Endpunktsicherheit

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More ENDPUNKTSICHERHEIT

⚡ Weekly Recap: VMware Exploits, Windows 0-Day, MCP Attacks, Browser Hijacks and More

The expensive attacks are not always the clever ones. This week had plenty of proof. Exposed services got hit, old...

18. Aug. 2026 Keine Kommentare
🟠 CVE-2026-10734: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-10734: High Schwachstelle

The Infility Global plugin for WordPress is vulnerable to Stored Cross-Site Scripting via /cf7_record Log Endpoint in all versions up...

18. Aug. 2026 Keine Kommentare
🟠 CVE-2026-73057: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-73057: High Schwachstelle

stoatchat before 0.15.0 fails to validate SVG viewBox dimensions in the proxy endpoint, allowing attackers to cause denial of service...

18. Aug. 2026 Keine Kommentare
🟠 CVE-2026-17087: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-17087: High Schwachstelle

The WP Travel Engine – Tour Booking Plugin – Tour Operator Software plugin for WordPress is vulnerable to authorization bypass...

18. Aug. 2026 Keine Kommentare
🟠 CVE-2026-19728: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-19728: High Schwachstelle

The Extra Product Options Builder for WooCommerce WordPress plugin before 1.2.176 does not verify that the requester is entitled to...

18. Aug. 2026 Keine Kommentare
🟠 CVE-2026-19717: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-19717: High Schwachstelle

The CatFolders Document Gallery & PDF Library WordPress plugin before 2.0.7 does not have authorisation checks in some of its...

18. Aug. 2026 Keine Kommentare
🔴 CVE-2026-19349: Critical Schwachstelle ENDPUNKTSICHERHEIT

🔴 CVE-2026-19349: Critical Schwachstelle

Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.17.0 before 2.21.5, from 2.22.0 before 2.23.3 for Perl allow authentication bypass via...

18. Aug. 2026 Keine Kommentare
Shell investigates ‚potential incident‘ after Clop data theft claims ENDPUNKTSICHERHEIT

Shell investigates ‚potential incident‘ after Clop data theft claims

Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole...

17. Aug. 2026 Keine Kommentare
New AmnesiaStealer macOS malware hijacks browser sessions via remote control ENDPUNKTSICHERHEIT

New AmnesiaStealer macOS malware hijacks browser sessions via remote control

A new information-stealing malware called AmnesiaStealer, which targets macOS users via ClickFix attacks, includes a streaming module that allows the...

17. Aug. 2026 Keine Kommentare
AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions ENDPUNKTSICHERHEIT

AmnesiaStealer macOS Malware Steals Data, Controls Browser Sessions

The Rust-based macOS infostealer harvests users’ passwords, keychain information, Chromium-based browser data, and Safari cookies. The post AmnesiaStealer macOS Malware...

16. Aug. 2026 Keine Kommentare