Meistinteragiert
Hacking & Pentesting
vor 2 Std.
Live Threat Intelligence Feed
Kategorie #7
Hacking & Pentesting
Ethical Hacking, Red Teaming & Attack Vectors. Analysen neuester Hacking-Methoden, Exploitation Frameworks, Credential Stuffing und Social Engineering Taktiken.
Meistinteragiert
Hacking & Pentesting
vor 1 Std.
Neue Hackerangriffe: Das müssen Brandenburger Unternehmen jetzt tun - MOZ.de
Meistinteragiert
Hacking & Pentesting
vor 42 Min.
Cybercrime: Mailserver der Hamburger Grünen gehackt - DIE ZEIT
Meistinteragiert
Hacking & Pentesting
vor 1 Std.
AI Agents Attempt SQL Injection While Searching Government Data
Meistinteragiert
Hacking & Pentesting
vor 4 Std.
Multiple cPanel & WHM Vulnerabilities Enable Root Code Execution and Admin Session Hijacking
Meistinteragiert
Hacking & Pentesting
vor 3 Std.
Exposed Hacker Server Reveals Toolkit Used in Viva Aerobus-Linked Intrusion
EILMELDUNGEN LIVE
1/10
Windows Tipps & SecurityHacker hijacked Microsoft’s X: “500,000 likes and we bring Clippy back,” all to pump a crypto token(02.10.2026 um 17:30 Uhr)
•Sicherheitslücken (CVE)CVE-2025-57933 | piotnetdotcom Piotnet Forms Plugin up to 1.0.30 on WordPress cross-site request forgery(02.10.2026 um 16:59 Uhr)
•Sicherheitslücken (CVE)CVE-2025-57929 | kanwei_doublethedonation Double the Donation Plugin up to 2.0.0 on WordPress cross site scripting(02.10.2026 um 16:59 Uhr)
•Sicherheitslücken (CVE)CVE-2025-57910 | AnyClip Video Platform AnyClip Luminous Studio Plugin up to 1.3.3 on WordPress cross site scripting(02.10.2026 um 16:59 Uhr)
•Sicherheitslücken (CVE)CVE-2025-57906 | Epeken All Kurir Plugin up to 2.0.2 on WordPress cross site scripting(02.10.2026 um 16:59 Uhr)
•Sicherheitslücken (CVE)CVE-2025-57899 | AresIT WP Compress Plugin up to 6.50.54 on WordPress authorization(02.10.2026 um 16:59 Uhr)
•Sicherheitslücken (CVE)CVE-2025-53458 | davaxi Goracash Plugin up to 1.1 on WordPress cross site scripting(02.10.2026 um 16:59 Uhr)
•Sicherheitslücken (CVE)CVE-2025-10808 | Campcodes Farm Management System 1.0 /uploadProduct.php type sql injection(02.10.2026 um 16:59 Uhr)
•Sicherheitslücken (CVE)CVE-2025-57935 | Ricky Dawn Bot Block Plugin up to 2.6 on WordPress cross site scripting(02.10.2026 um 16:59 Uhr)
•Sicherheitslücken (CVE)CVE-2025-10798 | code-projects Hostel Management System 1.0 index.php?view=view id sql injection(02.10.2026 um 16:59 Uhr)
•Windows Tipps & SecurityHacker hijacked Microsoft’s X: “500,000 likes and we bring Clippy back,” all to pump a crypto token(02.10.2026 um 17:30 Uhr)
•Sicherheitslücken (CVE)CVE-2025-57933 | piotnetdotcom Piotnet Forms Plugin up to 1.0.30 on WordPress cross-site request forgery(02.10.2026 um 16:59 Uhr)
•Sicherheitslücken (CVE)CVE-2025-57929 | kanwei_doublethedonation Double the Donation Plugin up to 2.0.0 on WordPress cross site scripting(02.10.2026 um 16:59 Uhr)
•Sicherheitslücken (CVE)CVE-2025-57910 | AnyClip Video Platform AnyClip Luminous Studio Plugin up to 1.3.3 on WordPress cross site scripting(02.10.2026 um 16:59 Uhr)
•Sicherheitslücken (CVE)CVE-2025-57906 | Epeken All Kurir Plugin up to 2.0.2 on WordPress cross site scripting(02.10.2026 um 16:59 Uhr)
•Sicherheitslücken (CVE)CVE-2025-57899 | AresIT WP Compress Plugin up to 6.50.54 on WordPress authorization(02.10.2026 um 16:59 Uhr)
•Sicherheitslücken (CVE)CVE-2025-53458 | davaxi Goracash Plugin up to 1.1 on WordPress cross site scripting(02.10.2026 um 16:59 Uhr)
•Sicherheitslücken (CVE)CVE-2025-10808 | Campcodes Farm Management System 1.0 /uploadProduct.php type sql injection(02.10.2026 um 16:59 Uhr)
•Sicherheitslücken (CVE)CVE-2025-57935 | Ricky Dawn Bot Block Plugin up to 2.6 on WordPress cross site scripting(02.10.2026 um 16:59 Uhr)
•Sicherheitslücken (CVE)CVE-2025-10798 | code-projects Hostel Management System 1.0 index.php?view=view id sql injection(02.10.2026 um 16:59 Uhr)
•
Cybersecurity News & Diskussionsportal
⚡ tsecurity.de Intelligence
Hacking & Pentesting (95360)
Hacking & Pentesting
- 🏠 Home
- ›
- IT Security
- ›
- 📑 Hacking & Pentesting (Seite 998)
LIVE …
95.360 Meldungen
Vektoren: Alle Vektoren 🚪 Initial Access ATT&CK 🎯 Privilege Escalation ATT&CK 🔄 Lateral Movement ATT&CK 🔴 Red Team ATT&CK 🌐 Web Exploitation ATT&CK ☁️ Cloud Exploitation ATT&CK 🎭 Social Engineering ATT&CK 💰 Bug Bounty Intel 🔥 Critical (CVSS 9+) Threat ⚠️ PoC & Exploit ATT&CK 🚨 0-Day & KEV Threat 🦠 Ransomware & APT Threat
Cyber Threat Intelligence & Forensik
ATT&CK-Taktiken über die sichtbaren Meldungen dieser Kategorie
MITRE ATT&CK HEATMAP 4 von 24 Meldungen kartiert
Live TTP Radar (Klick filtert Ansicht)
Initial Access 2
Execution 1
Impact / Ransomware 1
MITRE ATT&CK Matrix Navigator
Enterprise-Matrix · nur belegte Techniken
T1059TA0002 · Execution
Command and Scripting Interpreter
Mitigation: M1038 Execution Prevention & Script Block Logging
Quelle: Kontext-Klassifikation des Artikeltextes
T1190TA0001 · Initial Access
Exploit Public-Facing Application
Mitigation: M1042 Network Segmentation & WAF Rule Enforcement
Quelle: Kontext-Klassifikation des Artikeltextes
T1486TA0040 · Impact
Data Encrypted for Impact
Mitigation: M1053 Data Backup & Offline Isolation
Quelle: Kontext-Klassifikation des Artikeltextes
Reconnaissance
–
Resource Development
–
Initial Access
Execution
Persistence
–
Privilege Escalation
–
Defense Evasion
–
Credential Access
–
Discovery
–
Lateral Movement
–
Collection
–
Command and Control
–
Exfiltration
–
Impact
Nur belegte ATT&CK-Techniken werden kartiert — Taktiken ohne Beleg bleiben unausgefüllt.Enterprise Matrix v14.1
Älter
GuLoader implements new evasion techniques
TA0002 · T1059 Cloud & IT-Enterprise Alle Kategorien 75%
vor 3 Jahren 1 Min
0
Critical Linux Kernel Vulnerability Let Attackers Execute Remote Code
🛡️ Security Fix Unix & Linux Server 85%
vor 3 Jahren 1 Min
0
Zweite Staffel von Deep Science - Hacking Reality (Podcast-Trailer) | deutschlandfunk.de
vor 3 Jahren 1 Min
0
Ukrainer stiehlt Bitcoin vom russischen Darknet-Markt und spendet für wohltätige Zwecke
vor 3 Jahren 1 Min
0
Hackers Using Automated Attack to Exploit Exchange Server and SQL Injection Vulnerabilities
TA0001 · T1190 Alle Kategorien 65%
vor 3 Jahren 1 Min
0
Hacker wants Elon Musk or Twitter to buy back stolen data - IT Security News
vor 3 Jahren 1 Min
0
Experts warn of attacks exploiting WordPress gift card plugin
EPSS 13.5% Sicherheitslücken (CVE) 75%
vor 3 Jahren 1 Min
0
RisePro: Malware zielt auf Softwarepiraten - Tarnkappe.info
IT Nachrichten 75%
vor 3 Jahren 1 Min
0
Data of 400 Million Twitter users up for sale | IT Security News
IT Security 65%
vor 3 Jahren 1 Min
0
http://etebaspura.dilmil-semarang.go.id/end.html
vor 3 Jahren 1 Min
0
Neuer Datendieb entdeckt: Malware verbreitet sich über Crack-Websites - WinFuture.de
TA0001 · T1190
vor 3 Jahren 1 Min
0
Security Affairs newsletter Round 399 by Pierluigi Paganini
IT Nachrichten 75%
vor 3 Jahren 1 Min
0
Microsoft fined €60 million in France for using advertising cookies without consent
vor 3 Jahren 1 Min
0
https://dreamweaver.crirs.cr.gov.ng
Gov & Defense
vor 3 Jahren 1 Min
0
Der Markt für verteilte Blockchain-Ledger dürfte bis 2028 ein enormes Wachstum verzeichnen
vor 3 Jahren 1 Min
0
Your business should compensate for modern ransomware capabilities right now
TA0040 · T1486
vor 3 Jahren 1 Min
0
Ist Kim Jong-un der grösste Kryptodieb? - 20 Minuten
Finanzwesen & Banking
vor 3 Jahren 1 Min
0
Expert found Backdoor credentials in ZyXEL LTE3301 M209
Alle Kategorien 65%
vor 3 Jahren 1 Min
0
Raspberry Robin malware used in attacks against Telecom and Governments
Gov & Defense IT Nachrichten 75%
vor 3 Jahren 1 Min
0
️ Threat Hunter Status-Update verfassen
Community Stream News-Deck Hacking & Pentesting 📖 0 · ⏭ 0 · 🗳️ 0
Karten werden geladen …
Hoch = in der Vorschau lesen · Rechts = vor · Links/Runter = zurück · Enter/Karte tippen = Vorschau · V = Voting
KI-ZUSAMMENFASSUNG · AI SUMMARY
Hacking & Pentesting · 24 Artikel analysiert · Ca. 16 Min. Lesezeit gespart
1. Übergreifende Bedrohungslage & Fokus
Die aktuelle Nachrichtenlage in „Hacking & Pentesting“ fokussiert auf „GuLoader implements new evasion techniques“, „Critical Linux Kernel Vulnerability Let Attackers Execute Remote Code“, „Zweite Staffel von Deep Science - Hacking Reality (Podcast-Trailer) | deutschlandfunk.de“.
2. Betroffene Ökosysteme
Primär betroffene Hersteller & Ökosysteme: Generic Security, Linux, Microsoft sowie damit verbundene Cloud- und On-Premises-Infrastrukturen.
3. Empfohlene Maßnahmen
Sicherheitsverantwortliche und Administratoren sollten die genannten Schwachstellen priorisiert analysieren, offizielle Hersteller-Patches anwenden und Monitoring-Regeln für verdächtige Zugriffe scharfschalten.
Key Takeaways der aktuellen Artikel (8)
100% Echtdaten-Synthese
1. GuLoader implements new evasion techniques
Öffnen ↗
7
Generic Security ⏱️ ~2 Min. gespart
Bedrohung: Cybersecurity researchers exposed new evasion techniques adopted by an advanced malware downloader called GuLoader.
Betrifft: CrowdStrike researchers d a detailed multiple evasion techniques implemented by an advanced malware downloader called GuLoader (aka CloudEyE).
Maßnahme: Administratoren sollten unverzüglich verfügbare Sicherheitsupdates einspielen, Workarounds anwenden und Systemlogs auf verdächtige Zugriffe prüfen.
2. Critical Linux Kernel Vulnerability Let Attackers Execute Remote Code
Öffnen ↗
7
Linux ⏱️ ~2 Min. gespart
Bedrohung: SMB servers that have ksmbd enabled are vulnerable to hacking due to a major Linux kernel vulnerability (CVSS score of 10). KSMBD is a Linux kernel server that uses the SMB3 protocol to share files over the network in kernel space.
Betrifft: On vulnerable Linux Kernel installations, an unauthenticated, remote attacker can run any programme.
Maßnahme: Administratoren sollten unverzüglich verfügbare Sicherheitsupdates einspielen, Workarounds anwenden und Systemlogs auf verdächtige Zugriffe prüfen.
3. Zweite Staffel von Deep Science - Hacking Reality (Podcast-Trailer) | deutschlandfunk.de
Öffnen ↗
7
Generic Security ⏱️ ~2 Min. gespart
Bedrohung: Hacking Reality (Podcast-Trailer).
Betrifft: Was ist Wirklichkeit – und was existiert nur in meinem Kopf?
Maßnahme: Administratoren sollten unverzüglich verfügbare Sicherheitsupdates einspielen, Workarounds anwenden und Systemlogs auf verdächtige Zugriffe prüfen.
4. http://dpmd.mojokertokab.go.id/readme.php
Öffnen ↗
7
Generic Security ⏱️ ~2 Min. gespart
Bedrohung: http://dpmd.mojokertokab.go.id/readme.php notified by UCEN HAXOR
Betrifft: Betrifft Systeme und Installationen im Generic Security-Ökosystem sowie damit verknüpfte Netzwerkdienste.
Maßnahme: Administratoren sollten unverzüglich verfügbare Sicherheitsupdates einspielen, Workarounds anwenden und Systemlogs auf verdächtige Zugriffe prüfen.
5. Ukrainer stiehlt Bitcoin vom russischen Darknet-Markt und spendet für wohltätige Zwecke
Öffnen ↗
7
Generic Security ⏱️ ~2 Min. gespart
Bedrohung: Solaris mit &#x 2018; Patriotic &#x 2019; Russisches Hacking-Kollektiv Killnet.
Betrifft: Dem Darknet-Markt Solaris werden Verbindungen zum Hacker-Team ...
Maßnahme: Administratoren sollten unverzüglich verfügbare Sicherheitsupdates einspielen, Workarounds anwenden und Systemlogs auf verdächtige Zugriffe prüfen.
6. Late HackTheBox Walkthrough
Öffnen ↗
7
Linux ⏱️ ~2 Min. gespart
Bedrohung: Summary Late is a Linux machine and is considered as an easy box by the hack the box.
Betrifft: On this box, we will begin with
Maßnahme: Administratoren sollten unverzüglich verfügbare Sicherheitsupdates einspielen, Workarounds anwenden und Systemlogs auf verdächtige Zugriffe prüfen.
7. Hackers Using Automated Attack to Exploit Exchange Server and SQL Injection Vulnerabilities
Öffnen ↗
7
Microsoft ⏱️ ~2 Min. gespart
Bedrohung: Recently, cybersecurity analysts at Prodraft’s threat intelligence team detected that the hacker group FIN7 was actively exploiting vulnerabilities in Microsoft Exchange and SQL injection through an automated attack system in an attempt to
Betrifft: There are a number […] The post Hackers Using Automated Attack to Exploit Exchange Server and SQL Injection Vulnerabilities appeared first on GBHackers - Latest Cyber Security News | Hacker News.
Maßnahme: Administratoren sollten unverzüglich verfügbare Sicherheitsupdates einspielen, Workarounds anwenden und Systemlogs auf verdächtige Zugriffe prüfen.
8. https://satpolpp.balangankab.go.id/index.php
Öffnen ↗
7
Generic Security ⏱️ ~2 Min. gespart
Bedrohung: https://satpolpp.balangankab.go.id/index.php notified by Yrid06
Betrifft: Betrifft Systeme und Installationen im Generic Security-Ökosystem sowie damit verknüpfte Netzwerkdienste.
Maßnahme: Administratoren sollten unverzüglich verfügbare Sicherheitsupdates einspielen, Workarounds anwenden und Systemlogs auf verdächtige Zugriffe prüfen.
Generiert: 2026-10-02 17:42:16
CISO EXECUTIVE THREAT DOSSIER
Hacking & Pentesting · Strategisches Lagebild TLP:CLEAR
CISO EXECUTIVE THREAT DOSSIER
tsecurity.de Cyber Defense Intelligence · 02.10.2026 17:42 UTCGUARDED
Executive Summary
Lagebild für „Hacking & Pentesting": Identifizierte Bedrohungen weisen maximalen CVSS-Wert 7.5 (Heuristik) auf. Sofortige Risikominimierung empfohlen.
Identifizierte Schwachstellen
- CVE-2022-45359 CVSS 7.5
- CVE-2022-40602 CVSS 7.5
Betroffene Systeme
Linux / OpenSourceMicrosoft
Härtungs-Checkliste für Einsatzkräfte
- ■ 1. Perimeter & Firewalls: Exponierte Management-Ports und Weboberflächen auf Port 443/8443 sofort isolieren.
- ■ 2. Patch Management: Kritische Sicherheitsupdates für identifizierte CVEs binnen 24-48 Stunden auf Systemen einspielen.
- ■ 3. Telemetrie & EDR: Prozessausführungen (cmd.exe, powershell, bash) und unübliche Kindprozesse der Webdienste prüfen.
- ■ 4. Identity & Access: Multi-Faktor-Authentifizierung (MFA) für alle externen Zugänge (VPN, RDP, SSO) verifizieren.
- ■ 5. Offline Backups: Sicherstellen, dass unveränderliche (WORM) Datensicherungen von Kernsystemen getrennt vorgehalten werden.
TLP:CLEAR · Vertraulichkeit gewahrt
ESC
- Ansicht: Kachel-Raster 1
- Ansicht: Kompakte Liste 2
- Ansicht: Threat Feed Wall 3
- Ansicht: News-Deck Wischen 4
- CISO Threat Dossier öffnen D
- KI-Zusammenfassung (AI Summary) B
- Analyst Workbench (Gemerkt) W
↑↓ Navigieren · ↵ Ausführen
SOC Telemetry Terminal
ANALYST WORKBENCH
0 Artikel gemerkt
Keine gemerkten Artikel vorhanden.
Klicke auf 🔖 an einer Nachricht, um sie hinzuzufügen.
Klicke auf 🔖 an einer Nachricht, um sie hinzuzufügen.
SOC 24H SHIFT HANDOVER BRIEFING
Zeitpunkt: 02.10.2026 17:42 UTC
Analysiert
24Kritisch
0Exploits/PoC
2Prioritäten für die nächste Schicht:
- Patching & Virtual Patching (WAF) für verifizierte Exploits priorisieren.
GLOBAL CTI GEO-RADAR
LIVE VECTOR
DIFF:
Multi-CVE Comparative Matrix & Diff Engine
Side-by-Side Schwachstellen-Analyse · Live CTI Metriken
CTI-Metriken & Vektoren werden verglichen...
Powered by tsecurity.de
tsecurity.de Hub