Consulting News

News und Newsarchiv für unsere NC Consultants
Firefox Add-on

Estée Lauder discloses data breach via Oracle E-Business flaw

Erfasst 21.07.2026 00:39 | BleepingComputer
Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) ope...
Quelle ansehen

Hackers steal $23.7 million in crypto from Ostium in off-chain attack

Erfasst 21.07.2026 00:24 | BleepingComputer
The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed...
Quelle ansehen

SonicWall SMA1000 flaws exploited as zero-days to push custom malware

Erfasst 21.07.2026 00:24 | BleepingComputer
Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN applian...
Quelle ansehen

Cursor, Codex, Gemini CLI, Antigravity hit by sandbox escapes

Erfasst 20.07.2026 23:24 | BleepingComputer
Researchers escaped the sandboxes in Cursor, Codex, Gemini CLI and Antigravity by having the AI agent write files that trusted host tools later run. Multiple CVEs, patches, and ...
Quelle ansehen

JadePuffer agentic attacks now target AI model data with ransomware

Erfasst 20.07.2026 23:09 | BleepingComputer
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model ...
Quelle ansehen

New HollowGraph malware uses Microsoft Graph for stealthy C2 comms

Erfasst 20.07.2026 19:54 | BleepingComputer
A malicious component dubbed HollowGraph uses the calendar feature in compromised Microsoft 365 mailboxes as a command-and-control channel to receive attacker commands and exfil...
Quelle ansehen

An AI SOC Evaluation Guide for Security Leaders

Erfasst 20.07.2026 16:08 | BleepingComputer
Choosing an AI SOC platform requires understanding how it will perform in your own environment, not just during an evaluation. Prophet Security shares a practical framework for ...
Quelle ansehen

Hugging Face discloses breach linked to autonomous AI agent

Erfasst 20.07.2026 14:08 | BleepingComputer
The Hugging Face artificial intelligence repository disclosed that attackers gained access to internal datasets and credentials after breaching its production infrastructure usi...
Quelle ansehen

Microsoft confirms Windows Server Update Services sync delays

Erfasst 20.07.2026 12:53 | BleepingComputer
Microsoft is working to fix a known issue affecting Windows Server Update Services (WSUS) servers, which has caused synchronization problems for more than a week. [...]
Quelle ansehen

Windows KB5121767 OOB update fixes shutdowns on some Dell PCs

Erfasst 20.07.2026 12:08 | BleepingComputer
Microsoft has released emergency updates to fix a known issue causing some Dell PCs to shut down after installing the July 2026 Windows 11 security updates. [...]
Quelle ansehen

Critical ServiceNow code execution flaw now exploited in attacks

Erfasst 20.07.2026 11:38 | BleepingComputer
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused. [...]
Quelle ansehen

Hackers abuse ViPNet software to target Russian govt agencies

Erfasst 19.07.2026 16:34 | BleepingComputer
An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. [...]
Quelle ansehen

Update now: 7-Zip fixes RCE flaw exploitable with malicious archives

Erfasst 18.07.2026 21:32 | BleepingComputer
7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted ...
Quelle ansehen

WordPress Core "wp2shell" RCE flaws get public exploits, patch now

Erfasst 18.07.2026 19:31 | BleepingComputer
Public exploits have been released for the critical "wp2shell" remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch the...
Quelle ansehen

Microsoft warns of surge in ACR Stealer attacks on customers

Erfasst 18.07.2026 16:31 | BleepingComputer
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise cus...
Quelle ansehen

The Future of Age Verification: Your Face Never Leaves Your Device

Erfasst 18.07.2026 15:30 | BleepingComputer
As age verification laws expand worldwide, organizations face growing pressure to protect users' privacy while meeting regulatory requirements. Incode explains how on-device age...
Quelle ansehen

Abbott Laboratories probes two cyber incidents amid extortion claims

Erfasst 17.07.2026 22:58 | BleepingComputer
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostic...
Quelle ansehen

HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload

Erfasst 17.07.2026 19:58 | BleepingComputer
A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. [...
Quelle ansehen
Hinweis: Dies ist ein News-Aggregator. Das Copyright liegt bei den jeweiligen Webseiten. Die Links wurden zum Zeitpunkt der Abfrage als virenfrei und sicher bewertet. Bitte dennoch mit der nötigen Vorsicht prüfen.