RSS-Feeds
Heise Security-Alert
- Nvidia: Datenabfluss durch Sicherheitsleck in Grafiktreiber möglich 20. Januar 2025Nvidia hat Sicherheitslücken in seinen Grafikkartentreibern entdeckt. Angreifer können dadurch Informationen abgreifen. Updates stehen bereit.
- WordPress-Plug-in W3 Total Cache: Potenziell 1 Millionen Websites attackierbar 17. Januar 2025Stimmen die Voraussetzungen, können Angreifer Websites mit dem WordPress-Plug-in W3 Total Cache ins Visier nehmen. Ein Sicherheitspatch ist verfügbar.
- Es kann Schadcode auf HPE Aruba Networking AOS Controllers und Gateways gelangen 16. Januar 2025Netzwerktechnik von HPE Aruba ist verwundbar. Aktuelle Updates schließen insgesamt zwei Sicherheitslücken.
- Updates gegen Lecks in Ivanti Application Control Engine, Avalanche und EPM 16. Januar 2025Ivanti hat Sicherheitsupdates für Application Control Engine, Avalanche und EPM veröffentlicht. Sie bessern teils kritische Lecks aus.
BSI Bund-Cert
- Version 1.0: Microsoft Windows – Kritische Schwachstelle in Windows OLE 14. Januar 2025
- Version 1.0: Fortinet FortiOS & FortiProxy – Aktive Ausnutzung einer Zero-Day Schwachstelle 14. Januar 2025
- Version 1.0: Ivanti Connect Secure – Zero-Day Angriffe beobachtet 9. Januar 2025
- Version 1.0: Brute-Force-Angriffe auf exponierte Systeme 10. Dezember 2024
Bruce Schneier
- Biden Signs New Cybersecurity Order 20. Januar 2025President Biden has signed a new cybersecurity order. It has a bunch of provisions, most notably using the US governments procurement power to improve cybersecurity practices industry-wide. Some details: The core of the executive order is an array of mandates for protecting government networks based on lessons learned from recent major incidents—namely, the security failures […]
- Friday Squid Blogging: Opioid Alternatives from Squid Research 17. Januar 2025Is there nothing that squid research can’t solve? “If you’re working with an organism like squid that can edit genetic information way better than any other organism, then it makes sense that that might be useful for a therapeutic application like deadening pain,” he said. […] Researchers hope to mimic how squid and octopus use […]
- Social Engineering to Disable iMessage Protections 17. Januar 2025I am always interested in new phishing tricks, and watching them spread across the ecosystem. A few days ago I started getting phishing SMS messages with a new twist. They were standard messages about delayed packages or somesuch, with the goal of getting me to click on a link and entering some personal information into […]
- FBI Deletes PlugX Malware from Thousands of Computers 16. Januar 2025According to a DOJ press release, the FBI was able to delete the Chinese-used PlugX malware from “approximately 4,258 U.S.-based computers and networks.” Details: To retrieve information from and send commands to the hacked machines, the malware connects to a command-and-control server that is operated by the hacking group. According to the FBI, at least […]
Feeds
Die nachfolgenden Feeds sollen aktuelle Nachrichten wiedergeben, so dass hierauf gegebenfalls schnell reagiert werden kann.