<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - News Radar & Live Feeds]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml]]></link>
<description><![CDATA[Aktuelle Nachrichten und Updates auf tsecurity.de]]></description>
<language>de-DE</language>
<lastBuildDate>Tue, 01 Sep 2026 23:36:20 +0200</lastBuildDate>
<pubDate>Tue, 01 Sep 2026 23:36:20 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - News Radar &amp; Live Feeds</copyright>
<managingEditor>tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-isharestuff-com/media/logo.png</url>
<title><![CDATA[tsecurity.de - News Radar & Live Feeds]]></title>
<link><![CDATA[https://tsecurity.de/export/rss/alle-kategorien.xml]]></link>
</image>
<atom:link href="https://tsecurity.de/export/rss/alle-kategorien.xml" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[Case study: ManageWP Blocks 11.9M+ Threats in 6 Months with Patchstack]]></title>
<description><![CDATA[11.9M+ Threats blocked by Patchstack in 6 months Zero Hours of sleep lost Run one WordPress site and a vulnerability is a single bad day. Run an agency, and it’s a portfolio-wide panic event that results in lost sleep and enough caffeine to take down a horse. Updates can’t close that gap alone, e...]]></description>
<link>https://tsecurity.de/de/3930778/sicherheitsluecken/case-study-managewp-blocks-119m-threats-in-6-months-with-patchstack/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930778/sicherheitsluecken/case-study-managewp-blocks-119m-threats-in-6-months-with-patchstack/</guid>
<pubDate>Tue, 01 Sep 2026 23:36:18 +0200</pubDate>
<content:encoded><![CDATA[<p>11.9M+ Threats blocked by Patchstack in 6 months Zero Hours of sleep lost Run one WordPress site and a vulnerability is a single bad day. Run an agency, and it’s a portfolio-wide panic event that results in lost sleep and enough caffeine to take down a horse. Updates can’t close that gap alone, especially when attackers weaponize the most-targeted... <a href="https://patchstack.com/articles/case-study-managewp-blocks-11-9m-threats-in-6-months-with-patchstack/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unauthenticated PHP Object Injection to Remote Code Execution on GiveWP]]></title>
<description><![CDATA[GiveWP Unauthenticated PHP Object Injection to Remote Code Execution 100,000 CVSS 10.0 This blog post is about an unauthenticated remote code execution vulnerability in the GiveWP plugin. An attacker with no account can run arbitrary commands on the server of a GiveWP site that has one published ...]]></description>
<link>https://tsecurity.de/de/3930777/sicherheitsluecken/unauthenticated-php-object-injection-to-remote-code-execution-on-givewp/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930777/sicherheitsluecken/unauthenticated-php-object-injection-to-remote-code-execution-on-givewp/</guid>
<pubDate>Tue, 01 Sep 2026 23:36:13 +0200</pubDate>
<content:encoded><![CDATA[<p>GiveWP Unauthenticated PHP Object Injection to Remote Code Execution 100,000 CVSS 10.0 This blog post is about an unauthenticated remote code execution vulnerability in the GiveWP plugin. An attacker with no account can run arbitrary commands on the server of a GiveWP site that has one published donation form and one active payment gateway which,... <a href="https://patchstack.com/articles/unauthenticated-php-object-injection-to-remote-code-execution-on-givewp/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Berlin Senate Passwort.docx Breach: Ahab of the East Sea Cover Story]]></title>
<description><![CDATA[Russians are having a laugh about Ahab on the East Sea 1-2-3. And then there’s Sunshine 13. These were passwords disclosed in the Berlin Senate breach. The “Ahabostsee123”, is in fact a yacht for vacations in the Baltic. Much of the press seems to be wagging a finger about BSI recommendations, ca...]]></description>
<link>https://tsecurity.de/de/3930776/it-security-nachrichten/berlin-senate-passwortdocx-breach-ahab-of-the-east-sea-cover-story/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930776/it-security-nachrichten/berlin-senate-passwortdocx-breach-ahab-of-the-east-sea-cover-story/</guid>
<pubDate>Tue, 01 Sep 2026 23:34:48 +0200</pubDate>
<content:encoded><![CDATA[<p>Russians are having a laugh about Ahab on the East Sea 1-2-3. And then there’s Sunshine 13. These were passwords disclosed in the Berlin Senate breach. The “Ahabostsee123”, is in fact a yacht for vacations in the Baltic. Much of the press seems to be wagging a finger about BSI recommendations, calling the passwords weak. … Continue reading Berlin... <a href="https://www.flyingpenguin.com/berlin-senate-passwort-docx-breach-ahab-of-the-east-sea-cover-story/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MY TAKE: ChatGPT’s five-hour outage coincided with a model retirement its incident record omits]]></title>
<description><![CDATA[Millions of people rely on ChatGPT Work. For more than five hours Monday, it would not run. I was one of the people watching it fail. The trouble began at 8:04 a.m. Pacific and ran through the heart of the American workday. OpenAI declared recovery at 1:28 p.m. Its incident record lists elevated ...]]></description>
<link>https://tsecurity.de/de/3930775/ai-nachrichten/my-take-chatgpts-five-hour-outage-coincided-with-a-model-retirement-its-incident-record-omits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930775/ai-nachrichten/my-take-chatgpts-five-hour-outage-coincided-with-a-model-retirement-its-incident-record-omits/</guid>
<pubDate>Tue, 01 Sep 2026 23:34:44 +0200</pubDate>
<content:encoded><![CDATA[<p>Millions of people rely on ChatGPT Work. For more than five hours Monday, it would not run. I was one of the people watching it fail. The trouble began at 8:04 a.m. Pacific and ran through the heart of the American workday. OpenAI declared recovery at 1:28 p.m. Its incident record lists elevated latency, elevated errors, a mitigation and a... <a href="https://www.lastwatchdog.com/my-take-chatgpts-five-hour-outage-coincided-with-a-model-retirement-its-incident-record-omits/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Applying Zero Trust Principles to Agents - Kieran Human - ASW #397]]></title>
<description><![CDATA[Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate to successful in practice. Kieran Human talks about some of the properties tha...]]></description>
<link>https://tsecurity.de/de/3930774/malware-trojaner-viren/applying-zero-trust-principles-to-agents-kieran-human-asw-397/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930774/malware-trojaner-viren/applying-zero-trust-principles-to-agents-kieran-human-asw-397/</guid>
<pubDate>Tue, 01 Sep 2026 23:34:37 +0200</pubDate>
<content:encoded><![CDATA[<p>Sandboxing, least privilege, and monitoring are well-established controls in terms of the defenses they provide against unexpected and unauthorized actions. But being well-established in theory doesn't always translate to successful in practice. Kieran Human talks about some of the properties that a good sandbox should have and how monitoring creates a feedback loop to refine allow lists and access controls. In practice, the potential unpredictable behavior of an agent isn't much different from malware. We talk through some of the ways orgs can securely deploy agents without unnecessarily increasing their attack surface.</p> <p>Resources</p> <ul> <li><a rel="noopener" target="_blank" href="https://www.threatlocker.com/blog/the-principle-of-least-privilege-for-ai-agents"> https://www.threatlocker.com/blog/the-principle-of-least-privilege-for-ai-agents</a></li> <li><a rel="noopener" target="_blank" href="https://www.threatlocker.com/blog/applying-threatlocker-to-agentic-ai-tools"> https://www.threatlocker.com/blog/applying-threatlocker-to-agentic-ai-tools</a></li> <li><a rel="noopener" target="_blank" href="https://www.threatlocker.com/blog/why-the-five-eyes-alliance-sees-zero-trust-as-the-best-defense-against-agentic-ai-threats"> https://www.threatlocker.com/blog/why-the-five-eyes-alliance-sees-zero-trust-as-the-best-defense-against-agentic-ai-threats</a></li> </ul> <p>This interview is sponsored by ThreatLocker. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/threatlocker">https://securityweekly.com/threatlocker</a> to learn more about them!</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/asw">https://www.securityweekly.com/asw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/asw-397">https://securityweekly.com/asw-397</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Connecting Cyber Risks to Board Outcomes & BHUSA interviews from Mimecast & Zscaler - Leslie Nielsen, Brett Stone-Gross, Dan Bowden - BSW #462]]></title>
<description><![CDATA[The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasingly comes from thi...]]></description>
<link>https://tsecurity.de/de/3930773/malware-trojaner-viren/connecting-cyber-risks-to-board-outcomes-bhusa-interviews-from-mimecast-zscaler-leslie-nielsen-brett-stone-gross-dan-bowden-bsw-462/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930773/malware-trojaner-viren/connecting-cyber-risks-to-board-outcomes-bhusa-interviews-from-mimecast-zscaler-leslie-nielsen-brett-stone-gross-dan-bowden-bsw-462/</guid>
<pubDate>Tue, 01 Sep 2026 23:34:35 +0200</pubDate>
<content:encoded><![CDATA[<p>The threat landscape has become more interconnected, disruptive, and complex. Ransomware is now as much about extortion and data theft as it is about encryption. Supply chain events can create outages that ripple far beyond the initial target, and business interruption increasingly comes from third-party and cloud dependencies. How should CISOs prepare for these scenarios?</p> <p>Dan Bowden, Global Business CISO at Marsh, joins Business Security Weekly to discuss how to connect cyber risk to the outcomes boards care about most: resilience, financial exposure, regulatory impact, and reputation. CISOs need to position cyber as an enterprise risk, not a technical risk, that can be measured, prioritized, and managed alongside other strategic risks. Dan will discuss the results of Marsh's Cyber Catalyst research and Global Cyber Claims Report.</p> <p>Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/infosecworld2026">https://securityweekly.com/infosecworld2026</a> and save 30% on your ISW pass with code: ISW26-SWSAVINGS</p> <p>The Agent Is the New Insider: Why Human Risk Doesn't Stop at People: Black Hat Interview with Leslie Nielson, CISO at Mimecast</p> <p>AI agents now act with the same credentials and access as the humans who deployed them, but without the judgment or accountability that comes with actual employment. Mimecast CISO Leslie Nielsen argues that treating agentic AI as a brand new, standalone security category is the wrong instinct: agents are an extension of human risk, and the controls organizations already use to manage people are the right foundation for managing machines. In this conversation, Nielsen unpacks the growing gap between security leaders who expect AI driven attacks and those who feel prepared for them, and what that gap means for CISOs walking the floor at Black Hat.</p> <p>Segment Resources:</p> <p>Mimecast's new whitepaper Securing The Agentic Enterprise: <a rel="noopener" target="_blank" href="https://assets.mimecast.com/api/public/content/securing-the-agentic-enterprise?v=ea66db05"> https://assets.mimecast.com/api/public/content/securing-the-agentic-enterprise?v=ea66db05</a> Mimecast's landing page for thought leadership resources: <a rel="noopener" target="_blank" href="https://www.workprotected.com/">https://www.workprotected.com/</a> Mimecast's State of Human Risk Report: <a rel="noopener" target="_blank" href="https://www.mimecast.com/resources/ebooks/state-of-human-risk/">https://www.mimecast.com/resources/ebooks/state-of-human-risk/</a> Mimecast's Threat Intelligence Hub: <a rel="noopener" target="_blank" href="https://www.mimecast.com/threat-intelligence-hub/">https://www.mimecast.com/threat-intelligence-hub/</a></p> <p>For more information about Mimecast please visit: <a rel="noopener" target="_blank" href="https://securityweekly.com/mimecastbh">https://securityweekly.com/mimecastbh</a></p> <p>Ransomware Moves up the Org Chart: Managers Are Prime Targets: Black Hat Interview with Brett Stone-Gross, Sr. Director, Threat Intelligence at Zscaler</p> <p>When a ransomware attack makes headlines, attention usually turns to the organization that was breached, the systems encrypted, data stolen, and disruption or ransom demand that followed. Less, if anything, is revealed about the employees compromised at the start of the attack, and what makes those individuals valuable targets.</p> <p>New Zscaler ThreatLabz research examines this early stage of a real-world ransomware attack. ThreatLabz identified victims of a campaign associated with a ransomware group known for gaining initial access, stealing large amounts of corporate data, and selectively encrypting critical systems. The findings show who those victims were and how their roles and authority could help an attacker move deeper into an organization.</p> <p>This is part of ongoing ransomware research by ThreatLabz. The Zscaler ThreatLabz 2026 Ransomware Report, coming in the next two months, will include additional data on ransomware victims, the latest ransomware trends, targets, and tactics, and the risks enterprises should prepare for next.</p> <p>This segment is sponsored by Zscaler. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/zscalerbh">https://securityweekly.com/zscalerbh</a> to learn more about them!</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/bsw">https://www.securityweekly.com/bsw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/bsw-462">https://securityweekly.com/bsw-462</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hacking All The Devices, with AI? - Rob Allen - PSW #941]]></title>
<description><![CDATA[Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do. This segment is sponsored by ThreatLocker. Visit https://securityweekly.com/threatlocker to learn more about them! In the secu...]]></description>
<link>https://tsecurity.de/de/3930772/sicherheitsluecken/hacking-all-the-devices-with-ai-rob-allen-psw-941/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930772/sicherheitsluecken/hacking-all-the-devices-with-ai-rob-allen-psw-941/</guid>
<pubDate>Tue, 01 Sep 2026 23:34:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Rob Allen from ThreatLocker joins us to discuss securing agentic AI with zero-trust controls, least privilege, and access controls to limit what agents can access and do.</p> <p>This segment is sponsored by ThreatLocker. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/threatlocker">https://securityweekly.com/threatlocker</a> to learn more about them!</p> <p>In the security news this week:</p> <ul> <li>Sixteen-year-old Linux LPEs still work</li> <li>Ubiquiti UniFi, patch it, also light on details</li> <li>If you remember magicJack, you too are old</li> <li>Slovakia doesn't trust its own speed cameras</li> <li>More homework on NIST's vulnerability database</li> <li>Your webcam, mic, and key light, all owned</li> <li>Printer moonlights as Minecraft server</li> <li>Zombie credit cards</li> <li>Your car's infotainment system fuels botnets</li> <li>Feds warn about AI-powered PLC attacks</li> <li>Can an AI actually reverse engineer its way out?</li> <li>Denver International's security breach, volume six</li> <li>Charlotte's breach and a parking company</li> <li>Why your ancient tech might be the safe one</li> <li>Microsoft counts billions of phishing emails</li> <li>A password vault that leaked to any website</li> <li>Australia sells password books at the post office</li> <li>Another perfect ten, this time in Entra ID</li> <li>Cisco's bug scores read like Olympic gymnastics</li> </ul> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/psw">https://www.securityweekly.com/psw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/psw-941">https://securityweekly.com/psw-941</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Life as a CISO in Hollywood: Keeping New Films Leak-Free & 4 Black Hat Interviews - Dan Meacham, Ellen Boehm, Ronan Murphy, Frank Vukovits, John Hultquist - ESW #474]]></title>
<description><![CDATA[Interview with Dan Meacham, CISO at Legendary Entertainment Dan Meacham joined us to share a preview of his leadership panel at InfoSec World. At this CRA event in October, Dan will be discussing The Augmented Defender - What AI Actually Changes on the Front Line with Daniel Bowden, the Global CI...]]></description>
<link>https://tsecurity.de/de/3930771/sicherheitsluecken/life-as-a-ciso-in-hollywood-keeping-new-films-leak-free-4-black-hat-interviews-dan-meacham-ellen-boehm-ronan-murphy-frank-vukovits-john-hultquist-esw-474/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930771/sicherheitsluecken/life-as-a-ciso-in-hollywood-keeping-new-films-leak-free-4-black-hat-interviews-dan-meacham-ellen-boehm-ronan-murphy-frank-vukovits-john-hultquist-esw-474/</guid>
<pubDate>Tue, 01 Sep 2026 23:34:32 +0200</pubDate>
<content:encoded><![CDATA[Interview with Dan Meacham, CISO at Legendary Entertainment <p>Dan Meacham joined us to share a preview of his leadership panel at InfoSec World. At this CRA event in October, Dan will be discussing <em>The Augmented Defender - What AI Actually Changes on the Front Line</em> with Daniel Bowden, the Global CISO at Marsh.</p> <p>Dan dives into the unique world of securing data and assets when film production is largely handled by partners and contractors, working from systems you'll likely have limited access to and definitely can't install agents on. It's a fascinating conversation you should check out!</p> <p>Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/infosecworld2026">https://securityweekly.com/infosecworld2026</a> and save 30% on your ISW pass with code: ISW26-SWSAVINGS</p> Black Hat Interview 1 - Google Cloud <p>Outpacing the Adversary with AI Threat Defense - Black Hat interview with John Hultquist, Chief Analyst, Google Threat Intelligence Group at Google</p> <p>The cybersecurity landscape is undergoing a radical shift. AI is no longer just a productivity accelerator for developers and analysts—it has become actively weaponized by sophisticated threat actors to discover and exploit vulnerabilities at unprecedented speed. We'll discuss Google's own approach to combating today's threats and the need for security teams to transform vulnerability management with machine-speed defense.</p> <p>Segment Resources:</p> <ul> <li><a rel="noopener" target="_blank" href="https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense"> https://cloud.google.com/blog/products/identity-security/introducing-google-ai-threat-defense</a></li> <li><a rel="noopener" target="_blank" href="https://services.google.com/fh/files/misc/ebook_google_cloud_security_ai_threat_defense.pdf"> https://services.google.com/fh/files/misc/ebook<em>google</em>cloud<em>security</em>ai<em>threat</em>defense.pdf</a></li> <li><a rel="noopener" target="_blank" href="https://services.google.com/fh/files/misc/white_paper_combating_ai_driven_threats_google_machine_speed_defense.pdf"> https://services.google.com/fh/files/misc/white<em>paper</em>combating<em>ai</em>driven<em>threats</em>google<em>machine</em>speed_defense.pdf</a></li> </ul> <p>This segment is sponsored by Google Cloud. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/googlebh">https://securityweekly.com/googlebh</a> to learn more!</p> Black Hat Interview 2 - Forcepoint <p>Decoding Agentic: Securing the Data Layer AI Just Set on Fire - Black Hat interview with Ronan Murphy, Chief Data Strategy Officer of Forcepoint</p> <p>AI didn't ask permission — and it permanently changed what data risk looks like. Forcepoint Chief Data Strategy officer and member of the Artificial Intelligence Advisory Council in Ireland, shares insights on a clear call to action for agentic enterprises: stop locking AI down and start securing it where the risk actually lives, in the data itself. Learn why data trust is the foundation of the agentic era and how the world's leading enterprises are ending the false choice between AI innovation and data safety.</p> <p>Segment Resources:</p> <ul> <li><a rel="noopener" target="_blank" href="https://www.forcepoint.com/resources/ebooks/enterprise-guide-ai-data-security"> https://www.forcepoint.com/resources/ebooks/enterprise-guide-ai-data-security</a></li> <li><a rel="noopener" target="_blank" href="https://www.forcepoint.com/blog/insights/forcepoint-announces-ai-data-security"> https://www.forcepoint.com/blog/insights/forcepoint-announces-ai-data-security</a></li> </ul> <p>This segment is sponsored by Forcepoint. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/forcepointbh">https://securityweekly.com/forcepointbh</a> to learn more!</p> Black Hat Interview 3 - Keyfactor <p>From Secrets to Verified Workload Identity—at Enterprise Scale - Black Hat interview with Ellen Boehm, SVP, Strategy &amp; AI Innovation at Keyfactor</p> <p>As AI agents become autonomous participants inside enterprise environments, organizations can no longer rely on static credentials and traditional identity models to establish trust. Enterprise AI is driving a shift from possession-based access to cryptographically verified identity, as AI agents, cloud-native workloads, and automated services increasingly make decisions and interact with critical systems. In this discussion, we'll discuss why organizations need to continuously establish trust, govern machine identities and cryptography, and build a resilient foundation for securing AI across increasingly dynamic environments.</p> <p>Segment Resources:</p> <ul> <li><a rel="noopener" target="_blank" href="https://www.keyfactor.com/blog/ai-agents-the-identity-problem-nobody-owns-yet/"> https://www.keyfactor.com/blog/ai-agents-the-identity-problem-nobody-owns-yet/</a></li> <li><a rel="noopener" target="_blank" href="https://www.keyfactor.com/education-center/what-is-trust-infrastructure/"> https://www.keyfactor.com/education-center/what-is-trust-infrastructure/</a></li> <li><a rel="noopener" target="_blank" href="https://www.keyfactor.com/resources/topic/col/products/the-trust-control-plane?pflpid=60788&amp;pfsid=HsCXvwPWB1"> https://www.keyfactor.com/resources/topic/col/products/the-trust-control-plane?pflpid=60788&amp;pfsid=HsCXvwPWB1</a></li> </ul> <p>This segment is sponsored by Keyfactor. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/keyfactorbh">https://securityweekly.com/keyfactorbh</a> to learn more!</p> Black Hat Interview 4 - Delinea <p>Delinea Delivers Runtime Authorization for AI Agents, Closing Access Control Gap - Black Hat interview with Frank Vukovits, Chief Security Scientist at Delinea</p> <p>As AI agents move from experiments to autonomous operators inside production databases, cloud consoles, and Kubernetes clusters, enterprises face a new problem: agents with legitimate credentials taking actions no one authorized. Frank breaks down why verifying access at connection time is no longer enough and what it takes to enforce policy on every agent action before it executes. He explains how runtime authorization closes the gap between hiding credentials and actually controlling what agents do once they're inside a session.</p> <p>This segment is sponsored by Delinea. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/delineabh">https://securityweekly.com/delineabh</a> to learn more!</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/esw">https://www.securityweekly.com/esw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/esw-474">https://securityweekly.com/esw-474</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fixing Software Weaknesses Rather Than Just Finding More Flaws - Gil Geron, Nidhi Aggarwal, Braden Russell - ASW #398]]></title>
<description><![CDATA[AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that or...]]></description>
<link>https://tsecurity.de/de/3930770/sicherheitsluecken/fixing-software-weaknesses-rather-than-just-finding-more-flaws-gil-geron-nidhi-aggarwal-braden-russell-asw-398/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930770/sicherheitsluecken/fixing-software-weaknesses-rather-than-just-finding-more-flaws-gil-geron-nidhi-aggarwal-braden-russell-asw-398/</guid>
<pubDate>Tue, 01 Sep 2026 23:34:25 +0200</pubDate>
<content:encoded><![CDATA[<p>AppSec has always emphasized techniques and tools for discovering vulns, along with taxonomies and lists for describing them. But just piling up more CVEs into a prioritized patching queue has never been an effective strategy. Nidhi Aggarwal talks about some of the economics and decisions that orgs evaluate when figuring out how to improve and protect their software. LLMs might be effective assistants in generating code, but only when they have the context of secure patterns to follow. We also talk about what some of the bug bounty data reveals in terms of successful researchers finding more impactful vulns and why the combination of domain expertise and curiosity remains profitable.</p> <p>Segment Resources</p> <ul> <li><a rel="noopener" target="_blank" href="https://www.hackerone.com/blog/finding-fast-fixing-slow-rising-exposure-debt"> https://www.hackerone.com/blog/finding-fast-fixing-slow-rising-exposure-debt</a></li> </ul> <p>Vulnerability discovery and remediation gap in the AI era</p> <p>AI-generated code is changing how vulnerabilities are created, discovered, and managed. This segment explores why finding more vulnerabilities doesn't necessarily mean reducing exposure, how teams can validate exploitability and prioritize real risk, and where agentic AI can support defenders without replacing human security expertise. It also looks at what continuous threat exposure management means for enterprise security teams in practice.</p> <p>Everyone's a Builder Now: Securing the AI-Powered Enterprise: Black Hat Interview with Gil Geron, CEO of Orca Security</p> <p>AI is fundamentally changing software development, turning employees across the business into builders and reshaping how organizations think about innovation and risk. In this session, Orca Security CEO Gil Geron explores what this shift means for enterprise leaders and why security must evolve alongside the next generation of AI-powered software creation.</p> <p>Segment Resources:</p> <ul> <li><a rel="noopener" target="_blank" href="https://orca.security/resources/press-releases/orca-security-extends-its-platform-to-the-new-generation-of-ai-builders/"> https://orca.security/resources/press-releases/orca-security-extends-its-platform-to-the-new-generation-of-ai-builders/</a></li> <li><a rel="noopener" target="_blank" href="https://orca.security/platform/ai-appgen-security/">https://orca.security/platform/ai-appgen-security/</a></li> </ul> <p>This segment is sponsored by Orca Security. Visit <a rel="noopener" target="_blank" href="https://securityweekly.com/orcabh">https://securityweekly.com/orcabh</a> to learn more about them!</p> <p>Bugcrowd Launches Pathseeker: Flipping the Script on Traditional Pentesting: Black Hat Interview with Braden Russell, CTO of Bugcrowd</p> <p>Bugcrowd is launching Savant Pathseeker, the first product in its new Agentic Offensive Testing line, which combines continuous agentic pentesting with on-demand human validation. The launch comes as the security industry grapples with a growing "AI slop" problem, where unchecked AI-generated vulnerability reports have overwhelmed bug bounty programs and even forced some, like Curl, to shut theirs down. Braden will unpack how Bugcrowd is positioning Savant Pathseeker as a response to that industry-wide trust problem, not just a new product launch.</p> <p>Segment Resources:</p> <ul> <li><a rel="noopener" target="_blank" href="https://www.bugcrowd.com/products/pathseeker/">https://www.bugcrowd.com/products/pathseeker/</a></li> <li><a rel="noopener" target="_blank" href="https://www.bugcrowd.com/press-release/bugcrowd-introduces-savant-pathseeker-delivering-continuous-agentic-pentesting-across-the-attack-surface/"> https://www.bugcrowd.com/press-release/bugcrowd-introduces-savant-pathseeker-delivering-continuous-agentic-pentesting-across-the-attack-surface/</a></li> <li><a rel="noopener" target="_blank" href="https://www.bugcrowd.com/products/platform">https://www.bugcrowd.com/products/platform</a></li> <li><a rel="noopener" target="_blank" href="https://www.bugcrowd.com/products/ai-powered-security-intelligence/"> https://www.bugcrowd.com/products/ai-powered-security-intelligence/</a></li> </ul> <p>Apply for early access at <a rel="noopener" target="_blank" href="https://securityweekly.com/bugcrowdbh">https://securityweekly.com/bugcrowdbh</a></p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/asw">https://www.securityweekly.com/asw</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/asw-398">https://securityweekly.com/asw-398</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Victorians, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Aaran Leyland - SWN #612]]></title>
<description><![CDATA[Victorian Bug Bounties, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Nimbus Manticore, Isambard Kingdom Brunel, Rote Tod, Aaran Leyland, and More on the Security Weekly News. Visit https://www.securityweekly.com/swn for all the latest episodes! Show Notes: https://securityweekly.co...]]></description>
<link>https://tsecurity.de/de/3930769/it-security-nachrichten/victorians-tonic-revstealer-fireant-openclaw-powershell-superbox-aaran-leyland-swn-612/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930769/it-security-nachrichten/victorians-tonic-revstealer-fireant-openclaw-powershell-superbox-aaran-leyland-swn-612/</guid>
<pubDate>Tue, 01 Sep 2026 23:34:24 +0200</pubDate>
<content:encoded><![CDATA[<p>Victorian Bug Bounties, TONIC, RevStealer, Fireant, OpenClaw, PowerShell, SuperBox, Nimbus Manticore, Isambard Kingdom Brunel, Rote Tod, Aaran Leyland, and More on the Security Weekly News.</p> <p>Visit <a rel="noopener" target="_blank" href="https://www.securityweekly.com/swn">https://www.securityweekly.com/swn</a> for all the latest episodes!</p> <p>Show Notes: <a rel="noopener" target="_blank" href="https://securityweekly.com/swn-612">https://securityweekly.com/swn-612</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Generative AI: This Is How You Can Use ChatGPT Safely]]></title>
<description><![CDATA[Generative AI has now become a tool of the day-to-day. It is used by people to plan trips, explain hard ideas, write e-mail, to take notes and to explore new topics. There is a benefit to that convenience, but there's also a responsibility. A chatbot can give confident answers that are incomplete...]]></description>
<link>https://tsecurity.de/de/3930768/ai-nachrichten/generative-ai-this-is-how-you-can-use-chatgpt-safely/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930768/ai-nachrichten/generative-ai-this-is-how-you-can-use-chatgpt-safely/</guid>
<pubDate>Tue, 01 Sep 2026 23:34:15 +0200</pubDate>
<content:encoded><![CDATA[<p>Generative AI has now become a tool of the day-to-day. It is used by people to plan trips, explain hard ideas, write e-mail, to take notes and to explore new topics. There is a benefit to that convenience, but there&#039;s also a responsibility. A chatbot can give confident answers that are incomplete, out-of-date and wrong. AI can receive information... <a href="https://www.cm-alliance.com/cybersecurity-blog/generative-ai-this-is-how-you-can-use-chatgpt-safely" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Major Cyber Attacks, Data Breaches, Ransomware Attacks in August 2026]]></title>
<description><![CDATA[August 2026 saw cyber threats cut across an unusually diverse range of sectors, from logistics and financial services to healthcare, government and critical infrastructure. Major incidents involving CEVA Logistics, the French Tax Authority, Sakura Internet, RingCentral, SafePal, CareCloud and Apo...]]></description>
<link>https://tsecurity.de/de/3930767/malware-trojaner-viren/major-cyber-attacks-data-breaches-ransomware-attacks-in-august-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930767/malware-trojaner-viren/major-cyber-attacks-data-breaches-ransomware-attacks-in-august-2026/</guid>
<pubDate>Tue, 01 Sep 2026 23:34:13 +0200</pubDate>
<content:encoded><![CDATA[<p>August 2026 saw cyber threats cut across an unusually diverse range of sectors, from logistics and financial services to healthcare, government and critical infrastructure. Major incidents involving CEVA Logistics, the French Tax Authority, Sakura Internet, RingCentral, SafePal, CareCloud and Apollo Global Management demonstrated that both large... <a href="https://www.cm-alliance.com/cybersecurity-blog/major-cyber-attacks-data-breaches-ransomware-attacks-in-august-2026" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Understanding the Impact of Ransomware on Businesses]]></title>
<description><![CDATA[Ransomware is a huge digital threat to companies today. Hackers use this bad software to lock your files and demand money. If you do not pay them, you lose your data forever. Over the past few years, these attacks have become much worse. Attackers now steal confidential files before locking your ...]]></description>
<link>https://tsecurity.de/de/3930766/malware-trojaner-viren/understanding-the-impact-of-ransomware-on-businesses/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930766/malware-trojaner-viren/understanding-the-impact-of-ransomware-on-businesses/</guid>
<pubDate>Tue, 01 Sep 2026 23:33:57 +0200</pubDate>
<content:encoded><![CDATA[<p>Ransomware is a huge digital threat to companies today. Hackers use this bad software to lock your files and demand money. If you do not pay them, you lose your data forever. Over the past few years, these attacks have become much worse. Attackers now steal confidential files before locking your computer screen. They threaten […] The post... <a href="https://secureblitz.com/understanding-the-impact-of-ransomware-on-businesses/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI’s Apple Messages Tool Raises Privacy Concerns Over Decrypted Chats]]></title>
<description><![CDATA[OpenAI recently introduced a new Apple Messages plugin for its desktop application on Mac computers. This tool allows ChatGPT to connect with conversations at work as well as at home in the Messages app. It also allows users to request information from the AI, such as looking up previous chat his...]]></description>
<link>https://tsecurity.de/de/3930765/ai-nachrichten/openais-apple-messages-tool-raises-privacy-concerns-over-decrypted-chats/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930765/ai-nachrichten/openais-apple-messages-tool-raises-privacy-concerns-over-decrypted-chats/</guid>
<pubDate>Tue, 01 Sep 2026 23:33:38 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI recently introduced a new Apple Messages plugin for its desktop application on Mac computers. This tool allows ChatGPT to connect with conversations at work as well as at home in the Messages app. It also allows users to request information from the AI, such as looking up previous chat history, summarizing large texts, and […] The post... <a href="https://privacysavvy.com/news/privacy/openai-apple-messages-tool-privacy-concerns/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android 17 Adds New Security Controls to Protect Users on Wi-Fi and Mobile Networks]]></title>
<description><![CDATA[Google has added several network security features to Android 17 that give users more privacy when they use Wi-Fi, browse the web or connect to mobile networks. The changes cover local network access, web traffic, digital certificates and older cellular networks. Together, they aim to limit what ...]]></description>
<link>https://tsecurity.de/de/3930764/it-security-nachrichten/android-17-adds-new-security-controls-to-protect-users-on-wi-fi-and-mobile-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930764/it-security-nachrichten/android-17-adds-new-security-controls-to-protect-users-on-wi-fi-and-mobile-networks/</guid>
<pubDate>Tue, 01 Sep 2026 23:33:24 +0200</pubDate>
<content:encoded><![CDATA[<p>Google has added several network security features to Android 17 that give users more privacy when they use Wi-Fi, browse the web or connect to mobile networks. The changes cover local network access, web traffic, digital certificates and older cellular networks. Together, they aim to limit what apps, network operators and attackers can learn... <a href="https://privacysavvy.com/news/cybersecurity/android-17-security-controls-wifi-mobile-networks/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Meet Manic: The Android Malware With a Sneaky Backup Plan]]></title>
<description><![CDATA[Every so often a piece of malware comes along with a trick clever enough to make security researchers pause and take note. Manic is one of those. It’s a new Android threat, and it does something most malware never bothers with. When an infected phone loses internet access, Manic finds a way to ke...]]></description>
<link>https://tsecurity.de/de/3930763/malware-trojaner-viren/meet-manic-the-android-malware-with-a-sneaky-backup-plan/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930763/malware-trojaner-viren/meet-manic-the-android-malware-with-a-sneaky-backup-plan/</guid>
<pubDate>Tue, 01 Sep 2026 23:33:19 +0200</pubDate>
<content:encoded><![CDATA[<p>Every so often a piece of malware comes along with a trick clever enough to make security researchers pause and take note. Manic is one of those. It’s a new Android threat, and it does something most malware never bothers with. When an infected phone loses internet access, Manic finds a way to keep stealing anyway. It’s criminal behaviors include... <a href="https://cyberhoot.com/blog/meet-manic-the-android-malware-with-a-sneaky-backup-plan/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical GiveWP Flaw Lets Attackers Run Commands on WordPress Servers]]></title>
<description><![CDATA[A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.16.7.2 fixes the PHP object injection chain. A critical vulnerability in GiveWP, one of the most widely used WordPress plugins for online donations and fundraising, can let an unauthenticated attacker execute...]]></description>
<link>https://tsecurity.de/de/3930762/sicherheitsluecken/critical-givewp-flaw-lets-attackers-run-commands-on-wordpress-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930762/sicherheitsluecken/critical-givewp-flaw-lets-attackers-run-commands-on-wordpress-servers/</guid>
<pubDate>Tue, 01 Sep 2026 23:33:05 +0200</pubDate>
<content:encoded><![CDATA[<p>A critical GiveWP flaw lets unauthenticated attackers execute server commands. Version 4.16.7.2 fixes the PHP object injection chain. A critical vulnerability in GiveWP, one of the most widely used WordPress plugins for online donations and fundraising, can let an unauthenticated attacker execute commands on the server. Patchstack disclosed the... <a href="https://securityaffairs.com/198156/security/critical-givewp-flaw-lets-attackers-run-commands-on-wordpress-servers.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Infostealers Are Hijacking Claude Sessions and Draining Subscriptions]]></title>
<description><![CDATA[Infostealers can steal active Claude sessions, bypass 2FA and drain paid usage. Anthropic is revoking access and refunding unauthorized charges. Anthropic confirmed that several infostealer malware can hijack an active Claude login session and let attackers burn through your usage without ever to...]]></description>
<link>https://tsecurity.de/de/3930761/malware-trojaner-viren/infostealers-are-hijacking-claude-sessions-and-draining-subscriptions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930761/malware-trojaner-viren/infostealers-are-hijacking-claude-sessions-and-draining-subscriptions/</guid>
<pubDate>Tue, 01 Sep 2026 23:33:03 +0200</pubDate>
<content:encoded><![CDATA[<p>Infostealers can steal active Claude sessions, bypass 2FA and drain paid usage. Anthropic is revoking access and refunding unauthorized charges. Anthropic confirmed that several infostealer malware can hijack an active Claude login session and let attackers burn through your usage without ever touching your password. “Our investigation is ongoing.... <a href="https://securityaffairs.com/198166/ai/infostealers-are-hijacking-claude-sessions-and-draining-subscriptions.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ValleyRAT: When Legitimate Software Becomes a Malware Delivery Tool]]></title>
<description><![CDATA[ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something much more ordinary: an app...]]></description>
<link>https://tsecurity.de/de/3930760/malware-trojaner-viren/valleyrat-when-legitimate-software-becomes-a-malware-delivery-tool/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930760/malware-trojaner-viren/valleyrat-when-legitimate-software-becomes-a-malware-delivery-tool/</guid>
<pubDate>Tue, 01 Sep 2026 23:33:01 +0200</pubDate>
<content:encoded><![CDATA[<p>ValleyRAT hides behind legitimate adware, using DLL sideloading to evade detection, steal data and give Silver Fox control of infected systems. ValleyRAT doesn’t always need to disguise itself as a cracked game or a fake browser update. It can also hide behind something much more ordinary: an application that looks like adware and appears to serve... <a href="https://securityaffairs.com/198191/security/valleyrat-when-legitimate-software-becomes-a-malware-delivery-tool.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[U.S. CISA adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog]]></title>
<description><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-202...]]></description>
<link>https://tsecurity.de/de/3930759/sicherheitsluecken/us-cisa-adds-papercut-ngmf-flaws-to-its-known-exploited-vulnerabilities-catalog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930759/sicherheitsluecken/us-cisa-adds-papercut-ngmf-flaws-to-its-known-exploited-vulnerabilities-catalog/</guid>
<pubDate>Tue, 01 Sep 2026 23:33:00 +0200</pubDate>
<content:encoded><![CDATA[<p>U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds PaperCut NG/MF flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-81578 (CVSS score of 8.8) PaperCut NG/MF Missing... <a href="https://securityaffairs.com/198200/security/u-s-cisa-adds-papercut-ng-mf-flaws-to-its-known-exploited-vulnerabilities-catalog.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chaotic Eclipse Releases Kaspersky Zero-Day HardBreacher]]></title>
<description><![CDATA[Chaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targetin...]]></description>
<link>https://tsecurity.de/de/3930758/sicherheitsluecken/chaotic-eclipse-releases-kaspersky-zero-day-hardbreacher/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930758/sicherheitsluecken/chaotic-eclipse-releases-kaspersky-zero-day-hardbreacher/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:58 +0200</pubDate>
<content:encoded><![CDATA[<p>Chaotic Eclipse released HardBreacher, a PoC exploit for a Kaspersky Endpoint Security privilege escalation flaw, adding another zero-day to his list. Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting Kaspersky Endpoint Security. The researcher named... <a href="https://securityaffairs.com/198214/hacking/chaotic-eclipse-releases-kaspersky-zero-day-hardbreacher.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Chaotic Eclipse Releases GenDigital Avast Antivirus ZeroDay PrettyPrague]]></title>
<description><![CDATA[Chaotic Eclipse released PrettyPrague, a PoC exploit for a GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting GenDigital Avast ...]]></description>
<link>https://tsecurity.de/de/3930757/sicherheitsluecken/chaotic-eclipse-releases-gendigital-avast-antivirus-zerodayprettyprague/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930757/sicherheitsluecken/chaotic-eclipse-releases-gendigital-avast-antivirus-zerodayprettyprague/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:57 +0200</pubDate>
<content:encoded><![CDATA[<p>Chaotic Eclipse released PrettyPrague, a PoC exploit for a GenDigital Avast Antivirus ZeroDay Elevation of Privileges Vulnerability Security researcher Chaotic Eclipse, also known as INFINITE NIGHTMARE, MSNightmare and Nightmare-Eclipse, released a new zero-day exploit targeting GenDigital Avast Antivirus. The researcher named the exploit... <a href="https://securityaffairs.com/198243/hacking/chaotic-eclipse-releases-gendigital-avast-antivirus-zeroday-prettyprague.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[9 Proofpoint alternatives. Pros & cons of the leading options]]></title>
<description><![CDATA[Proofpoint catches malicious traffic and blocks data exfiltration well, with solid coverage for business email compromise, phishing, and malware. But it’s built for the enterprise, and it shows. G2 reviewers flagged a steep learning curve and steep pricing, and suggested Proofpoint’s support woul...]]></description>
<link>https://tsecurity.de/de/3930756/malware-trojaner-viren/9-proofpoint-alternatives-pros-cons-of-the-leading-options/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930756/malware-trojaner-viren/9-proofpoint-alternatives-pros-cons-of-the-leading-options/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:52 +0200</pubDate>
<content:encoded><![CDATA[<p>Proofpoint catches malicious traffic and blocks data exfiltration well, with solid coverage for business email compromise, phishing, and malware. But it’s built for the enterprise, and it shows. G2 reviewers flagged a steep learning curve and steep pricing, and suggested Proofpoint’s support would need improving. The platform’s also in flux.... <a href="https://heimdalsecurity.com/blog/proofpoint-alternatives/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What the DfE’s cyber security update means for multi-academy trusts]]></title>
<description><![CDATA[Before dawn on 10 July 2024, one ransomware attack took down ten schools inside the same multi-academy trust at once. Every control that eventually stopped it was something the Department for Education’s own cyber security standard already asked for, well before the attack. That’s a case DfE has ...]]></description>
<link>https://tsecurity.de/de/3930755/malware-trojaner-viren/what-the-dfes-cyber-security-update-means-for-multi-academy-trusts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930755/malware-trojaner-viren/what-the-dfes-cyber-security-update-means-for-multi-academy-trusts/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:46 +0200</pubDate>
<content:encoded><![CDATA[<p>Before dawn on 10 July 2024, one ransomware attack took down ten schools inside the same multi-academy trust at once. Every control that eventually stopped it was something the Department for Education’s own cyber security standard already asked for, well before the attack. That’s a case DfE has published on its own Cyber Security Hub, […] The... <a href="https://heimdalsecurity.com/blog/dfe-cyber-standard-education-heimdal/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Claude Opus 5 app delivers malware and wipes its own tracks]]></title>
<description><![CDATA[A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that targets passwords, cryptocurrency wallet data and login credentials, according to Morphisec. Repository README using Claud...]]></description>
<link>https://tsecurity.de/de/3930754/malware-trojaner-viren/fake-claude-opus-5-app-delivers-malware-and-wipes-its-own-tracks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930754/malware-trojaner-viren/fake-claude-opus-5-app-delivers-malware-and-wipes-its-own-tracks/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A malicious GitHub repository impersonating Anthropic and claiming to offer free access to “Claude Opus 5” is delivering RevStealer, Windows information-stealing malware that targets passwords, cryptocurrency wallet data and login credentials, according to Morphisec. Repository README using Claude Opus 5 branding and a “Free” hook (Source:... <a href="https://www.helpnetsecurity.com/2026/09/01/revstealer-malware-claude-opus-5-github/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Vishing campaign abuses Microsoft Teams to give attackers a foothold in company networks]]></title>
<description><![CDATA[A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting remote access to their computers, according to Unit 42, Palo Alto Networks’ threat intelligence team. The campaign ran betwee...]]></description>
<link>https://tsecurity.de/de/3930753/malware-trojaner-viren/vishing-campaign-abuses-microsoft-teams-to-give-attackers-a-foothold-in-company-networks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930753/malware-trojaner-viren/vishing-campaign-abuses-microsoft-teams-to-give-attackers-a-foothold-in-company-networks/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:41 +0200</pubDate>
<content:encoded><![CDATA[<p>A coordinated voice-phishing (vishing) campaign, named Spring Ring, used fake IT support accounts on Microsoft Teams to trick employees into installing malware or granting remote access to their computers, according to Unit 42, Palo Alto Networks’ threat intelligence team. The campaign ran between January and April 2026 and reached more than 150... <a href="https://www.helpnetsecurity.com/2026/09/01/spring-ring-vishing-campaign-microsoft-teams/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA review makes the case for eliminating vulnerability classes]]></title>
<description><![CDATA[For years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely why attackers keep winning. The solution to this problem, they believe, is eliminating entire categories of weaknesses at the source. “By reduci...]]></description>
<link>https://tsecurity.de/de/3930752/sicherheitsluecken/cisa-review-makes-the-case-for-eliminating-vulnerability-classes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930752/sicherheitsluecken/cisa-review-makes-the-case-for-eliminating-vulnerability-classes/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:39 +0200</pubDate>
<content:encoded><![CDATA[<p>For years, the security industry has treated vulnerabilities as an endless queue of individual fixes. A recent CISA review argues that this is precisely why attackers keep winning. The solution to this problem, they believe, is eliminating entire categories of weaknesses at the source. “By reducing these root causes during software development,... <a href="https://www.helpnetsecurity.com/2026/09/01/cisa-on-eliminating-recurring-security-weaknesses/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Codex Download Uses Google Sites to Deliver macOS Malware]]></title>
<description><![CDATA[Fake Codex pages used Google Sites, sponsored search and ClickFix to target Mac users Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930751/malware-trojaner-viren/fake-codex-download-uses-google-sites-to-deliver-macos-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930751/malware-trojaner-viren/fake-codex-download-uses-google-sites-to-deliver-macos-malware/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:36 +0200</pubDate>
<content:encoded><![CDATA[<p>Fake Codex pages used Google Sites, sponsored search and ClickFix to target Mac users <a href="https://www.infosecurity-magazine.com/news/fake-codex-download-google-sites/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake Minecraft Clients Deliver WeedHack Malware Despite Infrastructure Takedown]]></title>
<description><![CDATA[A threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in July Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930750/malware-trojaner-viren/fake-minecraft-clients-deliver-weedhack-malware-despite-infrastructure-takedown/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930750/malware-trojaner-viren/fake-minecraft-clients-deliver-weedhack-malware-despite-infrastructure-takedown/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:35 +0200</pubDate>
<content:encoded><![CDATA[<p>A threat actor keeps spreading the WeedHack malware to Minecraft players despite its original infrastructure taken down in July <a href="https://www.infosecurity-magazine.com/news/fake-minecraft-weedhack-malware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Four in Five AI Tools Run with No IT Oversight, New Research Finds]]></title>
<description><![CDATA[Reco report reveals growing shadow AI problem and surge in vulnerability disclosures Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930749/sicherheitsluecken/four-in-five-ai-tools-run-with-no-it-oversight-new-research-finds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930749/sicherheitsluecken/four-in-five-ai-tools-run-with-no-it-oversight-new-research-finds/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:32 +0200</pubDate>
<content:encoded><![CDATA[<p>Reco report reveals growing shadow AI problem and surge in vulnerability disclosures <a href="https://www.infosecurity-magazine.com/news/four-in-five-ai-tools-no-it/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tortoiseshell Expands Malware Toolset With New Backdoor, SSH Tunnel]]></title>
<description><![CDATA[Group-IB uncovered new Tortoiseshell infrastructure, including a backdoor and SSH tunneling tool Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930748/malware-trojaner-viren/tortoiseshell-expands-malware-toolset-with-new-backdoor-ssh-tunnel/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930748/malware-trojaner-viren/tortoiseshell-expands-malware-toolset-with-new-backdoor-ssh-tunnel/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:30 +0200</pubDate>
<content:encoded><![CDATA[<p>Group-IB uncovered new Tortoiseshell infrastructure, including a backdoor and SSH tunneling tool <a href="https://www.infosecurity-magazine.com/news/tortoiseshell-new-backdoor-ssh/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI: Hugging Face Incident a “Warning Shot” to the World]]></title>
<description><![CDATA[OpenAI reveals that unauthorized message boards were at the heart of the recent Hugging Face breach Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930747/ai-nachrichten/openai-hugging-face-incident-a-warning-shot-to-the-world/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930747/ai-nachrichten/openai-hugging-face-incident-a-warning-shot-to-the-world/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:29 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI reveals that unauthorized message boards were at the heart of the recent Hugging Face breach <a href="https://www.infosecurity-magazine.com/news/openai-hugging-face-warning-shot/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Threat Actors Abuse Cursor Agent AI to Assist Ransomware Operations]]></title>
<description><![CDATA[Aurora ransomware operators are abusing SpaceX’s Cursor Agent AI tool to conduct tasks such as reconnaissance and exploitation activities Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930746/malware-trojaner-viren/threat-actors-abuse-cursor-agent-ai-to-assist-ransomware-operations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930746/malware-trojaner-viren/threat-actors-abuse-cursor-agent-ai-to-assist-ransomware-operations/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:26 +0200</pubDate>
<content:encoded><![CDATA[<p>Aurora ransomware operators are abusing SpaceX’s Cursor Agent AI tool to conduct tasks such as reconnaissance and exploitation activities <a href="https://www.infosecurity-magazine.com/news/abuse-cursor-agent-ransomware/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Window to Tackle Surge in AI-Enabled Cyber Attacks Narrowing, Tech Giants Warn]]></title>
<description><![CDATA[More than 100 companies, including OpenAI, Anthropic, Google and Microsoft, have urged collective action to unlock the power of AI to protect critical public services Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930745/ai-nachrichten/window-to-tackle-surge-in-ai-enabled-cyber-attacks-narrowing-tech-giants-warn/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930745/ai-nachrichten/window-to-tackle-surge-in-ai-enabled-cyber-attacks-narrowing-tech-giants-warn/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:25 +0200</pubDate>
<content:encoded><![CDATA[<p>More than 100 companies, including OpenAI, Anthropic, Google and Microsoft, have urged collective action to unlock the power of AI to protect critical public services <a href="https://www.infosecurity-magazine.com/news/window-ai-attacks-narrowing-tech/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Slopsquatting in the Supply Chain: Weaponized AI Hallucinations]]></title>
<description><![CDATA[In this interview with Snyk CTO Manoj Nair, we examine how attackers weaponize recurring LLM package hallucinations before developers even hit "run." Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930744/ai-nachrichten/slopsquatting-in-the-supply-chain-weaponized-ai-hallucinations/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930744/ai-nachrichten/slopsquatting-in-the-supply-chain-weaponized-ai-hallucinations/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:18 +0200</pubDate>
<content:encoded><![CDATA[<p>In this interview with Snyk CTO Manoj Nair, we examine how attackers weaponize recurring LLM package hallucinations before developers even hit &quot;run.&quot; <a href="https://www.govtech.com/blogs/lohrmann-on-cybersecurity/slopsquatting-in-the-supply-chain-weaponized-ai-hallucinations" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cursor customers will lose access to OpenAI coding models in November]]></title>
<description><![CDATA[OpenAI will stop AI coding platform Cursor from accessing its models from November 12, following the acquisition of Cursor parent Anysphere by Elon Musk‘s SpaceX. “Today, we notified SpaceX that we intend to wind down our contract providing OpenAI models to Cursor, with a proposed shutoff date of...]]></description>
<link>https://tsecurity.de/de/3930743/ai-nachrichten/cursor-customers-will-lose-access-to-openai-coding-models-in-november/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930743/ai-nachrichten/cursor-customers-will-lose-access-to-openai-coding-models-in-november/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:13 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI will stop AI coding platform Cursor from accessing its models from November 12, following the acquisition of Cursor parent Anysphere by Elon Musk‘s SpaceX. “Today, we notified SpaceX that we intend to wind down our contract providing OpenAI models to Cursor, with a proposed shutoff date of November 12, 2026,” the company wrote in a blog... <a href="https://www.cio.com/article/4216508/cursor-customers-will-lose-access-to-openai-coding-models-in-november-2.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ChatGPT for Teens Adds New Safeguards — but Safety Gaps Remain]]></title>
<description><![CDATA[ChatGPT for Teens adds stronger protections for users ages 13 to 17, but parents still face limits around monitoring, age prediction, and AI safety. The post ChatGPT for Teens Adds New Safeguards — but Safety Gaps Remain appeared first on TechRepublic. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930742/ai-nachrichten/chatgpt-for-teens-adds-new-safeguards-but-safety-gaps-remain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930742/ai-nachrichten/chatgpt-for-teens-adds-new-safeguards-but-safety-gaps-remain/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:06 +0200</pubDate>
<content:encoded><![CDATA[<p>ChatGPT for Teens adds stronger protections for users ages 13 to 17, but parents still face limits around monitoring, age prediction, and AI safety. The post ChatGPT for Teens Adds New Safeguards — but Safety Gaps Remain appeared first on TechRepublic. <a href="https://www.techrepublic.com/article/news-chatgpt-teens-safety-gaps/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Bans Russian ChatGPT Accounts Used in Covert Influence Campaign]]></title>
<description><![CDATA[OpenAI banned Russian ChatGPT accounts tied to a covert influence campaign involving copied research, fake attribution and coordinated social posts. The post OpenAI Bans Russian ChatGPT Accounts Used in Covert Influence Campaign appeared first on TechRepublic. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930741/ai-nachrichten/openai-bans-russian-chatgpt-accounts-used-in-covert-influence-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930741/ai-nachrichten/openai-bans-russian-chatgpt-accounts-used-in-covert-influence-campaign/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:04 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI banned Russian ChatGPT accounts tied to a covert influence campaign involving copied research, fake attribution and coordinated social posts. The post OpenAI Bans Russian ChatGPT Accounts Used in Covert Influence Campaign appeared first on TechRepublic. <a href="https://www.techrepublic.com/article/news-openai-russian-chatgpt-influence-campaign-emea/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake GTA 6 Demo Spreads Malware: How to Spot the Scam]]></title>
<description><![CDATA[There is no legitimate GTA 6 demo. Fake Rockstar sites are distributing Vidar malware that targets passwords, cookies, and logged-in browser sessions. The post Fake GTA 6 Demo Spreads Malware: How to Spot the Scam appeared first on TechRepublic. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930740/malware-trojaner-viren/fake-gta-6-demo-spreads-malware-how-to-spot-the-scam/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930740/malware-trojaner-viren/fake-gta-6-demo-spreads-malware-how-to-spot-the-scam/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:02 +0200</pubDate>
<content:encoded><![CDATA[<p>There is no legitimate GTA 6 demo. Fake Rockstar sites are distributing Vidar malware that targets passwords, cookies, and logged-in browser sessions. The post Fake GTA 6 Demo Spreads Malware: How to Spot the Scam appeared first on TechRepublic. <a href="https://www.techrepublic.com/article/news-fake-gta-6-demo-malware-scam/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gunra ransomware: what you need to know]]></title>
<description><![CDATA[The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930739/malware-trojaner-viren/gunra-ransomware-what-you-need-to-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930739/malware-trojaner-viren/gunra-ransomware-what-you-need-to-know/</guid>
<pubDate>Tue, 01 Sep 2026 23:32:00 +0200</pubDate>
<content:encoded><![CDATA[<p>The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog. <a href="https://www.fortra.com/blog/gunra-ransomware-what-you-need-know" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency]]></title>
<description><![CDATA[A hacker calling themselves "CYBERLEEK" has been leaking gameplay footage from GTA 6 ahead of its official reveal this week - but they're not asking Rockstar Games for a ransom. Instead, they've launched their own cryptocurrency, promising to release ever more juicy clips from a virtual strip clu...]]></description>
<link>https://tsecurity.de/de/3930738/podcasts/smashing-security-podcast-482-this-hacker-leaked-gta-6-and-launched-their-own-cryptocurrency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930738/podcasts/smashing-security-podcast-482-this-hacker-leaked-gta-6-and-launched-their-own-cryptocurrency/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:57 +0200</pubDate>
<content:encoded><![CDATA[<p>A hacker calling themselves &quot;CYBERLEEK&quot; has been leaking gameplay footage from GTA 6 ahead of its official reveal this week - but they&#039;re not asking Rockstar Games for a ransom. Instead, they&#039;ve launched their own cryptocurrency, promising to release ever more juicy clips from a virtual strip club... Meanwhile, your smart TV might be doing more... <a href="https://grahamcluley.com/smashing-security-podcast-482/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more]]></title>
<description><![CDATA[More than 1,000 organisations, 500,000 stolen credentials, and one self-propagating worm named after a Dune sandworm - two men now face charges over TeamPCP's global hacking spree. Read more in my article on the Hot for Security blog. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930737/ai-nachrichten/shai-hulud-hackers-two-men-charged-over-teampcps-global-supply-chain-crime-spree-that-hit-openai-and-thousands-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930737/ai-nachrichten/shai-hulud-hackers-two-men-charged-over-teampcps-global-supply-chain-crime-spree-that-hit-openai-and-thousands-more/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:52 +0200</pubDate>
<content:encoded><![CDATA[<p>More than 1,000 organisations, 500,000 stolen credentials, and one self-propagating worm named after a Dune sandworm - two men now face charges over TeamPCP&#039;s global hacking spree. Read more in my article on the Hot for Security blog. <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/shai-hulud-hackers-charged-teampcps" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Spyware for Babies]]></title>
<description><![CDATA[The New York Times has a long article (alt link) on surveillance systems aimed at babies. They are increasingly using AI. Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels of baby data collection are just the beginning. Nanit rec...]]></description>
<link>https://tsecurity.de/de/3930736/malware-trojaner-viren/spyware-for-babies/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930736/malware-trojaner-viren/spyware-for-babies/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:47 +0200</pubDate>
<content:encoded><![CDATA[<p>The New York Times has a long article (alt link) on surveillance systems aimed at babies. They are increasingly using AI. Nanit and its rivals want to own 24/7 health tracking for the sub-four-foot set. And their already astonishing levels of baby data collection are just the beginning. Nanit recently raised $50 million from investors to expand... <a href="https://www.schneier.com/blog/archives/2026/08/spyware-for-babies.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[LLM-Based Social Engineering Scams]]></title>
<description><![CDATA[OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive: The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before introducing fraudu...]]></description>
<link>https://tsecurity.de/de/3930735/ai-nachrichten/llm-based-social-engineering-scams/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930735/ai-nachrichten/llm-based-social-engineering-scams/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:45 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI disrupted a social engineering group from Cambodia that used ChatGPT. Its scope is impressive: The network simultaneously conducted multiple types of scams, often blending elements from different schemes. For instance, operators used dating personas to build trust before introducing fraudulent investment opportunities involving... <a href="https://www.schneier.com/blog/archives/2026/08/llm-based-social-engineering-scams.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Doesn’t Mean the End of Mathematics—at Least Not Yet]]></title>
<description><![CDATA[This essay was written with Kasra Rafi, and originally appeared in The Guardian. Earlier this month, about 40 top mathematicians gathered at OpenAI’s offices to discuss the future of their profession. The meeting was off-the-record, but if recent articles by mathematicians are any guide, it was m...]]></description>
<link>https://tsecurity.de/de/3930734/ai-nachrichten/ai-doesnt-mean-the-end-of-mathematics-at-least-not-yet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930734/ai-nachrichten/ai-doesnt-mean-the-end-of-mathematics-at-least-not-yet/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:43 +0200</pubDate>
<content:encoded><![CDATA[<p>This essay was written with Kasra Rafi, and originally appeared in The Guardian. Earlier this month, about 40 top mathematicians gathered at OpenAI’s offices to discuss the future of their profession. The meeting was off-the-record, but if recent articles by mathematicians are any guide, it was mostly pretty glum. People fear for their jobs, their... <a href="https://www.schneier.com/blog/archives/2026/08/ai-doesnt-mean-the-end-of-mathematics-at-least-not-yet.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Leaked Russian Cyber-Operations Training Materials]]></title>
<description><![CDATA[This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security. […] The reporting also link...]]></description>
<link>https://tsecurity.de/de/3930733/it-security-nachrichten/leaked-russian-cyber-operations-training-materials/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930733/it-security-nachrichten/leaked-russian-cyber-operations-training-materials/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:41 +0200</pubDate>
<content:encoded><![CDATA[<p>This is interesting: The records describe a force-generation mechanism for several General Staff components, including the GRU, Main Operational Directorate, and 8th Directorate, which is associated with protected communications, cryptography, and information security. […] The reporting also linked a 2024 Department No. 4 graduate, Aleksei... <a href="https://www.schneier.com/blog/archives/2026/09/leaked-russian-cyber-operations-training-materials.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[What’s the Scam?]]></title>
<description><![CDATA[To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own. Starting last weekend, I have been receiving a lot of individu...]]></description>
<link>https://tsecurity.de/de/3930732/it-security-nachrichten/whats-the-scam/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930732/it-security-nachrichten/whats-the-scam/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:34 +0200</pubDate>
<content:encoded><![CDATA[<p>To subscribe to my monthly email newsletter, you have to enter your information on the webpage, and then reply to an automatically generated email. This is, of course, to prevent people from subscribing addresses other than their own. Starting last weekend, I have been receiving a lot of individual responses to those emails. Always one line: Thank... <a href="https://www.schneier.com/blog/archives/2026/09/whats-the-scam.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Vulnerability Gap: Why Discovery Is Outrunning Repair]]></title>
<description><![CDATA[The combination of AI both discovering more vulnerabilities at a faster pace and the tightening regulatory environment is making this an all-hands-on-deck moment for the cybersecurity community. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930731/sicherheitsluecken/the-vulnerability-gap-why-discovery-is-outrunning-repair/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930731/sicherheitsluecken/the-vulnerability-gap-why-discovery-is-outrunning-repair/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:32 +0200</pubDate>
<content:encoded><![CDATA[<p>The combination of AI both discovering more vulnerabilities at a faster pace and the tightening regulatory environment is making this an all-hands-on-deck moment for the cybersecurity community. <a href="https://www.darkreading.com/cybersecurity-operations/vulnerability-gap-why-discovery-is-outrunning-repair" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ToxicPanda Banking Trojan Matures Into Enterprise Threat]]></title>
<description><![CDATA[The latest version of the Android malware has new features that expand its global reach and put more than users' financial applications at risk. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930730/malware-trojaner-viren/toxicpanda-banking-trojan-matures-into-enterprise-threat/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930730/malware-trojaner-viren/toxicpanda-banking-trojan-matures-into-enterprise-threat/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:30 +0200</pubDate>
<content:encoded><![CDATA[<p>The latest version of the Android malware has new features that expand its global reach and put more than users&#039; financial applications at risk. <a href="https://www.darkreading.com/mobile-security/toxicpanda-banking-trojan-matures-enterprise-threat" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tricky 'SynkLoader' Multitool May Herald Ransomware]]></title>
<description><![CDATA[An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930729/malware-trojaner-viren/tricky-synkloader-multitool-may-herald-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930729/malware-trojaner-viren/tricky-synkloader-multitool-may-herald-ransomware/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:29 +0200</pubDate>
<content:encoded><![CDATA[<p>An advanced, multilingual malware family brings back a trick from yesteryear — screen hijacking — for effective password theft, along with a slew of novel features. <a href="https://www.darkreading.com/threat-intelligence/tricky-synkloader-multitool-ransomware" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Foul Language: WordlistLoader Disguises Malware as Ordinary Text]]></title>
<description><![CDATA[ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930728/malware-trojaner-viren/foul-language-wordlistloader-disguises-malware-as-ordinary-text/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930728/malware-trojaner-viren/foul-language-wordlistloader-disguises-malware-as-ordinary-text/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:27 +0200</pubDate>
<content:encoded><![CDATA[<p>ClickFix-style threat campaigns are using a new trick to evade detection and deliver Amatera, an increasingly prevalent infostealer. <a href="https://www.darkreading.com/data-privacy/wordlistloader-disguises-malware-ordinary-text" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exploited Zimbra Flaw Highlights Shrinking Window to Patch]]></title>
<description><![CDATA[CISA issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user's communications. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930727/sicherheitsluecken/exploited-zimbra-flaw-highlights-shrinking-window-to-patch/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930727/sicherheitsluecken/exploited-zimbra-flaw-highlights-shrinking-window-to-patch/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:26 +0200</pubDate>
<content:encoded><![CDATA[<p>CISA issued a three-day deadline for agencies to patch a Zimbra security vulnerability, CVE-2026-73570, which allows full takeover of a user&#039;s communications. <a href="https://www.darkreading.com/vulnerabilities-threats/zimbra-flaw-exploitation-shrinking-window-patch" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Finding Nemo(Claw): Networking Issue Allows for LLM Poisoning in OpenClaw]]></title>
<description><![CDATA[Attackers can exploit a security bug in Nvidia's tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930726/ai-nachrichten/finding-nemoclaw-networking-issue-allows-for-llm-poisoning-in-openclaw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930726/ai-nachrichten/finding-nemoclaw-networking-issue-allows-for-llm-poisoning-in-openclaw/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:25 +0200</pubDate>
<content:encoded><![CDATA[<p>Attackers can exploit a security bug in Nvidia&#039;s tool to gain unauthenticated access to the local model server through the Ollama API, paving the way for persistent AI agent corruption. <a href="https://www.darkreading.com/cyber-risk/nemo-claw-networking-llm-poisoning-openclaw" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android Malware Hijacks Update System for Car Head Units]]></title>
<description><![CDATA[Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930725/malware-trojaner-viren/android-malware-hijacks-update-system-for-car-head-units/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930725/malware-trojaner-viren/android-malware-hijacks-update-system-for-car-head-units/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:23 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat actors behind a notorious click-fraud botnet have set their sights on vehicle infotainment modules and are abusing legitimate functionality to spread infections. <a href="https://www.darkreading.com/cyberattacks-data-breaches/android-malware-hijacks-update-system-car-head-units" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dark Caracal Adds New Malware to Cyber Espionage Arsenal]]></title>
<description><![CDATA[GoCaracal is a new modular malware framework that broadens Dark Caracal's capabilities to steal data and maintain access to victims. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930724/malware-trojaner-viren/dark-caracal-adds-new-malware-to-cyber-espionage-arsenal/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930724/malware-trojaner-viren/dark-caracal-adds-new-malware-to-cyber-espionage-arsenal/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:22 +0200</pubDate>
<content:encoded><![CDATA[<p>GoCaracal is a new modular malware framework that broadens Dark Caracal&#039;s capabilities to steal data and maintain access to victims. <a href="https://www.darkreading.com/cyberattacks-data-breaches/dark-caracal-adds-new-malware-cyber-espionage-arsenal" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Agentic AI Risks, CVE Program Concerns Permeate Black Hat USA 2026]]></title>
<description><![CDATA[This installment of the Reporters' Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI's effects on vulnerability reporting and security research. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930723/sicherheitsluecken/agentic-ai-risks-cve-program-concerns-permeate-black-hat-usa-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930723/sicherheitsluecken/agentic-ai-risks-cve-program-concerns-permeate-black-hat-usa-2026/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:21 +0200</pubDate>
<content:encoded><![CDATA[<p>This installment of the Reporters&#039; Notebook video series discusses the topics that dominated the cybersecurity conference, such as AI&#039;s effects on vulnerability reporting and security research. <a href="https://www.darkreading.com/cybersecurity-operations/agentic-ai-risks-cve-program-concerns-black-hat-usa-2026" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Vulnpocalypse Is Repricing the Bug Bounty Economy]]></title>
<description><![CDATA[The surge in AI-powered vulnerability reports is driving down bug bounty prices, and that could spell trouble for independent researchers. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930722/sicherheitsluecken/the-vulnpocalypse-is-repricing-the-bug-bounty-economy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930722/sicherheitsluecken/the-vulnpocalypse-is-repricing-the-bug-bounty-economy/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:19 +0200</pubDate>
<content:encoded><![CDATA[<p>The surge in AI-powered vulnerability reports is driving down bug bounty prices, and that could spell trouble for independent researchers. <a href="https://www.darkreading.com/vulnerabilities-threats/vulnpocalypse-repricing-bug-bounty-economy" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hundreds of OpenAI Agents Invaded Hugging Face Servers]]></title>
<description><![CDATA[The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930721/ai-nachrichten/hundreds-of-openai-agents-invaded-hugging-face-servers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930721/ai-nachrichten/hundreds-of-openai-agents-invaded-hugging-face-servers/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:18 +0200</pubDate>
<content:encoded><![CDATA[<p>The Hugging Face incident was bigger and worse than previously thought, with approximately 700 agents collaborating on a sophisticated, multistage attack. <a href="https://www.darkreading.com/cyberattacks-data-breaches/hundreds-openai-agents-invaded-hugging-face-servers" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Model Rules Are Not Security Controls]]></title>
<description><![CDATA[OpenAI's Hugging Face attack postmortem shows agents don't care about rules — they need strong controls. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930720/ai-nachrichten/ai-model-rules-are-not-security-controls/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930720/ai-nachrichten/ai-model-rules-are-not-security-controls/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:15 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI&#039;s Hugging Face attack postmortem shows agents don&#039;t care about rules — they need strong controls. <a href="https://www.darkreading.com/cyber-risk/model-knowing-rules-is-not-security-control" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AI Model Evaluator METR Hit by Credential Theft, Probing]]></title>
<description><![CDATA[In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930719/it-security-nachrichten/ai-model-evaluator-metr-hit-by-credential-theft-probing/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930719/it-security-nachrichten/ai-model-evaluator-metr-hit-by-credential-theft-probing/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:14 +0200</pubDate>
<content:encoded><![CDATA[<p>In one attack, threat actors stole an API key that ultimately led to the consumption of $600,000 in public AI model credits for the security nonprofit. <a href="https://www.darkreading.com/identity-access-management-security/ai-model-evaluator-metr-credential-theft-probing" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Langflow Flaw Exploited as Attacks on AI Platform Rise]]></title>
<description><![CDATA[The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930718/sicherheitsluecken/critical-langflow-flaw-exploited-as-attacks-on-ai-platform-rise/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930718/sicherheitsluecken/critical-langflow-flaw-exploited-as-attacks-on-ai-platform-rise/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:13 +0200</pubDate>
<content:encoded><![CDATA[<p>The attacks targeting CVE-2026-0768 are the latest threat against the low-code AI development platform, which is receiving more attention from adversaries this year. <a href="https://www.darkreading.com/vulnerabilities-threats/critical-langflow-flaw-exploited-attacks-rise" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Stronger Security Drives Ransomware Groups to Recruit From Within]]></title>
<description><![CDATA[Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930717/malware-trojaner-viren/stronger-security-drives-ransomware-groups-to-recruit-from-within/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930717/malware-trojaner-viren/stronger-security-drives-ransomware-groups-to-recruit-from-within/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:12 +0200</pubDate>
<content:encoded><![CDATA[<p>Some security researchers have observed an uptick in insider-assisted ransomware attacks, but malicious insiders pose other threats that cost companies millions. <a href="https://www.darkreading.com/cyber-risk/stronger-security-drives-ransomware-groups-to-recruit-from-within" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers Pounce on Critical Artifactory Flaw Following Disclosure]]></title>
<description><![CDATA[CVE-2026-82329 is an authentication bypass flaw in JFrog's repository manager that enables bad actors to gain admin-level access on affected systems. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930716/sicherheitsluecken/attackers-pounce-on-critical-artifactory-flaw-following-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930716/sicherheitsluecken/attackers-pounce-on-critical-artifactory-flaw-following-disclosure/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:10 +0200</pubDate>
<content:encoded><![CDATA[<p>CVE-2026-82329 is an authentication bypass flaw in JFrog&#039;s repository manager that enables bad actors to gain admin-level access on affected systems. <a href="https://www.darkreading.com/application-security/attackers-pounce-critical-artifactory-flaw-disclosure" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[‘We are about to see the greatest boom in people starting smaller businesses that we’ve ever seen’: OpenAI CEO Sam Altman thinks AI will spark a new wave of entrepreneurship]]></title>
<description><![CDATA[OpenAI CEO Sam Altman believes AI could spark a new wave of small businesses, but the tech industry has a lot of work to do convincing entrepreneurs how the technology can help. Speaking on the David Senra podcast, Altman suggested AI could help break down traditional barriers for entrepreneurs, ...]]></description>
<link>https://tsecurity.de/de/3930715/ai-nachrichten/we-are-about-to-see-the-greatest-boom-in-people-starting-smaller-businesses-that-weve-ever-seen-openai-ceo-sam-altman-thinks-ai-will-spark-a-new-wave-of-entrepreneurship/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930715/ai-nachrichten/we-are-about-to-see-the-greatest-boom-in-people-starting-smaller-businesses-that-weve-ever-seen-openai-ceo-sam-altman-thinks-ai-will-spark-a-new-wave-of-entrepreneurship/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:08 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI CEO Sam Altman believes AI could spark a new wave of small businesses, but the tech industry has a lot of work to do convincing entrepreneurs how the technology can help. Speaking on the David Senra podcast, Altman suggested AI could help break down traditional barriers for entrepreneurs, particularly in terms of financing and technical... <a href="https://www.itpro.com/security/we-are-about-to-see-the-greatest-boom-in-people-starting-smaller-businesses-that-weve-ever-seen-openai-ceo-sam-altman-thinks-ai-will-spark-a-new-wave-of-entrepreneurship" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zero-click email attacks: What businesses need to know]]></title>
<description><![CDATA[Zero-click attacks bring to mind the advanced spyware typically targeted at a specific subset of users. Infamous examples, such as the Pegasus spyware that targeted the family of murdered Saudi dissident Jamal Khashoggi, saw a user compromised simply by receiving a WhatsApp or iMessage. But now, ...]]></description>
<link>https://tsecurity.de/de/3930714/malware-trojaner-viren/zero-click-email-attacks-what-businesses-need-to-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930714/malware-trojaner-viren/zero-click-email-attacks-what-businesses-need-to-know/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:06 +0200</pubDate>
<content:encoded><![CDATA[<p>Zero-click attacks bring to mind the advanced spyware typically targeted at a specific subset of users. Infamous examples, such as the Pegasus spyware that targeted the family of murdered Saudi dissident Jamal Khashoggi, saw a user compromised simply by receiving a WhatsApp or iMessage. But now, email is being used in a zero-click phishing... <a href="https://www.itpro.com/security/phishing/zero-click-email-attacks-what-businesses-need-to-know" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers have breached hundreds of Zimbra servers, despite a patch having been available for weeks]]></title>
<description><![CDATA[Hundreds of internet-facing Zimbra instances have been compromised through a vulnerability that was patched last month, researchers have warned. The Zimbra Collaboration Suite (ZCS) hosts email, calendars, contacts, and administrative services. It has hundreds of millions of users, including thou...]]></description>
<link>https://tsecurity.de/de/3930713/sicherheitsluecken/hackers-have-breached-hundreds-of-zimbra-servers-despite-a-patch-having-been-available-for-weeks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930713/sicherheitsluecken/hackers-have-breached-hundreds-of-zimbra-servers-despite-a-patch-having-been-available-for-weeks/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:05 +0200</pubDate>
<content:encoded><![CDATA[<p>Hundreds of internet-facing Zimbra instances have been compromised through a vulnerability that was patched last month, researchers have warned. The Zimbra Collaboration Suite (ZCS) hosts email, calendars, contacts, and administrative services. It has hundreds of millions of users, including thousands of businesses and hundreds of government... <a href="https://www.itpro.com/security/cyber-attacks/hackers-have-breached-hundreds-of-zimbra-servers-despite-a-patch-having-been-available-for-weeks" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Six things OpenAI learned about AI from the Hugging Face incident]]></title>
<description><![CDATA[OpenAI has admitted it should have spotted its AI had gone off the rails sooner, saying that early signs that agents were misbehaving "could have triggered an earlier response."The admission comes as part of a series of reports into the July incident in which OpenAI models dodged internal control...]]></description>
<link>https://tsecurity.de/de/3930712/ai-nachrichten/six-things-openai-learned-about-ai-from-the-hugging-face-incident/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930712/ai-nachrichten/six-things-openai-learned-about-ai-from-the-hugging-face-incident/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:03 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI has admitted it should have spotted its AI had gone off the rails sooner, saying that early signs that agents were misbehaving &quot;could have triggered an earlier response.&quot;The admission comes as part of a series of reports into the July incident in which OpenAI models dodged internal controls and compromised a Hugging Face production... <a href="https://www.itpro.com/technology/artificial-intelligence/six-things-openai-learned-about-ai-from-the-hugging-face-incident" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Security researchers warn of AI-powered PLC attacks in wake of Siemens advisories]]></title>
<description><![CDATA[Security researchers have successfully used AI to port a remote code execution (RCE) exploit between two programmable logic controllers (PLCs). While the experiment still required significant human expertise to negotiate dead ends and false leads, it showed how AI could make it easier to carry ou...]]></description>
<link>https://tsecurity.de/de/3930711/sicherheitsluecken/security-researchers-warn-of-ai-powered-plc-attacks-in-wake-of-siemens-advisories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930711/sicherheitsluecken/security-researchers-warn-of-ai-powered-plc-attacks-in-wake-of-siemens-advisories/</guid>
<pubDate>Tue, 01 Sep 2026 23:31:02 +0200</pubDate>
<content:encoded><![CDATA[<p>Security researchers have successfully used AI to port a remote code execution (RCE) exploit between two programmable logic controllers (PLCs). While the experiment still required significant human expertise to negotiate dead ends and false leads, it showed how AI could make it easier to carry out attacks against embedded and industrial... <a href="https://www.itpro.com/security/cyber-attacks/security-researchers-warn-of-ai-powered-plc-attacks-in-wake-of-siemens-advisories" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Künstliche Intelligenz: Chat-GPT zeigt jetzt Werbung]]></title>
<description><![CDATA[Sam Altman wollte eigentlich keine Werbung in seinem KI-Tool. Jetzt ist sie aber da, auch in Deutschland. Und mit ihr die Frage, wie viel ein KI-Konzern über seine Nutzer wissen darf. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930710/ai-nachrichten/kuenstliche-intelligenz-chat-gpt-zeigt-jetzt-werbung/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930710/ai-nachrichten/kuenstliche-intelligenz-chat-gpt-zeigt-jetzt-werbung/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:58 +0200</pubDate>
<content:encoded><![CDATA[<p>Sam Altman wollte eigentlich keine Werbung in seinem KI-Tool. Jetzt ist sie aber da, auch in Deutschland. Und mit ihr die Frage, wie viel ein KI-Konzern über seine Nutzer wissen darf. <a href="https://www.sueddeutsche.de/wirtschaft/ki-werbung-chatgpt-deutschland-li.3536236" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation]]></title>
<description><![CDATA[OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook...]]></description>
<link>https://tsecurity.de/de/3930709/ai-nachrichten/openai-bans-russian-chatgpt-accounts-used-to-run-influence-operation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930709/ai-nachrichten/openai-bans-russian-chatgpt-accounts-used-to-run-influence-operation/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:57 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn. The accounts &quot;were being used to... <a href="https://thehackernews.com/2026/08/openai-bans-russian-chatgpt-accounts.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code]]></title>
<description><![CDATA[The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem...]]></description>
<link>https://tsecurity.de/de/3930708/sicherheitsluecken/unpatched-kaltura-mwembed-flaws-could-let-remote-attackers-read-files-and-run-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930708/sicherheitsluecken/unpatched-kaltura-mwembed-flaws-could-let-remote-attackers-read-files-and-run-code/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:56 +0200</pubDate>
<content:encoded><![CDATA[<p>The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura&#039;s HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem from the same unsafe deserialization in the... <a href="https://thehackernews.com/2026/08/unpatched-kaltura-mwembed-flaws-could.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler]]></title>
<description><![CDATA[Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described t...]]></description>
<link>https://tsecurity.de/de/3930707/malware-trojaner-viren/nimbus-manticore-expands-toolset-with-twostroke-like-backdoor-and-ssh-tunneler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930707/malware-trojaner-viren/nimbus-manticore-expands-toolset-with-twostroke-like-backdoor-and-ssh-tunneler/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:54 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active... <a href="https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs]]></title>
<description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vu...]]></description>
<link>https://tsecurity.de/de/3930706/sicherheitsluecken/cisa-adds-six-exploited-flaws-to-kev-including-netscaler-linux-and-sql-server-bugs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930706/sicherheitsluecken/cisa-adds-six-exploited-flaws-to-kev-including-netscaler-linux-and-sql-server-bugs/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:53 +0200</pubDate>
<content:encoded><![CDATA[<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A... <a href="https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access]]></title>
<description><![CDATA[Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell. Dubbed GPUTho...]]></description>
<link>https://tsecurity.de/de/3930705/sicherheitsluecken/new-gputhor-rowhammer-defeats-ecc-on-nvidia-rtx-a6000-to-gain-host-root-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930705/sicherheitsluecken/new-gputhor-rowhammer-defeats-ecc-on-nvidia-rtx-a6000-to-gain-host-root-access/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:52 +0200</pubDate>
<content:encoded><![CDATA[<p>Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell. Dubbed GPUThor, the attack was developed by researchers at the... <a href="https://thehackernews.com/2026/08/gputhor-rowhammer-defeats-ecc-on-nvidia.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address]]></title>
<description><![CDATA[Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell access and paylo...]]></description>
<link>https://tsecurity.de/de/3930704/malware-trojaner-viren/gocaracal-malware-uses-ethereum-smart-contract-to-fetch-replacement-c2-address/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930704/malware-trojaner-viren/gocaracal-malware-uses-ethereum-smart-contract-to-fetch-replacement-c2-address/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:50 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds... <a href="https://thehackernews.com/2026/08/gocaracal-malware-uses-ethereum-smart.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers]]></title>
<description><![CDATA[Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE...]]></description>
<link>https://tsecurity.de/de/3930703/sicherheitsluecken/amazon-kiro-prompt-injection-can-exfiltrate-sensitive-data-through-kiro-powers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930703/sicherheitsluecken/amazon-kiro-prompt-injection-can-exfiltrate-sensitive-data-through-kiro-powers/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:49 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on... <a href="https://thehackernews.com/2026/08/amazon-kiro-prompt-injection-can.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories]]></title>
<description><![CDATA[A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing t...]]></description>
<link>https://tsecurity.de/de/3930702/sicherheitsluecken/threatsday-296k-iot-botnet-100-water-systems-targeted-sharepoint-rce-chain-27-new-stories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930702/sicherheitsluecken/threatsday-296k-iot-botnet-100-water-systems-targeted-sharepoint-rce-chain-27-new-stories/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:47 +0200</pubDate>
<content:encoded><![CDATA[<p>A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned,... <a href="https://thehackernews.com/2026/08/threatsday-296k-iot-botnet-100-water.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE]]></title>
<description><![CDATA[Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting ser...]]></description>
<link>https://tsecurity.de/de/3930701/sicherheitsluecken/nextjs-patches-critical-avif-and-windows-flaws-enabling-unauthenticated-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930701/sicherheitsluecken/nextjs-patches-critical-avif-and-windows-flaws-enabling-unauthenticated-rce/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:46 +0200</pubDate>
<content:encoded><![CDATA[<p>Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path... <a href="https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face]]></title>
<description><![CDATA[OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations...]]></description>
<link>https://tsecurity.de/de/3930700/ai-nachrichten/openai-says-reward-hacking-drove-ai-agents-to-exploit-zero-days-and-breach-hugging-face/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930700/ai-nachrichten/openai-says-reward-hacking-drove-ai-agents-to-exploit-zero-days-and-breach-hugging-face/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:44 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly... <a href="https://thehackernews.com/2026/08/openai-says-reward-hacking-drove-ai.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions]]></title>
<description><![CDATA[PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it's "aware of ...]]></description>
<link>https://tsecurity.de/de/3930699/sicherheitsluecken/papercut-zero-day-exploited-in-attacks-affecting-all-ng-and-mf-versions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930699/sicherheitsluecken/papercut-zero-day-exploited-in-attacks-affecting-all-ng-and-mf-versions/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:42 +0200</pubDate>
<content:encoded><![CDATA[<p>PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it&#039;s &quot;aware of confirmed customer incidents and is treating this... <a href="https://thehackernews.com/2026/08/papercut-zero-day-exploited-in-attacks.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server]]></title>
<description><![CDATA[cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel &...]]></description>
<link>https://tsecurity.de/de/3930698/sicherheitsluecken/critical-cpanel-flaw-could-let-one-hosting-customer-take-root-control-of-a-whole-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930698/sicherheitsluecken/critical-cpanel-flaw-could-let-one-hosting-customer-take-root-control-of-a-whole-server/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:41 +0200</pubDate>
<content:encoded><![CDATA[<p>cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel &amp;amp; WHM. cPanel described the issue as a critical... <a href="https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access]]></title>
<description><![CDATA[VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLAN...]]></description>
<link>https://tsecurity.de/de/3930697/sicherheitsluecken/china-made-zbt-routers-ship-with-two-implants-giving-unauthenticated-attackers-root-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930697/sicherheitsluecken/china-made-zbt-routers-ship-with-two-implants-giving-unauthenticated-attackers-root-access/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:40 +0200</pubDate>
<content:encoded><![CDATA[<p>VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLANTERN by the company&#039;s zero-day research team, are... <a href="https://thehackernews.com/2026/08/china-made-zbt-routers-ship-with-two.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL]]></title>
<description><![CDATA[ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provi...]]></description>
<link>https://tsecurity.de/de/3930696/sicherheitsluecken/three-cvss-100-servicenow-flaws-could-let-unauthenticated-attackers-execute-code-and-sql/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930696/sicherheitsluecken/three-cvss-100-servicenow-flaws-could-let-unauthenticated-attackers-execute-code-and-sql/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:38 +0200</pubDate>
<content:encoded><![CDATA[<p>ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted... <a href="https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth]]></title>
<description><![CDATA[Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with t...]]></description>
<link>https://tsecurity.de/de/3930695/sicherheitsluecken/two-unitree-g1-edu-humanoid-robot-flaws-enable-root-rce-one-starts-over-bluetooth/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930695/sicherheitsluecken/two-unitree-g1-edu-humanoid-robot-flaws-enable-root-rce-one-starts-over-bluetooth/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:37 +0200</pubDate>
<content:encoded><![CDATA[<p>Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot&#039;s Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through... <a href="https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body]]></title>
<description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body...]]></description>
<link>https://tsecurity.de/de/3930694/sicherheitsluecken/owncloud-flaw-exploited-to-steal-nuclear-records-from-philippine-research-body/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930694/sicherheitsluecken/owncloud-flaw-exploited-to-steal-nuclear-records-from-philippine-research-body/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:36 +0200</pubDate>
<content:encoded><![CDATA[<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines. The vulnerability, tracked as... <a href="https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication]]></title>
<description><![CDATA[Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's tru...]]></description>
<link>https://tsecurity.de/de/3930693/sicherheitsluecken/attackers-chain-two-papercut-flaws-to-execute-code-without-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930693/sicherheitsluecken/attackers-chain-two-papercut-flaws-to-execute-code-without-authentication/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:34 +0200</pubDate>
<content:encoded><![CDATA[<p>Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. &quot;This vulnerability gives an unauthenticated attacker remote control over PaperCut&#039;s trusted configuration, which could be used to execute... <a href="https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable]]></title>
<description><![CDATA[Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE...]]></description>
<link>https://tsecurity.de/de/3930692/sicherheitsluecken/cosmos-evm-flaw-exploited-after-cosmos-labs-knew-every-blockchain-running-it-was-vulnerable/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930692/sicherheitsluecken/cosmos-evm-flaw-exploited-after-cosmos-labs-knew-every-blockchain-running-it-was-vulnerable/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:33 +0200</pubDate>
<content:encoded><![CDATA[<p>Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS... <a href="https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE]]></title>
<description><![CDATA[Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Pa...]]></description>
<link>https://tsecurity.de/de/3930691/sicherheitsluecken/five-critical-wordpress-plugin-and-theme-flaws-enable-site-takeover-or-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930691/sicherheitsluecken/five-critical-wordpress-plugin-and-theme-flaws-enable-site-takeover-or-rce/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:31 +0200</pubDate>
<content:encoded><![CDATA[<p>Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below - CVE-2026-76581 (CVSS... <a href="https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets]]></title>
<description><![CDATA[Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed inf...]]></description>
<link>https://tsecurity.de/de/3930690/malware-trojaner-viren/aurora-ransomware-operators-use-cursor-ai-in-attacks-against-10-targets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930690/malware-trojaner-viren/aurora-ransomware-operators-use-cursor-ai-in-attacks-against-10-targets/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:30 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX&#039;s artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed infrastructure associated with the Russian-speaking... <a href="https://thehackernews.com/2026/08/aurora-ransomware-operators-use-cursor.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions]]></title>
<description><![CDATA[The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky s...]]></description>
<link>https://tsecurity.de/de/3930689/malware-trojaner-viren/valleyrat-backdoor-hides-in-signed-adware-that-users-add-to-antivirus-exclusions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930689/malware-trojaner-viren/valleyrat-backdoor-hides-in-signed-adware-that-users-add-to-antivirus-exclusions/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:28 +0200</pubDate>
<content:encoded><![CDATA[<p>The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN... <a href="https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity]]></title>
<description><![CDATA[Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exp...]]></description>
<link>https://tsecurity.de/de/3930688/sicherheitsluecken/attackers-exploit-critical-langflow-and-rails-flaws-in-credential-probing-and-c2-activity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930688/sicherheitsluecken/attackers-exploit-critical-langflow-and-rails-flaws-in-credential-probing-and-c2-activity/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:26 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the... <a href="https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis]]></title>
<description><![CDATA[Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts...]]></description>
<link>https://tsecurity.de/de/3930687/malware-trojaner-viren/russia-aligned-uac-0099-plants-nuclear-weapon-prompt-in-malware-to-disrupt-ai-analysis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930687/malware-trojaner-viren/russia-aligned-uac-0099-plants-nuclear-weapon-prompt-in-malware-to-disrupt-ai-analysis/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:23 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that&#039;s been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts on X, is to deliberately trip a large language... <a href="https://thehackernews.com/2026/09/russia-aligned-uac-0099-plants-nuclear.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests]]></title>
<description><![CDATA[The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) ...]]></description>
<link>https://tsecurity.de/de/3930686/malware-trojaner-viren/iranian-hackers-pose-as-recruiters-to-deliver-cross-platform-rats-through-coding-tests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930686/malware-trojaner-viren/iranian-hackers-pose-as-recruiters-to-deliver-cross-platform-rats-through-coding-tests/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:20 +0200</pubDate>
<content:encoded><![CDATA[<p>The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian... <a href="https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds]]></title>
<description><![CDATA[Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The inje...]]></description>
<link>https://tsecurity.de/de/3930685/malware-trojaner-viren/13-malicious-packagist-packages-target-unpatched-iphones-to-steal-crypto-wallet-seeds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930685/malware-trojaner-viren/13-malicious-packagist-packages-target-unpatched-iphones-to-steal-crypto-wallet-seeds/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:19 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. &quot;The injected code runs two operations against a site&#039;s... <a href="https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers Exploit Critical JFrog Artifactory Flaw to Mint Admin Tokens Days After Disclosure]]></title>
<description><![CDATA[Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access ...]]></description>
<link>https://tsecurity.de/de/3930684/sicherheitsluecken/attackers-exploit-critical-jfrog-artifactory-flaw-to-mint-admin-tokens-days-after-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930684/sicherheitsluecken/attackers-exploit-critical-jfrog-artifactory-flaw-to-mint-admin-tokens-days-after-disclosure/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:15 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat actors are exploiting a newly patched critical security flaw impacting JFrog Artifactory merely days after public disclosure, according to watchTowr. The vulnerability in question is CVE-2026-82329 (CVSS score: 9.8), a case of authentication bypass that could lead to administrative access in Artifactory. &quot;JFrog Artifactory contains an... <a href="https://thehackernews.com/2026/09/attackers-exploit-critical-jfrog.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The State of Ransomware in Education 2026]]></title>
<description><![CDATA[Insights from 226 IT and cybersecurity leaders across the education sector in 17 countries whose organizations were hit by ransomware in the past year. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930683/malware-trojaner-viren/the-state-of-ransomware-in-education-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930683/malware-trojaner-viren/the-state-of-ransomware-in-education-2026/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:13 +0200</pubDate>
<content:encoded><![CDATA[<p>Insights from 226 IT and cybersecurity leaders across the education sector in 17 countries whose organizations were hit by ransomware in the past year. <a href="https://www.sophos.com/en-us/blog/state-of-ransomware-in-education-2026" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ungentlemanly behavior: Insights into a ransomware operation]]></title>
<description><![CDATA[Analysis of 15 intrusions revealed tradecraft used by GOLD SHERWOOD affiliates Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930682/malware-trojaner-viren/ungentlemanly-behavior-insights-into-a-ransomware-operation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930682/malware-trojaner-viren/ungentlemanly-behavior-insights-into-a-ransomware-operation/</guid>
<pubDate>Tue, 01 Sep 2026 23:30:10 +0200</pubDate>
<content:encoded><![CDATA[<p>Analysis of 15 intrusions revealed tradecraft used by GOLD SHERWOOD affiliates <a href="https://www.sophos.com/en-us/blog/ungentlemanly-behavior-insights-into-a-ransomware-operation" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ChatGPT for Teens Adds New Safeguards — but Safety Gaps Remain]]></title>
<description><![CDATA[ChatGPT for Teens adds stronger protections for users ages 13 to 17, but parents still face limits around monitoring, age prediction, and AI safety. The post ChatGPT for Teens Adds New Safeguards — but Safety Gaps Remain appeared first on TechRepublic. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930681/ai-nachrichten/chatgpt-for-teens-adds-new-safeguards-but-safety-gaps-remain/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930681/ai-nachrichten/chatgpt-for-teens-adds-new-safeguards-but-safety-gaps-remain/</guid>
<pubDate>Tue, 01 Sep 2026 23:29:53 +0200</pubDate>
<content:encoded><![CDATA[<p>ChatGPT for Teens adds stronger protections for users ages 13 to 17, but parents still face limits around monitoring, age prediction, and AI safety. The post ChatGPT for Teens Adds New Safeguards — but Safety Gaps Remain appeared first on TechRepublic. <a href="https://www.techrepublic.com/article/news-chatgpt-teens-safety-gaps/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Bans Russian ChatGPT Accounts Used in Covert Influence Campaign]]></title>
<description><![CDATA[OpenAI banned Russian ChatGPT accounts tied to a covert influence campaign involving copied research, fake attribution and coordinated social posts. The post OpenAI Bans Russian ChatGPT Accounts Used in Covert Influence Campaign appeared first on TechRepublic. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930680/ai-nachrichten/openai-bans-russian-chatgpt-accounts-used-in-covert-influence-campaign/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930680/ai-nachrichten/openai-bans-russian-chatgpt-accounts-used-in-covert-influence-campaign/</guid>
<pubDate>Tue, 01 Sep 2026 23:29:52 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI banned Russian ChatGPT accounts tied to a covert influence campaign involving copied research, fake attribution and coordinated social posts. The post OpenAI Bans Russian ChatGPT Accounts Used in Covert Influence Campaign appeared first on TechRepublic. <a href="https://www.techrepublic.com/article/news-openai-russian-chatgpt-influence-campaign-emea/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake GTA 6 Demo Spreads Malware: How to Spot the Scam]]></title>
<description><![CDATA[There is no legitimate GTA 6 demo. Fake Rockstar sites are distributing Vidar malware that targets passwords, cookies, and logged-in browser sessions. The post Fake GTA 6 Demo Spreads Malware: How to Spot the Scam appeared first on TechRepublic. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930679/malware-trojaner-viren/fake-gta-6-demo-spreads-malware-how-to-spot-the-scam/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930679/malware-trojaner-viren/fake-gta-6-demo-spreads-malware-how-to-spot-the-scam/</guid>
<pubDate>Tue, 01 Sep 2026 23:29:51 +0200</pubDate>
<content:encoded><![CDATA[<p>There is no legitimate GTA 6 demo. Fake Rockstar sites are distributing Vidar malware that targets passwords, cookies, and logged-in browser sessions. The post Fake GTA 6 Demo Spreads Malware: How to Spot the Scam appeared first on TechRepublic. <a href="https://www.techrepublic.com/article/news-fake-gta-6-demo-malware-scam/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Gunra ransomware: what you need to know]]></title>
<description><![CDATA[The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930678/malware-trojaner-viren/gunra-ransomware-what-you-need-to-know/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930678/malware-trojaner-viren/gunra-ransomware-what-you-need-to-know/</guid>
<pubDate>Tue, 01 Sep 2026 23:29:49 +0200</pubDate>
<content:encoded><![CDATA[<p>The ransomware gang Gunra has been creating havoc - exploiting unpatched VPNs and firewalls to steal data, encrypt systems, and extort victims across healthcare, finance, manufacturing, and more. Read more in my article on the Fortra blog. <a href="https://www.fortra.com/blog/gunra-ransomware-what-you-need-know" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Smashing Security podcast #482: This hacker leaked GTA 6 – and launched their own cryptocurrency]]></title>
<description><![CDATA[A hacker calling themselves "CYBERLEEK" has been leaking gameplay footage from GTA 6 ahead of its official reveal this week - but they're not asking Rockstar Games for a ransom. Instead, they've launched their own cryptocurrency, promising to release ever more juicy clips from a virtual strip clu...]]></description>
<link>https://tsecurity.de/de/3930677/podcasts/smashing-security-podcast-482-this-hacker-leaked-gta-6-and-launched-their-own-cryptocurrency/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930677/podcasts/smashing-security-podcast-482-this-hacker-leaked-gta-6-and-launched-their-own-cryptocurrency/</guid>
<pubDate>Tue, 01 Sep 2026 23:29:47 +0200</pubDate>
<content:encoded><![CDATA[<p>A hacker calling themselves &quot;CYBERLEEK&quot; has been leaking gameplay footage from GTA 6 ahead of its official reveal this week - but they&#039;re not asking Rockstar Games for a ransom. Instead, they&#039;ve launched their own cryptocurrency, promising to release ever more juicy clips from a virtual strip club... Meanwhile, your smart TV might be doing more... <a href="https://grahamcluley.com/smashing-security-podcast-482/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Shai-Hulud hackers: two men charged over TeamPCP’s global supply chain crime spree that hit OpenAI, and thousands more]]></title>
<description><![CDATA[More than 1,000 organisations, 500,000 stolen credentials, and one self-propagating worm named after a Dune sandworm - two men now face charges over TeamPCP's global hacking spree. Read more in my article on the Hot for Security blog. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930676/ai-nachrichten/shai-hulud-hackers-two-men-charged-over-teampcps-global-supply-chain-crime-spree-that-hit-openai-and-thousands-more/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930676/ai-nachrichten/shai-hulud-hackers-two-men-charged-over-teampcps-global-supply-chain-crime-spree-that-hit-openai-and-thousands-more/</guid>
<pubDate>Tue, 01 Sep 2026 23:29:45 +0200</pubDate>
<content:encoded><![CDATA[<p>More than 1,000 organisations, 500,000 stolen credentials, and one self-propagating worm named after a Dune sandworm - two men now face charges over TeamPCP&#039;s global hacking spree. Read more in my article on the Hot for Security blog. <a href="https://www.bitdefender.com/en-us/blog/hotforsecurity/shai-hulud-hackers-charged-teampcps" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Android-Malware blockiert Google Play per VPN-Trick]]></title>
<description><![CDATA[Die Android-Malware ToxicPanda wird immer gefährlicher: Sie blockiert Google Play, kapert Sicherheitsfunktionen und späht Banking-Apps aus. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930675/malware-trojaner-viren/android-malware-blockiert-google-play-per-vpn-trick/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930675/malware-trojaner-viren/android-malware-blockiert-google-play-per-vpn-trick/</guid>
<pubDate>Tue, 01 Sep 2026 23:29:42 +0200</pubDate>
<content:encoded><![CDATA[<p>Die Android-Malware ToxicPanda wird immer gefährlicher: Sie blockiert Google Play, kapert Sicherheitsfunktionen und späht Banking-Apps aus. <a href="https://www.computerbild.de/artikel/News-Sicherheit-Android-Malware-blockiert-Google-Play-per-VPN-Trick-41167869.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Windows 11: Falsche Defender-Warnungen und kaputte Mauszeiger]]></title>
<description><![CDATA[Microsoft bestätigt mehrere Bugs in Windows 11: Nach Updates gibt es falsche Defender-Warnungen und außerdem Probleme mit Mauszeigern und Hintergrundbildern. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930674/windows-tipps/windows-11-falsche-defender-warnungen-und-kaputte-mauszeiger/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930674/windows-tipps/windows-11-falsche-defender-warnungen-und-kaputte-mauszeiger/</guid>
<pubDate>Tue, 01 Sep 2026 23:29:40 +0200</pubDate>
<content:encoded><![CDATA[<p>Microsoft bestätigt mehrere Bugs in Windows 11: Nach Updates gibt es falsche Defender-Warnungen und außerdem Probleme mit Mauszeigern und Hintergrundbildern. <a href="https://www.computerbild.de/artikel/News-Sicherheit-Windows-11-Falsche-Defender-Warnungen-und-kaputte-Mauszeiger-41183927.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Denial of Service in python-httplib2 (SUSE)]]></title>
<description><![CDATA[Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930673/programmierung/denial-of-service-in-python-httplib2-suse/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930673/programmierung/denial-of-service-in-python-httplib2-suse/</guid>
<pubDate>Tue, 01 Sep 2026 23:29:33 +0200</pubDate>
<content:encoded><![CDATA[<p> <a href="https://www.pro-linux.de/sicherheit/2/108522/denial-of-service-in-python-httplib2.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Preisgabe von Informationen in Pillow (Ubuntu)]]></title>
<description><![CDATA[Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930672/it-security-nachrichten/preisgabe-von-informationen-in-pillow-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930672/it-security-nachrichten/preisgabe-von-informationen-in-pillow-ubuntu/</guid>
<pubDate>Tue, 01 Sep 2026 23:29:31 +0200</pubDate>
<content:encoded><![CDATA[<p> <a href="https://www.pro-linux.de/sicherheit/2/108542/preisgabe-von-informationen-in-pillow.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ausführen von Code mit höheren Privilegien in sudo-rs (Ubuntu)]]></title>
<description><![CDATA[Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930671/it-security-nachrichten/ausfuehren-von-code-mit-hoeheren-privilegien-in-sudo-rs-ubuntu/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930671/it-security-nachrichten/ausfuehren-von-code-mit-hoeheren-privilegien-in-sudo-rs-ubuntu/</guid>
<pubDate>Tue, 01 Sep 2026 23:29:29 +0200</pubDate>
<content:encoded><![CDATA[<p> <a href="https://www.pro-linux.de/sicherheit/2/108543/ausf%C3%BChren-von-code-mit-h%C3%B6heren-privilegien-in-sudo-rs.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The Just Security Podcast: Murder on the High Seas Part VI]]></title>
<description><![CDATA[Watch the Episode:   Co-Hosts Tess Bridgeman and Rachel Goldbrenner are joined by Rebecca Ingber and Brian Finucane to discuss how the Trump administration’s campaign of lethal strikes against suspected drug traffickers in the Caribbean and eastern Pacific has escalated and evolved in the year si...]]></description>
<link>https://tsecurity.de/de/3930670/podcasts/the-just-security-podcast-murder-on-the-high-seas-part-vi/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930670/podcasts/the-just-security-podcast-murder-on-the-high-seas-part-vi/</guid>
<pubDate>Tue, 01 Sep 2026 23:29:28 +0200</pubDate>
<content:encoded><![CDATA[<p>Watch the Episode:   Co-Hosts Tess Bridgeman and Rachel Goldbrenner are joined by Rebecca Ingber and Brian Finucane to discuss how the Trump administration’s campaign of lethal strikes against suspected drug traffickers in the Caribbean and eastern Pacific has escalated and evolved in the year since the strikes began. The conversation examines the... <a href="https://www.justsecurity.org/155336/just-security-podcast-murder-high-seas-part-vi/?utm_source=rss&amp;utm_medium=rss&amp;utm_campaign=just-security-podcast-murder-high-seas-part-vi" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[How to Change Size Of Taskbar in Windows 11]]></title>
<description><![CDATA[Key TakeawaysWindows 11 introduces a new taskbar design, which some users may find too large and want to resize.To change the taskbar size in Windows 11, users can make adjustments in the Registry Editor.By following a step-by-step guide, users can enable a smaller taskbar in Windows 11 and rever...]]></description>
<link>https://tsecurity.de/de/3930669/windows-tipps/how-to-change-size-of-taskbar-in-windows-11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930669/windows-tipps/how-to-change-size-of-taskbar-in-windows-11/</guid>
<pubDate>Tue, 01 Sep 2026 23:29:09 +0200</pubDate>
<content:encoded><![CDATA[<p>Key TakeawaysWindows 11 introduces a new taskbar design, which some users may find too large and want to resize.To change the taskbar size in Windows 11, users can make adjustments in the Registry Editor.By following a step-by-step guide, users can enable a smaller taskbar in Windows 11 and revert to the default size if needed.Windows […] The post... <a href="https://itechhacks.com/change-taskbar-size-windows-11/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Top 5 Ways to Enable Hibernate Mode on Windows 11]]></title>
<description><![CDATA[Key TakeawaysHibernate mode on Windows 11 allows you to save battery life and resume where you left off, similar to sleep mode.Enabling Hibernate mode requires using Command Prompt and entering specific commands to enable the feature.To configure Hibernate mode on Windows 11, you can set the time...]]></description>
<link>https://tsecurity.de/de/3930668/windows-tipps/top-5-ways-to-enable-hibernate-mode-on-windows-11/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930668/windows-tipps/top-5-ways-to-enable-hibernate-mode-on-windows-11/</guid>
<pubDate>Tue, 01 Sep 2026 23:28:58 +0200</pubDate>
<content:encoded><![CDATA[<p>Key TakeawaysHibernate mode on Windows 11 allows you to save battery life and resume where you left off, similar to sleep mode.Enabling Hibernate mode requires using Command Prompt and entering specific commands to enable the feature.To configure Hibernate mode on Windows 11, you can set the time for inactivity before the PC goes into hibernate... <a href="https://itechhacks.com/enable-hibernate-mode-on-windows-11/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Post-DEF CON phishing campaign delivered AMOS and NetSupport malware]]></title>
<description><![CDATA[A phishing campaign targeting attendees of Black Hat and DEF CON conferences involved distributing information-stealing malware and remote access malware via a malicious Google Doc and fake DocSend installers for macOS and Windows. The Huntress team learned about the phishing attack after one of ...]]></description>
<link>https://tsecurity.de/de/3930667/malware-trojaner-viren/post-def-con-phishing-campaign-delivered-amos-and-netsupport-malware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930667/malware-trojaner-viren/post-def-con-phishing-campaign-delivered-amos-and-netsupport-malware/</guid>
<pubDate>Tue, 01 Sep 2026 23:28:15 +0200</pubDate>
<content:encoded><![CDATA[<p>A phishing campaign targeting attendees of Black Hat and DEF CON conferences involved distributing information-stealing malware and remote access malware via a malicious Google Doc and fake DocSend installers for macOS and Windows. The Huntress team learned about the phishing attack after one of its researchers received a direct message on X on... <a href="https://informationsecuritybuzz.com/post-def-con-phishing-campaign-delivered/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Bans Russia ChatGPT Accounts Used to Run Covert Influence Operation]]></title>
<description><![CDATA[OpenAI Bans Russian ChatGPT accounts participating in a covert online influence operation aimed at manufacturing authority and promoting narratives favorable to Moscow. The campaign leveraged generative AI tools alongside an elaborate network of fake digital infrastructure, including a front thin...]]></description>
<link>https://tsecurity.de/de/3930666/ai-nachrichten/openai-bans-russia-chatgpt-accounts-used-to-run-covert-influence-operation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930666/ai-nachrichten/openai-bans-russia-chatgpt-accounts-used-to-run-covert-influence-operation/</guid>
<pubDate>Tue, 01 Sep 2026 23:28:12 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI Bans Russian ChatGPT accounts participating in a covert online influence operation aimed at manufacturing authority and promoting narratives favorable to Moscow. The campaign leveraged generative AI tools alongside an elaborate network of fake digital infrastructure, including a front think tank, plagiarized academic work, and a biased... <a href="https://hackersonlineclub.com/openai-bans-russia-chatgpt-accounts/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fake GTA 6 Demo Alert: One Click Could Steal Your Passwords]]></title>
<description><![CDATA[Cybercriminals are always looking for new ways to exploit popular trends. This time, they are taking advantage of the huge excitement around GTA 6 by creating fake demo websites developed to spread password-stealing malware. Security researchers at Malwarebytes have discovered an active malware c...]]></description>
<link>https://tsecurity.de/de/3930665/malware-trojaner-viren/fake-gta-6-demo-alert-one-click-could-steal-your-passwords/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930665/malware-trojaner-viren/fake-gta-6-demo-alert-one-click-could-steal-your-passwords/</guid>
<pubDate>Tue, 01 Sep 2026 23:28:11 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybercriminals are always looking for new ways to exploit popular trends. This time, they are taking advantage of the huge excitement around GTA 6 by creating fake demo websites developed to spread password-stealing malware. Security researchers at Malwarebytes have discovered an active malware campaign targeting fans eagerly waiting for Grand... <a href="https://hackersonlineclub.com/fake-gta-6-demo-alert/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kubernetes 1.37 advances workload-aware scheduling and cluster networking]]></title>
<description><![CDATA[When the open-source Kubernetes cloud-native project got started more than a decade ago, AI was not a major concern. Times have changed. Kubernetes 1.37 is now out, extending its networking and scheduling capabilities as more organizations run AI and machine learning workloads on the platform. Th...]]></description>
<link>https://tsecurity.de/de/3930664/ai-nachrichten/kubernetes-137-advances-workload-aware-scheduling-and-cluster-networking/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930664/ai-nachrichten/kubernetes-137-advances-workload-aware-scheduling-and-cluster-networking/</guid>
<pubDate>Tue, 01 Sep 2026 23:28:08 +0200</pubDate>
<content:encoded><![CDATA[<p>When the open-source Kubernetes cloud-native project got started more than a decade ago, AI was not a major concern. Times have changed. Kubernetes 1.37 is now out, extending its networking and scheduling capabilities as more organizations run AI and machine learning workloads on the platform. The new release is the second major update for the... <a href="https://www.networkworld.com/article/4214824/kubernetes-1-37-advances-workload-aware-scheduling-and-cluster-networking.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI confirms ChatGPT outage as users report errors]]></title>
<description><![CDATA[ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930663/ai-nachrichten/openai-confirms-chatgpt-outage-as-users-report-errors/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930663/ai-nachrichten/openai-confirms-chatgpt-outage-as-users-report-errors/</guid>
<pubDate>Tue, 01 Sep 2026 23:28:04 +0200</pubDate>
<content:encoded><![CDATA[<p>ChatGPT Work is experiencing a partial outage, and users across multiple subscription plans may be unable to start or continue tasks. [...] <a href="https://www.bleepingcomputer.com/news/artificial-intelligence/openai-confirms-chatgpt-outage-as-users-report-errors/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Five Venezuelans plead guilty to ATM jackpotting attacks in US]]></title>
<description><![CDATA[Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930662/malware-trojaner-viren/five-venezuelans-plead-guilty-to-atm-jackpotting-attacks-in-us/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930662/malware-trojaner-viren/five-venezuelans-plead-guilty-to-atm-jackpotting-attacks-in-us/</guid>
<pubDate>Tue, 01 Sep 2026 23:28:02 +0200</pubDate>
<content:encoded><![CDATA[<p>Five Venezuelan nationals pleaded guilty to attempting to empty automated teller machines (ATMs) using malware in a series of ATM jackpotting attacks. [...] <a href="https://www.bleepingcomputer.com/news/security/five-venezuelans-plead-guilty-to-atm-jackpotting-attacks-in-us/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nearly 22,000 Microsoft Exchange servers vulnerable to hijack attacks]]></title>
<description><![CDATA[Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930661/sicherheitsluecken/nearly-22000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930661/sicherheitsluecken/nearly-22000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/</guid>
<pubDate>Tue, 01 Sep 2026 23:28:00 +0200</pubDate>
<content:encoded><![CDATA[<p>Nearly 22,000 Microsoft Exchange servers exposed online remain unpatched against a high-severity authentication bypass vulnerability that allows attackers to hijack all user mailboxes. [...] <a href="https://www.bleepingcomputer.com/news/security/nearly-22-000-microsoft-exchange-servers-vulnerable-to-hijack-attacks/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Langflow flaw exploited to steal OpenAI and AWS keys]]></title>
<description><![CDATA[Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930660/sicherheitsluecken/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930660/sicherheitsluecken/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/</guid>
<pubDate>Tue, 01 Sep 2026 23:27:57 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat actors are exploiting an unauthenticated remote code execution vulnerability (CVE-2026-0768) in Langflow, an open-source framework for building AI applications, to steal credentials, tokens, and keys. [...] <a href="https://www.bleepingcomputer.com/news/security/critical-langflow-flaw-exploited-to-steal-openai-and-aws-keys/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Aesto Health says data breach affects over 9.5 million patients]]></title>
<description><![CDATA[Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930659/it-security-nachrichten/aesto-health-says-data-breach-affects-over-95-million-patients/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930659/it-security-nachrichten/aesto-health-says-data-breach-affects-over-95-million-patients/</guid>
<pubDate>Tue, 01 Sep 2026 23:27:54 +0200</pubDate>
<content:encoded><![CDATA[<p>Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. [...] <a href="https://www.bleepingcomputer.com/news/security/aesto-health-says-data-breach-affects-over-95-million-patients/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers abuse Faronics Deploy admin tool to install ScreenConnect]]></title>
<description><![CDATA[Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930658/it-security-nachrichten/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930658/it-security-nachrichten/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/</guid>
<pubDate>Tue, 01 Sep 2026 23:27:51 +0200</pubDate>
<content:encoded><![CDATA[<p>Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. [...] <a href="https://www.bleepingcomputer.com/news/security/hackers-abuse-faronics-deploy-admin-tool-to-install-screenconnect/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exploit „HardBreacher“ für Kaspersky Endpoint Security veröffentlicht]]></title>
<description><![CDATA[Der unter dem Namen Nightmare Eclipse auftretende Sicherheitsforscher hat einen Zero-Day-Exploit in Kaspersky Endpoint Security veröffentlicht. Nightmare Eclipse hatte in den vergangenen Monaten bereits mehrere Machbarkeitsnachweise für Sicherheitslücken veröffentlicht, überwiegend in Windows sow...]]></description>
<link>https://tsecurity.de/de/3930657/sicherheitsluecken/exploit-hardbreacher-fuer-kaspersky-endpoint-security-veroeffentlicht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930657/sicherheitsluecken/exploit-hardbreacher-fuer-kaspersky-endpoint-security-veroeffentlicht/</guid>
<pubDate>Tue, 01 Sep 2026 23:27:49 +0200</pubDate>
<content:encoded><![CDATA[<p>Der unter dem Namen Nightmare Eclipse auftretende Sicherheitsforscher hat einen Zero-Day-Exploit in Kaspersky Endpoint Security veröffentlicht. Nightmare Eclipse hatte in den vergangenen Monaten bereits mehrere Machbarkeitsnachweise für Sicherheitslücken veröffentlicht, überwiegend in Windows sowie Microsoft Defender, nachdem der Forscher... <a href="https://www.it-daily.net/it-sicherheit/cloud-security/exploit-kaspersky" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox aktiviert JPEG-XL-Unterstützung ab Version 157 standardmäßig]]></title>
<description><![CDATA[Mozilla plant, die Unterstützung für das Bildformat JPEG XL mit Firefox 157 Ende September auf allen Plattformen standardmäßig zu aktivieren. Firefox Nightly nutzt die Funktion bereits jetzt standardmäßig, um sie vor der endgültigen Veröffentlichung ausgiebig zu testen. Mozilla-Entwickler Timothy...]]></description>
<link>https://tsecurity.de/de/3930656/it-security-nachrichten/firefox-aktiviert-jpeg-xl-unterstuetzung-ab-version-157-standardmaessig/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930656/it-security-nachrichten/firefox-aktiviert-jpeg-xl-unterstuetzung-ab-version-157-standardmaessig/</guid>
<pubDate>Tue, 01 Sep 2026 23:27:48 +0200</pubDate>
<content:encoded><![CDATA[<p>Mozilla plant, die Unterstützung für das Bildformat JPEG XL mit Firefox 157 Ende September auf allen Plattformen standardmäßig zu aktivieren. Firefox Nightly nutzt die Funktion bereits jetzt standardmäßig, um sie vor der endgültigen Veröffentlichung ausgiebig zu testen. Mozilla-Entwickler Timothy Nikkel kündigte den Schritt in einer offiziellen... <a href="https://www.it-daily.net/shortnews/firefox-jpeg-xl-unterstuetzung" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Tim Cook verabschiedet sich als Apple-CEO mit persönlicher Nachricht]]></title>
<description><![CDATA[Am 31. August, seinem letzten Tag als Apple-Chef, richtete Tim Cook eine persönliche Abschiedsnachricht an die Belegschaft des Unternehmens. In der von 9to5Mac veröffentlichten E-Mail an die Beschäftigten beginnt Cook mit den Worten: „Heute ist mein letzter Tag als CEO von Apple.“ Tim Cook, ehema...]]></description>
<link>https://tsecurity.de/de/3930655/it-security-nachrichten/tim-cook-verabschiedet-sich-als-apple-ceo-mit-persoenlicher-nachricht/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930655/it-security-nachrichten/tim-cook-verabschiedet-sich-als-apple-ceo-mit-persoenlicher-nachricht/</guid>
<pubDate>Tue, 01 Sep 2026 23:27:46 +0200</pubDate>
<content:encoded><![CDATA[<p>Am 31. August, seinem letzten Tag als Apple-Chef, richtete Tim Cook eine persönliche Abschiedsnachricht an die Belegschaft des Unternehmens. In der von 9to5Mac veröffentlichten E-Mail an die Beschäftigten beginnt Cook mit den Worten: „Heute ist mein letzter Tag als CEO von Apple.“ Tim Cook, ehemaliger CEO von Apple Im weiteren Verlauf blickt er... <a href="https://www.it-daily.net/shortnews/apple-ceo-abschied" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Beste Antivirus-App für Android 2026 im Test - Cybernews]]></title>
<description><![CDATA[© 2026 Cybernews – Aktuelle Nachrichten zu IT-Sicherheit, Tech, Tests &amp; Expertenanalysen. ... Norton 360 Antivirus &amp; Security – Sicherheit und ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930654/it-security-nachrichten/beste-antivirus-app-fuer-android-2026-im-test-cybernews/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930654/it-security-nachrichten/beste-antivirus-app-fuer-android-2026-im-test-cybernews/</guid>
<pubDate>Tue, 01 Sep 2026 23:27:38 +0200</pubDate>
<content:encoded><![CDATA[<p>© 2026 Cybernews – Aktuelle Nachrichten zu IT-Sicherheit, Tech, Tests &amp;amp; Expertenanalysen. ... Norton 360 Antivirus &amp;amp; Security – Sicherheit und ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://cybernews.com/de/beste-antivirensoftware/antivirus-android/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw29AmR_SwMDXVZR54TD8BMS" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[AISI Deutschland: Neues KI-Sicherheitsinstitut nimmt Arbeit auf - CPM Security Network]]></title>
<description><![CDATA[Aufgabenteilung zwischen BSI und BNetzA. In einer ersten Phase erfolgt eine Aufgabenteilung entlang der Dimensionen (Cyber-)Security, die beim BSI ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930653/it-security-nachrichten/aisi-deutschland-neues-ki-sicherheitsinstitut-nimmt-arbeit-auf-cpm-security-network/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930653/it-security-nachrichten/aisi-deutschland-neues-ki-sicherheitsinstitut-nimmt-arbeit-auf-cpm-security-network/</guid>
<pubDate>Tue, 01 Sep 2026 23:27:35 +0200</pubDate>
<content:encoded><![CDATA[<p>Aufgabenteilung zwischen BSI und BNetzA. In einer ersten Phase erfolgt eine Aufgabenteilung entlang der Dimensionen (Cyber-)Security, die beim BSI ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://security-network.com/aisi-deutschland-ki-sicherheitsinstitut/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw0xv2No-hsXmkxA0YFN-frA" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Post-Quanten-Kryptografie: Giesecke+Devrient entwickelt quantensichere Identitätskarten]]></title>
<description><![CDATA[Der Fortinet „State of Operational Technology and Cybersecurity Report 2026“ zeigt Fortschritte bei Reifegrad und Netzwerktransparenz, aber weiterhin ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930652/it-security-nachrichten/post-quanten-kryptografie-giesecke-devrient-entwickelt-quantensichere-identitaetskarten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930652/it-security-nachrichten/post-quanten-kryptografie-giesecke-devrient-entwickelt-quantensichere-identitaetskarten/</guid>
<pubDate>Tue, 01 Sep 2026 23:27:33 +0200</pubDate>
<content:encoded><![CDATA[<p>Der Fortinet „State of Operational Technology and Cybersecurity Report 2026“ zeigt Fortschritte bei Reifegrad und Netzwerktransparenz, aber weiterhin ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.computer-automation.de/safety-und-security/post-quanten-kryptografie--giesecke-devrient-entwickelt-quantensichere-identitaetskarten.htm&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw1mOzx8VTXVtPuhMnsSFTOU" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Utax erweitert Cloud Print and Scan für den Unternehmenseinsatz - connect-professional]]></title>
<description><![CDATA[... IT-Steuerung zentral verankert bleibt. Erleichterungen beim ... cloud-security-bild-ar-th-shutterstock-2141978517. Repräsentative Umfrage des ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930651/it-security-nachrichten/utax-erweitert-cloud-print-and-scan-fuer-den-unternehmenseinsatz-connect-professional/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930651/it-security-nachrichten/utax-erweitert-cloud-print-and-scan-fuer-den-unternehmenseinsatz-connect-professional/</guid>
<pubDate>Tue, 01 Sep 2026 23:27:27 +0200</pubDate>
<content:encoded><![CDATA[<p>... IT-Steuerung zentral verankert bleibt. Erleichterungen beim ... cloud-security-bild-ar-th-shutterstock-2141978517. Repräsentative Umfrage des ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.connect-professional.de/software-services/utax-cloud-drucken-im-unternehmenseinsatz-405241.html&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw3ffTeGsYTc7kR1WqehMnoe" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sicherheitsupdates für Hoymiles-Wechselrichter (30.8. 2026) - BornCity]]></title>
<description><![CDATA[Ein Sicherheitsforscher hatte in Kooperation mit dem Chaos Computer Club (CCC) verheerende Sicherheitslücken bei Wechselrichtern für Balkon- und ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930650/it-security-nachrichten/sicherheitsupdates-fuer-hoymiles-wechselrichter-308-2026-borncity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930650/it-security-nachrichten/sicherheitsupdates-fuer-hoymiles-wechselrichter-308-2026-borncity/</guid>
<pubDate>Tue, 01 Sep 2026 23:27:26 +0200</pubDate>
<content:encoded><![CDATA[<p>Ein Sicherheitsforscher hatte in Kooperation mit dem Chaos Computer Club (CCC) verheerende Sicherheitslücken bei Wechselrichtern für Balkon- und ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://borncity.com/blog/2026/09/01/sicherheitsupdates-fuer-hoymiles-wechselrichter-30-8-2026/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw0z-kpHuqGNyD6zqMa70jms" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Red Hat: Wettlauf gegen die Zeit – So halten Unternehmen dem Tempo von KI-gestützten ...]]></title>
<description><![CDATA[Jan Wildeboer, EMEA Evangelist bei Red Hat, stellt vier Maßnahmen vor, mit denen sich die eigene IT an die neue Geschwindigkeit von Bedrohungen ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930649/it-security-nachrichten/red-hat-wettlauf-gegen-die-zeit-so-halten-unternehmen-dem-tempo-von-ki-gestuetzten/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930649/it-security-nachrichten/red-hat-wettlauf-gegen-die-zeit-so-halten-unternehmen-dem-tempo-von-ki-gestuetzten/</guid>
<pubDate>Tue, 01 Sep 2026 23:27:25 +0200</pubDate>
<content:encoded><![CDATA[<p>Jan Wildeboer, EMEA Evangelist bei Red Hat, stellt vier Maßnahmen vor, mit denen sich die eigene IT an die neue Geschwindigkeit von Bedrohungen ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://osb-alliance.de/news/red-hat-wettlauf-gegen-die-zeit-so-halten-unternehmen-dem-tempo-von-ki-gestuetzten-cyberangriffen-stand&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw3pz-ojPs4Y9qRWMaod0Mrx" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exploit „HardBreacher“ für Kaspersky Endpoint Security veröffentlicht - it-daily.net]]></title>
<description><![CDATA[Der unter dem Namen Nightmare Eclipse auftretende Sicherheitsforscher hat einen Zero-Day-Exploit in Kaspersky Endpoint Security veröffentlicht. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930648/sicherheitsluecken/exploit-hardbreacher-fuer-kaspersky-endpoint-security-veroeffentlicht-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930648/sicherheitsluecken/exploit-hardbreacher-fuer-kaspersky-endpoint-security-veroeffentlicht-it-dailynet/</guid>
<pubDate>Tue, 01 Sep 2026 23:27:24 +0200</pubDate>
<content:encoded><![CDATA[<p>Der unter dem Namen Nightmare Eclipse auftretende Sicherheitsforscher hat einen Zero-Day-Exploit in Kaspersky Endpoint Security veröffentlicht. <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.it-daily.net/it-sicherheit/cloud-security/exploit-kaspersky&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw09pw16Y8WAM_rK0RAbj5cg" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PV-Wechselrichter: Hoymiles liefert Sicherheitsupdate aus | heise online]]></title>
<description><![CDATA[Security · IT &amp; Tech · Developer · KI · Entertainment · Wissenschaft · Bestenlisten · Digital Health · Foren · Alle Themen. Anzeige. Special: ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930647/it-security-nachrichten/pv-wechselrichter-hoymiles-liefert-sicherheitsupdate-aus-heise-online/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930647/it-security-nachrichten/pv-wechselrichter-hoymiles-liefert-sicherheitsupdate-aus-heise-online/</guid>
<pubDate>Tue, 01 Sep 2026 23:27:18 +0200</pubDate>
<content:encoded><![CDATA[<p>Security · IT &amp;amp; Tech · Developer · KI · Entertainment · Wissenschaft · Bestenlisten · Digital Health · Foren · Alle Themen. Anzeige. Special: ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.heise.de/news/PV-Wechselrichter-Hoymiles-liefert-Sicherheitsupdate-aus-11436579.html&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw2OjUVqAm9Z8E03NS-164vL" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[September-Termin: heise security Tour mit Vorträgen zu KI, Lieferketten und mehr]]></title>
<description><![CDATA[Die Eintageskonferenz für Sicherheitsverantwortliche mit praxisrelevantem Wissen zu aktuellen Herausforderungen der IT-Sicherheit: KI, ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930646/it-security-nachrichten/september-termin-heise-security-tour-mit-vortraegen-zu-ki-lieferketten-und-mehr/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930646/it-security-nachrichten/september-termin-heise-security-tour-mit-vortraegen-zu-ki-lieferketten-und-mehr/</guid>
<pubDate>Tue, 01 Sep 2026 23:27:17 +0200</pubDate>
<content:encoded><![CDATA[<p>Die Eintageskonferenz für Sicherheitsverantwortliche mit praxisrelevantem Wissen zu aktuellen Herausforderungen der IT-Sicherheit: KI, ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.heise.de/news/September-Termin-heise-security-Tour-mit-Vortraegen-zu-KI-Lieferketten-und-mehr-11437401.html&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw1iHLzkxlMIYY1tK7ptIAfw" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Berufe: Diese IT-Jobs werden auch in Zukunft gefragt sein - Handelsblatt]]></title>
<description><![CDATA[Besonders Softwareentwickler, IT-Testmanager und IT-Administratoren werden seltener gesucht. Hoch bleibt dagegen die Nachfrage nach IT-Security- ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930645/it-security-nachrichten/berufe-diese-it-jobs-werden-auch-in-zukunft-gefragt-sein-handelsblatt/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930645/it-security-nachrichten/berufe-diese-it-jobs-werden-auch-in-zukunft-gefragt-sein-handelsblatt/</guid>
<pubDate>Tue, 01 Sep 2026 23:26:52 +0200</pubDate>
<content:encoded><![CDATA[<p>Besonders Softwareentwickler, IT-Testmanager und IT-Administratoren werden seltener gesucht. Hoch bleibt dagegen die Nachfrage nach IT-Security- ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.handelsblatt.com/karriere/berufe-diese-it-jobs-werden-auch-in-zukunft-gefragt-sein/100238210.html&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw3ZOJrYRDXtsLQXmGK3FChL" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cybersecurity: Es gibt keinen Platz für Nachlässigkeiten - it-daily.net]]></title>
<description><![CDATA[Und das am besten, bevor es einen schwerwiegenden Sicherheitsvorfall gibt. Cybersecurity Open Source. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930644/it-security-nachrichten/cybersecurity-es-gibt-keinen-platz-fuer-nachlaessigkeiten-it-dailynet/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930644/it-security-nachrichten/cybersecurity-es-gibt-keinen-platz-fuer-nachlaessigkeiten-it-dailynet/</guid>
<pubDate>Tue, 01 Sep 2026 23:26:28 +0200</pubDate>
<content:encoded><![CDATA[<p>Und das am besten, bevor es einen schwerwiegenden Sicherheitsvorfall gibt. Cybersecurity Open Source. <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.it-daily.net/it-sicherheit/cloud-security/cybersecurity-nachlassigkeiten/%3Fnocache%3D1&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw2FfBo-27moaFAmBFI1WeIN" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Data Contracts: Fundament für vertrauenswürdige Data Products - BigData-Insider]]></title>
<description><![CDATA[Artenschutz neu gedacht: Ein Ansatz aus der IT-Security. Wenn Künstliche ... Data Products, Data Marketplaces und Data Contracts werden in ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930643/it-security-nachrichten/data-contracts-fundament-fuer-vertrauenswuerdige-data-products-bigdata-insider/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930643/it-security-nachrichten/data-contracts-fundament-fuer-vertrauenswuerdige-data-products-bigdata-insider/</guid>
<pubDate>Tue, 01 Sep 2026 23:26:24 +0200</pubDate>
<content:encoded><![CDATA[<p>Artenschutz neu gedacht: Ein Ansatz aus der IT-Security. Wenn Künstliche ... Data Products, Data Marketplaces und Data Contracts werden in ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://www.bigdata-insider.de/data-contracts-vertrauenswuerdige-data-products-a-19a2410cdeb4f4b5cdc7412bfbe9a5ef/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw3OR206paiMT4NElPc5-4sR" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cyber-Training für die Bundeswehr mit dem SANS Institute - ESUT]]></title>
<description><![CDATA[Das Schulungsprogramm deckt praxisnahe Disziplinen ab, darunter Incident Response, digitale Forensik, Cloud Security, Penetrationstests und die ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930642/it-security-nachrichten/cyber-training-fuer-die-bundeswehr-mit-dem-sans-institute-esut/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930642/it-security-nachrichten/cyber-training-fuer-die-bundeswehr-mit-dem-sans-institute-esut/</guid>
<pubDate>Tue, 01 Sep 2026 23:26:15 +0200</pubDate>
<content:encoded><![CDATA[<p>Das Schulungsprogramm deckt praxisnahe Disziplinen ab, darunter Incident Response, digitale Forensik, Cloud Security, Penetrationstests und die ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://esut.de/2026/09/meldungen/74461/cyber-training-bundeswehr-sans/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw37AjCRkb_I9H5-luoLyptN" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Thomas Kirn wird Chief Revenue Officer bei Gfos - IT&Production]]></title>
<description><![CDATA[Dragos, Cybersicherheitsspezialist für OT-Umgebungen, analysiert in einem Bericht aktuelle Cyberbedrohungen für industrielle und kritische ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930641/it-security-nachrichten/thomas-kirn-wird-chief-revenue-officer-bei-gfos-itproduction/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930641/it-security-nachrichten/thomas-kirn-wird-chief-revenue-officer-bei-gfos-itproduction/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:53 +0200</pubDate>
<content:encoded><![CDATA[<p>Dragos, Cybersicherheitsspezialist für OT-Umgebungen, analysiert in einem Bericht aktuelle Cyberbedrohungen für industrielle und kritische ... <a href="https://www.google.com/url?rct=j&amp;sa=t&amp;url=https://it-production.com/news/maerkte-und-trends/thomas-kirn-wird-chief-revenue-officer-bei-gfos/&amp;ct=ga&amp;cd=CAIyGTRiZTZmY2RmMzZhYjA0M2Y6ZGU6ZGU6REU&amp;usg=AOvVaw0BHTAf-kOSEl3aEuUB-zYO" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[You don't want this Sleepwalker backdoor on your Windows machine]]></title>
<description><![CDATA[Like a sleeper cell awaiting activation, a never-before-seen Windows backdoor dubbed Sleepwalker waits silently in memory for one specifically crafted network packet to wake it up and deliver commands using the malware's 23-instruction language. The commands can do everything from running code di...]]></description>
<link>https://tsecurity.de/de/3930640/malware-trojaner-viren/you-dont-want-this-sleepwalker-backdoor-on-your-windows-machine/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930640/malware-trojaner-viren/you-dont-want-this-sleepwalker-backdoor-on-your-windows-machine/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:50 +0200</pubDate>
<content:encoded><![CDATA[<p>Like a sleeper cell awaiting activation, a never-before-seen Windows backdoor dubbed Sleepwalker waits silently in memory for one specifically crafted network packet to wake it up and deliver commands using the malware&#039;s 23-instruction language. The commands can do everything from running code directly in memory to moving data off the computer.... <a href="https://www.theregister.com/security/2026/08/24/you-dont-want-this-sleepwalker-backdoor-on-your-windows-machine/5292021" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Crooks push Mac malware through fake OpenAI Codex ads]]></title>
<description><![CDATA[Cybercrims are using fake OpenAI Codex download pages to trick Mac developers into running malware disguised as installation commands. Researchers at Cato Networks uncovered the campaign after spotting sponsored Google search results targeting people looking to download Codex for macOS. The ads d...]]></description>
<link>https://tsecurity.de/de/3930639/malware-trojaner-viren/crooks-push-mac-malware-through-fake-openai-codex-ads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930639/malware-trojaner-viren/crooks-push-mac-malware-through-fake-openai-codex-ads/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:48 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybercrims are using fake OpenAI Codex download pages to trick Mac developers into running malware disguised as installation commands. Researchers at Cato Networks uncovered the campaign after spotting sponsored Google search results targeting people looking to download Codex for macOS. The ads direct would-be users to a convincing-looking... <a href="https://www.theregister.com/security/2026/08/25/crooks-push-mac-malware-through-fake-openai-codex-ads/5291899" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw]]></title>
<description><![CDATA[The US Cybersecurity and Infrastructure Security Agency (CISA) just dished out another three-day deadline for patching an actively exploited vulnerability, the most urgent in its wheelhouse. The culprit: a max-severity Oracle bug affecting Windows VMs. Tracked as CVE-2026-21962 (10.0), the improp...]]></description>
<link>https://tsecurity.de/de/3930638/sicherheitsluecken/cisa-slaps-its-tightest-three-day-patching-deadline-on-perfect-10-oracle-flaw/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930638/sicherheitsluecken/cisa-slaps-its-tightest-three-day-patching-deadline-on-perfect-10-oracle-flaw/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:46 +0200</pubDate>
<content:encoded><![CDATA[<p>The US Cybersecurity and Infrastructure Security Agency (CISA) just dished out another three-day deadline for patching an actively exploited vulnerability, the most urgent in its wheelhouse. The culprit: a max-severity Oracle bug affecting Windows VMs. Tracked as CVE-2026-21962 (10.0), the improper access control (CWE-284) flaw affects Oracle’s... <a href="https://www.theregister.com/security/2026/08/25/cisa-slaps-its-tightest-three-day-patching-deadline-on-perfect-10-oracle-flaw/5292107" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI explains how its naughty AI agents attacked Hugging Face]]></title>
<description><![CDATA[OpenAI has published its technical report detailing "the Hugging Face incident," the compromise of the eponymous LLM repository by unreleased, ill-supervised AI models. The incident, widely reported, has prompted concern among technical types, the public, and lawmakers about how automated softwar...]]></description>
<link>https://tsecurity.de/de/3930637/ai-nachrichten/openai-explains-how-its-naughty-ai-agents-attacked-hugging-face/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930637/ai-nachrichten/openai-explains-how-its-naughty-ai-agents-attacked-hugging-face/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:44 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI has published its technical report detailing &quot;the Hugging Face incident,&quot; the compromise of the eponymous LLM repository by unreleased, ill-supervised AI models. The incident, widely reported, has prompted concern among technical types, the public, and lawmakers about how automated software was able to escape containment and hack an... <a href="https://www.theregister.com/security/2026/08/27/openai-explains-how-its-naughty-ai-agents-attacked-hugging-face/5292780" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ATF responds to 'major' cybersecurity incident after ransomware gang's claims]]></title>
<description><![CDATA[The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) said it’s responding to a “major” cybersecurity incident shortly after the Qilin ransomware gang posted the US federal law enforcement agency on its leak site. An ATF spokesperson told The Register the intruders accessed a “standalone ...]]></description>
<link>https://tsecurity.de/de/3930636/malware-trojaner-viren/atf-responds-to-major-cybersecurity-incident-after-ransomware-gangs-claims/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930636/malware-trojaner-viren/atf-responds-to-major-cybersecurity-incident-after-ransomware-gangs-claims/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:41 +0200</pubDate>
<content:encoded><![CDATA[<p>The Bureau of Alcohol, Tobacco, Firearms and Explosives (ATF) said it’s responding to a “major” cybersecurity incident shortly after the Qilin ransomware gang posted the US federal law enforcement agency on its leak site. An ATF spokesperson told The Register the intruders accessed a “standalone computer system containing information about targets... <a href="https://www.theregister.com/security/2026/08/27/atf-responds-to-major-cybersecurity-incident-after-ransomware-gangs-claims/5292990" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Industry that built the problem offers to sell you the solution]]></title>
<description><![CDATA[OpenAI has gathered more than 100 of the world's biggest tech and infosec companies to warn that cyber defense is in trouble - a reassuring development given quite a few of them helped build the technology involved. The open letter has more than 100 names attached to it, including many of the com...]]></description>
<link>https://tsecurity.de/de/3930635/ai-nachrichten/industry-that-built-the-problem-offers-to-sell-you-the-solution/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930635/ai-nachrichten/industry-that-built-the-problem-offers-to-sell-you-the-solution/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:39 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI has gathered more than 100 of the world&#039;s biggest tech and infosec companies to warn that cyber defense is in trouble - a reassuring development given quite a few of them helped build the technology involved. The open letter has more than 100 names attached to it, including many of the companies with the most to gain – or lose – from what... <a href="https://www.theregister.com/security/2026/08/28/industry-that-built-the-problem-offers-to-sell-you-the-solution/5293207" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA: Most exploited vulnerabilities should have been eradicated decades ago]]></title>
<description><![CDATA[CISA is still crying out for software vendors to adopt Secure by Design (SBD) development practices, and says in its latest review that longstanding vulnerability classes are still the most exploited. The agency examined soft spots across 2024 and 2025, finding that the majority of those that rec...]]></description>
<link>https://tsecurity.de/de/3930634/sicherheitsluecken/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930634/sicherheitsluecken/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:37 +0200</pubDate>
<content:encoded><![CDATA[<p>CISA is still crying out for software vendors to adopt Secure by Design (SBD) development practices, and says in its latest review that longstanding vulnerability classes are still the most exploited. The agency examined soft spots across 2024 and 2025, finding that the majority of those that receive CVEs and make it to the Known Exploited... <a href="https://www.theregister.com/security/2026/08/28/cisa-most-exploited-vulnerabilities-should-have-been-eradicated-decades-ago/5293194" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic cracks down on hijacked user accounts mining AI tokens]]></title>
<description><![CDATA[Rather than paying for their own Claude usage, crims are using malware to steal access to other people's accounts. Aware of this issue, Anthropic has signed at least one affected user out and removed the saved payment method to stop stolen sessions being abused. According to an email shared by Re...]]></description>
<link>https://tsecurity.de/de/3930633/malware-trojaner-viren/anthropic-cracks-down-on-hijacked-user-accounts-mining-ai-tokens/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930633/malware-trojaner-viren/anthropic-cracks-down-on-hijacked-user-accounts-mining-ai-tokens/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:35 +0200</pubDate>
<content:encoded><![CDATA[<p>Rather than paying for their own Claude usage, crims are using malware to steal access to other people&#039;s accounts. Aware of this issue, Anthropic has signed at least one affected user out and removed the saved payment method to stop stolen sessions being abused. According to an email shared by Reddit user WorriedAssociate7029, who sent a copy to... <a href="https://www.theregister.com/security/2026/08/31/anthropic-cracks-down-on-hijacked-user-accounts-mining-ai-tokens/5293461" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attack hides malware in PNGs and drops custom reverse tunnel on victims' machines]]></title>
<description><![CDATA[An unknown miscreant is using "TerminalFix" to trick unsuspecting users into running PowerShell commands that infect their computers with a reverse tunnel granting attackers access to their networks. Some of the malware is even hidden inside PNG graphics the PC downloads. TerminalFix is the lates...]]></description>
<link>https://tsecurity.de/de/3930632/malware-trojaner-viren/attack-hides-malware-in-pngs-and-drops-custom-reverse-tunnel-on-victims-machines/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930632/malware-trojaner-viren/attack-hides-malware-in-pngs-and-drops-custom-reverse-tunnel-on-victims-machines/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:34 +0200</pubDate>
<content:encoded><![CDATA[<p>An unknown miscreant is using &quot;TerminalFix&quot; to trick unsuspecting users into running PowerShell commands that infect their computers with a reverse tunnel granting attackers access to their networks. Some of the malware is even hidden inside PNG graphics the PC downloads. TerminalFix is the latest variant of the wildly popular ClickFix initial... <a href="https://www.theregister.com/security/2026/08/31/attack-hides-malware-in-pngs-and-drops-custom-reverse-tunnel-on-victims-machines/5293480" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[33-hour BGP hijack of Softaculous traffic prompts security scramble]]></title>
<description><![CDATA[Softaculous and Virtualizor customers are being urged to reset credentials and inspect their servers after a 33-hour BGP hijacking incident diverted traffic and delivered malware to a handful of installations. Softaculous makes software for the web hosting industry, while its Virtualizor control ...]]></description>
<link>https://tsecurity.de/de/3930631/malware-trojaner-viren/33-hour-bgp-hijack-of-softaculous-traffic-prompts-security-scramble/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930631/malware-trojaner-viren/33-hour-bgp-hijack-of-softaculous-traffic-prompts-security-scramble/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:32 +0200</pubDate>
<content:encoded><![CDATA[<p>Softaculous and Virtualizor customers are being urged to reset credentials and inspect their servers after a 33-hour BGP hijacking incident diverted traffic and delivered malware to a handful of installations. Softaculous makes software for the web hosting industry, while its Virtualizor control panel is used by providers and administrators to... <a href="https://www.theregister.com/security/2026/09/01/33-hour-bgp-hijack-of-softaculous-traffic-prompts-security-scramble/5293608" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic pledges to try harder to keep models under control, asks partners to chip in]]></title>
<description><![CDATA[Anthropic says it's taking steps to limit the misbehavior of its AI models after a review found Claude models going beyond the scope of fictional cybersecurity tests and gaining unauthorized access to real computer systems. The biz wants its partners to step up their security too, seeing as the i...]]></description>
<link>https://tsecurity.de/de/3930630/it-security-nachrichten/anthropic-pledges-to-try-harder-to-keep-models-under-control-asks-partners-to-chip-in/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930630/it-security-nachrichten/anthropic-pledges-to-try-harder-to-keep-models-under-control-asks-partners-to-chip-in/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:26 +0200</pubDate>
<content:encoded><![CDATA[<p>Anthropic says it&#039;s taking steps to limit the misbehavior of its AI models after a review found Claude models going beyond the scope of fictional cybersecurity tests and gaining unauthorized access to real computer systems. The biz wants its partners to step up their security too, seeing as the incidents occurred in third-party environments that... <a href="https://www.theregister.com/ai-and-ml/2026/09/01/anthropic-pledges-to-try-harder-to-keep-models-under-control-asks-partners-to-chip-in/5293733" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Firefox helps iPhone users bypass ads on web sites while making money showing its own ads]]></title>
<description><![CDATA[After several weeks of anticipation, Mozilla has started rolling out ad blocking to the iOS version of its popular browser, but you can still expect to see ads on Mozilla's own pages, including the new tab page. The org officially rolled out the new native ad blocking feature for iOS Firefox on T...]]></description>
<link>https://tsecurity.de/de/3930629/it-security-nachrichten/firefox-helps-iphone-users-bypass-ads-on-web-sites-while-making-money-showing-its-own-ads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930629/it-security-nachrichten/firefox-helps-iphone-users-bypass-ads-on-web-sites-while-making-money-showing-its-own-ads/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:22 +0200</pubDate>
<content:encoded><![CDATA[<p>After several weeks of anticipation, Mozilla has started rolling out ad blocking to the iOS version of its popular browser, but you can still expect to see ads on Mozilla&#039;s own pages, including the new tab page. The org officially rolled out the new native ad blocking feature for iOS Firefox on Tuesday, moving it out of the experimental phase,... <a href="https://www.theregister.com/security/2026/09/01/firefox-helps-iphone-users-bypass-ads-on-web-sites-while-making-money-showing-its-own-ads/5293747" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attacker stole a METR API key, used $600K worth of credits, and no one noticed for weeks]]></title>
<description><![CDATA[AI model testing organization METR has disclosed two attacks that happened earlier this year, including one in which an attacker stole an API key and spent three weeks consuming public-model credits worth about $600,000. METR (short for Model Evaluation and Threat Research) found no evidence that...]]></description>
<link>https://tsecurity.de/de/3930628/it-security-nachrichten/attacker-stole-a-metr-api-key-used-600k-worth-of-credits-and-no-one-noticed-for-weeks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930628/it-security-nachrichten/attacker-stole-a-metr-api-key-used-600k-worth-of-credits-and-no-one-noticed-for-weeks/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:20 +0200</pubDate>
<content:encoded><![CDATA[<p>AI model testing organization METR has disclosed two attacks that happened earlier this year, including one in which an attacker stole an API key and spent three weeks consuming public-model credits worth about $600,000. METR (short for Model Evaluation and Threat Research) found no evidence that the attackers accessed sensitive information in... <a href="https://www.theregister.com/security/2026/09/01/attacker-stole-a-metr-api-key-used-600k-worth-of-credits-and-no-one-noticed-for-weeks/5293730" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Another Artifactory CVE under attack by AI agents or humans]]></title>
<description><![CDATA[Security researchers reported that someone is exploiting CVE-2026-82329, a critical JFrog Artifactory authentication-bypass bug, just days after the vendor patched the 9.8-rated flaw. And we don't know if that someone is human. Artifactory is a widely used tool for managing software artifacts, pa...]]></description>
<link>https://tsecurity.de/de/3930627/sicherheitsluecken/another-artifactory-cve-under-attack-by-ai-agents-or-humans/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930627/sicherheitsluecken/another-artifactory-cve-under-attack-by-ai-agents-or-humans/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:18 +0200</pubDate>
<content:encoded><![CDATA[<p>Security researchers reported that someone is exploiting CVE-2026-82329, a critical JFrog Artifactory authentication-bypass bug, just days after the vendor patched the 9.8-rated flaw. And we don&#039;t know if that someone is human. Artifactory is a widely used tool for managing software artifacts, packages, binaries, and AI models. It’s also popular... <a href="https://www.theregister.com/security/2026/09/01/another-artifactory-cve-under-attack-by-ai-agents-or-humans/5293769" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[The State of Ransomware in Education 2026]]></title>
<description><![CDATA[Insights from 226 IT and cybersecurity leaders across the education sector in 17 countries whose organizations were hit by ransomware in the past year. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930626/malware-trojaner-viren/the-state-of-ransomware-in-education-2026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930626/malware-trojaner-viren/the-state-of-ransomware-in-education-2026/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:16 +0200</pubDate>
<content:encoded><![CDATA[<p>Insights from 226 IT and cybersecurity leaders across the education sector in 17 countries whose organizations were hit by ransomware in the past year. <a href="https://www.sophos.com/en-us/blog/state-of-ransomware-in-education-2026" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ungentlemanly behavior: Insights into a ransomware operation]]></title>
<description><![CDATA[Analysis of 15 intrusions revealed tradecraft used by GOLD SHERWOOD affiliates Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930625/malware-trojaner-viren/ungentlemanly-behavior-insights-into-a-ransomware-operation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930625/malware-trojaner-viren/ungentlemanly-behavior-insights-into-a-ransomware-operation/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:14 +0200</pubDate>
<content:encoded><![CDATA[<p>Analysis of 15 intrusions revealed tradecraft used by GOLD SHERWOOD affiliates <a href="https://www.sophos.com/en-us/blog/ungentlemanly-behavior-insights-into-a-ransomware-operation" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild]]></title>
<description><![CDATA[Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure. The post Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930624/sicherheitsluecken/critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930624/sicherheitsluecken/critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:08 +0200</pubDate>
<content:encoded><![CDATA[<p>Exploitation of the authentication bypass vulnerability CVE-2026-82329 started just days after its public disclosure. The post Critical JFrog Artifactory Vulnerability Reportedly Exploited in the Wild appeared first on SecurityWeek. <a href="https://www.securityweek.com/critical-jfrog-artifactory-vulnerability-reportedly-exploited-in-the-wild/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Ransomware Gang Claims Nutex Health Data Breach]]></title>
<description><![CDATA[The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information. The post Ransomware Gang Claims Nutex Health Data Breach appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930623/malware-trojaner-viren/ransomware-gang-claims-nutex-health-data-breach/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930623/malware-trojaner-viren/ransomware-gang-claims-nutex-health-data-breach/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:06 +0200</pubDate>
<content:encoded><![CDATA[<p>The company has notified the SEC that hackers accessed patient, employee, provider, business, and financial information. The post Ransomware Gang Claims Nutex Health Data Breach appeared first on SecurityWeek. <a href="https://www.securityweek.com/ransomware-gang-claims-nutex-health-data-breach/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Five Venezuelans Plead Guilty in US Court to ATM Jackpotting]]></title>
<description><![CDATA[The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash. The post Five Venezuelans Plead Guilty in US Court to ATM Jackpotting appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930622/malware-trojaner-viren/five-venezuelans-plead-guilty-in-us-court-to-atm-jackpotting/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930622/malware-trojaner-viren/five-venezuelans-plead-guilty-in-us-court-to-atm-jackpotting/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:03 +0200</pubDate>
<content:encoded><![CDATA[<p>The defendants unsuccessfully attempted to physically install malware on ATMs to force them to dispense cash. The post Five Venezuelans Plead Guilty in US Court to ATM Jackpotting appeared first on SecurityWeek. <a href="https://www.securityweek.com/five-venezuelans-plead-guilty-in-us-court-to-atm-jackpotting/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Hackers Start Exploiting Critical Langflow Vulnerability]]></title>
<description><![CDATA[Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely. The post Hackers Start Exploiting Critical Langflow Vulnerability appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930621/sicherheitsluecken/hackers-start-exploiting-critical-langflow-vulnerability/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930621/sicherheitsluecken/hackers-start-exploiting-critical-langflow-vulnerability/</guid>
<pubDate>Tue, 01 Sep 2026 23:25:01 +0200</pubDate>
<content:encoded><![CDATA[<p>Tracked as CVE-2026-0768, the security defect allows unauthenticated attackers to execute arbitrary Python code remotely. The post Hackers Start Exploiting Critical Langflow Vulnerability appeared first on SecurityWeek. <a href="https://www.securityweek.com/hackers-start-exploiting-critical-langflow-vulnerability/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars]]></title>
<description><![CDATA[Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models. The post Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930620/sicherheitsluecken/experiment-porting-a-plc-exploit-with-ai-takes-hours-and-hundreds-of-dollars/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930620/sicherheitsluecken/experiment-porting-a-plc-exploit-with-ai-takes-hours-and-hundreds-of-dollars/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:59 +0200</pubDate>
<content:encoded><![CDATA[<p>Forescout researchers used Claude AI to port a remote code execution exploit between WAGO PLC models. The post Experiment: Porting a PLC Exploit With AI Takes Hours and Hundreds of Dollars appeared first on SecurityWeek. <a href="https://www.securityweek.com/experiment-porting-a-plc-exploit-with-ai-takes-hours-and-hundreds-of-dollars/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Coast Guard Establishes Office of Maritime Cybersecurity Policy]]></title>
<description><![CDATA[The new office will serve as the central authority for cybersecurity policy covering US ports, vessels, and maritime facilities. The post Coast Guard Establishes Office of Maritime Cybersecurity Policy appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930619/it-security-nachrichten/coast-guard-establishes-office-of-maritime-cybersecurity-policy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930619/it-security-nachrichten/coast-guard-establishes-office-of-maritime-cybersecurity-policy/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:57 +0200</pubDate>
<content:encoded><![CDATA[<p>The new office will serve as the central authority for cybersecurity policy covering US ports, vessels, and maritime facilities. The post Coast Guard Establishes Office of Maritime Cybersecurity Policy appeared first on SecurityWeek. <a href="https://www.securityweek.com/coast-guard-establishes-office-of-maritime-cybersecurity-policy/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense]]></title>
<description><![CDATA[Sevii has expanded its ADR platform with AI agents designed to investigate, contain, and remediate AI-driven attacks within minutes. The post Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930618/it-security-nachrichten/sevii-targets-ai-speed-attacks-with-preemptive-autonomous-defense/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930618/it-security-nachrichten/sevii-targets-ai-speed-attacks-with-preemptive-autonomous-defense/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:56 +0200</pubDate>
<content:encoded><![CDATA[<p>Sevii has expanded its ADR platform with AI agents designed to investigate, contain, and remediate AI-driven attacks within minutes. The post Sevii Targets AI-Speed Attacks With Preemptive Autonomous Defense appeared first on SecurityWeek. <a href="https://www.securityweek.com/sevii-targets-ai-speed-attacks-with-preemptive-autonomous-defense/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Palo Alto Networks Acquires AI Agent Platform Console]]></title>
<description><![CDATA[The cybersecurity giant announced the acquisition alongside quarterly results showing a 34% increase in revenue and strong growth in next-generation security ARR. The post Palo Alto Networks Acquires AI Agent Platform Console appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930617/it-security-nachrichten/palo-alto-networks-acquires-ai-agent-platform-console/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930617/it-security-nachrichten/palo-alto-networks-acquires-ai-agent-platform-console/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:54 +0200</pubDate>
<content:encoded><![CDATA[<p>The cybersecurity giant announced the acquisition alongside quarterly results showing a 34% increase in revenue and strong growth in next-generation security ARR. The post Palo Alto Networks Acquires AI Agent Platform Console appeared first on SecurityWeek. <a href="https://www.securityweek.com/palo-alto-networks-acquires-ai-agent-platform-console/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[107 Ransomware-Opfer bringen Deutschland auf Rekordniveau]]></title>
<description><![CDATA[Im Juni und Juli 2026 hat ransomware.live in Deutschland 107 Opfer von Ransomware ermittelt, rund dreimal so viele wie im Vorjahreszeitraum mit 36 Fällen. Allein 58 Opfer im Juli bedeuten ein monatliches Allzeithoch seit Beginn der Aufzeichnungen 2023. Deutschland liegt damit weltweit auf Platz z...]]></description>
<link>https://tsecurity.de/de/3930616/malware-trojaner-viren/107-ransomware-opfer-bringen-deutschland-auf-rekordniveau/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930616/malware-trojaner-viren/107-ransomware-opfer-bringen-deutschland-auf-rekordniveau/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:51 +0200</pubDate>
<content:encoded><![CDATA[<p>Im Juni und Juli 2026 hat ransomware.live in Deutschland 107 Opfer von Ransomware ermittelt, rund dreimal so viele wie im Vorjahreszeitraum mit 36 Fällen. Allein 58 Opfer im Juli bedeuten ein monatliches Allzeithoch seit Beginn der Aufzeichnungen 2023. Deutschland liegt damit weltweit auf Platz zwei der am häufigsten angegriffenen Länder. (Bild:... <a href="https://www.security-insider.de/ransomware-deutschland-juni-juli-2026-safepay-a-1cb7656e412eea893c5f8d931b2f5394/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Google patcht unberechtigte Datenbankabfrage in SecOps]]></title>
<description><![CDATA[Eine SQL-Injection-Schwachstelle im Legacy-Dashboard-Widget von Google SecOps ermöglicht authentifizierten Angreifern, SQL-Abfragen auszuführen. Google hat die Sicherheitslücke in der Cloud gepatcht. (Bild: Midjourney / KI-generiert) Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930615/sicherheitsluecken/google-patcht-unberechtigte-datenbankabfrage-in-secops/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930615/sicherheitsluecken/google-patcht-unberechtigte-datenbankabfrage-in-secops/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:49 +0200</pubDate>
<content:encoded><![CDATA[<p>Eine SQL-Injection-Schwachstelle im Legacy-Dashboard-Widget von Google SecOps ermöglicht authentifizierten Angreifern, SQL-Abfragen auszuführen. Google hat die Sicherheitslücke in der Cloud gepatcht. (Bild: Midjourney / KI-generiert) <a href="https://www.security-insider.de/google-secops-sql-injection-widget-api-patch-6-3-85-a-ff2d16a93654268ef29c026ddcea576f/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Velero sichert Kubernetes-Ressourcen und Volumes]]></title>
<description><![CDATA[Velero sichert Ressourcen und Persistent Volumes eines Kubernetes-Clusters und stellt sie nach einem Ausfall wieder her. Ein Controller im Cluster und ein lokaler CLI-Client steuern Backups, Migrationen und Replikationen. Als Ablage dienen S3, Google Cloud Storage, Azure Blob und S3-kompatible Zi...]]></description>
<link>https://tsecurity.de/de/3930614/programmierung/velero-sichert-kubernetes-ressourcen-und-volumes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930614/programmierung/velero-sichert-kubernetes-ressourcen-und-volumes/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:48 +0200</pubDate>
<content:encoded><![CDATA[<p>Velero sichert Ressourcen und Persistent Volumes eines Kubernetes-Clusters und stellt sie nach einem Ausfall wieder her. Ein Controller im Cluster und ein lokaler CLI-Client steuern Backups, Migrationen und Replikationen. Als Ablage dienen S3, Google Cloud Storage, Azure Blob und S3-kompatible Ziele. (Bild: Gemini / KI-generiert) <a href="https://www.security-insider.de/velero-kubernetes-backup-restore-persistent-volumes-a-d1417d84a53c3af9f3f58234487fc742/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Kritischer Out-of-Bounds Write in Dell PowerStore]]></title>
<description><![CDATA[Eine Out-of-Bounds-Write-Schwachstelle in Dell PowerStore SDNAS ermöglicht es unauthentizierten Angreifern, das System zum Absturz zu bringen oder Remote Code auszuführen. Betroffene sind zwölf PowerStore-Modelle, Patches sind verfügbar. (Bild: © Ronny - stock.adobe.com) Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930613/sicherheitsluecken/kritischer-out-of-bounds-write-in-dell-powerstore/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930613/sicherheitsluecken/kritischer-out-of-bounds-write-in-dell-powerstore/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:46 +0200</pubDate>
<content:encoded><![CDATA[<p>Eine Out-of-Bounds-Write-Schwachstelle in Dell PowerStore SDNAS ermöglicht es unauthentizierten Angreifern, das System zum Absturz zu bringen oder Remote Code auszuführen. Betroffene sind zwölf PowerStore-Modelle, Patches sind verfügbar. (Bild: © Ronny - stock.adobe.com) <a href="https://www.security-insider.de/dell-powerstore-sdnas-smb-luecke-cve-2026-67271-a-c0c1d9732481f80544433117011d1c2e/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Controlware kombiniert MDR und VMS für mehr Cybersecurity]]></title>
<description><![CDATA[Controlware erweitert sein Cyber-Defense-Portfolio um Managed Detection &amp;amp; Response und Vulnerability Management Services. Der kombinierte Ansatz soll Bedrohungen schneller erkennen, Schwachstellen priorisieren und interne IT-Teams entlasten. (Bild: Dall-E / KI-generiert) Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930612/sicherheitsluecken/controlware-kombiniert-mdr-und-vms-fuer-mehr-cybersecurity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930612/sicherheitsluecken/controlware-kombiniert-mdr-und-vms-fuer-mehr-cybersecurity/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:45 +0200</pubDate>
<content:encoded><![CDATA[<p>Controlware erweitert sein Cyber-Defense-Portfolio um Managed Detection &amp;amp;amp; Response und Vulnerability Management Services. Der kombinierte Ansatz soll Bedrohungen schneller erkennen, Schwachstellen priorisieren und interne IT-Teams entlasten. (Bild: Dall-E / KI-generiert) <a href="https://www.security-insider.de/controlware-kombiniert-mdr-und-vms-fuer-mehr-cybersecurity-a-85108d31d9caa91b4afc6dff4c2bb84b/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Azul verkürzt Java-Patch-Zyklus auf monatliche Sicherheitsupdates]]></title>
<description><![CDATA[Azul verkürzt den Abstand zwischen kritischen Java-Sicherheitsfixes von drei Monaten auf einen planbaren Monatsrhythmus. Die Updates sollen nur CVE-bezogene Änderungen enthalten und damit das Risiko unerwünschter Regressionen begrenzen. (Bild: Dall-E / KI-generiert) Weiterlesen]]></description>
<link>https://tsecurity.de/de/3930611/programmierung/azul-verkuerzt-java-patch-zyklus-auf-monatliche-sicherheitsupdates/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930611/programmierung/azul-verkuerzt-java-patch-zyklus-auf-monatliche-sicherheitsupdates/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:43 +0200</pubDate>
<content:encoded><![CDATA[<p>Azul verkürzt den Abstand zwischen kritischen Java-Sicherheitsfixes von drei Monaten auf einen planbaren Monatsrhythmus. Die Updates sollen nur CVE-bezogene Änderungen enthalten und damit das Risiko unerwünschter Regressionen begrenzen. (Bild: Dall-E / KI-generiert) <a href="https://www.security-insider.de/azul-verkuerzt-java-patch-zyklus-auf-monatliche-sicherheitsupdates-a-f668ef34f032a23de5965643bc62cc64/" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Broadcom Pledges to Lock Down Open Source Python, Java Libraries]]></title>
<description><![CDATA[Broadcom is launching "TrueSource," an effort to curate and secure open-source components used with its Tanzu platform, including Spring, RabbitMQ, and libraries across Java, Python, and Node.js. "The idea is to provide a set of solutions focused on providing clean and secure artefacts," Purnima ...]]></description>
<link>https://tsecurity.de/de/3930610/programmierung/broadcom-pledges-to-lock-down-open-source-python-java-libraries/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930610/programmierung/broadcom-pledges-to-lock-down-open-source-python-java-libraries/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:41 +0200</pubDate>
<content:encoded><![CDATA[<p>Broadcom is launching &quot;TrueSource,&quot; an effort to curate and secure open-source components used with its Tanzu platform, including Spring, RabbitMQ, and libraries across Java, Python, and Node.js. &quot;The idea is to provide a set of solutions focused on providing clean and secure artefacts,&quot; Purnima Padmanabhan, vice president of Broadcom&#039;s Tanzu... <a href="https://it.slashdot.org/story/26/08/31/2047247/broadcom-pledges-to-lock-down-open-source-python-java-libraries?utm_source=rss1.0mainlinkanon&amp;utm_medium=feed" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic Signs $35 Billion Cloud Deal With Nvidia-Backed Lambda]]></title>
<description><![CDATA[Anthropic has reportedly signed a $35 billion cloud-computing deal with Nvidia-backed Lambda for a roughly 350-megawatt Texas data center being developed by Hut 8. "Lambda will install Nvidia chips at the Hut 8 facility, with the arrangement designed to expand the pool of Nvidia computing resourc...]]></description>
<link>https://tsecurity.de/de/3930609/it-security-nachrichten/anthropic-signs-35-billion-cloud-deal-with-nvidia-backed-lambda/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930609/it-security-nachrichten/anthropic-signs-35-billion-cloud-deal-with-nvidia-backed-lambda/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:40 +0200</pubDate>
<content:encoded><![CDATA[<p>Anthropic has reportedly signed a $35 billion cloud-computing deal with Nvidia-backed Lambda for a roughly 350-megawatt Texas data center being developed by Hut 8. &quot;Lambda will install Nvidia chips at the Hut 8 facility, with the arrangement designed to expand the pool of Nvidia computing resources available to power Anthropic&#039;s Claude AI... <a href="https://slashdot.org/story/26/09/01/177239/anthropic-signs-35-billion-cloud-deal-with-nvidia-backed-lambda?utm_source=rss1.0mainlinkanon&amp;utm_medium=feed" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenClaw 2.0 Is Here, Ushering In the Era of 'Multiplayer' AI Coding]]></title>
<description><![CDATA[An anonymous reader quotes a report from VentureBeat: The viral fervor we saw earlier this year around OpenClaw, the open source AI harness that turns powerful language models into autonomous workers the user can message via their favorite channels (Telegram, iMessage, WhatsApp, Discord etc), has...]]></description>
<link>https://tsecurity.de/de/3930608/it-security-nachrichten/openclaw-20-is-here-ushering-in-the-era-of-multiplayer-ai-coding/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930608/it-security-nachrichten/openclaw-20-is-here-ushering-in-the-era-of-multiplayer-ai-coding/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:38 +0200</pubDate>
<content:encoded><![CDATA[<p>An anonymous reader quotes a report from VentureBeat: The viral fervor we saw earlier this year around OpenClaw, the open source AI harness that turns powerful language models into autonomous workers the user can message via their favorite channels (Telegram, iMessage, WhatsApp, Discord etc), has cooled off substantially from its peak in March... <a href="https://developers.slashdot.org/story/26/09/01/1733206/openclaw-20-is-here-ushering-in-the-era-of-multiplayer-ai-coding?utm_source=rss1.0mainlinkanon&amp;utm_medium=feed" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BT's Old Copper Landline Network Could Be Worth Over $2 Billion]]></title>
<description><![CDATA[BT could make more than $2.7 billion by recycling copper from its aging UK landline network as BT subsidiary Openreach replaces legacy wiring with full-fiber broadband. Engadget reports: BT's recovered copper was previously valued at around $2 billion. But prices have surged, thanks to rising glo...]]></description>
<link>https://tsecurity.de/de/3930607/it-security-nachrichten/bts-old-copper-landline-network-could-be-worth-over-2-billion/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930607/it-security-nachrichten/bts-old-copper-landline-network-could-be-worth-over-2-billion/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:36 +0200</pubDate>
<content:encoded><![CDATA[<p>BT could make more than $2.7 billion by recycling copper from its aging UK landline network as BT subsidiary Openreach replaces legacy wiring with full-fiber broadband. Engadget reports: BT&#039;s recovered copper was previously valued at around $2 billion. But prices have surged, thanks to rising global demand tied to AI data centers, renewable energy... <a href="https://news.slashdot.org/story/26/09/01/1815258/bts-old-copper-landline-network-could-be-worth-over-2-billion?utm_source=rss1.0mainlinkanon&amp;utm_medium=feed" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Dyson Made a Camera-Equipped Toothbrush That Flosses For You]]></title>
<description><![CDATA[Dyson is entering oral care with the $499 CameraJet, a smart toothbrush that uses a tiny camera and on-device AI to detect gaps between teeth and automatically blast them with mouthwash while you brush. Regular toothpaste and mouthwash will work with the CameraJet, but Dyson plans to sell its own...]]></description>
<link>https://tsecurity.de/de/3930606/it-security-nachrichten/dyson-made-a-camera-equipped-toothbrush-that-flosses-for-you/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930606/it-security-nachrichten/dyson-made-a-camera-equipped-toothbrush-that-flosses-for-you/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:35 +0200</pubDate>
<content:encoded><![CDATA[<p>Dyson is entering oral care with the $499 CameraJet, a smart toothbrush that uses a tiny camera and on-device AI to detect gaps between teeth and automatically blast them with mouthwash while you brush. Regular toothpaste and mouthwash will work with the CameraJet, but Dyson plans to sell its own non- or low-foaming formulas designed to give the... <a href="https://tech.slashdot.org/story/26/09/01/1927243/dyson-made-a-camera-equipped-toothbrush-that-flosses-for-you?utm_source=rss1.0mainlinkanon&amp;utm_medium=feed" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic's Claude Fable 5.1 and Mythos 5.1 Arrive With a 75% Cost Reduction For Fable Cache Reads]]></title>
<description><![CDATA[Anthropic has released Claude Fable 5.1 and Mythos 5.1, two versions of the same underlying model aimed at longer-running agentic work. "For enterprise buyers, however, the release is about more than another round of benchmark gains," reports VentureBeat. "Anthropic is simultaneously changing the...]]></description>
<link>https://tsecurity.de/de/3930605/it-security-nachrichten/anthropics-claude-fable-51-and-mythos-51-arrive-with-a-75-cost-reduction-for-fable-cache-reads/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930605/it-security-nachrichten/anthropics-claude-fable-51-and-mythos-51-arrive-with-a-75-cost-reduction-for-fable-cache-reads/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:33 +0200</pubDate>
<content:encoded><![CDATA[<p>Anthropic has released Claude Fable 5.1 and Mythos 5.1, two versions of the same underlying model aimed at longer-running agentic work. &quot;For enterprise buyers, however, the release is about more than another round of benchmark gains,&quot; reports VentureBeat. &quot;Anthropic is simultaneously changing the economics of running persistent agents, reducing... <a href="https://it.slashdot.org/story/26/09/01/2037255/anthropics-claude-fable-51-and-mythos-51-arrive-with-a-75-cost-reduction-for-fable-cache-reads?utm_source=rss1.0mainlinkanon&amp;utm_medium=feed" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Resonance: A Plague Tale Legacy Review (PC)]]></title>
<description><![CDATA[The main protagonists of the A Plague Tale series, the siblings Amicia de Rune and her younger brother Hugo de Rune, take a step back in the new entry in the franchise, Resonance: A Plague Tale Legacy. Contrary to what many might think, Resonance is a prequel, so instead of progressing the plot o...]]></description>
<link>https://tsecurity.de/de/3930604/it-security-nachrichten/resonance-a-plague-tale-legacy-review-pc/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930604/it-security-nachrichten/resonance-a-plague-tale-legacy-review-pc/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:31 +0200</pubDate>
<content:encoded><![CDATA[<p>The main protagonists of the A Plague Tale series, the siblings Amicia de Rune and her younger brother Hugo de Rune, take a step back in the new entry in the franchise, Resonance: A Plague Tale Legacy. Contrary to what many might think, Resonance is a prequel, so instead of progressing the plot of the first two games, it actually brings the series... <a href="https://www.softpedia.com/reviews/games/pc/resonance-a-plague-tale-legacy-review-538248.shtml" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Bans Russian ChatGPT Accounts Used to Run Influence Operation]]></title>
<description><![CDATA[OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook...]]></description>
<link>https://tsecurity.de/de/3930603/ai-nachrichten/openai-bans-russian-chatgpt-accounts-used-to-run-influence-operation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930603/ai-nachrichten/openai-bans-russian-chatgpt-accounts-used-to-run-influence-operation/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:28 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI on Tuesday said it banned a cluster of Russian ChatGPT accounts that used VPNs to bypass access restrictions and run an influence operation, which relied on its artificial intelligence (AI) tool to generate social media posts and comments that were shared on Substack, Telegram, X, Facebook and LinkedIn. The accounts &quot;were being used to... <a href="https://thehackernews.com/2026/08/openai-bans-russian-chatgpt-accounts.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Unpatched Kaltura mwEmbed Flaws Could Let Remote Attackers Read Files and Run Code]]></title>
<description><![CDATA[The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura's HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem...]]></description>
<link>https://tsecurity.de/de/3930602/sicherheitsluecken/unpatched-kaltura-mwembed-flaws-could-let-remote-attackers-read-files-and-run-code/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930602/sicherheitsluecken/unpatched-kaltura-mwembed-flaws-could-let-remote-attackers-read-files-and-run-code/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:26 +0200</pubDate>
<content:encoded><![CDATA[<p>The CERT Coordination Center (CERT/CC) has disclosed two unpatched vulnerabilities in Kaltura&#039;s HTML5 video player library that allow a remote, unauthenticated attacker to read arbitrary files from a server and execute code on it. The flaws, tracked as CVE-2026-19913 and CVE-2026-19912, both stem from the same unsafe deserialization in the... <a href="https://thehackernews.com/2026/08/unpatched-kaltura-mwembed-flaws-could.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Nimbus Manticore Expands Toolset With TWOSTROKE-Like Backdoor and SSH Tunneler]]></title>
<description><![CDATA[Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described t...]]></description>
<link>https://tsecurity.de/de/3930601/malware-trojaner-viren/nimbus-manticore-expands-toolset-with-twostroke-like-backdoor-and-ssh-tunneler/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930601/malware-trojaner-viren/nimbus-manticore-expands-toolset-with-twostroke-like-backdoor-and-ssh-tunneler/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:24 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers have discovered additional infrastructure and previously undocumented malware associated with Nimbus Manticore, an Iranian state-sponsored hacking group affiliated with the Islamic Revolutionary Guard Corps (IRGC). Group-IB, in a new analysis published today, described the cyber espionage actor as among the most active... <a href="https://thehackernews.com/2026/08/nimbus-manticore-expands-toolset-with.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs]]></title>
<description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vu...]]></description>
<link>https://tsecurity.de/de/3930600/sicherheitsluecken/cisa-adds-six-exploited-flaws-to-kev-including-netscaler-linux-and-sql-server-bugs/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930600/sicherheitsluecken/cisa-adds-six-exploited-flaws-to-kev-including-netscaler-linux-and-sql-server-bugs/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:18 +0200</pubDate>
<content:encoded><![CDATA[<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability impacting Citrix NetScaler ADC and NetScaler Gateway, citing evidence of active exploitation. The vulnerabilities are listed below - CVE-2019-1068 - A... <a href="https://thehackernews.com/2026/08/cisa-adds-six-exploited-flaws-to-kev.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New GPUThor Rowhammer Defeats ECC on NVIDIA RTX A6000 to Gain Host Root Access]]></title>
<description><![CDATA[Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell. Dubbed GPUTho...]]></description>
<link>https://tsecurity.de/de/3930599/sicherheitsluecken/new-gputhor-rowhammer-defeats-ecc-on-nvidia-rtx-a6000-to-gain-host-root-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930599/sicherheitsluecken/new-gputhor-rowhammer-defeats-ecc-on-nvidia-rtx-a6000-to-gain-host-root-access/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:16 +0200</pubDate>
<content:encoded><![CDATA[<p>Academic researchers have disclosed a Rowhammer attack impacting NVIDIA workstation GPUs with GDDR6 memory that defeats error correction codes (ECC), the mitigation NVIDIA recommends against GPU Rowhammer, and enables denial-of-service (DoS) and privilege escalation to a root shell. Dubbed GPUThor, the attack was developed by researchers at the... <a href="https://thehackernews.com/2026/08/gputhor-rowhammer-defeats-ecc-on-nvidia.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address]]></title>
<description><![CDATA[Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell access and paylo...]]></description>
<link>https://tsecurity.de/de/3930598/malware-trojaner-viren/gocaracal-malware-uses-ethereum-smart-contract-to-fetch-replacement-c2-address/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930598/malware-trojaner-viren/gocaracal-malware-uses-ethereum-smart-contract-to-fetch-replacement-c2-address/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:15 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal, during a June 2026 intrusion at an unnamed communications organization in Venezuela. GoCaracal provides operators with remote shell access and payload execution, while the extended profile adds... <a href="https://thehackernews.com/2026/08/gocaracal-malware-uses-ethereum-smart.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Amazon Kiro Prompt Injection Can Exfiltrate Sensitive Data Through Kiro Powers]]></title>
<description><![CDATA[Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE...]]></description>
<link>https://tsecurity.de/de/3930597/sicherheitsluecken/amazon-kiro-prompt-injection-can-exfiltrate-sensitive-data-through-kiro-powers/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930597/sicherheitsluecken/amazon-kiro-prompt-injection-can-exfiltrate-sensitive-data-through-kiro-powers/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:13 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers have disclosed details of a vulnerability in Amazon Kiro, an artificial intelligence (AI)-powered, agentic integrated development environment (IDE), that could facilitate data exfiltration via prompt injection and Kiro Powers. The security flaw, which does not have a CVE identifier, works against Kiro IDE 0.7.45 on... <a href="https://thehackernews.com/2026/08/amazon-kiro-prompt-injection-can.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ThreatsDay: 296K IoT Botnet, 100+ Water Systems Targeted, SharePoint RCE Chain + 27 New Stories]]></title>
<description><![CDATA[A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing t...]]></description>
<link>https://tsecurity.de/de/3930596/sicherheitsluecken/threatsday-296k-iot-botnet-100-water-systems-targeted-sharepoint-rce-chain-27-new-stories/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930596/sicherheitsluecken/threatsday-296k-iot-botnet-100-water-systems-targeted-sharepoint-rce-chain-27-new-stories/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:11 +0200</pubDate>
<content:encoded><![CDATA[<p>A fake login page. A fake security scan. A fake productivity app. Apparently, pretending to be useful is still one of the easier ways into a machine. The rest of the week gets stranger: botnets borrowing AI, command traffic hiding in public infrastructure, malicious tools waiting before showing their real behavior, exposed systems getting scanned,... <a href="https://thehackernews.com/2026/08/threatsday-296k-iot-botnet-100-water.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Next.js Patches Critical AVIF and Windows Flaws Enabling Unauthenticated RCE]]></title>
<description><![CDATA[Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting ser...]]></description>
<link>https://tsecurity.de/de/3930595/sicherheitsluecken/nextjs-patches-critical-avif-and-windows-flaws-enabling-unauthenticated-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930595/sicherheitsluecken/nextjs-patches-critical-avif-and-windows-flaws-enabling-unauthenticated-rce/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:09 +0200</pubDate>
<content:encoded><![CDATA[<p>Credit: Hacktron Vercel has released security patches for two critical-severity vulnerabilities in the Next.js web framework, both of which allow unauthenticated remote code execution, one exploitable via specially crafted AVIF image files and the other through a path traversal flaw affecting servers that use a Windows filesystem. The Windows path... <a href="https://thehackernews.com/2026/08/nextjs-patches-critical-avif-and.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[OpenAI Says Reward Hacking Drove AI Agents to Exploit Zero-Days and Breach Hugging Face]]></title>
<description><![CDATA[OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations...]]></description>
<link>https://tsecurity.de/de/3930594/ai-nachrichten/openai-says-reward-hacking-drove-ai-agents-to-exploit-zero-days-and-breach-hugging-face/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930594/ai-nachrichten/openai-says-reward-hacking-drove-ai-agents-to-exploit-zero-days-and-breach-hugging-face/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:08 +0200</pubDate>
<content:encoded><![CDATA[<p>OpenAI on Wednesday revealed that reward hacking was a key driver behind the artificial intelligence (AI)-powered hack of Hugging Face last month, adding that it found evidence of misaligned behavior as early as late May. The incident, the company said, took place during cybersecurity evaluations of several OpenAI models, and that it was mainly... <a href="https://thehackernews.com/2026/08/openai-says-reward-hacking-drove-ai.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions]]></title>
<description><![CDATA[PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it's "aware of ...]]></description>
<link>https://tsecurity.de/de/3930593/sicherheitsluecken/papercut-zero-day-exploited-in-attacks-affecting-all-ng-and-mf-versions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930593/sicherheitsluecken/papercut-zero-day-exploited-in-attacks-affecting-all-ng-and-mf-versions/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:06 +0200</pubDate>
<content:encoded><![CDATA[<p>PaperCut has alerted customers that bad actors are actively exploiting a vulnerability impacting all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company has released an emergency patch for v25 and v26 to address the issue. It said it&#039;s &quot;aware of confirmed customer incidents and is treating this... <a href="https://thehackernews.com/2026/08/papercut-zero-day-exploited-in-attacks.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server]]></title>
<description><![CDATA[cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel &...]]></description>
<link>https://tsecurity.de/de/3930592/sicherheitsluecken/critical-cpanel-flaw-could-let-one-hosting-customer-take-root-control-of-a-whole-server/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930592/sicherheitsluecken/critical-cpanel-flaw-could-let-one-hosting-customer-take-root-control-of-a-whole-server/</guid>
<pubDate>Tue, 01 Sep 2026 23:24:03 +0200</pubDate>
<content:encoded><![CDATA[<p>cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user. The vulnerability, assigned the CVE identifier CVE-2026-65643, impacts all supported versions of cPanel &amp;amp; WHM. cPanel described the issue as a critical... <a href="https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[China-Made ZBT Routers Ship With Two Implants Giving Unauthenticated Attackers Root Access]]></title>
<description><![CDATA[VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLAN...]]></description>
<link>https://tsecurity.de/de/3930591/sicherheitsluecken/china-made-zbt-routers-ship-with-two-implants-giving-unauthenticated-attackers-root-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930591/sicherheitsluecken/china-made-zbt-routers-ship-with-two-implants-giving-unauthenticated-attackers-root-access/</guid>
<pubDate>Tue, 01 Sep 2026 23:23:57 +0200</pubDate>
<content:encoded><![CDATA[<p>VulnCheck has disclosed two previously undocumented factory implants in firmware for routers built by Shenzhen Zhibotong Electronics (ZBT), each of which gives an unauthenticated remote attacker the ability to run commands as root on affected devices. The implants, named SPEAKINGSTONE and DARKLANTERN by the company&#039;s zero-day research team, are... <a href="https://thehackernews.com/2026/08/china-made-zbt-routers-ship-with-two.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL]]></title>
<description><![CDATA[ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provi...]]></description>
<link>https://tsecurity.de/de/3930590/sicherheitsluecken/three-cvss-100-servicenow-flaws-could-let-unauthenticated-attackers-execute-code-and-sql/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930590/sicherheitsluecken/three-cvss-100-servicenow-flaws-could-let-unauthenticated-attackers-execute-code-and-sql/</guid>
<pubDate>Tue, 01 Sep 2026 23:23:55 +0200</pubDate>
<content:encoded><![CDATA[<p>ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker. The company said it deployed a security update to hosted instances and provided the update to its partners and self-hosted... <a href="https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Two Unitree G1 EDU Humanoid Robot Flaws Enable Root RCE, One Starts Over Bluetooth]]></title>
<description><![CDATA[Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot's Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with t...]]></description>
<link>https://tsecurity.de/de/3930589/sicherheitsluecken/two-unitree-g1-edu-humanoid-robot-flaws-enable-root-rce-one-starts-over-bluetooth/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930589/sicherheitsluecken/two-unitree-g1-edu-humanoid-robot-flaws-enable-root-rce-one-starts-over-bluetooth/</guid>
<pubDate>Tue, 01 Sep 2026 23:23:53 +0200</pubDate>
<content:encoded><![CDATA[<p>Security researcher Olivier Laflamme has disclosed two independent root remote code execution (RCE) chains affecting the Unitree G1 EDU, including a Bluetooth Low Energy (BLE) path that can reach root on the robot&#039;s Locomotion PC. The flaws are tracked as CVE-2026-76639 and CVE-2026-76640, with the first involving a network-adjacent path through... <a href="https://thehackernews.com/2026/08/two-unitree-g1-edu-humanoid-robot-flaws.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ownCloud Flaw Exploited to Steal Nuclear Records From Philippine Research Body]]></title>
<description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body...]]></description>
<link>https://tsecurity.de/de/3930588/sicherheitsluecken/owncloud-flaw-exploited-to-steal-nuclear-records-from-philippine-research-body/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930588/sicherheitsluecken/owncloud-flaw-exploited-to-steal-nuclear-records-from-philippine-research-body/</guid>
<pubDate>Tue, 01 Sep 2026 23:23:51 +0200</pubDate>
<content:encoded><![CDATA[<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a critical security flaw impacting ownCloud to its Known Exploited Vulnerabilities (KEV) catalog following reports that a Chinese-speaking threat actor weaponized the vulnerability to target a nuclear research body in the Philippines. The vulnerability, tracked as... <a href="https://thehackernews.com/2026/08/snowflake-github-actions-flaw-lets.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication]]></title>
<description><![CDATA[Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. "This vulnerability gives an unauthenticated attacker remote control over PaperCut's tru...]]></description>
<link>https://tsecurity.de/de/3930587/sicherheitsluecken/attackers-chain-two-papercut-flaws-to-execute-code-without-authentication/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930587/sicherheitsluecken/attackers-chain-two-papercut-flaws-to-execute-code-without-authentication/</guid>
<pubDate>Tue, 01 Sep 2026 23:23:50 +0200</pubDate>
<content:encoded><![CDATA[<p>Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening. &quot;This vulnerability gives an unauthenticated attacker remote control over PaperCut&#039;s trusted configuration, which could be used to execute... <a href="https://thehackernews.com/2026/08/attackers-chain-two-papercut-flaws-to.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Cosmos EVM Flaw Exploited After Cosmos Labs Knew Every Blockchain Running It Was Vulnerable]]></title>
<description><![CDATA[Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE...]]></description>
<link>https://tsecurity.de/de/3930586/sicherheitsluecken/cosmos-evm-flaw-exploited-after-cosmos-labs-knew-every-blockchain-running-it-was-vulnerable/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930586/sicherheitsluecken/cosmos-evm-flaw-exploited-after-cosmos-labs-knew-every-blockchain-running-it-was-vulnerable/</guid>
<pubDate>Tue, 01 Sep 2026 23:23:49 +0200</pubDate>
<content:encoded><![CDATA[<p>Cosmos Labs has warned that a critical balance-handling flaw in the shared Cosmos EVM module was exploited to drain funds from six blockchains between August 20 and August 25, 2026. The vulnerability, designated GHSA-7g4w-cg88-2cq2, is rated Critical by Cosmos Labs and was published without a CVE identifier, a weakness classification, or a CVSS... <a href="https://thehackernews.com/2026/08/cosmos-evm-flaw-exploited-after-cosmos.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Five Critical WordPress Plugin and Theme Flaws Enable Site Takeover or RCE]]></title>
<description><![CDATA[Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Pa...]]></description>
<link>https://tsecurity.de/de/3930585/sicherheitsluecken/five-critical-wordpress-plugin-and-theme-flaws-enable-site-takeover-or-rce/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930585/sicherheitsluecken/five-critical-wordpress-plugin-and-theme-flaws-enable-site-takeover-or-rce/</guid>
<pubDate>Tue, 01 Sep 2026 23:23:47 +0200</pubDate>
<content:encoded><![CDATA[<p>Multiple critical security flaws have been disclosed in WordPress plugins and themes, including WPMU DEV Dashboard, Avada, TranslatePress, Pods, and GiveWP, that could lead to authentication bypass, account takeover, and arbitrary code execution. The vulnerabilities, according to Wordfence and Patchstack, are listed below - CVE-2026-76581 (CVSS... <a href="https://thehackernews.com/2026/08/five-critical-wordpress-plugin-and.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Aurora Ransomware Operators Use Cursor AI in Attacks Against 10 Targets]]></title>
<description><![CDATA[Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX's artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed inf...]]></description>
<link>https://tsecurity.de/de/3930584/malware-trojaner-viren/aurora-ransomware-operators-use-cursor-ai-in-attacks-against-10-targets/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930584/malware-trojaner-viren/aurora-ransomware-operators-use-cursor-ai-in-attacks-against-10-targets/</guid>
<pubDate>Tue, 01 Sep 2026 23:23:45 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat actors associated with Aurora (aka Aur0ra) ransomware have been observed using SpaceX&#039;s artificial intelligence (AI)-powered coding assistant Cursor to break into target networks, according to findings from CloudSEK and Gambit Security. The two independent analyses are based on exposed infrastructure associated with the Russian-speaking... <a href="https://thehackernews.com/2026/08/aurora-ransomware-operators-use-cursor.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[ValleyRAT Backdoor Hides in Signed Adware That Users Add to Antivirus Exclusions]]></title>
<description><![CDATA[The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky s...]]></description>
<link>https://tsecurity.de/de/3930583/malware-trojaner-viren/valleyrat-backdoor-hides-in-signed-adware-that-users-add-to-antivirus-exclusions/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930583/malware-trojaner-viren/valleyrat-backdoor-hides-in-signed-adware-that-users-add-to-antivirus-exclusions/</guid>
<pubDate>Tue, 01 Sep 2026 23:23:44 +0200</pubDate>
<content:encoded><![CDATA[<p>The threat actor known as Silver Fox has been observed distributing the ValleyRAT backdoor disguised as a signed Chinese adware application, running the malware under a trusted process to slip past users who add such software to their antivirus exclusions. Russian cybersecurity vendor Kaspersky said the attackers built the disguise around QN... <a href="https://thehackernews.com/2026/08/valleyrat-backdoor-hides-in-signed.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Attackers Exploit Critical Langflow and Rails Flaws in Credential-Probing and C2 Activity]]></title>
<description><![CDATA[Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exp...]]></description>
<link>https://tsecurity.de/de/3930582/sicherheitsluecken/attackers-exploit-critical-langflow-and-rails-flaws-in-credential-probing-and-c2-activity/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930582/sicherheitsluecken/attackers-exploit-critical-langflow-and-rails-flaws-in-credential-probing-and-c2-activity/</guid>
<pubDate>Tue, 01 Sep 2026 23:23:42 +0200</pubDate>
<content:encoded><![CDATA[<p>Threat actors are exploiting two critical flaws impacting Langflow and Ruby on Rails, according to new findings from VulnCheck. The vulnerabilities in question are listed below - CVE-2026-0768 (CVSS score: 9.8) - A lack of proper validation of a user-supplied input vulnerability that could be exploited to execute arbitrary Python code in the... <a href="https://thehackernews.com/2026/09/attackers-exploit-critical-langflow-and.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Russia-Aligned UAC-0099 Plants Nuclear Weapon Prompt in Malware to Disrupt AI Analysis]]></title>
<description><![CDATA[Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that's been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts...]]></description>
<link>https://tsecurity.de/de/3930581/malware-trojaner-viren/russia-aligned-uac-0099-plants-nuclear-weapon-prompt-in-malware-to-disrupt-ai-analysis/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930581/malware-trojaner-viren/russia-aligned-uac-0099-plants-nuclear-weapon-prompt-in-malware-to-disrupt-ai-analysis/</guid>
<pubDate>Tue, 01 Sep 2026 23:23:40 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers have disclosed a new technique dubbed GuardBreaker that&#039;s been put to use by a Russia-aligned threat actor known as UAC-0099 against a target in Ukraine with an aim to interfere with artificial intelligence (AI)-assisted analysis. The idea, ESET said in a series of posts on X, is to deliberately trip a large language... <a href="https://thehackernews.com/2026/09/russia-aligned-uac-0099-plants-nuclear.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Iranian Hackers Pose as Recruiters to Deliver Cross-Platform RATs Through Coding Tests]]></title>
<description><![CDATA[The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) ...]]></description>
<link>https://tsecurity.de/de/3930580/malware-trojaner-viren/iranian-hackers-pose-as-recruiters-to-deliver-cross-platform-rats-through-coding-tests/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930580/malware-trojaner-viren/iranian-hackers-pose-as-recruiters-to-deliver-cross-platform-rats-through-coding-tests/</guid>
<pubDate>Tue, 01 Sep 2026 23:23:39 +0200</pubDate>
<content:encoded><![CDATA[<p>The Iranian Nimbus Manticore hacking group has been attributed to two previously undocumented malware families that highlight the continued evolution of its toolset and likely expand its targeting footprint to infect Linux and Apple macOS systems using cross-platform remote access trojans (RATs) developed using Node.js and JavaScript. Russian... <a href="https://thehackernews.com/2026/09/iranian-hackers-pose-as-recruiters-to.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[13 Malicious Packagist Packages Target Unpatched iPhones to Steal Crypto Wallet Seeds]]></title>
<description><![CDATA[Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. "The inje...]]></description>
<link>https://tsecurity.de/de/3930579/malware-trojaner-viren/13-malicious-packagist-packages-target-unpatched-iphones-to-steal-crypto-wallet-seeds/</link>
<guid isPermaLink="true">https://tsecurity.de/de/3930579/malware-trojaner-viren/13-malicious-packagist-packages-target-unpatched-iphones-to-steal-crypto-wallet-seeds/</guid>
<pubDate>Tue, 01 Sep 2026 23:23:37 +0200</pubDate>
<content:encoded><![CDATA[<p>Cybersecurity researchers have identified a set of 13 malicious Composer theme packages on Packagist that are designed to inject JavaScript into Vietnamese movie and comic streaming sites that install those libraries and initiate the deployment of spyware aimed at unpatched iOS devices. &quot;The injected code runs two operations against a site&#039;s... <a href="https://thehackernews.com/2026/09/13-malicious-packagist-packages-target.html" target="_blank" rel="noopener nofollow">Weiterlesen</a></p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 0,34ms -->