Zum Inhalt springen

IT-Sicherheit · Aktuell

IT Security News

Aktuelle Meldungen zu IT-Sicherheit, Cyberbedrohungen und Datenschutz — automatisch kuratiert aus führenden Quellen.

BleepingComputer24. Sept. 2026

FedRAMP VDR & VER: Daily Scans Are Only the Beginning

FedRAMP's new VDR and VER requirements make vulnerability management more continuous, with faster scanning, tighter remediation deadlines, and stronger evidence requirements. Anecdotes explains why the December 7 deadlin

Weiterlesen
Heise Security24. Sept. 2026

DSGVO-Falle Smart Glasses: Datenschützer warnen Träger vor Rechtsverstößen

Die Datenschutzkonferenz (DSK) stellt klar: Beim Filmen Dritter haften Nutzer. Eine LED reicht als Information nicht aus. Die DSK sieht die Politik gefordert.

Weiterlesen
BleepingComputer24. Sept. 2026

Hackers now exploit critical Roundcube flaw in code injection attacks

A high-severity Roundcube Webmail vulnerability patched in May is now being actively exploited in attacks, according to the Canadian Centre for Cyber Security. [...]

Weiterlesen
Heise Security24. Sept. 2026

Angriff mit KI-Agenten auf hunderte Shops: 600.000 Kreditkartendaten geklaut

Ein Angreifer hat hunderte Online-Shops mit KI-Agenten angegriffen und dabei Daten von mehr als 600.000 Kreditkarten abgegriffen.

Weiterlesen
Fortinet FortiGuard24. Sept. 2026

Uncovering a SectopRAT Variant Embedded in Legitimate Software

Analysis of a SectopRAT variant hidden in tampered legitimate software that steals credentials and enables remote system control           

Weiterlesen
Golem Security24. Sept. 2026

Erpresser verlangen 3 Millionen Euro: Revolut will nach Cyberangriff kein Lösegeld zahlen

Eine umfangreiche Recherche mehrerer großer Medienhäuser macht Revolut zudem schwere Vorwürfe: Die Bank unternehme zu wenig gegen Geldwäsche. (<a href="https://www.golem.de/specials/revolut/">Revolut</a>, <a href="https:

Weiterlesen
BleepingComputer24. Sept. 2026

Windows 11 KB5124010 update released with 46 changes and fixes

Microsoft released the KB5124010 September 2026 non-security preview update for Windows 11 24H2 and 25H2, with 46 changes including Bluetooth improvements and the ability to remap the Copilot key. [...]

Weiterlesen
The Hacker News24. Sept. 2026

Corp MDM Spyware Targets Logistics Firms, Steals New SMS and Redirects Calls

The logistics sector has become the target of a new malicious cyber campaign that distributes an Android spyware codenamed Corp MDM. According to Have I Been Squatted, the campaign uses fake Google Play pages branded as

Weiterlesen
Golem Security24. Sept. 2026

(g+) SAP-Patchtag: 19, 21, 22 oder 33 Sicherheitslücken?

SAP-Patchtage liefern widersprüchliche Listen. Für Admins entscheiden ohnehin andere Kriterien, was zuerst gepatcht wird. Ein Ratgebertext von Steffen Zahn (<a href="https://www.golem.de/specials/sap/">SAP</a>, <a href="

Weiterlesen
The Hacker News24. Sept. 2026

Secrets Sprawl Is an Identity Problem That AI Just Made Impossible to Ignore

AI coding agents are changing how quickly developers can build and ship software as well as how quickly credentials can become exposed. According to GitGuardian’s 2026 State of Secrets Sprawl Report, commits identified a

Weiterlesen
Golem Security24. Sept. 2026

Meta-Ray-Ban-Display: Smarte Brille zeigt bei Anrufen Hologramm des Sprechers

Wer mit Trägern einer Meta-Ray-Ban-Display telefoniert, kann sich dabei ein Hologramm des Sprechenden anzeigen lassen. (<a href="https://www.golem.de/specials/meta/">Meta</a>, <a href="https://www.golem.de/specials/daten

Weiterlesen
BleepingComputer24. Sept. 2026

CISA: Ransomware gangs now exploiting critical TeamCity flaw

​The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned federal agencies on Wednesday that ransomware gangs are now also exploiting a critical JetBrains TeamCity vulnerability patched in July. [...]

Weiterlesen
Kaspersky SecureList24. Sept. 2026

MacSync under the microscope: new delivery methods and a new payload

We look at a new version of the MacSync macOS stealer with a backdoor module that targets crypto enthusiasts and developers.

Weiterlesen
BleepingComputer24. Sept. 2026

OpenAI hacked Australian Medicare govt site, probed data providers

OpenAI agents targeted public data providers in multiple countries, probing some for vulnerabilities and exploiting a security weakness in an Australian government portal while performing information-retrieval tasks as p

Weiterlesen
Heise Security24. Sept. 2026

Speicherort von Microsoft-365-Daten für kurze Zeit wählbar

IT-Verantwortliche haben bis zum 14. Dezember Zeit, den Speicherort ihrer Microsoft-365-Daten auszuwählen: im eigenen Land oder EU.

Weiterlesen
The Hacker News24. Sept. 2026

17,000 URLs Reveal How ClickFix Turns Trusted Websites Into Malware Traps: Report by CTM360

ClickFix has become the most common way attackers get into enterprise networks, and it does it without an exploit, an attachment, or a file on disk. Our new global threat report traces the technique from a novelty in lat

Weiterlesen
Heise Security24. Sept. 2026

Sicherheitspatch gegen Schadcode repariert SolarWinds Observability Self-Hosted

Die Monitoring-Lösung für IT-Infrastrukturen SolarWinds Observability Self-Hosted ist unter bestimmten Voraussetzungen verwundbar.

Weiterlesen
BleepingComputer24. Sept. 2026

Microsoft fixes bug that broke Windows File History backup feature

Microsoft has fixed a known issue that breaks the built-in File History backup feature on some Windows systems after installing the September 2026 security updates. [...]

Weiterlesen
The Hacker News24. Sept. 2026

OpenAI Agent Bypassed Australian Medicare Portal Controls to Access Non-Public Files

An AI agent on an internal OpenAI research task bypassed access controls on an Australian government Medicare statistics portal in June, Prime Minister&nbsp;Anthony Albanese said. The portal publishes aggregate figures,

Weiterlesen
Heise Security24. Sept. 2026

Cybergang ShinyHunters behauptet Einbruch in FBI-Jobportal

ShinyHunters behaupteten, in das Jobportal des FBI eingebrochen zu sein und dort Daten von Mitarbeitern erbeutet zu haben.

Weiterlesen
The Hacker News24. Sept. 2026

TeamFiltration Campaign Compromises Seven Microsoft 365 Accounts Using Default Passwords

Cybersecurity researchers have disclosed details of an active TeamFiltration campaign codenamed UNK_CondorFiltration that has targeted over 5,700 accounts across 28 Microsoft 365 tenants. According to Proofpoint, the act

Weiterlesen
SANS ISC24. Sept. 2026

One URL, Three Different Tricks, (Thu, Sep 24th)

Yesterday, we received a phishing email with an interesting link. At first sight, it looks like garbage, but every piece of it has been carefully crafted to confuse basic security controls. Here is the defanged link: &#x

Weiterlesen
The Hacker News24. Sept. 2026

Attackers Exploit WordPress CVE-2026-87902 Within Hours of Disclosure

Threat actors have begun to actively exploit a critical security flaw in WordPress within hours of public disclosure. The vulnerability in question is CVE-2026-87902 (CVSS score: 9.2), which could allow an unauthenticate

Weiterlesen
Heise Security24. Sept. 2026

OpenAI-Agent knackt australisches Regierungsportal

Eine KI sollte Gesundheitsstatistiken suchen – und knackte dabei ein australisches Regierungsportal. Die Empörung ist groß.

Weiterlesen
SANS ISC24. Sept. 2026

ISC Stormcast For Thursday, September 24th, 2026 https://isc.sans.edu/podcastdetail/10108, (Thu, Sep 24th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Weiterlesen
BleepingComputer23. Sept. 2026

Placeholder domain used in dev docs now serves ClickFix attacks

The "third-party.com" domain, commonly used as a placeholder in developer documentation and code examples, is serving a fake Cloudflare verification page that attempts to trick Windows users into executing PowerShell com

Weiterlesen
BleepingComputer23. Sept. 2026

New RemControl Android banking malware targets users in Europe and Canada

A new Android malware-as-a-service (MaaS) platform called RemControl is targeting users through malvertising campaigns that impersonate the TVTap IPTV application. [...]

Weiterlesen
BleepingComputer23. Sept. 2026

Check Point warns of hackers exploiting Security Gateway VPN RCE flaw

Cybersecurity company Check Point has confirmed active exploitation of CVE-2026-85102, a pre-authentication remote code execution (RCE) vulnerability in the VPN certificate-handling functionality of its Security Gateway

Weiterlesen
BleepingComputer23. Sept. 2026

Hackers start exploiting critical WordPress flaw for code execution

Threat actors have moved from probing WordPress sites vulnerable to CVE-2026-87902 to exploiting the flaw to write files to disk that execute shell commands when accessed. [...]

Weiterlesen
The Hacker News23. Sept. 2026

Attackers Use Malicious Terraform Providers to Deliver Go Malware via HashiCorp Registry

Cybersecurity researchers have disclosed Go-based malware distributed via two Go Modules and two Terraform providers, marking the first time threat actors are using the centralized repository hosted by HashiCorp as a dis

Weiterlesen
The Hacker News23. Sept. 2026

A Leaked GitLab Issue Email Address Lets Anyone Push Code and Run CI Jobs as You

The private email address GitLab gives you for filing issues by email is a credential. Anyone who gets it can email a patch that GitLab commits in your name, to any branch you can push to, including main, and can start C

Weiterlesen
Golem Security23. Sept. 2026

Anzeige: IT-Grundschutz systematisch umsetzen

IT-Grundschutz verlangt ein systematisches Vorgehen bei Risiken, Maßnahmen und Audits. Das Training der Golem Karrierewelt vermittelt die BSI-Methodik praxisorientiert. (<a href="https://www.golem.de/specials/golemakadem

Weiterlesen
BleepingComputer23. Sept. 2026

Malicious AI agents steal 600K credit cards, infect 100+ sites with skimmers

A financially motivated threat actor is using open-source AI agent frameworks to attack hundreds of online retailers at scale, stealing more than 600,000 credit card records. [...]

Weiterlesen
SANS ISC23. Sept. 2026

Macfinger ClickFix campaign, (Tue, Sep 22nd)

Introduction &#xd;

Weiterlesen
The Hacker News23. Sept. 2026

MikroTrick Chain Let Attackers Take Over MikroTik Routers Without a Password or SSH Key

Two MikroTik RouterOS SSH vulnerabilities chained together let attackers take full administrative control of Internet-exposed routers without a password, SSH key, or completed authentication. The chain, which CERT Polska

Weiterlesen
Microsoft Security23. Sept. 2026

Reimagining the SOC for the agentic era in Microsoft Defender

We are announcing ISOC in Microsoft Defender: a foundation built for agentic security that brings leading solutions for SIEM and threat protection together. The post Reimagining the SOC for the agentic era in Microsoft D

Weiterlesen
BleepingComputer23. Sept. 2026

InfraTrust report warns network management systems under attack

Attackers are increasingly targeting the management systems used to control enterprise infrastructure, with several critical vulnerabilities actively exploited before or shortly after vendors disclosed them. [...]

Weiterlesen
The Hacker News23. Sept. 2026

This Windows Malware is Built to Let Up to Four AI Models Vote on Its Next Move

A Windows malware called CLOSEDQUORUM is built to take orders from a vote of up to four AI models instead of an attacker's server,&nbsp;Cisco Talos said&nbsp;on September 22. The models can choose to steal Windows creden

Weiterlesen
BleepingComputer23. Sept. 2026

How One Kubernetes YAML Can Hand Over a GCP Organization

A Kubernetes user with limited permissions can potentially gain control of an entire Google Cloud organization by exploiting the authority granted to Google Kubernetes Config Connector. Varonis explains how this confused

Weiterlesen
The Hacker News23. Sept. 2026

Compromised MemTensor Packages Deliver sckit Credential Stealer via npm and PyPI

Unknown threat actors have managed to compromise two legitimate MemTensor packages across the npm and Python Package Index (PyPI) repositories to push a platform-specific Go-based implant dubbed sckit designed for Window

Weiterlesen

Wird alle 30 Minuten aktualisiert · CH/DE: BACS Schweiz, BSI, Allianz Cyber-Sicherheit, Heise Security, Golem · EN: BleepingComputer, The Hacker News, Fortinet, SANS ISC, Microsoft Security, Krebs on Security, Kaspersky