[CVE-2026-7849] DETECCIÓN (CVSS 9.8): Due to improper neutralization of special elements, an unauthenticated remote at... [CVE-2026-44108] DETECCIÓN (CVSS 9.8): Due to a flaw in the execution order of scripts during shutdown, the firewall is... [CVE-2026-44104] DETECCIÓN (CVSS 9.8): The firmware update process for the basemodule of the charging controller only v... [CVE-2026-44101] DETECCIÓN (CVSS 9.8): Due to missing authentication the CHARX OCPP Agent service allows an unauthentic... [CVE-2026-44100] DETECCIÓN (CVSS 9.4): The CHARX JupiCore service allows an unauthenticated remote attacker to reconfig... [CVE-2026-44092] DETECCIÓN (CVSS 9.1): An unauthenticated remote attacker can inject malicious input into the ModbusSer... [CVE-2026-44091] DETECCIÓN (CVSS 9.1): An unauthenticated remote attacker can post a malicious ID to the MQTT Broker re... [CVE-2026-44090] DETECCIÓN (CVSS 9.8): Due to missing authentication, an unauthenticated remote attacker may access the... [CVE-2026-16610] DETECCIÓN (CVSS 9.8): The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to ... [CVE-2026-48449] DETECCIÓN (CVSS 10): Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerabi...

01 Who am I

Mi nombre es Luis Diago de Aguilar, analista senior de ciberseguridad e ingeniero de software operando bajo el pseudónimo h3st4k3r. Mi trayectoria se centra en la convergencia entre la inteligencia artificial aplicada y la ciberseguridad defensiva.

He consolidado mi especialización técnica en la orquestación de sistemas complejos, integrando arquitecturas de Inteligencia Artificial para la optimización de procesos y el Análisis de Inteligencia para la prevención proactiva. Mi praxis profesional se fundamenta en la investigación de vulnerabilidades y en la construcción de soluciones de software robustas bajo estándares de alta disponibilidad.

24

Repositorios

61

Artículos

142

Contribs

5

Ponencias

02 Dominio Técnico
Vulnerability & Incident Management

Gestión del ciclo de vida de vulnerabilidades y respuesta a incidentes (Junior Incident Response). Análisis de alertas, clasificación de severidad y remediación técnica.

OpenVAS Tenable CrowdStrike Process Handling
CTI Specialist & Intelligence

Generación de inteligencia de amenazas mediante monitorización OSINT y Deep Web. Análisis de TTPs de actores de amenaza y enriquecimiento de IOCs.

VirusTotal OSINT Threat Actor Analysis
Scripting & Automation

Automatización de flujos de trabajo de seguridad mediante scripts personalizados e integración de APIs de terceros con plataformas de gestión.

Python API Integration Ticketing Platforms
Arquitecturas de IA

Diseño e implementación de modelos de aprendizaje automático orientados a la detección de anomalías y automatización cognitiva en entornos SOC.

Machine Learning Alert Handling Cognitive Auto

03 Alerta Vulnerabilidades

CVE-2026-7849 Publicación: 30/07/2026

Due to improper neutralization of special elements, an unauthenticated remote attacker is able to inject a command into the system configuration which is subsequently executed as root....

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-44108 Publicación: 30/07/2026

Due to a flaw in the execution order of scripts during shutdown, the firewall is terminated prematurely during system shutdown. This creates a temporary window in which internal services may become externally accessible,...

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-44104 Publicación: 30/07/2026

The firmware update process for the basemodule of the charging controller only validates the CRC32 checksum without cryptographic signature verification. This allows an unauthenticated remote attacker to install a modifi...

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-44101 Publicación: 30/07/2026

Due to missing authentication the CHARX OCPP Agent service allows an unauthenticated remote attacker to reconfigure the backend connection. This can lead to Denial-of-Service and confidential data being disclosed to the ...

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-44100 Publicación: 30/07/2026

The CHARX JupiCore service allows an unauthenticated remote attacker to reconfigure charging points. This can lead to disclosure of charging point UIDs, Denial-of-Service and files tampering....

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-44092 Publicación: 30/07/2026

An unauthenticated remote attacker can inject malicious input into the ModbusServer application because it does not validate the input it fetches from MQTT. This may lead to integrity and availability loss....

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-44091 Publicación: 30/07/2026

An unauthenticated remote attacker can post a malicious ID to the MQTT Broker results in the creation of a new configuration entry in the system configuration. This may lead to integrity and availability loss....

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-44090 Publicación: 30/07/2026

Due to missing authentication, an unauthenticated remote attacker may access the MQTT broker, which is only protected from external access by a firewall. This may lead to the device being fully compromised....

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-16610 Publicación: 30/07/2026

The Admin and Site Enhancements (ASE) Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.9.0 via the recursive_html function. This is due to the frontend save handler ...

OBJETIVO: SISTEMAS DISTRIBUIDOS
CVE-2026-48449 Publicación: 30/07/2026

Adobe Campaign Classic (ACC) is affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue does not require user inte...

OBJETIVO: SISTEMAS DISTRIBUIDOS