CyberMadrid's second SME Cybersecurity Congress: AI, suppliers and the human factor
Hard2bit was a Silver sponsor at CyberMadrid's SME congress. The themes we took to the panel on the human factor and suppliers, and what SMEs can apply now.
Blog de Hard2bit sobre ciberseguridad, cumplimiento normativo (DORA, NIS2, ENS, ISO 27001) y operación técnica.
Filtrar por categoría
Hard2bit was a Silver sponsor at CyberMadrid's SME congress. The themes we took to the panel on the human factor and suppliers, and what SMEs can apply now.
Hard2bit participó como patrocinador Silver en el congreso de CyberMadrid. Los temas que llevamos a la mesa sobre factor humano y proveedores, y qué aplicar ya.
On 29 September we will have a stand at Digitaliza Madrid and Thilina Manana joins the panel on the human factor and the supply chain.
El 29 de septiembre estaremos con stand en Digitaliza Madrid y Thilina Manana participará en la mesa redonda sobre factor humano y cadena de suministro.
Un fallo en Compartir pantalla de macOS concede acceso de root a quien alcance el puerto 5900. Hay explotación activa con mineros de Monero y el endurecimiento habitual no protege.
A macOS Screen Sharing flaw hands root to anyone who can reach port 5900. Exploitation is active with Monero miners, and the usual hardening offers no protection.
Lazarus combinó ofertas de empleo falsas, la carga lateral de una DLL en un visor de PDF y el zero-day CVE-2026-68820 en afd.sys para plantar el rootkit FudModule en defensa europea.
Lazarus paired fake job offers and DLL side-loading in a PDF viewer with zero-day CVE-2026-68820 in afd.sys to plant the FudModule rootkit inside European defence firms.
El 2 de agosto de 2026 se aplica el artículo 50 del Reglamento de IA. No va solo de grandes tecnológicas: si operas un chatbot o publicas contenido generado con IA, la transparencia también te obliga.
On 2 August 2026 Article 50 of the EU AI Act starts to apply. It is not only about big tech: if you run a chatbot or publish AI-generated content, the transparency duty is yours too.
What compliance software must actually deliver for ISO 27001, ENS, NIS2 and DORA: document control, risk, controls, evidence, audit, traceability and where AI genuinely helps.
El 18 de julio aparecieron los primeros ataques contra CVE-2026-6875, cinco días después del parche: un escape de sandbox en ServiceNow que da RCE sin autenticar. Qué vigilar y cómo contenerlo.
On 18 July the first attacks hit CVE-2026-6875, five days after the patch: a ServiceNow AI Platform sandbox escape giving unauthenticated RCE. What to watch and how to contain it.
Brussels did not pass a law. It published an execution policy linking the AI Act to NIS2, DORA and the CRA. The nine actions, the deadlines and the operating shift it demands of CISOs.
La Comisión no ha aprobado una ley, sino una política de ejecución que conecta el AI Act con NIS2, DORA y CRA. Sus nueve actuaciones, los plazos y el cambio operativo que exige a los CISO.
A flaw in the Microsoft Defender engine spawns a SYSTEM shell on fully patched Windows 10 and 11. What RoguePlanet is, how to check your engine version and how to detect and defend against it.
Un fallo en el motor de Microsoft Defender abre una consola con privilegios SYSTEM en Windows 10 y 11 al día. Qué es RoguePlanet, cómo verificar la versión del motor y cómo defenderse.
What a breach linked to the European Commission reveals about supply chain, API keys, third parties, cloud, monitoring and compliance under NIS2, DORA, ENS and ISO 27001.
A practical set of questions for evaluating a cybersecurity provider, MSSP or software product in 2026. Reduce hidden risk and buy with more judgement, operation and control.
On 23 June 2026 CISA added four UniFi OS and Lantronix EDS5000 flaws to its KEV catalogue. Chained, three of them give unauthenticated remote code execution on the box that manages your network.
CISA añadió el 23 de junio de 2026 cuatro fallos de UniFi OS y Lantronix EDS5000 a su catálogo KEV. Encadenados, dan ejecución remota sin autenticación sobre el equipo que administra la red.
Qué debe tener un software de compliance para gestionar ISO 27001, ENS, NIS2 y DORA: documentación, riesgos, controles, evidencias, auditorías, trazabilidad e IA.
Analizamos la brecha vinculada a la Comisión Europea y qué revela sobre supply chain, API keys, terceros, cloud, monitorización y cumplimiento en NIS2, DORA, ENS e ISO 27001.
Guía realista sobre cuánto cuesta un pentesting en 2026: precios orientativos, factores que cambian el presupuesto y claves para comparar proveedores con criterio técnico.
21 preguntas para evaluar un proveedor de ciberseguridad, MSSP o software en 2026. Reduce riesgo oculto y compra con más criterio, operación y control.
Hard2bit participa en ASLAN2026 como expositor y presenta Cortexwork y NormexAI, dos soluciones basadas en IA orientadas a riesgo humano, productividad ética, compliance y evidencias audit-ready.
Antes de irte…
Tenemos un 100% de éxito en implantaciones de Normativa. Si quieres, te damos un diagnóstico rápido (15 min) y te decimos qué priorizar: M365, vulnerabilidades, SOC y/o DORA/NIS2/ENS/ISO 27001.
Sin spam. Respuesta en 24h.