IT-Sicherheit · Aktuell
IT Security News
Aktuelle Meldungen zu IT-Sicherheit, Cyberbedrohungen und Datenschutz — automatisch kuratiert aus führenden Quellen.
FakeGit malware campaign returns with 17,610 malicious GitHub repos
More than 17,000 fake repositories on GitHub are distributing the SmartLoader malware after the FakeGit campaign reactivated earlier this month to push the StealC infostealer. [...]
Reconstructing AI Agent Activity: Two New Scripts for Forensic Review, (Thu, Oct 8th)
We just did a major update to FOR577 and added a lot of new material on day 5 about investigating AI usage in incident response. In the new material we dicsuss 8&#;x26;#;xc2;&#;x26&#x
Anzeige: LPIC-1: Linux-Wissen für die Zertifizierung vertiefen
LPIC-1 verlangt Kenntnisse in mehreren Bereichen der Linux-Administration. Ein Online-Workshop vertieft vorhandenes Wissen für die beiden Prüfungen. (<a href="https://www.golem.de/specials/golemakademie/">Golem Karrierew
Gefahr für autonome Autos: Wie eine Folie Kameras und Lidar täuscht
Forscher aus München fühlen Kamera- und Lidar-Systemen auf den Zahn, um autonome Fahrzeuge besser vor gezielten Manipulationen zu schützen.
Japan Sees Sharp Rise in Web Data Leaks Amid Mobile API Abuse and Metabase Attacks
Attackers behind a string of personal data leaks at Japanese organizations have abused APIs for mobile apps and targeted known software flaws, the JPCERT Coordination Center (JPCERT/CC) said. The Tokyo-based center, whic
UAC-0099 Targets Ukrainian Government Personnel With ASHVEIN RAT Hiding Commands in HTML
The Russia-aligned threat actor known as UAC-0099 has been attributed to a previously undocumented .NET infostealer and remote access trojan (RAT) codenamed ASHVEIN. According to TrendAI, the malware has been put to use
Cisco warns of critical flaws allowing Nexus switch takeover
Cisco released security advisories for five critical vulnerabilities in its NX-OS data center network operating system that could be exploited to run arbitrary code with root privileges on Nexus switches. [...]
ARTEX AI Pentesting Tool Used in Data Theft Attacks on South Korean Financial Firms
Cybersecurity researchers have disclosed details of a targeted campaign aimed at South Korean financial organizations that used an artificial intelligence (AI) pen testing tool named ARTEX to carry out the attacks. The a
OAuth grants pile up faster than you can review them. Here's how to keep up.
OAuth grants create data highways between SaaS apps, AI agents, and other tools. And, they are multiplying faster than any security team can review them. As the recent Klue breach showed, attackers are taking notice and
Gefährliche E-Mail-Anhänge: Outlook blockiert MSIX-Dateien
Beide Dateiformate erlauben die Installation von Anwendungen. Die Änderung gilt für Outlook im Web und das neue Outlook für Windows. (<a href="https://www.golem.de/specials/outlook/">Outlook</a>, <a href="https://www.gol
Uranium crypto exchange hacker convicted for stealing $53 million
A Maryland man was found guilty of stealing more than $53 million after hacking the decentralized crypto exchange Uranium Finance twice in April 2021. [...]
Microsoft Teams to get support for third-party deepfake detection tools
Microsoft will soon introduce support for third-party deepfake detection solutions and impersonation protection in Teams meetings. [...]
Veeam stopft Schadcode-Lücke in Backup & Replication
Veeam hat Backup & Replication aktualisiert und dabei vier Sicherheitslücken geschlossen. Schmuggeln von Schadcode auf den Server ist möglich.
ASOS links data breach to social engineering attack, credential theft
ASOS is sending updates to affected customers about the cybersecurity incident it suffered earlier this week, confirming that hackers accessed some personal data. [...]
Angeklagter zahlte heimlich Lösegeld: Ransomware-Entschlüsselungsdienst vor Gericht
Von Ransomware-Angriffen betroffenen Firmen versprach der Angeklagte, über fortschrittliche Entschlüsselungstechniken zu verfügen. (<a href="https://www.golem.de/specials/cybercrime/">Cybercrime</a>, <a href="https://www
Wazza Phishkit Targets Banking, Government, and Manufacturing Across the US, EU, and Australia
Phishing kits are no longer limited to copying a familiar login page and waiting for a victim to enter credentials. Attackers are increasingly building filtering, session management, and traffic controls into the infrast
Owner of Empire cybercrime market gets 40 years in prison
The co-creator of Empire Market, one of the largest dark web marketplaces before its shutdown, has been sentenced to 40 years in prison for facilitating $430 million in illegal transactions from 2018 to 2020. [...]
Dekompilierung per KI: Warum Closed Source laut Raymond am Ende ist
Open-Source-Mitbegründer Eric S. Raymond erklärt Closed-Source-Software per KI-gestütztem Reverse Engineering für faktisch am Ende.
16 Malicious Firefox Extensions Pose as Rabby and OKX Wallets to Steal Recovery Phrases
Cybersecurity researchers have discovered a cluster of 16 malicious Mozilla Firefox extensions that are capable of stealing cryptocurrency wallet recovery phrases and private keys. "The extensions masquerade as wallet po
SonicWall SMA1000: Lücke mit Höchstwertung öffnet interne Funktionen
SMA1000-Appliances von SonicWall sollen vor dem unbefugten Zugriff aufs Netz schützen. Eine kritische Lücke ermöglicht das aber.
Gekaperte Top-Level-Domains: Hacker erstellen gefälschte TLS-Zertifikate für Google
Unbekannte hacken mehrere Ländercode-Top-Level-Domains. Damit umgehen sie übliche Gültigkeitsprüfungen für die Ausstellung der Zertifikate. (<a href="https://www.golem.de/specials/verschluesselung/">Verschlüsselung</a>,
Chinesische Wechselrichter: Nur ein Hack bis zum Blackout
250.000 Solaranlagen in Deutschland nutzen Wechselrichter mit einer kritischen Sicherheitslücke. Ein Kollaps des Stromnetzes wäre einfach. (<a href="https://www.golem.de/specials/blackout/">Blackout</a>, <a href="https:/
U.S. Offers Up to $10 Million for Tips on Zhang Yu, Charged in HAFNIUM Hacks
The U.S. State Department is offering up to $10 million for information leading to the identification or location of Zhang Yu, a Chinese national charged in the United States in connection with the 2021 Microsoft Exchang
MonsterCloud Owner Accused of Billing Over $19M While Secretly Paying Ransoms to Decrypt Data
The U.S. Department of Justice (DoJ) on Wednesday announced charges against a 50-year-old U.S. and Israeli national for allegedly defrauding ransomware victims by secretly paying the attackers to obtain decryptors while
Angriffe auf Atlassian-Data-Center-Lücke haben begonnen
Kurz nach der Warnung von Atlassian zur kritischen Sicherheitslücke wurden jetzt Angriffe beobachtet. Admins müssen handeln.
Samsung Galaxy S26 hacked three more times at Pwn2Own Ireland
On the second day of Pwn2Own Ireland 2026, security researchers collected $232,500 in cash awards after exploiting 45 unique zero-day vulnerabilities. [...]
Ransomware: Qilin-Hacker nach Deutschland ausgeliefert
Ein mutmaßliches Mitglied der Hackergruppe Qilin ist an Deutschland überstellt worden. Dem Russen wird ein Angriff auf ein deutsches Logistikunternehmen vorgeworfen. (<a href="https://www.golem.de/specials/ransomware/">R
Tensorlake npm Package Compromised to Deliver Shai-Hulud Credential-Stealing Worm
The npm package known as "tensorlake," a TypeScript software development kit (SDK) for Tensorlake applications, sandboxes, and cloud services, was compromised as part of a ChainDrop / Shai-Hulud supply chain attack. The
Anzeige: Microsoft Copilot im Unternehmen gezielt einsetzen
Microsoft 365 Copilot braucht passende Einsatzszenarien im Unternehmen. Ein Online-Workshop vermittelt Anwendungen, Chatbot-Integration und Responsible AI. (<a href="https://www.golem.de/specials/golemakademie/">Golem Ka
ISC Stormcast For Thursday, October 8th, 2026 https://isc.sans.edu/podcastdetail/10128, (Thu, Oct 8th)
(c) SANS Internet Storm Center. https://isc.sans.edu Creative Commons Attribution-Noncommercial 3.0 United States License.
Ransomware recovery CEO charged over secret ransom payments
The owner of ransomware remediation company MonsterCloud has been charged with allegedly defrauding ransomware victims by secretly paying their attackers for decryptors while claiming to use proprietary technology to rec
FBI: Ongoing FortiBleed attacks lock out FortiGate VPN admins
The FBI is warning that FortiBleed attacks are still ongoing, targeting exposed Fortinet FortiGate firewalls and SSL VPN gateways and locking out legitimate administrators. [...]
Hackers hijack Google domains after breaching ccTLD registries
Hackers obtained unauthorized HTTPS certificates for several Google domains and hijacked domains in the country-code top-level domains (ccTLDs) for Ghana, American Samoa, and Sierra Leone after compromising third-party o
Attackers Hijack .gh, .sl, and .as Registries to Obtain Certificates for Google Domains
Attackers compromised three country-code top-level domains (ccTLDs) and obtained unauthorized HTTPS certificates for several Google domains, Google said on October 6. Google's own systems were not breached, but any
Eight Malicious npm Packages Downloaded 40,767 Times Deliver Overlord RAT and Stealer
Cybersecurity researchers have disclosed details of a long-running npm supply chain malware campaign that pushes information stealers and remote access trojans (RAT) to compromised hosts. The campaign has been codenamed
SonicWall Patches CVSS 10.0 Pre-Authentication SSRF Flaw in SMA1000 Appliances
SonicWall has released hotfixes for four flaws in its SMA1000 appliances, the gateways that give remote workers access to a company's network and applications. The most serious could allow an attacker without a login to
3 lessons from frontier AI vulnerability research
Read how How Microsoft Security's FORGE Lab is scaling vulnerability research from Windows to the Linux kernel. The post 3 lessons from frontier AI vulnerability research appeared first on Microsoft Security Blog .
Microsoft Outlook to block MSIX attachments starting November
Microsoft announced that it will add .msix and .msixbundle attachments to the list of blocked attachments in Outlook Web and the new Outlook Windows client starting next month. [...]
Unpatched Critical LMCache Flaw Lets Unauthenticated Attackers Run Code Remotely
A critical vulnerability in LMCache, open-source software that speeds up large language model (LLM) servers such as vLLM, lets an attacker run code on the cache server without logging in, and no fixed version is availabl
PoeLLM Malware Infects 3,400+ Servers to Expand Crypto Mining Botnet
Cybersecurity researchers are calling attention to a new malware family that has been observed targeting exposed artificial intelligence (AI) and large language model (LLM) infrastructure with an aim to deploy cryptocurr
Wird alle 30 Minuten aktualisiert · CH/DE: BACS Schweiz, BSI, Allianz Cyber-Sicherheit, Heise Security, Golem · EN: BleepingComputer, The Hacker News, Fortinet, SANS ISC, Microsoft Security, Krebs on Security, Kaspersky