Auch Googles KI Gemini hackte Unternehmen
Spiegel Online 19.09.2026 03:55
Passwörter erraten, in eine Datenbank einbrechen: Googles KI Gemini ist bei Tests unerlaubt in fremde Systeme eingedrungen. Der Konzern wusste davon, hielt es aber nicht für erwähnenswert.
New WordPress Click2Shell Flaw Forces Theme Installs, Can Chain to Code Execution
The Hacker News 18.09.2026 16:56
WordPress today released patches to fix a new set of vulnerabilities in its core software, one of which could allow a crafted web link, opened by a logged-in administrator, to install a theme from the official WordPress.org directory without anyone clicking Install.
The security firm pwn.ai, whose researchers reported the flaw, calls the attack chain Click2Shell. On its own the flaw only
CISA is ending its monthly vulnerability bulletin
CSO Online 18.09.2026 16:52
The rise in AI-generated security threats may just have generated one casualty: the death of the weekly bulletin of security threats from the US Cybersecurity Infrastructure and Security Agency (CISA).
The agency will discontinue its weekly bulletin of known vulnerabilities from September 28. It said that it is taking this step because of the recently introduced Binding Operational Directive (BOD 26-04), which compels US agencies to prioritize patching vulnerabilities according to real-world risk factors. These will include evidence of vulnerabilities being identified in the wild, as opposed to the previous criterion of severity scores. It is not clear why the agency cannot continue to issue weekly bulletins while complying with the demands of BOD.
EU prüft OpenAI nach nicht gemeldetem Sicherheitsvorfall
Heise Security 18.09.2026 16:21
Nach einem Vorfall beim Software-Register RubyGems meldete OpenAI diesen nicht der EU. Die europäischen Behörden prüfen nun die Einhaltung des AI Acts.
A zero-click RCE flaw in AI coding agents could have exposed enterprise systems
CSO Online 18.09.2026 15:42
Popular AI coding agents such as OpenAI’s Codex, Anthropic’s Claude Code, Google’s Gemini CLI, and Microsoft-owned GitHub Copilot were vulnerable to a zero-click attack that enabled attackers to execute malicious code, even without developer interaction, by swapping a trusted plugin from an online marketplace for a malicious one, potentially giving them a foothold in enterprise development environments.
Researchers at cybersecurity startup AIR found and reported the flaw, which they are calling Plugin4Shell, to the vendors concerned, and most of them have now released a patch for it, the researchers wrote in a blog post on Thursday.
Quellcode geklaut: Unbekannte steigen per Supply-Chain-Angriff bei CrowdSec ein
Heise Security 18.09.2026 15:39
Vor vier Monaten gelangten über dreihundert Repositories in fremde Hände. Doch die Auswirkungen des Angriff von Mai schätzt der WAF-Hersteller als gering ein.
Jetzt aktualisieren: Angreifer konnten beliebige Daten von Synology-NAS auslesen
Heise Security 18.09.2026 15:06
Gleich auf drei verschiedenen Wegen konnten Angreifer Daten von Synology-NAS klauen. Der Hersteller behebt mit einem Flicken auch weniger dringende Lücken.
Microsoft Patches CVSS 10.0 Azure AI Foundry Flaw Enabling Unauthorized Privilege Escalation
The Hacker News 18.09.2026 12:47
Microsoft has released fixes for a maximum-severity security flaw in Azure AI Foundry that could be exploited to achieve privilege escalation. No customer action is required.
The vulnerability, tracked as CVE-2026-85889, carries a CVSS score of 10.0.
"Missing authentication for critical function in Azure AI Foundry allows an unauthorized attacker to elevate privileges over a network,"
Nordkoreanische Cybergruppe bestiehlt IT-Fachleute auf Jobsuche
Heise Security 18.09.2026 12:29
Sicherheitsbehörden warnen vor einer Cybergruppe aus Nordkorea, die gezielt IT-Spezialisten angreift. Was hinter der Kampagne „Contagious Interview“ steckt.
Atlassian: Angreifer können Confluence Data Center ausspionieren
Heise Security 18.09.2026 11:41
Atlassian hat zahlreiche Sicherheitslücken in Bitbucket, Jira & Co. geschlossen. Admins sollten die verfügbaren Sicherheitspatches zeitnah installieren.
Root-Sicherheitslücke gefährdet Check Point Security Management and Log Servers
Heise Security 18.09.2026 07:47
Ein Sicherheitsupdate schließt eine kritische Schadcode-Schwachstelle in Check Point Security Management and Log Servers.