Seite wählen

22.08.2026

N-able Passportal: Zahlreiche Unternehmen durch kritisches Passwort-Leck gefährdet

Golem 21.08.2026 10:40
Ein Forscher hat bei N-able Passportal eine kritische Lücke entdeckt. Angreifer hätten damit leicht Zugangsdaten aus Passwort-Tresoren abgreifen können. (Sicherheitslücke, Browser)

Lücke in WordPress-Plug-in Elementor Pro: 6 Millionen Webseiten gefährdet

Heise Security 21.08.2026 10:24
Eine kritische Sicherheitslücke im WordPress-Plug-in Elementor Pro ermöglicht die komplette Übernahme von WordPress.

Cisco Patches Nine Crosswork and Secure Workload Flaws, Five Scoring CVSS 10.0

The Hacker News 21.08.2026 10:03
Cisco has published another round of security updates for Crosswork platforms and Secure Workload Software as part of a continued comprehensive internal security review.

Four of the security vulnerabilities affect Crosswork Data Gateway, Crosswork Network Controller, and Crosswork Planning, regardless of the device configuration. A brief description of each of the flaws is below –

Backdoored Rust packages hit crates.io, exposing developers to malware at build time

CSO Online 21.08.2026 09:29
Malicious versions of three Rust packages, including the widely used arrayref, were published to the crates.io registry on August 20, carrying a backdoor that executed automatically when affected projects were compiled.
Security researchers at Wiz said the attack also shares infrastructure with recent supply-chain campaigns attributed to North Korean threat actors.

Ransomware takes aim at enterprise resilience

CSO Online 21.08.2026 08:25
Ransomware remains one of the most disruptive cyber threats organizations face. Companies have strengthened their cyber defenses over the years, but attackers in 2026 have become faster, more targeted, and increasingly reliant on AI, forcing the need for a change in how organizations approach cyber resilience.
From the rise of AI-enabled attacks and extortion-only campaigns to growing concerns around third-party risk, several trends have emerged over the past several months that are reshaping the ransomware landscape and raising new challenges for enterprise security leaders.

Atlassian schließt mehr als 160 Sicherheitslücken in Confluence & Co.

Heise Security 21.08.2026 08:00
Angreifer können unter anderem an kritischen Schadcode-Schwachstellen in Softwareprodukten von Atlassian ansetzen.

Zimbra: Warnung vor Angriffen auf Befehlsschmuggel-Lücke

Heise Security 21.08.2026 07:12
Das polnische CERT warnt vor Angriffen auf eine Befehlsschmuggel-Lücke in der Zimbra Collaboration Suite. Ein Update ist verfügbar.

Bis zu 12.000 Systeme gefährdet: Zimbra-Server werden attackiert

Golem 21.08.2026 06:42
Eine gefährliche Sicherheitslücke lässt Angreifer ohne Authentifizierung Schadcode auf Zimbra-Server schleusen. Angriffe laufen bereits. (Sicherheitslücke, Server-Applikationen)

Microsoft Patches Severe Entra ID Flaw (CVSS 10.0) Allowing Remote Code Execution

The Hacker News 21.08.2026 06:06
Update: The story was updated after publication to note that the vulnerability has not been exploited.

Although the security bulletin originally marked the "Exploited" field under the Exploitability Assessment table as "Yes," on August 21, 2026, Microsoft corrected the "Exploited" status to "No" after The Hacker News contacted the company for comment. It also noted, "this vulnerability was not