*** GMail and Validation-Mails ***
There seems to be an issue that Gmail is not accepting mails from my server. The reason is that I am currently rebuilding my server infrastructure and the MX-entries are not correctly set. I have activated the accounts using a Gmail-address manually. If you do not receive the validation mail, drop me a note to k.e.klingner@gmail.com.
A vulnerability classified as problematic was found in cube-root directory-serve up to 1.3.7. Affected is an unknown function of the file lib/helper/html.js of the component Filename Handler. The manipulation results in…
A vulnerability classified as problematic has been found in mustafaakin cast-localvideo. This impacts the function res.sendFile of the file app.js. The manipulation of the argument dir leads to path traversal. This vuln…
A vulnerability described as critical has been identified in duhow xiaoai-patch. This affects an unknown function of the file api/main.py of the component Auth Endpoint. Executing a manipulation of the argument url can …
A vulnerability marked as very critical has been reported in NASA Fprime-gds up to 3.4.3. The impacted element is an unknown function of the file src/fprime_gds/flask/app.py of the component Flask Application. Performin…
A vulnerability labeled as problematic has been found in automatisch. The affected element is an unknown function of the file packages/backend/src/apps/http-request/actions/custom-request/index.js of the component Custo…
A vulnerability identified as critical has been detected in Daptin up to 0.12.34. Impacted is the function CanRead/CanPeek/CanCreate/CanUpdate/CanDelete/CanRefer of the file server/permission/permission.go of the compon…
A vulnerability categorized as critical has been discovered in 4xmen pm2panel. This issue affects the function exec of the file pm2panel.js of the component Handler. The manipulation of the argument ID results in os com…
A vulnerability was found in o1lab xmysql. It has been rated as problematic. This vulnerability affects the function path.join of the file lib/xapi.js of the component xapi. The manipulation of the argument Name leads t…
A vulnerability was found in Redis up to 8.8.1. It has been declared as critical. This affects the function getPingExtLength of the component Cluster Bus Message Parser. Executing a manipulation can lead to out-of-bound…
A vulnerability was found in duhow xiaoai-patch. It has been classified as critical. Affected by this issue is the function os.system of the file api/main.py of the component Endpoint Handler. Performing a manipulation …
A vulnerability was found in NASA HyperCP and classified as critical. Affected by this vulnerability is an unknown functionality of the file Source/OBPGSession.py of the component Handler. Such manipulation leads to os …
A vulnerability has been found in cube-root directory-serve up to 1.3.7 and classified as critical. Affected is an unknown function of the file lib/middleware/file-remove.js. This manipulation of the argument File cause…
A vulnerability, which was classified as critical, was found in Tencent APIJSON up to 8.1.8. This impacts an unknown function of the file AbstractSQLConfig.java of the component Per-role Allow-list Check. The manipulati…
A vulnerability, which was classified as critical, has been found in fosrl Pangolin up to 1.20.0. This affects the function verifyResourceAccessToken of the file server/routers/resource/authWithAccessToken.ts of the com…
A vulnerability classified as critical was found in Red Hat GIMP. The impacted element is an unknown function of the component Seattle Filmworks File Loader. Executing a manipulation can lead to heap-based buffer overfl…
A vulnerability classified as very critical has been found in AsyncFuncAI deepwiki-open. The affected element is an unknown function of the file api/api.py. Performing a manipulation of the argument owner/repo/repo_type…
A vulnerability described as problematic has been identified in FreePBX 17.0. Impacted is an unknown function of the file amp_conf/htdocs/admin/libraries/BMO/Ajax.class.php of the component Ajax. Such manipulation leads…
A vulnerability marked as problematic has been reported in Bludit 4.0.0-beta. This issue affects the function Filesystem::mv of the file bl-kernel/ajax/logo-upload.php of the component Upload Endpoint. This manipulation…
A vulnerability labeled as critical has been found in picocms Pico up to 2.1.4. This vulnerability affects the function Pico::getBaseUrl of the file lib/Pico.php of the component Base URL. The manipulation results in in…
The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances. The post Metabase Patches Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
This is good: Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support for ML-KEM, the NIST-standard key-establishment pr…
Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um vertrauliche Informationen offenzulegen, Daten zu manipulieren, einen Denial-of-Service-Zustand zu verursachen oder seine Rechte zu erweitern.
Ransomware campaigns are increasingly starting with people who hold the keys to everyday business decisions. Attackers are compromising managers whose accounts can open doors to contracts, payments, customer records, an…
Ein Angreifer kann mehrere Schwachstellen in WordPress ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, um seine Privilegien zu erhöhen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu um…
Ein Angreifer kann mehrere Schwachstellen in Google Chrome ausnutzen, um beliebigen Programmcode auszuführen, vertrauliche Informationen offenzulegen, Daten zu manipulieren oder einen Denial-of-Service-Zustand herbeizuf…
A vulnerability identified as problematic has been detected in WP Health Umbrella Plugin up to 2.26.2 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery. This vulnerability …
A vulnerability categorized as critical has been discovered in GNU Emacs up to 30.2. Affected by this issue is the function sfnt_vary_simple_glyph/sfnt_vary_compound_glyph of the file src/sfnt.c of the component Gvar Ta…
A vulnerability was found in GNU Emacs up to 30.2. It has been rated as critical. Affected by this vulnerability is the function sfnt_read_table_directory of the file src/sfnt.c of the component Font Parser. Performing …
A vulnerability was found in GNU Emacs. It has been declared as critical. Affected is the function sfnt_read_name_table of the file src/sfnt.c of the component Font Handler. Such manipulation leads to integer overflow. …
A vulnerability was found in GNU Emacs up to 30.2. It has been classified as critical. This impacts the function sfnt_read_cmap_format_12 of the file src/sfnt.c of the component TrueType Font Processing. This manipulati…
A vulnerability was found in GNU Cpio up to 2.15 and classified as critical. This affects an unknown function of the component Archive Member Listing. The manipulation results in injection. This vulnerability is catalog…
A vulnerability has been found in GNU Cpio up to 2.15 and classified as problematic. The impacted element is the function link_to_name of the component Tar Archive Extraction. The manipulation leads to path traversal. T…
A vulnerability, which was classified as problematic, was found in GNU cpio up to 2.15. The affected element is the function make_path of the file src/makepath.c. Executing a manipulation can lead to stack-based buffer …
Der Open-Source-Entwickler Daniel Stenberg sucht Helfer für das Curl-Security-Team. Die derzeitigen sieben Mitglieder haben alle eine Windows-Aversion. (Open Source, KI)
In einer Software-Dokumentation des chinesischen Herstellers MG taucht die Malware Teardroid auf. Das könnte jedoch ein Scan-Fehler sein. (Open Source, Malware)
A vulnerability, which was classified as critical, has been found in Fabrikar Fabrik Extension 1.0.0-4.6.6. Impacted is an unknown function. Performing a manipulation results in code injection. This vulnerability is ide…
A vulnerability classified as critical was found in Red Hat Directory Server. This issue affects some unknown processing of the component CleanAllRUV. Such manipulation leads to improper authorization. This vulnerabilit…
Kimsuky has been observed blending polished AI-made documents with familiar phishing tactics to push AsyncRAT, a remote-access trojan. The campaign shows how old delivery methods can gain new credibility when the bait l…
Im Rahmen des PCC-Bug-Bounty-Programms, das seit 2024 Sicherheitsexperten offensteht, kam es zu einem erfolgreichen Angriff. Telemetrie-Daten konnten abfließen.
CERT.PL said this appears to be the first instance of a private APN being used as an attack vector. The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek.
Ein wirksames Löschkonzept sollte sowohl die Anforderungen der DSGVO als auch die der ISO 27001 erfüllen. Dieser Beitrag zeigt, wie Datenschutzbeauftragte und Informationssicherheitsbeauftragte gemeinsam ein normkonform…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. [...]
The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands. The post CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability appeared first on SecurityWeek.
Critical flaws have been found in the Connective Signing Extension, a browser component used by more than 2 million people in Belgium to access electronic identity cards and Maestro payment cards. The now-patched issues…
Payroll Pirates are using phishing emails to seize Microsoft 365 sessions and search payroll-related mailboxes. The campaign turns a voicemail alert into a route for financial fraud, even when multi-factor authenticatio…
Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them. The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek.
A vulnerability classified as problematic has been found in ECOVACS ROBOTICS ECOVACS PRO App up to 1.3.81. This vulnerability affects unknown code. This manipulation causes improper certificate validation. The identific…
A vulnerability described as problematic has been identified in Samsung SmartThings. This affects an unknown part. The manipulation results in improper access controls. This vulnerability was named CVE-2026-21084. The a…
A vulnerability marked as very critical has been reported in ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC. Affected by this issue is some unknown functionality of the component Telnet Service. The manipulation le…
A vulnerability labeled as problematic has been found in ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC. Affected by this vulnerability is an unknown functionality of the component Web Server. Executing a manipulat…
A vulnerability identified as problematic has been detected in Samsung Smart Switch 3.7.64.10/3.7.66.6/3.7.67.2/3.7.68.6/3.7.69.15. Affected is an unknown function. Performing a manipulation results in improper input va…
A vulnerability categorized as problematic has been discovered in ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC. This impacts an unknown function. Such manipulation leads to improper certificate validation. This v…
A vulnerability was found in Ecovacs Robotics DEEBOT PRO M1 and DEEBOT PRO K1VAC. It has been rated as very critical. This affects an unknown function. This manipulation causes weak password requirements. This vulnerabi…