IT-Sicherheit · Aktuell
IT Security News
Aktuelle Meldungen zu IT-Sicherheit, Cyberbedrohungen und Datenschutz — automatisch kuratiert aus führenden Quellen.
ISC Stormcast For Monday, October 5th, 2026 https://isc.sans.edu/podcastdetail/10122, (Mon, Oct 5th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
TTY Logs and the Data it Captures, (Sun, Oct 4th)
For an experiment, I created a script [ 1 ] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs ar
Citrix patches NetScaler SAML zero-day exploited in attacks
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be explo
David Robinson: Warum OpenAIs Sicherheitschef nun geht
Ein Ex-Mitarbeiter warnt: Bei OpenAI komme Sicherheit im Tempo neuer KI-Produkte oft zu kurz. (<a href="https://www.golem.de/specials/openai/">OpenAI</a>, <a href="https://www.golem.de/specials/ki/">KI</a>) <img src="htt
Bericht: FBI-Angreifer von „ShinyHunters“ gefasst und kooperativ
Einem Bericht zufolge wurde ein weiteres Mitglied der Cyberbande „ShinyHunters“ in Jordanien festgesetzt. Er soll mit dem FBI kooperieren.
Citrix Netscaler aktualisieren! Zero-Day verursacht Crashes und Codeausführung
Sicherheitsforscher und Administratoren melden massenhafte Spontanreboots betroffener Geräte. Updates sind nun verfügbar und sollten schnell aufgespielt werden.
Anthropic asks Claude users to share voice data for AI model training
Anthropic has started asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. [...]
User Agent Strings Curiosities, (Sun, Oct 4th)
Sometimes I have to smile, or my interest is triggered, when I review new User Agent Strings in the honeypot logs. 
ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members
A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Re
China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing
A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal se
Google Gemini could soon get full access to your Mac’s files, apps and the web
Google's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. [...]
ShinyHunters hacker reportedly detained in Jordan, aiding FBI
A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]
YARA-X 1.21.0 Release, (Sat, Oct 3rd)
YARA-X&#;x26;#;39;s 1.21.0 release brings 5 improvements and 4 bugfixes. 
MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics
The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Servic
Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware
The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speak
Danish university DTU breach exposes data of up to 200,000 people
The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [.
The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations
Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and int
Macos: Apple verschärft Full Disk Access wegen KI-Agenten
Apple plant strengere Kontrollen für Full Disk Access. Grund sind laut Apple wachsende Risiken durch KI-Agenten. (<a href="https://www.golem.de/specials/macos/">MacOS</a>, <a href="https://www.golem.de/specials/apple/">A
Trickreicher Angriff knackt RSA-Signaturen – ein bisschen
Ein neues Paper reduziert die angenommene Sicherheit von 1024-Bit-RSA, indem es Signaturen fälscht. Doch die Methode ist in der Praxis kaum relevant.
Frontline Education breach exposes school district employee data
Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including So
Warlock ransomware breach SharePoint in water, telecom operator attacks
The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]
GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers
A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab said in an advisory. The gateway is the service that conn
Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign
Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India,
Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes
Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are liste
Anzeige: Microsoft 365 DSGVO-konform betreiben
Microsoft 365 DSGVO-konform zu betreiben erfordert technische und organisatorische Maßnahmen. Die Golem Karrierewelt vermittelt die relevanten Werkzeuge und Anforderungen. (<a href="https://www.golem.de/specials/golemaka
GitLab warns of critical RCE vulnerability in AI Gateway service
GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...]
US sanctions Tren de Aragua gang members in ATM hacks crackdown
The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. [...]
Sicherheit: OpenAIs KI-Agenten sind bei über 100 Organisationen eingedrungen
Im Rahmen einer internen Untersuchung hat OpenAI festgestellt, dass mehr Organisationen von KI-Angriffen betroffen waren als gedacht. (<a href="https://www.golem.de/specials/openai/">OpenAI</a>, <a href="https://www.gole
Mein Umzug auf einen neuen Passwort-Manager (Open Source)
Das Passwort-Chaos aufzuräumen, kann überfordern. Passwort-Manager schaffen betriebssystemübergreifend Ordnung und auf Wunsch auch Open Source.
The EDR blind spot: 3 ways browser attacks evade endpoint telemetry
Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and wh
Dell asks admins to patch max severity CSM flaws as soon as possible
Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. [...]
OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling
OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for viola
Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report
The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spread
Microsoft’s X account hacked in crypto pump-and-dump scheme
On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. [...]
1Password 7 ohne Cloud: Mac-Update streicht Browser-Plug-in
Seit 1Password 8 zwingt der populäre Passwortmanager Nutzer in die Cloud. Auf dem Mac gab es lange einen Ausweg. Der wird nun per Aktualisierung verbaut.
OpenAI feuert drei Mitarbeiter nach KI-Enthüllungen
Eskapaden von KI des ChatGPT-Entwicklers OpenAI schürten zuletzt die Angst vor der Technologie. Die Firma hat nun drei Mitarbeiter gefeuert.
Anzeige: GL.iNet-5G-Reiserouter mit eSIM als früher Prime-Deal zum Tiefpreis
Der GL.iNet Mudi 7 verwandelt jede SIM oder eSIM in ein privates Wi-Fi-7-Netz mit VPN und ist für Prime-Mitglieder jetzt spürbar günstiger. (<a href="https://www.golem.de/specials/technik-und-hardware/">Technik/Hardware<
iPhone-Sperre überlisten: Graykey trickst Reboot aus
iPhones sind nach Neustart schwerer zu knacken. Eine Sicherheitsfunktion, die den Reboot erzwingt, soll sich nun aushebeln lassen – mit einem besonderen Trick.
Hackerangriff: Pentagon verliert Daten von mehr als drei Millionen Personen
Unbefugte haben rund neun Monate lang Zugriff auf einen Server mit Personaldaten. Die Daten auf dem Server des Pentagon sind unverschlüsselt. (<a href="https://www.golem.de/specials/security/">Security</a>, <a href="http
Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools
Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android ap
Wird alle 30 Minuten aktualisiert · CH/DE: BACS Schweiz, BSI, Allianz Cyber-Sicherheit, Heise Security, Golem · EN: BleepingComputer, The Hacker News, Fortinet, SANS ISC, Microsoft Security, Krebs on Security, Kaspersky