CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)53
Última detecciónhace 18 h
Monitorizado porintelligence scouter
48signals
Acción Requerida
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaMicrosoft123Cisco53Google48GitHub40Apple37Adobe29Check Point19ServiceNow18Siemens17Ivanti

Priority Command Strip

What your team should look at right now

6 señales críticas
  1. Action RequiredImmediate18h

    Max severity SAP Commerce Cloud flaw now targeted in attacks

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    BleepingComputer · Microsoft · CiscoReview signal
  2. Action Required
All53Action Required48Exploited & KEV3Critical Vulns1Cloud & Identity4

Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Pro para abrir el feed completo, histórico ampliado y el catálogo KEV.

INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

Max severity SAP Commerce Cloud flaw now targeted in attacks

A maximum-severity SAP Commerce Cloud remote code execution vulnerability patched three days ago is already being targeted in attacks, according to threat intelligence company Defused. [...] CVEs: CVE-2026-58231, CVE-2026-44761, CVE-2026-22732, CVE-2026-34263. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, VMware, SAP, Adobe, Node.js. DORA relevance: medium.

Por qué importa

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

3signals
Explotados & KEV
1signals
Vulns Críticas
Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

También en el Intel CenterCloud & Identity4
16
PHP15
SonicWall15
Fortinet14
Linux13
Immediate
3d

CISA Adds Three Known Exploited Vulnerabilities to Catalog

Explotación activa confirmada. Riesgo material para entornos expuestos.

CISA All Alerts · Microsoft · CiscoReview signal
  • Action RequiredImmediate3d

    CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) : Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · CiscoReview signal
  • Action RequiredImmediate2d

    Critical VMware vCenter RCE flaw exploited for reverse SSH access

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    BleepingComputer · Microsoft · CiscoReview signal
  • Action RequiredImmediate2d

    Curiouser and Curiouser

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Talos Intelligence Blog · Microsoft · CiscoReview signal
  • Action RequiredImmediate2d

    Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Help Net Security · Microsoft · CiscoReview signal
  • Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-58231, CVE-2026-44761, CVE-2026-22732 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:MicrosoftCiscoVMwareSAPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    14 ago 2026, 13:45
    Actualizado
    14 ago 2026, 14:02
    Detectado
    14 ago 2026, 14:02
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-58231
    BleepingComputer
    Prioridad · 93/100published <24h (+40) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <24h (+5 cap)
    hace 18 horas
    INMEDIATOCríticoACTION REQUIREDGDPRNIS2Inteligencia operacional

    CISA Adds Three Known Exploited Vulnerabilities to Catalog

    CISA has added three new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-20349 Cisco Secure Firewall Adaptive Security Appliance (ASA) and Firewall Threat Defense (FTD) Heap Inspection Vulnerability CVE-2026-68820 Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability CVE-2026-72898 Metabase SQL Injection Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance CVEs: CVE-2026-20349, CVE-2026-68820, CVE-2026-72898. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, GitHub. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-20349, CVE-2026-68820, CVE-2026-72898 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:MicrosoftCiscoGitHubCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    11 ago 2026, 12:00
    Actualizado
    11 ago 2026, 21:00
    Detectado
    11 ago 2026, 21:00
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2026-20349
    CISA All Alerts
    Prioridad · 88/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <7d (+3 cap)
    hace 3 días
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2026-20349 · Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) : Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) Heap Inspection Vulnerability

    [CISA KEV actively exploited] Vendor: Cisco | Product: Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) | Cisco Secure Firewall Adaptive Security Appliance (ASA) and Secure Firewall Threat Defense (FTD) contain a heap inspection vulnerability that could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-08-14 | Ransomware use: Unknown | Added: 2026-08-11 CVEs: CVE-2026-20349. CISA KEV/exploitation signal detected. Vendors: Cisco. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:CiscoCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    11 ago 2026, 00:00
    Actualizado
    11 ago 2026, 21:00
    Detectado
    11 ago 2026, 21:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-20349
    CISA KEV Catalog
    Prioridad · 88/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12) · updated <7d (+3 cap)
    hace 3 días
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    Critical VMware vCenter RCE flaw exploited for reverse SSH access

    A recently patched critical vulnerability (CVE-2026-59310) in VMware vCenter Syslog Server is being exploited in an active campaign to deploy a reverse SSH tool for persistence and remote access. [...] CVEs: CVE-2026-59310. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, VMware. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-59310 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:MicrosoftCiscoVMwareCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 ago 2026, 16:40
    Actualizado
    13 ago 2026, 18:02
    Detectado
    13 ago 2026, 18:02
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-59310
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    Curiouser and Curiouser

    In this edition of the Threat Source newsletter, William reflects on the “Make Hazel a Hacker” segment in Beers with Talos, and how cybersecurity is a field where questions can lead to multiple correct answers. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Adobe. DORA relevance: high.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Prioriza la remediación por explotación in-the-wild; no esperes al ciclo mensual de parcheo.

    Vendors:MicrosoftCiscoAdobeCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 ago 2026, 18:00
    Actualizado
    13 ago 2026, 18:02
    Detectado
    13 ago 2026, 18:02
    Fuente
    Talos Intelligence Blog
    Referencia técnica
    Original advisory
    Talos Intelligence Blog
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349)

    A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog and needs to be remediated by US civilian federal agencies by August 14, 2026. Details about the attacks are currently under wraps. Cisco only shared that its Product Security Incident Response Team (PSIRT) became aware of active exploitation of this vulnerability in August … More → The post Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349) appeared first on Help Net Security. CVEs: CVE-2026-20349, CVE-2026-68820. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Salesforce, ServiceNow. DORA relevance: high.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-20349, CVE-2026-68820 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:MicrosoftCiscoSalesforceServiceNowCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 ago 2026, 07:30
    Actualizado
    13 ago 2026, 09:02
    Detectado
    13 ago 2026, 09:02
    Fuente
    Help Net Security
    Referencia técnica
    NVD · CVE-2026-20349
    Help Net Security
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    Hackers exploit critical Adobe Commerce flaw to hijack customer accounts

    Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe's Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. [...] CVEs: CVE-2026-71362, CVE-2026-48414, CVE-2026-48413, CVE-2026-48415, CVE-2026-48416. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Google, Adobe, SonicWall, Salesforce, ServiceNow. DORA relevance: high.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-71362, CVE-2026-48414, CVE-2026-48413 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:MicrosoftCiscoGoogleAdobeCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    12 ago 2026, 20:54
    Actualizado
    13 ago 2026, 00:02
    Detectado
    13 ago 2026, 00:02
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-71362
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    Lazarus hackers exploited Windows zero-day to target defense firms

    North Korean hackers have been exploiting a Windows zero-day vulnerability (CVE-2026-68820) to target defense-sector companies as part of the Operation Dream Job campaign. [...] CVEs: CVE-2026-68820, CVE-2025-49113. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Google, SonicWall, Mozilla, PHP, Check Point. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-68820, CVE-2025-49113 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:MicrosoftCiscoGoogleSonicWallCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    12 ago 2026, 15:38
    Actualizado
    12 ago 2026, 19:01
    Detectado
    12 ago 2026, 19:01
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-68820
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 3 días