¡Mi Curso completo de Docker desde cero!
✓ Contenedores e imágenes
✓ Dockerización de proyectos
✓ Docker Hub
✓ Modelos de IA en local
✓ Despliegue a producción
→ https://t.co/OHzAxAaCKT
Ataque MikroTrick da control total de routers MikroTik sin inicio de sesión
Los propietarios de routers MikroTik se enfrentan a un problema de seguridad grave debido a una cadena de ataques denominada MikroTrick.
Vulnerabilidad control total sin necesidad de contraseña, aprovechando dispositivos RouterOS expuestos a través de SSH
https://t.co/aFHBnP1jDk
Nueva vulnerabilidad Zero-Day en CISCO ISE permite eludir la autenticación y está siendo explotada en ataques activos (CVE-2026-76460)
https://t.co/8aNSZIbj9k
Microsoft reúne una excelente serie sobre #ActiveDirectory Hardening, con temas fundamentales para reducir la superficie de ataque:
✅ Deshabilitar NTLMv1
✅ Eliminar SMBv1
✅ Forzar LDAP Signing
✅ Implementar AES para Kerberos
✅ Configurar LDAP Channel Binding
✅ Forzar SMB Signing
✅ Aplicar Least Privilege
✅ Reducir y eliminar el uso de NTLM
⚠️ Hardening no significa aplicar una GPO y esperar lo mejor. Requiere inventario, auditoría, pruebas y validación de dependencias.
Una lectura imprescindible para cualquier administrador de Active Directory. 👇
https://t.co/1vpiTDL5Bu
Microsoft are limiting access for the User.ReadBasic.All Graph API permission. But, their recommendations aren't great. Here is the full post: https://t.co/v3IRyivxCu
It's seems that Microsoft are recommending you have to fall back on the https://t.co/zhfHznDIm9.All permission to access app role assignments and licensing data. For app role assignments, the recommended permissions in the official documentation don't align. Then, for licensing, Microsoft seem to have ignored the cloud licensing APIs which support the https://t.co/JOMcsIn031.All permission.
#Entra #Microsoft #News
Microsoft FINALLY adds support for Device Sync in Entra Cloud Sync!
For many organizations, the lack of device synchronization has been the last major blocker preventing a full migration from Microsoft Entra Connect Sync to Cloud Sync. With device sync now available, that migration is finally within reach.
Device sync lets you synchronize computer objects from Active Directory (AD) to Microsoft Entra ID by using the 𝗔𝗗𝟮𝗔𝗔𝗗𝗗𝗲𝘃𝗶𝗰𝗲𝗦𝘆𝗻𝗰 job in an AD to Microsoft Entra ID Cloud Sync configuration. After synchronization, the devices can become Microsoft Entra hybrid joined.
Note that device sync is disabled by default.
𝗣𝗿𝗲𝗿𝗲𝗾𝘂𝗶𝘀𝗶𝘁𝗲𝘀:
• Install the Microsoft Entra provisioning agent in your on-premises environment. The agent must be version 1.1.1107 or later. Download the latest available agent version from the Microsoft Entra admin center.
• Create an AD to Microsoft Entra ID Cloud Sync configuration.
• Your Microsoft Entra tenant ID and the verified domain that devices use for authentication. For federated environments, use a federated domain. Otherwise, use the primary *.onmicrosoft.com domain.
• If you need to configure the SCP, temporary access to an account that's a member of the Enterprise Admins group in each AD forest that contains domain-joined computers. Use your organization's just-in-time privileged access process, if available.
• To configure device sync in the Microsoft Entra admin center, use an account with at least the Hybrid Identity Administrator role.
Learn more:
https://t.co/V1mCpH4zHR
#Microsoft365 #EntraID #EntraConnect
AI Security Guide and Risk Assessment Tool - https://t.co/uzFJRvTnoK by RAND
This guide is a practical, risk-based resource for developers, security experts, and policy professionals navigating the AI security landscape.1 The guide addresses security of AI systems broadly, including machine learning (ML) models and other AI-enabled architectures. Certain sections, such as the threat landscape and model weight protection sections, focus more specifically on statistical, ML-based models. Building on industry best practices and expert insights, the guide helps you understand and manage the security risks associated with AI systems across their lifecycle—from design and development to deployment and operation.
𝗛𝗮𝗿𝗱𝗲𝗻 𝘆𝗼𝘂𝗿 𝗚𝗶𝘁𝗛𝘂𝗯! 🛠️🛡️
This CIS benchmark is a gold mine for DevSecOps and AppSec teams looking to implement a "Shift Left" security strategy using proven industry standards.
https://t.co/YvnReg4He6
#DevSecOps#AppSec
🔴Argentina ya pagó US$15.611 millones en intereses al FMI desde 2018 y sigue siendo el mayor deudor global: con un stock de deuda de US$57.230 millones, concentra el 35% de la cartera del organismo
Hasta 2030 el país deberá abonar otros US$12.700 millones solo en intereses
📊Ranking de pagos de intereses al FMI, por presidente
🔹Mauricio Macri: hasta diciembre de 2019, se pagaron US$1.491 millones.
🔹Alberto Fernández: durante sus 4 años, los pagos se dispararon a US$7.402 millones.
🔹Javier Milei: en 2024 pagó US$3.098 millones, el mayor desembolso anual de la serie histórica. En 2025, el total abonado fue de US$2.782 millones, sumando hasta ahora US$5.880 millones.
Welcome the new year by using managed identities in #Azure API Management!
✨ Eliminate secrets - Let Entra ID handle authentication
🔐 Securely access Key Vault and other resources
⚙️ Choose between system‑assigned or user‑assigned identities
Start here 👉
#APIM#Security
#Independiente Gustavo Quinteros en IdeA: "Siempre confío en sacarle lo mejor al jugador. Confío en que con este plantel, podemos ser competitivos en el fútbol argentino.
Si podemos sumar alguien, bienvenido, sino luchar al máximo con este plantel"
FRÁVEGA se suma al BLACK FRIDAY con promos que se pueden combinar 🔥🔥🔥
Hasta 50% DE DESCUENTO, HASTA 12 CUOTAS SIN INTERES y entrega en 24hs o retiro gratis en sucursal 🙌
+ CUPON EXCLUSIVO: LEAN20
De 20% OFF sin tope de reintegro!!!
Tiene vigencia hasta el sábado 23:59 APÚRENSE A USARLO 😱
+ hasta 20% de descuento pagando con bancos seleccionados + MODO, con tope de $20.000
Les dejo el link:
https://t.co/N8LCmiDjuA