Cloud-Sicherheit
🟠 CVE-2026-85609: High Schwachstelle
Openpanel before 2.3.0 contains an unauthenticated full-read server-side request forgery (SSRF) vulnerability in the GET /tools/site-checker endpoint (apps/api/src/controllers/tools.controller.ts). Th...
🟠 CVE-2026-85614: High Schwachstelle
OpenPanel before 2.3.0 contains an unauthenticated server-side request forgery vulnerability in the GET /tools/site-checker endpoint that accepts a fully client-controlled...
CLOUD-SICHERHEIT
Shai-Hulud’s Reach Just Grew to 469 Credential Locations. Here’s What That Means
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across...
CLOUD-SICHERHEIT
Plex Urges Immediate Updates After Patching Multiple Undisclosed Security Flaws
Plex is urging users to update their instances to the latest version following the release of an update that patches...
🟠 CVE-2026-85164: High Schwachstelle
WWBN AVideo through commit c91b5975d contains a server-side request forgery vulnerability in the set_api_userImages API endpoint that fails to validate...
Coder’s registry infrastructure compromised to push malicious modules
Attackers compromised Coder's Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. [...]...
CLOUD-SICHERHEIT
Shai-Hulud’s Reach Just Grew to 469 Credential Locations. Here’s What That Means
In early August, GitGuardian researchers found that a recent Shai-Hulud infostealer worm variant had evolved to scan for credentials across...
CLOUD-SICHERHEIT
NIST Warns of Unique Security Risks in Multi-Cloud Environments
NIST has set out 23 novel challenges that arise in multi-cloud environments and has encouraged the cyber community to find...
CLOUD-SICHERHEIT
CISA Warns of Six Exploited Flaws in Microsoft, Linux, Red Hat and Citrix Products
CISA added six new bugs to its Known Exploited Vulnerabilities catalog on August 26, showing signs of active exploitation in...
🟡 CVE-2025-15613: Medium Schwachstelle
Kyverno before v1.13.4 is vulnerable to server-side request forgery (SSRF) via its Service Call functionality. An attacker with permission to...