CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)39
Última detecciónhace 3 h
Monitorizado porintelligence scouter
38signals
Acción Requerida
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaMicrosoft118Google75Citrix56Linux45Cisco42WordPress42Cloudflare42MikroTik39F537Check Point

Priority Command Strip

What your team should look at right now

6 señales críticas
  1. Action RequiredImmediate7d

    CISA Adds Two Known Exploited Vulnerabilities to Catalog

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA All Alerts · Microsoft · GitHubReview signal
  2. Action Required
All39Action Required38Exploited & KEV8Critical Vulns1

Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Studio para abrir el feed completo, histórico ampliado y el catálogo KEV.

INMEDIATOCríticoACTION REQUIREDGDPRNIS2Inteligencia operacional

CISA Adds Two Known Exploited Vulnerabilities to Catalog

CISA has added two new vulnerabilities to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-65660 Microsoft SharePoint Code Injection Vulnerability CVE-2026-67279 Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability These types of vulnerabilities are a frequent attack vector for malicious cyber actors and pose significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. CVEs: CVE-2026-65660, CVE-2026-67279. CISA KEV/exploitation signal detected. Vendors: Microsoft, GitHub, MikroTik. DORA relevance: medium.

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

8signals
Explotados & KEV
1signals
Vulns Críticas
Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

37
GitLab37
GitHub36
Apple34
Zyxel30
Immediate
2d

TeamViewer urges users to patch severe flaws “as soon as possible”

Explotación activa confirmada. Riesgo material para entornos expuestos.

BleepingComputer · Microsoft · CiscoReview signal
  • Action RequiredImmediate2d

    Cisco warns of new SD-WAN zero-day exploited in attacks

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    BleepingComputer · Microsoft · CiscoReview signal
  • Action RequiredImmediate2d

    CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    BleepingComputer · Microsoft · CiscoReview signal
  • Action RequiredImmediate4d

    Stolen AI credentials feed growing LLM proxy economy

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CSO Online · Cisco · Palo Alto NetworksReview signal
  • Action RequiredImmediate6d

    CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    BleepingComputer · Microsoft · CiscoReview signal
  • Por qué importa

    CISA ha incorporado dos vulnerabilidades al catálogo KEV con evidencia de explotación activa y severidad crítica, lo que exige priorizar la remediación y evaluar una posible intrusión.

    Acción recomendada

    Comprueba inmediatamente la exposición de CVE-2026-65660 y CVE-2026-67279, aplica las mitigaciones o parches disponibles y realiza una búsqueda de compromiso en los activos afectados.

    Vendors:MicrosoftMikroTikGitHubSectores:public sectorCISO · SecOps · Incident Response · Vulnerability Management
    Mapeo regulatorio · riesgo 70

    La explotación activa de vulnerabilidades críticas exige priorizar su remediación y reforzar las medidas de gestión de riesgos de ciberseguridad conforme a NIS2.

    NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
    Publicado
    25 sept 2026, 12:00
    Actualizado
    25 sept 2026, 18:00
    Detectado
    25 sept 2026, 18:00
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2026-65660
    CISA All Alerts
    Prioridad · 88/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <7d (+3 cap)
    hace 7 días
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    TeamViewer urges users to patch severe flaws “as soon as possible”

    Remote access software company TeamViewer warned customers on Tuesday to immediately patch a set of high-severity vulnerabilities affecting its client and host software. [...] CVEs: CVE-2026-92370, CVE-2026-19743, CVE-2026-92368, CVE-2026-92369, CVE-2026-92371. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Oracle, Apple, Citrix, Atlassian, GitLab, ServiceNow, Zimbra, MikroTik, Cloudflare. DORA relevance: medium.

    Por qué importa

    TeamViewer ha advertido de vulnerabilidades de severidad alta con señal de explotación y presencia en CISA KEV, por lo que los activos afectados requieren remediación inmediata.

    Acción recomendada

    Identifica inmediatamente las instalaciones afectadas de TeamViewer, aplica las actualizaciones disponibles sin esperar al ciclo mensual y valida la exposición o explotación de los activos vulnerables.

    Vendors:TeamViewerMicrosoftCiscoOracleSectores:cloud/SaaSCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    30 sept 2026, 12:25
    Actualizado
    30 sept 2026, 16:01
    Detectado
    30 sept 2026, 16:01
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-92370
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    Cisco warns of new SD-WAN zero-day exploited in attacks

    Cisco released security updates to address a critical zero-day in the Catalyst SD-WAN Manager (tracked as CVE-2026-76504) that attackers are actively exploiting to escalate to admin privileges. [...] CVEs: CVE-2026-76504, CVE-2026-20127, CVE-2026-20182, CVE-2026-20245, CVE-2026-20262. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Oracle, Apple, Citrix, Atlassian, MikroTik, Cloudflare. DORA relevance: medium.

    Por qué importa

    Cisco confirma la explotación activa de una vulnerabilidad crítica de día cero en Catalyst SD-WAN Manager que permite elevar privilegios hasta administrador, con señal de explotación y presencia en CISA KEV.

    Acción recomendada

    Comprueba de inmediato la exposición de los activos afectados, aplica las actualizaciones oficiales de Cisco sin esperar al ciclo mensual, busca indicios de explotación y escala el resultado al CISO.

    Vendors:MicrosoftCiscoOracleAppleSectores:public sectorcloud/SaaSMITRE:T1068 Exploitation for Privilege EscalationCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    30 sept 2026, 14:46
    Actualizado
    30 sept 2026, 16:01
    Detectado
    30 sept 2026, 16:01
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-76504
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    CISA warns of critical pre-auth RCE flaw in MikroTik RouterOS

    The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of a new critical vulnerability in MikroTik RouterOS that could lead to remote code execution or cause a denial-of-service condition. [...] CVEs: CVE-2026-84411, CVE-2026-67276, CVE-2026-86060. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Oracle, Adobe, Apple, Citrix, SonicWall, Atlassian, Linux, Zimbra, MikroTik, Cloudflare. DORA relevance: medium.

    Por qué importa

    CISA ha señalado vulnerabilidades críticas en MikroTik RouterOS con posible ejecución remota de código o denegación de servicio y explotación activa.

    Acción recomendada

    Identifica inmediatamente los activos MikroTik RouterOS afectados, aplica las actualizaciones disponibles, restringe la exposición y realiza una revisión de compromiso el mismo día.

    Vendors:MikroTikSectores:public sectorcloud/SaaSMITRE:T1190 Exploit Public-Facing ApplicationCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    30 sept 2026, 15:49
    Actualizado
    30 sept 2026, 16:01
    Detectado
    30 sept 2026, 16:01
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-84411
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRNIS2AI ACTInteligencia operacional

    Stolen AI credentials feed growing LLM proxy economy

    Cyber threat groups have increasingly targeted enterprise AI assets, such as credentials, cloud environments, and research, as a means for operationalizing their own use of AI. Now, another sophisticated means for obfuscating illegitimate use of AI resources is coming more clearly to light. According to a report last week from security firm Team Cymru, malicious actors are employing proxy servers, known as transfer stations, to hide the origin of traffic to frontier AI models, providing cover for model distillation attacks and potential abuse of stolen AI subscription credentials. Team Cymru researchers initially identified 10,867 such servers running two open-source relay platforms called Claude Relay Service (CRS) and its successor, sub2api. Their investigation later expanded, and the total number of such proxies is now estimated at more than 80,000. “A transfer station breaks the assumption every frontier-model control depends on: that the account making a request belongs to the party consuming the answer,” said Scott Fisher, senior principal engineer at Team Cymru, in the company’s report. “What we have uncovered is an entire ecosystem designed explicitly to break the frontier model providers’ T&Cs, enabling fraud and illicit activity.” These transfer services authenticate customers with their own accounts but connect to upstream AI services using pools of API keys or logged-in consumer subscriptions that in many cases have been obtained through malicious activities such as credential theft. Team Cymru managed to tie several clusters of activity through these proxies to IP addresses in China and Hong Kong. Considering that over half of the transfer gateways are hosted on VPS services in the US, it suggests the intent is to hide the geographic location of the traffic, potentially to enable model distillation attacks, in which targeted prompts are designed to extract model knowledge that is then used to train and improve other AI models. All the frontier labs have CISA KEV/exploitation signal detected. Vendors: Cisco, Palo Alto Networks, Google, AWS, Citrix, F5, GitHub, Okta, Node.js, MikroTik. DORA relevance: high.

    Por qué importa

    Existe una economía activa de proxies que utiliza credenciales y API keys robadas para ocultar el origen del tráfico, abusar de servicios de IA y facilitar posibles ataques de destilación de modelos.

    Acción recomendada

    Revoca y rota inmediatamente las credenciales y API keys expuestas, inspecciona el uso anómalo de servicios de IA y bloquea proxies o relay no autorizados.

    Vendors:CiscoPalo Alto NetworksGoogleAWSSectores:bankingpublic sectorcloud/SaaSretailMITRE:T1078 Valid AccountsT1090 ProxyCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    28 sept 2026, 08:25
    Actualizado
    28 sept 2026, 12:01
    Detectado
    28 sept 2026, 12:01
    Fuente
    CSO Online
    Referencia técnica
    Original advisory
    CSO Online
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 4 días
    INMEDIATOCríticoACTION REQUIREDCRAGDPRInteligencia operacional

    CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

    The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. [...] CVEs: CVE-2026-5430, CVE-2026-71362, CVE-2026-65660, CVE-2026-67279. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Oracle, Adobe, Atlassian, Linux, WordPress, Zimbra, MikroTik. DORA relevance: high.

    Por qué importa

    CISA informa de explotación activa de una vulnerabilidad crítica de bypass de autenticación en productos WSO2 y de otras vulnerabilidades en SharePoint y Adobe Commerce, con señal KEV y posible impacto operativo y regulatorio.

    Acción recomendada

    Comprueba inmediatamente la exposición de todos los CVE afectados, aplica los parches o mitigaciones oficiales fuera del ciclo mensual, revisa indicios de compromiso y escala el estado al CISO.

    Vendors:MicrosoftWSO2AdobeCiscoSectores:bankingpublic sectorhealthcarecloud/SaaSCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    25 sept 2026, 17:24
    Actualizado
    25 sept 2026, 22:01
    Detectado
    25 sept 2026, 22:01
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-5430
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 6 días
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2026-67279 · MikroTik RouterOS: Mikrotik RouterOS Improper Enforcement of Behavioral Workflow Vulnerability

    [CISA KEV actively exploited] Vendor: MikroTik | Product: RouterOS | Mikrotik RouterOS contains an improper enforcement of behavioral workflow vulnerability that could allow an unauthenticated client to open a session channel and send an exec request. This vulnerability can be chained to achieve unauthenticated exploitation of CVE-2026-86060. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-09-28 | Ransomware use: Unknown | Added: 2026-09-25 CVEs: CVE-2026-67279, CVE-2026-86060. CISA KEV/exploitation signal detected. Vendors: MikroTik. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:MikroTikCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    25 sept 2026, 00:00
    Actualizado
    25 sept 2026, 16:00
    Detectado
    25 sept 2026, 16:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-67279
    CISA KEV Catalog
    Prioridad · 78/100published <30d (+10) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12) · updated <7d (+3 cap)
    hace 7 días
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2026-86060 · MikroTik RouterOS: MikroTik RouterOS Improper Neutralization of Argument Delimiters in a Command Vulnerability

    [CISA KEV actively exploited] Vendor: MikroTik | Product: RouterOS | MikroTik RouterOS contains an improper neutralization of argument delimiters in a command vulnerability which allows an attacked to change the trusted RouterOS policy mask, leading to privilege escalation. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-09-13 | Ransomware use: Unknown | Added: 2026-09-10 CVEs: CVE-2026-86060. CISA KEV/exploitation signal detected. Vendors: MikroTik. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:MikroTikCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    10 sept 2026, 00:00
    Actualizado
    10 sept 2026, 20:00
    Detectado
    10 sept 2026, 20:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-86060
    CISA KEV Catalog
    Prioridad · 76/100published <30d (+10) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 22 días