Consulting News

News und Newsarchiv für unsere NC Consultants
Firefox Add-on

FBI Warns Russian Hackers Target Signal, WhatsApp in Mass Phishing Attacks

Erfasst 21.03.2026 14:27 | The Hackers News
Threat actors affiliated with Russian Intelligence Services are conducting phishing campaigns to compromise commercial messaging applications (CMAs) like WhatsApp and Signal to ...
Quelle ansehen

Oracle Patches Critical CVE-2026-21992 Enabling Unauthenticated RCE in Identity Manager

Erfasst 21.03.2026 12:12 | The Hackers News
Oracle has released security updates to address a critical security flaw impacting Identity Manager and Web Services Manager that could be exploited to achieve remote code execu...
Quelle ansehen

CISA Flags Apple, Craft CMS, Laravel Bugs in KEV, Orders Patching by April 3, 2026

Erfasst 21.03.2026 09:57 | The Hackers News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Friday added five security flaws impacting Apple, Craft CMS, and Laravel Livewire to its Known Exploited Vuln...
Quelle ansehen

Trivy Supply Chain Attack Triggers Self-Spreading CanisterWorm Across 47 npm Packages

Erfasst 21.03.2026 08:56 | The Hackers News
The threat actors behind the supply chain attack targeting the popular Trivy scanner are suspected to be conducting follow-on attacks that have led to the compromise of a large ...
Quelle ansehen

Trivy Security Scanner GitHub Actions Breached, 75 Tags Hijacked to Steal CI/CD Secrets

Erfasst 20.03.2026 19:40 | The Hackers News
Trivy, a popular open-source vulnerability scanner maintained by Aqua Security, was compromised a second time within the span of a month to deliver malware that stole sensitive ...
Quelle ansehen

Critical Langflow Flaw CVE-2026-33017 Triggers Attacks within 20 Hours of Disclosure

Erfasst 20.03.2026 17:25 | The Hackers News
A critical security flaw impacting Langflow has come under active exploitation within 20 hours of public disclosure, highlighting the speed at which threat actors weaponize newl...
Quelle ansehen

Magento PolyShell Flaw Enables Unauthenticated Uploads, RCE and Account Takeover

Erfasst 20.03.2026 13:55 | The Hackers News
Sansec is warning of a critical security flaw in Magento's REST API that could allow unauthenticated attackers to upload arbitrary executables and achieve code execution and acc...
Quelle ansehen

Google Adds 24-Hour Wait for Unverified App Sideloading to Reduce Malware and Scams

Erfasst 20.03.2026 12:24 | The Hackers News
Google on Thursday announced a new "advanced flow" for Android sideloading that requires a mandatory 24-hour wait period to install apps from unverified developers in an attempt...
Quelle ansehen

The Importance of Behavioral Analytics in AI-Enabled Cyber Attacks

Erfasst 20.03.2026 11:39 | The Hackers News
Artificial Intelligence (AI) is changing how individuals and organizations conduct many activities, including how cybercriminals carry out phishing attacks and iterate on malwar...
Quelle ansehen

DoJ Disrupts 3 Million-Device IoT Botnets Behind Record 31.4 Tbps Global DDoS Attacks

Erfasst 20.03.2026 07:39 | The Hackers News
The U.S. Department of Justice (DoJ) on Thursday announced the disruption of command-and-control (C2) infrastructure used by several Internet of Things (IoT) botnets like AISURU...
Quelle ansehen

Apple Warns Older iPhones Vulnerable to Coruna, DarkSword Exploit Kit Attacks

Erfasst 20.03.2026 06:39 | The Hackers News
Apple is urging users who are still running an outdated version of iOS to update their iPhones to secure against web-based attacks carried out via powerful exploit kits like Cor...
Quelle ansehen

Speagle Malware Hijacks Cobra DocGuard to Steal Data via Compromised Servers

Erfasst 19.03.2026 21:38 | The Hackers News
Cybersecurity researchers have flagged a new malware dubbed Speagle that hijacks the functionality and infrastructure of a legitimate program called Cobra DocGuard. "Speagle is ...
Quelle ansehen

54 EDR Killers Use BYOVD to Exploit 34 Signed Vulnerable Drivers and Disable Security

Erfasst 19.03.2026 20:23 | The Hackers News
A new analysis of endpoint detection and response (EDR) killers has revealed that 54 of them leverage a technique known as bring your own vulnerable driver (BYOVD) by abusing a ...
Quelle ansehen

ThreatsDay Bulletin: FortiGate RaaS, Citrix Exploits, MCP Abuse, LiveChat Phish & More

Erfasst 19.03.2026 15:37 | The Hackers News
ThreatsDay Bulletin is back on The Hacker News, and this week feels off in a familiar way. Nothing loud, nothing breaking everything at once. Just a lot of small things that sho...
Quelle ansehen

New Perseus Android Banking Malware Monitors Notes Apps to Extract Sensitive Data

Erfasst 19.03.2026 14:37 | The Hackers News
Cybersecurity researchers have disclosed a new Android malware family called Perseus that's being actively distributed in the wild with an aim to conduct device takeover (DTO) a...
Quelle ansehen

How Ceros Gives Security Teams Visibility and Control in Claude Code

Erfasst 19.03.2026 12:07 | The Hackers News
Security teams have spent years building identity and access controls for human users and service accounts. But a new category of actor has quietly entered most enterprise envir...
Quelle ansehen

DarkSword iOS Exploit Kit Uses 6 Flaws, 3 Zero-Days for Full Device Takeover

Erfasst 19.03.2026 10:52 | The Hackers News
A new exploit kit for Apple iOS devices designed to steal sensitive data from is being wielded by multiple threat actors since at least November 2025, according to reports from ...
Quelle ansehen

CISA Warns of Zimbra, SharePoint Flaw Exploits; Cisco Zero-Day Hit in Ransomware Attacks

Erfasst 19.03.2026 07:52 | The Hackers News
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged government agencies to apply patches for two security flaws impacting Synacor Zimbra Collaboration Sui...
Quelle ansehen
Hinweis: Dies ist ein News-Aggregator. Das Copyright liegt bei den jeweiligen Webseiten. Die Links wurden zum Zeitpunkt der Abfrage als virenfrei und sicher bewertet. Bitte dennoch mit der nötigen Vorsicht prüfen.