Cloud-Sicherheit

🟠 CVE-2026-84199: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-84199: High Schwachstelle

Kyverno before 1.16.2 contains a server-side request forgery (SSRF) vulnerability in the APICall feature. The URL field in a Policy's...

03. Sep. 2026 Keine Kommentare
🟠 CVE-2026-84196: High Schwachstelle CLOUD-SICHERHEIT

🟠 CVE-2026-84196: High Schwachstelle

Kyverno before 1.18.0 contains a server-side request forgery vulnerability in apiCall.service.url that allows authenticated users to send arbitrary HTTP requests...

03. Sep. 2026 Keine Kommentare
Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency CLOUD-SICHERHEIT

Old, Unpatched Flaws Give Attackers Access to Philippines Nuclear Agency

Threat actors exploited commodity in ownCloud to gain initial access, resulting in stolen reactor databases, personnel records, and credential stores....

02. Sep. 2026 Keine Kommentare
SonicWall warns of actively exploited SMA1000 zero-day flaws CLOUD-SICHERHEIT

SonicWall warns of actively exploited SMA1000 zero-day flaws

SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. [...]...

02. Sep. 2026 Keine Kommentare
🔴 CVE-2026-82856: Critical Schwachstelle CLOUD-SICHERHEIT

🔴 CVE-2026-82856: Critical Schwachstelle

@hulumi/policies versions before 1.3.2 fail to properly validate set-qualified AWS IAM condition operators in GitHub OIDC trust policies. Attackers can...

02. Sep. 2026 Keine Kommentare
🔴 CVE-2026-82855: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-82855: Critical Schwachstelle

@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress...

02. Sep. 2026 Keine Kommentare
The ‚Industrial Accidents‘ Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed CLOUD-SICHERHEIT

The ‚Industrial Accidents‘ Behind Rogue AI Agent Attacks — and the Sandbox Failures Exposed

Rich Mogull, chief analyst with the Cloud Security Alliance, joins the Dark Reading News Desk with what defenders need to...

01. Sep. 2026 Keine Kommentare
Microsoft warns of TerminalFix attacks deploying reverse tunnels CLOUD-SICHERHEIT

Microsoft warns of TerminalFix attacks deploying reverse tunnels

A new ClickFix variant dubbed TerminalFix uses fake Cloudflare CAPTCHA prompts on compromised websites to trick victims into running malicious...

01. Sep. 2026 Keine Kommentare
🟠 CVE-2026-82648: High Schwachstelle CLOUD-SICHERHEIT

🟠 CVE-2026-82648: High Schwachstelle

WWBN AVideo contains a server-side request forgery filter bypass vulnerability in the isSSRFSafeURL function that fails to normalize NAT64 addresses...

01. Sep. 2026 Keine Kommentare
🟠 CVE-2026-56718: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-56718: High Schwachstelle

AJCloud AJY IPC firmware prior to version 01.10715.11.37 contains a path traversal vulnerability in the jdbhttpd web service that allows...

01. Sep. 2026 Keine Kommentare