Endpunktsicherheit
🟠 CVE-2026-80494: High Schwachstelle
The Yogeta WP Cloud WordPress plugin through 1.0 does not validate a user-supplied file path before passing it to a...
🟠 CVE-2026-90493: High Schwachstelle
A vulnerability was detected in Tonec Internet Download Manager up to 6.42 Build 63 on Windows. The impacted element is...
🟠 CVE-2026-81742: High Schwachstelle
The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read,...
How Threat Actors Are Turning Trusted AI Platforms Into an Attack Surface
Threat actors are abusing trusted AI platforms to host malicious content, poison search results, and trick users into installing malware....
Hackers abused Claude to extract secrets from 1.8M Android apps
Anthropic says multiple threat groups, including the financially motivated and state-sponsored espionage groups linked to Russia and China, tried to...
🟠 CVE-2026-89250: High Schwachstelle
WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains an unauthenticated file read vulnerability in the getRecordedFile.php endpoint that streams recorded FLV files...
🟠 CVE-2026-38058: High Schwachstelle
The endpoint on the iDirect iQ200 VSAT terminal returns the complete device configuration as JSON, including the SECURITY section which...
🟠 CVE-2026-89254: High Schwachstelle
AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the CustomizeUser plugin where the field_name parameter is stored...
🟠 CVE-2026-89176: High Schwachstelle
WeenyGenius, a computer lab management system developed by Howyar Technologies, has a Missing Authentication vulnerability. Unauthenticated attackers on the same...
ENDPUNKTSICHERHEIT
Gigabud Creates Android Work Profiles to Hide From Banking App Malware Checks
The Gigabud banking trojan now installs a second Android app that creates a work profile on an infected phone and...