CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)138
Última detecciónhace 3 h
Monitorizado porintelligence scouter
Acción Requerida

Sin señales activamente explotadas ni parches de emergencia.

15signals
Explotados & KEV
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaGoogle69Citrix57Microsoft47GitHub45Apple43Oracle25Mozilla19Kubernetes18Cisco17Cloudflare

Priority Command Strip

What your team should look at right now

6 señales críticas
  1. Exploited & KEVHigh17h

    CISA Launches Cybersecurity Awareness Month: Securing the Next 250

    Explotación reportada sobre GitHub. Verificar exposición real en el inventario.

    CISA News · GitHubReview signal
  2. Exploited & KEV
All138Action Required0Exploited & KEV15Critical Vulns51Vendor Advisories9Cloud & Identity69Monitor2

Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Studio para abrir el feed completo, histórico ampliado y el catálogo KEV.

Exploited & KEVALTAAltoEXPLOITEDGDPRNIS2Inteligencia operacional

CISA Launches Cybersecurity Awareness Month: Securing the Next 250

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

51signals
Vulns Críticas
9signals
Advisories de Vendor
También en el Intel CenterCloud & Identity69Monitor2
14
WordPress14
PHP14
Atlassian13
Apache11
High
17h

Warlock Ransomware Hits Large Spanish, Portuguese Orgs

CVE con evidencia de explotación. Revisar exposición del perímetro.

Dark Reading Review signal
  • Exploited & KEVHigh2d

    South Africa Seeks Help After Cyberattack Targets Air Traffic Control

    CVE con evidencia de explotación. Revisar exposición del perímetro.

    Dark Reading Review signal
  • Exploited & KEVHigh3d

    Japan's Keio confirms ransomware attack disrupted business systems

    Explotación reportada sobre Microsoft / Oracle. Verificar exposición real en el inventario.

    BleepingComputer · Microsoft · OracleReview signal
  • Exploited & KEVHigh4d

    JadePuffer agentic AI attacks target Azure, destroy cloud resources

    Explotación reportada sobre Microsoft / Oracle. Verificar exposición real en el inventario.

    BleepingComputer · Microsoft · OracleReview signal
  • Exploited & KEVHigh4d

    Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

    Explotación reportada sobre Microsoft / Google. Verificar exposición real en el inventario.

    KrebsOnSecurity · Microsoft · GoogleReview signal
  • CISA Launches Cybersecurity Awareness Month: Securing the Next 250 | CISA Skip to main content An official website of the United States government Here’s how you know Here’s how you know Official websites use .gov A .gov website belongs to an official government organization in the United States. Secure .gov websites use HTTPS A lock ( Lock A locked padlock ) or https:// means you’ve safely connected to the .gov website. Share sensitive information only on official, secure websites. Staying Secure at Events no-cost Cyber Services Cybersecurity Awareness Month KEV Catalog Report A Cyber Issue Search Menu Close Topics Topics Cybersecurity Best Practices Cyber Threats and Response Critical Infrastructure Security and Resilience Election Security Emergency Communications Industrial Control Systems Information and Communications Technology Supply Chain Security Partnerships and Collaboration Physical Security Risk Management How can we help? Government Educational Institutions Industry State, Local, Tribal, and Territorial Individuals and Families Small and Medium Businesses Find Help Locally Faith-Based Community Executives High-Risk Communities Spotlight Resources & Tools Resources & Tools All Resources & Tools Services Programs Resources Training Groups News & Events News & Events Directives News Events Cybersecurity Alerts & Advisories Request a CISA Speaker Congressional Testimony CISA Conferences CISA Live! Careers Careers Benefits & Perks Hiring and Recruitment New Employee Orientation & Onboarding Students & Recent Graduates Veteran and Military Spouses About About Divisions & Offices Regions Leadership Doing Business with CISA Site Links CISA GitHub CISA Central Contact Us Subscribe Transparency and Accountability Policies & Plans Staying Secure at Events no-cost Cyber Services Cybersecurity Awareness Month KEV Catalog Report A Cyber Issue Breadcrumb Home News & Events News CISA Launches Cybersecurity Awareness Month: Securing the Next 250 Share: Opens in a new Vendors: GitHub. DORA relevance: medium.

    Por qué importa

    Se trata de un anuncio institucional de CISA sobre el mes de la concienciación en ciberseguridad, sin contenido técnico de vulnerabilidades o amenazas activas.

    Acción recomendada

    No requiere acción técnica inmediata; archivar como comunicación informativa de concienciación.

    Vendors:GitHubSectores:public sectorhealthcareCISO · Vulnerability Management · SecOps · IT Ops
    Publicado
    01 oct 2026, 12:00
    Actualizado
    01 oct 2026, 16:01
    Detectado
    01 oct 2026, 16:01
    Fuente
    CISA News
    Referencia técnica
    Original advisory
    CISA News
    Prioridad · 93/100published <24h (+40) · active exploitation/KEV/ransomware signal (+50) · high severity (+15) · regulatory relevance (+15) · CISA News authority (+12) · updated <24h (+5 cap)
    hace 17 horas
    Exploited & KEVALTAAltoEXPLOITEDInteligencia operacional

    Warlock Ransomware Hits Large Spanish, Portuguese Orgs

    A year-old Chinese threat actor looks like a cybercrime gang, acts like a state-associated APT, and attacks organizations in unexpected places. DORA relevance: medium.

    Por qué importa

    El grupo Warlock está ejecutando campañas de ransomware dirigidas específicamente a organizaciones en España y Portugal, combinando tácticas de ciberdelincuencia con capacidades de APT.

    Acción recomendada

    Revisar los logs de perímetro y endpoints en busca de actividad inusual y reforzar las políticas de backup y segmentación de red.

    MITRE:T1486 Data Encrypted for ImpactCISO · Vulnerability Management · SecOps · IT Ops
    Mapeo regulatorio · riesgo 60

    La campaña de ransomware dirigida a organizaciones de España y Portugal exige reforzar la detección, la continuidad operativa, las copias de seguridad y el aprendizaje sobre amenazas conforme a DORA.

    DORA · Art. 10 Detection (direct) · Art. 11 Response and recovery (direct) · Art. 12 Backup policies and procedures, restoration and recovery procedures and methods (direct)
    Publicado
    01 oct 2026, 13:00
    Actualizado
    01 oct 2026, 16:02
    Detectado
    01 oct 2026, 16:02
    Fuente
    Dark Reading
    Referencia técnica
    Original advisory
    Dark Reading
    Prioridad · 86/100published <24h (+40) · active exploitation/KEV/ransomware signal (+50) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <24h (+5 cap)
    hace 17 horas
    Exploited & KEVALTAAltoEXPLOITEDInteligencia operacional

    South Africa Seeks Help After Cyberattack Targets Air Traffic Control

    As aviation infrastructure suffers more cyberattacks, air traffic systems are the latest target, with a ransomware toolkit installed on at least one operational network. DORA relevance: medium.

    Por qué importa

    Se identificó la instalación de un toolkit de ransomware en al menos una red operacional de control del tráfico aéreo, lo que puede afectar la continuidad y seguridad de una infraestructura crítica.

    Acción recomendada

    Confirma si existen activos o proveedores relacionados expuestos, revisa indicadores de compromiso de ransomware y valida de inmediato los controles de segmentación, monitorización y respuesta.

    Sectores:aviationair traffic controlcritical infrastructureCISO · Vulnerability Management · SecOps · IT Ops
    Publicado
    30 sept 2026, 07:00
    Actualizado
    30 sept 2026, 08:01
    Detectado
    30 sept 2026, 08:01
    Fuente
    Dark Reading
    Referencia técnica
    Original advisory
    Dark Reading
    Prioridad · 75/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    Exploited & KEVALTAAltoEXPLOITEDCRAGDPRInteligencia operacional

    Japan's Keio confirms ransomware attack disrupted business systems

    Keio Corporation (Keio), a major private railway operator in Japan, said its network was hit by a ransomware attack over the weekend, disrupting some of its business systems. [...] Vendors: Microsoft, Oracle, Citrix, Atlassian, Cloudflare. DORA relevance: high.

    Por qué importa

    Keio Corporation confirmó un ataque de ransomware que interrumpió sistemas empresariales, lo que evidencia impacto operativo y posible riesgo de propagación o afectación en dependencias tecnológicas de terceros.

    Acción recomendada

    Activa el playbook de respuesta a ransomware, valida la exposición de los entornos Microsoft, Oracle, Citrix, Atlassian y Cloudflare, y evalúa de inmediato el impacto operativo y la posible brecha de datos personales.

    Vendors:MicrosoftOracleCitrixAtlassianSectores:transporte ferroviarioMITRE:T1486 Data Encrypted for ImpactCISO · Vulnerability Management · SecOps · IT Ops
    Publicado
    28 sept 2026, 20:56
    Actualizado
    28 sept 2026, 22:00
    Detectado
    28 sept 2026, 22:00
    Fuente
    BleepingComputer
    Referencia técnica
    Original advisory
    BleepingComputer
    Prioridad · 75/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 3 días
    Exploited & KEVALTAAltoEXPLOITEDCRAGDPRInteligencia operacional

    JadePuffer agentic AI attacks target Azure, destroy cloud resources

    The JadePuffer ransomware operator is targeting Azure tenants with agent-driven attacks that conduct reconnaissance, steal credentials, and destroy core components. [...] Vendors: Microsoft, Oracle, Adobe, Citrix, Atlassian, GitHub, Cloudflare. DORA relevance: medium.

    Por qué importa

    El operador de ransomware JadePuffer está atacando tenants de Azure para realizar reconocimiento, robar credenciales y destruir componentes críticos de la nube.

    Acción recomendada

    Investiga de inmediato los tenants de Azure, revisa actividad de identidades y credenciales, valida cambios destructivos y aplica controles de contención y recuperación.

    Vendors:MicrosoftOracleAdobeCitrixSectores:cloud/SaaSMITRE:T1485 Data DestructionCISO · Vulnerability Management · SecOps · IT Ops
    Publicado
    28 sept 2026, 15:49
    Actualizado
    28 sept 2026, 17:01
    Detectado
    28 sept 2026, 17:01
    Fuente
    BleepingComputer
    Referencia técnica
    Original advisory
    BleepingComputer
    Prioridad · 75/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 4 días
    Exploited & KEVALTAAltoEXPLOITEDInteligencia operacional

    Dutch Police Arrest ‘Reformed’ Hacker in Shiny Hunters Investigation

    Authorities in the Netherlands have arrested a 23-year-old convicted cybercriminal on suspicion of aiding in data thefts and extortions by the prolific hacker group ShinyHunters. In the days immediately following the suspect's arrest, remaining ShinyHunters members dramatically escalated their attacks, stealing highly sensitive data from the FBI and extorting the Russian ransomware group Cl0p. CVEs: CVE-2026-35273. Vendors: Microsoft, Google, Oracle. DORA relevance: high.

    Por qué importa

    ShinyHunters mantiene una actividad activa de robo de datos y extorsión, con posible impacto en organizaciones de sectores regulados y exposición adicional asociada a CVE-2026-35273.

    Acción recomendada

    Verifica de inmediato la exposición a CVE-2026-35273, revisa indicadores de compromiso y actividad de exfiltración, y notifica a los responsables de los entornos Microsoft, Google y Oracle.

    Vendors:MicrosoftGoogleOracleSectores:bankingpublic sectorhealthcarecloud/SaaSCISO · Vulnerability Management · SecOps · IT Ops
    Mapeo regulatorio · riesgo 80

    La actividad activa de ShinyHunters y la posible explotación de CVE-2026-35273 exigen reforzar la detección, gestión y clasificación de incidentes y vulnerabilidades TIC conforme a DORA.

    DORA · Art. 10 Detection (direct) · Art. 13 Learning and evolving (direct) · Art. 15 Further harmonisation of ICT risk management tools, methods, processes and policies (direct)
    Publicado
    28 sept 2026, 15:08
    Actualizado
    28 sept 2026, 17:01
    Detectado
    28 sept 2026, 17:01
    Fuente
    KrebsOnSecurity
    Referencia técnica
    NVD · CVE-2026-35273
    KrebsOnSecurity
    Prioridad · 75/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 4 días
    Exploited & KEVALTAAltoEXPLOITEDGDPRInteligencia operacional

    Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks

    CISA added CVE-2026-65660 to its KEV catalog, giving federal agencies a patching deadline of September 28. The post Microsoft SharePoint Flaw CVE-2026-65660 Now Exploited in Attacks appeared first on SecurityWeek. CVEs: CVE-2026-65660. Vendors: Microsoft, Google, F5, Docker, WordPress. DORA relevance: medium.

    Por qué importa

    CVE-2026-65660 afecta a Microsoft SharePoint, figura en el catálogo KEV de CISA y está siendo explotada en ataques, por lo que requiere validación y remediación inmediata.

    Acción recomendada

    Comprueba hoy la exposición a CVE-2026-65660, aplica el parche o mitigación disponible de Microsoft y verifica indicios de explotación en los sistemas SharePoint.

    Vendors:MicrosoftGoogleF5DockerSectores:insurancepublic sectorcloud/SaaSCISO · Vulnerability Management · SecOps · IT Ops
    Mapeo regulatorio · riesgo 75

    La explotación activa de una vulnerabilidad crítica en SharePoint exige aplicar medidas técnicas y organizativas adecuadas para proteger los datos personales tratados.

    GDPR · Art. 32 Security of processing (direct)
    Publicado
    27 sept 2026, 09:23
    Actualizado
    27 sept 2026, 12:00
    Detectado
    27 sept 2026, 12:00
    Fuente
    SecurityWeek
    Referencia técnica
    NVD · CVE-2026-65660
    SecurityWeek
    Prioridad · 75/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 5 días
    Critical VulnsMEDIAAltoNEWNIS2Inteligencia operacional

    CISA Malcolm

    View CSAF Summary The following versions of CISA Malcolm are affected: Malcolm CVSS Vendor Equipment Vulnerabilities v3 8.8 CISA CISA Malcolm Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Server-Side Request Forgery (SSRF), Authentication Bypass by Spoofing, Missing Authorization, Missing Authentication for Critical Function, Incorrect Authorization, Use of Default Credentials, Improper Certificate Validation, URL Redirection to Untrusted Site ('Open Redirect'), Dependency on Vulnerable Third-Party Component, Use of Password Hash With Insufficient Computational Effort Background Critical Infrastructure Sectors: Energy, Information Technology, Water and Wastewater Countries/Areas Deployed: Worldwide Company Headquarters Location: United States Vulnerabilities Expand All + CVE-2026-90443 A web interface reflects a portion of the request URL into a script context and a hyperlink attribute without adequate encoding, and does not require authentication to reach. This allows an unauthenticated network attacker to craft a link that, when visited by a user, executes arbitrary script in the context of the affected application and can redirect the user's browser to an arbitrary external site. Successful exploitation could allow an attacker to act with the compromised user's session privileges within the application. View CVE Details Affected Products CISA Malcolm Vendor: CISA Product Version: CISA Malcolm <v26.06.0 Product Status: known_affected Remediations Vendor fix The latest version of Malcolm (September 2026 or later) fixes these vulnerabilities. Affected users are encouraged to update their instance of Malcolm to the latest version. Relevant CWE: CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') Metrics CVSS Version Bas CVEs: CVE-2026-90443, CVE-2026-90444, CVE-2026-90445, CVE-2026-90446, CVE-2026-90447. Vendors: CISA Product Version: CISA Malcolm <v26, GitHub. DORA relevance: medium.

    Por qué importa

    CISA Malcolm presenta múltiples vulnerabilidades críticas, incluyendo inyección de comandos y bypass de autenticación, que permiten a atacantes no autenticados comprometer la integridad y confidencialidad del sistema.

    Acción recomendada

    Actualice inmediatamente todas las instancias de CISA Malcolm a la versión de septiembre de 2026 o superior y audite los logs en busca de intentos de explotación previos.

    Vendors:CISASectores:EnergyInformation TechnologyWater and WastewaterMITRE:T1190 Exploit Public-Facing ApplicationCISO · Vulnerability Management · IT Ops
    Mapeo regulatorio · riesgo 55

    La vulnerabilidad de alta severidad en Malcolm requiere medidas de gestión de riesgos y remediación, pero no hay evidencia de explotación, incidente significativo o afectación confirmada a una entidad sujeta a NIS2.

    NIS2 · Art. 21 Cybersecurity risk-management measures (direct)
    Publicado
    01 oct 2026, 12:00
    Actualizado
    01 oct 2026, 17:01
    Detectado
    01 oct 2026, 17:01
    Fuente
    CISA All Alerts
    Referencia técnica
    NVD · CVE-2026-90443
    CISA All Alerts
    Prioridad · 59/100published <24h (+40) · high severity (+15) · regulatory relevance (+15) · CISA All Alerts authority (+12) · updated <24h (+5 cap)
    hace 16 horas