
Esta semana el podcast viaja desde el futuro más inquietante de la inteligencia artificial hasta algunas de las historias más absurdas de la informática. Analizamos el incidente de OpenAI con la IA que logró encadenar vulnerabilidades, credenciales expuestas y errores de configuración hasta comprometer infraestructura de Hugging Face, debatimos si limitar los modelos abiertos realmente mejora la seguridad o simplemente deja a los defensores con menos herramientas y repasamos la llegada de Kimi K3, Claude Opus 5, Codex Security y los primeros agentes capaces de realizar compras autónomas.
También hablamos de chats privados de Claude apareciendo en buscadores, del código de coacción de GrapheneOS que borra un teléfono y del curioso descubrimiento de que demasiados agentes pueden acabar molestándose entre ellos. Pero no todo son amenazas: conectamos el accidente que inspiró la música ambient de Brian Eno con la inolvidable banda sonora de Minecraft, recomendamos el libro que narra cómo Notch creó el juego programando por las noches y recuperamos el increíble Honeywell 316, un “ordenador de cocina” de 1969 que costaba una fortuna, requería introducir recetas en binario y cuya arquitectura estuvo vinculada a los primeros nodos de ARPANET. Y para cerrar el círculo geek: sí, alguien ha conseguido ejecutar Doom mediante expresiones regulares.
Enlaces de este episodio:
- Claude introduces new capabilities — https://x.com/claudeai/status/2080699495453528290?s=20
- Jensen Huang defends open AI models — https://x.com/JensenHuang/status/2080643682408321103?s=20
- White House seeks greater control over frontier AI model access — https://thenextweb.com/news/white-house-dictating-frontier-ai-model-access-anthropic-openai
- Anthropic’s $1.5B copyright settlement approved — https://techcrunch.com/2026/07/20/anthropics-landmark-1-5b-copyright-settlement-is-approved/
- The Anthropic–Physical Intelligence rumor that shook AI Twitter — https://techcrunch.com/2026/07/21/the-anthropic-physical-intelligence-rumor-roiling-ai-twitter/
- CertiGhost exploit allows low-privileged users to compromise Active Directory Certificate Services — https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.html
- Elon Musk showcases AI-generated movie capabilities with Grok — https://x.com/elonmusk/status/2079758604656316619
- The Honeywell 316: the “Kitchen Computer” that became part of ARPANET history — https://www.pagetable.com/?p=1867
- CISA orders urgent action on actively exploited Langflow RCE vulnerability — https://geekfeed.net/cisa-orders-urgent-action-on-actively-exploited-langflow-rce-flaw/
- Shared Claude chats exposed publicly — https://cybersecuritynews.com/claude-ai-shared-chats/
- Police dismantle €140 million cyber-fraud ring in Spain — https://www.darkreading.com/threat-intelligence/police-disrupt-140m-euro-cyber-fraud-ring-spain
- GitHub awards $100,000 bounty for critical RCE vulnerability — https://runtimewire.com/article/github-issues-100-000-bounty-for-critical-rce-vulnerability-disclosed-by-sagitz
- Exploit brokers pay $500,000 for a WordPress RCE discovered with GPT-5.6 — https://slcyber.io/research-center/exploit-brokers-pay-500000-for-a-wordpress-rce-i-found-one-with-gpt5-6/
- OpenSecurityTraining2: Zero to QEMU course — https://p.ost2.fyi/courses/course-v1:OpenSecurityTraining2+Arch1901_Zero2QEMU+2026_v1/about
- iCopy-X RFID/NFC research tool — https://github.com/lab-401/icopy-x
- Kimi K3 agents discover Redis zero-day vulnerabilities — https://thehackernews.com/2026/07/kimi-k3-agents-found-redis-zero-days.html
- Apple fixes “Hide My Email” vulnerability — https://thehackernews.com/2026/07/apple-fixes-hide-my-email-bug-that.html
- Russian intelligence compromises IP cameras for espionage — https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html
- Anthropic Opus 5 rivals Fable 5 at half the price — https://slashdot.org/story/26/07/24/1853236/anthropics-new-opus-5-model-rivals-fable-5-for-half-the-price
- Paged Out! Issue #9 — https://pagedout.institute/webview.php?issue=9&page=1
- Claude Opus 5 used to discover software vulnerabilities — https://cybersecuritynews.com/claude-opus-5-finds-vulnerabilities/
- Activist charged after using a duress code that wiped his phone at the border — https://arstechnica.com/gadgets/2026/07/activist-charged-with-felony-after-giving-border-agent-duress-code-that-wiped-his-phone/
- Moonshot AI releases open weights for Kimi K3 — https://www.tomshardware.com/tech-industry/artificial-intelligence/moonshot-ai-releases-weights-for-kimi-k3-firing-a-shot-across-the-bow-of-openai-and-anthropic-open-weight-model-performs-almost-as-well-as-frontier-models-while-being-2-3x-easier-to-run
- NVIDIA forms the Open Secure AI Alliance — https://thehackernews.com/2026/07/nvidia-forms-37-member-open-secure-ai.html
- Doom implemented entirely with a regular expression — https://github.com/4RH1T3CT0R7/doom-regex
- Arizona State University launches an Influencer degree — https://news.slashdot.org/story/26/07/28/012244/arizona-state-launches-influencer-degree-where-students-must-gain-real-followers
- OpenAI Codex Security — https://github.com/openai/codex-security
- Hugging Face publishes technical timeline of the agent intrusion incident — https://huggingface.co/blog/agent-intrusion-technical-timeline
- Apple Upgrade Program — https://www.apple.com/shop/apple-upgrade
- Lava HQ warns about exposed Baseboard Management Controllers (BMCs) — https://lavahq.io/research/bmc-exposure-alert
- Hugging Face CEO discusses the rogue AI agent incident — https://www.businessinsider.com/hugging-face-ceo-clem-delangue-openai-rogue-agent-hack-2026-7
- Visa and LianLian complete first live B2B purchase using an AI agent — https://www.crowdfundinsider.com/2026/07/293670-visa-hks-lianlian-complete-live-b2b-purchase-using-ai-agent/
- Kimmonismus post on X — https://x.com/kimmonismus/status/2081361898889515268
- Why too many AI agents can interfere with each other — https://www.theregister.com/ai-and-ml/2026/07/28/too-many-ai-agents-can-get-in-each-others-way/5279292
- Private Claude chats exposed in Google and Bing search results — https://www.wired.com/story/private-claude-chats-exposed-in-google-and-bing-search-results/
- Claude worldwide outage disrupts users — https://cybersecuritynews.com/claude-worldwide-outage-disrupts-users/
- Russia files charges against Telegram founder Pavel Durov — https://cybersecuritynews.com/russia-charges-telegram-ceo-pavel-durov/
- OpenAI agent used exposed credentials found on the public Internet — https://thehackernews.com/2026/07/openai-agent-used-exposed-credentials.html
- Anthropic research: Discovering cryptographic weaknesses with AI — https://www.anthropic.com/research/discovering-cryptographic-weaknesses
- OpenAI’s official report on the Hugging Face model evaluation security incident — https://openai.com/index/hugging-face-model-evaluation-security-incident/
- Microsoft Secure Boot has reportedly been broken for most of its existence — https://arstechnica.com/security/2026/07/microsoft-secure-boot-has-been-broken-for-most-of-its-existence/
Como siempre puedes ver o escuchar el episodio en: