CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)23
Última detecciónhace 3 h
Monitorizado porintelligence scouter
22signals
Acción Requerida
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaMicrosoft111Google100Citrix72GitHub67Apple59Cisco52Cloudflare36Linux31WordPress29Mozilla

Priority Command Strip

What your team should look at right now

6 señales críticas
  1. Action RequiredImmediate2d

    TeamViewer urges users to patch severe flaws “as soon as possible”

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    BleepingComputer · Microsoft · CiscoReview signal
  2. Action Required
All23Action Required22Exploited & KEV8Critical Vulns0Cloud & Identity1
Cloud & IdentityMEDIAAltoNEWGDPRNIS2AI ACTInteligencia operacional

Unsloth’s model picker had a code-execution problem

True to its name, AI-model-training tool Unsloth would do more work than it was asked to when developers checked out a model: It would also allow arbitrary code to execute on their machines. Pillar Security found that simply selecting a model in Unsloth Studio caused the application to download and execute Python code from the model repository. This could potentially allow attackers to use a specially crafted model to get malicious code executed on a developer’s system. “The code ran from nothing more than a metadata check,” researcher Ariel Fogel said in a post on Pillar’s blog. “Reading the model’s config.json was enough to trigger the exploit; the backend never loaded the weights or ran inference.” The code would run with the user’s permission which, Fogel said, could expose proprietary training data, model artifacts, Hugging Face tokens, SSH keys, or accessible cloud credentials in an enterprise’s AI development environment. Unsloth Studio is a web-based interface that is currently in beta, a status Unsloth’s maintainers cited when they reportedly declined to publish a security advisory or have a CVE assigned to the flaw after fixing it in June. Pillar contests that reasoning, pointing out that the vulnerable Studio code ships as part of the standard, generally available “unsloth” package on PyPI and can be installed through an ordinary “pip install unsloth” without selecting a beta or prerelease version. Transformers setting opened the door Unsloth uses Hugging Face’s trust_remote-code option, which allows a model to bring along its own Python code when needed. That’s not necessarily dangerous by itself. Some legitimate Hugging Face models, including IBM Granite Speech and Vision, DeepSeek-OCR, ChatGLM, and earlier Qwen releases, need custom code to work properly, Fogel said. The problem was that Unsloth enabled the feature automatically during a routine model check rather than requiring the user to explicitly opt into running remote code. Before the patch, “tr Vendors: Google, Citrix, GitLab, GitHub, Python, IBM. DORA relevance: high.

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

8signals
Explotados & KEV
Vulns Críticas

Sin CVEs críticas frescas en la ventana actual.

Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

También en el Intel CenterCloud & Identity1
28
PHP28
MikroTik26
GitLab23
Check Point21
Immediate
21d

CVE-2026-85706 · GitLab Community Edition and Enterprise Edition: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

Explotación activa confirmada. Riesgo material para entornos expuestos.

CISA KEV Catalog · GitLabReview signal
  • Action RequiredImmediate2d

    GitLab Critical Patch Release: 19.0.9, 18.11.12

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    GitLab Security Releases · GitLabReview signal
  • Action RequiredImmediate138d

    CVE-2021-22175 · GitLab GitLab: GitLab Server-Side Request Forgery (SSRF) Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · GitLabReview signal
  • Action RequiredImmediate138d

    CVE-2021-39935 · GitLab Community and Enterprise Editions: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · GitLabReview signal
  • Action RequiredImmediate3h

    Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes  Oct 02, 2026 Vulnerability / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    The Hacker News Vulnerability · Microsoft · CiscoReview signal
  • Por qué importa

    La selección de un modelo podía ejecutar código Python arbitrario desde su repositorio con los permisos del usuario, exponiendo datos de entrenamiento, tokens de Hugging Face, claves SSH y credenciales cloud.

    Acción recomendada

    Actualiza Unsloth a una versión corregida, revisa el uso de trust_remote_code y rota cualquier token, clave o credencial accesible desde los entornos afectados.

    Vendors:UnslothHugging FaceSectores:bankingpublic sectorcloud/SaaSMITRE:T1203 Exploitation for Client ExecutionCISO · Cloud Security · SecOps
    Mapeo regulatorio · riesgo 55

    La ejecución arbitraria de código desde repositorios de modelos constituye una vulnerabilidad que requiere gestión y divulgación coordinada, aunque no hay evidencia confirmada de explotación, incidente notificable o exposición de datos personales.

    NIS2 · Art. 12 Coordinated vulnerability disclosure and a European vulnerability database (direct)
    Publicado
    30 sept 2026, 13:56
    Actualizado
    30 sept 2026, 16:01
    Detectado
    30 sept 2026, 16:01
    Fuente
    CSO Online
    Referencia técnica
    Original advisory
    CSO Online
    Prioridad · 41/100published <7d (+25) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días