Seite wählen

Nachrichtenarchiv

30.06.2026

(g+) IKEv1-Altlast: Abgekündigtes Protokoll öffnet Ransomware-Banden das Firmen-VPN

Golem 29.06.2026 11:30
Eine kritische Lücke in Check Points VPN wird aktiv ausgenutzt. Kern ist ein totgesagtes Protokoll. Admins sollten IKEv1 abschalten und sich eine grundsätzliche Frage stellen. Ein Ratgebertext von Steffen Zahn (Security, Server)

Kritische libssh2-Lücke: Proof-of-Concept-Exploit veröffentlicht

Heise Security 29.06.2026 11:29
Vergangene Woche wurde eine Sicherheitslücke in libssh2 bekannt. Jetzt ist Exploit-Code aufgetaucht, der sie missbrauchen kann.

Root-Zugriff möglich: Exploits für gefährliche Lücke im Linux-Kernel geleakt

Golem 29.06.2026 09:09
Admins sollten zügig ihre Linux-Systeme absichern. Auf Github sind Exploits für eine Root-Lücke in Debian, Ubuntu und RHEL aufgetaucht. (Sicherheitslücke, Ubuntu)

Public PoC Released for Critical libssh2 CVE-2026-55200 Client-Side SSH Flaw

The Hacker News 29.06.2026 07:06
A public proof-of-concept is now out for CVE-2026-55200, a critical flaw in libssh2 that lets a malicious or compromised SSH server trigger memory corruption on a connecting client, with possible code execution. No credentials, no user interaction. The bug affects every release up to and including 1.11.1 and carries a CVSS 4.0 score of 9.2.

libssh2 is a client-side SSH library, not a server.

Innenministerium konkretisiert den Cyberdome teilweise

Heise Security 29.06.2026 04:49
Ein nationales Monitoring mit Informationsaustausch in Echtzeit soll der geplante Cyberdome bieten. Damit sollen vernetzte IT-Produkte „Cyberdome-ready“ werden.

29.06.2026

Ukraine Says Russian Intelligence Used Fake Support Texts to Steal Messaging Credentials

The Hacker News 27.06.2026 17:27
The Security Service of Ukraine (SSU) said it, together with the U.S. Federal Bureau of Investigation (FBI), uncovered a long-running campaign orchestrated by Russian intelligence services to break into the messaging accounts of government officials, military personnel, politicians, and activists in Ukraine, Europe, and the U.S.

The systematic cyber attacks aimed at stealing sensitive

OpenAI Previews GPT-5.6 Sol With Restricted Access and Stronger Cyber Safeguards

The Hacker News 27.06.2026 12:19
OpenAI on Friday released three versions of GPT-5.6, called Sol, Terra, and Luna, as a limited preview to a small number of companies as part of an ongoing engagement with the U.S. government.

While Sol is the latest flagship model and the most powerful, Terra strikes a balance between efficiency and power, and Luna is fine-tuned for speed and affordability.

"GPT‑5.6 Sol launches with our most

27.06.2026

Hackers exploit critical PTC Windchill PLM software flaw

CSO Online 26.06.2026 23:32
Hackers are exploiting a critical vulnerability recently patched in PTC Windchill and FlexPLM, two product lifecycle management solutions used by organizations across a range of industries, including defense, aerospace, automotive, medical, electronics, industrial machinery, and consumer goods.
The vulnerability, tracked as CVE-2026-12569, is an unsafe deserialization flaw that enables remote code execution. It’s located in the web-based Windchill PDMLink product data management component and is rated 9.3 severity on the CVSS scale.

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

The Hacker News 26.06.2026 13:57
A flaw in the Linux kernel's traffic-control subsystem can let a local unprivileged user gain root on affected systems.

CVE-2026-46331, nicknamed "pedit COW," is an out-of-bounds write in the packet-editing action (act_pedit) that corrupts shared page-cache memory. A public, working exploit appeared within a day of the CVE assignment on June 16. Red Hat rates the flaw as

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

The Hacker News 26.06.2026 13:53
A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The path was short: a developer opens the repo, trusts the workspace, and Amazon Q does the rest. Amazon has patched it.

Tracked as CVE-2026-12957 (CVSS 8.5), the bug sat in how Amazon's AI coding assistant handled Model Context Protocol (MCP) servers.

Wiz

CISA Adds Exploited PTC Windchill RCE Flaw to KEV as Web Shell Attacks Continue

The Hacker News 26.06.2026 12:31
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical remote code execution vulnerability impacting PTC Windchill PDMlink and PTC FlexPLM enterprise Product Data Management (PDM) and Product Lifecycle Management (PLM) software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.

The vulnerability in question is

Kritische Systemdatenlücke bedroht Netzwerkbetriebssystem Arista EOS

Heise Security 26.06.2026 07:53
Unter anderem eine kritische Sicherheitslücke gefährdet Netzwerkkomponenten mit Arista EOS. Noch sind nicht alle Updates verfügbar.

Windows 10: ESU-Updates bis Oktober 2027 verlängert

Heise Security 25.06.2026 15:17
Microsoft hat das ESU-Programm für Privatkunden ohne große Vorankündigung um ein weiteres Jahr verlängert.

Legen wir heute los

Aufschieben ist manchmal eine Lösung. Lassen Sie uns eine bessere finden. Wir stellen Ihnen gerne unseren Ansatz für Ihre Herausforderungen vor – selbstverständlich kostenfrei. 

Lassen Sie uns jetzt über Ihr Anliegen sprechen