⬇ Aktuelle
DARK READING RANSOMWARE 🔴 KRITISCH 10. Sep. 2026

Nightmare-Eclipse Strikes Again With ‚ShieldCrash‘ Windows Exploit

The disgruntled researcher continued their vendetta against Microsoft by publishing yet another zero-day exploit for Windows Defender.

Weiterlesen →
KREBS ON SECURITY 🔴 KRITISCH 10. Sep. 2026

Microsoft Plugs Nearly 400 Security Holes

Microsoft today released updates to remedy at least 398 security vulnerabilities in its Windows operating systems and supported software, including one weakness that is already…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 09. Sep. 2026

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google on Thursday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned…

Weiterlesen →
HEISE SECURITY 🔴 KRITISCH 09. Sep. 2026

Chrome 153: Google wechselt zu Zweiwochen-Update-Zyklus

Google stellt Chrome auf einen Zweiwochen-Rhythmus um. Version 153 behebt 230 Sicherheitslücken, darunter eine aktiv ausgenutzte.

Weiterlesen →
HEISE SECURITY 🔴 KRITISCH 09. Sep. 2026

September-Patchday: Adobe schließt kritische Zero-Day-Lücke und 172 weitere

Im Zentrum der Adobe-Patch-Welle steht das Update für Adobe Commerce, das bereits akut angegriffen wird. Besonders viele Updates betreffen Experience Manager.

Weiterlesen →
SANS 🔴 KRITISCH 09. Sep. 2026

September 2026 Microsoft Patch Tuesday, (Tue, Sep 8th)

This month, Microsoft released patches for a record-breaking 973 vulnerabilities, including 113 rated critical. It is by far the largest Patch Tuesday to date, well…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 08. Sep. 2026

Adobe Patches Magento Zero-Day Exploited to Deploy Rust Backdoor and PHP Web Shell

Adobe on Monday released security patches to address a maximum-severity flaw impacting Adobe Commerce and Magento Open Source that has come under active exploitation in the wild.…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 07. Sep. 2026

Telerik UI Padding-Oracle Bug Chained to Unauthenticated RCE — Public Exploit Released

A TantoSec proof-of-concept turns an AES-CBC „padding oracle“ in Telerik UI for ASP.NET AJAX into unauthenticated remote code execution — but only against applications in…

Weiterlesen →
HEISE SECURITY 🔴 KRITISCH 07. Sep. 2026

Zero-Day-Lücke StyleSmuggler in Magento und Adobe Commerce wird aktiv ausgenutzt

Onlineshops auf Basis von Magento und Adobe Commerce sind offenbar aufgrund einer ungepatchten Sicherheitslücke namens StyleSmuggler angreifbar.

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 06. Sep. 2026

Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores

Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s server…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 05. Sep. 2026

Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities

Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 04. Sep. 2026

Google Releases Chrome Update to Patch Actively Exploited V8 Zero-Day

Google on Thursday released security updates to patch 12 vulnerabilities, including one that has come under active exploitation in the wild. The high-severity vulnerability, tracked…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 03. Sep. 2026

Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon

The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting…

Weiterlesen →
CERT WARNUNG 🔴 KRITISCH 03. Sep. 2026

Kritische Sicherheitslücken in WordPress – Updates verfügbar

20. Juli 2026 Beschreibung In WordPress existieren zwei Sicherheitslücken. Eine SQL-Injection-Schwachstelle im Parameter „author__not_in“ von „WP_Query“ betrifft WordPress ab Version 6.8. Ab WordPress 6.9 lässt…

Weiterlesen →
DARK READING 🔴 KRITISCH 03. Sep. 2026

SonicWall SMA 1000 Zero-Days Enable Unauthenticated RCE

The exploitation activity follows attacks earlier this summer on two other zero-day vulnerabilities in the vendor’s edge devices.

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 02. Sep. 2026

Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials

Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 02. Sep. 2026

Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another

Forescout Research – Vedere Labs said it used Anthropic’s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 02. Sep. 2026

GeoNetwork Fixes Unauthenticated RCE Chain Affecting Government Geoportal Backends

Two vulnerabilities in GeoNetwork can be chained to achieve unauthenticated remote code execution (RCE) on the open-source geospatial metadata catalog, which sits behind many government…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 02. Sep. 2026

Attackers Exploit Two SonicWall SMA 1000 Zero-Days That May Form an Attack Chain

SonicWall has released security updates to address two security flaws impacting its Secure Mobile Access (SMA) 1000 series VPN appliances that have been exploited in…

Weiterlesen →
CERT WARNUNG 🔴 KRITISCH 02. Sep. 2026

Kritische Sicherheitslücken in SonicWall SMA1000 Series – aktiv ausgenutzt – Updates verfügbar

2.September 2026 Beschreibung In SonicWalls SMA1000 Series Appliances existieren zwei schwerwiegende Sicherheitslücken. Die schwerwiegendere der beiden Schwachstellen ermöglicht es Angreifer:innen aus der Ferne und ohne Authentifizierung,…

Weiterlesen →
DARK READING RANSOMWARE 🔴 KRITISCH 02. Sep. 2026

Stronger Security Drives Ransomware Groups to Recruit From Within

Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions.

Weiterlesen →
CERT WARNUNG 🔴 KRITISCH 29. Aug. 2026

Kritische Sicherheitslücken in SonicWall SMA1000 Series – aktiv ausgenutzt – Updates verfügbar

15. Juli 2026 Beschreibung In den SonicWall SMA1000 Series Appliances existieren mehrere Sicherheitslücken. Die schwerwiegendere der beiden Schwachstellen ermöglicht es Angreifer:innen aus der Ferne und…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 28. Aug. 2026

Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth

Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE)…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 28. Aug. 2026

PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions

PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 28. Aug. 2026

China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access

VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote…

Weiterlesen →
THE HACKER NEWS DATENLECK 🔴 KRITISCH 28. Aug. 2026

OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face

OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 27. Aug. 2026

Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE

Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 27. Aug. 2026

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability…

Weiterlesen →
DARK READING 🟠 HOCH 11. Sep. 2026

Indonesia Hit by Android Banking App-Cloning Campaign

The GoldFactory threat group exploits the Android Work Profile feature to deliver the Gigabud Trojan, while Mantax Otax spreads separately.

Weiterlesen →
DARK READING 🟠 HOCH 11. Sep. 2026

Voice Callers Exploit BYOD to Reach Microsoft 365, Corporate Data

Threat actors are leveraging Microsoft’s Graph API to identify lucrative targets, then passing their access to extortion groups like ShinyHunters.

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 10. Sep. 2026

PaperCut Attacker Uses Hundreds of AI Agents to Compromise 440+ Instances

A suspected Russian-speaking cyber actor has been attributed to the use of artificial intelligence (AI) to devise exploits targeting a recently disclosed pair of security…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 10. Sep. 2026

Check Point Discloses Two 9.8-Rated VPN Certificate Flaws Enabling Unauthenticated RCE

Check Point has patched two critical vulnerabilities in the way its firewall and management products handle VPN certificates. The company says both could allow an…

Weiterlesen →
HEISE SECURITY 🟠 HOCH 10. Sep. 2026

Sicherheitslücken in ePA-Clients: „Die Implementierungen hatten blinde Flecken“

Sicherheitsforscher sorgten für Fixes kritischer Lücken in ePA-Clients und der Telematikinfrastruktur. Dr. Simon Weber erklärt die Details im Interview.

Weiterlesen →
HEISE SECURITY 🟠 HOCH 10. Sep. 2026

Kritische Schadcode-Lücken bedrohen Ivanti Neurons for ITSM

Angreifer können Ivanti Endpoint Manager Mobile, Neurons for ITSM und Sentry attackieren. Sicherheitsupdates sind verfügbar.

Weiterlesen →
SCHNEIER ON SECURITY 🟠 HOCH 10. Sep. 2026

AIs Compress Exploit Timeline

Give an AI agent a mere rumor of an exploit, and it’s enough for them to find it. What’s worse, I found I could use…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 10. Sep. 2026

CISA Flags Exploited Cisco, Citrix, Fortinet Flaws, Sets Sept. 12 Federal Patch Deadline

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added three flaws, each impacting Cisco, Citrix, and Fortinet, to its Known Exploited Vulnerabilities (KEV)…

Weiterlesen →
THE HACKER NEWS APT 🟠 HOCH 10. Sep. 2026

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 09. Sep. 2026

Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

Bitcoin wallet company Alby has warned of a critical flaw in Alby Hub that could have let an attacker take over a wallet and send its funds,…

Weiterlesen →
HEISE SECURITY 🟠 HOCH 09. Sep. 2026

Patchday: Kritische Lücken ermöglichen Attacken auf Android 14, 15, 16 und 17

Der September-Patchday für Android schließt über 90 Sicherheitslücken, darunter mehr als 25 kritische Schwachstellen in Framework, System und Kernel.

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 09. Sep. 2026

N-able N-central Pre-Auth RCE Flaw Exploited in the Wild

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog,…

Weiterlesen →
DARK READING 🟠 HOCH 09. Sep. 2026

Patch Tuesday Sets Another Record With 974 CVEs

Attackers are actively exploiting two of the vulnerabilities and another 58 are more likely to be exploited, according to Microsoft.

Weiterlesen →
SCHNEIER ON SECURITY DATENLECK 🟠 HOCH 08. Sep. 2026

Stealing AI Reasoning Traces

Interesting research: “Stealing Reasoning Traces from Proprietary LLM APIs“: Abstract: Leading large language model providers now conceal their models’ step-by-step reasoning, or chain-of-thought, to protect…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 08. Sep. 2026

PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution

Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. „Requiring prior…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 07. Sep. 2026

N-able Issues Fourth N-central Hotfix in Five Weeks for Unauthenticated RCE Flaw

Every on-premises N-central build below 2026.3.1.14 — including servers updated to Hotfix 3 a day earlier — needs Hotfix 4. N-able’s incident notice says the…

Weiterlesen →
SANS 🟠 HOCH 07. Sep. 2026

Critical MikroTik Vulnerability – Patch Now, (Sun, Sep 6th)

Mikrotik released a patch late last week for an already-exploited vulnerability. The vulnerability allows an SSH authentication bypass and is already being exploited. At this…

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 11. Sep. 2026

„Doom“ läuft jetzt auch mit dem Hirn einer Fruchtfliege

Das Modell des Insektendenkorgans soll lernen, wie der Shooter funktioniert – und wurde auch schon an „Mario 64“ angebunden

Weiterlesen →
THE HACKER NEWS PHISHING 🟢 NIEDRIG 11. Sep. 2026

ThreatsDay: 200 Android Flaws, Browser-Built Phishing, 119K Scam Shops + 23 More Stories

A lot of this week’s security news has the same awkward answer to one question: “Why was that allowed to work?” An extension asks for…

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 11. Sep. 2026

Nostalgie: Wiener bringt verloren geglaubte Spieleschachteln zurück

Games-Archivierung: Benjamin Wimmer sammelt und digitalisiert die Kartonboxen von damals. Jetzt springt die Games-Plattform GOG mit auf und bietet Spieleschachteln als Bastelbogen an

Weiterlesen →
SANS 🟢 NIEDRIG 10. Sep. 2026

Redtail Payload Analysis [Guest Diary], (Wed, Sep 9th)

[This is a Guest Diary by Aaron Ng, an ISC intern as part of the SANS.edu BACS program]

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 10. Sep. 2026

Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks

The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and drops a tampered banking app…

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 10. Sep. 2026

Google Play Early Access Abused to Push Thousands of Deceptive Android Apps

Bad actors are misusing Google Play’s Early Access program to push deceptive apps that claim to offer money, rewards, casino winnings, and premium content. Early…

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 10. Sep. 2026

Ersteindrücke zum iPhone Duo: Falthandy-Verfeinerung mit mieser Selfiekamera

Von der Displaybeschichtung bis hin zu iOS-Anpassungen macht Apple wohl vieles richtig, außer man ist Linkshänder

Weiterlesen →
DER STANDARD DDOS 🟢 NIEDRIG 10. Sep. 2026

„Kallax Storageborn“: Ikea veröffentlicht sprechendes Regal für „Skyrim“

Der Begleiter aus Faserplatten soll Helden vor Überlastung retten

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 10. Sep. 2026

Europäer zahlen extra: Apple erhöht die Preise für alte iPhones deutlich

Das größte iPhone 18 Max kostet 3090 Euro. Aber selbst die Vorjahresmodelle werden durchwegs um 150 Euro teurer

Weiterlesen →
HEISE SECURITY 🟢 NIEDRIG 10. Sep. 2026

Vierter Hacking-Vorfall: Weiteres Anthropic-Modell bricht aus Testumgebung aus

Nachdem Anthropic schon Ende Juli drei Hacking-Angriffe meldete, ist nach Analyse der Daten jetzt noch ein vierter bei Claude Opus 4.6 hinzugekommen.

Weiterlesen →
DARK READING 🟢 NIEDRIG 10. Sep. 2026

EU Cyber Resilience Act to Enforce New Reporting Requirements

Starting Friday, businesses operating in the EU will have just 24 hours to notify the government any time they discover serious product security incidents.

Weiterlesen →
THE HACKER NEWS DATENLECK 🟢 NIEDRIG 10. Sep. 2026

Anthropic Discloses Fourth AI Hacking Incident Involving Claude Opus 4.6

Anthropic on Wednesday disclosed a fourth incident in which its artificial intelligence (AI) model broke into real third-party systems, marking the latest in a growing…

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 10. Sep. 2026

Nearly 1 in 10 Exposed LiteLLM Gateways Accepted the Example „sk-1234“ Admin Key

Nearly one in ten of the internet-facing LiteLLM servers that Wiz Research scanned in February accepted sk-1234, the example admin key in LiteLLM’s own setup guide. LiteLLM is…

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 10. Sep. 2026

Was soll man noch lernen, wenn die KI eh alles weiß?

Bildung muss sich verändern: Warum Menschen Technik verstehen und ihre eigenen Fähigkeiten stärken müssen

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 10. Sep. 2026

Zone5: Runtastic-Gründer Gschwandtner macht die Smartphone-Kamera zum Fitnesstrainer

Keine Sensoren, kein Vorwissen: Wie Florian Gschwandtner mit zehn Minuten Smartphone-Training Fitness und Lebenserwartung steigern will

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 10. Sep. 2026

Wegen KI-Angriff: US-Senat leitet Untersuchung gegen OpenAI ein

Nach dem Angriff auf die Plattform Hugging Face gerät der ChatGPT-Entwickler ins Visier der US-Politik. Autonome KI-Agenten sollen Sicherheitsvorkehrungen umgangen haben.

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 10. Sep. 2026

WTF Apple? Ausgerechnet die Apple Watch soll künftig unser aller Gespräche belauschen

Detailliert führt das Unternehmen aus, wie sicher neue Funktionen wie Siri Recap und Live Rewind technisch umgesetzt wurden, und übersieht dabei das eigentliche Problem

Weiterlesen →
HEISE SECURITY 🟢 NIEDRIG 10. Sep. 2026

OpenAI-Agenten haben auf mehr als 10 weiteren Websites unerlaubt kommuniziert

Sicherheitsforscher haben Spuren ausgebrochener KI-Agenten von OpenAI auf zusätzlichen Webseiten entdeckt. Zumeist haben sie sich auf Wiki-Seiten ausgetauscht.

Weiterlesen →
HEISE SECURITY 🟡 MITTEL 10. Sep. 2026

Jetzt patchen! Angreifer kompromittieren Cisco-Firewalls als Root

Angreifer attackieren derzeit Cisco Secure Firewall Management Center. Sicherheitsupdates sind seit März 2026 verfügbar.

Weiterlesen →
HEISE SECURITY 🟡 MITTEL 10. Sep. 2026

Sicherheitslücken: 36.000 Plex-Media-Server-Instanzen potenziell angreifbar

In aktuellen Versionen von Plex Media Server und Plex Desktop wurden mehrere Schwachstellen geschlossen. Weltweit sind zehntausende Instanzen angreifbar.

Weiterlesen →
WATCHLIST PHISHING 🟢 NIEDRIG 10. Sep. 2026

ID-Austria Phishing als Türöffner für falschen Bankanruf

„Jemand aus dem Ausland möchte Geld von Ihrem Konto abbuchen!“ Mit dieser Behauptung schrecken Kriminelle derzeit auf. Sie geben sich am Telefon als Bankmitarbeiter:innen aus…

Weiterlesen →
DARK READING 🟢 NIEDRIG 10. Sep. 2026

US Government Accuses Chinese AI Firms of Distilling Frontier Models

US agencies claim Chinese companies covertly extracted billions of tokens from OpenAI, Anthropic, Google Gemini, and SpaceX’s Grok to reduce development costs.

Weiterlesen →
DARK READING 🟡 MITTEL 10. Sep. 2026

Mythos Vulnerability Firehose Hits a Human Bottleneck

An analysis of Project Glasswing findings shows only a fraction have reached disclosure, and an even smaller number have been fixed.

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 10. Sep. 2026

U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including…

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 10. Sep. 2026

iPhone Duo und 18 Pro vorgestellt: Ein faltbares Smartphone und saftige Preissteigerungen

Unter dem neuen Chef gibt es den Einstieg ins Foldable-Zeitalter. Parallel dazu werden beim iPhone die Preise erhöht – zum Teil massiv

Weiterlesen →
SCHNEIER ON SECURITY 🟢 NIEDRIG 09. Sep. 2026

Driver’s License Data for Sale

A database of 153 million drivers licenses is for sale on the dark web. Brian Krebs has more detail.

Weiterlesen →
DARK READING 🟢 NIEDRIG 09. Sep. 2026

Identity-Based AI Attack Threatens Security of Enterprise Data

"Workflow identity hijacking" can bypass standard security controls and hijack an organization’s data by sending a basic request through an unauthenticated entry point.

Weiterlesen →
SANS 🟡 MITTEL 09. Sep. 2026

Scans for Proxmox Servers, (Wed, Sep 9th)

About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only…

Weiterlesen →
THE HACKER NEWS 🟡 MITTEL 09. Sep. 2026

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means…

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 09. Sep. 2026

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create „stolen keys“ that grant illicit access to tools from model providers…

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 09. Sep. 2026

Google passt Suche in Europa an und warnt vor schlechterer Qualität

Die EU forderte eine Änderung der Darstellung von Suchergebnissen, Google klagt über ein „verschlechtertes Nutzererlebnis“

Weiterlesen →
DER STANDARD PHISHING 🟢 NIEDRIG 09. Sep. 2026

Spam und Fake-Rechnungen: Was passiert, wenn KI Geld verdienen soll

Das Experiment von Bottleneck Labs sorgte für verärgerte Menschen und null Dollar Umsatz

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 09. Sep. 2026

Bloß nicht vor die Kamera: Elon Musk bot seiner Ex 40 Millionen Dollar Schweigegeld

Der Milliardär wollte den Auftritt der Mutter eines seiner 14 Kinder in einer Doku über ihn unbedingt verhindern

Weiterlesen →
HEISE SECURITY 🟡 MITTEL 09. Sep. 2026

Sicherheits-Updates: Samsung verteilt Patches für Galaxy-Smartphones

Samsung hat sein Security-Bulletin für September 2026 veröffentlicht. Der Hersteller verteilt 90 Sicherheitspatches für zahlreiche Galaxy-Geräte.

Weiterlesen →
HEISE SECURITY 🟢 NIEDRIG 09. Sep. 2026

Anstieg von Verbrauch an KI-Tokens – was einige Claude-Nutzer berichten

Einige Claude-User schauen derzeit geschockt auf ihren Token-Verbrauch. Obwohl sie die KI-Tools teilweise tagelang nicht nutzen, steigt der Verbrauch weiter.

Weiterlesen →
WATCHLIST PHISHING 🟢 NIEDRIG 09. Sep. 2026

Keine Panik: Zahlungsaufforderung vom Hansevia Forderungsmanagement ist ein Fake!

Eine E-Mail mit bedrohlich klingendem Betreff. Eine Forderung über mehrere tausend Euro. Ein angeblich bestehendes Dienstleistungsverhältnis mit Euromillion24. Aus diesen Bestandteilen bauen Kriminelle aktuell ein…

Weiterlesen →
SCHNEIER ON SECURITY 🟢 NIEDRIG 09. Sep. 2026

Claude Fable Solves a Historical Cipher

Claude Fable 5.1 solved a 370-year-old cipher in forty-four minutes. This tracks with what I wrote about AIs doing mathematics: It’s good at things that…

Weiterlesen →
DARK READING PHISHING 🟢 NIEDRIG 09. Sep. 2026

Cybercriminals Hack Brazilian Government Servers to Host Phishing Sites

A Chinese-language group is compromising government and education sites to create a reverse-proxy network with gambling-themed sites.

Weiterlesen →
THE HACKER NEWS 🟡 MITTEL 09. Sep. 2026

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related…

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 09. Sep. 2026

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting „systematic extraction“ of proprietary functionalities and capabilities of American frontier models…

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 09. Sep. 2026

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

A flaw in DeepSeek Harness, DeepSeek’s open-source tool for running AI coding agents on a developer’s machine, let a sandboxed agent turn off its own…

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 09. Sep. 2026

USA werfen Deepseek und Co vor Xi-Besuch Kopie von KI-Technologie vor

USA und China planen für Mitte September einen Dialog über KI-Sicherheitsrisiken

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 09. Sep. 2026

Ab 19 Uhr: Apples neuer CEO stellt neue iPhones vor

Die iPhone-18-Reihe, die auch ein Falthandy mitbringen soll, markiert den ersten großen Auftritt des Nachfolgers von Jobs und Cook

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 09. Sep. 2026

Weg von Microsoft: Schweizer Regierung baut weiter ihre IT um

Ein Pilotprojekt soll die Abnabelung von Microsoft 365 schnell vorantreiben. In Sachen Cybersicherheit stellt man wohl bereits Ende Oktober auf OpenDesk aus Deutschland um

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 09. Sep. 2026

Anthropic-Forscher kündigt, weil er die Auslöschung durch KI erwartet

Künstliche Intelligenz könnte schon sehr bald außer Kontrolle geraten, warnt ein britischer Mathematiker. Dabei ist die Panik auch ein Geschäftsmodell der KI-Entwickler

Weiterlesen →
HEISE SECURITY 🟢 NIEDRIG 09. Sep. 2026

Auf Lücke gespielt: Was in Berlin den Rhysida-Angriff begünstigte

Berlin hat bei der IT-Sicherheit geschlampt. Den Angreifern hat über Jahrzehnte gewachsene und nur halbherzig modernisierte IT in die Karten gespielt.

Weiterlesen →
HEISE SECURITY 🟢 NIEDRIG 09. Sep. 2026

KI absichern und belegen: OWASP veröffentlicht neue Hilfe

Das OWASP GenAI Security Project veröffentlicht den „Crosswalk“, der KI-Risiken mit Compliance-Anforderungen aus 25 Regelwerken verknüpft.

Weiterlesen →