AliExpress trackt Nutzer via unhörbarem Audio-Fingerprinting (2026-08-24 15:35 UTC)
Kurz: AliExpress nutzte die Web Audio API, um Geräte per unhörbarem Audiosignal zu identifizieren. Ein Entwickler entdeckte das Tracking durch Bluetooth-Probleme.
Kurz: An unpatched vulnerability in Calix GS7 XGS (GS5239XG) residential routers used by multiple U.S. broadband providers allows remote, unauthenticated attackers to create port-forwarding rules that can expose local network devices to the publi…
Kurz: Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress that can be used to forge SAML responses and log in as administrators. […]
TikTok reaches $400M settlement with US over COPPA violations (2026-08-24 17:56 UTC)
Kurz: The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA). […]
Kurz: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a maximum-severity security flaw impacting Oracle HTTP Server and Oracle WebLogic Server to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence …
Shipping More AI Code Than You Can Secure? Watch How to Control Remediation Debt (2026-08-24 17:41 UTC)
Kurz: If your developers are using AI coding tools, you are probably already seeing the upside: faster development, more code, and less time spent on routine work. The harder part is what comes after. AI can also introduce open-source packages at…
Weedhack Malware Spreads via Fake Minecraft Clients and SEO Poisoning (2026-08-24 17:41 UTC)
Kurz: Cybersecurity researchers have found that several websites are still actively distributing a malware family known as Weedhack to gamers by masquerading as Minecraft clients. McAfee Labs said it detected and blocked more than 6,300 attempts …
Kurz: Improper Authentication vulnerability in Apache Camel Platform HTTP Main component. This issue affects Apache Camel: from 4.8.0 before 4.22.0. The camel-main embedded HTTP server can protect its endpoints with JWT authen…