NetzBastion.de - IT-Sicherheit & Netzwerktechnik
📚 38 Tutorials | ⚠️ 59 CVE-Warnungen | 📰 30 News diese Woche

🎉 NetTopo ist jetzt Released!

Netzwerk-Topologien einfach im Browser planen - das kostenlose Tool für Netzwerk-Administratoren

NEU Neuestes Tutorial

NetTopo Tutorial: Netzwerk-Topologien im Browser & auf dem Smartphone planen

Umfassendes Tutorial zu NetTopo v3.0: KI-gestützte Netzwerkplanung mit Groq Cloud, Auto-Organize, Live-Ping, Netzwerk-Scanner und Export in PNG/PDF/JSON. Jetzt auch als Android App.

⏱️ 25 Minuten 📊 Fortgeschritten
Tutorial ansehen →
⚠️
CVE-Suche
Sicherheitslücken
🔧
Tools
Netzwerk-Tools
📚
Tutorials
Schritt-für-Schritt
📡
UniFi
Firmware Updates
🛡️
Security
Tools & Hardware
🤖
KI
Self-Hosted AI

Aktuelle Sicherheitslücken

Zur CVE-Datenbank

Zuletzt aktualisiert: 24.7.2026, 14:02:43

🚨 KRITISCH CVE-2026-62825
Azure
10.0

CVE-2026-62825 - Improper authentication in Azure Key Vault allows an unauthorized attacker to elevate privileges ove

24.07.2026 Details →
🚨 KRITISCH CVE-2026-58275
Azure
10.0

CVE-2026-58275 - Missing authorization in Azure DNS allows an unauthorized attacker to elevate privileges over a netw

24.07.2026 Details →
🚨 KRITISCH CVE-2026-56191
Microsoft
10.0

CVE-2026-56191 - Improper authentication in Microsoft Exchange Online allows an unauthorized attacker to perform tamp

24.07.2026 Details →
🚨 KRITISCH CVE-2026-42933
Sonstige
10.0

CVE-2026-42933 - Pronetiqs IntraVUE versions 3.2.1a14 and prior have an unintended proxy or intermediary vulnerabilit

23.07.2026 Details →
🚨 KRITISCH CVE-2025-71389
Sonstige
10.0

CVE-2025-71389 - Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because

23.07.2026 Details →

Alle Nachrichten

28 Artikel
NIEDRIG
The Hacker News

Seeing AI Agents Is Not Enough. Security Teams Must Enforce What They Can Do

AI agent security is moving through a familiar maturity curve: adoption, then visibility, and finally, control. But what we've collectively discovered is that enforcing least privilege for AI agents is harder than we ever imagined. This is why there are so many approaches, from prompt filtering to identity-layer access controls. Where we've collectively landed is that understanding the intent of

Mehr lesen
NIEDRIG
The Hacker News

Hacker Runs Hermes AI Agent Unattended for Post-Exploitation at Thai Finance Ministry

Someone installed a popular AI assistant on a rented server, switched off the setting that makes it ask permission before running risky commands, and pointed it at Thailand's Ministry of Finance, which runs the country's treasury and tax collection. The agent then worked through the ministry's network on its own, checking hosts for ways to gain root access, hunting through file systems, and

Mehr lesen
NIEDRIG
The Hacker News

Golden Chickens Resurfaces With Four New Malware Families and Modular Implants

The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings. The malware families in question are: TinyEgg, ChonkyChicken, a modularized variant of ChonkyChicken, and a modified web browser credential

Mehr lesen
NIEDRIG
The Hacker News

Kimi K3 Agents Found Redis Zero-Days and Built RCE Exploit, Researchers Say

Redis shipped seven security releases on July 23 after researchers published authenticated RCE PoCs for stock Redis 6.2.22, 7.4.9, 8.6.4, and 8.8.0. All four chains require RESTORE. The Streams chains also need EVAL and XGROUP; the 8.8.0 chain needs EVAL and the bundled RedisBloom module. Redis says the underlying memory flaws may lead to remote code execution. Redis 6.2.23, 7.2.15, and 7.4.10

Mehr lesen
NIEDRIG
The Hacker News

Fake Notepad++ Plugin Delivers MATCHBOIL.V2 in UAC-0099 Attacks

The Computer Emergency Response Team of Ukraine (CERT-UA) has warned of a new campaign that involves the use of a malicious program that's dressed up as a Notepad++ plugin to compromise Windows systems. The activity has been attributed by the agency to a threat cluster it tracks as UAC-0099, a Russia-aligned group that has previously observed weaponizing security flaws in WinRAR software to

Mehr lesen

Empfohlene Sicherheitstools

Unterstütze uns durch einen Kauf - wir erhalten eine kleine Provision.