Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.
Para análisis editorial y noticias generales visita Noticias.
Discover muestra 8 señales operativas recientes. Sube a Consultant Pro o Professional Pro para abrir el feed completo, histórico ampliado y el catálogo KEV.
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data. [...] CVEs: CVE-2026-12569. CISA KEV/exploitation signal detected. Vendors: Microsoft, SAP, Adobe, Salesforce, ServiceNow. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →
Threat actors have begun exploiting a critical Microsoft SharePoint flaw following the release of proof-of-concept (PoC) exploit code by Rapid7. About CVE-2026-55040 Tracked as CVE-2026-55040, the vulnerability was patched by Microsoft as part of its July 2026 Patch Tuesday updates. “The authentication feature could be bypassed as this vulnerability allows impersonation,” Microsoft said. “Exploiting this vulnerability could allow an attacker to disclose files and modify data, but the attacker cannot impact the availability of the … More → The post Attackers exploit critical SharePoint flaw after PoC goes public (CVE-2026-55040) appeared first on Help Net Security. CVEs: CVE-2026-55040, CVE-2026-63520, CVE-2026-68820. CISA KEV/exploitation signal detected. Vendors: Microsoft, Rapid7, Salesforce, ServiceNow. DORA relevance: high.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Comprueba la exposición a CVE-2026-55040, CVE-2026-63520, CVE-2026-68820 en el inventario de activos y las herramientas de vulnerabilidades.
The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek. CVEs: CVE-2026-26035, CVE-2026-70468, CVE-2026-70465, CVE-2026-49975. CISA KEV/exploitation signal detected. Vendors: Microsoft, Fortinet, VMware, Adobe, Ivanti, SonicWall, Apache, Salesforce, ServiceNow, WordPress, Zoom. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Comprueba la exposición a CVE-2026-26035, CVE-2026-70468, CVE-2026-70465 en el inventario de activos y las herramientas de vulnerabilidades.
A high-severity vulnerability (CVE-2026-20349) is being leveraged by attackers to temporarily interrupt the operation of Cisco firewalls, the company has confirmed. The flaw has been added to CISA’s Known Exploited Vulnerabilities catalog and needs to be remediated by US civilian federal agencies by August 14, 2026. Details about the attacks are currently under wraps. Cisco only shared that its Product Security Incident Response Team (PSIRT) became aware of active exploitation of this vulnerability in August … More → The post Cisco fixes vulnerability exploited to DoS its firewalls (CVE-2026-20349) appeared first on Help Net Security. CVEs: CVE-2026-20349, CVE-2026-68820. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Salesforce, ServiceNow. DORA relevance: high.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Comprueba la exposición a CVE-2026-20349, CVE-2026-68820 en el inventario de activos y las herramientas de vulnerabilidades.
Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent bypass that provides system-level control to attackers once they gain any level of access. The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security. Nightmare Eclipse has not provided the further details we requested, however Microsoft sent a brief statement, saying, “Microsoft is aware of the reported vulnerability and is actively investigating the validity and potential applicability of these claims,” and reiterating its commitment to investigating issues and supporting coordinated disclosure. But the proof of concept (PoC) security bypass, ShieldBreak, described by Nightmare Eclipse in a series of public posts, potentially threatens to be more damaging than earlier bypass. Like other recently reported vulnerabilities, ShieldBreak requires an attacker to first somehow gain system access, typically via a successful phishing scam. Once in, however, the attacker can gain full admin/root access. But there is a troubling psychological component to ShieldBreak, in that it is a bypass for a recently posted security patch from Microsoft, noted Justin Greis, CEO of consulting firm Acceligence. The problem is that CISOs who have already deployed that patch might feel protected when they are not. “This one is concerning because the patch bypass directly calls the integrity of the remediation into question,” he said. “ShieldBreak appears to demonstrate that an attacker can bypass the fix Microsoft shipped for CVE-2026-50656 and ultimately obtain system-level privileges on the endpoint. That is an important distinction for enterprise defenders, because organizations may believe they have already remediated the underlying vulnerability. A successful patch bypass means the exposure can persist even after the normal vulnerability-management process says the system is protected.” Greis added tha CVEs: CVE-2026-50656. CISA KEV/exploitation signal detected. Vendors: Microsoft, Google, ServiceNow, Check Point. DORA relevance: high.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Comprueba la exposición a CVE-2026-50656 en el inventario de activos y las herramientas de vulnerabilidades.
Just weeks after Microsoft patched a critical hole in Microsoft Defender, a cybersecurity researcher has posted an apparent workaround that provides system-level control to attackers once they gain any level of access. The researcher, who goes by the name Nightmare Eclipse, has been engaged in a long-running battle with Microsoft Security. As of publication time, neither Microsoft nor Nightmare Eclipse has provided further details we requested. But the proof of concept (PoC) security workaround, ShieldBreak, described by Nightmare Eclipse in a series of public posts, potentially threatens to be more damaging than earlier workarounds. Like other recently reported vulnerabilities, ShieldBreak requires an attacker to first somehow gain system access, typically via a successful phishing scam. Once in, however, the attacker can gain full admin/root access. But there is a troubling psychological component to ShieldBreak, in that it is a workaround for a recently posted security patch from Microsoft, noted Justin Greis, CEO of consulting firm Acceligence. The problem is that CISOs who have already deployed that patch might feel protected when they are not. “This one is concerning because the patch bypass directly calls the integrity of the remediation into question,” he said. “ShieldBreak appears to demonstrate that an attacker can bypass the fix Microsoft shipped for CVE-2026-50656 and ultimately obtain system-level privileges on the endpoint. That is an important distinction for enterprise defenders, because organizations may believe they have already remediated the underlying vulnerability. A successful patch bypass means the exposure can persist even after the normal vulnerability-management process says the system is protected.” Greis added that such workarounds can reduce overall trust in official patches. “When public proof of concept code can bypass it, the CISO’s question becomes ‘have we actually removed the exposure?’ rather than simply ‘have we deployed the pat CVEs: CVE-2026-50656. CISA KEV/exploitation signal detected. Vendors: Microsoft, Google, ServiceNow, Check Point. DORA relevance: high.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Comprueba la exposición a CVE-2026-50656 en el inventario de activos y las herramientas de vulnerabilidades.
The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild. The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek. CVEs: CVE-2026-55040, CVE-2026-63520, CVE-2026-50522, CVE-2026-58644, CVE-2026-56164. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Google, Rapid7, Ivanti, Mozilla, Siemens, Salesforce, ServiceNow, Zoom. DORA relevance: medium.
Por qué importa
Explotación activa confirmada. Riesgo material para entornos expuestos.
Acción recomendada
Comprueba la exposición a CVE-2026-55040, CVE-2026-63520, CVE-2026-50522 en el inventario de activos y las herramientas de vulnerabilidades.