⬇ Aktuelle
THE HACKER NEWS 🔴 KRITISCH 07. Aug. 2026

AI-Assisted HTTP Terminator Finds Novel HTTP Desync Techniques and Apache Zero-Day

PortSwigger says HTTP Terminator, an artificial intelligence (AI)-assisted research system built by James Kettle, generated and proved new HTTP desynchronization techniques after exploring 30,000 candidate…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 05. Aug. 2026

CISA Flags Langflow RCE, Tomcat, and N-central Flaws as Actively Exploited

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on August 5, 2026, added three flaws to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of…

Weiterlesen →
CERT WARNUNG 🔴 KRITISCH 04. Aug. 2026

Kritische Sicherheitslücke in Drupal Core – Updates verfügbar

20. Mai 2026 Beschreibung In Drupal Core existiert eine SQL-Injection-Schwachstelle in der Datenbank-Abstraktions-API. Speziell gestaltete Anfragen können zu beliebigen SQL-Injections führen. Die Schwachstelle ist ausschließlich…

Weiterlesen →
CERT WARNUNG 🔴 KRITISCH 04. Aug. 2026

Kritische Sicherheitslücken in WordPress – Updates verfügbar

20. Juli 2026 Beschreibung In WordPress existieren zwei Sicherheitslücken. Eine SQL-Injection-Schwachstelle im Parameter „author__not_in“ von „WP_Query“ betrifft WordPress ab Version 6.8. Ab WordPress 6.9 lässt…

Weiterlesen →
CERT WARNUNG 🔴 KRITISCH 30. Juli 2026

Kritische Sicherheitslücken in SonicWall SMA1000 Series – aktiv ausgenutzt – Updates verfügbar

15. Juli 2026 Beschreibung In den SonicWall SMA1000 Series Appliances existieren mehrere Sicherheitslücken. Die schwerwiegendere der beiden Schwachstellen ermöglicht es Angreifer:innen aus der Ferne und…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 30. Juli 2026

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 29. Juli 2026

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in…

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 29. Juli 2026

New Gitea RCE Lets Repository Writers Plant a Git Hook to Run Shell Commands

Gitea, the self-hosted Git platform, has patched a critical remote code execution vulnerability. A user with ordinary repository write access can turn attacker-controlled patch content…

Weiterlesen →
THE HACKER NEWS DATENLECK 🔴 KRITISCH 28. Juli 2026

JFrog Confirms OpenAI Models Exploited Artifactory Zero-Day Before Hugging Face Breach

JFrog has confirmed that OpenAI models exploited a zero-day in self-hosted Artifactory while trying to reach the open internet from a sealed evaluation environment. Artifactory…

Weiterlesen →
DARK READING 🔴 KRITISCH 27. Juli 2026

Adversaries Don’t Need a Zero-Day — They Read Your Rulebook

Confidence in autonomous security tools is declining, and here’s why.

Weiterlesen →
THE HACKER NEWS 🔴 KRITISCH 24. Juli 2026

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains…

Weiterlesen →
HEISE SECURITY 🔴 KRITISCH 24. Juli 2026

Kimi K3: Chinesische KI findet mehrere Zero-Day-Lücken in redis-Datenbank

Ein IT-Forscher hat mit der chinesischen KI Kimi K3 mehrere Zero-Day-Lücken in der redis-Datenbank entdeckt. Updates bestätigen die Funde.

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 07. Aug. 2026

Cisco Patches 12 SD-WAN and IOS XE Flaws, Including Three 9.8 CVSS Score Bugs

Cisco has rolled out updates to address multiple critical security vulnerabilities impacting Catalyst SD-WAN and IOS XE Software as part of a comprehensive internal security…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 06. Aug. 2026

CISA Flags TeamCity CVE-2026-63077 RCE Flaw Under Active Exploitation in the Wild

A newly patched security flaw impacting on-premise versions of JetBrains TeamCity has come under active exploitation in the wild, according to the U.S. Cybersecurity and…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 06. Aug. 2026

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Attackers broke into an organization’s Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 05. Aug. 2026

New OVSwrap Linux Kernel Flaw Lets Local Users Gain Root via Open vSwitch

A memory corruption flaw in the Linux kernel’s Open vSwitch datapath gives ordinary local users a path to root on a broad set of default-configured…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 05. Aug. 2026

Veeam, Terraform MCP, Django Patch Critical Flaws, Led by CVSS 10.0 Cross-Tenant Bug

HashiCorp, Veeam, and the Django Software Foundation have patched 11 vulnerabilities across Terraform MCP Server, Veeam Service Provider Console, and Django. The three most serious:…

Weiterlesen →
THE HACKER NEWS DATENLECK 🟠 HOCH 05. Aug. 2026

Leaked n8n API Tokens Exposed Live Instances to Credential Theft

GitGuardian researchers found 321 n8n instances accepting API tokens exposed in public GitHub commits and demonstrated four ways attackers could use them to access sensitive…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 05. Aug. 2026

Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup

An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login,…

Weiterlesen →
HEISE SECURITY 🟠 HOCH 05. Aug. 2026

Sicherheitsupdates: TP-Links Netzwerk-Ökosystem Omada ist kompromittierbar

Sicherheitsforscher entdecken unter anderem kritische Lücken in TP-Link Omada, die sich auf weitere Netzwerkkomponenten ausweiten.

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 04. Aug. 2026

CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 04. Aug. 2026

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database’s root context, crossing the privilege boundary between a cPanel…

Weiterlesen →
DARK READING 🟠 HOCH 04. Aug. 2026

Attackers Exploit N-able Patch Bypass Flaw on RMM Servers

Over the weekend, the vendor discovered another vector of authentication bypass CVE-2026-18577 that gives attackers administrator access.

Weiterlesen →
SCHNEIER ON SECURITY 🟠 HOCH 03. Aug. 2026

More on the OpenAI Agent’s Attack on Hugging Face

Hugging Face has published a detailed timeline of the attack. From the summary: The agent was running an internal OpenAI cyber-capability evaluation based on the…

Weiterlesen →
THE HACKER NEWS RANSOMWARE 🟠 HOCH 03. Aug. 2026

INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws

The INC Ransomware operation has emerged as the „dominant threat actor“ exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series…

Weiterlesen →
SCHNEIER ON SECURITY 🟠 HOCH 03. Aug. 2026

The OpenAI Hack Shows the Genie Is Out of the Bottle

This essay originally appeared in Foreign Policy. Earlier this month, two of OpenAI’s models broke out of their containment sandbox and attacked another AI company.…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 03. Aug. 2026

N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete

N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers. Its first…

Weiterlesen →
THE HACKER NEWS DATENLECK 🟠 HOCH 03. Aug. 2026

Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS

An unknown Chinese-threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.…

Weiterlesen →
HEISE SECURITY 🟠 HOCH 03. Aug. 2026

Kritische Schadcode-Sicherheitslücke bedroht Adobe Campaign Classic

Angreifer können Adobe Bridge und Campaign Classic attackieren. Dagegen abgesicherte Versionen stehen zum Download.

Weiterlesen →
HEISE SECURITY 🟠 HOCH 01. Aug. 2026

Schlüsselklau bei Ruby on Rails – Kritische Lücke mit präparierten Bildern

Über kompromittierte Bilder können Angreifer Umgebungsvariablen des Servers einschließlich der Secrets auslesen und sich damit weitere Türen ins System öffnen.

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 31. Juli 2026

Researchers Report 84 Flaws in 4G and 5G Cores, Including a Session Hijacking Flaw

An academic study has disclosed a „widespread class“ of security vulnerabilities impacting 4G and 5G core networks that, if successfully exploited, could trigger denial-of-service (DoS)…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 31. Juli 2026

Chinese Hacker Commands DeepSeek via Telegram to Launch Autonomous Attacks

Palo Alto Networks‘ Unit 42 says a Chinese-speaking threat actor used DeepSeek through the open-source Hermes Agent framework to launch attacks autonomously. After an initial…

Weiterlesen →
HEISE SECURITY 🟠 HOCH 31. Juli 2026

SolarWinds Web Help Desk: Update bessert umgehbare Authentifizierung aus

SolarWinds schließt Sicherheitslücken in Web Help Desk. Eine gilt als kritisch und ermöglicht Angreifern, die Authentifizierung zu umgehen.

Weiterlesen →
DARK READING 🟠 HOCH 31. Juli 2026

AI Harnesses Burst With Potential Exploit Opps

A myriad of software makes up the typical AI harness, and trust issues between the components can create concerning attack vectors.

Weiterlesen →
DARK READING 🟠 HOCH 31. Juli 2026

Minnesota Water Utility Attacks Expose Sector’s Cyber-Risks

A likely Iran-backed actor targeted more than 30 community water systems in Minnesota in a sobering reminder of rising threats to US critical infrastructure.

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 30. Juli 2026

Azure Cosmos DB Flaw Exposed Platform-Wide Key That Could Access Any Database

A now-patched vulnerability in Azure Cosmos DB could have let an attacker escape the service’s Gremlin query sandbox and obtain full read and write access…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 30. Juli 2026

ThreatsDay: AI-Powered Hacking, 370 Chrome Flaws, SonicWall Attacks, DNS Hijacking + 22 More Stories

A lot of security still comes down to trusting the wrong screen. This week, that screen might be a login page, an install guide, a…

Weiterlesen →
HEISE SECURITY 🟠 HOCH 30. Juli 2026

VMware ESX, vCenter, Workstation und Fusion: Updates schließen kritische Lücken

VMware-Updates für ESX, vCenter, Workstation und Fusion schließen Sicherheitslücken, die etwa die Umgehung der Authentifizierung erlauben.

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 30. Juli 2026

Russian Hackers Exploit Microsoft OWA Flaw to Keep Mailbox Access After Credential Rotation

The Russian threat actors recently linked to the exploitation of a now-patched vulnerability in Zimbra have been observed exploiting another vulnerability, this time in Microsoft…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 30. Juli 2026

Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts

South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally…

Weiterlesen →
HEISE SECURITY 🟠 HOCH 30. Juli 2026

Chrome-Update stopft weitere 370 Sicherheitslecks

Google hat wieder ein massives Sicherheitsupdate für Chrome veröffentlicht. Sieben der geschlossenen Lücken gelten als kritisch.

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 30. Juli 2026

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 29. Juli 2026

Mythos Asks the Right Question. It Doesn’t Answer It.

AI is compressing exploit timelines. The real question isn’t whether your vulnerability management playbook needs to change, it’s which part of it you’ve been getting…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 29. Juli 2026

Three Critical VMware Flaws Allow Auth Bypass, Code Execution, and VM Escape

Broadcom has released security updates to address multiple security flaws impacting VMware ESX, vCenter, Workstation, and Fusion, three of which have been designated as critical…

Weiterlesen →
THE HACKER NEWS 🟠 HOCH 29. Juli 2026

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server…

Weiterlesen →
HEISE SECURITY 🟠 HOCH 29. Juli 2026

OpenWrt: Updates schließen teils kritische Sicherheitslücken

Das OpenWrt-Projekt hat aktualisierte Fassungen veröffentlicht, die teils als kritisches Risiko eingestufte Sicherheitslücken stopfen.

Weiterlesen →
DARK READING 🟢 NIEDRIG 07. Aug. 2026

Déjà Vu? Meta’s AI Escapes Testing Lab in Hacking Joyride

In the span of three weeks, OpenAI, Anthropic, and Meta have all disclosed AI agent sandbox escape events affecting real organizations.

Weiterlesen →
DARK READING 🟡 MITTEL 07. Aug. 2026

AI-Generated Patches Fail Half the Time

A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 07. Aug. 2026

18-Year-Old Linux SCTP Flaw Could Let Local Users Gain Root and Escape Containers

A use-after-free bug in Linux’s SCTP networking code can be turned into full root on a host, and Tencent researchers say they used it to…

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 07. Aug. 2026

Growing Up The Hard Way

Open Source had a great childhood. For two decades it got to be a kid. It ran around barefoot, gave everything away, trusted strangers, and…

Weiterlesen →
THE HACKER NEWS 🟡 MITTEL 07. Aug. 2026

New WordPress Pre-Auth XSS Could Lead to PHP Code Execution – Patch ASAP

WordPress has fixed a pre-authentication reflected cross-site scripting (XSS) flaw in its login screen that affects every version of the content management system. pwn.ai demonstrated…

Weiterlesen →
SCHNEIER ON SECURITY 🟢 NIEDRIG 07. Aug. 2026

ICE Is Buying Access to Credit Card Records

Through data brokers, ICE is buying the information you provided to open a credit card.

Weiterlesen →
SANS 🟢 NIEDRIG 07. Aug. 2026

Linux Shell Forensic: Let?s Dive Into Atuin!, (Fri, Aug 7th)

UNIX systems (including Linux) are well-known to record a lot of activities in many different locations. But there is one domain where they definitely lack…

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 07. Aug. 2026

Claude Code and Gemini CLI Flaws Let a GitHub Issue Reach CI Workflow Secrets

A GitHub issue opened by an account with no repository privileges was enough to execute code on the CI runners behind Anthropic’s and Google’s own…

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 07. Aug. 2026

Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access

Entra ID researcher Dirk-jan Mollema demonstrated that malware already running in a signed-in Windows session can silently use the victim’s Windows Hello for Business key…

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 07. Aug. 2026

New NatJack Attacks Hijack TCP Sessions and Spoof DNS by Manipulating NAT Tables

Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS…

Weiterlesen →
THE HACKER NEWS PHISHING 🟢 NIEDRIG 07. Aug. 2026

Microsoft 365 AitM Phishing Hijacks Accounts to Collect Payroll and Finance Emails

Cybersecurity researchers have called attention to an active „widespread email-driven phishing campaign“ that employs adversary-in-the-middle (AitM) techniques to take control of Microsoft 365 accounts with…

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 07. Aug. 2026

Alternativ-Wikipedia gescheitert? Musks „Grokipedia“ seit Monaten ohne Updates

Im April stellte das KI-System jegliche Bearbeitungen von Usereingaben ein – die Ursache ist nicht bekannt

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 07. Aug. 2026

KI kann nicht nur hacken, sondern auch echte Viren erzeugen

Ein Forscherteam entwickelte mit den Genom-Sprachmodellen Evo 1 und Evo 2 einen Bakteriophagen und will damit die Forschung zur Behandlung resilienter Krankheitserreger vorantreiben

Weiterlesen →
HEISE SECURITY DATENLECK 🟡 MITTEL 07. Aug. 2026

Durch Metabase-0day: Datenleck bei Laptophersteller Framework

Nur wenige Stunden nach Bekanntwerden einer Sicherheitslücke informiert der Framework seine Kunden. Metabase veröffentlichte eigene Sicherheitshinweise.

Weiterlesen →
HEISE SECURITY 🟢 NIEDRIG 07. Aug. 2026

Angreifer attackieren IBM Langflow und Apache-Tomcat-Server

Derzeit schieben Angreifer Schadcode auf IBM-Langflow-Instanzen. Im Cluster-Betrieb von Apache Tomcat können sie Datenverkehr mitlesen.

Weiterlesen →
HEISE SECURITY RANSOMWARE 🟢 NIEDRIG 07. Aug. 2026

Verschlüsselte iPhone-Backups: Apple kämpft gegen Londoner Begehrlichkeiten

Auch unter dem neuen Labour-Premierminister Burnham verlangt der britische Staat Hintertüren von Apple. Dessen Anwälte versuchen, sich zu wehren.

Weiterlesen →
HEISE SECURITY 🟢 NIEDRIG 07. Aug. 2026

Lieferketten-Angriff auf keyv: Shai-Hulud-Wurm infiziert mehr als 440 npm-Pakete

Die populäre Key‑Value‑Datenbank keyv und andere weit verbreitete npm-Pakete waren Ziel einer Lieferkettenattacke. Der potenzielle Schaden ist groß.

Weiterlesen →
HEISE SECURITY 🟢 NIEDRIG 07. Aug. 2026

OpenAI: Neue, erschreckende Details zum Hugging-Face-Vorfall

Mitarbeiter von OpenAI enthüllen weitere Details rund um den Einbruch ihrer KI-Agenten bei anderen Firmen und offenbaren erschreckende Fahrlässigkeit.

Weiterlesen →
CERT WARNUNG 🟢 NIEDRIG 07. Aug. 2026

Angriffe gegen Checkpoint VPN Lösungen – Hotfix verfügbar

08.06.2026 Beschreibung Checkpoint warnt vor beobachteten Angriffen gegen die Produkte Checkpoint Security Gateway und Checkpoint Spark Firewall.  Auswirkungen Die zugrunde liegende Sicherheitslücke CVE-2026-50751 erlaubt unbefugten…

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 07. Aug. 2026

Ungenügender Kinderschutz: Meta muss in den USA 567 Millionen Dollar Strafe zahlen

Mit der Millionenstrafe soll laut der Gerichtsentscheidung ein Fonds zur Unterstützung von Minderjährigen finanziert werden

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 07. Aug. 2026

Überhitzt? Japanische Firma bietet Kühlschränke für Menschen an

Die „Do Hiemon Box“ bläst ihren Insassen mit einem fünf Grad kalten Luftstrom in den Nacken: Einstiegspreis: 8200 Euro

Weiterlesen →
HEISE SECURITY RANSOMWARE 🟢 NIEDRIG 07. Aug. 2026

Cyberkrimineller bekennt sich der Millionen-Erpressung von Cloud-Kunden schuldig

Nach dem Datenklau beim US-Cloud-Anbieter Snowflake hat ein Kanadier Millionen von dessen Kunden erpresst. Nach Schuldbekenntnis drohen ihm 2 bis 30 Jahre Haft.

Weiterlesen →
HEISE SECURITY 🟢 NIEDRIG 07. Aug. 2026

Auslegungssache 165: Europas Datenschutz in Bewegung

Der c’t-Datenschutz-Podcast beleuchtet den Datentransfer in die USA, neue Entscheidungen des EuGH und die stockende Reform der EU-Digitalregeln.

Weiterlesen →
DARK READING 🟢 NIEDRIG 07. Aug. 2026

From Bobmojis to Bobbleheads: How the Democratic Party Built a Security-First Culture

Former chief security officers of the Democratic National Committee explain that a strong security-first mindset requires executive support – and a dose of absurdity.

Weiterlesen →
DARK READING 🟢 NIEDRIG 07. Aug. 2026

Researcher Claims Control of ChatGPT Secure Sandbox

A researcher demonstrated a proof-of-concept attack chain that provided C2-style influence over ChatGPT’s isolated sandbox during a session at Black Hat USA 2026.

Weiterlesen →
DARK READING RANSOMWARE 🟢 NIEDRIG 07. Aug. 2026

The Coordination Gap: How Attackers Are Outpacing Law Enforcement

The fight against cybercrime continues because threat actors have adapted their strategies to avoid deterrents, but law enforcement still operates in silos.

Weiterlesen →
THE HACKER NEWS 🟡 MITTEL 07. Aug. 2026

New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts

Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and…

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 06. Aug. 2026

Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses

Cybersecurity researchers have disclosed a security issue with Apple’s iCloud Private Relay tool that can expose a user’s real IP address. Introduced with iOS 15,…

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 06. Aug. 2026

CryptoJS Weak RNG Behind $5.7 Million in Drains Affects Five Crypto Wallet Apps

Coinspect has identified CryptoJS.lib.WordArray.random() as the weak random number generator behind the Ill Bloom wallet drains. Introduced in the JavaScript cryptography library 12 years ago,…

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 06. Aug. 2026

Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities

Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile…

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 06. Aug. 2026

ThreatsDay: Odysseus RCE, Samsung One-Click Takeover, iCloud Backdoor Fight + 27 More Stories

Apparently, opening the thing is now enough. A repo can run before the first prompt, a package can hide among hundreds, and a harmless-looking PDF…

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 06. Aug. 2026

New Interrupt Injection Attack Can Bypass Spectre v2 Defenses on Intel and AMD CPUs

An unprivileged Linux program can time a hardware interrupt to land in the gap between a processor sanitizing its branch predictor and the kernel using…

Weiterlesen →
KREBS ON SECURITY 🟢 NIEDRIG 06. Aug. 2026

Canadian Man Pleads Guilty in Snowflake Extortions

A 26-year-old Canadian man once described as one of the most consequential cybercrime threat actors of 2024 has pleaded guilty to computer fraud and conspiracy…

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 06. Aug. 2026

„Headline Newds“: Klimajournalismus gibt es auch auf OnlyFans

Das Ziel des amerikanischen Projekts ist es laut eigenen Angaben, denjenigen eine größere Plattform zu bieten, die sich für den Fortbestand der Menschheit auf der…

Weiterlesen →
DER STANDARD PHISHING 🟢 NIEDRIG 06. Aug. 2026

Phishing-Mails, Fake-Profile: Wie Anthropic und Co KI-Angst für Marketing nutzen

„Schaut her, wie mächtig unsere Modelle eigentlich sind – sie können sogar andere Unternehmen hacken“

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 06. Aug. 2026

Hofer verkauft Luftkühler mit „Halbleiterplatte“: Was es damit auf sich hat

Was laut Shop-Beschreibung des Invictus Air AC5 ganze Räume „effizient“ kühlen soll, ist auf Nachfrage dann doch nur für „Frischeempfinden im Nahbereich“ gedacht

Weiterlesen →
HEISE SECURITY 🟢 NIEDRIG 06. Aug. 2026

Veeam One und Service Provider Console für Schadcode-Attacken anfällig

Die Backupmanagementlösungen Veeam One und Service Provider Console sind für verschiedene Attacken empfänglich. Sicherheitsupdates schaffen Abhilfe.

Weiterlesen →
HEISE SECURITY 🟢 NIEDRIG 06. Aug. 2026

Fehlende Kontaktmöglichkeit: Deutschland verschläft Sicherheit per security.txt

Nur 1,8 Prozent der deutschen Webseiten bieten eine standardisierte security.txt an. Das BSI warnt vor den Risiken und verweist auf kommende Meldepflichten.

Weiterlesen →
WATCHLIST PHISHING 🟢 NIEDRIG 06. Aug. 2026

„Ich habe bezahlt“: Diese Vinted-Masche zielt auf Verkäufer:innen ab

Auch Verkäufer:innen auf Kleinanzeigenplattformen können ins Visier von Kriminellen geraten. Eine Betrugsmasche tritt derzeit besonders häufig auf Vinted auf: Angebliche Interessenten fragen nach Videos der…

Weiterlesen →
SCHNEIER ON SECURITY 🟢 NIEDRIG 06. Aug. 2026

Adversarial Clothing Designed to Fool Facial Recognition Systems

There are many companies manufacturing adversarial clothing designed to confuse facial recognition systems. It’s a cool idea, but I worry that it’s mostly security theater:…

Weiterlesen →
THE HACKER NEWS RANSOMWARE 🟢 NIEDRIG 06. Aug. 2026

Ransom Cartel Creator Gets 16 Years in Prison for Operating Ransomware-as-a-Service

A federal judge in Alexandria, Virginia, sentenced Maksim Silnikau to 16 years in prison on August 5 for creating and running Ransom Cartel, the ransomware-as-a-service…

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 06. Aug. 2026

Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells

Cybersecurity researchers have disclosed details of a „factory-shipped backdoor“ implanted in at least 20 Chinese router models from Zbtlink. According to a new report from…

Weiterlesen →
THE HACKER NEWS 🟢 NIEDRIG 06. Aug. 2026

AWS, Google, and Vercel Agent Flaws Let Attackers Trigger Tools Without Running the Model

Security flaws in agent infrastructure from Amazon Web Services (AWS), Google, and Vercel let untrusted or forged instructions reach an agent’s tools with no check…

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 06. Aug. 2026

Windows 11 verbraucht zu viel RAM, gibt Microsoft zu und will das ändern

Das Unternehmen will sein System wieder mit 8 GB RAM nutzbar machen. Bis dahin löscht man mal Artikel, die 32 GB für Gamer empfohlen haben

Weiterlesen →
DER STANDARD 🟢 NIEDRIG 06. Aug. 2026

Erdbeben in Googles KI-Abteilung: Neue Rolle für Deepmind-Chef Hassabis, zentrale Entwickler gehen

Der Nobelpreisträger will sich künftig auf AGI und wissenschaftliche Forschung konzentrieren. Schmerzhafter dürfte der Abgang von Jeff Dean und anderen sein

Weiterlesen →
HEISE SECURITY 🟡 MITTEL 06. Aug. 2026

Sicherheitspatches: Angreifer können Schadcode auf n8n-Servern ausführen

Die n8n-Entwicklwer haben in aktuellen Versionen insgesamt 18 Sicherheitslücken geschlossen.

Weiterlesen →
HEISE SECURITY 🟢 NIEDRIG 06. Aug. 2026

Sicherheitsforscher hackt Nordkorea-Hacker

Ein Sicherheitsforscher hat Einblick in nordkoreanische Hackergruppen gewonnen. Die Bilanz: Tausende betroffene Firmen und Milliardenbeute für das Regime.

Weiterlesen →
CERT WARNUNG 🟡 MITTEL 06. Aug. 2026

Update #1: Angriffswelle gegen FortiGate Devices – „FortiBleed“

22. Juni 2026 Beschreibung Fortinet hat letzten Freitag, am 19.5.2026, nun auch ein offizielles Statement zu „FortiBleed“ veröffentlicht. Wir hatten zuvor in einem Blog-Artikel unseren…

Weiterlesen →