CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)111
Última detecciónhace 3 h
Monitorizado porintelligence scouter
86signals
Acción Requerida
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaMicrosoft111Google100Citrix72GitHub67Apple59Cisco52Cloudflare36Linux31WordPress29Mozilla

Priority Command Strip

What your team should look at right now

6 señales críticas
  1. Action RequiredImmediate7h

    Fortinet warns of critical FortiMail flaw exploited in zero-day attacks

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    BleepingComputer · Microsoft · CiscoReview signal
  2. Action Required
All111Action Required86Exploited & KEV8Critical Vulns5Cloud & Identity20
Critical VulnsMEDIAAltoNEWGDPRNIS2Inteligencia operacional

ABB Protection and Control IED Manager PCM600

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are affected: Protection and Control IED Manager PCM600 <=2.14 (CVE-2026-15952, CVE-2026-15953) CVSS Vendor Equipment Vulnerabilities v3 6.4 ABB ABB Protection and Control IED Manager PCM600 Incorrect Permission Assignment for Critical Resource, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-15952 A vulnerability exists in the Scheduler Service installed with PCM600. The service executes under the LocalSystem account while permissions are granted to standard PCM600 users through membership in the local users group. An attacker with local access and valid user credentials may exploit this vulnerability to elevate privileges and obtain control of the affected host. View CVE Details Affected Products ABB Protection and Control IED Manager PCM600 Vendor: ABB Product Version: ABB Protection and Control IED Manager PCM600: <=2.14 Product Status: known_affected Remediations Mitigation ABB recommends the following workaround. Although this workaround does not correct the underlying vulnerability, it reduces the risk of privilege escalation. Mitigation Configure the appropriate ABBPCMSchedulerService instance to run using the same Windows account that is used to operate PCM600: Open Services.msc. Locate the ABBPCMSchedulerService corresponding to the installed PCM600 version. Open Properties and select the Log On tab. The service should be configured to log on with the same Windows user account that is used for the PCM600 application. Ensure that this account has the required "Log on as a service" privilege. Mitigation When authentication is enabled for the IED, the Scheduler CVEs: CVE-2026-15952, CVE-2026-15953. Vendors: ABB Product Version: ABB Protection and Control IED Manager PCM600: <=2, Microsoft, GitHub. DORA relevance: medium.

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

8signals
Explotados & KEV
5signals
Vulns Críticas
Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

También en el Intel CenterCloud & Identity20
28
PHP28
MikroTik26
GitLab23
Check Point21
Immediate
12h

Zero Trust Creator Says Model Holds Firm Against AI-Assisted Attacks

Explotación activa confirmada. Riesgo material para entornos expuestos.

SecurityWeek · Microsoft · ZimbraReview signal
  • Action RequiredImmediate12h

    Give yourself room to be human

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Talos Intelligence Blog · Microsoft · CiscoReview signal
  • Action RequiredImmediate17h

    Zimbra Vulnerability Exploited in the Wild Prior to Public Disclosure

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    SecurityWeek · Microsoft · CiscoReview signal
  • Action RequiredImmediate17h

    Enterprises Struggle to Prepare for AI and Quantum Threats, PwC Says

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    SecurityWeek · Microsoft · GitHubReview signal
  • Action RequiredImmediate17h

    Hacker Conversations: Rob Juncker, a Knock at the Door and a Moral Compass

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    SecurityWeek · Microsoft · VMwareReview signal
  • Por qué importa

    Vulnerabilidades en software de gestión industrial (IED) que permiten escalada de privilegios y manipulación de archivos, afectando la integridad de sistemas críticos de energía.

    Acción recomendada

    Auditar el inventario de activos para identificar versiones de PCM600 <=2.14 y aplicar la mitigación recomendada por el fabricante configurando el servicio con privilegios restringidos.

    Vendors:ABBSectores:EnergyCritical InfrastructureMITRE:T1068 Exploitation for Privilege EscalationCISO · Vulnerability Management · IT Ops
    Mapeo regulatorio · riesgo 60

    La vulnerabilidad afecta software de gestión de sistemas energéticos críticos y requiere gestión de riesgos, mitigación y control de la cadena tecnológica conforme a NIS2, aunque no consta explotación confirmada ni incidente notificable.

    NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
    Publicado
    01 oct 2026, 12:00
    Actualizado
    01 oct 2026, 17:01
    Detectado
    01 oct 2026, 17:01
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2026-15952
    CISA All Alerts
    Prioridad · 59/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <24h (+5 cap)
    hace 16 horas
    Critical VulnsMEDIAAltoNEWGDPRInteligencia operacional

    Some car apps are slipping owners’ data to big tech companies

    The app that comes with your car may be sharing what it knows about you with some of the biggest tech companies. Northeastern University researchers tested 21 vehicles and 30 carmaker apps and found some sending vehicle identification numbers (VINs), email addresses, phone numbers or location data to advertising, tracking and analytics companies. The work was carried out with Consumer Reports, which gave them access to vehicles it had bought for testing. The 21 vehicles … More → The post Some car apps are slipping owners’ data to big tech companies appeared first on Help Net Security. CVEs: CVE-2026-76504, CVE-2026-88772. Vendors: Microsoft, Cisco, Google, Adobe, Citrix, GitHub. DORA relevance: medium.

    Por qué importa

    Investigaciones indican que aplicaciones de vehículos comparten datos personales (PII) con terceros, lo que representa un riesgo de cumplimiento bajo GDPR.

    Acción recomendada

    Auditar el uso de aplicaciones corporativas vinculadas a vehículos y revisar las políticas de privacidad de datos de terceros.

    Vendors:MicrosoftCiscoGoogleAdobeSectores:AutomotiveRetailCISO · Vulnerability Management · IT Ops
    Mapeo regulatorio · riesgo 70

    El intercambio de VIN, correo electrónico, teléfono y ubicación con empresas de publicidad, seguimiento y analítica exige revisar transparencia, privacidad desde el diseño y el registro de actividades de tratamiento conforme al GDPR.

    GDPR · Art. 25 Data protection by design and by default (direct) · Art. 30 Records of processing activities (direct) · Art. 13 Information to be provided where personal data are collected from the data subject (direct)
    Publicado
    01 oct 2026, 09:52
    Actualizado
    01 oct 2026, 11:02
    Detectado
    01 oct 2026, 11:02
    Fuente
    Help Net Security
    Referencia técnica
    NVD · CVE-2026-76504
    Help Net Security
    Prioridad · 52/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <24h (+5 cap)
    hace 22 horas
    Critical VulnsALTACríticoNEWGDPRInteligencia operacional

    ZDI-26-751: Microsoft Windows dxgkrnl Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability

    This vulnerability allows local attackers to escalate privileges on affected installations of Microsoft Windows. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2026-50375. CVEs: CVE-2026-50375. Vendors: Microsoft. DORA relevance: high.

    Por qué importa

    Vulnerabilidad crítica de escalada de privilegios local en el kernel de Windows que permite a un atacante con acceso inicial elevar sus permisos al nivel de sistema.

    Acción recomendada

    Identificar sistemas Windows vulnerables en el inventario y priorizar la aplicación de parches de seguridad de Microsoft en el ciclo de mantenimiento actual.

    Vendors:MicrosoftSectores:bankingMITRE:T1068 Exploitation for Privilege EscalationCISO · Vulnerability Management · IT Ops
    Publicado
    01 oct 2026, 05:00
    Actualizado
    01 oct 2026, 21:00
    Detectado
    01 oct 2026, 21:00
    Fuente
    Zero Day Initiative Advisories
    Referencia técnica
    NVD · CVE-2026-50375
    Zero Day Initiative Advisories
    Prioridad · 49/100published <7d (+25) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <24h (+5 cap)
    hace 12 horas
    Critical VulnsMEDIAAltoNEWNIS2Inteligencia operacional

    Multiples vulnérabilités dans Google Chrome (23 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Google Chrome. Elles permettent à un attaquant de provoquer un problème de sécurité non spécifié par l'éditeur. CVEs: CVE-2026-95274, CVE-2026-95275, CVE-2026-95276, CVE-2026-95277, CVE-2026-95278. Vendors: Microsoft, Google. DORA relevance: medium.

    Por qué importa

    Se han reportado múltiples vulnerabilidades en Google Chrome que podrían permitir la ejecución de código o comprometer la seguridad del navegador.

    Acción recomendada

    Actualizar todas las instancias de Google Chrome y navegadores basados en Chromium a la última versión estable disponible proporcionada por el fabricante.

    Vendors:GoogleMicrosoftMITRE:T1190 Exploit Public-Facing ApplicationCISO · Vulnerability Management · IT Ops
    Mapeo regulatorio · riesgo 5

    La vulnerabilidad crítica del navegador requiere aplicar medidas de gestión del riesgo y remediación, pero no hay evidencia de explotación ni de incidente notificable.

    NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
    Publicado
    23 sept 2026, 00:00
    Actualizado
    01 oct 2026, 16:01
    Detectado
    01 oct 2026, 16:01
    Fuente
    CERT-FR Avis
    Referencia técnica
    NVD · CVE-2026-95274
    CERT-FR Avis
    Prioridad · 32/100published <30d (+10) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <24h (+5 cap)
    hace 17 horas
    Critical VulnsMEDIAAltoNEWNIS2Inteligencia operacional

    Multiples vulnérabilités dans Microsoft Edge (21 septembre 2026)

    De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une élévation de privilèges et un problème de sécurité non spécifié par l'éditeur. CVEs: CVE-2026-91708, CVE-2026-91709, CVE-2026-91710, CVE-2026-91711, CVE-2026-91712. Vendors: Microsoft. DORA relevance: medium.

    Por qué importa

    Un aviso de CERT-FR identifica múltiples vulnerabilidades de severidad alta en Microsoft Edge, incluida una que permite elevación de privilegios, por lo que los sistemas con versiones afectadas deben actualizarse.

    Acción recomendada

    Identifica las versiones afectadas de Microsoft Edge, aplica las actualizaciones oficiales de Microsoft y verifica la instalación mediante inventario o gestión de endpoints.

    Vendors:MicrosoftCISO · Vulnerability Management · IT Ops
    Mapeo regulatorio · riesgo 35

    La vulnerabilidad de alta severidad exige gestionar el riesgo y aplicar parches conforme a NIS2, pero no hay evidencia de explotación activa ni de un incidente significativo que active obligaciones de notificación.

    NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
    Publicado
    21 sept 2026, 00:00
    Actualizado
    30 sept 2026, 16:01
    Detectado
    30 sept 2026, 16:01
    Fuente
    CERT-FR Avis
    Referencia técnica
    NVD · CVE-2026-91708
    CERT-FR Avis
    Prioridad · 31/100published <30d (+10) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días