Seite wählen

Nachrichtenarchiv

31.07.2026

Auch KI von Anthropic griff echte Firmen an

Spiegel Online 31.07.2026 02:50
Dass ein KI-Modell von OpenAI auf eigene Faust zum Hacker wurde, galt als »beispielloser Zwischenfall« und Weckruf für die Techbranche. Nun stellt sich heraus: Es war kein Einzelfall.

EU verhängt Sanktionen gegen Scam-Center in Südostasien

Heise Security 30.07.2026 15:10
Der EU-Rat verhängt restriktive Maßnahmen gegen Kriminelle und Firmen in Südostasien, die groß angelegte Betrugszentren betreiben und Menschen versklaven.

IBM WebSphere Application Server: Sicherheitsproblem in Admin-Konsole gelöst

Heise Security 30.07.2026 12:58
Mehrere Sicherheitslücken bedrohen IBM WebSphere Application Server und WebSphere Application Server Liberty.

VMware ESX, vCenter, Workstation und Fusion: Updates schließen kritische Lücken

Heise Security 30.07.2026 12:34
VMware-Updates für ESX, vCenter, Workstation und Fusion schließen Sicherheitslücken, die etwa die Umgehung der Authentifizierung erlauben.

E-Mail öffnen reicht: Russische Hacker attackieren Outlook-Nutzer

Golem 30.07.2026 11:16
Die Hackergruppe Laundry Bear dringt mit einem Half-Click-Exploit seit Monaten in E-Mail-Postfächer von Outlook-Nutzern ein. Die Angriffe treffen auch Europa. (Malware, Microsoft)

Cisco FMC Zero-Day Actively Exploited, Static Credentials Could Expose Sensitive Data

The Hacker News 30.07.2026 05:08
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a newly disclosed security flaw impacting Cisco Secure Firewall Management Center (FMC) Software to its Known Exploited Vulnerabilities (KEV) catalog, following reports of zero-day exploitation.

The vulnerability, assigned CVE-2026-20316 (CVSS score: 5.3), could permit an unauthenticated, remote attacker to log

30.07.2026

Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads

The Hacker News 29.07.2026 18:10
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads.

Tracked as CVE-2026-66066 (CVSS score: 9.5), the flaw can expose the Rails process environment and secrets such as secret_key_base, the Rails master key, database passwords, cloud storage credentials,

Ruflo MCP Flaw Lets Unauthenticated Attackers Run Commands and Poison AI Memory

The Hacker News 29.07.2026 15:39
Cybersecurity researchers have flagged a maximum-severity security flaw in Ruflo, an open-source agent meta-harness for Anthropic Claude Code and OpenAI Codex, that could result in unauthenticated remote code execution.

The vulnerability, tracked as CVE-2026-59726 (CVSS score: 10.0), impacts all versions of the project before version 3.16.3. It has been codenamed RufRoot by Noma Security's

Stackable Data Platform 26.7: Sicherheit, SBOMs und flexible Registries

Heise Security 29.07.2026 15:37
Stackable stellt die Data Platform 26.7 auf Qualität und Supply-Chain-Sicherheit um. Neben SLSA-Provenance drohen bei der Registry-Logik Breaking Changes.

Kritische Schwachstelle in JetBrains TeamCity entdeckt

Heise Security 29.07.2026 09:13
JetBrains hat eine kritische Sicherheitslücke in TeamCity geschlossen. Angreifer können CI/CD-Pipelines kompromittieren und Befehle auf dem Server ausführen.

OpenWrt: Updates schließen teils kritische Sicherheitslücken

Heise Security 29.07.2026 09:08
Das OpenWrt-Projekt hat aktualisierte Fassungen veröffentlicht, die teils als kritisches Risiko eingestufte Sicherheitslücken stopfen.

Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass

The Hacker News 29.07.2026 08:58
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that

29.07.2026

Arista patches maximum severity vulnerability that is already being exploited

CSO Online 29.07.2026 00:43
Arista has patched a VeloCloud Orchestrator (VCO) security hole that has been actively leveraged in the wild, one that the vendor says “may allow a remote attacker to access privileged internal functionality and impact the VCO host.”
The Arista security advisory added that the hole “may compromise the confidentiality, integrity, and availability of the orchestrator and data managed by the orchestrator.”

Critical OpenWrt DHCPv6 Flaw Could Let Unauthenticated Attackers Run Code as Root

The Hacker News 28.07.2026 12:56
OpenWrt has shipped version 24.10.8 to close a critical DHCPv6 stack overflow and a wider set of remotely triggerable flaws in network services enabled by default.

The critical issue, tracked as CVE-2026-53921 and rated 9.8 on CVSS 3.1 in OpenWrt's GitHub advisory, lets an unauthenticated attacker able to reach the DHCPv6 server overwrite a stack buffer in odhcpd through a crafted DHCPv6

Certighost: Gefährlicher Exploit lässt Angreifer Windows-Domänen kapern

Golem 28.07.2026 11:17
Im Netz kursiert ein Exploit, mit dem sich Windows-Domänen kompromittieren lassen. Admins sollten ihre Systeme dringend absichern. (Sicherheitslücke, Microsoft)

Microsoft: Proof-of-Concept-Exploit für „Certighost“-AD-Lücke aufgetaucht

Heise Security 28.07.2026 11:00
Am Juli-Patchday hat Microsoft eine AD-Lücke geschlossen, die Rechteausweitung ermöglicht. Nun warnt das Unternehmen vor PoC-Exploit.

Critical TeamCity Flaw Could Let Attackers Run OS Commands Without Logging In

The Hacker News 28.07.2026 08:11
JetBrains is urging customers of on-premise versions of TeamCity to update to the latest version following the discovery of a critical security issue that could result in arbitrary code execution.

The vulnerability, assigned CVE-2026-63077 (CVSS score: 9.8), affects all TeamCity On-Premises versions. It has been addressed in versions 2025.11.7 and 2026.1.3. TeamCity Cloud instances have already

Attackers Exploit Arista VeloCloud Orchestrator Command Injection Flaw

The Hacker News 28.07.2026 04:43
A maximum-severity security flaw impacting on-premises versions of Arista VeloCloud Orchestrator (VCO) has come under active exploitation in the wild.

The vulnerability, tracked as CVE-2026-16812 (CVSS score: 10.0), is a case of operating system command injection that could pave the way for arbitrary code execution.

"VeloCloud Orchestrator (VCO) on-prem has a security issue where this issue

Legen wir heute los

Aufschieben ist manchmal eine Lösung. Lassen Sie uns eine bessere finden. Wir stellen Ihnen gerne unseren Ansatz für Ihre Herausforderungen vor – selbstverständlich kostenfrei. 

Lassen Sie uns jetzt über Ihr Anliegen sprechen