Endpunktsicherheit
🟡 CVE-2026-49876: Medium Luecke in Apache Gravitino
Authenticated SSRF in Gravitino JobManager allows server-side HTTP requests to internal network and cloud metadata endpoints via unvalidated job template...
ENDPUNKTSICHERHEIT
⚡ Weekly Recap: ShareFile Threat, Citrix Bleed 2 Ransomware, AI Coding Attacks, and More
Somewhere right now, a security tool is quietly finding bugs faster than any human can fix them. That's supposed to...
ENDPUNKTSICHERHEIT
CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks
Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that's capable of harvesting sensitive data from compromised systems....
🟡 CVE-2026-15509: Medium Schwachstelle
A vulnerability has been found in Leantime up to 3.8.0. This impacts the function editUser/addUser of the component JSON-RPC Endpoint....
🟡 CVE-2026-15501: Medium Schwachstelle
A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.25.2. Affected by this issue is the function ToolsRoute.test_mcp_connection...
🟡 CVE-2026-15500: Medium Schwachstelle
A weakness has been identified in AstrBotDevs AstrBot up to 4.25.2. Affected by this vulnerability is the function get_online_plugins of...
ENDPUNKTSICHERHEIT
Ransomware Negotiator Gets 70 Months in Prison for Aiding BlackCat Attacks
A 41-year-old former ransomware negotiator has been sentenced to nearly six years (i.e., 70 months) in prison in the U.S....
ENDPUNKTSICHERHEIT
URGENT – Progress Tells ShareFile Customers to Shut Down Storage Zone Controllers Over Security Thre
Progress Software has told ShareFile customers to shut down the Windows servers running their Storage Zone Controllers, confirming to The...
🟠 CVE-2026-15479: High Schwachstelle
A vulnerability was found in H3C NX15 V100R017. Affected by this vulnerability is the function change_passwd of the file /api/login/modify...
🟠 CVE-2026-61428: High Schwachstelle
PraisonAI AgentMail versions before 4.6.78 lack signature verification in webhook mode, allowing unauthenticated attackers to inject messages with spoofed sender...