Cloud-Sicherheit
CLOUD-SICHERHEIT
Amazon Q Developer Flaw Could Let Malicious Repos Run Code via MCP Configs
A high-severity flaw in Amazon Q Developer let a malicious repository run commands and steal a developer's cloud credentials. The...
CLOUD-SICHERHEIT
OpenAI Expands Daybreak to Help Defenders Patch Flaws
OpenAI expanded Daybreak with a full GPT-5.5-Cyber release to help defenders patch software flaws...
CLOUD-SICHERHEIT
‚Cordyceps‘: Mushrooming Malicious Pull Requests Threaten Developer Workflows
The CI/CD workflow weakness affects Microsoft's Azure Sentinel, Google's AI Agent Development Kit, Apache's Doris analytics database, Cloudflare's Workers SDK,...
🟡 CVE-2026-11370: Medium Schwachstelle
The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including,...
🟠 CVE-2026-12095: High Schwachstelle
The Kargo Takip plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.2...
🟠 CVE-2026-56270: High Luecke in Flowiseai Flowise
Flowise before 3.1.0 (versions 3.0.13 and earlier) contains a missing authentication vulnerability in the /api/v1/loginmethod endpoint that allows unauthenticated users...
CISA warns of max severity Ubiquiti flaws exploited in attacks
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) is warning of hackers actively exploiting flaws in Ubiquity UniFi OS and Lantronix serial-to-ethernet servers. [...]...
CLOUD-SICHERHEIT
DoJ Seizes Huione Cloud Account Tied to Cyber Scam Money Laundering
The U.S. Department of Justice (DoJ) on Tuesday announced the seizure of a cloud computing account put to use by...
🟠 CVE-2026-12958: High Schwachstelle
Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary....
🟠 CVE-2026-12957: High Schwachstelle
Improper trust boundary enforcement in Language Servers for AWS before version 1.65.0 on all supported platforms may allow a for...