Endpunktsicherheit
Plug and Pwn attack uses fake USB devices for Windows SYSTEM access
Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows...
Android malware combo takes out loans and relays victims‘ credit cards
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal...
🟠 CVE-2026-72552: High Schwachstelle
A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP...
🟠 CVE-2026-15565: High Schwachstelle
A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on...
🟠 CVE-2026-72595: High Schwachstelle
A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket records belonging...
🟠 CVE-2026-72563: High Schwachstelle
A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite lead records belonging...
🟠 CVE-2026-72561: High Schwachstelle
A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the...
🟠 CVE-2026-72557: High Schwachstelle
An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP...
🟠 CVE-2026-72533: High Schwachstelle
An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via...
🔴 CVE-2026-19516: Critical Schwachstelle
A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also...