CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)1
Última detecciónhace 2 d
Monitorizado porintelligence scouter
Acción Requerida

Sin señales activamente explotadas ni parches de emergencia.

8signals
Explotados & KEV
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaGoogle70Citrix57Microsoft48GitHub46Apple43Oracle26Mozilla19Kubernetes18Cisco17Atlassian
✓

No priority signals demanding immediate attention.

La cola operativa está limpia en esta ventana. El scouter sigue monitorizando.

All1Action Required0Exploited & KEV8Critical Vulns0Cloud & Identity1
Cloud & IdentityMEDIAAltoNEWGDPRNIS2AI ACTInteligencia operacional

Unsloth’s model picker had a code-execution problem

True to its name, AI-model-training tool Unsloth would do more work than it was asked to when developers checked out a model: It would also allow arbitrary code to execute on their machines. Pillar Security found that simply selecting a model in Unsloth Studio caused the application to download and execute Python code from the model repository. This could potentially allow attackers to use a specially crafted model to get malicious code executed on a developer’s system. “The code ran from nothing more than a metadata check,” researcher Ariel Fogel said in a post on Pillar’s blog. “Reading the model’s config.json was enough to trigger the exploit; the backend never loaded the weights or ran inference.” The code would run with the user’s permission which, Fogel said, could expose proprietary training data, model artifacts, Hugging Face tokens, SSH keys, or accessible cloud credentials in an enterprise’s AI development environment. Unsloth Studio is a web-based interface that is currently in beta, a status Unsloth’s maintainers cited when they reportedly declined to publish a security advisory or have a CVE assigned to the flaw after fixing it in June. Pillar contests that reasoning, pointing out that the vulnerable Studio code ships as part of the standard, generally available “unsloth” package on PyPI and can be installed through an ordinary “pip install unsloth” without selecting a beta or prerelease version. Transformers setting opened the door Unsloth uses Hugging Face’s trust_remote-code option, which allows a model to bring along its own Python code when needed. That’s not necessarily dangerous by itself. Some legitimate Hugging Face models, including IBM Granite Speech and Vision, DeepSeek-OCR, ChatGLM, and earlier Qwen releases, need custom code to work properly, Fogel said. The problem was that Unsloth enabled the feature automatically during a routine model check rather than requiring the user to explicitly opt into running remote code. Before the patch, “tr Vendors: Google, Citrix, GitLab, GitHub, Python, IBM. DORA relevance: high.

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

Vulns Críticas

Sin CVEs críticas frescas en la ventana actual.

Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

También en el Intel CenterCloud & Identity1
14
Cloudflare14
WordPress14
PHP14
Apache11

Por qué importa

La selección de un modelo podía ejecutar código Python arbitrario desde su repositorio con los permisos del usuario, exponiendo datos de entrenamiento, tokens de Hugging Face, claves SSH y credenciales cloud.

Acción recomendada

Actualiza Unsloth a una versión corregida, revisa el uso de trust_remote_code y rota cualquier token, clave o credencial accesible desde los entornos afectados.

Vendors:UnslothHugging FaceSectores:bankingpublic sectorcloud/SaaSMITRE:T1203 Exploitation for Client ExecutionCISO · Cloud Security · SecOps
Mapeo regulatorio · riesgo 55

La ejecución arbitraria de código desde repositorios de modelos constituye una vulnerabilidad que requiere gestión y divulgación coordinada, aunque no hay evidencia confirmada de explotación, incidente notificable o exposición de datos personales.

NIS2 · Art. 12 Coordinated vulnerability disclosure and a European vulnerability database (direct)
Publicado
30 sept 2026, 13:56
Actualizado
30 sept 2026, 16:01
Detectado
30 sept 2026, 16:01
Fuente
CSO Online
Referencia técnica
Original advisory
CSO Online
Prioridad · 41/100published <7d (+25) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
hace 2 días