KI-Agenten führen git-Schadcode beim Starten automatisch aus (2026-09-02 05:23 UTC)
Kurz: Agenten von Claude, Qwen, Grok usw. starten in manipulierten Repositories automatisch Schadcode – ohne Zutun des Anwenders, aber mit dessen vollen Rechten.
Kurz: Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. […]
Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another (2026-09-02 07:47 UTC)
Kurz: Forescout Research - Vedere Labs said it used Anthropic’s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcod…
Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials (2026-09-02 07:08 UTC)
Kurz: Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a crit…
Authorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware Payloads (2026-09-02 06:56 UTC)
Kurz: The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authori…
Kurz: An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a …
Kurz: A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administra…
Kurz: An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker’s control are met…
Kurz: A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an admi…
Kurz: A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interfa…
Kurz: A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrat…