GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure
The Hacker News 11.09.2026 16:30
GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure.
The vulnerability in question is CVE-2026-85706 (CVSS score: 10.0), a path traversal issue in the repository commits API that could allow an unauthenticated user to read arbitrary files from the GitLab server under
ConnectWise patches critical ScreenConnect authentication failure after five days
CSO Online 11.09.2026 16:17
ConnectWise has issued a security update for ScreenConnect, five days after warning customers the product could allow files to be transferred and executed through active remote sessions without authorization or confirmation.
The company warned customers on Sept. 3 of the problem with support and access sessions in ConnectWise Remote Access, advising admins to log in and remove the “TransferFiles” permission from any users with an open session.
Anthropic-Sicherheitsreport: Wie KI genutzt wird, um Daten zu stehlen und Waffen zu bauen
Spiegel Online 11.09.2026 13:20
Derzeit tobt die Debatte, ob KI die Menschheit auslöschen kann. Anthropic gibt nun Einblicke, wie sein Dienst Claude schon heute genutzt wird, um konkreten Schaden anzurichten.
Patches: IT-Sicherheitsprodukte von Check Point werden zum Sicherheitsrisiko
Heise Security 11.09.2026 11:40
Mehrere Produkte von Check Point wie Security Gateway und Spark Firewall sind verwundbar. Davon sind auch nicht mehr im Support befindliche Versionen betroffen.
Portasplit-Sicherheitslücke: Midea verteilt Updates an Klimageräte
Heise Security 11.09.2026 11:18
Dass jeder die Portasplit von Midea per Bluetooth fernsteuern konnte, war nicht im Sinne der Entwickler – sie bessern nun nach.
Exploit-Kit Bluemoon: Chinesische Hacker attackieren Windows-Nutzer
Golem 11.09.2026 11:02
Ein neues Exploit-Kit nutzt gefährliche Sicherheitslücken in Windows und Google Chrome aus. Mehrere Cybergruppierungen machen davon Gebrauch. (Cybercrime, Google)
Patchday SAP: Präparierte Netzwerkanfrage ebnet Weg für Abstürze
Heise Security 11.09.2026 09:44
Mehrere kritische Sicherheitslücken gefährden unter anderem SAP Extended Passport und NetWeaver.
Die CRA-Meldepflicht startet – was Hersteller jetzt wissen müssen
Heise Security 11.09.2026 09:31
Die ersten Meldepflichten des Cyber Resilience Act (CRA) starten am Freitag. Eine Bitkom-Umfrage zeigt: Viele Unternehmen sind unvorbereitet.
Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors
The Hacker News 11.09.2026 07:31
Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report.
Wiz saw the attacks between August 15 and September 8. JFrog had fixed both flaws before then, so only servers that had not been updated were open to them.
PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws
The Hacker News 11.09.2026 06:46
PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation.
The software development company said PaperCut NG/MF versions 26.0.5, 25.0.13 and 24.1.10 are now available for customers to download.
"These are Regular Maintenance Releases (MR) that