Zum Inhalt springen

IT-Sicherheit · Aktuell

IT Security News

Aktuelle Meldungen zu IT-Sicherheit, Cyberbedrohungen und Datenschutz — automatisch kuratiert aus führenden Quellen.

SANS ISC11. Aug. 2026

ISC Stormcast For Tuesday, August 11th, 2026 https://isc.sans.edu/podcastdetail/10046, (Tue, Aug 11th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Weiterlesen
BleepingComputer10. Aug. 2026

Hackers breached a small Polish energy plant via private APN last year

Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network. [...]

Weiterlesen
BleepingComputer10. Aug. 2026

BdThemes plugins supply-chain hack creates rogue WordPress admins

A threat actor compromised the upstream infrastructure of BdThemes, a developer of premium WordPress web-design tools, and modified a remote JSON feed delivered to administrators' browsers to create rogue admin accounts.

Weiterlesen
BleepingComputer10. Aug. 2026

OpenAI releases ChatGPT 5.6 Cyber, but it's only for approved users

OpenAI has developed a new model called "GPT 5.6 Cyber," designed for vulnerability research, penetration testing, incident response, and remediation. [...]

Weiterlesen
BleepingComputer10. Aug. 2026

New StormEncryptor ransomware used by former Medusa affiliate

A financially motivated threat actor previously associated with the Medusa ransomware operation is now deploying a new ransomware strain called StormEncryptor. [...]

Weiterlesen
The Hacker News10. Aug. 2026

Shipping 10–50× More Code? Watch This Webinar on Securing AI-Speed Development

AI is helping development teams produce far more code, far faster. But security teams still have to review vulnerabilities, manage dependencies, prioritize fixes, and control risk at human speed. When software output jum

Weiterlesen
Heise Security10. Aug. 2026

Lahmer x86-Befehl hebelt triviale Schutzfunktion aus

Der mächtige System Management Mode (SMM) von x86-Prozessoren ist ein bevorzugtes Ziel von Angriffen. Ein Trick hebelt eine SMM-Schutzfunktion aus.

Weiterlesen
The Hacker News10. Aug. 2026

China-Linked Hackers Deploy New StormEncryptor Ransomware, Likely via N-central Flaw

Microsoft has disclosed that Storm-1175, a financially motivated threat actor linked to China, has deployed a previously undocumented ransomware strain called StormEncryptor. The use of StormEncryptor marks a shift from

Weiterlesen
SANS ISC10. Aug. 2026

Scans for Solana (Surfpool?) Endpoints, (Mon, Aug 10th)

Solana is a crypto platform known for speed. Developers like it to develop distributed applications or to implement crypto payments. To interact with the blockchain, APIs are provided for developers. These APIs will eith

Weiterlesen
Heise Security10. Aug. 2026

Dobrindt baut Drohnenabwehr nach Vorfall in Leipzig massiv aus

Nach dem versuchten Drohnenanschlag auf dem Leipziger Flughafen wächst der politische Druck. Innenminister Dobrindt reagiert mit mehr Abwehreinheiten.

Weiterlesen
Microsoft Security10. Aug. 2026

Microsoft named a Leader in the 2026 IDC MarketScape for MDR/MXDR for the Enterprise

Microsoft is named a Leader in the 2026 IDC MarketScape for MDR services. Discover how Microsoft Defender Experts MDR combines AI, threat intelligence, and human expertise. The post Microsoft named a Leader in the 2026 I

Weiterlesen
Golem Security10. Aug. 2026

Anzeige: Microsoft 365 mit Zero Trust absichern

Microsoft 365 Zero Trust verlangt klare Kontrollen für Identitäten, Daten und Geräte. Ein Online-Workshop zeigt, wie Schutzmechanismen und Monitoring strukturiert umgesetzt werden. (<a href="https://www.golem.de/specials

Weiterlesen
Allianz Cyber-Sicherheit10. Aug. 2026

BSI-Workshop: Erstellung geeigneter Vorgabendokumente f&#252;r Interconnection-Point-Funktionen in 5G-Mobilfunknetzen

Der BSI-Workshop "Erstellung geeigneter Vorgabendokumente f&#252;r Interconnection-Point-Funktionen in 5G-Mobilfunknetzen" richtet sich haupts&#228;chlich an Firmen aus dem Bereich Router und findet vor Ort in Berlin sta

Weiterlesen
The Hacker News10. Aug. 2026

⚡ Weekly Recap: AI Goes Rogue, Metabase 0-Day, MCP Supply-Chain Attacks, and Router Backdoors

A lot of security problems still begin with someone doing a completely normal thing. Cloning a repo. Answering a call. Leaving a box exposed. Trusting the default. That pretty much covers the mood this week. Old bugs are

Weiterlesen
Microsoft Security10. Aug. 2026

DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure

Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data le

Weiterlesen
BleepingComputer10. Aug. 2026

CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs

CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. [...]

Weiterlesen
BleepingComputer10. Aug. 2026

When Credentials Are No Longer Enough: Device Trust in the AI Era

AI is making phishing, credential theft, and social engineering faster and more efficient, while traditional trust signals such as passwords, MFA, IP reputation, and geolocation become easier to bypass. Specops explains

Weiterlesen
The Hacker News10. Aug. 2026

Kimsuky Builds Offline AI Stack to Boost Phishing and Automate Malware Development

North Korea's state hackers are no longer content to type prompts into public chatbots. One of the country's main espionage groups has begun running artificial intelligence (AI) offline on its own servers, connecting doc

Weiterlesen
BleepingComputer10. Aug. 2026

Member of The Com sent to prison for blackmail, sextortion

A member of "The Com," a loose-knit online cybercrime collective that targets children and teenagers, has been sentenced to two years in prison for blackmail and sextortion offenses against nearly 120 victims worldwide.

Weiterlesen
The Hacker News10. Aug. 2026

New Passkey Attacks Can Recover Synced Private Keys or Bypass Phishing-Resistant MFA

Three separate research efforts last week demonstrated ways to defeat passkey protections without breaking the cryptography they rest on. Passkeys are designed to replace reusable passwords and resist phishing. The attac

Weiterlesen
BleepingComputer10. Aug. 2026

LexisNexis shuts down services after suspicious activity on servers

LexisNexis took its Diligence, Metabase API, and Newsdesk services offline as part of its response to unusual activity on servers hosted and managed by an unnamed third-party vendor. [...]

Weiterlesen
BleepingComputer10. Aug. 2026

Valve notifies Steam hardware customers of a data breach

Video game publisher and digital distribution giant Valve is notifying Steam hardware customers in Europe that hackers stole their data after hacking its shipping partner, CEVA Logistics. [...]

Weiterlesen
The Hacker News10. Aug. 2026

TrueConf Server Flaws Exploited to Replace Client Installers with PhantomCore

The threat actor known as Head Mare has been observed weaponizing security flaws in unpatched TrueConf servers once again in attacks targeting Russian companies spanning instrumentation, electronics, transport, energy, I

Weiterlesen
Golem Security10. Aug. 2026

Curl-Entwickler sucht Verstärkung: "Niemand hier will mit Windows arbeiten"

Der Open-Source-Entwickler Daniel Stenberg sucht Helfer für das Curl-Security-Team. Die derzeitigen sieben Mitglieder haben alle eine Windows-Aversion. (<a href="https://www.golem.de/specials/open-source/">Open Source</a

Weiterlesen
Heise Security10. Aug. 2026

Schadcode-Attacken auf Progress LoadMaster im Gange

Derzeit haben Angreifer Progress LoadMaster auf dem Schirm und attackieren aktiv Systeme. Sicherheitspatches sind verfügbar.

Weiterlesen
Heise Security10. Aug. 2026

Angriff auf Apples Private Cloud Compute: 150.000 Dollar für Sicherheitsforscher

Im Rahmen des PCC-Bug-Bounty-Programms, das seit 2024 Sicherheitsexperten offensteht, kam es zu einem erfolgreichen Angriff. Telemetrie-Daten konnten abfließen.

Weiterlesen
Kaspersky SecureList10. Aug. 2026

IT threat evolution in Q2 2026. Non-mobile statistics

The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.

Weiterlesen
Kaspersky SecureList10. Aug. 2026

IT threat evolution in Q2 2026. Mobile statistics

This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.

Weiterlesen
BleepingComputer10. Aug. 2026

Critical Progress LoadMaster flaw now actively exploited in attacks

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warned that hackers are exploiting a critical-severity Progress Kemp LoadMaster command injection vulnerability. [...]

Weiterlesen
Golem Security10. Aug. 2026

Pwnie Award: Microsoft gewinnt Schampreis für angedrohte Strafverfolgung

Microsoft hat durch seinen Streit mit Chaotic Eclipse einen Pwnie Award gewonnen. Annehmen wollte ihn wohl keiner - aus Angst vor Jobverlust. (<a href="https://www.golem.de/specials/sicherheitsluecke/">Sicherheitslücke</

Weiterlesen
Heise Security10. Aug. 2026

Jetzt patchen! Admin-Attacken auf Metabase beobachtet

Angreifer nutzen zurzeit eine kritische Sicherheitslücke in der Business-Intelligence-Plattform Metabase aus. Admins müssen jetzt handeln.

Weiterlesen
The Hacker News10. Aug. 2026

Solidity Pro VS Code Extensions Steal Crypto Wallets, API Keys, and Credentials

Cybersecurity researchers have flagged a malicious Microsoft Visual Studio Code (VS Code) extension named Solidity Pro ("solidity-pro") that has been observed delivering a browser wallet and credential stealer. The names

Weiterlesen
Golem Security10. Aug. 2026

Nach KI-Hacks: Chinesisches KI-Modell trickst Forscher bei Cybertests aus

Das KI-Modell Kimi K3 hat bei Cybertests eine gesicherte Umgebung verlassen und sich die gesuchten Lösungen einfach bei Github beschafft. (<a href="https://www.golem.de/specials/ki/">KI</a>, <a href="https://www.golem.de

Weiterlesen
The Hacker News10. Aug. 2026

OpenAI's Next AI Model Astra Shows Cyber Performance Strong Enough to Trigger Pause

OpenAI has announced that it's pausing some "internal activities" involving its upcoming artificial intelligence (AI) model Astra after an internal evaluation found it had made significant advancements in agentic coding

Weiterlesen
Allianz Cyber-Sicherheit10. Aug. 2026

Partnerangebot: NIS2 kompakt, Cyber-Sicherheit als F&#252;hrungsaufgabe - nGENn GmbH in Kooperation mit IHK Hessen innovativ

NIS2 macht IT-Sicherheit endg&#252;ltig zur Chefsache und das mit pers&#246;nlicher Haftung f&#252;r die Gesch&#228;ftsf&#252;hrung. Im kostenfreien Webinar kl&#228;ren wir in einer Stunde die zwei Fragen, die uns am h&#

Weiterlesen
Allianz Cyber-Sicherheit10. Aug. 2026

Partnerangebot: UNIVADO &#8211; &#8220;Security & AI Awareness Paket&#8221;

Im Partnerbeitrag der UNIVADO geht es um das UNIVADO Security & AI Awareness Paket &#8211; eine moderne Komplettl&#246;sung f&#252;r Datenschutz, Cybersecurity und KI-Kompetenz. Unternehmen k&#246;nnen sich 10 kostenlose

Weiterlesen
SANS ISC10. Aug. 2026

ISC Stormcast For Monday, August 10th, 2026 https://isc.sans.edu/podcastdetail/10044, (Mon, Aug 10th)

(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.

Weiterlesen
Golem Security09. Aug. 2026

Berliner Staatsanwaltschaft: 350 Anklagen gegen Encrochat- und Sky-ECC-Nutzer

Die Berliner Staatsanwaltschaft zieht Zwischenbilanz zu Kryptohandys. Der Angriff auf die Systeme durch die Staatsapparate sind weiter umstritten. (<a href="https://www.golem.de/specials/man-in-the-middle/">Man-in-the-Mi

Weiterlesen
BleepingComputer08. Aug. 2026

Hackers breach TrueConf to trojanize client installers with backdoors

The Head Mare hacktivist group has been exploiting vulnerabilities in unpatched TrueConf video conferencing servers to replace client installers with malicious versions that deliver backdoors. [...]

Weiterlesen
Golem Security08. Aug. 2026

Astra: OpenAI will neues KI-Modell vorerst nicht veröffentlichen

Wie gefährlich darf eine KI werden, bevor sie zur Waffe wird? OpenAI kann diese Frage bei seinem Modell Astra derzeit nicht mehr sicher beantworten. (<a href="https://www.golem.de/specials/openai/">OpenAI</a>, <a href="h

Weiterlesen

Wird alle 30 Minuten aktualisiert · CH/DE: BACS Schweiz, BSI, Allianz Cyber-Sicherheit, Heise Security, Golem · EN: BleepingComputer, The Hacker News, Fortinet, SANS ISC, Microsoft Security, Krebs on Security, Kaspersky