Seite wählen

08.10.2026

SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances

The Hacker News 07.10.2026 16:17
SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to send requests through the appliance and reach internal functions.

SonicWall rates it 10.0 on the CVSS scale and says it has no evidence that any of the four flaws is being

ShinyHunters Extorted Boeing Spin-off Prior to Arrests

Krebs Security 07.10.2026 13:48
A teenager from Amman, Jordan suspected of leading the prolific data theft and extortion group ShinyHunters has been detained and is reportedly cooperating with the FBI to identify other members of the hacking gang. KrebsOnSecurity has learned that the suspect, who uses the hacker handle "Rey," was detained as ShinyHunters was in the process of extorting a business unit recently divested by the global aerospace company Boeing, which manufactures the fleet of planes used by the employer of Rey's father — Royal Jordanian Airlines.

Nach FBI-Datenleck: Dienstleister rausgeworfen

Heise Security 07.10.2026 11:16
Die Cybergang ShinyHunters hat aus dem FBI-Jobportal Daten vieler Mitarbeiter kopiert. Nun wirft das FBI deswegen einen Dienstleister raus.

Sexualisierte Deepfakes und Voyeurismus: Bundeskabinett verabschiedet Gesetz gegen digitale Gewalt

Spiegel Online 07.10.2026 10:42
Ein neues Gesetz gegen digitale Gewalt soll Betroffene besser schützen. Der Entwurf schafft gleich mehrere neue Strafvorschriften. Was künftig gelten soll und wie sich Opfer wehren können. Der Überblick.

Microsoft blockiert MSIX-Dateien in Outlook

Heise Security 07.10.2026 10:24
Microsoft blockiert ab November 2026 standardmäßig MSIX- und MSIXBUNDLE-Dateien in Outlook. Ausnahmen sind über Richtlinien möglich.

Jetzt aktualisieren! Atlassian warnt vor kritischer Data-Center-Lücke

Heise Security 07.10.2026 06:50
Ein kritisches Leck in Atlassians Data-Center-Produkten ermöglicht unbefugten Dateizugriff ohne Anmeldung. Updates stehen bereit.