Endpunktsicherheit
ENDPUNKTSICHERHEIT
Researchers Turn USB Auto-Install Into a Full SYSTEM Takeover on Windows 11
Windows Plug and Play can be abused to fetch signed vendor software for an emulated USB device and execute privileged...
ENDPUNKTSICHERHEIT
Mozilla Revokes Firefox and Thunderbird Linux Signing Key After Key Lands in Private Repo
Mozilla has scrapped the cryptographic key behind Firefox and Thunderbird downloads for Linux after an unencrypted copy of it was...
🟡 CVE-2026-15237: Medium Schwachstelle
The MotoPress Hotel Booking WordPress plugin before 6.2.3 does not perform any authorization or ownership check on a REST endpoint...
🟠 CVE-2026-17542: High Schwachstelle
The File Manager WordPress plugin before 6.9.1 does not perform any capability check on one of its file manager connector...
🟠 CVE-2026-16257: High Schwachstelle
The Arvow AI SEO Writer WordPress plugin before 1.5.4 does not properly restrict access to one of its REST endpoints,...
ENDPUNKTSICHERHEIT
Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development
North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage...
ENDPUNKTSICHERHEIT
China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw
Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain...
🟡 CVE-2026-16032: Medium Schwachstelle
The LWS Optimize WordPress plugin before 4.1.2 does not properly escape a value submitted through an unauthenticated analytics endpoint before...
🟠 CVE-2026-19379: High Schwachstelle
A vulnerability was determined in EFM ipTIME AX8004M 15.09.0. Impacted is the function popen of the file /cgi/d.cgi of the...
🟠 CVE-2026-19374: High Schwachstelle
A security vulnerability has been detected in adafap api-mcp up to 92b9a5d04acfec165c7d4ef852496593aa87be06. This affects the function customAxios of the file...