<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="/rss-style.xsl"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/">
<channel>
<title><![CDATA[tsecurity.de - News Radar & Live Feeds]]></title>
<link><![CDATA[https://tsecurity.de/rss/0/Exploit]]></link>
<description><![CDATA[Aktuelle Nachrichten und Updates auf tsecurity.de]]></description>
<language>de-DE</language>
<lastBuildDate>Mon, 05 Oct 2026 04:05:26 +0200</lastBuildDate>
<pubDate>Mon, 05 Oct 2026 04:05:26 +0200</pubDate>
<ttl>15</ttl>
<copyright>2026 tsecurity.de - News Radar &amp; Live Feeds</copyright>
<managingEditor>contact@tsecurity.de (tsecurity.de)</managingEditor>
<webMaster>contact@tsecurity.de (tsecurity.de)</webMaster>
<image>
<url>https://tsecurity.de/templates/mydraft-basis-tsecurity.de/media/logo.png</url>
<title><![CDATA[tsecurity.de - News Radar & Live Feeds]]></title>
<link><![CDATA[https://tsecurity.de/rss/0/Exploit]]></link>
</image>
<atom:link href="https://tsecurity.de/rss/0/Exploit" rel="self" type="application/rss+xml" />
<item>
<title><![CDATA[CVE-2026-88779 — Citrix NetScaler SAML Memory Overflow, Actively Exploited, CISA KEV]]></title>
<description><![CDATA[A memory overflow in Citrix NetScaler's SAML handler is being actively exploited as a zero-day. CISA added CVE-2026-88779 to the Known Exploited Vulnerabilities catalog on October 4, 2026. CVE-2026-88779 (CVSS 4.0: 8.7) — Unauthenticated memory overflow (CWE-119) triggered by malicious SAML reque...]]></description>
<link>https://tsecurity.de/de/4239343/sicherheitsluecken-cve/cve-2026-88779-citrix-netscaler-saml-memory-overflow-actively-exploited-cisa-kev/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4239343/sicherheitsluecken-cve/cve-2026-88779-citrix-netscaler-saml-memory-overflow-actively-exploited-cisa-kev/</guid>
<pubDate>Mon, 05 Oct 2026 03:57:03 +0200</pubDate>
<content:encoded><![CDATA[<p>A memory overflow in Citrix NetScaler&#039;s SAML handler is being actively exploited as a zero-day. CISA added CVE-2026-88779 to the Known Exploited Vulnerabilities catalog on October 4, 2026. CVE-2026-88779 (CVSS 4.0: 8.7) — Unauthenticated memory overflow (CWE-119) triggered by malicious SAML requests. Crashes the appliance&#039;s authentication service,... <a href="https://tsecurity.de/weiterlesen/1000016746/4239343/cve-2026-88779-citrix-netscaler-saml-memory-overflow-actively-exploited-cisa-kev/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Citrix NetScaler SAML 0-Day Vulnerability Actively Exploited in Attacks]]></title>
<description><![CDATA[Citrix has released emergency security updates for a NetScaler SAML zero-day vulnerability that attackers are actively exploiting. Tracked as CVE-2026-88779, the flaw affects customer-managed NetScaler ADC and NetScaler Gateway appliances and can cause denial of service, disrupting access to serv...]]></description>
<link>https://tsecurity.de/de/4239331/sicherheitsluecken-cve/citrix-netscaler-saml-0-day-vulnerability-actively-exploited-in-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4239331/sicherheitsluecken-cve/citrix-netscaler-saml-0-day-vulnerability-actively-exploited-in-attacks/</guid>
<pubDate>Mon, 05 Oct 2026 03:54:09 +0200</pubDate>
<content:encoded><![CDATA[<p>Citrix has released emergency security updates for a NetScaler SAML zero-day vulnerability that attackers are actively exploiting. Tracked as CVE-2026-88779, the flaw affects customer-managed NetScaler ADC and NetScaler Gateway appliances and can cause denial of service, disrupting access to services that depend on these systems. The vulnerability... <a href="https://tsecurity.de/weiterlesen/1000016734/4239331/citrix-netscaler-saml-0-day-vulnerability-actively-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Citrix patches NetScaler SAML zero-day exploited in attacks]]></title>
<description><![CDATA[Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4239118/sicherheitsluecken-cve/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4239118/sicherheitsluecken-cve/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/</guid>
<pubDate>Mon, 05 Oct 2026 00:21:23 +0200</pubDate>
<content:encoded><![CDATA[<p>Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be exploited for remote code execution. [...] <a href="https://tsecurity.de/weiterlesen/1000016521/4239118/citrix-patches-netscaler-saml-zero-day-exploited-in-attacks/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exploit-Index]]></title>
<description><![CDATA[The Ultimate CVE Proof of Concept (PoC) &amp; Exploit Database. A zero-API, high-performance aggregator for 0days, vulnerabilities, and Threat Intelligence. Replacing manual searches for elite SOC teams, DevSecOps, and Bug Bounty Hunters. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4238681/proof-of-concept-poc/exploit-index/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4238681/proof-of-concept-poc/exploit-index/</guid>
<pubDate>Sun, 04 Oct 2026 17:11:14 +0200</pubDate>
<content:encoded><![CDATA[<p>The Ultimate CVE Proof of Concept (PoC) &amp;amp; Exploit Database. A zero-API, high-performance aggregator for 0days, vulnerabilities, and Threat Intelligence. Replacing manual searches for elite SOC teams, DevSecOps, and Bug Bounty Hunters. <a href="https://tsecurity.de/weiterlesen/1000016084/4238681/exploit-index/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-58288 | Genexus Protection Server 9.7.2.10 Windows Service unquoted search path (Exploit 52065 / EDB-52065)]]></title>
<description><![CDATA[A vulnerability, which was classified as problematic, was found in Genexus Protection Server 9.7.2.10. This vulnerability affects unknown code of the component Windows Service. Such manipulation leads to unquoted search path. This vulnerability is documented as CVE-2024-58288. The attack needs to...]]></description>
<link>https://tsecurity.de/de/4238399/sicherheitsluecken-cve/cve-2024-58288-genexus-protection-server-97210-windows-service-unquoted-search-path-exploit-52065-edb-52065/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4238399/sicherheitsluecken-cve/cve-2024-58288-genexus-protection-server-97210-windows-service-unquoted-search-path-exploit-52065-edb-52065/</guid>
<pubDate>Sun, 04 Oct 2026 12:43:53 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability, which was classified as problematic, was found in Genexus Protection Server 9.7.2.10. This vulnerability affects unknown code of the component Windows Service. Such manipulation leads to unquoted search path. This vulnerability is documented as CVE-2024-58288. The attack needs to be performed locally. Additionally, an exploit... <a href="https://tsecurity.de/weiterlesen/1000015802/4238399/cve-2024-58288-genexus-protection-server-97210-windows-service-unquoted-search-path-exploit-52065-edb-52065/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-58292 | xmbforum2 XMB Forum 1.9.12.06 Setting cross site scripting (Exploit 52044 / EDB-52044)]]></title>
<description><![CDATA[A vulnerability classified as problematic was found in xmbforum2 XMB Forum 1.9.12.06. This impacts an unknown function of the component Setting Handler. Executing a manipulation can lead to cross site scripting. This vulnerability is registered as CVE-2024-58292. It is possible to launch the atta...]]></description>
<link>https://tsecurity.de/de/4238397/sicherheitsluecken-cve/cve-2024-58292-xmbforum2-xmb-forum-191206-setting-cross-site-scripting-exploit-52044-edb-52044/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4238397/sicherheitsluecken-cve/cve-2024-58292-xmbforum2-xmb-forum-191206-setting-cross-site-scripting-exploit-52044-edb-52044/</guid>
<pubDate>Sun, 04 Oct 2026 12:43:50 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as problematic was found in xmbforum2 XMB Forum 1.9.12.06. This impacts an unknown function of the component Setting Handler. Executing a manipulation can lead to cross site scripting. This vulnerability is registered as CVE-2024-58292. It is possible to launch the attack remotely. Furthermore, an exploit is available. <a href="https://tsecurity.de/weiterlesen/1000015800/4238397/cve-2024-58292-xmbforum2-xmb-forum-191206-setting-cross-site-scripting-exploit-52044-edb-52044/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-58296 | PhoenixCart CE Phoenix 1.0.8.20 Administration Panel title cross site scripting (Exploit 52015 / EDB-52015)]]></title>
<description><![CDATA[A vulnerability was found in PhoenixCart CE Phoenix 1.0.8.20. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Administration Panel. Such manipulation of the argument Title leads to cross site scripting. This vulnerability is uniquely iden...]]></description>
<link>https://tsecurity.de/de/4238396/sicherheitsluecken-cve/cve-2024-58296-phoenixcart-ce-phoenix-10820-administration-panel-title-cross-site-scripting-exploit-52015-edb-52015/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4238396/sicherheitsluecken-cve/cve-2024-58296-phoenixcart-ce-phoenix-10820-administration-panel-title-cross-site-scripting-exploit-52015-edb-52015/</guid>
<pubDate>Sun, 04 Oct 2026 12:43:46 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in PhoenixCart CE Phoenix 1.0.8.20. It has been declared as problematic. Affected by this issue is some unknown functionality of the component Administration Panel. Such manipulation of the argument Title leads to cross site scripting. This vulnerability is uniquely identified as CVE-2024-58296. The attack can be launched... <a href="https://tsecurity.de/weiterlesen/1000015799/4238396/cve-2024-58296-phoenixcart-ce-phoenix-10820-administration-panel-title-cross-site-scripting-exploit-52015-edb-52015/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-58300 | Siklu MultiHaul TG 1.x Network Request missing authentication (Exploit 51932 / EDB-51932)]]></title>
<description><![CDATA[A vulnerability was found in Siklu MultiHaul TG 1.x. It has been declared as critical. This affects an unknown function of the component Network Request Handler. Executing a manipulation can lead to missing authentication. This vulnerability is tracked as CVE-2024-58300. The attack can be launche...]]></description>
<link>https://tsecurity.de/de/4238395/sicherheitsluecken-cve/cve-2024-58300-siklu-multihaul-tg-1x-network-request-missing-authentication-exploit-51932-edb-51932/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4238395/sicherheitsluecken-cve/cve-2024-58300-siklu-multihaul-tg-1x-network-request-missing-authentication-exploit-51932-edb-51932/</guid>
<pubDate>Sun, 04 Oct 2026 12:43:45 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in Siklu MultiHaul TG 1.x. It has been declared as critical. This affects an unknown function of the component Network Request Handler. Executing a manipulation can lead to missing authentication. This vulnerability is tracked as CVE-2024-58300. The attack can be launched remotely. Moreover, an exploit is present. It is... <a href="https://tsecurity.de/weiterlesen/1000015798/4238395/cve-2024-58300-siklu-multihaul-tg-1x-network-request-missing-authentication-exploit-51932-edb-51932/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-58290 | Xhibiter NFT Marketplace 1.10.2 Collections Endpoint id sql injection (Exploit 52060 / EDB-52060)]]></title>
<description><![CDATA[A vulnerability classified as critical was found in Xhibiter NFT Marketplace 1.10.2. This affects an unknown function of the component Collections Endpoint. Such manipulation of the argument ID leads to sql injection. This vulnerability is traded as CVE-2024-58290. The attack may be launched remo...]]></description>
<link>https://tsecurity.de/de/4238394/sicherheitsluecken-cve/cve-2024-58290-xhibiter-nft-marketplace-1102-collections-endpoint-id-sql-injection-exploit-52060-edb-52060/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4238394/sicherheitsluecken-cve/cve-2024-58290-xhibiter-nft-marketplace-1102-collections-endpoint-id-sql-injection-exploit-52060-edb-52060/</guid>
<pubDate>Sun, 04 Oct 2026 12:43:45 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability classified as critical was found in Xhibiter NFT Marketplace 1.10.2. This affects an unknown function of the component Collections Endpoint. Such manipulation of the argument ID leads to sql injection. This vulnerability is traded as CVE-2024-58290. The attack may be launched remotely. Furthermore, there is an exploit available. <a href="https://tsecurity.de/weiterlesen/1000015797/4238394/cve-2024-58290-xhibiter-nft-marketplace-1102-collections-endpoint-id-sql-injection-exploit-52060-edb-52060/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-58295 | ElkArte Forum 1.1.9 unrestricted upload (Exploit 52026 / EDB-52026)]]></title>
<description><![CDATA[A vulnerability marked as critical has been reported in ElkArte Forum 1.1.9. Affected by this issue is some unknown functionality. This manipulation causes unrestricted upload. This vulnerability is handled as CVE-2024-58295. The attack can be initiated remotely. Additionally, an exploit exists. ...]]></description>
<link>https://tsecurity.de/de/4238393/sicherheitsluecken-cve/cve-2024-58295-elkarte-forum-119-unrestricted-upload-exploit-52026-edb-52026/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4238393/sicherheitsluecken-cve/cve-2024-58295-elkarte-forum-119-unrestricted-upload-exploit-52026-edb-52026/</guid>
<pubDate>Sun, 04 Oct 2026 12:43:45 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability marked as critical has been reported in ElkArte Forum 1.1.9. Affected by this issue is some unknown functionality. This manipulation causes unrestricted upload. This vulnerability is handled as CVE-2024-58295. The attack can be initiated remotely. Additionally, an exploit exists. It is suggested to upgrade the affected component. <a href="https://tsecurity.de/weiterlesen/1000015796/4238393/cve-2024-58295-elkarte-forum-119-unrestricted-upload-exploit-52026-edb-52026/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[CVE-2024-58298 | BMC Compuware iStrobe Web 20.13 JSP Endpoint fileName unrestricted upload (Exploit 51991 / EDB-51991)]]></title>
<description><![CDATA[A vulnerability was found in BMC Compuware iStrobe Web 20.13 and classified as critical. This vulnerability affects unknown code of the component JSP Endpoint. The manipulation of the argument fileName results in unrestricted upload. This vulnerability is identified as CVE-2024-58298. The attack ...]]></description>
<link>https://tsecurity.de/de/4238392/sicherheitsluecken-cve/cve-2024-58298-bmc-compuware-istrobe-web-2013-jsp-endpoint-filename-unrestricted-upload-exploit-51991-edb-51991/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4238392/sicherheitsluecken-cve/cve-2024-58298-bmc-compuware-istrobe-web-2013-jsp-endpoint-filename-unrestricted-upload-exploit-51991-edb-51991/</guid>
<pubDate>Sun, 04 Oct 2026 12:43:43 +0200</pubDate>
<content:encoded><![CDATA[<p>A vulnerability was found in BMC Compuware iStrobe Web 20.13 and classified as critical. This vulnerability affects unknown code of the component JSP Endpoint. The manipulation of the argument fileName results in unrestricted upload. This vulnerability is identified as CVE-2024-58298. The attack can be executed remotely. Additionally, an exploit... <a href="https://tsecurity.de/weiterlesen/1000015795/4238392/cve-2024-58298-bmc-compuware-istrobe-web-2013-jsp-endpoint-filename-unrestricted-upload-exploit-51991-edb-51991/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warlock Ransomware Still Exploits Year-Old SharePoint Flaws to Hit Critical Infrastructure]]></title>
<description><![CDATA[Warlock ransomware continues to exploit unpatched SharePoint flaws to breach water utilities, telecoms, governments, and universities worldwide. Warlock ransomware made headlines back in mid-2025 for exploiting a chain of SharePoint zero-days collectively dubbed ToolShell. More than a year later,...]]></description>
<link>https://tsecurity.de/de/4238223/malware-trojaner-viren/warlock-ransomware-still-exploits-year-old-sharepoint-flaws-to-hit-critical-infrastructure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4238223/malware-trojaner-viren/warlock-ransomware-still-exploits-year-old-sharepoint-flaws-to-hit-critical-infrastructure/</guid>
<pubDate>Sun, 04 Oct 2026 10:47:21 +0200</pubDate>
<content:encoded><![CDATA[<p>Warlock ransomware continues to exploit unpatched SharePoint flaws to breach water utilities, telecoms, governments, and universities worldwide. Warlock ransomware made headlines back in mid-2025 for exploiting a chain of SharePoint zero-days collectively dubbed ToolShell. More than a year later, the same group is still using that door, and it’s... <a href="https://tsecurity.de/weiterlesen/1000015626/4238223/warlock-ransomware-still-exploits-year-old-sharepoint-flaws-to-hit-critical-infrastructure/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Week in review: Researcher breaks into Microsoft analytics service, NetScaler RCE 0-day exploited]]></title>
<description><![CDATA[Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: 16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data A flaw in Titan, an internal Microsoft analytics service, could have let an attacker read employ...]]></description>
<link>https://tsecurity.de/de/4238167/sicherheitsluecken-cve/week-in-review-researcher-breaks-into-microsoft-analytics-service-netscaler-rce-0-day-exploited/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4238167/sicherheitsluecken-cve/week-in-review-researcher-breaks-into-microsoft-analytics-service-netscaler-rce-0-day-exploited/</guid>
<pubDate>Sun, 04 Oct 2026 10:11:07 +0200</pubDate>
<content:encoded><![CDATA[<p>Here’s an overview of some of last week’s most interesting news, articles, interviews and videos: 16-year-old researcher breaks into Microsoft analytics service with access to 17 trillion rows of data A flaw in Titan, an internal Microsoft analytics service, could have let an attacker read employee records and Bing search analytics, a 16-year-old... <a href="https://tsecurity.de/weiterlesen/1000015570/4238167/week-in-review-researcher-breaks-into-microsoft-analytics-service-netscaler-rce-0-day-exploited/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft catches hackers exploiting Zimbra bug before disclosure]]></title>
<description><![CDATA[Attackers were probing the mail server flaw weeks before it had a CVE to its name This article has been indexed from www.theregister.com – Articles Read the original article: Microsoft catches hackers exploiting Zimbra bug before disclosure The post Microsoft catches hackers exploiting Zimbra bug...]]></description>
<link>https://tsecurity.de/de/4237484/it-security-nachrichten/microsoft-catches-hackers-exploiting-zimbra-bug-before-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4237484/it-security-nachrichten/microsoft-catches-hackers-exploiting-zimbra-bug-before-disclosure/</guid>
<pubDate>Sat, 03 Oct 2026 20:42:41 +0200</pubDate>
<content:encoded><![CDATA[<p>Attackers were probing the mail server flaw weeks before it had a CVE to its name This article has been indexed from www.theregister.com – Articles Read the original article: Microsoft catches hackers exploiting Zimbra bug before disclosure The post Microsoft catches hackers exploiting Zimbra bug before disclosure appeared first on IT Security... <a href="https://tsecurity.de/weiterlesen/1000014887/4237484/microsoft-catches-hackers-exploiting-zimbra-bug-before-disclosure/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware]]></title>
<description><![CDATA[The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat...]]></description>
<link>https://tsecurity.de/de/4237309/malware-trojaner-viren/warlock-exploits-sharepoint-flaws-to-disable-security-tools-and-deploy-ransomware/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4237309/malware-trojaner-viren/warlock-exploits-sharepoint-flaws-to-disable-security-tools-and-deploy-ransomware/</guid>
<pubDate>Sat, 03 Oct 2026 17:54:06 +0200</pubDate>
<content:encoded><![CDATA[<p>The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speaking countries. The activity, observed by the Symantec and Carbon Black Threat Hunter Team, has hit critical infrastructure,... <a href="https://tsecurity.de/weiterlesen/1000014712/4237309/warlock-exploits-sharepoint-flaws-to-disable-security-tools-and-deploy-ransomware/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[New Citrix NetScaler SAML Flaw Triggers Crashes and Suspected Exploitation Attempts]]></title>
<description><![CDATA[Citrix NetScaler administrators are reporting repeated appliance crashes and forced reboots after applying emergency updates for recently disclosed zero-day vulnerabilities, with the disruption now linked to a newly observed issue affecting SAML authentication deployments. The incidents have been...]]></description>
<link>https://tsecurity.de/de/4236519/sicherheitsluecken-cve/new-citrix-netscaler-saml-flaw-triggers-crashes-and-suspected-exploitation-attempts/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4236519/sicherheitsluecken-cve/new-citrix-netscaler-saml-flaw-triggers-crashes-and-suspected-exploitation-attempts/</guid>
<pubDate>Sat, 03 Oct 2026 07:52:32 +0200</pubDate>
<content:encoded><![CDATA[<p>Citrix NetScaler administrators are reporting repeated appliance crashes and forced reboots after applying emergency updates for recently disclosed zero-day vulnerabilities, with the disruption now linked to a newly observed issue affecting SAML authentication deployments. The incidents have been reported on internet-facing NetScaler ADC and... <a href="https://tsecurity.de/weiterlesen/1000013922/4236519/new-citrix-netscaler-saml-flaw-triggers-crashes-and-suspected-exploitation-attempts/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Free malware analysis, reverse engineering and exploit development resources]]></title>
<description><![CDATA[submitted by /u/Potential-Couple-745 [link] [comments] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4236345/malware-trojaner-viren/free-malware-analysis-reverse-engineering-and-exploit-development-resources/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4236345/malware-trojaner-viren/free-malware-analysis-reverse-engineering-and-exploit-development-resources/</guid>
<pubDate>Sat, 03 Oct 2026 05:04:26 +0200</pubDate>
<content:encoded><![CDATA[<p>submitted by /u/Potential-Couple-745 [link] [comments] <a href="https://tsecurity.de/weiterlesen/1000013748/4236345/free-malware-analysis-reverse-engineering-and-exploit-development-resources/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[U.S. CISA adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog]]></title>
<description><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE...]]></description>
<link>https://tsecurity.de/de/4236120/sicherheitsluecken-cve/us-cisa-adds-zammad-gmbh-zammad-flaws-to-its-known-exploited-vulnerabilities-catalog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4236120/sicherheitsluecken-cve/us-cisa-adds-zammad-gmbh-zammad-flaws-to-its-known-exploited-vulnerabilities-catalog/</guid>
<pubDate>Sat, 03 Oct 2026 01:01:36 +0200</pubDate>
<content:encoded><![CDATA[<p>U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Zammad GmbH Zammad flaws to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added the following vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog: CVE-2026-102489 (CVSS score of 9.4) Zammad GmbH Zammad... <a href="https://tsecurity.de/weiterlesen/1000013523/4236120/us-cisa-adds-zammad-gmbh-zammad-flaws-to-its-known-exploited-vulnerabilities-catalog/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[FortiMail zero-day exploited in attacks as CISA urges immediate patching]]></title>
<description><![CDATA[A critical zero-day vulnerability in Fortinet FortiMail is being actively exploited in the wild, prompting the US Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2026-104286 and rated 9.8 (Critical) on th...]]></description>
<link>https://tsecurity.de/de/4235652/sicherheitsluecken-cve/fortimail-zero-day-exploited-in-attacks-as-cisa-urges-immediate-patching/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235652/sicherheitsluecken-cve/fortimail-zero-day-exploited-in-attacks-as-cisa-urges-immediate-patching/</guid>
<pubDate>Fri, 02 Oct 2026 19:52:46 +0200</pubDate>
<content:encoded><![CDATA[<p>A critical zero-day vulnerability in Fortinet FortiMail is being actively exploited in the wild, prompting the US Cybersecurity and Infrastructure Security Agency (CISA) to add the flaw to its Known Exploited Vulnerabilities (KEV) catalog. Tracked as CVE-2026-104286 and rated 9.8 (Critical) on the CVSS scale, the vulnerability allows... <a href="https://tsecurity.de/weiterlesen/1000013055/4235652/fortimail-zero-day-exploited-in-attacks-as-cisa-urges-immediate-patching/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical FortiMail zero-day exploited in the wild (CVE-2026-104286)]]></title>
<description><![CDATA[Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway. Fortinet says the flaw has been reported to be exploited in the wild, and urges customers to apply the workaround it shared until fixes are available. A...]]></description>
<link>https://tsecurity.de/de/4235646/sicherheitsluecken-cve/critical-fortimail-zero-day-exploited-in-the-wild-cve-2026-104286/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235646/sicherheitsluecken-cve/critical-fortimail-zero-day-exploited-in-the-wild-cve-2026-104286/</guid>
<pubDate>Fri, 02 Oct 2026 19:50:45 +0200</pubDate>
<content:encoded><![CDATA[<p>Fortinet is warning customers that attackers are exploiting a zero-day vulnerability (CVE-2026-104286) in FortiMail, its email security gateway. Fortinet says the flaw has been reported to be exploited in the wild, and urges customers to apply the workaround it shared until fixes are available. About CVE-2026-104286 “An Improper Limitation of a... <a href="https://tsecurity.de/weiterlesen/1000013049/4235646/critical-fortimail-zero-day-exploited-in-the-wild-cve-2026-104286/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[NEAR Intents identifiziert Hacker eines $3,8 Millionen Exploits und setzt Frist zur Rückgabe]]></title>
<description><![CDATA[NEAR Intents hat den Angreifer hinter einem Exploit in Höhe von $3,8 Millionen identifiziert und ihm 48 Stunden Zeit gegeben, die gestohlenen Gelder ... Weiterlesen]]></description>
<link>https://tsecurity.de/de/4235621/hacking-pentesting/near-intents-identifiziert-hacker-eines-38-millionen-exploits-und-setzt-frist-zur-rueckgabe/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235621/hacking-pentesting/near-intents-identifiziert-hacker-eines-38-millionen-exploits-und-setzt-frist-zur-rueckgabe/</guid>
<pubDate>Fri, 02 Oct 2026 19:47:10 +0200</pubDate>
<content:encoded><![CDATA[<p>NEAR Intents hat den Angreifer hinter einem Exploit in Höhe von $3,8 Millionen identifiziert und ihm 48 Stunden Zeit gegeben, die gestohlenen Gelder ... <a href="https://tsecurity.de/weiterlesen/1000013024/4235621/near-intents-identifiziert-hacker-eines-38-millionen-exploits-und-setzt-frist-zur-rueckgabe/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sony PS5 Relapse Jailbreak Exploit Uses JSC Memory Corruption and Kernel UAF]]></title>
<description><![CDATA[A newly released PlayStation 5 jailbreak chain, called Relapse, targets PS5 and PS5 Pro consoles running firmware versions 7.00 through 13.60. This jailbreak combines a browser-based JavaScriptCore memory corruption technique with a kernel use-after-free race condition. The project’s source code ...]]></description>
<link>https://tsecurity.de/de/4235550/it-security-nachrichten/sony-ps5-relapse-jailbreak-exploit-uses-jsc-memory-corruption-and-kernel-uaf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235550/it-security-nachrichten/sony-ps5-relapse-jailbreak-exploit-uses-jsc-memory-corruption-and-kernel-uaf/</guid>
<pubDate>Fri, 02 Oct 2026 19:26:18 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly released PlayStation 5 jailbreak chain, called Relapse, targets PS5 and PS5 Pro consoles running firmware versions 7.00 through 13.60. This jailbreak combines a browser-based JavaScriptCore memory corruption technique with a kernel use-after-free race condition. The project’s source code and documentation outline a two-stage chain that... <a href="https://tsecurity.de/weiterlesen/1000012953/4235550/sony-ps5-relapse-jailbreak-exploit-uses-jsc-memory-corruption-and-kernel-uaf/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[MSSQL Post-Exploitation Toolkit Could Enable Credential Theft and Lateral Movement Attacks]]></title>
<description><![CDATA[An exposed attacker server containing an MSSQL-focused post-exploitation toolkit, credential-harvesting artifacts, and stolen material. The discovery revealed how attackers could use Microsoft SQL Server access to run commands, collect credentials, and prepare attacks against additional systems. ...]]></description>
<link>https://tsecurity.de/de/4235536/it-security-nachrichten/mssql-post-exploitation-toolkit-could-enable-credential-theft-and-lateral-movement-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235536/it-security-nachrichten/mssql-post-exploitation-toolkit-could-enable-credential-theft-and-lateral-movement-attacks/</guid>
<pubDate>Fri, 02 Oct 2026 19:26:10 +0200</pubDate>
<content:encoded><![CDATA[<p>An exposed attacker server containing an MSSQL-focused post-exploitation toolkit, credential-harvesting artifacts, and stolen material. The discovery revealed how attackers could use Microsoft SQL Server access to run commands, collect credentials, and prepare attacks against additional systems. The staging server, located at 151.243.232.123, was... <a href="https://tsecurity.de/weiterlesen/1000012939/4235536/mssql-post-exploitation-toolkit-could-enable-credential-theft-and-lateral-movement-attacks/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[PS5 Relapse Jailbreak Uses WebKit and Kernel Exploit to Gain Read/Write Access]]></title>
<description><![CDATA[A newly published proof-of-concept called Relapse-Exploit targets PlayStation 5 consoles running firmware versions 7.00 through 13.60, chaining a browser-based WebKit compromise with a kernel use-after-free vulnerability to obtain kernel-level read/write access. The public project frames the rele...]]></description>
<link>https://tsecurity.de/de/4235531/sicherheitsluecken-cve/ps5-relapse-jailbreak-uses-webkit-and-kernel-exploit-to-gain-readwrite-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235531/sicherheitsluecken-cve/ps5-relapse-jailbreak-uses-webkit-and-kernel-exploit-to-gain-readwrite-access/</guid>
<pubDate>Fri, 02 Oct 2026 19:26:10 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly published proof-of-concept called Relapse-Exploit targets PlayStation 5 consoles running firmware versions 7.00 through 13.60, chaining a browser-based WebKit compromise with a kernel use-after-free vulnerability to obtain kernel-level read/write access. The public project frames the release as material for educational and... <a href="https://tsecurity.de/weiterlesen/1000012934/4235531/ps5-relapse-jailbreak-uses-webkit-and-kernel-exploit-to-gain-readwrite-access/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Zammad 0-Day Vulnerabilities Exploited to Gain Remote Code Execution and Root Access]]></title>
<description><![CDATA[Two critical Zammad zero-day flaws, reportedly exploited against the Dutch Institute for Vulnerability Disclosure (DIVD), could allow session hijacking, remote command execution as the Zammad service user, and potential root privilege escalation. The vulnerabilities are tracked as CVE-2026-102489...]]></description>
<link>https://tsecurity.de/de/4235475/sicherheitsluecken-cve/zammad-0-day-vulnerabilities-exploited-to-gain-remote-code-execution-and-root-access/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235475/sicherheitsluecken-cve/zammad-0-day-vulnerabilities-exploited-to-gain-remote-code-execution-and-root-access/</guid>
<pubDate>Fri, 02 Oct 2026 19:25:51 +0200</pubDate>
<content:encoded><![CDATA[<p>Two critical Zammad zero-day flaws, reportedly exploited against the Dutch Institute for Vulnerability Disclosure (DIVD), could allow session hijacking, remote command execution as the Zammad service user, and potential root privilege escalation. The vulnerabilities are tracked as CVE-2026-102489 and CVE-2026-102490. DIVD published the findings... <a href="https://tsecurity.de/weiterlesen/1000012878/4235475/zammad-0-day-vulnerabilities-exploited-to-gain-remote-code-execution-and-root-access/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fortinet warns that critical flaw in FortiMail is facing exploitation]]></title>
<description><![CDATA[Security researchers warn that attackers can gain access to credentials, stored mail and other connected systems. This article has been indexed from Cybersecurity Dive – Latest News Read the original article: Fortinet warns that critical flaw in FortiMail is facing exploitation The post Fortinet ...]]></description>
<link>https://tsecurity.de/de/4235466/it-security-nachrichten/fortinet-warns-that-critical-flaw-in-fortimail-is-facing-exploitation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235466/it-security-nachrichten/fortinet-warns-that-critical-flaw-in-fortimail-is-facing-exploitation/</guid>
<pubDate>Fri, 02 Oct 2026 19:25:43 +0200</pubDate>
<content:encoded><![CDATA[<p>Security researchers warn that attackers can gain access to credentials, stored mail and other connected systems. This article has been indexed from Cybersecurity Dive – Latest News Read the original article: Fortinet warns that critical flaw in FortiMail is facing exploitation The post Fortinet warns that critical flaw in FortiMail is facing... <a href="https://tsecurity.de/weiterlesen/1000012869/4235466/fortinet-warns-that-critical-flaw-in-fortimail-is-facing-exploitation/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Medusa Ransomware: Why Rapid Exploitation and Data Theft Demand a Prevention-First Strategy]]></title>
<description><![CDATA[threat intelligence brief · medusa ransomware Sector Medical · Education · Legal · Insurance · Technology · Manufacturing Brief An updated joint advisory from CISA, the FBI, and HHS reports that Medusa has now impacted more than 500 victims across critical infrastructure sectors. Affiliates explo...]]></description>
<link>https://tsecurity.de/de/4235425/malware-trojaner-viren/medusa-ransomware-why-rapid-exploitation-and-data-theft-demand-a-prevention-first-strategy/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235425/malware-trojaner-viren/medusa-ransomware-why-rapid-exploitation-and-data-theft-demand-a-prevention-first-strategy/</guid>
<pubDate>Fri, 02 Oct 2026 19:23:49 +0200</pubDate>
<content:encoded><![CDATA[<p>threat intelligence brief · medusa ransomware Sector Medical · Education · Legal · Insurance · Technology · Manufacturing Brief An updated joint advisory from CISA, the FBI, and HHS reports that Medusa has now impacted more than 500 victims across critical infrastructure sectors. Affiliates exploit exposed systems and  ⟶ <a href="https://tsecurity.de/weiterlesen/1000012828/4235425/medusa-ransomware-why-rapid-exploitation-and-data-theft-demand-a-prevention-first-strategy/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical Cisco Catalyst SD-WAN Zero-Day Under Active Exploitation]]></title>
<description><![CDATA[Vulnerability in Cisco Catalyst SD-WAN Manager allows an unauthenticated, remote attacker to access systems with admin privileges Weiterlesen]]></description>
<link>https://tsecurity.de/de/4235420/sicherheitsluecken-cve/critical-cisco-catalyst-sd-wan-zero-day-under-active-exploitation/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235420/sicherheitsluecken-cve/critical-cisco-catalyst-sd-wan-zero-day-under-active-exploitation/</guid>
<pubDate>Fri, 02 Oct 2026 19:23:25 +0200</pubDate>
<content:encoded><![CDATA[<p>Vulnerability in Cisco Catalyst SD-WAN Manager allows an unauthenticated, remote attacker to access systems with admin privileges <a href="https://tsecurity.de/weiterlesen/1000012823/4235420/critical-cisco-catalyst-sd-wan-zero-day-under-active-exploitation/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Two Zero-Days Exploited in Attack on Dutch Institute for Vulnerability Disclosure]]></title>
<description><![CDATA[The Dutch Institute for Vulnerability Disclosure reveals agentic AI-powered attack using Zammad zero-days Weiterlesen]]></description>
<link>https://tsecurity.de/de/4235419/sicherheitsluecken-cve/two-zero-days-exploited-in-attack-on-dutch-institute-for-vulnerability-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235419/sicherheitsluecken-cve/two-zero-days-exploited-in-attack-on-dutch-institute-for-vulnerability-disclosure/</guid>
<pubDate>Fri, 02 Oct 2026 19:23:25 +0200</pubDate>
<content:encoded><![CDATA[<p>The Dutch Institute for Vulnerability Disclosure reveals agentic AI-powered attack using Zammad zero-days <a href="https://tsecurity.de/weiterlesen/1000012822/4235419/two-zero-days-exploited-in-attack-on-dutch-institute-for-vulnerability-disclosure/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fortinet warns of critical FortiMail flaw exploited in zero-day attacks]]></title>
<description><![CDATA[Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...] Weiterlesen]]></description>
<link>https://tsecurity.de/de/4235377/sicherheitsluecken-cve/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235377/sicherheitsluecken-cve/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/</guid>
<pubDate>Fri, 02 Oct 2026 19:22:39 +0200</pubDate>
<content:encoded><![CDATA[<p>Fortinet is warning customers of a critical FortiMail vulnerability, tracked as CVE-2026-104286, that is being actively exploited in zero-day attacks to execute unauthorized code or commands on vulnerable devices. [...] <a href="https://tsecurity.de/weiterlesen/1000012780/4235377/fortinet-warns-of-critical-fortimail-flaw-exploited-in-zero-day-attacks/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[BigDiskBuster: Neuer Defender-Exploit soll Updates lahmlegen - B2B Cyber Security]]></title>
<description><![CDATA[Chaotic Eclipse: Ein Proof-of-Concept mit dem Namen BigDiskBuster zeigt eine neue Schwachstelle im Update-Prozess von Microsoft Defender. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4235360/sicherheitsluecken-cve/bigdiskbuster-neuer-defender-exploit-soll-updates-lahmlegen-b2b-cyber-security/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235360/sicherheitsluecken-cve/bigdiskbuster-neuer-defender-exploit-soll-updates-lahmlegen-b2b-cyber-security/</guid>
<pubDate>Fri, 02 Oct 2026 19:22:32 +0200</pubDate>
<content:encoded><![CDATA[<p>Chaotic Eclipse: Ein Proof-of-Concept mit dem Namen BigDiskBuster zeigt eine neue Schwachstelle im Update-Prozess von Microsoft Defender. <a href="https://tsecurity.de/weiterlesen/1000012763/4235360/bigdiskbuster-neuer-defender-exploit-soll-updates-lahmlegen-b2b-cyber-security/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action]]></title>
<description><![CDATA[CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system. The post Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4235335/sicherheitsluecken-cve/exploited-fortinet-fortimail-zero-day-calls-for-urgent-action/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235335/sicherheitsluecken-cve/exploited-fortinet-fortimail-zero-day-calls-for-urgent-action/</guid>
<pubDate>Fri, 02 Oct 2026 19:22:17 +0200</pubDate>
<content:encoded><![CDATA[<p>CVE-2026-104286 is a critical-severity path traversal vulnerability that could allow attackers to write arbitrary files to the system. The post Exploited Fortinet FortiMail Zero-Day Calls for Urgent Action appeared first on SecurityWeek. <a href="https://tsecurity.de/weiterlesen/1000012738/4235335/exploited-fortinet-fortimail-zero-day-calls-for-urgent-action/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks]]></title>
<description><![CDATA[The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025. The post Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks appeared first on SecurityWeek. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4235333/it-security-nachrichten/warlock-expands-sharepoint-exploitation-in-critical-infrastructure-attacks/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235333/it-security-nachrichten/warlock-expands-sharepoint-exploitation-in-critical-infrastructure-attacks/</guid>
<pubDate>Fri, 02 Oct 2026 19:22:17 +0200</pubDate>
<content:encoded><![CDATA[<p>The China-based hacking group has been exploiting SharePoint vulnerabilities since July 2025. The post Warlock Expands SharePoint Exploitation in Critical Infrastructure Attacks appeared first on SecurityWeek. <a href="https://tsecurity.de/weiterlesen/1000012736/4235333/warlock-expands-sharepoint-exploitation-in-critical-infrastructure-attacks/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Critical FortiMail Zero-Day Flaw Exploited in Attacks Allows Unauthenticated Arbitrary File Writes]]></title>
<description><![CDATA[The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8...]]></description>
<link>https://tsecurity.de/de/4235299/sicherheitsluecken-cve/critical-fortimail-zero-day-flaw-exploited-in-attacks-allows-unauthenticated-arbitrary-file-writes/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235299/sicherheitsluecken-cve/critical-fortimail-zero-day-flaw-exploited-in-attacks-allows-unauthenticated-arbitrary-file-writes/</guid>
<pubDate>Fri, 02 Oct 2026 19:22:11 +0200</pubDate>
<content:encoded><![CDATA[<p>The U.S. Cybersecurity and Infrastructure Security Agency (CISA), on Thursday, added a critical security flaw impacting Fortinet FortiMail to its Known Exploited Vulnerabilities (KEV) catalog, following reports of active exploitation. The vulnerability, tracked as CVE-2026-104286 (CVSS score: 9.8), allows unauthenticated attackers to write... <a href="https://tsecurity.de/weiterlesen/1000012702/4235299/critical-fortimail-zero-day-flaw-exploited-in-attacks-allows-unauthenticated-arbitrary-file-writes/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Microsoft catches hackers exploiting Zimbra bug before disclosure]]></title>
<description><![CDATA[Attackers were poking at a critical Zimbra mail server bug weeks before it was publicly disclosed, and then moved on to steal credentials, raid mailboxes, and take deeper control of compromised systems. Microsoft Threat Intelligence said it tracked exploitation of CVE-2026-73570, an unauthenticat...]]></description>
<link>https://tsecurity.de/de/4235141/sicherheitsluecken-cve/microsoft-catches-hackers-exploiting-zimbra-bug-before-disclosure/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235141/sicherheitsluecken-cve/microsoft-catches-hackers-exploiting-zimbra-bug-before-disclosure/</guid>
<pubDate>Fri, 02 Oct 2026 19:21:16 +0200</pubDate>
<content:encoded><![CDATA[<p>Attackers were poking at a critical Zimbra mail server bug weeks before it was publicly disclosed, and then moved on to steal credentials, raid mailboxes, and take deeper control of compromised systems. Microsoft Threat Intelligence said it tracked exploitation of CVE-2026-73570, an unauthenticated command injection vulnerability in Zimbra... <a href="https://tsecurity.de/weiterlesen/1000012544/4235141/microsoft-catches-hackers-exploiting-zimbra-bug-before-disclosure/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Fortinet sounds the alarm over actively exploited FortiMail zero-day]]></title>
<description><![CDATA[Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet's email security ...]]></description>
<link>https://tsecurity.de/de/4235124/sicherheitsluecken-cve/fortinet-sounds-the-alarm-over-actively-exploited-fortimail-zero-day/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4235124/sicherheitsluecken-cve/fortinet-sounds-the-alarm-over-actively-exploited-fortimail-zero-day/</guid>
<pubDate>Fri, 02 Oct 2026 19:21:15 +0200</pubDate>
<content:encoded><![CDATA[<p>Fortinet is warning customers to lock down FortiMail after attackers started exploiting a critical bug that lets them write files to vulnerable systems without logging in. The flaw, tracked as CVE-2026-104286, carries a CVSS score of 9.8 and affects multiple versions of Fortinet&#039;s email security platform. Fortinet describes the vulnerability as a... <a href="https://tsecurity.de/weiterlesen/1000012527/4235124/fortinet-sounds-the-alarm-over-actively-exploited-fortimail-zero-day/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Anthropic Finds China’s GLM-5.3 Can Build Working Cyber Exploits]]></title>
<description><![CDATA[Anthropic found China’s GLM-5.3 can build working cyber exploits with limited human help, with downloadable weights allowing users to alter safeguards. Weiterlesen]]></description>
<link>https://tsecurity.de/de/4234732/it-nachrichten/anthropic-finds-chinas-glm-53-can-build-working-cyber-exploits/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4234732/it-nachrichten/anthropic-finds-chinas-glm-53-can-build-working-cyber-exploits/</guid>
<pubDate>Fri, 02 Oct 2026 19:19:17 +0200</pubDate>
<content:encoded><![CDATA[<p>Anthropic found China’s GLM-5.3 can build working cyber exploits with limited human help, with downloadable weights allowing users to alter safeguards. <a href="https://tsecurity.de/weiterlesen/1000012135/4234732/anthropic-finds-chinas-glm-53-can-build-working-cyber-exploits/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[Sony PS5 Relapse Jailbreak Exploit Uses JSC Memory Corruption and Kernel UAF]]></title>
<description><![CDATA[A newly released PlayStation 5 jailbreak chain, called Relapse, targets PS5 and PS5 Pro consoles running firmware versions 7.00 through 13.60. This jailbreak combines a browser-based JavaScriptCore memory corruption technique with a kernel use-after-free race condition. The project’s source code ...]]></description>
<link>https://tsecurity.de/de/4234523/hacking-pentesting/sony-ps5-relapse-jailbreak-exploit-uses-jsc-memory-corruption-and-kernel-uaf/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4234523/hacking-pentesting/sony-ps5-relapse-jailbreak-exploit-uses-jsc-memory-corruption-and-kernel-uaf/</guid>
<pubDate>Fri, 02 Oct 2026 19:17:34 +0200</pubDate>
<content:encoded><![CDATA[<p>A newly released PlayStation 5 jailbreak chain, called Relapse, targets PS5 and PS5 Pro consoles running firmware versions 7.00 through 13.60. This jailbreak combines a browser-based JavaScriptCore memory corruption technique with a kernel use-after-free race condition. The project’s source code and documentation outline a two-stage chain that... <a href="https://tsecurity.de/weiterlesen/1000011926/4234523/sony-ps5-relapse-jailbreak-exploit-uses-jsc-memory-corruption-and-kernel-uaf/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
<item>
<title><![CDATA[U.S. CISA adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog]]></title>
<description><![CDATA[U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiMail flaw, tracked as CVE-2026-104286 (CVSS score of 9.8), to its Known ...]]></description>
<link>https://tsecurity.de/de/4234521/sicherheitsluecken-cve/us-cisa-adds-fortinet-fortimail-flaw-to-its-known-exploited-vulnerabilities-catalog/</link>
<guid isPermaLink="true">https://tsecurity.de/de/4234521/sicherheitsluecken-cve/us-cisa-adds-fortinet-fortimail-flaw-to-its-known-exploited-vulnerabilities-catalog/</guid>
<pubDate>Fri, 02 Oct 2026 19:17:30 +0200</pubDate>
<content:encoded><![CDATA[<p>U.S. Cybersecurity and Infrastructure Security Agency (CISA) adds Fortinet FortiMail flaw to its Known Exploited Vulnerabilities catalog. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) added a Fortinet FortiMail flaw, tracked as CVE-2026-104286 (CVSS score of 9.8), to its Known Exploited Vulnerabilities (KEV) catalog. The flaw is... <a href="https://tsecurity.de/weiterlesen/1000011924/4234521/us-cisa-adds-fortinet-fortimail-flaw-to-its-known-exploited-vulnerabilities-catalog/" target="_blank" rel="noopener noreferrer">Weiterlesen</a></p>]]></content:encoded>
</item>
</channel>
</rss>
<!-- Generated in 2,03ms -->