Anwendungssicherheit

Making Vulnerable Drivers Exploitable Without Hardware – The BYOVD Perspective ANWENDUNGSSICHERHEIT

Making Vulnerable Drivers Exploitable Without Hardware – The BYOVD Perspective

1 Introduction This article provides a technical analysis of how many Windows kernel mode drivers can be interacted with from...

22. Mai 2026 Keine Kommentare
Grafana GitHub Breach Exposes Source Code via TanStack npm Attack ANWENDUNGSSICHERHEIT

Grafana GitHub Breach Exposes Source Code via TanStack npm Attack

Grafana Labs, on May 19, 2026, said an investigation into its recent breach found no evidence of customer production systems...

22. Mai 2026 Keine Kommentare
Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit ANWENDUNGSSICHERHEIT

Microsoft Releases Mitigation for YellowKey BitLocker Bypass CVE-2026-45585 Exploit

Microsoft on Tuesday released a mitigation for a BitLocker bypass vulnerability named YellowKey following its public disclosure last week. The...

22. Mai 2026 Keine Kommentare
GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos ANWENDUNGSSICHERHEIT

GitHub Breached — Employee Device Hack Led to Exfiltration of 3,800+ Internal Repos

GitHub on Tuesday said it's investigating unauthorized access to its internal repositories after the notorious threat actor known as TeamPCP...

22. Mai 2026 Keine Kommentare
Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development ANWENDUNGSSICHERHEIT

Microsoft Open-Sources RAMPART and Clarity to Secure AI Agents During Development

Microsoft has unveiled two new open-source tools called RAMPART and Clarity to assist developers in better testing the security of...

22. Mai 2026 Keine Kommentare
Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws ANWENDUNGSSICHERHEIT

Ivanti, Fortinet, SAP, VMware, n8n Patch RCE, SQL Injection, Privilege Escalation Flaws

Ivanti, Fortinet, n8n, SAP, and VMware have released security fixes for various vulnerabilities that could be exploited by bad actors...

22. Mai 2026 Keine Kommentare
CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV ANWENDUNGSSICHERHEIT

CISA Adds Exploited Langflow and Trend Micro Apex One Vulnerabilities to KEV

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added two security flaws impacting Langflow and Trend Micro Apex...

22. Mai 2026 Keine Kommentare
SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access ANWENDUNGSSICHERHEIT

SEPPMail Secure E-Mail Gateway Vulnerabilities Enable RCE and Mail Traffic Access

Critical security vulnerabilities have been disclosed in SEPPMail Secure E-Mail Gateway, an enterprise-grade email security solution, that could be exploited...

22. Mai 2026 Keine Kommentare
Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access ANWENDUNGSSICHERHEIT

Cisco Patches CVSS 10.0 Secure Workload REST API Flaw Enabling Data Access

Cisco has rolled out updates for a maximum-severity security flaw impacting Secure Workload that could allow an unauthenticated, remote attacker...

22. Mai 2026 Keine Kommentare
Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks ANWENDUNGSSICHERHEIT

Highly Critical Drupal Core Flaw Exposes PostgreSQL Sites to RCE Attacks

Drupal has released security updates for a "highly critical" security vulnerability in Drupal Core that could be exploited by attackers...

22. Mai 2026 Keine Kommentare