Endpunktsicherheit
🟠 CVE-2026-75836: High Schwachstelle
The Grav API plugin (getgrav/grav-plugin-api, bundled with Grav's admin-next/API stack) before 1.0.14 fails to enforce the authorize requirement in MenubarController::executeAction()....
🔴 CVE-2026-75851: Critical Schwachstelle
ArcadeDB server (com.arcadedb:arcadedb-server) in versions 26.7.3 and earlier fails to propagate the authenticated principal to asynchronous command worker threads. When...
ENDPUNKTSICHERHEIT
16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer. OpenSourceMalware, which discovered the...
ENDPUNKTSICHERHEIT
Ransom Busters Claims It Hacked Ransomware Servers, Asks Victims for Up to $60,000
A ransomware affiliate calling itself Ransom Busters has been spotted proactively sending emails to victim organizations and claims to delete...
🟠 CVE-2026-74879: High Schwachstelle
openssl_encrypt versions before 1.4.0 contain an information disclosure vulnerability in the /ready endpoint that returns full database exception strings to...
🟠 CVE-2026-74802: High Schwachstelle
SiYuan versions before 3.7.4 contain a cross-site WebSocket hijacking vulnerability in the admin-only /ws/network/proxy endpoint that explicitly disables origin validation...
🔴 CVE-2026-74799: Critical Schwachstelle
SiYuan before 3.7.4 registers Go net/http/pprof debug endpoints including heap and goroutine dumps without authentication when --mode flag is not...
ENDPUNKTSICHERHEIT
Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices...
ENDPUNKTSICHERHEIT
⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More
The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old...
🟠 CVE-2026-10734: High Schwachstelle
The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all versions up...