Zum Inhalt springen

IT-Sicherheit · Aktuell

IT Security News

Aktuelle Meldungen zu IT-Sicherheit, Cyberbedrohungen und Datenschutz — automatisch kuratiert aus führenden Quellen.

The Hacker News20. Aug. 2026

Rust Supply Chain Attack Puts Build-Time Malware in Crates with 245 Million Downloads

The Rust Project has deleted malicious versions of three widely used Rust crates from crates.io after a compromised maintainer account published releases that added a typosquatted dependency whose build script downloaded

Weiterlesen
The Hacker News20. Aug. 2026

Suspected Russian Hackers Abuse Google OAuth and WhatsApp Linking to Hijack Accounts

Three distinct suspected Russian cyber espionage threat clusters have been observed leveraging legitimate authentication flows to single out individuals working in academia, aerospace and defense, governments, and think

Weiterlesen
BleepingComputer20. Aug. 2026

Hackers poison arrayref Rust crate to push infostealer malware

Hackers compromised the maintainer account behind the widely used Rust crate arrayref to introduce malware that executed on developers' systems during compilation. [...]

Weiterlesen
The Hacker News20. Aug. 2026

ThreatsDay: Gogs 10.0 RCE, n8n Workflow-to-RCE, $10M Reward, GLM-5.3 AI Exploit and More

A lot of this week’s trouble starts with something trusted doing exactly what it was allowed to do. Signed drivers get turned against defenses. Legitimate apps help malware blend in. A weak header check opens a path to c

Weiterlesen
The Hacker News20. Aug. 2026

AI-Generated Exploit Scripts Target Siemens S7 PLCs in U.S. Critical Infrastructure

The U.S. government on Wednesday warned of an "active threat" targeting critical infrastructure organizations in the country using artificial intelligence (AI)-generated exploit scripts. The activity is targeting Siemens

Weiterlesen
Golem Security20. Aug. 2026

Anzeige: Microsoft Azure administrieren: Workshop für IT-Profis

Die Administration von Microsoft Azure verlangt fundiertes Wissen zu Netzwerken, Storage und Sicherheit. Ein Workshop der Golem Karrierewelt vermittelt die nötigen Kompetenzen. (<a href="https://www.golem.de/specials/gol

Weiterlesen
BleepingComputer20. Aug. 2026

Critical Elementor Pro bug exposes WordPress sites to RCE attacks

A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server. [...]

Weiterlesen
The Hacker News20. Aug. 2026

New Cryptographic Context Injection Attack Could Let Web Pages Steal Grok Chat Data

Adversa AI has disclosed an attack technique that it says can cause xAI's Grok chatbot to send a user's name, approximate location, subscription tier, and the prompts from the ongoing conversation to an attacker-controll

Weiterlesen
BleepingComputer20. Aug. 2026

How MSPs can catch phishing attacks email filters miss

AI is making phishing attacks more personalized, convincing, and difficult for traditional email filters to detect. Kaseya explains how MSPs can monitor identity, email, and endpoint activity to detect and contain attack

Weiterlesen
The Hacker News20. Aug. 2026

Isolated-vm Flaw Lets Sandboxed JavaScript Escape to Host for Potential RCE

Cybersecurity researchers have disclosed a critical security flaw in isolated-vm, a popular open-source sandbox with more than 2,900 stars and 190 forks on GitHub, that could allow attackers to escape the confines of the

Weiterlesen
The Hacker News20. Aug. 2026

Critical NetScaler Flaw Can Bypass Authentication on Certain Gateway and AAA Servers

Citrix has released updates to address two security flaws impacting NetScaler ADC and NetScaler Gateway deployments, including a critical-severity authentication bypass vulnerability. According to the cloud computing and

Weiterlesen
The Hacker News20. Aug. 2026

Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution

A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska). The vulnerability in question is CV

Weiterlesen
SANS ISC20. Aug. 2026

Using Microsoft Graph and Powershell - Risk Detection Commands, (Thu, Aug 20th)

Building on the last diary on Using MS Graph and Powershell, let&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s look at "Risky" logins. &#xd;

Weiterlesen
SANS ISC20. Aug. 2026

Using Microsoft Graph and Powershell to Mine for Information - Stale Accounts and Licenses, (Thu, Aug 20th)

Microsoft Graph is a newer API that is meant to replace several others.&&#x23&#x3b;x26&#x3b;&#x23&#x3b;xc2&#x3b;&&#x23&#x3b;x26&#x3b;&#x23&#x3b;xa0&#x3b; OK, it&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s at version 2.3.9,

Weiterlesen
Heise Security20. Aug. 2026

Microsoft behebt Sicherheitslücke: KI-Assistent Copilot verrät Schwachstellen

Sicherheitsforscher haben Microsofts KI-Assistenten dazu gebracht, seine eigenen Schutzmechanismen offenzulegen.

Weiterlesen
BleepingComputer20. Aug. 2026

Citrix urges admins to patch new NetScaler flaws as soon as possible

Citrix has warned customers to immediately secure their systems against two vulnerabilities affecting NetScaler Gateway secure remote access solutions and NetScaler ADC networking appliances. [...]

Weiterlesen
The Hacker News20. Aug. 2026

Zombie Card Attack Can Revive Expired Visa Cards for Contactless Payments

Researchers at the University of Massachusetts Amherst have demonstrated an attack that revives expired Visa contactless credit cards for real in-store purchases by rewriting the expiration date a point-of-sale (POS) ter

Weiterlesen
Heise Security20. Aug. 2026

Gefälschte Seite, falsche Software – trotz korrekt aussehender Links

Eine Kampagne mit gefälschten Webseiten zeigt korrekt erscheinende Links an, schiebt Opfern jedoch unerwünschte Software unter.

Weiterlesen
The Hacker News20. Aug. 2026

Why "Shady AI" is Security's Next Big Governance Problem

In March 2026, an internal AI agent at Meta triggered a “Sev 1” incident after sensitive company and user data was exposed to employees who weren’t authorized to access it.&nbsp; The incident began when a Meta employee p

Weiterlesen
The Hacker News20. Aug. 2026

CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification

Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front,

Weiterlesen
Golem Security20. Aug. 2026

(g+) PGLite: PostgreSQL zieht in den Browser

PGLite eröffnet neue Möglichkeiten mit der Open-Source-Datenbank PostgreSQL und ist ideal für datenschutzfreundliche KI-Anwendungen. Wir erklären es anhand eines Praxisbeispiels. Eine Anleitung von Antony Ghiroz (<a href

Weiterlesen
The Hacker News20. Aug. 2026

Manic Android Malware Exfiltrates Data From Offline Phones via Nearby Infected Devices

A new Android threat codenamed Manic has been observed actively targeting Ukrainian banks, government and identity services, and messaging applications, as well as Russian and European financial institutions, global fint

Weiterlesen
BleepingComputer20. Aug. 2026

CISA warns of hackers exploiting critical MLflow vulnerability

The Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies that threat actors are now exploiting a critical vulnerability in the MLflow open-source AI engineering platform. [...]

Weiterlesen
The Hacker News20. Aug. 2026

NASA AIT-GUI Flaws Could Let Unauthenticated Attackers Issue Spacecraft Commands

Security researchers at Cycode have disclosed a chain of flaws in AIT-GUI, the browser-based operator console for NASA/JPL's open-source AMMOS Instrument Toolkit, that allow an unauthenticated attacker to issue arbitrary

Weiterlesen
The Hacker News20. Aug. 2026

ToxicPanda 2.0 and GoldDigger Expand Android Banking Attacks with On-Device Fraud

Cybersecurity researchers have shed light on an updated version of ToxicPanda (aka TgToxic) that comes with "significant enhancements," including a set of 167 remote commands and expands its targeting footprint globally.

Weiterlesen
Golem Security20. Aug. 2026

Softwareprojekte gefährdet: Angriffe auf Gitlab beobachtet

Angreifer können durch eine Sicherheitslücke auf Gitlab-Instanzen verheerende Schäden anrichten. Attacken laufen bereits. (<a href="https://www.golem.de/specials/sicherheitsluecke/">Sicherheitslücke</a>, <a href="https:/

Weiterlesen
BleepingComputer20. Aug. 2026

New Manic Android malware can exfiltrate data through nearby devices

A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices. [...]

Weiterlesen
Heise Security20. Aug. 2026

Citrix: Kritische Lücke erlaubt Umgehung der Authentifizierung

In Netscaler ADC und Gateway von Citrix können Angreifer mehrere Lücken missbrauchen. Sie können etwa unbefugt Zugriff erlangen.

Weiterlesen
BleepingComputer20. Aug. 2026

Critical Zimbra RCE flaw now actively exploited in attacks

CERT Polska, the Polish Computer Emergency Response Team (CERT), warned that attackers have begun exploiting a critical vulnerability in Zimbra Collaboration Suite (ZCS). [...]

Weiterlesen
Heise Security20. Aug. 2026

Angriffsversuche auf GitLab-Lücke beobachtet

Attacken auf eine jüngst außerplanmäßig geschlossene Lücke in GitLab wurden beobachtet. Angreifer können etwa Projekte löschen.

Weiterlesen
The Hacker News20. Aug. 2026

40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets

A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products. According to the Socket Threat Research team, the ex

Weiterlesen
Heise Security20. Aug. 2026

Cisco-Sicherheitslücken: Angreifer können Anmeldung von Secure Workload umgehen

Es sind wichtige Sicherheitsupdates für unter anderem Cisco BroadWorks, Crosswork Security und Secure Workload erschienen.

Weiterlesen
Heise Security20. Aug. 2026

Anonymisierendes Linux: Tails 7.11 pflegt Software und schließt Schwachstellen

Die Entwickler der anonymisierenden Linux-Distribution Tails für USB-Sticks aktualisieren in Version 7.11 Kernkomponenten.

Weiterlesen
BleepingComputer20. Aug. 2026

Microsoft says August Windows updates may cause gaming issues

Microsoft is investigating a potential issue with the August 2026 updates that may prevent some games from launching or cause them to crash on affected Windows 11 systems. [...]

Weiterlesen
Heise Security20. Aug. 2026

Windows-Updates: Microsoft untersucht Spieleprobleme

Nach der Installation der Windows-Updates vom August-Patchday erhält Microsoft vermehrt Meldungen zu Problemen mit einigen Spielen.

Weiterlesen
The Hacker News20. Aug. 2026

Elementor Pro Flaw Could Let Unauthenticated Attackers Upload PHP and Execute Code

Cybersecurity researchers have disclosed details of a critical flaw in the Elementor Pro WordPress plugin that, if successfully exploited, could lead to remote code execution. The vulnerability, tracked as CVE-2026-32475

Weiterlesen
SANS ISC20. Aug. 2026

ISC Stormcast For Thursday, August 20th, 2026 https://isc.sans.edu/podcastdetail/10060, (Thu, Aug 20th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Weiterlesen
BleepingComputer20. Aug. 2026

OpenAI confirms ChatGPT is down as logins and signups fail

ChatGPT is experiencing a major outage, and users are unable to sign in, create accounts, or load chats, including previous conversations. [...]

Weiterlesen
BleepingComputer19. Aug. 2026

Rogue ransomware affiliate poses as recovery firm to steal payments

A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete s

Weiterlesen
BleepingComputer19. Aug. 2026

Sakura Internet hack exposes data of up to 1.36 million accounts

Japanese cloud and data center service provider Sakura Internet disclosed that hackers accessed its sales management system, where customer contract and membership information is stored. [...]

Weiterlesen

Wird alle 30 Minuten aktualisiert · CH/DE: BACS Schweiz, BSI, Allianz Cyber-Sicherheit, Heise Security, Golem · EN: BleepingComputer, The Hacker News, Fortinet, SANS ISC, Microsoft Security, Krebs on Security, Kaspersky