Critical ServiceNow code execution flaw now exploited in attacks
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. [...]
Quelle ansehen
Hugging Face: IT-Sicherheitsvorfall bei KI-Plattform
Die Plattform zum Teilen quelloffener KI-Modelle und -Datensätze Hugging Face wurde Opfer eines Cyberangriffs einer KI.
Quelle ansehen
Volkswagen sperrt Nutzer von Custom ROMs aus der VW-App aus
Volkswagen hat den Zugriff auf seine App für Nutzer von Custom ROMs wie GrapheneOS oder LineageOS gesperrt. Grund ist die Google Play Integrity API.
Quelle ansehen
Kritische Sicherheitslücke: Schadcode kann auf Nginx-Server schlüpfen
Angreifer können Nginx Open Source und Nginx Plus attackieren. Sicherheitsupdates sind verfügbar.
Quelle ansehen
Von Creeper zu Morris zu Zeus – eine kleine Geschichte der Malware
Malware ist keine Erfindung des 21. Jahrhunderts. Seit mindestens 40 Jahren ärgert sie User und Admins. Aber welcher Schädling fing damit an? Diese Frage lässt sich nicht so ein...
Quelle ansehen
Shark-Saugroboter: Sicherheitslücke ermöglicht Übernahme aus dem Netz
Ein IT-Sicherheitsforscher hat eine Schwachstelle in Shark-Saugrobotern entdeckt, die die Übernahme aus dem Internet ermöglicht.
Quelle ansehen
SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems...
Quelle ansehen
World's Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent
In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The co...
Quelle ansehen
Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution
F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-...
Quelle ansehen
Googles cleverer KI-Schachzug – oder: wer kontrolliert zukünftig den KI-Markt?
Macht das Modell den entscheidenden Unterschied? Google zumindest scheint eher auf den richtigen Rahmen zu setzen als das eigene Top-Modell. Eine Analyse.
Quelle ansehen
Hackers abuse ViPNet software to target Russian govt agencies
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]
Quelle ansehen
SonicWall SMA Zero-Days Exploited Before Disclosure to Gain Root Access
A previously undocumented threat actor has been attributed to the exploitation of recently disclosed SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances as zero-days...
Quelle ansehen
UAC-0145 Uses ClickFix CAPTCHAs to Infect Ukrainian Devices wih Malware
Russian state-sponsored threat actors have been observed leveraging the infamous ClickFix strategy to trick Ukrainian targets into infecting their own machines with data-stealin...
Quelle ansehen
Windows-Update außer der Reihe korrigiert Performanceprobleme
Microsoft verteilt ein ungeplantes Windows-Update. Es soll Probleme beheben, die insbesondere bei Dell-Computern aufgetreten sind.
Quelle ansehen
Update now: 7-Zip fixes RCE flaw exploitable with malicious archives
7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted ...
Quelle ansehen
WordPress Core "wp2shell" RCE flaws get public exploits, patch now
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch the...
Quelle ansehen
Microsoft warns of surge in ACR Stealer attacks on customers
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise cus...
Quelle ansehen
The Future of Age Verification: Your Face Never Leaves Your Device
As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age...
Quelle ansehen
Hinweis: Dies ist ein News-Aggregator. Das Copyright liegt bei den jeweiligen Webseiten. Die Links wurden zum Zeitpunkt der Abfrage als virenfrei und sicher bewertet. Bitte dennoch mit der nötigen Vorsicht prüfen.