Missbrauch von Passkeys: Phishing-Toolkit soll Passwort-Reset umgehen können
Ein ab 10.000 US-Dollar gehandeltes Phishing-Toolkit soll Angreifern über Passkeys einen dauerhaften Zugriff etwa auf gekaperte Google-Konten verleihen. (<a href="https://www.golem.de/specials/phishing/">Phishing</a>, <a
CISA orders urgent patching of actively exploited Zimbra flaw
The Cybersecurity and Infrastructure Security Agency (CISA) has ordered U.S. government agencies to patch an actively exploited vulnerability in Zimbra Collaboration Suite (ZCS) within three days. [...]
Zahlreiche Sicherheitslücken bedrohen VMware-Tanzu-Spring-Software
Angreifer können Systeme mit unter anderem VMware Tanzu Spring AI, Integration oder Security attackieren. Sicherheitspatches sind verfügbar.
Microsoft shares temporary fix for Windows 11 gaming issues
Microsoft has shared a temporary fix for ongoing gaming issues caused by Windows 11 updates released during the August 2026 Patch Tuesday. [...]
Nach Hackerangriff: Berliner Senat überrascht über Größe des IT-Systems
Nach einem Hackerangriff sind zwei Berliner Verwaltungen wieder am Netz. Es gibt jedoch weiter Verdachtsmomente für eine Infiltration. (<a href="https://www.golem.de/specials/security/">Security</a>, <a href="https://www
Partnerangebot: Blackfort Technology – “NIS2 Security Operations Pilot"
Im Partnerbeitrag der Blackfort Technology erhalten Teilnehmende die Möglichkeit, eine Sicherheitslösung für Schwachstellenmanagement sowie die zentrale Erfassung, Aufbewahrung und Auswertung von sicherhei
„GTA 6“-ISO: Vermeintliche Leak-Abbilddatei voller Malware
Bösartige Akteure bieten das vermeintlich geleakte ISO von „GTA 6“ im Netz an. Die 113 GByte enthalten aufgepumpte Virendaten.
„Computer History“: OpenAI bringt Windows-Recall-ähnliche Funktion auf Macs
Business-, Enterprise- und Pro-Nutzer können ihre gesamte Rechnerarbeit unter macOS künftig von ChatGPT mitschreiben lassen. Die Memory-Files liegen offen.
Cyberangriff: Staatssekretär fordert mehr Abwehrmaßnahmen
Monatlich werden in Berlin 1,2 Millionen Cyberangriffe abgewehrt. Der jüngste Angriff auf Senatsverwaltungen löst nun Sorgen aus.
UAT-10147 Uses AI to Scale Server Attacks, Deploys SPECTRE With EDR Bypass and Linux Rootkit
Cybersecurity researchers have disclosed details of a Chinese-speaking cybercrime group dubbed UAT-10147 that's targeting Windows and Linux web servers globally across the education, media, technology, and gaming sectors
DOUBLECUP's PNG Payload, (Mon, Aug 24th)
New malware that uses steganography always gets my attention, but I was disappointed when I looked at the latest DOUBLECUP write-up . It doesn&#;x26;#;39;t use real steganography: 
Partnerangebot: ANMATHO AG – Online-Seminar „Security Awareness – Sicherheit leben“
Im Partnerbeitrag der ANMATHO AG geht es um das Online-Seminar „Security Awareness – Sicherheit leben“, welches die gängigsten Einfallstore von Angriffen auf die Informationssicherheit über de
Cyberangriff trifft Energieversorgung: Hacker legen britisches Kraftwerk lahm
Hacker haben im Vereinigten Königreich erfolgreich ein Kraftwerk für vier Tage stillgelegt. Verantwortlich sollen iranische Cyberakteure sein. (<a href="https://www.golem.de/specials/cyberwar/">Cyberwar</a>, <a href="htt
Microsoft stopft zahlreiche Cloud-Schwachstellen
Microsoft dokumentiert 18 teils kritische Sicherheitslücken in Cloud-Produkten, die die Entwickler geschlossen haben.
Partnerangebot: Wavestone Germany AG – „CMMC – Aktuelle Anforderungen und Umsetzung für die Verteidigungsindustrie“
CMMC ist endgültig in der Vertragsrealität angekommen: Seit dem 10. November 2025 verankert die finale DFARS-Regel die CMMC-Anforderungen verbindlich in Ausschreibungen und Verträgen des US-Verteidigungsmi
Nach Cyberangriff: Senatsverwaltungen wieder am Netz
Wegen einer Cyberattacke waren zwei Senatsverwaltungen aus Sicherheitsgründen vom Netz genommen worden. Nach mehr als einer Woche sind sie wieder online.
ISC Stormcast For Monday, August 24th, 2026 https://isc.sans.edu/podcastdetail/10064, (Mon, Aug 24th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Britische Regierung bestätigt Cyberattacke auf Kraftwerk
Für vier Tage haben Angreifer in Großbritannien ein Kraftwerk abgeschaltet. Die Behörden warnen und besänftigten zugleich.
ToxicPanda Android malware uses VPN permissions to block Google Play
The ToxicPanda Android malware has evolved with new malicious functionality, expanding its targeting to 349 applications and adding support for 167 remote commands. [...]
Virusalarm: Mysteriöse 113 GByte große ISO von GTA 6 im Internet aufgetaucht
Die angebliche ISO-Datei von GTA 6 soll laut ihrem Namen von Cyberleek persönlich stammen. Allerdings finden mehrere Personen ein Virus. (<a href="https://www.golem.de/specials/gta-6/">GTA 6</a>, <a href="https://www.gol
TikTok Agrees to $400 Million Settlement in U.S. Child Privacy Lawsuit
The U.S. Department of Justice (DoJ) announced on Friday that ByteDance-owned TikTok will pay $400 million to settle a 2024 lawsuit accusing the company of violating child privacy laws in the country. As part of the sett
Hackers infect Android car head units with proxy botnet malware
A supply-chain attack targeting Android-based car head units is using a legitimate device-update app to spread malware that enlists compromised devices in a proxy botnet or uses them for ad fraud. [...]
(g+) Artificial Intelligence: AI hasn't gone rogue. It's worse than that
Recent cyber attacks reflect what the technology was trained to do but safeguards are falling short Von Madhumita Murgia (<a href="https://www.golem.de/specials/llm/">LLM</a>, <a href="https://www.golem.de/specials/ki/">
Named Pipes Under Attack: Securing Windows Interprocess Communication
Windows named pipes provide fast interprocess communication, but weak access controls can expose privileged services to untrusted processes. ThreatLocker explains how endpoint verification, command authorization, strict
14 Trojanized npm Packages Drop RedC2 4.0 Linux Backdoor With AI-Assisted C2
Cybersecurity researchers have discovered a set of trojanized npm packages that masquerade as working calendar and streak utilities but are engineered to stealthily deliver an artificial intelligence (AI)-powered Linux i
New SynkLoader malware pushed in Microsoft Teams phishing campaign
A previously unknown malware family dubbed SynkLoader is being distributed in Microsoft Teams phishing campaigns to steal credentials via a fake lock screen. [...]
Anzeige: Microsoft Purview: Sensitivity Labels, DLP und Insider Risk
Sensitive Daten in Microsoft 365 zu schützen, ist für viele Unternehmen eine zentrale Aufgabe. Ein Workshop zu Microsoft Purview vermittelt praxisnahe Lösungsansätze. (<a href="https://www.golem.de/specials/golemakademie
Hundreds of leaked AWS keys give full control over corporate accounts
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. [...]
Microsoft Defender's Own Driver Can Be Weaponized to Delete Security Software at Boot
Check Point Research has disclosed a technique that uses Microsoft Defender's own legitimately signed boot-time remediation driver to perform arbitrary kernel-level file and registry operations on Windows systems ranging
Android Car Malware Spreads Through Built-In Updaters for Ad Fraud, Proxy Botnet
Cybersecurity researchers have flagged a new malware family that's specifically designed to infect Android-based vehicle head unit firmware developed by DoFun. Kaspersky, which discovered the threat in June 2026, said th
Microsoft blames Windows gaming issues on RGB lighting devices
Microsoft says ongoing issues causing games to crash or fail to launch after installing the August 2026 Windows updates may be caused by peripherals with RGB lighting. [...]
Is Online Privacy Possible? How Digital Identities Can Help
Using the same email, phone number, payment method, and other identifiers makes it easier for data brokers and attackers to profile your activity. Anonyome Labs explains how separate digital personas can reduce correlati
Microsoft rolls out Classic Outlook theme for New Outlook users
Microsoft has started rolling out a Classic Outlook theme for users of Outlook on the web and the New Outlook for Windows. [...]
CISA orders feds to patch actively exploited TrueConf Server flaws
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) ordered U.S. federal agencies to prioritize patching two actively exploited vulnerabilities in the TrueConf Server self-hosted communications platform. [..
Wazuh and AI For Enhanced SOC Workflows
Artificial Intelligence (AI) has become one of this decade's defining technologies. From healthcare and finance to manufacturing and education, organizations increasingly rely on AI to automate repetitive tasks, uncover
Microsoft patches max severity code execution, privilege escalation flaws
Microsoft has patched multiple maximum-severity vulnerabilities in Entra ID, Azure Arc, and Exchange Online that allowed attackers to gain remote code execution and escalate privileges. [...]
Beinahe militärische Telefonate abgehört: Deutsche Hackerin kaperte ENUM-Domains
Einige Inselnationen hatten geschlampt und ihre Telefonie angreifbar gemacht. Die Sicherheitsbehörden reagierten erst spät und nach einem Raketenangriff.
Hackers abuse FTP server banners to deliver new Windows malware
Threat actors are abusing FTP banners to hide commands that deliver two previously undocumented remote access trojans named E4del and PINHOLE. [...]
N-able Passportal: Zahlreiche Unternehmen durch kritisches Passwort-Leck gefährdet
Ein Forscher hat bei N-able Passportal eine kritische Lücke entdeckt. Angreifer hätten damit leicht Zugangsdaten aus Passwort-Tresoren abgreifen können. (<a href="https://www.golem.de/specials/sicherheitsluecke/">Sicherh
Lücke in WordPress-Plug-in Elementor Pro: 6 Millionen Webseiten gefährdet
Eine kritische Sicherheitslücke im WordPress-Plug-in Elementor Pro ermöglicht die komplette Übernahme von WordPress.
Wird alle 30 Minuten aktualisiert · CH/DE: BACS Schweiz, BSI, Allianz Cyber-Sicherheit, Heise Security, Golem · EN: BleepingComputer, The Hacker News, Fortinet, SANS ISC, Microsoft Security, Krebs on Security, Kaspersky