CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)4
Última detecciónhace 25 d
Monitorizado porintelligence scouter
4signals
Acción Requerida
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaMicrosoft128Google63Cisco47Apple45ServiceNow30GitHub29Salesforce28Palo Alto Networks21Adobe21Siemens16

Priority Command Strip

What your team should look at right now

4 señales críticas
  1. Action RequiredImmediate25d

    CVE-2026-0770 · Langflow Langflow: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · Langflow · GitHubReview signal
  2. Action RequiredImmediate
All4Action Required4Exploited & KEV3Critical Vulns0
INMEDIATOCríticoACTION REQUIREDInteligencia operacional

CVE-2026-0770 · Langflow Langflow: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

[CISA KEV actively exploited] Vendor: Langflow | Product: Langflow | Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-07-24 | Ransomware use: Unknown | Added: 2026-07-21 CVEs: CVE-2026-0770. CISA KEV/exploitation signal detected. Vendors: Langflow, GitHub. DORA relevance: medium.

Por qué importa

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

3signals
Explotados & KEV
Vulns Críticas

Sin CVEs críticas frescas en la ventana actual.

Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

Fortinet15
Ivanti14
SonicWall14
VMware13
39d

CVE-2026-55255 · Langflow Langflow: Langflow Authorization Bypass Through User-Controlled Key Vulnerability

Explotación activa confirmada. Riesgo material para entornos expuestos.

CISA KEV Catalog · LangflowReview signal
  • Action RequiredImmediate86d

    CVE-2025-34291 · Langflow Langflow: Langflow Origin Validation Error Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · LangflowReview signal
  • Action RequiredImmediate90d

    CVE-2026-33017 · Langflow Langflow: Langflow Code Injection Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · LangflowReview signal
  • Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:LangflowGitHubCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    21 jul 2026, 00:00
    Actualizado
    21 jul 2026, 15:00
    Detectado
    21 jul 2026, 15:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-0770
    CISA KEV Catalog
    Prioridad · 76/100published <30d (+10) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 25 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2026-55255 · Langflow Langflow: Langflow Authorization Bypass Through User-Controlled Key Vulnerability

    [CISA KEV actively exploited] Vendor: Langflow | Product: Langflow | Langflow contains an authorization bypass through user-controlled key vulnerability which allows an authenticated attacker to execute any flow belonging to another user by specifying the victim's flow ID in the request. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-07-10 | Ransomware use: Unknown | Added: 2026-07-07 CVEs: CVE-2026-55255. CISA KEV/exploitation signal detected. Vendors: Langflow. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:LangflowCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    07 jul 2026, 00:00
    Actualizado
    07 jul 2026, 18:00
    Detectado
    07 jul 2026, 18:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-55255
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 39 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2025-34291 · Langflow Langflow: Langflow Origin Validation Error Vulnerability

    [CISA KEV actively exploited] Vendor: Langflow | Product: Langflow | Langflow contains an origin validation error vulnerability in which an overly permissive CORS configuration combined with a refresh token cookie configured as SameSite=None allows a malicious webpage to perform cross-origin requests that include credentials and successfully call the refresh endpoint. This could allow the attacker to execute arbitrary code and achieve full system compromise via obtained tokens that permit access to authenticated endpoints. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2026-06-04 | Ransomware use: Unknown | Added: 2026-05-21 CVEs: CVE-2025-34291. CISA KEV/exploitation signal detected. Vendors: Langflow. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Vendors:LangflowCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    21 may 2026, 00:00
    Actualizado
    21 may 2026, 20:00
    Detectado
    21 may 2026, 20:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2025-34291
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 86 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2026-33017 · Langflow Langflow: Langflow Code Injection Vulnerability

    [CISA KEV actively exploited] Vendor: Langflow | Product: Langflow | Langflow contains a code injection vulnerability that could allow building public flows without requiring authentication. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2026-04-08 | Ransomware use: Unknown | Added: 2026-03-25 CVEs: CVE-2026-33017. CISA KEV/exploitation signal detected. Vendors: Langflow. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Vendors:LangflowCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    25 mar 2026, 00:00
    Actualizado
    17 may 2026, 13:01
    Detectado
    17 may 2026, 13:01
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-33017
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 90 días