Zum Inhalt springen
ITtechNews – Cybersicherheit und Datenschutz
  • Datenschutzbeauftragter & Skillset
  • Externer ISB/CISO und NIS2/27001 Consulting
  • Blog IT-Security
  • Datenschutzerklärung
  • Impressum
Suche
ITtechNews – Cybersicherheit und Datenschutz
Menü schließen
  • Datenschutzbeauftragter & Skillset
  • Externer ISB/CISO und NIS2/27001 Consulting
  • Blog IT-Security
  • Datenschutzerklärung
  • Impressum
ITtechNews – Cybersicherheit und Datenschutz
Suche Menü umschalten

Neueste Beiträge

  • Crowdstrike Ausfall
  • Apple iOS 17.5 released
  • Apple iOS 14.8 Update dringend installieren
  • Microsoft Exchange Zero Day Schwachstelle
  • Angriffe und Informationen im Zusammenhang mit der Solarwinds Sicherheitslücke

Neueste Kommentare

    Seiten

    • Datenschutzbeauftragter & Skillset
    • Datenschutzerklärung
    • Externer ISB/CISO und NIS2/27001 Consulting
    • Impressum
    • IT-Sicherheit & News-Blog
    • Startseite

    Archiv

    • Juli 2024
    • Mai 2024
    • September 2021
    • März 2021
    • Januar 2021
    • September 2020
    • Februar 2020
    • Januar 2020
    • August 2019
    • Mai 2019
    • März 2019
    • Februar 2019
    • Dezember 2018
    • Oktober 2018
    • August 2018
    • Juli 2018
    • Mai 2018
    • März 2018
    • Februar 2018
    • Januar 2018
    • Dezember 2017
    • Oktober 2017
    • September 2017
    • August 2017

    Kategorien

    • allgemein (5)
    • Cloud (3)
    • Datenschutz (5)
    • Hardware (7)
    • IT-Sicherheit (29)
    • Software (18)
    • Uncategorized (6)

    RSS Golem Security News

    • Github reagiert auf KI-Flut: Hohe Bug-Bounty-Prämien bald nur noch für VIPs 24. Juli 2026
      Github überarbeitet sein Bug-Bounty-Programm. Wer sich nur auf KI verlässt und sich wenig Mühe gibt, bekommt künftig geringere Prämien. (Github, KI)
    • Belästigung: Instagram sperrt Prankster und Anmacher mit Smart Glasses 24. Juli 2026
      Streichvideos und Anmachfilmchen, die heimlich mit Smart Glasses gefilmt werden - sowas will Instagram künftig nicht mehr sehen. (Smartglass, Datenschutz)
    • RefluXFS: Kernel-Bug verleiht auf Millionen von Linux-Systemen Root-Zugriff 24. Juli 2026
      Eine Sicherheitslücke im Linux-Kernel lässt Angreifer beliebige Dateien auf XFS-Volumes überschreiben. Root-Rechte sind damit leicht zu beschaffen. (Sicherheitslücke, Fedora)
    • Datenpanne: OpenAI-Crawler greift Kundendaten von Universa ab 24. Juli 2026
      Durch eine Fehlkonfiguration sind Kundendaten der Universa-Versicherungen zeitweise offen im Netz gestanden. Ein Crawler von OpenAI hat die Gelegenheit genutzt. (Datenleck, KI)
    • Messenger-Interoperabilität: Threema lehnt Vernetzung mit Whatsapp ab 24. Juli 2026
      Trotz EU-Vorgaben verzichtet Threema auf eine Anbindung an Whatsapp und verweist auf Datenschutz- sowie Finanzierungsrisiken. (Threema, Instant Messenger)
    • Anzeige: Penetration Testing: Schwachstellen in Webanwendungen erkennen 24. Juli 2026
      Penetration Testing deckt Schwachstellen in Webanwendungen und Netzwerken auf. Ein Online-Workshop vermittelt Methodik und Tools, um Findings nachvollziehbar zu prüfen. (Golem Karrierewelt, Server-Applikationen)
    • Bis April 2028: Anlasslose Chatkontrolle tritt wieder in Kraft 23. Juli 2026
      Die EU-Mitgliedsstaaten haben dem Beschluss zur Wiedereinführung der Chatkontrolle zugestimmt. (Chatkontrolle, Instant Messenger)

    RSS CERT EU

    • 2026-009: Critical Vulnerabilities in Microsoft SharePoint 23. Juli 2026
      [UPDATED] On 14 July 2026, Microsoft released security updates addressing critical remote code execution (RCE) vulnerabilities in Microsoft SharePoint Server. On 20 July 2026, WatchTowr identified a proof-of-concept exploit code and subsequently observed active exploitation of CVE-2026-50522, a vulnerability part of an ongoing series of actively exploited flaws affecting on-premise SharePoint Server instances, including CVE-2026-32201, […]
    • 2026-008: Critical vulnerabilities in Ivanti Sentry 10. Juni 2026
      On 9 June 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their Sentry products[1]. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device.
    • 2026-007: Critical Vulnerability in Windows Netlogon 10. Juni 2026
      On 12 May 2026, Microsoft published a security advisory addressing a critical vulnerability affecting Windows Server when acting as a domain controller. This vulnerability allows an unauthenticated attacker to execute arbitrary code over a network. According to The Centre for Cybersecurity Belgium (CCB), this vulnerability is currently exploited by threat actors. It is strongly recommended […]
    • 2026-006: Critical Vulnerability in PAN-OS 6. Mai 2026
      On 6 May 2026, Palo Alto published a security advisory addressing a critical vulnerability affecting PAN-OS. This vulnerability allows an unauthenticated attacker to execute arbitrary code with root privileges. Palo Alto observed limited exploitation of this vulnerability. It is strongly recommended updating affected appliances as soon as patches will be available, and to apply workarounds […]
    • 2026-005: High Vulnerability in the Linux Kernel ("Copy Fail") 30. April 2026
      On 29 April 2026, a high local privilege escalation vulnerability in the Linux kernel, tracked as CVE-2026-31431 and named "Copy Fail", was publicly disclosed. The vulnerability affects every mainstream Linux distributions shipping a kernel built since 2017. A public proof-of-concept exploit has been released. As of the date of this advisory, no distribution has shipped […]
    • 2026-004: Critical Vulnerability in SharePoint Exploited 25. März 2026
      On 17 March 2026, Microsoft updated one of its January 2026 security advisories related to a remote code execution vulnerability in Microsoft SharePoint. Specifically, Microsoft raised the CVSS score and changed the FAQ section to indicate that the vulnerability could be exploited by an unauthenticated attacker. This vulnerability was added in the CISA's Known Exploited […]
    • 2026-003: Multiple Vulnerabilities in Citrix NetScaler and Citrix ADC 23. März 2026
      On 23 March 2026, Citrix published a security advisory addressing multiple vulnerabilities affecting NetScaler ADC and NetScaler Gateway. These vulnerabilities may lead to sensitive information disclosure and user session mix-up under specific configurations. At the time of writing, there is no public evidence of active exploitation. It is strongly recommended updating affected gateways, prioritising internet-facing […]
    • 2026-002: Multiple Vulnerabilities in Cisco Products 26. Februar 2026
      On 25 February 2026, Cisco released security advisories addressing multiple high and critical severity vulnerabilities in Cisco Catalyst SD-WAN controllers and Cisco SD-WAN Manager. If exploited, these vulnerabilities could allow attackers to gain administrative access to compromised systems. It is recommended to capture forensic evidence, hunt for indicators of compromise, and apply updates as soon […]
    • 2026-001: Critical vulnerabilities in Ivanti EPMM 30. Januar 2026
      On 29 January 2026, Ivanti released a security advisory addressing two critical vulnerabilities in their EPMM products. An attacker could exploit those flaws to achieve unauthenticated remote code execution on the vulnerable device. One of these vulnerabilities have been exploited in a limited number of cases.
    • 2025-042: Critical Vulnerability in Cisco Secure Email and Web Manager 18. Dezember 2025
      On December 17, 2025, Cisco released a security advisory for a critical vulnerability affecting Cisco Secure Email Gateway and Cisco Secure Email and Web Manager products. It is recommended to follow Cisco's recommendations to check whether vulnerable appliances have been compromised, and to remediate the issue. There is no patch available for this vulnerability yet.
    © 2026 ITtechNews - Cybersicherheit und Datenschutz.