Seite wählen

25.09.2026

WordPress patches a critical severity security vulnerability

CSO Online 24.09.2026 20:26
WordPress has patched what it described as a critical severity security vulnerability that would allow an unauthenticated attacker full remote code execution (RCE) capabilities. There have already been reports of attacks in the wild.
Given its popularity, WordPress has frequently been under attack, and patched another maximum severity bug allowing RCE in July. WordPress said the current hole, tracked as CVE-2026-87902, was discovered and reported to the company by Switzerland-based security researcher Robert Ressl.

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

The Hacker News 24.09.2026 18:10
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software to gain root access, the highest level of control over an Android phone.

OnePlus told him the same flaws affect many more of its own devices and those of OPPO, though it has not

Angriff mit KI-Agenten auf hunderte Shops: 600.000 Kreditkartendaten geklaut

Heise Security 24.09.2026 13:02
Ein Angreifer hat hunderte Online-Shops mit KI-Agenten angegriffen und dabei Daten von mehr als 600.000 Kreditkarten abgegriffen.

UK Government Shifts to Service-Led Cyber Governance After Stinging Audit

Infosecurity Magazine 24.09.2026 11:00
Whitehall is shifting from mandatory cyber controls to service-led governance following a critical audit exposing failures of its 2022 cyber strategy

Speicherort von Microsoft-365-Daten für kurze Zeit wählbar

Heise Security 24.09.2026 09:29
IT-Verantwortliche haben bis zum 14. Dezember Zeit, den Speicherort ihrer Microsoft-365-Daten auszuwählen: im eigenen Land oder EU.

Sicherheitspatch gegen Schadcode repariert SolarWinds Observability Self-Hosted

Heise Security 24.09.2026 08:23
Die Monitoring-Lösung für IT-Infrastrukturen SolarWinds Observability Self-Hosted ist unter bestimmten Voraussetzungen verwundbar.