Zum Inhalt springen

IT-Sicherheit · Aktuell

IT Security News

Aktuelle Meldungen zu IT-Sicherheit, Cyberbedrohungen und Datenschutz — automatisch kuratiert aus führenden Quellen.

BleepingComputer05. Okt. 2026

Denmark population registry data breach affects 8.8 million people

Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. [...]

Weiterlesen
BleepingComputer05. Okt. 2026

New Dell System Update flaw lets hackers gain root privileges

Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible. [...]

Weiterlesen
Golem Security05. Okt. 2026

Fast neun Millionen Betroffene: Dänisches Melderegister gehackt

Die Angreifer missbrauchen den legalen Zugang eines Privatunternehmens. Die zuständige Ministerin spricht von einem schwerwiegenden Vorfall. (<a href="https://www.golem.de/specials/security/">Security</a>, <a href="https

Weiterlesen
BleepingComputer05. Okt. 2026

South Korea probes bank breaches amid suspected AI-powered attacks

South Korea's Financial Services Commission (FSC) held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. [...]

Weiterlesen
The Hacker News05. Okt. 2026

⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests

A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. Th

Weiterlesen
BleepingComputer05. Okt. 2026

tenfold CE: Our free Identity Governance tool just got 2 new features

tenfold has added shared content governance and real-time event auditing to its free Community Edition for organizations with under 150 users. The new features help teams manage Microsoft 365 sharing and investigate susp

Weiterlesen
BleepingComputer05. Okt. 2026

Alleged dev of Ploutus ATM malware appears in US court after arrest

The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. [...]

Weiterlesen
Fortinet FortiGuard05. Okt. 2026

ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure

FortiGuard Labs examines how ClingSTUN exploits vulnerable devices and abuses public STUN servers to support a Linux proxy backdoor. &#160; &#160; &#160; &#160; &nbsp;&#160;

Weiterlesen
The Hacker News05. Okt. 2026

The Credential Layer Is Expanding Faster Than Security Teams Can See It

Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capa

Weiterlesen
The Hacker News05. Okt. 2026

Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2

Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not becau

Weiterlesen
The Hacker News05. Okt. 2026

Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access

Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk

Weiterlesen
BleepingComputer05. Okt. 2026

OpenAI will show visual ads in ChatGPT while you generate images

OpenAI is expanding ads in ChatGPT, and one of the first new formats will show visual ads while you're generating images. [...]

Weiterlesen
Heise Security05. Okt. 2026

Microsoft-Authenticator-Backup ab Januar nicht mehr mit Microsoft-Konto

Microsofts Authenticator kann ein Backup in der Cloud ablegen. Ab Januar geht das unter Android nicht mehr mit persönlichen Microsoft-Konten.

Weiterlesen
Golem Security05. Okt. 2026

Cyberangriff: Antriebssystem eines Öl-Supertankers gehackt

Unbefugte kontrollieren das digitale System des Schiffs. Es ist nicht der erste Vorfall dieser Art. (<a href="https://www.golem.de/specials/hacker/">Hacker</a>, <a href="https://www.golem.de/specials/security/">Security<

Weiterlesen
Allianz Cyber-Sicherheit05. Okt. 2026

Partnerangebot: isits AG &#8211; Seminar &#8222;Krisenkommunikationsbeauftrage bzw. Kommunikationsbeauftragter bei Cyberangriffen (T&#220;V)&#8220;

Im Partnerbeitrag der isits AG geht es darum, die strukturierte und souver&#228;ne Krisenkommunikation bei Cyberangriffen zu erlernen. Das Seminar kann bei Interesse mit einer Personenzertifizierung abgeschlossen werden

Weiterlesen
BleepingComputer05. Okt. 2026

Microsoft: Windows KB5124010 update crashes some games and apps

Microsoft confirmed over the weekend that some games and applications using AC-3 (Dolby Digital) audio decoding will crash after installing the September 2026 KB5124010 Windows 11 preview update. [...]

Weiterlesen
Heise Security05. Okt. 2026

ChatGPT-App für macOS: Angreifer konnten sensible Daten einsehen – wie bei Muse

Nach Meta hatte auch OpenAI ein Sicherheitsproblem in seiner macOS-App. Erneut wurde es vom Security-Experten Patrick Wardle entdeckt.

Weiterlesen
BleepingComputer05. Okt. 2026

Google halts open-source bug bounty program amid AI spam surge

Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. [...]

Weiterlesen
The Hacker News05. Okt. 2026

Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE

A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session f

Weiterlesen
Allianz Cyber-Sicherheit05. Okt. 2026

Partnerangebot: CCVOSSEL GmbH &#8211; &#8222;Escape the Cyber Crisis&#8220;

Montag 08:12 Uhr. Die Systeme sind verschl&#252;sselt, die Produktion steht. Wie gehst du vor? Im Partnerangebot der CCVOSSEL GmbH erleben die Teilnehmenden die ersten 24 Stunden eines Ransomware-Angriffs auf ein mittels

Weiterlesen
Golem Security05. Okt. 2026

KI-Agenten: Metas Muse legt Profile über Freunde und Familie an

Metas KI-Assistent Muse führt Seiten über Familie, Partner und Freunde. Forscher haben die Anweisungen dafür ausgelesen. (<a href="https://www.golem.de/specials/meta/">Meta</a>, <a href="https://www.golem.de/specials/ki/

Weiterlesen
Heise Security05. Okt. 2026

CISA warnt vor Angriffen auf Zammad und Citrix NetScaler

Bösartige Akteure attackieren aktuell nicht nur Sicherheitslücken in Citrix NetScaler, sondern auch in Zammad. Davor warnt die CISA.

Weiterlesen
The Hacker News05. Okt. 2026

New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline

Citrix has released security updates for a high-severity security flaw in NetScaler ADC and Citrix NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88

Weiterlesen
Heise Security05. Okt. 2026

Microsoft schiebt Exchange-Update nach

Zum Wochenende hat Microsoft weitere Exchange-Updates nachgelegt. Sie stopfen eine Rechteausweitungslücke.

Weiterlesen
Heise Security05. Okt. 2026

Bericht: Bei Cyberangriff Zugriff auf Antrieb von Öl-Supertanker erlangt

Ende August haben FBI und US-Küstenwache einen Öltanker geentert, der stundenlang nicht kommunizieren konnte. Nun gibt es Erkenntnisse über den Cyberangriff.

Weiterlesen
SANS ISC05. Okt. 2026

ISC Stormcast For Monday, October 5th, 2026 https://isc.sans.edu/podcastdetail/10122, (Mon, Oct 5th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Weiterlesen
SANS ISC05. Okt. 2026

TTY Logs and the Data it Captures, (Sun, Oct 4th)

For an experiment, I created a script &#x5b; 1 &#x5d; that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs ar

Weiterlesen
BleepingComputer04. Okt. 2026

Citrix patches NetScaler SAML zero-day exploited in attacks

Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be explo

Weiterlesen
Golem Security04. Okt. 2026

David Robinson: Warum OpenAIs Sicherheitschef nun geht

Ein Ex-Mitarbeiter warnt: Bei OpenAI komme Sicherheit im Tempo neuer KI-Produkte oft zu kurz. (<a href="https://www.golem.de/specials/openai/">OpenAI</a>, <a href="https://www.golem.de/specials/ki/">KI</a>) <img src="htt

Weiterlesen
Heise Security04. Okt. 2026

Bericht: FBI-Angreifer von „ShinyHunters“ gefasst und kooperativ

Einem Bericht zufolge wurde ein weiteres Mitglied der Cyberbande „ShinyHunters“ in Jordanien festgesetzt. Er soll mit dem FBI kooperieren.

Weiterlesen
Heise Security04. Okt. 2026

Citrix Netscaler aktualisieren! Zero-Day verursacht Crashes und Codeausführung

Sicherheitsforscher und Administratoren melden massenhafte Spontanreboots betroffener Geräte. Updates sind nun verfügbar und sollten schnell aufgespielt werden.

Weiterlesen
BleepingComputer04. Okt. 2026

Anthropic asks Claude users to share voice data for AI model training

Anthropic has started asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. [...]

Weiterlesen
SANS ISC04. Okt. 2026

User Agent Strings Curiosities, (Sun, Oct 4th)

Sometimes I have to smile, or my interest is triggered, when I review new User Agent Strings in the honeypot logs. &#xd;

Weiterlesen
The Hacker News04. Okt. 2026

ShinyHunters Suspect Rey Reportedly Detained in Jordan, Helping FBI Identify Group Members

A suspected member of the ShinyHunters digital extortion group, who goes by the online alias "Rey," has been allegedly detained by authorities in Jordan, Reuters reported, citing three people familiar with the matter. Re

Weiterlesen
The Hacker News04. Okt. 2026

China-Aligned TA419 Targets U.S. AI Policy Experts With Microsoft AitM Phishing

A new China-nexus cyber espionage group known as TA419 has been attributed to multiple credential phishing campaigns targeting artificial intelligence (AI) experts working for U.S. think tanks, universities, and legal se

Weiterlesen
BleepingComputer03. Okt. 2026

Google Gemini could soon get full access to your Mac’s files, apps and the web

Google's Gemini could soon access any file on your macOS device, open apps, browse the web, and perform actions without asking for permission every time. [...]

Weiterlesen
BleepingComputer03. Okt. 2026

ShinyHunters hacker reportedly detained in Jordan, aiding FBI

A suspected ShinyHunters hacking group member known online as "Rey" has reportedly been detained in Jordan and is cooperating with the FBI to help locate other members of the extortion group. [...]

Weiterlesen
SANS ISC03. Okt. 2026

YARA-X 1.21.0 Release, (Sat, Oct 3rd)

YARA-X&&#x23&#x3b;x26&#x3b;&#x23&#x3b;39&#x3b;s 1.21.0 release brings 5 improvements and 4 bugfixes. &#xd;

Weiterlesen
The Hacker News03. Okt. 2026

MI5 Says China’s MSS Funded Research Involving 100+ U.K.-Linked Academics

The U.K.'s domestic intelligence and security agency has warned that more than 100 academics have helped China boost its intelligence gathering efforts on behalf of Beijing's state security service. In a "Security Servic

Weiterlesen
The Hacker News03. Okt. 2026

Warlock Exploits SharePoint Flaws to Disable Security Tools and Deploy Ransomware

The suspected China-linked threat actor known as Warlock is still continuing to weaponize Microsoft SharePoint vulnerabilities, likely both old and new, in attacks targeting organizations in Portuguese- and Spanish-speak

Weiterlesen

Wird alle 30 Minuten aktualisiert · CH/DE: BACS Schweiz, BSI, Allianz Cyber-Sicherheit, Heise Security, Golem · EN: BleepingComputer, The Hacker News, Fortinet, SANS ISC, Microsoft Security, Krebs on Security, Kaspersky