<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/">
  <channel>
    <title>Seguridad AWS on David Gómez — AWS, seguridad y dirección técnica</title>
    <link>https://blog.itsdavidg.co/es/tags/seguridad-aws/</link>
    <description>Recent content in Seguridad AWS on David Gómez — AWS, seguridad y dirección técnica</description>
    <generator>Hugo</generator>
    <language>es-ES</language>
    <lastBuildDate>Fri, 11 Sep 2026 09:30:00 +0000</lastBuildDate>
    <atom:link href="https://blog.itsdavidg.co/es/tags/seguridad-aws/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Seguridad en AWS: Amazon S3 Object Lock now supports variable retention with event holds</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-09-11-seguridad-aws-amazon-s3-object-lock-now-supports-variable-retention-with/</link>
      <pubDate>Fri, 11 Sep 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-09-11-seguridad-aws-amazon-s3-object-lock-now-supports-variable-retention-with/</guid>
      <description>Seguridad en AWS — Amazon S3 Object Lock now supports variable retention, allowing you to apply write-once-read-many (WORM) protection to objects whose required retention period starts with a future event, such as a contract closing or an audit completing. You place an event hold with a retention du</description>
    </item>
    <item>
      <title>Seguridad en AWS: Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-09-10-seguridad-aws-anthropic-discloses-fourth-ai-hacking-incident-involving-c/</link>
      <pubDate>Thu, 10 Sep 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-09-10-seguridad-aws-anthropic-discloses-fourth-ai-hacking-incident-involving-c/</guid>
      <description>Seguridad en AWS — Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing list of cases that have raised concerns about the security risks posed by autonomous AI agents. The AI company sa</description>
    </item>
    <item>
      <title>Seguridad en AWS: Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside San...</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-09-09-seguridad-aws-chrome-v8-zero-day-exploited-in-the-wild-enables-code-exec/</link>
      <pubDate>Wed, 09 Sep 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-09-09-seguridad-aws-chrome-v8-zero-day-exploited-in-the-wild-enables-code-exec/</guid>
      <description>Seguridad en AWS — Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (CVSS score: N/A), has been described as an out-of-bounds bug</description>
    </item>
    <item>
      <title>Seguridad en AWS: Trezor Says ShipMonk Breach Exposed 67,000 U.S. Customers&#39; Data It Said Wa...</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-09-08-seguridad-aws-trezor-says-shipmonk-breach-exposed-67-000-u-s-customers-d/</link>
      <pubDate>Tue, 08 Sep 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-09-08-seguridad-aws-trezor-says-shipmonk-breach-exposed-67-000-u-s-customers-d/</guid>
      <description>Seguridad en AWS — Hardware wallet manufacturer Trezor on Friday disclosed that another 67,000 customers from the U.S. have been impacted in a breach at its shipping provider ShipMonk. The exposed information includes customer names, email addresses, phone numbers, shipping addresses, and order numb</description>
    </item>
    <item>
      <title>Seguridad en AWS: Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-09-07-seguridad-aws-critical-vmware-workstation-and-fusion-flaw-lets-vm-admins/</link>
      <pubDate>Mon, 07 Sep 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-09-07-seguridad-aws-critical-vmware-workstation-and-fusion-flaw-lets-vm-admins/</guid>
      <description>Seguridad en AWS — Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026-59346 (CVSS score: 9.3), is an integer-o</description>
    </item>
    <item>
      <title>Seguridad en AWS: Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online...</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-09-06-seguridad-aws-unpatched-magento-and-adobe-commerce-zero-day-exploited-to/</link>
      <pubDate>Sun, 06 Sep 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-09-06-seguridad-aws-unpatched-magento-and-adobe-commerce-zero-day-exploited-to/</guid>
      <description>Seguridad en AWS — Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store&amp;#39;s server without logging in, Dutch e-commerce security company Sansec said in an advisory published on September 5. Sansec, which d</description>
    </item>
    <item>
      <title>Seguridad en AWS: Amazon S3 now supports PrivateLink for FIPS endpoints</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-09-05-seguridad-aws-amazon-s3-now-supports-privatelink-for-fips-endpoints/</link>
      <pubDate>Sat, 05 Sep 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-09-05-seguridad-aws-amazon-s3-now-supports-privatelink-for-fips-endpoints/</guid>
      <description>Seguridad en AWS — Amazon S3 now supports AWS PrivateLink for endpoints that have been validated under the Federal Information Processing Standard (FIPS) 140-3 program. Customers with security and compliance requirements can use FIPS-validated cryptographic modules when connecting to S3 while keepin</description>
    </item>
    <item>
      <title>Seguridad en AWS: Over 440,000 Exploit Attempts Target Super Forms and Elementor Pro RCE Flaws</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-09-04-seguridad-aws-over-440-000-exploit-attempts-target-super-forms-and-eleme/</link>
      <pubDate>Fri, 04 Sep 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-09-04-seguridad-aws-over-440-000-exploit-attempts-target-super-forms-and-eleme/</guid>
      <description>Seguridad en AWS — Threat actors are exploiting two critical security flaws in WordPress plugins Super Forms and Elementor Pro, according to findings from Wordfence. The vulnerabilities in question are - CVE-2026-14894 (CVSS score: 9.8) - A missing file type validation vulnerability in Super Forms –</description>
    </item>
    <item>
      <title>Seguridad en AWS: Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Day...</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-09-03-seguridad-aws-attackers-exploit-critical-jfrog-artifactory-flaw-to-mint/</link>
      <pubDate>Thu, 03 Sep 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-09-03-seguridad-aws-attackers-exploit-critical-jfrog-artifactory-flaw-to-mint/</guid>
      <description>Seguridad en AWS — Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to admini</description>
    </item>
    <item>
      <title>Seguridad en AWS: Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without...</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-09-02-seguridad-aws-attackers-exploit-critical-switchvox-flaw-to-deploy-revers/</link>
      <pubDate>Wed, 02 Sep 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-09-02-seguridad-aws-attackers-exploit-critical-switchvox-flaw-to-deploy-revers/</guid>
      <description>Seguridad en AWS — Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a critical unauthenticated SQL injection vulner</description>
    </item>
    <item>
      <title>Seguridad en AWS: AWS Agent Registry for centralized agent discovery and governance is now g...</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-09-01-seguridad-aws-aws-agent-registry-for-centralized-agent-discovery-and-gov/</link>
      <pubDate>Tue, 01 Sep 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-09-01-seguridad-aws-aws-agent-registry-for-centralized-agent-discovery-and-gov/</guid>
      <description>Seguridad en AWS — AWS Agent Registry is now generally available. It provides a private, governed catalog and discovery layer for agents, tools, skills, MCP servers, and custom resources within your organization. Teams get complete visibility into their AI landscape, so they can discover existing ca</description>
    </item>
    <item>
      <title>Seguridad en AWS: Securing Claude Code: The New Compliance API, Local Visibility, and Identi...</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-08-31-seguridad-aws-securing-claude-code-the-new-compliance-api-local-visibili/</link>
      <pubDate>Mon, 31 Aug 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-08-31-seguridad-aws-securing-claude-code-the-new-compliance-api-local-visibili/</guid>
      <description>Seguridad en AWS — Claude Code reads files, runs shell commands, invokes MCP tools, and acts through the credentials available on a developer’s machine. Anthropic’s new Compliance API endpoints give security teams their clearest view yet into that activity. They also expose a larger problem: activit</description>
    </item>
    <item>
      <title>Seguridad en AWS: AWS Transform now in scope for FedRAMP Class C</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-08-30-seguridad-aws-aws-transform-now-in-scope-for-fedramp-class-c/</link>
      <pubDate>Sun, 30 Aug 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-08-30-seguridad-aws-aws-transform-now-in-scope-for-fedramp-class-c/</guid>
      <description>Seguridad en AWS — AWS Transform is now in scope for FedRAMP Class C (formerly Moderate baseline) in the US East (Ohio) Region. You can now use AWS Transform to build applications and run workloads that are subject to FedRAMP Class C compliance requirements. The Federal Risk and Authorization Manage</description>
    </item>
    <item>
      <title>Seguridad en AWS: PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-08-29-seguridad-aws-papercut-zero-day-exploited-in-attacks-affecting-all-ng-an/</link>
      <pubDate>Sat, 29 Aug 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-08-29-seguridad-aws-papercut-zero-day-exploited-in-attacks-affecting-all-ng-an/</guid>
      <description>Seguridad en AWS — PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said</description>
    </item>
    <item>
      <title>Seguridad en AWS: Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a...</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-08-28-seguridad-aws-critical-cpanel-flaw-could-let-one-hosting-customer-take-r/</link>
      <pubDate>Fri, 28 Aug 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-08-28-seguridad-aws-critical-cpanel-flaw-could-let-one-hosting-customer-take-r/</guid>
      <description>Seguridad en AWS — cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported vers</description>
    </item>
    <item>
      <title>Seguridad en AWS: OpenAI releases its official report on the Hugging Face breach</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-08-27-seguridad-aws-openai-releases-its-official-report-on-the-hugging-face-br/</link>
      <pubDate>Thu, 27 Aug 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-08-27-seguridad-aws-openai-releases-its-official-report-on-the-hugging-face-br/</guid>
      <description>Seguridad en AWS — The report, which spans several discrete cybersecurity compromises, is the most complete accounting of the incident to date.</description>
    </item>
    <item>
      <title>Seguridad en AWS: Marimo Notebook Flaw Could Run MCP Commands Before Cells Execute in Edit Mode</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-08-26-seguridad-aws-marimo-notebook-flaw-could-run-mcp-commands-before-cells-e/</link>
      <pubDate>Wed, 26 Aug 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-08-26-seguridad-aws-marimo-notebook-flaw-could-run-mcp-commands-before-cells-e/</guid>
      <description>Seguridad en AWS — Marimo has addressed a high-severity security flaw in its notebook software that allowed an attacker to execute an attacker-supplied Model Context Protocol (MCP) command in a specially crafted notebook, according to VulnCheck&amp;#39;s CVE Numbering Authority (CNA) record. The CNA record </description>
    </item>
    <item>
      <title>Seguridad en AWS: Actively Exploited Oracle WebLogic Flaw Lets Unauthenticated Attackers Acc...</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-08-25-seguridad-aws-actively-exploited-oracle-weblogic-flaw-lets-unauthenticat/</link>
      <pubDate>Tue, 25 Aug 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-08-25-seguridad-aws-actively-exploited-oracle-weblogic-flaw-lets-unauthenticat/</guid>
      <description>Seguridad en AWS — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation. The vulnerability</description>
    </item>
    <item>
      <title>Seguridad en AWS: AWS Partner Central agents MCP Server now supports OAuth with AWS Sign-In</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-08-24-seguridad-aws-aws-partner-central-agents-mcp-server-now-supports-oauth-w/</link>
      <pubDate>Mon, 24 Aug 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-08-24-seguridad-aws-aws-partner-central-agents-mcp-server-now-supports-oauth-w/</guid>
      <description>Seguridad en AWS — AWS partners can now access AWS Partner Central agents from tools they already use, such as Amazon Quick and Kiro, using OAuth through AWS Sign-In. Partners can authorize agent access with their existing AWS identities, sign-in methods, IAM permissions, and governance controls wit</description>
    </item>
    <item>
      <title>Seguridad en AWS: Critical macOS, SharePoint, vCenter, and Microsoft IKE Flaws Under Active...</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-08-23-seguridad-aws-critical-macos-sharepoint-vcenter-and-microsoft-ike-flaws/</link>
      <pubDate>Sun, 23 Aug 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-08-23-seguridad-aws-critical-macos-sharepoint-vcenter-and-microsoft-ike-flaws/</guid>
      <description>Seguridad en AWS — The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added four critical vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, stating they are being exploited in the wild. The shortcomings added to the KEV catalog are listed below - CVE-2026</description>
    </item>
    <item>
      <title>Seguridad en AWS: Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-08-22-seguridad-aws-attackers-exploit-zimbra-snmp-flaw-for-unauthenticated-rem/</link>
      <pubDate>Sat, 22 Aug 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-08-22-seguridad-aws-attackers-exploit-zimbra-snmp-flaw-for-unauthenticated-rem/</guid>
      <description>Seguridad en AWS — A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CVE-2026-73570 (CVSS score: 8.9), which refers to a case of com</description>
    </item>
    <item>
      <title>Seguridad en AWS: Microsoft Entra ID Flaw (CVSS 10.0) Exploited in Wild, Allows Remote Code...</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-08-21-seguridad-aws-microsoft-entra-id-flaw-cvss-10-0-exploited-in-wild-allows/</link>
      <pubDate>Fri, 21 Aug 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-08-21-seguridad-aws-microsoft-entra-id-flaw-cvss-10-0-exploited-in-wild-allows/</guid>
      <description>Seguridad en AWS — Microsoft on Thursday warned of a maximum-severity security flaw in Entra ID that it said has been exploited in the wild, but noted that no customer action is required. The vulnerability, tracked as CVE-2026-69836 (CVSS score: 10.0), is a case of remote code execution impacting th</description>
    </item>
    <item>
      <title>Seguridad en AWS: Amazon CloudWatch pipelines adds GeoIP, RDS, and XML processors</title>
      <link>https://blog.itsdavidg.co/es/posts/2026-08-20-seguridad-aws-amazon-cloudwatch-pipelines-adds-geoip-rds-and-xml-process/</link>
      <pubDate>Thu, 20 Aug 2026 09:30:00 +0000</pubDate>
      <guid>https://blog.itsdavidg.co/es/posts/2026-08-20-seguridad-aws-amazon-cloudwatch-pipelines-adds-geoip-rds-and-xml-process/</guid>
      <description>Seguridad en AWS — Amazon CloudWatch pipelines now includes three new processors that parse and enrich log data as it&amp;#39;s ingested: an Amazon RDS log parser, an XML parser and a GeoIP enrichment processor. CloudWatch pipelines is a fully managed service that ingests, transforms, and routes telemetry t</description>
    </item>
  </channel>
</rss>
