IT‑Sicherheits‑Digest (2026-03-12)

Aktuelle Security‑News

heise security

  • Staatstrojaner-Einsatz: BGH zieht rote Linie bei Messenger-Überwachung (2026-03-11 16:53 UTC)
    • Kurz: Der BGH zieht eine klare rote Linie bei der Überwachung von Messengern per Quellen-TKÜ: Das Mitlesen alter Nachrichten ohne strenge Auflagen ist rechtswidrig.
    • Quelle: Link
  • Fortinet: Hochriskante Lücken in FortiWeb, FortiManager und weiteren (2026-03-11 11:47 UTC)
    • Kurz: Fortinet schließt Lücken in FortiWeb oder FortiManager, die etwa Einschleusen von Befehlen erlauben. FortiGate-Firewalls wurden attackiert.
    • Quelle: Link
  • Passwort-Manager KeePassXC 2.7.12: Was Nutzer beim Update beachten müssen (2026-03-11 11:16 UTC)
    • Kurz: KeePassXC 2.7.12 schützt Windows-Nutzer vor DLL-Injection über OpenSSL, ändert Passkey-Flags und unterstützt TOTP-Platzhalter in Auto-Type.
    • Quelle: Link

BleepingComputer

  • WhatsApp introduces parent-managed accounts for pre-teens (2026-03-11 20:06 UTC)
    • Kurz: WhatsApp has begun rolling out parent-managed accounts for pre-teens, allowing parents and guardians to decide who can contact them and which groups they can join. […]
    • Quelle: Link
  • SQLi flaw in Elementor Ally plugin impacts 250k+ WordPress sites (2026-03-11 19:38 UTC)
    • Kurz: An SQL injection vulnerability in Ally, a WordPress plugin from Elementor for web accessibility and usability with more than 400,000 installations, could be exploited to steal sensitive data without authentication. […]
    • Quelle: Link
  • CISA orders feds to patch n8n RCE flaw exploited in attacks (2026-03-11 18:21 UTC)
    • Kurz: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered government agencies on Wednesday to patch their systems against an actively exploited n8n vulnerability. […]
    • Quelle: Link

The Hacker News

  • CISA Flags Actively Exploited n8n RCE Bug as 24,700 Instances Remain Exposed (2026-03-12 05:18 UTC)
    • Kurz: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added a critical security flaw impacting n8n to its Known Exploited Vulnerabilities (KEV) catalog, based on evidence of active exploitation. The vulnerability, tr…
    • Quelle: Link
  • Researchers Trick Perplexity’s Comet AI Browser Into Phishing Scam in Under Four Minutes (2026-03-11 16:38 UTC)
    • Kurz: Agentic web browsers that leverage artificial intelligence (AI) capabilities to autonomously execute actions across multiple websites on behalf of a user could be trained and tricked into falling prey to phishing and scam traps. The attack,…
    • Quelle: Link
  • Critical n8n Flaws Allow Remote Code Execution and Exposure of Stored Credentials (2026-03-11 14:51 UTC)
    • Kurz: Cybersecurity researchers have disclosed details of two now-patched security flaws in the n8n workflow automation platform, including two critical bugs that could result in arbitrary command execution. The vulnerabilities are listed below -…
    • Quelle: Link

Neue CVEs (letzte 24h, NVD‑Abgleich)

Fortinet FortiGate (7.4.x)

  • Keine neuen Treffer in den letzten 24h.

Atlassian (Jira/Confluence)

  • Keine neuen Treffer in den letzten 24h.

HPE/Aruba Switches

  • Keine neuen Treffer in den letzten 24h.

VMware ESXi/vCenter (7.x)

  • Keine neuen Treffer in den letzten 24h.

Hinweis

  • CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches).