IT-Sicherheit · Aktuell
IT Security News
Aktuelle Meldungen zu IT-Sicherheit, Cyberbedrohungen und Datenschutz — automatisch kuratiert aus führenden Quellen.
U.S. Soldier Gets 70 Months in Prison for AT&T, Verizon Extortions
A U.S. Army soldier who pleaded guilty to hacking into multiple telecommunications companies and stealing mobile call and text metadata for more than 100 million AT&T customers in 2024 was sentenced to 70 months in
Kiteworks urges 6-hour server shutdown over potential zero-day attacks
Secure file-sharing software company Kiteworks is urging customers worldwide to temporarily shut down their servers on Saturday for a six-hour window after receiving threat intelligence warning of a potentially imminent
ShinyHunters hacked Clop leak site using Grav CMS path traversal flaw
The Clop ransomware gang has moved its data leak site to a new Tor address after confirming its previous server was compromised and defaced through an unpatched Grav CMS flaw that BleepingComputer has learned is an unaut
Elementor WordPress flaw lets attackers create admin accounts
A cross-site request forgery (CSRF) vulnerability in the Elementor plugin for WordPress could allow an unauthenticated attacker to create administrator accounts. [...]
CISA warns of Sharepoint, WSO2, Adobe Commerce flaws exploited in attacks
The Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical authentication bypass vulnerability (CVE-2026-5430) affecting multiple products from enterprise software provider W
Anthropic rolls out up to $250 in free Claude Code credits, but only for cloud sessions
Anthropic now allows you to run Claude Code via cloud sessions without signing up for the research preview, and it's offering up to $250 in free usage credits, so more users can give it a try. [...]
Storm-3168: Agentic-driven cloud attacks using compromised service principals
Microsoft details JADEPUFFER-linked Azure reconnaissance, resource deletion, and credential access using compromised service principals, identifying the activity as associated with Storm-3168 and providing guidance for d
OpenAI is preparing a $500 ChatGPT Pro Max plan with faster Codex
OpenAI appears to be preparing a new ChatGPT Pro Max subscription that could cost $500 per month, but it's unclear when it'll begin rolling out. [...]
With the Rise of AI Agents, SOC 2 Should Adapt or Risk Irrelevance
AI agents can operate through human credentials and take actions that existing SOC 2 controls may not distinguish from human activity. Token Security explains why SOC 2 needs to adapt to address the security gaps created
Compromised GitHub Actions Came Back Online and Resumed Executing Mini Shai-Hulud Malware
Two actions-cool GitHub Actions have been disabled for a second time after the repositories became accessible last week, months after they were compromised during the May 2026 Mini Shai-Hulud campaign. The affected GitHu
PamStealer macOS Malware Adds Live C2 Payload Decryption and Multi-Layer Persistence
Cybersecurity researchers have flagged a new version of PamStealer that ensures that the main payload can only be recovered using a server-side decryption chain. The latest artifacts, per Jamf Threat Labs, continue to re
A Closer Look at Malware From the Macfinger ClickFix Campaign, (Fri, Sep 25th)
Introduction 
Phishing-Angriffe mit echten Hotel-Buchungsdaten
Über eine Schwachstelle bei HotelNetSolutions wurden Buchungsdaten von Hotelgästen abgegriffen. Kriminelle nutzen sie für glaubhafte Phishing-Nachrichten.
Microsoft plans to deprecate Windows Deployment Services
Microsoft announced it will deprecate the Windows Deployment Services (WDS) server role starting with the next Windows Server release. [...]
Knapp 10.000 Rufnummern von Cyberkriminellen abgeschaltet
Mit internationalen Partnern gehen Ermittler aus Baden-Württemberg und Deutschland gegen betrügerische Anrufe und manipulierte Handelsplattformen vor.
Server am Samstagmorgen herunterfahren: Kiteworks warnt Admins vor Zero-Day
Man habe konkrete Hinweise von Strafverfolgern auf eine Attacke, schreibt der Hersteller seinen Kunden. Auch hierzulande sind große Unternehmen betroffen.
Rydox marketplace admin pleads guilty, faces 22 years in prison
A Kosovar national has pleaded guilty to operating Rydox, a large illegal online marketplace that sold stolen personal information, login credentials, credit card details, and cybercrime tools. [...]
The SOC Doesn't Need to Start Over with Every Alert
Security leaders keep debating whether AI will produce an entirely new class of cyberattack. The nearer change is quieter and already visible: AI has made a failed attack cheap to retry. The routine version looks like th
WordPress-Lücke nur Stunden nach Patch attackiert
WordPress hat am Dienstag zwei Sicherheitsupdates veröffentlicht. Die kritische Lücke aus dem zweiten wird bereits attackiert.
Bitget Says Suspected North Korean Hackers Stole $351.6M After Backend Compromise
Cryptocurrency exchange Bitget said suspected North Korean threat actors have stolen $351.6 million from its hot and warm wallets. "At 18:31 UTC on September 24, 2026, Bitget's security systems identified unauthori
macOS: Metas Muse-Agent war per ClickFix übernehmbar
Meta hält es nicht für eine Remote-Übernahme, doch der Sicherheitsexperte Patrick Wardle sieht das anders: Die mächtige Muse-App für macOS war angreifbar.
Microsoft: Recent Windows updates cause desktop loading issues
Microsoft has confirmed that some users may experience desktop loading issues, including black screens, after installing the August 2026 preview updates and subsequent updates. [...]
Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild
The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question is CVE-2026-48842 (CVSS score: 8.1), a pre-authe
Schadcode-Attacken möglich: Angreifer können Gitlab-Instanzen kapern
Mehrere Sicherheitslücken lassen Angreifer Schadcode auf Gitlab-Server sowie in die Webbrowser anderer Nutzer einschleusen. Admins sollten zügig handeln. (<a href="https://www.golem.de/specials/sicherheitsluecke/">Sicher
Neobank Revolut: Cybergang „Imnotavillain“ behauptet Datendiebstahl
Die kriminelle Online-Bande „Imnotavillain“ behauptet im Darknet, von der Neobank Revolut vertrauliche Daten erhalten zu haben.
Sicherheitslücken: GitLab-Server sind für Schadcode-Attacken anfällig
Die GitLab-Entwickler raten zur zügigen Installation der jüngst veröffentlichten Sicherheitsupdates.
Muse leakt Systemdateien: Metas KI-Agent gibt auf Anfrage sein Dateisystem aus
Ein Entwickler hat Metas KI-Agent Muse 6,8 GByte an Daten aus seiner Betriebsumgebung entlockt. Laut Meta ist das ein erwartetes Verhalten. (<a href="https://www.golem.de/specials/ki/">KI</a>, <a href="https://www.golem.
Hackers steal $351.6 million in Bitget crypto exchange hack
Cryptocurrency exchange Bitget disclosed today that suspected North Korean hackers have stolen $351.6 million from its hot and warm wallets. [...]
Jetzt updaten! Attacken auf Roundcube-Webmail-Instanzen beobachtet
Angreifer nutzen derzeit eine Sicherheitslücke in Roundcube Webmail aus. Dafür müssen aber die Voraussetzungen stimmen.
Video-Tool VLC: Version 3.0.24 stopft über 130 Sicherheitslecks
Der Videoplayer VLC ist in Version 3.0.24 erschienen. Mehr als 130 Sicherheitslücken soll das Release schließen.
Anzeige: Sicherheitsvorfälle: Die ersten Schritte entscheiden
First Response auf Security Incidents verlangt klare Abläufe und technische Maßnahmen. Ein Workshop der Golem Karrierewelt vermittelt Vorgehen, Forensik und Beweissicherung. (<a href="https://www.golem.de/specials/golema
Partnerangebot: UNIVADO – Webinar „KI-Agenten außer Kontrolle?“ & E-Learning „KI-Kompetenz Training nach Art. 4 der KI-VO“
Im Partnerbeitrag der UNIVADO geht es darum, wer haftet, wenn künstliche Intelligenz plötzlich selbst entscheidet, bucht und Verträge abschießt. Begleitet wird das Webinar von kostenfreien Lizenzen f&
Cloudflare Fixes Flaw That Let One Container Read Another Customer's Leftover Disk Data
A flaw in Cloudflare Containers let a paying customer read data that other customers' containers had left behind on the same server, Cloudflare and the researchers who found it said on Thursday. The data came from disk s
WSO2 and Adobe Commerce Flaws Exploited in Attacks, Added to CISA KEV
The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added two critical security flaws impacting WSO2 and Adobe Commerce and Magento to its Known Exploited Vulnerabilities (KEV) catalog, based o
ISC Stormcast For Friday, September 25th, 2026 https://isc.sans.edu/podcastdetail/10110, (Fri, Sep 25th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
MacSync malware uses public iCloud calendars to deliver new payloads
A new variant of the MacSync malware targeting macOS systems now uses public iCloud calendar events to deliver new native payloads. [...]
New Carbonato malware uses AI agents to hijack exposed Docker hosts
A new botnet malware called Carbonato is targeting insecure hosts running Docker daemons to install the Hermes Agent AI framework and take control. [...]
Unpatched OnePlus Flaws Let Installed Android Apps Gain Root Without Permissions
A OnePlus 15 running the latest OxygenOS can be rooted by a malicious app the owner installs, one that asks for no special permissions. A researcher, Rasmus Moorats, chained two flaws in OnePlus's own software
ThreatsDay: AI Search Poisoning, AI Coding Tool Leaking Repos, One-Click Code Execution and 13 More Stories
This week, the dangerous stuff keeps arriving dressed as something boring. An update. A login box. A search answer. A coding tool. A link you have clicked a hundred times before. That is the thread running through the pi
Exposed GitLab project email addresses let attackers push code
Private GitLab email addresses that allow developers to push issues or tasks to a project are being deliberately exposed in READMEs, contributing guides, and support pages used to collect bug reports. [...]
Wird alle 30 Minuten aktualisiert · CH/DE: BACS Schweiz, BSI, Allianz Cyber-Sicherheit, Heise Security, Golem · EN: BleepingComputer, The Hacker News, Fortinet, SANS ISC, Microsoft Security, Krebs on Security, Kaspersky