CyberComplianceAI
InicioNoticiasIntel Center
CyberForoPrecios
Acceder
The Pulse · Live Intelligence Feed

Intel Center

Una señal es cualquier evento operacional detectado en las últimas 24h–30d: CVEs en KEV explotados activamente, advisories de vendor, exposición cloud, ransomware y avisos regulatorios. Cada señal se prioriza por severidad, freshness y match con tu Digital Twin.

Para análisis editorial y noticias generales visita Noticias.

Priorizado con IA

La priorizacion, resumen y accion recomendada pueden estar enriquecidos por IA y heuristicas. La fuente original permanece visible para verificacion.

Consola en vivo · last 7d
Señales (ventana)7
Última detecciónhace 1 d
Monitorizado porintelligence scouter
4signals
Acción Requerida
Ventana24h7d30d7d / 30d solo en ProSeveridadCríticaAltaLimpiar filtros
Tecnología afectadaMicrosoft129Google56Cisco48Apple39ServiceNow30GitHub30Salesforce28Palo Alto Networks21Adobe21Siemens16

Priority Command Strip

What your team should look at right now

4 señales críticas
  1. Action RequiredImmediate2d

    Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    SecurityWeek · Microsoft · FortinetReview signal
  2. Action Required
All7Action Required4Exploited & KEV3Critical Vulns0Cloud & Identity3
INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

Fortinet Patches Authentication Flaws in FortiWeb and FortiManager

The vulnerabilities could allow attackers to log in with random usernames and passwords or impersonate any FortiGate appliance. The post Fortinet Patches Authentication Flaws in FortiWeb and FortiManager appeared first on SecurityWeek. CVEs: CVE-2026-26035, CVE-2026-70468, CVE-2026-70465, CVE-2026-49975. CISA KEV/exploitation signal detected. Vendors: Microsoft, Fortinet, VMware, Adobe, Ivanti, SonicWall, Apache, Salesforce, ServiceNow, WordPress, Zoom. DORA relevance: medium.

Por qué importa

Explotación activa confirmada. Riesgo material para entornos expuestos.

Acción recomendada

Filtered for operational relevance. Powered by a curated catalog of vulnerability, CERT, vendor and threat-intelligence sources.View methodology →

CyberComplianceAI

¿Quieres esto priorizado para tu rol cada mañana?

El Morning Brief Pro filtra estas señales por tu rol (CISO, SecOps, risk), sector y framework prioritario, y las convierte en acciones recomendadas listas a las 7:00.

Probar Morning Brief Pro →Ver precio

¿Aún no quieres Pro? Recibe el resumen de cumplimiento gratis cada semana.

3signals
Explotados & KEV
Vulns Críticas

Sin CVEs críticas frescas en la ventana actual.

Advisories de Vendor

Sin nuevos advisories PSIRT de vendor en la ventana.

También en el Intel CenterCloud & Identity3
Fortinet15
Linux14
Ivanti14
SonicWall14
Immediate
3d

SharePoint Vulnerability Exploited Shortly After PoC Release

Explotación activa confirmada. Riesgo material para entornos expuestos.

SecurityWeek · Microsoft · CiscoReview signal
  • Action RequiredImmediate1d

    Attackers target zero-day vulnerability in geospatial data platform GeoServer

    Severidad crítica con vector accionable a corto plazo.

    CSO Online · Microsoft · GoogleReview signal
  • Action RequiredImmediate2d

    Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

    Severidad crítica con vector accionable a corto plazo.

    SecurityWeek · Microsoft · CiscoReview signal
  • Comprueba la exposición a CVE-2026-26035, CVE-2026-70468, CVE-2026-70465 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:MicrosoftFortinetVMwareAdobeCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 ago 2026, 10:40
    Actualizado
    13 ago 2026, 14:02
    Detectado
    13 ago 2026, 14:02
    Fuente
    SecurityWeek
    Referencia técnica
    NVD · CVE-2026-26035
    SecurityWeek
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    SharePoint Vulnerability Exploited Shortly After PoC Release

    The vulnerability was patched by Microsoft in July and CISA warned that it could end up being exploited in the wild. The post SharePoint Vulnerability Exploited Shortly After PoC Release appeared first on SecurityWeek. CVEs: CVE-2026-55040, CVE-2026-63520, CVE-2026-50522, CVE-2026-58644, CVE-2026-56164. CISA KEV/exploitation signal detected. Vendors: Microsoft, Cisco, Google, Rapid7, Ivanti, Mozilla, Siemens, Salesforce, ServiceNow, Zoom. DORA relevance: medium.

    Por qué importa

    Explotación activa confirmada. Riesgo material para entornos expuestos.

    Acción recomendada

    Comprueba la exposición a CVE-2026-55040, CVE-2026-63520, CVE-2026-50522 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:MicrosoftCiscoGoogleRapid7CISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    12 ago 2026, 14:47
    Actualizado
    12 ago 2026, 15:01
    Detectado
    12 ago 2026, 15:01
    Fuente
    SecurityWeek
    Referencia técnica
    NVD · CVE-2026-55040
    SecurityWeek
    Prioridad · 82/100published <7d (+25) · active exploitation/KEV/ransomware signal (+50) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 3 días
    INMEDIATOCríticoACTION REQUIREDGDPRNIS2AI ACTInteligencia operacional

    Attackers target zero-day vulnerability in geospatial data platform GeoServer

    Security researchers have seen evidence that attackers are attempting to exploit a currently unpatched SQL injection vulnerability in GeoServer, an open-source web server for managing and publishing geospatial data. The software is widely used by organizations in many industries, including the government, defense, science, education, engineering and technology sectors, and has been targeted by hackers in the past. A bug bounty hunter shared the vulnerability Wednesday on X as a zero day. According to his post, the jsonArrayContains function contains a vulnerability that allows unauthenticated users to inject SQL commands into the database. If the database runs with administrator permissions on Microsoft SQL Server, the account also has the ability to execute commands on the system, so the SQL injection becomes a remote code execution vector. Another user confirmed on X that they were able to reproduce the flaw in a non-default configuration. “Within hours of public disclosure, we began observing exploitation attempts and have since recorded hundreds of attempts originating from a small number of source IP addresses,” researchers from security firm watchTowr told CSO via email on Thursday. “Yet another example of how quickly attackers move once a vulnerability enters the public domain.” So far, the researchers haven’t seen any malicious payloads or commands being sent, and the attempts look more like probes to identify vulnerable GeoServer instances. However, this is likely to change; GeoServer has a history of being exploited, since its users are usually seen as high value targets. Until a patch becomes available, organizations who run GeoServer should identify their internet exposed instances and restrict public access to them. They should also check the logs for any signs that exploitation has already occurred. Vendors: Microsoft, Google, Zoom, Node.js, Zimbra. DORA relevance: high.

    Por qué importa

    Severidad crítica con vector accionable a corto plazo.

    Acción recomendada

    Avisa a los owners de los stacks Microsoft, Google, Zoom, Node.js.

    Vendors:MicrosoftGoogleZoomNode.jsCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 ago 2026, 20:43
    Actualizado
    13 ago 2026, 23:02
    Detectado
    13 ago 2026, 23:02
    Fuente
    CSO Online
    Referencia técnica
    Original advisory
    CSO Online
    Prioridad · 48/100published <7d (+25) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 1 día
    INMEDIATOCríticoACTION REQUIREDGDPRInteligencia operacional

    Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’

    Dropped on Patch Tuesday, the exploit allows any user to spawn a shell with System privileges. The post Nightmare Eclipse Drops Windows Zero-Day Exploit ‘ShieldBreak’ appeared first on SecurityWeek. CVEs: CVE-2026-50656. Vendors: Microsoft, Cisco, SAP, Adobe, Ivanti, SonicWall, Salesforce, ServiceNow, Zoom. DORA relevance: medium.

    Por qué importa

    Severidad crítica con vector accionable a corto plazo.

    Acción recomendada

    Comprueba la exposición a CVE-2026-50656 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:MicrosoftCiscoSAPAdobeCISO · SecOps · Incident Response · Vulnerability Management
    Publicado
    13 ago 2026, 08:38
    Actualizado
    13 ago 2026, 09:02
    Detectado
    13 ago 2026, 09:02
    Fuente
    SecurityWeek
    Referencia técnica
    NVD · CVE-2026-50656
    SecurityWeek
    Prioridad · 48/100published <7d (+25) · critical severity (+25) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    Cloud & IdentityMEDIAAltoNEWGDPRInteligencia operacional

    Adobe Commerce Bug Targeted Immediately After Disclosure

    The first exploitation attempts targeting CVE-2026-71362 were observed shortly after Adobe released patches. The post Adobe Commerce Bug Targeted Immediately After Disclosure appeared first on SecurityWeek. CVEs: CVE-2026-71362. Vendors: Microsoft, Fortinet, VMware, Adobe, Ivanti, SonicWall, WordPress, Zoom. DORA relevance: medium.

    Por qué importa

    Postura cloud / identity comprometida o reforzada. Revisar configuración y baseline.

    Acción recomendada

    Comprueba la exposición a CVE-2026-71362 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:MicrosoftFortinetVMwareAdobeCISO · Cloud Security · SecOps
    Publicado
    13 ago 2026, 14:17
    Actualizado
    13 ago 2026, 18:02
    Detectado
    13 ago 2026, 18:02
    Fuente
    SecurityWeek
    Referencia técnica
    NVD · CVE-2026-71362
    SecurityWeek
    Prioridad · 41/100published <7d (+25) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    Cloud & IdentityMEDIAAltoNEWGDPRInteligencia operacional

    Critical VMware vCenter Vulnerability in Attackers’ Crosshairs

    Tracked as CVE-2026–59310, the directory traversal bug allows remote attackers to execute arbitrary code. The post Critical VMware vCenter Vulnerability in Attackers’ Crosshairs appeared first on SecurityWeek. CVEs: CVE-2026-59310. Vendors: Microsoft, Fortinet, VMware, Adobe, Ivanti, SonicWall, Siemens, Salesforce, ServiceNow, WordPress, Zoom. DORA relevance: medium.

    Por qué importa

    Postura cloud / identity comprometida o reforzada. Revisar configuración y baseline.

    Acción recomendada

    Comprueba la exposición a CVE-2026-59310 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:MicrosoftFortinetVMwareAdobeCISO · Cloud Security · SecOps
    Publicado
    13 ago 2026, 09:06
    Actualizado
    13 ago 2026, 14:02
    Detectado
    13 ago 2026, 14:02
    Fuente
    SecurityWeek
    Referencia técnica
    NVD · CVE-2026-59310
    SecurityWeek
    Prioridad · 41/100published <7d (+25) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días
    Cloud & IdentityMEDIAAltoNEWGDPRInteligencia operacional

    WordPress 7.0.4 Patches Remote Code Execution Vulnerability

    Attackers with Author-level user or higher permissions could exploit the flaw via malicious Postscript files. The post WordPress 7.0.4 Patches Remote Code Execution Vulnerability appeared first on SecurityWeek. CVEs: CVE-2026-65640. Vendors: Microsoft, Fortinet, VMware, SAP, Adobe, Ivanti, SonicWall, Salesforce, ServiceNow, WordPress, Zoom. DORA relevance: medium.

    Por qué importa

    Postura cloud / identity comprometida o reforzada. Revisar configuración y baseline.

    Acción recomendada

    Comprueba la exposición a CVE-2026-65640 en el inventario de activos y las herramientas de vulnerabilidades.

    Vendors:MicrosoftFortinetVMwareSAPCISO · Cloud Security · SecOps
    Publicado
    13 ago 2026, 12:53
    Actualizado
    13 ago 2026, 14:02
    Detectado
    13 ago 2026, 14:02
    Fuente
    SecurityWeek
    Referencia técnica
    NVD · CVE-2026-65640
    SecurityWeek
    Prioridad · 41/100published <7d (+25) · high severity (+15) · regulatory relevance (+15) · source authority (+2) · updated <7d (+3 cap)
    hace 2 días