„wp2shell“: Kritische WordPress-Lücke erlaubt Codeeinschleusung über API (2026-07-18 05:19 UTC)
Kurz: Durch Verkettung einer SQL-Injection- und einer API-Lücke können Angreifer Code einschleusen. WordPress hat ein Update veröffentlicht, die Finder einen Hotfix.
Kurz: Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that atta…
HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload (2026-07-17 17:56 UTC)
Kurz: A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. […]
Ernst & Young discloses data breach after support system hack (2026-07-17 14:55 UTC)
Kurz: Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. […]
New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code (2026-07-17 21:20 UTC)
Kurz: Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP…
OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests (2026-07-17 20:20 UTC)
Kurz: Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in Ju…
Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT (2026-07-17 18:54 UTC)
Kurz: Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, m…