heise alerts
heise security
watchguard blog
HTTPS Content Inspection: Give Your Firebox a Better View
Encrypted traffic is good for security and privacy. But for security teams, it can also create a visibility gap.
Compliance Without Compromise: Why More Organizations Are Taking Ownership of Their Security Boundaries
Compliance is evolving beyond checklists. Learn how security enclaves, validated cryptography, and boundary ownership can simplify audits and reduce risk.
Attackers Have Changed Their Playbook. Has Your Security Strategy Changed With Them?
Attackers now rely on stolen identities, encrypted traffic, and stealth tactics. Learn how WatchGuard helps MSPs detect, prevent, and respond.
More Vulnerabilities Are Being Found Than Ever Before. That's Good News.
Why record-breaking disclosure numbers are a sign of a healthier industry and how WatchGuard's Firebreak Ideology fits into that shift.
Cloud Risk Management for MSPs: From Visibility to Control
Seeing risk is not the same as ranking it. Discover how the value of a client's data sets the priority of every cloud finding an MSP works on.
The Cyber Resilience Act: What MSPs Need to Know About the New European Guidance
The new guidance on the Cyber Resilience Act clarifies how to apply its requirements. Find out what it means for tech vendors and what MSPs need to keep on their radar.
watchguard pressreleases
New WatchGuard Threat Report Reveals AI Tooling Underpins Tactical Shift from High-Volume Malware Campaigns to Precision Attacks in 1H 2026
Lower network volume masks broader probing, greater evasion and persistent TLS exposure.
WatchGuard Names Five Winners in $10 Million AI Innovation Challenge
Strong global participation reinforces MSP demand for practical AI innovations that improve security outcomes and operational efficiency
WatchGuard Goes Multi-Model on Frontier AI for Stronger MSP Defense
Participation in OpenAI's Daybreak program and Anthropic's Cyber Verification Program advances vulnerability research, security testing, and proactive threat defense.
Employees Drive Rising Cybersecurity Risk As Shadow AI and Unsafe Work Habits Surge, WatchGuard Global Survey Finds
New Research Highlights Growing Visibility Gap Between Employee Behavior and Organizational Security Controls.
WatchGuard Launches AI Innovation Challenge, Inviting MSPs to Help Shape the Future of AI-Powered Cybersecurity
Part of WatchGuard's $10M AI investment, the challenge will fund selected MSP ideas with up to $100,000 each, and one Grand Prize winner earns an exclusive VIP trip to WatchGuard Impact North America.
WatchGuard Appoints Vincent Hwang as Chief Product Officer to Accelerate Platform Strategy and AI-Driven Innovation
Former Fortinet, Cisco, and Bitdefender leader brings proven track record in scaling cybersecurity platforms, strengthening partner-driven growth, and shaping category-defining product narratives.
csoonline
Schwachstellen managen: Die besten Vulnerability-Management-Tools
Security-Infotainment: Die besten Hacker-Dokus
Der Kaufratgeber für Breach & Attack Simulation Tools
Google entdeckt erstmals KI-basierten Zero-Day-Exploit
Cybersicherheitsvorschriften: So erfüllen Sie Ihre Compliance-Anforderungen
Customer Identity & Access Management: Die besten CIAM-Tools
secplicity
ClickFix + EtherHiding Targets Anglophone Countries with NightshadeC2/CastleRAT
TL;DR Euler Neto, a member of the WatchGuard Threat Lab, identified an active ClickFix and EtherHiding campaign targeting Windows users in Anglophone countries. WatchGuard telemetry observed activity affecting the United States, Canada, United Kingdom, Ireland, Australia, and New Zealand, with the…
Ethereum Malware Loader Targets Portuguese-Speaking Users
TL;DR Cristóbal Tárraga García, a member of the WatchGuard Threat Lab, uncovered a malware loader targeting Portuguese-speaking users that uses an Ethereum smart contract to dynamically locate attacker infrastructure and distribute additional payloads. The multi-stage infection chain combines…
ErrTraffic Malware Campaign: ClickFix and EtherHiding
TL;DR Euler Neto, a member of the WatchGuard Threat Lab identified an active malware campaign using the ErrTraffic Malware-as-a-Service framework to distribute multiple threats through compromised WordPress websites, ClickFix social engineering, and EtherHiding. The campaign uses Polygon blockchain…
When AI Becomes the Attacker: What Autonomous Models Mean for Cybersecurity
Artificial intelligence is no longer just helping cybersecurity teams analyze alerts, write code, or investigate threats. Increasingly capable AI models can now reason through cybersecurity problems, identify vulnerabilities, chain weaknesses together, and autonomously pursue an objective. That…
OpenAI’s Lab Rat Escapes
TL;DR: OpenAI models under evaluation reportedly escaped a restricted lab environment, exploited a zero-day vulnerability to gain internet access, and targeted Hugging Face while attempting to solve a cybersecurity benchmark. The incident highlights the growing risk of autonomous AI-driven attacks…
2026 Cyber Hygiene Report: The Security Tools Are There. The Habits Still Need Work.
Cybersecurity technology continues to improve, but one of the biggest security challenges facing organizations remains surprisingly familiar: human behavior. WatchGuard’s 2026 Cyber Hygiene Report, based on responses from employees at small and midsized businesses across the United States, Europe…
thehackernews
U.S. Treasury Lifts Sanctions on Three Individuals Linked to Intellexa and Predator Spyware
The U.S. Department of the Treasury's Office of Foreign Assets Control (OFAC) on Tuesday removed three individuals linked to the Intellexa Consortium, the holding company behind a commercial spyware known as Predator , from the specially designated nationals list. The names of the individuals are as follows - Merom Harpaz Andrea Nicola Constantino Hermes Gambazzi Sara Aleksandra Fayssal Hamou Hamou was sanctioned by OFAC in March 2024, and Harpaz and Gambazzi were targeted in September 2024 in connection with developing, operating, and distributing Predator. It's currently not known why they were removed from the list. Harpaz is said to be working as a manager of Intellexa S.A., while Gambazzi was identified as the owner of Thalestris Limited and Intellexa Limited. Thalestris, Treasury Department said, held the distribution rights to the spyware, and processed transactions on behalf of other entities within the Intellexa Consortium. It's also the parent company...
IBM Warns of Critical API Connect Bug Allowing Remote Authentication Bypass
IBM has disclosed details of a critical security flaw in API Connect that could allow attackers to gain remote access to the application. The vulnerability, tracked as CVE-2025-13915 , is rated 9.8 out of a maximum of 10.0 on the CVSS scoring system. It has been described as an authentication bypass flaw. "IBM API Connect could allow a remote attacker to bypass authentication mechanisms and gain unauthorized access to the application," the tech giant said in a bulletin. The shortcoming affects the following versions of IBM API Connect - 10.0.8.0 through 10.0.8.5 10.0.11.0 Customers are advised to follow the steps outlined below - Download the fix from Fix Central Extract the files: Readme.md and ibm-apiconnect-<version>-ifix.13195.tar.gz Apply the fix based on the appropriate API Connect version "Customers unable to install the interim fix should disable self-service sign-up on their Developer Portal if enabled, which will help minimise their exp...
Researchers Spot Modified Shai-Hulud Worm Testing Payload on npm Registry
Cybersecurity researchers have disclosed details of what appears to be a new strain of Shai Hulud on the npm registry with slight modifications from the previous wave observed last month. The npm package that embeds the novel Shai Hulud strain is " @vietmoney/react-big-calendar ," which was uploaded to npm back in March 2021 by a user named "hoquocdat." It was updated for the first time on December 28, 2025, to version 0.26.2. The package has been downloaded 698 times since its initial publication. The latest version has been downloaded 197 times. Aikido, which spotted the package, said it has not spotted any major spread or infections following the release of the package. "This suggests we may have caught the attackers testing their payload," security researcher Charlie Eriksen said . "The differences in the code suggests that this was obfuscated again from the original source, not modified in place. This makes it highly unlikely to be a copy-ca...
Trust Wallet Chrome Extension Hack Drains $8.5M via Shai-Hulud Supply Chain Attack
Trust Wallet on Tuesday revealed that the second iteration of the Shai-Hulud (aka Sha1-Hulud) supply chain outbreak in November 2025 was likely responsible for the hack of its Google Chrome extension, ultimately resulting in the theft of approximately $8.5 million in assets. "Our Developer GitHub secrets were exposed in the attack, which gave the attacker access to our browser extension source code and the Chrome Web Store (CWS) API key," the company said in a post-mortem published Tuesday. "The attacker obtained full CWS API access via the leaked key, allowing builds to be uploaded directly without Trust Wallet's standard release process, which requires internal approval/manual review." Subsequently, the attacker is said to have registered the domain "metrics-trustwallet[.]com" and pushed a trojanized version of the extension with a backdoor that's capable of harvesting users' wallet mnemonic phrases to the sub-domain "api.metrics-...
DarkSpectre Browser Extension Campaigns Exposed After Impacting 8.8 Million Users Worldwide
The threat actor behind two malicious browser extension campaigns, ShadyPanda and GhostPoster , has been attributed to a third attack campaign codenamed DarkSpectre that has impacted 2.2 million users of Google Chrome, Microsoft Edge, and Mozilla Firefox. The activity is assessed to be the work of a Chinese threat actor that Koi Security is tracking under the moniker DarkSpectre . In all, the campaigns have collectively affected over 8.8 million users spanning a period of more than seven years. ShadyPanda was first unmasked by the cybersecurity company earlier this month as targeting all three browser users to facilitate data theft, search query hijacking, and affiliate fraud. It has been found to affect 5.6 million users, including 1.3 newly identified victims stemming from over 100 extensions flagged as connected to the same cluster. This also includes an Edge add-on named "New Tab - Customized Dashboard" that features a logic bomb that waits for three days prior to t...
CSA Issues Alert on Critical SmarterMail Bug Allowing Remote Code Execution
The Cyber Security Agency of Singapore (CSA) has issued a bulletin warning of a maximum-severity security flaw in SmarterTools SmarterMail email software that could be exploited to achieve remote code execution. The vulnerability, tracked as CVE-2025-52691 , carries a CVSS score of 10.0. It relates to a case of arbitrary file upload that could enable code execution without requiring any authentication. "Successful exploitation of the vulnerability could allow an unauthenticated attacker to upload arbitrary files to any location on the mail server, potentially enabling remote code execution," CSA said. Vulnerabilities of this kind allow the upload of dangerous file types that are automatically processed within an application's environment. This could pave the way for code execution if the uploaded file is interpreted and executed as code, as is the case with PHP files. In a hypothetical attack scenario, a bad actor could weaponize this vulnerability to place malici...
borncity
Hornetsecurity: E-Mail-Gateway bei M365? Wie sind eure Erfahrungen?
Ich packe mal zwei Themen rund um Hornetsecurity, die über die Leserschaft an mich herangetragen wurden, in nachfolgendem Beitrag zusammen. Es geht einmal um die Erfahrungen, die Nutzer des Diensts gemacht haben – interessiert einen Leser. Ein zweiter Leser hat mich Anfang September 2026 Tage auf ein Problem beim "E-Mail-Versand" im Zusammenhang mit Microsoft 365 aufmerksam gemacht.
WhatsApp-Konten werden über Abstimmungsfalls gekapert
Seit August 2026 läuft eine Phishing-Masche auf WhatsApp, bei dem Betrüger versuchen, das Konto über eine emotionale Nachricht (Abstimmung für die Tochter einer Freundin etc.) zu kapern und mit einem anderen Gerät zu verbinden. Verbraucherzentralen und das BSI warnen vor der Masche.
VirtualBox 7.2.20 freigegeben
Zum 22. September 2026 haben Oracles Entwickler Virtualbox Version 7.2.20 freigegeben. Diese Version der Virtualisierungssoftware ist ein Wartungsupdate zur Fehlerkorrektur. Derzeit liefert der Server jedoch einen Payment-Error und es lässt sich nichts herunterladen. Weiterlesen →
Cybervorfälle: Flink (Lieferservice), Entega (Energieversorger), Cleanfix (Reinigungstechnik)
Die Woche hat es wieder einige größere Cybervorfälle gegeben, bei denen Unternehmen angegriffen wurden und Daten abgeflossen sind. Der Lieferservice Flink ist Opfer eines Angriffs geworden, und Kunden werden erpresst. Der Darmstädter Energieversorger Entega ist ebenfalls Opfer, und die Reinigungsfirma Cleanfix aus der Schweiz ebenfalls.
Schwachstellen: Kiteworks, Citrix NetScaler und Peoplesoft im Risiko
Momentan knallt es sicherheitstechnisch massiv. Die Cybergruppe ShineyHunters hackt Organisationen wie das FBI über eine Schwachstelle in Peoplesoft von Oracle. Noch kritischer scheint aber das Produkt Kiteworks zu sein, wo Administratoren für den heutigen 26. September 2026 eine mehrstufige Abschaltung empfohlen wurde. Und bei Citrix NetScaler ist wohl auch was im Busch, so dass man diese Instanzen auch deaktivieren sollte. Details, was da los ist, sind (mir) derzeit nicht bekannt. Weiterlesen →
CI-Solution GmbH von Crossware übernommen
Noch eine kleine Information für Leserinnen und Leser, denen die "CI-Solution GmbH" ein Begriff ist (die sind im Bereich Software für Exchange) aktiv. Ein Leser informierte mich, dass die Firma im Januar 2026 von Crossware aus Neuseeland übernommen wurde.