Consulting News

News und Newsarchiv für unsere NC Consultants
Firefox Add-on

9-Year-Old Linux Kernel Flaw Enables Root Command Execution on Major Distros

Erfasst 21.05.2026 10:20 | The Hackers News
Cybersecurity researchers have disclosed details of a vulnerability in the Linux kernel that remained undetected for nine years. The vulnerability, tracked as CVE-2026-46333 (CV...
Quelle ansehen

Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks

Erfasst 21.05.2026 06:50 | The Hackers News
Drupal has released security updates for a "highly critical" security vulnerability in Drupal Core that could be exploited by attackers to achieve remote code execution, privile...
Quelle ansehen

GitHub Internal Repositories Breached via Malicious Nx Console VS Code Extension

Erfasst 21.05.2026 06:50 | The Hackers News
GitHub on Wednesday officially confirmed that the breach of its internal repositories was the result of a compromise of an employee device involving a poisoned version of the Nx...
Quelle ansehen

Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development

Erfasst 20.05.2026 19:18 | The Hackers News
Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of artificial intelligence (AI) agents. RAMPART, ...
Quelle ansehen

Microsoft Takes Down Malware-Signing Service Behind Ransomware Attacks

Erfasst 20.05.2026 16:48 | The Hackers News
Microsoft on Tuesday said it disrupted a malware-signing-as-a-service (MSaaS) operation that weaponized the company's Artifact Signing system to deliver malicious code and condu...
Quelle ansehen

Agent AI is Coming. Are You Ready?

Erfasst 20.05.2026 15:33 | The Hackers News
New Industry Data Just Released Suggests Not. On May 19th, 2026, Orchid Security released the results of our Identity Gap: Snapshot 2026. Among the findings, "identity dark matt...
Quelle ansehen

Webworm Deploys EchoCreep and GraphWorm Backdoors Using Discord and MS Graph API

Erfasst 20.05.2026 15:33 | The Hackers News
Cybersecurity researchers have flagged fresh activity from a China-aligned threat actor known as Webworm in 2025, deploying custom backdoors that employ Discord and Microsoft Gr...
Quelle ansehen

Typosquatting Is No Longer a User Problem. It's a Supply Chain Problem

Erfasst 20.05.2026 13:03 | The Hackers News
AI-generated lookalike domains are now embedded inside the third-party scripts running on your web properties. Here's why your current stack can't see them, and what detection a...
Quelle ansehen

Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit

Erfasst 20.05.2026 11:47 | The Hackers News
Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The zero-day flaw, now tracked as CVE-...
Quelle ansehen

Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

Erfasst 20.05.2026 08:02 | The Hackers News
Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems or operations being compromised. It said the scope o...
Quelle ansehen

GitHub Investigating TeamPCP Claimed Breach of ~4,000 Internal Repositories

Erfasst 20.05.2026 06:32 | The Hackers News
GitHub on Tuesday said it's investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP listed the platform's source code an...
Quelle ansehen

Trapdoor Android Ad Fraud Scheme Hit 659 Million Daily Bid Requests Using 455 Apps

Erfasst 19.05.2026 19:30 | The Hackers News
Cybersecurity researchers have disclosed details of a new ad fraud and malvertising operation dubbed Trapdoor targeting Android device users. The activity, per HUMAN's Satori Th...
Quelle ansehen

DirtyDecrypt PoC Released for Linux Kernel CVE-2026-31635 LPE Vulnerability

Erfasst 19.05.2026 17:00 | The Hackers News
Proof-of-concept (PoC) exploit code has now been released for a recently patched security flaw in the Linux kernel that could allow for local privilege escalation (LPE). Dubbed ...
Quelle ansehen

Drupal to Release Urgent Core Security Updates on May 20, Sites Told to Prepare

Erfasst 19.05.2026 14:45 | The Hackers News
Drupal has issued an alert stating that it intends to release a "core security release" for all supported branches on May 20, 2026, from 5-9 p.m. UTC. "The Drupal Security Team ...
Quelle ansehen

The New Phishing Click: How OAuth Consent Bypasses MFA

Erfasst 19.05.2026 14:45 | The Hackers News
In February 2026, a phishing-as-a-service (PhaaS) platform called EvilTokens went live. Within five weeks, it had compromised more than 340 Microsoft 365 organizations across fi...
Quelle ansehen

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

Erfasst 19.05.2026 12:30 | The Hackers News
Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited to achieve remote c...
Quelle ansehen

Compromised Nx Console 18.95.0 Targeted VS Code Developers with Credential Stealer

Erfasst 19.05.2026 10:29 | The Hackers News
Cybersecurity researchers have flagged a compromised version of the Nx Console extension that was published to the Microsoft Visual Studio Code (VS Code) Marketplace. The extens...
Quelle ansehen

Mini Shai-Hulud Pushes Malicious AntV npm Packages via Compromised Maintainer Account

Erfasst 19.05.2026 07:31 | The Hackers News
Cybersecurity researchers have discovered a fresh software supply chain attack campaign that has compromised various npm packages associated with the @antv ecosystem as part of ...
Quelle ansehen
Hinweis: Dies ist ein News-Aggregator. Das Copyright liegt bei den jeweiligen Webseiten. Die Links wurden zum Zeitpunkt der Abfrage als virenfrei und sicher bewertet. Bitte dennoch mit der nötigen Vorsicht prüfen.