Endpunktsicherheit

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access ENDPUNKTSICHERHEIT

Plug and Pwn attack uses fake USB devices for Windows SYSTEM access

Security researchers have disclosed new "Plug and Pwn" attacks that abuse the Windows Plug and Play feature to trigger Windows...

13. Aug. 2026 Keine Kommentare
Android malware combo takes out loans and relays victims‘ credit cards ENDPUNKTSICHERHEIT

Android malware combo takes out loans and relays victims‘ credit cards

A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal...

13. Aug. 2026 Keine Kommentare
🟠 CVE-2026-72552: High Schwachstelle CLOUD-SICHERHEIT

🟠 CVE-2026-72552: High Schwachstelle

A server-side request forgery vulnerability in Dub as of 2026-07-10 allows unauthenticated remote attackers to make the server issue HTTP...

13. Aug. 2026 Keine Kommentare
🟠 CVE-2026-15565: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-15565: High Schwachstelle

A flaw was found in Undertow. A remote attacker can cause Out of Memory on websockets endpoint without authentication on...

13. Aug. 2026 Keine Kommentare
🟠 CVE-2026-72595: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-72595: High Schwachstelle

A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to update ticket records belonging...

13. Aug. 2026 Keine Kommentare
🟠 CVE-2026-72563: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-72563: High Schwachstelle

A broken access control vulnerability in BadChoice Handesk as of 2026-07-10 allows any authenticated agent to overwrite lead records belonging...

13. Aug. 2026 Keine Kommentare
🟠 CVE-2026-72561: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-72561: High Schwachstelle

A broken access control vulnerability in Peppermint Lab Peppermint through commit ba6e217 allows any authenticated non-administrative user to reconfigure the...

13. Aug. 2026 Keine Kommentare
🟠 CVE-2026-72557: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-72557: High Schwachstelle

An unrestricted file upload vulnerability in Cockpit CMS 2.6.0 allows authenticated users to upload files of any extension including PHP...

13. Aug. 2026 Keine Kommentare
🟠 CVE-2026-72533: High Schwachstelle CLOUD-SICHERHEIT

🟠 CVE-2026-72533: High Schwachstelle

An authentication bypass vulnerability in Portainer CE through 2.44.0 allows authenticated low-privileged users to bypass Docker proxy authorization checks via...

13. Aug. 2026 Keine Kommentare
🔴 CVE-2026-19516: Critical Schwachstelle ENDPUNKTSICHERHEIT

🔴 CVE-2026-19516: Critical Schwachstelle

A caller-supplied X-Grafana-URL request header controls the destination of mcp-grafana's outbound requests, and the grafana_api_request tool lets the caller also...

13. Aug. 2026 Keine Kommentare