Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.
Para análisis editorial y noticias generales visita Noticias.
The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek. CVEs: CVE-2026-26035, CVE-2026-70468, CVE-2026-70465, CVE-2026-49975. CISA KEV/exploitation signal detected. Vendors: Microsoft, Fortinet, VMware, Adobe, Ivanti, SonicWall, Apache, Salesforce, ServiceNow, WordPress, Zoom. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →
3signals
Explotados & KEV
Vulns Críticas
Sin CVEs críticas frescas en la ventana actual.
Advisories de Vendor
Sin nuevos advisories PSIRT de vendor en la ventana.
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild. The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek. CVEs: CVE-2026-55040, CVE-2026-63520, CVE-2026-50522, CVE-2026-58644, CVE-2026-56164. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Google, Rapid7, Ivanti, Mozilla, Siemens, Salesforce, ServiceNow, Zoom. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Comprueba la exposición a CVE-2026-55040, CVE-2026-63520, CVE-2026-50522 en el inventario de activos y las herramientas de vulnerabilidades.
Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing geospatial data. The software is widely used by organizations in many industries, including the government, defense, science, education, engineering and technology sectors, and has been targeted by hackers in the past. A bug bounty hunter shared the vulnerability Wednesday on X as a zero day. According to his post, the jsonArrayContains function contains a vulnerability that allows unauthenticated users to inject SQL commands into the database. If the database runs with administrator permissions on Microsoft SQL Server, the account also has the ability to execute commands on the system, so the SQL injection becomes a remote code execution vector. Another user confirmed on X that they were able to reproduce the flaw in a non-default configuration. “Within hours of public disclosure, we began observing exploitation attempts and have since recorded hundreds of attempts originating from a small number of source IP addresses,” researchers from security firm watchTowr told CSO via email on Thursday. “Yet another example of how quickly attackers move once a vulnerability enters the public domain.” So far, the researchers haven’t seen any malicious payloads or commands being sent, and the attempts look more like probes to identify vulnerable GeoServer instances. However, this is likely to change; GeoServer has a history of being exploited, since its users are usually seen as high value targets. Until a patch becomes available, organizations who run GeoServer should identify their internet exposed instances and restrict public access to them. They should also check the logs for any signs that exploitation has already occurred. Vendors: Microsoft, Google, Zoom, Node.js, Zimbra. DORA relevance: high.
Por qué importa
Severidad crítica con vector accionable a corto plazo.
Acción recomendada
Avisa a los owners de los stacks Microsoft, Google, Zoom, Node.js.
Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges. The post Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ appeared first on SecurityWeek. CVEs: CVE-2026-50656. Vendors: Microsoft, Cisco, SAP, Adobe, Ivanti, SonicWall, Salesforce, ServiceNow, Zoom. DORA relevance: medium.
Por qué importa
Severidad crítica con vector accionable a corto plazo.
Acción recomendada
Comprueba la exposición a CVE-2026-50656 en el inventario de activos y las herramientas de vulnerabilidades.