Seguridad en AWS: AWS Transform now in scope for FedRAMP Class C

La señal de hoy AWS What’s New ha publicado AWS Transform now in scope for FedRAMP Class C (28 de agosto de 2026). AWS Transform is now in scope for FedRAMP Class C (formerly Moderate baseline) in the US East (Ohio) Region. You can now use AWS Transform to build applications and run workloads that are subject to FedRAMP Class C compliance requirements. The Federal Risk and Authorization Management Program (FedRAMP) is a US government-wide program that delivers a standard ...

30 de agosto de 2026 · 2 min · David Gómez

Seguridad en AWS: PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

La señal de hoy The Hacker News ha publicado PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions (28 de agosto de 2026). PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it’s “aware of confirmed customer incidents and is treating this matter with t ...

29 de agosto de 2026 · 2 min · David Gómez

Seguridad en AWS: Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a...

La señal de hoy The Hacker News ha publicado Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server (28 de agosto de 2026). cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM. cPanel described the issue as a critical security vulnera ...

28 de agosto de 2026 · 2 min · David Gómez

Seguridad en AWS: OpenAI releases its official report on the Hugging Face breach

La señal de hoy TechCrunch ha publicado OpenAI releases its official report on the Hugging Face breach (26 de agosto de 2026). The report, which spans several discrete cybersecurity compromises, is the most complete accounting of the incident to date. Una noticia genera atención. La pregunta útil es otra: ¿esto cambia algo de lo que tu equipo tiene que hacer esta semana, o no? Por qué importa para la seguridad de tu cuenta de AWS Si eres de responsables técnicos que operan sobre AWS sin un dueño senior de la nube, esto apunta a una necesidad concreta: una auditoría de seguridad de alcance cerrado que encuentra los riesgos antes de que se conviertan en una brecha o en una factura sorpresa. ...

27 de agosto de 2026 · 2 min · David Gómez

Seguridad en AWS: Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode

La señal de hoy The Hacker News ha publicado Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode (25 de agosto de 2026). Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck’s CVE Numbering Authority (CNA) record. The CNA record says the command can run as a local subprocess when the notebook is opened in e ...

26 de agosto de 2026 · 2 min · David Gómez

Seguridad en AWS: Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Acc...

La señal de hoy The Hacker News ha publicado Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Access Critical Data (25 de agosto de 2026). The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability, tracked as CVE-2026-21962 (CVSS score: 10.0), allows an unauthenticated attac ...

25 de agosto de 2026 · 2 min · David Gómez

Seguridad en AWS: AWS Partner Central agents MCP Server now supports OAuth with AWS Sign-In

La señal de hoy AWS What’s New ha publicado AWS Partner Central agents MCP Server now supports OAuth with AWS Sign-In (20 de agosto de 2026). AWS partners can now access AWS Partner Central agents from tools they already use, such as Amazon Quick and Kiro, using OAuth through AWS Sign-In. Partners can authorize agent access with their existing AWS identities, sign-in methods, IAM permissions, and governance controls without installing or maintaining additional authentication software. Previously, ...

24 de agosto de 2026 · 2 min · David Gómez

Seguridad en AWS: Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active...

La señal de hoy The Hacker News ha publicado Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active Exploitation (19 de agosto de 2026). The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026-65400 (CVSS score: 9.8) - An improper authentication vulnerability impacting A ...

23 de agosto de 2026 · 2 min · David Gómez

Seguridad en AWS: Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

La señal de hoy The Hacker News ha publicado Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution (20 de agosto de 2026). A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of command injection that can lead to remote code execution. “A remote code execution ...

22 de agosto de 2026 · 2 min · David Gómez

Seguridad en AWS: Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code...

La señal de hoy The Hacker News ha publicado Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code Execution (21 de agosto de 2026). Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting the tech giant’s cloud-based identity and access management service. It was previ ...

21 de agosto de 2026 · 2 min · David Gómez

Seguridad en AWS: Amazon CloudWatch pipelines adds GeoIP, RDS, and XML processors

La señal de hoy AWS What’s New ha publicado Amazon CloudWatch pipelines adds GeoIP, RDS, and XML processors (19 de agosto de 2026). Amazon CloudWatch pipelines now includes three new processors that parse and enrich log data as it’s ingested: an Amazon RDS log parser, an XML parser and a GeoIP enrichment processor. CloudWatch pipelines is a fully managed service that ingests, transforms, and routes telemetry to CloudWatch without managing infrastructure. Log sources often produce data th ...

20 de agosto de 2026 · 2 min · David Gómez