CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)13
Última detecciónhace 2 d
Monitorizado porintelligence scouter
11signals
Acción Requerida
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaMicrosoft123Cisco53Google48GitHub40Apple37Adobe29Check Point19ServiceNow18Siemens17Ivanti

Priority Command Strip

What your team should look at right now

6 señales críticas
  1. Action RequiredImmediate2d

    Hitachi Energy APM Edge Product

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA ICS Advisories · Hitachi Energy Product Version: APM Edge versions 6 · GitHubReview signal
  2. Action RequiredImmediate
All13Action Required11Exploited & KEV3Critical Vulns1Cloud & Identity1

Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Pro para abrir el feed completo, histórico ampliado y el catálogo KEV.

INMEDIATOCríticoACTION REQUIREDGDPRNIS2Inteligencia operacional

Hitachi Energy APM Edge Product

View CSAF Summary Hitachi Energy is aware of Dirty Frag vulnerabilities that affect APM Edge product versions listed in this document. Successful exploitation of these vulnerabilities could result in impact on confidentiality, integrity and availability of the product. Please refer to the Recommended Immediate Actions for information about the mitigation/remediation. The following versions of Hitachi Energy APM Edge Product are affected: APM Edge vers:APM_Edge/<=6.10 (CVE-2026-43284, CVE-2026-43500) CVSS Vendor Equipment Vulnerabilities v3 8.8 Hitachi Energy Hitachi Energy APM Edge Product Write-what-where Condition, Out-of-bounds Write Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-43284 CWE-123: Write-what-where Condition A vulnerability exists in the IPsec ESP subsystem (esp4, esp6) of the Linux kernel used in APM Edge that allows a local unprivileged user to escalate privileges to root. The flaw exists in how the kernel handles memory pages when processing ESP encrypted network packets. An attacker can craft a packet that causes the kernel to decrypt data directly into memory pages it does not own, including the cached copies of privileged operating system binaries. When one of those binaries is executed, the attacker's injected code runs with root privileges. In APM Edge, the vulnerable kernel modules (esp4, esp6) can be loaded by any local user and exploited. View CVE Details Affected Products Hitachi Energy APM Edge Product Vendor: Hitachi Energy Product Version: APM Edge versions 6.10 and prior Product Status: known_affected Remediations Mitigation Disable the esp4 and esp6 modules [2] Relevant CWE: CWE-123 Write-what-where Condition Metrics CVSS Version Base Score Base Severity Vector String 3.1 8.8 HIGH CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H CVE-2026-43500 CWE-787: Out-of-bounds Write A vulnerability exists in the RxRPC protocol im CVEs: CVE-2026-43284, CVE-2026-43500. CISA KEV/exploitation signal detected. Vendors: Hitachi Energy Product Version: APM Edge versions 6, GitHub, Linux, Siemens. DORA relevance: medium.

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

3signals
Explotados & KEV
1signals
Vulns Críticas
Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

También en el Intel CenterCloud & Identity1
16
PHP15
SonicWall15
Fortinet14
Linux13
74d

CVE-2022-0492 · Linux Kernel: Linux Kernel Improper Authentication Vulnerability

Explotación activa confirmada. Riesgo material para entornos expuestos.

CISA KEV Catalog · LinuxReview signal
  • Action RequiredImmediate90d

    CVE-2018-14634 · Linux Kernel: Linux Kernel Integer Overflow Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · LinuxReview signal
  • Action RequiredImmediate90d

    CVE-2025-48703 · CWP Control Web Panel: CWP Control Web Panel OS Command Injection Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · CWP · LinuxReview signal
  • Action RequiredImmediate90d

    CVE-2021-22555 · Linux Kernel: Linux Kernel Heap Out-of-Bounds Write Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · Linux · GoogleReview signal
  • Action RequiredImmediate92d

    CVE-2026-31431 · Linux Kernel: Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

    Severidad crítica con vector accionable a corto plazo.

    CISA KEV (Known Exploited Vulnerabilities) · LinuxReview signal
  • Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-43284, CVE-2026-43500 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:Hitachi Energy Product Version: APM Edge versions 6GitHubLinuxSiemensCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 ago 2026, 12:00
    Actualizado
    13 ago 2026, 18:02
    Detectado
    13 ago 2026, 18:02
    Fuente
    CISA ICS Advisories
    Referencia técnica
    NVD · CVE-2026-43284
    CISA ICS Advisories
    Prioridad · 88/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA ICS Advisories authority (+12) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2022-0492 · Linux Kernel: Linux Kernel Improper Authentication Vulnerability

    [CISA KEV actively exploited] Vendor: Linux | Product: Kernel | Linux Kernel contains an improper authentication vulnerability which could allow for privilege escalation via the cgroups v1 release_agent feature. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2026-06-05 | Ransomware use: Unknown | Added: 2026-06-02 CVEs: CVE-2022-0492. CISA KEV/exploitation signal detected. Vendors: Linux. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Vendors:LinuxCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    02 jun 2026, 00:00
    Actualizado
    02 jun 2026, 19:00
    Detectado
    02 jun 2026, 19:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2022-0492
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 74 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2018-14634 · Linux Kernel: Linux Kernel Integer Overflow Vulnerability

    [CISA KEV actively exploited] Vendor: Linux | Product: Kernel | Linux Kernel contains an integer overflow vulnerability in the create_elf_tables() function which could allow an unprivileged local user with access to SUID (or otherwise privileged) binary to escalate their privileges on the system. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2026-02-16 | Ransomware use: Unknown | Added: 2026-01-26 CVEs: CVE-2018-14634. CISA KEV/exploitation signal detected. Vendors: Linux. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Vendors:LinuxCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    26 ene 2026, 00:00
    Actualizado
    17 may 2026, 13:01
    Detectado
    17 may 2026, 13:01
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2018-14634
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 90 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2025-48703 · CWP Control Web Panel: CWP Control Web Panel OS Command Injection Vulnerability

    [CISA KEV actively exploited] Vendor: CWP | Product: Control Web Panel | CWP Control Web Panel (formerly CentOS Web Panel) contains an OS command Injection vulnerability that allows unauthenticated remote code execution via shell metacharacters in the t_total parameter in a filemanager changePerm request. A valid non-root username must be known. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2025-11-25 | Ransomware use: Unknown | Added: 2025-11-04 CVEs: CVE-2025-48703. CISA KEV/exploitation signal detected. Vendors: CWP. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Vendors:CWPLinuxCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    04 nov 2025, 00:00
    Actualizado
    17 may 2026, 13:01
    Detectado
    17 may 2026, 13:01
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2025-48703
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 90 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2021-22555 · Linux Kernel: Linux Kernel Heap Out-of-Bounds Write Vulnerability

    [CISA KEV actively exploited] Vendor: Linux | Product: Kernel | Linux Kernel contains a heap out-of-bounds write vulnerability that could allow an attacker to gain privileges or cause a DoS (via heap memory corruption) through user name space. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2025-10-27 | Ransomware use: Unknown | Added: 2025-10-06 CVEs: CVE-2021-22555. CISA KEV/exploitation signal detected. Vendors: Linux, Google. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Vendors:LinuxGoogleCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    06 oct 2025, 00:00
    Actualizado
    17 may 2026, 13:01
    Detectado
    17 may 2026, 13:01
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2021-22555
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 90 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2026-31431 · Linux Kernel: Linux Kernel Incorrect Resource Transfer Between Spheres Vulnerability

    [CISA KEV] Linux Kernel contains an incorrect resource transfer between spheres vulnerability that could allow for privilege escalation. | Ransomware use: Unknown | Added: 2026-05-01

    Por qué importa

    Severidad crítica con vector accionable a corto plazo.

    Acción recomendada

    Triage same-day: validar exposición, aplicar mitigación temporal y notificar Incident Response.

    Vendors:LinuxCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    01 may 2026, 00:00
    Actualizado
    15 may 2026, 18:57
    Detectado
    15 may 2026, 18:57
    Fuente
    CISA KEV (Known Exploited Vulnerabilities)
    Referencia técnica
    NVD · CVE-2026-31431
    CISA KEV (Known Exploited Vulnerabilities)
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV (Known Exploited Vulnerabilities) authority (+12)
    hace 92 días
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables &#59394; Aug 07, 2026 Network Security / Vulnerability Security researcher Malcolm Stagg has disclosed a new attack class called&#160; NatJack &#160;that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, expose mapped ports, and exhaust NAT tables. Presented at Black Hat USA 2026 , the research found affected behavior across independently developed imp

    HTML source discovery from thehackernews.com CVEs: CVE-2026-56181, CVE-2026-63913, CVE-2026-50522. CISA KEV/exploitation signal detected. Vendors: Microsoft, Google, AWS, Adobe, Apple, GitLab, GitHub, Linux, Redis. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-56181, CVE-2026-63913, CVE-2026-50522 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:MicrosoftGoogleAWSAdobeCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    n/a
    Actualizado
    08 ago 2026, 08:01
    Detectado
    08 ago 2026, 08:01
    Fuente
    The Hacker News Vulnerability
    Referencia técnica
    NVD · CVE-2026-56181
    The Hacker News Vulnerability
    Prioridad · 65/100active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 7 días
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers &#59394; Aug 07, 2026 Linux / Vulnerability A use-after-free bug in Linux&#39;s SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to escape a container and reach the machine underneath. The flaw has existed since 2008. The fix already shipped: stable kernels 7.1.6, 6.18.42, 6.12.101 and 6.6.148, released August 3, close it. Anyone running an older kernel with SCTP

    HTML source discovery from thehackernews.com CVEs: CVE-2026-64564, CVE-2026-50522. CISA KEV/exploitation signal detected. Vendors: Microsoft, Google, AWS, Adobe, Apple, GitLab, GitHub, Linux, Redis. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-64564, CVE-2026-50522 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:MicrosoftGoogleAWSAdobeCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    n/a
    Actualizado
    08 ago 2026, 08:01
    Detectado
    08 ago 2026, 08:01
    Fuente
    The Hacker News Vulnerability
    Referencia técnica
    NVD · CVE-2026-64564
    The Hacker News Vulnerability
    Prioridad · 65/100active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 7 días