ServiceNow patches three maximum severity flaws that could put enterprise data at risk
CSO Online 28.08.2026 22:59
Code injection and SQL injection attacks have been around for decades, and they are still tried-and-true ways for attackers to compromise systems.
ServiceNow’s latest trio of maximum severity flaws shows that even AI-era platforms remain vulnerable to these techniques: The software provider has released patches for three bugs in its ServiceNow AI Platform that could be exploited via low-complexity code injection, SQL injection, and privilege escalation attacks, with no user interaction required.
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable
The Hacker News 28.08.2026 20:38
Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026.
The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS score.
Affected versions are < 0.6.2 and >=
GPUThor hardware attack can root Nvidia GPU systems
CSO Online 28.08.2026 18:46
Hardware security researchers from University of Toronto have developed a new memory bit flipping technique that significantly improves on previously known attacks against GPU memory. The new method can defeat the error-correcting codes (ECC) defense used on enterprise Nvidia GPUs and can lead to root access on the underlying system.
Dubbed GPUThor, the technique falls in a category of attacks known as Rowhammer that exploits the cell density of modern random access memory (RAM) chips. The original Rowhammer attack was demonstrated against DDR3 and DDR4 chips back in 2015 and relies on an older observation that tightly packed rows of memory cells can sometimes leak electrical charges to adjacent rows, flipping the stored bit values in those cells from 0 to 1 or the other way around.
Android 17 Adds OS-Wide ECH to Hide Website Visits From Network Providers
The Hacker News 28.08.2026 16:20
Google on Thursday announced new network security protections in Android 17 to bolster connection privacy, address cellular vulnerabilities, and safeguard the privacy of users' home networks.
Topping the list is support for Encrypted Client Hello (ECH), a privacy standard that prevents networks from eavesdropping on which websites a user is visiting.
"This new privacy standard works in tandem
Berlin: Cyberangriff auf die Hauptstadt – die Hacker fordern 30 Bitcoin
Spiegel Online 28.08.2026 15:09
Hinter dem Cyberangriff auf Berlin steckt die Ransomware-Gang Rhysida. Die Hacker behaupten, fast sechs Terabyte teils kritischer Daten erbeutet zu haben, wollen dafür gut zwei Millionen Euro – und setzen eine Frist.
Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL
The Hacker News 28.08.2026 11:20
ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker.
The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted customers, which leaves organizations that run their
(OEM-)China-Router von ZBT mit Backdoors
Heise Security 28.08.2026 10:39
IT-Forscher haben Router vom OEM-Hersteller ZBT untersucht, die weltweit von Anbietern verkauft werden. Darin fanden sie Backdoors.
Patch-Defizit in Deutschland: Exploit gefährdet 85 Prozent aller Exchange-Server
Golem 28.08.2026 10:20
Auf Github ist ein Exploit für eine gefährliche Exchange-Lücke aufgetaucht. Einen Patch gibt es zwar, doch den haben in Deutschland nur wenige installiert. (Sicherheitslücke, Microsoft)
Zwei kritische Lücken in Next.js – Remote-Code-Ausführung unter Windows
Heise Security 28.08.2026 10:11
Die zwei kritischen von Vercel gemeldeten Lücken im JavaScript-Framework Next.js ermöglichen es Angreifern, Code auszuführen.
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
The Hacker News 28.08.2026 09:45
cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user.
The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel & WHM.
cPanel described the issue as a critical security vulnerability and said that an
PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
The Hacker News 28.08.2026 08:25
PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.
The company has released an emergency patch for v25 and v26 to address the issue. It said it's "aware of confirmed customer incidents and is treating this matter with the highest priority." An
Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations
Infosecurity Magazine 28.08.2026 08:00
Aurora ransomware operators are abusing SpaceX’s Cursor Agent AI tool to conduct tasks such as reconnaissance and exploitation activities
Google macht Android 17 sicherer: ECH-Unterstützung und 2G-Abschaltung
Heise Security 28.08.2026 07:58
Mit Android 17 führt Google neue Netzwerksicherheitsfunktionen ein. Diese sollen Verbindungen absichern und die Privatsphäre im heimischen WLAN schützen.
TeamViewer schließt hochriskante Lücken in Clients
Heise Security 28.08.2026 07:46
Die TeamViewer-Clients können Angreifern das Ausführen von Schadcode ermöglichen. Updates stopfen die hochriskanten Sicherheitslücken.
Jetzt patchen! Angreifer attackieren PaperCut NG/MF
Heise Security 28.08.2026 07:02
Der Hersteller der Druckerverwaltungssoftware PaperCut NG/MF hat ein Notfall-Sicherheitsupdate veröffentlicht.