Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.
Para análisis editorial y noticias generales visita Noticias.
Sin señales activamente explotadas ni parches de emergencia.
Priority Command Strip
Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Pro para abrir el feed completo, histórico ampliado y el catálogo KEV.
Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →
Sin nuevos advisories PSIRT de vendor en la ventana.
Akira ransomware affiliates were seen using a new technique to evade endpoint detection and response (EDR), where they rebooted a compromised Windows system into Safe Mode with Networking enabled. According to Huntress, the technique successfully took both its agent and Microsoft Defender’s real-time protection offline. This, the researchers said, gave the attacker a window to operate without endpoint defenses. The incident investigated by Huntress began on August 4 with a credential-spraying attack against an exposed SonicWall SSL VPN. About seven minutes after the failed login attempts began, an attacker successfully authenticated to an account that did not have multi-factor authentication (MFA) enabled, Huntress analyst James Northey said in a blog post. Two hours after authentication was managed, the operator reportedly accessed the domain controller over RDP, performed extensive Active Directory enumeration, and subsequently moved to an application server to archive mapped file shares with WinRAR. The stolen data was uploaded to an attacker-controlled S3 bucket using s5cmd, establishing the data-theft component of a double-extortion attack. Ultimately, AnyDesk was installed on the host machine for persistent remote access and to deliver the Akira ransomware payload. This is when the operator used “msconfig.exe” to force the machine into Safe Mode with Networking, instead of disabling EDR directly. Huntress says this is the first time it has observed Akira using the technique. Safe Mode is becoming a popular ransomware technique Safe Mode is normally a Windows troubleshooting environment that loads only essential drivers and services. That makes it useful to attackers because many third-party security products are excluded from the minimal startup configuration. Anticipating that AnyDesk itself might also be unavailable in Safe Mode, the attackers modified the Safe Boot registry configuration to ensure the remote-access service would start. The approach is not e Vendors: Microsoft, Google, AWS, Oracle, SonicWall, Atlassian, GitHub. DORA relevance: high.
Por qué importa
Explotación reportada sobre Microsoft / Google. Verificar exposición real en el inventario.
Acción recomendada
Avisa a los owners de los stacks Microsoft, Google, AWS, Oracle.
Group-IB researchers discovered WindRelay, a new Android malware built to capture live payment card data over NFC (Near Field Communication) and relay it to attackers in real time. WindRelay is paired with the SpyNote remote access trojan, which gives attackers remote access to a victim’s device. Attack chain overview (Source: Group-IB) How the scam unfolds The scam starts with a phone call, in which the fraudster claims to be from the victim’s bank and says … More → The post New Android malware relays bank cards to fraudsters while victims still hold them appeared first on Help Net Security. CVEs: CVE-2026-20349, CVE-2026-68820. Vendors: Microsoft, Cisco, Google, Salesforce, ServiceNow. DORA relevance: high.
Por qué importa
CVE de alto impacto sobre Microsoft / Cisco. Planificar ventana de parche.
Acción recomendada
Comprueba la exposición a CVE-2026-20349, CVE-2026-68820 en el inventario de activos y las herramientas de vulnerabilidades.
Ukrainian police have disrupted 94 fraudulent call centers during a nationwide operation that involved more than 400 searches and the seizure of thousands of computers, phones, and SIM cards. Ukrainian police raid at a fraudulent call center (Source: Cyberpolice Ukraine) The call centers were linked to schemes involving callers impersonating bank employees, fraudulent investment services, cryptocurrency platforms, and attempts to gain remote access to victims’ devices. Some groups collected personal information about prospective victims and … More → The post Ukrainian police raid 94 fraudulent call centers, seize $2 million appeared first on Help Net Security. CVEs: CVE-2026-20349, CVE-2026-68820. Vendors: Microsoft, Cisco, Salesforce, ServiceNow. DORA relevance: high.
Por qué importa
CVE de alto impacto sobre Microsoft / Cisco. Planificar ventana de parche.
Acción recomendada
Comprueba la exposición a CVE-2026-20349, CVE-2026-68820 en el inventario de activos y las herramientas de vulnerabilidades.
Organizations expect AI agents to change how work gets done, driving productivity and growth while allowing employees to focus on higher-value tasks. Few, however, have the processes and workflows needed to realize those benefits, according to Deloitte’s latest research. Preparing the operating model for AI agents About half of surveyed leaders say they understand how AI agents will affect their future operating model. Three main challenges limit wider adoption: the lack of a unified and … More → The post The hardest part of agentic AI may be rebuilding the business appeared first on Help Net Security. CVEs: CVE-2026-20349, CVE-2026-68820. Vendors: Microsoft, Cisco, Salesforce, ServiceNow. DORA relevance: high.
Por qué importa
CVE de alto impacto sobre Microsoft / Cisco. Planificar ventana de parche.
Acción recomendada
Comprueba la exposición a CVE-2026-20349, CVE-2026-68820 en el inventario de activos y las herramientas de vulnerabilidades.
De multiples vulnérabilités ont été découvertes dans Microsoft .Net. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance. CVEs: CVE-2026-58641, CVE-2026-62871, CVE-2026-62872, CVE-2026-62886, CVE-2026-62897. Vendors: Microsoft. DORA relevance: medium.
Por qué importa
CVE de alto impacto sobre Microsoft. Planificar ventana de parche.
Acción recomendada
Comprueba la exposición a CVE-2026-58641, CVE-2026-62871, CVE-2026-62872 en el inventario de activos y las herramientas de vulnerabilidades.
De multiples vulnérabilités ont été découvertes dans Microsoft Windows. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et un déni de service à distance. Microsoft indique que la vulnérabilité CVE-2026-68820... CVEs: CVE-2026-68820, CVE-2026-42976, CVE-2026-49179, CVE-2026-50472, CVE-2026-54113. Vendors: Microsoft. DORA relevance: medium.
Por qué importa
CVE de alto impacto sobre Microsoft. Planificar ventana de parche.
Acción recomendada
Comprueba la exposición a CVE-2026-68820, CVE-2026-42976, CVE-2026-49179 en el inventario de activos y las herramientas de vulnerabilidades.
De multiples vulnérabilités ont été découvertes dans Microsoft Office. Certaines d'entre elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance, une élévation de privilèges et une atteinte à la confidentialité des données. CVEs: CVE-2026-58651, CVE-2026-62842, CVE-2026-62882, CVE-2026-63513, CVE-2026-63515. Vendors: Microsoft. DORA relevance: medium.
Por qué importa
CVE de alto impacto sobre Microsoft. Planificar ventana de parche.
Acción recomendada
Comprueba la exposición a CVE-2026-58651, CVE-2026-62842, CVE-2026-62882 en el inventario de activos y las herramientas de vulnerabilidades.
De multiples vulnérabilités ont été découvertes dans Microsoft Edge. Elles permettent à un attaquant de provoquer une exécution de code arbitraire à distance et un problème de sécurité non spécifié par l'éditeur. CVEs: CVE-2026-19137, CVE-2026-19138, CVE-2026-19139, CVE-2026-19140, CVE-2026-19142. Vendors: Microsoft. DORA relevance: medium.
Por qué importa
CVE de alto impacto sobre Microsoft. Planificar ventana de parche.
Acción recomendada
Comprueba la exposición a CVE-2026-19137, CVE-2026-19138, CVE-2026-19139 en el inventario de activos y las herramientas de vulnerabilidades.