Vierter Hacking-Vorfall: Weiteres Anthropic-Modell bricht aus Testumgebung aus (2026-09-10 13:46 UTC)
Kurz: Nachdem Anthropic schon Ende Juli drei Hacking-Angriffe meldete, ist nach Analyse der Daten jetzt noch ein vierter bei Claude Opus 4.6 hinzugekommen.
Sicherheitslücken in ePA-Clients: „Die Implementierungen hatten blinde Flecken“ (2026-09-10 12:53 UTC)
Kurz: Sicherheitsforscher sorgten für Fixes kritischer Lücken in ePA-Clients und der Telematikinfrastruktur. Dr. Simon Weber erklärt die Details im Interview.
Trezor: 347,000 users targeted in phishing attacks after Brevo breach (2026-09-11 07:55 UTC)
Kurz: Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. […]
New Android malware encrypts files, steals data, and harasses victims (2026-09-10 21:40 UTC)
Kurz: A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. […]
Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors (2026-09-11 07:31 UTC)
Kurz: Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw th…
Kurz: A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims’ computers, security company Gen Digital said in research publ…
PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws (2026-09-11 06:46 UTC)
Kurz: PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development comp…
Kurz: A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user.
Kurz: A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS).
Kurz: The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Content in all versions up to, and including, 3.0.14 due to insufficient input sanitization and output escaping. This…