Feed aggregator

Android: Google-System-Update für Oktober bringt Neuerungen

heise Security - Tue, 10/07/2025 - 14:00
Googles Oktober-Update der Systemdienste bringt einige Neuerungen mit sich. Unter anderem wird die Nacktbild-Erkennung in Messages erweitert.
Categories:

Microsoft Outlook: Zur Sicherheit keine SVG-Anzeige mehr

heise Security - Tue, 10/07/2025 - 11:52
Ein Einfallstor für Malware ist das Vektorgrafikformat SVG. Microsoft zieht dem Format in Outlook daher den Stecker – etwas.
Categories:

Google: KI-Bug-Bounty-Programm zahlt bis zu 30.000 US-Dollar pro Fehler

heise Security - Tue, 10/07/2025 - 10:58
Google führt ein Bug-Bounty-Programm für KI-Anwendungen ein. Entdecker schwerwiegender Fehler in Gemini oder der KI-Suche erhalten Belohnungen.
Categories:

Salesforce-Datenklau: Cybergangs erpressen namhafte Unternehmen auf Leaksite

heise Security - Tue, 10/07/2025 - 10:18
Cyberkriminelle erpressen auf einer Leaksite im Darknet 39 namhafte Unternehmen. Deren Daten haben sie aus Salesforce kopiert.
Categories:

Signal sichert seine Chats gegen Quantencomputer

heise Security - Mon, 10/06/2025 - 15:32
Signal ergänzt sein Double-Ratchet-Verfahren um eine neue Komponente, sodass auch zukünftige Quantencomputer die Kommunikation nicht knacken können.
Categories:

Spiele-Engine Unity: Lücke bedroht Android, Linux, macOS und Windows

heise Security - Mon, 10/06/2025 - 10:13
Unity steckt in zahlreichen populären Spielen für Mobilgeräte und Desktop. Eine gravierende Lücke ermöglicht Angreifern, Schadcode auszuführen.
Categories:

Cyberangriff am BER: Passagierabfertigung wieder am Netz

heise Security - Sun, 10/05/2025 - 15:52
Zwei Wochen nach einem Cyberangriff auf einen IT-Dienstleister am Berliner Flughafen BER läuft das System zur Passagierabfertigung wieder.
Categories:

Unzählige Sicherheitslücken in Dell PowerProtect Data Domain geschlossen

heise Security - Sun, 10/05/2025 - 14:58
Dells Backuplösung PowerProtect Data Domain ist verwundbar. Sicherheitsupdates schaffen Abhilfe.
Categories:

Datenleck bei Discord: Support-Dienstleister erfolgreich attackiert

heise Security - Sun, 10/05/2025 - 14:21
Kriminelle konnten persönliche Daten von bestimmten Discord-Nutzern erbeuten. Diese könnten für Phishing-Attacken missbraucht werden.
Categories:

Jetzt patchen! Angreifer erpressen Oracle-E-Business-Suite-Kunden

heise Security - Sun, 10/05/2025 - 13:37
Admins der Oracle-Software E-Business Suite sollten ihre Instanzen aufgrund von derzeit laufenden Attacken absichern.
Categories:

Attacke auf Red-Hat-GitLab-Instanz, Kundendaten kopiert

heise Security - Sun, 10/05/2025 - 11:32
Beim Softwarehersteller Red Hat kam es zu einem IT-Sicherheitsvorfall. Die Angreifer geben an, 570 GB an Daten kopiert zu haben.
Categories:

Proxmox Mail Gateway 9.0 mit mehr Schutz und einfacherem Quarantäne-Management

heise Security - Fri, 10/03/2025 - 10:46
Das Proxmox Mail Gateway feiert seinen 20. Geburtstag und soll in Version 9.0 noch besser vor Viren, Spam und anderem digitalen Ungemach schützen.
Categories:

Auslegungssache 144: Wege aus der US-Abhängigkeit

heise Security - Fri, 10/03/2025 - 06:00
Die Dominanz US-amerikanischer Tech-Konzerne wird zunehmend zum Problem. Im c't-Datenschutz-Podcast geht es um praktische Alternativen und europäische Lösungen.
Categories:

Online-Wahlen in Ontario: Hohes Risiko von Wahlbetrug

heise Security - Thu, 10/02/2025 - 23:20
Viele Kommunen der größten Provinz Kanadas lassen nur noch online wählen. Die Sicherheit ist mau, das Betrugsrisiko hoch.
Categories:

Sicherheitspatches: OpenSSL für Schadcode-Attacken anfällig

heise Security - Thu, 10/02/2025 - 09:22
In aktuellen OpenSSL-Versionen haben die Entwickler drei Sicherheitslücken geschlossen. Bislang gibt es keine Berichte zu Attacken.
Categories:

Now Available: Firebox M295, M395, M495, M595, M695

WatchGuard Wire (englisch) - Wed, 10/01/2025 - 18:37

We’re excited to announce that our new Firebox rackmount appliances are officially available for sale starting October 1!

Key Features

  • Throughput: With UTM throughput of up to 10.2 Gbps and VPN throughput of up to 13.0 Gbps, the new Firebox® rackmount appliances are built to last your network needs for years to come.
  • Interface Layout: Each model comes with a variety of interfaces, including 2.5 Gbps Ethernet, SFP, and SFP+ options built in. The M495 and above also include 10 Gbps Ethernet interfaces to support your highest speed connections.
  • A Clouds-Eye View of Your Network: WatchGuard Cloud Visibility provides full visibility into your network so that you can make timely, informed, and effective decisions about your network security anywhere, anytime.
  • Automation Core: WatchGuard Firebox appliances are designed with automation to the core, allowing your IT team to do more with less. Deploy from the Cloud, update signatures, detect and kill malware, all without lifting a finger.

Visit the Firebox Rackmount Appliances landing page for more information on the new Rackmount Fireboxes

View the Datasheets for details on the new Rackmount Fireboxes.

Stay Informed

WatchGuard is committed to keeping our customers informed about the latest security threats. For the most up-to-date information on vulnerabilities and how WatchGuard products address them, please visit our Trust Center. Please contact your local WatchGuard representative with any additional questions about this release. For Sales or Support questions, you can find phone numbers for your region online. If you contact WatchGuard Technical Support, please have your registered appliance Serial Number or Partner ID available. 

Categories:

End-of-Sale Announcement: WatchGuard Firebox T85-PoE

WatchGuard Wire (englisch) - Thu, 09/18/2025 - 01:29

We want to inform our valued partners and customers that the WatchGuard Firebox T85-PoE will officially reach its End-of-Sale (EOS) milestone on October 1, 2025.

The Firebox T85-PoE has been a trusted solution for delivering enterprise-grade security to small and distributed environments. As technology evolves, we remain committed to providing the most advanced and efficient security solutions to meet our customers' changing needs.

What This Means:

  • After October 1, 2025, the Firebox T85-PoE will no longer be available for purchase. End-of-life (EOL) is scheduled for December 31, 2030
  • Existing T85-PoE devices will continue to receive support, including firmware updates and technical assistance, through their lifecycle
  • Renewals for active subscriptions and services will remain available until the EOL date

Recommended Next Steps 

We encourage customers currently using the T85-PoE to begin planning their migration to newer Firebox models. Our latest tabletop appliances offer enhanced performance, expanded capabilities, and future-ready security features.

For guidance on migration options or to explore the latest Firebox models, please contact your WatchGuard representative or authorized partner. The EOL page will be updated on October 1, 2025.

Categories:

Fireware Updates Available: Upgrade Your Firebox Firmware Now

WatchGuard Wire (englisch) - Wed, 09/17/2025 - 17:00

For a consistent, strong security posture, it’s more important than ever to quickly update all cybersecurity infrastructure with the latest firmware and up-to-date patches. Therefore, we recommend that you upgrade your Fireboxes now to apply the latest security fixes.  The following new versions are now available to download from the WatchGuard Software Downloads Center, WatchGuard Cloud, or the Firebox Web UI.  You should immediately update your Firebox appliance(s) to one of these versions or higher (if available):

  • Fireware 2025.1.1
  • Fireware v12.11.4
  • Fireware v12.5.13
  • Fireware v12.3.1 Update 3

This firmware includes a fix for a critical security flaw we discovered through our ongoing internal programs to test the security of our products. We have not seen any indication that this vulnerability has been exploited. After discovery and validation, WatchGuard filed CVE-2025-9242 according to our responsible disclosure process and we have issued WatchGuard Security Advisory WGSA-2025-0015 and posted it to our PSIRT page. 

At WatchGuard, we embrace a responsible disclosure process as essential to keeping customers knowledgeable about the cybersecurity products they use. In circumstances when the vulnerability is unexploited, and when certain details could speed exploitation attempts, we may delay including them in the security advisory to reduce exposure and protect our customers. After a reasonable time to apply patches with upgraded firmware, we will then add indicators of attack (IoAs) and additional information. 

Which products are affected by this release?

  • Fireware 2025.1.1 for Firebox T115-W, T125, T125-W, T145, T145-W, and T185
  • Fireware 12.11.4 for Firebox NV5, T20, T25, T20, T45, T55, T70, T80, T85-PoE, M270, M290, M370, M390, M470, M570, M590, M670, M690, M4600, M4800, M5600, M5800, FireboxV, and Firebox Cloud
  • 12.5.13 : for Firebox T15 and T35
  • 12.3.1 Update 3 for Fireboxes running in FIPS mode under FIPS140-2. Applicable models are Firebox T15, T35, T55, T70, M270, M370, M470, M570, M670, M4600, and M5600

If you have any further questions, please contact  WatchGuard Support or your WatchGuard account representative. 

Categories:

Zero-Click-Angriff auf Apple-Geräte via WhatsApp

heise Security - Sat, 08/30/2025 - 14:37
WhatsApp meldet eine geschlossene Lücke, über die anfällige iOS- und macOS-Geräte ohne Bestätigung des Nutzers per Spyware angegriffen werden können.
Categories:

Vishing: So gelingt der Angriff per Telefon selbst auf Großunternehmen

heise Security - Sat, 08/30/2025 - 07:09
Auf der Def Con konnte man sich live ansehen, wie Vishing funktioniert. Erstaunlich oft ergattern Angreifer per Telefon selbst wichtigste Firmeninformationen.
Categories:
Syndicate content