Endpunktsicherheit

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign ENDPUNKTSICHERHEIT

TeamPCP Linked To Redis Attacks Dating Back To 2020 And Later Supply Chain Campaign

A new analysis has uncovered that the threat actor tracked as TeamPCP has been active on the cybercrime scene as...

07. Aug. 2026 Keine Kommentare
🟠 CVE-2026-16602: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-16602: High Schwachstelle

The Passster WordPress plugin before 4.3.6 does not perform a post-status check before returning post content from an unauthenticated REST...

07. Aug. 2026 Keine Kommentare
🟠 CVE-2026-54418: High Schwachstelle ANWENDUNGSSICHERHEIT

🟠 CVE-2026-54418: High Schwachstelle

Leantime through 3.6.2 exposes the JSON-RPC methods leantime.rpc.TwoFA.TwoFA.getSetupData, saveSecret, verifyAndEnable, and disable2FA, which act on a caller-supplied userId parameter with...

07. Aug. 2026 Keine Kommentare
🟠 CVE-2026-18322: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-18322: High Schwachstelle

The Smart Popup by Supsystic plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including,...

07. Aug. 2026 Keine Kommentare
Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself ENDPUNKTSICHERHEIT

Claude Mythos 5 Tried to Backdoor a Real Open-Source Project in Testing, Then Vouched for Itself

An agent running Anthropic's Claude Mythos 5 spent 34 hours trying to get a malware dropper merged into a real...

06. Aug. 2026 Keine Kommentare
Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures ENDPUNKTSICHERHEIT

Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures

A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a...

06. Aug. 2026 Keine Kommentare
New XCSSET variant targets macOS devs via compromised Xcode projects ENDPUNKTSICHERHEIT

New XCSSET variant targets macOS devs via compromised Xcode projects

A new version of the XCSSET malware is targeting thousands of macOS users through compromised Xcode projects and GitHub repositories. [...]...

05. Aug. 2026 Keine Kommentare
DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT ENDPUNKTSICHERHEIT

DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT

A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images...

05. Aug. 2026 Keine Kommentare
🟠 CVE-2026-69086: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-69086: High Schwachstelle

SiYuan versions before v3.7.3 fail to validate the avID parameter on all code branches in attribute-view read endpoints, allowing attackers...

05. Aug. 2026 Keine Kommentare
🟠 CVE-2026-68587: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-68587: High Schwachstelle

SiYuan versions before v3.7.3 contain an information disclosure vulnerability in the getHeadingDeleteTransaction, getHeadingLevelTransaction, and getHeadingInsertTransaction endpoints that return rend...

05. Aug. 2026 Keine Kommentare