Atlassian’s critical flaw turns eight enterprise products into one big security problem
CSO Online 07.10.2026 01:51
A newly-disclosed critical flaw in Atlassian’s data center software has a remarkably wide reach, affecting eight core products across the company’s enterprise portfolio.
CVE-2026-21589, rated 9.3 (critical) in severity, is an arbitrary file access vulnerability that could allow an attacker with no login access to read files in web app root directories that they should not otherwise see, and potentially use them for nefarious purposes.
Ransomware Qilin: Russe von Japan an Deutschland ausgeliefert
Heise Security 06.10.2026 20:52
Er soll für die Qilin-Bande Ransomware programmiert haben. Jetzt wurde der Russe von Japan an Deutschland ausgeliefert. Das passiert selten.
Post-Quanten-Krypto: BSI besorgt über McEliece
Heise Security 06.10.2026 20:42
Das BSI hat Forschungsergebnisse zu einem der ältesten quantensicheren Kryptoverfahren analysiert und rät vom Einsatz ab – zumindest für neue Projekte.
FBI removes contractor working with its PeopleSoft system after data breach, says report
CSO Online 06.10.2026 18:26
The US Federal Bureau of Investigation has removed an Accenture contractor working on its PeopleSoft installation over their role in a data breach that exposed personal details of FBI employees, Reuters reported Monday.
This is the first time that anyone other than the hacker group Shinyhunters that claimed responsibility for the breach has linked it to PeopleSoft.
Google stellt Bug-Bounty-Programm für Open Source vorerst ein
Heise Security 06.10.2026 11:58
Google nimmt seit 1. Oktober im Bug-Bounty-Programm für Open-Source-Software vorerst keine Produktlücken mehr an.
ASOS Customers Receive Bizarre “Hacked” Message Amid Suspected Snowflake Compromise
Infosecurity Magazine 06.10.2026 11:41
ASOS customers have received a seemingly legitimate push notifications claiming the retailer’s IT systems have been breached through a Snowflake breach
Android-Patchday: Mehr als 25 Sicherheitslücken gestopft
Heise Security 06.10.2026 09:52
Im Oktober versorgt Google mehr als 25 Sicherheitslücken mit Patches. Sieben gelten als kritisches Risiko.
Android-Patchday: Google stopft sieben kritische Löcher
Golem 06.10.2026 08:31
Mindestens zwei Anfälligkeiten lassen sich ohne Interaktion mit einem Anwender ausnutzen. Sie erlauben Denial-of-Service und eine Rechteausweitung. (Android-Updates, Google)
Despite ShinyHunters arrests after FBI jobs data breach, enterprises still have no answers about PeopleSoft risks
CSO Online 06.10.2026 01:02
The theft of FBI employee data by hacking group ShinyHunters, and the subsequent shutdown of the FBI’s Peoplesoft-based jobs portal, is causing concern for enterprise users of the Oracle product, with analysts recommending extreme measures in response.
Law enforcement has made some progress in its pursuit of the cyber criminals involved, but there has still been no official word from either the FBI or Oracle about Peoplesoft’s alleged involvement.