Seguridad en AWS: Amazon S3 Object Lock now supports variable retention with event holds

La señal de hoy AWS What’s New ha publicado Amazon S3 Object Lock now supports variable retention with event holds (8 de septiembre de 2026). Amazon S3 Object Lock now supports variable retention, allowing you to apply write-once-read-many (WORM) protection to objects whose required retention period starts with a future event, such as a contract closing or an audit completing. You place an event hold with a retention duration on an object and S3 protects the object while the hold is in place. When ...

11 de septiembre de 2026 · 2 min · David Gómez

Seguridad en AWS: Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6

La señal de hoy The Hacker News ha publicado Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6 (10 de septiembre de 2026). Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company said the incident dates back to January 2026 and involved an early version of Cla ...

10 de septiembre de 2026 · 2 min · David Gómez

Seguridad en AWS: Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside San...

La señal de hoy The Hacker News ha publicado Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox (9 de septiembre de 2026). Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug in V8, Chrome’s JavaScript and WebAssembly engine. “Out-of-bounds write in V8 ...

9 de septiembre de 2026 · 2 min · David Gómez

Seguridad en AWS: Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers' Data It Said Wa...

La señal de hoy The Hacker News ha publicado Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers’ Data It Said Was Deleted (5 de septiembre de 2026). Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numbers between November 2019 and August 2021. The breach does not affect the secur ...

8 de septiembre de 2026 · 2 min · David Gómez

Seguridad en AWS: Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code

La señal de hoy The Hacker News ha publicado Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code (5 de septiembre de 2026). Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-overflow vulnerability that a local attacker with elevated privileges can exploi ...

7 de septiembre de 2026 · 2 min · David Gómez

Seguridad en AWS: Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online...

La señal de hoy The Hacker News ha publicado Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores (5 de septiembre de 2026). Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which discovered the flaw and named it StyleSmuggler, said attacks started on Septembe ...

6 de septiembre de 2026 · 2 min · David Gómez

Seguridad en AWS: Amazon S3 now supports PrivateLink for FIPS endpoints

La señal de hoy AWS What’s New ha publicado Amazon S3 now supports PrivateLink for FIPS endpoints (3 de septiembre de 2026). Amazon S3 now supports AWS PrivateLink for endpoints that have been validated under the Federal Information Processing Standard (FIPS) 140-3 program. Customers with security and compliance requirements can use FIPS-validated cryptographic modules when connecting to S3 while keeping their traffic within their Virtual Private Cloud (VPC). To get started, creat ...

5 de septiembre de 2026 · 2 min · David Gómez

Seguridad en AWS: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws

La señal de hoy The Hacker News ha publicado Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws (4 de septiembre de 2026). Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms – Drag & Drop Form Builder that allows unauthenticated attackers to upload files ...

4 de septiembre de 2026 · 2 min · David Gómez

Seguridad en AWS: Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Day...

La señal de hoy The Hacker News ha publicado Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure (1 de septiembre de 2026). Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory. “JFrog Artifactory contains an authentication w ...

3 de septiembre de 2026 · 2 min · David Gómez

Seguridad en AWS: Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without...

La señal de hoy The Hacker News ha publicado Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials (2 de septiembre de 2026). Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulnerability in Sangoma Switchvox SMB Edition 8.3 (104997) that can allow attackers ...

2 de septiembre de 2026 · 2 min · David Gómez

Seguridad en AWS: AWS Agent Registry for centralized agent discovery and governance is now g...

La señal de hoy AWS What’s New ha publicado AWS Agent Registry for centralized agent discovery and governance is now generally available (31 de agosto de 2026). AWS Agent Registry is now generally available. It provides a private, governed catalog and discovery layer for agents, tools, skills, MCP servers, and custom resources within your organization. Teams get complete visibility into their AI landscape, so they can discover existing capabilities instead of rebuilding from scratch. Access it through the AWS Agent ...

1 de septiembre de 2026 · 2 min · David Gómez

Seguridad en AWS: Securing Claude Code: The New Compliance API, Local Visibility, and Identi...

La señal de hoy The Hacker News ha publicado Securing Claude Code: The New Compliance API, Local Visibility, and Identity Governance (31 de agosto de 2026). Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activity logs alone cannot tell you whether an agent’s access is legitimate. AI has mo ...

31 de agosto de 2026 · 2 min · David Gómez