Cloud-Sicherheit

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs CLOUD-SICHERHEIT

Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs

A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The...

27. Juni 2026 Keine Kommentare
OpenAI Expands Daybreak to Help Defenders Patch Flaws CLOUD-SICHERHEIT

OpenAI Expands Daybreak to Help Defenders Patch Flaws

OpenAI expanded Daybreak with a full GPT-5.5-Cyber release to help defenders patch software flaws...

26. Juni 2026 Keine Kommentare
‚Cordyceps‘: Mushrooming Malicious Pull Requests Threaten Developer Workflows CLOUD-SICHERHEIT

‚Cordyceps‘: Mushrooming Malicious Pull Requests Threaten Developer Workflows

The CI/CD workflow weakness affects Microsoft's Azure Sentinel, Google's AI Agent Development Kit, Apache's Doris analytics database, Cloudflare's Workers SDK,...

26. Juni 2026 Keine Kommentare
🟡 CVE-2026-11370: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-11370: Medium Schwachstelle

The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,...

26. Juni 2026 Keine Kommentare
🟠 CVE-2026-12095: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-12095: High Schwachstelle

The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2...

26. Juni 2026 Keine Kommentare
🟠 CVE-2026-56270: High Luecke in Flowiseai Flowise CLOUD-SICHERHEIT

🟠 CVE-2026-56270: High Luecke in Flowiseai Flowise

Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users...

26. Juni 2026 Keine Kommentare
CISA warns of max severity Ubiquiti flaws exploited in attacks CLOUD-SICHERHEIT

CISA warns of max severity Ubiquiti flaws exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers actively exploiting flaws in Ubiquity UniFi OS and Lantronix serial-to-ethernet servers. [...]...

25. Juni 2026 Keine Kommentare
DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering CLOUD-SICHERHEIT

DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering

The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use by...

25. Juni 2026 Keine Kommentare
🟠 CVE-2026-12958: High Schwachstelle CLOUD-SICHERHEIT

🟠 CVE-2026-12958: High Schwachstelle

Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary....

25. Juni 2026 Keine Kommentare
🟠 CVE-2026-12957: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-12957: High Schwachstelle

Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for...

25. Juni 2026 Keine Kommentare