Seite wählen

04.09.2026

Kehrtwende bei Cybersicherheit: Bund gibt Plan für BSI-Grundgesetzänderung auf

Heise Security 03.09.2026 16:58
Trotz der verschärften Bedrohungslage und verstärkter IT-Angriffe verzichtet die Bundesregierung überraschend auf eine Verfassungsänderung zur Stärkung des BSI.

Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root

The Hacker News 03.09.2026 15:52
Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7 umbrella CVEs, 2 of which are rated 9.8, with no workaround for any IOS XR version.

The Nexus vulnerability, tracked as CVE-2026-20212 (CVSS score: 9.8), is

BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory

The Hacker News 03.09.2026 15:26
Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts.

"Unlike the standard infostealer model, BraZetsu is a comprehensive master toolkit that empowers Initial Access Brokers (IABs) by turning compromised systems into highly valuable commercial

Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data

The Hacker News 03.09.2026 14:39
Thomson Reuters disclosed on Wednesday that an unauthorized party obtained files from C-Track, the court case management platform sold by its West Publishing Corporation unit, in March 2026, affecting courts in 11 U.S. states, the U.S. Virgin Islands, and Ontario, Canada.

West Publishing said it discovered the activity on June 30, 2026. A subset of court records could contain individuals' names

Sicherheitspatches: Attacken auf Switches mit ArubaOS-CX möglich

Heise Security 03.09.2026 13:49
Die Entwickler von HPE Aruba Networking haben 34 Sicherheitslücken in ArubaOS-CX geschlossen.

US and Canadian Court Records Breached Following Thomson Reuters Incident

Infosecurity Magazine 03.09.2026 12:00
Thomson Reuters has disclosed a cyber incident affecting its C-Track court management software, potentially exposing court records in Canada and the US

US Becomes Top Target in RMM Phishing Campaign Spanning 46 Countries

The Hacker News 03.09.2026 11:58
An RMM phishing campaign initially associated with Canadian targeting due to its use of Canada Revenue Agency (CRA) tax forms as lures has turned out to be part of a broader campaign spanning 46 countries.

Around 45% of observed activity was associated with the United States, making it the campaign's top geographic target. ANY.RUN research connected 601 cases to the wider operation, which uses

Decade-old PostgreSQL flaw turns backup account into a backdoor

CSO Online 03.09.2026 11:38
A critical vulnerability in PostgreSQL had remained hidden for more than a decade, potentially turning a routine backup account into a path to full database and server compromise.
The issue, dubbed PostGREShell by Cyera Research, exists in the database’s replication functionality and could allow an attacker with a low-privilege account carrying the REPLICATION attribute to load and execute arbitrary code.

Counterfeit installers turn routine software downloads into enterprise breaches

CSO Online 03.09.2026 11:17
Microsoft has warned that attackers are breaching enterprise systems via counterfeit download sites impersonating software including Microsoft Edge, Kaspersky and Razer, delivering trojanized installers for persistent access.
“Once executed, the malicious installers deploy malware that establishes persistence, attempts to weaken security protections, and communicates with attacker-controlled infrastructure,” Microsoft security researchers wrote in a blog post.

Attackers Turn Trusted Node.js Runtime Into Malware Delivery Tool in Targeted Attacks

The Hacker News 03.09.2026 10:43
Threat actors are leveraging the trusted Node.js JavaScript runtime in multiple cyber attacks as a way to deploy malicious payloads.

According to a new report published by the Symantec Threat Hunter Team today, the attack method has been put to use in attacks targeting government departments, technology companies, and hotels since February 2026.

"The technique's appeal is that node.exe (the

WordPress All-in-One WP Migration: Angreifer können Admin-Falle auslegen

Heise Security 03.09.2026 10:32
Eine Sicherheitslücke im WordPress-Plug-in All-in-One WP Migration and Backup gefährdet potenziell 5 Millionen Websites. Ein Update löst das Problem.

Wordpress: Lücke in Backup-Tool gefährdet Millionen von Websites

Golem 03.09.2026 08:07
In einem WordPress-Plug-in mit über 5 Millionen Installationen klafft eine gefährliche Sicherheitslücke. Admins sollten dringend handeln. (Sicherheitslücke, WordPress)

Jetzt patchen! Angreifer attackieren JFrog Artifactory und machen sich zu Admins

Heise Security 03.09.2026 07:56
JFrog Artifactory ist über zahlreiche Sicherheitslücken angreifbar. Eine Schwachstelle nutzen Angreifer bereits aus.