Endpunktsicherheit

Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer ENDPUNKTSICHERHEIT

Hijacked npm and Go Packages Use VS Code Tasks to Deploy Python Infostealer

Cybersecurity researchers have uncovered two hijacked npm packages and a cluster of Go packages that are designed to deploy a...

29. Juni 2026 Keine Kommentare
🟡 CVE-2026-13525: Medium Schwachstelle ANWENDUNGSSICHERHEIT

🟡 CVE-2026-13525: Medium Schwachstelle

A vulnerability was detected in CodeAstro Human Resource Management System 1.0. This issue affects the function emselectByCode of the file...

29. Juni 2026 Keine Kommentare
🟡 CVE-2026-10593: Medium Schwachstelle ENDPUNKTSICHERHEIT

🟡 CVE-2026-10593: Medium Schwachstelle

The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications. In unicast_client_ep_qos_state() (subsys/bluetooth/audio/bap_unicast_client.c),...

29. Juni 2026 Keine Kommentare
🟠 CVE-2026-13528: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-13528: High Schwachstelle

A vulnerability was found in YunaiV/zhijiantianya ruoyi-vue-pro up to 2026.04-jdk8-SNAPSHOT. The impacted element is the function generateUploadPath of the file...

29. Juni 2026 Keine Kommentare
Google Details Turla’s New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks ENDPUNKTSICHERHEIT

Google Details Turla’s New STOCKSTAY Backdoor Used in Ukraine Espionage Attacks

The Russian state-sponsored threat actor known as Turla has been attributed to a previously undocumented .NET backdoor called STOCKSTAY that...

28. Juni 2026 Keine Kommentare
Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack ENDPUNKTSICHERHEIT

Miasma Malware Targets npm Packages and GitHub Actions in Supply Chain Attack

Cybersecurity researchers have flagged yet another evolution of the supply chain attack linked to the Mini Shai-Hulud, Miasma, and Hades...

28. Juni 2026 Keine Kommentare
🟠 CVE-2026-10823: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-10823: High Schwachstelle

The YMC Filter WordPress plugin before 3.11.3 does not properly authorize access to one of its REST API endpoints and...

28. Juni 2026 Keine Kommentare
🟠 CVE-2026-57920: High Schwachstelle ENDPUNKTSICHERHEIT

🟠 CVE-2026-57920: High Schwachstelle

Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.

28. Juni 2026 Keine Kommentare
New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries ENDPUNKTSICHERHEIT

New Linux pedit COW Exploit Enables Root Access by Poisoning Cached Binaries

A flaw in the Linux kernel's traffic-control subsystem can let a local unprivileged user gain root on affected systems. CVE-2026-46331,...

27. Juni 2026 Keine Kommentare
New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks ENDPUNKTSICHERHEIT

New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks

A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as...

27. Juni 2026 Keine Kommentare