Zum Inhalt springen

IT-Sicherheit · Aktuell

IT Security News

Aktuelle Meldungen zu IT-Sicherheit, Cyberbedrohungen und Datenschutz — automatisch kuratiert aus führenden Quellen.

SANS ISC05. Okt. 2026

ISC Stormcast For Monday, October 5th, 2026 https://isc.sans.edu/podcastdetail/10122, (Mon, Oct 5th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Weiterlesen
SANS ISC05. Okt. 2026

TTY Logs and the Data it Captures, (Sun, Oct 4th)

For an experiment, I created a script [ 1 ] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs ar

Weiterlesen
BleepingComputer04. Okt. 2026

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be explo

Weiterlesen
Golem Security04. Okt. 2026

David Robinson: Warum OpenAIs Sicherheitschef nun geht

Ein Ex-Mitarbeiter warnt: Bei OpenAI komme Sicherheit im Tempo neuer KI-Produkte oft zu kurz. (<a href="https://www.golem.de/specials/openai/">OpenAI</a>, <a href="https://www.golem.de/specials/ki/">KI</a>) <img src="htt

Weiterlesen
Heise Security04. Okt. 2026

Bericht: FBI-Angreifer von „ShinyHunters“ gefasst und kooperativ

Einem Bericht zufolge wurde ein weiteres Mitglied der Cyberbande „ShinyHunters“ in Jordanien festgesetzt. Er soll mit dem FBI kooperieren.

Weiterlesen
Heise Security04. Okt. 2026

Citrix Netscaler aktualisieren! Zero-Day verursacht Crashes und Codeausführung

Sicherheitsforscher und Administratoren melden massenhafte Spontanreboots betroffener Geräte. Updates sind nun verfügbar und sollten schnell aufgespielt werden.

Weiterlesen
BleepingComputer04. Okt. 2026

Anthropic asks Claude users to share voice data for AI model training

Anthropic has started asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. [...]

Weiterlesen
SANS ISC04. Okt. 2026

User Agent Strings Curiosities, (Sun, Oct 4th)

Sometimes I have to smile, or my interest is triggered, when I review new User Agent Strings in the honeypot logs. &#xd;

Weiterlesen
The Hacker News04. Okt. 2026

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Re

Weiterlesen
The Hacker News04. Okt. 2026

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal se

Weiterlesen
BleepingComputer03. Okt. 2026

Google Gemini could soon get full access to your Mac’s files, apps and the web

Google's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. [...]

Weiterlesen
BleepingComputer03. Okt. 2026

ShinyHunters hacker reportedly detained in Jordan, aiding FBI

A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]

Weiterlesen
SANS ISC03. Okt. 2026

YARA-X 1.21.0 Release, (Sat, Oct 3rd)

YARA-X&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s 1.21.0 release brings 5 improvements and 4 bugfixes. &#xd;

Weiterlesen
The Hacker News03. Okt. 2026

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Servic

Weiterlesen
The Hacker News03. Okt. 2026

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speak

Weiterlesen
BleepingComputer03. Okt. 2026

Danish university DTU breach exposes data of up to 200,000 people

The Technical University of Denmark (DTU) says information belonging to up to 200,000 users may have been exposed after hackers accessed its identity and access management system and downloaded a large amount of data. [.

Weiterlesen
The Hacker News03. Okt. 2026

The State of Cybersecurity in 2026: Key Segments, Insights, and Innovations

Featuring: Cybersecurity is being reshaped by the expansion of cloud infrastructure, AI, distributed systems, and increasingly complex digital environments. As organizations manage more identities, devices, data, and int

Weiterlesen
Golem Security03. Okt. 2026

Macos: Apple verschärft Full Disk Access wegen KI-Agenten

Apple plant strengere Kontrollen für Full Disk Access. Grund sind laut Apple wachsende Risiken durch KI-Agenten. (<a href="https://www.golem.de/specials/macos/">MacOS</a>, <a href="https://www.golem.de/specials/apple/">A

Weiterlesen
Heise Security02. Okt. 2026

Trickreicher Angriff knackt RSA-Signaturen – ein bisschen

Ein neues Paper reduziert die angenommene Sicherheit von 1024-Bit-RSA, indem es Signaturen fälscht. Doch die Methode ist in der Praxis kaum relevant.

Weiterlesen
BleepingComputer02. Okt. 2026

Frontline Education breach exposes school district employee data

Frontline Education is notifying school districts of a data breach after attackers exploited a vulnerability in third-party software to gain unauthorized access to its systems and steal employee information, including So

Weiterlesen
BleepingComputer02. Okt. 2026

Warlock ransomware breach SharePoint in water, telecom operator attacks

The China-linked ransomware group Warlock targeted a water utility, a telecom provider, a regional government body, and a university by exploiting SharePoint vulnerabilities to gain initial access. [...]

Weiterlesen
The Hacker News02. Okt. 2026

GitLab Patches Critical 9.9 AI Gateway Flaw Allowing Command Execution on Self-Hosted Servers

A critical flaw in GitLab's AI Gateway could let a logged-in user with Duo Agent Platform access run commands on the gateway under certain conditions, GitLab&nbsp;said in an advisory. The gateway is the service that conn

Weiterlesen
The Hacker News02. Okt. 2026

Antino Backdoor Uses Outlook and OneDrive for C2 in China-Nexus Espionage Campaign

Government and policy organizations across Asia have become the target of a new campaign orchestrated by a China-nexus threat actor. The activity, which has targeted government and policy organizations in Taiwan, India,

Weiterlesen
The Hacker News02. Okt. 2026

Dell CSM Flaws Enable Unauthenticated Admin Access and Root on Kubernetes Nodes

Dell has released security updates to address multiple critical security flaws in Dell Container Storage Modules (CSM) that could be exploited by bad actors to take over susceptible systems. The vulnerabilities are liste

Weiterlesen
Golem Security02. Okt. 2026

Anzeige: Microsoft 365 DSGVO-konform betreiben

Microsoft 365 DSGVO-konform zu betreiben erfordert technische und organisatorische Maßnahmen. Die Golem Karrierewelt vermittelt die relevanten Werkzeuge und Anforderungen. (<a href="https://www.golem.de/specials/golemaka

Weiterlesen
BleepingComputer02. Okt. 2026

GitLab warns of critical RCE vulnerability in AI Gateway service

GitLab warned customers today to immediately patch a critical AI Gateway vulnerability that could let attackers run arbitrary commands on vulnerable instances. [...]

Weiterlesen
BleepingComputer02. Okt. 2026

US sanctions Tren de Aragua gang members in ATM hacks crackdown

The U.S. Treasury Department has sanctioned eight members of the Venezuelan gang Tren de Aragua (TdA) for their role in the theft of millions of dollars in ATM jackpotting attacks across the United States. [...]

Weiterlesen
Golem Security02. Okt. 2026

Sicherheit: OpenAIs KI-Agenten sind bei über 100 Organisationen eingedrungen

Im Rahmen einer internen Untersuchung hat OpenAI festgestellt, dass mehr Organisationen von KI-Angriffen betroffen waren als gedacht. (<a href="https://www.golem.de/specials/openai/">OpenAI</a>, <a href="https://www.gole

Weiterlesen
Heise Security02. Okt. 2026

Mein Umzug auf einen neuen Passwort-Manager (Open Source)

Das Passwort-Chaos aufzuräumen, kann überfordern. Passwort-Manager schaffen betriebssystemübergreifend Ordnung und auf Wunsch auch Open Source.

Weiterlesen
BleepingComputer02. Okt. 2026

The EDR blind spot: 3 ways browser attacks evade endpoint telemetry

Browser-based attacks can steal sessions, abuse extensions, or manipulate users without creating the endpoint artifacts EDR is designed to detect. NordLayer explains three ways attacks can evade endpoint telemetry and wh

Weiterlesen
BleepingComputer02. Okt. 2026

Dell asks admins to patch max severity CSM flaws as soon as possible

Dell has patched two maximum severity vulnerabilities in the Container Storage Modules (CSM) that connect Dell enterprise storage arrays to Kubernetes environments. [...]

Weiterlesen
The Hacker News02. Okt. 2026

OpenAI Parts Ways With Three Safety Researchers Over Sensitive Information Mishandling

OpenAI has parted ways with three members of its safety team after they leaked private information in violation of company policies, The Wall Street Journal reported. "We have parted ways with three individuals for viola

Weiterlesen
The Hacker News02. Okt. 2026

Why CISOs Struggle to Answer the Board's Three Hardest Questions, and How to Fix the Report

The quarterly board meeting is two weeks out. The security team is pulling exports from the identity provider, the cloud posture tool, the vulnerability scanner, the SIEM and the EDR console. Someone is building a spread

Weiterlesen
BleepingComputer02. Okt. 2026

Microsoft’s X account hacked in crypto pump-and-dump scheme

On Thursday, unknown attackers hijacked the official Microsoft account on X, which has over 13 million followers, in what appeared to be a pump-and-dump scheme promoting a crypto token. [...]

Weiterlesen
Heise Security02. Okt. 2026

1Password 7 ohne Cloud: Mac-Update streicht Browser-Plug-in

Seit 1Password 8 zwingt der populäre Passwortmanager Nutzer in die Cloud. Auf dem Mac gab es lange einen Ausweg. Der wird nun per Aktualisierung verbaut.

Weiterlesen
Heise Security02. Okt. 2026

OpenAI feuert drei Mitarbeiter nach KI-Enthüllungen

Eskapaden von KI des ChatGPT-Entwicklers OpenAI schürten zuletzt die Angst vor der Technologie. Die Firma hat nun drei Mitarbeiter gefeuert.

Weiterlesen
Golem Security02. Okt. 2026

Anzeige: GL.iNet-5G-Reiserouter mit eSIM als früher Prime-Deal zum Tiefpreis

Der GL.iNet Mudi 7 verwandelt jede SIM oder eSIM in ein privates Wi-Fi-7-Netz mit VPN und ist für Prime-Mitglieder jetzt spürbar günstiger. (<a href="https://www.golem.de/specials/technik-und-hardware/">Technik/Hardware<

Weiterlesen
Heise Security02. Okt. 2026

iPhone-Sperre überlisten: Graykey trickst Reboot aus

iPhones sind nach Neustart schwerer zu knacken. Eine Sicherheitsfunktion, die den Reboot erzwingt, soll sich nun aushebeln lassen – mit einem besonderen Trick.

Weiterlesen
Golem Security02. Okt. 2026

Hackerangriff: Pentagon verliert Daten von mehr als drei Millionen Personen

Unbefugte haben rund neun Monate lang Zugriff auf einen Server mit Personaldaten. Die Daten auf dem Server des Pentagon sind unverschlüsselt. (<a href="https://www.golem.de/specials/security/">Security</a>, <a href="http

Weiterlesen
The Hacker News02. Okt. 2026

Android 17 Advanced Protection Locks Accessibility Services to Verified Accessibility Tools

Google has announced a new security measure that limits access to Android's accessibility services to verified applications classified as Accessibility Tools when Advanced Protection is enabled. With malicious Android ap

Weiterlesen

Wird alle 30 Minuten aktualisiert · CH/DE: BACS Schweiz, BSI, Allianz Cyber-Sicherheit, Heise Security, Golem · EN: BleepingComputer, The Hacker News, Fortinet, SANS ISC, Microsoft Security, Krebs on Security, Kaspersky