*** GMail and Validation-Mails ***
There seems to be an issue that Gmail is not accepting mails from my server. The reason is that I am currently rebuilding my server infrastructure and the MX-entries are not correctly set. I have activated the accounts using a Gmail-address manually. If you do not receive the validation mail, drop me a note to k.e.klingner@gmail.com.
A vulnerability was found in Redis up to 8.8.1. It has been declared as critical. This affects the function getPingExtLength of the component Cluster Bus Message Parser. Executing a manipulation can lead to out-of-bound…
A vulnerability was found in duhow xiaoai-patch. It has been classified as critical. Affected by this issue is the function os.system of the file api/main.py of the component Endpoint Handler. Performing a manipulation …
A vulnerability was found in NASA HyperCP and classified as critical. Affected by this vulnerability is an unknown functionality of the file Source/OBPGSession.py of the component Handler. Such manipulation leads to os …
A vulnerability has been found in cube-root directory-serve up to 1.3.7 and classified as critical. Affected is an unknown function of the file lib/middleware/file-remove.js. This manipulation of the argument File cause…
A vulnerability, which was classified as critical, was found in Tencent APIJSON up to 8.1.8. This impacts an unknown function of the file AbstractSQLConfig.java of the component Per-role Allow-list Check. The manipulati…
A vulnerability, which was classified as critical, has been found in fosrl Pangolin up to 1.20.0. This affects the function verifyResourceAccessToken of the file server/routers/resource/authWithAccessToken.ts of the com…
A vulnerability classified as critical was found in Red Hat GIMP. The impacted element is an unknown function of the component Seattle Filmworks File Loader. Executing a manipulation can lead to heap-based buffer overfl…
A vulnerability classified as very critical has been found in AsyncFuncAI deepwiki-open. The affected element is an unknown function of the file api/api.py. Performing a manipulation of the argument owner/repo/repo_type…
A vulnerability described as problematic has been identified in FreePBX 17.0. Impacted is an unknown function of the file amp_conf/htdocs/admin/libraries/BMO/Ajax.class.php of the component Ajax. Such manipulation leads…
A vulnerability marked as problematic has been reported in Bludit 4.0.0-beta. This issue affects the function Filesystem::mv of the file bl-kernel/ajax/logo-upload.php of the component Upload Endpoint. This manipulation…
A vulnerability labeled as critical has been found in picocms Pico up to 2.1.4. This vulnerability affects the function Pico::getBaseUrl of the file lib/Pico.php of the component Base URL. The manipulation results in in…
The security defect allows unauthenticated, remote attackers to gain administrative access to Metabase instances. The post Metabase Patches Vulnerability Exploited as Zero-Day appeared first on SecurityWeek.
This is good: Post-quantum cryptography is now one pip-install away for the entire Python ecosystem. With funding from the Sovereign Tech Agency, we implemented support for ML-KEM, the NIST-standard key-establishment pr…
Ein Angreifer kann mehrere Schwachstellen in Linux Kernel ausnutzen, um vertrauliche Informationen offenzulegen, Daten zu manipulieren, einen Denial-of-Service-Zustand zu verursachen oder seine Rechte zu erweitern.
Ransomware campaigns are increasingly starting with people who hold the keys to everyday business decisions. Attackers are compromising managers whose accounts can open doors to contracts, payments, customer records, an…
Ein Angreifer kann mehrere Schwachstellen in WordPress ausnutzen, um einen Cross-Site Scripting Angriff durchzuführen, um seine Privilegien zu erhöhen, um Informationen offenzulegen, und um Sicherheitsvorkehrungen zu um…
Ein Angreifer kann mehrere Schwachstellen in Google Chrome ausnutzen, um beliebigen Programmcode auszuführen, vertrauliche Informationen offenzulegen, Daten zu manipulieren oder einen Denial-of-Service-Zustand herbeizuf…
A vulnerability identified as problematic has been detected in WP Health Umbrella Plugin up to 2.26.2 on WordPress. This affects an unknown part. The manipulation leads to cross-site request forgery. This vulnerability …
A vulnerability categorized as critical has been discovered in GNU Emacs up to 30.2. Affected by this issue is the function sfnt_vary_simple_glyph/sfnt_vary_compound_glyph of the file src/sfnt.c of the component Gvar Ta…
A vulnerability was found in GNU Emacs up to 30.2. It has been rated as critical. Affected by this vulnerability is the function sfnt_read_table_directory of the file src/sfnt.c of the component Font Parser. Performing …
A vulnerability was found in GNU Emacs. It has been declared as critical. Affected is the function sfnt_read_name_table of the file src/sfnt.c of the component Font Handler. Such manipulation leads to integer overflow. …
A vulnerability was found in GNU Emacs up to 30.2. It has been classified as critical. This impacts the function sfnt_read_cmap_format_12 of the file src/sfnt.c of the component TrueType Font Processing. This manipulati…
A vulnerability was found in GNU Cpio up to 2.15 and classified as critical. This affects an unknown function of the component Archive Member Listing. The manipulation results in injection. This vulnerability is catalog…
A vulnerability has been found in GNU Cpio up to 2.15 and classified as problematic. The impacted element is the function link_to_name of the component Tar Archive Extraction. The manipulation leads to path traversal. T…
A vulnerability, which was classified as problematic, was found in GNU cpio up to 2.15. The affected element is the function make_path of the file src/makepath.c. Executing a manipulation can lead to stack-based buffer …
Der Open-Source-Entwickler Daniel Stenberg sucht Helfer für das Curl-Security-Team. Die derzeitigen sieben Mitglieder haben alle eine Windows-Aversion. (Open Source, KI)
In einer Software-Dokumentation des chinesischen Herstellers MG taucht die Malware Teardroid auf. Das könnte jedoch ein Scan-Fehler sein. (Open Source, Malware)
A vulnerability, which was classified as critical, has been found in Fabrikar Fabrik Extension 1.0.0-4.6.6. Impacted is an unknown function. Performing a manipulation results in code injection. This vulnerability is ide…
A vulnerability classified as critical was found in Red Hat Directory Server. This issue affects some unknown processing of the component CleanAllRUV. Such manipulation leads to improper authorization. This vulnerabilit…
Kimsuky has been observed blending polished AI-made documents with familiar phishing tactics to push AsyncRAT, a remote-access trojan. The campaign shows how old delivery methods can gain new credibility when the bait l…
Im Rahmen des PCC-Bug-Bounty-Programms, das seit 2024 Sicherheitsexperten offensteht, kam es zu einem erfolgreichen Angriff. Telemetrie-Daten konnten abfließen.
CERT.PL said this appears to be the first instance of a private APN being used as an attack vector. The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek.
Ein wirksames Löschkonzept sollte sowohl die Anforderungen der DSGVO als auch die der ISO 27001 erfüllen. Dieser Beitrag zeigt, wie Datenschutzbeauftragte und Informationssicherheitsbeauftragte gemeinsam ein normkonform…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. [...]
The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands. The post CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability appeared first on SecurityWeek.
Critical flaws have been found in the Connective Signing Extension, a browser component used by more than 2 million people in Belgium to access electronic identity cards and Maestro payment cards. The now-patched issues…
Payroll Pirates are using phishing emails to seize Microsoft 365 sessions and search payroll-related mailboxes. The campaign turns a voicemail alert into a route for financial fraud, even when multi-factor authenticatio…
Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them. The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek.
A vulnerability classified as problematic has been found in ECOVACS ROBOTICS ECOVACS PRO App up to 1.3.81. This vulnerability affects unknown code. This manipulation causes improper certificate validation. The identific…
A vulnerability described as problematic has been identified in Samsung SmartThings. This affects an unknown part. The manipulation results in improper access controls. This vulnerability was named CVE-2026-21084. The a…
A vulnerability marked as very critical has been reported in ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC. Affected by this issue is some unknown functionality of the component Telnet Service. The manipulation le…
A vulnerability labeled as problematic has been found in ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC. Affected by this vulnerability is an unknown functionality of the component Web Server. Executing a manipulat…
A vulnerability identified as problematic has been detected in Samsung Smart Switch 3.7.64.10/3.7.66.6/3.7.67.2/3.7.68.6/3.7.69.15. Affected is an unknown function. Performing a manipulation results in improper input va…
A vulnerability categorized as problematic has been discovered in ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC. This impacts an unknown function. Such manipulation leads to improper certificate validation. This v…
A vulnerability was found in Ecovacs Robotics DEEBOT PRO M1 and DEEBOT PRO K1VAC. It has been rated as very critical. This affects an unknown function. This manipulation causes weak password requirements. This vulnerabi…
A vulnerability was found in ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC. It has been declared as critical. The impacted element is an unknown function of the component Wi-Fi Hotspot. The manipulation results in…
A vulnerability was found in ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC. It has been classified as very critical. The affected element is an unknown function. The manipulation leads to channel accessible by non…
A vulnerability was found in Ecovacs Robotics DEEBOT PRO M1 and DEEBOT PRO K1VAC and classified as problematic. Impacted is an unknown function. Executing a manipulation can lead to improper certificate validation. This…
A vulnerability has been found in ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC and classified as critical. This issue affects some unknown processing of the component Websocket. Performing a manipulation results …
Microsoft hat durch seinen Streit mit Chaotic Eclipse einen Pwnie Award gewonnen. Annehmen wollte ihn wohl keiner - aus Angst vor Jobverlust. (Sicherheitslücke, Microsoft)
A vulnerability, which was classified as problematic, was found in Samsung Devices. This vulnerability affects unknown code of the component AppLock. Such manipulation leads to improper export of android application com…
A vulnerability, which was classified as problematic, has been found in Samsung Health up to 6.x. This affects an unknown part. This manipulation causes relative path traversal. This vulnerability is tracked as CVE-2026…
A vulnerability classified as problematic was found in Samsung Health up to 6.30.5.105. Affected by this issue is some unknown functionality. The manipulation results in incorrect authorization. This vulnerability is id…