Cloud-Sicherheit
🟠 CVE-2026-56259: High Schwachstelle
Crawl4AI before 0.8.8 contains credential exfiltration vulnerabilities in the Docker API server that allow attackers to redirect LLM API calls...
🔴 CVE-2026-56260: Critical Schwachstelle
Crawl4AI before 0.8.7 contains an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The output_path...
CLOUD-SICHERHEIT
CISA Details Incident Response to Exposed AWS GovCloud Keys
CISA reveals how it responded after sensitive AWS GovCloud credentials and internal data were exposed in a public GitHub repository...
CLOUD-SICHERHEIT
AI Gateways Offer Attackers the Keys to the Kingdom
A cryptomining incident highlights how AI gateways can provide access to AI models, cloud infrastructure, and identity and access management...
🟠 CVE-2026-59794: High Luecke in Jetbrains Teamcity
In JetBrains TeamCity before 2026.1.2 stored XSS on the cloud profile page was possible via agent-reported data
🟠 CVE-2026-56261: High Schwachstelle
Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which...
🔴 CVE-2026-15143: Critical Schwachstelle
A flaw was found in the file_type content detector of guardrails-detectors. This vulnerability allows a remote attacker to supply an...
🔴 CVE-2026-15378: Critical Schwachstelle
A flaw was found in the `guardrails-detectors` component. This vulnerability allows a remote attacker to perform a blind Server-Side Request...
CLOUD-SICHERHEIT
More Countries Jump on the Social Media ‚Ban Wagon‘
Age restrictions on accounts may be more of a stopgap because industry compliance is already falling short. Tech giants are...
New U-Boot flaws could enable stealthy firmware attacks
Six vulnerabilities in the widely used U-Boot bootloader have been discovered that could allow attackers to execute malicious code during...