CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 24h
Señales (ventana)21
Última detecciónhace 16 h
Monitorizado porintelligence scouter
21signals
Acción Requerida
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaMicrosoft58Cisco21Google15Apple13Adobe10Fortinet10PHP8Oracle7VMware6Ivanti6

Priority Command Strip

What your team should look at right now

6 señales críticas
  1. Action RequiredImmediate16h

    Max severity SAP Commerce Cloud flaw now targeted in attacks

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    BleepingComputer · Microsoft · CiscoReview signal
  2. Action Required
All21Action Required21Exploited & KEV3Critical Vulns0

Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Pro para abrir el feed completo, histórico ampliado y el catálogo KEV.

INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

Max severity SAP Commerce Cloud flaw now targeted in attacks

A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. [...] CVEs: CVE-2026-58231, CVE-2026-44761, CVE-2026-22732, CVE-2026-34263. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, VMware, SAP, Adobe, Node.js. DORA relevance: medium.

Por qué importa

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

3signals
Explotados & KEV
Vulns Críticas

Sin CVEs críticas frescas en la ventana actual.

Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

Linux5
Synacor5
Zimbra5
SonicWall4
Immediate
3d

CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) : Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

Explotación activa confirmada. Riesgo material para entornos expuestos.

CISA KEV Catalog · CiscoReview signal
  • Action RequiredImmediate16d

    CVE-2026-20316 · Cisco Secure Firewall Management Center (FMC): Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · CiscoReview signal
  • Action RequiredImmediate32d

    CVE-2008-4128 · Cisco IOS: Cisco IOS Cross-Site Request Forgery Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · Cisco · AppleReview signal
  • Action RequiredImmediate50d

    CVE-2026-20230 · Cisco Unified Communications Manager: Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · CiscoReview signal
  • Action RequiredImmediate60d

    CVE-2026-20262 · Cisco Catalyst SD-WAN Manager: Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · CiscoReview signal
  • Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-58231, CVE-2026-44761, CVE-2026-22732 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:MicrosoftCiscoVMwareSAPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    14 ago 2026, 13:45
    Actualizado
    14 ago 2026, 14:02
    Detectado
    14 ago 2026, 14:02
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-58231
    BleepingComputer
    Prioridad · 93/100published <24h (+40) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <24h (+5 cap)
    hace 16 horas
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) : Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

    [CISA KEV actively exploited] Vendor: Cisco | Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-08-14 | Ransomware use: Unknown | Added: 2026-08-11 CVEs: CVE-2026-20349. CISA KEV/exploitation signal detected. Vendors: Cisco. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:CiscoCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    11 ago 2026, 00:00
    Actualizado
    11 ago 2026, 21:00
    Detectado
    11 ago 2026, 21:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-20349
    CISA KEV Catalog
    Prioridad · 88/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12) · updated <7d (+3 cap)
    hace 3 días
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2026-20316 · Cisco Secure Firewall Management Center (FMC): Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

    [CISA KEV actively exploited] Vendor: Cisco | Product: Secure Firewall Management Center (FMC) | Cisco Secure Firewall Management Center (FMC) formerly known as Firepower Management Center contains a use of hard-coded password vulnerability that could allow an unauthenticated, remote attacker to log in to an affected device using a low-privileged account to access sensitive data within the impacted systems. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-08-01 | Ransomware use: Unknown | Added: 2026-07-29 CVEs: CVE-2026-20316. CISA KEV/exploitation signal detected. Vendors: Cisco. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:CiscoCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    29 jul 2026, 00:00
    Actualizado
    29 jul 2026, 19:00
    Detectado
    29 jul 2026, 19:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-20316
    CISA KEV Catalog
    Prioridad · 76/100published <30d (+10) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 16 días
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2008-4128 · Cisco IOS: Cisco IOS Cross-Site Request Forgery Vulnerability

    [CISA KEV actively exploited] Vendor: Cisco | Product: IOS | Cisco IOS 12.4 contains multiple cross-site forgery vulnerabilities that allows remote attackers to execute arbitrary commands via (1) a certain "show privilege" command to the /level/15/exec/- URI, and (2) a certain "alias exec" command to the /level/15/exec/-/configure/http URI. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-07-16 | Ransomware use: Unknown | Added: 2026-07-13 CVEs: CVE-2008-4128. CISA KEV/exploitation signal detected. Vendors: Cisco, Apple. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:CiscoAppleCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 jul 2026, 00:00
    Actualizado
    13 jul 2026, 19:00
    Detectado
    13 jul 2026, 19:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2008-4128
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 32 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2026-20230 · Cisco Unified Communications Manager: Cisco Unified Communications Manager Server-Side Request Forgery (SSRF) Vulnerability

    [CISA KEV actively exploited] Vendor: Cisco | Product: Unified Communications Manager | Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) contain a server-side request forgery (SSRF) Vulnerability that could allow an unauthenticated, remote attacker to write files to the underlying operating system that could be used later to elevate to root. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-06-28 | Ransomware use: Unknown | Added: 2026-06-25 CVEs: CVE-2026-20230. CISA KEV/exploitation signal detected. Vendors: Cisco. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:CiscoCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    25 jun 2026, 00:00
    Actualizado
    25 jun 2026, 20:00
    Detectado
    25 jun 2026, 20:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-20230
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 50 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2026-20262 · Cisco Catalyst SD-WAN Manager: Cisco Catalyst SD-WAN Manager Directory or Path Traversal Vulnerability

    [CISA KEV actively exploited] Vendor: Cisco | Product: Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager contains a directory or path traversal vulnerability that could allow an authenticated, remote attacker to create a file or overwrite any file on the filesystem of an affected system. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-06-29 | Ransomware use: Unknown | Added: 2026-06-15 CVEs: CVE-2026-20262. CISA KEV/exploitation signal detected. Vendors: Cisco. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:CiscoCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    15 jun 2026, 00:00
    Actualizado
    15 jun 2026, 20:00
    Detectado
    15 jun 2026, 20:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-20262
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 60 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2026-20245 · Cisco Catalyst SD-WAN Manager: Cisco Catalyst SD-WAN Manager Improper Encoding or Escaping of Output Vulnerability

    [CISA KEV actively exploited] Vendor: Cisco | Product: Catalyst SD-WAN Manager | Cisco Catalyst SD-WAN Manager formerly SD-WAN vManage contains an improper encoding or escaping of output vulnerability. This vulnerability could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to the affected system. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2026-06-23 | Ransomware use: Unknown | Added: 2026-06-09 CVEs: CVE-2026-20245. CISA KEV/exploitation signal detected. Vendors: Cisco. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Vendors:CiscoCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    09 jun 2026, 00:00
    Actualizado
    09 jun 2026, 19:00
    Detectado
    09 jun 2026, 19:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-20245
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 66 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2026-20122 · Cisco Catalyst SD-WAN Manger: Cisco Catalyst SD-WAN Manager Incorrect Use of Privileged APIs Vulnerability

    [CISA KEV actively exploited] Vendor: Cisco | Product: Catalyst SD-WAN Manger | Cisco Catalyst SD-WAN Manager contains an incorrect use of privileged APIs vulnerability due to improper file handling on the API interface of an affected system. An attacker could exploit this vulnerability by uploading a malicious file on the local file system. A successful exploit could allow the attacker to overwrite arbitrary files on the affected system and gain vmanage user privileges. | Required action: Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available. | Due date: 2026-04-23 | Ransomware use: Unknown | Added: 2026-04-20 CVEs: CVE-2026-20122. CISA KEV/exploitation signal detected. Vendors: Cisco. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Please adhere to CISA’s guidelines to assess exposure and mitigate risks associated with Cisco SD-WAN devices as outlines in CISA’s Emergency Directive 26-03 (URL listed below in Notes) and CISA’s “Hunt & Hardening Guidance for Cisco SD-WAN Devices (URL listed below in Notes). Adhere to the applicable BOD 22-01 guidance for cloud services or discontinue use of the product if mitigations are not available.

    Vendors:CiscoCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    20 abr 2026, 00:00
    Actualizado
    17 may 2026, 13:01
    Detectado
    17 may 2026, 13:01
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-20122
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 90 días