CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)37
Última detecciónhace 3 h
Monitorizado porintelligence scouter
37signals
Acción Requerida
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaMicrosoft118Google75Citrix56Linux45Cisco42WordPress42Cloudflare42MikroTik39F537Check Point

Priority Command Strip

What your team should look at right now

6 señales críticas
  1. Action RequiredImmediate2d

    TeamViewer urges users to patch severe flaws “as soon as possible”

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    BleepingComputer · Microsoft · CiscoReview signal
  2. Action Required
All37Action Required37Exploited & KEV8Critical Vulns0

Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Studio para abrir el feed completo, histórico ampliado y el catálogo KEV.

INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

TeamViewer urges users to patch severe flaws “as soon as possible”

Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...] CVEs: CVE-2026-92370, CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Oracle, Apple, Citrix, Atlassian, GitLab, ServiceNow, Zimbra, MikroTik, Cloudflare. DORA relevance: medium.

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

8signals
Explotados & KEV
Vulns Críticas

Sin CVEs críticas frescas en la ventana actual.

Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

37
GitLab37
GitHub36
Apple34
Zyxel30
Immediate
4d

NetScaler admins told to patch critical zero-days in ADC and Gateway now

Explotación activa confirmada. Riesgo material para entornos expuestos.

CSO Online · Microsoft · GoogleReview signal
  • Action RequiredImmediate6d

    ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

    Severidad crítica con vector accionable a corto plazo.

    BleepingComputer · Microsoft · OracleReview signal
  • Action RequiredImmediate21d

    CVE-2026-85706 · GitLab Community Edition and Enterprise Edition: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · GitLabReview signal
  • Action RequiredImmediate2d

    GitLab Critical Patch Release: 19.0.9, 18.11.12

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    GitLab Security Releases · GitLabReview signal
  • Action RequiredImmediate138d

    CVE-2021-22175 · GitLab GitLab: GitLab Server-Side Request Forgery (SSRF) Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · GitLabReview signal
  • Por qué importa

    TeamViewer ha advertido de vulnerabilidades de severidad alta con señal de explotación y presencia en CISA KEV, por lo que los activos afectados requieren remediación inmediata.

    Acción recomendada

    Identifica inmediatamente las instalaciones afectadas de TeamViewer, aplica las actualizaciones disponibles sin esperar al ciclo mensual y valida la exposición o explotación de los activos vulnerables.

    Vendors:TeamViewerMicrosoftCiscoOracleSectores:cloud/SaaSCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    30 sept 2026, 12:25
    Actualizado
    30 sept 2026, 16:01
    Detectado
    30 sept 2026, 16:01
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-92370
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDHIPAAGDPRNIS2AI ACTInteligencia operacional

    NetScaler admins told to patch critical zero-days in ADC and Gateway now

    Citrix NetScaler ADC and NetScaler Gateway users should take their systems offline and patch them immediately, they were told over the weekend, as news emerged of two critical unauthenticated remote code execution zero-day vulnerabilities in the products under active attack. “Monday will be too late,” watchtower CEO Benjamin Harris wrote in a LinkedIn post on Sunday. Citrix subsequently confirmed the two remotely exploitable vulnerabilities were under attack, and released fixes for both. Affected customers should install the patched versions “as soon as possible,” Citrix wrote in an advisory issued later on Sunday. NetScaler appliances are an important part of many enterprise networks, providing VPN and remote access, load balancing and other application delivery services. Citrix is tracking the two exploited vulnerabilities as CVE-2026-88771 and CVE-2026-88772. It has released fixes in NetScaler ADC and Gateway 14.1-73.37 and later, 13.1-64.23 and later, with corresponding FIPS and NDcPP builds also available. CVE-2026-88771 is a critical remote code execution (RCE) vulnerability in Netscaler ADC and Netscaler Gateway caused by improper input validation. With a CVSS rating of 9.5, it enables unauthenticated attackers to execute arbitrary commands on the appliance. Citrix said all NetScaler ADC and NetScaler Gateway deployments are affected, including default configurations, with no additional feature required to meet the vulnerability’s precondition. It’s barely a month since Citrix patched two other critical security holes in the appliances CVE-2026-88772 also has a CVSS score of 9.5; it involves a memory overflow that can result in remote code execution or denial of service. It requires Datagram Transport Layer Security (DTLS) to be enabled, but Citrix notes that is the case by default on VPN virtual servers, making the condition relevant to many NetScaler Gateway deployments. Citrix said exploitation of both vulnerabilities had been observed on unmitigated deplo CVEs: CVE-2026-88771, CVE-2026-88772, CVE-2026-88773, CVE-2026-88774, CVE-2026-88775. CISA KEV/exploitation signal detected. Vendors: Microsoft, Google, Citrix, GitLab, GitHub. DORA relevance: high.

    Por qué importa

    Dos vulnerabilidades críticas de ejecución remota de código en NetScaler ADC y Gateway están siendo explotadas activamente, afectan configuraciones predeterminadas y pueden comprometer infraestructura VPN y de acceso remoto expuesta a Internet.

    Acción recomendada

    Activa el procedimiento de emergencia, identifica inmediatamente los dispositivos NetScaler expuestos, aíslalos cuando sea posible, aplica las versiones corregidas 14.1-73.37 o posteriores y 13.1-64.23 o posteriores, y busca indicios de compromiso.

    Vendors:CitrixSectores:bankingpublic sectorcloud/SaaSMITRE:T1190 Exploit Public-Facing ApplicationCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    28 sept 2026, 10:02
    Actualizado
    28 sept 2026, 12:01
    Detectado
    28 sept 2026, 12:01
    Fuente
    CSO Online
    Referencia técnica
    NVD · CVE-2026-88771
    CSO Online
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 4 días
    INMEDIATOCríticoACTION REQUIREDCRAGDPRInteligencia operacional

    ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

    The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...] CVEs: CVE-2026-42608. Vendors: Microsoft, Oracle, Adobe, SonicWall, Atlassian, GitLab, WordPress. DORA relevance: high.

    Por qué importa

    Una vulnerabilidad crítica de path traversal no autenticada fue explotada para comprometer y desfigurar el sitio de filtraciones de una banda de ransomware, lo que exige validar exposición y posibles compromisos de activos públicos.

    Acción recomendada

    Comprueba hoy la exposición a CVE-2026-42608, aplica la corrección o mitigación disponible, revisa indicadores de compromiso y escala el resultado al CISO.

    Vendors:MicrosoftOracleAdobeSonicWallSectores:bankinghealthcareMITRE:T1190 Exploit Public-Facing ApplicationCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    25 sept 2026, 20:57
    Actualizado
    25 sept 2026, 22:01
    Detectado
    25 sept 2026, 22:01
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-42608
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 6 días
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2026-85706 · GitLab Community Edition and Enterprise Edition: GitLab Community Edition and Enterprise Edition Path Traversal Vulnerability

    [CISA KEV actively exploited] Vendor: GitLab | Product: Community Edition and Enterprise Edition | GitLab Community Edition and Enterprise Edition contains a path traversal vulnerability that allows an unauthenticated user to read arbitrary files due to an improper path confinement and missing authentication enforcement in the repository commits API. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-09-14 | Ransomware use: Unknown | Added: 2026-09-11 CVEs: CVE-2026-85706. CISA KEV/exploitation signal detected. Vendors: GitLab. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:GitLabCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    11 sept 2026, 00:00
    Actualizado
    11 sept 2026, 20:00
    Detectado
    11 sept 2026, 20:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-85706
    CISA KEV Catalog
    Prioridad · 76/100published <30d (+10) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 21 días
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    GitLab Critical Patch Release: 19.0.9, 18.11.12

    On September 23, 2026, we released versions 19.0.9 and 18.11.12 for GitLab Community Edition (CE) and Enterprise Edition (EE). These versions backport the fixes for two critical vulnerabilities, CVE-2026-85706 and CVE-2026-87719, that were originally patched in 19.3.2, 19.2.6, and 19.1.8 on September 10, 2026. These backports were made available outside of our standard maintenance policy so that self-managed administrators running 18.11 and 19.0 can apply the fixes without first completing a version upgrade. These versions contain no other changes. We strongly recommend that all self-managed GitLab installations still running 18.11 or 19.0 be upgraded to one of these versions immediately. Installations running 19.1, 19.2, or 19.3 should upgrade to 19.1.8, 19.2.6, or 19.3.2 or later instead. GitLab.com is already running the patched version. GitLab Dedicated customers do not need to take action. GitLab releases fixes for vulnerabilities in patch releases. There are two types of patch releases: scheduled releases and ad-hoc critical patches for high-severity vulnerabilities. Scheduled releases are released twice a month on the second and fourth Wednesdays. For more information, please visit our releases handbook and security FAQ. You can see all GitLab release blog posts. For security fixes, the issues detailing each vulnerability are made public on our issue tracker 90 days after the release in which they were patched. We are committed to ensuring that all aspects of GitLab that are exposed to customers or that host customer data are held to the highest security standards. To maintain good security hygiene, it is highly recommended that all customers upgrade to the latest patch release for their supported version. You can read more best practices in securing your GitLab instance in our blog post. Recommended Action We strongly recommend that all installations running a version affected by the issues described below are upgraded to the latest version as soon as possib CVEs: CVE-2026-85706, CVE-2026-87719. CISA KEV/exploitation signal detected. Vendors: GitLab. DORA relevance: medium.

    Por qué importa

    GitLab identifica dos vulnerabilidades críticas con señal de explotación y recomienda actualizar inmediatamente las instalaciones self-managed afectadas.

    Acción recomendada

    Identifica las instancias afectadas y actualízalas inmediatamente a GitLab 18.11.12, 19.0.9, 19.1.8, 19.2.6, 19.3.2 o posteriores según la rama instalada.

    Vendors:GitLabSectores:cloud/SaaStechnologyCISO · SecOps · Incident Response · Vulnerability Management
    Mapeo regulatorio · riesgo 75

    La vulnerabilidad crítica con señal de explotación puede comprometer la seguridad de los datos personales alojados en GitLab y exige aplicar medidas técnicas y organizativas adecuadas, incluida la corrección inmediata.

    GDPR · Art. 32 Security of processing (direct)
    Publicado
    23 sept 2026, 00:00
    Actualizado
    30 sept 2026, 08:01
    Detectado
    30 sept 2026, 08:01
    Fuente
    GitLab Security Releases
    Referencia técnica
    NVD · CVE-2026-85706
    GitLab Security Releases
    Prioridad · 71/100published <30d (+10) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2021-22175 · GitLab GitLab: GitLab Server-Side Request Forgery (SSRF) Vulnerability

    [CISA KEV actively exploited] Vendor: GitLab | Product: GitLab | GitLab contains a server-side request forgery (SSRF) vulnerability when requests to the internal network for webhooks are enabled. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2026-03-11 | Ransomware use: Unknown | Added: 2026-02-18 CVEs: CVE-2021-22175. CISA KEV/exploitation signal detected. Vendors: GitLab. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Vendors:GitLabCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    18 feb 2026, 00:00
    Actualizado
    17 may 2026, 13:01
    Detectado
    17 may 2026, 13:01
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2021-22175
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 138 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2021-39935 · GitLab Community and Enterprise Editions: GitLab Community and Enterprise Editions Server-Side Request Forgery (SSRF) Vulnerability

    [CISA KEV actively exploited] Vendor: GitLab | Product: Community and Enterprise Editions | GitLab Community and Enterprise Editions contain a server-side request forgery vulnerability which could allow unauthorized external users to perform Server Side Requests via the CI Lint API. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2026-02-24 | Ransomware use: Unknown | Added: 2026-02-03 CVEs: CVE-2021-39935. CISA KEV/exploitation signal detected. Vendors: GitLab. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Vendors:GitLabCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    03 feb 2026, 00:00
    Actualizado
    17 may 2026, 13:01
    Detectado
    17 may 2026, 13:01
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2021-39935
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 138 días
    INMEDIATOCríticoACTION REQUIREDISO27001GDPRInteligencia operacional

    Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes &#59394; Oct 02, 2026 Vulnerability / Enterprise Security The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities ( KEV ) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write

    HTML source discovery from thehackernews.com CVEs: CVE-2026-104286, CVE-2026-85102, CVE-2026-93616, CVE-2026-93952, CVE-2026-94127. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Google, Fortinet, Citrix, F5, Zyxel, GitLab, Linux, WordPress, Veeam, MikroTik, Cloudflare, Check Point. DORA relevance: medium.

    Por qué importa

    La vulnerabilidad CVE-2026-104286 en FortiMail está siendo explotada activamente in-the-wild y ha sido incluida en el catálogo KEV de CISA, permitiendo ejecución de escritura de archivos no autenticada.

    Acción recomendada

    Identificar y parchear inmediatamente los dispositivos FortiMail afectados; no esperar al ciclo de mantenimiento regular y realizar triage de seguridad hoy mismo.

    Vendors:FortinetMicrosoftCiscoGoogleSectores:public sectorcloud/SaaSMITRE:T1190 Exploit Public-Facing ApplicationCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    n/a
    Actualizado
    02 oct 2026, 06:00
    Detectado
    02 oct 2026, 06:00
    Fuente
    The Hacker News Vulnerability
    Referencia técnica
    NVD · CVE-2026-104286
    The Hacker News Vulnerability
    Prioridad · 66/100active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <24h (+5 cap)
    hace 3 horas