Zum Inhalt springen
ITtechNews – Cybersicherheit und Datenschutz
  • Datenschutzbeauftragter & Skillset
  • Externer ISB/CISO und NIS2/27001 Consulting
  • Blog IT-Security
  • Datenschutzerklärung
  • Impressum
Suche
ITtechNews – Cybersicherheit und Datenschutz
Menü schließen
  • Datenschutzbeauftragter & Skillset
  • Externer ISB/CISO und NIS2/27001 Consulting
  • Blog IT-Security
  • Datenschutzerklärung
  • Impressum
ITtechNews – Cybersicherheit und Datenschutz
Suche Menü umschalten

Monat: September 2021

14. September 202116. Dezember 2025Uncategorized

Apple iOS 14.8 Update dringend installieren

Kurz vor dem Release von iOS 15 hat Apple heute noch ein wichtiges Security-Update veröffentlicht.Es gibt wohl mehrere Zero-Day Exploits, deshalb schnellstmöglich die Geräte aktualisieren. Angriffsszenario: Sophos Link Apple Sicherheitshinweis

RSS-Feed: Golem Security News Golem Security News

  • (g+) Metabase Datenbank-Leck: Passwort-Reset - und die Zugangsdaten aller Datenbanken sind weg 1. September 2026
    Eine SQL-Lücke in Metabase liefert die Zugangsdaten aller angebundenen Datenbanken. Worauf es jetzt ankommt. (Security, Datenbank)
  • Unibleed: Wenn ein Wurm ganze Armeen humanoider Roboter kapern kann 1. September 2026
    Ein Forscher hat die Firmware eines Unitree-Roboters auf Schwachstellen untersucht. Schadcode hätte wohl von Roboter zu Roboter springen können. (Sicherheitslücke, WLAN)
  • AISI Deutschland: KI-Institut soll Gefahren von KI-Modellen bewerten 1. September 2026
    Die Bundesregierung sieht in KI-Systemen auch Gefahren für die nationale Sicherheit. BSI und Bundesnetzagentur sollen nun KI-Modelle bewerten. (KI, Politik)
  • Passwörter geleakt: Berliner Senatsverwaltungen schränken Homeoffice ein 1. September 2026
    Nach einem Cyberangriff auf die Berliner Landes-IT werden die VPN-Zugänge der Mitarbeiter gekappt. Der Grund: Passwörter sind an die Öffentlichkeit gelangt. (Cybercrime, Cyberwar)
  • Android-ROM: GrapheneOS-Macher lästern über Pixel 11 1. September 2026
    Google hat bei der Pixel-11-Serie eine für GrapheneOS elementare Funktion deaktiviert - die neuen Modelle werden nicht unterstützt. (GrapheneOS, Smartphone)
  • Anzeige: IT-Grundschutz-Praktiker: Workshop nach BSI-Methodik 31. August 2026
    Informationssicherheit nach BSI-Standard umzusetzen ist für viele Unternehmen anspruchsvoll. Ein Workshop vermittelt die Grundschutz-Methodik und bereitet auf die Zertifizierung vor. (Golem Karrierewelt, Server-Applikationen)
  • Chrome und Edge: Mehrere Browser-Add-ons per Update mit Malware verseucht 31. August 2026
    Forscher haben 19 mit Malware verseuchte Browsererweiterungen für Chrome und Edge entdeckt. Der Schadcode wurde erst nachträglich eingeschleust. (Malware, Virus)

RSS-Feed: CERT EU CERT EU

  • 2026-010: Critical Vulnerabilities in Citrix NetScaler ADC and NetScaler Gateway 19. August 2026
    On 19 August 2026, Citrix published a security advisory addressing multiple critical vulnerabilities in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway). CERT-EU recommends updating affected devices as soon as possible.
  • 2026-009: Critical Vulnerabilities in Microsoft SharePoint 23. Juli 2026
    [UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, […]
  • 2026-008: Critical vulnerabilities in Ivanti Sentry 10. Juni 2026
    On 9 June 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their Sentry products[1]. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device.
  • 2026-007: Critical Vulnerability in Windows Netlogon 10. Juni 2026
    On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (CCB), this vulnerability is currently exploited by threat actors. It is strongly recommended […]
  • 2026-006: Critical Vulnerability in PAN-OS 6. Mai 2026
    On 6 May 2026, Palo Alto published a security advisory addressing a critical vulnerability affecting PAN-OS. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges. Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended updating affected appliances as soon as patches will be available, and to apply workarounds […]
  • 2026-005: High Vulnerability in the Linux Kernel ("Copy Fail") 30. April 2026
    On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed. The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released. As of the date of this advisory, no distribution has shipped […]
  • 2026-004: Critical Vulnerability in SharePoint Exploited 25. März 2026
    On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited […]
  • 2026-003: Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC 23. März 2026
    On 23 March 2026, Citrix published a security advisory addressing multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway. These vulnerabilities may lead to sensitive information disclosure and user session mix-up under specific configurations. At the time of writing, there is no public evidence of active exploitation. It is strongly recommended updating affected gateways, prioritising internet-facing […]
  • 2026-002: Multiple Vulnerabilities in Cisco Products 26. Februar 2026
    On 25 February 2026, Cisco released security advisories addressing multiple high and critical severity vulnerabilities in Cisco Catalyst SD-WAN controllers and Cisco SD-WAN Manager. If exploited, these vulnerabilities could allow attackers to gain administrative access to compromised systems. It is recommended to capture forensic evidence, hunt for indicators of compromise, and apply updates as soon […]
  • 2026-001: Critical vulnerabilities in Ivanti EPMM 30. Januar 2026
    On 29 January 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their EPMM products. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device. One of these vulnerabilities have been exploited in a limited number of cases.
© 2026 ITtechNews - Cybersicherheit und Datenschutz.