Padre de dos hermosas niñas | Computer Engineer | IT Leadership, Data, AI, Cybersecurity & Innovation |
Setup OpenClaw with me / Configura OpenClaw conmigo
@__spekulator__ claude-security has no save mechanisms and never performs automatic updates: it runs on demand. If the code changes after a scan, it refuses to apply patches from a stale report this would be a safeguard, not a failure.
To learn Claude Code from scratch: understand context, tools, plan mode, CLAUDE.md, commands, hooks, skills, subagents, and MCP. Always review diffs and run tests, lint, types, and builds. That’s the foundation; the rest is practice.
The Claude Security plugin for Claude Code is now available in beta.
Scan your changes for vulnerabilities before you commit, or run a full scan across your codebase, all from your terminal on the Claude inference you already run.
⚠🇨🇴 Atención Colombia: detectamos una operación de acceso inicial en curso, dirigida a la infraestructura de la @DIANColombia (Dirección de Impuestos y Aduanas Nacionales).
Una de las herramientas se denomina "DIAN ATTACK v2" y está diseñada para automatizar ataques de autenticación contra múltiples servicios institucionales:
→ VPN corporativa (FortiGate).
→ SharePoint institucional.
→ Portales internos como KactusRL y MUISCA.
→ ADFS (Active Directory Federation Services).
→ OWA (Outlook Web Access).
Al menos 148 credenciales potencialmente válidas comprometidas, tomar precauciones ASAP.
La operación incluye la explotación de brute force y credential stuffing.
Today might just be one of the biggest days of 2026 so far, here's what's on deck:
Anthropic is very likely launching Opus 5
OpenAI announcing new realtime voice + maybe, and this is just my hope, cloud agents
SpaceX is launching Starship 13
And there's another surprise coming out today, that I don't think I'm supposed to know about, so I'm going to keep that one to myself 🤫
But I would say, expect four pretty big deal things to happen today, very excited!
Este comerciante ofrece 10 millones de pesos y su Jeep, al Uribestia q le demuestre con pruebas y evidencias, q el doctor @IvanCepedaCast fue guerrillero.
¡FALSO! Como autora de proyecto de ley ANTIFRACKING, voy a desmentir cada una de las barbaridades dichas en este nefasto video:
1. El fracking sostenible no existe. Es falso. Están documentados todos sus daños. No hay versión limpia ni controlada de esta práctica.
2. Colombia es el segundo país más biodiverso del mundo. Hacer fracking aquí significaría asesinar millones de animales. Un dato que usted parece desconocer o ignorar convenientemente.
3. Hablan de control del metano como si fuera posible. Entre el 3,6% y el 7,2% del gas metano producido por el fracking se escapa a la atmósfera por fugas en los pozos. El metano tiene un potencial contaminante 86 veces mayor que el dióxido de carbono. Su impacto en el calentamiento global es devastador.
4. Los territorios donde harían fracking incluyen el Magdalena Medio, una región que alberga ecosistemas únicos y especies emblemáticas como el jaguar y el manatí. Del bosque original solo queda el 15%. Y quieren destruir lo que queda.
¿A eso le llaman fracking sostenible? Una práctica que se traduce en deforestación, contaminación de acuíferos, desplazamiento de comunidades y especies, uso desmedido del agua y contribución directa al cambio climático. Sin contar la violencia que desatará la codicia por el dinero del petróleo.
Y para terminar: cuéntenle al país por qué esconden a Abelardo y lo mandan a usted a dar las entrevistas. Ya se dio cuenta de que todo lo que dice ese engañabobos es puro populismo sin sustento.
🔴 La movilización, convocada por la Confederación de Estudiantes de Chile, es la primera protesta masiva desde que Kast asumió como presidente y tiene como una de sus consignas que “la educación pública se defiende”
����️ @Maoliscastro
https://t.co/WlrCLkLyod
. ¡Hoy retumban como nunca las palabras del inmortal Jaime Garzón!
Somos el pueblo, los únicos que podemos salvar y seguir por el rumbo progresista.
O nos hundimos en el retroceso con salvadores de la patria de papel
🚨 CYBER INTELLIGENCE ALERT: POTENTIAL CRITICAL DATA BREACH - NATIONAL ELECTORAL COUNCIL (CNE) OF 🇨🇴 COLOMBIA
⚠️ STATUS: UNDER INVESTIGATION; LIMITED REPORT, SAMPLES VIEWED
A cyber incursion against the National Electoral Council (CNE) of Colombia has been identified, perpetrated by the actor identified as Hydr0gen, under the banner of the EsqueleSquad collective.
📋 INCIDENT SUMMARY
Access Vector: The actors claim to have gained direct access to the CNE's servers, extracting classified material that compromises the institution's confidentiality.
Scope of Exfiltrated Information: The group claims to possess:
Confidential internal documents, including audit reports and formal complaints regarding irregularities in the electoral process.
Sensitive correspondence between CNE officials and campaign teams.
Financial records from the 2026 campaigns, including donor lists, money transfers, and significant financial discrepancies.
Evidence: The group has shared screenshots showing CNE administrative management interfaces and detailed campaign income and expenditure forms, along with an external link to verify the data's legitimacy.
🛡️ SECURITY RECOMMENDATIONS
Given the seriousness of this breach, the competent authorities and the public are urged to consider the following measures:
Immediate Containment: The CNE must conduct an urgent forensic audit to close the access vector, revoke compromised access, and secure the affected endpoints.
Information Verification: Electoral entities and oversight bodies must issue official statements to verify or refute the authenticity of the leaked documents and prevent the spread of misinformation.
⚡Strategic Monitoring Tools
Intelligence Platform: https://t.co/wk9bZJ2Nli
Security Verification: https://t.co/5LuqwzYuS6
#CyberSecurity #DataBreach #Colombia #CNE #ThreatIntelligence #EsqueleSquad #IncidentResponse #Infosec #CiberSeguridad
🚨🇨🇴 CNE (National Electoral Council) allegedly targeted by EsqueleSquad
A threat actor on an underground forum, attributing the leak to a group called EsqueleSquad, is claiming to have obtained confidential material directly from the CNE (Consejo Nacional Electoral), Colombia's National Electoral Council, and related sources. The actor timed the post to coincide with Colombia's elections.
The actor claims to hold internal confidential documents and campaign financing records.
𝗪𝗵𝗮𝘁'𝘀 𝗮𝗹𝗹𝗲𝗴𝗲𝗱𝗹𝘆 𝗲𝘅𝗽𝗼𝘀𝗲𝗱:
• CNE internal confidential documents (internal reports, audit findings, formal complaints about electoral irregularities)
• Sensitive correspondence between CNE officials and campaign teams
• Documents showing weaknesses and anomalies in the voter registry and polling stations
• 2026 campaign financing records (declared and hidden donor lists)
• Alleged dark money movements and suspicious transfers
• Ghost companies and large contracts awarded to campaign donors
• Discrepancies between official reports and actual financial movements
𝗗𝗲𝘁𝗮𝗶𝗹𝘀:
𝗧𝗮𝗿𝗴𝗲𝘁: CNE (Consejo Nacional Electoral)
𝗖𝗼𝘂𝗻𝘁𝗿𝘆: Colombia 🇨🇴
𝗦𝗲𝗰𝘁𝗼𝗿: Government / Elections
𝗔𝗰𝘁𝗼𝗿: Hydr0gen (EsqueleSquad)
𝗖𝗹𝗮𝗶𝗺: Confidential electoral documents and campaign financing records
𝗘𝘅𝗽𝗼𝘀𝘂𝗿𝗲: Internal documents and financial records
𝗣𝗿𝗶𝗰𝗲: Free
𝗢𝗯𝘀𝗲𝗿𝘃𝗲𝗱: May 30, 2026
💥 Stop guessing what's redacted. Paid subscribers see everything: https://t.co/281Qjc6p2J
🚨 STRATEGIC CYBERINTELLIGENCE ALERT: ANATOMY OF THE CaaS PLATFORM IN COLOMBIA 🇨🇴
⚠️ TECHNICAL BREAKDOWN OF THE CRIMINAL INTELLIGENCE BOT AND THE EROSION OF DATA PRIVACY
[STATUS: ACTIVE TOOL / CRIME-AS-A-SERVICE MODEL / EXTREME RISK OF FINANCIAL FRAUD AND EXTORTION]
The cybercrime ecosystem targeting Colombia has evolved toward industrialization. The detected tool is not merely a leaked database, but a sophisticated Crime-as-a-Service (CaaS) engine operated via Telegram (attributed in recent investigations to the threat actor ɪʀᴏɴ ᴀᴛʟᴀꜱ). This platform enables any criminal—regardless of their technical proficiency—to perform real-time queries (utilizing both OSINT and private databases) to comprehensively profile any Colombian citizen, thereby facilitating attacks.
🧠 TECHNICAL ANATOMY OF THE PLATFORM
The success of this bot lies in its distributed client-server architecture and its ability to unify disparate data sources into a single, user-friendly interface.
1. Operator Interface (Frontend - Telegram)
Anonymity and Accessibility: By being hosted on Telegram, the bot inherits the application's privacy infrastructure, making it difficult to trace the IP address of the operator (the criminal client) as well as that of the central server.
Query Modules: The interface offers an interactive menu featuring predefined commands. The criminal simply needs to input an initial data point—such as a national ID number, a phone number, or an email address—to trigger a massive, cascading search.
2. Correlation Engine and Backend (The Core)
Microservices Architecture: Behind the Telegram bot lies a backend server (likely hosted in "bulletproof" jurisdictions) that receives the request and simultaneously distributes it to multiple extraction scripts (scrapers) and APIs. Data Enrichment: If a cybercriminal enters a phone number, the engine queries telecommunications providers to obtain the name of the account holder. It then takes that name and queries the National Registry Office to retrieve the corresponding National ID number. Using the National ID, it queries the DIAN (Tax Authority), the Traffic Registry (RUNT), and credit bureaus.
Structured Output: The engine compiles all this information into a clean, structured report (a "Dossier") that is delivered to the client within seconds.
🗄️ DATA SOURCE ECOSYSTEM (DATA PIPELINE)
To achieve this level of detail, the platform has successfully channeled—through the theft of API credentials, the exploitation of web vulnerabilities, or the purchase of access from insiders—three major information verticals:
🏛️ Government and Public Infrastructure:
Identity and Demographics: National Civil Registry (validation of biometric data and National IDs) and Migration Colombia.
Taxes and Property: DIAN (Tax Registry/RUT, business activity), IGAC (Cadastre/real estate records), and RUNT (vehicle ownership, mandatory insurance/SOAT, traffic fines).
Security and Defense: National Police, Inspector General's Office, and Military Forces (criminal records, disciplinary records, and military service status).
🏢 Private Sector and Telecommunications:
Operators (Telcos): Claro, Tigo, Movistar, and WOM. This enables the association of identities with mobile numbers—a capability fundamental to SIM hijacking (line hijacking) attacks.
Comprehensive Healthcare: ADRES, EPS (Health Service Providers), and Insurance Companies (Sura, Seguros Bolívar).
🏴☠️ Underground Sources (Dark Web):
Integration with historical data breaches and records derived from "Infostealers" (malware designed to steal passwords and browser cookies from infected systems).
💸 IMPACT ON FINANCIAL INVESTIGATIONS AND CRIMINAL TTPs
The integration of queries directed at credit bureaus (Datacrédito, TransUnion) and banking institutions transforms this bot into a lethal weapon against the financial sector. Attackers leverage this infrastructure to execute the following Tactics, Techniques, and Procedures (TTPs):
SIM Swapping Fraud: Armed with Telco data and the victim's full identity, the scammer impersonates the victim—either in person at a retail branch or over the phone—to port the phone number to a new SIM card, thereby intercepting one-time passwords (OTPs) sent via SMS by banks.
Highly Personalized Extortion: Criminals select victims based on their tax filings (DIAN) or vehicle ownership records (RUNT). These extortion calls feature specific details regarding the victim's vehicles, immediate family members, and home address, thereby drastically increasing the likelihood of payment through intimidation.
#CyberSecurity #Colombia #CrimeAsAService #OSINT #DataBreach #FinancialFraud #ThreatIntelligence #CiberAlerta #VECERT #Infosec #SIMSwapping
Hoy hubo otro ataque digital gravísimo. Con supuesta exposición de contraseñas de administradores del @HospitalUNAL. Si esto fue verdad es re grave. El lunes o martes miraremos en @MuchoHacker
‼️🚨 BREAKING: An AI found a Linux kernel zero-day that roots every distribution since 2017. The exploit fits in 732 bytes of Python. Patch your kernel ASAP.
The vulnerability is CVE-2026-31431, nicknamed "Copy Fail," disclosed today by Theori. It has been sitting quietly in the Linux kernel for nine years.
Most Linux privilege-escalation bugs are picky. They need a precise timing window (a "race"), or specific kernel addresses leaked from somewhere, or careful tuning per distribution. Copy Fail needs none of that. It is a straight-line logic mistake that works on the first try, every time, on every mainstream Linux box.
The attacker just needs a normal user account on the machine. From there, the script asks the kernel to do some encryption work, abuses how that work is wired up, and ends up writing 4 bytes into a memory area called the "page cache" (Linux's high-speed copy of files in RAM). Those 4 bytes can be aimed at any program the system trusts, like /usr/bin/su, the shortcut to becoming root.
Result: the next time anyone runs that program, it lets the attacker in as root.
What should worry most: the corruption never touches the file on disk. It only exists in Linux's in-memory copy of that file. If you imaged the hard drive afterwards, the on-disk file would match the official package hash exactly. Reboot the machine, or just put it under memory pressure (any normal system load that needs the RAM), and the cached copy reloads fresh from disk.
Containers do not help either. The page cache is shared across the whole host, so a process inside a container can use this bug to compromise the underlying server and reach into other tenants.
The original sin was a 2017 "in-place optimization" in a kernel crypto module called algif_aead. It was meant to make encryption slightly faster. The change broke a critical safety assumption, and nobody noticed for nine years. That bug then rode every kernel update from 2017 to today.
This vulnerability affects the following:
🔴 Shared servers (dev boxes, jump hosts, build servers): any user becomes root
🔴 Kubernetes and container clusters: one compromised pod escapes to the host
🔴 CI runners (GitHub Actions, GitLab, Jenkins): a malicious pull request becomes root on the runner
🔴 Cloud platforms running user code (notebooks, agent sandboxes, serverless functions): a tenant becomes host root
Timeline:
🔴 March 23, 2026: reported to the Linux kernel security team
🔴 April 1: patch committed to mainline (commit a664bf3d603d)
🔴 April 22: CVE assigned
🔴 April 29: public disclosure
Mitigation: update your kernel to a build that includes mainline commit a664bf3d603d. If you cannot patch immediately, turn off the vulnerable module:
echo "install algif_aead /bin/false" > /etc/modprobe.d/disable-algif.conf
rmmod algif_aead 2>/dev/null || true
For environments that run untrusted code (containers, sandboxes, CI runners), block access to the kernel's AF_ALG crypto interface entirely, even after patching. Almost nothing legitimate needs it, and blocking it shuts the door on this whole class of bug...
🚨 FINANCIAL SECURITY ALERT: MASSIVE DATA LEAK AFFECTING BANCO FALABELLA AND CONALCRÉDITOS – COLOMBIA 🇨🇴💳
A data leak of critical proportions has been detected, affecting the collections unit of Banco Falabella in Colombia—an operation managed by the third-party vendor CONALCRÉDITOS EMERGIACC (Iserra Bogotá and Medellín branches). The threat group NyxarGroup has released a first tranche of the data, claiming that the banking institution had initially denied the existence of the breach.
🏢 Affected Entities: Banco Falabella Colombia / Conalcréditos Emergiacc.
👤 Threat Actors: NyxarGroup.
📂 Leak Volume (Part 1): 7,055,610 customer records.
📅 Publication Date: April 25, 2026.
⚠️ Status: The data includes records updated through March 2026.
📊 Scope of the Breach (Exposed Data)
This data leak is extremely sensitive, as it exposes not only the identities but also the detailed financial and personal situations of over 7 million citizens:
Full Identity: First and last names, national ID numbers (*Cédula*).
Contact Information: Mobile phone numbers and WhatsApp chat logs.
Critical Financial Details: Obligation numbers (loan/credit IDs), outstanding debt amounts, days past due, billing cycles, and payment commitments.
⚠️ Risk Implications (VECERT Intelligence)
Identity Theft and Fraud: Armed with ID numbers and phone numbers, attackers can perpetrate financial fraud or open fraudulent accounts.
Social Engineering and Extortion: Information regarding exact debt amounts and private "internal notes" enables criminals to make fraudulent debt collection calls or engage in extortion schemes that exploit the victim's financial vulnerability. 🛡️ Immediate Response Recommendations
🔒 Total Distrust: Banco Falabella customers are strongly urged not to make payments via links received via WhatsApp or through unverified phone calls, as criminals now possess the exact details regarding their outstanding debts.
🔑 Credential Update: Proactively change passwords for both the mobile app and online banking services.
Intelligence Monitor: https://t.co/wk9bZJ2Nli
🛡️ "The exposure of 7 million debt collection records is not merely a technical glitch; it constitutes a violation of the dignity and financial privacy of millions of Colombians. VECERT is issuing this Red-Level Alert."
#CyberSecurity #Colombia #BancoFalabella #Conalcreditos #DataBreach #HabeasData #NyxarGroup #VECERT #InfoSec #CyberCrime 🇨🇴🛡️⚠️
Colombia avanza hacia una IA más segura y responsable! 🇨🇴🤖
El @Ministerio_TIC ya tiene disponibles para consulta los Lineamientos de Seguridad y Privacidad de la Información para Sistemas de IA, un marco clave para fortalecer la confianza digital, la protección de datos y la seguridad en el uso de estas tecnologías. 🛡️🔒
Encuentra este documento y sus recursos relacionados en:
🔗 https://t.co/sO1HyHGYKo