[CVE-2026-10579] DETECCIÓN (CVSS 9.8): A flaw was found in Picketlink Federation SAML; the unsolcited response handler ... [CVE-2026-19425] DETECCIÓN (CVSS 9.8): Travel Agency Management System developed by Win Men Intermational has a SQL Inj... [CVE-2026-44758] DETECCIÓN (CVSS 9.1): SAP Manufacturing Integration and Intelligence (MII) allows an attacker with hig... [CVE-2026-34265] DETECCIÓN (CVSS 9.8): SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to expl... [CVE-2026-14450] DETECCIÓN (CVSS 9.9): A flaw was found in the MaaS API. This vulnerability allows any pod within the c... [CVE-2026-71991] DETECCIÓN (CVSS 9.8): MSI Radix AXE6600 router firmware version v781521 contains a command injection v... [CVE-2026-71990] DETECCIÓN (CVSS 9.8): MSI Radix AXE6600 router firmware version v781521 contains a command injection v... [CVE-2026-71986] DETECCIÓN (CVSS 9.8): MSI Radix AXE6600 router firmware version v781521 contains a command injection v... [CVE-2026-71985] DETECCIÓN (CVSS 9.8): MSI Radix AXE6600 router firmware version v781521 contains a command injection v... [CVE-2026-71957] DETECCIÓN (CVSS 9.8): D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_2...

01 Who am I

Mi nombre es Luis Diago de Aguilar, analista senior de ciberseguridad e ingeniero de software operando bajo el pseudónimo h3st4k3r. Mi trayectoria se centra en la convergencia entre la inteligencia artificial aplicada y la ciberseguridad defensiva.

He consolidado mi especialización técnica en la orquestación de sistemas complejos, integrando arquitecturas de Inteligencia Artificial para la optimización de procesos y el Análisis de Inteligencia para la prevención proactiva. Mi praxis profesional se fundamenta en la investigación de vulnerabilidades y en la construcción de soluciones de software robustas bajo estándares de alta disponibilidad.

24

Repositorios

61

Artículos

142

Contribs

5

Ponencias

02 Dominio Técnico
Vulnerability & Incident Management

Gestión del ciclo de vida de vulnerabilidades y respuesta a incidentes (Junior Incident Response). Análisis de alertas, clasificación de severidad y remediación técnica.

OpenVAS Tenable CrowdStrike Process Handling
CTI Specialist & Intelligence

Generación de inteligencia de amenazas mediante monitorización OSINT y Deep Web. Análisis de TTPs de actores de amenaza y enriquecimiento de IOCs.

VirusTotal OSINT Threat Actor Analysis
Scripting & Automation

Automatización de flujos de trabajo de seguridad mediante scripts personalizados e integración de APIs de terceros con plataformas de gestión.

Python API Integration Ticketing Platforms
Arquitecturas de IA

Diseño e implementación de modelos de aprendizaje automático orientados a la detección de anomalías y automatización cognitiva en entornos SOC.

Machine Learning Alert Handling Cognitive Auto

03 Alerta Vulnerabilidades

CVE-2026-10579 Publicación: 11/08/2026

A flaw was found in Picketlink Federation SAML; the unsolcited response handler would accept forged assertions with no verification or validation, permitting an unauthed attacker to authenticate as any principal in any r...

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-19425 Publicación: 11/08/2026

Travel Agency Management System developed by Win Men Intermational has a SQL Injection vulnerability. Unauthenticated remote attackers can inject arbitrary SQL commands to read, modify, and delete database contents....

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-44758 Publicación: 11/08/2026

SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successf...

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-34265 Publicación: 11/08/2026

SAP NetWeaver Application Server ABAP allows an unauthenticated attacker to exploit logical errors in DIAG protocol parsing, resulting in memory corruption. This vulnerability could potentially disclose sensitive system ...

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-14450 Publicación: 10/08/2026

A flaw was found in the MaaS API. This vulnerability allows any pod within the cluster to bypass the Kuadrant AuthPolicy gateway by forging HTTP headers, specifically `X-MaaS-Username` and `X-MaaS-Group`, which are trust...

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-71991 Publicación: 09/08/2026

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for Telnet configuration that allows remote attackers to execute arbitrary commands on the affec...

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-71990 Publicación: 09/08/2026

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the TelnetSSH function used for SSH configuration that allows remote attackers to execute arbitrary commands on the affected...

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-71986 Publicación: 09/08/2026

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the dmz function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can exploit th...

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-71985 Publicación: 09/08/2026

MSI Radix AXE6600 router firmware version v781521 contains a command injection vulnerability in the accesscontrol function that allows remote attackers to execute arbitrary commands on the affected device. Attackers can ...

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-71957 Publicación: 08/08/2026

D-Link DWR-M961 devices with hardware version C1 and software version 1.1.2_C1_202602110044 contain a buffer overflow vulnerability in the app.cgi interface. A remote attacker can write an overly long string to the netAc...

OBJETIVO: SISTEMAS DISTRIBUIDOS