Endpunktsicherheit

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations ENDPUNKTSICHERHEIT

APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations

Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between...

29. Aug. 2026 Keine Kommentare
🔴 CVE-2026-59354: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-59354: Critical Schwachstelle

In versions of Spring Security's OAuth2 Authorization Server module 7.0.0 through 7.0.4, when Dynamic Client Registration is explicitly enabled, the...

29. Aug. 2026 Keine Kommentare
🔴 CVE-2026-47892: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-47892: Critical Schwachstelle

A WebFlux application using functional endpoints and deployed with DispatcherServlet may be vulnerable to a header predicate bypass in a...

29. Aug. 2026 Keine Kommentare
Microsoft Defender’s Own Driver Can Be Weaponized to Delete Security Software at Boot ENDPUNKTSICHERHEIT

Microsoft Defender’s Own Driver Can Be Weaponized to Delete Security Software at Boot

Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary...

28. Aug. 2026 Keine Kommentare
GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address ENDPUNKTSICHERHEIT

GoCaracal Malware Uses Ethereum Smart Contract to Fetch Replacement C2 Address

Threat actors linked by Arctic Wolf to Dark Caracal with medium confidence deployed a previously undocumented Go-based malware framework, GoCaracal,...

28. Aug. 2026 Keine Kommentare
🟠 CVE-2026-19042: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-19042: High Schwachstelle

A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker...

28. Aug. 2026 Keine Kommentare
🟠 CVE-2026-58096: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-58096: High Schwachstelle

LcpDecodeConfig() did not validate the length of received endpoint discriminator options against the minimum required by RFC 1717. Undersized options...

28. Aug. 2026 Keine Kommentare
🟠 CVE-2026-58095: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-58095: High Schwachstelle

mp_Enddisc() used incorrect length calculations when formatting endpoint discriminator addresses for display, allowing a received endpoint option to overflow a...

28. Aug. 2026 Keine Kommentare
🔴 CVE-2026-80203: Critical Schwachstelle ANWENDUNGSSICHERHEIT

🔴 CVE-2026-80203: Critical Schwachstelle

The getgrav/grav-plugin-api plugin before 1.0.18 does not enforce API-key scope in the requireNotSuperTarget() function in UsersController.php across seven sensitive user-management...

28. Aug. 2026 Keine Kommentare
New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode ENDPUNKTSICHERHEIT

New SLEEPWALKER Backdoor Waits for One Crafted Packet, Then Runs Its Own Bytecode

An independent malware researcher has documented a previously unreported Windows backdoor, dubbed SLEEPWALKER, that stays inert in memory until a...

27. Aug. 2026 Keine Kommentare