heise alerts
Adobe-Patchday: Schadcodeschmuggel in Reader, Illustrator und weiteren möglich
Im März veröffentlicht Adobe Sicherheitsupdates für acht Programme, die teils kritische Sicherheitslücken schließen.
- Kritische Sicherheitslücken: Angreifer können Schadcode einschmuggeln oder ihre Rechte ausweiten.
- Adobe Commerce und Magento: 19 Sicherheitslücken, darunter mehrere kritische Cross-Site-Scripting-Schwachstellen.
- Adobe Illustrator: Fünf von sieben Schwachstellen ermöglichen das Einschleusen und Ausführen von beliebigem Code.
- Acrobat Produkte: Drei Sicherheitslücken, davon zwei mit kritischem Risiko für Codeschmuggel.
- Substance 3D Stager: Sechs kritische Lücken, die Schadcode einschleusen können, sollten sofort gepatcht werden.
- Adobe Experience Manager: 33 Cross-Site-Scripting-Sicherheitslecks, mit einem CVSS-Wert von 5.4, eingestuft als „wichtig“.
Microsoft Patchday: Zwei Zero-Days und insgesamt 83 neue Lücken gestopft
Im März 2026 veröffentlicht Microsoft Updates für 83 Schwachstellen, darunter zwei Zero-Day-Schwachstellen, die bislang nicht angegriffen wurden.
- Zero-Day-Schwachstellen: Zwei Schwachstellen sind neu und bislang nicht ausgenutzt worden.
- Kritisch eingestufte Lücken: Acht Schwachstellen werden als kritisch eingestuft, darunter CVE-2026-21536 (CVSS 9.8) und CVE-2026-26125 (CVSS 8.6).
- Öffentlich verfügbare Schwachstellen: CVE-2026-21262 und CVE-2026-26127 sind bekannt, aber noch nicht angegriffen.
- Sandbox-Umgehung in Excel: Eine Zero-Click-Lücke ermöglicht unbefugte Datenweitergabe (CVE-2026-26144, CVSS 7.5).
- Update für Chromium-Projekt: Zehn Schwachstellen werden mit aktuellen Edge-Updates geschlossen.
- Wichtigkeit von Updates: IT-Verantwortliche sollten gefährdete Produkte identifizieren und aktualisieren.
SAP-Patchday: NetWeaver-Lücke ermöglicht Einschleusen von Schadcode
SAP hat 15 Schwachstellen in seinen Produkten bekannt gegeben, darunter zwei als kritisch eingestuft, und empfiehlt ein zügiges Anwenden der bereitgestellten Updates.
- Kritische Schwachstellen: Zwei Schwachstellen ermöglichen das Einschleusen von Schadcode und werden als "kritisch" eingestuft (CVE-2019-17571, CVE-2026-27685).
- Hochriskante Schwachstelle: Eine Sicherheitslücke in der Supply Chain Management kann für Denial-of-Service-Angriffe genutzt werden (CVE-2026-27689).
- Mittel- und niedrig riskante Schwachstellen: Weitere Schwachstellen betreffen verschiedene SAP Produkte, mit niedrigeren Risikostufen.
Nextcloud: Codeschmuggel durch Lücke in Flow möglich
heise security
Adobe-Patchday: Schadcodeschmuggel in Reader, Illustrator und weiteren möglich
Im März veröffentlicht Adobe Sicherheitsupdates für acht Programme, die teils kritische Sicherheitslücken schließen.
- Kritische Sicherheitslücken: Angreifer können Schadcode einschmuggeln oder ihre Rechte ausweiten.
- Adobe Commerce und Magento: 19 Sicherheitslücken, darunter mehrere kritische Cross-Site-Scripting-Schwachstellen.
- Adobe Illustrator: Fünf von sieben Schwachstellen ermöglichen das Einschleusen und Ausführen von beliebigem Code.
- Acrobat Produkte: Drei Sicherheitslücken, davon zwei mit kritischem Risiko für Codeschmuggel.
- Substance 3D Stager: Sechs kritische Lücken, die Schadcode einschleusen können, sollten sofort gepatcht werden.
- Adobe Experience Manager: 33 Cross-Site-Scripting-Sicherheitslecks, mit einem CVSS-Wert von 5.4, eingestuft als „wichtig“.
Microsoft Patchday: Zwei Zero-Days und insgesamt 83 neue Lücken gestopft
Im März 2026 veröffentlicht Microsoft Updates für 83 Schwachstellen, darunter zwei Zero-Day-Schwachstellen, die bislang nicht angegriffen wurden.
- Zero-Day-Schwachstellen: Zwei Schwachstellen sind neu und bislang nicht ausgenutzt worden.
- Kritisch eingestufte Lücken: Acht Schwachstellen werden als kritisch eingestuft, darunter CVE-2026-21536 (CVSS 9.8) und CVE-2026-26125 (CVSS 8.6).
- Öffentlich verfügbare Schwachstellen: CVE-2026-21262 und CVE-2026-26127 sind bekannt, aber noch nicht angegriffen.
- Sandbox-Umgehung in Excel: Eine Zero-Click-Lücke ermöglicht unbefugte Datenweitergabe (CVE-2026-26144, CVSS 7.5).
- Update für Chromium-Projekt: Zehn Schwachstellen werden mit aktuellen Edge-Updates geschlossen.
- Wichtigkeit von Updates: IT-Verantwortliche sollten gefährdete Produkte identifizieren und aktualisieren.
watchguard blog
Demystifying the Alphabet Soup That Is Detection and Response
Tradeshow acronyms overwhelm meetings, derailing decisions. In Detection & Response all systems share one goal: quickly detect threats and respond effectively.
How to Scale as an MSP by Combining Firewalls and Integrated Security Services
Find out why combining firewalls with integrated services is key to scaling your MSP security offering without adding complexity.
The Machine War: Why MSPs Must Move from AI-Assistance to Autonomy
Find out how AI is executing autonomous attacks and why defenses need to respond at the same pace to stay protected.
Boost Security Strategy: Join WatchGuard Webinar on Automation vs. Augmentation
Join this webinar to learn how automation and human expertise combine to strengthen cybersecurity, boost efficiency, and scale protection.
WatchGuard Wins CRN 5-Star Award for the 10th Year, Celebrating 30 Years
WatchGuard Technologies wins CRN 5-Star Award for the 10th year in the 2026 Partner Program Guide, celebrating 30 years of empowering MSP partners.
Microsoft Defender vs. MDR: What’s Missing?
Microsoft Defender detects threats, but without 24/7 response gaps remain. Learn why MSPs add WatchGuard MDR to turn alerts into fast action.
watchguard pressreleases
WatchGuard Marks 30 Years of Setting the MSP Security Standard
Cybersecurity leader has helped MSPs reduce complexity, scale protection, and profitably grow through every market shift
Over 1500% Increase in New, Unique Malware Highlights Growing Security Complexity, according to WatchGuard Biannual Threat Report
MSPs must shift from reactive security to proactive threat intelligence and unified protection
WatchGuard Open MDR Gives MSPs a Faster Path to Enterprise-Grade, High-Margin Managed Security Services Across Existing Customer Environments
Open MDR delivers unified visibility and rapid response across WatchGuard and third-party environments, removing the constraints of single-vendor security models and accelerating MSP time to market
WatchGuard Delivers a Simple Path to Modern Zero Trust Security
A decade of zero trust complexity finally simplified through a unified approach built for MSPs and organizations of every size
Strong, Quiet, Predictable. WatchGuard Delivers Total Protection Without Operational Burden in MITRE ER7 Evaluation.
WatchGuard delivers full coverage with almost no noise in MITRE ATT&CK ER7 testing, giving MSPs stronger protection, faster response, and lower operational burden.
Zero Trust Emerges as Top Growth Opportunity at WatchGuard Partner Roadshow
High partner turnout and strong session engagement signal accelerating demand for advanced security strategies across global MSP market
csoonline
Tarnung als Taktik: Warum Ransomware-Angriffe raffinierter werden
NIS-2: Tausende reißen BSI-Frist und riskieren Strafen
Europa im Visier von Cyber-Identitätsdieben
Europol schließt riesigen Markt für gestohlene Daten
Europol: Großer Markt für gestohlene Daten geschlossen
Studie: Hacker legen Betrieb bei vielen Unternehmen lahm
secplicity
AI-Powered Cyber Attacks Are Rising: What Security Teams Need to Know
The cybersecurity landscape is shifting quickly. In Episode 361 of The443 Podcast, Marc Laliberte and Corey Nachreiner discuss three emerging issues shaping modern security: A critical authentication bypass in a popular JSON Web Token (JWT) library An autonomous AI bot exploiting GitHub repositories…
Cisco SD-WAN 0-Day: What MSPs Should Do Now
Three stories, one theme: control planes, supply chains, and human workflows remain high-leverage targets. This Secplicity blog follows the sequence and details covered by Marc Laliberte and Corey Nachreiner in The443 Podcast Episode 360. 1) Cisco Catalyst SD-WAN 0-Day (CVSS 10): What happened Cisco…
Why CMMC Is Important in 2026: Simplified
Let’s be honest: cybersecurity rules are not exactly thrilling. But if your company supports the U.S. Department of Defense (DoD), CMMC (Cybersecurity Maturity Model Certification) is becoming increasingly difficult to ignore. At its core, CMMC exists for one simple reason: to help ensure sensitive…
Ongoing Widespread Credential Harvesting Campaign Targets VPN Providers
Introduction At the turn of the year, we were alerted to a doppelganger domain impersonating WatchGuard’s Mobile VPN with SSL, delivering a malicious spoofed client to steal credentials. Navigating directly to the doppelganger domain resulted in a benign informational WatchGuard VPN page. However…
New Kyber Ransomware Posts U.S. Defense Contractor As First Victim
A new ransomware operation known as Kyber has emerged. Their first and current only posted victim is L3Harris, a major defense contractor in the United States. The operators have provided a timer that ends around 6 PM EST on Sunday, October 19. The group claims to have stolen over 300 GB of data…
dAn0n Hacker Group Reemerges as White Lock Ransomware
The first samples of the new(ish) White Lock ransomware began emerging towards the end of September. The earliest compilation time stamp of the four samples currently on MalwareBazaar, Triage, and VirusTotal is September 29, 2025. It has all the hallmarks of traditional crypto-ransomware: kills anti…
thehackernews
U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) on Tuesday removed three individuals linked to the Intellexa Consortium, the holding company behind a commercial spyware known as Predator , from the specially designated nationals list. The names of the individuals are as follows - Merom Harpaz Andrea Nicola Constantino Hermes Gambazzi Sara Aleksandra Fayssal Hamou Hamou was sanctioned by OFAC in March 2024, and Harpaz and Gambazzi were targeted in September 2024 in connection with developing, operating, and distributing Predator. It's currently not known why they were removed from the list. Harpaz is said to be working as a manager of Intellexa S.A., while Gambazzi was identified as the owner of Thalestris Limited and Intellexa Limited. Thalestris, Treasury Department said, held the distribution rights to the spyware, and processed transactions on behalf of other entities within the Intellexa Consortium. It's also the parent company...
IBM Warns of Critical API Connect Bug Allowing Remote Authentication Bypass
IBM has disclosed details of a critical security flaw in API Connect that could allow attackers to gain remote access to the application. The vulnerability, tracked as CVE-2025-13915 , is rated 9.8 out of a maximum of 10.0 on the CVSS scoring system. It has been described as an authentication bypass flaw. "IBM API Connect could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application," the tech giant said in a bulletin. The shortcoming affects the following versions of IBM API Connect - 10.0.8.0 through 10.0.8.5 10.0.11.0 Customers are advised to follow the steps outlined below - Download the fix from Fix Central Extract the files: Readme.md and ibm-apiconnect-<version>-ifix.13195.tar.gz Apply the fix based on the appropriate API Connect version "Customers unable to install the interim fix should disable self-service sign-up on their Developer Portal if enabled, which will help minimise their exp...
Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry
Cybersecurity researchers have disclosed details of what appears to be a new strain of Shai Hulud on the npm registry with slight modifications from the previous wave observed last month. The npm package that embeds the novel Shai Hulud strain is " @vietmoney/react-big-calendar ," which was uploaded to npm back in March 2021 by a user named "hoquocdat." It was updated for the first time on December 28, 2025, to version 0.26.2. The package has been downloaded 698 times since its initial publication. The latest version has been downloaded 197 times. Aikido, which spotted the package, said it has not spotted any major spread or infections following the release of the package. "This suggests we may have caught the attackers testing their payload," security researcher Charlie Eriksen said . "The differences in the code suggests that this was obfuscated again from the original source, not modified in place. This makes it highly unlikely to be a copy-ca...
Trust Wallet Chrome Extension Hack Drains $8.5M via Shai-Hulud Supply Chain Attack
Trust Wallet on Tuesday revealed that the second iteration of the Shai-Hulud (aka Sha1-Hulud) supply chain outbreak in November 2025 was likely responsible for the hack of its Google Chrome extension, ultimately resulting in the theft of approximately $8.5 million in assets. "Our Developer GitHub secrets were exposed in the attack, which gave the attacker access to our browser extension source code and the Chrome Web Store (CWS) API key," the company said in a post-mortem published Tuesday. "The attacker obtained full CWS API access via the leaked key, allowing builds to be uploaded directly without Trust Wallet's standard release process, which requires internal approval/manual review." Subsequently, the attacker is said to have registered the domain "metrics-trustwallet[.]com" and pushed a trojanized version of the extension with a backdoor that's capable of harvesting users' wallet mnemonic phrases to the sub-domain "api.metrics-...
DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide
The threat actor behind two malicious browser extension campaigns, ShadyPanda and GhostPoster , has been attributed to a third attack campaign codenamed DarkSpectre that has impacted 2.2 million users of Google Chrome, Microsoft Edge, and Mozilla Firefox. The activity is assessed to be the work of a Chinese threat actor that Koi Security is tracking under the moniker DarkSpectre . In all, the campaigns have collectively affected over 8.8 million users spanning a period of more than seven years. ShadyPanda was first unmasked by the cybersecurity company earlier this month as targeting all three browser users to facilitate data theft, search query hijacking, and affiliate fraud. It has been found to affect 5.6 million users, including 1.3 newly identified victims stemming from over 100 extensions flagged as connected to the same cluster. This also includes an Edge add-on named "New Tab - Customized Dashboard" that features a logic bomb that waits for three days prior to t...
CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution
The Cyber Security Agency of Singapore (CSA) has issued a bulletin warning of a maximum-severity security flaw in SmarterTools SmarterMail email software that could be exploited to achieve remote code execution. The vulnerability, tracked as CVE-2025-52691 , carries a CVSS score of 10.0. It relates to a case of arbitrary file upload that could enable code execution without requiring any authentication. "Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution," CSA said. Vulnerabilities of this kind allow the upload of dangerous file types that are automatically processed within an application's environment. This could pave the way for code execution if the uploaded file is interpreted and executed as code, as is the case with PHP files. In a hypothetical attack scenario, a bad actor could weaponize this vulnerability to place malici...
borncity
Patchday: Windows Server-Updates (10. März 2026)
Zum 10. März 2026 (zweiter Dienstag im Monat, Patchday bei Microsoft) wurden verschiedene kumulative Updates für die unterstützten Versionen von Windows Server freigegeben. Nachfolgend habe ich die bereitgestellten Updates samt einigen Details für diese Windows Server-Versionen (von Windows Server 2012 bis 2025) herausgezogen.
Patchday: Windows 10/11 Updates (10. März 2026)
Am 10. März 2026 (zweiter Dienstag im Monat, Patchday bei Microsoft) hat Microsoft kumulative Updates für die noch unterstützten Client-Betriebssystem-Versionen von Windows 10 (mit ESU-Lizenz) und Windows 11 veröffentlicht. Hier einige Details zu diesen Updates, die Schwachstellen sowie Probleme beheben sollen.
Meta kauft Moltbook
Kleine Meldung am Rande: Facebook Mutter Meta hat wohl Moltbook gekauft. Das ist quasi das "reddit für Chatbots", was aus einer Laune heraus im Umfeld des OpenClaw-Projekts (als dies noch Motbot hieß, siehe Clawdbot – Moltbot – Openclaw: Heißer AI-Scheiß und Sicherheitsdesaster) entstanden ist.
Mozilla verlängert den Firefox 115-Support für Windows 7/8.1 bis August 2026
Die Entwickler von Mozilla haben Nutzern von Windows 7 SP1 und Windows 8.1 erneut so etwas wie eine Gnadenfrist für den Firefox-Browser spendiert. Eigentlich wäre im März 2026 der Support für den Firefox 115 abgelaufen. Jetzt wurde der Supportzeitraum vorerst auf August 2026 verlängert.
Digitalisierungsirrsinn in Schulklassen Anno 2026
Heute noch ein Informationssplitter, der mir die Tage untergekommen ist, und den Irrsinn der Digitalisierung aufzeigt. Es geht um die Digitalisierung in Schulen – wo andere Länder längst den Rückzug antreten, treibt das deutsche Schulwesen seine Digitalisierungsblüten.
HP EliteBook 660 G11: Weshalb wurde das BIOS v. 1.08.01 zurückgezogen?
Ein Blog-Leser hat mich vorige Woche mit der Frage kontaktiert, ob das BIOS in der Version 1.08.01 für das HP EliteBook 660 G11 zurückgezogen wurde. Das Revoke der BIOS-Version ist von Dritten bestätigt. Es gibt aber keine Informationen, was passiert sein könnte (nur Mutmaßungen, dass es mit Samsung Speicher zu BlueScreens gekommen sei).