🕵️ Sicherheitslücken[webapps] Bludit CMS - Stored XSS(01.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] Grav CMS 2.0.7 - RCE(01.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] miniOrange 5.4.3 - Unauthenticated Auth Bypass(01.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting(02.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] PodcastGenerator 3.2.9 - Stored XSS(02.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] Ghost_CMS 6.19.0 - Remote Code Execution(02.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] Langflow 1.10.0 - RCE(02.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] Marimo 0.20.4 - RCE(02.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] FreePBX 17.0.2 - Remote Code Execution (RCE)(03.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] Metabase 0.61.0 - Authenticated Remote Code Execution(03.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] Bludit CMS - Stored XSS(01.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] Grav CMS 2.0.7 - RCE(01.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] miniOrange 5.4.3 - Unauthenticated Auth Bypass(01.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] Bludit CMS 3.20.0 - Reflected Cross-Site Scripting(02.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] PodcastGenerator 3.2.9 - Stored XSS(02.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] Ghost_CMS 6.19.0 - Remote Code Execution(02.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] Langflow 1.10.0 - RCE(02.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] Marimo 0.20.4 - RCE(02.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] FreePBX 17.0.2 - Remote Code Execution (RCE)(03.09.2026 um 02:00 Uhr)
🕵️ Sicherheitslücken[webapps] Metabase 0.61.0 - Authenticated Remote Code Execution(03.09.2026 um 02:00 Uhr)

10 🕛 kürzlich 1 Min Lesezeit CVE-RADAR
0

Security Weekly - A CRA Resource: Linux Threat Hunting - PSW #942

Cyber Threat & Vulnerability Dossier CVSS 9.5 CRITICAL EPSS 96.4%
ANGRIPPSVEKTOR
🌐 Netzwerk (Remote)
AUTHENTIFIZIERUNG
🔓 Keine Authentifizierung nötig
SCHADENSPROFIL
RCE / Vollzugriff / Full Compromise
CWE-KLASSIFIZIERUNG
CWE-94: Code Injection
Handlungsempfehlung: Patch-Tuesday Update einspielen oder betroffene Dienste in Windows Defender isolieren.
Im CVE-Radar öffnen
↗ Quelle (YouTube · Security Weekly - A CRA Resource)
🗣️ Stimme:
📺
YouTube · Security Weekly - A CRA Resource
22 YouTube-Aufrufe
First up: a technical segment on Linux threat hunting. We'll start this series by covering the best places to look for IoCs on Linux systems and devices, starting with startup services and scheduled tasks. Then, in the security news this week:

- SonicWall zero-days, again
- AI finds a pile of Cisco bugs, and a root RCE
- Claude Code Auto Mode dangers
- BGP hijacks your unsigned software update
- California, Linux and age verification
- Free movies, complimentary malware
- Citrix puts Linux alongside Windows
- Signal's "secure" enclave
- An expired domain answers military phone calls
- MORE Cheap Android TV boxes arrive pre-pwned
- CISA red teams meet critical infrastructure
- PaperCut vulnerability cuts both ways
- Big Tech asks everyone to secure its AI future
Pacemaker monitoring
- DOJ files on a criminal leak site
- Water utility security, right after the breaches

Visit https://www.securityweekly.com/psw for all the latest episodes!

Show Notes: https://securityweekly.com/psw-942
Vollständiger Original-Bericht
Ausführliche Details, Code-Beispiele & Hersteller-Stellungnahme auf youtube.com.
↗ Original-Artikel auf youtube.com lesen
Wie bewertest du diesen Beitrag?
1 Klick Feedback
Teilen mit Netzwerk & Team:
Community Threat-Level Barometer
Live Votum

Wie stufst du das Risiko dieser Schwachstelle / Bedrohung für dein Unternehmen ein?

Noch keine Stimmen — schätze das Risiko als Erster ein.

Community-Analysen & Experten-Meinungen 0

Verfasse deine eigene Analyse, teile Workarounds oder diskutiere diesen Vorfall im Blog.
Noch keine Community-Analyse verfasst. Markiere einen Textabschnitt oder klicke oben auf Eigene Analyse verfassen“!
Community Pulse: Relevanz-Einschätzung
1 Klick Experten-Votum
🔴 Akute Relevanz 47%
🟡 In Evaluierung 20%
🟢 Keine Auswirkung 13%
Spannende Innovation 20%
Verwandte Story-Cluster & Quellen (Vektor-KI)
Port 8095 Engine
4 Quellen
Black Hat Asia 2026 | Large-Scale macOS PID-Domain Vulnerability Discovery with LLM Reasoning
1 Quelle
Who’s afraid of an open-weight model? GLM, context bombing and post-Black Hat attacks
1 Quelle
LLM & AI Agent Benchmarks vs Reality: Why AI Applications Break