CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)42
Última detecciónhace 3 h
Monitorizado porintelligence scouter
42signals
Acción Requerida
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaMicrosoft118Google75Citrix56Linux45Cisco42WordPress42Cloudflare42MikroTik39F537Check Point

Priority Command Strip

What your team should look at right now

6 señales críticas
  1. Action RequiredImmediate7d

    CISA Adds One Known Exploited Vulnerability to Catalog

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA All Alerts · GitHub · WordPressReview signal
  2. Action Required
All42Action Required42Exploited & KEV8Critical Vulns0

Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Studio para abrir el feed completo, histórico ampliado y el catálogo KEV.

INMEDIATOCríticoACTION REQUIREDGDPRNIS2Inteligencia operacional

CISA Adds One Known Exploited Vulnerability to Catalog

CISA has added one new vulnerability to its Known Exploited Vulnerabilities (KEV) Catalog, based on evidence of active exploitation. CVE-2026-87902 WordPress Core Remote File Inclusion Vulnerability This type of vulnerability is a frequent attack vector for malicious cyber actors and poses significant risks to the federal enterprise. Binding Operational Directive (BOD) 26-04: Prioritizing Security Updates Based on Risk establishes vulnerability management requirements for Federal Civilian Executive Branch (FCEB) agencies. BOD 26-04 reinforces the importance of the KEV Catalog and requires federal agencies to prioritize rapid remediation of high-risk vulnerabilities, specifically those identified by Common Vulnerabilities and Exposures (CVEs) listed in CISA’s KEV Catalog on publicly exposed assets that grant total control of the asset post-exploitation, while deferring action for lower-risk vulnerabilities. BOD 26-04 further establishes basic expectations for when agencies must check whether threat actors compromised the system before the patch was applied. While BOD 26-04 applies only to FCEB agencies, CISA encourages all organizations to adopt risk-based vulnerability management and prioritize remediation of KEV Catalog vulnerabilities. CISA will continue to add vulnerabilities to the catalog that meet the specified criteria. Aware of an exploited vulnerability not currently listed in the KEV Catalog? Submit it for potential addition through CISA’s KEV Nomination Form. Potential KEV additions must have a CVE ID, evidence of exploitation, and clear mitigation guidance. CVEs: CVE-2026-87902. CISA KEV/exploitation signal detected. Vendors: GitHub, WordPress. DORA relevance: medium.

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

8signals
Explotados & KEV
Vulns Críticas

Sin CVEs críticas frescas en la ventana actual.

Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

37
GitLab37
GitHub36
Apple34
Zyxel30
Immediate
4d

28th September – Threat Intelligence Report

Explotación activa confirmada. Riesgo material para entornos expuestos.

Check Point Research · Microsoft · CiscoReview signal
  • Action RequiredImmediate6d

    CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    BleepingComputer · Microsoft · CiscoReview signal
  • Action RequiredImmediate6d

    Elementor WordPress flaw lets attackers create admin accounts

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    BleepingComputer · Microsoft · OracleReview signal
  • Action RequiredImmediate6d

    ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

    Severidad crítica con vector accionable a corto plazo.

    BleepingComputer · Microsoft · OracleReview signal
  • Action RequiredImmediate7d

    CVE-2026-87902 · WordPress Core: WordPress Core Remote File Inclusion Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · WordPress · GitHubReview signal
  • Por qué importa

    CISA confirmó explotación activa de una vulnerabilidad crítica de inclusión remota de archivos en WordPress y la incorporó al catálogo KEV, lo que exige priorización inmediata y evaluación de posible compromiso.

    Acción recomendada

    Identifica inmediatamente los activos WordPress afectados, aplica la mitigación o actualización disponible, verifica indicios de compromiso y notifica el estado al CISO.

    Vendors:WordPressGitHubSectores:public sectorCISO · SecOps · Incident Response · Vulnerability Management
    Mapeo regulatorio · riesgo 60

    La explotación activa de CVE-2026-87902 exige priorizar la mitigación y verificar el posible compromiso como parte de las medidas de gestión del riesgo de ciberseguridad, aunque no se ha confirmado un incidente en la entidad.

    NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
    Publicado
    25 sept 2026, 12:00
    Actualizado
    25 sept 2026, 20:00
    Detectado
    25 sept 2026, 20:00
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2026-87902
    CISA All Alerts
    Prioridad · 88/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <7d (+3 cap)
    hace 7 días
    INMEDIATOCríticoACTION REQUIREDGDPRAI ACTInteligencia operacional

    28th September – Threat Intelligence Report

    For the latest discoveries in cyber research for the week of 28th September, please download our Threat Intelligence Bulletin. TOP ATTACKS AND BREACHES The FBI has confirmed unauthorized activity affecting FBIjobs.gov after the ShinyHunters group defaced the website. The group claimed to have stolen employee and applicant information and shared samples of purported FBI personnel […] The post 28th September – Threat Intelligence Report appeared first on Check Point Research. CVEs: CVE-2026-85102, CVE-2026-93616, CVE-2026-94127, CVE-2026-87902. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Google, F5, WordPress, PHP, HPE, Check Point. DORA relevance: high.

    Por qué importa

    Se ha detectado explotación activa asociada a CVEs con señal CISA KEV y actividad no autorizada, incluida la desfiguración de FBIjobs.gov y una posible sustracción de datos.

    Acción recomendada

    Verifica inmediatamente la exposición a las CVEs afectadas, prioriza el parcheo fuera del ciclo mensual y valida cualquier indicio de compromiso o exfiltración.

    Vendors:MicrosoftCiscoGoogleF5Sectores:public sectorCISO · SecOps · Incident Response · Vulnerability Management
    Mapeo regulatorio · riesgo 65

    La actividad no autorizada y la posible sustracción de datos de empleados y solicitantes requieren verificar de inmediato la responsabilidad del controlador y la adecuación de las medidas de protección de datos.

    GDPR · Art. 24 Responsibility of the controller (direct) · Art. 25 Data protection by design and by default (direct)
    Publicado
    28 sept 2026, 13:55
    Actualizado
    28 sept 2026, 17:01
    Detectado
    28 sept 2026, 17:01
    Fuente
    Check Point Research
    Referencia técnica
    NVD · CVE-2026-85102
    Check Point Research
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 4 días
    INMEDIATOCríticoACTION REQUIREDCRAGDPRInteligencia operacional

    CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

    The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider WSO2. [...] CVEs: CVE-2026-5430, CVE-2026-71362, CVE-2026-65660, CVE-2026-67279. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Oracle, Adobe, Atlassian, Linux, WordPress, Zimbra, MikroTik. DORA relevance: high.

    Por qué importa

    CISA informa de explotación activa de una vulnerabilidad crítica de bypass de autenticación en productos WSO2 y de otras vulnerabilidades en SharePoint y Adobe Commerce, con señal KEV y posible impacto operativo y regulatorio.

    Acción recomendada

    Comprueba inmediatamente la exposición de todos los CVE afectados, aplica los parches o mitigaciones oficiales fuera del ciclo mensual, revisa indicios de compromiso y escala el estado al CISO.

    Vendors:MicrosoftWSO2AdobeCiscoSectores:bankingpublic sectorhealthcarecloud/SaaSCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    25 sept 2026, 17:24
    Actualizado
    25 sept 2026, 22:01
    Detectado
    25 sept 2026, 22:01
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-5430
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 6 días
    INMEDIATOCríticoACTION REQUIREDCRAGDPRInteligencia operacional

    Elementor WordPress flaw lets attackers create admin accounts

    A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...] CISA KEV/exploitation signal detected. Vendors: Microsoft, Oracle, Adobe, Atlassian, WordPress. DORA relevance: high.

    Por qué importa

    Una vulnerabilidad CSRF crítica en Elementor permite a atacantes no autenticados crear cuentas de administrador y existe una señal de explotación activa/KEV.

    Acción recomendada

    Aplica inmediatamente el parche o mitigación oficial de Elementor, verifica cuentas administrativas creadas recientemente y revisa posibles indicadores de compromiso.

    Vendors:WordPressElementorSectores:bankinghealthcarecloud/SaaSMITRE:T1190 Exploit Public-Facing ApplicationCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    25 sept 2026, 18:13
    Actualizado
    25 sept 2026, 22:01
    Detectado
    25 sept 2026, 22:01
    Fuente
    BleepingComputer
    Referencia técnica
    Original advisory
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 6 días
    INMEDIATOCríticoACTION REQUIREDCRAGDPRInteligencia operacional

    ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

    The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unauthenticated path traversal vulnerability. [...] CVEs: CVE-2026-42608. Vendors: Microsoft, Oracle, Adobe, SonicWall, Atlassian, GitLab, WordPress. DORA relevance: high.

    Por qué importa

    Una vulnerabilidad crítica de path traversal no autenticada fue explotada para comprometer y desfigurar el sitio de filtraciones de una banda de ransomware, lo que exige validar exposición y posibles compromisos de activos públicos.

    Acción recomendada

    Comprueba hoy la exposición a CVE-2026-42608, aplica la corrección o mitigación disponible, revisa indicadores de compromiso y escala el resultado al CISO.

    Vendors:MicrosoftOracleAdobeSonicWallSectores:bankinghealthcareMITRE:T1190 Exploit Public-Facing ApplicationCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    25 sept 2026, 20:57
    Actualizado
    25 sept 2026, 22:01
    Detectado
    25 sept 2026, 22:01
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-42608
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 6 días
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2026-87902 · WordPress Core: WordPress Core Remote File Inclusion Vulnerability

    [CISA KEV actively exploited] Vendor: WordPress | Product: Core | WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-09-28 | Ransomware use: Unknown | Added: 2026-09-25 CVEs: CVE-2026-87902. CISA KEV/exploitation signal detected. Vendors: WordPress, GitHub, PHP. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:WordPressGitHubPHPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    25 sept 2026, 00:00
    Actualizado
    25 sept 2026, 20:00
    Detectado
    25 sept 2026, 20:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-87902
    CISA KEV Catalog
    Prioridad · 78/100published <30d (+10) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12) · updated <7d (+3 cap)
    hace 7 días
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2026-60137 · WordPress Core: WordPress Core SQL Injection Vulnerability

    [CISA KEV actively exploited] Vendor: WordPress | Product: Core | WordPress Core contains a SQL injection vulnerability when a plugin or theme passes untrusted input to the parameter. This vulnerability can be chained with CVE-2026-63030 to allow an unauthenticated attacker to gain remote code execution on default WordPress installations. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-08-04 | Ransomware use: Unknown | Added: 2026-07-21 CVEs: CVE-2026-60137, CVE-2026-63030. CISA KEV/exploitation signal detected. Vendors: WordPress. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:WordPressCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    21 jul 2026, 00:00
    Actualizado
    21 jul 2026, 15:00
    Detectado
    21 jul 2026, 15:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-60137
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 73 días
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2026-63030 · WordPress Core: WordPress Core Interpretation Conflict Vulnerability

    [CISA KEV actively exploited] Vendor: WordPress | Product: Core | WordPress Core contains an interpretation conflict vulnerability that could allow an attacker to perform SQL Injection and achieve Remote Code Execution. This vulnerability can be chained with CVE-2026-60137. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-07-24 | Ransomware use: Unknown | Added: 2026-07-21 CVEs: CVE-2026-63030, CVE-2026-60137. CISA KEV/exploitation signal detected. Vendors: WordPress. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:WordPressCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    21 jul 2026, 00:00
    Actualizado
    21 jul 2026, 15:00
    Detectado
    21 jul 2026, 15:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-63030
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 73 días