Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.
Para análisis editorial y noticias generales visita Noticias.
Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Pro para abrir el feed completo, histórico ampliado y el catálogo KEV.
The security defect is described as an SQL injection that could allow attackers to achieve remote code execution. The post Hackers Exploiting Unpatched GeoServer Zero-Day appeared first on SecurityWeek. CISA KEV/exploitation signal detected. Vendors: Microsoft, Fortinet, VMware, Oracle, Adobe, Apple, Ivanti, SonicWall, WordPress. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →
[CISA KEV actively exploited] Vendor: Oracle | Product: E-Business Suite | Oracle E-Business Suite contains an improper privilege management vulnerability that allows an unauthenticated attacker with network access via HTTP to compromise Oracle Payments. Successful attacks of this vulnerability can result in takeover of Oracle Payments. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-07-18 | Ransomware use: Unknown | Added: 2026-07-15 CVEs: CVE-2026-46817. CISA KEV/exploitation signal detected. Vendors: Oracle. DORA relevance: high.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
[CISA KEV actively exploited ransomware] Vendor: Oracle | Product: PeopleSoft Enterprise PeopleTools | Oracle PeopleSoft Enterprise PeopleTools contains a missing authentication for critical function vulnerability which could allow an unauthenticated attacker to obtain takeover of PeopleSoft Enterprise PeopleTools. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-06-15 | Ransomware use: Known | Added: 2026-06-12 CVEs: CVE-2026-35273. CISA KEV/exploitation signal detected. Vendors: Oracle. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.
[CISA KEV actively exploited] Vendor: Oracle | Product: WebLogic Server | Oracle WebLogic contains an unspecified vulnerability that could allow an unauthenticated attacker with network access via T3, IIOP to compromise Oracle WebLogic Server. Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle WebLogic Server accessible data. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2026-06-04 | Ransomware use: Unknown | Added: 2026-06-01 CVEs: CVE-2024-21182. CISA KEV/exploitation signal detected. Vendors: Oracle. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
[CISA KEV actively exploited] Vendor: Oracle | Product: Fusion Middleware | Oracle Fusion Middleware contains a missing authentication for critical function vulnerability, allowing unauthenticated remote attackers to take over Identity Manager. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2025-12-12 | Ransomware use: Unknown | Added: 2025-11-21 CVEs: CVE-2025-61757. CISA KEV/exploitation signal detected. Vendors: Oracle. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
[CISA KEV actively exploited ransomware] Vendor: Oracle | Product: E-Business Suite | Oracle E-Business Suite contains a server-side request forgery (SSRF) vulnerability in the Runtime component of Oracle Configurator. This vulnerability is remotely exploitable without authentication. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2025-11-10 | Ransomware use: Known | Added: 2025-10-20 CVEs: CVE-2025-61884. CISA KEV/exploitation signal detected. Vendors: Oracle. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
[CISA KEV actively exploited ransomware] Vendor: Oracle | Product: E-Business Suite | Oracle E-Business Suite contains an unspecified vulnerability in the BI Publisher Integration component. The vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Concurrent Processing. Successful attacks can result in takeover of Oracle Concurrent Processing. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2025-10-27 | Ransomware use: Known | Added: 2025-10-06 CVEs: CVE-2025-61882. CISA KEV/exploitation signal detected. Vendors: Oracle. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Akira ransomware affiliates were seen using a new technique to evade endpoint detection and response (EDR), where they rebooted a compromised Windows system into Safe Mode with Networking enabled. According to Huntress, the technique successfully took both its agent and Microsoft Defender’s real-time protection offline. This, the researchers said, gave the attacker a window to operate without endpoint defenses. The incident investigated by Huntress began on August 4 with a credential-spraying attack against an exposed SonicWall SSL VPN. About seven minutes after the failed login attempts began, an attacker successfully authenticated to an account that did not have multi-factor authentication (MFA) enabled, Huntress analyst James Northey said in a blog post. Two hours after authentication was managed, the operator reportedly accessed the domain controller over RDP, performed extensive Active Directory enumeration, and subsequently moved to an application server to archive mapped file shares with WinRAR. The stolen data was uploaded to an attacker-controlled S3 bucket using s5cmd, establishing the data-theft component of a double-extortion attack. Ultimately, AnyDesk was installed on the host machine for persistent remote access and to deliver the Akira ransomware payload. This is when the operator used “msconfig.exe” to force the machine into Safe Mode with Networking, instead of disabling EDR directly. Huntress says this is the first time it has observed Akira using the technique. Safe Mode is becoming a popular ransomware technique Safe Mode is normally a Windows troubleshooting environment that loads only essential drivers and services. That makes it useful to attackers because many third-party security products are excluded from the minimal startup configuration. Anticipating that AnyDesk itself might also be unavailable in Safe Mode, the attackers modified the Safe Boot registry configuration to ensure the remote-access service would start. The approach is not e Vendors: Microsoft, Google, AWS, Oracle, SonicWall, Atlassian, GitHub. DORA relevance: high.
Por qué importa
Explotación reportada sobre Microsoft / Google. Verificar exposición real en el inventario.
Acción recomendada
Avisa a los owners de los stacks Microsoft, Google, AWS, Oracle.
Vendors:MicrosoftGoogleAWSOracleCISO · Vulnerability Management · SecOps · IT Ops