Seite wählen

29.09.2026

Gefährlicher Bug: Apple fixt ältere Betriebsysteme, Updates auch für neue

Heise Security 29.09.2026 01:26
Apple hat wichtige Fehlerbehebungen für iOS 26, iPadOS 26 und mehrere ältere macOS-Versionen publiziert. Außerdem gibt es Bugfixes für die neuen Systeme.

Flink warnt Kunden nach Hackerangriff vor Betrugsversuchen

Spiegel Online 28.09.2026 20:04
Bei einer Cyberattacke auf den Lieferdienst Flink sollen Unbekannte Zugriff auf Namen von Kunden, Telefonnummern sowie Mail- und Lieferadressen gehabt haben. Nun erhalten einige von ihnen offenbar Zahlungsforderungen.

Angriffe auf Microsoft-SharePoint-Schwachstelle

Heise Security 28.09.2026 12:37
Die CISA warnt vor beobachteten Angriffen auf eine hochriskante SharePoint-Lücke und auf Mikrotik-Router.

Zero-Day in Netscaler: Citrix bestätigt Angriffe

Golem 28.09.2026 12:14
Sicherheitsforscher und -behörden warnen seit dem Wochenende vor den Schwachstellen. Citrix stellt nun auch Updates zur Beseitigung der Fehler bereit. (Security, Sicherheitslücke)

New Attack Against RSA

Schneier on Security 28.09.2026 11:02
ArsTechnica is reporting on a “new” attack against RSA, one that bypasses factoring.
First, this attack isn’t new. The original research is from 2007. What is new is the implementation.
Second, it is a forgery attack. It allows an attacker to forge digital signatures. It does not recover the private key from the public key.
Third, the attack only works against pure signatures. That is, signatures without any formatting or padding. This is not generally how we use RSA in practice.
Fourth, speed is all relative. This is not a polynomial-time algorithm; it’s a subexponential-time algorithm. But it is somewhat faster than factoring. The authors were able to forge messages for 1024-bit RSA with 1380 CPU core-years (over five real-world months)…

NetScaler admins told to patch critical zero-days in ADC and Gateway now

CSO Online 28.09.2026 10:02
Citrix NetScaler ADC and NetScaler Gateway users should take their systems offline and patch them immediately, they were told over the weekend, as news emerged of two critical unauthenticated remote code execution zero-day vulnerabilities in the products under active attack.
“Monday will be too late,” watchtower CEO Benjamin Harris wrote in a LinkedIn post on Sunday.

CISA Says Attackers Are Exploiting Two Critical Citrix NetScaler Flaws Globally

The Hacker News 28.09.2026 07:21
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Sunday added two critical Citrix NetScaler ADC and Gateway flaws to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation.

The vulnerabilities are listed below –

CVE-2026-88771 (CVSS score: 9.5) – An improper input validation vulnerability that could allow an unauthenticated attacker to

Sicherheitslücken in Wireshark: Angreifer können Abstürze auslösen

Heise Security 28.09.2026 07:01
Updates schließen 19 Lücken im Netzwerkanalysetool Wireshark. Über präparierte Profile kann Schadcode auf PCs gelangen.