IT-Sicherheit · Aktuell
IT Security News
Aktuelle Meldungen zu IT-Sicherheit, Cyberbedrohungen und Datenschutz — automatisch kuratiert aus führenden Quellen.
Denmark Says Attackers Accessed CPR Data for 8.8 Million People via Company Account
Unauthorized parties have gained access to the names, addresses, and personal identification numbers of about 8.8 million people, living and dead, in Denmark's national population register, the country's digitalization m
ClickFix Smuggles Payloads Through Browser Cache to Bypass Windows Run Limits
A new type of ClickFix attack is using compromised websites to trick users into executing a malicious payload cached in a web browser's cache. "Instead of downloading and executing remote payloads like the typical attack
Anzeige: Microsoft Purview: Daten schützen und Risiken steuern
Microsoft Purview bündelt Funktionen für Datenklassifizierung, DLP und Insider Risk. Die Golem Karrierewelt vermittelt den praktischen Einsatz in Microsoft 365. (<a href="https://www.golem.de/specials/golemakademie/">Gol
OpenAI is adding invisible watermarks to ChatGPT and Codex text in the EU
OpenAI is preparing to add invisible watermarks to text generated by ChatGPT and Codex in the European Union. [...]
Rejetto HFS servers now actively scanned for critical RCE flaw
Hackers are actively scanning for a Rejetto HFS weak signing key vulnerability, tracked as CVE-2026-61500, that allows session forgery, account takeover, and remote code execution (RCE). [...]
IQVIA fined $7.8 million for failing to properly anonymize health data
Italy's Data Protection Authority (GPDP) has fined IQVIA €7 million ($7.8M) over poor data-processing practices that the agency says could have put roughly one million patients at risk of data exposure and de-anonymizati
Anzeige: T.I.S.P. - Informationssicherheit systematisch vertiefen
Der T.I.S.P. Zertifikatskurs bündelt zentrale Themen der Informationssicherheit. Die Vorbereitung umfasst Technik, Sicherheitsmanagement und rechtliche Grundlagen. (<a href="https://www.golem.de/specials/golemakademie/">
Microsoft Exchange Flaw Lets Authenticated Attackers Read Other Users' Mailboxes
Microsoft has released out-of-band security updates to address a high-severity flaw in Microsoft Exchange Server that could allow an attacker to escalate privileges under certain conditions. The vulnerability, tracked as
Denmark population registry data breach affects 8.8 million people
Denmark's Central Population Register (CPR) is warning of a data breach that exposed the personal information of approximately 8.8 million registered individuals. [...]
New Dell System Update flaw lets hackers gain root privileges
Dell warned customers to patch a critical vulnerability in the System Update (DSU) command-line interface (CLI) deployment tool as soon as possible. [...]
Fast neun Millionen Betroffene: Dänisches Melderegister gehackt
Die Angreifer missbrauchen den legalen Zugang eines Privatunternehmens. Die zuständige Ministerin spricht von einem schwerwiegenden Vorfall. (<a href="https://www.golem.de/specials/security/">Security</a>, <a href="https
South Korea probes bank breaches amid suspected AI-powered attacks
South Korea's Financial Services Commission (FSC) held an emergency meeting following a series of cyberattacks targeting financial institutions in the country. [...]
⚡ Weekly Recap: NetScaler and FortiMail 0-Days, AI Coding Leaks, Spectre v2 and Ransomware Arrests
A blank field. A public repo. One reply to an email. A box left exposed. None of this sounds dramatic, which is partly the problem. This week’s threats keep finding leverage in small things that were easy to overlook. Th
tenfold CE: Our free Identity Governance tool just got 2 new features
tenfold has added shared content governance and real-time event auditing to its free Community Edition for organizations with under 150 users. The new features help teams manage Microsoft 365 sharing and investigate susp
Alleged dev of Ploutus ATM malware appears in US court after arrest
The U.S. Department of Justice has announced the arrest of the alleged developer of Ploutus malware, used to steal millions of dollars in ATM jackpotting attacks across the United States. [...]
ClingSTUN Linux Backdoor Abuses Public STUN Infrastructure
FortiGuard Labs examines how ClingSTUN exploits vulnerable devices and abuses public STUN servers to support a Linux proxy backdoor.          
The Credential Layer Is Expanding Faster Than Security Teams Can See It
Every modern enterprise depends on credentials. This is how humans, systems, and now AI, all connect to data, services, and each other securely. GitGuardian helps secure that credential layer through three connected capa
Realtek Jungle SDK Exploit Attempts Deliver Cling Botnet With STUN-Based C2
Threat actors have been observed attempting to exploit a now-patched critical security flaw impacting the Realtek Jungle software development kit (SDK) to deploy a botnet malware called Cling. "Cling is notable not becau
Apple Plans Tighter macOS Full Disk Access Controls Over AI Agent Data Access
Apple has announced that it's taking steps to tighten controls around a macOS setting called Full Disk Access (FDA) due to security risks posed by artificial intelligence (AI) agents. "Some developers are using Full Disk
OpenAI will show visual ads in ChatGPT while you generate images
OpenAI is expanding ads in ChatGPT, and one of the first new formats will show visual ads while you're generating images. [...]
Microsoft-Authenticator-Backup ab Januar nicht mehr mit Microsoft-Konto
Microsofts Authenticator kann ein Backup in der Cloud ablegen. Ab Januar geht das unter Android nicht mehr mit persönlichen Microsoft-Konten.
Cyberangriff: Antriebssystem eines Öl-Supertankers gehackt
Unbefugte kontrollieren das digitale System des Schiffs. Es ist nicht der erste Vorfall dieser Art. (<a href="https://www.golem.de/specials/hacker/">Hacker</a>, <a href="https://www.golem.de/specials/security/">Security<
Partnerangebot: isits AG – Seminar „Krisenkommunikationsbeauftrage bzw. Kommunikationsbeauftragter bei Cyberangriffen (TÜV)“
Im Partnerbeitrag der isits AG geht es darum, die strukturierte und souveräne Krisenkommunikation bei Cyberangriffen zu erlernen. Das Seminar kann bei Interesse mit einer Personenzertifizierung abgeschlossen werden
Microsoft: Windows KB5124010 update crashes some games and apps
Microsoft confirmed over the weekend that some games and applications using AC-3 (Dolby Digital) audio decoding will crash after installing the September 2026 KB5124010 Windows 11 preview update. [...]
ChatGPT-App für macOS: Angreifer konnten sensible Daten einsehen – wie bei Muse
Nach Meta hatte auch OpenAI ein Sicherheitsproblem in seiner macOS-App. Erneut wurde es vom Security-Experten Patrick Wardle entdeckt.
Google halts open-source bug bounty program amid AI spam surge
Google has now suspended submissions to its Open Source Software Vulnerability Rewards Program (OSS VRP) after being flooded by AI-generated reports. [...]
Attackers Target Rejetto HFS Flaw That Enables Admin Session Forgery and RCE
A critical security flaw impacting Rejetto HTTP File Server (HFS) is witnessing active exploitation attempts, according to VulnCheck. The vulnerability in question is CVE-2026-61500 (CVSS score: 9.3), a case of session f
Partnerangebot: CCVOSSEL GmbH – „Escape the Cyber Crisis“
Montag 08:12 Uhr. Die Systeme sind verschlüsselt, die Produktion steht. Wie gehst du vor? Im Partnerangebot der CCVOSSEL GmbH erleben die Teilnehmenden die ersten 24 Stunden eines Ransomware-Angriffs auf ein mittels
KI-Agenten: Metas Muse legt Profile über Freunde und Familie an
Metas KI-Assistent Muse führt Seiten über Familie, Partner und Freunde. Forscher haben die Anweisungen dafür ausgelesen. (<a href="https://www.golem.de/specials/ki/">KI</a>, <a href="https://www.golem.de/specials/datensc
CISA warnt vor Angriffen auf Zammad und Citrix NetScaler
Bösartige Akteure attackieren aktuell nicht nur Sicherheitslücken in Citrix NetScaler, sondern auch in Zammad. Davor warnt die CISA.
New NetScaler Zero-Day Exploited in Targeted Attacks Can Knock SAML Deployments Offline
Citrix has released security updates for a high-severity security flaw in NetScaler ADC and NetScaler Gateway that has been exploited as part of targeted zero-day attacks. The vulnerability, tracked as CVE-2026-88779, ca
Microsoft schiebt Exchange-Update nach
Zum Wochenende hat Microsoft weitere Exchange-Updates nachgelegt. Sie stopfen eine Rechteausweitungslücke.
Bericht: Bei Cyberangriff Zugriff auf Antrieb von Öl-Supertanker erlangt
Ende August haben FBI und US-Küstenwache einen Öltanker geentert, der stundenlang nicht kommunizieren konnte. Nun gibt es Erkenntnisse über den Cyberangriff.
ISC Stormcast For Monday, October 5th, 2026 https://isc.sans.edu/podcastdetail/10122, (Mon, Oct 5th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
TTY Logs and the Data it Captures, (Sun, Oct 4th)
For an experiment, I created a script [ 1 ] that parses and send the TTY logs collected from actors or bots activity that run various commands after they successfully login the DShield sensor. Those TTY logs ar
Citrix patches NetScaler SAML zero-day exploited in attacks
Citrix has released emergency updates for a new NetScaler denial-of-service vulnerability tracked as CVE-2026-88779 that has been exploited in zero-day attacks, with researchers investigating whether it can also be explo
David Robinson: Warum OpenAIs Sicherheitschef nun geht
Ein Ex-Mitarbeiter warnt: Bei OpenAI komme Sicherheit im Tempo neuer KI-Produkte oft zu kurz. (<a href="https://www.golem.de/specials/openai/">OpenAI</a>, <a href="https://www.golem.de/specials/ki/">KI</a>) <img src="htt
Bericht: FBI-Angreifer von „ShinyHunters“ gefasst und kooperativ
Einem Bericht zufolge wurde ein weiteres Mitglied der Cyberbande „ShinyHunters“ in Jordanien festgesetzt. Er soll mit dem FBI kooperieren.
Citrix Netscaler aktualisieren! Zero-Day verursacht Crashes und Codeausführung
Sicherheitsforscher und Administratoren melden massenhafte Spontanreboots betroffener Geräte. Updates sind nun verfügbar und sollten schnell aufgespielt werden.
Anthropic asks Claude users to share voice data for AI model training
Anthropic has started asking Claude users to voluntarily share their voice conversations to help train and improve its AI models. [...]
Wird alle 30 Minuten aktualisiert · CH/DE: BACS Schweiz, BSI, Allianz Cyber-Sicherheit, Heise Security, Golem · EN: BleepingComputer, The Hacker News, Fortinet, SANS ISC, Microsoft Security, Krebs on Security, Kaspersky