*** GMail and Validation-Mails ***
There seems to be an issue that Gmail is not accepting mails from my server. The reason is that I am currently rebuilding my server infrastructure and the MX-entries are not correctly set. I have activated the accounts using a Gmail-address manually. If you do not receive the validation mail, drop me a note to k.e.klingner@gmail.com.
A vulnerability, which was classified as problematic, has been found in Dell Secure Connect Gateway Policy Manager. The affected element is an unknown function. This manipulation causes cross-site request forgery. This …
A vulnerability classified as problematic was found in Dell Secure Connect Gateway Policy Manager. Impacted is an unknown function. The manipulation results in improper initialization. This vulnerability is identified a…
A vulnerability classified as critical has been found in Apache DolphinScheduler. This issue affects some unknown processing of the component Alert Script Plugin. The manipulation leads to command injection. This vulner…
A vulnerability described as critical has been identified in Apache DolphinScheduler. This vulnerability affects unknown code of the component Sub-Workflow Tasks. Executing a manipulation can lead to improper authorizat…
A vulnerability marked as problematic has been reported in Apache DolphinScheduler. This affects an unknown part. Performing a manipulation results in improper privilege management. This vulnerability was named CVE-2026…
A vulnerability labeled as critical has been found in Apache DolphinScheduler. Affected by this issue is some unknown functionality. Such manipulation leads to improper authorization. This vulnerability is uniquely iden…
A vulnerability identified as critical has been detected in Apache DolphinScheduler. Affected by this vulnerability is an unknown functionality of the component Actuator Endpoint. This manipulation causes improper authe…
A vulnerability categorized as problematic has been discovered in Apache DolphinScheduler. Affected is an unknown function. The manipulation results in improper authorization. This vulnerability is known as CVE-2026-718…
A vulnerability was found in Interprobe Information Qorela DC up to 1.6.1. It has been rated as critical. This impacts an unknown function. The manipulation leads to improper authorization. This vulnerability is traded …
A vulnerability was found in OpenSolution Quick.Cart up to 6.7.0. It has been declared as problematic. This affects an unknown function of the component Admin Config Panel. Executing a manipulation can lead to cross-sit…
A vulnerability was found in BishopFox Sliver up to 1.7.7. It has been classified as critical. The impacted element is the function BinaryMagic of the component operator gRPC handler. Performing a manipulation results i…
A vulnerability was found in Dell Secure Connect Gateway Policy Manager up to 5.36 and classified as critical. The affected element is an unknown function. Such manipulation leads to improper validation of integrity che…
A vulnerability has been found in Apache XmlSchema up to 2.3.2 and classified as problematic. Impacted is an unknown function of the component walker. This manipulation causes stack-based buffer overflow. This vulnerabi…
A vulnerability, which was classified as problematic, was found in Apache XmlSchema up to 2.3.2. This issue affects some unknown processing. The manipulation results in stack-based buffer overflow. This vulnerability is…
A vulnerability, which was classified as problematic, has been found in Apache XmlSchema up to 2.3.2. This vulnerability affects unknown code of the component Schema Parsing. The manipulation leads to stack-based buffer…
A vulnerability classified as problematic was found in Apache DolphinScheduler up to 3.4.2. This affects an unknown part of the file /datasources/unauth-datasource of the component Data Source Authorization. Executing a…
Hackers are abusing ChatGPT’s Custom GPT feature to impersonate AI products and trick users into installing a sophisticated remote access trojan (RAT), according to Huntress researchers. The campaign turns a trusted Cha…
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to replace software and execute arbitrary code with root privileges. The following versions of Lantronix G520 Series Cellular Ga…
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access critical data or execute arbitrary code. The following versions of Toptech TMS7 and TopHAT are affected: TMS7 7.6.3 (C…
View CSAF Summary Successful exploitation of these vulnerabilities could allow attackers to access, modify, or delete sensitive user data and critical system files, potentially compromising the operation of the entire p…
View CSAF Summary Successful exploitation of these vulnerabilities could allow an attacker to access sensitive information, access user accounts, execute OS-level commands, or take full control over the device. The foll…
View CSAF Summary Successful exploitation of this vulnerability may allow attackers to achieve remote command execution on affected devices, potentially with root privileges, leading to full compromise of the camera sys…
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to achieve remote code execution or cause a denial of service. The following versions of MikroTik RouterOS are affected: RouterOS
View CSAF Summary Successful exploitation of this vulnerability could allow an attacker to inject malformed messages which may lead to a denial-of-service condition. The following versions of Baicells Nova 430H are affe…
Rig provides an identity dependencies graph to distinguish between legitimate users and rogue AI agents The post Rig Security Emerges From Stealth With $12M to Tackle Agentic AI Identity Risks appeared first on Security…
A vulnerability classified as problematic has been found in Dell Secure Connect Gateway Policy Manager. Affected by this issue is some unknown functionality. Performing a manipulation results in improper authorization. …
A vulnerability described as problematic has been identified in Dell Secure Connect Gateway Policy Manager up to 5.35.x. Affected by this vulnerability is an unknown functionality. Such manipulation leads to improper ce…
A vulnerability marked as critical has been reported in MyPresta Google Merchant Center Feed up to 2.3.8. Affected is an unknown function of the file feed.php. This manipulation causes improper input validation. The ide…
Die neuesten Entwicklungen bei der KI, das weiterhin unklare Verhältnis der DSGVO zu den übrigen EU-Digitalrechtsakten und nicht zuletzt die angekündigten Gesetzesänderungen: Die zentralen Themen der Datenschutzkonferen…
Tests von Forschern decken ein Risiko für Angriffe auf die Lieferkette auf. Als Beispiel nennen sie das Einschleusen von Payloads in Open-Source-Code. (Security, KI)
A Vietnamese national was charged with money laundering for his role in a massive "pig butchering" scam, which defrauded a victim out of $16 million worth of cryptocurrency. [...]
Ein entfernter, authentisierter Angreifer kann mehrere Schwachstellen in Froxlor ausnutzen, um Cross-Site-Scripting-Angriffe durchzuführen, vertrauliche Informationen offenzulegen, Daten zu manipulieren und möglicherwei…
Ein Angreifer kann mehrere Schwachstellen in verschiedenen Apache Airflow Providern ausnutzen, um Dateien zu manipulieren, um einen SQL-Injection Angriff durchzuführen, um Informationen offenzulegen und um Sicherheitsvo…
A vulnerability labeled as problematic has been found in Red Hat Enterprise Linux and Hardened Images. This impacts the function iterReadArchiveNext of the component Symlink Parsing. The manipulation results in integer …
Ein lokaler Angreifer kann mehrere Schwachstellen in Wind River VxWorks ausnutzen, um einen Denial of Service Angriff durchzuführen, möglicherweise beliebigen Code auszuführen und Daten offenzulegen oder zu manipulieren.
Ein Angreifer kann mehrere Schwachstellen in WebKitGTK ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren, Spoofing-Angriff…
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (cjose) ausnutzen, um einen Denial of Service Angriff durchzuführen, und um Daten zu manipulieren.
Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Node.js ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, einen Denial-of-Service-Zustand zu verursachen, vertrauliche Informat…
- AI, supply-chain exposure, quantum computing and geopolitical conflict are testing security programs. Preparing for disruption must become part of day-to-day operations. The post Four Cyber Threats Harboring Big Plans…
Ein entfernter, anonymer Angreifer kann eine Schwachstelle in Red Hat Enterprise Linux (rhc) ausnutzen, um einen Denial of Service Angriff durchzuführen.
Ein Angreifer kann mehrere Schwachstellen in IBM DataPower Gateway ausnutzen, um beliebigen Programmcode auszuführen, erweiterte Berechtigungen zu erlangen, Sicherheitsmaßnahmen zu umgehen, Daten zu manipulieren oder of…
Ein entfernter Angreifer kann mehrere Schwachstellen in FreeRDP ausnutzen,um möglicherweise einen Denial-of-Service-Zustand zu verursachen, beliebigen Code auszuführen, Daten zu manipulieren oder vertrauliche Informatio…
Ein entfernter, anonymer Angreifer kann mehrere Schwachstellen in Wireshark ausnutzen, um einen Denial of Service herbeizuführen und potenziell um beliebigen Programmcode auszuführen.
Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox, Firefox ESR und Thunderbird ausnutzen, um seine Privilegien zu erhöhen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Spoofing- o…
Ein Angreifer kann mehrere Schwachstellen in Mozilla Firefox und Mozilla Thunderbird ausnutzen, um beliebigen Code auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Berechtigungen zu…
Ein Angreifer kann mehrere Schwachstellen in FreeRDP ausnutzen, um beliebigen Programmcode auszuführen, Sicherheitsmaßnahmen zu umgehen, vertrauliche Informationen offenzulegen, Daten zu manipulieren oder einen Denial-o…
Ein Angreifer kann mehrere Schwachstellen in OpenSSH ausnutzen, um einen nicht näher spezifizierten Angriff durchzuführen, um einen Denial of Service Angriff durchzuführen, um Informationen offenzulegen, um Dateien zu m…
Ein Angreifer kann mehrere Schwachstellen in FreeRDP ausnutzen, um beliebigen Programmcode auszuführen, um einen Denial of Service Angriff durchzuführen, und um Informationen offenzulegen.