Veeam stopft Schadcode-Lücke in Backup & Replication
❌ Fehler bei Anfrage an n8n: ConnectTimeout – HTTPSConnectionPool(host='packetstreamapp.space', port=443): Max retries exceeded with url: /webhook/scrape_websites (Caused by ConnectTimeoutError(
Aktuelle Bedrohungen & Systemstatus auf einen Blick
❌ Fehler bei Anfrage an n8n: ConnectTimeout – HTTPSConnectionPool(host='packetstreamapp.space', port=443): Max retries exceeded with url: /webhook/scrape_websites (Caused by ConnectTimeoutError(
❌ Fehler bei Anfrage an n8n: ConnectTimeout – HTTPSConnectionPool(host='packetstreamapp.space', port=443): Max retries exceeded with url: /webhook/scrape_websites (Caused by ConnectTimeoutError(
Meet the 2026 WatchGuard Partner Award Winners and celebrate the MSPs and partners driving growth, innovation, marketing, and success.
Discover how Firebox T175, Prime Security Suite, and AP340 Wi‑Fi 7 deliver stronger security, better performance, and simplified management.
Join WatchGuard’s October webinar series to explore cyber threat trends, unified managed security strategies, and NDR for MSPs.
Discover how WatchGuard is evolving its Unified Security Platform with agentic AI, deeper threat visibility, and secure access for modern cyber risks.
Meet the 2026 WatchGuard Partner Award finalists and celebrate the MSPs and partners driving growth, innovation, marketing, and success.
AI is changing cyberattacks from isolated activities into connected operations that require a new level of speed, context, and understanding.
New innovations help MSPs scale security operations and combat increasingly automated threats
Former Sophos and SonicWall channel leader joins WatchGuard to accelerate a frictionless partner experience and unified go-to-market strategy.
Lower network volume masks broader probing, greater evasion and persistent TLS exposure.
Strong global participation reinforces MSP demand for practical AI innovations that improve security outcomes and operational efficiency
Participation in OpenAI's Daybreak program and Anthropic's Cyber Verification Program advances vulnerability research, security testing, and proactive threat defense.
New Research Highlights Growing Visibility Gap Between Employee Behavior and Organizational Security Controls.
72,000 CVEs are projected to be published in 2026, while the median time from vulnerability disclosure to in-the-wild weaponization has fallen to well under 24 hours. Those two figures capture a growing challenge for defenders: more vulnerabilities to manage and less time to respond. Marc and Corey…
Cyberattacks do not always begin with malware. Sometimes they start with a job application. Sometimes with a trusted account. And increasingly, they may involve an AI agent operating with access that was originally intended for something much more routine. In Episode 389 of The 443: Security…
TL;DR Euler Neto, a member of the WatchGuard Threat Lab, identified an active ClickFix and EtherHiding campaign targeting Windows users in Anglophone countries. WatchGuard telemetry observed activity affecting the United States, Canada, United Kingdom, Ireland, Australia, and New Zealand, with the…
TL;DR Cristóbal Tárraga García, a member of the WatchGuard Threat Lab, uncovered a malware loader targeting Portuguese-speaking users that uses an Ethereum smart contract to dynamically locate attacker infrastructure and distribute additional payloads. The multi-stage infection chain combines…
TL;DR Euler Neto, a member of the WatchGuard Threat Lab identified an active malware campaign using the ErrTraffic Malware-as-a-Service framework to distribute multiple threats through compromised WordPress websites, ClickFix social engineering, and EtherHiding. The campaign uses Polygon blockchain…
Artificial intelligence is no longer just helping cybersecurity teams analyze alerts, write code, or investigate threats. Increasingly capable AI models can now reason through cybersecurity problems, identify vulnerabilities, chain weaknesses together, and autonomously pursue an objective. That…
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) on Tuesday removed three individuals linked to the Intellexa Consortium, the holding company behind a commercial spyware known as Predator , from the specially designated nationals list. The names of the individuals are as follows - Merom Harpaz Andrea Nicola Constantino Hermes Gambazzi Sara Aleksandra Fayssal Hamou Hamou was sanctioned by OFAC in March 2024, and Harpaz and Gambazzi were targeted in September 2024 in connection with developing, operating, and distributing Predator. It's currently not known why they were removed from the list. Harpaz is said to be working as a manager of Intellexa S.A., while Gambazzi was identified as the owner of Thalestris Limited and Intellexa Limited. Thalestris, Treasury Department said, held the distribution rights to the spyware, and processed transactions on behalf of other entities within the Intellexa Consortium. It's also the parent company...
IBM has disclosed details of a critical security flaw in API Connect that could allow attackers to gain remote access to the application. The vulnerability, tracked as CVE-2025-13915 , is rated 9.8 out of a maximum of 10.0 on the CVSS scoring system. It has been described as an authentication bypass flaw. "IBM API Connect could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application," the tech giant said in a bulletin. The shortcoming affects the following versions of IBM API Connect - 10.0.8.0 through 10.0.8.5 10.0.11.0 Customers are advised to follow the steps outlined below - Download the fix from Fix Central Extract the files: Readme.md and ibm-apiconnect-<version>-ifix.13195.tar.gz Apply the fix based on the appropriate API Connect version "Customers unable to install the interim fix should disable self-service sign-up on their Developer Portal if enabled, which will help minimise their exp...
Cybersecurity researchers have disclosed details of what appears to be a new strain of Shai Hulud on the npm registry with slight modifications from the previous wave observed last month. The npm package that embeds the novel Shai Hulud strain is " @vietmoney/react-big-calendar ," which was uploaded to npm back in March 2021 by a user named "hoquocdat." It was updated for the first time on December 28, 2025, to version 0.26.2. The package has been downloaded 698 times since its initial publication. The latest version has been downloaded 197 times. Aikido, which spotted the package, said it has not spotted any major spread or infections following the release of the package. "This suggests we may have caught the attackers testing their payload," security researcher Charlie Eriksen said . "The differences in the code suggests that this was obfuscated again from the original source, not modified in place. This makes it highly unlikely to be a copy-ca...
Trust Wallet on Tuesday revealed that the second iteration of the Shai-Hulud (aka Sha1-Hulud) supply chain outbreak in November 2025 was likely responsible for the hack of its Google Chrome extension, ultimately resulting in the theft of approximately $8.5 million in assets. "Our Developer GitHub secrets were exposed in the attack, which gave the attacker access to our browser extension source code and the Chrome Web Store (CWS) API key," the company said in a post-mortem published Tuesday. "The attacker obtained full CWS API access via the leaked key, allowing builds to be uploaded directly without Trust Wallet's standard release process, which requires internal approval/manual review." Subsequently, the attacker is said to have registered the domain "metrics-trustwallet[.]com" and pushed a trojanized version of the extension with a backdoor that's capable of harvesting users' wallet mnemonic phrases to the sub-domain "api.metrics-...
The threat actor behind two malicious browser extension campaigns, ShadyPanda and GhostPoster , has been attributed to a third attack campaign codenamed DarkSpectre that has impacted 2.2 million users of Google Chrome, Microsoft Edge, and Mozilla Firefox. The activity is assessed to be the work of a Chinese threat actor that Koi Security is tracking under the moniker DarkSpectre . In all, the campaigns have collectively affected over 8.8 million users spanning a period of more than seven years. ShadyPanda was first unmasked by the cybersecurity company earlier this month as targeting all three browser users to facilitate data theft, search query hijacking, and affiliate fraud. It has been found to affect 5.6 million users, including 1.3 newly identified victims stemming from over 100 extensions flagged as connected to the same cluster. This also includes an Edge add-on named "New Tab - Customized Dashboard" that features a logic bomb that waits for three days prior to t...
The Cyber Security Agency of Singapore (CSA) has issued a bulletin warning of a maximum-severity security flaw in SmarterTools SmarterMail email software that could be exploited to achieve remote code execution. The vulnerability, tracked as CVE-2025-52691 , carries a CVSS score of 10.0. It relates to a case of arbitrary file upload that could enable code execution without requiring any authentication. "Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution," CSA said. Vulnerabilities of this kind allow the upload of dangerous file types that are automatically processed within an application's environment. This could pave the way for code execution if the uploaded file is interpreted and executed as code, as is the case with PHP files. In a hypothetical attack scenario, a bad actor could weaponize this vulnerability to place malici...
Ein Blog-Leser hat mich auf ein Problem beim Adobe Acrobat/Reader 26.002.21996 hingewiesen. Unter Windows Server 2016 funktioniert der Adobe Acrobat/Reader nicht, da er nicht mehr startet, sondern mit einem Fehlerdialog abstürzt.
Noch eine kurze Erinnerung für Administratoren von Microsoft Exchange Online-Tenants. Ab dem 10. Oktober 2026 müssen Administratoren bei Exchange Online-Tenants EWSAllowedAppIDs konfigurieren, um den Zugriff von Apps auf Exchange Web Services (EWS) zu ermöglichen. Die bisherige Einstellung "EWSEnabled=True" allein reicht dann nicht mehr aus.
Unschöne Erkenntnis eines Blog-Lesers rund um die mit Microsoft vorinstallierten Intel Netzwerk-Treiber für Windows. Der Leser berichtet, dass diese Treiber Probleme mit IPv6 und Microsoft 365 verursachen. Es "sieht so aus", als gebe es Netzwerkverbindungsabbrüche. Die Intel Connectivity Performance Suite scheint der Verursacher zu sein. Deaktiviert man eine Komponente, sind diese Fehler weg. Das Problem "dümpelt" seit 2021 unter Windows 11, ohne das etwas passierte. Intel hat sogar einen Report zum Problem von November 2025 in seinem Forum geschlossen. Zum 7. Oktober 2026 informierte mich der Leser, dass Intel wohl einen undokumentierten Fix implementiert habe, der das Problem fixt. Ich bereite die Informationen mal auf.
Neue "Wasserstandsmeldung" zu einem Thema, welches für Beobachter längst klar zu sein scheint. Eine neue Umfrage unter VMware by Broadcom-Kunden hat, wenig überraschend, ergeben, dass 90 % bei der Virtualisierung auf andere Anbieter wechseln wollen.
Kurze Frage an die Administratoren, die den Microsoft Defender in Unternehmensumgebungen zur Absicherung verwenden: Gibt es bei euch seit dem 6. Oktober 2026 Probleme mit Sicherheitsupdates und Signaturupdates für den Virenschutz? Ein Blog-Leser hat mich heute per E-Mail kontaktiert und diesbezüglich nachgefragt.
Viele Leute sind es ja schon gewohnt, dass alles, von der Doorbell-Kamera bis zur Toilettenspülung eine Internetverbindung brauchen. Ich hätte ja postuliert, dass die Verblödung arg fortschreitet – aber das wäre nicht nett. Also lasse ich es, und lasst die Realität sprechen. Vor einigen Tagen gab es einen viralen Tweet auf X. Die Eltern eines X-Nutzers hatten sich einen Kaffeeautomaten gekauft, der mit dem Internet verbunden war und binnen 10 Tagen schlappe 1 Terabyte an Daten an den Hersteller übertrug.