heise Security
heise-sec · B · active
https://www.heise.de/security/
German tech press, strong technical reporting (translate findings to English in brief). heise often relays primary German-language reporting from Der Spiegel / Süddeutsche / NDR — when an article cites such an outlet, walk the chain and prefer the original. RECIPE: discovery via rss (python3 tools/fetch_source.py feed https://www.heise.de/security/feed.xml [N] — summaries are ~150-char teasers), then drill each article with the jina reader (python3 tools/fetch_source.py jina <article-url>) for the FULL body. | History: per-article URLs were TollBit-gated / heise+-paywalled to every direct transport (2026-06-20 v2.64: DEMOTED as fetch-waste; 2026-07-05 admiralty audit kept demoted, B as a source). | 2026-07-12 RECOVERED: the r.jina.ai reader with X-Engine: browser (now the connector default for markdown page fetches, JINA_API_KEY from env) returns the complete article body — operator-verified on heise.de/news/RoguePlanet-Zero-Day-…-11358997.html (full text incl. section structure and outbound links). Do NOT WebFetch or `url --direct` per-article pages — only the jina drill works; free articles only (a heise+ article body stays paywalled — pivot to a corroborating publisher).
Cited in 33 entries
Citation cadence
Citation days per ISO week (13 weeks of coverage span, total 22).
- CVE-2026-28323 — SolarWinds Web Help Desk: unauthenticated SAML 2.0 authentication bypass on a helpdesk portal (CVSS 9.8)2026-08-01
- CVE-2026-14512 / CVE-2026-14446 — IBM WebSphere Application Server: two pre-auth CVSS 9.8 flaws with no workaround and no fix pack until 3Q2026 (interim APARs only)2026-08-01
- BaFin fined TeamViewer EUR 240,000 for how it disclosed its 2024 nation-state breach — a website notice did not satisfy the ad-hoc-disclosure duty, setting a breach-disclosure-mechanics precedent for any SIX/EU-listed software or CI supplier2026-07-26
- SolarWinds Serv-U 2026.3 — 15 critical IDOR flaws let authenticated users escalate to root RCE on the file-transfer server (CVSS 9.1)2026-07-23
- CVE-2026-47865 — VMware Avi Load Balancer: unauthenticated control-plane authentication bypass (CVSS 9.8), no workaround2026-07-18
- Progress orders ShareFile Storage Zone Controller shutdown over a 'credible external threat' — day three, no patch or root cause disclosed2026-07-13
- France and the EU attribute the Turla intrusion set to FSB Centre 16, with French victimology, TTPs and EU/UK sanctions2026-07-13
- Zimbra Classic Web Client: crafted-email code execution fixed in ZCS 10.1.19, surfaced by NCSC-CH (no CVE, exploitation unknown)2026-07-10
- Nextcloud GmbH's own hosting infrastructure exposed 367K internal records via a misconfigured public Elasticsearch cluster, including client setup scripts with hardcoded credentials2026-07-10
- Insider and process failures — Munich school data, a lost SSD, and an NHS records caution2026-06-22
- CVE-2026-12569 — PTC Windchill / FlexPLM pre-auth deserialization RCE, exploited, BSI calling admins at 02:302026-06-22
- PTC Windchill CVE-2026-12569: unauthenticated Java deserialization to RCE on the PLM management plane2026-06-20
- CVE-2026-52806 — Gogs self-hosted Git server: argument injection to OS command execution (BSI critical batch)2026-06-20
- Munich: ~120,000 student records suspected on the darknet — terminated employee under investigation2026-06-17
- CVE-2026-49200 / CVE-2026-49201 — Acer Wave-7 mesh routers: cleartext-credential log + hardcoded backup key, CVSS 10.0, no patch2026-06-08
- University of Toronto / Vector Institute: a self-propagating worm that runs open-weight LLMs on compromised hosts to synthesise per-target exploits2026-06-05
- CVE-2026-8206 + CVE-2026-8181 — Kirki and Burst Statistics WordPress plugins: unauthenticated account takeover under active mass-exploitation2026-06-04
- Nightmare Eclipse / Chaotic Eclipse — Microsoft's Digital Crimes Unit threatens criminal action; GreenPlasma and MiniPlasma (cldflt.sys SYSTEM escalation) remain unpatched; researcher announces July 14 drop2026-05-30
- Germany's federal cabinet approves the Cybersicherheitsstärkungsgesetz — BKA, BSI and Federal Police gain authority to redirect traffic and disable attacker infrastructure2026-05-28
- CVE-2026-48842 — Roundcube Webmail pre-authentication SQL injection in virtuser_query plugin (CVSS 8.1)2026-05-28
- Six German university hospitals lose ~97,600+ patient records to a breach at billing processor Unimed2026-05-24
- Rhysida claims Stuttgart municipal-data theft for 5 BTC; city denies a confirmed incident2026-05-23
- ARWINI (Lower Saxony statutory-prescription audit body) — investigators confirm data exfiltration after 4 May intrusion; Kairos ransomware group claims 2.87 TB; ~70,000 GDPR Art. 9 records in scope2026-05-19
- Six German university hospitals — patient records exfiltrated via billing processor Unimed2026-05-18
- Rhysida claims Stuttgart municipal data — city denies a confirmed incident2026-05-18
- DENIC .de DNSSEC outage post-mortem — three private keys generated with the same Key Tag (33834); only one DNSKEY published2026-05-10
- Bauman University "Department No. 4" — leaked GRU cyber-operator training pipeline reveals direct line to Sandworm and APT28 operations against European targets2026-05-10
- German court finds bank liable for sophisticated phishing loss — PSD2/IP-analytics obligations clarified2026-05-09
- DENIC .de DNSSEC outage — faulty key rollover; 3.5 h disruption for German government and public-sector .de domains2026-05-09
- Qilin ransomware hits Die Linke (Germany): 1.5 TB claimed, DPA notified (~April 2026, first coverage)2026-05-08
- German LG Berlin II ruling — Apobank liable for €218,000+ phishing loss; PSD2 IP-analytics obligation clarified2026-05-04
- German LG Berlin II — Apobank ruling sets PSD2 IP-analytics obligation as case law2026-05-04
- DENIC .de DNSSEC outage — 3.5 h registry-side trust failure traced to keytag 33834 collision and an alerting-layer fire-without-page2026-05-04