Wenn die IT ausfällt: Krisensimulation für Krankenhäuser (2026-08-04 04:11 UTC)
Kurz: Wie Krankenhäuser bei IT-Ausfällen reagieren, testet Nico Brüggemann vom Fraunhofer SIT. Er erklärt, warum Abläufe oft nur auf dem Papier funktionieren.
Hotel Wi-Fi attacks use custom malware to breach Microsoft 365 accounts (2026-08-04 00:17 UTC)
Kurz: Microsoft has linked a global campaign targeting hospitality Wi-Fi networks to the Russian threat actor Midnight Blizzard, also known as APT29. […]
New Pass-ta-key attacks let malware hijack Google-synced passkeys (2026-08-03 23:58 UTC)
Kurz: Security researchers have discovered three attacks that allow malware on already-compromised Windows devices to abuse Google Password Manager’s synced passkeys to take over accounts, bypass user verification, and extract passkey private key…
New DOUBLECUP ClickFix service hides malware in browser cache images (2026-08-03 20:01 UTC)
Kurz: A new Russian loader-as-a-service named DOUBLECUP uses ClickFix attacks to hide malicious code in PNG images cached by victims’ browsers, ultimately delivering CountLoader to Windows and macOS devices and a new remote access trojan named De…
CISA Adds Exploited N-able N-central Flaw to KEV After Customer Compromises (2026-08-04 07:00 UTC)
Kurz: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog following reports of active exploitation in the w…
18 Malicious npm Packages Deliver Cross-Platform RAT to Alibaba Tool Users (2026-08-03 18:43 UTC)
Kurz: Cybersecurity researchers have discovered a new set of malicious npm packages that target users of Alibaba developer tools with a cross-platform remote access trojan (RAT) as part of a sophisticated, targeted software supply chain attack ta…
Google Password Manager Attacks Could Let Malware Hijack Passkey-Protected Accounts (2026-08-03 16:24 UTC)
Kurz: Malware running as an ordinary user on a Windows machine can sign into a victim’s passkey-protected accounts without a fingerprint, a PIN, or anything at all appearing on the victim’s screen. Unit 42 detailed three attack paths against Chro…