Endpunktsicherheit
Shell investigates ‚potential incident‘ after Clop data theft claims
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole...
🟠 CVE-2026-72825: High Schwachstelle
The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key scope cap bypass in the POST /reports/twig-content/allowlist endpoint (ReportsController). The endpoint enforces...
🟠 CVE-2026-69101: High Schwachstelle
Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vulnerability that allows authenticated attackers to perform server-side request forgery...
🟠 CVE-2026-72859: High Schwachstelle
Budibase versions 3.39.4 before 3.40.0 contain an authorization regression in the S3 attachment upload endpoint that allows BASIC users to...
🟠 CVE-2026-16772: High Schwachstelle
In Akaunting versions
🟠 CVE-2026-72836: High Schwachstelle
FileBrowser before 2.63.19 does not account for case-insensitive filesystems when checking home directory ownership during self-registration. When Signup and CreateUserDir...
🟠 CVE-2026-72833: High Schwachstelle
The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and
🟠 CVE-2026-72831: High Schwachstelle
The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) contains an incorrect authorization vulnerability in its Flex Objects API....
🔴 CVE-2026-72822: Critical Schwachstelle
The getgrav/grav-plugin-api Composer package before 1.0.13 (affected
ENDPUNKTSICHERHEIT
Ransomware Hits Colombian Justice Ministry Days Before Presidential Transition
Attackers continue to target critical infrastructure and government-linked organizations in the country, mirroring the increased activity across Latin America....