Digital Services, Data Centers & Tech Providers, Sep 2026
September ended with hosting outages, SaaS incidents, and active exploitation of critical CVEs, with regional focus on Argentina, Colombia
Key findings
- DonWeb concentrated the month’s most severe operational outage in regional hosting and cloud, with backups and migration affected during the interruption.
- ICETEX and Aeroméxico showed the critical dependence on external vendors and the need for forensic and contractual governance over third parties.
- Brevo confirmed a supply chain path via the Cloudflare API, with direct lessons for SaaS platforms that use credentials and edge workers.
- Brazil dominated critical vulnerability alerts, with particular weight on Cisco FMC, Citrix, Fortinet, Exchange, Proxmox, Adobe Commerce, Magento, and CKAN.
- The TeamFiltration campaign and Storm-3168 activity confirm that abuse of cloud identities remains a high-impact regional vector.
- September did not record ransomware as the primary typified axis, but it did show silent intrusion, data exposure, and availability failures with downstream impact.
- The month’s risk reading is medium, due to lower volume than August but technically relevant severity in service providers and identity platforms.
Monthly reference modules
These modules are filled automatically with verified, dated facts within the period. Each one states its source base and counting criterion, so the figures reconcile across modules. They are the recurring month-to-month reading; the analysis that follows expands on the cases without repeating this summary.
Indicator window: 52 dated facts in September 2026. Facts from earlier months are used only as comparative context in the analysis, never as volume for this period.
Executive Summary
The period was dominated by availability incidents and by the exposure of external dependencies in digital services, with a common pattern, the disruption did not necessarily originate in the core of the affected organizations, but in infrastructure nodes, vendors, or third-party components that sustain day-to-day operations. That pattern is especially visible at DonWeb, where a problem in the NOVA node took cloud servers and related services offline. It also appears in ICETEX, which attributed the impact to an external provider, and in Aeroméxico, which linked the data leak to a customer management platform run by a third party. Taken together, this month’s material reinforces a familiar but often underestimated operational conclusion, in SaaS, hosting, and data center environments, continuity no longer depends only on hardening in-house servers, but on precisely governing identities, recovery paths, service contracts, and controls across the provider ecosystem.
Another key trend was the exposure of critical vulnerabilities with potential active exploitation in products widely used by companies and governments. Alerts from CTIR Gov of Brazil and CISC show that the region continues to receive indirect impact from global vulnerability chains in Cisco, Citrix, Fortinet, Adobe Commerce, Magento, Microsoft Exchange, Proxmox, and CKAN DataStore. At the same time, Cisco Talos confirmed active exploitation of CVE-2026-20079, and Beazley described a chain involving CVE-2026-20316 against Cisco Secure Firewall Management Center consoles. Although the material available for this report does not allow us to confirm campaigns with verified Latin American victims in all of those cases, it does show that the regional attack surface remains exposed and that several of those flaws were already included in known-exploitation catalogs.
The month also showed that compromised identities and exposed keys continue to work as master keys for access and destruction. Storm-3168, documented by Microsoft Security Research and Check Point Research, used compromised service principals to carry out destructive actions in Azure and collect cloud credentials. Separately, the campaign attributed to TeamFiltration affected more than 5,700 Microsoft 365 accounts across 28 tenants in Latin America, with a particular focus on organizations in Chile. In both cases, the central issue is not just the initial intrusion, but the fact that poorly governed service identities can become vectors for reconnaissance, lateral movement, destruction, or silent persistence.
On the supply chain and SaaS front, the Brevo/Cloudflare case again put the risk of long-lived credentials embedded in code into focus. Brevo confirmed the use of a compromised API key to deploy a Cloudflare Worker, while F5 Labs detailed how attackers modified content at the CDN edge, removed CSP headers, and injected ClickFix scripts into Brevo domains and integrated customer assets. The figure of up to 100,000 sites cited by external sources should be treated as potential scope, not confirmed impact. From a defensive standpoint, the case illustrates a classic failure, a single credential with broad permissions, without effective alerts, can turn a peripheral component into a risk multiplier for thousands of third parties.
From a CISO perspective, the thread running through the period is clear. First, review the external dependency architecture, with a real inventory of nodes, vendors, service accounts, and recovery mechanisms. Second, prioritize identity and secrets controls over purely perimeter-based controls. Third, treat operational continuity as an interorganizational discipline, in digital services, resilience often breaks at the point where storage, orchestration, authentication, and vendor support meet. Fourth, turn vulnerability management into a remediation practice driven by real exposure, not only theoretical severity. The month showed that the combination of a poorly protected credential, an exposed console, or a compromised vendor can degrade operations far more effectively than noisy low-impact campaigns.
Overview
The period can be read as a convergence of three forces. The first is the operational fragility of digital services infrastructure when a single node or an external dependency becomes the point of failure. The second is the continued pressure on cloud identities, service accounts, and shared credentials. The third is the region’s growing institutional response maturity, visible in bulletins and alerts from Brazilian agencies and in protocol activations by affected entities and companies. The result is a month defined less by mass malware and more by precise outages, credential abuse, and attacks on administrative interfaces.
In that context, DonWeb’s availability incidents were the most visible because of their immediate operational impact on customers who could not invoice, run e-commerce operations, access databases, or keep websites online. The fact that other products remained operational while the NOVA node and Cloud and IaaS services were listed as major outages suggests a focused failure in one piece of the platform, but one critical enough to block essential functions for hundreds or thousands of users. The later confirmation that no data was lost and that the node returned to operation offers a useful lesson for the sector: restoring service does not erase the operating costs accumulated during hours or days of downtime.
In Colombia, the ICETEX case showed a service crisis with both a security component and an institutional response. The agency reported disruption in some services and operational processes because of an incident at an external provider, began containment and forensic analysis, and received support from ColCERT, the Superintendence of Industry and Commerce, and other competent authorities. Public debate moved between hacking theories, concerns about data exposure, and the need not to overstate what had not been verified. That distinction matters: in information security, prudence does not mean minimizing the incident, but separating what is confirmed from what is likely while technical verification is still underway.
Mexico closed the month with the Aeroméxico case, where the authority and the airline responded to a possible exposure of a database linked to customers. Coverage indicates that the information appeared on Telegram and that the authority opened an ex officio investigation to determine its origin, authenticity, and scope. Aeroméxico, for its part, said the unauthorized access occurred on a platform managed by a third-party provider and that the allegedly exposed data did not include financial information, bank accounts, payment cards, passwords, or flight itineraries. Beyond the limits of the affected data, the case shows the pressure that incidents involving providers and data markets can place on reputation, legal handling, and crisis communications.
Brazil contributed the period’s most consistent technical intelligence and preventive defense component. CTIR Gov published alerts on Cisco, Citrix, SonicWall, Fortinet, Adobe Commerce, Magento, Microsoft Exchange, and Proxmox; CISC issued bulletins on campaigns targeting .gov.br domains and SQL injection vulnerabilities in CKAN DataStore. In practical terms, this shows that Brazilian security teams are regularly monitoring and reporting flaws that can affect both government environments and service operators. At the regional level, those alerts are valuable because they anticipate exposure in technologies widely used in hosting, virtualization, e-commerce, and perimeter security management.
Finally, Microsoft and Check Point activity around Storm-3168 and TeamFiltration confirms that identities remain the gravitational center of the conflict. This is not only about stealing a username and password, but about abusing trust relationships between systems, tenants, cloud applications, and providers. When a service principal or a service account with excessive privileges is compromised, the attacker may not need to break through more defenses. They can use exactly the mechanisms the company designed to automate operations and recovery. That is a key lesson from the period for organizations operating SaaS, IaaS, and distributed digital platforms.
Indicators
The period indicators should be read with strict methodological precision. They reflect only what appeared in the material analyzed for this report and should not be confused with the full regional risk picture. If an indicator shows zero, that means there was not enough evidence in the reviewed corpus to support that line of analysis this month. It does not mean the phenomenon does not exist in the region or that the risk has disappeared. That distinction is especially important for exploited vulnerabilities, where the absence of confirmed cases in the source material does not equal the absence of real-world exploitation.
The month was marked by availability incidents, security incidents at providers, cloud identity abuse campaigns, and multiple critical vulnerability alerts. In digital services, the clearest evidence involved DonWeb, ICETEX, and Aeroméxico, with varying levels of confirmation about scope, cause, and type of exposure. On the vulnerability front, alerts from Brazil and analyses from Cisco, Beazley, Microsoft, and F5 show that the regional ecosystem continues to rely on technologies where delayed patching can have an immediate operational impact.
A central point for interpreting the indicators is that sectors are not exclusive. The same event can affect digital services, education, transportation, cloud, hosting, and public administration at the same time. For that reason, any sector tally should be understood as overlapping impact surfaces, not as a count of mutually exclusive incidents. In other words, trend analysis should be done by technical vector and by the role of the affected dependency, not by the temptation to add up headlines.
The period’s data also serve as a reminder that scan telemetry, blocked attempts, or automated activity should not be confused with confirmed intrusion. When the report cites technical findings from vendors or official bulletins, it does so because they describe relevant activity or confirmed flaws, not because they represent the full universe of compromises for the month. In operational terms, that means security teams must combine vulnerability intelligence, exposure monitoring, and external dependency review so that a simple catalog alert does not turn into a real outage.
Incidents
DonWeb: NOVA node outage and gradual restoration
DonWeb was the period’s most notable digital service outage. Confirmed information shows that the NOVA node and Cloud and IaaS services appeared as a major interruption in the public status dashboard, while dedicated servers, email, and shared hosting remained operational. That pattern points to a disruption concentrated in one layer of the infrastructure, but serious enough to push hundreds of customers into a functional outage: no invoicing, no e-commerce operations, no database access, and no websites staying online.
The company said the incident began with a logical failure inside the storage infrastructure of the NOVA node. That detail matters because it shifts attention away from a possible isolated hardware problem and toward a storage logic failure, with implications for resilience, orchestration, and recovery. During the incident, the company said backups could not be accessed and affected services could not be migrated to other nodes, which worsened the operational picture. When neither backup copies nor movement to alternative infrastructure are available, dependence on the compromised node becomes a systemic block.
The timeline was just as important. First came reports of a downed server with hundreds of customers affected. Then the company confirmed the failure hit 100% of the servers and cloud servers hosted on the Nova node. Later, DonWeb said about 80% of the servers were already back up and expected the issue to be fully resolved on Thursday. Finally, it reported that 100% of the NOVA node was operational again and said no data loss had been recorded. That sequence shows something continuity teams often underestimate, partial restoration can ease public pressure, but full recovery usually depends on additional checks, component synchronization, and integrity validation.
From the customer side, the damage is not limited to the hours of downtime. An e-commerce business that cannot bill during a major interruption can lose orders, weaken its standing with repeat users, and trigger secondary incidents with payment, ERP, or logistics integrations. The same applies to inaccessible databases and environments where downtime blocks reconciliation or updating processes. For hosting and cloud services, the relevant metric is not just uptime, but the time to restore business-useful operations.
Operationally, the case suggests several lessons. First, digital service providers need recovery paths that do not depend on the same logical domain that is failing. If backups and migration are unreachable during the incident, the recovery architecture is too tightly coupled to the primary failure. Second, customer communication must distinguish between infrastructure restoration and function restoration. Third, service segmentation by node or cluster must be matched with real capacity to isolate and move workloads without spreading the incident to other layers. In the end, the DonWeb case was not a data-loss event but a platform resilience test, and the platform showed weaknesses in cross-layer recovery.
ICETEX: security incident at an external provider and service continuity
The ICETEX case sits in a different space from DonWeb, although it shares third-party dependence as a risk factor. The agency said a security incident involving one of its external providers affected the availability of some services and operational processes. It also said the disruption originated outside systems directly managed by the agency and that neither the provider involved nor the details of the affected services were publicly identified. That mix of confirmation and restraint is typical of an ongoing investigation, where revealing too much could complicate containment or lead to attribution errors.
Media coverage showed that the agency activated containment, forensic analysis, and recovery measures with support from ColCERT, the Superintendence of Industry and Commerce, and other competent authorities. At the same time, El Heraldo reported that the active undergraduate education credit call remained open until September 30 and that credit payments at in-person channels continued while digital services were being restored. That matters because it separates two levels: on one side, the technical and security incident, and on the other, the minimum continuity needed to avoid fully halting the relationship with users.
The coverage also showed the usual tensions in this kind of event. Caracol Radio said a suspected hack could be discussed, but that it was not appropriate to claim a confirmed cyberattack while forensic analysis was still underway. Blu Radio, for its part, attributed to ICETEX the statement that personal data was not breached or exposed, although the material presents that as a claim still subject to technical verification. Beyond that caution, the operational reading is that the incident was not limited to a minor symptom. It affected visible services and triggered formal response protocols.
The analytical value of the case lies in dependency architecture. When a public or semi-public entity exposes availability to an external provider, the risk perimeter becomes shared but not necessarily visible. That complicates defense for several reasons. The process owner may not have full observability into the technical chain. Containment may depend on a third party. Reputational damage still falls on the institution that maintains the relationship with the end user. The fact that the provider was not publicly identified should not be read as an information gap, but as a sign that technical and contractual attribution was still underway.
For a CISO, the ICETEX case leaves two priority lessons. The first is contractual, provider agreements must cover not only availability, but verifiable procedures for notification, isolation, evidence preservation, and recovery. The second is crisis governance, in public services or high-volume user environments, minimum continuity through in-person or alternate channels can be decisive in containing disruption and preventing a technical incident from becoming a broader institutional problem. The main lesson, however, is that an organization does not control only its own systems. It controls, or should control, the risk it inherits from its digital supply chain.
Aeroméxico: possible data exposure and pressure on a third-party platform
Aeroméxico closed the month with an event that combines data exposure, state monitoring, and a partially bounded technical attribution. The airline said the unauthorized access happened on a customer information management platform run by an external provider and that the incident involved data stolen during an incident recorded in October 2025. The information was shared on Telegram on September 18, 2026, according to press coverage citing monitoring by the Mexican authority. The Secretariat of Anti-Corruption and Good Governance warned about the possible exposure of a database allegedly linked to Aeroméxico and opened an ex officio investigation to determine its origin, authenticity, and scope.
Available material shows that the airline activated response protocols and mitigation measures, and worked with its provider to strengthen containment actions and maintain continuous monitoring of the situation. It also says the information allegedly involved did not include financial data, bank accounts, payment cards, passwords, or flight itinerary information. The exposed data mentioned names and, in some cases, dates of birth, email addresses, and phone numbers. That distinction matters both for impact assessment and public communication, because it reduces uncertainty around the most sensitive categories that would not have been present.
Even so, the case should not be underestimated. Exposure of names and contact details can fuel phishing, identity fraud, impersonation in customer support, and abuse of support channels. In addition, the fact that the source sits on a customer management platform run by a third party reinforces a lesson already visible in other incidents this month: functional ownership of the customer experience is not the same as full technical control over the chain supporting it. If a database appears in a criminal marketplace or messaging channel, reputational damage accelerates even when the exposure does not involve credentials or financial data.
The case also illustrates an attribution problem around scope. The Secretariat of Anti-Corruption and Good Governance opened an ex officio investigation, and one source reported that the file offered on Telegram was 1.10 GB. In another part of the coverage, the allegedly linked database was said to contain more than 15 million customer records, but that figure should be treated as attributed and not definitive. The authority still had to determine whether the database came directly from Aeroméxico systems or from external provider infrastructure, and the origin had not been established. In other words, the case is still in the verification phase, not the analytical closure phase.
For corporate risk management, the value of the episode lies in coordination across three fronts, forensic, legal, and communications. When a database appears in a channel like Telegram, the challenge is not just deciding whether it is genuine, but whether it reflects current data, legacy data, or material partly recycled from earlier incidents. It also matters which provider processes were exposed and what tokenization, segmentation, or data minimization controls were active. For an airline, where customer trust depends on protecting itineraries, contact data, and loyalty programs, a partial exposure can still justify review of vendors, credentials, and information classification.
Brevo and Cloudflare: supply chain, workers, and injected scripts
The Brevo/Cloudflare case was the clearest example in the period of how a long-lived credential can become a vector for ecosystem-wide compromise. Brevo officially confirmed that an attacker used a compromised Cloudflare API key to deploy a Cloudflare Worker in the company’s account. In its postmortem, the company explained that the API key had full permissions, was hardcoded in source code, and allowed the creation of Workers, routes, and DNS records without triggering an alert. It also clarified that Brevo’s core infrastructure was not compromised, according to the available coverage.
F5 Labs said attackers used that key to deploy a malicious Worker that modified content at the CDN edge, removed Content-Security-Policy headers, and injected ClickFix scripts into Brevo domains and integrated customer assets. That mechanism is serious for several reasons. First, it changes content at the edge, where the final victim may not have direct visibility. Second, removing CSP reduces a defense layer that might have blocked some malicious payloads. Third, the injection affects not only the provider’s main domain, but also integrated customer assets that trust its infrastructure.
The timeline adds context. Brevo’s official source makes it possible to place the incident on September 14, 2026. SecurityWeek said the malicious Worker remained active for about five and a half hours and that the key was first used in late August 2026, although that last point should be treated as a claim attributed to the investigation and not as a final incident fact. That interval is a reminder that in software-as-a-service and content distribution infrastructures, a few hours are enough for an edge modification to spread across many dependent assets.
As for potential scope, several sources mentioned up to 100,000 sites that incorporated Brevo components. However, that figure should be treated as potential exposure radius or reach, not as a confirmed volume of compromised sites. The source material makes clear that no confirmed number of affected sites was published by the official source. That distinction is essential to avoid inflating impact. One thing is the possibility that multiple sites were exposed to the same infrastructure. Quite another is to claim verified infections across that entire universe.
From a defensive perspective, the Brevo case shows that SaaS integrations must be audited as part of the security plane, not treated as a simple auxiliary service. API keys with full privileges, especially if they are embedded in repositories or pipelines, create a persistent compromise path. If they also allow manipulation of DNS, Workers, or edge security policies, the attacker does not need core access to cause cross-cutting damage. For organizations consuming third-party components, the question should not be only whether they trust the provider, but what local controls they have to detect changes in scripts, headers, and third-party calls that can become infection vectors.
Storm-3168 and TeamFiltration: compromised identities and cloud abuse
Activity observed by Microsoft and Check Point during the period reinforces that modern cloud attacks often exploit trust relationships before isolated technical flaws. Microsoft Security Research published an official analysis of Storm-3168, associated with JADEPUFFER, and described extensive destructive activity in Azure through compromised service principals, along with cloud credential harvesting that could support future exfiltration. According to Microsoft, one observed intrusion used two compromised service principals from the same tenant, one performed reconnaissance, and the other carried out discovery, destructive actions, and credential collection.
Check Point Research also reported that it tracked an active TeamFiltration campaign targeting more than 5,700 Microsoft 365 accounts across 28 tenants in Latin America, particularly organizations in Chile. According to the research, seven service accounts were compromised and subsequent authentication attempts were observed in corporate VPNs and access to the Azure portal and SharePoint Online. Precision matters here, the source speaks of an active campaign and compromised accounts, but the observed later access attempts do not automatically mean full intrusion across all affected tenants. Even so, the pattern is troubling because it connects abuse of service accounts with attempts to move between identity, cloud, and remote access surfaces.
Microsoft recommended applying least privilege to workload identities, protecting secrets, enabling relevant Defender for Cloud capabilities, and restricting access to backup and recovery resources against attacks using compromised service principals. That guidance is especially relevant because Storm-3168 does more than steal data. It also destroys resources and may prepare a second stage of exfiltration. In other words, a compromised identity can serve both sabotage and persistence. In a poorly governed architecture, a service account with broad permissions over storage, databases, Key Vault, or virtual machines can cause far greater operational loss than a human account.
Check Point also added a significant regional dimension. The TeamFiltration campaign reached Latin American environments, with a particular focus on Chile. For a regional CISO, that has practical implications. First, service accounts and tenants shared with external integrations should be reviewed for anomalous activity. Second, Azure portals, SharePoint, and VPNs should not be treated as separate silos, because the attacker is precisely trying to move between them using the same identity. Third, secret rotation and deprovisioning of orphaned accounts should become operational hygiene priorities.
ICETEX, Aeroméxico, and DonWeb as a mirror of the same dependency
Although the three cases above belong to different sectors, the structural pattern is the same and deserves to be stated explicitly. DonWeb showed how a storage failure in one node can paralyze thousands of customer services. ICETEX showed how an incident at an external provider can affect service availability and trigger response with authorities. Aeroméxico showed how a customer database hosted on a third-party platform can end up under investigation and public pressure, even when there is no evidence of exposed cards or credentials. Taken together, the three cases force a move away from the idea that technology risk is contained within the organization’s perimeter.
The most useful reading for risk management is that providers are not only a source of resilience, but also a multiplier of fragility if contractual and technical observability are missing. An incident in a hosting node, a failure in a third-party platform, or a database exposed in a messaging channel can trigger operational, regulatory, and reputational impacts at the same time. Response coordination, therefore, cannot be improvised once the problem has already broken out. It has to exist beforehand, with roles, notification thresholds, evidence preservation criteria, and communication paths already defined.
Countries
Argentina
Argentina saw the month’s most visible operational outage, centered on DonWeb. The NOVA node disruption affected customers who could not bill, run e-commerce stores, access databases, or keep websites online. The later confirmation that no data loss was recorded and that the node was back online is positive, but it does not erase the continuity impact. In a market where many SMEs rely on a single platform for hosting, email, databases, and cloud services, a localized failure can quickly become a broader economic disruption.
The country also underscores a wider regional problem, the concentration of critical services in a small number of nodes or platforms. When a status panel shows a major outage for Cloud and IaaS but not for other services, enterprise customers should read that immediately as a sign their architecture depends on more than one layer. For Argentine teams using hosting and cloud services, the lesson is to review contingency strategies, exit testing, and migration plans, and avoid letting a single dependency turn a vendor outage into a full business stoppage.
Colombia
Colombia presented a classic provider-side incident with a visible institutional response. ICETEX reported an impact on some services and operational processes, activated containment and forensic analysis, and received support from ColCERT, the Superintendence of Industry and Commerce, and other competent authorities. The key point was not speculation about hacking, but confirmation that the disruption originated outside the systems directly managed by the agency. That distinction changes the expected fix, because reviewing internal servers is not enough, the third party’s contractual and technical exposure also has to be assessed.
Keeping the undergraduate education loan application process and in-person payments running while digital services were restored shows a cautious response aimed at preserving essential functions. At the same time, public debate over whether personal data had been compromised or not reflects a familiar tension, the public wants quick answers, but forensic verification takes time. For public-sector and financial operators, the case reinforces the need to classify processes by criticality and keep alternate channels ready so a digital disruption does not block an essential service.
Mexico
Mexico was where the possible exposure of Aeroméxico data and the authority’s intervention were concentrated. The Secretariat of Anti-Corruption and Good Governance opened a de oficio investigation to determine the origin, authenticity, and scope of the possible exposure, showing that monitoring data leaks is now part of the institutional agenda. The airline, for its part, linked the unauthorized access to a customer management platform run by an external provider and clarified which categories of data were not believed to be present.
The significance of this episode for the country is twofold. First, it highlights the value of state capabilities to track the circulation of databases through channels such as Telegram. Second, it puts third-party governance under the microscope in industries that are highly data- and transaction-intensive. Even without public evidence of compromised cards or passwords, exposure of names, birth dates, email addresses, and phone numbers is enough to fuel fraud and impersonation. In the Mexican context, companies must review not only data protection, but also monitoring of exchange ecosystems and leak markets.
Brazil
Brazil posted the highest density of formal technical response during the period. CTIR Gov issued alerts on Cisco Secure Firewall Management Center, Citrix NetScaler, SMA1000 Appliances, Proxmox VE, Microsoft Exchange, Fortinet, Adobe Commerce, and Magento. CISC, meanwhile, released bulletins mentioning a campaign targeting .gov.br domains and an SQL injection vulnerability in CKAN DataStore. The volume of alerts should not be read as a count of incidents, but as an exposure indicator, the country is receiving and processing high-impact vulnerabilities that affect everything from critical infrastructure to web and e-commerce platforms.
The alert on CVE-2026-20079 is especially important because Cisco Talos confirmed active exploitation and CISA added it to the KEV catalog, with a federal remediation deadline set for September 12. Although the technical coverage does not identify confirmed regional victims, the KEV inclusion and the direction of the Brazilian advisories make patching a priority for network and security operators across the region. Likewise, the alerts on Citrix, Fortinet, and Adobe Commerce/Magento show Brazil functioning as an early warning node for technologies widely used throughout Latin America.
Latin America
At the regional level, TeamFiltration’s campaign against more than 5,700 Microsoft 365 accounts across 28 tenants, with a focus on organizations in Chile, is the clearest regional data point of the period. This is not an isolated observation about a single company, but an active campaign that exploits service identities and could open the door to later access in VPN, Azure, and SharePoint. For Latin America, where many organizations rely on collaborative suites and cloud integrations with accumulated legacy privileges, the message is straightforward, service accounts must be treated as critical, auditable, and revocable assets.
The region is also feeling the impact of global incidents in widely used products. The active exploitation of Cisco Secure Firewall Management Center, the alerts on Citrix NetScaler, Fortinet, Proxmox, and Microsoft Exchange, and the Brevo/Cloudflare case show that regional risk does not always come from attackers specifically targeting Latin America. Often, the impact arrives through local adoption of global technologies that are vulnerable in other markets. The response, then, cannot depend on the attacker’s geography, but on how quickly regional operators identify their exposure and apply fixes.
Operational takeaways
The first operational lesson from this period is that resilience has to be built around real dependencies, not assumed ones. DonWeb showed that a failure in one specific node can make backups inaccessible and limit migration. ICETEX showed that a third-party provider can drag down service availability. Brevo showed that an API key can alter content at the CDN edge. In all three cases, the weakness is not only in the affected component, but in the lack of sufficiently isolated fallback paths.
The second lesson is that identity and secret management is now a strategic priority. Storm-3168 and TeamFiltration are not just access campaigns. They show how a compromised identity can enable discovery, destruction, or cross-platform access. If a service account has broad privileges over Azure, SharePoint, or VPN, the damage surface grows quickly. For CISOs, that means reducing privileges, rotating secrets, removing embedded credentials, and regularly auditing trust relationships between applications, scripts, and automation.
The third lesson is that response time remains a business variable. In DonWeb's case, partial and then full restoration took long enough to disrupt the operations of hundreds of customers. In Aeroméxico, the appearance of data on Telegram forced monitoring and communication with the authorities. In ICETEX, forensic analysis and containment began while public pressure continued. Every hour of delay means more affected users, more reputational exposure, and more recovery complexity.
The fourth lesson is that defense needs both technical observability and governance. CISC and CTIR Gov bulletins are examples of how a country can turn technical intelligence into guidance for patching and mitigation. But that information only reduces risk if internal teams have inventory, prioritization, and remediation capacity. Publishing an alert does not, by itself, fix an exposed console, a vulnerable version, or an application that keeps hard-coded keys in code.
The fifth lesson is that data incidents should be handled with minimization and traceability in mind. Aeroméxico said which data would not have been exposed, and that is useful, but the case still requires validation of the source and scope. ICETEX said its personal data was not compromised, although forensic analysis was still underway. That mix of precision and caution is the right way to communicate, confirm what is known, narrow what is unverified, and avoid claims that later have to be corrected.
CISO recommendations
First, review the third-party dependency map with an operational focus, not just a contractual one. Any organization using hosting, IaaS, SaaS, messaging platforms, CDNs, or collaboration tools should identify which functions depend on each provider, what backups exist outside its domain, and which exit or failover procedures have been tested. If a provider goes down, the business needs to know within minutes which processes stop and which can be migrated.
Second, audit service identities and API keys as critical assets. The Brevo case shows that a single embedded key can deploy code at the edge and alter traffic. Workload identities should have least privilege, regular rotation, secure storage, and monitoring for anomalous use. Secrets should never remain hardcoded in source code or be reused without a clear expiration date.
Third, strengthen console and remote administration controls. Alerts about Cisco Secure Firewall Management Center, Citrix NetScaler, Proxmox, and other management products show that control interfaces remain top targets. Exposure should be limited to trusted networks, with strong authentication, segmentation, rapid patching, and centralized logs. When the console goes down, the ability to govern the rest of the environment goes down with it.
Fourth, establish response playbooks that include vendors. In incidents such as ICETEX or Aeroméxico, the investigation depends on information from the third party and on legal and technical coordination. The playbook should define contacts, response times, evidence preservation, escalation thresholds, and preapproved messages. Without that framework, improvised coordination often delays containment and worsens the public crisis.
Fifth, validate actual recovery capability, not just the existence of backups. DonWeb showed that lacking access to backups or the ability to migrate during an incident is a bigger problem than the mere existence of copies. Organizations should test restoration, isolation, credential independence, and reconstruction paths outside the same failure domain. A backup that cannot be accessed during a crisis is, operationally, the same as no backup.
Sixth, prioritize remediation based on exposure. Brazilian alerts and notices from Cisco, Microsoft, and Beazley should not be filed away as vulnerability noise. If a product is in use and the vulnerability is listed as exploited or included in KEV, the exposure window remains high risk until effective remediation or mitigation is in place. In regulated or high-availability sectors, remediation should be treated as a continuity project, not a maintenance task.
Seventh, strengthen data leak monitoring and alternative distribution channels. The Aeroméxico case shows that Telegram and similar channels can host allegedly stolen data and accelerate the need to respond. Organizations should monitor marketplaces, channels, and repositories where datasets may appear, but without automatically assuming authenticity. The right response combines intelligence, forensic validation, and careful communication.
Regional trends and implications
The month’s main trend is the consolidation of an attack and disruption model centered on trusted infrastructure. This is no longer just about ransomware or isolated phishing. It now involves incidents that exploit identity layers, SaaS providers, hosting nodes, and recovery mechanisms. DonWeb, ICETEX, Aeroméxico, Brevo, and Storm-3168 are different in form, but they converge on the same idea: the attacker is going after the point where the organization delegated critical functions to another system, another tenant, or a third party.
The second trend is the growing visibility of regional defensive operations, especially in Brazil. CISC bulletins and CTIR Gov alerts show a state ecosystem that does not just react, but also prioritizes and communicates clearly. For Latin America, that is positive because it shortens the time between disclosure and remediation, even if it does not eliminate the gap between notice and effective action. Alerts do not guarantee patching, but they do create a more mature baseline for collective defense.
The third trend is the persistence of cross-border dependencies. A Mexican airline can become involved in a data incident circulating on Telegram. A Colombian entity can be affected by an external provider whose identity is not disclosed. A Microsoft 365 campaign can impact tenants in several Latin American countries. A global provider like Brevo can turn an API key problem into exposure for customer-integrated assets. The result is that regional resilience now depends increasingly on governing international software relationships, not only local assets.
The fourth trend is that availability and confidentiality are increasingly intertwined. DonWeb started as an availability problem. ICETEX began as a security incident with operational impact. Aeroméxico involved a possible data exposure. Brevo involved an edge intrusion with script injection. In all four cases, the final impact combines disruption, reputation, and trust. For security and business continuity teams, that means it is not enough to classify an incident as technical or data-related. They need to understand its chain of consequences.
The fifth regional implication is that Latin American companies must assume a shared-exposure reality. Microsoft 365 identities, firewall consoles, virtualization environments, CDNs, and CRM platforms are now part of the backbone of digital operations. If one of those pieces fails or is abused, the impact spreads across multiple industries. The response cannot be sectoral and isolated. It needs cooperation among providers, customers, CSIRTs, regulators, and legal teams.
Material Limitations
This report is based exclusively on the research material provided and on facts confirmed or attributed by the sources listed there. It does not include network telemetry, proprietary sensor data, or information outside that documentary window. For that reason, some incidents appear only partially or with unpublished details, especially in the case of third-party vendors, ongoing forensic investigations, and databases whose authenticity was still under verification.
It should also be remembered that the absence of certain themes in the indicators does not mean there was no real activity in the region. If a type of incident does not appear with sufficient evidence in the reviewed corpus for this period, that only means the sources used in the report did not support it. In particular, critical exploited vulnerabilities may exist in the field without having been documented in the material analyzed here. For that reason, readers should treat this report as a limited snapshot of the period, not as a complete census of regional risk.
Frequently Asked Questions
What was the most significant incident during the period?
DonWeb was the event with the clearest operational impact, due to the number of affected customers and the interruption of cloud and IaaS services. However, ICETEX also stands out for its institutional response, and Aeroméxico for the possible exposure of data through an external provider.
Was data loss confirmed at DonWeb?
No. The company said 100% of the NOVA node was back online and stated that no data loss was recorded. The incident did cause downtime and affected critical services, but the main confirmed impact was on continuity, not on information loss.
Was an attack on ICETEX confirmed?
The available material does not allow that to be stated as a closed fact. The entity reported a security incident at an external provider and activated containment and forensic analysis. Some coverage described it as a suspected hack, but technical verification was still underway when the information was published.
Did Aeroméxico confirm a financial data breach?
No. The airline said the information allegedly involved did not include financial data, bank accounts, payment cards, passwords, or flight itineraries. It did mention names and, in some cases, dates of birth, email addresses, and phone numbers.
What should a regional CISO prioritize?
Service identities, secrets, third-party dependencies, and real recovery capability. The period showed that a poorly managed credential, an affected vendor, or a vulnerable storage node can do more operational damage than a noisy but superficial attack.
Sources
- Steam: más de 12 TB de juegos y prototipos quedaron...Brodersen Dark News
- Empresa de hosting afirma que se normaliza el corteElonce
- DonWeb: una de las mayores empresas de hosting del país lleva tres días caída y hay cientos de pymes afectadasClarín
- Don Web explicó qué originó el problema en el servidor y cuándo lo solucionaráLa Capital
- Cientos de páginas web argentinas paralizadas por una falla crítica que bloqueó bases de datos y facturaciónLa Voz del Interior
- El servidor de una empresa líder rosarina está caído y hay cientos de clientes afectadosLa Capital
- ICETEX reporta presunto hackeo que afecta sus servicios y activa protocolos de seguridadCaracol Radio
- Icetex reporta afectación en sus servicios por incidente de seguridad: ¿fueron vulnerados los datos de los usuarios?El Heraldo
- El ICETEX cobrará solo la inflación a 170.000 deudores al día: interrupción digital y subsidio de tasaMás Colombia
- ICETEX reporta incidente de seguridad: varios de sus servicios fueron afectadosBlu Radio
- Icetex reporta problemas en varios servicios tras incidente de seguridadVanguardia
- El Icetex reportó un incidente de seguridad en un proveedor externo y confirmó fallas en algunos servicios virtualesInfobae Colombia
- Aeroméxico Niega Exposición de Datos de Pasajeros tras Presunto Robo de InformaciónN+
- Aeroméxico vincula filtración de presunta base de datos con ciberataques ocurridos en 2025Infobae
- Investigan venta de datos de clientes de AeromexicoLa Verdad
- Aeroméxico vincula filtración de presunta base de datos con ciberataques ocurridos en 2025ABC Color
- Mexico probes possible Aeromexico customer data breachYahoo News
- Boletim do CISC de Vulnerabilidades — 28 de septiembre de 2026Centro de Estudos, Resposta e Tratamento de Incidentes de Segurança de Informação — CISC
- ALERTA 89/2026Gabinete de Segurança Institucional — CTIR Gov
- ALERTA 90/2026Gabinete de Segurança Institucional — CTIR Gov
- ALERTA 86/2026Gabinete de Segurança Institucional — CTIR Gov
- Boletim do CISC de Vulnerabilidades — 22 de septiembre de 2026Centro de Estudos, Resposta e Tratamento de Incidentes de Segurança de Informação — CISC
- InfraTrust report warns network management systems under attackBleepingComputer
- Cisco FMC Auth Bypass Exploited to Deploy Qilin RansomwareCloud Security Alliance Research
- Critical Vulnerabilities in Cisco Secure Firewall Management CenterBeazley Security Labs
- Critical Infrastructure Threat Intelligence BriefingBorder Cyber Group
- Boletim do CISC de Vulnerabilidades — 15 de septiembre de 2026Centro de Estudos, Resposta e Tratamento de Incidentes de Segurança de Informação — CISC
- ALERTA 81/2026Gabinete de Segurança Institucional — CTIR Gov
- ALERTA 82/2026Gabinete de Segurança Institucional — CTIR Gov
- ALERTA 79/2026Gabinete de Segurança Institucional — CTIR Gov
- Active exploitation of Cisco Secure Firewall Management Center vulnerabilityCisco Talos
- RECOMENDAÇÃO 16/2026Gabinete de Segurança Institucional — CTIR Gov
- RECOMENDAÇÃO 15/2026Gabinete de Segurança Institucional — CTIR Gov
- 28th September – Threat Intelligence ReportCheck Point Research
- Storm-3168: Agentic-driven cloud attacks using compromised service principalsMicrosoft Security
- Autonomous agents attack Azure using compromised identities, destroying resourcesCSO Online
- Brevo supply-chain attack injected ClickFix scripts on customer sitesBleepingComputer
- Active Exploitation Alert: Brevo CDN Supply-Chain Compromise — ClickFix Injection via Stolen Cloudflare API KeyRESCANA
- Security Incident - ClickFixBrevo Status
- Brevo Supply Chain Attack Injects Malware Into 100,000 WebsitesSecurityWeek
- Weekly Threat Bulletin – September 23rd, 2026F5 Labs
