Seite wählen

Nachrichtenarchiv

10.07.2026

Operation „First Light 2026“: 5.800 Verdächtige weltweit festgenommen

Heise Security 09.07.2026 19:12
In einer weltweiten Aktion gegen Social-Engineering-Betrug wurden Tausende Verdächtige inhaftiert und Beträge in Millionenhöhe sichergestellt.

n8n: CERT-Bund veröffentlicht Warnmeldung zu kürzlich beseitigten Schwachstellen

Heise Security 09.07.2026 14:27
Kritisch ist keine der jüngst gefixten Lücken in der Automatisierungslösung n8n. Dennoch betont eine Warnmeldung des BSI die hohe Update-Relevanz.

Chrome-Browser & ChromeOS LTS : Updates schließen teils kritische Lücken

Heise Security 09.07.2026 12:01
Fur Windows, macOS, Linux und die Android-Version des Chrome-Browsers sind Sicherheitsupdates verfügbar. Auch die LTS-Fassung von ChromeOS wurde abgedichtet.

Chinese-Funded Interpol Cybercrime Crackdown Leads to 5,800 Arrests

Infosecurity Magazine 09.07.2026 11:45
Operation First Light 2026, coordinated by Interpol and funded by the Chinese government, has led to 5,811 arrests

RoguePlanet-Zero-Day: Microsoft legt neuen Windows-Patch nach

Heise Security 09.07.2026 10:09
Für eine zuvor nur rudimentär abgedichtete Schwachstelle aus dem Exploit-Fundus von "Nightmare Eclipse" gibt es jetzt einen neuen, (hoffentlich) finalen Patch.

Update gegen Rogueplanet: Microsoft reagiert auf gefährlichen Defender-Exploit

Golem 09.07.2026 06:52
Der Rogueplanet-Exploit verleiht Angreifern unter Windows weitreichende Systemrechte. Ein Update für den Microsoft Defender soll schützen. (Sicherheitslücke, Microsoft)

09.07.2026

Massiver Datendiebstahl bei US-Autoversicherer betrifft fast 7 Millionen Kunden

Heise Security 09.07.2026 03:04
Kriminelle haben Daten des Kfz-Versicherers AssuranceAmerica erbeutet, darunter Führerscheinangaben. Betroffen sind 6,99 Millionen Kunden in über 12 US-Staaten.

Foxit-Entwickler schließen Schwachstellen in PDF Reader und Editor

Heise Security 08.07.2026 15:16
Nicht kritisch, aber zahlreich: Aktuelle Sicherheitsupdates dichten Foxits PDF Reader und Editor gegen eine lange Lückenliste ab.

Ubiquiti Patches Critical UniFi Flaws Across Connect, Talk, Access, Protect, and OS

The Hacker News 08.07.2026 14:38
Ubiquiti has shipped updates to address multiple critical security flaws impacting UniFi Connect, UniFi Talk, UniFi Access, UniFi Protect, and UniFi OS that could result in privilege escalation and arbitrary command execution.

The list of vulnerabilities is as follows –

CVE-2026-50746 (CVSS score: 10.0) – An improper access control vulnerability in UniFi Connect Application that an attacker

Offene Datenbank: Nextcloud GmbH behebt potenzielles Datenleck

Heise Security 08.07.2026 14:21
Daten des Unternehmens hinter der populären Kollaborationslösung standen wegen einer Fehlkonfiguration offen im Netz. Die Software ist nicht betroffen.

Europa stärkt KI-Sicherheit nach US-Modell-Blockade

Heise Security 08.07.2026 13:16
Die US-Regierung hatte den Zugang zu zwei KI-Modellen von Anthropic für Ausländer blockiert. Die EU-Kommission reagiert mit einem Plan für mehr KI-Sicherheit.

CERT betont Wichtigkeit: Security-Patch für Geoinformationssystem-Plattform

Heise Security 08.07.2026 12:43
Admins, die Esris Juni-Patch noch nicht eingespielt haben, sollten dies angesichts einzelner zielgerichteter Angriffe und einem aktuellen Warnhinweis nachholen.

08.07.2026

16-year-old KVM flaw allows attackers to escape VMs and take over Linux servers

CSO Online 07.07.2026 21:53
A critical vulnerability in the Kernel-based Virtual Machine (KVM) module of the Linux kernel allows attackers with root access in a guest VM to execute arbitrary code on the host system. This violates the most important security boundary that cloud providers and enterprises rely on to isolate sensitive processes on servers.
The vulnerability, tracked as CVE-2026-53359, stems from a use-after-free memory bug in the shadow MMU emulation of KVM on x86 CPU architecture. According to Hyunwoo Kim, the researcher who discovered it, the flaw has been present in the Linux kernel code for the past 16 years and is the first KVM guest-to-host escape vulnerability that works on both Intel and AMD CPUs.

Rogue Agent Flaw Could Have Let Attackers Hijack Google Dialogflow CX Chatbots

The Hacker News 07.07.2026 16:37
A critical flaw in Google's Dialogflow CX could have let an attacker with edit rights on one Code Block-enabled agent compromise other Code Block-enabled agents in the same Google Cloud project.

From there, they could read live conversations, steal the data users shared, and make the bots send attacker-written messages, including requests to re-enter a password.

Security firm Varonis found it

Sicherheitsalbtraum Wechselrichter: Hoymiles lässt Nachbarschaften verstummen

Heise Security 07.07.2026 15:30
Schwere Funkschwachstellen bei Hunderttausenden PV-Anlagen erlauben laut Forschern das Abschalten im Vorbeifahren und sogar die physische Zerstörung der Geräte.

OpenSSH stärkt SSH gegen heutige und künftige Angriffe

Heise Security 07.07.2026 12:29
OpenSSH 10.4 behebt mehrere Sicherheitslücken in SSH, SCP und SFTP. Zudem gibt es Protokollverschärfungen und experimentelle Post-Quantum-Signaturen.

Zimbra Collaboration Suite: Kritische Lücke macht Classic Web Client angreifbar

Heise Security 07.07.2026 12:06
Admins aufgepasst: Ein Update der Zimbra Collaboration Suite kann Mail-basierte Angriffe auf den Classic Web Client abschmettern.

Samsung-Sicherheitsupdate: Juli-Patches für Galaxy-Geräte

Heise Security 07.07.2026 10:22
Samsung hat sein Security-Bulletin für Juli 2026 veröffentlicht und verteilt wichtige Sicherheitspatches vor allem für die Topmodelle der Galaxy-Reihe.

Linux-Kernel: 16 Jahre alte KVM-Lücke ermöglicht VM-Ausbruch

Golem 07.07.2026 09:07
Eine seit 2010 bestehende Lücke im KVM-Code des Linux-Kernels gefährdet unter anderem Cloudsysteme. Angreifer können damit VM-Hosts kapern. (Sicherheitslücke, Virtualisierung)

Hackers Exploit Maximum Severity Adobe ColdFusion Flaw

Infosecurity Magazine 07.07.2026 08:20
Threat actors are exploiting an Adobe ColdFusion vulnerability which has a CVSS score of 10.0

CERT/CC Warns of Hidden Admin Backdoor in Tenda Router Firmware

The Hacker News 07.07.2026 06:40
Several versions of firmware released by Chinese network device manufacturer Tenda have been found to embed an undocumented authentication backdoor that enables administrative access to the devices' web management interfaces, the CERT Coordination Center (CERT/CC) warned Monday.

"An attacker can exploit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process

BeyondTrust Patches Critical Auth Bypass Flaws in Remote Support and PRA

The Hacker News 07.07.2026 05:16
BeyondTrust has released updates to address two critical security flaws affecting Remote Support (RS) and Privileged Remote Access (PRA) products that, if successfully exploited, could allow unauthenticated attackers to take control of susceptible devices.

The vulnerabilities are listed below –

CVE-2026-40138 (CVSS score: 9.2) – A pre-authentication vulnerability exists in the

Legen wir heute los

Aufschieben ist manchmal eine Lösung. Lassen Sie uns eine bessere finden. Wir stellen Ihnen gerne unseren Ansatz für Ihre Herausforderungen vor – selbstverständlich kostenfrei. 

Lassen Sie uns jetzt über Ihr Anliegen sprechen