Endpunktsicherheit

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11 ENDPUNKTSICHERHEIT

Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11

Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged...

12. Aug. 2026 Keine Kommentare
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo ENDPUNKTSICHERHEIT

Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo

Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was...

12. Aug. 2026 Keine Kommentare
🟡 CVE-2026-15237: Medium Schwachstelle ENDPUNKTSICHERHEIT

🟡 CVE-2026-15237: Medium Schwachstelle

The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint...

12. Aug. 2026 Keine Kommentare
🟠 CVE-2026-17542: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-17542: High Schwachstelle

The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector...

12. Aug. 2026 Keine Kommentare
🟠 CVE-2026-16257: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-16257: High Schwachstelle

The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints,...

12. Aug. 2026 Keine Kommentare
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development ENDPUNKTSICHERHEIT

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage...

11. Aug. 2026 Keine Kommentare
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw ENDPUNKTSICHERHEIT

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain...

11. Aug. 2026 Keine Kommentare
🟡 CVE-2026-16032: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-16032: Medium Schwachstelle

The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before...

11. Aug. 2026 Keine Kommentare
🟠 CVE-2026-19379: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-19379: High Schwachstelle

A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the...

11. Aug. 2026 Keine Kommentare
🟠 CVE-2026-19374: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-19374: High Schwachstelle

A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file...

11. Aug. 2026 Keine Kommentare