CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 24h
Señales (ventana)15
Última detecciónhace 15 h
Monitorizado porintelligence scouter
Acción Requerida

Sin señales activamente explotadas ni parches de emergencia.

9signals
Explotados & KEV
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaGoogle22GitHub15Citrix15Cisco14Apple8Microsoft7PHP3Johnson Controls Product Version: Johnson Controls EasyIO Neo Series EC Controllers: V32Apache2WordPress

Priority Command Strip

What your team should look at right now

1 señal críticas
  1. Exploited & KEVHigh16h

    CISA Launches Cybersecurity Awareness Month: Securing the Next 250

    Explotación reportada sobre GitHub. Verificar exposición real en el inventario.

    CISA News · GitHubReview signal
All15Action Required0Exploited & KEV9Critical Vulns9Cloud & Identity5

Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Studio para abrir el feed completo, histórico ampliado y el catálogo KEV.

Exploited & KEVALTAAltoEXPLOITEDGDPRNIS2Inteligencia operacional

CISA Launches Cybersecurity Awareness Month: Securing the Next 250

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

9signals
Vulns Críticas
Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

También en el Intel CenterCloud & Identity5
2
Kubernetes2
Atlassian2
Mozilla2
OpenSSL2

CISA Launches Cybersecurity Awareness Month: Securing the Next 250 | CISA Skip to main content An official website of the United States government Here’s how you know Here’s how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock A locked padlock ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Staying Secure at Events no-cost Cyber Services Cybersecurity Awareness Month KEV Catalog Report A Cyber Issue Search Menu Close Topics Topics Cybersecurity Best Practices Cyber Threats and Response Critical Infrastructure Security and Resilience Election Security Emergency Communications Industrial Control Systems Information and Communications Technology Supply Chain Security Partnerships and Collaboration Physical Security Risk Management How can we help? Government Educational Institutions Industry State, Local, Tribal, and Territorial Individuals and Families Small and Medium Businesses Find Help Locally Faith-Based Community Executives High-Risk Communities Spotlight Resources & Tools Resources & Tools All Resources & Tools Services Programs Resources Training Groups News & Events News & Events Directives News Events Cybersecurity Alerts & Advisories Request a CISA Speaker Congressional Testimony CISA Conferences CISA Live! Careers Careers Benefits & Perks Hiring and Recruitment New Employee Orientation & Onboarding Students & Recent Graduates Veteran and Military Spouses About About Divisions & Offices Regions Leadership Doing Business with CISA Site Links CISA GitHub CISA Central Contact Us Subscribe Transparency and Accountability Policies & Plans Staying Secure at Events no-cost Cyber Services Cybersecurity Awareness Month KEV Catalog Report A Cyber Issue Breadcrumb Home News & Events News CISA Launches Cybersecurity Awareness Month: Securing the Next 250 Share: Opens in a new Vendors: GitHub. DORA relevance: medium.

Por qué importa

Se trata de un anuncio institucional de CISA sobre el mes de la concienciación en ciberseguridad, sin contenido técnico de vulnerabilidades o amenazas activas.

Acción recomendada

No requiere acción técnica inmediata; archivar como comunicación informativa de concienciación.

Vendors:GitHubSectores:public sectorhealthcareCISO · Vulnerability Management · SecOps · IT Ops
Publicado
01 oct 2026, 12:00
Actualizado
01 oct 2026, 16:01
Detectado
01 oct 2026, 16:01
Fuente
CISA News
Referencia técnica
Original advisory
CISA News
Prioridad · 93/100published <24h (+40) · active exploitation/KEV/ransomware signal (+50) · high severity (+15) · regulatory relevance (+15) · CISA News authority (+12) · updated <24h (+5 cap)
hace 16 horas
Critical VulnsMEDIAAltoNEWNIS2Inteligencia operacional

CISA Malcolm

View CSAF Summary The following versions of CISA Malcolm are affected: Malcolm CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF), Authentication Bypass by Spoofing, Missing Authorization, Missing Authentication for Critical Function, Incorrect Authorization, Use of Default Credentials, Improper Certificate Validation, URL Redirection to Untrusted Site ('Open Redirect'), Dependency on Vulnerable Third-Party Component, Use of Password Hash With Insufficient Computational Effort Background Critical Infrastructure Sectors: Energy, Information Technology, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-90443 A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redirect the user's browser to an arbitrary external site. Successful exploitation could allow an attacker to act with the compromised user's session privileges within the application. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Metrics CVSS Version Bas CVEs: CVE-2026-90443, CVE-2026-90444, CVE-2026-90445, CVE-2026-90446, CVE-2026-90447. Vendors: CISA Product Version: CISA Malcolm <v26, GitHub. DORA relevance: medium.

Por qué importa

CISA Malcolm presenta múltiples vulnerabilidades críticas, incluyendo inyección de comandos y bypass de autenticación, que permiten a atacantes no autenticados comprometer la integridad y confidencialidad del sistema.

Acción recomendada

Actualice inmediatamente todas las instancias de CISA Malcolm a la versión de septiembre de 2026 o superior y audite los logs en busca de intentos de explotación previos.

Vendors:CISASectores:EnergyInformation TechnologyWater and WastewaterMITRE:T1190 Exploit Public-Facing ApplicationCISO · Vulnerability Management · IT Ops
Mapeo regulatorio · riesgo 55

La vulnerabilidad de alta severidad en Malcolm requiere medidas de gestión de riesgos y remediación, pero no hay evidencia de explotación, incidente significativo o afectación confirmada a una entidad sujeta a NIS2.

NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
Publicado
01 oct 2026, 12:00
Actualizado
01 oct 2026, 17:01
Detectado
01 oct 2026, 17:01
Fuente
CISA All Alerts
Referencia técnica
NVD · CVE-2026-90443
CISA All Alerts
Prioridad · 59/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <24h (+5 cap)
hace 15 horas
Critical VulnsMEDIAAltoNEWGDPRNIS2Inteligencia operacional

Johnson Controls EasyIO Neo Series EC and CW Controllers

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker tointercept and read sensitive information, including credentials andsession data. The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected: EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64893) EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64893) EasyIO Neo Series CW Controllers V3.3b24 (CVE-2026-64893) EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64893) CVSS Vendor Equipment Vulnerabilities v3 5.4 Johnson Controls Johnson Controls EasyIO Neo Series EC and CW Controllers Cleartext Transmission of Sensitive Information Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-64893 Johnson Controls is aware of a vulnerability in EasyIO Neo which may allow an attacker to intercept and read sensitive information, including credentials and session data, transmitted in cleartext over the network. Successful exploitation could result in technical or operational impact. EasyIO Neo is a programmable building automation edge controller used to manage and automate HVAC, lighting, and energy systems in commercial buildings through a web-based interface. View CVE Details Affected Products Johnson Controls EasyIO Neo Series EC and CW Controllers Vendor: Johnson Controls Product Version: Johnson Controls EasyIO Neo Series EC Controllers: V3.3b62, Johnson Controls EasyIO Neo Series EC Controllers: V3.3b63, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b24, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b25 Product Status: known_affected Remediations Mitigation Johnson Controls released fixed versions for EasyIO Neo Series EC and CW Controllers. Users should upgrade to the fixed version or later as soon as operation CVEs: CVE-2026-64893. Vendors: Johnson Controls Product Version: Johnson Controls EasyIO Neo Series EC Controllers: V3, GitHub. DORA relevance: medium.

Por qué importa

La vulnerabilidad permite la interceptación de credenciales y datos de sesión en texto claro en sistemas de automatización de edificios, lo que podría facilitar el acceso no autorizado a infraestructuras críticas.

Acción recomendada

Identificar los controladores EasyIO Neo afectados en el inventario y actualizar al firmware corregido proporcionado por Johnson Controls lo antes posible.

Vendors:Johnson ControlsSectores:Critical ManufacturingCommercial FacilitiesGovernment ServicesTransportation SystemsMITRE:T1190 Exploit Public-Facing ApplicationCISO · Vulnerability Management · IT Ops
Mapeo regulatorio · riesgo 60

La vulnerabilidad expone credenciales y datos de sesión en texto claro en controladores de automatización, lo que requiere medidas de gestión de riesgos y corrección conforme a NIS2 Art. 21 cuando la entidad esté dentro de su ámbito.

NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
Publicado
01 oct 2026, 12:00
Actualizado
01 oct 2026, 17:01
Detectado
01 oct 2026, 17:01
Fuente
CISA All Alerts
Referencia técnica
NVD · CVE-2026-64893
CISA All Alerts
Prioridad · 59/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <24h (+5 cap)
hace 15 horas
Critical VulnsMEDIAAltoNEWGDPRNIS2Inteligencia operacional

ABB Protection and Control IED Manager PCM600

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are affected: Protection and Control IED Manager PCM600 <=2.14 (CVE-2026-15952, CVE-2026-15953) CVSS Vendor Equipment Vulnerabilities v3 6.4 ABB ABB Protection and Control IED Manager PCM600 Incorrect Permission Assignment for Critical Resource, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-15952 A vulnerability exists in the Scheduler Service installed with PCM600. The service executes under the LocalSystem account while permissions are granted to standard PCM600 users through membership in the local users group. An attacker with local access and valid user credentials may exploit this vulnerability to elevate privileges and obtain control of the affected host. View CVE Details Affected Products ABB Protection and Control IED Manager PCM600 Vendor: ABB Product Version: ABB Protection and Control IED Manager PCM600: <=2.14 Product Status: known_affected Remediations Mitigation ABB recommends the following workaround. Although this workaround does not correct the underlying vulnerability, it reduces the risk of privilege escalation. Mitigation Configure the appropriate ABBPCMSchedulerService instance to run using the same Windows account that is used to operate PCM600: Open Services.msc. Locate the ABBPCMSchedulerService corresponding to the installed PCM600 version. Open Properties and select the Log On tab. The service should be configured to log on with the same Windows user account that is used for the PCM600 application. Ensure that this account has the required "Log on as a service" privilege. Mitigation When authentication is enabled for the IED, the Scheduler CVEs: CVE-2026-15952, CVE-2026-15953. Vendors: ABB Product Version: ABB Protection and Control IED Manager PCM600: <=2, Microsoft, GitHub. DORA relevance: medium.

Por qué importa

Vulnerabilidades en software de gestión industrial (IED) que permiten escalada de privilegios y manipulación de archivos, afectando la integridad de sistemas críticos de energía.

Acción recomendada

Auditar el inventario de activos para identificar versiones de PCM600 <=2.14 y aplicar la mitigación recomendada por el fabricante configurando el servicio con privilegios restringidos.

Vendors:ABBSectores:EnergyCritical InfrastructureMITRE:T1068 Exploitation for Privilege EscalationCISO · Vulnerability Management · IT Ops
Mapeo regulatorio · riesgo 60

La vulnerabilidad afecta software de gestión de sistemas energéticos críticos y requiere gestión de riesgos, mitigación y control de la cadena tecnológica conforme a NIS2, aunque no consta explotación confirmada ni incidente notificable.

NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
Publicado
01 oct 2026, 12:00
Actualizado
01 oct 2026, 17:01
Detectado
01 oct 2026, 17:01
Fuente
CISA All Alerts
Referencia técnica
NVD · CVE-2026-15952
CISA All Alerts
Prioridad · 59/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <24h (+5 cap)
hace 15 horas
Critical VulnsMEDIAAltoNEWGDPRNIS2Inteligencia operacional

Johnson Controls EasyIO Neo Series EC and CW Controllers

View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to gain access to sensitive information that could be used to conduct further attacks against the system. The following versions of Johnson Controls EasyIO Neo Series EC and CW Controllers are affected: EasyIO Neo Series EC Controllers V3.3b63 (CVE-2026-64892) EasyIO Neo Series EC Controllers V3.3b62 (CVE-2026-64892) EasyIO Neo Series CW Controllers V3.3b25 (CVE-2026-64892) EasyIO Neo Series CW Controllers V3.3b24 (CVE-2026-64892) CVSS Vendor Equipment Vulnerabilities v3 3.5 Johnson Controls Johnson Controls EasyIO Neo Series EC and CW Controllers Exposure of Sensitive Information to an Unauthorized Actor Background Critical Infrastructure Sectors: Critical Manufacturing, Commercial Facilities, Government Services and Facilities, Transportation Systems, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Ireland Vulnerabilities Expand All + CVE-2026-64892 Johnson Controls is aware of a vulnerability in EasyIO Neo Series EC and CW Controllers relating to an attacker gaining access to sensitive information that could be used to conduct further attacks against the system. The EC and CW are programmable edge controllers designed for building automation and control systems, used to manage and automate various building functions including HVAC, lighting, and energy management, supporting open protocols such as BACnet and Modbus for adaptable system connections. View CVE Details Affected Products Johnson Controls EasyIO Neo Series EC and CW Controllers Vendor: Johnson Controls Product Version: Johnson Controls EasyIO Neo Series EC Controllers: V3.3b63, Johnson Controls EasyIO Neo Series EC Controllers: V3.3b62, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b25, Johnson Controls EasyIO Neo Series CW Controllers: V3.3b24 Product Status: known_affected Remediations Mitigation Johnson Controls released fixed versions for EasyIO Neo Series EC and CW Controllers CVEs: CVE-2026-64892. Vendors: Johnson Controls Product Version: Johnson Controls EasyIO Neo Series EC Controllers: V3, GitHub. DORA relevance: medium.

Por qué importa

Vulnerabilidad de exposición de información sensible en controladores industriales (OT) que podría facilitar ataques laterales en infraestructuras críticas.

Acción recomendada

Identificar los controladores afectados en el inventario OT y aplicar las actualizaciones de firmware proporcionadas por Johnson Controls.

Vendors:Johnson ControlsSectores:Critical ManufacturingCommercial FacilitiesGovernment ServicesTransportation SystemsMITRE:T1190 Exploit Public-Facing ApplicationCISO · Vulnerability Management · IT Ops
Mapeo regulatorio · riesgo 55

La vulnerabilidad afecta a controladores OT utilizados en sectores críticos y requiere medidas de gestión de riesgos y mitigación, aunque no se ha confirmado explotación ni un incidente regulatoriamente notificable.

NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
Publicado
01 oct 2026, 12:00
Actualizado
01 oct 2026, 17:01
Detectado
01 oct 2026, 17:01
Fuente
CISA All Alerts
Referencia técnica
NVD · CVE-2026-64892
CISA All Alerts
Prioridad · 59/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <24h (+5 cap)
hace 15 horas
Critical VulnsMEDIAAltoNEWGDPRNIS2Inteligencia operacional

Monta monta.app

View CSAF Summary Successful exploitation of these vulnerabilities could enable attackers to gain unauthorized administrative control over vulnerable charging stations or disrupt charging services through denial-of-service attacks. The following versions of Monta monta.app are affected: monta.app vers:all/* (CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474) CVSS Vendor Equipment Vulnerabilities v3 9.4 Monta Monta monta.app Missing Authentication for Critical Function, Improper Restriction of Excessive Authentication Attempts, Insufficient Session Expiration, Insufficiently Protected Credentials Background Critical Infrastructure Sectors: Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: Netherlands Vulnerabilities Expand All + CVE-2026-95102 WebSocket endpoints lack proper authentication mechanisms, enabling attackers to impersonate charging stations. As a result, attackers can exploit this weakness to gain unauthorized access to sensitive data or perform unauthorized actions. Given that no authentication is required, this can lead to privilege escalation and potentially compromise the security of the entire system. View CVE Details Affected Products Monta monta.app Vendor: Monta Product Version: Monta monta.app: vers:all/* Product Status: known_affected Remediations Mitigation Monta states that they are actively working to increase adoption of authenticated connections across their network and to deprecate unauthenticated access on a rolling basis. Monta states that they provide support for OCPP 1.6 Security Profile 2 (HTTP Basic Auth with TLS) and encourage operators to enable it. Mitigation Monta states that they have implemented rate limiting and automated connection throttling at the WebSocket layer. Connections exhibiting abusive patterns, including rapid reconnection, ID brute-forcing behavior, or excessive command volume, are automatically identified and blocked. Mitigation Monta states that their CVEs: CVE-2026-95102, CVE-2026-97363, CVE-2026-97212, CVE-2026-93474. Vendors: Monta Product Version: Monta monta, GitHub. DORA relevance: medium.

Por qué importa

Vulnerabilidades críticas (CVSS 9.4) en infraestructura de carga permiten el control administrativo no autorizado y la interrupción del servicio, afectando sectores críticos bajo regulación NIS2.

Acción recomendada

Auditar el inventario de activos para identificar instancias de Monta monta.app y aplicar las mitigaciones de autenticación (OCPP 1.6 Security Profile 2) recomendadas por el proveedor.

Vendors:MontaSectores:EnergyTransportation SystemsMITRE:T1190 Exploit Public-Facing ApplicationCISO · Vulnerability Management · IT Ops
Mapeo regulatorio · riesgo 85

Vulnerabilidades críticas con posible control administrativo no autorizado y denegación de servicio requieren medidas técnicas, operativas y organizativas de gestión del riesgo conforme a NIS2.

NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
Publicado
01 oct 2026, 12:00
Actualizado
01 oct 2026, 17:01
Detectado
01 oct 2026, 17:01
Fuente
CISA All Alerts
Referencia técnica
NVD · CVE-2026-95102
CISA All Alerts
Prioridad · 59/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <24h (+5 cap)
hace 15 horas
Critical VulnsMEDIAAltoNEWGDPRNIS2Inteligencia operacional

Armatura LLC Armatura One

View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to gain unauthorized access to the database, execute arbitrary code on the host with the highest level of privilege, or gain control of the physical access-control system. The following versions of Armatura LLC Armatura One are affected: Armatura One <4.7.2 (CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593, CVE-2026-94594) Armatura One (USA) <4.6.1 (CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593, CVE-2026-94594) CVSS Vendor Equipment Vulnerabilities v3 9.8 Armatura LLC Armatura LLC Armatura One Deserialization of Untrusted Data, Use of Hard-coded Cryptographic Key, Use of Hard-coded Credentials, Insertion of Sensitive Information into Log File Background Critical Infrastructure Sectors: Communications, Critical Manufacturing, Energy, Transportation Systems Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2023-46604 Armatura One embeds Apache ActiveMQ, exposing its OpenWire protocol listener on the network by default. This embedded version is affected by CVE-2023-46604, a deserialization flaw in the OpenWire marshaller that allows an unauthenticated network attacker to trigger deserialization of an arbitrary object graph before authentication is checked. This can result in arbitrary code execution with the highest level of privilege on the host operating system. View CVE Details Affected Products Armatura LLC Armatura One Vendor: Armatura LLC Product Version: Armatura LLC Armatura One: <4.7.2, Armatura LLC Armatura One (USA): <4.6.1 Product Status: known_affected Remediations Vendor fix Armatura LLC Armatura One vers:all/<4.7.2: Armatura LLC has released Armatura One V4.7.2, which resolves this issue. Users should upgrade from V4.7.1 or earlier to V4.7.2. Vendor fix Armatura LLC Armatura One (USA) vers:all/<4.6.1: Armatura LLC has released Armatura One V4.6.1_USA, which resolves this CVEs: CVE-2023-46604, CVE-2026-94591, CVE-2026-94592, CVE-2026-94593, CVE-2026-94594. Vendors: Armatura LLC Product Version: Armatura LLC Armatura One: <4, GitHub, Apache.

Por qué importa

Las vulnerabilidades permiten la ejecución remota de código con privilegios de sistema y el control total de sistemas de acceso físico, afectando infraestructura crítica.

Acción recomendada

Actualice inmediatamente Armatura One a la versión 4.7.2 o superior y aísle los sistemas expuestos de redes públicas hasta completar el parcheo.

Vendors:Armatura LLCApacheSectores:CommunicationsCritical ManufacturingEnergyTransportation SystemsMITRE:T1190 Exploit Public-Facing ApplicationT1210 Exploitation of Remote ServicesCISO · Vulnerability Management · IT Ops
Mapeo regulatorio · riesgo 85

La vulnerabilidad crítica permite ejecución remota de código y control de sistemas de acceso físico, por lo que exige medidas inmediatas de gestión del riesgo y mitigación conforme a NIS2.

NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
Publicado
01 oct 2026, 12:00
Actualizado
01 oct 2026, 17:01
Detectado
01 oct 2026, 17:01
Fuente
CISA All Alerts
Referencia técnica
NVD · CVE-2023-46604
CISA All Alerts
Prioridad · 59/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <24h (+5 cap)
hace 15 horas
Critical VulnsMEDIAAltoNEWGDPRInteligencia operacional

DeepKeep’s AI Lens flags coding agent data leaks and routes destructive commands for approval

DeepKeep has announced AI Lens for Developers, a new extension to the company’s AI usage control and runtime protection modules to secure software developers and their coding agents that can write, modify, and execute code on their behalf. The capability gives security teams policy enforcement, audit visibility, and runtime security over coding agents such as Cursor and Claude Code, closing a critical gap most security programs have ever had to cover before. 90% of developers … More → The post DeepKeep’s AI Lens flags coding agent data leaks and routes destructive commands for approval appeared first on Help Net Security. CVEs: CVE-2026-76504, CVE-2026-88772. Vendors: Cisco, Google, Citrix, GitHub. DORA relevance: medium.

Por qué importa

La aparición de vulnerabilidades críticas asociadas a agentes de codificación y herramientas de IA representa un riesgo de ejecución de código no autorizado y fuga de datos sensibles en el ciclo de vida de desarrollo.

Acción recomendada

Auditar el uso de agentes de IA en el entorno de desarrollo, verificar la exposición a los CVEs mencionados en los stacks de Cisco, Google, Citrix y GitHub, y restringir permisos de ejecución automática.

Vendors:CiscoGoogleCitrixGitHubMITRE:T1195 Supply Chain CompromiseCISO · Vulnerability Management · IT Ops
Publicado
01 oct 2026, 13:57
Actualizado
01 oct 2026, 15:02
Detectado
01 oct 2026, 15:02
Fuente
Help Net Security
Referencia técnica
NVD · CVE-2026-76504
Help Net Security
Prioridad · 52/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <24h (+5 cap)
hace 17 horas