CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)43
Última detecciónhace 17 h
Monitorizado porintelligence scouter
Acción Requerida

Sin señales activamente explotadas ni parches de emergencia.

8signals
Explotados & KEV
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaGoogle70Citrix57Microsoft48GitHub46Apple43Oracle26Mozilla19Kubernetes18Cisco17Atlassian
✓

No priority signals demanding immediate attention.

La cola operativa está limpia en esta ventana. El scouter sigue monitorizando.

All43Action Required0Exploited & KEV8Critical Vulns6Cloud & Identity36Monitor1

Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Studio para abrir el feed completo, histórico ampliado y el catálogo KEV.

Critical VulnsMEDIAAltoNEWGDPRInteligencia operacional

Most organizations need six months or longer to roll out new security controls

Cisco surveyed 8,000 security professionals in 30 markets about how well their organizations defend against AI-era threats, and only 8% landed in the top group. Cisco gave the most weight in its scoring to internal friction, meaning the delays and turf problems inside a company that slow a security team when something changes. Cisco says frontier AI models can find software vulnerabilities at a scale and speed no human team working alone can match. Fewer … More → The post Most organizations need six months or longer to roll out new security controls appeared first on Help Net Security. CVEs: CVE-2026-88771, CVE-2026-86950. Vendors: Cisco, Apple, Citrix. DORA relevance: medium.

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

6signals
Vulns Críticas
Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

También en el Intel CenterCloud & Identity36Monitor1
14
Cloudflare14
WordPress14
PHP14
Apache11

Por qué importa

El informe evidencia retrasos prolongados en la adopción de controles de seguridad y referencia dos CVE que requieren validación en activos Cisco, Apple y Citrix, pero no aporta evidencia de explotación activa ni detalles técnicos suficientes para una acción inmediata.

Acción recomendada

Verifica la presencia y exposición de las CVE indicadas en el inventario, confirma los avisos y versiones afectadas con los proveedores y comunica los resultados a los responsables de los entornos Cisco, Apple y Citrix.

Vendors:CiscoAppleCitrixSectores:healthcareCISO · Vulnerability Management · IT Ops
Publicado
30 sept 2026, 03:30
Actualizado
30 sept 2026, 05:00
Detectado
30 sept 2026, 05:00
Fuente
Help Net Security
Referencia técnica
NVD · CVE-2026-88771
Help Net Security
Prioridad · 41/100published <7d (+25) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
hace 2 días
Critical VulnsMEDIAAltoNEWGDPRNIS2AI ACTCRAInteligencia operacional

In this new SME cybersecurity service, the AI assists and the consultants decide

BH Consulting, the Irish cybersecurity and data protection consultancy, has launched BH Haven, an ongoing service that gives Irish small and medium-sized enterprises (SMEs) access to its specialist consultants, supported by a proprietary AI tool for analysis, evidence review, regulatory mapping and reporting. Ireland and the UK come first, with the Nordic countries and other EU markets to follow. The companies it targets answer to GDPR, the NIS2 Directive, the EU AI Act and the … More → The post In this new SME cybersecurity service, the AI assists and the consultants decide appeared first on Help Net Security. CVEs: CVE-2026-88771, CVE-2026-86950. Vendors: Apple, Citrix. DORA relevance: medium.

Por qué importa

El contenido describe un nuevo servicio de consultoría y menciona dos CVE asociados a productos Apple y Citrix, pero no aporta evidencia de explotación activa ni de inclusión en KEV.

Acción recomendada

Verifica la presencia de CVE-2026-88771 y CVE-2026-86950 en el inventario y prioriza la revisión de los activos Apple y Citrix afectados.

Vendors:AppleCitrixSectores:healthcareCISO · Vulnerability Management · IT Ops
Publicado
30 sept 2026, 04:30
Actualizado
30 sept 2026, 05:00
Detectado
30 sept 2026, 05:00
Fuente
Help Net Security
Referencia técnica
NVD · CVE-2026-88771
Help Net Security
Prioridad · 41/100published <7d (+25) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
hace 2 días
Critical VulnsMEDIAAltoNEWGDPRInteligencia operacional

GitHub’s AI agent found 24 Android app vulnerabilities

GitHub Security Lab researcher Kevin Stubbings built custom AI-driven audit workflows, called taskflows, on top of the lab’s open source Taskflow Agent, and used them to find and report more than 20 vulnerabilities in Android apps. Two of the disclosed bugs show what’s at stake. In OsmAnd, a navigation app with over 10 million downloads on the Play Store, an exported activity called MapActivity accepted intent extras that should have stayed restricted to an internal … More → The post GitHub’s AI agent found 24 Android app vulnerabilities appeared first on Help Net Security. CVEs: CVE-2026-86950. Vendors: Microsoft, Google, Oracle, Apple, GitHub. DORA relevance: medium.

Por qué importa

Se han identificado 24 vulnerabilidades en aplicaciones Android, incluida una actividad exportada que aceptaba parámetros de intención restringidos, lo que puede ampliar la superficie de ataque de aplicaciones móviles.

Acción recomendada

Comprueba la exposición a CVE-2026-86950 y a las vulnerabilidades divulgadas en el inventario de aplicaciones Android, valida las versiones afectadas y aplica las correcciones disponibles.

Vendors:MicrosoftGoogleOracleAppleSectores:healthcareCISO · Vulnerability Management · IT Ops
Publicado
29 sept 2026, 06:39
Actualizado
29 sept 2026, 10:01
Detectado
29 sept 2026, 10:01
Fuente
Help Net Security
Referencia técnica
NVD · CVE-2026-86950
Help Net Security
Prioridad · 41/100published <7d (+25) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
hace 3 días
Critical VulnsMEDIAAltoNEWGDPRInteligencia operacional

Cloudflare’s EmDash 1.0 makes sandboxed plugins ask for access first

Cloudflare released EmDash 1.0, a free, open source content management system that locks each sandboxed plugin in its own isolated runtime. A plugin starts with access to its own private storage. It cannot reach the site’s content, media, users, secrets, environment, filesystem, or network until it declares what it needs and a site administrator approves the request. The people this protects are site owners who run code they did not write. Cloudflare pitches EmDash as … More → The post Cloudflare’s EmDash 1.0 makes sandboxed plugins ask for access first appeared first on Help Net Security. CVEs: CVE-2026-86950. Vendors: Microsoft, Oracle, Apple, GitHub, WordPress, PHP, Cloudflare.

Por qué importa

EmDash 1.0 introduce aislamiento y control de permisos para plugins no confiables, pero el finding no aporta evidencia de explotación activa, inclusión en KEV ni una acción urgente.

Acción recomendada

Verifica si CVE-2026-86950 y EmDash 1.0 están presentes en el inventario y confirma las versiones y controles de aislamiento aplicables.

Vendors:CloudflareSectores:healthcareCISO · Vulnerability Management · IT Ops
Publicado
29 sept 2026, 09:03
Actualizado
29 sept 2026, 10:01
Detectado
29 sept 2026, 10:01
Fuente
Help Net Security
Referencia técnica
NVD · CVE-2026-86950
Help Net Security
Prioridad · 41/100published <7d (+25) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
hace 3 días
Critical VulnsMEDIAAltoNEWGDPRNIS2Inteligencia operacional

Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider

Hackers stole patient data from Qbusoft, a Polish medical software maker, weeks after a breach at another provider exposed records of nearly 19 million people in the country. The data comes from Medyc, a platform the company sells to medical offices and clinics to manage patient registration, records and prescriptions. In August, attackers stole data on nearly 19 million people from MyDr, a Warsaw-based company whose software is used by about 12,000 healthcare facilities. The … More → The post Hackers exploit SQL injection flaw to steal patient data from Polish medical software provider appeared first on Help Net Security. CVEs: CVE-2026-86950. Vendors: Microsoft, Oracle, Apple. DORA relevance: medium.

Por qué importa

La explotación activa de una inyección SQL ya provocó el robo de datos de pacientes en una plataforma sanitaria, con posibles obligaciones de notificación bajo GDPR y NIS2.

Acción recomendada

Investiga de inmediato la exposición a CVE-2026-86950, contiene los sistemas afectados, preserva evidencias y evalúa la notificación de la brecha.

Vendors:QbusoftMedycMicrosoftOracleSectores:healthcareinsuranceCISO · Vulnerability Management · IT Ops
Mapeo regulatorio · riesgo 90

La explotación activa de una inyección SQL con robo confirmado de datos de pacientes puede activar obligaciones de gestión y notificación de incidentes bajo NIS2 y exige demostrar responsabilidad y protección de datos desde el diseño bajo GDPR.

GDPR · Art. 24 Responsibility of the controller (direct) · Art. 25 Data protection by design and by default (direct)
NIS2 · Art. 21 Cybersecurity risk-management measures (direct) · Art. 23 Reporting obligations (direct)
Publicado
29 sept 2026, 09:17
Actualizado
29 sept 2026, 10:01
Detectado
29 sept 2026, 10:01
Fuente
Help Net Security
Referencia técnica
NVD · CVE-2026-86950
Help Net Security
Prioridad · 41/100published <7d (+25) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
hace 3 días
Critical VulnsMEDIAAltoNEWGDPRInteligencia operacional

Other users can watch your browsing and time your keystrokes through OS file notifications

Researchers at Graz University of Technology have used the file-notification systems in Windows, Linux, and macOS to spy on activity in other accounts. On Windows, a standard unprivileged account detected 95.7 percent of another user’s visits to popular websites in Firefox, and every site it flagged was one the victim’s browser had loaded. On Linux, a separate weakness exposed keystroke timing, both at the local keyboard and in SSH sessions. Programs use these notifications to … More → The post Other users can watch your browsing and time your keystrokes through OS file notifications appeared first on Help Net Security. CVEs: CVE-2025-27738, CVE-2025-21197, CVE-2025-68788, CVE-2026-88771, CVE-2026-88772. Vendors: Microsoft, Google, Oracle, Apple, Citrix, Linux, Mozilla, Docker, Zoom. DORA relevance: high.

Por qué importa

Las vulnerabilidades permiten que una cuenta local sin privilegios observe la actividad web de otros usuarios y exponga patrones temporales de pulsaciones, con posibles implicaciones de confidencialidad, GDPR y resiliencia operativa.

Acción recomendada

Identifica los activos y productos afectados, valida las versiones instaladas y aplica las actualizaciones o mitigaciones proporcionadas por los fabricantes; prioriza los sistemas multiusuario y los entornos con sesiones SSH.

Vendors:MicrosoftGoogleOracleAppleSectores:bankingfinancial_servicesCISO · Vulnerability Management · IT Ops
Mapeo regulatorio · riesgo 55

La vulnerabilidad puede permitir la observación no autorizada de actividad web y patrones de pulsaciones, por lo que requiere medidas técnicas y organizativas adecuadas para proteger los datos personales.

GDPR · Art. 32 Security of processing (direct)
Publicado
28 sept 2026, 12:14
Actualizado
28 sept 2026, 16:01
Detectado
28 sept 2026, 16:01
Fuente
Help Net Security
Referencia técnica
NVD · CVE-2025-27738
Help Net Security
Prioridad · 41/100published <7d (+25) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
hace 4 días
Cloud & IdentityMEDIAAltoNEWGDPRInteligencia operacional

Kiteworks patches max severity code injection vulnerability

Secure file-sharing software company Kiteworks has released security updates to address 126 vulnerabilities, including a max-severity flaw affecting its Email Protection Gateway (EPG) security solution. [...] CVEs: CVE-2026-54154. Vendors: Microsoft, Oracle, Apple, Citrix, Atlassian, MikroTik. DORA relevance: medium.

Por qué importa

Se ha identificado una vulnerabilidad de inyección de código de severidad máxima en Kiteworks EPG que requiere parcheo inmediato para evitar la ejecución remota de comandos.

Acción recomendada

Identifica y actualiza inmediatamente todas las instancias de Kiteworks EPG y audita los logs en busca de intentos de explotación.

Vendors:KiteworksMicrosoftOracleAppleSectores:public sectorhealthcarecloud/SaaSMITRE:T1190 Exploit Public-Facing ApplicationCISO · Cloud Security · SecOps
Publicado
01 oct 2026, 13:51
Actualizado
01 oct 2026, 16:02
Detectado
01 oct 2026, 16:02
Fuente
BleepingComputer
Referencia técnica
NVD · CVE-2026-54154
BleepingComputer
Prioridad · 52/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <24h (+5 cap)
hace 17 horas
Cloud & IdentityMEDIAAltoNEWGDPRNIS2AI ACTInteligencia operacional

One year later: Sovereign AI and the fight for choice

AI sovereignty is not a zero-sum game, but many governments now believe it is. Cloudflare's answer: more local open-source models, model-agnostic security tools, and a commitment to giving nations genuine choice. CVEs: CVE-2023-50387. Vendors: Microsoft, Google, AWS, CrowdStrike, Apple, Atlassian, GitHub, Apache, Mozilla, Kubernetes, Okta, WordPress, OpenSSL, PHP, Node.js, Python, IBM, Elastic, PostgreSQL, MySQL, NGINX, Grafana, HashiCorp, Cloudflare. DORA relevance: high.

Por qué importa

El informe aborda la soberanía de la IA y la seguridad en la cadena de suministro, destacando la necesidad de resiliencia operativa bajo marcos como DORA y NIS2 ante la dependencia de múltiples proveedores tecnológicos.

Acción recomendada

Audita el inventario de activos frente a la CVE-2023-50387 y revisa los controles de seguridad en la cadena de suministro de IA según las directrices de cumplimiento vigentes.

Vendors:MicrosoftGoogleAWSCrowdStrikeSectores:bankingpublic sectorcloud/SaaSretailCISO · Cloud Security · SecOps
Mapeo regulatorio · riesgo 35

La presencia de la CVE-2023-50387 y la necesidad de revisar la gestión de vulnerabilidades hacen aplicable la divulgación coordinada de vulnerabilidades bajo NIS2, aunque no se evidencia explotación ni incidente.

NIS2 · Art. 12 Coordinated vulnerability disclosure and a European vulnerability database (direct)
Publicado
01 oct 2026, 13:04
Actualizado
01 oct 2026, 16:01
Detectado
01 oct 2026, 16:01
Fuente
Cloudflare Blog Security
Referencia técnica
NVD · CVE-2023-50387
Cloudflare Blog Security
Prioridad · 52/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <24h (+5 cap)
hace 17 horas