IT Nachrichten22. September(22.09.2026 um 00:05 Uhr)
IT NachrichtenLizenzprobleme: AnyDesk und TeamViewer(22.09.2026 um 00:30 Uhr)
Apple iOS & macOSApple's iOS 27.2 beta 2 reveals new anti-snatching protections(22.09.2026 um 00:27 Uhr)
AI & KI NachrichtenUC Irvine to Study AI for Writing Instruction(21.09.2026 um 23:31 Uhr)
AI & KI NachrichtenBurnham to call for global effort to control threats posed by AI(21.09.2026 um 23:30 Uhr)
IT Nachrichten22. September(22.09.2026 um 00:05 Uhr)
IT NachrichtenLizenzprobleme: AnyDesk und TeamViewer(22.09.2026 um 00:30 Uhr)
Apple iOS & macOSApple's iOS 27.2 beta 2 reveals new anti-snatching protections(22.09.2026 um 00:27 Uhr)
AI & KI NachrichtenUC Irvine to Study AI for Writing Instruction(21.09.2026 um 23:31 Uhr)
AI & KI NachrichtenBurnham to call for global effort to control threats posed by AI(21.09.2026 um 23:30 Uhr)
Cybersecurity News & Diskussionsportal
⚡ tsecurity.de Intelligence

Reverse Engineering

Sicherheitslücken (CVE) ENISA European Union Vulner…
CVE-2026-18963 | A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core (EUVD-2026-61063)

A flaw was found in the reset-credentials flow of the keycloak-services component, which is the core engine for identity and access management in Red…

vor 1 Monat 1 Min
0
Weiterlesen ↗
Admin & Dev Tools blog.mozilla.org
The wait is over. NVIDIA GeForce NOW adds Firefox to its supported browser lineup.

Gamers have asked for GeForce NOW support for years. Today, NVIDIA made it official, opening up GeForce RTX-powered play to Firefox on Windows.

vor 1 Monat 1 Min
0
Weiterlesen ↗
Admin & Dev Tools blog.mozilla.org
A billion searches a year, now built in: Startpage comes to Firefox

Firefox users were choosing Startpage long before today — to the tune of more than a billion searches a year, every one of them required some…

vor 1 Monat 3 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
iCal export header/line-break injection hardening in iCal generator

The Events Calendar 6.16.4.1 (released June 19, 2026) hardens the iCalendar export feed against header injection and line-break injection.

Kat #Workaround / Mitigation 80%
vor 1 Monat 1 Min
+1
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Authenticated (Contributor+) Stored XSS in Nested Nav Menu Widget

A Contributor-level user could inject arbitrary JavaScript via the menu divider ("menudivider") attribute of the nested navigation menu widget.

Kat #Workaround / Mitigation 65%
vor 1 Monat 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Stored XSS in Form Builder Submissions Admin List

The custom_date_key post-meta value (populated from a form's custom-date field submission) was echoed directly into the admin submissions list column…

Kat #Workaround / Mitigation 65%
vor 1 Monat 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Unauthenticated Privilege Escalation in Duplicator One-Click Upgrade

The Duplicator plugin registered its one-click upgrade AJAX endpoint for unauthenticated visitors and only required a low-privilege capability to use…

vor 1 Monat 1 Min
0
Weiterlesen ↗
ENISA European Union Vu…CVE-2026-74985 | Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 1 (EUVD-2026-60697)vor 1 MonatENISA European Union Vu…CVE-2026-74955 | Privilege escalation in the Request Handling component. This vulnerability was fixed in Firefox 154, (EUVD-2026-60682)vor 1 MonatENISA European Union Vu…CVE-2026-74952 | Privilege escalation in the Application Update component. This vulnerability was fixed in Firefox 15 (EUVD-2026-60680)vor 1 MonatENISA European Union Vu…CVE-2026-74950 | Privilege escalation in the Downloads API component. This vulnerability was fixed in Firefox 154, Fi (EUVD-2026-60678)vor 1 MonatENISA European Union Vu…CVE-2026-74947 | Privilege escalation due to invalid pointer in the Graphics component. This vulnerability was fixed (EUVD-2026-60677)vor 1 MonatENISA European Union Vu…CVE-2026-74965 | Privilege escalation in the Shell Integration component. This vulnerability was fixed in Firefox 154 (EUVD-2026-60663)vor 1 MonatENISA European Union Vu…CVE-2026-74953 | Privilege escalation in the Networking: Cookies component. This vulnerability was fixed in Firefox 1 (EUVD-2026-60756)vor 1 MonatENISA European Union Vu…CVE-2026-74949 | Privilege escalation due to use-after-free in the Graphics: Canvas2D component. This vulnerability w (EUVD-2026-60755)vor 1 MonatENISA European Union Vu…CVE-2026-74946 | Privilege escalation due to incorrect boundary conditions in the Graphics: CanvasWebGL component. Th (EUVD-2026-60753)vor 1 MonatENISA European Union Vu…CVE-2026-74942 | Privilege escalation in the Remote Settings Client component. This vulnerability was fixed in Firefo (EUVD-2026-60749)vor 1 MonatENISA European Union Vu…CVE-2026-74941 | Privilege escalation in the Graphics: CanvasWebGL component. This vulnerability was fixed in Firefox (EUVD-2026-60748)vor 1 MonatENISA European Union Vu…CVE-2026-74939 | Privilege escalation in the DOM: Navigation component. This vulnerability was fixed in Firefox 154, (EUVD-2026-60746)vor 1 MonatENISA European Union Vu…CVE-2026-74935 | Privilege escalation in the DOM: Networking component. This vulnerability was fixed in Firefox 154, (EUVD-2026-60744)vor 1 Monat
Sicherheitslücken (CVE) Vulnerability definition fe…
Stored Cross-Site Scripting in Ninja Forms Repeatable Fieldset

Ninja Forms before 3.14.9 does not escape the repetition index when rendering the submission summary for Repeatable Fieldset fields.

vor 1 Monat 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Stored XSS in Product Compare via unescaped product SKU / attribute term name

The Product Compare widget's comparison table populated the SKU and taxonomy-term-name fields directly from WooCommerce product data (`$sku`…

Kat #Workaround / Mitigation 65%
vor 1 Monat 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Broken Access Control in Pricing Table Builder REST endpoints

The `/king-addons/v1/pricing-table/list` and `/king-addons/v1/pricing-table/{id}` REST routes were registered with `'permission_callback' =>…

Kat #Workaround / Mitigation 65%
vor 1 Monat 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Authenticated (Administrator+) SQL Injection via Import File 'settings' Key

The Ninja Forms – The Contact Form Builder That Grows With You plugin for WordPress is vulnerable to generic SQL Injection via Import File 'settings'…

vor 1 Monat 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
JavaScript-context injection hardening for redirect URL in Debug Redirections

Improper Neutralization in a JavaScript context — CWE-79 (hardening). No CVE assigned at time of writing (1.0.275 released 2026-07-28).

vor 1 Monat 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) Vulnerability definition fe…
Stored XSS in Duplicate Post scheduled republish notice

Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice.

vor 1 Monat 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) ENISA European Union Vulner…
CVE-2026-71574 | Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0. (EUVD-2026-61025)

Joomla! Core - [20260803] - Inconsistent ACL checks for mutating webservice endpoints in Joomla 4.0.0-5.4.7, 6.0.0-6.1.

vor 1 Monat 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) ENISA European Union Vulner…
CVE-2026-15806 | The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWit (EUVD-2026-61013)

The HTTPPasswordMgr class in the urllib.request module, along with its subclasses HTTPPasswordMgrWithDefaultRealm and HTTPPasswordMgrWithPriorAuth…

vor 1 Monat 1 Min
0
Weiterlesen ↗
Admin & Dev Tools blog.mozilla.org
Smart Window: Finish what you start online

Browsers make it easy to start things, but picking them back up is another story.

vor 1 Monat 1 Min
0
Weiterlesen ↗
Admin & Dev Tools blog.mozilla.org
Firefox and Exa: Building AI search around people, not platforms

AI has changed how we browse. Full stop. The real question is whether AI leads to one browser experience for everyone, or gives people more ways to…

vor 1 Monat 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) ENISA European Union Vulner…
CVE-2026-75898 | RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "In (EUVD-2026-60824)

RAGFlow before 0.26.3 contains a server-side request forgery vulnerability in the agent workflow "Invoke" component (agent/component/invoke.py).

vor 1 Monat 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) ENISA European Union Vulner…
CVE-2026-66046 | Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic compl (EUVD-2026-60821)

Expat through 2.8.3 contains a denial of service vulnerability caused by quadratic algorithmic complexity in the storeAtts() function in xmlparse.

vor 1 Monat 1 Min
0
Weiterlesen ↗
Reverse Engineering reddit.com
Image viewer for 2003 Neighbours From Hell's .tga image format

submitted by /u/Brilliant-Box-5344 [link] [comments]

vor 1 Monat 1 Min
0
Weiterlesen ↗
Sicherheitslücken (CVE) ENISA European Union Vulner…
CVE-2026-24301 | Improper neutralization of special elements used in a command ('command injection') in Microsoft Cop (EUVD-2026-60762)

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to disclose…

vor 1 Monat 1 Min
0
Weiterlesen ↗
Reverse Engineering schneier.com
LLMs and Contextual Integrity

I have been thinking a lot about AI and integrity. Part of that is contextual integrity. I recently found two papers on the topic.

vor 1 Monat 1 Min
0
Weiterlesen ↗
Admin & Dev Tools fxdx.dev
Firefox Developer Experience: Firefox WebDriver Newsletter 154

WebDriver is a remote control interface that enables introspection and control of user agents.

vor 1 Monat 1 Min
0
Weiterlesen ↗
Weitere 36 Beiträge laden
Seite 200 von 1.000 • Gesamt: 418.019 Artikel
Threat Hunter Status-Update verfassen
Community Stream
News-Deck Reverse Engineering 📖 0 · ⏭ 0 · 🗳️ 0

Karten werden geladen …

Hoch = in der Vorschau lesen · Rechts = vor · Links/Runter = zurück · Enter/Karte tippen = Vorschau · V = Voting