CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)45
Última detecciónhace 3 h
Monitorizado porintelligence scouter
45signals
Acción Requerida
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaMicrosoft118Google75Citrix56Linux45Cisco42WordPress42Cloudflare42MikroTik39F537Check Point

Priority Command Strip

What your team should look at right now

6 señales críticas
  1. Action RequiredImmediate2d

    Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    SecurityWeek · Microsoft · GoogleReview signal
  2. Action Required
All45Action Required45Exploited & KEV8Critical Vulns0

Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Studio para abrir el feed completo, histórico ampliado y el catálogo KEV.

INMEDIATOCríticoACTION REQUIREDGDPRNIS2AI ACTInteligencia operacional

Google: AI Is Changing the Pace and Profile of Vulnerability Discovery

Google’s analysis found that AI-discovered vulnerabilities are more likely to enable remote code execution. The post Google: AI Is Changing the Pace and Profile of Vulnerability Discovery appeared first on SecurityWeek. CVEs: CVE-2026-1731, CVE-2026-65660. CISA KEV/exploitation signal detected. Vendors: Microsoft, Google, Apple, Citrix, Linux, Mozilla, OpenSSL, WatchGuard. DORA relevance: medium.

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

8signals
Explotados & KEV
Vulns Críticas

Sin CVEs críticas frescas en la ventana actual.

Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

37
GitLab37
GitHub36
Apple34
Zyxel30
Immediate
2d

CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

Explotación activa confirmada. Riesgo material para entornos expuestos.

BleepingComputer · Microsoft · CiscoReview signal
  • Action RequiredImmediate2d

    Hackers exploit Citrix NetScaler zero-day to deploy web shells

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    BleepingComputer · Microsoft · GoogleReview signal
  • Action RequiredImmediate6d

    CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    BleepingComputer · Microsoft · CiscoReview signal
  • Action RequiredImmediate14d

    CVE-2025-39682 · Linux Kernel: Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · LinuxReview signal
  • Action RequiredImmediate14d

    CVE-2025-39964 · Linux Kernel: Linux Kernel Race Condition Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · LinuxReview signal
  • Por qué importa

    Señal crítica con explotación indicada en CISA KEV y posible capacidad de ejecución remota de código, por lo que requiere priorización y triage el mismo día.

    Acción recomendada

    Verifica inmediatamente la exposición a CVE-2026-1731 y CVE-2026-65660, identifica los activos afectados y aplica las mitigaciones o parches disponibles fuera del ciclo mensual.

    Vendors:MicrosoftGoogleAppleCitrixSectores:insurancepublic sectorcloud/SaaSCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    30 sept 2026, 14:05
    Actualizado
    30 sept 2026, 16:01
    Detectado
    30 sept 2026, 16:01
    Fuente
    SecurityWeek
    Referencia técnica
    NVD · CVE-2026-1731
    SecurityWeek
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. [...] CVEs: CVE-2026-84411, CVE-2026-67276, CVE-2026-86060. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Oracle, Adobe, Apple, Citrix, SonicWall, Atlassian, Linux, Zimbra, MikroTik, Cloudflare. DORA relevance: medium.

    Por qué importa

    CISA ha señalado vulnerabilidades críticas en MikroTik RouterOS con posible ejecución remota de código o denegación de servicio y explotación activa.

    Acción recomendada

    Identifica inmediatamente los activos MikroTik RouterOS afectados, aplica las actualizaciones disponibles, restringe la exposición y realiza una revisión de compromiso el mismo día.

    Vendors:MikroTikSectores:public sectorcloud/SaaSMITRE:T1190 Exploit Public-Facing ApplicationCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    30 sept 2026, 15:49
    Actualizado
    30 sept 2026, 16:01
    Detectado
    30 sept 2026, 16:01
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-84411
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    Hackers exploit Citrix NetScaler zero-day to deploy web shells

    Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. [...] CVEs: CVE-2026-88772, CVE-2026-88771. CISA KEV/exploitation signal detected. Vendors: Microsoft, Google, Oracle, Apple, Citrix, Atlassian, Linux, PHP, Python, Cloudflare. DORA relevance: medium.

    Por qué importa

    Explotación activa de un zero-day en Citrix NetScaler que permite acceso root, robo de credenciales y movimiento lateral en la red interna.

    Acción recomendada

    Identificar y parchear inmediatamente todos los dispositivos Citrix NetScaler expuestos; buscar indicadores de compromiso (web shells) en los logs del sistema.

    Vendors:CitrixSectores:public sectorcloud/SaaSMITRE:T1190 Exploit Public-Facing ApplicationT1505.003 Server Software Component: Web ShellT1078 Valid AccountsCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    29 sept 2026, 18:37
    Actualizado
    29 sept 2026, 22:01
    Detectado
    29 sept 2026, 22:01
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-88772
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDCRAGDPRInteligencia operacional

    CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

    The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. [...] CVEs: CVE-2026-5430, CVE-2026-71362, CVE-2026-65660, CVE-2026-67279. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Oracle, Adobe, Atlassian, Linux, WordPress, Zimbra, MikroTik. DORA relevance: high.

    Por qué importa

    CISA informa de explotación activa de una vulnerabilidad crítica de bypass de autenticación en productos WSO2 y de otras vulnerabilidades en SharePoint y Adobe Commerce, con señal KEV y posible impacto operativo y regulatorio.

    Acción recomendada

    Comprueba inmediatamente la exposición de todos los CVE afectados, aplica los parches o mitigaciones oficiales fuera del ciclo mensual, revisa indicios de compromiso y escala el estado al CISO.

    Vendors:MicrosoftWSO2AdobeCiscoSectores:bankingpublic sectorhealthcarecloud/SaaSCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    25 sept 2026, 17:24
    Actualizado
    25 sept 2026, 22:01
    Detectado
    25 sept 2026, 22:01
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-5430
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 6 días
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2025-39682 · Linux Kernel: Linux Kernel Improper Check for Unusual or Exceptional Conditions Vulnerability

    [CISA KEV actively exploited] Vendor: Linux | Product: Kernel | Linux Kernel contains an improper check for unusual or exceptional conditions vulnerability in the TLS receive path which allows a zero-length record retrieved from the rx_list to bypass the intended recvmsg() record-type handling, potentially causing subsequent TLS records to be processed using incorrect zero-copy and queuing assumptions. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-09-21 | Ransomware use: Unknown | Added: 2026-09-18 CVEs: CVE-2025-39682. CISA KEV/exploitation signal detected. Vendors: Linux. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:LinuxCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    18 sept 2026, 00:00
    Actualizado
    18 sept 2026, 21:00
    Detectado
    18 sept 2026, 21:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2025-39682
    CISA KEV Catalog
    Prioridad · 76/100published <30d (+10) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 14 días
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2025-39964 · Linux Kernel: Linux Kernel Race Condition Vulnerability

    [CISA KEV actively exploited] Vendor: Linux | Product: Kernel | Linux Kernel contains a race condition vulnerability which allows concurrent writes to the same AF_ALG socket causing data to be unpredictably interleaved and creating inconsistencies in the socket's internal state. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-09-21 | Ransomware use: Unknown | Added: 2026-09-18 CVEs: CVE-2025-39964. CISA KEV/exploitation signal detected. Vendors: Linux. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:LinuxCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    18 sept 2026, 00:00
    Actualizado
    18 sept 2026, 15:00
    Detectado
    18 sept 2026, 15:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2025-39964
    CISA KEV Catalog
    Prioridad · 76/100published <30d (+10) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 14 días
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2026-53266 · Linux Kernel: Linux Kernel Out-of-Bounds Write Vulnerability

    [CISA KEV actively exploited] Vendor: Linux | Product: Kernel | Linux Kernel contains an out-of-bounds write vulnerability in the ebtables SNAT target which allows an ARP sender hardware address rewrite to write directly into a nonlinear socket-buffer fragment backed by a splice-imported file page. The impacted product(s) could be end-of-life (EoL) and/or end-of-service (EoS). Users are advised to discontinue use and/or transition to a supported version. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-09-21 | Ransomware use: Unknown | Added: 2026-09-18 CVEs: CVE-2026-53266. CISA KEV/exploitation signal detected. Vendors: Linux. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:LinuxCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    18 sept 2026, 00:00
    Actualizado
    18 sept 2026, 15:00
    Detectado
    18 sept 2026, 15:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-53266
    CISA KEV Catalog
    Prioridad · 76/100published <30d (+10) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 14 días
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2026-53362 · Linux Kernel: Linux Kernel Unspecified Vulnerability

    [CISA KEV actively exploited] Vendor: Linux | Product: Kernel | Linux Kernel contains an unspecified vulnerability that can allow for privilege escalation via IPv6 networking subsystem. This vulnerability can impact multiple products, including but not limited to Suse, Red Hat, and other products using Linux. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-08-30 | Ransomware use: Unknown | Added: 2026-08-27 CVEs: CVE-2026-53362. CISA KEV/exploitation signal detected. Vendors: Linux. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:LinuxCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    27 ago 2026, 00:00
    Actualizado
    27 ago 2026, 18:00
    Detectado
    27 ago 2026, 18:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-53362
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 36 días