CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)28
Última detecciónhace 17 h
Monitorizado porintelligence scouter
16signals
Acción Requerida
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaMicrosoft111Google100Citrix72GitHub67Apple59Cisco52Cloudflare36Linux31WordPress29Mozilla28

Priority Command Strip

What your team should look at right now

6 señales críticas
  1. Action RequiredImmediate1d

    Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Palo Alto Unit 42 · Palo Alto Networks · CitrixReview signal
  2. Action Required
All28Action Required16Exploited & KEV8Critical Vulns3Cloud & Identity8Monitor1

Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Studio para abrir el feed completo, histórico ampliado y el catálogo KEV.

INMEDIATOCríticoACTION REQUIREDInteligencia operacional

Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30)

Unit 42 is aware of possible 0-day activity against NetScaler devices. Citrix reports CVE-2026-88771, CVE-2026-88772 have been exploited in the wild. The post Threat Brief: NetScaler Zero Days CVE-2026-88771 and CVE-2026-88772 Exploited in the Wild (Updated September 30) appeared first on Unit 42. CVEs: CVE-2026-88771, CVE-2026-88772. CISA KEV/exploitation signal detected. Vendors: Palo Alto Networks, Citrix, Apache, PHP, Cloudflare. DORA relevance: medium.

Por qué importa

Dos vulnerabilidades zero-day críticas en NetScaler han sido explotadas in-the-wild y cuentan con señal de CISA KEV, lo que requiere triage y remediación inmediata.

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

8signals
Explotados & KEV
3signals
Vulns Críticas
Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

También en el Intel CenterCloud & Identity8Monitor1
PHP28
MikroTik26
GitLab23
Check Point21
Immediate
2d

Hackers exploit Citrix NetScaler zero-day to deploy web shells

Explotación activa confirmada. Riesgo material para entornos expuestos.

BleepingComputer · Microsoft · GoogleReview signal
  • Action RequiredImmediate7d

    CVE-2026-87902 · WordPress Core: WordPress Core Remote File Inclusion Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · WordPress · GitHubReview signal
  • Action RequiredImmediate84d

    CVE-2026-48939 · iCagenda iCagenda: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · iCagenda · PHPReview signal
  • Action RequiredImmediate87d

    CVE-2026-48908 · JoomShaper SP Page Builder: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · JoomShaper · PHPReview signal
  • Action RequiredImmediate108d

    CVE-2026-48907 · Widget Factory Joomla Content Editor : Widget Factory Joomla Content Editor Improper Access Control Vulnerability

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    CISA KEV Catalog · Widget Factory · PHPReview signal
  • Acción recomendada

    Comprueba inmediatamente la exposición de CVE-2026-88771 y CVE-2026-88772, aplica las mitigaciones o parches del proveedor y eleva el estado al CISO.

    Vendors:CitrixPalo Alto NetworksApachePHPSectores:cloud/SaaSCISO · SecOps · Incident Response · Vulnerability Management
    Mapeo regulatorio · riesgo 65

    La explotación activa de dos zero-days críticos en NetScaler exige detección, gestión y clasificación inmediata de la amenaza conforme a DORA, aunque no se ha confirmado impacto en la entidad.

    DORA · Art. 10 Detection (direct) · Art. 13 Learning and evolving (direct) · Art. 17 ICT-related incident management process (direct)
    Publicado
    30 sept 2026, 20:00
    Actualizado
    01 oct 2026, 01:00
    Detectado
    01 oct 2026, 01:00
    Fuente
    Palo Alto Unit 42
    Referencia técnica
    NVD · CVE-2026-88771
    Palo Alto Unit 42
    Prioridad · 84/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · Palo Alto Unit 42 authority (+6) · updated <7d (+3 cap)
    hace 1 día
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    Hackers exploit Citrix NetScaler zero-day to deploy web shells

    Cybersecurity firms say attackers exploited the Citrix NetScaler CVE-2026-88772 zero-day to deploy custom web shells and tunneling malware, gain root access, steal credentials, and spread into internal networks. [...] CVEs: CVE-2026-88772, CVE-2026-88771. CISA KEV/exploitation signal detected. Vendors: Microsoft, Google, Oracle, Apple, Citrix, Atlassian, Linux, PHP, Python, Cloudflare. DORA relevance: medium.

    Por qué importa

    Explotación activa de un zero-day en Citrix NetScaler que permite acceso root, robo de credenciales y movimiento lateral en la red interna.

    Acción recomendada

    Identificar y parchear inmediatamente todos los dispositivos Citrix NetScaler expuestos; buscar indicadores de compromiso (web shells) en los logs del sistema.

    Vendors:CitrixSectores:public sectorcloud/SaaSMITRE:T1190 Exploit Public-Facing ApplicationT1505.003 Server Software Component: Web ShellT1078 Valid AccountsCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    29 sept 2026, 18:37
    Actualizado
    29 sept 2026, 22:01
    Detectado
    29 sept 2026, 22:01
    Fuente
    BleepingComputer
    Referencia técnica
    NVD · CVE-2026-88772
    BleepingComputer
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2026-87902 · WordPress Core: WordPress Core Remote File Inclusion Vulnerability

    [CISA KEV actively exploited] Vendor: WordPress | Product: Core | WordPress Core contains a remote file inclusion vulnerability which could allow an unauthenticated attacker to make page-template resolution include a chosen readable local `.php` file outside the active theme directories, leading to remote code execution. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-09-28 | Ransomware use: Unknown | Added: 2026-09-25 CVEs: CVE-2026-87902. CISA KEV/exploitation signal detected. Vendors: WordPress, GitHub, PHP. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:WordPressGitHubPHPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    25 sept 2026, 00:00
    Actualizado
    25 sept 2026, 20:00
    Detectado
    25 sept 2026, 20:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-87902
    CISA KEV Catalog
    Prioridad · 78/100published <30d (+10) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12) · updated <7d (+3 cap)
    hace 7 días
    INMEDIATOCríticoACTION REQUIREDInteligencia operacional

    CVE-2026-48939 · iCagenda iCagenda: iCagenda Unrestricted Upload of File with Dangerous Type Vulnerability

    [CISA KEV actively exploited] Vendor: iCagenda | Product: iCagenda | iCagenda contains an unrestricted upload of file with dangerous type vulnerability that allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-07-13 | Ransomware use: Unknown | Added: 2026-07-10 CVEs: CVE-2026-48939. CISA KEV/exploitation signal detected. Vendors: iCagenda. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:iCagendaPHPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    10 jul 2026, 00:00
    Actualizado
    10 jul 2026, 18:00
    Detectado
    10 jul 2026, 18:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-48939
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 84 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2026-48908 · JoomShaper SP Page Builder: JoomShaper SP Page Builder Unrestricted Upload of File with Dangerous Type Vulnerability

    [CISA KEV actively exploited] Vendor: JoomShaper | Product: SP Page Builder | JoomShaper SP Page Builder contains an unrestricted upload of file with dangerous type vulnerability that allows unauthenticated users to upload arbitrary files, ultimately resulting in the upload and execution of PHP code. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-07-10 | Ransomware use: Unknown | Added: 2026-07-07 CVEs: CVE-2026-48908. CISA KEV/exploitation signal detected. Vendors: JoomShaper. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:JoomShaperPHPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    07 jul 2026, 00:00
    Actualizado
    07 jul 2026, 18:00
    Detectado
    07 jul 2026, 18:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-48908
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 87 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2026-48907 · Widget Factory Joomla Content Editor : Widget Factory Joomla Content Editor Improper Access Control Vulnerability

    [CISA KEV actively exploited] Vendor: Widget Factory | Product: Joomla Content Editor | Widget Factory Joomla Content Editor contains an improper access control vulnerability which could allow for upload and execution of PHP code via the creation of new editor profiles for unauthenticated users. | Required action: Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines. | Due date: 2026-06-19 | Ransomware use: Unknown | Added: 2026-06-16 CVEs: CVE-2026-48907. CISA KEV/exploitation signal detected. Vendors: Widget Factory. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations in accordance with vendor instructions, ensuring compliance with CISA’s BOD 26-04 Prioritizing Security Updates Based on Risk (see URL in Notes) guidance and CISA’s “Forensics Triage Requirements” (see URL in Notes). Follow applicable BOD 26-04 guidance for cloud services or discontinue use of the product if mitigations are unavailable. Stakeholders are responsible for evaluating each asset's internet exposure and ensuring adherence to BOD 26-04 patching guidelines.

    Vendors:Widget FactoryPHPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    16 jun 2026, 00:00
    Actualizado
    16 jun 2026, 20:00
    Detectado
    16 jun 2026, 20:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-48907
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 108 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2026-45247 · Mirasvit Mirasvit Full Page Cache Warmer: Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability

    [CISA KEV actively exploited] Vendor: Mirasvit | Product: Mirasvit Full Page Cache Warmer | Mirasvit Full Page Cache Warmer contains a deserialization of untrusted data vulnerability that could allow unauthenticated attackers to achieve remote code execution by supplying a crafted serialized PHP object in the CacheWarmer cookie. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2026-06-06 | Ransomware use: Unknown | Added: 2026-06-03 CVEs: CVE-2026-45247. CISA KEV/exploitation signal detected. Vendors: Mirasvit. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Vendors:MirasvitPHPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    03 jun 2026, 00:00
    Actualizado
    03 jun 2026, 18:00
    Detectado
    03 jun 2026, 18:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-45247
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 121 días
    INMEDIATOCríticoACTION REQUIREDNIS2CRAInteligencia operacional

    CVE-2026-9082 · Drupal Core: Drupal Core SQL Injection Vulnerability

    [CISA KEV actively exploited] Vendor: Drupal | Product: Core | Drupal Core contains a SQL injection vulnerability that could allow for privilege escalation and remote code execution via specially crafted requests sent with the database abstraction API. | Required action: Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable. | Due date: 2026-05-27 | Ransomware use: Unknown | Added: 2026-05-22 CVEs: CVE-2026-9082. CISA KEV/exploitation signal detected. Vendors: Drupal. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.

    Vendors:DrupalPHPCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    22 may 2026, 00:00
    Actualizado
    22 may 2026, 20:00
    Detectado
    22 may 2026, 20:00
    Fuente
    CISA KEV Catalog
    Referencia técnica
    NVD · CVE-2026-9082
    CISA KEV Catalog
    Prioridad · 69/100publication is historical (+0) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · CISA KEV Catalog authority (+12)
    hace 133 días