Cloud-Sicherheit

🔴 CVE-2026-56274: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-56274: Critical Schwachstelle

Flowise before 3.1.2 contains multiple OS command injection vulnerabilities in the Custom MCP Server feature due to incomplete command-flag validation...

25. Juni 2026 Keine Kommentare
‚Cordyceps‘: Mushrooming Malicious Pull Requests Threaten Developer Workflows CLOUD-SICHERHEIT

‚Cordyceps‘: Mushrooming Malicious Pull Requests Threaten Developer Workflows

The CI/CD workflow weakness affects Microsoft's Azure Sentinel, Google's AI Agent Development Kit, Apache's Doris analytics database, Cloudflare's Workers SDK,...

24. Juni 2026 Keine Kommentare
FFmpeg fixes PixelSmash flaw in widely used video decoder CLOUD-SICHERHEIT

FFmpeg fixes PixelSmash flaw in widely used video decoder

A newly disclosed FFmpeg flaw dubbed 'PixelSmash' could be exploited for remote code execution on Jellyfin servers under certain conditions, and...

24. Juni 2026 Keine Kommentare
🟡 CVE-2024-54178: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2024-54178: Medium Schwachstelle

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an...

24. Juni 2026 Keine Kommentare
🟠 CVE-2026-56424: High Luecke in Misp-Project Misp ANWENDUNGSSICHERHEIT

🟠 CVE-2026-56424: High Luecke in Misp-Project Misp

MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks...

24. Juni 2026 Keine Kommentare
Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants CLOUD-SICHERHEIT

Researchers Detail DifyTap Flaws in Dify That Could Expose AI Chats Across Tenants

Cybersecurity researchers have disclosed details of four vulnerabilities in Dify, an open-source agentic workflow platform with more than 146,000 GitHub...

23. Juni 2026 Keine Kommentare
OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws CLOUD-SICHERHEIT

OpenAI Expands Daybreak With GPT-5.5-Cyber to Help Defenders Patch Security Flaws

OpenAI on Monday said it's releasing an improved version of its GPT‑5.5‑Cyber model to trusted defenders as part of the...

23. Juni 2026 Keine Kommentare
AWS Unveils ‚Continuum,‘ an AI-Powered Vulnerability Management Platform CLOUD-SICHERHEIT

AWS Unveils ‚Continuum,‘ an AI-Powered Vulnerability Management Platform

Working with frontier AI models, this new platform aims to help discovering, prioritizing, validating and remediating code vulnerabilities...

22. Juni 2026 Keine Kommentare
LATAM Infrastructure Hit by Fortinet and Ivanti Exploits CLOUD-SICHERHEIT

LATAM Infrastructure Hit by Fortinet and Ivanti Exploits

CloudSEK maps Operation Escaneo, a campaign hitting Latin American infrastructure via perimeter bugs...

21. Juni 2026 Keine Kommentare
AWS Unveils ‚Continuum,‘ an AI-Powered Vulnerability Management Platform CLOUD-SICHERHEIT

AWS Unveils ‚Continuum,‘ an AI-Powered Vulnerability Management Platform

Working with frontier AI models, this new platform aims to help discovering, prioritizing, validating and remediating code vulnerabilities...

21. Juni 2026 Keine Kommentare