*** GMail and Validation-Mails ***
There seems to be an issue that Gmail is not accepting mails from my server. The reason is that I am currently rebuilding my server infrastructure and the MX-entries are not correctly set. I have activated the accounts using a Gmail-address manually. If you do not receive the validation mail, drop me a note to k.e.klingner@gmail.com.
A vulnerability has been found in GNU Cpio up to 2.15 and classified as problematic. The impacted element is the function link_to_name of the component Tar Archive Extraction. The manipulation leads to path traversal. T…
A vulnerability, which was classified as problematic, was found in GNU cpio up to 2.15. The affected element is the function make_path of the file src/makepath.c. Executing a manipulation can lead to stack-based buffer …
Der Open-Source-Entwickler Daniel Stenberg sucht Helfer für das Curl-Security-Team. Die derzeitigen sieben Mitglieder haben alle eine Windows-Aversion. (Open Source, KI)
In einer Software-Dokumentation des chinesischen Herstellers MG taucht die Malware Teardroid auf. Das könnte jedoch ein Scan-Fehler sein. (Open Source, Malware)
A vulnerability, which was classified as critical, has been found in Fabrikar Fabrik Extension 1.0.0-4.6.6. Impacted is an unknown function. Performing a manipulation results in code injection. This vulnerability is ide…
A vulnerability classified as critical was found in Red Hat Directory Server. This issue affects some unknown processing of the component CleanAllRUV. Such manipulation leads to improper authorization. This vulnerabilit…
Kimsuky has been observed blending polished AI-made documents with familiar phishing tactics to push AsyncRAT, a remote-access trojan. The campaign shows how old delivery methods can gain new credibility when the bait l…
Im Rahmen des PCC-Bug-Bounty-Programms, das seit 2024 Sicherheitsexperten offensteht, kam es zu einem erfolgreichen Angriff. Telemetrie-Daten konnten abfließen.
CERT.PL said this appears to be the first instance of a private APN being used as an attack vector. The post Novel Private APN Pivot Let Hackers Sabotage Second Polish Energy Facility appeared first on SecurityWeek.
Ein wirksames Löschkonzept sollte sowohl die Anforderungen der DSGVO als auch die der ISO 27001 erfüllen. Dieser Beitrag zeigt, wie Datenschutzbeauftragte und Informationssicherheitsbeauftragte gemeinsam ein normkonform…
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. [...]
The critical-severity flaw allows unauthenticated, remote attackers to execute arbitrary commands. The post CISA Urges Immediate Patching of Exploited Progress LoadMaster Vulnerability appeared first on SecurityWeek.
Critical flaws have been found in the Connective Signing Extension, a browser component used by more than 2 million people in Belgium to access electronic identity cards and Maestro payment cards. The now-patched issues…
Payroll Pirates are using phishing emails to seize Microsoft 365 sessions and search payroll-related mailboxes. The campaign turns a voicemail alert into a route for financial fraud, even when multi-factor authenticatio…
Using social engineering, a threat actor accessed the computers of three employees and exfiltrated data from them. The post Corporate Data Stolen in Levi Strauss Cyberattack appeared first on SecurityWeek.
A vulnerability classified as problematic has been found in ECOVACS ROBOTICS ECOVACS PRO App up to 1.3.81. This vulnerability affects unknown code. This manipulation causes improper certificate validation. The identific…
A vulnerability described as problematic has been identified in Samsung SmartThings. This affects an unknown part. The manipulation results in improper access controls. This vulnerability was named CVE-2026-21084. The a…
A vulnerability marked as very critical has been reported in ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC. Affected by this issue is some unknown functionality of the component Telnet Service. The manipulation le…
A vulnerability labeled as problematic has been found in ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC. Affected by this vulnerability is an unknown functionality of the component Web Server. Executing a manipulat…
A vulnerability identified as problematic has been detected in Samsung Smart Switch 3.7.64.10/3.7.66.6/3.7.67.2/3.7.68.6/3.7.69.15. Affected is an unknown function. Performing a manipulation results in improper input va…
A vulnerability categorized as problematic has been discovered in ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC. This impacts an unknown function. Such manipulation leads to improper certificate validation. This v…
A vulnerability was found in Ecovacs Robotics DEEBOT PRO M1 and DEEBOT PRO K1VAC. It has been rated as very critical. This affects an unknown function. This manipulation causes weak password requirements. This vulnerabi…
A vulnerability was found in ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC. It has been declared as critical. The impacted element is an unknown function of the component Wi-Fi Hotspot. The manipulation results in…
A vulnerability was found in ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC. It has been classified as very critical. The affected element is an unknown function. The manipulation leads to channel accessible by non…
A vulnerability was found in Ecovacs Robotics DEEBOT PRO M1 and DEEBOT PRO K1VAC and classified as problematic. Impacted is an unknown function. Executing a manipulation can lead to improper certificate validation. This…
A vulnerability has been found in ECOVACS ROBOTICS DEEBOT PRO M1 and DEEBOT PRO K1VAC and classified as critical. This issue affects some unknown processing of the component Websocket. Performing a manipulation results …
Microsoft hat durch seinen Streit mit Chaotic Eclipse einen Pwnie Award gewonnen. Annehmen wollte ihn wohl keiner - aus Angst vor Jobverlust. (Sicherheitslücke, Microsoft)
A vulnerability, which was classified as problematic, was found in Samsung Devices. This vulnerability affects unknown code of the component AppLock. Such manipulation leads to improper export of android application com…
A vulnerability, which was classified as problematic, has been found in Samsung Health up to 6.x. This affects an unknown part. This manipulation causes relative path traversal. This vulnerability is tracked as CVE-2026…
A vulnerability classified as problematic was found in Samsung Health up to 6.30.5.105. Affected by this issue is some unknown functionality. The manipulation results in incorrect authorization. This vulnerability is id…
A vulnerability classified as problematic has been found in Samsung Health up to 6.0.x. Affected by this vulnerability is an unknown functionality. The manipulation leads to incorrect authorization. This vulnerability i…
A vulnerability described as very critical has been identified in Samsung Bixby. Affected is an unknown function. Executing a manipulation can lead to incorrect default permissions. The identification of this vulnerabil…
A vulnerability marked as very critical has been reported in Samsung Devices. This impacts an unknown function. Performing a manipulation results in improper input validation. This vulnerability was named CVE-2026-21073…
A vulnerability labeled as problematic has been found in Samsung Devices 2026. This affects an unknown function of the file libsavsvc.so of the component VC1 codec. Such manipulation leads to improper input validation. …
A vulnerability identified as very critical has been detected in Samsung Devices. The impacted element is an unknown function of the file libsavsvc.so of the component MPEG4 codec. This manipulation causes improper inpu…
A vulnerability categorized as problematic has been discovered in Samsung Devices. The affected element is an unknown function of the component Samsung Message. The manipulation results in improper input validation. Thi…
A vulnerability was found in Samsung Devices. It has been rated as problematic. Impacted is an unknown function of the file libsavsvc.so of the component VC1 codec. The manipulation leads to incorrect conversion between…
A newly observed malware campaign is using simple Windows scripts to open the door to remote control and data theft. The chain relies on Visual Basic Script, or VBS, and PowerShell, two tools present on business compute…
A vulnerability was found in Samsung Devices. It has been declared as problematic. This issue affects some unknown processing of the file libril_sem.so. Executing a manipulation can lead to stack-based buffer overflow. …
A vulnerability was found in Samsung Devices. It has been classified as very critical. This vulnerability affects unknown code of the file libsmsd.so. Performing a manipulation results in improper input validation. This…
A vulnerability was found in Samsung Devices and classified as very critical. This affects an unknown part of the file libcodec2_sec_flacdec.so of the component Flac Decoder. Such manipulation leads to improper input va…
A vulnerability has been found in Samsung Devices and classified as very critical. Affected by this issue is some unknown functionality of the file libcodec2secqcelpdec.so. This manipulation causes improper input valida…
A vulnerability, which was classified as critical, was found in Samsung Devices. Affected by this vulnerability is an unknown functionality. The manipulation results in improper access controls. This vulnerability is ca…
A vulnerability, which was classified as problematic, has been found in Samsung Smart Switch 3.7.64.10/3.7.66.6/3.7.67.2/3.7.68.6/3.7.69.15. Affected is an unknown function. The manipulation leads to cleartext storage o…
A vulnerability classified as problematic was found in Samsung Smart Switch. This impacts an unknown function of the component Trouble Scanning Mode. Executing a manipulation can lead to insufficient verification of dat…
A vulnerability classified as problematic has been found in Samsung My Galaxy up to 6.2. This affects an unknown function. Performing a manipulation results in improper authorization in handler for custom url scheme. Th…
A vulnerability described as problematic has been identified in Samsung SamsungPassAutofill. The impacted element is an unknown function. Such manipulation leads to improper export of android application components. Thi…
A vulnerability marked as problematic has been reported in Samsung Smart Switch 3.7.64.10/3.7.66.6/3.7.67.2/3.7.68.6/3.7.69.15. The affected element is an unknown function. This manipulation causes missing encryption of…
RovoBlast is a one-click prompt-injection vulnerability in Atlassian Rovo that could allow attackers to exfiltrate sensitive enterprise data from Jira, Confluence, SharePoint, and other connected services. Atlassian add…
Ein lokaler Angreifer kann eine Schwachstelle in Sophos Endpoint für macOS ausnutzen, um seine Privilegien zu erhöhen, und um beliebigen Programmcode mit Administratorrechten auszuführen.
A vulnerability labeled as problematic has been found in Samsung Devices. Impacted is an unknown function of the component SemClipboardService. The manipulation results in improper authorization in handler for custom ur…
A vulnerability identified as problematic has been detected in Samsung Devices. This issue affects some unknown processing. The manipulation leads to improper input validation. This vulnerability is uniquely identified …