CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)12
Última detecciónhace 2 d
Monitorizado porintelligence scouter
10signals
Acción Requerida
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaMicrosoft129Google56Cisco48Apple39ServiceNow30GitHub30Salesforce28Palo Alto Networks21Adobe21Siemens

Priority Command Strip

What your team should look at right now

6 señales críticas
  1. Action RequiredImmediate2d

    Haiwell IoT Cloud HMI Gateway

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA ICS Advisories · Haiwell Product Version: Haiwell Haiwell IoT Cloud HMI Gateway: 3 · GitHubReview signal
  2. Action Required
All12Action Required10Exploited & KEV3Critical Vulns0Cloud & Identity2

Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Pro para abrir el feed completo, histórico ampliado y el catálogo KEV.

INMEDIATOCríticoACTION REQUIREDGDPRNIS2Inteligencia operacional

Haiwell IoT Cloud HMI Gateway

View CSAF Summary Successful exploitation of this vulnerability may allow an attacker to inject and execute arbitrary OS commands with root privileges. The following versions of Haiwell IoT Cloud HMI Gateway are affected: Haiwell IoT Cloud HMI Gateway 3.40.1.12 (CVE-2026-19188) CVSS Vendor Equipment Vulnerabilities v3 10 Haiwell Haiwell IoT Cloud HMI Gateway Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Background Critical Infrastructure Sectors: Energy, Critical Manufacturing, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-19188 A critical OS command injection vulnerability has been identified in the Haiwell IoT Cloud HMI Gateway product. The vulnerability exists in the Net Check feature accessible via the /setting endpoint. The cmdPing Socket.io event fails to properly sanitize user-supplied input before passing it to the underlying operating system, allowing an attacker to inject and execute arbitrary OS commands with root privileges View CVE Details Affected Products Haiwell IoT Cloud HMI Gateway Vendor: Haiwell Product Version: Haiwell Haiwell IoT Cloud HMI Gateway: 3.40.1.12 Product Status: known_affected Remediations Mitigation Haiwell has addressed the issue in patch version number Scada-v3.50.1.19, which is available for download on their website: https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=dodown&lang=en&id=361 https://en.haiwell.com/app/system/entrance.php?m=include&c=access&a=dodown&lang=en&id=361 Relevant CWE: CWE-78 Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') Metrics CVSS Version Base Score Base Severity Vector String 3.1 10 CRITICAL CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H 4.0 10 CRITICAL CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H Acknowledgments Fiqram Akmal reported this vulnerability to CISA Legal Notice and Terms of Use This CVEs: CVE-2026-19188. CISA KEV/exploitation signal detected. Vendors: Haiwell Product Version: Haiwell Haiwell IoT Cloud HMI Gateway: 3, GitHub, Siemens, PHP. DORA relevance: medium.

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

3signals
Explotados & KEV
Vulns Críticas

Sin CVEs críticas frescas en la ventana actual.

Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

También en el Intel CenterCloud & Identity2
16
Fortinet15
Linux14
Ivanti14
SonicWall14
Immediate
3d

Lazarus hackers exploited Windows zero-day to target defense firms

Explotación activa confirmada. Riesgo material para entornos expuestos.

BleepingComputer · Microsoft · CiscoReview signal
  • Action RequiredImmediate36d

    CVE-2026-48939 · iCagenda iCagenda: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · iCagenda · PHPReview signal
  • Action RequiredImmediate39d

    CVE-2026-48908 · JoomShaper SP Page Builder: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · JoomShaper · PHPReview signal
  • Action RequiredImmediate60d

    CVE-2026-48907 · Widget Factory Joomla Content Editor : Widget Factory Joomla Content Editor Improper Access Control Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · Widget Factory · PHPReview signal
  • Action RequiredImmediate73d

    CVE-2026-45247 · Mirasvit Mirasvit Full Page Cache Warmer: Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · Mirasvit · PHPReview signal
  • Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-19188 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:Haiwell Product Version: Haiwell Haiwell IoT Cloud HMI Gateway: 3GitHubSiemensPHPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 ago 2026, 12:00
    Actualizado
    13 ago 2026, 18:02
    Detectado
    13 ago 2026, 18:02
    Fuente
    CISA ICS Advisories
    Referencia técnica
    NVD · CVE-2026-19188
    CISA ICS Advisories
    Prioridad · 88/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA ICS Advisories authority (+12) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    Lazarus hackers exploited Windows zero-day to target defense firms

    North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...] CVEs: CVE-2026-68820, CVE-2025-49113. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Google, SonicWall, Mozilla, PHP, Check Point. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-68820, CVE-2025-49113 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:MicrosoftCiscoGoogleSonicWallCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    12 ago 2026, 15:38
    Actualizado
    12 ago 2026, 19:01
    Detectado
    12 ago 2026, 19:01
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-68820
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 3 días
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2026-48939 · iCagenda iCagenda: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

    [CISA KEV actively exploited] Vendor: iCagenda | Product: iCagenda | iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-07-13 | Ransomware use: Unknown | Added: 2026-07-10 CVEs: CVE-2026-48939. CISA KEV/exploitation signal detected. Vendors: iCagenda. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:iCagendaPHPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    10 jul 2026, 00:00
    Actualizado
    10 jul 2026, 18:00
    Detectado
    10 jul 2026, 18:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-48939
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 36 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2026-48908 · JoomShaper SP Page Builder: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

    [CISA KEV actively exploited] Vendor: JoomShaper | Product: SP Page Builder | JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-07-10 | Ransomware use: Unknown | Added: 2026-07-07 CVEs: CVE-2026-48908. CISA KEV/exploitation signal detected. Vendors: JoomShaper. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:JoomShaperPHPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    07 jul 2026, 00:00
    Actualizado
    07 jul 2026, 18:00
    Detectado
    07 jul 2026, 18:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-48908
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 39 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2026-48907 · Widget Factory Joomla Content Editor : Widget Factory Joomla Content Editor Improper Access Control Vulnerability

    [CISA KEV actively exploited] Vendor: Widget Factory | Product: Joomla Content Editor | Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-06-19 | Ransomware use: Unknown | Added: 2026-06-16 CVEs: CVE-2026-48907. CISA KEV/exploitation signal detected. Vendors: Widget Factory. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:Widget FactoryPHPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    16 jun 2026, 00:00
    Actualizado
    16 jun 2026, 20:00
    Detectado
    16 jun 2026, 20:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-48907
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 60 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2026-45247 · Mirasvit Mirasvit Full Page Cache Warmer: Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

    [CISA KEV actively exploited] Vendor: Mirasvit | Product: Mirasvit Full Page Cache Warmer | Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2026-06-06 | Ransomware use: Unknown | Added: 2026-06-03 CVEs: CVE-2026-45247. CISA KEV/exploitation signal detected. Vendors: Mirasvit. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Vendors:MirasvitPHPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    03 jun 2026, 00:00
    Actualizado
    03 jun 2026, 18:00
    Detectado
    03 jun 2026, 18:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-45247
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 73 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2026-9082 · Drupal Core: Drupal Core SQL Injection Vulnerability

    [CISA KEV actively exploited] Vendor: Drupal | Product: Core | Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2026-05-27 | Ransomware use: Unknown | Added: 2026-05-22 CVEs: CVE-2026-9082. CISA KEV/exploitation signal detected. Vendors: Drupal. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Vendors:DrupalPHPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    22 may 2026, 00:00
    Actualizado
    22 may 2026, 20:00
    Detectado
    22 may 2026, 20:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-9082
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 85 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2025-54068 · Laravel Livewire: Laravel Livewire Code Injection Vulnerability

    [CISA KEV actively exploited] Vendor: Laravel | Product: Livewire | Laravel Livewire contain a code injection vulnerability that could allow unauthenticated attackers to achieve remote command execution in specific scenarios. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2026-04-03 | Ransomware use: Unknown | Added: 2026-03-20 CVEs: CVE-2025-54068. CISA KEV/exploitation signal detected. Vendors: Laravel. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Vendors:LaravelPHPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    20 mar 2026, 00:00
    Actualizado
    17 may 2026, 13:01
    Detectado
    17 may 2026, 13:01
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2025-54068
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 90 días