Zum Inhalt springen

IT-Sicherheit · Aktuell

IT Security News

Aktuelle Meldungen zu IT-Sicherheit, Cyberbedrohungen und Datenschutz — automatisch kuratiert aus führenden Quellen.

Krebs on Security25. Sept. 2026

U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions

A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in

Weiterlesen
BleepingComputer25. Sept. 2026

Kiteworks urges 6-hour server shutdown over potential zero-day attacks

Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent

Weiterlesen
BleepingComputer25. Sept. 2026

ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw

The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unaut

Weiterlesen
BleepingComputer25. Sept. 2026

Elementor WordPress flaw lets attackers create admin accounts

A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...]

Weiterlesen
BleepingComputer25. Sept. 2026

CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks

The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider W

Weiterlesen
BleepingComputer25. Sept. 2026

Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions

Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it's offering up to $250 in free usage credits, so more users can give it a try. [...]

Weiterlesen
Microsoft Security25. Sept. 2026

Storm-3168: Agentic-driven cloud attacks using compromised service principals

Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for d

Weiterlesen
BleepingComputer25. Sept. 2026

OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex

OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it's unclear when it'll begin rolling out. [...]

Weiterlesen
BleepingComputer25. Sept. 2026

With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance

AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created

Weiterlesen
The Hacker News25. Sept. 2026

Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware

Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHu

Weiterlesen
The Hacker News25. Sept. 2026

PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence

Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to re

Weiterlesen
SANS ISC25. Sept. 2026

A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)

Introduction 

Weiterlesen
Heise Security25. Sept. 2026

Phishing-Angriffe mit echten Hotel-Buchungsdaten

Über eine Schwachstelle bei HotelNetSolutions wurden Buchungsdaten von Hotelgästen abgegriffen. Kriminelle nutzen sie für glaubhafte Phishing-Nachrichten.

Weiterlesen
BleepingComputer25. Sept. 2026

Microsoft plans to deprecate Windows Deployment Services

Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. [...]

Weiterlesen
Heise Security25. Sept. 2026

Knapp 10.000 Rufnummern von Cyberkriminellen abgeschaltet

Mit internationalen Partnern gehen Ermittler aus Baden-Württemberg und Deutschland gegen betrügerische Anrufe und manipulierte Handelsplattformen vor.

Weiterlesen
Heise Security25. Sept. 2026

Server am Samstagmorgen herunterfahren: Kiteworks warnt Admins vor Zero-Day

Man habe konkrete Hinweise von Strafverfolgern auf eine Attacke, schreibt der Hersteller seinen Kunden. Auch hierzulande sind große Unternehmen betroffen.

Weiterlesen
BleepingComputer25. Sept. 2026

Rydox marketplace admin pleads guilty, faces 22 years in prison

A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. [...]

Weiterlesen
The Hacker News25. Sept. 2026

The SOC Doesn't Need to Start Over with Every Alert

Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry. The routine version looks like th

Weiterlesen
Heise Security25. Sept. 2026

WordPress-Lücke nur Stunden nach Patch attackiert

WordPress hat am Dienstag zwei Sicherheitsupdates veröffentlicht. Die kritische Lücke aus dem zweiten wird bereits attackiert.

Weiterlesen
The Hacker News25. Sept. 2026

Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise

Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets.  "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthori

Weiterlesen
Heise Security25. Sept. 2026

macOS: Metas Muse-Agent war per ClickFix übernehmbar

Meta hält es nicht für eine Remote-Übernahme, doch der Sicherheitsexperte Patrick Wardle sieht das anders: Die mächtige Muse-App für macOS war angreifbar.

Weiterlesen
BleepingComputer25. Sept. 2026

Microsoft: Recent Windows updates cause desktop loading issues

Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. [...]

Weiterlesen
The Hacker News25. Sept. 2026

Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authe

Weiterlesen
Golem Security25. Sept. 2026

Schadcode-Attacken möglich: Angreifer können Gitlab-Instanzen kapern

Mehrere Sicherheitslücken lassen Angreifer Schadcode auf Gitlab-Server sowie in die Webbrowser anderer Nutzer einschleusen. Admins sollten zügig handeln. (<a href="https://www.golem.de/specials/sicherheitsluecke/">Sicher

Weiterlesen
Heise Security25. Sept. 2026

Neobank Revolut: Cybergang „Imnotavillain“ behauptet Datendiebstahl

Die kriminelle Online-Bande „Imnotavillain“ behauptet im Darknet, von der Neobank Revolut vertrauliche Daten erhalten zu haben.

Weiterlesen
Heise Security25. Sept. 2026

Sicherheitslücken: GitLab-Server sind für Schadcode-Attacken anfällig

Die GitLab-Entwickler raten zur zügigen Installation der jüngst veröffentlichten Sicherheitsupdates.

Weiterlesen
Golem Security25. Sept. 2026

Muse leakt Systemdateien: Metas KI-Agent gibt auf Anfrage sein Dateisystem aus

Ein Entwickler hat Metas KI-Agent Muse 6,8 GByte an Daten aus seiner Betriebsumgebung entlockt. Laut Meta ist das ein erwartetes Verhalten. (<a href="https://www.golem.de/specials/ki/">KI</a>, <a href="https://www.golem.

Weiterlesen
BleepingComputer25. Sept. 2026

Hackers steal $351.6 million in Bitget crypto exchange hack

​Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. [...]

Weiterlesen
Heise Security25. Sept. 2026

Jetzt updaten! Attacken auf Roundcube-Webmail-Instanzen beobachtet

Angreifer nutzen derzeit eine Sicherheitslücke in Roundcube Webmail aus. Dafür müssen aber die Voraussetzungen stimmen.

Weiterlesen
Heise Security25. Sept. 2026

Video-Tool VLC: Version 3.0.24 stopft über 130 Sicherheitslecks

Der Videoplayer VLC ist in Version 3.0.24 erschienen. Mehr als 130 Sicherheitslücken soll das Release schließen.

Weiterlesen
Golem Security25. Sept. 2026

Anzeige: Sicherheitsvorfälle: Die ersten Schritte entscheiden

First Response auf Security Incidents verlangt klare Abläufe und technische Maßnahmen. Ein Workshop der Golem Karrierewelt vermittelt Vorgehen, Forensik und Beweissicherung. (<a href="https://www.golem.de/specials/golema

Weiterlesen
Allianz Cyber-Sicherheit25. Sept. 2026

Partnerangebot: UNIVADO &#8211; Webinar &#8222;KI-Agenten au&#223;er Kontrolle?&#8220; & E-Learning &#8222;KI-Kompetenz Training nach Art. 4 der KI-VO&#8220;

Im Partnerbeitrag der UNIVADO geht es darum, wer haftet, wenn k&#252;nstliche Intelligenz pl&#246;tzlich selbst entscheidet, bucht und Vertr&#228;ge abschie&#223;t. Begleitet wird das Webinar von kostenfreien Lizenzen f&

Weiterlesen
The Hacker News25. Sept. 2026

Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data

A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk s

Weiterlesen
The Hacker News25. Sept. 2026

WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based o

Weiterlesen
SANS ISC25. Sept. 2026

ISC Stormcast For Friday, September 25th, 2026 https://isc.sans.edu/podcastdetail/10110, (Fri, Sep 25th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Weiterlesen
BleepingComputer24. Sept. 2026

MacSync malware uses public iCloud calendars to deliver new payloads

A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. [...]

Weiterlesen
BleepingComputer24. Sept. 2026

New Carbonato malware uses AI agents to hijack exposed Docker hosts

A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]

Weiterlesen
The Hacker News24. Sept. 2026

Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions

A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats,&nbsp;chained two flaws in OnePlus's own software&nbsp;

Weiterlesen
The Hacker News24. Sept. 2026

ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories

This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pi

Weiterlesen
BleepingComputer24. Sept. 2026

Exposed GitLab project email addresses let attackers push code

Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...]

Weiterlesen

Wird alle 30 Minuten aktualisiert · CH/DE: BACS Schweiz, BSI, Allianz Cyber-Sicherheit, Heise Security, Golem · EN: BleepingComputer, The Hacker News, Fortinet, SANS ISC, Microsoft Security, Krebs on Security, Kaspersky