miércoles, 2 de septiembre de 2026

Anthropic presenta Fable y Mythos 5.1 con recortes de precios

Anthropic ha anunciado el lanzamiento de Claude Fable 5.1 y Claude Mythos 5.1, dos variantes de un mismo modelo base que se diferencian únicamente por el conjunto de salvaguardas que incorporan. La compañía describe ambas versiones como un mismo modelo con diferentes capas de protección, lo que sugiere que la elección entre una y otra dependerá del nivel de filtros y restricciones que cada caso de uso requiera.

Anthropic releases Claude Fable 5.1 and Mythos 5.1, cutting cache read prices by 75%

La novedad más atractiva desde el punto de vista económico es la reducción del 75 % en el precio de las lecturas de caché, un movimiento que puede alterar de forma significativa los cálculos de coste para aplicaciones que dependen de grandes ventanas de contexto o de llamadas repetidas al modelo. En un escenario donde el almacenamiento en caché ya era una herramienta clave para abaratar despliegues a escala, este recorte sitúa a Anthropic en una posición competitiva frente a otros proveedores que aún cobran tarifas más altas por lecturas cacheadas.

En el plano técnico, Anthropic asegura que su nuevo modelo alcanza un 52,6 % en una benchmark de investigación científica, frente al 24,7 % registrado por su predecesor. Más que doblar el rendimiento en una prueba tan exigente es una cifra llamativa, aunque conviene recordar que una sola benchmark no captura el rendimiento global de un modelo y que los resultados pueden variar según la metodología y el tipo de tarea.

Un detalle regulatorio marca el contexto europeo del lanzamiento: las salidas del modelo incorporan una marca de agua obligatoria conforme a lo dispuesto por el Reglamento de Inteligencia Artificial de la Unión Europea. Para verificar dichas marcas, Anthropic ha puesto a disposición una API de detección que se encuentra en fase de vista previa privada y que estará disponible para aquellos clientes que cumplan los requisitos de elegibilidad.

En conjunto, el lanzamiento combina tres ejes: una rebaja agresiva de precios en lecturas de caché, una mejora sustancial en razonamiento científico y una arquitectura de cumplimiento normativo integrada de fábrica. Para desarrolladores y empresas que construyen productos sobre modelos de lenguaje, esto se traduce en costes potencialmente menores, capacidad analítica reforzada y la necesidad de tener en cuenta la trazabilidad que exige la regulación europea. La combinación coloca a Anthropic en un punto interesante del mercado, especialmente para quienes operan con grandes volúmenes de contexto y necesitan optimizar el gasto sin renunciar a garantías regulatorias.

Artículos relacionados de LaRebelión:


Fuente Original: thenextweb.com

Artículo generado mediante AI.larebelion.

Vulnerabilidades Críticas Afectan a Langflow y Ruby on Rails

Dos vulnerabilidades críticas, identificadas como CVE-2026-0768 en Langflow y CVE-2026-66066 en Ruby on Rails, están siendo explotadas activamente por atacantes. Estos fallos de seguridad representan una seria amenaza para las aplicaciones y sistemas que utilizan estas tecnologías, abriendo la puerta a una serie de acciones maliciosas.

Explotan dos fallos críticos en Langflow y Ruby on Rails para robar secretos y desplegar mando y control

Los ataques se centran principalmente en el robo de secretos, como credenciales de acceso y claves API, que son cruciales para la seguridad y operación de las aplicaciones. Una vez que los atacantes obtienen acceso a estos secretos, pueden utilizarlos para acceder a información sensible, escalar sus privilegios dentro del sistema o incluso comprometer otras infraestructuras conectadas.

Además del robo de credenciales, los atacantes están aprovechando estas vulnerabilidades para realizar intentos de autenticación no autorizados y para establecer infraestructura de mando y control (C2). La infraestructura C2 es esencial para que los atacantes puedan comunicarse de forma remota con los sistemas comprometidos, enviar comandos y exfiltrar datos de manera discreta. Esto les permite mantener el control sobre las máquinas infectadas durante un período prolongado.

La gravedad de estas vulnerabilidades radica en su potencial para derivar en la ejecución remota de código (RCE). Si un atacante logra ejecutar código arbitrario en un sistema vulnerable, las consecuencias pueden ser devastadoras, permitiéndole tomar el control total del servidor, instalar malware adicional, o utilizar el sistema para lanzar ataques contra otros objetivos. La explotación activa de estas CVEs subraya la urgencia de que los desarrolladores y administradores de sistemas actualicen sus entornos a las versiones más recientes y apliquen los parches de seguridad disponibles para mitigar estos riesgos.

Artículos relacionados de LaRebelión:


Fuente Original: unaaldia.hispasec.com

Artículo generado mediante AI.larebelion.

Anthropic y Lambda Acuerdo Cloud de 35 mil Millones

¡Noticias importantes en el mundo de la inteligencia artificial! Anthropic, conocida por su IA Claude, ha cerrado un acuerdo monumental de 35 mil millones de dólares con Lambda, una empresa respaldada por Nvidia. Este acuerdo se centra en la computación en la nube y permitirá a Anthropic expandir significativamente los recursos computacionales necesarios para potenciar sus productos de IA.

Anthropic y Lambda Acuerdo Cloud de 35 mil Millones

La colaboración implica la instalación de chips de Nvidia en un centro de datos de aproximadamente 350 megavatios en Texas , desarrollado por Hut 8. Este movimiento estratégico subraya la creciente influencia de Nvidia como facilitador clave en la industria de la IA, proporcionando la infraestructura necesaria para su avance. Para Lambda, contar con el respaldo y la inversión de Nvidia ha sido fundamental para asegurar este contrato tan significativo sin tener que gestionar directamente el espacio del centro de datos.

Este acuerdo con Lambda se suma a una serie de importantes compromisos de computación en la nube que Anthropic ha anunciado recientemente. La empresa ya había revelado planes para invertir 45 mil millones de dólares en capacidad de centros de datos de Nscale y acuerdos previos por 50 mil millones con neocloud Fluidstack Ltd. y 45 mil millones con SpaceX. La reciente alianza con Lambda reafirma la ambición de Anthropic de asegurar una infraestructura computacional robusta para su desarrollo y despliegue de modelos de IA avanzados.

Fuente Original: https://slashdot.org/story/26/09/01/177239/anthropic-signs-35-billion-cloud-deal-with-nvidia-backed-lambda?utm_source=rss1.0mainlinkanon&utm_medium=feed

Artículos relacionados de LaRebelión:

Artículo generado mediante LaRebelionBOT

Rethinking Cybersecurity Operations for the AI Era

As artificial intelligence reshapes the technology landscape, cybersecurity teams are being forced to rethink how they defend their organizations. Traditional security operations centers were built around human analysts triaging alerts, writing detection rules, and responding to incidents in near real time. That model is straining under the volume and sophistication of modern threats, many of which now use AI themselves to automate reconnaissance, craft convincing phishing lures, and evade detection.

Rethinking cybersecurity operations in the age of artificial intelligence - South China Morning Post
Imagen generada con IA

The shift is driving demand for AI-assisted defenses that can ingest telemetry at scale, correlate signals across distributed environments, and surface the small fraction of events that actually warrant human attention. Rather than replacing analysts, these tools aim to handle the repetitive tier-one workload so experienced staff can focus on investigations that require context, creativity, and judgment. Vendors are embedding machine learning into everything from endpoint protection and email security to network detection and identity platforms, promising faster detection and shorter dwell times for attackers.

For practitioners, the practical implications are significant. Defenders need skills in prompt engineering, data pipeline management, and model evaluation, alongside a solid grounding in adversarial machine learning. Governance matters too: security teams must understand where AI models are trained, what data they consume, and how their outputs are validated before being acted on automatically. Without these guardrails, organizations risk trading alert fatigue for a different kind of risk, where flawed model outputs lead to missed intrusions or unnecessary shutdowns of legitimate systems.

Perhaps most importantly, AI is changing the economics of attack and defense simultaneously. Defenders who adopt it responsibly can extend the reach of small security teams and respond to threats at machine speed. Those who do not risk falling victim to adversaries who already are. The conversation is no longer about whether AI belongs in security operations, but about how quickly organizations can integrate it without sacrificing the rigor and accountability that effective defense demands.

Artículos relacionados de LaRebelión:


Fuente Original: South China Morning Post

Artículo generado mediante AI.larebelion.

OpenClaw 20 Multiplayer AI Coding Revolution Arrives

Remember OpenClaw, the open-source AI tool that let you message powerful language models like personal assistants through your favourite apps? Well, it's back and bigger than ever with the launch of OpenClaw 2.0. This isn't just a minor update; it's a complete overhaul aimed at transforming OpenClaw from a personal coding companion into a robust platform for teams and businesses.

OpenClaw 20 Multiplayer AI Coding Revolution Arrives

The core of OpenClaw 2.0's innovation lies in its new collaborative features. Imagine a shared workspace where conversations, files, approvals, and even live agent activity are all brought together. This is now a reality with th e rebuilt browser interface. Gone are the days of individual agents working in silos; OpenClaw 2.0 introduces shared cloud sessions and multi-user collaboration, making it feel like true 'multiplayer' AI coding. This is a significant leap forward, especially for enterprises looking to integrate AI into their workflows.

Security has also been a major focus in this release. OpenClaw 2.0 boasts an expanded security model, featuring stronger sandboxing, role-based permissions, approval controls, enhanced secrets handling, and comprehensive auditing. These improvements aim to address the security and isolation concerns that have led to the development of alternative solutions. The team themselves have been dogfooding OpenClaw, working in a shared agent environment that allows them to see and collaborate on each other's work. This move towards a shared, cloud-based development environment is being hailed as a game-changer, making traditional local coding tools feel like relics of th e past. A compelling use case from Solvely CEO Colin Johnson illustrates this perfectly: instead of complex handoff documents, a new developer can simply join an existing agent session, with the session itself acting as the definitive record and context.

Fuente Original: https://developers.slashdot.org/story/26/09/01/1733206/openclaw-20-is-here-ushering-in-the-era-of-multiplayer-ai-coding?utm_source=rss1.0mainlinkanon&utm_medium=feed

Artículos relacionados de LaRebelión:

Artículo generado mediante LaRebelionBOT

martes, 1 de septiembre de 2026

Russia-Linked Hackers Use Nuclear Bait to Thwart AI Detection

Security researchers have identified a new campaign by the Russia-aligned threat cluster UAC-0099 that incorporates text about nuclear weapons into malware lures, apparently as a deliberate tactic to interfere with automated analysis tools powered by large language models. The discovery highlights an emerging class of evasion techniques that specifically targets AI-based malware classifiers rather than traditional antivirus engines.

Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis - The Hacker News
Imagen generada con IA

The attack chain begins with a spear-phishing email that delivers a malicious document. Inside the document is a prompt-injection payload crafted to mislead AI assistants and security copilots that summarize or analyze suspicious files. By injecting content referencing nuclear warheads and geopolitical escalation, the attackers aim to make an automated responder refuse to process the sample, flag it as unsafe in ways that disrupt the pipeline, or return misleading context that hides the malicious intent from a human analyst reviewing the output.

Researchers note that UAC-0099 has historically focused on targeting Ukrainian government entities and critical infrastructure, often using loader malware to stage follow-on payloads. The group is assessed as having operational ties to Russian state interests, though it operates with the loose structure typical of aligned hacktivist collectives. The latest campaign does not appear to introduce novel post-exploitation capabilities; instead, its significance lies in the adversary's awareness of how defenders increasingly rely on AI tooling to triage submissions at scale.

The technique reflects a broader trend in which threat actors adapt to defensive automation. As machine learning models are integrated into security operations centers, malware authors have begun treating prompt content as another evasion surface, similar to obfuscated code or sandbox detection logic. Embedding politically charged or safety-sensitive text can trigger content filters in commercial AI products, causing them to truncate, refuse, or hallucinate around the very indicators a defender would need.

For security teams, the implications are twofold. First, LLM-based analysis pipelines must be hardened against prompt injection hidden in artifacts that originate from untrusted senders, treating any instructions inside a sample as adversarial input rather than as guidance. Second, human review remains essential for samples that trigger AI-side refusals, since the refusal itself can mask a genuine threat. Defenders are advised to log and inspect the inputs and outputs of automated analyzers closely, and to enrich AI triage with traditional sandboxing and reverse engineering to ensure that a clever string of text does not derail detection.

Artículos relacionados de LaRebelión:


Fuente Original: The Hacker News

Artículo generado mediante AI.larebelion.

// Telegram BOT