CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 24h
Señales (ventana)311
Última detecciónhace 2 h
Monitorizado porintelligence scouter
272signals
Acción Requerida
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaMicrosoft71Google49Cisco44GitHub37Citrix30Apple21Linux15PHP13Zimbra12Fortinet11

Priority Command Strip

What your team should look at right now

6 señales críticas
  1. Action RequiredImmediate9h

    CISA Adds One Known Exploited Vulnerability to Catalog

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA All Alerts · Fortinet · GitHubReview signal
  2. Action Required
All311Action Required272Exploited & KEV10Critical Vulns21Cloud & Identity16

Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Studio para abrir el feed completo, histórico ampliado y el catálogo KEV.

Critical VulnsMEDIAAltoNEWNIS2Inteligencia operacional

CISA Malcolm

View CSAF Summary The following versions of CISA Malcolm are affected: Malcolm CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF), Authentication Bypass by Spoofing, Missing Authorization, Missing Authentication for Critical Function, Incorrect Authorization, Use of Default Credentials, Improper Certificate Validation, URL Redirection to Untrusted Site ('Open Redirect'), Dependency on Vulnerable Third-Party Component, Use of Password Hash With Insufficient Computational Effort Background Critical Infrastructure Sectors: Energy, Information Technology, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-90443 A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redirect the user's browser to an arbitrary external site. Successful exploitation could allow an attacker to act with the compromised user's session privileges within the application. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Metrics CVSS Version Bas CVEs: CVE-2026-90443, CVE-2026-90444, CVE-2026-90445, CVE-2026-90446, CVE-2026-90447. Vendors: CISA Product Version: CISA Malcolm <v26, GitHub. DORA relevance: medium.

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

10signals
Explotados & KEV
21signals
Vulns Críticas
Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

También en el Intel CenterCloud & Identity16
WordPress11
Check Point10
MikroTik9
GitLab9
Immediate
6h

Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

Explotación activa confirmada. Riesgo material para entornos expuestos.

BleepingComputer · Microsoft · CiscoReview signal
  • Action RequiredImmediate11h

    Osavul Lands $10 Million to Spot Hostile Intent Across Cyber, Physical Domains

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    SecurityWeek · SAP · DockerReview signal
  • Action RequiredImmediate11h

    Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    SecurityWeek · Microsoft · ZimbraReview signal
  • Action RequiredImmediate11h

    Give yourself room to be human

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Talos Intelligence Blog · Microsoft · CiscoReview signal
  • Action RequiredImmediate16h

    Kevin Mandia’s Armadin Raises $255 Million at $2.5 Billion Valuation

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    SecurityWeek · Palo Alto Networks · GoogleReview signal
  • Por qué importa

    CISA Malcolm presenta múltiples vulnerabilidades críticas, incluyendo inyección de comandos y bypass de autenticación, que permiten a atacantes no autenticados comprometer la integridad y confidencialidad del sistema.

    Acción recomendada

    Actualice inmediatamente todas las instancias de CISA Malcolm a la versión de septiembre de 2026 o superior y audite los logs en busca de intentos de explotación previos.

    Vendors:CISASectores:EnergyInformation TechnologyWater and WastewaterMITRE:T1190 Exploit Public-Facing ApplicationCISO · Vulnerability Management · IT Ops
    Mapeo regulatorio · riesgo 55

    La vulnerabilidad de alta severidad en Malcolm requiere medidas de gestión de riesgos y remediación, pero no hay evidencia de explotación, incidente significativo o afectación confirmada a una entidad sujeta a NIS2.

    NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
    Publicado
    01 oct 2026, 12:00
    Actualizado
    01 oct 2026, 17:01
    Detectado
    01 oct 2026, 17:01
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2026-90443
    CISA All Alerts
    Prioridad · 59/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <24h (+5 cap)
    hace 15 horas
    Critical VulnsMEDIAAltoNEWGDPRNIS2Inteligencia operacional

    Johnson Controls EasyIO Neo Series EC and CW Controllers

    View CSAF Summary Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data. The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected: EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64893) EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64893) EasyIO Neo Series CW Controllers V3.3b24 (CVE-2026-64893) EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64893) CVSS Vendor Equipment Vulnerabilities v3 5.4 Johnson Controls Johnson Controls EasyIO Neo Series EC and CW Controllers Cleartext Transmission of Sensitive Information Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-64893 Johnson Controls is aware of a vulnerability in EasyIO Neo which may allow an attacker to intercept and read sensitive information, including credentials and session data, transmitted in cleartext over the network. Successful exploitation could result in technical or operational impact. EasyIO Neo is a programmable building automation edge controller used to manage and automate HVAC, lighting, and energy systems in commercial buildings through a web-based interface. View CVE Details Affected Products Johnson Controls EasyIO Neo Series EC and CW Controllers Vendor: Johnson Controls Product Version: Johnson Controls EasyIO Neo Series EC Controllers: V3.3b62, Johnson Controls EasyIO Neo Series EC Controllers: V3.3b63, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b24, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b25 Product Status: known_affected Remediations Mitigation Johnson Controls released fixed versions for EasyIO Neo Series EC and CW Controllers. Users should upgrade to the fixed version or later as soon as operation CVEs: CVE-2026-64893. Vendors: Johnson Controls Product Version: Johnson Controls EasyIO Neo Series EC Controllers: V3, GitHub. DORA relevance: medium.

    Por qué importa

    La vulnerabilidad permite la interceptación de credenciales y datos de sesión en texto claro en sistemas de automatización de edificios, lo que podría facilitar el acceso no autorizado a infraestructuras críticas.

    Acción recomendada

    Identificar los controladores EasyIO Neo afectados en el inventario y actualizar al firmware corregido proporcionado por Johnson Controls lo antes posible.

    Vendors:Johnson ControlsSectores:Critical ManufacturingCommercial FacilitiesGovernment ServicesTransportation SystemsMITRE:T1190 Exploit Public-Facing ApplicationCISO · Vulnerability Management · IT Ops
    Mapeo regulatorio · riesgo 60

    La vulnerabilidad expone credenciales y datos de sesión en texto claro en controladores de automatización, lo que requiere medidas de gestión de riesgos y corrección conforme a NIS2 Art. 21 cuando la entidad esté dentro de su ámbito.

    NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
    Publicado
    01 oct 2026, 12:00
    Actualizado
    01 oct 2026, 17:01
    Detectado
    01 oct 2026, 17:01
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2026-64893
    CISA All Alerts
    Prioridad · 59/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <24h (+5 cap)
    hace 15 horas
    Critical VulnsMEDIAAltoNEWGDPRNIS2Inteligencia operacional

    ABB Protection and Control IED Manager PCM600

    View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are affected: Protection and Control IED Manager PCM600 <=2.14 (CVE-2026-15952, CVE-2026-15953) CVSS Vendor Equipment Vulnerabilities v3 6.4 ABB ABB Protection and Control IED Manager PCM600 Incorrect Permission Assignment for Critical Resource, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-15952 A vulnerability exists in the Scheduler Service installed with PCM600. The service executes under the LocalSystem account while permissions are granted to standard PCM600 users through membership in the local users group. An attacker with local access and valid user credentials may exploit this vulnerability to elevate privileges and obtain control of the affected host. View CVE Details Affected Products ABB Protection and Control IED Manager PCM600 Vendor: ABB Product Version: ABB Protection and Control IED Manager PCM600: <=2.14 Product Status: known_affected Remediations Mitigation ABB recommends the following workaround. Although this workaround does not correct the underlying vulnerability, it reduces the risk of privilege escalation. Mitigation Configure the appropriate ABBPCMSchedulerService instance to run using the same Windows account that is used to operate PCM600: Open Services.msc. Locate the ABBPCMSchedulerService corresponding to the installed PCM600 version. Open Properties and select the Log On tab. The service should be configured to log on with the same Windows user account that is used for the PCM600 application. Ensure that this account has the required "Log on as a service" privilege. Mitigation When authentication is enabled for the IED, the Scheduler CVEs: CVE-2026-15952, CVE-2026-15953. Vendors: ABB Product Version: ABB Protection and Control IED Manager PCM600: <=2, Microsoft, GitHub. DORA relevance: medium.

    Por qué importa

    Vulnerabilidades en software de gestión industrial (IED) que permiten escalada de privilegios y manipulación de archivos, afectando la integridad de sistemas críticos de energía.

    Acción recomendada

    Auditar el inventario de activos para identificar versiones de PCM600 <=2.14 y aplicar la mitigación recomendada por el fabricante configurando el servicio con privilegios restringidos.

    Vendors:ABBSectores:EnergyCritical InfrastructureMITRE:T1068 Exploitation for Privilege EscalationCISO · Vulnerability Management · IT Ops
    Mapeo regulatorio · riesgo 60

    La vulnerabilidad afecta software de gestión de sistemas energéticos críticos y requiere gestión de riesgos, mitigación y control de la cadena tecnológica conforme a NIS2, aunque no consta explotación confirmada ni incidente notificable.

    NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
    Publicado
    01 oct 2026, 12:00
    Actualizado
    01 oct 2026, 17:01
    Detectado
    01 oct 2026, 17:01
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2026-15952
    CISA All Alerts
    Prioridad · 59/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <24h (+5 cap)
    hace 15 horas
    Critical VulnsMEDIAAltoNEWGDPRNIS2Inteligencia operacional

    Johnson Controls EasyIO Neo Series EC and CW Controllers

    View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system. The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected: EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64892) EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64892) EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64892) EasyIO Neo Series CW Controllers V3.3b24 (CVE-2026-64892) CVSS Vendor Equipment Vulnerabilities v3 3.5 Johnson Controls Johnson Controls EasyIO Neo Series EC and CW Controllers Exposure of Sensitive Information to an Unauthorized Actor Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-64892 Johnson Controls is aware of a vulnerability in EasyIO Neo Series EC and CW Controllers relating to an attacker gaining access to sensitive information that could be used to conduct further attacks against the system. The EC and CW are programmable edge controllers designed for building automation and control systems, used to manage and automate various building functions including HVAC, lighting, and energy management, supporting open protocols such as BACnet and Modbus for adaptable system connections. View CVE Details Affected Products Johnson Controls EasyIO Neo Series EC and CW Controllers Vendor: Johnson Controls Product Version: Johnson Controls EasyIO Neo Series EC Controllers: V3.3b63, Johnson Controls EasyIO Neo Series EC Controllers: V3.3b62, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b25, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b24 Product Status: known_affected Remediations Mitigation Johnson Controls released fixed versions for EasyIO Neo Series EC and CW Controllers CVEs: CVE-2026-64892. Vendors: Johnson Controls Product Version: Johnson Controls EasyIO Neo Series EC Controllers: V3, GitHub. DORA relevance: medium.

    Por qué importa

    Vulnerabilidad de exposición de información sensible en controladores industriales (OT) que podría facilitar ataques laterales en infraestructuras críticas.

    Acción recomendada

    Identificar los controladores afectados en el inventario OT y aplicar las actualizaciones de firmware proporcionadas por Johnson Controls.

    Vendors:Johnson ControlsSectores:Critical ManufacturingCommercial FacilitiesGovernment ServicesTransportation SystemsMITRE:T1190 Exploit Public-Facing ApplicationCISO · Vulnerability Management · IT Ops
    Mapeo regulatorio · riesgo 55

    La vulnerabilidad afecta a controladores OT utilizados en sectores críticos y requiere medidas de gestión de riesgos y mitigación, aunque no se ha confirmado explotación ni un incidente regulatoriamente notificable.

    NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
    Publicado
    01 oct 2026, 12:00
    Actualizado
    01 oct 2026, 17:01
    Detectado
    01 oct 2026, 17:01
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2026-64892
    CISA All Alerts
    Prioridad · 59/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <24h (+5 cap)
    hace 15 horas
    Critical VulnsMEDIAAltoNEWGDPRNIS2Inteligencia operacional

    Monta monta.app

    View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. The following versions of Monta monta.app are affected: monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474) CVSS Vendor Equipment Vulnerabilities v3 9.4 Monta Monta monta.app Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials Background Critical Infrastructure Sectors: Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Netherlands Vulnerabilities Expand All + CVE-2026-95102 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system. View CVE Details Affected Products Monta monta.app Vendor: Monta Product Version: Monta monta.app: vers:all/* Product Status: known_affected Remediations Mitigation Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it. Mitigation Monta states that they have implemented rate limiting and automated connection throttling at the WebSocket layer. Connections exhibiting abusive patterns, including rapid reconnection, ID brute-forcing behavior, or excessive command volume, are automatically identified and blocked. Mitigation Monta states that their CVEs: CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474. Vendors: Monta Product Version: Monta monta, GitHub. DORA relevance: medium.

    Por qué importa

    Vulnerabilidades críticas (CVSS 9.4) en infraestructura de carga permiten el control administrativo no autorizado y la interrupción del servicio, afectando sectores críticos bajo regulación NIS2.

    Acción recomendada

    Auditar el inventario de activos para identificar instancias de Monta monta.app y aplicar las mitigaciones de autenticación (OCPP 1.6 Security Profile 2) recomendadas por el proveedor.

    Vendors:MontaSectores:EnergyTransportation SystemsMITRE:T1190 Exploit Public-Facing ApplicationCISO · Vulnerability Management · IT Ops
    Mapeo regulatorio · riesgo 85

    Vulnerabilidades críticas con posible control administrativo no autorizado y denegación de servicio requieren medidas técnicas, operativas y organizativas de gestión del riesgo conforme a NIS2.

    NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
    Publicado
    01 oct 2026, 12:00
    Actualizado
    01 oct 2026, 17:01
    Detectado
    01 oct 2026, 17:01
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2026-95102
    CISA All Alerts
    Prioridad · 59/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <24h (+5 cap)
    hace 15 horas
    Critical VulnsMEDIAAltoNEWGDPRNIS2Inteligencia operacional

    Armatura LLC Armatura One

    View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system. The following versions of Armatura LLC Armatura One are affected: Armatura One <4.7.2 (CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593, CVE-2026-94594) Armatura One (USA) <4.6.1 (CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593, CVE-2026-94594) CVSS Vendor Equipment Vulnerabilities v3 9.8 Armatura LLC Armatura LLC Armatura One Deserialization of Untrusted Data, Use of Hard-coded Cryptographic Key, Use of Hard-coded Credentials, Insertion of Sensitive Information into Log File Background Critical Infrastructure Sectors: Communications, Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2023-46604 Armatura One embeds Apache ActiveMQ, exposing its OpenWire protocol listener on the network by default. This embedded version is affected by CVE-2023-46604, a deserialization flaw in the OpenWire marshaller that allows an unauthenticated network attacker to trigger deserialization of an arbitrary object graph before authentication is checked. This can result in arbitrary code execution with the highest level of privilege on the host operating system. View CVE Details Affected Products Armatura LLC Armatura One Vendor: Armatura LLC Product Version: Armatura LLC Armatura One: <4.7.2, Armatura LLC Armatura One (USA): <4.6.1 Product Status: known_affected Remediations Vendor fix Armatura LLC Armatura One vers:all/<4.7.2: Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2. Vendor fix Armatura LLC Armatura One (USA) vers:all/<4.6.1: Armatura LLC has released Armatura One V4.6.1_USA, which resolves this CVEs: CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593, CVE-2026-94594. Vendors: Armatura LLC Product Version: Armatura LLC Armatura One: <4, GitHub, Apache.

    Por qué importa

    Las vulnerabilidades permiten la ejecución remota de código con privilegios de sistema y el control total de sistemas de acceso físico, afectando infraestructura crítica.

    Acción recomendada

    Actualice inmediatamente Armatura One a la versión 4.7.2 o superior y aísle los sistemas expuestos de redes públicas hasta completar el parcheo.

    Vendors:Armatura LLCApacheSectores:CommunicationsCritical ManufacturingEnergyTransportation SystemsMITRE:T1190 Exploit Public-Facing ApplicationT1210 Exploitation of Remote ServicesCISO · Vulnerability Management · IT Ops
    Mapeo regulatorio · riesgo 85

    La vulnerabilidad crítica permite ejecución remota de código y control de sistemas de acceso físico, por lo que exige medidas inmediatas de gestión del riesgo y mitigación conforme a NIS2.

    NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
    Publicado
    01 oct 2026, 12:00
    Actualizado
    01 oct 2026, 17:01
    Detectado
    01 oct 2026, 17:01
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2023-46604
    CISA All Alerts
    Prioridad · 59/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <24h (+5 cap)
    hace 15 horas
    Critical VulnsMEDIAAltoNEWDORACRAGDPRInteligencia operacional

    Christine Lagarde: Where AI risks meet

    Where AI risks meet Skip to: Skip to navigation Skip to content Skip to footer EN Български Čeština Dansk Deutsch Eλληνικά English Español Eesti keel Suomi Français Gaeilge Hrvatski Magyar Italiano Lietuvių Latviešu Malti Nederlands Polski Português Română Slovenčina Slovenščina Svenska Menu Monetary policy & markets Monetary policy & markets Our monetary policy strategy, the tools we use and the impact they have Overview of monetary policy and markets Quick links What is monetary policy? Strategy review Asset purchase programmes Latest monetary policy press conference 10 September 2026 Introduction Benefits of price stability Scope of monetary policy Transmission mechanism Decisions, statements & accounts Monetary policy strategy Strategy review Medium-term orientation Two per cent inflation target Economic, monetary and financial analysis Economic analysis Monetary and financial analysis Monetary policy operations Open market operations TLTROs Asset purchase programmes Securities lending Pandemic emergency purchase programme Standing facilities Minimum reserves Two-tier system Euro central bank liquidity lines Swap lines EUREP Chronology of Eurosystem liquidity lines Emergency liquidity assistance (ELA) Liquidity analysis Collateral Eligibility criteria and assessment Marketable assets Non-marketable assets List of eligible marketable assets User guide Collateral management Eligible SSSs Eligible links Eligible triparty agents Risk mitigation ECAF Risk control Haircut categories Valuation Loan-level requirements Contacts Structure of the euro area economy Economic policy Fiscal policies External trade Effective exchange rates Financial structure Financial markets Financial intermediaries Economic diversity Labour market Market contact groups Bond market (BMCG) Money market (MMCG) Debt Issuance Market Contact Group (DIMCG) ECB Operations managers group (ECB OMG) Foreign exchange (FXCG) Institutional Investor Dialogue (IID) Monetary Analysis Contact Group (MACG) Pay DORA relevance: high.

    Por qué importa

    El comunicado del BCE destaca la creciente preocupación regulatoria sobre los riesgos operativos y de resiliencia asociados a la adopción de IA en el sector financiero bajo el marco DORA.

    Acción recomendada

    Revisar la estrategia de gobernanza de IA y asegurar que los riesgos identificados por el BCE estén integrados en el registro de riesgos TIC y el plan de resiliencia operativa.

    Sectores:bankingfinancial_servicesCISO · Vulnerability Management · IT Ops
    Publicado
    01 oct 2026, 13:30
    Actualizado
    01 oct 2026, 16:01
    Detectado
    01 oct 2026, 16:01
    Fuente
    ECB Banking Supervision Press Releases
    Referencia técnica
    Original advisory
    ECB Banking Supervision Press Releases
    Prioridad · 56/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · ECB Banking Supervision Press Releases authority (+8) · updated <24h (+5 cap)
    hace 16 horas
    Critical VulnsMEDIAAltoNEWGDPRInteligencia operacional

    New infosec products of the week: October 2, 2026

    Here’s a look at the most interesting products from the past week, featuring releases from BlackFog, Genea, Vega, and Thales. Vega II brings security-trained AI and lasting memory to the SOC Vega has introduced Vega II, its biggest platform release since emerging from stealth. The update brings frontier AI trained for security operations into the SOC, gives teams a lasting record of what they have learned, and removes the legacy SIEM and data pipeline barriers … More → The post New infosec products of the week: October 2, 2026 appeared first on Help Net Security. CVEs: CVE-2026-76504, CVE-2026-88772. Vendors: Cisco, Google, Citrix. DORA relevance: medium.

    Por qué importa

    Se han reportado nuevas vulnerabilidades asociadas a proveedores críticos (Cisco, Google, Citrix) que requieren validación en el inventario de activos.

    Acción recomendada

    Verificar la presencia de los productos afectados en el inventario y aplicar los parches de seguridad correspondientes según los boletines oficiales de cada proveedor.

    Vendors:CiscoGoogleCitrixCISO · Vulnerability Management · IT Ops
    Publicado
    02 oct 2026, 04:00
    Actualizado
    02 oct 2026, 06:01
    Detectado
    02 oct 2026, 06:01
    Fuente
    Help Net Security
    Referencia técnica
    NVD · CVE-2026-76504
    Help Net Security
    Prioridad · 52/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <24h (+5 cap)
    hace 2 horas