CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)48
Última detecciónhace 16 h
Monitorizado porintelligence scouter
Acción Requerida

Sin señales activamente explotadas ni parches de emergencia.

12signals
Explotados & KEV
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaGoogle70Citrix57Microsoft48GitHub46Apple43Oracle26Mozilla19Kubernetes18Cisco17Atlassian

Priority Command Strip

What your team should look at right now

4 señales críticas
  1. Exploited & KEVHigh3d

    Japan's Keio confirms ransomware attack disrupted business systems

    Explotación reportada sobre Microsoft / Oracle. Verificar exposición real en el inventario.

    BleepingComputer · Microsoft · OracleReview signal
  2. Exploited & KEV
All48Action Required0Exploited & KEV12Critical Vulns9Cloud & Identity35

Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Studio para abrir el feed completo, histórico ampliado y el catálogo KEV.

Exploited & KEVALTAAltoEXPLOITEDCRAGDPRInteligencia operacional

Japan's Keio confirms ransomware attack disrupted business systems

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

9signals
Vulns Críticas
Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

También en el Intel CenterCloud & Identity35
14
Cloudflare14
WordPress14
PHP14
Apache11
High
4d

JadePuffer agentic AI attacks target Azure, destroy cloud resources

Explotación reportada sobre Microsoft / Oracle. Verificar exposición real en el inventario.

BleepingComputer · Microsoft · OracleReview signal
  • Exploited & KEVHigh4d

    Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

    Explotación reportada sobre Microsoft / Google. Verificar exposición real en el inventario.

    KrebsOnSecurity · Microsoft · GoogleReview signal
  • Exploited & KEVHigh5d

    Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

    Explotación reportada sobre Microsoft / Google. Verificar exposición real en el inventario.

    SecurityWeek · Microsoft · GoogleReview signal
  • Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...] Vendors: Microsoft, Oracle, Citrix, Atlassian, Cloudflare. DORA relevance: high.

    Por qué importa

    Keio Corporation confirmó un ataque de ransomware que interrumpió sistemas empresariales, lo que evidencia impacto operativo y posible riesgo de propagación o afectación en dependencias tecnológicas de terceros.

    Acción recomendada

    Activa el playbook de respuesta a ransomware, valida la exposición de los entornos Microsoft, Oracle, Citrix, Atlassian y Cloudflare, y evalúa de inmediato el impacto operativo y la posible brecha de datos personales.

    Vendors:MicrosoftOracleCitrixAtlassianSectores:transporte ferroviarioMITRE:T1486 Data Encrypted for ImpactCISO · Vulnerability Management · SecOps · IT Ops
    Publicado
    28 sept 2026, 20:56
    Actualizado
    28 sept 2026, 22:00
    Detectado
    28 sept 2026, 22:00
    Fuente
    BleepingComputer
    Referencia técnica
    Original advisory
    BleepingComputer
    Prioridad · 75/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 3 días
    Exploited & KEVALTAAltoEXPLOITEDCRAGDPRInteligencia operacional

    JadePuffer agentic AI attacks target Azure, destroy cloud resources

    The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...] Vendors: Microsoft, Oracle, Adobe, Citrix, Atlassian, GitHub, Cloudflare. DORA relevance: medium.

    Por qué importa

    El operador de ransomware JadePuffer está atacando tenants de Azure para realizar reconocimiento, robar credenciales y destruir componentes críticos de la nube.

    Acción recomendada

    Investiga de inmediato los tenants de Azure, revisa actividad de identidades y credenciales, valida cambios destructivos y aplica controles de contención y recuperación.

    Vendors:MicrosoftOracleAdobeCitrixSectores:cloud/SaaSMITRE:T1485 Data DestructionCISO · Vulnerability Management · SecOps · IT Ops
    Publicado
    28 sept 2026, 15:49
    Actualizado
    28 sept 2026, 17:01
    Detectado
    28 sept 2026, 17:01
    Fuente
    BleepingComputer
    Referencia técnica
    Original advisory
    BleepingComputer
    Prioridad · 75/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 4 días
    Exploited & KEVALTAAltoEXPLOITEDInteligencia operacional

    Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

    Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p. CVEs: CVE-2026-35273. Vendors: Microsoft, Google, Oracle. DORA relevance: high.

    Por qué importa

    ShinyHunters mantiene una actividad activa de robo de datos y extorsión, con posible impacto en organizaciones de sectores regulados y exposición adicional asociada a CVE-2026-35273.

    Acción recomendada

    Verifica de inmediato la exposición a CVE-2026-35273, revisa indicadores de compromiso y actividad de exfiltración, y notifica a los responsables de los entornos Microsoft, Google y Oracle.

    Vendors:MicrosoftGoogleOracleSectores:bankingpublic sectorhealthcarecloud/SaaSCISO · Vulnerability Management · SecOps · IT Ops
    Mapeo regulatorio · riesgo 80

    La actividad activa de ShinyHunters y la posible explotación de CVE-2026-35273 exigen reforzar la detección, gestión y clasificación de incidentes y vulnerabilidades TIC conforme a DORA.

    DORA · Art. 10 Detection (direct) · Art. 13 Learning and evolving (direct) · Art. 15 Further harmonisation of ICT risk management tools, methods, processes and policies (direct)
    Publicado
    28 sept 2026, 15:08
    Actualizado
    28 sept 2026, 17:01
    Detectado
    28 sept 2026, 17:01
    Fuente
    KrebsOnSecurity
    Referencia técnica
    NVD · CVE-2026-35273
    KrebsOnSecurity
    Prioridad · 75/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 4 días
    Exploited & KEVALTAAltoEXPLOITEDGDPRInteligencia operacional

    Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

    CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28. The post Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks appeared first on SecurityWeek. CVEs: CVE-2026-65660. Vendors: Microsoft, Google, F5, Docker, WordPress. DORA relevance: medium.

    Por qué importa

    CVE-2026-65660 afecta a Microsoft SharePoint, figura en el catálogo KEV de CISA y está siendo explotada en ataques, por lo que requiere validación y remediación inmediata.

    Acción recomendada

    Comprueba hoy la exposición a CVE-2026-65660, aplica el parche o mitigación disponible de Microsoft y verifica indicios de explotación en los sistemas SharePoint.

    Vendors:MicrosoftGoogleF5DockerSectores:insurancepublic sectorcloud/SaaSCISO · Vulnerability Management · SecOps · IT Ops
    Mapeo regulatorio · riesgo 75

    La explotación activa de una vulnerabilidad crítica en SharePoint exige aplicar medidas técnicas y organizativas adecuadas para proteger los datos personales tratados.

    GDPR · Art. 32 Security of processing (direct)
    Publicado
    27 sept 2026, 09:23
    Actualizado
    27 sept 2026, 12:00
    Detectado
    27 sept 2026, 12:00
    Fuente
    SecurityWeek
    Referencia técnica
    NVD · CVE-2026-65660
    SecurityWeek
    Prioridad · 75/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 5 días
    Critical VulnsMEDIAAltoNEWGDPRNIS2Inteligencia operacional

    ABB Protection and Control IED Manager PCM600

    View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to escalate privileges or overwrite files. The following versions of ABB Protection and Control IED Manager PCM600 are affected: Protection and Control IED Manager PCM600 <=2.14 (CVE-2026-15952, CVE-2026-15953) CVSS Vendor Equipment Vulnerabilities v3 6.4 ABB ABB Protection and Control IED Manager PCM600 Incorrect Permission Assignment for Critical Resource, Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') Background Critical Infrastructure Sectors: Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Switzerland Vulnerabilities Expand All + CVE-2026-15952 A vulnerability exists in the Scheduler Service installed with PCM600. The service executes under the LocalSystem account while permissions are granted to standard PCM600 users through membership in the local users group. An attacker with local access and valid user credentials may exploit this vulnerability to elevate privileges and obtain control of the affected host. View CVE Details Affected Products ABB Protection and Control IED Manager PCM600 Vendor: ABB Product Version: ABB Protection and Control IED Manager PCM600: <=2.14 Product Status: known_affected Remediations Mitigation ABB recommends the following workaround. Although this workaround does not correct the underlying vulnerability, it reduces the risk of privilege escalation. Mitigation Configure the appropriate ABBPCMSchedulerService instance to run using the same Windows account that is used to operate PCM600: Open Services.msc. Locate the ABBPCMSchedulerService corresponding to the installed PCM600 version. Open Properties and select the Log On tab. The service should be configured to log on with the same Windows user account that is used for the PCM600 application. Ensure that this account has the required "Log on as a service" privilege. Mitigation When authentication is enabled for the IED, the Scheduler CVEs: CVE-2026-15952, CVE-2026-15953. Vendors: ABB Product Version: ABB Protection and Control IED Manager PCM600: <=2, Microsoft, GitHub. DORA relevance: medium.

    Por qué importa

    Vulnerabilidades en software de gestión industrial (IED) que permiten escalada de privilegios y manipulación de archivos, afectando la integridad de sistemas críticos de energía.

    Acción recomendada

    Auditar el inventario de activos para identificar versiones de PCM600 <=2.14 y aplicar la mitigación recomendada por el fabricante configurando el servicio con privilegios restringidos.

    Vendors:ABBSectores:EnergyCritical InfrastructureMITRE:T1068 Exploitation for Privilege EscalationCISO · Vulnerability Management · IT Ops
    Mapeo regulatorio · riesgo 60

    La vulnerabilidad afecta software de gestión de sistemas energéticos críticos y requiere gestión de riesgos, mitigación y control de la cadena tecnológica conforme a NIS2, aunque no consta explotación confirmada ni incidente notificable.

    NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
    Publicado
    01 oct 2026, 12:00
    Actualizado
    01 oct 2026, 17:01
    Detectado
    01 oct 2026, 17:01
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2026-15952
    CISA All Alerts
    Prioridad · 59/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <24h (+5 cap)
    hace 16 horas
    Critical VulnsMEDIAAltoNEWGDPRInteligencia operacional

    Some car apps are slipping owners’ data to big tech companies

    The app that comes with your car may be sharing what it knows about you with some of the biggest tech companies. Northeastern University researchers tested 21 vehicles and 30 carmaker apps and found some sending vehicle identification numbers (VINs), email addresses, phone numbers or location data to advertising, tracking and analytics companies. The work was carried out with Consumer Reports, which gave them access to vehicles it had bought for testing. The 21 vehicles … More → The post Some car apps are slipping owners’ data to big tech companies appeared first on Help Net Security. CVEs: CVE-2026-76504, CVE-2026-88772. Vendors: Microsoft, Cisco, Google, Adobe, Citrix, GitHub. DORA relevance: medium.

    Por qué importa

    Investigaciones indican que aplicaciones de vehículos comparten datos personales (PII) con terceros, lo que representa un riesgo de cumplimiento bajo GDPR.

    Acción recomendada

    Auditar el uso de aplicaciones corporativas vinculadas a vehículos y revisar las políticas de privacidad de datos de terceros.

    Vendors:MicrosoftCiscoGoogleAdobeSectores:AutomotiveRetailCISO · Vulnerability Management · IT Ops
    Mapeo regulatorio · riesgo 70

    El intercambio de VIN, correo electrónico, teléfono y ubicación con empresas de publicidad, seguimiento y analítica exige revisar transparencia, privacidad desde el diseño y el registro de actividades de tratamiento conforme al GDPR.

    GDPR · Art. 25 Data protection by design and by default (direct) · Art. 30 Records of processing activities (direct) · Art. 13 Information to be provided where personal data are collected from the data subject (direct)
    Publicado
    01 oct 2026, 09:52
    Actualizado
    01 oct 2026, 11:02
    Detectado
    01 oct 2026, 11:02
    Fuente
    Help Net Security
    Referencia técnica
    NVD · CVE-2026-76504
    Help Net Security
    Prioridad · 52/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <24h (+5 cap)
    hace 22 horas
    Critical VulnsMEDIAAltoNEWGDPRInteligencia operacional

    GitHub’s AI agent found 24 Android app vulnerabilities

    GitHub Security Lab researcher Kevin Stubbings built custom AI-driven audit workflows, called taskflows, on top of the lab’s open source Taskflow Agent, and used them to find and report more than 20 vulnerabilities in Android apps. Two of the disclosed bugs show what’s at stake. In OsmAnd, a navigation app with over 10 million downloads on the Play Store, an exported activity called MapActivity accepted intent extras that should have stayed restricted to an internal … More → The post GitHub’s AI agent found 24 Android app vulnerabilities appeared first on Help Net Security. CVEs: CVE-2026-86950. Vendors: Microsoft, Google, Oracle, Apple, GitHub. DORA relevance: medium.

    Por qué importa

    Se han identificado 24 vulnerabilidades en aplicaciones Android, incluida una actividad exportada que aceptaba parámetros de intención restringidos, lo que puede ampliar la superficie de ataque de aplicaciones móviles.

    Acción recomendada

    Comprueba la exposición a CVE-2026-86950 y a las vulnerabilidades divulgadas en el inventario de aplicaciones Android, valida las versiones afectadas y aplica las correcciones disponibles.

    Vendors:MicrosoftGoogleOracleAppleSectores:healthcareCISO · Vulnerability Management · IT Ops
    Publicado
    29 sept 2026, 06:39
    Actualizado
    29 sept 2026, 10:01
    Detectado
    29 sept 2026, 10:01
    Fuente
    Help Net Security
    Referencia técnica
    NVD · CVE-2026-86950
    Help Net Security
    Prioridad · 41/100published <7d (+25) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 3 días
    Critical VulnsMEDIAAltoNEWGDPRInteligencia operacional

    Cloudflare’s EmDash 1.0 makes sandboxed plugins ask for access first

    Cloudflare released EmDash 1.0, a free, open source content management system that locks each sandboxed plugin in its own isolated runtime. A plugin starts with access to its own private storage. It cannot reach the site’s content, media, users, secrets, environment, filesystem, or network until it declares what it needs and a site administrator approves the request. The people this protects are site owners who run code they did not write. Cloudflare pitches EmDash as … More → The post Cloudflare’s EmDash 1.0 makes sandboxed plugins ask for access first appeared first on Help Net Security. CVEs: CVE-2026-86950. Vendors: Microsoft, Oracle, Apple, GitHub, WordPress, PHP, Cloudflare.

    Por qué importa

    EmDash 1.0 introduce aislamiento y control de permisos para plugins no confiables, pero el finding no aporta evidencia de explotación activa, inclusión en KEV ni una acción urgente.

    Acción recomendada

    Verifica si CVE-2026-86950 y EmDash 1.0 están presentes en el inventario y confirma las versiones y controles de aislamiento aplicables.

    Vendors:CloudflareSectores:healthcareCISO · Vulnerability Management · IT Ops
    Publicado
    29 sept 2026, 09:03
    Actualizado
    29 sept 2026, 10:01
    Detectado
    29 sept 2026, 10:01
    Fuente
    Help Net Security
    Referencia técnica
    NVD · CVE-2026-86950
    Help Net Security
    Prioridad · 41/100published <7d (+25) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 3 días