Un fallo de WhatsApp permite acceder a fotografías en determinados móviles Android bloqueados
El problema, descubierto por el investigador José Rodríguez, necesita acceso físico al teléfono y que se atienda una videollamada entrante desde la pantalla de bloqueo. No se trata de un ataque remoto ni requiere la instalación de software adicional, códigos o conocimientos técnicos avanzados.
El fallo se produce al utilizar la integración de las herramientas de Meta AI en los efectos de videollamada.
En los terminales afectados, al seleccionar la opción de editar una fotografía mediante “Crear con Meta AI” en la pestaña de fondos, la aplicación abre la galería del dispositivo sin solicitar PIN, contraseña, huella dactilar ni reconocimiento facial.
El investigador ha publicado una demostración en vídeo y ha comunicado el hallazgo tanto a Meta como a Google. Hasta el momento no existe comunicado oficial de ninguna de las dos compañías, ni identificador CVE ni parche anunciado.
Las pruebas realizadas confirman el comportamiento en un Google Pixel 6 Pro con Android 17 (incluido el último parche de seguridad) y en un OPPO K13 con ColorOS 16. En cambio, un Samsung Galaxy S25 Ultra con One UI 8.5 bloquea el acceso y exige autenticación.
Los iPhone no se ven afectados porque WhatsApp emplea CallKit de Apple, lo que impide acceder a los efectos de la aplicación desde la pantalla de bloqueo.
La incidencia depende de cómo cada fabricante gestiona los permisos y las actividades iniciadas desde la pantalla de bloqueo.
Mientras no se publique una corrección, se recomienda no dejar el teléfono bloqueado al alcance de terceros y mantener actualizados tanto WhatsApp como el sistema operativo Android.
🔴LLAMADO URGENTE EN CIBERSEGURIDAD
Con el liderazgo de OpenAI, más de 100 empresas, incluyendo a Google, Anthropic y Microsoft, firmaron una carta para gobiernos, empresas y la sociedad llamando a una alerta sobre lo que se viene en ciberseguridad indicando que tenemos una ventana muy limitada para mejorar las defensas para lo que se viene en unos meses.
Dicen que la infraestructura mundial, incluyendo hospitales, Internet y hasta el tratamiento de agua potable, estará en riesgo.
Piden poner IA defensiva en manos de más equipos, corregir las vulnerabilidades más peligrosas, comprobar los resultados y compartir lo aprendido, mediante una respuesta coordinada entre empresas y gobiernos.
Importante destacar que las empresas de IA desplegaron la tecnología que genera el riesgo y ahora la defensa de ese riesgo es vendida por esas mismas empresas de IA. No quita que no sea verdad el riesgo que se plantea ni que sea un proceso planificado pero no hay que dejar de ver el panorama completo.
https://t.co/OFtKkk3SwJ
AliExpress tiene una forma de identificarte casi invisible. ¿Cómo? Usando el audio de tu PC.
1. Abres la web → se te corta la música del móvil.
No hay <audio> ni <video>. Silenciar la pestaña no sirve. ¿Qué está pasando entonces?
2. Están generando un sonido con JavaScript:
Tú no oyes nada: el volumen va a 0.
Pero sí se manda a los altavoces.
El PC cree que hay audio.
Los auriculares se quedan pillados y no saltan al móvil.
Ese sonido lo usan para identificarte.
Cada CPU y navegador procesa el audio un pelín distinto.
Y eso, junto a canvas, WebGL y más, es tu huella.
Firefox ya hace que la parte del audio casi no sirva.
El truco del Bluetooth… sigue funcionando.
El post original (y el filtro de uBlock):
→ https://t.co/gpDjRxP8dF
A developer using Bluetooth headphones accidentally caught Chinese e-commerce giant Alibaba secretly hijacking his computer's audio system without making a single sound.
When his wireless headphones refused to switch audio to his phone while browsing AliExpress, he inspected the site's hidden code. He discovered background scripts holding his computer's audio pipeline wide open.
Alibaba was using the browser's WebAudio API to run invisible sound waves at zero volume. By measuring tiny hardware differences in how each computer processes those signals, the site created a unique digital fingerprint to track devices.
Because the secret audio path stayed active, it froze his Bluetooth connection while quietly scraping hardware memory, screen dimensions, and network data in the background.
Alibaba's AliExpress was caught using users' audio systems to track them.
AliExpress wasn't recording users but instead playing a silent sound and measuring how users' specific devices processed it in order to fingerprint them.
But don't worry because Brave stops this.
🤯 A partir del 1 de octubre de 2026, Meta cobrará los mensajes de atención de las empresas (bots de WhatsApp), aun dentro de la ventana de 24 horas. https://t.co/XPbfEEBj4X
Atención bots WhatsApp.🚨
Desde el 01/10/2026, Meta cobrará por mensajes de servicio. También cobrará por mensajes de utility enviados en respuesta a usuarios dentro de una ventana de servicio al cliente de 24 horas abierta. +Info: https://t.co/kuBvpQSDWS
Un usuario parece que logró registrar la cadena de pensamiento de Claude Fable al pedirle resolver un problema matemático. No parece pensar en frases completas y genera signos de frustración (grrrr) cuando no le sale y de alivio cuando se va acercando a la solución.
Las dos cosas son llamativas. La primera porque significa que los modelos más grandes que se están generando cada vez se alejarían más del pensamiento humano que podamos revisar y entender. Lo segundo es un poco más de lo que ya se venía hablando sobre los modelos y las emociones.
@maxifirtman Para los devs: que hicieron bots con la API de meta: hay que actualizar las integraciones para que contemple el username en lugar del phone number.
Today at the https://t.co/BCZwnyneVK advisory council.
I gave my approval to the council’s proposal that Estonia become the first country in the world to create a digital identity for AI agents — an AI personal identification code.
This may sound technical, but the idea is simple. In the future, artificial intelligence will carry out digital actions on behalf of a person, company, or institution: compiling reports, preparing declarations, or communicating with information systems. But it must be clear who is acting, on whose behalf, with what rights, and who is responsible.
It cannot be the case that a person is forced to give their AI assistant access to all of their rights, services, and data. Agents must have limited, controllable, and auditable authorizations. For example, it must be possible to specify whether an agent may only view data, prepare a document, or act within a fixed monetary limit.
The success of Estonia’s digital state was born of trust. Digital identity, X-Road, the digital signature, and the data tracker have made our country faster, simpler, and more secure. Now we face the same question in the age of AI agents: how to use new technology so that convenience grows, but control and accountability are not lost.
If we act quickly and wisely, Estonia can become a country that helps shape the international standard in this field. A small country, but a big opportunity.
Thank you to the members, experts, and partners of the https://t.co/BCZwnyneVK advisory council who are thinking alongside us. Let’s move forward.
India blocks Telegram ahead of scandal-hit medical school entrance exam
2.3 million people sit test chasing 100,000 places, and country already canceled it once this year
https://t.co/LaljGvEamu
The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national, whether inside or outside the United States, including foreign national Anthropic employees.
The net effect of this order is that we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance.
Access to all other Claude models is not affected.
We apologize for this disruption to our customers. We believe this is a misunderstanding and are working to restore access as soon as possible.
Read our full statement: https://t.co/bwn0sximKZ
Today we reduced headcount by 22%. The business is the strongest it's ever been. So I think it's important to be direct about what I'm seeing and why.
First, I made this decision and I own it. I did it because the way to operate at the highest level of productivity is changing, and to win the future, ClickUp needs to change with it.
Second, this wasn't about cutting costs. Most savings from this change will flow directly back into the people who stay. We'll be introducing million-dollar salary bands. If you create outsized impact using AI, you'll be paid outside of traditional bands.
Most importantly, I have the deepest gratitude for those affected. We're doing this from a position of strength specifically so we can take care of people properly. Everyone affected receives a package aimed at honoring their contributions and easing the transition.
I only see two options: wait for this to play out gradually in the market or be honest about what I'm seeing and act proactively.
THE 100X ORGANIZATION
The primary change is that we're restructuring around what I call 100x org. The goal is 100x output. The roles required to build at the highest level are fundamentally different than they were a year ago.
Incremental improvements to existing systems won't get us there. We need new ones. That means creating enough disruption to rebuild rather than iterate on what's already broken.
The common narrative is that AI makes everyone more productive. It doesn't. Many of the workflows of today, if left unchanged, create bottlenecks in AI systems.
These roles will evolve. But waiting for that to happen naturally means falling behind now.
The 100x org is actually heavily dependent on people - infinitely more than today. This is only possible with 10x people that have embraced and adopted new ways of working.
THE BUILDERS, AGENT MANAGERS, AND FRONT-LINERS
— THE BUILDERS: 10X ENGINEERS
I don't think most companies have internalized what's actually happening with AI in engineering. The common narrative is that AI makes all engineers more productive. That may be true in isolation, but at an organization level - that is the farthest thing from reality.
Here's what we've validated recently at ClickUp: the great engineers, the ones who can orchestrate, architect, and review, are becoming 100x engineers. They're not writing code. They're directing agents that write code. The skill is judgment.
AI makes the best engineers wildly more productive, and everyone else using AI slows these engineers down.
Think about it - the bottlenecks are (1) orchestration - telling AI what to do, and (2) reviewing - what AI did. Everything is leapfrogged and no longer needed.
So who do you want orchestrating and reviewing code?
And how do you want your best engineers to spend their time?
If your best engineers are spending time reviewing other people's code, then this is inherently an inefficient bottleneck. These engineers can review their agent's code much faster than reviewing human code.
The new world is about enabling your 10x engineers to become 100x.
The wrong strategy is to push every engineer to use infinite tokens. Companies doing this are celebrating 500% more pull requests. But customer outcomes don't match the volume of code being generated.
I call this the great reckoning of AI coding, and every company will face this soon if not already.
More code is just another bottleneck to the best engineers, and ultimately to your company's impact as well.
— THE BUILDERS: 10X PRODUCT MANAGERS
Product management and design roles are merging.
Designers that have customer focus, become more like product managers.
And product managers that have intuition for UX become more like designers.
The bottleneck of user research is gone. It takes us just one mention of an agent to kickoff research and analyze results.
The bottleneck of product <> design iteration is also gone. The product builder iterates on their own, along with agents and skills that ensure alignment with quality and strategy.
Also controversial today - I believe that the wrong strategy is to have your PMs shipping code - that just introduces another bottleneck that the best engineers will waste their time on.
To be clear, PMs should be coding but they should do this in a playground to iterate, validate, and scope. That code should not go to production.
Everything outside of managing systems, orchestrating AI, and reviewing output becomes a bottleneck.
That's why the other roles that are critical along with these are the systems managers (to reduce bottlenecks) along with a bottleneck you can't replace - customer meeting time.
— THE SYSTEM MANAGERS
Ironically, the people that automate their jobs with AI will always have a job. They become owners of the AI systems - agent managers. We have many examples of these people at ClickUp.
The underlying systems in which we operate are absolutely critical to get right. I think most companies are delusional to think they can iterate on existing systems and compete in this new world.
You must create enough disruption so that old systems are deprecated entirely. If there's any definition for 'AI native' that's what it is.
— THE FRONT-LINERS
In a world that will become saturated with AI communication, the human touch will matter more than anything to customers.
This is a bottleneck that you shouldn't replace - even when agents are high enough quality to do video meetings.
One-on-one meeting time with customers is something that shouldn't be automated. The systems around the meetings should be - so that front-liners spend nearly 100% of their time with customers.
REWARDING 100X IMPACT
In a world where companies are able to do so much more with less, where does that excess money go?
In our case, much of the savings in this new operating model will flow directly back to those that enabled it.
We must reward people that create productivity accordingly. This aligns incentives on both sides. Plus, in a world where your best people create 100x impact, you can't afford to lose them.
You should aim to retain these employees for decades. The context they have and their ability to efficiently orchestrate and review will be nearly impossible to replace.
Compensation bands of today should be thrown out the door. We're introducing $1 million cash/year salary bands with a path available to nearly everyone in the company if they produce 100x impact by creating or managing AI systems.
THE FUTURE
Nearly every company will make changes like these. The ones that do it proactively will define what comes next.
The future is not fewer people. It's different work, new roles, and better rewards for those who embrace it. We're already seeing entirely new roles emerge, like Agent Managers, that didn't exist a year ago.
ClickUp is positioning to lead this shift, not just internally, but for our customers too. I've never been more certain about where we're headed.
🚨 JUST IN - Google published a long piece about "Optimizing your website for generative AI features on Google Search" 👀
A lot in it https://t.co/22t75EtwUH
🧵
To check if your Google Workspace has been compromised by the same tool that compromised Vercel:
1. Go to https://t.co/TpuIOW5Fwg
- This is Google Admin Console > Security > Access and Data Control > API Controls > Manage app access > Accessed Apps
2. Filter by ID = https://t.co/uqJnCqp5Ah
- This is the ID of the compromised OAuth app
If you see an app after filtering, you have potentially been compromised
Desde que entró en vigor la prohibición de redes sociales para menores de 16 años en Australia (el 10 de diciembre de 2025), el servicio de ayuda Kids Helpline ha recibido casi 100 llamadas en las primeras tres semanas que mencionaban directamente el veto. Entre quienes llaman hay adolescentes suicidas, muy angustiados, con discapacidades o que se sienten aislados. Muchos dicen haber perdido sus redes de apoyo, amistades digitales de largo tiempo y herramientas que usaban para manejar la ansiedad, las ganas de autolesionarse o la soledad (como distraerse con YouTube o chatear con amigos).
No solo llaman los jóvenes sino también padres preocupados que contactan con el servicio por conflictos en casa, rabietas, comportamientos regresivos, discusiones constantes y niños que se esconden con los dispositivos o se niegan a relacionarse con la familia. El mayor nivel de angustia se observa en niños de 10 a 14 años, especialmente en niñas y en jóvenes neurodivergentes (como aquellos con autismo), que usaban las redes para sentirse conectados y no solos, sobre todo si sufrían acoso escolar.
Expertos como la Dra. Lisa Harrison señalan que el cambio es difícil porque las redes generan “golpes de dopamina” y muchos jóvenes las usaban para combatir la soledad nocturna o el estrés. El artículo muestra los primeros efectos negativos inmediatos de la medida, aunque el gobierno sigue evaluando su cumplimiento (ya se desactivaron millones de cuentas) y planea más regulaciones. Kids Helpline y otros servicios siguen ofreciendo apoyo a familias que lo necesitan durante esta transición.
Zuckerberg quiere que sus 80.000 empleados puedan hablar con él a toda hora, así que se armó un clon de IA para estar presente en cada escritorio.
Literalmente le están cargando sus gestos y su forma de pensar a un avatar para que puedan chatear con "él" cuando quieran. El objetivo es pura productividad: cuando sentís que el jefe te está mirando o te responde al toque, no bajás el ritmo ni loco.
De hecho, Mark ya vive en esa frecuencia. Hoy usa un "Agente CEO" para saltearse la burocracia y decidir en segundos; este clon es el siguiente paso para inyectar esa misma velocidad en toda la empresa.
Pero lo más fuerte es que esto no queda en Meta. Si funciona, se lo van a vender a los creadores de contenido para que puedan estar con su audiencia las 24 horas sin poner la cara. Básicamente, están inventando la forma de que el "protagonista" nunca descanse y el negocio siga facturando mientras dormís.
Según el Financial Times y The Guardian, ya están en fase de entrenamiento.
Estamos entrando en la era de la presencia infinita. El tiempo dejó de ser un límite para escalar un negocio.
🚨 CHINA ACABA DE CAMBIAR LAS REGLAS DEL JUEGO EN INTERNET 📱🇨🇳
El carisma y los millones de seguidores ya no bastan.
A partir de ahora, si quieres hablar de medicina, finanzas, derecho, educación o temas militares, tienes que demostrarlo con un título universitario o certificación profesional. 🎓📜
Douyin (el TikTok chino), Weibo y Bilibili ahora verifican tus diplomas. Sin comprobante oficial… no publicas. Punto. 🛡️
Las multas son brutales: hasta 100.000 yuanes (unos 14.000 dólares), eliminación de videos, bloqueo de cuenta y adiós a la monetización. El negocio de la desinformación se puso muy caro 💸🚫
Además, todo video debe:
- Etiquetar si usa IA 🤖
- Citar fuentes verificables
- Dejar claro si es opinión personal o consejo profesional.
China decidió poner orden donde cualquiera daba consejos sin respaldo.
❓ La gran pregunta: ¿este modelo llegará pronto a otros países con la ola de desinformación?
¿Qué opinas tú? 👇
#China #Regulación #Influencers #Desinformación #RedesSociales