Linux Tipps & HardeningDSA-6534-2 webkit2gtk - regression update(02.10.2026 um 02:00 Uhr)
••••••••••
Linux Tipps & HardeningDSA-6534-2 webkit2gtk - regression update(02.10.2026 um 02:00 Uhr)
••••••••••
Cybersecurity News & Diskussionsportal
⚡ tsecurity.de Intelligence
Reverse Engineering (451559)

Reverse Engineering

LIVE …

Cyber Threat Intelligence & Forensik

ATT&CK-Taktiken über die sichtbaren Meldungen dieser Kategorie
MITRE ATT&CK HEATMAP 2 von 20 Meldungen kartiert
Live TTP Radar (Klick filtert Ansicht)
Initial Access 2
MITRE ATT&CK Matrix Navigator
Enterprise-Matrix · nur belegte Techniken
14 Taktiken
1 belegte Technik
T1190TA0001 · Initial Access
Exploit Public-Facing Application
Mitigation: M1042 Network Segmentation & WAF Rule Enforcement
Quelle: Kontext-Klassifikation des Artikeltextes
Reconnaissance
Resource Development
Initial Access
Execution
Persistence
Privilege Escalation
Defense Evasion
Credential Access
Discovery
Lateral Movement
Collection
Command and Control
Exfiltration
Impact
Sicherheitslücken (CVE) VulDB Updates

CVE-2026-102806 | OpenClaw up to 2026.9.4 Media Pipeline improper authorization (WID-SEC-2026-3673)

A vulnerability was found in OpenClaw. It has been rated as problematic. This affects an unknown part of the component Media Pipeline.

vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Sicherheitslücken (CVE) VulDB Updates

CVE-2026-102621 | Freedesktop Poppler up to 26.08.0 splash/SplashClip.cc SplashClip::clipToPath integer overflow (ID 1763 / WID-SEC-2026-3674)

A vulnerability was found in Freedesktop Poppler up to 26.08.0. It has been declared as problematic.

vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Sicherheitslücken (CVE) DEV Community

Checkpoint Restore: Destination Policy Was Never Reapplied

A checkpoint restore can rebuild a process from saved state without passing that state back through the destination's normal policy translation.

vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Sicherheitslücken (CVE) GBHackers Security

Critical MikroTik RouterOS Vulnerability Exposes Devices to Remote Code Execution

A critical vulnerability in MikroTik RouterOS could allow unauthenticated remote attackers to execute code on vulnerable devices or trigger a…

🛡️ Security Fix TA0001 · T1190
vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
BSI Warn- und Informati…[NEU] [hoch] MikroTik RouterOS: Schwachstelle ermöglicht Codeausführung und DoSvor 2 Tagen
Sicherheitslücken (CVE) Vulnerability definition fe…

Incorrect Permissions in YITH WooCommerce Wishlist Wishlist Creation

YITH WooCommerce Wishlist up to and including 4.10.0 exposes YITH_WCWL_Wishlists::create() through the unauthenticated REST route…

vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Vulnerability definitio…Incorrect Permissions in Spectra Popup Builder REST Endpointsvor 2 Tagen
Sicherheitslücken (CVE) Vulnerability definition fe…

Email Header Injection in Contact Form 7 Mail Additional Headers

Contact Form 7 expanded mail-tags across the entire "Additional headers" mail template in a single pass and appended the result to the outgoing…

vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Sicherheitslücken (CVE) Vulnerability definition fe…

Input Validation in WP Fastest Cache Cache File Path

WP Fastest Cache derives the on-disk cache file path from the incoming request URL. Before 1.4.

vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Vulnerability definitio…Missing Authorization in WP Fastest Cache Varnish Cache Actionsvor 2 Tagen
Sicherheitslücken (CVE) Vulnerability definition fe…

Missing Authorization in Custom Post Type UI Post Type Processing

Custom Post Type UI does not check the current user's capabilities before handling post type management requests in cptui_process_post_type().

vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Vulnerability definitio…Missing Authorization in Cookie Notice Cache Purge and AJAX Handlersvor 2 TagenVulnerability definitio…Missing Authorization in Google XML Sitemaps Upgrade Handlervor 2 Tagen
Sicherheitslücken (CVE) Vulnerability definition fe…

Unauthenticated Information Disclosure via Repeater Field Merge Tags in Ninja Forms

Ninja Forms up to and including 3.14.0 resolves merge tags inside user-submitted repeater field values during form submission (nf_ajax_submit).

Kat #Workaround / Mitigation 65%
vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Sicherheitslücken (CVE) Vulnerability definition fe…

Unauthenticated SQL Injection in The Events Calendar Custom Tables Query

The Events Calendar up to and including 6.15.1 redirects the ORDER BY clause of event queries through Custom_Tables_Query::parse_orderby(), but falls…

TA0001 · T1190
vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Sicherheitslücken (CVE) Vulnerability definition fe…

Authorization bypass through predictable unsubscribe token in Popup Builder

Popup Builder generates newsletter unsubscribe tokens as an MD5 of the subscriber ID and e-mail address, a value an attacker can reproduce.

vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Sicherheitslücken (CVE) Vulnerability definition fe…

Broken Access Control in Elementor User Query REST Endpoint

The /elementor/v1/user REST endpoint only requires the edit_posts capability, yet it ran its own get_users() query instead of going through WordPress…

vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Sicherheitslücken (CVE) Vulnerability definition fe…

Insecure Direct Object Reference in Fluent Forms Stripe Payment Confirmation

The Stripe SCA payment confirmation endpoints in Fluent Forms accept a submission_id from the request without verifying that the caller is entitled…

Finanzwesen & Banking
vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Sicherheitslücken (CVE) Ubuntu security notices

USN-8852-1: OpenVPN vulnerabilities

It was discovered that OpenVPN had a use-after-free vulnerability in its TLS session handling.

TA0040 · T1498
vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Sicherheitslücken (CVE) BSI Warn- und Informationsd…

[NEU] [mittel] Moodle: Mehrere Schwachstellen

Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Moodle ausnutzen, um Sicherheitsvorkehrungen zu umgehen und um eine…

vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Sicherheitslücken (CVE) Linux Handbook

Command Conqueror

Command Conqueror is a capture-the-flag game with 10 levels of Linux command line puzzles.

TA0004 · T1068
vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Reverse Engineering IT Security News

AI Is Making Software Cheaper to Attack. Defenders Need to Change the Price

By Ansgar Dodt, VP Product Management for Software Monetization at Thales Not every piece of software is worth attacking.

vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Sicherheitslücken (CVE) VulDB Updates

CVE-2026-75887 | Red Hat OpenShift Container Platform Console /locales/resource.json lng/ns path traversal (EUVD-2026-85702)

A vulnerability categorized as critical has been discovered in Red Hat OpenShift Container Platform.

vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
Sicherheitslücken (CVE) VulDB Updates

CVE-2026-102010 | GCC use after free (EUVD-2026-88443)

A vulnerability was found in GCC. It has been classified as problematic. The impacted element is an unknown function.

vor 2 Tagen 1 Min Original-Quelle öffnen
0
Weiterlesen
VulDB UpdatesCVE-2026-103113 | OS4ED openSIS-Classic up to 9.3 General Information Tab Student.php save action students sql injection (Issue 475 / EUVD-2026-89762)vor 2 Tagen
️ Threat Hunter Status-Update verfassen
Community Stream
News-Deck Reverse Engineering 📖 0 · ⏭ 0 · 🗳️ 0

Karten werden geladen …

Hoch = in der Vorschau lesen · Rechts = vor · Links/Runter = zurück · Enter/Karte tippen = Vorschau · V = Voting

0 Artikel gemerkt
Keine gemerkten Artikel vorhanden.
Klicke auf an einer Nachricht, um sie hinzuzufügen.
GLOBAL CTI GEO-RADAR
LIVE VECTOR
APT29 / SandwormVolt TyphoonLazarus GroupCharming KittenKRITIS Target ZoneScattered Spider
DIFF: