Category Archives: Security

Check Point discovers WhatsApp vulnerability in image filter

[German]Another brief security information for the few remaining WhatsApp users. Security researchers from Check Point have discovered a vulnerability in the WhatsApp image filter function that hackers could exploit. In the meantime, however, this vulnerability has been fixed with an … Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Next Azure container vulnerability allowed data theft

[German]Microsoft issued a warning to its Azure customers about a security vulnerability that could have allowed hackers to access data. The punchline: It involved containers whose code had a known vulnerability that had not been patched. Microsoft has now updated … Continue reading

Posted in Cloud, Security | Tagged , , | Leave a comment

WordPress 5.8.1 released

[German]WordPress 5.8.1 has been released as a maintenance update on September 8, 2021. The update fixed three vulnerabilities in WordPress versions between 5.4 and 5.8. Therefore, older were all WordPress versions since 5.4 also updated. Furthermore, a number of bugs … Continue reading

Posted in Security, Software, Update | Tagged | Leave a comment

GhostScript 0-day vulnerability allows server compromise

[German]An unpatched vulnerability exists in GhostScript (up to v 9.50) that allows privilege escalation. Servers running the ImageMagick program are particularly at risk. These could be taken over by attackers. The vulnerability was discovered a year ago, but allegedly not … Continue reading

Posted in Security | Tagged , | Leave a comment

Attack via Office Documents on Microsoft MSHTML (ActiveX) RCE Vulnerability (CVE-2021-40444)

[German]Microsoft has issued a warning about the remote code execution vulnerability CVE-2021-40444 as of September 7, 2021. In campaigns, this vulnerability, which targets the MSHTML component of Internet Explorer, is exploited via compromised Office documents. Microsoft provides guidance on mitigating … Continue reading

Posted in browser, Office, Security, Windows | Tagged , , , | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


Thunderbird 91.1.0

[German]In addition to the update of Thunderbird 78.14.0, the developers have also released Thunderbird 91.1.0 as of September 7, 2021. This is a maintenance and security update for the 91 development branch.

Posted in Security, Software, Update | Tagged , | Leave a comment

ProtonMail issues IP of a French activist to police

[German]Swiss-based email service ProtonMail offers end-to-end encryption of mails before they are sent to ProtonMail's server. ProtonMail is operated by Proton Technologies AG, which is based in Plan-les-Ouates (Canton of Geneva). Its servers are located in two locations in Switzerland, … Continue reading

Posted in Security | Tagged | Leave a comment

Turn off Defender in Windows with symbolic links

[German]Symbolic links allow to disable Defender as antivirus protection under Windows without disabling features like Tamper Protection. The approach simply lets Defender run into the woods during scanning, because the virus scanner is redirected to other folders. I came across … Continue reading

Posted in Security, Windows | Tagged , , | Leave a comment

Bluetooth risks: Braktooth vulnerability and tracking via head phones

[German]Riskante Technik Bluetooth: So haben Sicherheitsforscher bei verschiedenen Bluetooth-Chip-Sets, die in Geräten wie Notebooks, Lautsprechern oder IoT-Geräten verwendet werden, gleich 16 verschiedene Sicherheitslücken entdeckt. Die Schwachstellen firmieren unter dem Namen Braktooth. Und in Oslo ist es gelungen, durch umherfahren mit … Continue reading

Posted in Security | Tagged , | Leave a comment

Cisco fixes critical authentication bypass vulnerability CVE-2021-34746

[German]A vulnerability (CVE-2021-34746) was recently found in the TACACS+ authentication, authorization and accounting (AAA) feature of Cisco's Enterprise NFV Infrastructure software. This is a solution designed to virtualize network services for easier management of virtual network functions (VNFs). The CVE-2021-34746 … Continue reading

Posted in Security | Tagged | Leave a comment