Zum Inhalt springen

IT-Sicherheit · Aktuell

IT Security News

Aktuelle Meldungen zu IT-Sicherheit, Cyberbedrohungen und Datenschutz — automatisch kuratiert aus führenden Quellen.

Heise Security12. Sept. 2026

Sam Altman: Börsengang von OpenAI verschoben

Der ChatGPT-Entwickler OpenAI ist das wohl bekannteste KI-Unternehmen und plant einen großen Börsengang. Doch Firmenchef Sam Altman findet den Moment ungünstig.

Weiterlesen
The Hacker News12. Sept. 2026

CISA Adds 5 Actively Exploited Artifactory, ScreenConnect, and RouterOS Flaws to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added five security flaws impacting JFrog Artifactory, ConnectWise ScreenConnect, and MikroTik RouterOS to its Known Exploited Vulnerabilities (KEV) ca

Weiterlesen
Heise Security12. Sept. 2026

Chaos Communication Congress zieht um

Der Chaos Computer Club verlässt das CCH: Mehr Platz, stabile Ticketpreise und eine Rückkehr zu dezentraler Gestaltung sollen den 40C3 im Dezember prägen.

Weiterlesen
BleepingComputer12. Sept. 2026

Dutch NCSC: Critical Check Point VPN flaws exploitation is imminent

The Dutch Nationaal Cyber Security Centrum (NCSC) is warning of imminent exploitation of two critical flaws in Check Point VPN tracked as CVE-2026-85102 and CVE-2026-85103. [...]

Weiterlesen
The Hacker News12. Sept. 2026

When the Whole Company Adopts AI: What It Does to Your SOC

Over the past year, we watched a new class of alert appear in enterprise security operations centers and grow faster than anything else in the stream: alerts that were triggered by AI tools and agents. Not attacks agains

Weiterlesen
Golem Security12. Sept. 2026

Urteil zu Rabatt-Apps: Laut OLG gelten Daten rechtlich nicht als Preis

Nutzerdaten in Rabatt-Apps gelten rechtlich nicht als Preis. Das OLG Köln weist eine Klage des Verbraucherzentrale Bundesverbands ab. (<a href="https://www.golem.de/specials/verbraucherschutz/">Verbraucherschutz</a>, <a

Weiterlesen
The Hacker News12. Sept. 2026

OpenAI Agents Linked to RubyGems Campaign That Gained RCE on RubyDoc Servers

The "major malicious attack" that targeted RubyGems in May 2026 was the work of a swarm of OpenAI agents, according to a new report published by researchers Spencer Kitts, Thomas Larsen, and Sydney Von Arx. On May 12, Ma

Weiterlesen
Heise Security12. Sept. 2026

Salto rückwärts: Apple möchte KI-Modelle doch mit Nutzerdaten trainieren

Apples Versprechen war simpel: Persönliche Daten von iPhone-Nutzern fließen niemals in das Training von KI-Modellen ein. Damit ist es jetzt vorbei.

Weiterlesen
Golem Security12. Sept. 2026

(g+) Sidecar-Angriffsfläche: Die Dienste, die kein Portscan sieht

Ein Postgresql-Helfer riss Splunk auf. Solche Dienste laufen überall mit, ungezählt. Worauf Admins achten müssen. Ein Ratgebertext von Steffen Zahn (<a href="https://www.golem.de/specials/security/">Security</a>, <a href

Weiterlesen
Heise Security12. Sept. 2026

Interview: Zehntausende US-Dollar Schaden durch aufgeblähte Sicherheitswarnungen

Meldungen zu Sicherheitslücken sind für Open-Source-Projekte wichtig – viele davon seien inzwischen aber aufgeblähtes Marketing, meint Peter Gutmann.

Weiterlesen
BleepingComputer11. Sept. 2026

Hackers abused Claude to extract secrets from 1.8M Android apps

Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to abuse its Claude AI model for malicious purposes. [...]

Weiterlesen
BleepingComputer11. Sept. 2026

Florida confirms DMV database breached via stolen police account

The Florida Department of Highway Safety and Motor Vehicles (FLHSMV) has confirmed that its DAVID driver database suffered a data breach, saying the attackers gained access using credentials belonging to a police departm

Weiterlesen
BleepingComputer11. Sept. 2026

Passkey-themed phishing attacks lead to Microsoft 365 data theft

Microsoft says threat actors linked to ShinyHunters, Helix, and other extortion gangs are using passkey and single sign-on-themed social engineering attacks to compromise corporate Microsoft accounts and steal data from

Weiterlesen
The Hacker News11. Sept. 2026

GitLab CVSS 10 File-Read Flaw Draws In-the-Wild Probes After Disclosure

GitLab has released patches to address multiple flaws, including a maximum-severity security vulnerability that has witnessed in-the-wild probes within hours of public disclosure. The vulnerability in question is CVE-202

Weiterlesen
BleepingComputer11. Sept. 2026

Artifactory flaws chained in attacks deploying backdoor malware

Threat actors are exploiting critical and high-severity vulnerabilities in JFrog Artifactory to bypass authentication, gain administrative privileges, and deploy a Rust backdoor on vulnerable self-hosted servers. [...]

Weiterlesen
The Hacker News11. Sept. 2026

Anthropic Says Seven China-Based AI Labs Ran Industrial-Scale Claude Distillation Attacks

Anthropic on Thursday said it identified and disrupted industrial-scale illicit distillation attacks against Claude from seven labs based in China, including Alibaba, Moonshot, DeepSeek, Z.ai (aka Zhipu), and MiniMax. Kn

Weiterlesen
SANS ISC11. Sept. 2026

The Self-Expanding Stolen Inference Supply Chain: An AI Agent Harvesting and Re-Serving LLM Access, (Fri, Sep 11th)

I identified an attacker using a semi-autonomous coding agent to run an offensive operation: finding poorly secured LLM resale gateways, acquiring API access through ordinary web flaws and account farming, validating the

Weiterlesen
The Hacker News11. Sept. 2026

Claude Used to Automate Exploitation and Data Theft Across Multiple Victims

Anthropic has warned that cybercriminals and state-sponsored hackers alike are using its Claude models for cyber attacks, weapons design, propaganda, and mass surveillance between December 2025 and August 2026. The threa

Weiterlesen
The Hacker News11. Sept. 2026

Russian State-Sponsored Hackers Use Claude to Rebuild Malware After Detection

Anthropic on Thursday revealed it disrupted a campaign mounted by a Russian state-sponsored threat actor that abused Claude for developing an AI-assisted workflow to get ahead of the detection curve. The operation has be

Weiterlesen
BleepingComputer11. Sept. 2026

How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface

Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware. Huntress examines campaigns targeting AI users through weaponized Claude Artifacts

Weiterlesen
Heise Security11. Sept. 2026

Passwortmanager auf Android: Wechsel ohne manuellen Export

Google vereinfacht unter Android den Wechsel des Passwortmanagers. Passwörter und Passkeys lassen sich direkt übertragen.

Weiterlesen
Heise Security11. Sept. 2026

Patches: IT-Sicherheitsprodukte von Check Point werden zum Sicherheitsrisiko

Mehrere Produkte von Check Point wie Security Gateway und Spark Firewall sind verwundbar. Davon sind auch nicht mehr im Support befindliche Versionen betroffen.

Weiterlesen
The Hacker News11. Sept. 2026

Your Critical Vulnerabilities Might Not Be Your Biggest Risk

Security teams have become exceptionally talented at finding vulnerabilities. Now, it’s time to turn our attention to optimizing the process for determining which of those vulnerabilities actually create a path to compro

Weiterlesen
Heise Security11. Sept. 2026

Portasplit-Sicherheitslücke: Midea verteilt Updates an Klimageräte

Dass jeder die Portasplit von Midea per Bluetooth fernsteuern konnte, war nicht im Sinne der Entwickler – sie bessern nun nach.

Weiterlesen
BleepingComputer11. Sept. 2026

GitLab urges users to patch max severity path traversal flaw

GitLab urged users on Thursday to patch their servers immediately against a maximum-severity path traversal vulnerability tracked as CVE-2026-85706. [...]

Weiterlesen
Golem Security11. Sept. 2026

Exploit-Kit Bluemoon: Chinesische Hacker attackieren Windows-Nutzer

Ein neues Exploit-Kit nutzt gefährliche Sicherheitslücken in Windows und Google Chrome aus. Mehrere Cybergruppierungen machen davon Gebrauch. (<a href="https://www.golem.de/specials/cybercrime/">Cybercrime</a>, <a href="

Weiterlesen
Golem Security11. Sept. 2026

Siri Recap und Live Rewind: Lauschangriff durch die Apple Watch

Die neuen Apple Watches kommen mit automatischer KI-Transkription von Gesprächen in der Umgebung. Apple trifft Vorkehrungen, um die Belauschten schützen - aber reicht das? Ein IMHO von Tobias Költzsch (<a href="https://w

Weiterlesen
Heise Security11. Sept. 2026

Patchday SAP: Präparierte Netzwerkanfrage ebnet Weg für Abstürze

Mehrere kritische Sicherheitslücken gefährden unter anderem SAP Extended Passport und NetWeaver.

Weiterlesen
BleepingComputer11. Sept. 2026

Microsoft fixes Teams, Outlook launch failures on ARM Windows PCs

Microsoft has fixed a bug that prevented Teams and Outlook from launching on ARM-based Windows devices after installing updates released since the August 2026 Patch Tuesday. [...]

Weiterlesen
Heise Security11. Sept. 2026

Die CRA-Meldepflicht startet – was Hersteller jetzt wissen müssen

Die ersten Meldepflichten des Cyber Resilience Act (CRA) starten am Freitag. Eine Bitkom-Umfrage zeigt: Viele Unternehmen sind unvorbereitet.

Weiterlesen
Golem Security11. Sept. 2026

Enisa: Anthropic öffnet Mythos-Modell für EU-Cyberagentur

Nach monatelangen Verhandlungen gibt Anthropic der EU-Agentur Enisa Zugang zu seinem KI-Modell Mythos. Doch die neueste Version gibt es nicht. (<a href="https://www.golem.de/specials/anthropic/">Anthropic</a>, <a href="h

Weiterlesen
Heise Security11. Sept. 2026

Nach Cyberangriff in Berlin: Anlaufstelle für Betroffene

Cyberkriminelle haben große Mengen von Daten aus der Berliner Verwaltung veröffentlicht. Betroffene erhalten nun Informationen und Hilfe auf einer Serviceseite.

Weiterlesen
BleepingComputer11. Sept. 2026

Trezor: 347,000 users targeted in phishing attacks after Brevo breach

Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. [...]

Weiterlesen
The Hacker News11. Sept. 2026

Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors

Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz&nbsp;sai

Weiterlesen
The Hacker News11. Sept. 2026

China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor

A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims' computers, security company Gen Digital s

Weiterlesen
BleepingComputer11. Sept. 2026

Conti ransomware gang member sentenced to 4 years in prison

A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. [...]

Weiterlesen
The Hacker News11. Sept. 2026

PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws

PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The softw

Weiterlesen
The Hacker News11. Sept. 2026

Cisco FMC Flaws Exploited to Steal Credentials and Deploy Qilin Ransomware

Cisco has revealed that three distinct threat clusters linked to ransomware and state-sponsored attacks have been exploiting two recently patched Secure Firewall Management Center (FMC) vulnerabilities. The attacks lever

Weiterlesen
SANS ISC11. Sept. 2026

ISC Stormcast For Friday, September 11th, 2026 https://isc.sans.edu/podcastdetail/10090, (Fri, Sep 11th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Weiterlesen
BleepingComputer10. Sept. 2026

New Android malware encrypts files, steals data, and harasses victims

A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. [...]

Weiterlesen

Wird alle 30 Minuten aktualisiert · CH/DE: BACS Schweiz, BSI, Allianz Cyber-Sicherheit, Heise Security, Golem · EN: BleepingComputer, The Hacker News, Fortinet, SANS ISC, Microsoft Security, Krebs on Security, Kaspersky