Tycoon2FA takedown reshapes the phishing landscape
CSO Online 24.07.2026 10:23
Traditional phishing techniques are in decline as a result of the disruption of the Tycoon2FA phishing-as-a-service (PHaaS) platform, Microsoft said in a new report, “Email threat landscape: Q2 2026 trends and insights”.
“Phishing volume linked to the platform fell 92% from pre-disruption averages, including QR code phishing and CAPTCHA-gated phishing both declining from their March highs,” the company wrote in the report.
Kimi K3: Chinesische KI findet mehrere Zero-Day-Lücken in redis-Datenbank
Heise Security 24.07.2026 09:47
Ein IT-Forscher hat mit der chinesischen KI Kimi K3 mehrere Zero-Day-Lücken in der redis-Datenbank entdeckt. Updates bestätigen die Funde.
RefluXFS: Kernel-Bug verleiht auf Millionen von Linux-Systemen Root-Zugriff
Golem 24.07.2026 09:05
Eine Sicherheitslücke im Linux-Kernel lässt Angreifer beliebige Dateien auf XFS-Volumes überschreiben. Root-Rechte sind damit leicht zu beschaffen. (Sicherheitslücke, Fedora)
Sicherheitsupdate n8n: Accountübernahme und Sandboxausbruch möglich
Heise Security 24.07.2026 08:21
Das Workflow-Automatisierungstool n8n ist verwundbar und Angreifer können Instanzen kompromittieren.
Adobe-Chrome-Erweiterung ermöglichte Datenklau
Heise Security 24.07.2026 07:52
In der Chrome-Erweiterung Adobe Acrobat mit 312 Millionen Nutzern klaffte eine Schwachstelle. Dadurch konnten Angreifer Daten stehlen.
Ransomware groups are hammering your vulnerable VPNs
CSO Online 24.07.2026 07:00
Cybercriminals are actively exploiting a recently discovered vulnerability in Palo Alto Networks firewall and VPN appliances to deploy the Qilin ransomware strain.
A critical authentication bypass flaw (CVE-2026-0257) in Palo Alto GlobalProtect portal and gateway was the common link in a series of intrusions in June, Arctic Wolf Labs warns. Exploitation of the vulnerability came within days of disclosure.
Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say
The Hacker News 24.07.2026 06:58
Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0.
All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution.
Redis 6.2.23, 7.2.15, and 7.4.10
Russische Angreifer missbrauchen Zero-Click-Lücke in Zimbra
Heise Security 24.07.2026 06:21
Russische Angreifer attackieren seit Juli 2025 westliche Regierungen und Einrichtungen durch eine Zero-Click-Lücke in Zimbra.