Admins müssen D-Trust-Zertifikate tauschen – bis Ostermontag (2026-04-04 17:20 UTC)
Kurz: Die Bundesdruckerei-Tochter D-Trust beschert Administatoren kurzfristige Ostereinsätze: Ihre TLS-Zertifikate müssen bis Ostermontag 17 Uhr getauscht sein.
Desolate FCC-Vorgabe: „Freedom Router“ für US-Verbraucher (2026-04-03 05:30 UTC)
Kurz: Ab sofort lassen die USA für Verbraucher nur noch im Inland hergestellte Router zu. Die Vorgaben des FCC sind jedoch unrealistisch und sicherheitsmäßig heikel.
Axios npm hack used fake Teams error fix to hijack maintainer account (2026-04-04 20:30 UTC)
Kurz: The maintainers of the popular Axios HTTP client have published a detailed post-mortem describing how one of its developers was targeted by a social engineering campaign believed to have been conducted by North Korean threat actors. […]
Device code phishing attacks surge 37x as new kits spread online (2026-04-04 14:17 UTC)
Kurz: Device code phishing attacks that abuse the OAuth 2.0 Device Authorization Grant flow to hijack accounts have surged more than 37 times this year. […]
LinkedIn secretly scans for 6,000+ Chrome extensions, collects data (2026-04-03 20:40 UTC)
Kurz: A new report dubbed “BrowserGate” warns that Microsoft’s LinkedIn is using hidden JavaScript scripts on its website to scan visitors’ browsers for installed extensions and collect device data. […]
Kurz: Cybersecurity researchers have discovered 36 malicious packages in the npm registry that are disguised as Strapi CMS plugins but come with different payloads to facilitate Redis and PostgreSQL exploitation, deploy reverse shells, harvest cr…
Kurz: Fortinet has released out-of-band patches for a critical security flaw impacting FortiClient EMS that it said has been exploited in the wild. The vulnerability, tracked as CVE-2026-35616 (CVSS score: 9.1), has been described as a pre-authen…
China-Linked TA416 Targets European Governments with PlugX and OAuth-Based Phishing (2026-04-03 17:34 UTC)
Kurz: A China-aligned threat actor has set its sights on European government and diplomatic organizations since mid-2025, following a two-year period of minimal targeting in the region. The campaign has been attributed to TA416, a cluster of acti…