WhatsApp-Benutzernamen: Vor- und Nachteile im Überblick (2026-08-13 04:57 UTC)
Kurz: Wie schützt ein WhatsApp-Benutzername vor Betrug – und welche Daten gibt man preis? Verbraucherschützer bewerten den Status quo beim Meta-Messenger.
Phishing-Wellen: Cyberangriffe auf IT-Dienstleister für Hotels (2026-08-13 04:30 UTC)
Kurz: Nach einem Sicherheitsvorfall bei einem österreichischen IT-Dienstleister sehen sich Hotels mit gezielten Phishing-Angriffen auf ihre Gäste konfrontiert.
Kurz: An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. […]
Android malware combo takes out loans and relays victims’ credit cards (2026-08-12 22:22 UTC)
Kurz: A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. […]
Kurz: Attempts to exploit a critical vulnerability (CVE-2026-71362) in Adobe’s Commerce and Magento e-commerce platforms have been detected, potentially allowing attackers to hijack customer accounts. […]
Attackers Exploit SharePoint Authentication Bypass After Public PoC Release (2026-08-13 06:09 UTC)
Kurz: Threat actors have begun to exploit a newly disclosed Microsoft SharePoint vulnerability following the release of a proof-of-concept (PoC) code. The vulnerability in question is CVE-2026-55040 (CVSS score: 9.1), which refers to a critical s…
Lazarus Exploits Windows Zero-Day to Gain SYSTEM Access and Deploy Backdoor (2026-08-12 17:39 UTC)
Kurz: The North Korean threat actor known as Lazarus Group has been attributed to the zero-day exploitation of a newly patched security flaw impacting Microsoft Windows to deliver a never-before-seen backdoor targeting defense and aerospace compa…
737 Chrome VPN Extensions Caught Routing Traffic Through Proxies. Check If You Have One (2026-08-12 14:09 UTC)
Kurz: A massive set of 737 free VPN and proxy extensions have been found to mainly target Russian-speaking users seeking access to blocked services with an aim to intercept browser traffic and route them through a proxy infrastructure. The extens…
Kurz: An Improper Authentication vulnerability [CWE-287] vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.6, FortiWeb 7.4.0 through 7.4.11, FortiWeb 7.2.0 through 7.2.12, FortiWeb 7.0.0 throug…
Kurz: A buffer copy without checking size of input (‘classic buffer overflow’) vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.3, FortiClientWindows 7.2.0 through 7.2.11 may allow an unauthenticated attacker in …
Kurz: A authentication bypass using an alternate path or channel vulnerability in Fortinet FortiManager 7.6.1, FortiManager 7.4.3 through 7.4.5, FortiManager 7.2.5 through 7.2.9, FortiManager Cloud 7.6.1, FortiManager Cloud 7.…
Kurz: A Stack-based Buffer Overflow vulnerability [CWE-121] vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6 may allow an unauthenticated attacker who can bypass stack protection and ASLR to execute arbitrary code or comm…
Kurz: A incomplete list of disallowed inputs vulnerability in Fortinet FortiWeb 8.0.0 through 8.0.2, FortiWeb 7.6.0 through 7.6.5, FortiWeb 7.4 all versions, FortiWeb 7.2 all versions, FortiWeb 7.0 all versions may allow attac…
Kurz: A allocation of resources without limits or throttling vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions may allow attacker to denial of service via <insert attack …
Kurz: MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian products (Confluence and Jira). Prior to 0.22.0, confluence_upload_attachment passes its client-supplied file_path directly to open(file_path, “rb”) in…