0-day attack via Zoho vulnerability; patching is required

Sicherheit (Pexels, allgemeine Nutzung)[German]The U.S. Cybersecurity and Infrastructure Security Agency (CISA) warns that hackers are exploiting a critical vulnerability in Zoho's password management solution ManageEngine ADSelfService Plus. The vulnerability allows attackers to take control of the system. The vendor has provided a security update to close the vulnerability.

Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Data leak with 87,000 FortiGate SSL VPN credentials used for attacks

Sicherheit (Pexels, allgemeine Nutzung)[German]Another short information for administrators of FortiGate installations, which has been dangling with me for a few days. Unknown persons have created a collection of 87,000 FortiGate SSL-VPN credentials, which they are now using specifically to attack corresponding installations. CERT-Bund has just issued a warning to this effect, administrators need to act.

Continue reading

Posted in Security | Tagged | Leave a comment

MSHTML vulnerability CVE-2021-40444 more critical than known

Sicherheit (Pexels, allgemeine Nutzung)[German]A few days ago, Microsoft disclosed a security advisory for the CVE-2021-40444 vulnerability in the MSHTML component included in Windows. It said there was an attempt to exploit the vulnerability in the wild via crafted Office documents. But Office users are actually protected from this threat by the protected view, they said. Now it is becoming known that this protection can be bypassed and does not work.

Continue reading

Posted in Office, Security, Windows | Tagged , | Leave a comment

Check Point discovers WhatsApp vulnerability in image filter

[German]Another brief security information for the few remaining WhatsApp users. Security researchers from Check Point have discovered a vulnerability in the WhatsApp image filter function that hackers could exploit. In the meantime, however, this vulnerability has been fixed with an update to the app.

Continue reading

Posted in Security, Software | Tagged , | Leave a comment

Next Azure container vulnerability allowed data theft

[German]Microsoft issued a warning to its Azure customers about a security vulnerability that could have allowed hackers to access data. The punchline: It involved containers whose code had a known vulnerability that had not been patched. Microsoft has now updated the programs. This is now the second case within a few days where serious vulnerabilities in Azure containers became public.

Continue reading

Posted in Cloud, Security | Tagged , , | Leave a comment

Why ISL Online: Critical factors when choosing a remote desktop solution

[Sponsored Post]In the rapidly evolving IT world, choosing the right remote desktop software is critical for organizations that value security, ease of use and reliability. One provider of secure remote access that has been on the market since 2001 is ISL Online, which presents some considerations for choosing such software below. More ...


WordPress 5.8.1 released

[German]WordPress 5.8.1 has been released as a maintenance update on September 8, 2021. The update fixed three vulnerabilities in WordPress versions between 5.4 and 5.8. Therefore, older were all WordPress versions since 5.4 also updated. Furthermore, a number of bugs were fixed. Details about the security issues and bug fixes can be found in the release notes.

Posted in Security, Software, Update | Tagged | Leave a comment

GhostScript 0-day vulnerability allows server compromise

Sicherheit (Pexels, allgemeine Nutzung)[German]An unpatched vulnerability exists in GhostScript (up to v 9.50) that allows privilege escalation. Servers running the ImageMagick program are particularly at risk. These could be taken over by attackers. The vulnerability was discovered a year ago, but allegedly not reported to the developers. And now there is a proof-of-concept (PoC) to exploit the vulnerability via exploit. Since tools like ImageMagick use GhostScript internally and are used by many companies, admins should respond and update GhostScript

Continue reading

Posted in Security | Tagged , | Leave a comment

Attack via Office Documents on Microsoft MSHTML (ActiveX) RCE Vulnerability (CVE-2021-40444)

Sicherheit (Pexels, allgemeine Nutzung)[German]Microsoft has issued a warning about the remote code execution vulnerability CVE-2021-40444 as of September 7, 2021. In campaigns, this vulnerability, which targets the MSHTML component of Internet Explorer, is exploited via compromised Office documents. Microsoft provides guidance on mitigating this vulnerability, which stems from the ActiveX technology introduced with Internet Explorer.

Continue reading

Posted in browser, Office, Security, Windows | Tagged , , , | Leave a comment

Thunderbird 91.1.0

[German]In addition to the update of Thunderbird 78.14.0, the developers have also released Thunderbird 91.1.0 as of September 7, 2021. This is a maintenance and security update for the 91 development branch.

Continue reading

Posted in Security, Software, Update | Tagged , | Leave a comment

Microsoft Office Patchday (September 7, 2021)

[German]On September 7, 2021 (first Tuesday of the month, Office Patchday), Microsoft releases non-security updates for still-supported versions of Microsoft Office. This month, however, there is only one update for Microsoft Office 2016. . Here's a brief overview.

Continue reading

Posted in Office, Update | Tagged , | Leave a comment