Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.
Para análisis editorial y noticias generales visita Noticias.
Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Studio para abrir el feed completo, histórico ampliado y el catálogo KEV.
IT teams responsible for identity security are concerned about AI agents’ ongoing access to company systems and the actions they take on users’ behalf, according to a Delinea’s 2026 Identity Security Report: The AI Enforcement Gap. “Written policy is only as good as your ability to enforce it at the moment an AI agent acts,” said Art Gilliland, CEO of Delinea. “Our research echoes what I hear from leaders constantly: they have the AI policies … More → The post AI agents keep access to company data after their work is done appeared first on Help Net Security. CVEs: CVE-2026-76504, CVE-2026-88772. Vendors: Cisco, Google, Citrix, Kubernetes. DORA relevance: medium.
Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →
Los agentes de IA mantienen acceso persistente a datos corporativos tras finalizar sus tareas, creando un riesgo crítico de escalada de privilegios y exposición de datos sensibles bajo normativas GDPR/HIPAA.
Acción recomendada
Audita los permisos y tokens de acceso de los agentes de IA en entornos cloud y revisa la configuración de ciclo de vida de sesiones para mitigar el acceso no autorizado.
El acceso persistente y potencialmente excesivo de agentes de IA a datos corporativos puede incumplir los principios de protección desde el diseño, procesamiento bajo instrucciones y seguridad adecuada al riesgo.
GDPR · Art. 25 Data protection by design and by default (direct) · Art. 29 Processing under the authority of the controller or processor (direct) · Art. 32 Security of processing (direct)
When a journalist suspects their phone has been hacked, the first question is whether any trace of the attack is left. Google has added six features to Advanced Protection in Android 17, including one that keeps a copy of that evidence off the device. Existing users will receive a notification when the new capabilities become available on their devices. Forensic logging and data retention Intrusion Logging records security and network events, including app activity. Users … More → The post Android 17 makes it harder for spyware to cover its tracks appeared first on Help Net Security. CVEs: CVE-2026-76504, CVE-2026-88772. Vendors: Cisco, Google, Citrix. DORA relevance: medium.
Por qué importa
Se han reportado vulnerabilidades asociadas a múltiples proveedores (Cisco, Google, Citrix) en el contexto de nuevas capacidades de seguridad de Android 17, lo que requiere validación de exposición.
Acción recomendada
Audita el inventario de activos para identificar sistemas afectados por CVE-2026-76504 y CVE-2026-88772 y notifica a los responsables de infraestructura de Cisco, Google y Citrix.
AI sovereignty is not a zero-sum game, but many governments now believe it is. Cloudflare's answer: more local open-source models, model-agnostic security tools, and a commitment to giving nations genuine choice. CVEs: CVE-2023-50387. Vendors: Microsoft, Google, AWS, CrowdStrike, Apple, Atlassian, GitHub, Apache, Mozilla, Kubernetes, Okta, WordPress, OpenSSL, PHP, Node.js, Python, IBM, Elastic, PostgreSQL, MySQL, NGINX, Grafana, HashiCorp, Cloudflare. DORA relevance: high.
Por qué importa
El informe aborda la soberanía de la IA y la seguridad en la cadena de suministro, destacando la necesidad de resiliencia operativa bajo marcos como DORA y NIS2 ante la dependencia de múltiples proveedores tecnológicos.
Acción recomendada
Audita el inventario de activos frente a la CVE-2023-50387 y revisa los controles de seguridad en la cadena de suministro de IA según las directrices de cumplimiento vigentes.
La presencia de la CVE-2023-50387 y la necesidad de revisar la gestión de vulnerabilidades hacen aplicable la divulgación coordinada de vulnerabilidades bajo NIS2, aunque no se evidencia explotación ni incidente.
NIS2 · Art. 12 Coordinated vulnerability disclosure and a European vulnerability database (direct)
Armadin has raised $255.5 million in Series B funding co-led by Andreessen Horowitz (a16z) and Accel that brings the company’s valuation to over $2.5 billion. The round includes participation from new investors Bain Capital Ventures (BCV) and Redpoint. Existing investors 8VC, Ballistic Ventures, Google Ventures, In-Q-Tel, Kleiner Perkins, and Menlo Ventures also returned, reflecting their continued confidence, bringing Armadin’s total funding to $445 million. Seven months after emerging from stealth, Armadin is running agentic attack … More → The post Armadin raises $255.5 million to expand AI offensive security platform appeared first on Help Net Security. CVEs: CVE-2026-76504, CVE-2026-88772. Vendors: Cisco, Google, Citrix. DORA relevance: medium.
Por qué importa
Se han identificado vulnerabilidades críticas asociadas a proveedores clave (Cisco, Google, Citrix) que requieren validación inmediata en el inventario de activos.
Acción recomendada
Auditar el inventario de activos para identificar versiones afectadas de Cisco, Google y Citrix y aplicar los parches de seguridad correspondientes.
Legit Security has announced an expansion of its Agentic Remediation capability to cover vulnerabilities found in open-source dependencies, not just first-party code, enabling development teams to move from vulnerability detection to a verified fix without manual triage. The expansion addresses a growing gap in application security: as AI-generated code accelerates software delivery, most modern codebases are made up largely of open-source dependencies, and every new package introduces potential exposure to known vulnerabilities. Traditional find-it, fix-it … More → The post Legit Security extends automated fixes to vulnerable open-source dependencies appeared first on Help Net Security. CVEs: CVE-2026-76504, CVE-2026-88772. Vendors: Cisco, Google, Citrix. DORA relevance: medium.
Por qué importa
Se han identificado vulnerabilidades en dependencias de código abierto que afectan a productos de Cisco, Google y Citrix, requiriendo validación de exposición en el inventario.
Acción recomendada
Audita el inventario de software para identificar la presencia de CVE-2026-76504 y CVE-2026-88772 y aplica los parches recomendados por los proveedores.
Exabeam has introduced a new wave of capabilities that bring the Agentic SOC to life in the cloud and on-premises environments, combining AI-driven investigation, execution, and governance. Analyst workflows alone can’t keep pace with machine-speed threats or the growing complexity of goal-driven AI agents and autonomous workflows. The future of the SOC is agentic. For more than a decade, Exabeam has built applied machine learning into security operations, beginning with its pioneering work in user … More → The post Exabeam brings AI-assisted security investigations to data that must stay on-premises appeared first on Help Net Security. CVEs: CVE-2026-76504, CVE-2026-88772. Vendors: Cisco, Google, Citrix, GitHub, Elastic. DORA relevance: medium.
Por qué importa
Se han reportado vulnerabilidades asociadas a múltiples proveedores críticos en el ecosistema, requiriendo validación de inventario.
Acción recomendada
Verificar la presencia de los activos afectados (Cisco, Google, Citrix, GitHub, Elastic) y aplicar parches si las versiones son vulnerables.
The flaws were chained to hijack sessions, achieve remote code execution, and elevate privileges to root. The post Zammad Zero-Days Exploited in AI-Powered DIVD Hack appeared first on SecurityWeek. CVEs: CVE-2026-102489, CVE-2026-102490. Vendors: Microsoft, Cisco, Google, Citrix, GitHub, Mozilla, OpenSSL, WatchGuard. DORA relevance: medium.
Por qué importa
Explotación activa de zero-days en Zammad que permite ejecución remota de código y escalada de privilegios a root, con riesgo crítico de compromiso total del sistema.
Acción recomendada
Identificar y aislar inmediatamente cualquier instancia de Zammad expuesta, aplicar parches de seguridad si están disponibles y auditar logs en busca de intentos de secuestro de sesión.
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire platform. The following versions of Viidure Dashcam Android Application are affected: Dashcam Android Application <=3.3.1.260403 (CVE-2026-94204, CVE-2026-96587) CVSS Vendor Equipment Vulnerabilities v3 10 Viidure Viidure Dashcam Android Application Incorrect Permission Assignment for Critical Resource, Use of Hard-coded Credentials Background Critical Infrastructure Sectors: Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: China Vulnerabilities Expand All + CVE-2026-94204 The central cloud storage backend for the entire dashcam platform is misconfigured with public‑read permissions, allowing unrestricted access to all stored objects. Because this bucket serves as shared storage for the platform, sensitive user records, live dashcam footage, application packages, and firmware files are exposed to anyone on the internet. View CVE Details Affected Products Viidure Dashcam Android Application Vendor: Viidure Product Version: Viidure Dashcam Android Application: <=3.3.1.260403 Product Status: known_affected Remediations No fix planned Viidure did not respond to CISA's coordination attempts. Users of affected versions of the Viidure Dashcam Android Application are advised to contact Viidure customer support for additional information https://viidure.app/. Relevant CWE: CWE-732 Incorrect Permission Assignment for Critical Resource Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.5 HIGH CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N 4.0 8.7 HIGH CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVE-2026-96587 The Viidure Android application embeds permanent, plaintext cloud storage credentials within its compiled code. These credentials provide full access to critical platform storage, incl CVEs: CVE-2026-94204, CVE-2026-96587. Vendors: Viidure Product Version: Viidure Dashcam Android Application: <=3, Google, GitHub, MikroTik. DORA relevance: medium.
Por qué importa
La aplicación expone credenciales hardcoded y tiene una mala configuración en el almacenamiento en la nube, permitiendo acceso público a datos sensibles de usuarios y firmware sin posibilidad de parcheo oficial.
Acción recomendada
Identificar y restringir el uso de la aplicación Viidure en dispositivos corporativos y auditar cualquier conexión a los buckets de almacenamiento asociados a esta plataforma.
Vendors:ViidureSectores:Transportation SystemsMITRE:T1552 Unsecured CredentialsT1530 Data from Cloud Storage ObjectCISO · Cloud Security · SecOps
Mapeo regulatorio · riesgo 85
La exposición pública de datos personales, credenciales cloud y firmware evidencia controles insuficientes de protección de datos y gestión del riesgo de ciberseguridad.
GDPR · Art. 24 Responsibility of the controller (direct) · Art. 25 Data protection by design and by default (direct)