IT-Sicherheit · Aktuell

IT Security News

Aktuelle Meldungen zu IT-Sicherheit, Cyberbedrohungen und Datenschutz — automatisch kuratiert aus führenden Quellen.

Heise Security23. Juli 2026

Milliardenlast für Europas Netze: Der teure Abschied von Huawei und ZTE

Ein Verbot chinesischer Netzwerkausrüster würde europäische Mobilfunker laut Studie bis zu 40 Milliarden Euro kosten – viermal mehr als von Brüssel geschätzt.

Weiterlesen
BleepingComputer23. Juli 2026

FedRAMP Rev5 Is Ending: What the 20x Transition Really Requires

FedRAMP 20X replaces point-in-time assessments with continuous, machine-readable evidence that demonstrates security controls are working. Anecdotes explains what the transition from Rev5 to FedRAMP 20X means and how org

Weiterlesen
Golem Security23. Juli 2026

Bis April 2028: Anlasslose Chatkontrolle tritt wieder in Kraft

Die EU-Mitgliedsstaaten haben dem Beschluss zur Wiedereinführung der Chatkontrolle zugestimmt. (<a href="https://www.golem.de/specials/chatkontrolle/">Chatkontrolle</a>, <a href="https://www.golem.de/specials/instantmess

Weiterlesen
SANS ISC23. Juli 2026

When the "Autonomous Attacker" Is Your Own AI Model, (Thu, Jul 23rd)

Two disclosures, five days apart, described the same intrusion from opposite ends &#xe2;&#x80;&#x94; &#xd; one from the victim, one from the party that turned out to be responsible &#xe2;&#x80;&#x94; and &#xd; together t

Weiterlesen
Heise Security23. Juli 2026

Anonymisierendes Linux Tails 7.10: Neuer Shutdown und Videoplayer

Die Maintainer der anonymisierenden Linux-Distribution Tails setzen zum Shutdown auf Gnome-Standard. Neu ist der Videoplayer Celluloid.

Weiterlesen
BleepingComputer23. Juli 2026

EU fines Google $1 billion for search, app store antitrust violations

The European Commission fined Google €890 million ($1 billion) on Thursday after finding the company had violated the European Union's Digital Markets Act (DMA), which ensures fair online competition. [...]

Weiterlesen
The Hacker News23. Juli 2026

How Synthetic Identity Fraud is Coming for Machine Identities

Most people understand identity theft as an attacker stealing a real person's sensitive information and impersonating them. Synthetic identity fraud is much harder to catch. Instead of stealing a real identity, the attac

Weiterlesen
BleepingComputer23. Juli 2026

New RefluXFS Linux flaw lets attackers gain root privileges

A nine-year-old race condition vulnerability in the Linux kernel's XFS filesystem, tracked as CVE-2026-64600, allows local attackers to overwrite protected files and gain root privileges. [...]

Weiterlesen
The Hacker News23. Juli 2026

Attackers Weaponize GitHub Actions Runners to Target cPanel and WHM Servers

Cybersecurity researchers have shed light on a large-scale campaign that has turned compromised GitHub repositories into distributed attack infrastructure designed to target cPanel and WebHost Manager (WHM) instances. Th

Weiterlesen
Heise Security23. Juli 2026

Datenschutzvorfall bei uniVersa: Crawler von OpenAI griff Daten ab

Bei den uniVersa-Versicherungen gab es einen Datenschutzvorfall. Ein KI-Crawler hat Kundendaten abgegriffen, darunter Namen, Adressen und teilweise Bankdaten.

Weiterlesen
Heise Security23. Juli 2026

Rechteausweitungslücke in Ubuntu durch snap

Standardinstallationen von Ubuntu sind für eine Schwachstelle anfällig, die die Rechteausweitung zu root ermöglicht. Auslöser ist snap.

Weiterlesen
Heise Security23. Juli 2026

Neuer ClickFix-Angriff auf Mac-Nutzer im Umlauf: Erpressung trifft auf Datenklau

ClickLock Stealer soll bisher über 100 Personen per Shellscript angegriffen haben. Er geht dabei recht fies vor, um ans Passwort zu kommen und Daten abzuziehen.

Weiterlesen
BleepingComputer23. Juli 2026

New msaRAT malware uses Chrome, Edge browsers to route C2 traffic

The Chaos ransomware gang is using a new backdoor dubbed msaRAT that hides command-and-control (C2) communication by routing it through the Chrome or Edge browsers. [...]

Weiterlesen
The Hacker News23. Juli 2026

Google Adds Selfie Video Recovery for Users Locked Out of Their Accounts

Google on Thursday announced a new way for users to sign-in to their accounts by letting them take a selfie video. The selfie for sign-in, per the tech giant, is another option on top of existing recovery methods to log

Weiterlesen
Heise Security23. Juli 2026

Atlassian: Bamboo und Bitbucket für Schadcode-Attacken anfällig

Wichtige Sicherheitsupdates schließen mehrere Schwachstellen in verschiedenen Anwendungen von Atlassian.

Weiterlesen
Golem Security23. Juli 2026

Über Add-on von Adobe: Forscher zeigen Whatsapp-Datenklau mit nur einem Klick

Über 300 Millionen Nutzer vertrauen einer Chrome-Erweiterung von Adobe. Angreifer konnten darüber jedoch leicht Whatsapp-Chats ausleiten. (<a href="https://www.golem.de/specials/sicherheitsluecke/">Sicherheitslücke</a>,

Weiterlesen
BleepingComputer23. Juli 2026

Microsoft working to fix Exchange Online mailbox quarantine issue

Microsoft is working to resolve an ongoing Exchange Online issue that has been mistakenly quarantining customers' mailboxes since Sunday. [...]

Weiterlesen
BleepingComputer23. Juli 2026

Check Point warns of SmartConsole zero-day exploited in attacks

Israeli cybersecurity firm Check Point Software has addressed an actively exploited zero-day flaw in the company's SmartConsole graphical user interface (GUI) admin panel. [...]

Weiterlesen
The Hacker News23. Juli 2026

Nine-Year-Old RefluXFS Linux Flaw Gives Local Users Root on Default RHEL Installs

RefluXFS, a new Linux kernel flaw disclosed on July 22 and tracked as CVE-2026-64600, lets an unprivileged local user overwrite root-owned files on an XFS filesystem and gain persistent root access. Qualys said default i

Weiterlesen
Heise Security23. Juli 2026

Microsoft SharePoint: Angriffe auf weitere Sicherheitslücke

Weitere Sicherheitslücken in SharePoint stehen unter Beschuss. Auch Check Point SmartConsole wird derzeit attackiert.

Weiterlesen
Golem Security23. Juli 2026

Nach Cyberangriff: Hacker erpressen Zugbauer Stadler um Millionenbetrag

Hacker fordern von dem Zughersteller Stadler nach einem IT-Einbruch 10 Millionen Schweizer Franken. Doch Stadler hält sich für "nicht erpressbar". (<a href="https://www.golem.de/specials/cybercrime/">Cybercrime</a>, <a h

Weiterlesen
The Hacker News23. Juli 2026

Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Access

Check Point has released security updates to address multiple vulnerabilities impacting Security Management and Multi-Domain Management (MDSM) products, including a critical flaw that has come under active exploitation i

Weiterlesen
Golem Security23. Juli 2026

Sicherheit: Politik, Industrie und Behörden reagieren auf autonomen OpenAI-Hack

Nach dem Sicherheitsvorfall bei OpenAI mehren sich Stellungnahmen aus Politik, Wirtschaft und Aufsichtsbehörden mit Warnungen und Sorgen. (<a href="https://www.golem.de/specials/ki/">KI</a>, <a href="https://www.golem.de

Weiterlesen
Heise Security23. Juli 2026

Cyberattacken auf Landesverwaltung nehmen weiter zu

Cyberangriffe nehmen in Sachsen-Anhalt deutlich zu: Im ersten Halbjahr meldet die Landesverwaltung mehr als doppelt so viele Vorfälle wie zuvor.

Weiterlesen
Heise Security23. Juli 2026

Online-Trading-Betrug: Opfer investieren über eine Million

24 Menschen aus ganz Deutschland sollen Geld in vermeintliche Online-Trading-Plattformen investiert haben. Doch Gewinne wurden nie ausgezahlt.

Weiterlesen
SANS ISC23. Juli 2026

ISC Stormcast For Thursday, July 23rd, 2026 https://isc.sans.edu/podcastdetail/10020, (Thu, Jul 23rd)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Weiterlesen
BleepingComputer22. Juli 2026

Upbound says hack caused $13 million in fraudulent Acima leases

The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. [...]

Weiterlesen
BleepingComputer22. Juli 2026

South Korea discloses data breach impacting diplomats worldwide

South Korea disclosed that hackers breached the National Diplomatic Academy's online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Aff

Weiterlesen
The Hacker News22. Juli 2026

GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier

Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier

Weiterlesen
The Hacker News22. Juli 2026

Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs

Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target e

Weiterlesen
SANS ISC22. Juli 2026

Rondo Meets Geoserver, (Wed, Jul 22nd)

This isn&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;t a new attack, but something I saw "pop-up" in our logs this week: &#xd;

Weiterlesen
BleepingComputer22. Juli 2026

Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack

Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. [...]

Weiterlesen
Microsoft Security22. Juli 2026

Real world incident response: Microsoft and AXA XL strengthen cyber resilience

Our collaboration with AXA XL brings Microsoft Incident Response services directly to cyber insurance policyholders, helping organizations coordinate technical, business, and insurance decisions. The post Real world inci

Weiterlesen
BleepingComputer22. Juli 2026

How enterprise GenAI can amplify ransomware risk — and how to contain it

Enterprise AI can accelerate ransomware attacks when AI assistants and agents inherit excessive permissions or compromised identities. Acronis explains how identity controls, governance, and least-privilege access help r

Weiterlesen
The Hacker News22. Juli 2026

Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data

Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user

Weiterlesen
BleepingComputer22. Juli 2026

New InfraTrust report reveals infrastructure flaws admins should patch first

Eclypsium has launched InfraTrust, a new infrastructure cybersecurity knowledge base and monthly InfraTrust Pulse report designed to help organizations prioritize vulnerabilities affecting infrastructure, firmware, netwo

Weiterlesen
BleepingComputer22. Juli 2026

Adobe Chrome extension flaw let sites access private WhatsApp chats

The Adobe Acrobat extension for Chrome could be used to access conversations and data rendered in WhatsApp Web without any form of authentication. [...]

Weiterlesen
Fortinet FortiGuard22. Juli 2026

Inside a TrickBot Variant Using DNS Tunneling for C2

FortiGuard Labs analyzes a TrickBot variant that uses DNS tunneling for C2 communication, modular execution, and employs persistence and obfuscation techniques &#160; &#160; &#160; &#160; &nbsp;&#160;

Weiterlesen
Heise Security22. Juli 2026

Container-Images ohne CVEs: BellSofts neuer Buildpacks-Builder

BellSofts gehärteter Builder für Paketo Buildpacks baut Container-Images auf einer weitgehend CVE-freien Alpaquita-Basis – ganz ohne Dockerfile.

Weiterlesen
The Hacker News22. Juli 2026

Hackers Exploit Windmill Flaw to Read Arbitrary Server Files Without Authentication

A high-severity security flaw impacting open-source developer platform Windmill has come under active exploitation in the wild, per VulnCheck. The vulnerability in question is CVE-2026-29059 (CVSS score: 7.5), a case of

Weiterlesen

Wird alle 30 Minuten aktualisiert · CH/DE: BACS Schweiz, BSI, Allianz Cyber-Sicherheit, Heise Security, Golem · EN: BleepingComputer, The Hacker News, Fortinet, SANS ISC, Microsoft Security, Krebs on Security, Kaspersky