Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.
Para análisis editorial y noticias generales visita Noticias.
Sin señales activamente explotadas ni parches de emergencia.
Priority Command Strip
Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Pro para abrir el feed completo, histórico ampliado y el catálogo KEV.
Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →
Sin nuevos advisories PSIRT de vendor en la ventana.
Explotación reportada sobre Microsoft / AWS. Verificar exposición real en el inventario.
Akira ransomware affiliates were seen using a new technique to evade endpoint detection and response (EDR), where they rebooted a compromised Windows system into Safe Mode with Networking enabled. According to Huntress, the technique successfully took both its agent and Microsoft Defender’s real-time protection offline. This, the researchers said, gave the attacker a window to operate without endpoint defenses. The incident investigated by Huntress began on August 4 with a credential-spraying attack against an exposed SonicWall SSL VPN. About seven minutes after the failed login attempts began, an attacker successfully authenticated to an account that did not have multi-factor authentication (MFA) enabled, Huntress analyst James Northey said in a blog post. Two hours after authentication was managed, the operator reportedly accessed the domain controller over RDP, performed extensive Active Directory enumeration, and subsequently moved to an application server to archive mapped file shares with WinRAR. The stolen data was uploaded to an attacker-controlled S3 bucket using s5cmd, establishing the data-theft component of a double-extortion attack. Ultimately, AnyDesk was installed on the host machine for persistent remote access and to deliver the Akira ransomware payload. This is when the operator used “msconfig.exe” to force the machine into Safe Mode with Networking, instead of disabling EDR directly. Huntress says this is the first time it has observed Akira using the technique. Safe Mode is becoming a popular ransomware technique Safe Mode is normally a Windows troubleshooting environment that loads only essential drivers and services. That makes it useful to attackers because many third-party security products are excluded from the minimal startup configuration. Anticipating that AnyDesk itself might also be unavailable in Safe Mode, the attackers modified the Safe Boot registry configuration to ensure the remote-access service would start. The approach is not e Vendors: Microsoft, Google, AWS, Oracle, SonicWall, Atlassian, GitHub. DORA relevance: high.
Por qué importa
Explotación reportada sobre Microsoft / Google. Verificar exposición real en el inventario.
Acción recomendada
Avisa a los owners de los stacks Microsoft, Google, AWS, Oracle.
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking. [...] Vendors: Microsoft, AWS, SonicWall. DORA relevance: medium.
Por qué importa
Explotación reportada sobre Microsoft / AWS. Verificar exposición real en el inventario.
Acción recomendada
Avisa a los owners de los stacks Microsoft, AWS, SonicWall.
Lock your ssh-agent and it should sit there refusing to sign anything until you unlock it. In OpenSSH 10.4, locking it also switched off the check that tells the agent whether a request came from your own machine or arrived down a forwarded connection from a remote server. The fix shipped today in OpenSSH 10.5. The agent holds your decrypted private keys so you are not retyping a passphrase every few minutes, and agent forwarding … More → The post Locking your ssh-agent exposed local-only keys until OpenSSH 10.5 appeared first on Help Net Security. CVEs: CVE-2026-18577. Vendors: AWS, OpenSSL. DORA relevance: high.
Por qué importa
CVE de alto impacto sobre AWS / OpenSSL. Planificar ventana de parche.
Acción recomendada
Comprueba la exposición a CVE-2026-18577 en el inventario de activos y las herramientas de vulnerabilidades.
AWS Certificate Manager (ACM) will phase out email validation for public certificates throughout 2027, ahead of the Certification Authority/Browser (CA/B) Forum’s March 15, 2028 deadline for ending email-based domain validation. The CA/B Forum sets standards that browsers and certificate authorities follow for publicly trusted certificates. From March 15, 2028, public certificate authorities will no longer be able to use email-based domain validation to issue or renew publicly trusted certificates. Certificates issued before that date will … More → The post AWS Certificate Manager sets 2027 end date for email-validated certificate renewals appeared first on Help Net Security. CVEs: CVE-2026-20349, CVE-2026-68820. Vendors: Microsoft, Cisco, AWS, Salesforce, ServiceNow. DORA relevance: high.
Por qué importa
Postura cloud / identity comprometida o reforzada. Revisar configuración y baseline.
Acción recomendada
Comprueba la exposición a CVE-2026-20349, CVE-2026-68820 en el inventario de activos y las herramientas de vulnerabilidades.
Misconfiguration remains one of the leading threats to cloud environments because a single configuration error can result in public network access, unrotated keys, missing encryption, exposed services, and logging gaps. CISA now mandates baseline cloud configuration practices for US federal agencies. More than two-thirds of midmarket organizations use multiple cloud providers, each with its own security model, terminology, and configuration settings. The same security issue can manifest differently across AWS, Azure, and Google Cloud, often … More → The post Weak IAM affects up to 98% of cloud environments appeared first on Help Net Security. CVEs: CVE-2026-20349, CVE-2026-68820. Vendors: Microsoft, Cisco, Google, AWS, Salesforce, ServiceNow. DORA relevance: high.
Por qué importa
Postura cloud / identity comprometida o reforzada. Revisar configuración y baseline.
Acción recomendada
Comprueba la exposición a CVE-2026-20349, CVE-2026-68820 en el inventario de activos y las herramientas de vulnerabilidades.
A massive 153GB archive stolen during the LiteLLM supply chain attack exposes credentials and other sensitive data linked to thousands of corporate domains, including AWS, Samsung, Cisco, and Salesforce. Hudson Rock says it obtained and analyzed the archive, which contains 433,909 files, and attributed 118,829 CI runner dumps to 2,488 corporate domains. “We are leveraging this data for a global ethical disclosure effort,” Alon Gal, Hudson Rock’s co-founder and CTO, told Help Net Security. “We … More → The post 153GB of stolen credentials surface after LiteLLM supply chain attack appeared first on Help Net Security. CVEs: CVE-2026-68820. Vendors: Microsoft, Cisco, AWS, GitLab, Siemens, Salesforce, ServiceNow, Python. DORA relevance: high.
Por qué importa
Postura cloud / identity comprometida o reforzada. Revisar configuración y baseline.
Acción recomendada
Comprueba la exposición a CVE-2026-68820 en el inventario de activos y las herramientas de vulnerabilidades.
LiteLLM was compromised through the Trivy hack and abused to distribute information-stealing malware to its users. The post Over 2,500 Organizations Impacted by LiteLLM Supply Chain Attack appeared first on SecurityWeek. Vendors: Microsoft, Cisco, AWS, SAP, Adobe, Apple, Ivanti, SonicWall, GitHub, Siemens, Salesforce, ServiceNow, Zoom, Node.js, Python, NGINX. DORA relevance: medium.
Por qué importa
Postura cloud / identity comprometida o reforzada. Revisar configuración y baseline.
Acción recomendada
Avisa a los owners de los stacks Microsoft, Cisco, AWS, SAP.
Bulletin ID: 2026-074-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/04/2026 12:30 PM PDT Description: Kiro is an agentic IDE and command-line interface users install on their desktop. We identified CVE-2026-18656 and CVE-2026-18657, an issue where an uncontrolled search path element on Windows might allow an actor to execute arbitrary code via a maliciously crafted project directory containing a planted executable that is resolved before the system PATH when a local user opens the directory. Impacted versions: - Kiro IDE for Windows between versions 1.0.0 through 1.0.212 - Kiro CLI for Windows prior to v2.10.0 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin. CVEs: CVE-2026-18656, CVE-2026-18657. Vendors: Microsoft, AWS, PHP, Python, PostgreSQL, MySQL. DORA relevance: high.
Por qué importa
Postura cloud / identity comprometida o reforzada. Revisar configuración y baseline.
Acción recomendada
Comprueba la exposición a CVE-2026-18656, CVE-2026-18657 en el inventario de activos y las herramientas de vulnerabilidades.