*** GMail and Validation-Mails *** There seems to be an issue that Gmail is not accepting mails from my server. The reason is that I am currently rebuilding my server infrastructure and the MX-entries are not correctly set. I have activated the accounts using a Gmail-address manually. If you do not receive the validation mail, drop me a note to k.e.klingner@gmail.com.

Latest

Metabase Patches Vulnerability Exploited as Zero-Day

The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances. The post Metabase Patches Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.

SecurityWeek

Python Now Has a Post-Quantum Encryption Library

This is good: Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support for ML-KEM, the NIST-standard key-establishment pr…

Bruce Schneier

[UPDATE] [kritisch] Linux Kernel: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um vertrauliche Informationen offenzulegen, Daten zu manipulieren, einen Denial-of-Service-Zustand zu verursachen oder seine Rechte zu erweitern.

BSI CERT Security Advisory

[UPDATE] [hoch] WordPress: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in WordPress ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, um seine Privilegien zu erhöhen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu um…

BSI CERT Security Advisory

[UPDATE] [hoch] Google Chrome: Mehrere Schwachstellen

Ein Angreifer kann mehrere Schwachstellen in Google Chrome ausnutzen, um beliebigen Programmcode auszuführen, vertrauliche Informationen offenzulegen, Daten zu manipulieren oder einen Denial-of-Service-Zustand herbeizuf…

BSI CERT Security Advisory

Löschkonzept DSGVO und ISO 27001 konform umsetzen

Ein wirksames Löschkonzept sollte sowohl die Anforderungen der DSGVO als auch die der ISO 27001 erfüllen. Dieser Beitrag zeigt, wie Datenschutzbeauftragte und Informationssicherheitsbeauftragte gemeinsam ein normkonform…

Dr. Datenschutz

Corporate Data Stolen in Levi Strauss Cyberattack

Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them. The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek.

SecurityWeek

CVE-2026-21082 | Samsung Health up to 6.x path traversal

A vulnerability, which was classified as problematic, has been found in Samsung Health up to 6.x. This affects an unknown part. This manipulation causes relative path traversal. This vulnerability is tracked as CVE-2026…

vuldb

CVE-2026-21077 | Samsung Health up to 6.30.5.105 authorization

A vulnerability classified as problematic was found in Samsung Health up to 6.30.5.105. Affected by this issue is some unknown functionality. The manipulation results in incorrect authorization. This vulnerability is id…

vuldb