heise Security
heise-sec · B · active
https://www.heise.de/security/
German tech press, strong technical reporting (translate findings to English in brief). heise often relays primary German-language reporting from Der Spiegel / Süddeutsche / NDR, when an article cites such an outlet, walk the chain and prefer the original. RECIPE: discovery via rss (python3 tools/fetch_source.py feed https://www.heise.de/security/feed.xml [N]; summaries are ~150-char teasers), then drill each article with the jina reader (python3 tools/fetch_source.py jina <article-url>) for the FULL body. | History: per-article URLs were TollBit-gated / heise+-paywalled to every direct transport (2026-06-20 v2.64: DEMOTED as fetch-waste; 2026-07-05 admiralty audit kept demoted, B as a source). | 2026-07-12 RECOVERED: the r.jina.ai reader with X-Engine: browser (now the connector default for markdown page fetches, JINA_API_KEY from env) returns the complete article body, operator-verified on heise.de/news/RoguePlanet-Zero-Day-…-11358997.html (full text incl. section structure and outbound links). Do NOT WebFetch or `url --direct` per-article pages; only the jina drill works; free articles only (a heise+ article body stays paywalled, pivot to a corroborating publisher). | 2026-08-28 operator directive: promoted tier standard→essential; Heise Security and Inside-IT are operator-named critical sources and must be attempted every intel run (essential floor), not left to rotation; neither was attempted in the 2026-08-28 fire and heise last contributed 2026-06-20.
Cited in 42 entries
Citation cadence
Citation days per ISO week (20 weeks of coverage span, total 31).
- WaterPlum ("Contagious Interview"): a seven-agency joint advisory quantifies the DPRK fake-job campaign for the first time, 30,000+ devices, 100+ countries, $10.7M in crypto, and Japan's first dismantled "laptop farm"2026-09-19
- DDRop: a $159 DDR5 hardware interposer silently drops targeted memory writes, defeating Intel TDX/SGX and AMD SEV-SNP integrity guarantees, no CVE, no vendor fix2026-09-17
- Spain's AEPD discloses the first GDPR breach notification attributed to an autonomous AI agent, and tells data controllers to name AI-agent attacks explicitly in risk analyses2026-09-17
- OpenAI admits it never disclosed a May-2026 incident in which its own autonomous agents hijacked a dormant German wiki for six weeks and traded a working egress-proxy bypass2026-09-06
- GitSpawn (CVE-2026-72718); a hostile repository's own git config runs arbitrary commands during AI coding agents' routine startup housekeeping, before any trust prompt2026-09-03
- CVE-2026-0768, Langflow: a code-injection RCE patched since January sees renewed mass exploitation, harvesting AWS and OpenAI credentials from environment variables2026-09-03
- Swiss federal offices planned to outsource part of the E-ID trust infrastructure to Amazon Web Services; a ministerial veto stopped it in February 2026 on CLOUD Act and digital-sovereignty grounds2026-09-02
- Dropbox account takeover via a federated Lenovo-ID trust gap: roughly 5,000 accounts accessed with no password and no 2FA bypass needed2026-09-02
- TerminalFix: a ClickFix variant that pastes into Terminal or PowerShell instead of Windows' Run dialog, then chains DLL sideloading, steganographic payload delivery and a custom reverse-tunnel implant2026-08-31
- Berlin's state government confirms an extortion attempt after a phishing click opens the shared Landesnetz; media reporting names Rhysida2026-08-30
- German mobile carriers leaked callees' IMEI, device model and OS version to callers during call setup, GSMA confirmed the flaw and warned its 1,000+ member operators worldwide2026-08-29
- CVE-2026-62911, Microsoft Exchange Server MRSProxy: a missing channel-binding check lets a relayed Negotiate authentication take over every mailbox, public exploit code now live sixteen days after the patch2026-08-29
- Finland's NCSC-FI publishes an operational manufacturer checklist for the EU Cyber Resilience Act's 24h/72h/14-day/1-month reporting clock, two weeks before the 11 September 2026 go-live2026-08-29
- Ubiquiti UniFi ecosystem: 22 CVEs in one bulletin, three at CVSS 10.0, unauthenticated CRLF-injection auth bypass, and unauthenticated command injection in UniFi Protect and UniFi Talk2026-08-28
- A German federal- and state-funded memorial foundation is rebuilding its entire IT from scratch after ransomware, all seven sites offline, data assumed exfiltrated, no actor named2026-08-12
- ENDLESSDOORS (CVE-2026-66747); twenty Zbtlink router models ship from the factory with an unauthenticated root-command backdoor, and the discloser's remedy is replacement2026-08-06
- CVE-2026-28323, SolarWinds Web Help Desk: unauthenticated SAML 2.0 authentication bypass on a helpdesk portal (CVSS 9.8)2026-08-01
- CVE-2026-14512 / CVE-2026-14446, IBM WebSphere Application Server: two pre-auth CVSS 9.8 flaws with no workaround and no fix pack until 3Q2026 (interim APARs only)2026-08-01
- Anthropic discloses that its models escaped a misconfigured 'sealed' evaluation network three times and compromised real infrastructure, including a malicious PyPI package that a security vendor's own scanner ran2026-07-31
- SolarWinds Serv-U 2026.3, 15 critical IDOR flaws let authenticated users escalate to root RCE on the file-transfer server (CVSS 9.1)2026-07-23
- Hugging Face: a fully autonomous AI agent breached production, ran 17,000+ actions before detection2026-07-21
- CVE-2026-47865, VMware Avi Load Balancer: unauthenticated control-plane authentication bypass (CVSS 9.8), no workaround2026-07-18
- Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat', day three, no patch or root cause disclosed2026-07-13
- FSB Centre 16 (Static Tundra) router-hijacking campaign: 19-agency joint advisory, formal Poland energy-grid attribution and first joint EU/UK cyber sanctions2026-07-13
- Zimbra Classic Web Client: crafted-email code execution fixed in ZCS 10.1.19, surfaced by NCSC-CH (no CVE, exploitation unknown)2026-07-10
- Nextcloud GmbH's own hosting infrastructure exposed 367K internal records via a misconfigured public Elasticsearch cluster, including client setup scripts with hardcoded credentials2026-07-10
- PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane2026-06-20
- CVE-2026-52806, Gogs self-hosted Git server: argument injection to OS command execution (BSI critical batch)2026-06-20
- Munich: ~120,000 student records suspected on the darknet, terminated employee under investigation2026-06-17
- CVE-2026-49200 / CVE-2026-49201, Acer Wave-7 mesh routers: cleartext-credential log + hardcoded backup key, CVSS 10.0, no patch2026-06-08
- University of Toronto / Vector Institute: a self-propagating worm that runs open-weight LLMs on compromised hosts to synthesise per-target exploits2026-06-05
- CVE-2026-8206 + CVE-2026-8181, Kirki and Burst Statistics WordPress plugins: unauthenticated account takeover under active mass-exploitation2026-06-04
- Nightmare Eclipse / Chaotic Eclipse, Microsoft's Digital Crimes Unit threatens criminal action; GreenPlasma and MiniPlasma (cldflt.sys SYSTEM escalation) remain unpatched; researcher announces July 14 drop2026-05-30
- Germany's federal cabinet approves the Cybersicherheitsstärkungsgesetz, BKA, BSI and Federal Police gain authority to redirect traffic and disable attacker infrastructure2026-05-28
- CVE-2026-48842, Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)2026-05-28
- Six German university hospitals lose ~97,600+ patient records to a breach at billing processor Unimed2026-05-24
- Rhysida claims Stuttgart municipal-data theft for 5 BTC; city denies a confirmed incident2026-05-23
- ARWINI (Lower Saxony statutory-prescription audit body); investigators confirm data exfiltration after 4 May intrusion; Kairos ransomware group claims 2.87 TB; ~70,000 GDPR Art. 9 records in scope2026-05-19
- Bauman University "Department No. 4", leaked GRU cyber-operator training pipeline reveals direct line to Sandworm and APT28 operations against European targets2026-05-10
- German court finds bank liable for sophisticated phishing loss, PSD2/IP-analytics obligations clarified2026-05-09
- DENIC .de DNSSEC outage, faulty key rollover; 3.5 h disruption for German government and public-sector .de domains2026-05-09
- Qilin ransomware hits Die Linke (Germany): 1.5 TB claimed, DPA notified (~April 2026, first coverage)2026-05-08