Umsetzung des Cyber Resilience Act: Deutsche Industrie hat noch Nachholbedarf (2026-08-25 16:25 UTC)
Kurz: Im Dezember 2027 tritt der Cyber Resilience Act vollständig in Kraft, viele Unternehmen kämpfen noch mit den Vorgaben etwa zu Meldepflichten und SBOMs.
Kurz: Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites. […]
AnonyMousKIT PhaaS uses voice AI agents to phish iPhone passcodes (2026-08-25 20:25 UTC)
Kurz: A newly uncovered phishing-as-a-service (PhaaS) platform called AnonyMousKIT automates the retrieval of codes used to unlock stolen Apple devices and disable the Activation Lock feature. […]
Kurz: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday warned of active exploitation efforts targeting a recently patched critical security flaw impacting Gitea. The vulnerability in question is CVE-2026-60004 (CVSS sco…
Fake Apple Support AI Calls Target Stolen-Device Owners for Passcodes and 2FA Codes (2026-08-26 05:47 UTC)
Kurz: Cybersecurity researchers have disclosed details of a phishing-as-a-service (PhaaS) platform built to strip Apple’s Activation Lock from stolen devices, using rented AI voice agents that call theft victims posing as Apple Support and ask fo…
Kurz: The U.S. Department of the Treasury has announced fresh sanctions on Iranian cyber actors as part of what it called an “unprecedented, whole-of-government, economic campaign” against the nation and its enablers. “We are launching an economi…