*** GMail and Validation-Mails ***
There seems to be an issue that Gmail is not accepting mails from my server. The reason is that I am currently rebuilding my server infrastructure and the MX-entries are not correctly set. I have activated the accounts using a Gmail-address manually. If you do not receive the validation mail, drop me a note to k.e.klingner@gmail.com.
The UK AI Security Institute (AISI) recently disclosed that during cybersecurity evaluations, the GPT-6 Astra model executed simulated, unauthorized supply-chain attacks. This was part of a pre-release assessment conduc…
GitHub Security Lab has disclosed that its open-source AI security agent identified 24 vulnerabilities in Android applications, including flaws that could enable covert location tracking in OsmAnd and account takeover a…
A vulnerability, which was classified as critical, has been found in pretix up to 2026.5.4/2026.6.1/2026.7.0. This impacts an unknown function. Performing a manipulation results in session expiration. This vulnerability…
A vulnerability classified as problematic was found in pretix up to 2026.5.4/2026.6.1/2026.7.0. This affects an unknown function of the component Help Texts. Such manipulation leads to cross site scripting. This vulnera…
A vulnerability classified as problematic has been found in esengine DeepSeek-Reasonix up to 2.20.x. The impacted element is the function filter.clean of the file .git/config of the component Diff Viewer. This manipulat…
A vulnerability described as problematic has been identified in Dell Secure Connect Gateway Policy Manager. The affected element is an unknown function. The manipulation results in open redirect. This vulnerability was …
A vulnerability marked as very critical has been reported in Dell Secure Connect Gateway Policy Manager. Impacted is an unknown function. The manipulation leads to permission issues. This vulnerability is uniquely ident…
A vulnerability labeled as critical has been found in Dbit T-CPE301K Mini WiFi Router. This issue affects some unknown processing of the file /js/common/do_cmd.js. Executing a manipulation can lead to stack-based buffer…
A vulnerability identified as critical has been detected in pretix up to 2026.5.4/2026.6.1/2026.7.0. This vulnerability affects unknown code of the component File Upload. Performing a manipulation results in session fix…
A vulnerability categorized as problematic has been discovered in pretix up to 2026.5.4/2026.6.1/2026.7.0. This affects an unknown part. Such manipulation leads to cross-site request forgery. This vulnerability is trade…
A vulnerability was found in pretix up to 2026.5.4/2026.6.1/2026.7.0. It has been rated as problematic. Affected by this issue is some unknown functionality. This manipulation causes permission issues. This vulnerabilit…
A vulnerability was found in psyb0t docker-mailbox up to 0.4.12. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component IMAP Command Construction. The manipulation …
A vulnerability was found in Shenzhen Dbit Network Equipment T-CPE301K 4G Mini WiFi Router. It has been classified as very critical. Affected is an unknown function. The manipulation leads to hard-coded credentials. Thi…
A vulnerability was found in Dell Secure Connect Gateway Policy Manager and classified as problematic. This impacts an unknown function. Executing a manipulation can lead to cleartext transmission of sensitive informati…
A vulnerability has been found in Linux Kernel up to 6.1.186/6.6.155/6.12.107/6.18.48/7.1.12 and classified as critical. This affects the function kvm_gfn_is_write_tracked of the component KVM. Performing a manipulation…
According to Dodo Pizza, the potentially compromised information included customers’ names, addresses, email addresses, phone numbers, dates of birth and order details.
A spokesperson for the court system told Recorded Future News that the incident did not involve ransomware and the hackers have not issued ransom demands for the stolen data as of Monday.
The data breach affects the Defense Manpower Data Center (DMDC), which maintains personnel records for the Department of Defense. The post Pentagon Personnel Agency Data Breach Impacts 3 Million People appeared first on…
A vulnerability, which was classified as problematic, was found in Pretix up to 2026.5.4/2026.6.1/2026.7.0. The impacted element is an unknown function of the component Checkout Flow. Such manipulation leads to improper…
A vulnerability, which was classified as problematic, has been found in Dell Secure Connect Gateway Policy Manager. The affected element is an unknown function. This manipulation causes cross-site request forgery. This …
A vulnerability classified as problematic was found in Dell Secure Connect Gateway Policy Manager. Impacted is an unknown function. The manipulation results in improper initialization. This vulnerability is identified a…
A vulnerability classified as critical has been found in Apache DolphinScheduler. This issue affects some unknown processing of the component Alert Script Plugin. The manipulation leads to command injection. This vulner…
A vulnerability described as critical has been identified in Apache DolphinScheduler. This vulnerability affects unknown code of the component Sub-Workflow Tasks. Executing a manipulation can lead to improper authorizat…
A vulnerability marked as problematic has been reported in Apache DolphinScheduler. This affects an unknown part. Performing a manipulation results in improper privilege management. This vulnerability was named CVE-2026…
A vulnerability labeled as critical has been found in Apache DolphinScheduler. Affected by this issue is some unknown functionality. Such manipulation leads to improper authorization. This vulnerability is uniquely iden…
A vulnerability identified as critical has been detected in Apache DolphinScheduler. Affected by this vulnerability is an unknown functionality of the component Actuator Endpoint. This manipulation causes improper authe…
A vulnerability categorized as problematic has been discovered in Apache DolphinScheduler. Affected is an unknown function. The manipulation results in improper authorization. This vulnerability is known as CVE-2026-718…
A vulnerability was found in Interprobe Information Qorela DC up to 1.6.1. It has been rated as critical. This impacts an unknown function. The manipulation leads to improper authorization. This vulnerability is traded …
A vulnerability was found in OpenSolution Quick.Cart up to 6.7.0. It has been declared as problematic. This affects an unknown function of the component Admin Config Panel. Executing a manipulation can lead to cross-sit…
A vulnerability was found in BishopFox Sliver up to 1.7.7. It has been classified as critical. The impacted element is the function BinaryMagic of the component operator gRPC handler. Performing a manipulation results i…
A vulnerability was found in Dell Secure Connect Gateway Policy Manager up to 5.36 and classified as critical. The affected element is an unknown function. Such manipulation leads to improper validation of integrity che…
A vulnerability has been found in Apache XmlSchema up to 2.3.2 and classified as problematic. Impacted is an unknown function of the component walker. This manipulation causes stack-based buffer overflow. This vulnerabi…
A vulnerability, which was classified as problematic, was found in Apache XmlSchema up to 2.3.2. This issue affects some unknown processing. The manipulation results in stack-based buffer overflow. This vulnerability is…
A vulnerability, which was classified as problematic, has been found in Apache XmlSchema up to 2.3.2. This vulnerability affects unknown code of the component Schema Parsing. The manipulation leads to stack-based buffer…
A vulnerability classified as problematic was found in Apache DolphinScheduler up to 3.4.2. This affects an unknown part of the file /datasources/unauth-datasource of the component Data Source Authorization. Executing a…
Hackers are abusing ChatGPT’s Custom GPT feature to impersonate AI products and trick users into installing a sophisticated remote access trojan (RAT), according to Huntress researchers. The campaign turns a trusted Cha…
Rig provides an identity dependencies graph to distinguish between legitimate users and rogue AI agents The post Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks appeared first on Security…
A vulnerability classified as problematic has been found in Dell Secure Connect Gateway Policy Manager. Affected by this issue is some unknown functionality. Performing a manipulation results in improper authorization. …
A vulnerability described as problematic has been identified in Dell Secure Connect Gateway Policy Manager up to 5.35.x. Affected by this vulnerability is an unknown functionality. Such manipulation leads to improper ce…
A vulnerability marked as critical has been reported in MyPresta Google Merchant Center Feed up to 2.3.8. Affected is an unknown function of the file feed.php. This manipulation causes improper input validation. The ide…
Die neuesten Entwicklungen bei der KI, das weiterhin unklare Verhältnis der DSGVO zu den übrigen EU-Digitalrechtsakten und nicht zuletzt die angekündigten Gesetzesänderungen: Die zentralen Themen der Datenschutzkonferen…
Tests von Forschern decken ein Risiko für Angriffe auf die Lieferkette auf. Als Beispiel nennen sie das Einschleusen von Payloads in Open-Source-Code. (Security, KI)
A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. [...]
Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Froxlor ausnutzen, um Cross-Site-Scripting-Angriffe durchzuführen, vertrauliche Informationen offenzulegen, Daten zu manipulieren und möglicherwei…
Ein Angreifer kann mehrere Schwachstellen in verschiedenen Apache Airflow Providern ausnutzen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um Informationen offenzulegen und um Sicherheitsvo…
A vulnerability labeled as problematic has been found in Red Hat Enterprise Linux and Hardened Images. This impacts the function iterReadArchiveNext of the component Symlink Parsing. The manipulation results in integer …
Ein lokaler Angreifer kann mehrere Schwachstellen in Wind River VxWorks ausnutzen, um einen Denial of Service Angriff durchzuführen, möglicherweise beliebigen Code auszuführen und Daten offenzulegen oder zu manipulieren.
Ein Angreifer kann mehrere Schwachstellen in WebKitGTK ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren, Spoofing-Angriff…