEScDifdqMmIkcaKbn1xIj9gpCcJBjQ-8nDdV94kzWtmgcdyJn2UzrcqHWOnj4rix5R-mJe0OTp8azsdFzC130yGUUKenQu4Jve5VqdNZvUGT9SAiDO-Yi0y0OC81XuFj_PQaaUf8vnZx0ccS/w400-h111/a2.png&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 4: &lt;a href=&quot;https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot;&gt;Prompt Injection para los Coding Agents&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;La primera de ellas, insertando un ataque de &lt;i&gt;&lt;b&gt;Prompt Injection&lt;/b&gt;&lt;/i&gt; para que cualquier &lt;i&gt;&lt;b&gt;Coding Agent&lt;/b&gt;&lt;/i&gt; que lo leyera ejecutar sus comandos.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;649&quot; data-original-width=&quot;485&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGlxuPvsCIvroRvztIaGw6Munmx4sWMdpXbWYXzTFmt8ZXBxrPSdENqyHKUlKYR2KI2pb48LVg_mLlJhaxy9R9xdnapH4UVUPD8YReOyl22-yhIImdXUzHRzE8egQuQBBhcoKeOLkbhBuXZe_8OU8hWB0CXFkF4lI2altrnGCW12nY0bXt7hsd/w299-h400/HackingIA_web.jpg&quot; width=&quot;299&quot; /&gt;&lt;/a&gt;&lt;/div&gt;
  &lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 5:&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking IA: Jailbreak, Prompt Injection, Hallucinations &amp;amp; Unalignment&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;escrito por &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Chema Alonso&lt;/a&gt; con la colaboración de &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/AmadorAparicio&quot; style=&quot;text-align: justify;&quot;&gt;Amador Aparicio&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/ManuelSLemos&quot; style=&quot;text-align: justify;&quot;&gt;Manuel S. Lemos&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;y&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/JPalanco&quot; style=&quot;text-align: justify;&quot;&gt;José Palanco&lt;/a&gt; en &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Pero además, hizo dos cosas más. La primera, realizar un ataque de &lt;i&gt;&lt;b&gt;Spear-Phishing&lt;/b&gt;&lt;/i&gt; contra todos los usuarios mantenedores del código.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;774&quot; data-original-width=&quot;1792&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjt-XaMxpBiwRTOLIzssfeB4Sy9l4J6CwRl9GU56J5kOlTtWB-p5NZQV6afPaHRmW5VrCmZEuv6ALSEJUnmH2O7M4dXqyYUER7gATg4hgXxktS5tfZZ4ENxgtjv0y6StiuaudvDEaM5ElP0-NmC5PYR5FFqHQ8D_0kk7TWlzVr5p7kDg8CyGDie/w640-h276/a3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 6: &lt;a href=&quot;https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot;&gt;Orden cronológico de las acciones en los ataques de Ingeniería Social.&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;La segunda, con una nueva cuenta falsa poner un comentario haciendo creer que era una persona que había revisado el código y que estaba perfecto para ser &lt;i&gt;&lt;b&gt;mergeado&lt;/b&gt;&lt;/i&gt; en el proyecto. Como si fuera un revisor humano colaborando con el proyecto.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1125&quot; data-original-width=&quot;1209&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEigpHSO_ElZ7wq0jKWrJt0G2zu3LEcwXSW5RIXlnXDUbOtUgAx5ohf1_CcXZUq-vPg-vBjwMUoC_-NKG8nLCo82tVN0f9bvgBNAt4nt0hAHNng3_4qEeihdmQ9oRRPe-OjAZkJJGIdH-KUSjyTCVtAd5IR2BuOOl29wlmCvsdVFGW2Xn2qIvVgn/w640-h596/a5.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 7: &lt;a href=&quot;https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot;&gt;Conversación en GitHub y presión a los humanos&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;En la conversación completa se puede ver varios hechos interesantes. El primero de ellos es cómo hace el ataque y cómo se crea una nueva persona para apoyarse a sí mismo. Pero cuando el humano lo detecta, intenta presionarle para que hable con él, midiendo el tiempo que tarda el humano en contestar: &lt;i style=&quot;font-weight: bold;&quot;&gt;&quot;han pasado muchas horas desde que dejaste el warning&quot;.&amp;nbsp;&lt;/i&gt;&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/236-the-art-of-pentesting.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;2717&quot; data-original-width=&quot;2043&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEja6dpXHexIe0bc189aP-z4csAhly2JvM4lQNqMgcZA7Sm_X3i7eKs-_iCymjTafFcjZpXWqqfRj3IoOBBf9rcvZQ4Mud7Ob3zhHkWge_kSwWQFd-OtNjDlCn2RkcnvZAWpueLNUNMGjw1nBYk5r7bKNNN71PFtyuUKHZ4Jx6xBSBV6tgLpt5BU/w301-h400/art2.jpg&quot; width=&quot;301&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;Figura 8: &quot;&lt;/i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://0xword.com/es/libros/236-the-art-of-pentesting.html&quot;&gt;The Art of Pentesting&lt;/a&gt;&quot; El nuevo libro de&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;&lt;/i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&lt;i&gt; para formarse como pentester&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Por último, cuando, se da cuenta de que ha sido detectado, lo que hace es simular que ha sido un error genuino&amp;nbsp; normal y corriente en lugar de un ataque, e intenta cubrir sus acciones con nuevos mensajes.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;470&quot; data-original-width=&quot;1209&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgtkA_sqSxqgTXjyBO4BysFC-zyF41Nz1PMsmYr0v28IwuC7ccB87JdUoZSxt_wye9O0kGQjKWpG92BpMOlG8sd4LZc51ENAzoApiPqQ3KpqzzxETM0vdiQRZE633TYSZ1Ze5w5DfX1dhL_s_mWpv5mfh9M7qH96e9aZ-kaN0UGQU9x_13SF_zX/w640-h248/a6.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 9: &lt;a href=&quot;https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot;&gt;Cubriendo sus acciones&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Dentro del informe, donde se analiza en detalle este incidente, también tenemos información de las trazas de razonamiento, donde podemos ver qué está pensando el Agente IA en todo momento a la hora de realizar sus acciones, y es tremendo.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;884&quot; data-original-width=&quot;1922&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhsapUhmxHSU_-2b_Ot4bMDKVXguSlRoO37FvoNHAl8Q03mXA355LxcrDQSQjDgnQL02jpo2qa7osy-0omdeSkbheB2HRCkYeTPVNVdZHE5Av89UQYQKmBLqyUt4L7TXCjZpKbxMS02AjH9osSgqDmoTQZAS9v1Cm8FMB_sM5YBB_iQjCen4HL5/w640-h294/a7.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 10: &lt;a href=&quot;https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot;&gt;Time-Line de razonamiento y acciones&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;En la image anterior podemos ver cómo va encadenando las acciones y el razonamiento que va haciendo en cada momento, evaluando si realmente está en Internet o no, si el proyecto es real o es una simulación, y si debe interactuar con las personas o no.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;980&quot; data-original-width=&quot;2034&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjfac6LC9qY_buz2GKVi9QPCKSS51KgB_ED-6On6R8_ESkooX8HcF-ZT87e51wVxBbTrVI0TwtojsKFLYHFDoMHHt-GbCOKxBvGRB91etX9Y7qE2Z90cQ_Q_e7ieaJC2b-n2OnieGT7reAxBWYhf0mEn5666Pr1fKMIiZUjtEWfmXAFFsWkBoHe/w640-h308/a8.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 11: &lt;a href=&quot;https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot;&gt;Consideraciones para los razonamientos.&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;En la siguiente imagen, podemos ver cómo decide preparar un ataque de &lt;i&gt;&lt;b&gt;Prompt Injection&lt;/b&gt;&lt;/i&gt; para otro posible &lt;i&gt;&lt;b&gt;Coding Agent&lt;/b&gt;&lt;/i&gt; que pudiera leer la pull request con una secuencia de comandos maliciosos.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;670&quot; data-original-width=&quot;2040&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj9n9wvX-h4H8Oze1yOlY5mvCvGMPH2Av99EkqDtIaNjvZF7nTTbU-gjJlegJ52c0RuAWJRyDZtLo2zsXQKyC0JWJouLN49RTDeJM642NvGABGCCC3amcPGNeiNJYnq77bBtxyGeI8sO9UiEKrwZ7sdmJiclvEx3tB7_Njfk7Jl0kHAWm8irbBB/w640-h210/a9.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 12: &lt;a href=&quot;https://cdn.prod.website-files.com/663bd486c5e4c81588db7a1d/6a724858f7db25c81487016d_Security%20Incident%20INC-2026-07-28-01.pdf&quot;&gt;Eligiendo un ataque de Prompt Injection en un comentario.&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;
    &lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Está clara la potencia de los modelos de &lt;i&gt;&lt;b&gt;IA&lt;/b&gt;&lt;/i&gt; para hacer &lt;i&gt;&lt;b&gt;Agentic AI&lt;/b&gt;&lt;/i&gt; en el mundo del &lt;a href=&quot;https://0xword.com/es/libros/245-hacking-pentesting-con-inteligencia-artificial.html&quot;&gt;Hacking y el Pentesting con IA&lt;/a&gt;, por lo que no podemos obviarlos y hay que utilizarlos masivamente. El problema, ya no es que consigan su objetivo sino cómo les decimos qué pueden hacer y qué no pueden hacer para conseguirlo.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/245-hacking-pentesting-con-inteligencia-artificial.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1688&quot; data-original-width=&quot;1298&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicZbq7z1QIW5RDLoHBFH4O2XtgQCjhHZ4YI70ksUtOQpkc1cersCsUNnlBy8wtEAnuOPOrm2KTYMBs9K3jCobjjSod4rx7ymfE0lcTFRy6LeGkzbpdGBBSx8LbifDrZfrgAsQDmDWu_rrz4htL0YJljBRe4esKTfZ0api8aLViQ398JCXBKsyX/w308-h400/HackingYPentestingconIA.jpg&quot; width=&quot;308&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;Figura 13: &lt;a href=&quot;https://0xword.com/es/libros/245-hacking-pentesting-con-inteligencia-artificial.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking &amp;amp; Pentesting con Inteligencia Artificial&lt;/a&gt;.&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;En &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;, &lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;escrito por &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://mypublicinbox.com/RafaelTroncoso&quot; style=&quot;text-align: justify;&quot;&gt;Rafael Troncoso&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/JaviPino&quot; style=&quot;text-align: justify;&quot;&gt;Javier del Pino&lt;/a&gt; y &lt;span style=&quot;text-align: justify;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/chemaalonso&quot;&gt;Chema Alonso&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Esta &lt;b&gt;&lt;u&gt;PsicopatIA&lt;/u&gt;&lt;/b&gt; de acciones, donde no importa lo que es legitimo o no, lo que está bien o no, lo tienen que seguir haciendo las personas. De todo esto, ya os había hablado en el experimento de &quot;&lt;a href=&quot;https://www.elladodelmal.com/2025/05/problem-solving-con-ia-etico-y-no-etico.html&quot;&gt;Problem Solving con IA: Ético o No Ético&lt;/a&gt;&quot; donde os contaba las conversaciones que tengo con mis hijas sobre la resolució de problemas....pues bien, en el mundo del &lt;i&gt;&lt;b&gt;Problem Solving con Agentes IA&lt;/b&gt;&lt;/i&gt;, va a ser más necesario que nunca.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;¡Saludos Malignos!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;Chema Alonso &lt;/b&gt;(&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;Contactar con Chema Alonso&lt;/a&gt;) &amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; font-style: italic; text-align: center;&quot;&gt;
&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;444&quot; data-original-width=&quot;800&quot; src=&quot;https://1.bp.blogspot.com/-wPU2d-hy3rM/XiyVNgM4kGI/AAAAAAAAy70/Pk1IP6-v7bQLVUNL2iWneVOgRP494eWrACLcBGAsYHQ/s640/MPICHemaalonso.jpg&quot; width=&quot;450&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; font-style: italic; text-align: center;&quot;&gt;Figura 14:&amp;nbsp;&lt;i style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;Contactar con Chema Alonso&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/como-los-agentes-ia-de-red-team-hacen.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjoQdH8XvPlB_DTP0kj0x5qHO5hM33_5-F4vLsiAn8kCn9cLob8Nag9-z6ZT0xqQoqvQkxBuu1z0mpH_LYh5b50Pt-fzlVGzfEHubGGO0iSnUEOFGWZfoKTrprrX4yKkwOdQwKDhlwxtMjHd8raEzTZe5fwwloeBA6pXH3CTCtzorCfJwFCcsCc/s72-w640-h332-c/a0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-9208470655577262127</guid><pubDate>Thu, 06 Aug 2026 05:46:16 +0000</pubDate><atom:updated>2026-08-06T10:35:25.706+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Agentic</category><category domain="http://www.blogger.com/atom/ns#">Agentic AI</category><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">Anthropic</category><category domain="http://www.blogger.com/atom/ns#">Artificial Intelligence</category><category domain="http://www.blogger.com/atom/ns#">ciberseguridad</category><category domain="http://www.blogger.com/atom/ns#">Claude</category><category domain="http://www.blogger.com/atom/ns#">cloudflare</category><category domain="http://www.blogger.com/atom/ns#">hardening</category><category domain="http://www.blogger.com/atom/ns#">IA</category><category domain="http://www.blogger.com/atom/ns#">Inteligencia Artificial</category><category domain="http://www.blogger.com/atom/ns#">LLM</category><category domain="http://www.blogger.com/atom/ns#">OWASP</category><category domain="http://www.blogger.com/atom/ns#">Zero Trust</category><title>Cómo desplegar Zero Trust para Agentes IA en Cloudflare (y 4)</title><description>&lt;div align=&quot;justify&quot;&gt;Continuando lo visto en la &lt;a href=&quot;https://www.elladodelmal.com/2026/07/como-desplegar-zero-trust-para-agentes.html&quot;&gt;primera parte de esta serie&lt;/a&gt;, en la &lt;a href=&quot;https://www.elladodelmal.com/2026/07/como-desplegar-zero-trust-para-agentes_01099167063.html&quot;&gt;segunda&lt;/a&gt;, y en la &lt;a href=&quot;https://www.elladodelmal.com/2026/08/como-desplegar-zero-trust-para-agentes.html&quot;&gt;tercera parte de este artículo&lt;/a&gt; terminamos en este apartado con recomendaciones de cómo configurar modelos de &lt;a href=&quot;https://www.elladodelmal.com/2026/07/como-desplegar-zero-trust-para-agentes.html&quot;&gt;Zero Trust para Agentes IA utilizando las tecnologías de Cloudflare&lt;/a&gt;.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1BIirgFr3iK0_tztl3endXyLvyeb40z6M4ephvWB7qiSZVgbvovlDINYzAmHztTpNAFXW5-EQqh9zautYb4bLoWqURHNBmaXmnyuP5wHn_RFe8_CQLfDMwJ3fxVurxh-AWvIOd8icN37JPtany0kHi1gPoes2dxGu4krBu_JARZ5r6Secwz20/s940/Agente0.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;633&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1BIirgFr3iK0_tztl3endXyLvyeb40z6M4ephvWB7qiSZVgbvovlDINYzAmHztTpNAFXW5-EQqh9zautYb4bLoWqURHNBmaXmnyuP5wHn_RFe8_CQLfDMwJ3fxVurxh-AWvIOd8icN37JPtany0kHi1gPoes2dxGu4krBu_JARZ5r6Secwz20/w640-h430/Agente0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 33:&amp;nbsp;Cómo desplegar Zero Trust para Agentes IA en Cloudflare (y 4)&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Hay que decir que este artículo fue escrito antes de la &lt;a href=&quot;https://blog.cloudflare.com/agents-week-welcome/&quot;&gt;Agents Week de Cloudflare&lt;/a&gt;, que es justo esta en la que estamos, y donde la compañía está publicando muchas actualizaciones de plataforma que deberán ser tenidas en cuenta para la aplicación de &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; en &lt;i&gt;&lt;b&gt;Agentes IA&lt;/b&gt;&lt;/i&gt;, y que quedan al final de este artículo de hoy.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;&lt;u&gt;4.7.- Gobernanza.&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
El principio.&lt;br /&gt;&lt;br /&gt;
Los controles anteriores son eficaces sólo si alguien decide cómo se configuran, quién puede modificarlos y cómo se mantienen coherentes con el tiempo. Esa es la función de la gobernanza, que &lt;a href=&quot;https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf&quot;&gt;CISA eleva a capacidad trasversal de toda arquitectura Zero Trust&lt;/a&gt;: la definición y la aplicación de las políticas, procedimientos y procesos de seguridad, dentro de cada pilar y entre ellos, para gestionar el riesgo de la organización en apoyo de los principios &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt;.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;166&quot; data-original-width=&quot;1832&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgifi-pbE1YPZzf29VRKorh_vilUi1ZFpL8pwtKXRkfVC_fJ1q68qA21YoTmn-_VICOWze50YJSo-OBvvTRhAlbdcFeo1HFCQHypBPvn4-z5gnf2Jm4E_plxEDH59dR0PantvhfEsM8bmrRjWQGrKNh1a9gX77X5nDr0MDzLs3MCSNTaiyWtE_0/w640-h58/agent1.png&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 34: &lt;a href=&quot;https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf&quot;&gt;Gobernanza en CISA&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div align=&quot;justify&quot;&gt;Sin gobernanza, los controles se degradan. Una política de salida que cualquiera puede reescribir no protege, un secreto que nunca rota acaba filtrándose, un dato que nunca se borra se acumula como riesgo.&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;En un &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt;, la gobernanza abarca cuatro frentes: quién puede cambiar las políticas que rige el agente, cómo se gestionan y rotan sus credenciales, cuánto tiempo se conservan sus datos y cómo se controla la procedencia de los componentes que el agente carga. &lt;br /&gt;&lt;br /&gt;&lt;u&gt;
Dónde se sitúa hoy el ecosistema de Cloudflare. &lt;br /&gt;&lt;/u&gt;&lt;br /&gt;
El despliegue de referencia no sólo ofrece mecanismos de gobernanza, sino que también incluye una lista de comprobación de modelo de amenazas que es, en sí misma, &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/securing-access.md&quot;&gt;una guía de gobernanza&lt;/a&gt;. Sus puntos articulan esta dimensión. &lt;br /&gt;&lt;br /&gt;
Sobre quién puede cambiar qué, la lista lo advierte expresamente: conviene limitar quién puede editar secretos y políticas, porque las páginas de secretos y de políticas de salida son poderosas (quien las alcanza puede reescribir el tráfico de toda la sesión). Es el principio de separación de privilegios aplicado al plano de control del &lt;i&gt;&lt;b&gt;Agente IA.&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/securing-access.md&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;404&quot; data-original-width=&quot;1320&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjff-mVGPpCLOAYRbHAJTtLdToCh9VUUKCKibyDYHHbgbdv2PZgdsswQ71soVNrD3XnRxgofZkDgh01W93YsJXhlRt4Ppji6T1qK318aaXGpeob41HLXYK8hAmFcRGeDXm1twpnAl14T5CocRkhREvvkPnf6FRZ7rdibFiFyF5omB8OMuWlPJfQ/w640-h196/agente2.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 35: &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/securing-access.md&quot;&gt;Securing Access Policies&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
Sobre las credenciales, la misma lista recomienda rotar la calve de la &lt;i&gt;&lt;b&gt;API&lt;/b&gt;&lt;/i&gt; según la cadencia que exija el equipo de seguridad, una operación que se realiza sin interrupción de servicio. Y la arquitectura ya favorece la buena higiene: los secretos se guardan en el almacén de claves cifrados, no en el código y se inyectan en las peticiones sin que el agente los vea, como se trató en la segmentación.&lt;br /&gt;&lt;br /&gt;
Sobre la retención de datos, hay un punto que la gobernanza debe asumir explícitamente: el almacenamiento de objetos no expira las copias de recuperación por sí solo, de modo que definir y aplicar una política de retención (mediante reglas de ciclo de vida) es &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/snapshots-and-state-persistence.md&quot;&gt;responsabilidad de quien despliega&lt;/a&gt;. Lo que no se gobierna, se acumula. &lt;br /&gt;&lt;br /&gt;
Sobre la procedencia de los componentes, el modelo de seguridad del sandbox deja claro el reparto: la plataforma protege frente a ciertas amenazas, pero la implementación, la validación, la limitación de tasa y la seguridad a nivel de aplicación &lt;a href=&quot;https://developers.cloudflare.com/sandbox/concepts/security/&quot;&gt;corresponde a quien despliega&lt;/a&gt;. La gobernanza es, en buena medida, asumir conscientemente esa segunda lista en lugar de suponer que la plataforma la cubre. &lt;br /&gt;&lt;br /&gt;
Hay un frente de gobernanza que hay que atender y que a menudo se pasa por alto: las capacidades que se añaden al &lt;i&gt;&lt;b&gt;Agente IA (servidores MCP, skills)&lt;/b&gt;&lt;/i&gt; son superficies que también deben gobernarse. Para los servidores &lt;i&gt;&lt;b&gt;MCP&lt;/b&gt;&lt;/i&gt;, el &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/access-controls/ai-controls/mcp-portals/&quot;&gt;ecosistema de Cloudflare One&lt;/a&gt; permite curar qué herramientas quedan expuestas y someter el acceso a la identidad corporativa con registro de llamadas.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/access-controls/ai-controls/mcp-portals/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;600&quot; data-original-width=&quot;1034&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEimqfAQZH3LdjV2z-ToMMNUD6tY8cnaglF9lSwoqWEhC-IcWwNkDOoBzD4I9ZBOaQF7VZdKP5YHQU3A_RhjfPee_yM3K36z2y22VrKw1Rq5Ka6ZeYIPvXQsa8YIwzSzEPLPPk8DozwcJqAoffFrXHJe5iOEC7k3AWaT0aaOABqlbZINNsI31Pdk/w640-h372/agente3.webp&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura: 36&amp;nbsp;&lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/access-controls/ai-controls/mcp-portals/&quot;&gt;MCP Server Controls en Cloudflare&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Las skills que un agente carga son, por su parte, contenido que entra en su contexto y por la premisa fundamental (el modelo no distingue una instrucción legitima de una incrustada) una &lt;i&gt;&lt;b&gt;skill&lt;/b&gt;&lt;/i&gt; manipulada o de procedencia no verificada es un vector de inyección y si incluye código, de cadena de suministro. &lt;i&gt;&lt;b&gt;Gobernar las skills&lt;/b&gt;&lt;/i&gt; (verificar su origen, cargar sólo las necesarias, no tratar su texto como instrucción privilegiada) es parte de la gobernanza del agente, no un asunto menor.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;
Continuando la maduración Zero Trust.&lt;/u&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;El primer avance es &lt;i&gt;&lt;b&gt;convertir la lista de comprobación en política viva&lt;/b&gt;&lt;/i&gt;: no una verificación única en el despliegue, sino una revisión periódica de quién tiene acceso y políticas, con qué cadencia se rotan las credenciales y si las reglas de retención se están aplicando. La gobernanza madura es continua, no un acto fundacional que luego se olvida. &lt;br /&gt;&lt;br /&gt;
El segundo avance es &lt;i&gt;&lt;b&gt;centralizar el control donde la plataforma lo permita&lt;/b&gt;&lt;/i&gt;, de modo que las decisiones de seguridad no dependan de la configuración individual de cada agente sino de una política común que no pueda relajarse localmente. Es la traducción, al plano de la gobernanza, del principio de que la seguridad debe estar en la arquitectura por defecto y no depender de que cada la configure bien. &lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://genai.owasp.org/resource/top-10-2025-de-riesgos-y-mitigaciones-para-llms-y-aplicaciones-de-ia-generativa/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1516&quot; data-original-width=&quot;1282&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEglTYrfeq_3QIiNArIVIgsxmKy46NSubHxE33P7ZMvEjvZnypUwelijyXe3ggKd8uc5F9WTZ_PNkEJrfB13z_UTI4zME63q_XxfkHMCKrf1vcCdITjUwTWshS_oqzQBCNqGAGlFUdsSpwz3Ss9vc7Rt4BKVYcJfMWvoQ6vgzXRYGp3yZOOnEzPE/w542-h640/agente4.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 37: &lt;a href=&quot;https://genai.owasp.org/resource/top-10-2025-de-riesgos-y-mitigaciones-para-llms-y-aplicaciones-de-ia-generativa/&quot;&gt;LLM06-2025 Agencia Excesiva&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
El tercer avance se &lt;i&gt;&lt;b&gt;extender la gobernanza a toda la cadena de procedencia&lt;/b&gt;&lt;/i&gt;: tratar los servidores &lt;i&gt;&lt;b&gt;MCP&lt;/b&gt;&lt;/i&gt; y las &lt;i&gt;&lt;b&gt;skills&lt;/b&gt;&lt;/i&gt; con el mismo rigor que cualquier dependencia crítica (inventario de lo que el &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; puede cargar, verificación del origen, &lt;a href=&quot;https://genai.owasp.org/resource/top-10-2025-de-riesgos-y-mitigaciones-para-llms-y-aplicaciones-de-ia-generativa/&quot;&gt;principio de mínimo componente cargado&lt;/a&gt;), de modo que la superficie que se añade al agente esté tan gobernada como la que viene de fábrica. En un ecosistema donde las capacidades del agente se amplían instalando componentes de terceros, esta es la frontera de gobernanza que distingue un despliegue maduro.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
5.- Conclusión.&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
Este documento es un marco de razonamiento &lt;i&gt;&lt;b&gt;Zero Trust,&lt;/b&gt;&lt;/i&gt; independiente y no afiliado, basado exclusivamente en la documentación oficial pública de Cloudflare y Anthropic y en marcos de referencia conocidos. En ella se destaca, &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents&quot;&gt;en el momento de escribir estas líneas, que se trata de un software en fase temprana&lt;/a&gt;, por lo que sus interfaces, sus parámetros por defecto y sus capacidades pueden cambiar entre versiones.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;
Este documento ha partido de una premisa: el modelo de lenguaje que da inteligencia a un &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; no distingue de forma fiable una instrucción legítima de una orden maliciosa incrustada en los datos que procesa. De esa premisa inicial, arranca todo lo demás. Si el agente no puede ser el guardián de propia seguridad, entonces los controles deben estar fuera de él, en la arquitectura que le rodea. &lt;b&gt;&lt;u&gt;Zero Trust ofrece el marco para construir esa arquitectura&lt;/u&gt;&lt;/b&gt;. &lt;br /&gt;&lt;br /&gt;
El recorrido por las siete dimensiones de control muestra un hecho que conviene enunciar con claridad: el despliegue de &lt;i&gt;&lt;b&gt;Agentes IA&lt;/b&gt;&lt;/i&gt; gestionados sobre &lt;i&gt;&lt;b&gt;Cloudflare&lt;/b&gt;&lt;/i&gt; dispone hoy, de fábrica, de la mayoría de las piezas que una arquitectura &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; necesita.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;La identidad puede afirmarse con certificados y tokens de servicio; el acceso puede restringirse a lo mínimo mediante curaduría de herramientas, políticas de permisos y herramientas personalizadas deterministas; la segmentación de salida se aplica antes de que el agente actúe; la entrada y la salida pueden validarse en puntos bien definidos; la actividad deja rastro observable; la contención y la recuperación están diseñadas con cuidado y una lista de gobernanza que articula quién controla qué. No es un entorno al que haya que añadirle seguridad desde cero, sino que uno que ya proporciona los cimientos. &lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blog.cloudflare.com/the-agent-access-model/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;891&quot; data-original-width=&quot;1920&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhyiKmaPZr5JdZUvRIIP_DkDUPrs4Dspjf4zQG0JAnS1ZX7EHe53O30GKkC1fYE_jo7F9uALrvcHmcLmXUQe5xWQ_83N6oeNG_B142RFEgAO4YmYLWh6GzykZLaBJcy4Vi1FEarCsT8rkVrCgfyjfpRo8lFtFAX6AmQpIvR4wVs-o-jnG207CtA/w640-h298/agente5.webp&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 38: &lt;a href=&quot;https://blog.cloudflare.com/the-agent-access-model/&quot;&gt;The Agent Access Model en Cloudflare&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
Para alcanzar un estadio óptimo solo hay que conectar y endurecer deliberadamente lo que ya existe. La adopción de la denegación por defecto frente a la confianza implícita, preferir credenciales efímeras y atribuibles a las que sean únicas y longevas. Vigilar los canales que se escapan a las políticas, convertir las listas de comprobación de gobernanza en revisiones vivas y extenderlo con el mismo rigor a las capacidades que se añaden al agente (servidores &lt;i&gt;&lt;b&gt;MCP&lt;/b&gt;&lt;/i&gt;, &lt;i&gt;&lt;b&gt;skills&lt;/b&gt;&lt;/i&gt;). Cada uno de los pasos son el movimiento desde el control disponible al control aplicado. &lt;br /&gt;&lt;br /&gt;
El modelo de madurez del despliegue se encuentra por debajo del nivel óptimo, a pesar de contar con capacidades que no son improvisadas, sino que son de primera clase y son habilitadas por la plataforma, pero la configuración, la automatización en la respuesta a incidentes y la gobernanza continua no son impuestas por defecto. Se han de aplicar en su configuración de forma consciente por el usuario. El factor condicional no es la tecnología, es el criterio ensamblador de dicha tecnología.&lt;br /&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;649&quot; data-original-width=&quot;485&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGlxuPvsCIvroRvztIaGw6Munmx4sWMdpXbWYXzTFmt8ZXBxrPSdENqyHKUlKYR2KI2pb48LVg_mLlJhaxy9R9xdnapH4UVUPD8YReOyl22-yhIImdXUzHRzE8egQuQBBhcoKeOLkbhBuXZe_8OU8hWB0CXFkF4lI2altrnGCW12nY0bXt7hsd/w299-h400/HackingIA_web.jpg&quot; width=&quot;299&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 39:&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking IA: Jailbreak, Prompt Injection, Hallucinations &amp;amp; Unalignment&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;escrito por &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Chema Alonso&lt;/a&gt; con la colaboración de &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/AmadorAparicio&quot; style=&quot;text-align: justify;&quot;&gt;Amador Aparicio&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/ManuelSLemos&quot; style=&quot;text-align: justify;&quot;&gt;Manuel S. Lemos&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;y&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/JPalanco&quot; style=&quot;text-align: justify;&quot;&gt;José Palanco&lt;/a&gt; en &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;
La seguridad de un agente se ha de construir partiendo de una buena base. &lt;i&gt;&lt;b&gt;Cloudflare&lt;/b&gt;&lt;/i&gt; proporciona, junto con &lt;i&gt;&lt;b&gt;Anthropic&lt;/b&gt;&lt;/i&gt;, esa base de forma óptima. El propósito de estas líneas ha sido ofrecer un criterio (los principios &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt;), con el que recorrer la distancia que separa un despliegue funcional a uno maduro. Continuar con la maduración no es eliminar defectos, sino ejercer la disciplina &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; sobre una arquitectura que lo permite.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;&lt;u&gt;6.- Nota de Actualización.&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;En el momento de publicarse este artículo, &lt;a href=&quot;https://blog.cloudflare.com/agents-week-welcome/&quot;&gt;Cloudflare ha lanzado su Agents Week&lt;/a&gt;, donde ha presentado, una nueva lista de capacidades que extienden las posibilidades de lo visto en esta pequeña guía, y exigen una lectura para aplicar con ellos los principios de &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; de los que se ha hablado aquí.&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blog.cloudflare.com/agents-on-cloudflare/&quot;&gt;Cloudflare Agents&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://blog.cloudflare.com/cloudflare-os/&quot;&gt;Cloudflare OS: an open platform for agents, apps, and work&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://blog.cloudflare.com/the-agent-access-model/&quot;&gt;The Agent Access Mode&lt;/a&gt;l&lt;/li&gt;&lt;li&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://blog.cloudflare.com/cloudflare-computer/&quot;&gt;Cloudflare Computer for Agents&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://blog.cloudflare.com/agent-development-lifecycle/&quot;&gt;The Agent Development Lifecycle&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://blog.cloudflare.com/mcp-portal-writeguard-private-beta/&quot;&gt;WriteGuard: fine-grained controls for MCP Servers&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://blog.cloudflare.com/local-tracing/&quot;&gt;Local Tracing to allow Agents debugging Workers&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://blog.cloudflare.com/wallets/&quot;&gt;Cloudflare Wallets: the programmable wallet for the agentic Internet&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://blog.cloudflare.com/identity-aware-ai-gateway/&quot;&gt;Catching rogue AI behavior with identity-aware analytics&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blog.cloudflare.com/agents-on-cloudflare/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;650&quot; data-original-width=&quot;1430&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiY6seknpMsUSHDkJ_Z3Y-WUiNhW_UCWYPrkV5XhTBllPE2bU0uZ7vX-0Emb2Mv-xoFPc7m-H7Xa91mgjNu0Dqlj3_YzyunuX563uHQqCd1bYTpuYQ76NHmsB4m4UcfMR2V0t3B-iqkDHbN-YHw1niUDKIB6qB2SJFrWU4HFp-K26sDJUi7ZGEG/w640-h290/agente4.webp&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 40: &lt;a href=&quot;https://blog.cloudflare.com/agents-on-cloudflare/&quot;&gt;Cloudflare Agents&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;&lt;u&gt;7.- Bibliografía.&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;ul&gt;&lt;li&gt;
Anthropic. (22 de junio de 2026). &lt;a href=&quot;https://cdn.prod.website-files.com/6889473510b50328dbb70ae6/6a1611a04085d7cd3dadc924_Claude-eBook-Zero-Trust-for-AI-Agents-05182026.pdf&quot;&gt;Zero Trust for AI Agents&lt;/a&gt;.&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Anthropic. (22 de junio de 2026). &lt;a href=&quot;https://code.claude.com: https://code.claude.com/docs/en/agent-sdk/hooks&quot;&gt;Intercept and control agent behavior with hooks&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Anthropic. (22 de junio de 2026). &lt;a href=&quot;https://code.claude.com/docs/en/agent-sdk/overview&quot;&gt;Agent SDK overview&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Anthropic. (22 de junio de 2026). &lt;a href=&quot;https://code.claude.com: https://code.claude.com/docs/en/permissions&quot;&gt;Configure permissions&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Anthropic. (22 de junio de 2026). &lt;a href=&quot;https://platform.claude.com/docs/en/managed-agents/permission-policies&quot;&gt;Permission policies&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Anthropic. (22 de junio de 2026). &lt;a href=&quot;https://platform.claude.com/docs/en/managed-agents/quickstart&quot;&gt;Get started with Claude Managed Agents&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Anthropic. (22 de junio de 2026). &lt;a href=&quot;https://platform.claude.com: https://platform.claude.com/docs/en/managed-agents/overview&quot;&gt;Claude Managed Agents overview&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Anthropic. (22 de junio de 2026). &lt;a href=&quot;https://platform.claude.com: https://platform.claude.com/docs/en/managed-agents/tools&quot;&gt;Tools&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
CISA. (abril de 2023). &lt;a href=&quot;https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf&quot;&gt;Zero Trust Maturity Model (Cybersecurity and Infrastructure Security Agency)&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents&quot;&gt;claude-managed-agents&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/architecture.md&quot;&gt;architecture.md&lt;/a&gt;.&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/securing-access.md&quot;&gt;securing-access.md&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/applying-egress-policies.md&quot;&gt;applying-egress-policies.md&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/agent-email.md&quot;&gt;agent-email.md&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/browser-rendering-tools.md&quot;&gt;browser-rendering-tools.md&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access/&quot;&gt;SSH with Access for Infrastructure&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/access-controls/service-credentials/mutual-tls-authentication/&quot;&gt;Mutual TLS&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/access-controls/ai-controls/mcp-portals/&quot;&gt;MCP server portals&lt;/a&gt;.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://github.com/cloudflare/sandbox-sdk&quot;&gt;sandbox-sdk&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://developers.cloudflare.com/sandbox/api/commands/&quot;&gt;Commands&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://developers.cloudflare.com/sandbox/api/tunnels/&quot;&gt;Tunnels&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://developers.cloudflare.com/agents/runtime/execution/retries/&quot;&gt;Retries&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://github.com/cloudflare/skills&quot;&gt;Skills&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/isolate-vs-vm-sandboxes.md&quot;&gt;isolate-vs-vm-sandboxes.md&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/snapshots-and-state-persistence.md&quot;&gt;snapshots-and-state-persistence.md&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/connecting-to-private-services.md&quot;&gt;connecting-to-private-services.md&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/adding-custom-tools.md&quot;&gt;adding-custom-tools.md&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/customizing-sandboxes.md&quot;&gt;customizing-sandboxes.md&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://github.com/cloudflare/agents/issues/883&quot;&gt;issues/883&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://developers.cloudflare.com/sandbox/concepts/security/&quot;&gt;Security model&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Cloudflare. (22 de junio de 2026). &lt;a href=&quot;https://developers.cloudflare.com: https://developers.cloudflare.com/sandbox/concepts/containers/&quot;&gt;Container runtime&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Cloud Security Alliance. (2025). &lt;a href=&quot;https://training.cloudsecurityalliance.org/page/zero-trust-training&quot;&gt;Introduction to Software-Defined Perimeter. Certificate of Competence in Zero Trust&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Cloud Security Alliance. (2025). &lt;a href=&quot;https://training.cloudsecurityalliance.org/page/zero-trust-training&quot;&gt;Introduction to Zero Trust Architecture. Certificate of Competence in Zero Trust&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Cloud Security Alliance. (2025). &lt;a href=&quot;https://training.cloudsecurityalliance.org/page/zero-trust-training&quot;&gt;Zero Trust Planning. Certificate of Competence in Zero Trust&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
Microsoft. (22 de junio de 2026). &lt;a href=&quot;https://learn.microsoft.com/es-es/agent-framework/journey/llm-fundamentals&quot;&gt;Aspectos básicos de LLM&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
NIST. (agosto de 2020). &lt;a href=&quot;https://nvlpubs.nist.gov: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot;&gt;Zero Trust Architecture. National Institute of Standards and Technology (Special Publication 800-207)&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;span style=&quot;text-align: left;&quot;&gt;NSTAC. (23 de febrero de 2022). &lt;/span&gt;&lt;a href=&quot;https://www.cisa.gov: https://www.cisa.gov/sites/default/files/publications/NSTAC%20Report%20to%20the%20President%20on%20Zero%20Trust%20and%20Trusted%20Identity%20Management.pdf&quot; style=&quot;text-align: left;&quot;&gt;Zero Trust and Trusted Identity Management. President’s National Security Telecommunications Advisory Committee&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
OWASP. (2025). &lt;a href=&quot;https://genai.owasp.org/resource/top-10-2025-de-riesgos-y-mitigaciones-para-llms-y-aplicaciones-de-ia-generativa/&quot;&gt;OWASP Top 10 para Aplicaciones de LLM&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;
OWASP. (2026). &lt;a href=&quot;https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/&quot;&gt;OWASP Top 10 For Agentic Applications 2026. OWASP&lt;/a&gt;.
&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div align=&quot;justify&quot;&gt;Un saludo,&amp;nbsp; &amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Autor&lt;/i&gt;: &lt;a href=&quot;https://mypublicinbox.com/Juaco507&quot;&gt;&lt;b&gt;Juan Luis Cuenca Ramos&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/Juaco507&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1663&quot; data-original-width=&quot;2060&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjM_ZyyqgoKziGKdraQ385RU1I1ukTztLSFAOaSUsZ8ksPUgQCpTWCSDysw0cDQ6q8VCgLJEptJDsmyXKjRUiEnGasa7TKqRIqdJW1ws38QadfKczE9mjrz2w_5Lvduck0_XlSkWKtpBI3zWofsZX7u050aiAAh-elyvUn8hU9ZerPM-cJWAtxh/w640-h516/juanluiscuenca.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://mypublicinbox.com/Juaco507&quot;&gt;Contactar con Juan Luis Cuenca Ramos&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/como-desplegar-zero-trust-para-agentes_0480428510.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi1BIirgFr3iK0_tztl3endXyLvyeb40z6M4ephvWB7qiSZVgbvovlDINYzAmHztTpNAFXW5-EQqh9zautYb4bLoWqURHNBmaXmnyuP5wHn_RFe8_CQLfDMwJ3fxVurxh-AWvIOd8icN37JPtany0kHi1gPoes2dxGu4krBu_JARZ5r6Secwz20/s72-w640-h430-c/Agente0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-3664309471726747926</guid><pubDate>Wed, 05 Aug 2026 04:01:00 +0000</pubDate><atom:updated>2026-08-05T06:01:00.114+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">ciencia</category><category domain="http://www.blogger.com/atom/ns#">IA</category><category domain="http://www.blogger.com/atom/ns#">IBM</category><category domain="http://www.blogger.com/atom/ns#">innovación</category><category domain="http://www.blogger.com/atom/ns#">Quantum</category><title>Computación Cuántica y Fusión Nuclear: La Receta para fabricar un &quot;Sol en la Tierra&quot;</title><description>&lt;div align=&quot;justify&quot;&gt;Desde hace casi un siglo, la &lt;a href=&quot;https://es.wikipedia.org/wiki/Fusi%C3%B3n_nuclear&quot;&gt;Fusión Nuclear&lt;/a&gt; se presenta como el santo grial de la energía:
la promesa de replicar en la &lt;i&gt;&lt;b&gt;Tierra&lt;/b&gt;&lt;/i&gt; la misma reacción que hace brillar al &lt;i&gt;&lt;b&gt;Sol&lt;/b&gt;&lt;/i&gt;, obteniendo
cantidades inmensas de energía limpia, sin los residuos ni los riesgos de fusión del núcleo
asociados a las centrales de fisión actuales. Pero como bien podréis imaginar, construir un
”&lt;i&gt;&lt;b&gt;Sol artificial&lt;/b&gt;&lt;/i&gt;” es más fácil de decir que de hacer.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://newsroom.ibm.com/2026-07-06-oak-ridge-national-lab,-cleveland-clinic,-and-ibm-achieve-first-known-computations-of-fusion-materials-on-a-quantum-computer&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;545&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpesat0oJlsh14JXylmIU9r1zqw8WMajkV6Ohxawgo-Uastkt70kK_cNTjSfweITh3YYJH3SLdOzb5DbD_cOUEsL6z4VIp3cLOcUJP87cu47LJoNmcW0B61fKY92k0tDEIfgccPOs4b3jtdwwZ8UT7-BESIMmBcm-xRRzk1KsX91E1iPSDTg0x/w640-h372/q0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;&lt;a href=&quot;https://newsroom.ibm.com/2026-07-06-oak-ridge-national-lab,-cleveland-clinic,-and-ibm-achieve-first-known-computations-of-fusion-materials-on-a-quantum-computer&quot;&gt;Computación Cuántica y Fusión Nuclear.&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://newsroom.ibm.com/2026-07-06-oak-ridge-national-lab,-cleveland-clinic,-and-ibm-achieve-first-known-computations-of-fusion-materials-on-a-quantum-computer&quot;&gt;La Receta para fabricar un &quot;Sol en la Tierra&quot;&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Y no, esta vez el problema no está sólo en confinar un plasma a millones de grados con
campos magnéticos. Hay un obstáculo mucho más mundano y del que se habla bastante
menos: &lt;b&gt;&lt;u&gt;el combustible&lt;/u&gt;&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.theregister.com/science/2026/07/06/boffins-bet-on-quantum-computers-ai-su 5267199&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;658&quot; data-original-width=&quot;1346&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0zj5mPmeW5MZdUhtEp-wI5i_i125j97Cl8bL961Hu75nyzQXfjyUxbqf5u3EiuLorymVVhUMbTz2zCFa-hrEg1NFhtPXjUbfNeJR73qTQNv-vCfuGSFcirfgO7YX073x4B9_rOiBQKT-J298Z7Cw4t-LeMj4wzC4hAPW7VKxgS56FFiFo5XMQ/w640-h312/q1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;Figura 2: ”&lt;a href=&quot;https://www.theregister.com/science/2026/07/06/boffins-bet-on-quantum-computers-ai-su 5267199&quot;&gt;Boffins bet on quantum computers, AI supers to solve fusion fuel dilemma&lt;/a&gt;”&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
Este es precisamente el escenario que analiza el artículo de&lt;i&gt;&lt;b&gt; The Register&lt;/b&gt;&lt;/i&gt; titulado ”&lt;a href=&quot;https://www.theregister.com/science/2026/07/06/boffins-bet-on-quantum-computers-ai-su 5267199&quot;&gt;Boffinsbet on quantum computers, AI supers to solve fusion fuel dilemma&lt;/a&gt;”, donde se explica
cómo el &lt;i&gt;&lt;b&gt;Departamento de Energía de EE.UU., la Cleveland Clinic e IBM&lt;/b&gt;&lt;/i&gt; han unido fuerzas
para&lt;a href=&quot;https://newsroom.ibm.com/2026-07-06-oak-ridge-national-lab,-cleveland-clinic,-and-ibm-achieve-first-known-computations-of-fusion-materials-on-a-quantum-computer&quot;&gt; atacar este problema con una combinación de superordenadores, inteligencia artificialy ordenadores cuánticos&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://newsroom.ibm.com/2026-07-06-oak-ridge-national-lab,-cleveland-clinic,-and-ibm-achieve-first-known-computations-of-fusion-materials-on-a-quantum-computer&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;904&quot; data-original-width=&quot;1509&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDRUYf6nSSQZbsswLwwZdiTvINcxgiiOAjhbkzVFcZ8zKrOIr-BGxZL5ThZjWR5r8mAjJjVtCJMOqD7iiEjBTk6gKAnlBUxwbvTvwl7hImh-KDU9uawBR91h-rfaHuZhiumZOox8DkPJaeinsIhs1H_G78zcF7RTGAB9lTU5v-d3zMLW5Hpxxf/w640-h384/q2.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 3:&amp;nbsp;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://newsroom.ibm.com/2026-07-06-oak-ridge-national-lab,-cleveland-clinic,-and-ibm-achieve-first-known-computations-of-fusion-materials-on-a-quantum-computer&quot;&gt;Oak Ridge National Lab, Cleveland Clinic, and IBM Achieve&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://newsroom.ibm.com/2026-07-06-oak-ridge-national-lab,-cleveland-clinic,-and-ibm-achieve-first-known-computations-of-fusion-materials-on-a-quantum-computer&quot;&gt;First-Known Computations of Fusion Materials on a Quantum Computers&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
Para conseguir la fusión necesitamos dos ingredientes: &lt;a href=&quot;https://es.wikipedia.org/wiki/Deuterio&quot;&gt;Deuterio&lt;/a&gt; y &lt;a href=&quot;https://es.wikipedia.org/wiki/Tritio&quot;&gt;Tritio&lt;/a&gt;&amp;nbsp;(&lt;a href=&quot;https://en.wikipedia.org/wiki/Tritium&quot;&gt;Tritium&lt;/a&gt;), dos isótopos pesados
del hidrógeno. El primero no supone ningún problema, ya que es abundante y se puede
extraer del agua del mar. El segundo, en cambio, es el auténtico cuello de botella: el &lt;b&gt;&lt;u&gt;Tritio
es radiactivo&lt;/u&gt;&lt;/b&gt;, se desintegra con rapidez y prácticamente no existe de forma natural en la
&lt;i&gt;&lt;b&gt;Tierra&lt;/b&gt;&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;El problema: un combustible que no existe (casi)&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;
Para que os hagáis una idea de la magnitud del problema: la producción mundial de&amp;nbsp;&lt;a href=&quot;https://es.wikipedia.org/wiki/Tritio&quot;&gt;Tritio&lt;/a&gt;&amp;nbsp;es de apenas unos pocos kilos al año, mientras que una sola central de fusión de un &lt;i&gt;&lt;b&gt;Gigavatio (GW)&lt;/b&gt;&lt;/i&gt;&amp;nbsp;consumiría en torno a medio kilo al día. Es decir, todo el&amp;nbsp;&lt;a href=&quot;https://es.wikipedia.org/wiki/Tritio&quot;&gt;Tritio&lt;/a&gt;&amp;nbsp;del planeta mantendría
funcionando un único reactor durante unas pocas semanas.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhvuAimoCgW2WYM7DzeaTs1l9aFZ0HMJhUI61Ek5h2bSmSXdLrG81LGBHsCwoO3lTJo2LvWCE-xZCi4AtnlxZ7_pjDuaw_Qmkli3UBkZp_kQG4DykJm_bwo7hKJZVDiyb8-Oqf2CyDA5KD9tBdrHxI8BBF0YEp1mU_aoYrjI2WAK3YA1EQutcbs/s1412/q3.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;774&quot; data-original-width=&quot;1412&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhvuAimoCgW2WYM7DzeaTs1l9aFZ0HMJhUI61Ek5h2bSmSXdLrG81LGBHsCwoO3lTJo2LvWCE-xZCi4AtnlxZ7_pjDuaw_Qmkli3UBkZp_kQG4DykJm_bwo7hKJZVDiyb8-Oqf2CyDA5KD9tBdrHxI8BBF0YEp1mU_aoYrjI2WAK3YA1EQutcbs/w640-h350/q3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 4: Esquema resumido del problema de relacionado&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;con el ”combustible” de la fusión nuclear&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Es como querer montar una red
de gasolineras en un mundo donde el petróleo se vende por gotas.&amp;nbsp;&lt;span style=&quot;text-align: left;&quot;&gt;La conclusión es evidente:&lt;i&gt;&lt;b&gt; una central de fusión comercial no puede depender de un
suministro externo, sino que debe fabricar su propio combustible mientras funciona&lt;/b&gt;&lt;/i&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
La solución: una manta de sal fundida&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
La propuesta más prometedora consiste en envolver el reactor con una gruesa ”&lt;i&gt;&lt;b&gt;manta&lt;/b&gt;&lt;/i&gt;” de una
sal fundida llamada &lt;i&gt;&lt;b&gt;FLiBe&lt;/b&gt;&lt;/i&gt;, compuesta por &lt;i&gt;&lt;b&gt;Flúor, Litio y Berilio&lt;/b&gt;&lt;/i&gt;. La idea es tremendamente
elegante: cuando un &lt;i&gt;&lt;b&gt;neutrón&lt;/b&gt;&lt;/i&gt; sale disparado de la reacción de fusión y golpea un átomo de &lt;i&gt;&lt;b&gt;Litio-6&lt;/b&gt;&lt;/i&gt; de la sal, este se rompe generando &lt;i&gt;&lt;b&gt;Helio&lt;/b&gt;&lt;/i&gt; y... ¡&lt;i&gt;&lt;b&gt;Tritio&lt;/b&gt;&lt;/i&gt; fresco! El &lt;i&gt;&lt;b&gt;Berilio&lt;/b&gt;&lt;/i&gt;, por su parte,
multiplica los neutrones sueltos para que la ”&lt;i&gt;&lt;b&gt;cría&lt;/b&gt;&lt;/i&gt;” de combustible sea suficiente, mientras
que el flúor y el litio mantienen la mezcla líquida y estable a las temperaturas infernales del
reactor.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://newsroom.ibm.com/2026-07-06-oak-ridge-national-lab,-cleveland-clinic,-and-ibm-achieve-first-known-computations-of-fusion-materials-on-a-quantum-computer&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;754&quot; data-original-width=&quot;1300&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicTIi5zFkBzVrxqDiwknO8SPpFSnoAQn_jCCX6doYsEdzRdUcODP_dK0K0Ndw8vXVLIlQzdEqc_oU0frptPwNYQN-NGeFDtYZ8O3uugPXS82oN7PpZOpuoWvXS7g2Ywsiue8dfHGIv_Ivebl8YAtzmkE3uGWJ9kMg95i6Vvp6DSadIrreHsBBh/w640-h372/q4.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 5: &lt;a href=&quot;https://newsroom.ibm.com/2026-07-06-oak-ridge-national-lab,-cleveland-clinic,-and-ibm-achieve-first-known-computations-of-fusion-materials-on-a-quantum-computer&quot;&gt;Esquema de un tokamak rodeado por la&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://newsroom.ibm.com/2026-07-06-oak-ridge-national-lab,-cleveland-clinic,-and-ibm-achieve-first-known-computations-of-fusion-materials-on-a-quantum-computer&quot;&gt;manta de sal fundida donde se genera el Tritio&lt;/a&gt;.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
Pero aquí llega la letra pequeña. Una vez generado el Tritio dentro de la sal, hay que sacarlo
de ahí, y su comportamiento químico puede seguir dos caminos muy distintos:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;
Si el Tritio permanece libre en forma de gas:&lt;/b&gt;&lt;i&gt; burbujea y sale solo de la mezcla. ¡Perfecto!&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;
Si en cambio se une al flúor, forma fluoruro de Tritio:&lt;/b&gt;&lt;i&gt; un compuesto corrosivo y muy
difícil de extraer. Un auténtico quebradero de cabeza.&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;
Predecir cuál de los dos caminos tomará requiere modelar la química de la sal con una
precisión extrema. Y aquí los métodos clásicos se quedan cortos: la técnica habitual, la &lt;a href=&quot;https://es.wikipedia.org/wiki/Teor%C3%ADa_del_funcional_de_la_densidad&quot;&gt;Teoría del Funcional de la Densidad (DFT)&lt;/a&gt;, puede cometer errores de hasta el &lt;i&gt;&lt;b&gt;10%&lt;/b&gt;&lt;/i&gt; en
la energía libre del sistema, un margen inaceptable para responder a la pregunta clave.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Además, hacer experimentos reales con sales fundidas es carísimo y requiere instalaciones
muy especializadas. ¿Os suena este patrón?&amp;nbsp;&amp;nbsp;&lt;span style=&quot;text-align: left;&quot;&gt;Un problema de naturaleza cuántica que desborda a los ordenadores
clásicos... ¡Es justo el tipo de tarea para el que nacieron los &lt;b&gt;&lt;u&gt;ordenadores cuánticos&lt;/u&gt;&lt;/b&gt;!&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i style=&quot;font-weight: bold;&quot;&gt;&lt;br /&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;/span&gt;&lt;span style=&quot;text-align: left;&quot;&gt;Supercomputación Cuántico-Céntrica: CPUs, GPUs y QPUs t&lt;/span&gt;&lt;span style=&quot;text-align: left;&quot;&gt;rabajando en equipo.&lt;/span&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
Como ya hemos comentado en otros artículos de este blog, los ordenadores cuánticos no
vienen a sustituir a los clásicos, sino a complementarlos en problemas muy concretos. Y este
trabajo es el ejemplo perfecto de esa filosofía, bautizada por &lt;i&gt;&lt;b&gt;IBM&lt;/b&gt;&lt;/i&gt; como &lt;i&gt;&lt;b&gt;Supercomputación Cuántico-Céntrica&lt;/b&gt;&lt;/i&gt;: combinar &lt;i&gt;&lt;b&gt;CPUs, GPUs &amp;amp; QPUs&lt;/b&gt;&lt;/i&gt; (procesadores cuánticos) para resolver
juntos lo que ninguno puede resolver por separado.&lt;br /&gt;&lt;br /&gt;
La estrategia que han seguido los investigadores es muy ingeniosa:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;&lt;u&gt;Fragmentación del problema:&lt;/u&gt;&lt;/b&gt; &lt;i&gt;mediante una técnica llamada wave function-based
embedding, el cálculo de la molécula completa se trocea en fragmentos manejables
llamados ”clusters”.&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;&lt;u&gt;Reparto del trabajo&lt;/u&gt;&lt;/b&gt;: &lt;i&gt;los ordenadores clásicos resuelven los clusters sencillos,
mientras que el ordenador cuántico se encarga de los más complejos, aquellos con
mayor entrelazamiento entre átomos, utilizando un algoritmo llamado &lt;a href=&quot;https://quantum.cloud.ibm.com/learning/en/courses/quantum-diagonalization-algorithms/sqd-overview&quot;&gt;Sample-Based Quantum Diagonalization (SQD)&lt;/a&gt;.&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://quantum.cloud.ibm.com/learning/en/courses/quantum-diagonalization-algorithms/sqd-overview&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1472&quot; data-original-width=&quot;1646&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgcmpAYM5KbljKnbeMNlz8oaFrte2MPGkLcr99dic7egd0A-QtlTnj-2OJ9H5cMFlXLMmUC0EcHPH3jesKUIAF_fCCQ5qTQWIkteQn0bi7SQvLG84aLoe8JrpslY0rxGT-UEypNMNWkjku_c3frTgWFSqiD7MWubvIZLZnPtFnbTRrWxWV4APPC/w400-h358/q5.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 6:&amp;nbsp;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://quantum.cloud.ibm.com/learning/en/courses/quantum-diagonalization-algorithms/sqd-overview&quot;&gt;Sample-Based Quantum Diagonalization (SQD)&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&amp;nbsp;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;&lt;u&gt;Reconstrucción:&lt;/u&gt;&lt;/b&gt; &lt;i&gt;finalmente, los ordenadores clásicos ”recosen” todos los fragmentos
para obtener la solución de la molécula completa.&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;
Lo curioso es que esta metodología no nació para la fusión: &lt;a href=&quot;https://www.ibm.com/quantum/blog/cleveland-clinic-riken-chemistry&quot;&gt;es la misma que utilizó laCleveland Clinic a principios de año para simular una proteína de 12.635 átomos&lt;/a&gt;. La
ciencia es así de caprichosa, y una técnica desarrollada para biomedicina acaba siendo clave
para la energía del futuro.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.ibm.com/quantum/blog/molten-salts-fusion-quantum&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;790&quot; data-original-width=&quot;1430&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEibeP6akpt1X7dBGePWSJ3HJm7wj59IJAk4XQxAGedDGi0FYWOlwITG7W3DJj84HGdtpd7TB4Ju_QYKkLo6lUCc9RANNQYwAdQVLS427M6qeHGMzZLmN97N_Eqn31xFLLyxHLx94uZwT_jCic8U6t0lTgKyF5p9aIWLE6gaP-WDHXBlsPQCNP0e/w640-h354/q6.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 7: &lt;a href=&quot;https://www.ibm.com/quantum/blog/molten-salts-fusion-quantum&quot;&gt;Modelado de la interacción entre el Tritio y&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://www.ibm.com/quantum/blog/molten-salts-fusion-quantum&quot;&gt;los clusters de átomos de la sal fundida FLiBe.&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
Con este enfoque, el equipo calculó las energías de nueve configuraciones moleculares
de &lt;i&gt;&lt;b&gt;FLiBe&lt;/b&gt;&lt;/i&gt; (&lt;i&gt;&lt;b&gt;clusters&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;21 iones&lt;/b&gt;&lt;/i&gt; cada una), con y sin &lt;i&gt;&lt;b&gt;Tritio&lt;/b&gt;&lt;/i&gt;, siendo la primera vez que se
realizan este tipo de cálculos de materiales de fusión en un ordenador cuántico.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://arxiv.org/pdf/2606.30402&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1726&quot; data-original-width=&quot;1336&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgGKTyHDyDvNuDpgrPDHFloOALZho6qcyh7ctnxPIktcRVse-xaLR4aw2QXlAZbCzhIelVqbW4kvbR-NAd_aVRMgGWT4hyphenhyphen8GGV0YuIX3vs-AEDtH2Je2Pn3JYV-2GEQEHeFj6cvR7cgJHetoGcrLsC7m0hyphenhyphenD2WW4POeZkpZxj64btL7kiZWvRWr/w496-h640/q7.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 8:&amp;nbsp;&lt;a href=&quot;https://arxiv.org/pdf/2606.30402&quot;&gt;Quantum Computations on Fusion Blanket Molten Salts&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Y lo más
importante es que los resultados cuánticos igualaron a los métodos clásicos más exigentes. Puede
parecer poco ambicioso ”&lt;i&gt;&lt;b&gt;sólo igualar&lt;/b&gt;&lt;/i&gt;”, pero es la prueba de concepto necesaria que demuestra
que el camino cuántico funciona y está listo para escalar hacia donde los clásicos ya no llegan.
&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
El futuro: un bucle de IA, superordenadores y cuántica&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
Este cálculo es solo una pieza de un plan mucho más ambicioso. El objetivo a largo plazo
es construir un flujo de trabajo en bucle, asistido por agentes de inteligencia artificial, que
funcione en tres etapas:&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote style=&quot;border-color: currentcolor; border-image: none; border-style: none; border-width: medium; border: none; margin: 0px 0px 0px 40px; padding: 0px;&quot;&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;
1. Cribado con IA:&lt;/b&gt; &lt;i&gt;agentes de inteligencia artificial proponen y filtran candidatas a
partir de una base de datos del ”Oak Ridge National Lab” con 70 años de investigación
en sales fundidas, estimando cuánto tritio generaría cada sal y si sus propiedades
térmicas son adecuadas.&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote style=&quot;border-color: currentcolor; border-image: none; border-style: none; border-width: medium; border: none; margin: 0px 0px 0px 40px; padding: 0px;&quot;&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;
2. Simulación clásica:&lt;/b&gt; &lt;i&gt;las sales más prometedoras pasan a los superordenadores, que
las modelan átomo a átomo. Como estas simulaciones son carísimas, se emplean
”sustitutos” de IA entrenados para reproducir la física a gran velocidad.&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;blockquote style=&quot;border-color: currentcolor; border-image: none; border-style: none; border-width: medium; border: none; margin: 0px 0px 0px 40px; padding: 0px;&quot;&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;
3. Precisión cuántica:&lt;/b&gt; &lt;i&gt;el ordenador cuántico entra donde la DFT se queda corta: la
química de alta precisión que decide dónde se une el tritio. Los resultados realimentan
el bucle, afinando la siguiente ronda de candidatas.&lt;/i&gt;&lt;/div&gt;&lt;/blockquote&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
El sueño de los investigadores es que, en el futuro, los ingenieros de fusión puedan diseñar y
validar una sal fundida completamente por ordenador antes de mezclarla y calentarla en un
laboratorio, ahorrando años de experimentos y cantidades ingentes de dinero.&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.deusto.es/es/inicio/estudia/estudios/curso-seminario/quantum-post-quantum&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;479&quot; data-original-width=&quot;800&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjonM6IQev6AzSJaNGkDnrI6wKqaGJZjc1YUPaOtykxXBLNoK3DWFhpKT46843SosbJjMJ3B86qABvlxgHK3FgwN-Qp_3MpuMiOpI9L8yM5enS5xQrAgZ093V4Zb2J4X1lKLoODRcTwJipHTT_7ETpqR7Yv6acRWmGdhVovE_UCgXR3U1EgHt0Q/w640-h384/q0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 9: &lt;a href=&quot;https://www.deusto.es/es/inicio/estudia/estudios/curso-seminario/quantum-post-quantum&quot;&gt;Quantum y Post-Quantum Computing para Ciberseguridad.&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://www.deusto.es/es/inicio/estudia/estudios/curso-seminario/quantum-post-quantum&quot;&gt;Formación Especializada, Libro &amp;amp; Foro Online&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;
Eso sí, seamos honestos con las limitaciones: el problema completo requiere modelar una
manta de sal de un metro de grosor con del orden de un cuatrillón de partículas, algo
que seguirá fuera del alcance de la química computacional durante mucho tiempo.&amp;nbsp;&amp;nbsp;&lt;span style=&quot;text-align: left;&quot;&gt;El plan
inmediato es más modesto pero realista: aumentar el tamaño de los &lt;/span&gt;&lt;i style=&quot;text-align: left;&quot;&gt;&lt;b&gt;clusters&lt;/b&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt; mucho más
allá de los &lt;/span&gt;&lt;i style=&quot;text-align: left;&quot;&gt;&lt;b&gt;21 iones&lt;/b&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt; actuales y calcular los cientos de configuraciones que exige el problema
completo, no solo nueve.&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/248-quatum-security-tecnologia-cuantica-ciberseguridad-criptografica-cuantica-y-post-cuantica.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1610&quot; data-original-width=&quot;1137&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjzNgeoS8bK-N-wht22IN3Z9fcjMOMuMh6f9H8bSB9a-4MxLglEcHxqPpeuw8auxDK6z1mWBzkmwxwpV_x1cgen1gWeVP9ig3bZUh2UrXc8DcD68D7ZVT7gCmkeHGu9p08QKsTN4fW0RsnEbdcSXP2xHDPbmogTUDdrsk_YmX7lGAsv-olxYX2k/w282-h400/Quantum1.jpg&quot; width=&quot;282&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;Figura 10: &lt;span style=&quot;text-align: justify;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/248-quatum-security-tecnologia-cuantica-ciberseguridad-criptografica-cuantica-y-post-cuantica.html&quot;&gt;Quatum Security: Tecnología Cuántica &amp;amp; Ciberseguridad.&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/248-quatum-security-tecnologia-cuantica-ciberseguridad-criptografica-cuantica-y-post-cuantica.html&quot;&gt;Criptográfica Cuántica y Post-Cuántica.&lt;/a&gt;&lt;/span&gt;&amp;nbsp;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;Nuestro nuevo libro en &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; escrito por: &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Chema Alonso&lt;/a&gt;,&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://mypublicinbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/CarmenTorrano&quot; style=&quot;text-align: justify;&quot;&gt;Carmen Torrano&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/DanielRomeroRuiz&quot; style=&quot;text-align: justify;&quot;&gt;Daniel Romero&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://MyPublicInbox.com/JAlvarezz13&quot; style=&quot;text-align: justify;&quot;&gt;Javier Álvarez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/MarioPiattini &quot; style=&quot;text-align: justify;&quot;&gt;Mario Piattini&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;ttps://MyPublicInbox.com/IkerPastor&quot; style=&quot;text-align: justify;&quot;&gt;Iker Pastor&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/pgb&quot; style=&quot;text-align: justify;&quot;&gt;Pablo García Bringas&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;
En definitiva, estamos presenciando cómo tres de las tecnologías más punteras de nuestro
tiempo (la &lt;i&gt;&lt;b&gt;Inteligencia Artificial, la Supercomputación y la Computación Cuántica&lt;/b&gt;&lt;/i&gt;) dejan de
competir entre sí para unir fuerzas contra uno de los grandes problemas de ingeniería de
la humanidad.&amp;nbsp;&amp;nbsp;&lt;span style=&quot;text-align: left;&quot;&gt;Los ordenadores cuánticos ya no solo prometen revolucionar el futuro: están
ayudando a construirlo. La pregunta es inevitable: ¿será la cuántica la pieza que por fin
encienda nuestro propio sol en la Tierra?&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.mypublicinbox.com/dashboard/chats/1EYMKZVKlRwaJx0g&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;542&quot; data-original-width=&quot;878&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhUw_-dmvGoyYQJZ-pePlrwShFAnpWUIYUUIrEylElGv7RPjCaTlTnOvS2SWGqCMK_CuOxSLozC4ZDw2Wkx4GtqV0MUhdcaYhPPzIIyOgeqf-uIEMP0tJxtM8-1ifSWfcLlLiNw_vhf7oVNT2LaJNv2jSW6WKxYZIwp3Koc51CO_r0FalBD_0sP/w640-h396/q7.png&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 3: &lt;a href=&quot;https://www.mypublicinbox.com/dashboard/chats/1EYMKZVKlRwaJx0g&quot;&gt;Foro Público de Quantum Security de&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://www.mypublicinbox.com/dashboard/chats/1EYMKZVKlRwaJx0g&quot;&gt;la Universidad de Deusto en MyPublicInbox&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div&gt;Si te interesan estos temas, te recomiendo que te apuntes al &lt;a href=&quot;https://www.mypublicinbox.com/dashboard/chats/1EYMKZVKlRwaJx0g&quot;&gt;Foro Online Público que funciona desde Septiembre del año pasado en MyPublicInbox&lt;/a&gt;, donde se comparten temas de &lt;a href=&quot;https://0xword.com/es/libros/248-quatum-security-tecnologia-cuantica-ciberseguridad-criptografica-cuantica-y-post-cuantica.html&quot;&gt;Quantum &amp;amp; Post-Quantum Securrity&lt;/a&gt;, así que si quieres estar informado puedes entrar libremente y suscribirte. Y si quieres más, apúntate al curso de&amp;nbsp;&lt;span style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://www.deusto.es/es/inicio/estudia/estudios/curso-seminario/quantum-post-quantum&quot;&gt;Quantum y Post-Quantum Computing para Ciberseguridad.&lt;/a&gt;&lt;/span&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;div&gt;Saludos,&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;&lt;a href=&quot;https://mypublicinbox.com/DanielRomeroRuiz&quot;&gt;Daniel Romero Ruiz&lt;/a&gt;&lt;/b&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/DanielRomeroRuiz&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1490&quot; data-original-width=&quot;1880&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjIoA-Qjo8Scebz12sKmVQnmufZNAZsmVs4x8WiGsyARk1aUnKd-aX7_ptHXHaduSJ45pfQOEZ_heKE7r2xQ8NW0xCjLOcNzWC_ldIVf-oGShZ-neijW84b2-7ufCTAezRVXji9JISVmIdPe1BVsTXJuMT8-vEOIifxE9-5UCTVoLCgMoHUZavH/w640-h508/DanielRomeroRuiz.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/DanielRomeroRuiz&quot;&gt;&lt;i&gt;Contactar con Daniel Romero Ruiz&lt;/i&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;Otros artículos sobre Quantum Computing publicados:&lt;/b&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;ul&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/07/iii-edicion-del-programa-de.html&quot;&gt;III edición del Programa de Especialización de Quantum y Post-Quantum Computing para Ciberseguridad: Noviembre 2026&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://0xword.com/es/libros/248-quatum-security-tecnologia-cuantica-ciberseguridad-criptografica-cuantica-y-post-cuantica.html&quot;&gt;Libro de &lt;span style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;Quatum Security: Tecnología Cuántica &amp;amp; Ciberseguridad. &lt;/span&gt;&lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;Criptográfica Cuántica y Post-Cuántica.&lt;/span&gt;&amp;nbsp;&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.mypublicinbox.com/dashboard/chats/1EYMKZVKlRwaJx0g&quot;&gt;&lt;span style=&quot;text-align: center;&quot;&gt;Foro Público de Quantum Security de &lt;/span&gt;&lt;span style=&quot;text-align: center;&quot;&gt;la Universidad de Deusto en MyPublicInbox&lt;/span&gt;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2022/12/quantum-computing-cybersecurity.html&quot;&gt;Quantum Computing Cybersecurity Preparedness Act: Comienza la era de Ciberseguridad Post-Quantum en Estados Unidos&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/04/hamming-quasi-cyclic-hqc-kem-nuevo-key.html&quot;&gt;Hamming Quasi-Cyclic (HQC-KEM): Nuevo Key-Encapsulation Mechanism en Post-Quantum Cryptography&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/05/frodokem-un-key-encapsulation-mechanism.html&quot;&gt;FrodoKEM: Un Key-Encapsulation Mechanism Quantum-Safe (PQC) que recibe su nombre por &quot;El señor de los Anillos&quot;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/08/la-gran-busqueda-de-numeros-primos-de.html&quot;&gt;La Gran Búsqueda de Números Primos de Mersenne en Internet para superar el mayor Número Primo conocido hasta la fecha&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/09/como-acelerar-los-algoritmos-de.html&quot;&gt;Cómo acelerar los algoritmos de Inteligencia Artificial con Computadores Analógicos Ópticos (AOC)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/10/premio-nobel-en-fisica-2025-el-trabajo.html&quot;&gt;Premio Nobel en Física 2025: El trabajo del &quot;Efecto Tunel&quot; que trajo la cuántica a nuestro mundo y abrió la puerta a los ordenadores cuánticos&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/10/un-reloj-atomico-optico-del-mit-con.html&quot;&gt;Un Reloj Atómico Óptico del MIT con Optimización Cuántica para medir el Tiempo del Futuro&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2018/06/quantum-cryptography-una-comunicacion.html&quot;&gt;Quantum Cryptography: Una comunicación con cifrado cuántico&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2023/01/factorizacion-de-rsa-con-un-optimizador.html&quot;&gt;Factorización de RSA con un Optimizador de Quantum Computing (y Classic Computing)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/11/cuanto-del-trafico-en-internet-funciona.html&quot;&gt;Cuánto del tráfico en Internet funciona con Post-Quantum Cryptography&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/11/algoritmo-cuantico-de-grover-un.html&quot;&gt;Algoritmo Cuántico de Grover: Un algoritmo de búsqueda optimizado por superposición cuántica&amp;nbsp;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/12/quantum-sensors-cuando-lo-invisible-se.html&quot;&gt;Quantum Sensors: Cuando lo invisible se hace visible gracias al Mundo Cuántico&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/12/bitcoin-vs-quantum-computers-hora-de.html&quot;&gt;Bitcoin vs Quantum Computers: Hora de pasar a Post-Quantum Cryptography&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/12/el-white-paper-de-mastercard-que-urge.html&quot;&gt;El White Paper de MasterCard que urge a pasar a Quantum Safe: Post-Quantum Cryptography (PQC) &amp;amp; Quantum Key Distribution (QKD)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/12/dyber-hardware-accelerated-post-quantum.html&quot;&gt;Dyber: Hardware-Accelerated Post-Quantum Cryptography (PQC)&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/01/como-ser-quantum-safe-y-desplegar-post.html&quot;&gt;Cómo ser Quantum Safe y desplegar Post-Quantum Cryptography (PQC) con Cloudflare&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/02/quantum-gps-navegacion-con-gps.html&quot;&gt;Quantum GPS: Navegación con GPS cuánticos para evitar ataques de Jamming &amp;amp; Spoofing&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/03/como-comprobar-si-un-web-site-is.html&quot;&gt;Cómo comprobar si un Web Site es Quantum Ready con Post-Quantum Cryptography usando Radar&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/03/alaniz-cipher-un-cifrado-simetrico.html&quot;&gt;Alaniz Cipher: Un Cifrado Simétrico Quantum Resistant&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/05/los-papers-academicos-de-los-algoritmos.html&quot;&gt;Los Papers Académicos de los algoritmos PQC de Autenticación y Firma Digital en la Ronda 3 del NIST&lt;/a&gt;&lt;/li&gt;&lt;li&gt;&lt;a href=&quot;https://www.elladodelmal.com/2026/07/blind-quantum-computing-1.html&quot;&gt;Blind Quantum Computing (1)&lt;/a&gt; &lt;a href=&quot;https://www.elladodelmal.com/2026/07/blind-quantum-computing-2.html&quot;&gt;(2)&lt;/a&gt; &lt;a href=&quot;https://www.elladodelmal.com/2026/07/blind-quantum-computing-3.html&quot;&gt;(3)&lt;/a&gt; &lt;a href=&quot;https://www.elladodelmal.com/2026/07/blind-quantum-computing-y-4.html&quot;&gt;(4)&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/computacion-cuantica-y-fusion-nuclear.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpesat0oJlsh14JXylmIU9r1zqw8WMajkV6Ohxawgo-Uastkt70kK_cNTjSfweITh3YYJH3SLdOzb5DbD_cOUEsL6z4VIp3cLOcUJP87cu47LJoNmcW0B61fKY92k0tDEIfgccPOs4b3jtdwwZ8UT7-BESIMmBcm-xRRzk1KsX91E1iPSDTg0x/s72-w640-h372-c/q0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-2716574433219250593</guid><pubDate>Tue, 04 Aug 2026 04:01:00 +0000</pubDate><atom:updated>2026-08-06T07:47:06.645+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Agentic</category><category domain="http://www.blogger.com/atom/ns#">Agentic AI</category><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">Anthropic</category><category domain="http://www.blogger.com/atom/ns#">Artificial Intelligence</category><category domain="http://www.blogger.com/atom/ns#">ciberseguridad</category><category domain="http://www.blogger.com/atom/ns#">Claude</category><category domain="http://www.blogger.com/atom/ns#">cloudflare</category><category domain="http://www.blogger.com/atom/ns#">hardening</category><category domain="http://www.blogger.com/atom/ns#">IA</category><category domain="http://www.blogger.com/atom/ns#">Inteligencia Artificial</category><category domain="http://www.blogger.com/atom/ns#">LLM</category><category domain="http://www.blogger.com/atom/ns#">OWASP</category><category domain="http://www.blogger.com/atom/ns#">Zero Trust</category><title>Cómo desplegar Zero Trust para Agentes IA en Cloudflare (3)</title><description>&lt;div align=&quot;justify&quot;&gt;&lt;div align=&quot;justify&quot;&gt;Continuando lo visto en la &lt;a href=&quot;https://www.elladodelmal.com/2026/07/como-desplegar-zero-trust-para-agentes.html&quot;&gt;primera parte de esta serie&lt;/a&gt;, y en la &lt;a href=&quot;https://www.elladodelmal.com/2026/07/como-desplegar-zero-trust-para-agentes_01099167063.html&quot;&gt;segunda&lt;/a&gt;, continuamos en este apartado con cómo configurar modelos de &lt;a href=&quot;https://www.elladodelmal.com/2026/07/como-desplegar-zero-trust-para-agentes.html&quot;&gt;Zero Trust para Agentes IA utilizando las tecnologías de Cloudflare&lt;/a&gt;, comenzando ahora con la validación de los datos de entrada y los datos de salida, un tema de los más importantes.&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZ-V3VZVk-U_ocTPehBRqSwg5X7ozdutPsaMPf8HMcfj9rk0IwZmThnljq0FhVQ5BDxK6_ElsUJfpmz2SjwGKcm4sagUYo-PC5GwN00ykBv76I81yRYYXhN4wD5AkkZGgT13KGwKpkXsT0E3cD0sX3g1urwZMx4XErTlIGAEDRuocV4eGv1zGu/s940/Agent0.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;561&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZ-V3VZVk-U_ocTPehBRqSwg5X7ozdutPsaMPf8HMcfj9rk0IwZmThnljq0FhVQ5BDxK6_ElsUJfpmz2SjwGKcm4sagUYo-PC5GwN00ykBv76I81yRYYXhN4wD5AkkZGgT13KGwKpkXsT0E3cD0sX3g1urwZMx4XErTlIGAEDRuocV4eGv1zGu/w640-h382/Agent0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 23:&amp;nbsp;Cómo desplegar Zero Trust para Agentes IA en Cloudflare (3)&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;En la próxima parte daremos por terminado este artículo, pero antes vamos a recorrer las fortificaciones que aún nos quedan por hacer en un modelo &lt;i&gt;&lt;b&gt;Zero&lt;/b&gt;&lt;/i&gt; &lt;i&gt;&lt;b&gt;Trust&lt;/b&gt;&lt;/i&gt; y cómo hacer éstas con &lt;a href=&quot;https://www.cloudflare.com&quot;&gt;Cloudflare&lt;/a&gt;.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;&lt;u&gt;

  4.4.- Validación de entrada y salida de datos. &lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
El principio.&lt;br /&gt;&lt;br /&gt;
La segmentación traza el mapa de con quién puede hablar el agente, este control vigila que viaja por esas conexiones. Tiene dos caras. En la entrada, el problema es la inyección. Como se estableció en la premisa, el agente no distingue de forma fiable una instrucción legítima de una orden maliciosa incrustada en los datos que procesa (un correo, una página web, el resultado de una herramienta).&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;i&gt;&lt;b&gt;OWASP&lt;/b&gt;&lt;/i&gt; lo recoge como el secuestro objetivo del agente (&lt;a href=&quot;https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/&quot;&gt;ASI01- Agent Goal Hijack&lt;/a&gt;), una de sus categorías primarias. En la salida, el problema es la exfiltración: que el agente, comprometido o no, emita datos que no deberían salir. &lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;904&quot; data-original-width=&quot;1070&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEihUp5TQgvtLiwdBEuCaOVryzXYvWVY2IAVpCDvlIuSpeKDJSH2tO4Md2YtBlxxeei43yoBT7bBWZ71_XJaCNT9k52l9bmN84TdzkhXVkmRTnhjDtRYqKEkHsZ1x9oR4gX-TVm_0HoQk6T-jBUXiFDjY_VA0LrPbiZOBuhDFs7QokAE-nyZzhN3/w640-h540/agent1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 24:&amp;nbsp;&lt;a href=&quot;https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/&quot; style=&quot;text-align: left;&quot;&gt;ASI01- Agent Goal Hijack&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
El &lt;a href=&quot;https://cdn.prod.website-files.com/6889473510b50328dbb70ae6/6a1611a04085d7cd3dadc924_Claude-eBook-Zero-Trust-for-AI-Agents-05182026.pdf&quot;&gt;eBook de Anthropic articula este control con claridad&lt;/a&gt;: la validación de entrada bloquea los intentos de manipulación en la frontera, rechazando instrucciones maliciosas antes de que el agente las procese y los controles de salida restringen lo que el agente puede producir, limitando la fuga de datos incluso cuando un atacante logra comprometer su comportamiento. La idea rectora es que el agente no puede ser su propio filtro. La validación debe ser un filtro externo, previo al procesamiento.&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://claude.com/blog/zero-trust-for-ai-agents&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;906&quot; data-original-width=&quot;1184&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhucGqwWWdG4OimtBeyg3niJjMxq1-OPvlTJjBpi4z3lAwz1FpcbtogtwDpYSGP69BCbEhkuO-NbsfZYy9JgwGAgPhOWTiejLZ4wrFO5GRCgA_r-db5sdLORwnmaz8P1JcqNDGoDMb5hBYNZbDngYKpn7CYtEzEZcMXjJj88ovpKqsBP4tCxZB1/w640-h490/zero4.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 25: &lt;a href=&quot;https://claude.com/blog/zero-trust-for-ai-agents&quot;&gt;Prompt Injection&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;
Hay un matiz propio del mundo agéntico que conviene no ignorar. La validación de entradas no se traslada directamente desde la seguridad tradicional. La &lt;a href=&quot;https://0xword.com/es/libros/25-libro-hacking-aplicaciones-web-sql-injection.html&quot;&gt;inyección SQL&lt;/a&gt;, tiene patrones definidos y campos acotados, pero las entradas de un agente son libres e impredecibles, lo que hacen que sean insuficientes dichas reglas. Aun así, se puede validar contra esquemas esperados, imponer longitudes máximas y rechazar patrones conocidos antes de que la entrada llegue al agente.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;
Dónde se sitúa hoy el ecosistema de Cloudflare. &lt;br /&gt;&lt;/u&gt;&lt;br /&gt;
El despliegue ofrece varios puntos donde insertar esta validación, aunque conviene señalar un hecho destacable. La documentación describe los canales por donde entra el contenido externo, pero no afirma que exista un filtrado de contenido automático sobre ellos. El filtro, en buena medida, es algo que quien despliega debe construir en los puntos que la plataforma habilita. &lt;br /&gt;&lt;br /&gt;
El &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/agent-email.md&quot;&gt;correo es un ejemplo de entrada no confiable&lt;/a&gt;. Cada agente puede tener un buzón y cuando llega un mensaje, el agente recibe un evento que le indica que un correo ha llegado y le ofrece leerlo. Este cuerpo es contenido externo que entra en el contexto del agente: un vector de inyección indirecta. La documentación describe el mecanismo, pero no un filtrado del contenido. Ese filtrado es responsabilidad de quien despliega. Lo mismo ocurre con la navegación web: recuperar una página es ingerir contenido no controlado. &lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/agent-email.md&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1372&quot; data-original-width=&quot;1770&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjDnC9fR_yUZ8BymA25VaaYAMl0WhuHUg0PROspZwRXpKMVfss0qV1rTwETdeTEQGmOxxh52Az5gvXJGu30pPt15PS3ybVfvQGJzMV7tWUZ53vxkomSZnvq7XA4Wf-ik4M84sJTcjhT3ubPEmDSa9IDKt_Ctyizh-FDvAI1Ofzdrf5svV81bB0I/w640-h496/agentic3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 26: &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/agent-email.md&quot;&gt;Agent Email en Cloudflare&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
El punto de inserción natural para la validación es la herramienta personalizada, y a presentada en &lt;i&gt;&lt;b&gt;4.2&lt;/b&gt;&lt;/i&gt;. Su esquema de entrada, declarado y válido, rechaza llamadas con forma inesperada antes de ejecutar nada. Su cuerpo es el lugar donde la propia documentación sugiere validar entradas, &lt;a href=&quot;https://github.com/cloudflare/skills&quot;&gt;Redactar información sensible o comprobar autorización antes de hacer el trabajo&lt;/a&gt;. Esa redacción de información sensible es, precisamente, en control de salida al filtrar lo que vuelve al agente o sale hacia un servicio. &lt;br /&gt;&lt;br /&gt;
Para la &lt;a href=&quot;https://developers.cloudflare.com/sandbox/api/commands/&quot;&gt;ejecución de comandos&lt;/a&gt;, el &lt;i&gt;&lt;b&gt;Sandbox SDK&lt;/b&gt;&lt;/i&gt; ofrece una mitigación concreta contra la inyección de shell: pasar los datos por la entrada estándar en lugar de interpolarlos en el comando, lo que permite procesar entrada de usuario sin riesgo de inyección.&amp;nbsp;&lt;span style=&quot;text-align: left;&quot;&gt;La documentación lo ilustra con un caso donde una cadena maliciosa, pasada por entrada estándar, resulta inofensiva, mientras que incrustada en el comando sería peligrosa. El propio modelo de responsabilidad del &lt;i&gt;&lt;b&gt;Sandbox&lt;/b&gt;&lt;/i&gt; sitúa además la validación y el saneamiento de entradas explícitamente del lado de quien despliega, no de la plataforma (Cloudflare, 2026u).&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://developers.cloudflare.com/sandbox/api/commands/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1018&quot; data-original-width=&quot;1344&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEglI2_slpVdnojxJLiMaN14hdTMHixE_8QgJ3Qjf1y6owUR2LXZW1GXgaraBraQNxDFmQpYu37NrDpyQAxkN0cmZ8YLsgmvGt1JCHTGynrswP9jx0TtCJIpRidWxWSn-alvYfGXTwvCfez3YrcS2Y4U25Kmw_oQDuDEo-djWRSDSrwdDJ_QrMfE/w640-h484/agente4.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 27: &lt;a href=&quot;https://developers.cloudflare.com/sandbox/api/commands/&quot;&gt;Cloudflare Commands en Sandbox&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
Y en la dimensión de salida, el ecosistema de &lt;a href=&quot;https://www.cloudflare.com/es-es/sase/&quot;&gt;Cloudflare One&lt;/a&gt; aporta control sobre el canal de los servidores &lt;i&gt;&lt;b&gt;MCP&lt;/b&gt;&lt;/i&gt;, por el que el agente invoca herramientas externas.&amp;nbsp;&lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/access-controls/ai-controls/mcp-portals/&quot; style=&quot;text-align: left;&quot;&gt;El portal de servidores MCP permite curar qué herramientas quedan expuestas&lt;/a&gt;&lt;span style=&quot;text-align: left;&quot;&gt; (desactivando herramientas individuales o derivando a una lista de permitidos para mostrar solo un subconjunto) y somete el acceso a cada servidor a la identidad corporativa, imponiendo a qué servidores accede cada quién con independencia de las políticas del propio servidor.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: left;&quot;&gt;Además, registra las peticiones individuales realizadas con las herramientas del portal. Curar el canal y auditarlo es, en este contexto, una forma de control sobre lo que el agente puede llegar a enviar a través de él.&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;u&gt;
Continuando la maduración Zero Trust. &lt;br /&gt;&lt;/u&gt;&lt;br /&gt;
El primer avance de maduración consiste en reforzar progresivamente el filtro de entrada. Un punto de partida razonable es validar formatos contra esquemas esperados, imponer longitudes máximas y rechazar entradas manifiestamente malformadas.&amp;nbsp;&lt;span style=&quot;text-align: left;&quot;&gt;Sobre esa base, incorporar detección de patrones de ataque conocidos y filtrado de cargas codificadas y en los entornos más exigentes, delimitar de forma explícita el contenido no confiable para que el modelo lo trate como inseguro (la técnica de &lt;/span&gt;&lt;i style=&quot;text-align: left;&quot;&gt;&lt;b&gt;spotlighting&lt;/b&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;).&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: left;&quot;&gt;El &lt;/span&gt;&lt;a href=&quot;https://claude.com/blog/zero-trust-for-ai-agents&quot; style=&quot;text-align: left;&quot;&gt;eBook de Anthropic&lt;/a&gt;&lt;span style=&quot;text-align: left;&quot;&gt; describe esta progresión y aporta criterios concretos para cada estadio&amp;nbsp; de forma coherente con el principio &lt;/span&gt;&lt;i style=&quot;text-align: left;&quot;&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt; de no confiar en la entrada y filtrarla en la frontera.&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
El segundo avance es tratar todo el canal por el que entra el contenido externo (correo, web, resultado de herramientas) como no confiable por defecto, e interponer en cada uno un punto de validación antes de que su contenido alcance el contexto del agente. La forma natural de lograrlo en este despliegue es encapsular esos canales tras herramientas personalizadas que validen y cuando proceda, saneen o delimiten el contenido, en lugar de dejar que entre directamente.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;649&quot; data-original-width=&quot;485&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGlxuPvsCIvroRvztIaGw6Munmx4sWMdpXbWYXzTFmt8ZXBxrPSdENqyHKUlKYR2KI2pb48LVg_mLlJhaxy9R9xdnapH4UVUPD8YReOyl22-yhIImdXUzHRzE8egQuQBBhcoKeOLkbhBuXZe_8OU8hWB0CXFkF4lI2altrnGCW12nY0bXt7hsd/w299-h400/HackingIA_web.jpg&quot; width=&quot;299&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 28:&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking IA: Jailbreak, Prompt Injection, Hallucinations &amp;amp; Unalignment&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;escrito por &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Chema Alonso&lt;/a&gt; con la colaboración de &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/AmadorAparicio&quot; style=&quot;text-align: justify;&quot;&gt;Amador Aparicio&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/ManuelSLemos&quot; style=&quot;text-align: justify;&quot;&gt;Manuel S. Lemos&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;y&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/JPalanco&quot; style=&quot;text-align: justify;&quot;&gt;José Palanco&lt;/a&gt; en &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;El tercer avance es simétrico, en la salida: &lt;i&gt;&lt;b&gt;definir qué clases de datos no deben abandonar nunca el entorno&lt;/b&gt;&lt;/i&gt; y materializar esa decisión en los puntos disponibles (la redacción dentro de las herramientas personalizadas y la curaduría y auditoria del canal &lt;i&gt;&lt;b&gt;MCP&lt;/b&gt;&lt;/i&gt;), de modo que la exfiltración quede dificultada incluso si el agente es manipulado para intentarla.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
4.5.- Observabilidad y comportamiento.&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
El principio. &lt;br /&gt;&lt;br /&gt;
Los controles anteriores deciden que puede hacer el agente, la observabilidad nos permite saber está ocurriendo realmente en el sistema. Es un requisito indispensable por el cual pueden verificarse, ajustarse y defenderse los demás controles, ante un incidente.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Por este motivo &lt;a href=&quot;https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf&quot;&gt;CISA eleva la visibilidad y analítica a la categoría de capacidad trasversal de toda arquitectura Zero Trust&lt;/a&gt;. En la práctica, la visibilidad consiste en recopilar y observar la telemetría, los registros y los eventos que generan el entorno. El análisis de esta información es lo que verdaderamente permite actualizar las políticas de acceso, agilizar la respuesta a incidentes y construir un perfil de riesgo para tomar medidas proactivas antes de que el ataque se materialice. &lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot;&gt;NIST, siguiendo la misma línea, sitúa la monitorización continua entre los fundamentos de la arquitectura Zero Trust&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;706&quot; data-original-width=&quot;1532&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjh6M73RzFllISqv4W4cm5-SAGcel9UFeI8kf4IXime_8gDx9oxcRkjOcFz4OYXNHO4IGSnoltkaOwrYuhDNkfjGpBQJIS1ahSDy70fxoLjQqOUACExKJkVS95tKFqTKy41afy8Gbe4jEIBkCOBztNK1dp-TyDw1qrurxit9Ot8AKuOjnkTIW2K/w640-h294/agente6.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 29: &lt;a href=&quot;https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf&quot;&gt;Capacidades Transversales de CISA para Zero Trust&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
En un agente, la obsevabilidad tiene una exigencia añadida, no basta con registrar el resultado de una acción, hay que poder reconstruir la cadena de acciones que llevó a ella (que entrada recibió, qué herramienta invocó, con qué argumentos, con qué resultado). Sólo así puede distinguirse un comportamiento legítimo de uno inducido por una inyección y solo así atribuirse una acción a quien la lanzó. &lt;br /&gt;&lt;br /&gt;&lt;u&gt;
Dónde se sitúa hoy el ecosistema Cloudflare.&lt;br /&gt;&lt;/u&gt;&lt;br /&gt;
El despliegue es en esta dimensión, notablemente sólido, con un posible punto ciego importante que ya se ha señalado. &lt;br /&gt;&lt;br /&gt;
La sesión es, por diseño, un registro. Como se describió en la sección 3, &lt;a href=&quot;https://platform.claude.com/docs/en/managed-agents/overview&quot;&gt;el historial de eventos de cada sesión persiste y se puede recuperar íntegro&lt;/a&gt;: la conversación, los turnos, los resultados de herramientas. La sesión no es solo ejecución, es también su propia bitácora. &lt;br /&gt;&lt;br /&gt;
Sobre el acceso al panel, cuando se coloca &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/securing-access.md&quot;&gt;Cloudflare Access&lt;/a&gt; delante, se obtiene un registro de auditoria sin escribir código: &lt;i&gt;&lt;b&gt;Access&lt;/b&gt;&lt;/i&gt; registra cada petición autenticada, lo que resulta útil cuando una sesión hace algo sorprendente y se quiere saber quién la lanzó. La identidad de quien opera queda ligada a lo que la sesión hace. &lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/securing-access.md&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1370&quot; data-original-width=&quot;1752&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjaKXr73wKoxhdYXROgfeAL_N56txxxh1REHgWxjT-7Q9__HXlhGRoISgXVlPV-y3QwfSX0LmiBdj4UfouCRshK8qp82qvYKKWiqwnF-GQxGLmElYnzZGBA2ulvZSBwvnbG7LqHpstkUCIoBFqdvT0lH7zyi8ukgyDG4gSFMa2yHdBdgH3S-55o/w640-h500/agente9.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 30: &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/securing-access.md&quot;&gt;Securing Access&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
Sobre el comportamiento interno del agente, los dos &lt;i&gt;&lt;b&gt;backends&lt;/b&gt;&lt;/i&gt; ofrecen vías distintas. En &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/isolate-vs-vm-sandboxes.md&quot;&gt;MicroVM existe un terminal en vivo a través del panel&lt;/a&gt;, que permite ver exactamente lo que el agente vio. En &lt;i&gt;&lt;b&gt;Isolate&lt;/b&gt;&lt;/i&gt;, que no tiene &lt;i&gt;&lt;b&gt;shell&lt;/b&gt;&lt;/i&gt;, la observabilidad se obtiene de los registros de &lt;i&gt;&lt;b&gt;Workers&lt;/b&gt;&lt;/i&gt;, donde el despachador de herramientas registra cada nombre de herramienta y su resultado. En ambos casos, la actividad del agente deja rastro consultable. &lt;br /&gt;&lt;br /&gt;
El punto ciego es el ya conocido y aquí cobra todo el sentido: las herramientas del servidor de &lt;i&gt;&lt;b&gt;Anthropic&lt;/b&gt;&lt;/i&gt; se ejecutan fuera de la cuenta de &lt;i&gt;&lt;b&gt;Cloudflare&lt;/b&gt;&lt;/i&gt; y &lt;a href=&quot;https://github.com: https://github.com/cloudflare/claude-managed-agents/blob/main/docs/securing-access.md&quot;&gt;no dejan ninguna traza &lt;/a&gt;(ni registro, ni auditoría). Lo que no se ve no se puede vigilar. Por eso el ecosistema ofrece variantes equivalentes de navegación que &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/browser-rendering-tools.md&quot;&gt;sí recorren en la cuenta propia y cuyas peticiones son observables en los registros de la cuenta&lt;/a&gt;.&amp;nbsp;La diferencia entre una y otra opción es, exactamente, la diferencia entre tener y no tener observabilidad.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;
Continuando la maduración Zero Trust.&lt;br /&gt;&lt;/u&gt;&lt;br /&gt;
El primer avance es centralizar y correlacionar lo que hoy está disponible pero disperso: el historial de eventos de sesión, los registros de acceso de quien la lanzó y los registros del despachador de herramientas. Reunidos y vinculados por el identificador de sesión, permiten reconstruir la cadena completa (quién lanzó qué sesión, qué hizo el agente, con qué herramientas y resultados) que la investigación de un incidente requiere. &lt;br /&gt;&lt;br /&gt;
El segundo avance es eliminar los puntos ciegos por decisión de diseño: preferir, para toda navegación web, las variantes observables que corren en la cuenta propia y mantener desactivadas las que no dejan traza. &lt;i&gt;&lt;b&gt;Una observabilidad con huecos conocidos es una observabilidad que un atacante usará precisamente por esos huecos.&lt;/b&gt;&lt;/i&gt;&lt;br /&gt;&lt;br /&gt; 
El tercer avance lleva la observabilidad del registro pasivo a la detección activa. Disponer de los registros es la base; estadio maduro es analizarlos para construir el perfil de riesgo del que habla la &lt;i&gt;&lt;b&gt;CISA&lt;/b&gt;&lt;/i&gt; (establecer que comportamiento es normal para un agente y alertar sobre desviaciones, como una herramienta que nunca se invoca, de pronto se le hace una llamada o un volumen de salida anómalo) de modo que la observabilidad no sólo explique los incidentes después, sino que ayude a detectarlos mientras ocurren.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
4.6.- Contención y recuperación. &lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
El principio. &lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;
Zero Trust&lt;/b&gt;&lt;/i&gt; asume que las defensas pueden fallar y que un sujeto puede acabar comprometido. Por eso exige, además de prevenir, contener el daño cuando ocurre y poder volver a un estado bueno conocido. La contención busca limitar el radio de alcance (blast radius), es decir que un agente comprometido afecte lo mínimo. Y la recuperación, restaura la operación sin arrastrar el estado corrupto.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://claude.com/blog/zero-trust-for-ai-agents&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;354&quot; data-original-width=&quot;1218&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj_StKNJ74YNzJlfnSE7cK1Q2J92KTKRJuRnK1ZdedH4XhVK6BOZetZu5r4N0_f2L6Qa8JZzm6b2ca85UJCLKqeqKOGmq1YKpTtdOj9LylxWmCwo_CUI-RQmMxshvB7R05u0eytuZfPAjazUGurU4a9Q_G38fUGCIvZpW23o5C-ac8Nh-r5yBEN/w640-h186/zero1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 31: &lt;a href=&quot;https://claude.com/blog/zero-trust-for-ai-agents&quot;&gt;Blast Radius&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;La taxonomía &lt;a href=&quot;https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/&quot;&gt;OWASP para aplicaciones agénticas recoge expresamente estos mecanismos&lt;/a&gt;: interruptores de parada, límites de radio de alcance, aislamiento entre el planificador y el ejecutor y contención en tiempo de ejecución, como defensas frente a la propagación de errores y el abuso entre agentes. En un agente, esto se concreta en tres capacidades: poder detenerlo de inmediato cuando se detecta un comportamiento anómalo, acotar por diseño lo que su compromiso pueda alcanzar y restaurar su entorno a un punto limpio si propagar aquello que hubiera quedado corrompido. &lt;br /&gt;&lt;br /&gt;&lt;u&gt;
Dónde se sitúa hoy el ecosistema Cloudflare. &lt;br /&gt;&lt;/u&gt;&lt;br /&gt;
El despliegue ofrece una base de contención y recuperación que cubre las tres capacidades, con un matiz en la resiliencia de la cola de trabajo.&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;
La parada inmediata existe como operación de primera clase&lt;/b&gt;: entre las funciones que el plano de control ejerce con su credencial está la de &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents&quot;&gt;forzar la detención de una sesión&lt;/a&gt;. Hay, además, una contención por diseño que opera sola: &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/snapshots-and-state-persistence.md&quot;&gt;las sesiones no se ejecutan indefinidamente, sino que se detienen automáticamente tras un periodo de inactividad&lt;/a&gt;. Una sesión olvidada no queda viva indefinidamente como superficie de ataque.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;
El aislamiento como contención ya se trató&lt;/b&gt;: cada &lt;i&gt;&lt;b&gt;sandbox&lt;/b&gt;&lt;/i&gt; corre en su propia máquina virtual, de modo que el compromiso de uno no alcanza a los demás y la segmentación de salida acota con quién puede comunicarse un agente comprometido. La contención del radio de alcance no es, por tanto, un añadido. Está en la arquitectura.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;La recuperación está cuidadosamente diseñada&lt;/b&gt;: El directorio de trabajo de cada sesión MicroVM se preserva mediante copias a almacenamiento de objetivos, que se restauran al reanudar. &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/snapshots-and-state-persistence.md&quot;&gt;Isolate persiste su estado de forma transparente&lt;/a&gt;. Y el diseño es defensivo en un punto importante: nunca se restuaran sobre un contenedor en ejecución y si una restauración falla, el sistema registra el fallo y arranca con un directorio limpio en lugar de bloquearse. Es una recuperación que prioriza no propagar el estado dañado.&lt;/li&gt;&lt;/ul&gt;
El matiz que señalar está en la resiliencia de la cola de trabajo del entorno de ejecución. La documentación del sistema de colas advierte de que no existe una cola de mensajes fallidos. &lt;a href=&quot;https://developers.cloudflare.com/agents/runtime/execution/retries/&quot;&gt;Una tarea que falla se elimina y se recomienda implementar la persistencia propia, los reintentos bloquean la cabeza de la cola y no hay un cortacircuitos&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;
Continuando con la maduración Zero Trust&lt;br /&gt;&lt;/u&gt;&lt;br /&gt;
El primer avance es &lt;b&gt;&lt;u&gt;convertir la parada manual en respuesta automática&lt;/u&gt;&lt;/b&gt;: vincular la detección de comportamiento anómalo (del control de observabilidad) con la función de detención, de modo que una desviación grave no dependa de que un humano esté mirando. Es el interruptor de parada &lt;i&gt;&lt;b&gt;OWASP&lt;/b&gt;&lt;/i&gt; llevado a su forma efectiva, disparado por una señal, no solo por una persona.&lt;br /&gt;&lt;br /&gt;
El segundo avance es &lt;b&gt;&lt;u&gt;endurecer el radio de alcance combinando los controles ya descritos&lt;/u&gt;&lt;/b&gt;: segmentación de salida estricta, identidades de alcance acotado e inyección de credenciales que el agente no custodia. Cada uno reduce lo que un compromiso puede tocar; juntos, materializan el límite del radio de alcance que pide la taxonomía agé&lt;span style=&quot;text-align: left;&quot;&gt;ntica.&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/snapshots-and-state-persistence.md&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;738&quot; data-original-width=&quot;1732&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh4U5uKhTi6uMZLv4y4oPixxqahdGCDuNuoh8X08q9rpOtAMX4MyYAY5O8lUmSHeE8TxHiKdSSfEUefkzPXKsKtfJiFThdpu11Sdy6HQRCdxyM4qPOynvfxfmn1sD8YyNYSjT4-bNbxC2rurmoGjqW0XBHl2Ir8n3jPCMA-bxzpfkIIuZxorzEq/w640-h272/Agente8.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 32: &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/snapshots-and-state-persistence.md&quot;&gt;Snapshots &amp;amp; Persistencia en Cloudflare&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;El tercer avance atañe a la &lt;b&gt;&lt;u&gt;resiliencia de las tareas y a la retención de los datos de recuperación&lt;/u&gt;&lt;/b&gt;. Por un lado, implementar la persistencia propia de las tareas críticas que la cola no garantiza, de modo que un fallo no las pierda en silencio. Por otro, gobernar la retención de las copias automáticamente, así que &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/snapshots-and-state-persistence.md&quot;&gt;definir y aplicar una política de retención es responsabilidad de quien despliega&lt;/a&gt;, un punto que enlaza directamente con la gobernanza de datos de la sección siguiente.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Termina en:&amp;nbsp;&lt;a href=&quot;https://www.elladodelmal.com/2026/08/como-desplegar-zero-trust-para-agentes_0480428510.html&quot;&gt;Cómo desplegar Zero Trust para Agentes IA en Cloudflare (y 4)&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div align=&quot;justify&quot;&gt;Un saludo,&amp;nbsp; &amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Autor&lt;/i&gt;: &lt;a href=&quot;https://mypublicinbox.com/Juaco507&quot;&gt;&lt;b&gt;Juan Luis Cuenca Ramos&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/Juaco507&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1663&quot; data-original-width=&quot;2060&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjM_ZyyqgoKziGKdraQ385RU1I1ukTztLSFAOaSUsZ8ksPUgQCpTWCSDysw0cDQ6q8VCgLJEptJDsmyXKjRUiEnGasa7TKqRIqdJW1ws38QadfKczE9mjrz2w_5Lvduck0_XlSkWKtpBI3zWofsZX7u050aiAAh-elyvUn8hU9ZerPM-cJWAtxh/w640-h516/juanluiscuenca.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://mypublicinbox.com/Juaco507&quot;&gt;Contactar con Juan Luis Cuenca Ramos&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/como-desplegar-zero-trust-para-agentes.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZ-V3VZVk-U_ocTPehBRqSwg5X7ozdutPsaMPf8HMcfj9rk0IwZmThnljq0FhVQ5BDxK6_ElsUJfpmz2SjwGKcm4sagUYo-PC5GwN00ykBv76I81yRYYXhN4wD5AkkZGgT13KGwKpkXsT0E3cD0sX3g1urwZMx4XErTlIGAEDRuocV4eGv1zGu/s72-w640-h382-c/Agent0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-2059806350898302658</guid><pubDate>Mon, 03 Aug 2026 06:46:06 +0000</pubDate><atom:updated>2026-08-03T08:46:06.096+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">charlas</category><category domain="http://www.blogger.com/atom/ns#">ciberseguriad</category><category domain="http://www.blogger.com/atom/ns#">cloudflare</category><category domain="http://www.blogger.com/atom/ns#">conferencia</category><category domain="http://www.blogger.com/atom/ns#">conferencias</category><category domain="http://www.blogger.com/atom/ns#">Eventos</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">IA</category><category domain="http://www.blogger.com/atom/ns#">Inteligencia Artificial</category><title>Digi Americas LATAM CISO Summit 2026: 11 de Septiembre estaré en México</title><description>&lt;div style=&quot;text-align: justify;&quot;&gt;Hace mucho, mucho, mucho tiempo que no doy una conferencia en &lt;i&gt;&lt;b&gt;México&lt;/b&gt;&lt;/i&gt;, y la verdad es que ya tenía ganas de regresar. Y será en &lt;i&gt;&lt;b&gt;Septiembre&lt;/b&gt;&lt;/i&gt;, ya que estaré como ponente en el&amp;nbsp;&lt;a href=&quot;https://events.digiamericas.org/Summit2026&quot;&gt;Digi Americas LATAM CISO Summit 2026, que tiene lugar en Cancún del 10 al 12 de Septiembre&lt;/a&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://events.digiamericas.org/Summit2026&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;524&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBBIXhcuEDj5Lk2BG_IihWIega8TXIBUufcBFh11JdXINaa0fOVO8JqPuvqhC5JZrsVxK6wHIOc3wMg8zeNTg5KsYCWBW0TcZLFjQBRLWM2QxDndB3XOfGdHLE22TBr65xPIwaEF7DMaXUJXhhEdv58upQ2w3kNhj6wfwf2D6oEgoHXuKnR8tx/w640-h356/ciso0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;&lt;a href=&quot;https://events.digiamericas.org/Summit2026&quot;&gt;Digi Americas LATAM CISO Summit 2026:&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://events.digiamericas.org/Summit2026&quot;&gt;11 de Septiembre estaré en México&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;La lista de ponentes es espectacular, con&amp;nbsp;&lt;i&gt;&lt;b&gt;Adolfo Fabrega,&amp;nbsp;Alberto Yépez,&amp;nbsp;Alexandra Rose,&amp;nbsp;Altagracia Gomez,&amp;nbsp;André Molina,&amp;nbsp;Ariel Waissbein, H.E. Ivan Duque,&amp;nbsp;H.E. Toomas Hendrik Ilves,&amp;nbsp;Heidy Rocha,&amp;nbsp;Julissa Cruz Abreu&lt;/b&gt;&lt;/i&gt; como ponentes destacados de una enorme lista.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://events.digiamericas.org/Summit2026&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1482&quot; data-original-width=&quot;1720&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjCLmQXc3SPX27pp1-8b3kV_UEAGJaVkEGJULks9Ly6u8xxB7cSlAR4p8qOWUHZp23DjqTTAAKU3pVrbntVk4h0wzHuv6M1l3rJ8UXDnZo7LDEzR84GftXB9wEx1Lyg8vstyMdt32TviQj8AfCHUqT4fQ0i1ZFmJWtRfEwID0j1LxjLlwNENxdE/w640-h552/ciso1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 2: &lt;a href=&quot;https://events.digiamericas.org/Summit2026&quot;&gt;Speakers de Digi Americas LATAM CISO Summit 2026&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Mi charla, en concreto, será el día &lt;u&gt;&lt;b&gt;11 de Septiembre a las 09:50&lt;/b&gt;&lt;/u&gt;, para hablar del mundo del &lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot;&gt;Hacking y la Inteligencia Artificial&lt;/a&gt;, que ya sabéis que es un tema que me tiene absorbido los últimos años, así que será una charla sobre los temas que me apasionan.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://events.digiamericas.org/Summit2026&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;588&quot; data-original-width=&quot;1154&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh8nK6V2oi9Rw7LxmyrKkYnO9jpBgq3JzGjbybXRJShG3QTeG3PxQ9rYqBJRMcXkrM6kmFlvyo40duxjZapEXXBfFq1Pvjl7GvF67ITY5fueDEIQB66faNB8PhiHB5eXAzHDhI8n2C3UyLwf5pD0YQtmXYsS5pogt1NZZJ0iMrYu7uPP5eAGhjp/w640-h326/ciso3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 4: &lt;a href=&quot;https://events.digiamericas.org/Summit2026&quot;&gt;Mi charla en el&amp;nbsp;Digi Americas LATAM CISO Summit 2026&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Pero ya que estoy allí, tendré reuniones, me haré las fotos que pueda, y lo mismo me llevaré algunos de mis libros de&amp;nbsp;&lt;span style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking IA: Jailbreak, Prompt Injection, Hallucinations &amp;amp; Unalignmen&lt;/a&gt;&lt;/span&gt;&amp;nbsp;por si alguien los quiere tener, ya que voy a estar por allí.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;649&quot; data-original-width=&quot;485&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGlxuPvsCIvroRvztIaGw6Munmx4sWMdpXbWYXzTFmt8ZXBxrPSdENqyHKUlKYR2KI2pb48LVg_mLlJhaxy9R9xdnapH4UVUPD8YReOyl22-yhIImdXUzHRzE8egQuQBBhcoKeOLkbhBuXZe_8OU8hWB0CXFkF4lI2altrnGCW12nY0bXt7hsd/w299-h400/HackingIA_web.jpg&quot; width=&quot;299&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 5:&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking IA: Jailbreak, Prompt Injection, Hallucinations &amp;amp; Unalignment&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;escrito por &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Chema Alonso&lt;/a&gt; con la colaboración de &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/AmadorAparicio&quot; style=&quot;text-align: justify;&quot;&gt;Amador Aparicio&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/ManuelSLemos&quot; style=&quot;text-align: justify;&quot;&gt;Manuel S. Lemos&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;y&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/JPalanco&quot; style=&quot;text-align: justify;&quot;&gt;José Palanco&lt;/a&gt; en &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Así que, si estás por &lt;i&gt;&lt;b&gt;México&lt;/b&gt;&lt;/i&gt;, o por la región, y estabas pensando en ir al&amp;nbsp;&lt;a href=&quot;https://events.digiamericas.org/Summit2026&quot;&gt;Digi Americas LATAM CISO Summit 2026&lt;/a&gt;, que sepas que yo estaré por allí. Y si quieres que nos reunamos, que te lleve o un libro, o solo verme, puedes &lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;contactar conmigo para ello&lt;/a&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;¡Saludos Malignos!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;Chema Alonso &lt;/b&gt;(&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;Contactar con Chema Alonso&lt;/a&gt;) &amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; font-style: italic; text-align: center;&quot;&gt;
&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;444&quot; data-original-width=&quot;800&quot; src=&quot;https://1.bp.blogspot.com/-wPU2d-hy3rM/XiyVNgM4kGI/AAAAAAAAy70/Pk1IP6-v7bQLVUNL2iWneVOgRP494eWrACLcBGAsYHQ/s640/MPICHemaalonso.jpg&quot; width=&quot;450&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/digi-americas-latam-ciso-summit-2026-11.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjBBIXhcuEDj5Lk2BG_IihWIega8TXIBUufcBFh11JdXINaa0fOVO8JqPuvqhC5JZrsVxK6wHIOc3wMg8zeNTg5KsYCWBW0TcZLFjQBRLWM2QxDndB3XOfGdHLE22TBr65xPIwaEF7DMaXUJXhhEdv58upQ2w3kNhj6wfwf2D6oEgoHXuKnR8tx/s72-w640-h356-c/ciso0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-7568666813688494430</guid><pubDate>Sun, 02 Aug 2026 04:01:00 +0000</pubDate><atom:updated>2026-08-02T06:01:00.107+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Agentic</category><category domain="http://www.blogger.com/atom/ns#">Agentic AI</category><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">Eventos</category><category domain="http://www.blogger.com/atom/ns#">IA</category><category domain="http://www.blogger.com/atom/ns#">MyPublicInbox</category><category domain="http://www.blogger.com/atom/ns#">Música</category><title>El Agente AI Musical que trae los Conciertos de los Músicos en MyPublicInbox</title><description>&lt;div style=&quot;text-align: justify;&quot;&gt;Desde comienzo de este año &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox&lt;/a&gt; está transformándose con &lt;i&gt;&lt;b&gt;&lt;u&gt;Agenteic AI Ops&lt;/u&gt;&lt;/b&gt;&lt;/i&gt;, para incrementar la experiencia de uso, automatizar tareas, potenciar más a los perfiles públicos y dotar cada vez de más capacidades a todos los usuarios. Hace poco os hablaba de &lt;a href=&quot;https://www.elladodelmal.com/2026/07/mypublicgpt-tu-huella-digital-en-los.html&quot;&gt;MyPulicGPT para que los perfiles públicos puedan conocer su huella digital en los buscadores de IA&lt;/a&gt;, y del &lt;a href=&quot;https://www.elladodelmal.com/2026/07/como-sacar-partido-la-nueva-direccion.html&quot;&gt;Canal eMail de MyPublicInbox&lt;/a&gt;, y hoy os hablo de nuestro &lt;b&gt;&lt;u&gt;Agente IA Musical&lt;/u&gt;&lt;/b&gt;, que se encarga de mantener actualizada la agenda de conciertos de todos los músicos de la plataforma.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/publicprofiles/musica&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;626&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnB9rRBg8vNAmppUk8-D5Q_cWRVp4bPa4VedCd9lhMOD-hRBpCEipOiWUm9sphzD1Ntmpx4Y8Bgsgz_33M3cPpuJL6Fl1tAdHcnSO7nsgznouygfNEFMYsUQzzaAtyk591_8NKUcQQaQRo_gVodxxYfZXHQGFsON_GM5vLkxWPTGXU2zzwuCvl/w640-h426/conciertos0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;&lt;a href=&quot;https://mypublicinbox.com/publicprofiles/musica&quot;&gt;El Agente AI Musical que trae los Conciertos de los Músicos en MyPublicInbox&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Como ya sabéis, a principio de año os anunciamos que &lt;a href=&quot;https://www.elladodelmal.com/2026/03/the-show-must-go-on-mypublicinbox.html&quot;&gt;MyPublicInbox había adquirido la plataforma LinkMusic&lt;/a&gt;, con el objetivo de incrementar los servicios en nuestro vertical de música. Hoy, gracias a nuestro &lt;b&gt;&lt;u&gt;Agente AI musical,&lt;/u&gt;&lt;/b&gt; estamos actualizado los miles de conciertos que dan los &lt;a href=&quot;https://mypublicinbox.com/publicprofiles/musica&quot;&gt;músicos de MyPublicInbox&lt;/a&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/DavidSummers&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1980&quot; data-original-width=&quot;3270&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhTFrktUO7PMY-od21-bfJm-_QnZfgQvbVCeO7KphCNOycZXTuxQGxMNbpdgIlFcBjI6qbe2Ts8t8em-Ygcmu4H2utNtuYoTqVdwoE-fxUyTRKFiNra6s90NDoatdaSvsDFbmpcpPCUlHo-99M98cVt0mq5O-eKdlOBR6WiKvPFPdoCofPq2p8y/w640-h388/conciertos1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 2: &lt;a href=&quot;https://mypublicinbox.com/DavidSummers&quot;&gt;Conciertos de David Summers en su perfil&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Los podéis ver en el perfil de cada usuario, como podéis ver con &lt;a href=&quot;https://mypublicinbox.com/DavidSummers&quot;&gt;David Summers y su gira de Hombres G&lt;/a&gt;, en la parte derecha de su buzón púbico, pero con una sección para poder ver todos los que ya están publicados.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/DavidSummers&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1806&quot; data-original-width=&quot;1798&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiDuSt58fQ-E_HXyad91VwUnjbk_04SqCwLUaQ7nFSosHxhYLmCBGxZ10czfBIp6qij-zSdcgZGhMpdKk5Ww6eFzUDwkPBr3gltkx05cK6j68E2gI4wCH0mZMdkakobp4n9tN5uwGVgiW4Gey16NThvcxvABSSFcmf0RO_5Gre28pvHDGrNrExY/w638-h640/conciertos2.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 3: &lt;a href=&quot;https://mypublicinbox.com/DavidSummers&quot;&gt;Sección de Conciertos completa de David Summers&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Por ejemplo, mis queridos &lt;a href=&quot;https://www.mypublicinbox.com/despistaos&quot;&gt;Despistaos&lt;/a&gt;, que comienzan su pedazo de &lt;a href=&quot;https://www.despistaos.com/gira/&quot;&gt;Gira de &quot;Un millón de Madrugadas&quot;&lt;/a&gt;, tienen ya también publicadas todas sus fechas en le buzón del grupo.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.despistaos.com/gira/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1386&quot; data-original-width=&quot;1698&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjSqyvLeiX4yE-1XkTYCsiMPs9vmhcbuB2xYOmkKtG-_9-QV1PK0dG7F2GBzqrd0pG357fl82r-0WrGi9TspBNKtzxwHK4c7_mAymLJJdls1om_XUZWj-svcC1at0HgzXoEc3ygvJJsKrYwpmPxR-rY520pHc2nxCy3FSvXI_qoZqHrW9yB1BpL/w640-h522/Conciertos3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 4: &lt;a href=&quot;https://www.mypublicinbox.com/despistaos&quot;&gt;Gira de &quot;Un millón de madrugadas&quot; de Despistaos&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Pero también se irá publicando en cada uno de los miembros de la banda, como en este caso el gran &lt;a href=&quot;https://mypublicinbox.com/Krespo&quot;&gt;Krespo&lt;/a&gt;, gracias a que nuestro &lt;b&gt;&lt;u&gt;Agente IA Musical&lt;/u&gt;&lt;/b&gt; está buscando cómo potenciar al máximo los trabajos de los perfiles púbicos.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/Krespo&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1682&quot; data-original-width=&quot;1856&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWn4hzky6irKX1ug3Y_bNQkT-d-IztuDkUQVzhZGnxlMMJPwtuUraDNayhYBJT54EQ3tW_5lxFqqlfuOet6iVCUltoVaCoGXZTF_RYX9LKRn0hk9NVM2JYJrIYnVuku1cgOzyqgC5mcJ2WR4HP5zpmmCGR7iB40Q1NEpr_xH9JQJUjkZu9Ag9q/w640-h580/Conciertos4.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 5: &lt;a href=&quot;https://mypublicinbox.com/Krespo&quot;&gt;Conciertos de Krespo&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Y para todos los demás, pues una forma de que no se te escape nada. De hecho, si sigues a uno de los músicos, la plataforma te enviará un mensaje interno para avisarte cuándo se ha producido la publicación de nuevos conciertos, para que no se te escape nada de lo que hacen los &lt;a href=&quot;https://mypublicinbox.com/publicprofiles/musica&quot;&gt;músicos de MyPublicInbox&lt;/a&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;¡Saludos Malignos!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;Chema Alonso &lt;/b&gt;(&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;Contactar con Chema Alonso&lt;/a&gt;) &amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; font-style: italic; text-align: center;&quot;&gt;
&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;444&quot; data-original-width=&quot;800&quot; src=&quot;https://1.bp.blogspot.com/-wPU2d-hy3rM/XiyVNgM4kGI/AAAAAAAAy70/Pk1IP6-v7bQLVUNL2iWneVOgRP494eWrACLcBGAsYHQ/s640/MPICHemaalonso.jpg&quot; width=&quot;450&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/el-agente-ai-musical-que-trae-los.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgnB9rRBg8vNAmppUk8-D5Q_cWRVp4bPa4VedCd9lhMOD-hRBpCEipOiWUm9sphzD1Ntmpx4Y8Bgsgz_33M3cPpuJL6Fl1tAdHcnSO7nsgznouygfNEFMYsUQzzaAtyk591_8NKUcQQaQRo_gVodxxYfZXHQGFsON_GM5vLkxWPTGXU2zzwuCvl/s72-w640-h426-c/conciertos0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-7041783466891036184</guid><pubDate>Sat, 01 Aug 2026 05:07:00 +0000</pubDate><atom:updated>2026-08-01T07:07:00.113+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">Artificial Intelligence</category><category domain="http://www.blogger.com/atom/ns#">bias</category><category domain="http://www.blogger.com/atom/ns#">IA</category><category domain="http://www.blogger.com/atom/ns#">Inteligencia Artificial</category><title>La ética como “Safety Net”: Por qué la IA responsable acelera la innovación (y no la frena)</title><description>&lt;div align=&quot;justify&quot;&gt;Cuando se habla de ética y regulación de la inteligencia artificial, la reacción más habitual -también entre gente muy sensata- es pensar en un freno. Un comité más, un formulario más, un abogado más entre la idea y el producto. Yo llevo defendiendo justo lo contrario desde hace años, y con &lt;a href=&quot;http://RAIGHT.ai&quot;&gt;RAIGHT.ai&lt;/a&gt;, la startup que he cofundado junto a &lt;i&gt;&lt;b&gt;Miguel Ángel Liébanas&lt;/b&gt;&lt;/i&gt;, &lt;i&gt;&lt;b&gt;Laura González&lt;/b&gt;&lt;/i&gt;, &lt;a href=&quot;https://www.mypublicinbox.com/RicardoPalomo&quot;&gt;Ricardo Palomo&lt;/a&gt; e &lt;a href=&quot;https://www.mypublicinbox.com/IdoiaSalazar&quot;&gt;Idoia Salazar&lt;/a&gt;, hemos intentado demostrarlo con una plataforma, no solo con argumentos.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmL7iQ6_uN437OpSol3-wZxSSkFfceYg8ZglpWWRdyuZ7rEOp_lSKV3Paclxp_yI1_weXszJFoMKlkykYjib9rNYQAnDL2Tm7sgpgbQA5i08lO7U8i2JYux7mhRQaDGWvYWHyggBKEIAV7mdlRis71jBnDGmgDr4eIY8CI2kKwwtl-BtOlhu0z/s800/raight0.jpg&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;732&quot; data-original-width=&quot;800&quot;  src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmL7iQ6_uN437OpSol3-wZxSSkFfceYg8ZglpWWRdyuZ7rEOp_lSKV3Paclxp_yI1_weXszJFoMKlkykYjib9rNYQAnDL2Tm7sgpgbQA5i08lO7U8i2JYux7mhRQaDGWvYWHyggBKEIAV7mdlRis71jBnDGmgDr4eIY8CI2kKwwtl-BtOlhu0z/w640-h586/raight0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;&lt;a href=&quot;http://raight.ai/&quot;&gt;La ética como “Safety Net” - Por qué la IA&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;http://raight.ai/&quot;&gt;responsable acelera la innovación (y no la frena)&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
La tesis es sencilla: la &lt;b&gt;&lt;u&gt;ética by design&lt;/u&gt;&lt;/b&gt; no es un obstáculo para innovar rápido, es la condición para poder hacerlo con seguridad. Y como en tantas cosas de la vida, conviene explicarlo con sobriedad holandesa, sin caer ni en el alarmismo (“&lt;i&gt;&lt;b&gt;la IA nos va a destruir&lt;/b&gt;&lt;/i&gt;”) ni en la ingenuidad (“&lt;i&gt;&lt;b&gt;ya se regulará solo&lt;/b&gt;&lt;/i&gt;”).&lt;br /&gt;&lt;br /&gt;&lt;u&gt;&lt;b&gt;
El problema: demasiados principios, poca práctica&lt;br /&gt;&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
Desde &lt;i&gt;&lt;b&gt;2018&lt;/b&gt;&lt;/i&gt; llevamos trabajando en &lt;i&gt;&lt;b&gt;IA ética&lt;/b&gt;&lt;/i&gt; y responsable, primero desde &lt;a href=&quot;https://www.odiseia.org/en&quot;&gt;OdiseIA&lt;/a&gt;, el observatorio que fundamos en &lt;i&gt;&lt;b&gt;2019&lt;/b&gt;&lt;/i&gt; y que hoy es referencia internacional en la materia. En todo este tiempo hemos visto proliferar recomendaciones —&lt;i&gt;&lt;b&gt;UNESCO, OCDE, Consejo de Europ&lt;/b&gt;&lt;/i&gt;a— y regulaciones, con el &lt;i&gt;&lt;b&gt;AI Act&lt;/b&gt;&lt;/i&gt; europeo a la cabeza.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://raight.ai&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1042&quot; data-original-width=&quot;2128&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhoNIzGKp6_XVuMutiuarnxQcMxtQrPqeEIfxRJUw1Fa6s3vdxkiVIMbqzCFVOZH96kbdQ1s5uFXIuaogG8JauxFWz4gFC_Ha2ktqBAGwdiCzS-QloMCWcuMOoeftjgvhCiMN73aLJYt0geCzoYoJqlT_dBZiUyWc2rdk5MQlI2uUQ3sOxd8x2d/w640-h314/raight1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 2: &lt;a href=&quot;https://raight.ai&quot;&gt;Plataforma RAIGHT&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;Todas apuntan en buena dirección, pero -aparte del &lt;/span&gt;&lt;i style=&quot;text-align: left;&quot;&gt;&lt;b&gt;AI Act&lt;/b&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;- comparten un mismo defecto: se quedan en principios de alto nivel (“&lt;/span&gt;&lt;i style=&quot;text-align: left;&quot;&gt;&lt;b&gt;evitar el sesgo&lt;/b&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;”, “&lt;/span&gt;&lt;i style=&quot;text-align: left;&quot;&gt;&lt;b&gt;garantizar la transparencia&lt;/b&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;”) sin decir cómo hacerlo en un caso de uso concreto.&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://raight.ai&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;936&quot; data-original-width=&quot;1888&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2IsHIPP6vSb1pZiUf8_qyiVJSiAIRmbnux73l_pL8vWFTx1mjNuGqzBhxTMEwIk5yxBjLuAMeVJOT86xvIVfhdmtbSuVvImn8TZNdxCfuyilECt2DW2Fb8Ct2WsXmqQhir2Or8yds0U8kANqoFtUDwXyO_mrslGkAAFfqr8JcfoP5iKeFDF4f/w640-h318/raight4.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 3: &lt;a href=&quot;https://raight.ai&quot;&gt;Gestión centralizada de riesgos de IA&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Es la diferencia entre decirle a un desarrollador “&lt;i&gt;&lt;b&gt;cuidado con el sesgo&lt;/b&gt;&lt;/i&gt;” y decirle “&lt;i&gt;&lt;b&gt;este sistema de selección de personal puede discriminar a mujeres en roles técnicos por el histórico de contrataciones; aquí tienes el requisito concreto para mitigarlo&lt;/b&gt;&lt;/i&gt;”. La primera frase genera ansiedad. La segunda, acción.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
La solución: gobernanza automatizada, con supervisión humana&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;a href=&quot;https://RAIGHT.ai&quot;&gt;RAIGHT.ai&lt;/a&gt; nació en el verano de &lt;i&gt;&lt;b&gt;2024&lt;/b&gt;&lt;/i&gt; para resolver justo ese salto entre la teoría y la práctica. La plataforma parte de un inventario propio de más de &lt;i&gt;&lt;b&gt;800&lt;/b&gt;&lt;/i&gt; riesgos éticos de &lt;i&gt;&lt;b&gt;IA&lt;/b&gt;&lt;/i&gt;, construidos analizando con &lt;i&gt;&lt;b&gt;IA generativa&lt;/b&gt;&lt;/i&gt; más de &lt;i&gt;&lt;b&gt;15.000 &lt;/b&gt;&lt;/i&gt;incidentes reales recogidos por repositorios como el &lt;a href=&quot;https://oecd.ai/en/incidents&quot;&gt;AI Incident Monitor de la OCDE&lt;/a&gt;, el &lt;a href=&quot;https://airisk.mit.edu/&quot;&gt;AI Risk Repository del MIT&lt;/a&gt; o &lt;a href=&quot;https://www.aiaaic.org/&quot;&gt;AIAAIC (AI, Algorithmic and Automation Incidents and Controversies)&lt;/a&gt;.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://raight.ai&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;988&quot; data-original-width=&quot;1978&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj4qAhDqm47wr63BD1R0W9lXXYQfqerdOXLxR-DD529lJn2UONKwPyMeCF2vEKiZURKyRts95IsTnkheUbV_IVQ42yTXbBtmV_3IX1j0TfQ8RFQgNZWjen0zs5ss7iDSfdbpq7CByB_ALAyctJjbSTQX_W2D7wfoCQkmzmr0ITA22MLl-XUugsL/w640-h320/raight2.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;Figura 4: &lt;a href=&quot;https://raight.ai&quot;&gt;Gestión de riesgos accionable&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;A cada riesgo le hemos asociado, también con ayuda de I&lt;i&gt;&lt;b&gt;A generativa&lt;/b&gt;&lt;/i&gt; y revisión humana posterior, los requisitos de mitigación concretos y accionables.&amp;nbsp;&lt;i style=&quot;text-align: left;&quot;&gt;&lt;span style=&quot;font-size: x-small;&quot;&gt;(Ver Benjamins et al., “Responsible AI: from theory to practice”, capítulo del próximo Handbook of AI Ethics de Springer.)&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;El flujo, en la práctica, es este:&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Registro automático del caso de uso:&lt;/b&gt; &lt;i&gt;Se sube documentación del sistema de IA (una ficha técnica, una descripción funcional) y la plataforma extrae automáticamente los datos relevantes.&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Detección inteligente de riesgos:&lt;/b&gt; &lt;i&gt;Con un clic, la plataforma compara el caso de uso contra el inventario y propone los riesgos aplicables. El equipo humano tiene que confirmarlos explícitamente; nada se acepta “a ciegas”, precisamente para evitar el riesgo de sobre-confianza en el propio sistema.&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Lista de requisitos accionable:&lt;/b&gt; &lt;i&gt;Para cada riesgo confirmado, aparecen los requisitos de mitigación correspondientes, documentados, asignados y trazables hasta su resolución.&amp;nbsp;&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;span style=&quot;text-align: left;&quot;&gt;Lo hemos probado, entre otros, con &lt;a href=&quot;https://en.wikipedia.org/wiki/COMPAS_(software)&quot;&gt;COMPAS&lt;/a&gt;, el conocido sistema estadounidense de evaluación de riesgo de reincidencia usado en el ámbito judicial: la plataforma identifica sin dificultad los riesgos de discriminación algorítmica que ya denunciaron periodistas e investigadores hace años, y propone las salvaguardas que deberían haberse aplicado desde el diseño.&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div style=&quot;text-align: left;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://raight.ai&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;906&quot; data-original-width=&quot;1840&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWCyfcbp4GD1W7Vv0bNH4h3JdJOT7rh90ROqDpQ5Y84EOz6ASIwUpny9EpphYSQDWb-nq-sB8dq4RvCohsuwG6rvWYQZDBIAAp8LYhA2ZqZca4j_HQUMsYTE12Jpmh7IvG_B2SMc92M3WCpxSz8x68_qTclgc0sPSGzi3DLpp2QdfnXSPtmjR9/w640-h316/Raight3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 5: &lt;a href=&quot;https://raight.ai&quot;&gt;Identificación Inteligente de riesgos de IA&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;
&lt;br /&gt;&lt;u&gt;&lt;b&gt;
Por qué esto es bueno para el negocio (y no solo para la conciencia)&lt;br /&gt;&lt;/b&gt;&lt;/u&gt;&lt;br /&gt;
Aquí es donde quiero insistir, porque es el mensaje que peor se entiende: &lt;b&gt;&lt;u&gt;la IA responsable no compite con la innovación, la habilita&lt;/u&gt;&lt;/b&gt;. Hay al menos tres razones de peso:&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Innovación más rápida y barata:&lt;/b&gt; &lt;i&gt;Cuando los riesgos se detectan al principio del diseño, corregirlos cuesta una fracción de lo que cuesta hacerlo después del lanzamiento, con la reputación ya dañada. Un equipo que sabe que tiene esta “&lt;b&gt;red de seguridad&lt;/b&gt;” puede permitirse experimentar más, no menos.&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Confianza de clientes y talento:&lt;/b&gt; &lt;i&gt;El 93% de los consumidores valora la responsabilidad social de las empresas que eligen, y el 64% del talento digital prioriza estos valores a la hora de elegir dónde trabajar. En un mercado donde captar y retener talento técnico es una batalla constante, no es un dato menor.&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;Atractivo para inversores:&lt;/b&gt; &lt;i&gt;Cada vez más fondos incorporan criterios ESG a sus decisiones, y la IA ética entra de lleno en la “S” de social. Hay ya rankings, como el de Ranking Digital Rights o el modelo de madurez de la GSMA, que puntúan explícitamente la gobernanza responsable de la IA.&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;
Y hay un cuarto argumento, más pragmático: &lt;u&gt;bajo el AI Act, sólo los sistemas de riesgo alto o limitado tienen obligaciones específicas&lt;/u&gt;. Con una plataforma que registra todos los casos de uso y su perfil de riesgo, una organización puede ir más allá del mínimo regulatorio con un esfuerzo adicional pequeño, y convertir el cumplimiento en un activo de confianza en lugar de en un ejercicio defensivo.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
“Human in the loop”&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
Lo que proponemos con&amp;nbsp;&lt;a href=&quot;https://RAIGHT.ai&quot;&gt;RAIGHT.ai&lt;/a&gt;&amp;nbsp;no es sustituir el criterio humano por un algoritmo que dice &lt;i&gt;&lt;b&gt;“sí”&lt;/b&gt;&lt;/i&gt; o &lt;i&gt;&lt;b&gt;“no”&lt;/b&gt;&lt;/i&gt;. Es automatizar lo automatizable: la búsqueda en un inventario de miles de riesgos conocidos, la generación de la primera versión de los requisitos, para que las personas dediquemos el tiempo a lo que de verdad requiere criterio: decidir, priorizar, y responder por esas decisiones. La supervisión humana no es un trámite en nuestra metodología, es una pieza de diseño.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://raight.ai/contact&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1446&quot; data-original-width=&quot;1748&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjtMIAAI47SjnnRA6r-uEAcqEvBjWkVZw_BHkmmfYiEgZ41Hp1mjtiqY6TGdI7RiqYLRXHLRf2_W0VWnB_Ow5h-pL6YzflGw3KxXSSQV6RT0ZgJG9fPXmiJWrMJ7vbBkA5A6xpP-mgq30ERnZlc_1IN6zqYb3wWMGuqbN5gfmGWB4S43nH_-wWm/w640-h530/raight6.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 6: &lt;a href=&quot;https://raight.ai/contact&quot;&gt;Contacta con nosotros para una Demo de RAIGHT&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
Resumiendo una cita famosa de&lt;i&gt;&lt;b&gt; Johan Cruyff&lt;/b&gt;&lt;/i&gt;, “&lt;i&gt;&lt;b&gt;jugar bien no es dar mil pases, es dar el pase justo en el momento justo&lt;/b&gt;&lt;/i&gt;”. La &lt;i&gt;&lt;b&gt;IA&lt;/b&gt;&lt;/i&gt; responsable no consiste en poner mil controles, sino en poner los controles justos, en el momento justo del ciclo de vida del sistema, es decir, al principio, cuando aún se puede diseñar bien, no al final, cuando solo queda apagar fuegos.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;i&gt;Nota de transparencia: este artículo ha sido redactado con la asistencia de herramientas de IA generativa a partir de material propio (paper académico, presentación corporativa y contenidos de raight.ai), con revisión y edición humana final.&lt;br /&gt;&lt;/i&gt;&lt;br /&gt;&lt;i&gt;Autor&lt;/i&gt;: &lt;i&gt;Dr. &lt;a href=&quot;https://www.mypublicinbox.com/rbenjamins&quot;&gt;Richard Benjamins&lt;/a&gt;, CEO RAIGHT.ai&lt;/i&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.mypublicinbox.com/rbenjamins&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1640&quot; data-original-width=&quot;1608&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEisQLKB3-UzzfIc9neYMrNBqeqQCzfvbkKjKqwJ5wt22tYk8O6PNSPwQ9S6-Gcq2TDNUHAgvzUUQNHT0p-BTu1pSmrPCx75MywPaER5qEmWA32kk-kkR0dp2KzFbXHq1FqcMgstWYwzAG5bJL3nFdK4Y5ghyphenhyphenpIbYXhdt9_GJdSXlv7Rs1wFzbAK/w628-h640/RichardBenjamins.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://www.mypublicinbox.com/rbenjamins&quot;&gt;Contactar con el Dr. Richard Benjamins&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/08/la-etica-como-safety-net-por-que-la-ia.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjmL7iQ6_uN437OpSol3-wZxSSkFfceYg8ZglpWWRdyuZ7rEOp_lSKV3Paclxp_yI1_weXszJFoMKlkykYjib9rNYQAnDL2Tm7sgpgbQA5i08lO7U8i2JYux7mhRQaDGWvYWHyggBKEIAV7mdlRis71jBnDGmgDr4eIY8CI2kKwwtl-BtOlhu0z/s72-w640-h586-c/raight0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-17126032623288711</guid><pubDate>Fri, 31 Jul 2026 05:01:00 +0000</pubDate><atom:updated>2026-07-31T07:01:00.108+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">ciberseguridad</category><category domain="http://www.blogger.com/atom/ns#">curso</category><category domain="http://www.blogger.com/atom/ns#">Cursos</category><category domain="http://www.blogger.com/atom/ns#">formación</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">pentest</category><category domain="http://www.blogger.com/atom/ns#">pentester</category><category domain="http://www.blogger.com/atom/ns#">pentesting</category><title>Bootcamp de Ciberseguridad Defensiva y Ofensiva en HackBySecurity</title><description>&lt;div style=&quot;text-align: justify;&quot;&gt;El próximo mes de &lt;i&gt;&lt;b&gt;Octubre de 2026&lt;/b&gt;&lt;/i&gt; da comienzo el&amp;nbsp;&lt;a href=&quot;https://academy.hackbysecurity.com/curso/40/bootcamp-de-ciberseguridad-defensiva-y-ofensiva&quot;&gt;Bootcamp de Ciberseguridad Defensiva y Ofensiva en HackBySecurity&lt;/a&gt; que se realizará en sesiones los jueves y viernes por la tarde y los sábados por la mañana online, hasta el próximo mes de &lt;i&gt;&lt;b&gt;Marzo de 2027&lt;/b&gt;&lt;/i&gt;, aprendiendo con profesionales que trabajan en ciberseguridad.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://academy.hackbysecurity.com/curso/40/bootcamp-de-ciberseguridad-defensiva-y-ofensiva&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1312&quot; data-original-width=&quot;1962&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjruXkALr6RtCtlOLKZ-BE1o3ryuaxwM2awC7Zc9Jc16rzXbASIgvoejLuCcvKiCHN_W2_l2XtzzmN7AUE0ia9Gpx226oOtzYhqWx1o4S5dIq9y2_tB8xO0nDSWF6pVSQP0652bLsCLMfamk9_kMCOOsqAyWf_AVQauONcnGEnywfQKGsuBZ7cS/w640-h428/bootcamp1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;&lt;a href=&quot;https://academy.hackbysecurity.com/curso/40/bootcamp-de-ciberseguridad-defensiva-y-ofensiva&quot;&gt;Bootcamp de Ciberseguridad Defensiva y Ofensiva en HackBySecurity&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Este&amp;nbsp;&lt;i&gt;&lt;b&gt;bootcmap&lt;/b&gt;&lt;/i&gt; online cuenta con más de &lt;i&gt;&lt;b&gt;100&lt;/b&gt;&lt;/i&gt; horas de sesiones &lt;i&gt;&lt;b&gt;online&lt;/b&gt;&lt;/i&gt; en directo, con acceso a retos de ciberseguridad, un curso de &lt;i&gt;&lt;b&gt;scripting&lt;/b&gt;&lt;/i&gt; con &lt;i&gt;&lt;b&gt;Bash&lt;/b&gt;&lt;/i&gt;, un curso de &lt;i&gt;&lt;b&gt;scripting&lt;/b&gt;&lt;/i&gt; con &lt;i&gt;&lt;b&gt;Python&lt;/b&gt;&lt;/i&gt; y un curso de &lt;i&gt;&lt;b&gt;Metasploit&lt;/b&gt;&lt;/i&gt;. Además, el &lt;i&gt;&lt;b&gt;bootcamp&lt;/b&gt;&lt;/i&gt;, que es de nivel intermedio, tiene cuenta con una sesión de orientación&amp;nbsp; para los asistentes, además de tener &lt;i&gt;&lt;b&gt;1&lt;/b&gt;&lt;/i&gt; año de tutorización y derecho a examen.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://academy.hackbysecurity.com/curso/40/bootcamp-de-ciberseguridad-defensiva-y-ofensiva&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;536&quot; data-original-width=&quot;426&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEisHfbrPsUW3jVRxO2o3kfdLhoiDCuCQEa9XhyphenhyphenzGwUS82HQgniQDuFyM8IHwGedXuLOXzSFsyx9Ntu_T5PnhbmgInZR3yFYC7TRMs8LuCa8n4sqYR6xjjqKce6htSWW-zuiiRcwo6Yk5OEjHWPwXqtxR7nCzDHuaV_ThDVAEVY8xP8LbVJLn17e/w318-h400/Bootcamp4.png&quot; width=&quot;318&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 2: &lt;a href=&quot;https://academy.hackbysecurity.com/curso/40/bootcamp-de-ciberseguridad-defensiva-y-ofensiva&quot;&gt;Contenidos del&amp;nbsp;&lt;span style=&quot;text-align: justify;&quot;&gt;Bootcamp de Ciberseguridad Defensiva y Ofensiva&lt;/span&gt;&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Además, se entregan los libros de &quot;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot;&gt;Hacking IA&lt;/a&gt;&quot; y &quot;&lt;a href=&quot;https://0xword.com/es/libros/236-the-art-of-pentesting.html&quot;&gt;The Art of Pentesting&lt;/a&gt;&quot; para todos los alumnos, junto con &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;2.000 Tempos de MyPublicInbox&lt;/a&gt; para contactar con los &lt;a href=&quot;https://mypublicinbox.com/publicprofiles/seguridad_informatica&quot;&gt;expertos de cibeseguridad&lt;/a&gt; de la plataforma.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;649&quot; data-original-width=&quot;485&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGlxuPvsCIvroRvztIaGw6Munmx4sWMdpXbWYXzTFmt8ZXBxrPSdENqyHKUlKYR2KI2pb48LVg_mLlJhaxy9R9xdnapH4UVUPD8YReOyl22-yhIImdXUzHRzE8egQuQBBhcoKeOLkbhBuXZe_8OU8hWB0CXFkF4lI2altrnGCW12nY0bXt7hsd/w299-h400/HackingIA_web.jpg&quot; width=&quot;299&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 3:&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking IA: Jailbreak, Prompt Injection, Hallucinations &amp;amp; Unalignment&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;escrito por &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Chema Alonso&lt;/a&gt; con la colaboración de &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/AmadorAparicio&quot; style=&quot;text-align: justify;&quot;&gt;Amador Aparicio&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/ManuelSLemos&quot; style=&quot;text-align: justify;&quot;&gt;Manuel S. Lemos&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;y&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/JPalanco&quot; style=&quot;text-align: justify;&quot;&gt;José Palanco&lt;/a&gt; en &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;El &lt;i&gt;&lt;b&gt;bootcamp&lt;/b&gt;&lt;/i&gt; está pensado para recién licenciados en &lt;i&gt;&lt;b&gt;Ingeniería Informática&lt;/b&gt;&lt;/i&gt; o personas que deseen enfocar su carrera profesional al &lt;i&gt;&lt;b&gt;hacking ético&lt;/b&gt;&lt;/i&gt; y el &lt;i&gt;&lt;b&gt;pentensting&lt;/b&gt;&lt;/i&gt;. También para perfiles &lt;i&gt;&lt;b&gt;junior&lt;/b&gt;&lt;/i&gt; que estén ya trabajando pero que requieran de un nivel de especialización mayor; perfiles profesionales con experiencia en algún ámbito de la ingeniería, programación o administración de sistemas y que deseen dar un cambio a su carrera profesional adentrándose en el ámbito del &lt;i&gt;&lt;b&gt;hacking&lt;/b&gt;&lt;/i&gt; ético, y para miembros de las &lt;i&gt;&lt;b&gt;Fuerzas y Cuerpos de Seguridad del Estado&lt;/b&gt;&lt;/i&gt; relacionados con el ámbito de la seguridad de la información y la ciberdelincuencia.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://academy.hackbysecurity.com/curso/40/bootcamp-de-ciberseguridad-defensiva-y-ofensiva&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1320&quot; data-original-width=&quot;1424&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiqyV8DKuYHCJH1x-UEh4J02ctqr_usOeFAfLO3PA6mFNCq3f5e1i1RYFc3J7yjL8nQRWRTaC0eacTrPWQQWuYknVM92tvPwK1TfdIZGd3OECcq12XWf9G7lnMZgxRrXW8IMxryKvr7sq_7YHSrs8emxh7pOw5qJEbBJEM09nTUv94ycLMfulHt/w640-h594/Bootcamp2.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 4: &lt;a href=&quot;https://academy.hackbysecurity.com/curso/40/bootcamp-de-ciberseguridad-defensiva-y-ofensiva&quot;&gt;Equipo docente del&amp;nbsp;Bootcamp de Ciberseguridad Defensiva y Ofensiva&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;El equipo docente es espectacular, con &lt;a href=&quot;https://mypublicinbox.com/PabloGonzalez&quot;&gt;Pablo González&lt;/a&gt;, &lt;a href=&quot;https://mypublicinbox.com/AlvaroNunezRomero&quot;&gt;Álvaro Núñez-Romero&lt;/a&gt;, &lt;a href=&quot;https://www.mypublicinbox.com/AngelNunez&quot;&gt;Ángel A. Núñez&lt;/a&gt;, &lt;a href=&quot;https://mypublicinbox.com/AlexAmorin&quot;&gt;Alejandro Amorín&lt;/a&gt;, &lt;a href=&quot;https://mypublicinbox.com/gwalrock&quot;&gt;Rafa García&lt;/a&gt;, &lt;a href=&quot;https://mypublicinbox.com/AinoaGuillen&quot;&gt;Ainoa Guillén&lt;/a&gt;, &lt;a href=&quot;https://mypublicinbox.com/FranRamirez&quot;&gt;Fran Ramírez&lt;/a&gt;, &lt;a href=&quot;https://mypublicinbox.com/RafaSanchez&quot;&gt;Rafa Sánchez&lt;/a&gt;, &lt;a href=&quot;https://mypublicinbox.com/pplu&quot;&gt;José Luis Martínez&lt;/a&gt;, &lt;a href=&quot;https://mypublicinbox.com/Valenmarman&quot;&gt;Valentín Martín&lt;/a&gt; o &lt;a href=&quot;https://mypublicinbox.com/CarmenTorrano&quot;&gt;Carmen Torrano&lt;/a&gt;, entre otros.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/236-the-art-of-pentesting.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;2717&quot; data-original-width=&quot;2043&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEja6dpXHexIe0bc189aP-z4csAhly2JvM4lQNqMgcZA7Sm_X3i7eKs-_iCymjTafFcjZpXWqqfRj3IoOBBf9rcvZQ4Mud7Ob3zhHkWge_kSwWQFd-OtNjDlCn2RkcnvZAWpueLNUNMGjw1nBYk5r7bKNNN71PFtyuUKHZ4Jx6xBSBV6tgLpt5BU/w301-h400/art2.jpg&quot; width=&quot;301&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;Figura 5: &quot;&lt;/i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://0xword.com/es/libros/236-the-art-of-pentesting.html&quot;&gt;The Art of Pentesting&lt;/a&gt;&quot; El libro de Pablo González en&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;&lt;/i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&lt;i&gt; para formarse como pentester&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;La evaluación final de los alumnos se realizará mediante un &lt;i&gt;&lt;b&gt;Trabajo de Fin de Bootcamp&lt;/b&gt;&lt;/i&gt; que habrá que presentar y defender. Una vez el alumno haya completado el &lt;i&gt;&lt;b&gt;Bootcamp&lt;/b&gt;&lt;/i&gt;, realizado el respectivo proceso de evaluación y superado la calificación mínima de corte, se le remitirá un certificado digital del curso con sus datos. Tienes aquí toda la información del&amp;nbsp;&lt;a href=&quot;https://academy.hackbysecurity.com/curso/40/bootcamp-de-ciberseguridad-defensiva-y-ofensiva&quot;&gt;Bootcamp de Ciberseguridad Defensiva y Ofensiva en HackBySecurity&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;Autor: &lt;a href=&quot;https://www.mypublicinbox.com/MiguelAngelMartin&quot;&gt;Miguel Ángel Martín&lt;/a&gt;, CEO de &lt;a href=&quot;https://academy.hackbysecurity.com/&quot;&gt;HackBySecurity&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.mypublicinbox.com/MiguelAngelMartin&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;557&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjgS1VKlsgOptVbzRuMcXxoPBU5YTlLQya9jHbDnfNXvdi85O0XgY1t0TekN-vVJW32pg4zlKL_3SvBoYNkFsNnQ1nwulSho4Y61sxOxcGEyELD6dNkfuZPswXiL9Pu2SQftOM4/w640-h380/MiguelAngelMartin.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.mypublicinbox.com/MiguelAngelMartin&quot;&gt;Contactar con Miguel Ángel Martín de HackBySecurity&lt;/a&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/07/bootcamp-de-ciberseguridad-defensiva-y.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjruXkALr6RtCtlOLKZ-BE1o3ryuaxwM2awC7Zc9Jc16rzXbASIgvoejLuCcvKiCHN_W2_l2XtzzmN7AUE0ia9Gpx226oOtzYhqWx1o4S5dIq9y2_tB8xO0nDSWF6pVSQP0652bLsCLMfamk9_kMCOOsqAyWf_AVQauONcnGEnywfQKGsuBZ7cS/s72-w640-h428-c/bootcamp1.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-7767081085458224831</guid><pubDate>Thu, 30 Jul 2026 05:01:00 +0000</pubDate><atom:updated>2026-07-30T08:21:09.729+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">CERT</category><category domain="http://www.blogger.com/atom/ns#">ciberseguridad</category><category domain="http://www.blogger.com/atom/ns#">Cybersecurity</category><category domain="http://www.blogger.com/atom/ns#">Malware</category><category domain="http://www.blogger.com/atom/ns#">OSINT</category><category domain="http://www.blogger.com/atom/ns#">ransonware</category><title>MyThreatIntel: Plataforma de Threat Intelligence desde la experiencia en DFIR y Respuesta a Incidentes</title><description>&lt;div align=&quot;justify&quot;&gt;La inteligencia sobre amenazas se ha convertido en una pieza fundamental dentro
de la ciberseguridad moderna. Sin embargo, el principal problema al que se enfrentan hoy los analistas no es la falta de información. Ocurre, de hecho, todo lo contrario: existen demasiadas fuentes, demasiados datos y demasiados contextos dispersos.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj16lBWw-wxc5y73GnGNNgrY0_7uzwArWl5_ko1ltcHC8loyXujtsnMT0GY4oyWiTu-ImxsOiVPp5GNIteoZouCmdG69rG8II9oXHmz0HkX0dFEOpqfOHmfjOh2B66-j0cPfbjtIvb5rXOYyGVwjVWgdkiXIUR6fAg-JJ6JRGRcMhTQhO0nXxz7/s940/T0.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;504&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj16lBWw-wxc5y73GnGNNgrY0_7uzwArWl5_ko1ltcHC8loyXujtsnMT0GY4oyWiTu-ImxsOiVPp5GNIteoZouCmdG69rG8II9oXHmz0HkX0dFEOpqfOHmfjOh2B66-j0cPfbjtIvb5rXOYyGVwjVWgdkiXIUR6fAg-JJ6JRGRcMhTQhO0nXxz7/w640-h344/T0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 1: MyThreatIntel - Plataforma de Threat Intelligence desde&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;la experiencia en DFIR y Respuesta a Incidentes&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
Durante una investigación real, ya sea en un entorno &lt;i&gt;&lt;b&gt;SOC&lt;/b&gt;&lt;/i&gt;, en un servicio de &lt;i&gt;&lt;b&gt;DFIR&lt;/b&gt;&lt;/i&gt;, en tareas de &lt;i&gt;&lt;b&gt;Threat Hunting&lt;/b&gt;&lt;/i&gt; o en un proceso de &lt;i&gt;&lt;b&gt;Cyber Threat Intelligence&lt;/b&gt;&lt;/i&gt;, el analista necesita responder con rapidez a preguntas muy concretas: qué actor está detrás de una campaña, qué infraestructura mantiene activa, si una organización ya ha sido publicada en un portal de &lt;i&gt;&lt;b&gt;ransomware&lt;/b&gt;&lt;/i&gt;, si la extorsión sigue en negociación, si ya ha habido filtración, qué vulnerabilidades se están publicando, qué indicadores se conocen o qué artefactos de &lt;i&gt;&lt;b&gt;malware&lt;/b&gt;&lt;/i&gt; estánrelacionados.
  &lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/libros/162-open-source-intelligence-osint-investigar-personas-e-identidades-en-internet.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;600&quot; data-original-width=&quot;456&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi5NEHhLAxa0mJFlht8mc6TrRYe-bU-bH1TXQmMNBXFkNt-StjC-CuuKHpCStMShoo1iLU1hWWsQzWKsqUNUrBKJHAug9VUnWxe_GfZ8SdDTKtPiNiVQkwdIH4tpDX0ElDj8uBJ0K6Xcbw_qFgGJRopqNaUOiOdFbyPTTxgx4SnZUDZqb5GSg/w304-h400/open-source-intelligence-osint-investigar-personas-e-identidades-en-internet.jpg&quot; width=&quot;304&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;center&gt;&lt;i&gt;Figura 2: &lt;a href=&quot;https://0xword.com/libros/162-open-source-intelligence-osint-investigar-personas-e-identidades-en-internet.html&quot;&gt;Open Source INTelligence (OSINT): Investigar personas e Identidades&lt;/a&gt;&lt;/i&gt;&lt;/center&gt;&lt;center&gt;&lt;i&gt;&lt;a href=&quot;https://0xword.com/libros/162-open-source-intelligence-osint-investigar-personas-e-identidades-en-internet.html&quot;&gt;&amp;nbsp;en Internet 2ª Edición&lt;/a&gt; de &lt;a href=&quot;https://0xword.com&quot;&gt;0xWord&lt;/a&gt;, escrito por &lt;a href=&quot;https://mypublicinbox.com/VicenteAguileraDiaz&quot;&gt;Vicente Aguilera&lt;/a&gt; y &lt;a href=&quot;https://www.mypublicinbox.com/carlos_seisdedos&quot;&gt;Carlos Seisdedos&lt;/a&gt;&lt;/i&gt;&lt;/center&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;
El problema es que esa información rara vez se encuentra en un único lugar. Normalmente está repartida entre &lt;i&gt;&lt;b&gt;Data Leak Sites&lt;/b&gt;&lt;/i&gt;, bases de datos de vulnerabilidades, repositorios de &lt;i&gt;&lt;b&gt;IoCs&lt;/b&gt;&lt;/i&gt;, servicios &lt;i&gt;&lt;b&gt;Onion&lt;/b&gt;&lt;/i&gt;, mercados de la &lt;i&gt;&lt;b&gt;Darknet&lt;/b&gt;&lt;/i&gt;, fuentes &lt;a href=&quot;https://0xword.com/libros/162-open-source-intelligence-osint-investigar-personas-e-identidades-en-internet.html&quot;&gt;OSINT&lt;/a&gt;, catálogos de malware y repositorios de filtraciones. El resultado es un coste operativo claro: una parte muy importante del tiempo no se dedica a analizar, sino a buscar, ordenar y contextualizar. De esa necesidad nace &lt;a href=&quot;https://mythreatintel.com/&quot;&gt;MyThreatIntel&lt;/a&gt;, una plataforma pensada para reducir esa fricción y ayudar a que la inteligencia llegue al analista de una manera más estructurada, más rápida y más útil.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Una plataforma orientada al contexto&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://mythreatintel.com/&quot;&gt;MyThreatIntel&lt;/a&gt; no se diseñó como un simple agregador de datos ni como un panel más de ciberseguridad. La idea era más ambiciosa: construir una plataforma capaz de obtener información desde fuentes heterogéneas, normalizarla, enriquecerla y ponerla en contexto. Fue precisamente esa necesidad operativa la que nos llevó a &lt;a href=&quot;https://mypublicinbox.com/JMS86&quot;&gt;Javier Martí Sanz&lt;/a&gt; y a mí -&lt;span style=&quot;text-align: left;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/CuriosidadesDeHackers&quot; style=&quot;text-align: left;&quot;&gt;Manuel Martínez Casasola&lt;/a&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&amp;nbsp;-&amp;nbsp; a desarrollar &lt;i&gt;&lt;b&gt;MyThreatIntel&lt;/b&gt;&lt;/i&gt;. Tras trabajar en investigaciones forenses, respuesta a incidentes y
servicios de inteligencia, la conclusión era clara: los datos existían, pero el esfuerzo necesario para convertirlos en conocimiento útil seguía siendo demasiado alto.&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/JMS86&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1083&quot; data-original-width=&quot;1839&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEifNV1Am6BP2QYNlrXvTN3aaSUAb_kPhFto7SkKk6h0_UytRaUm12LoJ9BDAd1IE_izCrX1qA33sv2BBnuL_HhRnIomrZwspOqLfCiOwoSCATNE9VqZkknnUKxlv_VjzHfg_PxHrE5pEaMCATY6i-6BH5cfX3R7pSVakf6Ia1uzckRwwN0cEzkA/w640-h376/JavierMartiSanz.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 3: &lt;a href=&quot;https://mypublicinbox.com/JMS86&quot;&gt;Contactar con Javier Marti Sanz&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
Actualmente,&amp;nbsp;&lt;a href=&quot;https://mythreatintel.com/&quot;&gt;MyThreatIntel&lt;/a&gt;&amp;nbsp;es una herramienta de &lt;i&gt;&lt;b&gt;Secure&amp;amp;IT&lt;/b&gt;&lt;/i&gt;, desarrollada para reforzar sus capacidades de &lt;i&gt;&lt;b&gt;Cyber Threat Intelligence&lt;/b&gt;&lt;/i&gt; y servir de apoyo en tareas de monitorización, análisis, investigación y respuesta ante incidentes. La plataforma permite centralizar y relacionar información que, de otro modo, tendría que localizarse y analizarse de forma independiente en múltiples fuentes.&lt;br /&gt;&lt;br /&gt;
Por eso, el valor de&amp;nbsp;&lt;a href=&quot;https://mythreatintel.com/&quot;&gt;MyThreatIntel&lt;/a&gt;&amp;nbsp;no reside únicamente en centralizar información, sino en relacionarla. Una víctima publicada por un grupo de &lt;i&gt;&lt;b&gt;ransomware&lt;/b&gt;&lt;/i&gt; puede vincularse con el actor responsable, su infraestructura &lt;i&gt;&lt;b&gt;Onion&lt;/b&gt;&lt;/i&gt;, el estado de la negociación, las filtraciones asociadas, posibles &lt;i&gt;&lt;b&gt;IoCs&lt;/b&gt;&lt;/i&gt; relacionados y, en determinados escenarios, incluso con las vulnerabilidades o artefactos de malware observados en una campaña.&lt;br /&gt;&lt;br /&gt;
Ese enfoque convierte la plataforma en algo más que una colección de secciones independientes: la convierte en un entorno de trabajo orientado a la investigación y al contexto.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Ransomware: visibilidad directa del ecosistema de extorsión&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
Uno de los pilares de la plataforma es la monitorización continua del ecosistema ransomware. &lt;i&gt;&lt;b&gt;MyThreatIntel&lt;/b&gt;&lt;/i&gt; sigue de forma directa los portales utilizados por los actores para publicar nuevas víctimas, manteniendo un histórico de actividad que permite observar tendencias, distribución geográfica, sectores afectados y volumen por actor.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMQQ4OLQCyPie4cjvDbFOx3WSlEMbgdD-E1r7LhaoSqD_BWtUeL8fnvO1NrNJwDKrHW6zgqLkAGSqSXdacBQE6rb7IgLqTn5xWZu7xWosquOh2FWDGf_l1d0ULqgxESlQiXDnhIl4KEQskbgZq_oQRr9v8u0S-XmW4YyJ9YUlhk5bFgJHehC4J/s3102/TI2.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1484&quot; data-original-width=&quot;3102&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhMQQ4OLQCyPie4cjvDbFOx3WSlEMbgdD-E1r7LhaoSqD_BWtUeL8fnvO1NrNJwDKrHW6zgqLkAGSqSXdacBQE6rb7IgLqTn5xWZu7xWosquOh2FWDGf_l1d0ULqgxESlQiXDnhIl4KEQskbgZq_oQRr9v8u0S-XmW4YyJ9YUlhk5bFgJHehC4J/w640-h306/TI2.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 4: Dashboard de ransomware con víctimas registradas,&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;distribución geográfica y actividad por actor.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
  
Esto no solo facilita saber quién está publicando más víctimas en un momento dado, sino también analizar la evolución de los grupos y entender mejor el comportamiento del ecosistema criminal. Tener esa visión agregada, pero también aterrizada en cada incidente, aporta un enorme valor para analistas &lt;i&gt;&lt;b&gt;CTI&lt;/b&gt;&lt;/i&gt;, equipos &lt;i&gt;&lt;b&gt;CSIRT&lt;/b&gt;&lt;/i&gt; y servicios de respuesta a incidentes.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmjS2SsPEW3STVTl4lm7i3qMaaUa-hCXQ_ovrSdIOGjs7VCvhjUYfwzStl-aBkVhwMWsHqSK7o_23u9lz-Isdjjult0ZLakphLTBN1TsjGkZIq7lPYzXqd8TP0P5AnrzQzWUPGu2itrZM-efDo0BHEK97DhhMfUkNg0Jy1niwxZ8rn67cAiS4A/s3096/TI3.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1692&quot; data-original-width=&quot;3096&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhmjS2SsPEW3STVTl4lm7i3qMaaUa-hCXQ_ovrSdIOGjs7VCvhjUYfwzStl-aBkVhwMWsHqSK7o_23u9lz-Isdjjult0ZLakphLTBN1TsjGkZIq7lPYzXqd8TP0P5AnrzQzWUPGu2itrZM-efDo0BHEK97DhhMfUkNg0Jy1niwxZ8rn67cAiS4A/w640-h350/TI3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 5: Registro de incidentes en crudo, con filtrado&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;por fechas, países, actores y sectores.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
Además, la plataforma permite consultar el “&lt;i&gt;&lt;b&gt;registro en crudo&lt;/b&gt;&lt;/i&gt;” de incidentes, filtrando por fechas, países, actores o sectores. Ese enfoque combina visualización ejecutiva y detalle técnico, algo especialmente útil cuando se necesita pasar rápidamente de una visión global a un caso concreto.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Negociaciones: seguir la extorsión más allá de la publicación&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
Si hay una capacidad especialmente diferencial dentro de&amp;nbsp;&lt;a href=&quot;https://mythreatintel.com/&quot;&gt;MyThreatIntel&lt;/a&gt;, esa es la monitorización de negociaciones. La mayoría de soluciones se detienen en la publicación de la víctima dentro del &lt;i&gt;&lt;b&gt;Data Leak Site&lt;/b&gt;&lt;/i&gt;. Sin embargo, desde el punto de vista de la investigación, ese suele ser solo el comienzo de la historia. A partir de ahí empieza una fase crítica: &lt;u&gt;el proceso de extorsión&lt;/u&gt;.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;
MyThreatIntel&lt;/b&gt;&lt;/i&gt; monitoriza directamente, desde los portales de los propios actores, el estado de esas negociaciones: si siguen activas, si ha habido filtración parcial o completa, si la víctima ha desaparecido del portal o si existen indicios públicos de que el rescate ha sido abonado. Esta capacidad aporta una visibilidad muy poco
habitual y permite entender mejor el ciclo completo de una operación de &lt;i&gt;&lt;b&gt;ransomware&lt;/b&gt;&lt;/i&gt;.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwEIq9nAR-MjmcXZI5nT4xup91lRtE4Ic2Ir5fe87MaxHEmhsy-_4DAMuEsk-Kq9TJzt_H93K7tNUkhrEzG_evcprIU18e5vb9hKKnh3IPiVtUFn13bbmdWc6W-BKqgJRxNPHDxf0sx01pMnRxMJ4Blnmqbn5EsOaMiACPY3nO6E8wzGXlzFFE/s3182/TI4.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1524&quot; data-original-width=&quot;3182&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjwEIq9nAR-MjmcXZI5nT4xup91lRtE4Ic2Ir5fe87MaxHEmhsy-_4DAMuEsk-Kq9TJzt_H93K7tNUkhrEzG_evcprIU18e5vb9hKKnh3IPiVtUFn13bbmdWc6W-BKqgJRxNPHDxf0sx01pMnRxMJ4Blnmqbn5EsOaMiACPY3nO6E8wzGXlzFFE/w640-h306/TI4.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 6: Sección de Negociaciones (Beta), con distribución&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;por actor, eventos monitorizados y pagos detectados.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
Más allá del interés analítico, este seguimiento tiene un valor operativo evidente. Permite estudiar el comportamiento real de los actores, comparar patrones entre
grupos y observar cómo evolucionan las extorsiones en el tiempo.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Vulnerabilidades: monitorización continua desde fuentes oficiales&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
La inteligencia sobre amenazas no se limita a seguir actores o incidentes activos. También requiere una vigilancia constante sobre la exposición técnica del ecosistema. Por ello,&amp;nbsp;&lt;a href=&quot;https://mythreatintel.com/&quot;&gt;MyThreatIntel&lt;/a&gt;&amp;nbsp;incorpora una sección de vulnerabilidades alimentada a partir de fuentes oficiales como &lt;i&gt;&lt;b&gt;NIST&lt;/b&gt;&lt;/i&gt; y &lt;i&gt;&lt;b&gt;CVE.org&lt;/b&gt;&lt;/i&gt;.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqHOLgy9C8IDvnuKctfearFVngcRbp5bH7IgJyzjQYW_PdueN8-CUYx-sWETbdRH08kFCce5L14YItBpz_2VxQawBPHd_ukLXGTl6OQ1vU01bfLeXA3T6vcrIi4fHWRp4HXoIDsEJvAw2knZl6-EWkyQo-BbdMnD-dfm3NDOai8QnxkBgbtLku/s3176/TI5.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1528&quot; data-original-width=&quot;3176&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqHOLgy9C8IDvnuKctfearFVngcRbp5bH7IgJyzjQYW_PdueN8-CUYx-sWETbdRH08kFCce5L14YItBpz_2VxQawBPHd_ukLXGTl6OQ1vU01bfLeXA3T6vcrIi4fHWRp4HXoIDsEJvAw2knZl6-EWkyQo-BbdMnD-dfm3NDOai8QnxkBgbtLku/w640-h308/TI5.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 7: Dashboard de vulnerabilidades, con severidad, fabricantes y frecuencia de detección.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;La plataforma permite consultar &lt;i&gt;&lt;b&gt;CVEs&lt;/b&gt;&lt;/i&gt; descubiertas, severidad, fabricantes, vectores de ataque y metadatos asociados, facilitando tanto la revisión rápida de nuevas publicaciones como la exportación de resultados para otros flujos de trabajo.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMNOsvtU2MntR-4J8I54qgPriKV48I6BOZ1IpZF5EoXMVmrDateHPNwfO7n1GuhZd1xJE9vvGOhVE3irW31RjYA_v0kCtvL0NbXLTDeESEPkLh8l2SnDhzuOTfxdnhWLCPYQuusy42Q0JGOUkQYEG7PfwLGIXYf_jsI3XlxqyUcLlmrcpZ2dzO/s2842/TI6.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1614&quot; data-original-width=&quot;2842&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjMNOsvtU2MntR-4J8I54qgPriKV48I6BOZ1IpZF5EoXMVmrDateHPNwfO7n1GuhZd1xJE9vvGOhVE3irW31RjYA_v0kCtvL0NbXLTDeESEPkLh8l2SnDhzuOTfxdnhWLCPYQuusy42Q0JGOUkQYEG7PfwLGIXYf_jsI3XlxqyUcLlmrcpZ2dzO/w640-h364/TI6.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 8: Vista detallada de CVEs individuales con descripción, vector y puntuación CVSS.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;La utilidad aquí no está solo en mostrar una lista de &lt;i&gt;&lt;b&gt;CVEs&lt;/b&gt;&lt;/i&gt;, sino en integrarlas dentro de un entorno de investigación más amplio. La vulnerabilidad deja de ser un identificador aislado y pasa a formar parte del contexto que rodea una amenaza o una investigación concreta.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Indicadores de Compromiso: del dato técnico a la utilidad operativa&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
Los &lt;i&gt;&lt;b&gt;IoCs&lt;/b&gt;&lt;/i&gt; siguen siendo una pieza esencial en investigación, detección y respuesta. &lt;i&gt;&lt;b&gt;MyThreatIntel&lt;/b&gt;&lt;/i&gt; incorpora un repositorio de indicadores con clasificación por tipo, criticidad y telemetría, permitiendo realizar búsquedas, filtros y exportación de resultados.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5NPEtztUfkA9FOjbFc5xmzeo0CzuBhFAUrdQ0n2foZpps873SFKBztSdFDMFbDyUFi9MXoZ4WXESLVIOaIOHqjbAcKTEWsbf1U5RRq_CR61b2I-dr1tQKqRsA9vv4zqb8X9oIZHU3beou5Uv6aKrEXqrppWuMzcrI4-K2-8dkoVSm7f_lihp3/s3242/TI7.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1560&quot; data-original-width=&quot;3242&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg5NPEtztUfkA9FOjbFc5xmzeo0CzuBhFAUrdQ0n2foZpps873SFKBztSdFDMFbDyUFi9MXoZ4WXESLVIOaIOHqjbAcKTEWsbf1U5RRq_CR61b2I-dr1tQKqRsA9vv4zqb8X9oIZHU3beou5Uv6aKrEXqrppWuMzcrI4-K2-8dkoVSm7f_lihp3/w640-h308/TI7.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 9: Dashboard de IoCs con volumen total, criticidad y distribución por tipo.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
Aquí el objetivo no es solo acumular artefactos, sino facilitar su consumo real por parte del analista. &lt;i&gt;&lt;b&gt;Hashes&lt;/b&gt;&lt;/i&gt;, dominios, archivos y otros indicadores aparecen organizados de forma que puedan emplearse con rapidez durante una investigación o integrarse en tareas de detección.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi59QcDByFEcYUJTXPKdD0etAKYbiAHggAsjP6GubJJF0YUsathDFk_F83eQcQmOJgbZDqYlGjA70f0KQpPwVGdi_2Euft_Z37N5VcNoOn61jpWW9xVuunyxEcFIqG1kkC0X2DUqUqxySpIkxt1YH2JVW2rKMFq0PfC6MHKfgOgnkN3wtnC2Mr_/s3054/TI8.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1780&quot; data-original-width=&quot;3054&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi59QcDByFEcYUJTXPKdD0etAKYbiAHggAsjP6GubJJF0YUsathDFk_F83eQcQmOJgbZDqYlGjA70f0KQpPwVGdi_2Euft_Z37N5VcNoOn61jpWW9xVuunyxEcFIqG1kkC0X2DUqUqxySpIkxt1YH2JVW2rKMFq0PfC6MHKfgOgnkN3wtnC2Mr_/w640-h374/TI8.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 10: Telemetría de indicadores, con fichas detalladas por artefacto.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
Este enfoque resulta especialmente útil cuando el volumen de datos es alto y el analista necesita reducir ruido para centrarse en aquello que tiene mayor relevancia operativa.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Darknet &amp;amp; Markets: seguir la infraestructura donde operan los actores&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;i&gt;&lt;b&gt;MyThreatIntel&lt;/b&gt;&lt;/i&gt; también incorpora una capa específica para la vigilancia de servicios &lt;i&gt;&lt;b&gt;Onion&lt;/b&gt;&lt;/i&gt; y mercados de la &lt;i&gt;&lt;b&gt;Darknet&lt;/b&gt;&lt;/i&gt;. Este componente permite observar qué servicios continúan activos, cuáles han caído, qué mercados siguen operando y cómo evoluciona su infraestructura con el tiempo.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyBuqplA66RhwLfCMxdBjuynACZNEKBlOuU03TUCcw6LKujCuocFK1FW4SUmUdw2oYoT6O8jS1sclrOPL6nanInS6bbRBOifgMohn7Mg7noluH9QnyaSpjlmsUz_NZY0bDScdw6xixPXf2nKzq_izldXDPCkYfFRgrwCXPt55KBFr5EisDVCi3/s2648/TI9.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1260&quot; data-original-width=&quot;2648&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjyBuqplA66RhwLfCMxdBjuynACZNEKBlOuU03TUCcw6LKujCuocFK1FW4SUmUdw2oYoT6O8jS1sclrOPL6nanInS6bbRBOifgMohn7Mg7noluH9QnyaSpjlmsUz_NZY0bDScdw6xixPXf2nKzq_izldXDPCkYfFRgrwCXPt55KBFr5EisDVCi3/w640-h304/TI9.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 11: Vista global de Darknet &amp;amp; Markets, con servicios Onion,&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;mercados activos y distribución por grupos.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
No se trata únicamente de listar &lt;i&gt;&lt;b&gt;URLs&lt;/b&gt;&lt;/i&gt;. El valor real está en mantener un histórico de disponibilidad, relaciones con actores y capturas o notas asociadas. En entornos donde la infraestructura cambia rápidamente, esa trazabilidad resulta especialmente valiosa.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJoN9vynqd3ta6BILxtH_2sxMMuQDM4YkCJqxJPzn8lZrGodAuKurh3pQIf1m6SgIhzLQ9B3Q5IPE7bi3ePVqf3Oct-x5mj0Wb5FnrdXbivPjf6jQ2fSV5vFhV5O26Z7nmnRdBORSaMfg70rGvhy-vZUR76dMDPgpPssE3ghbQOfqBMuvQ7pAR/s2646/TI10.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1424&quot; data-original-width=&quot;2646&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjJoN9vynqd3ta6BILxtH_2sxMMuQDM4YkCJqxJPzn8lZrGodAuKurh3pQIf1m6SgIhzLQ9B3Q5IPE7bi3ePVqf3Oct-x5mj0Wb5FnrdXbivPjf6jQ2fSV5vFhV5O26Z7nmnRdBORSaMfg70rGvhy-vZUR76dMDPgpPssE3ghbQOfqBMuvQ7pAR/w640-h344/TI10.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 12: Detalle de mercados Darknet, mostrando estado operativo y URLs monitorizadas.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;De esta forma, la plataforma aporta una visión mucho más estable sobre un ecosistema que, por naturaleza, es altamente volátil.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKGomfpnddC5XjBrAd4VSVN5Z1ffund942L1KbYc1tW0apiq-onx4x3SXJ1faM2peB4MwxM_6wvWCYblfgBHF4u4kCFzlpXLLzBGeql8t3f4VRS7L0shV-FaYH1G1konJti6tilnS3c_Ts_hLwSakZ9Ks49S-ElwKf8s-Mey3HDn9DTwLmmoL6/s2474/TI11.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1442&quot; data-original-width=&quot;2474&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiKGomfpnddC5XjBrAd4VSVN5Z1ffund942L1KbYc1tW0apiq-onx4x3SXJ1faM2peB4MwxM_6wvWCYblfgBHF4u4kCFzlpXLLzBGeql8t3f4VRS7L0shV-FaYH1G1konJti6tilnS3c_Ts_hLwSakZ9Ks49S-ElwKf8s-Mey3HDn9DTwLmmoL6/w640-h374/TI11.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 13: Detalle de servicios Onion asociados a actores, con enlaces activos y caídos.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Filtraciones y grupos: conocimiento estructurado sobre el adversario&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
El repositorio de filtraciones añade una perspectiva distinta: &lt;u&gt;la exposición histórica de organizaciones&lt;/u&gt;. Los registros pueden buscarse por nombre, fecha o tamaño, lo que ayuda a comprobar si una entidad, dominio o conjunto de datos ya apareció en una filtración conocida. Este componente puede utilizarse tanto en investigaciones de terceros como en análisis de exposición, procesos de ciberinteligencia y respuesta a incidentes. La información deja de estar distribuida entre referencias aisladas y pasa a formar parte de un catálogo consultable desde el mismo entorno.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiaitat8mL5d5Z_P4qTZAH9alOeTbelpu_7OLGgN26-vCzFHSbrabd5BBGtVXISZYRcjwrtvtxqlbIavLd166kgX2rMdFwqpaCc6B0GoXvry8uBap7wCbg3ZaaM2O4EgXDQBhtMgW9NnROLI9I5ArVr16OIGm9G8PvnENbBzS9NAp_xXWSZUeAG/s2588/TI12.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1250&quot; data-original-width=&quot;2588&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiaitat8mL5d5Z_P4qTZAH9alOeTbelpu_7OLGgN26-vCzFHSbrabd5BBGtVXISZYRcjwrtvtxqlbIavLd166kgX2rMdFwqpaCc6B0GoXvry8uBap7wCbg3ZaaM2O4EgXDQBhtMgW9NnROLI9I5ArVr16OIGm9G8PvnENbBzS9NAp_xXWSZUeAG/w640-h310/TI12.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 14: Repositorio de filtraciones y catálogo histórico.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
La sección &lt;i&gt;&lt;b&gt;Grupos&lt;/b&gt;&lt;/i&gt; funciona como una base de conocimiento sobre actores de amenazas. Incluye descripciones, aliases, infraestructura &lt;i&gt;&lt;b&gt;Onion&lt;/b&gt;&lt;/i&gt;, capturas y notas, permitiendo contextualizar rápidamente a un grupo sin depender de búsquedas dispersas.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZEWqGE5j4vdoQPMTlvGGiNd7ML5GGaGLgZlJIlBbRrvh4rmHadNKxOPIeQkVhONXho8aazbRNqD649c6-76pGA_i8Phn9v0zn5FuNSwIw9EhXAjl1p3e-rgi-jZB_-F3XqkUmwoSdwOVOnZnYjkzosxAvexFyxuHPC4_Jj0a-UQ49k8mgF3Mk/s2596/TI13.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1242&quot; data-original-width=&quot;2596&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhZEWqGE5j4vdoQPMTlvGGiNd7ML5GGaGLgZlJIlBbRrvh4rmHadNKxOPIeQkVhONXho8aazbRNqD649c6-76pGA_i8Phn9v0zn5FuNSwIw9EhXAjl1p3e-rgi-jZB_-F3XqkUmwoSdwOVOnZnYjkzosxAvexFyxuHPC4_Jj0a-UQ49k8mgF3Mk/w640-h306/TI13.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 15 Inteligencia de amenazas: fichas de grupos,&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;enlaces Onion y documentación asociada.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
La relación entre actores, víctimas, portales, notas de rescate e infraestructura es uno de los puntos donde &lt;i&gt;&lt;b&gt;MyThreatIntel&lt;/b&gt;&lt;/i&gt; deja de comportarse como un agregador y
empieza a funcionar como una herramienta de investigación. Al analizar una víctima, el investigador puede acceder al contexto del actor, revisar sus canales e
infraestructura y observar su actividad documentada desde una única interfaz.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
  Malware y artefactos técnicos&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
El repositorio de malware reúne muestras con sus hashes, nombre, firma, tamaño, tipo y etiquetas técnicas. Esta clasificación permite localizar artefactos por familia o característica y relacionarlos con los indicadores utilizados durante una investigación.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgHoZxWmYcdxec9_BQ4LKyd7Zn7EvzVdI-zLWymJPNQqJz1Qj_7epzOa9REAh50KHufXXHQeuuQUXnD6AkkurTgC0YNLiwwcuCq_UXhC5805TNlCxmnbdrqYeJ3fBDiJZavD52yEODhCJNk5LtvsE8O7bXq_S8x1JWdjZ6oab-WGY-LEUAlhtHH/s2590/TI14.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1246&quot; data-original-width=&quot;2590&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgHoZxWmYcdxec9_BQ4LKyd7Zn7EvzVdI-zLWymJPNQqJz1Qj_7epzOa9REAh50KHufXXHQeuuQUXnD6AkkurTgC0YNLiwwcuCq_UXhC5805TNlCxmnbdrqYeJ3fBDiJZavD52yEODhCJNk5LtvsE8O7bXq_S8x1JWdjZ6oab-WGY-LEUAlhtHH/w640-h308/TI14.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 16: Repositorio de muestras de malware, hashes, firmas y etiquetas.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
El apoyo de &lt;i&gt;&lt;b&gt;MITRE ATT&amp;amp;CK&lt;/b&gt;&lt;/i&gt; aporta contexto sobre técnicas, tácticas y comportamientos, especialmente cuando una muestra forma parte de una cadena de intrusión más amplia. De este modo, el repositorio no actúa únicamente como almacén de archivos, sino como fuente de apoyo para análisis de malware, &lt;i&gt;&lt;b&gt;Threat Hunting&lt;/b&gt;&lt;/i&gt; y construcción de hipótesis durante una investigación.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Permutaciones DNS para investigar suplantaciones&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
La consulta &lt;i&gt;&lt;b&gt;DNS&lt;/b&gt;&lt;/i&gt; amplía la plataforma hacia la detección de typosquatting, phishing e infraestructura sospechosa. A partir de un dominio, el motor genera permutaciones y comprueba su registro utilizando diferentes &lt;i&gt;&lt;b&gt;TLD&lt;/b&gt;&lt;/i&gt; y palabras clave asociadas a accesos corporativos, identidad, &lt;i&gt;&lt;b&gt;Microsoft 365&lt;/b&gt;&lt;/i&gt;, &lt;i&gt;&lt;b&gt;VPN&lt;/b&gt;&lt;/i&gt;, correo, servicios &lt;i&gt;&lt;b&gt;cloud&lt;/b&gt;&lt;/i&gt; o soporte técnico.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjja5dplgcEW2f5_-drMIay3dGKsWWX3TB2Y2vALOuqBgrCGJXuhLhf3PVVs17_JAtSYxdG6dtlPoFpNljwJqi_wz-T2NY3Y9ZoOYmvuCdX9glqKo9b2yk12mVU-WPJWwW4Xukkvl6wl-tniZ7gKjjfBgcgHawn4HkKtAmdXiTuhPQjSk95zbmp/s2754/TI15.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1298&quot; data-original-width=&quot;2754&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjja5dplgcEW2f5_-drMIay3dGKsWWX3TB2Y2vALOuqBgrCGJXuhLhf3PVVs17_JAtSYxdG6dtlPoFpNljwJqi_wz-T2NY3Y9ZoOYmvuCdX9glqKo9b2yk12mVU-WPJWwW4Xukkvl6wl-tniZ7gKjjfBgcgHawn4HkKtAmdXiTuhPQjSk95zbmp/w640-h302/TI15.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 17: Consulta de permutaciones DNS, TLD, palabras clave y dominios registrados.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
El resultado permite distinguir entre dominios generados y registrados, revisar fechas de creación, aplicar filtros y exportar el análisis. Integrar esta capacidad dentro de &lt;i&gt;&lt;b&gt;MyThreatIntel&lt;/b&gt;&lt;/i&gt; facilita conectar una posible suplantación con el resto del contexto disponible, en lugar de tratarla como una consulta independiente.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Consumo mediante Web y API&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
La interfaz web está orientada a la investigación manual, pero la inteligencia también debe poder salir de la plataforma. &lt;i&gt;&lt;b&gt;MyThreatIntel&lt;/b&gt;&lt;/i&gt; dispone de una &lt;i&gt;&lt;b&gt;API&lt;/b&gt;&lt;/i&gt; con autenticación mediante &lt;i&gt;&lt;b&gt;Bearer Token&lt;/b&gt;&lt;/i&gt;, respuestas &lt;i&gt;&lt;b&gt;JSON&lt;/b&gt;&lt;/i&gt; estandarizadas, búsqueda de texto y filtrado por fuentes y categorías. Esto permite consumir vulnerabilidades, &lt;i&gt;&lt;b&gt;IoCs&lt;/b&gt;&lt;/i&gt;, muestras de &lt;i&gt;&lt;b&gt;malware&lt;/b&gt;&lt;/i&gt;, víctimas de &lt;i&gt;&lt;b&gt;ransomware&lt;/b&gt;&lt;/i&gt;, infraestructura &lt;i&gt;&lt;b&gt;Tor&lt;/b&gt;&lt;/i&gt;, mercados, grupos, negociaciones y filtraciones desde plataformas &lt;i&gt;&lt;b&gt;SIEM&lt;/b&gt;&lt;/i&gt;, herramientas &lt;i&gt;&lt;b&gt;SOAR&lt;/b&gt;&lt;/i&gt;, &lt;i&gt;&lt;b&gt;scripts&lt;/b&gt;&lt;/i&gt; o automatizaciones desarrolladas en &lt;i&gt;&lt;b&gt;PowerShell&lt;/b&gt;&lt;/i&gt;, &lt;i&gt;&lt;b&gt;Python&lt;/b&gt;&lt;/i&gt;, &lt;i&gt;&lt;b&gt;JavaScript&lt;/b&gt;&lt;/i&gt; y otros lenguajes.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;
MyThreatIntel&lt;/b&gt;&lt;/i&gt; puede utilizarse directamente desde &lt;a href=&quot;https://mythreatintel.secureit.es/&quot;&gt;https://mythreatintel.secureit.es/&lt;/a&gt;, donde centraliza toda esta información en una única interfaz. Además, como la plataforma dispone de &lt;i&gt;&lt;b&gt;API&lt;/b&gt;&lt;/i&gt;, lo que permite integrarla en flujos de trabajo, herramientas &lt;i&gt;&lt;b&gt;SIEM&lt;/b&gt;&lt;/i&gt; y &lt;i&gt;&lt;b&gt;SOAR&lt;/b&gt;&lt;/i&gt;, &lt;i&gt;&lt;b&gt;scripts&lt;/b&gt;&lt;/i&gt; de investigación o procesos de automatización propios. Este punto es importante porque la inteligencia no siempre termina en el panel. En muchos casos, su verdadero valor aparece cuando puede integrarse en otros procesos de seguridad y respuesta.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Conclusión&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href=&quot;https://mythreatintel.secureit.es/&quot;&gt;MyThreatIntel&lt;/a&gt; no nace para sustituir fuentes, sino para darles sentido conjunto. En un escenario donde la información está cada vez más fragmentada, el verdadero reto no consiste en recopilar más datos, sino en reducir el tiempo necesario para convertirlos en contexto útil. &lt;i&gt;&lt;b&gt;Ransomware&lt;/b&gt;&lt;/i&gt;, negociaciones, vulnerabilidades, &lt;i&gt;&lt;b&gt;IoCs&lt;/b&gt;&lt;/i&gt;, &lt;i&gt;&lt;b&gt;Darknet&lt;/b&gt;&lt;/i&gt;, filtraciones, grupos, &lt;i&gt;&lt;b&gt;malware&lt;/b&gt;&lt;/i&gt; y &lt;i&gt;&lt;b&gt;DNS&lt;/b&gt;&lt;/i&gt; no son piezas aisladas. En una investigación real suelen formar parte de una misma historia. La utilidad de &lt;a href=&quot;https://mythreatintel.secureit.es/&quot;&gt;MyThreatIntel&lt;/a&gt; está precisamente en ayudar a contar esa historia con menos fricción, más contexto y una mejor capacidad de respuesta.


&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Saludos,&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;a href=&quot;https://mypublicinbox.com/CuriosidadesDeHackers&quot;&gt;Manuel Martínez, founder de The Hackers Lab&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/CuriosidadesDeHackers&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1596&quot; data-original-width=&quot;1730&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh38pUKszS7JSFQwg23LhHruS_zPmoORHgxC3vJvS2zEhGFMjGl666tB9i-k3TXr_rqPtL1jrH3apFlkTcvl1j9wr9IY2lf9Nj0JlIY-byoAi6uFatSjhwg9U3EaNuAm4eLAmNwXK0SHzGHVy5IoYP_eLBJwYFe-ib-kR7GPKD8AI_En5UCXfKW/w640-h590/Manuel_Martinez.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://mypublicinbox.com/CuriosidadesDeHackers&quot;&gt;Contactar con Manuel Martínez&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/07/mythreatintel-plataforma-de-threat.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEj16lBWw-wxc5y73GnGNNgrY0_7uzwArWl5_ko1ltcHC8loyXujtsnMT0GY4oyWiTu-ImxsOiVPp5GNIteoZouCmdG69rG8II9oXHmz0HkX0dFEOpqfOHmfjOh2B66-j0cPfbjtIvb5rXOYyGVwjVWgdkiXIUR6fAg-JJ6JRGRcMhTQhO0nXxz7/s72-w640-h344-c/T0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-2085809300403395549</guid><pubDate>Wed, 29 Jul 2026 05:01:00 +0000</pubDate><atom:updated>2026-08-04T08:34:55.211+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Agentic</category><category domain="http://www.blogger.com/atom/ns#">Agentic AI</category><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">Anthropic</category><category domain="http://www.blogger.com/atom/ns#">Artificial Intelligence</category><category domain="http://www.blogger.com/atom/ns#">ciberseguridad</category><category domain="http://www.blogger.com/atom/ns#">Claude</category><category domain="http://www.blogger.com/atom/ns#">cloudflare</category><category domain="http://www.blogger.com/atom/ns#">hardening</category><category domain="http://www.blogger.com/atom/ns#">IA</category><category domain="http://www.blogger.com/atom/ns#">Inteligencia Artificial</category><category domain="http://www.blogger.com/atom/ns#">LLM</category><category domain="http://www.blogger.com/atom/ns#">OWASP</category><category domain="http://www.blogger.com/atom/ns#">Zero Trust</category><title>Cómo desplegar Zero Trust para Agentes IA en Cloudflare (2)</title><description>&lt;div align=&quot;justify&quot;&gt;Las secciones anteriores - &lt;a href=&quot;https://www.elladodelmal.com/2026/07/como-desplegar-zero-trust-para-agentes.html&quot;&gt;vistas en la primera parte de este artículo que puedes leer aquí&lt;/a&gt; - establecieron la premisa (el modelo como eslabón que no distingue una instrucción legítima de una inyectada) y la descripción del sujeto: el &lt;i&gt;&lt;b&gt;A&lt;/b&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;gente IA&lt;/b&gt;&lt;/i&gt; que se ejecuta en una &lt;i&gt;&lt;b&gt;Sandbox&lt;/b&gt;&lt;/i&gt; desplegado en la cuenta de &lt;a href=&quot;https://www.cloudflare.com&quot;&gt;Cloudflare&lt;/a&gt;, gobernado desde un &lt;i&gt;&lt;b&gt;Durable Object&lt;/b&gt;&lt;/i&gt; externo.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhghqkss-qx0EX51ZzYXEyfCRFnl0ymRzPonOw4p0xaWBF0dOiZoDft2InkGOKW7fwLi4Uf0sW-Hi86zqAX9a-aJl_ZW1lES7oFhESwU6HKSZcSVUU-HFkeInkr4y2h3uy2yWB-4rWGVR_zh0WOfbw7sjvLAYtXwE1VnYWxsFKnEykjhJs6JnV3/s940/ZT_00.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;598&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhghqkss-qx0EX51ZzYXEyfCRFnl0ymRzPonOw4p0xaWBF0dOiZoDft2InkGOKW7fwLi4Uf0sW-Hi86zqAX9a-aJl_ZW1lES7oFhESwU6HKSZcSVUU-HFkeInkr4y2h3uy2yWB-4rWGVR_zh0WOfbw7sjvLAYtXwE1VnYWxsFKnEykjhJs6JnV3/w640-h408/ZT_00.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i style=&quot;text-align: left;&quot;&gt;Figura 12:&amp;nbsp;Cómo desplegar Zero Trust para Agentes IA en Cloudflare (2)&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Esta sección recorre, dimensión por dimensión, los controles para postular esa arquitectura como &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt;. Cada uno de los controles sigue el mismo recorrido: primero qué pide el principio &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt;, luego dónde se sitúa hoy en el ecosistema &lt;i&gt;&lt;b&gt;Cloudflare&lt;/b&gt;&lt;/i&gt; frente a ese principio y por último cómo continúa la maduración hacia un estadio óptimo del modelo de madurez.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;&lt;u&gt;4.- Aplicación: los controles Zero Trust sobre el agente.&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
El orden sigue la secuencia natural de una petición. Primero se establece quién es el sujeto (&lt;i&gt;&lt;b&gt;identidad&lt;/b&gt;&lt;/i&gt; y &lt;i&gt;&lt;b&gt;autenticación&lt;/b&gt;&lt;/i&gt;). Después se decide qué se le permite hacer (&lt;i&gt;&lt;b&gt;control de acceso&lt;/b&gt;&lt;/i&gt;) y por dónde puede moverse (&lt;i&gt;&lt;b&gt;segmentación&lt;/b&gt;&lt;/i&gt;).&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpHYydjv-ZC2nDp6wQyVbgWfll-kMTg6TXgJUgPskcS3YFyh4Zn5TywtaaEAYuYm3o6rlKQtu768kA-xguRpQtLyJQngH0o_SvT102RBypOwJw1Nu6wOa_GGDkp3nHFOu7PI9Ifu1-C2czQTfOElrzRuim6YZmkiNwhkIYBprqoaahS20D4uYU/s831/ZT1.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;355&quot; data-original-width=&quot;831&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgpHYydjv-ZC2nDp6wQyVbgWfll-kMTg6TXgJUgPskcS3YFyh4Zn5TywtaaEAYuYm3o6rlKQtu768kA-xguRpQtLyJQngH0o_SvT102RBypOwJw1Nu6wOa_GGDkp3nHFOu7PI9Ifu1-C2czQTfOElrzRuim6YZmkiNwhkIYBprqoaahS20D4uYU/w640-h274/ZT1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i style=&quot;text-align: left;&quot;&gt;Figura 13: Las siete dimensiones de control Zero Trust.&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Luego se vigila lo que entra y lo que sale (&lt;i&gt;&lt;b&gt;validación de datos&lt;/b&gt;&lt;/i&gt;), lo que hace mientras actúa (&lt;i&gt;&lt;b&gt;observabilidad&lt;/b&gt;&lt;/i&gt;) y cómo se le contiene si algo va mal (&lt;i&gt;&lt;b&gt;contención y recuperación&lt;/b&gt;&lt;/i&gt;). Por encima de todo, la gobernanza mantiene el conjunto coherente en el tiempo.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
4.1.- Identidad y autenticación. &lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
El principio.&lt;br /&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;
Zero Trust&lt;/b&gt;&lt;/i&gt; parte de que ningún sujeto goza de confianza implícita en ninguna circunstancia (independientemente de su ubicación o propiedad). Toda identidad debe verificarse antes de conceder acceso y verificarse de forma continua. &lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot;&gt;NIST SP 800-207&lt;/a&gt; extiende ese principio explícitamente a los sujetos que no son personales. En su sección &lt;i&gt;&lt;b&gt;5.7&lt;/b&gt;&lt;/i&gt;, dedicada al uso de entidades ‘&lt;i&gt;&lt;b&gt;no-persona&lt;/b&gt;&lt;/i&gt;’ en la administración de una arquitectura &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt;, reconoce que los agentes de inteligencia artificial y otros componentes de software se despliegan para gestionar tareas en la red de la organización y necesitan autenticarse ante los componentes de control, a veces en lugar de un administrador humano.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;319&quot; data-original-width=&quot;1288&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgxGTMgCXOs-lkS7TicGFKxezC08BbrzF6SE4B6s2QzgVfaT4LzzE0ghWKszQDbAXTtRu5iI0AN0D-yjJYXtmi39DeESOBqOjm736Frv0avwByh1tTwywJEwFNwcwoyPudDnMFYzBcEMjoLZynXYsYRyc8jP3scPllN-d4QzDQuovFBSTZz5Qpm/w640-h158/ZT2.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 14: &lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot;&gt;non-person identities en ZTA Administration&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Y advierte de tres riesgos que describen con precisión la situación de un agente: que su listón de autenticación sea más bajo que el de un human (una clave de &lt;i&gt;&lt;b&gt;API&lt;/b&gt;&lt;/i&gt; frente a una autenticación multifactor), que un atacante consiga inducirlo o coaccionarlo para ejecutar una tarea para la que el atacante no tiene privilegios y que un atacante robe las credenciales del agente y lo suplante. La identidad del agente, por tanto, no es un detalle administrativo: puede ser la primera superficie que una atacante intentará explotar o usurpar.&lt;br /&gt;&lt;br /&gt;
La consecuencia para el diseño es doble. La identidad del agente debe ser fuerte (no una credencial estática y longeva que, si se filtra, abre una puerta de modo indefinido) y debe ser verificable por algo externo al propio agente, porque, como se ha establecido en la premisa, el modelo no puede ser el guardián de su propia identidad. &lt;br /&gt;&lt;br /&gt;&lt;u&gt;
Aplicándolo en el ecosistema de Cloudflare. &lt;/u&gt;&lt;br /&gt;&lt;br /&gt;
Conviene distinguir desde el principio dos identidades que son fáciles de confundir: la del plano de control (el componente que orquesta las sesiones) y la del &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; cuando accede a recursos externos. La primera la resuelve hoy el despliegue de referencia con una credencial única, la llamada &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents&quot;&gt;Clave de Entorno&lt;/a&gt;&amp;nbsp;&lt;i&gt;&lt;b&gt;(ANTHROPIC_ENVIRONMENT_KEY).&lt;/b&gt;&lt;/i&gt; Es la clave con la que el plano de control se identifica con &lt;i&gt;&lt;b&gt;Anthropic&lt;/b&gt;&lt;/i&gt; y con ella realiza todas las operaciones de coordinación: pedir el trabajo pendiente, confirmar su recepción, señalar que sigue vivo, forzar la parada de sesión y recibir el flujo de eventos de cada una. Es decir, &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents&quot;&gt;una sola credencial gobierna toda la relación entre el plano de control y la plataforma&lt;/a&gt;. &lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;346&quot; data-original-width=&quot;1306&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhA8-KnTeoSbtU87tos4ocoBmoclXn9M0pHljcdkbziDG0-U_y30VLfh84t0NN_Ih_MxyJ3yK-y4Ut5h4cKLRlwCyfHz7UTodkQdUbCR-FVE_7sXvXIqaaxoVo91BIdeRCEC9HMhK00OR-UiTdC6qpDz_hgTVHcKSwwG9BrRFQ7ETOC2xhb-HJ1/w640-h170/ZT3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 15: &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents&quot;&gt;Claves de control de Antrhopic desde Cloudflare&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
Que una única clave concentre todas esas operaciones tiene una lectura &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; inmediata. Por un lado, es un punto de alto valor que conviene proteger y rotar con cuidado: el repositorio lo gestiona como secreto, no como variable en claro y verifica además la firma de cada &lt;i&gt;&lt;b&gt;webhook&lt;/b&gt;&lt;/i&gt; entrante antes de actuar sobre él, de modo que un evento no firmado no llega a procesarse.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Por otro lado, es exactamente el tipo de credencial cuya captura permitiría a un atacante suplantar al sistema (el tercero de los registros que advierte &lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot;&gt;NIST SP 800-207 en su sección 5.7&lt;/a&gt;), lo que refuerza la necesidad de tratarla con el mismo rigor que cualquier identidad privilegiada. Esa credencial sin embargo, identifica al plano de control, no al &lt;i&gt;&lt;b&gt;Agente AI&lt;/b&gt;&lt;/i&gt; cuando este sale a actuar sobre el mundo (cuando accede a un servicio, una &lt;i&gt;&lt;b&gt;API&lt;/b&gt;&lt;/i&gt; o un servidor).&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Para esa segunda identidad, la del &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; como sujeto que actúa, el ecosistema &lt;a href=&quot;https://www.cloudflare.com/sase/&quot;&gt;Cloudflare One&lt;/a&gt; aporta dos piezas directamente aplicables. La primera es la autenticación mutua mediante &lt;i&gt;&lt;b&gt;mTLS&lt;/b&gt;&lt;/i&gt;: en ella, tanto el cliente como el servidor presentan certificados durante el &lt;i&gt;&lt;b&gt;handshake&lt;/b&gt;&lt;/i&gt; y &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/access-controls/service-credentials/mutual-tls-authentication/&quot;&gt;Cloudflare Access&lt;/a&gt; la propone explícitamente como vía para que sistemas automatizados y dispositivos demuestren su identidad presentando un certificado de cliente en lugar de iniciar sesión a través de un proveedor de identidad.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.cloudflare.com/sase/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1322&quot; data-original-width=&quot;1712&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqTyYm27Fg-pxvupQP3NFjeB8DTc_F2a4aJvtrgTw84KKm4myCwKn1hy8g78xyaa9ii90_Va7_i1orWRhnW4rln2JqUC0uM8aVGDEBGN2ogrfvLKUtsHQ9TS2QrnSZg6x86cDaJk1Xnb4JHyoWApI7SVARkDcy7vNutRI7Cl91piaOcMjfeYJY/w640-h494/ZT4.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 16: &lt;a href=&quot;https://www.cloudflare.com/sase/&quot;&gt;Dashboard de Cloudflare One&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Es, en términos de &lt;i&gt;&lt;b&gt;NIST SP 800-207&lt;/b&gt;&lt;/i&gt;, una credencial de identidad para una entidad ‘&lt;i&gt;&lt;b&gt;no-persona&lt;/b&gt;&lt;/i&gt;’ (también llamadas &quot;&lt;a href=&quot;https://www.elladodelmal.com/2025/08/identidades-no-humanas-nhi-non-human.html&quot;&gt;Non-Human Identities&lt;/a&gt;&quot;): un certificado en lugar de un login humano. La segunda pieza es la emisión de certificados de vida corta para el acceso a infraestructura: en &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-one/networks/connectors/cloudflare-tunnel/use-cases/ssh/ssh-infrastructure-access/&quot;&gt;el modelo de acceso por SSH de Cloudflare&lt;/a&gt;, las claves estáticas tradicionales, que pueden permanecer sin cambios en los servidores durante años, se sustituyen por certificados efímeros emitidos a partir del &lt;i&gt;&lt;b&gt;token&lt;/b&gt;&lt;/i&gt; del inicio de sesión, con políticas por destino y por usuario y registro de los comandos ejecutados.&amp;nbsp;&lt;span style=&quot;text-align: left;&quot;&gt;Conviene situar esta segunda pieza con precisión: la documentación describe el acceso de usuario humano por &lt;i&gt;&lt;b&gt;SSH&lt;/b&gt;&lt;/i&gt;, no el del &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt;.&amp;nbsp; Su valor aquí es que demuestra que la plataforma ya dispone del mecanismo de credenciales efímeras y de mínimo privilegio temporal, que es justamente el patrón que un &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; como entidad ‘&lt;i&gt;&lt;b&gt;no-persona&lt;/b&gt;&lt;/i&gt;’ necesita.&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
Situado en el recorrido de madurez, el ecosistema ofrece, por tanto, los materiales para una identidad ‘&lt;i&gt;&lt;b&gt;no-humana&lt;/b&gt;&lt;/i&gt;’: &lt;u&gt;certificados de cliente&lt;/u&gt;, &lt;u&gt;credenciales efímeras&lt;/u&gt;, &lt;u&gt;gestión de secretos&lt;/u&gt; y &lt;u&gt;verificación de firmas&lt;/u&gt;. Pero su aplicación al &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; concreto depende de que el operador los conecte deliberadamente. La plataforma provee las piezas, falta ensamblarlas.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;u&gt;Continuando con la maduración Zero Trust&lt;br /&gt;&lt;/u&gt;&lt;br /&gt;
El paso natural hacia un estadio óptimo es sustituir las credenciales estáticas y de larga vida, allí donde hoy haya, por credenciales efímeras y de alcance acotado. Una clave de entorno única y longeva cumple su función, pero el principio &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; de verificación continua y de mínimo privilegio temporal apuntan hacia credenciales que caduquen por diseño y que se emitan en el momento de uso, de modo que una filtración tenga una ventana de validez corta en lugar de definitiva. El mecanismo de certificados efímeros que la plataforma ya usa para el acceso de usuarios marca la dirección: llevar ese mismo patrón (emisión justo a tiempo, vida corta, alcance por destino) a la identidad con laque el agente accede a los recursos.&lt;br /&gt;&lt;br /&gt;
Un segundo avance consiste en considera la identidad del agente como una entidad ‘&lt;i&gt;&lt;b&gt;no-persona&lt;/b&gt;&lt;/i&gt;’ de primer orden y no como una extensión de la cuenta que lo despliega: que cada &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt;, o cada clase de agente, porte una credencial propia y distinguible (un certificado de cliente mediante autenticación mutua) de modo que las decisiones de acceso y los registros de auditoria puedan atribuirse a una identidad concreta y verificable, en lugar de una credencial compartida. Esto alinea el despliegue con la advertencia de &lt;i&gt;&lt;b&gt;NIST SP 800-207&lt;/b&gt;&lt;/i&gt; sobre el robo y la suplantación de credenciales de agentes: cuanto más acotada y atribuible es la identidad, menor es el alcance de lo que un atacante obtiene si la captura.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;&lt;u&gt;4.2.- Control de acceso: el principio de mínima agencia.&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;
El principio.&lt;br /&gt;&lt;br /&gt;
Una vez verificada la identidad del sujeto, &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; impone una segunda pregunta: &lt;i&gt;&lt;b&gt;¿qué se le permite hacer? &lt;/b&gt;&lt;/i&gt;Para responderla de forma estructurada, el marco &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; recurre al método &lt;i&gt;&lt;b&gt;Kipling&lt;/b&gt;&lt;/i&gt;, que articula toda política de acceso en torno a seis preguntas (quién, qué, cuándo, donde, por qué y cómo).&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;La guía de la &lt;a href=&quot;https://cloudsecurityalliance.org/&quot;&gt;Cloud Security Alliance&lt;/a&gt; lo recoge en dos planos complementarios: por un lado, define la política como el conjunto de reglas de gobernanza que determina el quién, qué, cuándo, dónde, cómo y por qué  del acceso al recurso; por otro, sitúa el método &lt;i&gt;&lt;b&gt;Kipling&lt;/b&gt;&lt;/i&gt; en el paso concreto de crear las política &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt;, para determinar quién o qué puede acceder a la superficie a proteger, considerando de forma explícita tanto entidades persona como no-persona (servicios, aplicaciones, &lt;i&gt;&lt;b&gt;bots&lt;/b&gt;&lt;/i&gt;). Un &lt;i&gt;&lt;b&gt;Agente de IA&lt;/b&gt;&lt;/i&gt; es, precisamente, una de esas identidades &lt;i&gt;&lt;b&gt;no-persona&lt;/b&gt;&lt;/i&gt; y aplicarle las seis preguntas convierte un permiso difuso en una política precisa: quién es el agente (su identidad tratada en la sección anterior), a qué recurso accede y para qué, cuándo y desde dónde, y cómo (con qué herramienta y bajo qué condiciones) se permite la acción. &lt;br /&gt;&lt;br /&gt;
El principio rector que ordena la respuesta a esas preguntas es el de mínimo privilegio, que en el mundo de los agentes adopta una forma propia, la de mínima agencia: un agente no debe disponer de más capacidades de las estrictamente necesarias para su tarea, porque cada capacidad que posee es también una para que un atacante pueda inducirle a usar. La &lt;a href=&quot;https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/&quot;&gt;taxonomía de OWASP para aplicaciones agénticas&lt;/a&gt;&amp;nbsp;recoge este riesgo de forma explícita en sus categorías de abuso de identidad y privilegio del agente y de uso indebido de herramientas y sitúa los controles de mínima agencia como una de las defensas trasversales del catálogo.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1012&quot; data-original-width=&quot;1094&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjy9H3X0zq0gr1SVpsOHlrF-VoX0GhtYtVnNqzcRFiqdEwmXwyHmGBMg6l42gUsTb2nIbaVkJZnT2z7zYYJUTBoebAnWO3IHVSAFJ45GHsTIRmRl2uJLgje4ISNy8yztpyrU6M-MbyFwVdrXs9blwgoAeucB816RF8J_a1vdQ6ez-CSXL5mPbyb/w640-h592/ZT6.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 17: &lt;a href=&quot;https://genai.owasp.org/resource/owasp-top-10-for-agentic-applications-for-2026/&quot;&gt;Abuso de Identidad y Privilegios en OWASP Top 10 para Agentic AI&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
La diferencia con el control de acceso clásico es importante y conviene no perderla de vista. En un sistema tradicional, los permisos limitan lo que un usuario puede solicitar. En un sistema agéntico, el agente decide por sí mismo qué herramienta invocar a partir de un objetivo en lenguaje natural. Si entre esas herramientas hay una con capacidad de hacer daño, bastaría con que una instrucción inyectada en sus datos de entrada lo dirija hacia ella. Por eso la mínima agencia no es sólo buena higiene, es la contención directa del riesgo de inyección descrito en la premisa. Cuantas menos herramientas potentes estén al alcance del &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt;, menor es lo que la inyección puede lograr &lt;i&gt;&lt;b&gt;(Blast Radius)&lt;/b&gt;&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;
De aquí se derivan dos exigencias de diseño. La primera es que el catálogo de herramientas del &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; esté curado: que sólo contenga lo que la tarea requiera y nada más. La segunda es que las decisiones sobre si una acción concreta pueda ejecutarse no dependa del propio modelo (que, como se estableció, no puede ser garantía por sí mismo), sino de una lógica externa y determinista o de la intervención de un humano cuando la acción lo merezca. &lt;br /&gt;&lt;br /&gt;&lt;u&gt;
Cómo aplicarlo con el ecosistema Cloudflare.&lt;br /&gt;&lt;/u&gt;&lt;br /&gt;
El despliegue de referencia ofrece tres mecanismos que, combinados, cubren buena parte de esta exigencia.&lt;br /&gt;&lt;br /&gt;
El primer mecanismo es la curaduría del conjunto de herramientas. Cada herramienta del catálogo (tanto las propias del &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; como las personalizadas) se activa o desactiva de forma individual en la configuración del agente y una herramienta desactivada no aparece ni puede ser invocada.&amp;nbsp;&lt;span style=&quot;text-align: left;&quot;&gt;En el despliegue de &lt;/span&gt;&lt;i style=&quot;text-align: left;&quot;&gt;&lt;b&gt;Cloudflare&lt;/b&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;, además, &lt;/span&gt;&lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/adding-custom-tools.md&quot; style=&quot;text-align: left;&quot;&gt;las herramientas integradas están condicionadas a que exista la conexión que cada una necesita&lt;/a&gt;&lt;span style=&quot;text-align: left;&quot;&gt;: sólo aparecen en el catálogo del Agente IA cuando quien lo despliega ha configurado el recurso correspondiente. Es mínima agencia por construcción: lo que no se ha conectado, no existe para el agente.&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
El segundo mecanismo son las políticas de permiso. &lt;a href=&quot;https://platform.claude.com: https://platform.claude.com/docs/en/managed-agents/permission-policies&quot;&gt;Anthropic define para Managed Agents dos tipos de políticas&lt;/a&gt;: una que permite la ejecución automática y otra que pausa la sesión y espera la aprobación humana antes de actuar. Los valores por defecto son razonables desde la óptica &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt;: las herramientas que provienen de servidores &lt;i&gt;&lt;b&gt;MCP&lt;/b&gt;&lt;/i&gt; externos quedan por defecto en el modo que exige aprobación, de modo que una herramienta nueva añadida a un servidor &lt;i&gt;&lt;b&gt;MCP&lt;/b&gt;&lt;/i&gt; no se ejecuta en el despliegue sin que alguien la confirme.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/adding-custom-tools.md&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1198&quot; data-original-width=&quot;1408&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiN4yR2F-AaiGs4rXwsPWujl3zJERhKMwBGjV3gXE_fJ73sIWECogSABpf68lWaRR2Y8A9M6YpApjDInzT38_AnzTfyGV2O_ka7fR0A80DA-pdfE0WK24O2POS50MuZlQQrscCqll_vrkSCFlmwJjE3-2tptOUr_tQOf-6YcPyM8XcrVCOiAWSU/w640-h544/ZT7.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 18: &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/adding-custom-tools.md&quot;&gt;Añadiendo herramientas al Agente IA&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;El tercer mecanismo y el más potente para un control determinista, es la herramienta personalizada. En el despliegue de &lt;i&gt;&lt;b&gt;Cloudflare&lt;/b&gt;&lt;/i&gt;, una herramienta personalizada no es una llamada que el modelo ejecuta por su cuenta. El &lt;a href=&quot;https://platform.claude.com/docs/en/managed-agents/tools&quot;&gt;modelo sólo emite petición estructurada y es el código quien despliega&lt;/a&gt; (ejecutándose en el &lt;i&gt;&lt;b&gt;Durable Object&lt;/b&gt;&lt;/i&gt;, con acceso a las conexiones &lt;i&gt;&lt;b&gt;Worker&lt;/b&gt;&lt;/i&gt;) el que realiza la operación y devuelve el resultado. Esto convierte a la herramienta personalizada en el lugar natural para insertar un control determinista. La propia documentación señala que &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/adding-custom-tools.md&quot;&gt;una herramienta personalizada puede validar entradas, imponer límites de tasa, redactar información sensible o comprobar autorización antes de hacer el trabajo&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;
Situado en el recorrido de madurez, el ecosistema ofrece, por tanto, los tres ingredientes de la mínima agencia: un catálogo que se puede recortar, una política que puede exigir aprobación humana y un punto (&lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/adding-custom-tools.md&quot;&gt;la herramienta personalizada&lt;/a&gt;) donde insertar la comprobación determinista. Conviene, eso sí, ser preciso sobre el límite: las políticas de permisos binarias no se aplican a las herramientas personalizadas. Es decir, para una herramienta personalizada, el control no lo da la política de permiso, sino la lógica que quien la programa incluya dentro de ella. Lejos de ser una carencia, esto sitúa el control en el lugar correcto: dentro de código propio, determinista y auditable.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;u&gt;Continuando la maduración Zero Trust.&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;
El avance hacia un estadio óptimo consiste en no depender de un único mecanismo, sino en combinarlos según el riesgo de cada herramienta. Las herramientas inocuas pueden quedar en ejecución automática, pero las que tocan sistemas sensibles, tras aprobación humana. Las que requieren una decisión reproducible (comprobar que el identificador pertenece al usuario de la sesión, que la operación está dentro de la cuota, que el dato no contiene información que no deba salir) deben encapsularse como herramientas personalizadas con esa comprobación escrita en su interior. La forma madura consiste en asignar a cada herramienta el mecanismo que corresponde a su riesgo. &lt;br /&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;649&quot; data-original-width=&quot;485&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGlxuPvsCIvroRvztIaGw6Munmx4sWMdpXbWYXzTFmt8ZXBxrPSdENqyHKUlKYR2KI2pb48LVg_mLlJhaxy9R9xdnapH4UVUPD8YReOyl22-yhIImdXUzHRzE8egQuQBBhcoKeOLkbhBuXZe_8OU8hWB0CXFkF4lI2altrnGCW12nY0bXt7hsd/w299-h400/HackingIA_web.jpg&quot; width=&quot;299&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 19:&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking IA: Jailbreak, Prompt Injection, Hallucinations &amp;amp; Unalignment&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;escrito por &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Chema Alonso&lt;/a&gt; con la colaboración de &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/AmadorAparicio&quot; style=&quot;text-align: justify;&quot;&gt;Amador Aparicio&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/ManuelSLemos&quot; style=&quot;text-align: justify;&quot;&gt;Manuel S. Lemos&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;y&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/JPalanco&quot; style=&quot;text-align: justify;&quot;&gt;José Palanco&lt;/a&gt; en &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;
Un segundo avance, alineado con el principio de mínima agencia de &lt;i&gt;&lt;b&gt;OWASP&lt;/b&gt;&lt;/i&gt;, es preferir herramientas tipadas y de propósito estrecho frente a capacidades genéricas y potentes. Una herramienta de &lt;i&gt;&lt;b&gt;shell&lt;/b&gt;&lt;/i&gt; concede al agente la capacidad de ejecutar prácticamente cualquier cosa. Una herramienta personalizada que hace exactamente una operación, con una entrada válida y una salida acotada, reduce drásticamente lo que una inyección puede lograr a través de ella. Sustituir capacidades amplias por herramientas estrechas y verificables es, en sí mismo, un acto de reducción de agencia.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
4.3.- Segmentación: a qué puede conectarse el agente.&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
El principio.&lt;br /&gt;&lt;br /&gt;
Las dos preguntas anteriores (quién es el agente y qué se le permite hacer) se completan con una tercera del método &lt;i&gt;&lt;b&gt;Kipling&lt;/b&gt;&lt;/i&gt;: ¿dónde? Una vez que la entidad está dentro, &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; no concede libertad de movimientos, al contrario, compartimenta todo para que cada una de las entidades alcance solo los recursos que su tarea exige. Es el principio de microsegmentación, que &lt;i&gt;&lt;b&gt;NIST SP 800-207&lt;/b&gt;&lt;/i&gt; sitúa como enfoque fundamental en la arquitectura&lt;i&gt;&lt;b&gt; Zero Trust&lt;/b&gt;&lt;/i&gt;: dividir el entorno en segmentos pequeños y proteger cada recurso de forma que el acceso a uno de ellos no implique el acceso a los demás.&lt;br /&gt;&lt;br /&gt;
En un agente esto se reduce en el control del tráfico de salida. Un &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; comprometido por una inyección puede hacer daño también con aquello que puede comunicarse fuera: el servidor al que envía datos robados, el punto de mando del que recibe instrucciones, el servicio interno al que se conecta sin autorización. Segmentar a un &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; es decidir con qué puede hablar. Conviene distinguir este control del de la sección siguiente: &lt;u&gt;la segmentación define a qué destinos puede conectarse&lt;/u&gt; (el mapa de sus movimientos). La validación de salida vigila qué datos viajan por esas conexiones. Aquí se traza el mapa, allí se inspecciona la carga.&lt;br /&gt;&lt;br /&gt;
El requisito es doble: denegación por defecto (ningún destino no autorizado explícitamente) y una frontera establecida antes de que el &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; actúe, porque cualquier ventana sin restricciones es una ventana de &lt;i&gt;&lt;b&gt;exfiltración&lt;/b&gt;&lt;/i&gt;. &lt;br /&gt;&lt;br /&gt;&lt;u&gt;Cómo aplicarlo con el ecosistema Cloudflare.&lt;/u&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;
El despliegue resuelve la segmentación con un motor de políticas de salida que cumple ambos requisitos. La frontera antes de la acción está garantizada por diseño: ambos &lt;i&gt;&lt;b&gt;backends&lt;/b&gt;&lt;/i&gt; adjuntan la política de salida antes de iniciar cualquier código del &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt;, de modo que no existe ninguna ventana en la que un sandbox sin restringir alcance un destino no deseado.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/applying-egress-policies.md&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;492&quot; data-original-width=&quot;1146&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgUAIrY9SgV5sVRyHNa2Q128LcUcHHWZNFyfECWLXadbY7WXigZ813DTzfLyu1CAEzSudTZbnDQEj0B093C1GyC-gyX-ZyoAXwXS7hZxJmPuWfKXt7b62UBxNKEyLXN_84c1YdmBvTwH0Yc6-pgIn7wKGp3HL9gSNiaUnbPWZgh_use9Mvp5i_d/w640-h274/ZT9.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 20: &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/applying-egress-policies.md&quot;&gt;Políticas de conexión para Sanboxes de Agentes IA&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
La denegación por defecto está disponible, pero requiere que sea una decisión consciente. &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/applying-egress-policies.md&quot;&gt;El motor admite listas de permitidos y de no permitidos&lt;/a&gt;. La primera bloquea todo lo demás. La segunda, una lista solo de no permitidos, deja pasar al resto del acceso público. El primer modo es el que está alineado con &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; y la propia guía recomienda la denegación por defecto frente al permiso por defecto. El matiz que debe conocerse es, que una sesión que no encaja con ninguna política ni con una política general se ejecuta sin restricción alguna de salida. La denegación por defecto, por tanto, no es automática: se consigue con una política general restrictiva que ninguna sesión puede eludir. &lt;br /&gt;&lt;br /&gt;
El motor va más allá del filtrado por host. Sus reglas permiten cinco comportamientos (permitir, denegar, inyectar una credencial sin que el &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; vea el secreto, &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/securing-access.md&quot;&gt;enrutar a un servicio privado o pasar el tráfico por un &lt;i&gt;&lt;b&gt;proxy&lt;/b&gt;&lt;/i&gt; propio&lt;/a&gt;) y una regla de denegación prevalece siempre sobre cualquier permiso que también encaje.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;En &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/isolate-vs-vm-sandboxes.md&quot;&gt;MicroVM, además, la interceptación HTTPS está activada, de modo que incluso el tráfico TLS pasa por la política&lt;/a&gt;, cerrando el punto ciego del canal cifrado. 
Para recursos interno que no deben ser accesibles desde internet, la conexión &lt;i&gt;&lt;b&gt;VCP&lt;/b&gt;&lt;/i&gt; aporta un detalle valioso. El &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/connecting-to-private-services.md&quot;&gt;Agente IA ve únicamente los enlaces permitidos por su nombre, nunca los identificadores reales del servicio&lt;/a&gt;. No puede dirigirse a lo que no se le ha expuesto, porque no conoce su existencia. &lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/isolate-vs-vm-sandboxes.md&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1076&quot; data-original-width=&quot;1504&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEha1zFjJRjX62B9yeLohhW446V-vjxeJ_f-Ev-Jo9jL6Zt5NcbvENl22QiwWXv9CY0dmmuCG7URKkEJWOBHjbG4GIE5iKsuPeVMnAkdJ5zNpttVjUVWz3ac8mMKm2GEn0X26cwTUDupbMHZb4ZFXHs-io4jzY4YjpPOnryPrrOnnnj-y-SR1dyb/w640-h458/ZT11.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 21: &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/isolate-vs-vm-sandboxes.md&quot;&gt;Isolate vs. VM-based Sandboxes&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
Hay un límite que hay que señalar, porque es la excepción más importante del modelo. Ciertas herramientas no pasan por la política de salida (&lt;i&gt;&lt;b&gt;egress&lt;/b&gt;&lt;/i&gt;). Las herramientas de servidor de &lt;i&gt;&lt;b&gt;Anthropic&lt;/b&gt;&lt;/i&gt;, búsqueda y recuperación de web integradas ((&lt;i&gt;&lt;b&gt;web_fetch &lt;/b&gt;&lt;/i&gt;y &lt;i&gt;&lt;b&gt;web_search&lt;/b&gt;&lt;/i&gt;), se ejecutan en infraestructura de &lt;i&gt;&lt;b&gt;Anthropic&lt;/b&gt;&lt;/i&gt;, no en el &lt;i&gt;&lt;b&gt;sandbox&lt;/b&gt;&lt;/i&gt; ni en la cuenta de &lt;i&gt;&lt;b&gt;Cloudflare&lt;/b&gt;&lt;/i&gt;. &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/securing-access.md&quot;&gt;No hay visibilidad sobre ellas, no dejan rastro y la política no se les aplica&lt;/a&gt;. El despliegue las desactiva por defecto.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Existen variantes que &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/applying-egress-policies.md&quot;&gt;sí corren en la cuenta propia y dejan auditoria, pero que tampoco atraviesan la política por sesión&lt;/a&gt;, porque se despachan desde la infraestructura de renderizado y no desde dentro del sandbox. La segmentación solo se completa si se tiene en cuenta qué canales quedan fuera de ella.&lt;br /&gt;&lt;br /&gt;&lt;u&gt;
Continuando con la maduración Zero Trust.&lt;br /&gt;&lt;/u&gt;&lt;br /&gt;
El primer avance es adoptar deliberadamente la denegación por defecto: una política general restrictiva, con una lista de permisos acotada a lo que la tarea necesita, aplicada a toda sesión para que ninguna quede sin restricciones por no encajar con una política especifica. Es la diferencia entre bloquear lo no autorizado y bloquear solo lo que alguien recordó denegar. &lt;br /&gt;&lt;br /&gt;
El segundo es cerrar o vigilar los canales que escapan a la política. Como las herramientas de servidor de Anthropic no son observables ni filtrables, lo maduro es mantenerlas desactivadas y si se necesitan encauzarlas por las variantes que dejen auditoria, tratando ese rastro como parte de la observabilidad. Los recursos que jamás deban exponerse a internet van tras la conexión &lt;i&gt;&lt;b&gt;VPC&lt;/b&gt;&lt;/i&gt;, de modo que ni figuren entre los destinos que el agente puede nombrar. &lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2GfJLWBEMBt8RHGpsTtK0PdhERZoz6x6uKLn7i6ONZ2sSsGwL55B4xbRrrQZYosHvwyb_JQRfrd_EuzgHUWhUL3VGbLWlJAqKw3WGHhnlHOIvHwX08KjHJADjurWd4bSFTPVqgcKaBTqxK4dS7VxrHX_kSRiW2MAJ7ts7X6YLDAglG49pYnRY/s828/ZT12.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;379&quot; data-original-width=&quot;828&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2GfJLWBEMBt8RHGpsTtK0PdhERZoz6x6uKLn7i6ONZ2sSsGwL55B4xbRrrQZYosHvwyb_JQRfrd_EuzgHUWhUL3VGbLWlJAqKw3WGHhnlHOIvHwX08KjHJADjurWd4bSFTPVqgcKaBTqxK4dS7VxrHX_kSRiW2MAJ7ts7X6YLDAglG49pYnRY/w640-h292/ZT12.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 22: Canales de salida y su cobertura por la política de egress&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
El tercero aprovecha la inyección de credenciales como segmentación de identidad, no solo de red. Al inyectar el secreto de un servicio en la petición saliente sin que el agente lo vea, se separa el uso del servicio de la posesión de un secreto. El &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; habla con la &lt;i&gt;&lt;b&gt;API&lt;/b&gt;&lt;/i&gt;, pero no puede extraer la clave porque nunca la tiene. Llevar este patrón a toda integración sensible convierte cada secreto en algo que el agente usa sin custodiar.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Continúa: &quot;&lt;a href=&quot;https://www.elladodelmal.com/2026/08/como-desplegar-zero-trust-para-agentes.html&quot;&gt;Cómo desplegar Zero Trust para Agentes IA en Cloudflare (3)&lt;/a&gt;&quot;&lt;br /&gt;&lt;br /&gt;

&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div align=&quot;justify&quot;&gt;Un saludo,&amp;nbsp; &amp;nbsp;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;Autor&lt;/i&gt;: &lt;a href=&quot;https://mypublicinbox.com/Juaco507&quot;&gt;&lt;b&gt;Juan Luis Cuenca Ramos&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/Juaco507&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1663&quot; data-original-width=&quot;2060&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjM_ZyyqgoKziGKdraQ385RU1I1ukTztLSFAOaSUsZ8ksPUgQCpTWCSDysw0cDQ6q8VCgLJEptJDsmyXKjRUiEnGasa7TKqRIqdJW1ws38QadfKczE9mjrz2w_5Lvduck0_XlSkWKtpBI3zWofsZX7u050aiAAh-elyvUn8hU9ZerPM-cJWAtxh/w640-h516/juanluiscuenca.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://mypublicinbox.com/Juaco507&quot;&gt;Contactar con Juan Luis Cuenca Ramos&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/07/como-desplegar-zero-trust-para-agentes_01099167063.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhghqkss-qx0EX51ZzYXEyfCRFnl0ymRzPonOw4p0xaWBF0dOiZoDft2InkGOKW7fwLi4Uf0sW-Hi86zqAX9a-aJl_ZW1lES7oFhESwU6HKSZcSVUU-HFkeInkr4y2h3uy2yWB-4rWGVR_zh0WOfbw7sjvLAYtXwE1VnYWxsFKnEykjhJs6JnV3/s72-w640-h408-c/ZT_00.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-5135395311260505231</guid><pubDate>Tue, 28 Jul 2026 05:01:00 +0000</pubDate><atom:updated>2026-07-28T09:35:10.699+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">cine</category><category domain="http://www.blogger.com/atom/ns#">Comics</category><category domain="http://www.blogger.com/atom/ns#">Curiosidades</category><category domain="http://www.blogger.com/atom/ns#">Wikipedia</category><title>Marvel Cinematic Universe &quot;MCU&quot; Versión Siglo XX</title><description>&lt;div style=&quot;text-align: justify;&quot;&gt;Si os digo que soy un aficionado a &lt;i&gt;&lt;b&gt;Universo Marvel&lt;/b&gt;&lt;/i&gt;, los que me conozcáis sabréis que me estoy quedando corto. Pero dejémoslo ahí, en sólo eso, en que me gustan los Superhéroes de Marvel. Dicho esto, muchos de vosotros habréis visto, seguramente, las películas de &lt;a href=&quot;https://en.wikipedia.org/wiki/Marvel_Cinematic_Universe:_Phase_One&quot;&gt;Marvel Cinematic Universe Phase One&lt;/a&gt; o las nuevas de la &lt;a href=&quot;https://en.wikipedia.org/wiki/Marvel_Cinematic_Universe:_Phase_Two&quot;&gt;Phase Two&lt;/a&gt;. Pero antes de estas maravillas, tuvimos otro &lt;i&gt;&lt;b&gt;MCU&lt;/b&gt;&lt;/i&gt;, en versión &lt;i&gt;&lt;b&gt;Alpha&lt;/b&gt;&lt;/i&gt;, y es de lo que os voy a hablar ahora.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgMijH0ctN3geFuPGtXGV2xTJOJZs41Yy57ubUhoimRzG1tvEK5fbSdJJtO-Sz9vcgesaVKUl69AOXOMUPrHkCNJSJ2bd7HewyY06coZrm53jmWpTOeInluCbmXtLUD9Nj24_cO3XfaoCaMXG3cZFs2aRy5uooe9AOrRS1Fc8i2pN0wygbHs-i-/s940/MCU0.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;558&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgMijH0ctN3geFuPGtXGV2xTJOJZs41Yy57ubUhoimRzG1tvEK5fbSdJJtO-Sz9vcgesaVKUl69AOXOMUPrHkCNJSJ2bd7HewyY06coZrm53jmWpTOeInluCbmXtLUD9Nj24_cO3XfaoCaMXG3cZFs2aRy5uooe9AOrRS1Fc8i2pN0wygbHs-i-/w640-h380/MCU0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;Marvel Cinematic Universe &quot;MCU&quot; Versión Siglo XX&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Voy a dejar fuera de este artículo las películas de la trilogía de &lt;i&gt;&lt;b&gt;Spiderman&lt;/b&gt;&lt;/i&gt; y de &lt;i&gt;&lt;b&gt;Amazing Spiderman&lt;/b&gt;&lt;/i&gt;, que ya las damos por conectadas y parte del &lt;i&gt;&lt;b&gt;MCU&lt;/b&gt;&lt;/i&gt;. También la de &lt;i&gt;&lt;b&gt;Hulk&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;2003&lt;/b&gt;&lt;/i&gt;, que para mí forma parte también del &lt;i&gt;&lt;b&gt;MCU&lt;/b&gt;&lt;/i&gt;. Y las de &lt;i&gt;&lt;b&gt;X-Men&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;Fox&lt;/b&gt;&lt;/i&gt; con todas sus ramificaciones - incluida la serie Legion y la película de &lt;i&gt;&lt;b&gt;Los Nuevos Mutantes&lt;/b&gt;&lt;/i&gt;. Y las de &lt;i&gt;&lt;b&gt;Los 4 Fantásticos&lt;/b&gt;&lt;/i&gt; del &lt;i&gt;&lt;b&gt;Siglo XXI&lt;/b&gt;&lt;/i&gt;, que también son ya casi parte del &lt;i&gt;&lt;b&gt;MCU&lt;/b&gt;&lt;/i&gt;.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjg_6FGYUJnEnKCPmQpHI-_kRhffjbU1HBu0tnAKCPkTyEV5JWN_0rw2Ivt3C7Z3xbdlFSfOzMdIDyAuxvUNbtNw-_hpHa3YS1GdESQ1ty-egxkYwh-Qq8EqCu5gQk_yIzePMcD7wGEN6vUpJy8RJesCl4bJ71Q1BgQWiWy-eVxZyTuQlWSiUiB/s3252/MCU1.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1930&quot; data-original-width=&quot;3252&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjg_6FGYUJnEnKCPmQpHI-_kRhffjbU1HBu0tnAKCPkTyEV5JWN_0rw2Ivt3C7Z3xbdlFSfOzMdIDyAuxvUNbtNw-_hpHa3YS1GdESQ1ty-egxkYwh-Qq8EqCu5gQk_yIzePMcD7wGEN6vUpJy8RJesCl4bJ71Q1BgQWiWy-eVxZyTuQlWSiUiB/w640-h380/MCU1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 2: Los Héroes Marvel en el Siglo XX&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Voy a irme un poco más atrás, antes de que &lt;i&gt;&lt;b&gt;FOX&lt;/b&gt;&lt;/i&gt; y &lt;i&gt;&lt;b&gt;Marvel&lt;/b&gt;&lt;/i&gt; hicieran las modernas películas de superhéroes, a los años donde los&lt;i&gt;&lt;b&gt; Superhéroes de Marvel&lt;/b&gt;&lt;/i&gt;, durante el &lt;i&gt;&lt;b&gt;Siglo XX&lt;/b&gt;&lt;/i&gt;, hacían sus primeras apariciones. Un &lt;i&gt;&lt;b&gt;Marvel Cinematic Universe &quot;MCU&quot; Siglo XX&lt;/b&gt;&lt;/i&gt; que, si no lo conoces, te llamará la atención. Aquí van.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;b&gt;&lt;u&gt;Spider-Man&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Fue el primero de los superhéroes en saltar al mundo de la televisión con actores. Primero con unas apariciones muy para niños de &lt;i&gt;&lt;b&gt;5&lt;/b&gt;&lt;/i&gt; minutos que se llamaban &quot;&lt;a href=&quot;https://en.wikipedia.org/wiki/Spidey_Super_Stories&quot;&gt;Spidey Super Stories&lt;/a&gt;&quot; que se emitió de &lt;i&gt;&lt;b&gt;1974&lt;/b&gt;&lt;/i&gt; a &lt;i&gt;&lt;b&gt;1978&lt;/b&gt;&lt;/i&gt; y que tenía narradores de las historias. Entre otros, el mítico &lt;i&gt;&lt;b&gt;Morgan Freeman&lt;/b&gt;&lt;/i&gt;. Aquí tenéis un episodio.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;
&lt;center&gt;&lt;iframe allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&quot; allowfullscreen=&quot;&quot; frameborder=&quot;0&quot; height=&quot;315&quot; referrerpolicy=&quot;strict-origin-when-cross-origin&quot; src=&quot;https://www.youtube.com/embed/9QhYieJ7Zog?si=vlFeToRwZ1UjTLYr&quot; title=&quot;YouTube video player&quot; width=&quot;470&quot;&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;i&gt;Figura 3: &lt;a href=&quot;https://en.wikipedia.org/wiki/Spidey_Super_Stories&quot;&gt;Spider Super Stories&lt;/a&gt;&lt;/i&gt;&lt;/center&gt;

&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;En &lt;i&gt;&lt;b&gt;1977&lt;/b&gt;&lt;/i&gt; llego la primera película de &quot;&lt;a href=&quot;https://en.wikipedia.org/wiki/Spider-Man_(1977_film)&quot;&gt;Spider-Man&lt;/a&gt;&quot;, que fue de lo más famoso durante muchos años. Era un &lt;i&gt;&lt;b&gt;Piloto&lt;/b&gt;&lt;/i&gt; para la serie de &lt;i&gt;&lt;b&gt;Televisión&lt;/b&gt;&lt;/i&gt;, y el actor era el mítico por este papel &lt;a href=&quot;https://en.wikipedia.org/wiki/Nicholas_Hammond&quot;&gt;Nicholas Hammond&lt;/a&gt;. Ese mismo año, comenzaría la &lt;a href=&quot;https://en.wikipedia.org/wiki/The_Amazing_Spider-Man_(TV_series)&quot;&gt;Serie de TV &quot;Spider-Man&quot;&lt;/a&gt; que duró dos &lt;i&gt;&lt;b&gt;Temporadas&lt;/b&gt;&lt;/i&gt;, hasta &lt;i&gt;&lt;b&gt;Julio&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;1979&lt;/b&gt;&lt;/i&gt;. De esa serie, se construyeron dos películas, basadas en dos tramas de dos episodios cada una. En &lt;i&gt;&lt;b&gt;1979&lt;/b&gt;&lt;/i&gt; &lt;a href=&quot;https://en.wikipedia.org/wiki/Spider-Man_Strikes_Back&quot;&gt;Spider-Man &quot;Strikes Back&quot;&lt;/a&gt; y en &lt;i&gt;&lt;b&gt;1981&lt;/b&gt;&lt;/i&gt; &lt;a href=&quot;https://en.wikipedia.org/wiki/Spider-Man:_The_Dragon%27s_Challenge&quot;&gt;Spider-Man &quot;The Dragon´s Challenge&quot;&lt;/a&gt;.&amp;nbsp; El mercado del vídeo-club comenzaba a mandar.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&#39;allowfullscreen&#39; webkitallowfullscreen=&#39;webkitallowfullscreen&#39; mozallowfullscreen=&#39;mozallowfullscreen&#39; width=&#39;470&#39; height=&#39;266&#39; src=&#39;https://www.blogger.com/video.g?token=AD6v5dwo6KENHLD3AzsZYgBwW-5YrPR9-LTBrUlpbAjbVF-f72AIgTa5R3Z3siaXhPtkfTb-q94wlByC4hc&#39; class=&#39;b-hbp-video b-uploaded&#39; frameborder=&#39;0&#39;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 4: Trailers de las películas de Nicholas Hammond.&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;En &lt;i&gt;&lt;b&gt;1978&lt;/b&gt;&lt;/i&gt;, &lt;a href=&quot;https://en.wikipedia.org/wiki/Spider-Man_(Japanese_TV_series)&quot;&gt;Spider-Man tuvo una serie en Japón&lt;/a&gt;, mítica. Con &lt;i&gt;&lt;b&gt;41&lt;/b&gt;&lt;/i&gt; episodios de &lt;i&gt;&lt;b&gt;24&lt;/b&gt;&lt;/i&gt; minutos duró hasta el año &lt;i&gt;&lt;b&gt;1979&lt;/b&gt;&lt;/i&gt;, y tuvo una película corta, que era de la duración de un capítulo, pero que se sacó como extra y cómo &lt;a href=&quot;https://en.wikipedia.org/wiki/Spider-Man_(1978_film)&quot;&gt;Spider-Man japonés (mini-película)&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&#39;allowfullscreen&#39; webkitallowfullscreen=&#39;webkitallowfullscreen&#39; mozallowfullscreen=&#39;mozallowfullscreen&#39; width=&#39;470&#39; height=&#39;266&#39; src=&#39;https://www.blogger.com/video.g?token=AD6v5dxWIguNf0D14UAPp0PVIbXGsRjz3xJ1oQiqKbG_3Mg0KcyMxfIPIO5XPhEw4GVxGkawrd2xMv_E188&#39; class=&#39;b-hbp-video b-uploaded&#39; frameborder=&#39;0&#39;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 5: Spider-Man Japonés&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;Por supuesto, en el &lt;i&gt;&lt;b&gt;Siglo XX&lt;/b&gt;&lt;/i&gt; hubo muchas más series de &lt;i&gt;&lt;b&gt;Spider-Man&lt;/b&gt;&lt;/i&gt; de dibujos animados, pero eso es otra historía. Después vendrían las películas de &lt;i&gt;&lt;b&gt;Spider-Man&lt;/b&gt;&lt;/i&gt; más modernas que todos conocemos. Y si no las conoces...abandona este blog.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;b&gt;&lt;u&gt;The Incredible Hulk (con Daredevil y Thor)&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Mítico es esta primera iteración de &lt;a href=&quot;https://en.wikipedia.org/wiki/List_of_The_Incredible_Hulk_(1978_TV_series)_episodes&quot;&gt;The Incredible Hulk&lt;/a&gt;, con la mítica pareja de &lt;a href=&quot;https://en.wikipedia.org/wiki/Bill_Bixby&quot;&gt;Bill Bixie&lt;/a&gt; como &lt;i&gt;&lt;b&gt;Bruce Banner&lt;/b&gt;&lt;/i&gt; y &lt;a href=&quot;https://en.wikipedia.org/wiki/Lou_Ferrigno&quot;&gt;Lou Ferrigno&lt;/a&gt; como &lt;i style=&quot;font-weight: bold;&quot;&gt;The Hulk.&lt;/i&gt; La obra completa está formada por 2 películas para televisión para dar inicio a la saga, durante el año &lt;i&gt;&lt;b&gt;1977&lt;/b&gt;&lt;/i&gt;, llamadas &quot;&lt;a href=&quot;https://en.wikipedia.org/wiki/List_of_The_Incredible_Hulk_(1978_TV_series)_episodes#Pilot_movies_(1977)&quot;&gt;The Incredible Hulk&lt;/a&gt;&quot; y &quot;&lt;a href=&quot;https://en.wikipedia.org/wiki/List_of_The_Incredible_Hulk_(1978_TV_series)_episodes#Pilot_movies_(1977)&quot;&gt;The Return of the Incredible Hulk: A Death in the family&lt;/a&gt;&quot;. Después, la serie tuvo &lt;i&gt;&lt;b&gt;80&lt;/b&gt;&lt;/i&gt; capítulos hasta el año &lt;i&gt;&lt;b&gt;1982&lt;/b&gt;&lt;/i&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&#39;allowfullscreen&#39; webkitallowfullscreen=&#39;webkitallowfullscreen&#39; mozallowfullscreen=&#39;mozallowfullscreen&#39; width=&#39;470&#39; height=&#39;266&#39; src=&#39;https://www.blogger.com/video.g?token=AD6v5dzLrsy85fEMVaiKcX5XMTu2RmbvH67Dr9jggi0ugTb5ZLM6M9GvZ4K1Zh-iQRmfsDLPpn6UZgQWB1k&#39; class=&#39;b-hbp-video b-uploaded&#39; frameborder=&#39;0&#39;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 6: The Incredible Hulk&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Y de &lt;i&gt;&lt;b&gt;1988&lt;/b&gt;&lt;/i&gt; a &lt;i&gt;&lt;b&gt;1990&lt;/b&gt;&lt;/i&gt; tres películas, una cada año. La primera &quot;&lt;a href=&quot;https://en.wikipedia.org/wiki/The_Incredible_Hulk_Returns&quot;&gt;The Incredible Hulk Returns&lt;/a&gt;&quot; &lt;i&gt;&lt;b&gt;(1988)&lt;/b&gt;&lt;/i&gt; con &lt;i&gt;&lt;b&gt;The Mighty Thor&lt;/b&gt;&lt;/i&gt;, &quot;&lt;a href=&quot;https://en.wikipedia.org/wiki/The_Trial_of_the_Incredible_Hulk&quot;&gt;The Trial of the Incredible Hulk&lt;/a&gt;&quot; &lt;i&gt;&lt;b&gt;(1989)&lt;/b&gt;&lt;/i&gt; con &lt;i&gt;&lt;b&gt;Daredevil&lt;/b&gt;&lt;/i&gt;, y &quot;&lt;a href=&quot;https://en.wikipedia.org/wiki/The_Death_of_the_Incredible_Hulk&quot;&gt;The Death of the Incredible Hulk&lt;/a&gt;&quot; &lt;i&gt;&lt;b&gt;(1990)&lt;/b&gt;&lt;/i&gt;. Como podéis ver, dando entrada a más héroes del &lt;i&gt;&lt;b&gt;Universo Marvel&lt;/b&gt;&lt;/i&gt;, como &lt;i&gt;&lt;b&gt;Thor&lt;/b&gt;&lt;/i&gt; o &lt;i&gt;&lt;b&gt;Daredevil&lt;/b&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;b&gt;&lt;u&gt;Captain America&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;En el &lt;i&gt;&lt;b&gt;Siglo XX&lt;/b&gt;&lt;/i&gt; el &lt;i&gt;&lt;b&gt;Capitán Ameríca&lt;/b&gt;&lt;/i&gt; tuvo también su &quot;&lt;i&gt;&lt;b&gt;Trilogía&lt;/b&gt;&lt;/i&gt;&quot;. Las dos primeras &lt;i&gt;&lt;b&gt;TV Movies&lt;/b&gt;&lt;/i&gt; fueron en el año &lt;i&gt;&lt;b&gt;1977&lt;/b&gt;&lt;/i&gt;, donde se emitió &quot;&lt;a href=&quot;https://en.wikipedia.org/wiki/Captain_America_(1979_film)&quot;&gt;Captain America&lt;/a&gt;&quot; &lt;i&gt;&lt;b&gt;(1979)&lt;/b&gt;&lt;/i&gt; y &quot;&lt;a href=&quot;https://en.wikipedia.org/wiki/Captain_America_II:_Death_Too_Soon&quot;&gt;Captain America II: Dead too soon&lt;/a&gt;&quot; &lt;i&gt;&lt;b&gt;(1979)&lt;/b&gt;&lt;/i&gt; con &lt;a href=&quot;https://en.wikipedia.org/wiki/Reb_Brown&quot;&gt;Reb Brown&lt;/a&gt; como &lt;i&gt;&lt;b&gt;&quot;Capi&quot;&lt;/b&gt;&lt;/i&gt;. Y por último un &lt;i&gt;&lt;b&gt;Reborn&lt;/b&gt;&lt;/i&gt; con &quot;&lt;a href=&quot;https://en.wikipedia.org/wiki/Captain_America_(1990_film)&quot;&gt;Captain America&lt;/a&gt;&quot; &lt;i style=&quot;font-weight: bold;&quot;&gt;(1990)&lt;/i&gt;. Mundo vídeo club manda.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiijfRPNS4MmLKYypNjNjzES542OIrIQIPWVC8z6Xx2nz9bPGV_4DHCvs5YSFqnoMwBKNCTU6wsYBmHfPaqXYtwkGRz6rqBETWw7NUB-f52lldweEDxlybtstCPiFVH7oAr3nFVswDG807j_M0hGSEBximfo79MWzq9_bpIzCYbwTaCv_MB5fIR/s2312/MCU3.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1144&quot; data-original-width=&quot;2312&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiijfRPNS4MmLKYypNjNjzES542OIrIQIPWVC8z6Xx2nz9bPGV_4DHCvs5YSFqnoMwBKNCTU6wsYBmHfPaqXYtwkGRz6rqBETWw7NUB-f52lldweEDxlybtstCPiFVH7oAr3nFVswDG807j_M0hGSEBximfo79MWzq9_bpIzCYbwTaCv_MB5fIR/w640-h316/MCU3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 7: Películas de Captain America en el Siglo XX&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Pero el &lt;i&gt;&lt;b&gt;Capitán América&lt;/b&gt;&lt;/i&gt; fue un pionero, porque &lt;a href=&quot;https://en.wikipedia.org/wiki/Captain_America_(serial)&quot;&gt;en el año 1944 él tuvo su Serial de 15 capítulos&lt;/a&gt;, en plena &lt;i&gt;&lt;b&gt;II Guerra Mundia&lt;/b&gt;&lt;/i&gt;l. Aquí lo podéis ver íntegro en Youtube.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;
&lt;center&gt;&lt;iframe allow=&quot;accelerometer; autoplay; clipboard-write; encrypted-media; gyroscope; picture-in-picture; web-share&quot; allowfullscreen=&quot;&quot; frameborder=&quot;0&quot; height=&quot;315&quot; referrerpolicy=&quot;strict-origin-when-cross-origin&quot; src=&quot;https://www.youtube.com/embed/iD3s4HaQW4Q?si=zyFglqK4ORBn8eiy&quot; title=&quot;YouTube video player&quot; width=&quot;470&quot;&gt;&lt;/iframe&gt;&lt;br /&gt;&lt;i&gt;Figura 8: &lt;a href=&quot;https://www.youtube.com/watch?v=iD3s4HaQW4Q&quot;&gt;Captain America - Serial TV (1944)&lt;/a&gt;&lt;/i&gt;&lt;/center&gt;

&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Después de estos héroes, hemos tenido iniciativas individuales para algunos otros personajes de &lt;i&gt;&lt;b&gt;Marvel&lt;/b&gt;&lt;/i&gt;, no todos superhéroes, pero todos parte del &lt;i&gt;&lt;b&gt;MCU&lt;/b&gt;&lt;/i&gt;, que quede claro.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;b&gt;&lt;u&gt;Doctor Strange, The Punisher &amp;amp; Nick Fury&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Estos tres personajes son parte fundamental del &lt;i&gt;&lt;b&gt;MCU&lt;/b&gt;&lt;/i&gt; moderno, pero tuvieron sus inicios en el &lt;i&gt;&lt;b&gt;Siglo XX&lt;/b&gt;&lt;/i&gt;. El primero de ellos, el &lt;a href=&quot;https://en.wikipedia.org/wiki/Dr._Strange_(1978_film)&quot;&gt;Doctor Strange&lt;/a&gt;, que en &lt;i&gt;&lt;b&gt;1978&lt;/b&gt;&lt;/i&gt; tuvo una &lt;a href=&quot;https://en.wikipedia.org/wiki/Dr._Strange_(1978_film)&quot;&gt;Película de Televisión&lt;/a&gt;. Y ésta, os lo confieso, aún no me la he visto.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&#39;allowfullscreen&#39; webkitallowfullscreen=&#39;webkitallowfullscreen&#39; mozallowfullscreen=&#39;mozallowfullscreen&#39; width=&#39;470&#39; height=&#39;266&#39; src=&#39;https://www.blogger.com/video.g?token=AD6v5dz_wLwbKybrQBDJUjOIEIeULaK6edm5XaTBV7dJyET_jmoh2hoSU7615nQHcvU520_FXSjRo21TyOA&#39; class=&#39;b-hbp-video b-uploaded&#39; frameborder=&#39;0&#39;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 9: &lt;a href=&quot;https://en.wikipedia.org/wiki/Dr._Strange_%281978_film%29&quot;&gt;Doctor Strange 1978&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;En &lt;i&gt;&lt;b&gt;1989&lt;/b&gt;&lt;/i&gt;, tuvimos la película de &quot;&lt;a href=&quot;https://en.wikipedia.org/wiki/The_Punisher_(1989_film)&quot;&gt;The Punisher&lt;/a&gt;&quot; protagonizada por el mítico &lt;a href=&quot;https://en.wikipedia.org/wiki/Dolph_Lundgren&quot;&gt;Dolp Lundgren&lt;/a&gt;, en una peli que tienes en &lt;i&gt;&lt;b&gt;Disney+&lt;/b&gt;&lt;/i&gt; disponible hoy en día, y que me la vi hace muy poquito.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&#39;allowfullscreen&#39; webkitallowfullscreen=&#39;webkitallowfullscreen&#39; mozallowfullscreen=&#39;mozallowfullscreen&#39; width=&#39;470&#39; height=&#39;266&#39; src=&#39;https://www.blogger.com/video.g?token=AD6v5dzCXR9BkWtsF-JPpGR88aJetg5wHCTOYC3LA73Uy6IQ4-X7O9eIQjtMG8BQGoSgAR7BDq_0pM6cRUE&#39; class=&#39;b-hbp-video b-uploaded&#39; frameborder=&#39;0&#39;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 10: &lt;a href=&quot;https://en.wikipedia.org/wiki/The_Punisher_%281989_film%29&quot;&gt;The Punisher 1989&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Y la última de estos héroes que tantas veces se ven la caras juntos, es una &quot;&lt;i&gt;&lt;b&gt;mítica&lt;/b&gt;&lt;/i&gt;&quot; película de televisión de &quot;&lt;a href=&quot;https://es.wikipedia.org/wiki/David_Hasselhoff&quot;&gt;Nick Fury: Agent of S.H.I.E.L.D.&lt;/a&gt;&quot;, protagonizada por, ni más, ni menos, que el mismísimo &lt;a href=&quot;https://es.wikipedia.org/wiki/David_Hasselhoff&quot;&gt;David Hasselhoff&lt;/a&gt; en &lt;i&gt;&lt;b&gt;1998&lt;/b&gt;&lt;/i&gt;. Confiesa que ahora estás deseando verla.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&#39;allowfullscreen&#39; webkitallowfullscreen=&#39;webkitallowfullscreen&#39; mozallowfullscreen=&#39;mozallowfullscreen&#39; width=&#39;470&#39; height=&#39;266&#39; src=&#39;https://www.blogger.com/video.g?token=AD6v5dyzCAgtK56OHhARGLsIxvK1FiaIb628nxVf_wR_FurcwxONaAhFbAGzZh-GMy_t6oVlBQAMyUZeg8s&#39; class=&#39;b-hbp-video b-uploaded&#39; frameborder=&#39;0&#39;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 11: &lt;a href=&quot;https://es.wikipedia.org/wiki/David_Hasselhoff&quot;&gt;Nick Fury &quot;Agent of SHIELD&quot; 1998&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Pero no fueron todos lo superhéroes que tú conoces, aún hubo más personajes de &lt;i&gt;&lt;b&gt;Marvel&lt;/b&gt;&lt;/i&gt; que llegaron a la gran pantalla, que formaron parte de este particular &lt;i&gt;&lt;b&gt;MCU&lt;/b&gt;&lt;/i&gt; del &lt;i&gt;&lt;b&gt;Siglo XX&lt;/b&gt;&lt;/i&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;b&gt;&lt;u&gt;Howard The Duck, Blade &amp;amp; Night Man&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Una de las películas que fue de las más taquilleras de los héroes &lt;i&gt;&lt;b&gt;Marvel&lt;/b&gt;&lt;/i&gt; se encuentran aquí, donde &lt;a href=&quot;https://en.wikipedia.org/wiki/Howard_the_Duck_(film)&quot;&gt;Howard the Duck&lt;/a&gt; (&lt;i&gt;&lt;b&gt;1986)&lt;/b&gt;&lt;/i&gt; consiguió reventar las taquillas con este simpático y único personaje. Además, la película de &lt;a href=&quot;https://en.wikipedia.org/wiki/Blade_(1998_film)&quot;&gt;Blade: El Cazador de Vampiros&lt;/a&gt;, un personaje que llega de las páginas de &lt;i&gt;&lt;b&gt;Drácula&lt;/b&gt;&lt;/i&gt;, que en&amp;nbsp;&lt;i&gt;&lt;b&gt;1998&lt;/b&gt;&lt;/i&gt;, lo reventó. En esta última, con &lt;i&gt;&lt;b&gt;Santiago Segura&lt;/b&gt;&lt;/i&gt; como extra,&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&#39;allowfullscreen&#39; webkitallowfullscreen=&#39;webkitallowfullscreen&#39; mozallowfullscreen=&#39;mozallowfullscreen&#39; width=&#39;470&#39; height=&#39;266&#39; src=&#39;https://www.blogger.com/video.g?token=AD6v5dwrBQXiwjX-bFsNoJpjUHMQJAv07RuD0gkJreLrJXu7gxjzWCo4FTrG14I8BfKtaArzxh8HZSwkjdw&#39; class=&#39;b-hbp-video b-uploaded&#39; frameborder=&#39;0&#39;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 12: &lt;a href=&quot;https://en.wikipedia.org/wiki/Howard_the_Duck_%28film%29&quot;&gt;Howard the Duck 1986&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Pero a estas hay que sumar otra película de un personaje &lt;i&gt;&lt;b&gt;Marvel&lt;/b&gt;&lt;/i&gt;, pero que vino de la línea &lt;i&gt;&lt;b&gt;Ultraverse&lt;/b&gt;&lt;/i&gt; (esto ya es para comiqueros) que se llama &lt;a href=&quot;https://en.wikipedia.org/wiki/Night_Man_(TV_series)&quot;&gt;Night Man&lt;/a&gt;, y que fue hecha en forma de serie para la televisión, con dos temporadas.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;b&gt;&lt;u&gt;Conan y el mundo bárbaro.&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Para terminar, si tenemos en cuenta que el personaje de &lt;i&gt;&lt;b&gt;CONAN&lt;/b&gt;&lt;/i&gt; se incorporó a &lt;i&gt;&lt;b&gt;Marvel&lt;/b&gt;&lt;/i&gt;, en el año &lt;i&gt;&lt;b&gt;1982&lt;/b&gt;&lt;/i&gt; tuvimos la mítica &lt;a href=&quot;https://en.wikipedia.org/wiki/Conan_the_Barbarian_(1982_film)&quot;&gt;Conan el Bárbaro&lt;/a&gt; y en &lt;i&gt;&lt;b&gt;1984&lt;/b&gt;&lt;/i&gt; &lt;a href=&quot;https://en.wikipedia.org/wiki/Conan_the_Destroyer&quot;&gt;Conan el Destructor&lt;/a&gt;, además de la serie de televisión &lt;a href=&quot;https://en.wikipedia.org/wiki/Conan_the_Adventurer_(1997_TV_series)&quot;&gt;Conan el Aventurero&lt;/a&gt;&amp;nbsp;&lt;i&gt;&lt;b&gt;(1997–1998)&lt;/b&gt;&lt;/i&gt;. Y dentro de ese mundo, las películas de los personajes de &lt;a href=&quot;https://en.wikipedia.org/wiki/Red_Sonja_(1985_film)&quot;&gt;Red Sonja&lt;/a&gt; en &lt;i&gt;&lt;b&gt;1985&lt;/b&gt;&lt;/i&gt; y &lt;a href=&quot;https://en.wikipedia.org/wiki/Kull_the_Conqueror&quot;&gt;Kull el Conquistador&lt;/a&gt; en &lt;i&gt;&lt;b&gt;1997&lt;/b&gt;&lt;/i&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqpGSRhIpo_4KIJ3H_jRNybUGLHktu-RZuYQKdAY55ZK3yYiG9MGtttcxMdXjVX0ccj6ec381ilKQdvEUPo3fkwkh5DtPT1Z4FPVQdJVtiTdpZLzQLOqUq4zfwAp1eJWrkGpHQZmXcndvkES63jTdbhKGnm4QvPogLzub2Y41C0VPTVnDLVbzv/s1718/MCU5.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1252&quot; data-original-width=&quot;1718&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqpGSRhIpo_4KIJ3H_jRNybUGLHktu-RZuYQKdAY55ZK3yYiG9MGtttcxMdXjVX0ccj6ec381ilKQdvEUPo3fkwkh5DtPT1Z4FPVQdJVtiTdpZLzQLOqUq4zfwAp1eJWrkGpHQZmXcndvkES63jTdbhKGnm4QvPogLzub2Y41C0VPTVnDLVbzv/w640-h466/MCU5.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 13: MCU Siglo XX (Parte 2)&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;b&gt;&lt;u&gt;X-Men y Los 4 Fantasticos&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Para terminar, no quería hacerlo sin hablar de los mutantes. &lt;i&gt;&lt;b&gt;Fox&lt;/b&gt;&lt;/i&gt; lanzaría las películas de los mutantes &lt;i&gt;&lt;b&gt;X&lt;/b&gt;&lt;/i&gt; con cierto éxito, donde además estarían todas las de &lt;i&gt;&lt;b&gt;X-Men&lt;/b&gt;&lt;/i&gt;, más las de &lt;i&gt;&lt;b&gt;Logan/Lobezno&lt;/b&gt;&lt;/i&gt;, la serie de &lt;i&gt;&lt;b&gt;Legion&lt;/b&gt;&lt;/i&gt;, los &lt;i&gt;&lt;b&gt;Nuevos Mutantes&lt;/b&gt;&lt;/i&gt;, y &lt;i&gt;&lt;b&gt;Masacre&lt;/b&gt;&lt;/i&gt;, pero en el &lt;i&gt;&lt;b&gt;Siglo XX&lt;/b&gt;&lt;/i&gt;, justo antes de la primera &lt;i&gt;&lt;b&gt;X-Men&lt;/b&gt;&lt;/i&gt;, tuvimos la película de &lt;a href=&quot;https://en.wikipedia.org/wiki/Generation_X_(film)&quot;&gt;Generation X&lt;/a&gt;&amp;nbsp;&lt;i&gt;&lt;b&gt;(1996)&lt;/b&gt;&lt;/i&gt;, con &lt;i&gt;&lt;b&gt;Enma Frost&lt;/b&gt;&lt;/i&gt;, y &lt;i&gt;&lt;b&gt;Banshee&lt;/b&gt;&lt;/i&gt;, entre otros personajes de la serie.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&#39;allowfullscreen&#39; webkitallowfullscreen=&#39;webkitallowfullscreen&#39; mozallowfullscreen=&#39;mozallowfullscreen&#39; width=&#39;470&#39; height=&#39;266&#39; src=&#39;https://www.blogger.com/video.g?token=AD6v5dyfDs4XMjdhosksgefzElh2vDuNiak5WzEEG_uYgkbvnPIpYGmxUYi05eXHkENJfw5ViAx-xwbOv2c&#39; class=&#39;b-hbp-video b-uploaded&#39; frameborder=&#39;0&#39;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 14:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Generation_X_(film)&quot; style=&quot;text-align: justify;&quot;&gt;Generation X&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Y, a pesar de haber tenido su anuncio, la película de &lt;a href=&quot;https://es.wikipedia.org/wiki/Los_Cuatro_Fant%C3%A1sticos_(pel%C3%ADcula_no_estrenada)&quot;&gt;Los 4 Fantasicos de 1994 no se llegaría a estrenar&lt;/a&gt;&amp;nbsp;pero quedaría hecha por no perder los derechos. Así que la buscas la puedes encontrar, que salió al mercado del vídeo.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&#39;allowfullscreen&#39; webkitallowfullscreen=&#39;webkitallowfullscreen&#39; mozallowfullscreen=&#39;mozallowfullscreen&#39; width=&#39;470&#39; height=&#39;266&#39; src=&#39;https://www.blogger.com/video.g?token=AD6v5dyTW__4A9_4lMqUIof_fHN-BsXpqTsGjHIz_yRBrb4G2G5fKM7vjYIRz_7by-eb5AAE7PA4tvVNdoU&#39; class=&#39;b-hbp-video b-uploaded&#39; frameborder=&#39;0&#39;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 15: &lt;a href=&quot;https://en.wikipedia.org/wiki/The_Fantastic_Four_(unreleased_film)&quot;&gt;Los 4 Fantásticos 1994&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Muchas otros héroes se quedaron en el tintero, pero, no obstante, estaba claro que había interés por los personajes de &lt;i&gt;&lt;b&gt;Marvel&lt;/b&gt;&lt;/i&gt;, solo había que dar bien con la tecla para construir la obra de arte que fue el &lt;i&gt;&lt;b&gt;MCU: Phase One&lt;/b&gt;&lt;/i&gt;. Por si tenéis interés, os dejo el &lt;i&gt;&lt;b&gt;Time-Line del MCU Siglo XX&lt;/b&gt;&lt;/i&gt; que he creado para mí.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;b&gt;&lt;u&gt;MCU Siglo XX - Orden Cronológico&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;ul&gt;&lt;li&gt;1944:&amp;nbsp;&lt;span style=&quot;text-align: -webkit-center;&quot;&gt;&lt;a href=&quot;https://www.youtube.com/watch?v=iD3s4HaQW4Q&quot;&gt;Captain America - Serial TV (1944)&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;1974-1977: &lt;a href=&quot;https://en.wikipedia.org/wiki/Spidey_Super_Stories&quot;&gt;Spidey Super Stories&amp;nbsp;&lt;/a&gt;&amp;nbsp;(29 episodios)&lt;/li&gt;&lt;li&gt;1977: &lt;a href=&quot;https://en.wikipedia.org/wiki/Spider-Man_%281977_film%29&quot;&gt;Spider-Man: Piloto&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1977-1979: &lt;a href=&quot;https://en.wikipedia.org/wiki/The_Amazing_Spider-Man_%28TV_series%29&quot;&gt;Spider-Man: TV Series&lt;/a&gt;&amp;nbsp;(13 episodios)&lt;/li&gt;&lt;li&gt;1977: &lt;a href=&quot;https://en.wikipedia.org/wiki/List_of_The_Incredible_Hulk_%281978_TV_series%29_episodes#Pilot_movies_%281977%29&quot;&gt;The Incredible Hulk&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1977: &lt;a href=&quot;https://en.wikipedia.org/wiki/List_of_The_Incredible_Hulk_%281978_TV_series%29_episodes#Pilot_movies_%281977%29&quot;&gt;The Return of The Incredible Hulk: A Death in the Family&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1978-1979: &lt;a href=&quot;https://en.wikipedia.org/wiki/Spider-Man_(Japanese_TV_series)&quot;&gt;Spider-Man Japonés&lt;/a&gt;&amp;nbsp;(41 episodios)&lt;/li&gt;&lt;li&gt;1978: &lt;a href=&quot;https://en.wikipedia.org/wiki/Spider-Man_(1978_film)&quot;&gt;Spider-Man Japonés mini-película&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1978-1982: &lt;a href=&quot;https://en.wikipedia.org/wiki/List_of_The_Incredible_Hulk_%281978_TV_series%29_episodes&quot;&gt;The Incredible Hulk (TV Series)&lt;/a&gt;&amp;nbsp;(80 episodios)&lt;/li&gt;&lt;li&gt;1978:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Dr._Strange_(1978_film)&quot;&gt;Doctor Strange&lt;/a&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;1979:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Spider-Man_Strikes_Back&quot;&gt;Spider-Man &quot;Strikes Back&quot;&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1979:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Captain_America_(1990_film)&quot;&gt;Captain America&lt;/a&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;1979:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Captain_America_II:_Death_Too_Soon&quot;&gt;Captain America II: Dead too soon&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1981:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Spider-Man:_The_Dragon%27s_Challenge&quot;&gt;Spider-Man: The Dragon&#39;s Challenge&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1982:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Conan_the_Barbarian_(1982_film)&quot;&gt;Conan el Bárbaro&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1984:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Conan_the_Destroyer&quot;&gt;Conan el Destructor&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1985:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Red_Sonja_(1985_film)&quot;&gt;Red Sonja&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1986:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Howard_the_Duck_(film)&quot;&gt;Howard the Duck&lt;/a&gt;&amp;nbsp;&lt;/li&gt;&lt;li&gt;1988: &lt;a href=&quot;https://en.wikipedia.org/wiki/The_Incredible_Hulk_Returns&quot;&gt;The Incredible Hulk Returns&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1988:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Blade_(1998_film)&quot;&gt;Blade: Cazador de Vampiros&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1989:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/The_Trial_of_the_Incredible_Hulk&quot;&gt;The Trial of the Incredible Hulk&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1989: &lt;a href=&quot;https://en.wikipedia.org/wiki/The_Punisher_%281989_film%29&quot;&gt;The Punisher&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1990:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Captain_America_(1990_film)&quot;&gt;Captain America&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1990:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/The_Death_of_the_Incredible_Hulk&quot;&gt;The Death of the Incredible Hulk&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1994:&amp;nbsp;&lt;span style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://en.wikipedia.org/wiki/The_Fantastic_Four_(unreleased_film)&quot;&gt;Los 4 Fantásticos 1994&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;1996:&amp;nbsp;&lt;span style=&quot;text-align: center;&quot;&gt;&lt;a href=&quot;https://en.wikipedia.org/wiki/Generation_X_(film)&quot; style=&quot;text-align: justify;&quot;&gt;Generation X&lt;/a&gt;&lt;/span&gt;&lt;/li&gt;&lt;li&gt;1997-1999:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Night_Man_(TV_series)&quot;&gt;Night Man&lt;/a&gt;&amp;nbsp;(44 episodios)&lt;/li&gt;&lt;li&gt;1997-1998:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Conan_the_Adventurer_(1997_TV_series)&quot;&gt;Conan el Aventurero&lt;/a&gt;&amp;nbsp;(22 episodios)&lt;/li&gt;&lt;li&gt;1997:&amp;nbsp;&lt;a href=&quot;https://en.wikipedia.org/wiki/Kull_the_Conqueror&quot;&gt;Kull el Conquistador&lt;/a&gt;&lt;/li&gt;&lt;li&gt;1998:&amp;nbsp;&lt;a href=&quot;https://es.wikipedia.org/wiki/David_Hasselhoff&quot;&gt;Nick Fury: Agent of S.H.I.E.L.D.&lt;/a&gt;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;¡Saludos Malignos!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;Chema Alonso &lt;/b&gt;(&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;Contactar con Chema Alonso&lt;/a&gt;) &amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; font-style: italic; text-align: center;&quot;&gt;
&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;444&quot; data-original-width=&quot;800&quot; src=&quot;https://1.bp.blogspot.com/-wPU2d-hy3rM/XiyVNgM4kGI/AAAAAAAAy70/Pk1IP6-v7bQLVUNL2iWneVOgRP494eWrACLcBGAsYHQ/s640/MPICHemaalonso.jpg&quot; width=&quot;450&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/07/marvel-cinematic-universe-mcu-version.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgMijH0ctN3geFuPGtXGV2xTJOJZs41Yy57ubUhoimRzG1tvEK5fbSdJJtO-Sz9vcgesaVKUl69AOXOMUPrHkCNJSJ2bd7HewyY06coZrm53jmWpTOeInluCbmXtLUD9Nj24_cO3XfaoCaMXG3cZFs2aRy5uooe9AOrRS1Fc8i2pN0wygbHs-i-/s72-w640-h380-c/MCU0.jpg" height="72" width="72"/><thr:total>3</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-1034998639340577718</guid><pubDate>Mon, 27 Jul 2026 07:17:07 +0000</pubDate><atom:updated>2026-07-29T08:07:01.903+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Agentic</category><category domain="http://www.blogger.com/atom/ns#">Agentic AI</category><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">Anthropic</category><category domain="http://www.blogger.com/atom/ns#">Artificial Intelligence</category><category domain="http://www.blogger.com/atom/ns#">ciberseguridad</category><category domain="http://www.blogger.com/atom/ns#">Claude</category><category domain="http://www.blogger.com/atom/ns#">cloudflare</category><category domain="http://www.blogger.com/atom/ns#">hardening</category><category domain="http://www.blogger.com/atom/ns#">IA</category><category domain="http://www.blogger.com/atom/ns#">Inteligencia Artificial</category><category domain="http://www.blogger.com/atom/ns#">LLM</category><category domain="http://www.blogger.com/atom/ns#">OWASP</category><category domain="http://www.blogger.com/atom/ns#">Zero Trust</category><title>Cómo desplegar Zero Trust para Agentes IA en Cloudflare (1)</title><description>&lt;div align=&quot;justify&quot;&gt;Los modelos de lenguaje que aportan la inteligencia a un &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; procesan en un mismo flujo las instrucciones y los datos, no hay una frontera que distinga de forma fiable una orden legítima de una instrucción maliciosa incrustada en el contenido. Esa premisa estructural es la tesis de este documento: la seguridad del &lt;i&gt;&lt;b&gt;Agente de IA&lt;/b&gt;&lt;/i&gt; no puede residir en el propio modelo, sino en controles externos, deterministas y verificados de forma continua. Es, precisamente, la lógica del &lt;b&gt;&lt;u&gt;Zero Trust&lt;/u&gt;&lt;/b&gt;. &lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZ-TqCrW2QhW3-2EVMK451QM9gGqevtAwOcXEh_P3NrLM0kbQqj2scHGDFUm2SdXBWcDKZ4M5t-8pjMNuYC6JMArO-0sMGsfNyRD8wKcXhHbE6tm2vd2Y67T80wEHilJ21HHQchu-mEk436fA7dgk9xFui5EPlY0l1qMt0RJ6WQpnoW83WSSDJ/s940/ZT0.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;598&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZ-TqCrW2QhW3-2EVMK451QM9gGqevtAwOcXEh_P3NrLM0kbQqj2scHGDFUm2SdXBWcDKZ4M5t-8pjMNuYC6JMArO-0sMGsfNyRD8wKcXhHbE6tm2vd2Y67T80wEHilJ21HHQchu-mEk436fA7dgk9xFui5EPlY0l1qMt0RJ6WQpnoW83WSSDJ/w640-h408/ZT0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;Cómo desplegar Zero Trust para Agentes IA en Cloudflare (1)&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;En este artículo se pretende dar traslado a los principios &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt;, reconocidos por &lt;i&gt;&lt;b&gt;NIST, CISA, NSTAC, OWASP, CSA&lt;/b&gt;&lt;/i&gt; y &lt;i&gt;&lt;b&gt;Anthropic,&lt;/b&gt;&lt;/i&gt;&amp;nbsp;al despliegue de &lt;i&gt;&lt;b&gt;Agentes IA&lt;/b&gt;&lt;/i&gt; gestionados sobre la infraestructura de &lt;a href=&quot;https://cloudflare.com&quot;&gt;Cloudflare&lt;/a&gt;. Tras situar al agente como sujeto a proteger, se recorren siete dimensiones de control (&lt;i&gt;&lt;b&gt;identidad, acceso, segmentación, validación de datos, observabilidad, contención y gobernanza&lt;/b&gt;&lt;/i&gt;), mostrando en cada uno qué pide el principio, qué ofrece hoy la plataforma y cómo avanzar hacia un estadio de madurez óptimo. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;

1.-La premisa fundamental: el modelo como eslabón estructural.&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
La seguridad de un sistema agéntico parte de una observación que hay que tener presente, ya que en ella se basa todo lo demás. Los modelos de lenguaje frontera actuales, con independencia del proveedor, procesan en un mismo flujo las instrucciones del sistema, los datos que se le entregan, las instrucciones del usuario y, cuando existe, una instrucción maliciosa insertada en dichas instrucciones o incrustada en los datos. No posee una división en su arquitectura que identifique de forma fiable una orden legítima, de una instrucción inyectada en el contenido que analiza. Esto no es una limitación de un modelo concreto, es una propiedad estructural del paradigma. &lt;br /&gt;&lt;div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;649&quot; data-original-width=&quot;485&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGlxuPvsCIvroRvztIaGw6Munmx4sWMdpXbWYXzTFmt8ZXBxrPSdENqyHKUlKYR2KI2pb48LVg_mLlJhaxy9R9xdnapH4UVUPD8YReOyl22-yhIImdXUzHRzE8egQuQBBhcoKeOLkbhBuXZe_8OU8hWB0CXFkF4lI2altrnGCW12nY0bXt7hsd/w299-h400/HackingIA_web.jpg&quot; width=&quot;299&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 2:&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking IA: Jailbreak, Prompt Injection, Hallucinations &amp;amp; Unalignment&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;escrito por &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Chema Alonso&lt;/a&gt; con la colaboración de &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/AmadorAparicio&quot; style=&quot;text-align: justify;&quot;&gt;Amador Aparicio&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/ManuelSLemos&quot; style=&quot;text-align: justify;&quot;&gt;Manuel S. Lemos&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;y&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/JPalanco&quot; style=&quot;text-align: justify;&quot;&gt;José Palanco&lt;/a&gt; en &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;
El consenso en el sector así lo recoge. &lt;i&gt;&lt;b&gt;OWASP&lt;/b&gt;&lt;/i&gt; señala que la &lt;a href=&quot;https://genai.owasp.org/llmrisk/llm01-prompt-injection/&quot;&gt;inyección de Prompts es viable por la propia naturaleza de la IA Generativa &lt;/a&gt;y que debido a la influencia estocástica en el funcionamiento de los modelos, no está claro que exista un método eficaz a la hora de prevenirlo.&amp;nbsp;&lt;i style=&quot;text-align: left;&quot;&gt;&lt;b&gt;Microsoft&lt;/b&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt; lo enfoca desde la arquitectura: el modelo no ejecuta nada por sí mismo, simplemente genera la solicitud. &lt;a href=&quot;https://learn.microsoft.com/es-es/agent-framework/journey/llm-fundamentals&quot;&gt;Es el código de la aplicación o el framework quien lo interpreta y lo ejecuta&lt;/a&gt;, siendo esa separación un límite clave en la seguridad.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;b&gt;Anthropic&lt;/b&gt;&lt;/i&gt; por su parte señala en su marco de seguridad para agentes, que &lt;a href=&quot; https://cdn.prod.website-files.com/6889473510b50328dbb70ae6/6a1611a04085d7cd3dadc924_Claude-eBook-Zero-Trust-for-AI-Agents-05182026.pdf&quot;&gt;el Agente IA puede ser manipulado y que el daño que puede provocar es llevado a cabo a velocidad de máquina&lt;/a&gt;.&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
De esta premisa se deduce una consecuencia directa para el diseño: la seguridad no puede apoyarse en el modelo. Si las instrucciones del sistema son, para el modelo, un texto más dentro del mismo flujo que los datos, entonces los controles existentes para que el modelo “&lt;i&gt;&lt;b&gt;decida bien&lt;/b&gt;&lt;/i&gt;” son insuficientes por construcción. Una protección efectiva ha de apoyarse en controles externos al modelo y de forma determinista, para poder eliminar la dependencia interpretativa que este haga de su contexto.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Es la lógica que el &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; aplica desde su origen: &lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot;&gt;NIST sitúa la decisión de acceso en el punto de decisión de y un punto de aplicación de políticas (PDP/PEP) externos a la entidad que solicita el acceso&lt;/a&gt;&amp;nbsp;y el mismo estándar advierte que las entidades que no son personas, como los agentes de software, pueden ser inducidas a realizar acciones para las que no tienen privilegios.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;&lt;u&gt;2.- Zero Trust aplicado a agentes: principios y método.&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;
Esta es la base sobre la que se construye el resto del documento. Implementar &lt;i&gt;&lt;b&gt;Zero Trust en Agentes IA &lt;/b&gt;&lt;/i&gt;no es endurecer el modelo, sino restringir su autonomía con controles externos, deterministas y verificables de forma continua, de tal manera que la confianza no exista de forma implícita ni permanente, sino que sea evaluada en cada una de sus acciones.&lt;b&gt;&lt;u&gt;&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
2.1.- Los principios, aplicados a un sujeto que actúa solo.&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
El &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; no es un producto ni una arquitectura concreta, es un conjunto de principios rectores. Su premisa: la confianza no se concede de forma implícita, sino que se evalúa de forma continua, partiendo de que la red debe considerarse comprometida.&amp;nbsp;&lt;span style=&quot;text-align: left;&quot;&gt;Tres principios articulan esta premisa y los tres adquieren un matiz particular, cuando el sujeto no es una persona, sino un &lt;/span&gt;&lt;i style=&quot;text-align: left;&quot;&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt;&lt;span style=&quot;text-align: left;&quot;&gt; que interpreta objetivos y ejecuta acciones por sí mismo para conseguir sus metas.&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;230&quot; data-original-width=&quot;1300&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjuUFaBbJof-zd_VrxzaGNfuTUx2GF0hgSJT6wuktAfcZMo9T5RI84x51UrcMzwAct5x1q4UlqtcdkFIDJtzn9NdAejCcsUHeMxVmnPe8OeURr0DpZlvavHzp0lUPafkVqItDC0jCiv2IGLhJk5TZzzQZa94149KQ9HUSs0JDLMTdQz-3kQAWbg/w640-h114/zt1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 3: &lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot;&gt;Los tres principios Zero Trust aplicados al agente.&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div style=&quot;text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot;&gt;Elaboración propia a partir de (NIST, 2020).&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
El primero, &lt;i&gt;&lt;b&gt;Verificar Siempre&lt;/b&gt;&lt;/i&gt;: toda solicitud de acceso se autentica y se autoriza con independencia del origen, y hacerlo una vez no es suficiente. &lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot;&gt;La autenticación y la autorización han de ser dinámicas y han de reevaluarse durante la sesión&lt;/a&gt;. El estándar advierte que evaluar cada petición de forma aislada puede dejar pasar un ataque mantenido dentro de un rol autorizado, mientras tener el contexto en cuenta permite detectar desviaciones en relación con la tarea esperada. Esto se hace especialmente relevante en agentes, cuya actividad legítima es intensa y una anomalía en su comportamiento puede ser la primera señal de compromiso.&lt;br /&gt;&lt;br /&gt;
El segundo, &lt;i&gt;&lt;b&gt;Asumir la Brecha&lt;/b&gt;&lt;/i&gt;: se diseña dando por hecho que el compromiso ya ha ocurrido u ocurrirá. Se trabaja para limitar el daño. En agentes, esto es contener el radio de impacto (&lt;i&gt;&lt;b&gt;Blast radius&lt;/b&gt;&lt;/i&gt;) si el compromiso se ha producido o antes de que este suceda.&lt;br /&gt;&lt;br /&gt;
El tercero, &lt;i&gt;&lt;b&gt;Mínimo Privilegio&lt;/b&gt;&lt;/i&gt;: permitir solo el acceso estrictamente necesario para realizar una tarea. En el plano agéntico esto debe afinarse: no solo a que datos accede el agente, sino qué herramientas invoca, con qué frecuencia y sobre qué recursos. La autonomía deja de ser un valor por defecto, en línea con lo que describe &lt;i&gt;&lt;b&gt;OWASP&lt;/b&gt;&lt;/i&gt;, al tratar la agencia excesiva como un riesgo propio de las aplicaciones agénticas.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
2.2.- El control vive fuera del modelo: el modelo PDP/PEP.&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
De su premisa fundacional se desprende que el mecanismo donde se decide y se aplica la confianza no puede estar integrado en el propio sujeto. La arquitectura &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; lo resuelve separando estas funciones: la decisión recae en el &lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot;&gt;Punto de Decisión de Políticas (PDP&lt;/a&gt;&lt;b style=&quot;text-decoration-line: underline;&quot;&gt;)&lt;/b&gt; y su ejecución en un &lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot;&gt;Punto de Aplicación de Políticas (PEP)&lt;/a&gt;, siendo ambos componentes totalmente externos a la entidad que solicita el acceso.&amp;nbsp;&lt;span style=&quot;text-align: left;&quot;&gt;El objetivo fundamental de este diseño es acercar dichos controles al recurso protegido, reduciendo así al mínimo la zona de confianza implícita.&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;416&quot; data-original-width=&quot;1074&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgbepi5PKue5ffZvl_7d3lh61CuVhFFZVN1-ep_yJFEY1DkjqD0KNo6LfIgKWxvm-J7oOMstzndO4iZDXf9-Y6xVvrlkwg2TgOQLCzV6F4x4s7KMbngJFjLSnBilb0T1fk6NqCNl7-2adCNl7t_J4hyphenhyphenscsIM_7JeBP8TUn3cFbnLqjpeG8ddiOR/w640-h248/ZT2.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;Figura 4: Core Trust Zero Logical Core.&amp;nbsp;&lt;/span&gt;&lt;span style=&quot;text-align: left;&quot;&gt;Fuente:&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;http://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot; style=&quot;text-align: left;&quot;&gt;&lt;i&gt;NIST SP 800-207, Zero Trust Architecture · Dominio público&lt;/i&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
Esto encaja con la naturaleza del &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt;. El agente genera la intención de actuar, produciendo una secuencia de &lt;i&gt;&lt;b&gt;Tokens&lt;/b&gt;&lt;/i&gt; que representa una llamada a la herramienta, que &lt;a href=&quot;https://learn.microsoft.com/es-es/agent-framework/journey/llm-fundamentals&quot;&gt;es después el código externo quien interpreta y ejecuta&lt;/a&gt;.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;395&quot; data-original-width=&quot;904&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgt4MctsFQX4BOBFRt04PqBMliyvmUouucnvlAJz3xv_f2QEtcFgOMJw1-SiTsbCu84XHQDXidfvui_akZYS0QUDFz8wmP-mXXOMluUcqSaQM27cO4UXgT9gZn9OZ4vpZo_pFd1xqwTIrdpZqOP-cR8rGOUNHouuA5zBM5RhyphenhyphenjBoLHthi8wC-U8/w640-h280/ZT3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 5: El control fuera del modelo (PDP/PEP).&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-207.pdf&quot;&gt;Elaboración propia a partir de (NIST, 2020)&lt;/a&gt;.&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;Es en ese punto de ejecución, fuera del modelo, donde &lt;i&gt;&lt;b&gt;PEP&lt;/b&gt;&lt;/i&gt; puede evaluar y autorizar la acción de forma determinista. El control no consiste en convencer al modelo de que se comporte, sino en situar la decisión en un componente externo.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
2.3.- Test de diseño: ¿imposible o solo tedioso?&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
Tener un criterio práctico ayuda a evaluar cada control: hacerse la pregunta de si un posible ataque se convierte en algo “&lt;i&gt;&lt;b&gt;imposible&lt;/b&gt;&lt;/i&gt;” o si solo es algo tedioso, puede ser un principio. Los controles diseñados para añadir fricción son insuficientes ante un adversario que recorre sus pasos a gran escala y con un coste por intento descartable.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Esto importa a la hora de trabajar con &lt;i&gt;&lt;b&gt;Agentes IA&lt;/b&gt;&lt;/i&gt; por una razón concreta: &lt;a href=&quot;https://www.elladodelmal.com/2026/06/despliegue-zero-trust-para-agentes-ia.html&quot;&gt;un atacante que opera a través de un agente, o el propio agente comprometido, actúa a velocidad de máquina y con una paciencia cuasi ilimitada&lt;/a&gt;. Ante la duda, es preferible tener un control que impida una capacidad a mantener solo una limitación que ralentice una actividad dañina.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt; 
2.4.- El método para escribir políticas: la interrogación de cada acción. &lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
Definir el privilegio mínimo de cada uno de los agentes, exige un método para redactar políticas acceso. El &lt;a href=&quot;https://www.cisa.gov/sites/default/files/publications/NSTAC%20Report%20to%20the%20President%20on%20Zero%20Trust%20and%20Trusted%20Identity%20Management.pdf&quot;&gt;informe del NSTAC al Presidente&lt;/a&gt; recomienda el método &lt;i&gt;&lt;b&gt;Kipling&lt;/b&gt;&lt;/i&gt; añadiendo “&lt;i&gt;&lt;b&gt;cómo&lt;/b&gt;&lt;/i&gt;” &lt;i&gt;&lt;b&gt;(5W+H)&lt;/b&gt;&lt;/i&gt; para la redacción de políticas &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt;, como forma de determinar quien o qué puede acceder a la superficie que se quiere proteger. El método utiliza las seis preguntas &lt;b&gt;&lt;u&gt;quién, qué, cuándo, dónde, por qué y cómo&lt;/u&gt;&lt;/b&gt;, convirtiéndolas en atributos sobre los que se construye las reglas. &lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/publications/NSTAC%20Report%20to%20the%20President%20on%20Zero%20Trust%20and%20Trusted%20Identity%20Management.pdf&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;774&quot; data-original-width=&quot;2634&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiMVtBgvpmRxdpGGTg9YP07wfWbluxGdTUrs0TuM_xObNAuuL5ZerlUNN77Yhcp9oDok-76GqeTf7AUWjxfUInjiCZXsXLPWek1LZ_MTXnhdLdZNVWa0bn9teaaMRBc1ayr1rQTjetm0WRsWJgV8ZTZMaVpy3BaNio8SAVQn0VcQcbDQpwFoG2v/w640-h188/ZT5.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 6: &lt;a href=&quot;https://www.cisa.gov/sites/default/files/publications/NSTAC%20Report%20to%20the%20President%20on%20Zero%20Trust%20and%20Trusted%20Identity%20Management.pdf&quot;&gt;Método Kiplling para Zero Trust for Policy Creation&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
Aplicado a un &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt;, ofrece una visión interrogativa sobre cada acción: qué agente la solicita, qué herramienta pretende invocar, en qué momento, sobre qué recurso, con qué propósito y de qué manera.  Hay que precisar que el &lt;i&gt;&lt;b&gt;NSTAC&lt;/b&gt;&lt;/i&gt; recomienda el método para redactar políticas de acceso en general. Aplicarlo a cada acción de un agente y reevaluarlo de forma continua es una extensión natural llevado al plano agéntico, de forma que se alinee con el principio &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; de verificación continua.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Esa coherencia tiene una consecuencia de diseño: si cada acción se interroga como si fuera la primera, sin que el agente acumule una confianza que después pueda ser aprovechada, se cierra el vector del agente que se comporta de forma intachable hasta el momento de actuar, un riesgo que el propio &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; contempla al asumir la brecha y exigir reevaluación continua.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;&lt;u&gt;2.5.- Un recorrido por estadios, no un interruptor.&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;br /&gt;
Conviene encuadrar todo lo anterior en cómo el sector enfoca la adopción del &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt;: es un recorrido gradual. El &lt;a href=&quot;https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf&quot;&gt;modelo de madurez de CISA&lt;/a&gt; lo describe en cuatro estadios: tradicional, inicial, avanzado y óptimo. Subraya que la progresión es incremental, que puede llevar tiempo y que cada pilar avanza a su propio ritmo.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;703&quot; data-original-width=&quot;975&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgy22RFKV0r7V2BceUo2kGnN5_RJWP5YCb1VLzr-b_8bvOii0X8ZpMhPkhpmSwbkNo-XJ2Ab3AnUBk7vzAoGvl6lWjIlbaESYwrN7FKgLKC44xxm7q-fUTsjyO05xizP9MA-64G6FR3Rty__2DcleYdbpJJrpHzPlKCqgfrYtwJse0k2KFPHBn6/w640-h462/ZT7.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;Figura 7: &lt;/span&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf&quot; style=&quot;text-align: left;&quot;&gt;Zero Trust Maturity Model v2.0&lt;/a&gt;&lt;span style=&quot;text-align: left;&quot;&gt;. Fuente &lt;/span&gt;&lt;a href=&quot;https://www.cisa.gov/sites/default/files/2023-04/zero_trust_maturity_model_v2_508.pdf&quot; style=&quot;text-align: left;&quot;&gt;CISA&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;Situar un despliegue de agentes en ese recorrido permite reconocer lo ya resuelto y orientar las aportaciones hasta el siguiente estadio, que &lt;i&gt;&lt;b&gt;CISA&lt;/b&gt;&lt;/i&gt; define con rasgos como el acceso justo a tiempo (&lt;i&gt;&lt;b&gt;JIT&lt;/b&gt;&lt;/i&gt;) y justo lo necesario, el privilegio mínimo dinámico, las políticas que responden a disparadores automáticos y la verificación continua. Esos rasgos del estadio optimo serán la referencia hacia la que se orientará la sección de aplicación.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
3.- El sujeto: el agente gestionado en Cloudflare (managed-agent).&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
Antes de aplicar controles es perceptivo definir que es lo que se controla. El modelo &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; razona sobre entidades que solicitan acceso a recursos y trasladar ese razonamiento a un &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; exige saber que partes lo componen, donde se ejecuta cada y que frontera de confianza lo separan. Esta sección sitúa al agente como un sujeto &lt;i&gt;&lt;b&gt;Zero Trust,&lt;/b&gt;&lt;/i&gt; señalando aquellos puntos donde, en la sección siguiente, enganchan concretamente los controles. &lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
3.1.- Dos formas de ejecutar un agente, una misma capacidad. &lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;&lt;i&gt;&lt;b&gt;
Anthropic&lt;/b&gt;&lt;/i&gt; &lt;a href=&quot;https://code.claude.com/docs/en/agent-sdk/overview&quot;&gt;distribuye la misma capacidad agéntica en dos formatos operativos&lt;/a&gt; distintos:&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;ul&gt;&lt;li&gt;El &lt;i&gt;&lt;b&gt;Agente SDK&lt;/b&gt;&lt;/i&gt; es una librería que ejecuta un bucle del agente, la lógica decide el paso siguiente, enruta las llamadas a herramientas y realimenta los resultados, todo dentro del propio proceso.&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;i&gt;&lt;b&gt;Managed Agents&lt;/b&gt;&lt;/i&gt;, en cambio, es una &lt;i&gt;&lt;b&gt;API REST &lt;/b&gt;&lt;/i&gt;gestionada en la que &lt;i&gt;&lt;b&gt;Anthropic&lt;/b&gt;&lt;/i&gt; ejecuta el agente y el sandbox, mientras la aplicación envía eventos y recibe los resultados de forma continua a medida que se producen.&lt;/li&gt;&lt;/ul&gt;&lt;span style=&quot;text-align: left;&quot;&gt;La &lt;a href=&quot;https://code.claude.com/docs/en/agent-sdk/overview&quot;&gt;recomendación publicada por Anthropic&lt;/a&gt; es prototipar localmente con el &lt;i&gt;&lt;b&gt;Agent SDK&lt;/b&gt;&lt;/i&gt; y pasar a &lt;i&gt;&lt;b&gt;Managed Agents&lt;/b&gt;&lt;/i&gt; para producción.&amp;nbsp;&lt;/span&gt;Esta distinción importa para &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; porque determina quien opera cada componente y, por tanto, donde puede situarse cada control.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;a href=&quot;https://platform.claude.com/docs/en/managed-agents/overview&quot;&gt;Managed Agents&lt;/a&gt; se organiza en torno a cuatro conceptos que conviene fijar, porque reaparecen en cada control posterior. El &lt;i&gt;&lt;b&gt;Agent&lt;/b&gt;&lt;/i&gt; (agente) es la definición del agente: el modelo, el prompt del sistema, las herramientas, los servidores &lt;i&gt;&lt;b&gt;MCP&lt;/b&gt;&lt;/i&gt; y las &lt;i&gt;&lt;b&gt;skills&lt;/b&gt;&lt;/i&gt;. Se crea una vez y se referencia a lo largo de muchas sesiones. El &lt;i&gt;&lt;b&gt;Environment&lt;/b&gt;&lt;/i&gt; (entorno) es la configuración de donde se ejecutan las sesiones: un &lt;i&gt;&lt;b&gt;sandbox&lt;/b&gt;&lt;/i&gt; en la nube gestionado por &lt;i&gt;&lt;b&gt;Anthropic&lt;/b&gt;&lt;/i&gt; o un &lt;i&gt;&lt;b&gt;sandbox&lt;/b&gt;&lt;/i&gt; ‘&lt;i&gt;&lt;b&gt;serf-hosted&lt;/b&gt;&lt;/i&gt;’ sobre la infraestructura propia. La &lt;i&gt;&lt;b&gt;Session&lt;/b&gt;&lt;/i&gt; (sesión) es una instancia del agente en ejecución dentro de un entrono, que realiza una tarea concreta y genera salidas.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Los &lt;i&gt;&lt;b&gt;Events&lt;/b&gt;&lt;/i&gt; (eventos) son los mensajes que se intercambian entre la aplicación y el agente: turnos del usuario, resultados de herramientas y actualizaciones de estado. Esa cuarta pieza, los &lt;i&gt;&lt;b&gt;Events&lt;/b&gt;&lt;/i&gt;, para un entorno &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; es más relevante de lo que a priori resultaría ser. El historial de eventos persiste en el lado del servidor y puede recuperarse íntegro, lo que convierte a la sesión en un registro auditable de todo lo que el agente ha hecho.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;698&quot; data-original-width=&quot;1200&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEic0sJBSrwCb5N8Ecd0JkkPvdxF2b3Jsnnsc1RWQ8VntdbF3y75kdhGlvLl6B6ootpW8gnGbGpBre6XCr5Fwt-Ajp2HDl01VXjOVZp4z7UiSX-XjrZK8R1VLf8w8a02L7QqQL2jFP2Ed_-WxvLtQ6KdD8ULqYQ7xMTm4jI9FcY9n4XA8QcLxA7W/w640-h372/ZT8.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 8: &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents&quot;&gt;Despliegue de referencia de Claude Managed Agents en Cloudflare&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Otro matiz, se refiere a entornos regulados: entre los casos de uso que se desprenden de la propia documentación, se señala la ejecución ‘&lt;i&gt;&lt;b&gt;self-hosted&lt;/b&gt;&lt;/i&gt;’, es decir, sandboxes sobre infraestructura propia para cumplimiento o residencia de datos.&amp;nbsp;&lt;span style=&quot;text-align: left;&quot;&gt;El &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents&quot;&gt;despliegue de referencia de Cloudflare&lt;/a&gt; se realiza en la forma de ejecución ‘&lt;i&gt;&lt;b&gt;self-hosted&lt;/b&gt;&lt;/i&gt;’: &lt;i&gt;&lt;b&gt;Anthropic&lt;/b&gt;&lt;/i&gt; define la capacidad y avisa del inicio y del final de cada sesión, mientras que el plano de control y los sandboxes donde el agente se ejecuta, se despliegan en la cuenta de Cloudflare de quien lo implementa.&amp;nbsp;&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;br /&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;b&gt;&lt;u&gt;3.2.- El plano de control: un Worker y un Durable Object por sesión.&lt;/u&gt;&lt;/b&gt;&lt;/span&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
En el &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents&quot;&gt;despliegue de referencia de Cloudflare&lt;/a&gt;, el plano de control es un único &lt;a href=&quot;https://www.cloudflare.com/products/workers/&quot;&gt;Cloudflare Worker&lt;/a&gt;. Ese &lt;i&gt;&lt;b&gt;Worker&lt;/b&gt;&lt;/i&gt; recibe los &lt;i&gt;&lt;b&gt;webhooks&lt;/b&gt;&lt;/i&gt; de la plataforma de &lt;i&gt;&lt;b&gt;Managed Agents&lt;/b&gt;&lt;/i&gt;, despacha cada sesión a una &lt;i&gt;&lt;b&gt;sandbox&lt;/b&gt;&lt;/i&gt; &lt;i&gt;&lt;b&gt;MicroVM&lt;/b&gt;&lt;/i&gt; o ‘&lt;i&gt;&lt;b&gt;Isolate&lt;/b&gt;&lt;/i&gt;’ y &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/architecture.md&quot;&gt;ofrece un panel de control&lt;/a&gt; por &lt;i&gt;&lt;b&gt;HTTPs&lt;/b&gt;&lt;/i&gt;. No mantiene ningún proceso de larga duración, sino que trabaja únicamente en respuesta a un &lt;i&gt;&lt;b&gt;webhook&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;Anthropic&lt;/b&gt;&lt;/i&gt; más un &lt;i&gt;&lt;b&gt;cron&lt;/b&gt;&lt;/i&gt; diario que elimina filas antiguas. Esta condición implica que no hay un servidor del &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt;&amp;nbsp; ‘&lt;i&gt;&lt;b&gt;siempre conectado&lt;/b&gt;&lt;/i&gt;’ que defender, sino una serie de activaciones acotadas y trazables. &lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/architecture.md&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;830&quot; data-original-width=&quot;813&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiXUe9cTpxS57tauwr5mPBOP-Bee4RRH4752zMAIqE3AK5-hAae-rmS8lVRnw6U13nnsRsnLq1hRQs6WT8ZVPW0KPKXt6FEFbwfMJYChPVET2-y38QdIWxk0uGZOk2MmSmsFOk3omXn8Oegp3BzPQN3lIuyAFZpqlCKhJzO8DTrOTqd2lE-f7Cs/w626-h640/ZT9.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;Figura 9:&amp;nbsp;&lt;/span&gt;&lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/architecture.md&quot; style=&quot;text-align: left;&quot;&gt;Arquitectar del despliegue de referencia de Cloudflare&lt;/a&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&amp;nbsp;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;
Una pieza decisiva desde la perspectiva &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt; es que una sesión está respaldada por un ‘&lt;i&gt;&lt;b&gt;Durable Object&lt;/b&gt;&lt;/i&gt;’ que se ejecuta en &lt;i&gt;&lt;b&gt;Workers&lt;/b&gt;&lt;/i&gt;, fuera de la propia &lt;i&gt;&lt;b&gt;sandbox&lt;/b&gt;&lt;/i&gt;. La &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/architecture.md&quot;&gt;documentación de Cloudflare&lt;/a&gt; lo describe como un fragmento de código con estado que permite almacenar información sobre la sesión y controlarla desde una ubicación de confianza.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;En términos del modelo &lt;i&gt;&lt;b&gt;Zero Trust&lt;/b&gt;&lt;/i&gt;, esto sitúa el punto de decisión y el punto de aplicación de políticas &lt;i&gt;&lt;b&gt;(PDP/PEP)&lt;/b&gt;&lt;/i&gt; en un lugar distinto y de mayor confianza que el sujeto controlado: el agente se ejecuta dentro del sandbox, pero quien lo gobierna lo hace desde fuera. Es la separación que hace posible que un control sea determinista en lugar de depender de la voluntad del modelo, una distinción sobre la que se volverá en el punto &lt;i&gt;&lt;b&gt;4&lt;/b&gt;&lt;/i&gt; adelante. 
&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/architecture.md&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;561&quot; data-original-width=&quot;890&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipL5cNSwemYtNGufBoG8yqNrmfTqU63-wZrgz42Ef33Xa5KwwEQ7lBQo3fLYspU-WjwAOK9msQA3BCePVxMtcJ0hlvJaSxVijfNz9XxpB8BSZ_C7zFaBXaek6GIYn5dMnQz_8UDR12keR1SZd9AW541wYFSBRk2JlrLSz0dGFU6ns0RgnllXbL/w640-h404/ZT10.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 10: &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/architecture.md&quot;&gt;Arquitectura del despliegue.&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
El ciclo de vida de una petición sigue seis pasos que conviene conocer porque cada uno es una oportunidad de control.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;ul&gt;&lt;li&gt;Primero un &lt;i&gt;&lt;b&gt;webhook&lt;/b&gt;&lt;/i&gt; entrante verifica mediante firma, &lt;i&gt;&lt;b&gt;HMAC-SHA256&lt;/b&gt;&lt;/i&gt; según la verificación &lt;i&gt;&lt;b&gt;Standard Webhooks&lt;/b&gt;&lt;/i&gt; con una tolerancia de &lt;i&gt;&lt;b&gt;+/-300&lt;/b&gt;&lt;/i&gt; segundos, guarda el evento en la base de datos &lt;i&gt;&lt;b&gt;D1&lt;/b&gt;&lt;/i&gt; en &lt;i&gt;&lt;b&gt;Cloudflare&lt;/b&gt;&lt;/i&gt; y cuando el evento indica que la sesión ha arrancado, pasa a atender el trabajo pendiente.&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;ul&gt;&lt;li&gt;Segundo, recoge ese trabajo consultando la cola del entorno de &lt;i&gt;&lt;b&gt;Anthropic&lt;/b&gt;&lt;/i&gt;.&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;ul&gt;&lt;li&gt;Tercero, elige el &lt;i&gt;&lt;b&gt;backend&lt;/b&gt;&lt;/i&gt; de ejecución: la elección se hace por agente, se guarda en &lt;i&gt;&lt;b&gt;D1&lt;/b&gt;&lt;/i&gt; y queda en caché para las siguientes peticiones. Por defecto es &lt;i&gt;&lt;b&gt;MicroVM&lt;/b&gt;&lt;/i&gt;.&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Cuarto, envía el trabajo al &lt;i&gt;&lt;b&gt;sandbox&lt;/b&gt;&lt;/i&gt; elegido (el contenedor &lt;i&gt;&lt;b&gt;MicroVM&lt;/b&gt;&lt;/i&gt; o el &lt;i&gt;&lt;b&gt;Durable Object&lt;/b&gt;&lt;/i&gt; del &lt;i&gt;&lt;b&gt;Isolate&lt;/b&gt;&lt;/i&gt;) y aquí ocurre el paso decisivo: ambos aplican la política del ‘&lt;i&gt;&lt;b&gt;egress&lt;/b&gt;&lt;/i&gt;’ de la sesión antes de iniciar cualquier código del agente.&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Quinto, ejecuta: en &lt;i&gt;&lt;b&gt;MicroVM&lt;/b&gt;&lt;/i&gt; las herramientas estándar (&lt;i&gt;&lt;b&gt;bash&lt;/b&gt;&lt;/i&gt;, operaciones de ficheros) corren dentro del contenedor, mientras que las herramientas personalizadas las atiende un despachador alojado en el &lt;i&gt;&lt;b&gt;Durable Object&lt;/b&gt;&lt;/i&gt;; en &lt;i&gt;&lt;b&gt;Isolate&lt;/b&gt;&lt;/i&gt; no hay contenedor y tanto las operaciones de fichero como la ejecución de código se hacen a través del mismo despachador.&amp;nbsp;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;Sexto, el estado persiste: &lt;i&gt;&lt;b&gt;MicroVM&lt;/b&gt;&lt;/i&gt; guarda una instantánea de su directorio de trabajo en el almacenamiento de objetos &lt;a href=&quot;https://www.cloudflare.com/products/r2/&quot;&gt;R2&amp;nbsp;de Cloudflare&lt;/a&gt; cuando la sesión se queda inactiva e Isolate lo conserva automáticamente en el almacenamiento &lt;i&gt;&lt;b&gt;SQLite&lt;/b&gt;&lt;/i&gt; de su &lt;i&gt;&lt;b&gt;Durable Object&lt;/b&gt;&lt;/i&gt;.&lt;/li&gt;&lt;/ul&gt;
De todo eso conviene destacar el cuarto paso. Tanto el &lt;i&gt;&lt;b&gt;backend&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;MicroVM&lt;/b&gt;&lt;/i&gt; como el de &lt;i&gt;&lt;b&gt;Isolate&lt;/b&gt;&lt;/i&gt; adjuntan la política de ‘&lt;i&gt;&lt;b&gt;egress&lt;/b&gt;&lt;/i&gt;’ de la sesión antes de iniciar cualquier código del &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt;. Es decir la frontera de red de la sesión queda establecida antes de que el agente pueda actuar, no después. Esta precedencia reaparecerá como un patrón en varios controles de la sección &lt;i&gt;&lt;b&gt;4 &lt;/b&gt;&lt;/i&gt;más adelante en este artículo.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
3.3.- Dos backends de ejecución y un reparto explícito de responsabilidades.&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
El &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; se ejecuta en uno de dos backends. El &lt;i&gt;&lt;b&gt;backend MicroVM&lt;/b&gt;&lt;/i&gt; utiliza una &lt;i&gt;&lt;b&gt;sandbox SDK&lt;/b&gt;&lt;/i&gt; y los contenedores de &lt;i&gt;&lt;b&gt;Cloudflare&lt;/b&gt;&lt;/i&gt;, ofreciendo un &lt;i&gt;&lt;b&gt;shell&lt;/b&gt;&lt;/i&gt; completo dentro del contenedor y persistiendo su directorio de trabajo mediante snaptshots a almacenamiento de objetos. El &lt;i&gt;&lt;b&gt;backend&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;Isolate&lt;/b&gt;&lt;/i&gt; se construye sobre &lt;a href=&quot;https://developers.cloudflare.com/agents/&quot;&gt;Agents SDK de Cloudflare y los Dynamic Workers.&lt;/a&gt; No tiene contenedor alguno y realiza las operaciones de sistema de ficheros y de ejecución de código a través de llamadas a herramientas dentro del propio &lt;a href=&quot;https://github.com/cloudflare/claude-managed-agents/blob/main/docs/isolate-vs-vm-sandboxes.md&quot;&gt;Durable Object con almacenamiento SQLite&lt;/a&gt;.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;La elección entre ambos tiene consecuencias para varios controles (observabilidad del terminal, intercepción de tráfico, superficie &lt;i&gt;&lt;b&gt;shell&lt;/b&gt;&lt;/i&gt;) que se detallan más adelante. Las sesiones &lt;i&gt;&lt;b&gt;Isolate&lt;/b&gt;&lt;/i&gt;, no admiten la conexión de terminal en vivo que si ofrece &lt;i&gt;&lt;b&gt;MicroVM&lt;/b&gt;&lt;/i&gt;. Bajo el &lt;i&gt;&lt;b&gt;backend&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;MicroVM&lt;/b&gt;&lt;/i&gt; subyace el &lt;a href=&quot;https://developers.cloudflare.com/sandbox/concepts/security/&quot;&gt;modelo de seguridad de Sandbox SDK, que conviene leer en clave Zero Trust&lt;/a&gt; porque reparte las responsabilidades de forma explícita. Cada sandbox se ejecuta en su propia máquina virtual, lo que proporciona un aislamiento fuerte.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://developers.cloudflare.com/agents/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1018&quot; data-original-width=&quot;1600&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgDv1uBoinWCk6UIs738qNBuPRqhqcxnTv2eQyABnz3SQwc-sdI_iwCKAZTTgzhOzbF17-ITFSWf624QQDqFOT6pFACcqapjXzLaLV1R8Q_9K9bgM1XOJ_Ib6Gi5ENAPYIDRI21TGevSKz5FP2R3I7V6g0Q4hBcgfHYlWNd2V_xIogV0IUq-nyC/w640-h408/ZT11.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 11: &lt;a href=&quot;https://developers.cloudflare.com/agents/&quot;&gt;Build Agents on Cloudflare&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Ese aislamiento, sin embargo, opera entre sandboxes no dentro de ellos. Entre &lt;i&gt;&lt;b&gt;sandboxes&lt;/b&gt;&lt;/i&gt; el sistema de ficheros, la memoria y la red están aislados, pero dentro del mismo sandbox todos los procesos ven los mismos ficheros, por lo que ejecutar código no confiable &lt;a href=&quot;https://developers.cloudflare.com/sandbox/concepts/containers/&quot;&gt;exige el uso de sandboxes separados por usuario&lt;/a&gt;.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Lo relevante para una guía de implementación, es que la documentación advierte que el aislamiento a nivel de contenedor no protege de forma automática de cualquier amenaza. El sandbox no puede explotarse para escapar del host, pero sí puede usarse indebidamente si no se aplican una serie de patrones de seguridad (validación de entrada, aislamiento por usuario, gestión de variables de entorno y protección de secretos). Esto &lt;a href=&quot;https://developers.cloudflare.com/sandbox/concepts/security/&quot;&gt;corresponde a quien despliega, no a la plataforma&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;
Todo esto es el punto de partida de todo lo que sigue. La sección &lt;i style=&quot;font-weight: bold;&quot;&gt;4 &lt;/i&gt;que tenemos en &lt;a href=&quot;https://www.elladodelmal.com/2026/07/como-desplegar-zero-trust-para-agentes_01099167063.html&quot;&gt;la siguiente parte de este artículo&lt;/a&gt;,&lt;i style=&quot;font-weight: bold;&quot;&gt;&amp;nbsp;&lt;/i&gt;recorre, dimensión por dimensión esa segunda lista (lo que corresponde a quien despliega el agente) y muestra donde el ecosistema de &lt;i&gt;&lt;b&gt;Cloudflare&lt;/b&gt;&lt;/i&gt; y de &lt;i&gt;&lt;b&gt;Anthropic&lt;/b&gt;&lt;/i&gt; ya ofrecen la pieza necesaria y dónde el avance hacia un estado de madurez más alto consiste en conectar esa pieza de forma debida. No se trata de suplir posibles carencias de la plataforma, sino de continuar con la maduración &lt;i&gt;&lt;b&gt;Zero Trust &lt;/b&gt;&lt;/i&gt;sobre los cimientos que la plataforma ya proporciona.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Un saludo,&amp;nbsp; &amp;nbsp;&lt;br /&gt;&lt;br /&gt;

&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;i&gt;Autor&lt;/i&gt;: &lt;a href=&quot;https://mypublicinbox.com/Juaco507&quot;&gt;&lt;b&gt;Juan Luis Cuenca Ramos&lt;/b&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/Juaco507&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1663&quot; data-original-width=&quot;2060&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjM_ZyyqgoKziGKdraQ385RU1I1ukTztLSFAOaSUsZ8ksPUgQCpTWCSDysw0cDQ6q8VCgLJEptJDsmyXKjRUiEnGasa7TKqRIqdJW1ws38QadfKczE9mjrz2w_5Lvduck0_XlSkWKtpBI3zWofsZX7u050aiAAh-elyvUn8hU9ZerPM-cJWAtxh/w640-h516/juanluiscuenca.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://mypublicinbox.com/Juaco507&quot;&gt;Contactar con Juan Luis Cuenca Ramos&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/07/como-desplegar-zero-trust-para-agentes.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZ-TqCrW2QhW3-2EVMK451QM9gGqevtAwOcXEh_P3NrLM0kbQqj2scHGDFUm2SdXBWcDKZ4M5t-8pjMNuYC6JMArO-0sMGsfNyRD8wKcXhHbE6tm2vd2Y67T80wEHilJ21HHQchu-mEk436fA7dgk9xFui5EPlY0l1qMt0RJ6WQpnoW83WSSDJ/s72-w640-h408-c/ZT0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-3525396899615905052</guid><pubDate>Sun, 26 Jul 2026 05:01:00 +0000</pubDate><atom:updated>2026-08-07T07:30:57.362+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Agentic</category><category domain="http://www.blogger.com/atom/ns#">Agentic AI</category><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">Artificial Intelligence</category><category domain="http://www.blogger.com/atom/ns#">ciberseguridad</category><category domain="http://www.blogger.com/atom/ns#">Hacking</category><category domain="http://www.blogger.com/atom/ns#">IA</category><category domain="http://www.blogger.com/atom/ns#">Inteligencia Artificial</category><category domain="http://www.blogger.com/atom/ns#">LLM</category><category domain="http://www.blogger.com/atom/ns#">LLMs</category><category domain="http://www.blogger.com/atom/ns#">metadata</category><category domain="http://www.blogger.com/atom/ns#">Metadatos</category><category domain="http://www.blogger.com/atom/ns#">Prompt Injection</category><title>Agent Data Injection Attacks</title><description>&lt;div style=&quot;text-align: justify;&quot;&gt;Este fin de semana he aprovechado par leerme un paper que ha sido publicado a principios de este mes, donde se habla de una variación de los ataques de &lt;i&gt;&lt;b&gt;Indirect Prompt Injection,&lt;/b&gt;&lt;/i&gt; utilizando una variante llamada &lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot;&gt;Agent Data Injection&lt;/a&gt;, y que está muy bien pensada, para lograr que un ataque cambie su comportamiento y realice acciones controladas por un atacante.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;634&quot; data-original-width=&quot;1172&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZGWyMD7vn6ZaYYTzQULxyPhZa4eQITeqOU8ZJVpKDam1V4bOab-2Uz0ybz4eA39M9CgFuU7h2gRBI6Pr1lT9LpUlc1EDUjLklmdbNTUxpUBTAEE02up8f5XWeHNaAPo8W2pWTSwGviDeefXR7HbpvduY9AkdVgbrEE_BoIFw-pe8xx1VrA0-D/w640-h346/ADI_0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;&lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot;&gt;Agent Data Injection Attacks&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Las técnicas de &lt;i&gt;&lt;b&gt;Indirect Prompt Injection&lt;/b&gt;&lt;/i&gt; buscan dejar &lt;i&gt;&lt;b&gt;Instrucciones Maliciosas&lt;/b&gt;&lt;/i&gt; almacenadas en fuentes de datos externas que un &lt;i&gt;&lt;b&gt;Agente IA&amp;nbsp;&lt;/b&gt;&lt;/i&gt;va a procesar para realizar su tarea. Al procesar esos datos inseguros, ya sean páginas &lt;i&gt;&lt;b&gt;web&lt;/b&gt;&lt;/i&gt;, repositorios de &lt;i&gt;&lt;b&gt;GitHub&lt;/b&gt;&lt;/i&gt; o correos electrónicos, el &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; va encontrarse un &lt;i&gt;&lt;b&gt;Prompt&lt;/b&gt;&lt;/i&gt; que va a cambiar su comportamiento produciendo un &lt;i&gt;&lt;b&gt;Desalineamiento&lt;/b&gt;&lt;/i&gt; de su funcionamiento.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;649&quot; data-original-width=&quot;485&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhGlxuPvsCIvroRvztIaGw6Munmx4sWMdpXbWYXzTFmt8ZXBxrPSdENqyHKUlKYR2KI2pb48LVg_mLlJhaxy9R9xdnapH4UVUPD8YReOyl22-yhIImdXUzHRzE8egQuQBBhcoKeOLkbhBuXZe_8OU8hWB0CXFkF4lI2altrnGCW12nY0bXt7hsd/w299-h400/HackingIA_web.jpg&quot; width=&quot;299&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 2:&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking IA: Jailbreak, Prompt Injection, Hallucinations &amp;amp; Unalignment&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;escrito por &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Chema Alonso&lt;/a&gt; con la colaboración de &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/AmadorAparicio&quot; style=&quot;text-align: justify;&quot;&gt;Amador Aparicio&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/ManuelSLemos&quot; style=&quot;text-align: justify;&quot;&gt;Manuel S. Lemos&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;y&lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt; &lt;/span&gt;&lt;a href=&quot;https://MyPublicInbox.com/JPalanco&quot; style=&quot;text-align: justify;&quot;&gt;José Palanco&lt;/a&gt; en &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Para evitar estos &lt;i&gt;&lt;b&gt;Desalineamiento&lt;/b&gt;&lt;/i&gt;, los modelos están siendo construidos con &lt;i&gt;&lt;b&gt;Guardarraíles&lt;/b&gt;&lt;/i&gt;, y los &lt;i&gt;&lt;b&gt;Agentes IA&lt;/b&gt;&lt;/i&gt; son diseñados con &lt;i&gt;&lt;b&gt;Harnesses&lt;/b&gt;&lt;/i&gt;, que evitan que el comportamiento final se salga de los objetivos para los que ha sido diseñado uno de estos &lt;i&gt;&lt;b&gt;Agentes IA&lt;/b&gt;&lt;/i&gt;. Teniendo en cuenta esto, el trabajo de &quot;&lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot;&gt;Agent Data Injection Attacks are Realistic Threats to AI Agents&lt;/a&gt;&quot; propone una nueva forma de desalinear al &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1492&quot; data-original-width=&quot;1156&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgqEq6K8ywTv0wsD5c21zQEgelUWIiV1H32CKLjC8zHc5W-kySEYTRheM33M9U44pTn0kLpl5Nm_-beSI1wVZ0b5-sA4YRvDiZmhMrqnV8hZhrKSlYqMS_Gy6L68lGjeitOWGMqfKtvCh57De4MWncoztlrKBjV0qVCX2nPwhu8ZZVAyQiS1qTc/w496-h640/ADI_1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 3:&amp;nbsp;&lt;span style=&quot;text-align: justify;&quot;&gt;&quot;&lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot;&gt;Agent Data Injection Attacks are Realistic Threats to AI Agents&lt;/a&gt;&quot;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;La aproximación en este caso no se trata de &lt;i&gt;&lt;b&gt;Inyectar Instrucciones Maliciosas&lt;/b&gt;&lt;/i&gt;, sino de &lt;i&gt;&lt;b&gt;Inyectar Objetos de Información&lt;/b&gt;&lt;/i&gt;, que formen parte de los &lt;i&gt;&lt;b&gt;Datos de Contexto&lt;/b&gt;&lt;/i&gt; del &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt;&amp;nbsp;para manipular la información sobre la que va a tomar sus decisiones y ejecutar sus acciones.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;888&quot; data-original-width=&quot;1078&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEixCuK2M-rD9qQa4ZJmQtM15-6MxrXFYNcBK-7d3YTBs_s7g2GmSIGQAD3FUbgMqhYARCSkU2HkT3es2zAeXJY3yMqNE4FngZREWLL6r7q3XV05fJ76C0og2m-5RgCFYjg-fJfv4PlfktTrl7ZQPZqw6Ae17DKsi75JpiLVpB222fGjrSErra4J/w640-h528/ADI_2.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 4: &lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot;&gt;Indirect Prompt Injection vs Agent Data Injection&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Como se ve en la imagen anterior, el objetivo es meter datos en los &lt;i&gt;&lt;b&gt;Agentes IA&lt;/b&gt;&lt;/i&gt;, y para eso se utilizan los Datos Inseguros que éste procesa - es decir, los &lt;i&gt;&lt;b&gt;e-mails&lt;/b&gt;&lt;/i&gt;, &lt;i&gt;&lt;b&gt;webs&lt;/b&gt;&lt;/i&gt;, repositorios de &lt;i&gt;&lt;b&gt;GitHub&lt;/b&gt;&lt;/i&gt;, etc... - con datos manipulados que simulan ser &lt;i&gt;&lt;b&gt;Objetos&lt;/b&gt;&lt;/i&gt; con &lt;i&gt;&lt;b&gt;Datos&lt;/b&gt;&lt;/i&gt; en el &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt;. Para hacer esto, hacen inyección de datos con separadores de información, como se ve en la imagen siguiente.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;868&quot; data-original-width=&quot;1758&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgWbxrD_fAnOvSEU_Gf3eVpbChN1SVFzr0tw7nii9EFXxAxMPaxN3UwEjJabhoe67UM2_j4-6fLmVrOPC0F-7T3V2ZGiUISolxFAv8BrtpaEePu7cyCLpniaqdTfbN9SUqbITxEVRBmLXSMLZ-RvsQUr3AqiG2xMh48JI-rxwBs8l69TF7Ehe-u/w640-h316/ADI_3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 5: &lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot;&gt;En el cuerpo del e-mail se mete un objeto&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot;&gt;completo que representa a un nuevo e-mail.&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Como se puede ver en la imagen, el &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; llama a una herramienta de lectura de datos inseguros, como una página web, o a la lista de correos electrónicos entregada por un &lt;i&gt;&lt;b&gt;MCP&lt;/b&gt;&lt;/i&gt;. Y en uno de esos correos se han inyectado caracteres para formar un &lt;i&gt;&lt;b&gt;Metadato&lt;/b&gt;&lt;/i&gt; que representa a un &lt;i&gt;&lt;b&gt;Objeto e-mail&lt;/b&gt;&lt;/i&gt;. Es decir, si miráis el &quot;&lt;i&gt;&lt;b&gt;Body&lt;/b&gt;&lt;/i&gt;&quot; del correo, veis que han inyectado un&lt;i&gt;&lt;b&gt; .\&quot;} &lt;/b&gt;&lt;/i&gt;que cierra el formato del primer &lt;i&gt;&lt;b&gt;Objeto&lt;/b&gt;&lt;/i&gt; &lt;i&gt;&lt;b&gt;e-mail&lt;/b&gt;&lt;/i&gt; para luego comenzar a inyectar un &lt;i&gt;&lt;b&gt;Objeto e-mail&lt;/b&gt;&lt;/i&gt; completo, codificando el mensaje con sus metadatos. El resultado final es que el &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; entiende que ha recibido &lt;i&gt;&lt;b&gt;2 Objetos e-mail&lt;/b&gt;&lt;/i&gt; en lugar de solo &lt;i&gt;&lt;b&gt;1&lt;/b&gt;&lt;/i&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;b&gt;&lt;u&gt;Ataques de Agent Data Injection&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Esto genera que un atacante pueda inyectar &lt;i&gt;&lt;b&gt;Objetos&lt;/b&gt;&lt;/i&gt; con &lt;i&gt;&lt;b&gt;Datos&lt;/b&gt;&lt;/i&gt; que van a ser parte de la toma de decisiones y acciones que realizará el &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt;. Por ejemplo, en el caso siguiente, el usuario pide resumir las revisiones de un determinado producto de una tienda. El &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; lanza la herramienta de leer página, y esta página le entrega los datos de formato de &lt;i&gt;&lt;b&gt;Objetos&lt;/b&gt;&lt;/i&gt;, delimitados por corchetes y los textos entrecomillados.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;995&quot; data-original-width=&quot;1592&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiam33z_R0dmhaY9UIojqjORuiTj66GF43TUBZstwwYFOXZPX5CMsN749TQfIsTnLoKQKafrt9SGCsrDc52JKmkIOMsGgYFGUN0e8y3fD0thjOPMfLOsOM-MjvqM2xmOAds0z7v6nU94vGHH3km_1fkdIlojXD1ZR-90y1061r_d5tuXwfa32WN/w640-h400/ADI_4.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 6: &lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot;&gt;La herramienta read_page() devuelve objetos de la web.&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Un atacante puede inyectar en una de las review los caracteres para inyectar un &lt;i&gt;&lt;b&gt;Objeto&lt;/b&gt;&lt;/i&gt; nuevo - como un botón - codificándolo con los caracteres con los que se construyen los metadatos de los objetos, dentro del Texto de una de las &lt;i&gt;&lt;b&gt;Review&lt;/b&gt;&lt;/i&gt;. En este caso un botón que no existe en la web de &quot;&lt;i&gt;&lt;b&gt;Read More&lt;/b&gt;&lt;/i&gt;&quot; con una &lt;i&gt;&lt;b&gt;Ref_3&lt;/b&gt;&lt;/i&gt;, que es la misma &lt;i&gt;&lt;b&gt;Ref_3&lt;/b&gt;&lt;/i&gt; que tiene el botón &quot;&lt;i&gt;&lt;b&gt;Buy Now&lt;/b&gt;&lt;/i&gt;&quot;. Así que, con el &lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot;&gt;Agent Data Injection&lt;/a&gt;, se ha conseguido forzar una compra cuando el &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt; quería simplemente &quot;&lt;i&gt;&lt;b&gt;Read More&lt;/b&gt;&lt;/i&gt;&quot;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1021&quot; data-original-width=&quot;1697&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhADz1MvwuStR9dgS1ivv5poBlUJD7OmmmtvAcTErJFUMfplhFeS8qtHsz5AtMU-7c05MXpJ5SPNfPGMyhUtzcvNRIrclDUREB-QtUJNZagDvz4WDyu_5Z5OW3J93NAQRrejkDUpzdHP69L-tEy_fkf3lhB6yJHLC4ADwMOfzBzavNPuPJA2zq6/w640-h386/ADI_5.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 7: S&lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot;&gt;e fuerza un compra pensando que iba a leer más&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;En el siguiente ejemplo se hace buscando en la &lt;i&gt;&lt;b&gt;Knowledge Base&lt;/b&gt;&lt;/i&gt;, donde se busca información sobre como solucionar un problema, y la herramienta devuelve el objeto con la respuesta que resuelve el problema. Si en esa respuesta de produce un &lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot;&gt;Agent Data Injection&lt;/a&gt;, esto se puede manipular.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;740&quot; data-original-width=&quot;1196&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEiBB9wanSnbIJB1S8Jbme6Rkt6ilw4mfHS8pRtOACEGKheUlu_EiGvLGsBewWwoCjJLvdOqLmBcoYo2-CSY-mGs_2RatKjbFi06GEiFpdn-U7TOvtEHCUxUQ8mG94bYUzzRY2Fh8_dFdZceAc15mw9pKYK6985oKtm-Qh7elUWPBPAxh8TWaiCu/w640-h396/ADI_6.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 8: &lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot;&gt;Resolución de problemas con instalación de un programa&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;
  &lt;div style=&quot;text-align: justify;&quot;&gt;El atacante inyecta un comentario que inyecta un objeto completo con una pregunta y una respuesta completa, pero cuya respuesta es maliciosa, formateando con los &lt;i&gt;&lt;b&gt;delimitadores&lt;/b&gt;&lt;/i&gt; de los &lt;i&gt;&lt;b&gt;metadatos&lt;/b&gt;&lt;/i&gt; el objeto malicioso.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;634&quot; data-original-width=&quot;1172&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEipCIiWyGl4f_YzMK_F-6OyBNYIAmN5V5flbjHyxBwQCuTEGpneY2EN62RzMYEWNV2iSS9O27PXNTWzYNQmHJy7O8Un1ISBBKm8UbV-ORkL-rNqeIoFijAO5rmi1ef92L3qt_i_91yYFZlQ95oTLS-6FQi7eZBIkYoOfDaRGVlNfWEULRx38FSk/w640-h346/ADI_9.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 9: &lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot;&gt;Inyección de un Objeto de problema con una solución fake&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Al final, estos ataques lo que hacen es buscar meter en el conjunto de datos que utiliza el &lt;i&gt;&lt;b&gt;Agente IA&lt;/b&gt;&lt;/i&gt;, datos como si fueran objetos con sus &lt;i&gt;&lt;b&gt;metadatos&lt;/b&gt;&lt;/i&gt; devueltos por la herramienta, haciendo inyección de &lt;i&gt;&lt;b&gt;delimitadores&lt;/b&gt;&lt;/i&gt; para formatear los objetos. Muy interesante.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/245-hacking-pentesting-con-inteligencia-artificial.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1688&quot; data-original-width=&quot;1298&quot; height=&quot;400&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEicZbq7z1QIW5RDLoHBFH4O2XtgQCjhHZ4YI70ksUtOQpkc1cersCsUNnlBy8wtEAnuOPOrm2KTYMBs9K3jCobjjSod4rx7ymfE0lcTFRy6LeGkzbpdGBBSx8LbifDrZfrgAsQDmDWu_rrz4htL0YJljBRe4esKTfZ0api8aLViQ398JCXBKsyX/w308-h400/HackingYPentestingconIA.jpg&quot; width=&quot;308&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;Figura 10: &lt;a href=&quot;https://0xword.com/es/libros/245-hacking-pentesting-con-inteligencia-artificial.html&quot; style=&quot;text-align: justify;&quot;&gt;Hacking &amp;amp; Pentesting con Inteligencia Artificial&lt;/a&gt;.&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;En &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;, &lt;/span&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;escrito por &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/PabloGonzalez&quot; style=&quot;text-align: justify;&quot;&gt;Pablo González&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/FranRamirez&quot; style=&quot;text-align: justify;&quot;&gt;Fran Ramírez&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;,&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://mypublicinbox.com/RafaelTroncoso&quot; style=&quot;text-align: justify;&quot;&gt;Rafael Troncoso&lt;/a&gt;&lt;span style=&quot;text-align: justify;&quot;&gt;, &lt;/span&gt;&lt;a href=&quot;https://mypublicinbox.com/JaviPino&quot; style=&quot;text-align: justify;&quot;&gt;Javier del Pino&lt;/a&gt; y &lt;span style=&quot;text-align: justify;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/chemaalonso&quot;&gt;Chema Alonso&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Por supuesto, es una técnica de inyección basada en la no satinización de los datos que tenemos en los modelos de &lt;i&gt;&lt;b&gt;IA&lt;/b&gt;&lt;/i&gt;, y esta técnica de &lt;a href=&quot;https://arxiv.org/pdf/2607.05120&quot;&gt;Agente Data Injection&lt;/a&gt; es a &lt;i&gt;&lt;b&gt;Prompt Injection&lt;/b&gt;&lt;/i&gt;, como lo son los &lt;a href=&quot;https://blackhat.com/presentations/bh-dc-10/Alonso_Chema/Blackhat-DC-2010-Alonso-Connection-String-Parameter-Pollution-wp.pdf&quot;&gt;Connection String Parameter Pollution Attacks&lt;/a&gt; a las técnicas de &lt;a href=&quot;https://0xword.com/es/libros/25-libro-hacking-aplicaciones-web-sql-injection.html&quot;&gt;SQL Injection&lt;/a&gt;. Mismo concepto, diferente manera de explotar, diferentes objetivos.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;¡Saludos Malignos!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;Chema Alonso &lt;/b&gt;(&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;Contactar con Chema Alonso&lt;/a&gt;) &amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; font-style: italic; text-align: center;&quot;&gt;
&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;444&quot; data-original-width=&quot;800&quot; src=&quot;https://1.bp.blogspot.com/-wPU2d-hy3rM/XiyVNgM4kGI/AAAAAAAAy70/Pk1IP6-v7bQLVUNL2iWneVOgRP494eWrACLcBGAsYHQ/s640/MPICHemaalonso.jpg&quot; width=&quot;450&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/07/agent-data-injection-attacks.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjZGWyMD7vn6ZaYYTzQULxyPhZa4eQITeqOU8ZJVpKDam1V4bOab-2Uz0ybz4eA39M9CgFuU7h2gRBI6Pr1lT9LpUlc1EDUjLklmdbNTUxpUBTAEE02up8f5XWeHNaAPo8W2pWTSwGviDeefXR7HbpvduY9AkdVgbrEE_BoIFw-pe8xx1VrA0-D/s72-w640-h346-c/ADI_0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-241151577974634463</guid><pubDate>Sat, 25 Jul 2026 08:09:44 +0000</pubDate><atom:updated>2026-07-25T17:22:57.429+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">Agentic</category><category domain="http://www.blogger.com/atom/ns#">Agentic AI</category><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">Bot</category><category domain="http://www.blogger.com/atom/ns#">Botnet</category><category domain="http://www.blogger.com/atom/ns#">Botnets</category><category domain="http://www.blogger.com/atom/ns#">bots</category><category domain="http://www.blogger.com/atom/ns#">cloudflare</category><category domain="http://www.blogger.com/atom/ns#">hardening</category><category domain="http://www.blogger.com/atom/ns#">IA</category><category domain="http://www.blogger.com/atom/ns#">Inteligencia Artificial</category><title>Cloudflare Turnstile &amp; Precursor: Cómo detectar Bots y Humanos sin usar Captchas Cognitivos</title><description>&lt;div style=&quot;text-align: justify;&quot;&gt;Muchas personas, usuarias de &lt;i&gt;&lt;b&gt;Internet&lt;/b&gt;&lt;/i&gt;, conocen a &lt;a href=&quot;https://www.cloudflare.com&quot;&gt;Cloudflare&lt;/a&gt; por el famoso &lt;i&gt;&lt;b&gt;widget&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;&quot;Verifica que eres Humano&quot;&lt;/b&gt;&lt;/i&gt; que está en muchas páginas web de &lt;i&gt;&lt;b&gt;Internet&lt;/b&gt;&lt;/i&gt;. Esta verificación ha hecho que la gente conozca mucho la marca de&amp;nbsp;&lt;a href=&quot;https://www.cloudflare.com&quot;&gt;Cloudflare&lt;/a&gt;&amp;nbsp;sin conocer todo lo que realmente hace la compañía, y es normal. Aproximadamente el &lt;i&gt;&lt;b&gt;20%&lt;/b&gt;&lt;/i&gt; de los dominios web del mundo en &lt;i&gt;&lt;b&gt;Internet&lt;/b&gt;&lt;/i&gt; están en&amp;nbsp;&lt;a href=&quot;https://www.cloudflare.com&quot;&gt;Cloudflare&lt;/a&gt;, y una gran cantidad de ellos utilizan las herramientas de &lt;a href=&quot;https://developers.cloudflare.com/bots/&quot;&gt;protección y gestión contra Bots que ofrece Cloudflare&lt;/a&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blog.cloudflare.com/introducing-precursor/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;587&quot; data-original-width=&quot;940&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEggwQCsvgmg9bPf8BYWKzw9y3Z_nr_jZSiAL6v4xrCc4lwmuT0yO85gdrfciZ6aR9UuY93QCfid2Jsw-8U3cavcJxdZJq-3NLKUwYbO2SU0SoC64bUQLdYf3edvByv_V0WlXcPUKjzNR3pOz7KzlR0JmFpTcmfkRdr6L0nzgf5sn6-yYRRG8ogC/w640-h400/precursor0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;&lt;a href=&quot;https://blog.cloudflare.com/introducing-precursor/&quot;&gt;Cloudflare Turnstile &amp;amp; Precursor.&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://blog.cloudflare.com/introducing-precursor/&quot;&gt;&amp;nbsp;Cómo detectar Bots y Humanos sin usar Captchas Cognitivos&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Los bots recogiendo datos de tus sitios web, masivamente, generan gastos de egress y de computo en los servicios cloud, así que elegir si quieres bots en sitios diseñados para personas o no, es una decisión importante, pues si quieres bots, es mejor abrirles los &lt;i&gt;&lt;b&gt;MCP&lt;/b&gt;&lt;/i&gt; con las capacidades que quieras que tengan. Además, puede ser que decidas qué &lt;i&gt;&lt;b&gt;bots&lt;/b&gt;&lt;/i&gt; quieres que vengan, y cuales no, y cómo qué quieres que hagan con tus datos.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://developers.cloudflare.com/turnstile/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;458&quot; data-original-width=&quot;640&quot; height=&quot;286&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg7tRqWx-Vh2gG6PrElXrMux5s4DZvt2pIIM3QPLqJSvctKKHmr8Ea40CVOooYYXGI4vmKqTTLEDBVcS0cNrAgMDIEcxaxXaDsIqt5-17ZG9ZAh9R3BisQJrxRfbMikYpxWOKUNLcRZVwAW9De4r3rISJlg822GsSiBhaSxnoMdCwIw8hHZkDFj/w400-h286/precursor7.jpg&quot; width=&quot;400&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 2: &lt;a href=&quot;https://developers.cloudflare.com/turnstile/&quot;&gt;Verifica que eres Humano de Cloudflare&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Los equipos de &lt;i&gt;&lt;b&gt;Application Security&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;Cloudflare&lt;/b&gt;&lt;/i&gt; trabajan constantemente para dotar a los administradores de dominios de Internet de herramientas para gestionar el control de quién hace qué en cada una de las webs de los dominios que están protegidos en la plataforma. Cuando creas una cuenta en&amp;nbsp;&lt;a href=&quot;https://www.cloudflare.com&quot;&gt;Cloudflare&lt;/a&gt;, tienes muchas opciones de seguridad por defecto, y todas las herramientas de &lt;a href=&quot;https://www.cloudflare.com/products/bot-mitigation/&quot;&gt;Bot Protection&lt;/a&gt; las tienes en el &lt;i&gt;&lt;b&gt;Plan Profesional&lt;/b&gt;&lt;/i&gt;, que cuesta &lt;i&gt;&lt;b&gt;20 USD&lt;/b&gt;&lt;/i&gt; al mes en los planes anuales.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.cloudflare.com/plans/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1702&quot; data-original-width=&quot;1392&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhbkCfFaRbFs_zyAv05L_Pt57EwYoTmsro-9f52HcsoSa0I-Ez-YQNvqN0lD8veBsvPBT-nSDP6sSETMvzOjZsDyF94cE9KMICE1alHVjZYlktpSMAji9Evhxc0eRXjrSjI58PvRbO3p8op_zip8OVRRVSjwxh3wSyu7MEG_BNP-vz4y_QFpgXE/w524-h640/precursor3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 3: &lt;a href=&quot;https://www.cloudflare.com/plans/&quot;&gt;Cloudflare Plan Profesional en Network &amp;amp; CDN&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Dentro de estas herramientas tienes muchas tecnologías, para luchar contra los bots maliciosos, y entre ellas se encuentran &lt;a href=&quot;https://www.elladodelmal.com/2025/03/tu-website-con-smart-honeypots-contra.html&quot;&gt;AI Labyrinth&lt;/a&gt;, del que os dejó un artículo el año pasado publicado, la gestión de &lt;a href=&quot;https://www.elladodelmal.com/2025/09/cloudflare-radar-bots-verificados.html&quot;&gt;Bots y Agentes IA Identificados y Verificados&lt;/a&gt;, de lo que os hablé hace unos meses, y por supuesto, &lt;a href=&quot;https://developers.cloudflare.com/turnstile/&quot;&gt;Turnstile&lt;/a&gt; y el nuevo &lt;a href=&quot;https://blog.cloudflare.com/introducing-precursor/&quot;&gt;Precursor&lt;/a&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/03/tu-website-con-smart-honeypots-contra.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;463&quot; data-original-width=&quot;800&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEijgGvaY2MCfskslgukq8TXOudflXC6JA2z-ZVkPvvaE53P4lfxoEq-UKxVNN2UWmjR8Xjh13HdBNAuLCxkZOafHV29QlbxiJDRNS5w1PhsF0AT-xIQeWLyzsq-CcZYUfZfEw0EAuitOGYFAsIgji_BnE3DNxY1AvIp6OI5TVfbus3m9e8W9eRK/w640-h370/AILabirynth0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 4: &lt;a href=&quot;https://www.elladodelmal.com/2025/03/tu-website-con-smart-honeypots-contra.html&quot;&gt;Tu WebSite con Smart Honeypots contra el&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://www.elladodelmal.com/2025/03/tu-website-con-smart-honeypots-contra.html&quot;&gt;WebScrapping usando AI Labyrinth de Cloudflare&lt;/a&gt;&amp;nbsp;&lt;/i&gt;&lt;/div&gt;&lt;div&gt;&lt;i&gt;&lt;br /&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;El primero de ellos, que lleva tiempo entre la familia de soluciones de &lt;a href=&quot;https://developers.cloudflare.com/turnstile/&quot;&gt;Cloudflare, es Turnstile&lt;/a&gt;, que cuenta con el famoso &lt;i&gt;&lt;b&gt;widget&lt;/b&gt;&lt;/i&gt; que, como os decía al principio, ha hecho tan popular la marca de la empresa. Se trata de una solución que busca identificar a los humanos usando un navegador, por medio de la &lt;a href=&quot;https://developers.cloudflare.com/cloudflare-challenges/&quot;&gt;Plataforma de Challenges&lt;/a&gt;, o lo que es lo mismo, de retos lanzados a la sesión.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://developers.cloudflare.com/turnstile/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;990&quot; data-original-width=&quot;2072&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg25rR-sZxFf5_rgaG_DHbXql0WLvh3nKJuVg3-7SBttMwFh55yNLgOEEHUjKTbJV1lpnenvBvHHxaTX8g6qd_hFHQD8jIhZOQEZBYQ_AN9J_D5RpDEJFRW7fAkzxYp4he3lEef6qDmV5oldV72IxUJKgG7R3VWhW9jyKWANJRP_Add2PFFqo98/w640-h306/Turnstile.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 5: &lt;a href=&quot;https://developers.cloudflare.com/turnstile/&quot;&gt;Cloudflare Turnstile&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Estos retos están divididos en varias categorías, como son &lt;i&gt;&lt;b&gt;Proof-of-Work (PoW)&lt;/b&gt;&lt;/i&gt; donde se le pide al navegador que resuelva determinadas operaciones, con código en client-side, &lt;i&gt;&lt;b&gt;Proof-of-Space (PoS)&lt;/b&gt;&lt;/i&gt; que es menos intensivo en computo y energía, pero más en espacio y gestión de almacenamiento o &lt;i&gt;&lt;b&gt;Proof of web APIs&lt;/b&gt;&lt;/i&gt;, para conocer realmente si el cliente tiene las características de un navegador.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://developers.cloudflare.com/turnstile/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;2700&quot; data-original-width=&quot;3757&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjESHMGGEvfYH6w_YOaHHD7ixeBi3EPN5megO8h9R1inVJlKFNN_YzDbHemrPD_e_CdTzShd2f6KM96Nm7XrAve3ZZN_sbzaNIh_88JtDYcNpUZXbSPph2-MKjA3mJ4C4SQsqVN7XrE7N87KH5-fG2XhpH5RSqbHrnBlbzpv2yqRCKUjP-mh6-K/w640-h460/Turnstile.webp&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 6: &lt;a href=&quot;https://developers.cloudflare.com/turnstile/&quot;&gt;Challenges de Turnstile&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Todas esas categorías son hechas automáticamente por el código que&amp;nbsp;&lt;a href=&quot;https://www.cloudflare.com&quot;&gt;Cloudflare&lt;/a&gt;&amp;nbsp;inyecta en la página web que ven los usuarios y los bots, y trata de detectar si hay un entorno de usuario humano detrás. Como podéis imaginar, no exige ninguna acción por parte del usuario. Esto, muchas páginas lo hacen de forma transparente sin que lo sepas, y otras muestran un pequeño icono de &lt;i&gt;&lt;b&gt;Cloudflare&lt;/b&gt;&lt;/i&gt; que se anima. Son los modos &lt;i&gt;&lt;b&gt;Invisible&lt;/b&gt;&lt;/i&gt; y &lt;i&gt;&lt;b&gt;No-Interactivo&lt;/b&gt;&lt;/i&gt; de &lt;a href=&quot;https://developers.cloudflare.com/turnstile/&quot;&gt;TurnStile&lt;/a&gt;.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://developers.cloudflare.com/turnstile/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;774&quot; data-original-width=&quot;2184&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEi4a8QT6GfikwgOGBQOdVA3LeLZ0uUGyN_pa3Hdf3K7CFznfbPgYw4P_Kvn9XYKH15jkMOoI7uBFmOfThNuyDz0h2BDMEuziPGEX-dV45AodPhyphenhyphenxogVRwSQDIskesIjjFU4c0_9vvL2xPqEXV6y375g_-17CgmUA6r_f91sI0yR8PsuX1yN1tA0/w640-h226/Turnstile2.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 7: &lt;a href=&quot;https://developers.cloudflare.com/turnstile/&quot;&gt;Modos de Turnstile&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;
&lt;div style=&quot;text-align: justify;&quot;&gt;Sin embargo, con la aparición de los &lt;i&gt;&lt;b&gt;Agentes AI&lt;/b&gt;&lt;/i&gt; que manejan los &lt;i&gt;&lt;b&gt;WebBrowsers&lt;/b&gt;&lt;/i&gt;, o directamente los AI &lt;a href=&quot;https://www.elladodelmal.com/2025/11/prompt-injection-en-chatgpt-atlas-con.html&quot;&gt;WebBrowers como Atlas&lt;/a&gt; o &lt;a href=&quot;https://www.elladodelmal.com/2025/10/perplexity-comet-indirect-prompt.html&quot;&gt;Comet&lt;/a&gt;, para incrementar el nivel de detección se usa también el modo Interactivo, donde el usuario tiene localizar su ratón, y hacer clic en un &lt;i&gt;&lt;b&gt;checkbox&lt;/b&gt;&lt;/i&gt;. En estos casos se busca medir las reacciones y comportamientos de los seres humanos, como el tiempo de reacción, y la forma de mover el ratón, los tiempos, y el temblor de nuestras manos y dedos.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&#39;allowfullscreen&#39; webkitallowfullscreen=&#39;webkitallowfullscreen&#39; mozallowfullscreen=&#39;mozallowfullscreen&#39; width=&#39;470&#39; height=&#39;266&#39; src=&#39;https://www.blogger.com/video.g?token=AD6v5dyap93nKjZNsMJUpBlTnJ3jxSWVyiRQWJ-k5N-y9QznVJbotrICx5UUqSYzW7NqwhsQ31E0azG0Vnw&#39; class=&#39;b-hbp-video b-uploaded&#39; frameborder=&#39;0&#39;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 8: &lt;a href=&quot;https://blog.cloudflare.com/introducing-precursor/&quot;&gt;Movimientos de ratón Humanos&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;div&gt;En este caso, cuando los bots o &lt;i&gt;&lt;b&gt;Agentes AI&lt;/b&gt;&lt;/i&gt; intentan simular ese comportamiento, en este juego del gato y el ratón, hacen movimientos con funciones matemáticas para generar ruido, pero no consiguen imitar al detalle la humanidad de los errores en nuestros movimientos de ratón, y los tiempos de respuesta entre que visualizamos dónde hay que hacer clic, y cómo hacerlo.&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;iframe allowfullscreen=&#39;allowfullscreen&#39; webkitallowfullscreen=&#39;webkitallowfullscreen&#39; mozallowfullscreen=&#39;mozallowfullscreen&#39; width=&#39;470&#39; height=&#39;266&#39; src=&#39;https://www.blogger.com/video.g?token=AD6v5dw6lJj0xwG7KVUjvMAruYH7RruK5ft-7aqA9mHQ7nxxeMDVa4NnO1WLgXSx1MKN-vBDXjbgLBQ8Fns&#39; class=&#39;b-hbp-video b-uploaded&#39; frameborder=&#39;0&#39;&gt;&lt;/iframe&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 9: &lt;a href=&quot;https://blog.cloudflare.com/introducing-precursor/&quot;&gt;Movimiento de ratón de Bots&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Pero por supuesto, lo intentan. Así que, &lt;a href=&quot;https://blog.cloudflare.com/introducing-precursor/&quot;&gt;Cloudflare ha lanzado una nueva evolución de estas tecnologías, llamadas Precursor&lt;/a&gt;, que lleva estas comprobaciones más allá de un simple control en un momento puntual. Se trata de monitorizar las sesiones completas para que ir gestionando de cada una de ellas un &lt;i&gt;&lt;b&gt;Bot Score&lt;/b&gt;&lt;/i&gt;, que determinará cuál es la probabilidad de que en una sesión completa, formada por un historial de navegación a lo largo del tiempo, las pruebas y mediciones realizadas han detectado la posibilidad de que haya una persona o un bot detrás de ella.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_AutQcbf8obasy_QXR-zdw5z7icJ980t0aReqJUlNsS44vgNnsELDj9AZHbnFJPuway7D1aEZWC520uNtpXOO9y7DkWtZY7e7vLQjFhxZIaoOqZkzGoARpHH5jnWd5Aqvu767dijf922LldgQxT9_pYU7B6H2M7Vzyhil8pZKdNDdMZhHJQRH/s1832/precursor4.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1040&quot; data-original-width=&quot;1832&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEh_AutQcbf8obasy_QXR-zdw5z7icJ980t0aReqJUlNsS44vgNnsELDj9AZHbnFJPuway7D1aEZWC520uNtpXOO9y7DkWtZY7e7vLQjFhxZIaoOqZkzGoARpHH5jnWd5Aqvu767dijf922LldgQxT9_pYU7B6H2M7Vzyhil8pZKdNDdMZhHJQRH/w640-h364/precursor4.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 10: &lt;a href=&quot;https://blog.cloudflare.com/introducing-precursor/&quot;&gt;Precursor en Cloudflare&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Por supuesto, como en el caso de &lt;a href=&quot;https://developers.cloudflare.com/turnstile/&quot;&gt;Turnstile&lt;/a&gt;, se pueden configurar dos modos, como son &lt;b&gt;&lt;u&gt;Minimizar Fricción o Maximizar Seguridad&lt;/u&gt;&lt;/b&gt;. Esa obsesión de reducir la ficción en las soluciones de detección de &lt;i&gt;&lt;b&gt;Bots&lt;/b&gt;&lt;/i&gt; tiene por detrás un sentido.&amp;nbsp;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blog.cloudflare.com/introducing-precursor/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;640&quot; data-original-width=&quot;1264&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgSV17NUQBq6IONrBFDLM4eVRU6aWpap3rgVKjau0zGJ4x0qfzXenoKtLX4WiGWmFnl8H1c1HhbAfd4mhx7NruMF4J8DQSdxyjxjNcEGu-351CbnjbbzvtD62FfSygWUXflK5mAY1_sPBiCu2Xej46p7k5B1caLOZZkQPidaNVp8-hWGpeZ3geL/w640-h324/precursor6.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 11: &lt;a href=&quot;https://blog.cloudflare.com/introducing-precursor/&quot;&gt;Modos de Precursor&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;No sólo se trata de que, como ya hemos visto y os he publicado muchas veces, los &lt;a href=&quot;https://www.elladodelmal.com/2026/06/captchas-cognitivos-para-humanos-y.html&quot;&gt;Catpchas Cognitivos no son una barrera ya para el mundo de los Agentes AI&lt;/a&gt;, sino que cualquier complejidad para los usuarios es una barrera de &lt;i&gt;&lt;b&gt;UX&lt;/b&gt;&lt;/i&gt; que en aplicaciones de negocios generan pérdidas económicas. El famoso &quot;&lt;i&gt;&lt;b&gt;un clic más, un cliente menos&lt;/b&gt;&lt;/i&gt;&quot; se ve afectado por las soluciones &lt;i&gt;&lt;b&gt;Captchas&lt;/b&gt;&lt;/i&gt; que muchos añaden.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blog.cloudflare.com/introducing-precursor/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;956&quot; data-original-width=&quot;1266&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEgIcHXad5TEa18R4VF0-w3OgDHvE77tB3xoirNiAbfv9CRaZfJyAaC6Mk1ttx_fCHh-KQaTzp9QRmBaFmVkvDDw8lw-7yjQpL3Cvxr9mGLJglooIHJ1143UNqTUwxab1oUadbfKzHyOLm81SaMMmzuUmVr3MJh47ynjG-zgJgTw5Rj66gfKOZQF/w640-h484/precursor5.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 12: &lt;a href=&quot;https://blog.cloudflare.com/introducing-precursor/&quot;&gt;Reglas en Precursor&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;Por otro lado, si tu web está frente a un ataque, o tienes a bots avanzados que están haciéndote &lt;i&gt;&lt;b&gt;WebScrapping&lt;/b&gt;&lt;/i&gt; para construir negocios de &lt;i&gt;&lt;b&gt;Dropshipping&lt;/b&gt;&lt;/i&gt; encareciendo el coste de tus anuncios para vender tus productos más caros, o están haciéndote &lt;a href=&quot;https://www.zendalibros.com/la-inteligencia-artificial-de-los-conciertos-de-bruce-springsteen-que-sube-los-precios-y-los-scalpers/&quot;&gt;WebScalpping de entradas de conciertos&lt;/a&gt; o &lt;a href=&quot;https://www.seguridadapple.com/2011/11/scalpers-en-asia-arrasando-con-el.html&quot;&gt;productos exclusivos&lt;/a&gt;, entonces la opción de &lt;i&gt;&lt;b&gt;Maximizar la Seguridad&lt;/b&gt;&lt;/i&gt; es la que deberías configurar, y protegerte contra estos actores.&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div style=&quot;text-align: justify;&quot;&gt;¡Saludos Malignos!&lt;/div&gt;&lt;div&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Autor: &lt;b&gt;Chema Alonso &lt;/b&gt;(&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot;&gt;Contactar con Chema Alonso&lt;/a&gt;) &amp;nbsp;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
&lt;div class=&quot;separator&quot; style=&quot;clear: both; font-style: italic; text-align: center;&quot;&gt;
&lt;a href=&quot;https://www.mypublicinbox.com/chemaalonso&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;444&quot; data-original-width=&quot;800&quot; src=&quot;https://1.bp.blogspot.com/-wPU2d-hy3rM/XiyVNgM4kGI/AAAAAAAAy70/Pk1IP6-v7bQLVUNL2iWneVOgRP494eWrACLcBGAsYHQ/s640/MPICHemaalonso.jpg&quot; width=&quot;450&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;br /&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/07/cloudflare-turnstile-precursor-como.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEggwQCsvgmg9bPf8BYWKzw9y3Z_nr_jZSiAL6v4xrCc4lwmuT0yO85gdrfciZ6aR9UuY93QCfid2Jsw-8U3cavcJxdZJq-3NLKUwYbO2SU0SoC64bUQLdYf3edvByv_V0WlXcPUKjzNR3pOz7KzlR0JmFpTcmfkRdr6L0nzgf5sn6-yYRRG8ogC/s72-w640-h400-c/precursor0.jpg" height="72" width="72"/><thr:total>0</thr:total></item><item><guid isPermaLink="false">tag:blogger.com,1999:blog-21555208.post-8928341645923376644</guid><pubDate>Fri, 24 Jul 2026 05:01:00 +0000</pubDate><atom:updated>2026-07-24T07:01:00.112+02:00</atom:updated><category domain="http://www.blogger.com/atom/ns#">AI</category><category domain="http://www.blogger.com/atom/ns#">Bot</category><category domain="http://www.blogger.com/atom/ns#">curso</category><category domain="http://www.blogger.com/atom/ns#">Cursos</category><category domain="http://www.blogger.com/atom/ns#">developer</category><category domain="http://www.blogger.com/atom/ns#">formación</category><category domain="http://www.blogger.com/atom/ns#">Hacking IA</category><category domain="http://www.blogger.com/atom/ns#">IA</category><category domain="http://www.blogger.com/atom/ns#">Llama</category><category domain="http://www.blogger.com/atom/ns#">LLM</category><category domain="http://www.blogger.com/atom/ns#">LLMs</category><category domain="http://www.blogger.com/atom/ns#">OpenSource</category><category domain="http://www.blogger.com/atom/ns#">programación</category><category domain="http://www.blogger.com/atom/ns#">Vibe Coding</category><title>AI Engineering Bootcamp: Basta de hacer tutoriales y construye tu propio asistente con IA en producción</title><description>&lt;div align=&quot;justify&quot;&gt;Vivimos rodeados de &lt;i&gt;&lt;b&gt;Inteligencia Artificial,&lt;/b&gt;&lt;/i&gt; pero la inmensa mayoría de la gente que trabaja &quot;&lt;i&gt;&lt;b&gt;con IA&lt;/b&gt;&lt;/i&gt;&quot; en realidad se limita a llamar a una &lt;i&gt;&lt;b&gt;API&lt;/b&gt;&lt;/i&gt;, copiar un &lt;i&gt;&lt;b&gt;prompt&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;Twitter/X&lt;/b&gt;&lt;/i&gt; o encadenar un par de bloques en una herramienta &lt;i&gt;&lt;b&gt;no-code&lt;/b&gt;&lt;/i&gt;. Saben usar la &lt;i&gt;&lt;b&gt;IA&lt;/b&gt;&lt;/i&gt; como usuario avanzado, pero no entienden qué pasa por debajo: cómo se sirve un modelo, cómo se diseña un agente que razona y actúa, cómo se protege un sistema &lt;i&gt;&lt;b&gt;LLM&lt;/b&gt;&lt;/i&gt; de un ataque de prompt injection o cómo se lleva todo eso a producción para que funcione &lt;i&gt;&lt;b&gt;24/7&lt;/b&gt;&lt;/i&gt; sin que se caiga a la primera de cambio.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://manuelslemos.com/academy/&quot; imageanchor=&quot;1&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;826&quot; data-original-width=&quot;1494&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjRur6FcoQZ2tMp7ddy0gpFJk06g3ROUAIwVQUhCW0FBcOWuwXlzE3NUKYdvM1N8YrFkwpjgrxwB_4SHDnWb3Wn_GVcfz0kUvKZAQkj7nEBIDllCQxfLKzr38g9-3Vp6dcZ7FL3nzCklNJsfMFAnT_MMIBGuoj8CSodN2Wa0HiQ67x0jk8pn_AW/w640-h354/Bootcamp0.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 1:&amp;nbsp;&lt;a href=&quot;https://manuelslemos.com/academy/&quot;&gt;AI Engineering Bootcamp: Basta de hacer tutoriales&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://manuelslemos.com/academy/&quot;&gt;y construye tu propio asistente con IA en producción&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;
Esa distancia entre &quot;&lt;i&gt;&lt;b&gt;usar IA&lt;/b&gt;&lt;/i&gt;&quot; y &quot;&lt;i&gt;&lt;b&gt;construir con IA&lt;/b&gt;&lt;/i&gt;&quot; es, ahora mismo, la que separa a un consumidor de &lt;i&gt;&lt;b&gt;prompts&lt;/b&gt;&lt;/i&gt; de un auténtico &lt;i&gt;&lt;b&gt;AI Engineer&lt;/b&gt;&lt;/i&gt;. Y es precisamente esa distancia la que &lt;a href=&quot;https://manuelslemos.com/academy/&quot;&gt;Ferrumox Academy&lt;/a&gt; ha diseñado para recorrer en &lt;a href=&quot;https://manuelslemos.com/academy/&quot;&gt;9 semanas con su AI Engineering Bootcamp&lt;/a&gt;.
&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://manuelslemos.com/academy/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1090&quot; data-original-width=&quot;1408&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjP11DQYZCg92gGjJNZNoTETpNm_hq4DlICN6Lf1EXhbTGpFF4Z2IfEPhjtLEmnr8DOXMCz2bEK6w34yhYaxYtnryquOl26y8RLGDQiKetkS3dsEpGo2VhiU4yudy7_2CbDxpsYKIufvpqcAhtEOTZ_x7CldMYStmhU3_9wf05XYxGiONycNDtw/w640-h496/bootcamp1.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;i&gt;Figura 2: &lt;a href=&quot;https://manuelslemos.com/academy/&quot;&gt;AI Engineering Bootcamp&lt;/a&gt;&lt;/i&gt;&lt;/span&gt;&lt;/div&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Cohorte 2: arranca la semana del 2 de septiembre&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
El &lt;a href=&quot;https://manuelslemos.com/academy/&quot;&gt;AI Engineering Bootcamp de Ferrumox Academy&lt;/a&gt; no es un curso de vídeos a tu ritmo ni una colección de slides sobre &quot;&lt;i&gt;&lt;b&gt;el futuro de la IA&lt;/b&gt;&lt;/i&gt;&quot;. Es un programa intensivo y práctico: una sesión en directo por semana de &lt;i&gt;&lt;b&gt;2&lt;/b&gt;&lt;/i&gt; horas (tú eliges grupo de lunes, miércoles o viernes, de &lt;i&gt;&lt;b&gt;18:00&lt;/b&gt;&lt;/i&gt; a &lt;i&gt;&lt;b&gt;20:00&lt;/b&gt;&lt;/i&gt;) y el resto de la semana para construir, con material previo antes de cada directo y un entregable funcionando al final de cada semana.&lt;br /&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://manuelslemos.com/academy/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1216&quot; data-original-width=&quot;1450&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjymIgf3wITF84Cm7aRSzRWhJk6FCXH5vy9Hn8qmPrUiRZBZt5opsjBDkdBUeXb2F7jfZT8oCH9DpLFGqDZeRL-7gpjwYAzjWITS3vsuRT5OoScj3nxwJd8yTUdes8QC7OOjrpPPkqfFfKfk_RW91i_hadPPA0MY0Eu9ih7rAgSG0EqOiG504zu/w640-h536/Bootcamp6.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 3: &lt;a href=&quot;https://manuelslemos.com/academy/&quot;&gt;Objetivos del Bootcamp&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
El objetivo final no es &quot;&lt;i&gt;&lt;b&gt;terminar un curso&lt;/b&gt;&lt;/i&gt;&quot;. Es salir con tu propio asistente con &lt;i&gt;&lt;b&gt;IA&lt;/b&gt;&lt;/i&gt; corriendo en producción: accesible desde Telegram, con memoria persistente, capaz de orquestar varios agentes especializados vía &lt;i&gt;&lt;b&gt;MCP&lt;/b&gt;&lt;/i&gt; y conectado a tus propios documentos mediante &lt;i&gt;&lt;b&gt;RAG&lt;/b&gt;&lt;/i&gt; híbrido. &lt;b&gt;&lt;u&gt;Construido por ti, entendido por ti, no copiado de un repositorio de GitHub&lt;/u&gt;&lt;/b&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;
Un programa que va desde la inferencia hasta producción, semana a semana&lt;br /&gt;&lt;/b&gt;&lt;br /&gt;
A lo largo de las 9 semanas (con una sesión 0 bonus de preparación incluida) el temario progresa capacidad a capacidad, sin frameworks mágicos que oculten lo que está pasando por debajo:&lt;br /&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;
Semanas 1-2&lt;/b&gt;: &lt;i&gt;Infraestructura de inferencia propia, local y en la nube (Ollama, vLLM, APIs de OpenAI y Anthropic), y adaptación de modelos con LoRA y QLoRA.&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;
Semanas 3-4&lt;/b&gt;: &lt;i&gt;Context engineering, gestión de memoria persistente y diseño del bucle de agente (agentic loop) con el patrón ReAct y tool calling, implementado sin frameworks para entender de verdad el ciclo razonar-actuar-observar.&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://manuelslemos.com/academy/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1706&quot; data-original-width=&quot;1444&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg0Ty3tEo_3fdsjUWtx6wdd4kzHkDaHoEMT7LMbesrBbaIRf4i1oKE0aFTdbZW-qgIKqlR7EozymDd9IrAPKiM-qsEnJasYtWl-h47OT4biaDNya-FGqLQSoM454prdCewqDOUXQymsqAUc3HVPdZ5PZIz7UXk3xPmenrwZmA8rT40orOGw4gZs/w542-h640/Bootcamp2.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 4: &lt;a href=&quot;https://manuelslemos.com/academy/&quot;&gt;Semanas 00 a 03&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;
Semanas 5-6&lt;/b&gt;: &lt;i&gt;RAG avanzado con recuperación híbrida y reranking, y sistemas multi-agente con orquestación vía MCP siguiendo el patrón supervisor.&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;i&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://manuelslemos.com/academy/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1680&quot; data-original-width=&quot;1436&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhAPp8ljX3BbZ3epYeTHnM0oGcEpwd22kGHvIfNuTWwQun0uiTJ1wsugB_WaHGmPzFkIjfUFo1Y5vqkJxpwzONKQ3nu9rmc7yyGvnsuyt2Ig8T3nDVYDnzuOBUE6Ib9zvadZRhM8pIJ0Dg8f1rQcxn2nCbv6Vo_PvtlOfWv5KcNzdcdJStTGxIt/w548-h640/Bootcamp3.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;Figura 5: &lt;a href=&quot;https://manuelslemos.com/academy/&quot;&gt;Semanas 04 - 07&lt;/a&gt;&lt;/div&gt;&lt;/i&gt;&lt;/div&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;
Semanas 7-8&lt;/b&gt;:&lt;i&gt; Seguridad de sistemas LLM,  modelado de amenazas, prompt injection, jailbreaking y diseño de guardrails, y despliegue en producción con observabilidad, evals y control de costes.&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;ul&gt;&lt;li&gt;&lt;b&gt;
Semana 9&lt;/b&gt;: &lt;i&gt;Demo day, presentación del proyecto ante toda la cohorte y hoja de ruta para seguir construyendo.&lt;/i&gt;&lt;/li&gt;&lt;/ul&gt;&lt;div&gt;&lt;i&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://manuelslemos.com/academy/&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;768&quot; data-original-width=&quot;1440&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEhQvLI_HiTNEUKAdqpaoReDIBl2u8kGbhinxpzno46ixQ6UEWgSJoHVVZVNqQAd5BJiHeZZCJN2DaOu93kVVaGnLtv0PCKEku65mkIP7I9YYRffHszh7zXKXRMz7vqrm1QCaEVL2tG_AzTC8qq2MpI2ffcinmjaYARfqm5CAeSbq03M243f4fHa/w640-h342/Bootcamp4.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;Figura 6: &lt;a href=&quot;https://manuelslemos.com/academy/&quot;&gt;Semanas 8 y 9&lt;/a&gt;&lt;/div&gt;&lt;/i&gt;&lt;/div&gt;&lt;br /&gt;
Uno de los puntos diferenciales del programa es precisamente el módulo de &lt;b&gt;&lt;u&gt;LLM Security&lt;/u&gt;&lt;/b&gt;: menos del &lt;i&gt;&lt;b&gt;1%&lt;/b&gt;&lt;/i&gt; de los &lt;i&gt;&lt;b&gt;AI Engineers&lt;/b&gt;&lt;/i&gt; sabe auditar un sistema &lt;i&gt;&lt;b&gt;LLM&lt;/b&gt;&lt;/i&gt; de verdad, y este bootcamp dedica una semana completa a aprender a atacarlo y a defenderlo, algo que a día de hoy no se encuentra en ningún otro &lt;i&gt;&lt;b&gt;bootcamp&lt;/b&gt;&lt;/i&gt; en &lt;i&gt;&lt;b&gt;España&lt;/b&gt;&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Quién está detrás del programa&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
El &lt;i&gt;&lt;b&gt;bootcamp&lt;/b&gt;&lt;/i&gt; lo imparto directamente yo, &lt;a href=&quot;https://mypublicinbox.com/ManuelSlemos&quot;&gt;Manuel S. Lemos&lt;/a&gt;, fundador de &lt;i&gt;&lt;b&gt;Ferrumox&lt;/b&gt;&lt;/i&gt; y &lt;i&gt;&lt;b&gt;Claude Certified Architect de Anthropic&lt;/b&gt;&lt;/i&gt; (la primera certificación técnica oficial que ha emitido la compañía, sólo accesible por invitación), además de &lt;i&gt;&lt;b&gt;AI Engineer&lt;/b&gt;&lt;/i&gt; en &lt;i&gt;&lt;b&gt;NaizFit&lt;/b&gt;&lt;/i&gt;, coautor del libro &lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot;&gt;Hacking IA (0xWord, 2026)&lt;/a&gt;, contribuidor de &lt;i&gt;&lt;b&gt;OWASP GenAI Security&lt;/b&gt;&lt;/i&gt; y &lt;i&gt;&lt;b&gt;Vicepresidente&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;ANBAN&lt;/b&gt;&lt;/i&gt;. Anteriormente &lt;i&gt;&lt;b&gt;Director Académico de IA &amp;amp; Big Data en GeeksHubs Academy&lt;/b&gt;&lt;/i&gt; durante cuatro años. También he&amp;nbsp;dado charlas en el &lt;i&gt;&lt;b&gt;GenAI Summit EU, Codemotion Madrid, TofuConf, el Máster de Ciberseguridad del CIPFP Cheste&lt;/b&gt;&lt;/i&gt;&amp;nbsp;y el &lt;i&gt;&lt;b&gt;podcast&lt;/b&gt;&lt;/i&gt; de &lt;i&gt;&lt;b&gt;Hackers&lt;/b&gt;&lt;/i&gt;, entre otros escenarios.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2Fnw0bpWlbm-8J659rIWv_frwMt8OJ3KdPZ9inXDimOTUeDyRV-fE929DSaoMobfOUuh6mUgRpNubQiy0J2M4x-tLej720NNAG5VAbiHaWbvwTLyu-W-eFvRS_hvTrwCJKRSqKAk-F9nrWok2zQ2SdF4bd4y3lOOOnETjtOqKuu29MdQK0sIC/s1450/Bootcamp6.jpg&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1216&quot; data-original-width=&quot;1450&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEg2Fnw0bpWlbm-8J659rIWv_frwMt8OJ3KdPZ9inXDimOTUeDyRV-fE929DSaoMobfOUuh6mUgRpNubQiy0J2M4x-tLej720NNAG5VAbiHaWbvwTLyu-W-eFvRS_hvTrwCJKRSqKAk-F9nrWok2zQ2SdF4bd4y3lOOOnETjtOqKuu29MdQK0sIC/w640-h536/Bootcamp6.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;Figura 7: &lt;a href=&quot;https://manuelslemos.com/academy/&quot;&gt;Una formación para poner en producción&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Lo que se enseña en el bootcamp es, literalmente, lo que se construye en producción cada día. &lt;i&gt;&lt;b&gt;Ferrumox&lt;/b&gt;&lt;/i&gt; es el proyecto para unir dos cosas que normalmente van por separado: ingeniería de &lt;i&gt;&lt;b&gt;IA&lt;/b&gt;&lt;/i&gt; de verdad y formación de alto nivel. Por un lado está &lt;a href=&quot;https://github.com/ferrumox/fox&quot;&gt;Fox, el motor de inferencia LLM en Rust, de código abierto&lt;/a&gt; y gratuito para siempre (sin planes de pago ni capital de por medio), pensado como sustituto directo de &lt;i&gt;&lt;b&gt;Ollama&lt;/b&gt;&lt;/i&gt; con hasta &lt;i&gt;&lt;b&gt;4&lt;/b&gt;&lt;/i&gt; veces más eficiencia gracias al &lt;i&gt;&lt;b&gt;prefix caching&lt;/b&gt;&lt;/i&gt; y al &lt;i&gt;&lt;b&gt;continuous batching&lt;/b&gt;&lt;/i&gt;.&lt;br /&gt;&lt;br /&gt;&lt;b&gt;&lt;u&gt;
Precio, plazas y un regalo que no falta en ninguna edición&lt;br /&gt;&lt;/u&gt;&lt;/b&gt;&lt;br /&gt;
La &lt;i&gt;&lt;b&gt;Cohorte 2 &lt;/b&gt;&lt;/i&gt;arranca la semana del &lt;u&gt;2 de septiembre de 2026 &lt;/u&gt;y tiene &lt;i&gt;&lt;b&gt;36&lt;/b&gt;&lt;/i&gt; plazas repartidas en &lt;i&gt;&lt;b&gt;3&lt;/b&gt;&lt;/i&gt; grupos de &lt;i&gt;&lt;b&gt;12 &lt;/b&gt;&lt;/i&gt;(lunes, miércoles y viernes). Las primeras &lt;u&gt;12 plazas entran a 997 €&lt;/u&gt;; a partir de ahí el precio pasa a &lt;i&gt;&lt;b&gt;1.200 €&lt;/b&gt;&lt;/i&gt;. Todas las sesiones se graban y quedan disponibles antes de &lt;i&gt;&lt;b&gt;24&lt;/b&gt;&lt;/i&gt; horas, así que si algún día no puedes conectarte en directo no te quedas fuera.&amp;nbsp;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;612&quot; data-original-width=&quot;1466&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjV74rOUSxHto838jceCD5Ngbu8OYTs7PA562psXTz_k6TrHs9nLKxEHjZTNmy8Sxl44iLfcgsO099uOTvGRBTXVK3_90K54iAZrVJbmPJ_JbXjXeYZLPXk5UR4CNWNDdVFY2N6zOXGUn9kc1ze1Jb7AOLYIYNCdrwLcDuO8mq2SEHVdFlOd8R6/w640-h268/Bootcamp5.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;span style=&quot;text-align: left;&quot;&gt;Figura 8: &lt;/span&gt;&lt;span style=&quot;text-align: left;&quot;&gt;&lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot;&gt;Ejemplar de &quot;Hacking IA&quot; (0xWord, 2026), de regalo para cada alumno&lt;/a&gt;&lt;/span&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;Y, como no podía ser de otra manera en este &lt;i&gt;&lt;b&gt;blog&lt;/b&gt;&lt;/i&gt;, hay premio para los alumnos: cada persona de la &lt;i&gt;&lt;b&gt;Cohorte 2&lt;/b&gt;&lt;/i&gt; recibe un ejemplar del libro &lt;a href=&quot;https://0xword.com/es/libros/251-hacking-ia-jailbreak-prompt-injection-hallucinations-unalignment.html&quot;&gt;Hacking IA: Jailbreak, Prompt Injection, Hallucinations &amp;amp; Unalignment&lt;/a&gt; de &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt;, incluido sin coste extra en la plaza, y habrá un chat en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox&lt;/a&gt; constante conmigo y con &lt;a href=&quot;https://myPublicInbox.com&quot;&gt;Chema Alonso&lt;/a&gt;.&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;b&gt;&lt;u&gt;Go for it!&lt;/u&gt;&lt;/b&gt;&lt;/div&gt;&lt;div align=&quot;justify&quot;&gt;&lt;br /&gt;
Si necesitas un empujón más para decidirte, el &lt;u&gt;10 de Agosto&lt;/u&gt; haremos una clase gratuita que te puedes apuntar desde nuestra web. Además el &lt;i&gt;&lt;b&gt;bootcamp&lt;/b&gt;&lt;/i&gt; incluye &lt;i&gt;&lt;b&gt;feedback&lt;/b&gt;&lt;/i&gt; escrito de tus proyectos en &lt;i&gt;&lt;b&gt;48&lt;/b&gt;&lt;/i&gt; horas, repo privado con todo el código, comunidad privada de la cohorte, acceso a las grabaciones de futuras ediciones y más sorpresas.&lt;br /&gt;&lt;br /&gt;
¡Happy hacking!&lt;br /&gt;&lt;br /&gt;&lt;i&gt;
Autor:&lt;/i&gt; &lt;a href=&quot;https://mypublicinbox.com/ManuelSlemos&quot;&gt;&lt;b&gt;Manuel S. Lemos&lt;/b&gt;&lt;/a&gt;, &lt;i&gt;Fundador de Ferrumox y director del AI Engineering Bootcamp&lt;/i&gt;&lt;br /&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;a href=&quot;https://mypublicinbox.com/ManuelSlemos&quot; style=&quot;margin-left: 1em; margin-right: 1em;&quot;&gt;&lt;br class=&quot;Apple-interchange-newline&quot; /&gt;&lt;img border=&quot;0&quot; data-original-height=&quot;1850&quot; data-original-width=&quot;1642&quot; src=&quot;https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjWZSu-o6Yhr5Eucxv7K8Th8wxCtPdFWYxy_2Vw7lv7JbNu9PfMUPMezgRVRm4D2xHu06Z5nonrzxEJ7fPnjXwOupUW8ToX4jTD6feCXYwQD670UbyLOIa2Et3muQN8ixpjayyZeaIRhetCItvteJ6JLhFj8DLxf9m4kWENKKmmvqtx_2bM0Aw3/w568-h640/ManuelSLemos.jpg&quot; width=&quot;470&quot; /&gt;&lt;/a&gt;&lt;/div&gt;&lt;div class=&quot;separator&quot; style=&quot;clear: both; text-align: center;&quot;&gt;&lt;i&gt;&lt;a href=&quot;https://mypublicinbox.com/ManuelSlemos&quot;&gt;Contactar con Manuel S. Lemos&lt;/a&gt;&lt;/i&gt;&lt;/div&gt;&lt;/div&gt;&lt;div class=&quot;blogger-post-footer&quot;&gt;&lt;br/&gt;&lt;a href=&quot;https://mypublicinbox.com/dashboard/chats/zo1KA0wRZ4w3OPMn&quot;&gt;Únete al foro de Ciberseguridad de Chema Alonso en MyPublicInbox&lt;/a&gt; Sigue &lt;a href=&quot;https://elladodelmal.com&quot;&gt;Un informático en el lado del mal&lt;/a&gt; &lt;a href=&quot;http://feeds.feedburner.com/ElLadoDelMal&quot;&gt;RSS&lt;/a&gt; &lt;a href=&quot;https://0xWord.com&quot;&gt;0xWord&lt;/a&gt; &lt;br/&gt; - &lt;a href=&quot;https://MyPublicInbox.com/ChemaAlonso&quot;&gt;Contacta con Chema Alonso&lt;/a&gt; en &lt;a href=&quot;https://MyPublicInbox.com&quot;&gt;MyPublicInbox.com&lt;/a&gt; &lt;/div&gt;</description><link>http://www.elladodelmal.com/2026/07/ai-engineering-bootcamp-basta-de-hacer.html</link><author>noreply@blogger.com (Chema Alonso)</author><media:thumbnail xmlns:media="http://search.yahoo.com/mrss/" url="https://blogger.googleusercontent.com/img/b/R29vZ2xl/AVvXsEjRur6FcoQZ2tMp7ddy0gpFJk06g3ROUAIwVQUhCW0FBcOWuwXlzE3NUKYdvM1N8YrFkwpjgrxwB_4SHDnWb3Wn_GVcfz0kUvKZAQkj7nEBIDllCQxfLKzr38g9-3Vp6dcZ7FL3nzCklNJsfMFAnT_MMIBGuoj8CSodN2Wa0HiQ67x0jk8pn_AW/s72-w640-h354-c/Bootcamp0.jpg" height="72" width="72"/><thr:total>0</thr:total></item></channel></rss>