Wie OpenAI die Cybersecurity mit fiesen Tricks vor den eigenen Karren spannt (2026-08-28 12:34 UTC)
Kurz: OpenAIs Cybersecurity-Aufruf ist ein manipulativer Trick. Denn natürlich brauchen wir mehr Security – aber nicht zwingend von denen, meint Jürgen Schmidt.
McKesson discloses breach after ShinyHunters claims patient data theft (2026-08-28 22:40 UTC)
Kurz: Healthcare and pharmaceutical distribution giant McKesson has disclosed a cybersecurity incident involving unauthorized access to third-party applications and data theft, with the ShinyHunters extortion group claiming it stole 284 million p…
PaperCut releases second emergency patch for exploited flaws (2026-08-28 19:08 UTC)
Kurz: PaperCut has released a second emergency security update for two actively exploited vulnerabilities in its PaperCut NG and MF print management software after researchers discovered multiple ways to bypass the initial fixes. […]
Kurz: A maximum-severity vulnerability in the GiveWP plugin for WordPress allows an unauthenticated attacker to execute arbitrary commands on the hosting server. […]
Berlin Refuses to Pay Hackers Who Stole Data From the City’s State Network (2026-08-28 21:30 UTC)
Kurz: Berlin’s state government has confirmed that it is the target of an extortion attempt following the August compromise of the city’s state administrative network, and said it will not meet the extortionists’ demands. The same statement discl…
Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable (2026-08-28 20:38 UTC)
Kurz: Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rate…
Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication (2026-08-28 17:12 UTC)
Kurz: Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. “This vulnerability gives an un…
Kurz: Graylog is a free and open log management platform. Prior to Graylog Server versions 6.3.12, 7.0.7, and 7.1.2 and Graylog Forwarder version 7.3, the FortiGate key-value syslog parser in graylog2-server/src/main/java/org/…
Kurz: Traffic interception vulnerability in BOSH Director vCenter CPI allows attackers positioned between BOSH Director and vCenter to impersonate vCenter REST API and capture administrator credentials via HTTP Basic auth, lea…