Anwendungssicherheit

KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike ANWENDUNGSSICHERHEIT

KnowledgeDeliver LMS Flaw Exploited to Deploy Godzilla and Cobalt Strike

A now-patched high-severity security flaw affecting Digital Knowledge KnowledgeDeliver, a Learning Management System (LMS) popular in Japan, was exploited as...

26. Mai 2026 Keine Kommentare
Fake Android Apps Commit Carrier Billing Fraud for Premium Services ANWENDUNGSSICHERHEIT

Fake Android Apps Commit Carrier Billing Fraud for Premium Services

The disguised apps use WebView automation, JavaScript injection, and OTP interception to avoid detection and complete fraudulent subscriptions....

25. Mai 2026 Keine Kommentare
Content Delivery Exploit Opens Websites to Brand Hijacking ANWENDUNGSSICHERHEIT

Content Delivery Exploit Opens Websites to Brand Hijacking

The Underminr domain-fronting attack allows threat actors to modify Web requests and leverage trusted websites to cloak malicious activity....

25. Mai 2026 Keine Kommentare
Patch Tuesday, April 2026 Edition ANWENDUNGSSICHERHEIT

Patch Tuesday, April 2026 Edition

Microsoft today pushed software updates to fix a staggering 167 security vulnerabilities in its Windows operating systems and related software,...

24. Mai 2026 Keine Kommentare
Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign ANWENDUNGSSICHERHEIT

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that...

24. Mai 2026 Keine Kommentare
Patch Tuesday, May 2026 Edition ANWENDUNGSSICHERHEIT

Patch Tuesday, May 2026 Edition

Artificial intelligence platforms may be just as susceptible to social engineering as human beings, but they are proving remarkably good...

24. Mai 2026 Keine Kommentare
Max severity Cisco Secure Workload flaw gives Site Admin privileges ANWENDUNGSSICHERHEIT

Max severity Cisco Secure Workload flaw gives Site Admin privileges

Cisco has released security updates to address a maximum-severity vulnerability in Secure Workload that allows attackers to gain Site Admin...

24. Mai 2026 Keine Kommentare
Ubiquiti patches three max severity UniFi OS vulnerabilities ANWENDUNGSSICHERHEIT

Ubiquiti patches three max severity UniFi OS vulnerabilities

Ubiquiti has released security updates to patch three maximum severity vulnerabilities in UniFi OS that can be exploited by remote...

23. Mai 2026 Keine Kommentare
Drupal: Critical SQL injection flaw now targeted in attacks ANWENDUNGSSICHERHEIT

Drupal: Critical SQL injection flaw now targeted in attacks

Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier this week. [...]...

23. Mai 2026 Keine Kommentare
Trend Micro warns of Apex One zero-day exploited in the wild ANWENDUNGSSICHERHEIT

Trend Micro warns of Apex One zero-day exploited in the wild

Japanese cybersecurity software company Trend Micro has addressed an Apex One zero-day vulnerability exploited in attacks targeting Windows systems. [...]...

23. Mai 2026 Keine Kommentare