Zum Inhalt springen

IT-Sicherheit · Aktuell

IT Security News

Aktuelle Meldungen zu IT-Sicherheit, Cyberbedrohungen und Datenschutz — automatisch kuratiert aus führenden Quellen.

Heise Security10. Sept. 2026

OpenAI-Agenten haben auf mehr als 10 weiteren Websites unerlaubt kommuniziert

Sicherheitsforscher haben Spuren ausgebrochener KI-Agenten von OpenAI auf zusätzlichen Webseiten entdeckt. Zumeist haben sie sich auf Wiki-Seiten ausgetauscht.

Weiterlesen
BleepingComputer09. Sept. 2026

Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks

Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. [...]

Weiterlesen
BleepingComputer09. Sept. 2026

AdaptHealth confirms 4.1 million people exposed in July cyberattack

Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. [...]

Weiterlesen
Microsoft Security09. Sept. 2026

Threat matrix: Mapping threats across cloud web applications

Microsoft introduces the Cloud Web Applications Threat Matrix, a MITRE ATT&CK-aligned framework that helps defenders understand, prioritize, and mitigate threats to cloud-hosted web apps and serverless platforms. Th

Weiterlesen
BleepingComputer09. Sept. 2026

Skullcandy Dime 3 earbuds expose users to Bluetooth hijacking

The Carnegie Mellon University CERT Coordination Center (CERT/CC) is warning that Skullcandy Dime 3 wireless earbuds accept Bluetooth pairing requests from nearby unpaired devices without requiring user interaction. [...

Weiterlesen
The Hacker News09. Sept. 2026

U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto

The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run th

Weiterlesen
SANS ISC09. Sept. 2026

Scans for Proxmox Servers, (Wed, Sep 9th)

About a week ago, Proxmox published an advisory revealing a vulnerability in older versions of Proxmox VE, its flagship Virtual Environment product. The vulnerability only affects version 7, which has not been supported

Weiterlesen
Microsoft Security09. Sept. 2026

Passkey-themed social engineering leads to identity and cloud compromise

Passkey-themed social engineering is being used to compromise identities and enable broader cloud attacks. Learn how threat actors establish MFA persistence, abuse Microsoft Graph for reconnaissance, and access SharePoin

Weiterlesen
BleepingComputer09. Sept. 2026

US says Chinese firms extracted billions of tokens from frontier AI models

U.S. cybersecurity and intelligence agencies say that six Chinese AI companies conducted industrial-scale distillation attacks on American frontier AI models since at least late 2024. [...]

Weiterlesen
Golem Security09. Sept. 2026

Anzeige: Microsoft 365 DSGVO-konform betreiben und absichern

Datenresidenz, Drittlandtransfer und Audit-Pflichten stellen Unternehmen bei Microsoft 365 vor Herausforderungen. Ein Onlineworkshop zeigt die DSGVO-konforme Konfiguration. (<a href="https://www.golem.de/specials/golemak

Weiterlesen
The Hacker News09. Sept. 2026

Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week

Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome.

Weiterlesen
BleepingComputer09. Sept. 2026

Veradigm warns of patient data breach after ransomware gang claims attack

Healthcare technology company Veradigm disclosed a data breach after a cybersecurity incident at one of its third-party vendors exposed patients' personal data. [...]

Weiterlesen
Golem Security09. Sept. 2026

KI-Sicherheit: Anthropic-Forscher sieht über 10 Prozent Auslöschungsrisiko

Der Anthropic-Forscher Jacob Coxon zieht sich aus der KI-Branche zurück. Er befürchtet, dass sich selbst verbessernde KI-Systeme künftig menschliche Befehle verweigern könnten. (<a href="https://www.golem.de/specials/ki/

Weiterlesen
BSI Sicherheitsmitteilungen09. Sept. 2026

Version 1.0: SAP - Kritische Schwachstellen bedrohen verschiedene Anwendungen

Weiterlesen
The Hacker News09. Sept. 2026

Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA

Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create "stolen keys" that grant illicit access to tools from model providers like Google, Anthropic, and others.&nbs

Weiterlesen
BleepingComputer09. Sept. 2026

MFA's Weakest Link: Account Recovery Is the New Attack Path

MFA makes account takeover harder, but attackers are increasingly targeting the recovery processes used to reset passwords and authentication methods. Specops explains why stronger identity verification at the service de

Weiterlesen
Heise Security09. Sept. 2026

Anstieg von Verbrauch an KI-Tokens – was einige Claude-Nutzer berichten

Einige Claude-User schauen derzeit geschockt auf ihren Token-Verbrauch. Obwohl sie die KI-Tools teilweise tagelang nicht nutzen, steigt der Verbrauch weiter.

Weiterlesen
Heise Security09. Sept. 2026

Sicherheits-Updates: Samsung verteilt Patches für Galaxy-Smartphones

Samsung hat sein Security-Bulletin für September 2026 veröffentlicht. Der Hersteller verteilt 90 Sicherheitspatches für zahlreiche Galaxy-Geräte.

Weiterlesen
The Hacker News09. Sept. 2026

Webinar: Learn How to Answer “Are We Exposed?” Faster After a New CVE

A major vulnerability is disclosed. The alert lands immediately. Then comes the harder question: Are we actually exposed? For many security teams, answering that means jumping between vulnerability scanners, endpoint too

Weiterlesen
The Hacker News09. Sept. 2026

DeepSeek Harness Flaw Let AI Agents Disable Their Own File Sandbox Without Approval

A flaw in DeepSeek Harness, DeepSeek's open-source tool for running AI coding agents on a developer's machine, let a sandboxed agent turn off its own sandbox with a single command. The tool runs an agent's commands insid

Weiterlesen
Heise Security09. Sept. 2026

KI absichern und belegen: OWASP veröffentlicht neue Hilfe

Das OWASP GenAI Security Project veröffentlicht den „Crosswalk“, der KI-Risiken mit Compliance-Anforderungen aus 25 Regelwerken verknüpft.

Weiterlesen
Golem Security09. Sept. 2026

Ohne Nutzerinteraktion: Angreifer können Android-Geräte aus der Ferne kapern

Die neuesten Android-Updates schließen 200 Sicherheitslücken. Einige davon sind besonders gefährlich und ermöglichen etwa Schadcode-Attacken. (<a href="https://www.golem.de/specials/sicherheitsluecke/">Sicherheitslücke</

Weiterlesen
Heise Security09. Sept. 2026

Patchday: Kritische Lücken ermöglichen Attacken auf Android 14, 15, 16 und 17

Der September-Patchday für Android schließt über 90 Sicherheitslücken, darunter mehr als 25 kritische Schwachstellen in Framework, System und Kernel.

Weiterlesen
Heise Security09. Sept. 2026

Kommentar: Auf Lücke gespielt - was in Berlin den Rhysida-Angriff begünstigte

Berlin hat bei der IT-Sicherheit geschlampt. Den Angreifern hat über Jahrzehnte gewachsene und nur halbherzig modernisierte IT in die Karten gespielt.

Weiterlesen
The Hacker News09. Sept. 2026

Alby Hub Critical Flaw Could Let Attackers Take Over Internet-Exposed Bitcoin Wallets

Bitcoin wallet company Alby has&nbsp;warned of a critical flaw&nbsp;in Alby Hub that could have let an attacker take over a wallet and send its funds, but only where the owner had made the Hub reachable from the internet

Weiterlesen
Heise Security09. Sept. 2026

September-Patchday: Adobe schließt kritische Zero-Day-Lücke und 172 weitere

Im Zentrum der Adobe-Patch-Welle steht das Update für Adobe Commerce, das bereits akut angegriffen wird. Besonders viele Updates betreffen Experience Manager.

Weiterlesen
BleepingComputer09. Sept. 2026

Over 36,000 exposed Plex servers vulnerable to recent flaws

Over 36,000 Plex Media servers exposed online remain unpatched against multiple security vulnerabilities and are vulnerable to attacks. [...]

Weiterlesen
Heise Security09. Sept. 2026

Chrome 153: Google wechselt zu Zweiwochen-Update-Zyklus

Google stellt Chrome auf einen Zweiwochen-Rhythmus um. Version 153 behebt 230 Sicherheitslücken, darunter eine aktiv ausgenutzte.

Weiterlesen
The Hacker News09. Sept. 2026

U.S. Agencies Accuse China AI Firms of Distilling Claude, GPT, Gemini, and Grok

U.S. cybersecurity and intelligence agencies have accused China-based artificial intelligence (AI) companies of conducting "systematic extraction" of proprietary functionalities and capabilities of American frontier mode

Weiterlesen
The Hacker News09. Sept. 2026

Chrome V8 Zero-Day Exploited in the Wild Enables Code Execution Inside Sandbox

Google on Tuesday released updates to patch 230 security vulnerabilities, including one that has come under active exploitation in the wild. The medium-severity vulnerability, assigned the CVE identifier CVE-2026-87491 (

Weiterlesen
BleepingComputer09. Sept. 2026

Man gets 15 years for extorting women with AI-generated porn videos

An Ohio man was sentenced to 15 years in prison for multiple cybercrimes, including sextortion and cyberstalking of numerous victims using AI-generated sexually explicit content. [...]

Weiterlesen
The Hacker News09. Sept. 2026

New cPanel Flaw Lets a Hosting Account With Mail Privileges Run Code as Root

cPanel has patched a flaw that it says lets a single hosting account take control of an entire server. An authenticated account holder with mail-related privileges can create files of their choosing on the server through

Weiterlesen
Heise Security09. Sept. 2026

Microsoft schließt Rekordzahl an Sicherheitslücken

Microsoft schließt fast 1000 Sicherheitslücken am Patchday. Zwei davon werden bereits aktiv ausgenutzt und haben höchste Priorität.

Weiterlesen
Golem Security09. Sept. 2026

Ein falscher Klick genügt: Google warnt vor Schadcode-Attacken auf Chrome-Nutzer

Die jüngsten Chrome-Updates schließen 230 Sicherheitslücken. Mindestens eine wird schon aktiv ausgenutzt. Anwender sollten zügig patchen. (<a href="https://www.golem.de/specials/sicherheitsluecke/">Sicherheitslücke</a>,

Weiterlesen
The Hacker News09. Sept. 2026

F5 BIG-IP APM Malware Injects a PHP Web Shell Into Memory, Evading Disk Scans

Malware linked to break-ins at F5 BIG-IP Access Policy Manager appliances hides a PHP web shell in memory instead of in a file on disk, Sophos said in an&nbsp;analysis published on September 7. When Apache loads any of t

Weiterlesen
BleepingComputer09. Sept. 2026

New Microsoft Defender 'ShieldCrash' zero-day grants SYSTEM access

An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named "ShieldCrash" right after Microsoft rolled out its September 2026 Patch Tuesday security updates. [

Weiterlesen
Golem Security09. Sept. 2026

Patchday-Rekord: Fast 1.000 Sicherheitslücken in Windows, Office und Co.

Noch nie zuvor hat Microsoft innerhalb eines Monats so viele Sicherheitslücken gepatcht. Anwender sollten zügig updaten, denn Attacken laufen bereits. (<a href="https://www.golem.de/specials/patchday/">Patchday</a>, <a h

Weiterlesen
The Hacker News09. Sept. 2026

Researcher Drops New Microsoft Defender PoC Showing ShieldBreak Patch Can Be Bypassed

The security researcher known as Chaotic Eclipse has dropped a proof-of-concept (PoC) for yet another zero-day in Microsoft Defender. The vulnerability, codenamed ShieldCrash, is assessed to be a patch bypass for CVE-202

Weiterlesen
BleepingComputer09. Sept. 2026

Google warns of new Chrome zero-day bug exploited in attacks

Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. [...]

Weiterlesen
The Hacker News09. Sept. 2026

SAP Patches CVSS 10.0 Kernel Flaw Enabling Unauthenticated Remote Code Execution

SAP has released security updates to address multiple vulnerabilities, including a maximum-severity flaw in SAP Extended Passport (EPP) Processing that could have a severe impact on the confidentiality, integrity, and av

Weiterlesen

Wird alle 30 Minuten aktualisiert · CH/DE: BACS Schweiz, BSI, Allianz Cyber-Sicherheit, Heise Security, Golem · EN: BleepingComputer, The Hacker News, Fortinet, SANS ISC, Microsoft Security, Krebs on Security, Kaspersky