<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"><channel><title>SEKurity Blog | Professionelle Cybersecurity-Einblicke</title><description>Professionelle Cybersecurity-Einblicke, Schwachstellenforschung und Branchenexpertise vom SEKurity-Team. Bleiben Sie auf dem Laufenden mit den neuesten Sicherheitstrends und Best Practices.</description><link>https://blog.sekurity.de/</link><language>de-de</language><managingEditor>noreply@sekurity.de (SEKurity Team)</managingEditor><webMaster>noreply@sekurity.de (SEKurity Team)</webMaster><copyright>Copyright 2026 SEKurity GmbH. Alle Rechte vorbehalten.</copyright><category>Technologie</category><category>Cybersecurity</category><category>Informationssicherheit</category><docs>https://www.rssboard.org/rss-specification</docs><generator>Astro RSS</generator><ttl>60</ttl><item><title>InSEKurity of the Week (CW31/2026): Cisco Secure Firewall Management Center Static Credentials (CVE-2026-20316)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw31-2026-cisco-secure-fmc/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw31-2026-cisco-secure-fmc/</guid><description>Ein fest einprogrammiertes Konto mit niedrigen Rechten in jedem Cisco Secure Firewall Management Center erlaubt unauthentifizierten Angreifern die Anmeldung an der Firewall-Management-Ebene -- ausgenutzt als Zero-Day, bevor Cisco ueberhaupt ein Advisory veroeffentlichte.</description><pubDate>Tue, 04 Aug 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Cisco</category><category>Secure Firewall Management Center</category><category>Hard-coded Credentials</category><category>Zero-Day</category><category>Firewall</category><author>sekurity-team</author></item><item><title>InSEKurity of the Week (CW30/2026): WordPress Core wp2shell Pre-Auth RCE (CVE-2026-63030 &amp; CVE-2026-60137)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw30-2026-wordpress-wp2shell/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw30-2026-wordpress-wp2shell/</guid><description>Eine Route-Confusion im REST-API-Batch-Endpunkt von WordPress Core, verkettet mit einer SQL-Injection in WP_Query, ermoeglicht unauthentifizierten Angreifern Remote Code Execution auf einer Standard-WordPress-Installation -- ohne Plugins, ohne Zugangsdaten, und sie wird bereits aktiv ausgenutzt.</description><pubDate>Tue, 28 Jul 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>WordPress</category><category>WordPress Core</category><category>SQL Injection</category><category>RCE</category><category>REST API</category><category>wp2shell</category><author>sekurity-team</author></item><item><title>InSEKurity of the Week (CW29/2026): SonicWall SMA 1000 Unauthenticated SSRF to Root RCE (CVE-2026-15409 &amp; CVE-2026-15410)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw29-2026-sonicwall-sma1000/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw29-2026-sonicwall-sma1000/</guid><description>Zwei Zero-Days in SonicWalls SMA-1000-Remote-Access-Appliance -- eine unauthentifizierte CVSS-10.0-SSRF verkettet mit einer Post-Auth-Root-Code-Injection -- werden aktiv ausgenutzt, um Zugangsdaten, Session-Datenbanken und MFA-Seeds zu stehlen.</description><pubDate>Tue, 21 Jul 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>SonicWall</category><category>SMA 1000</category><category>SSRF</category><category>RCE</category><category>VPN</category><category>Zero-Day</category><author>sekurity-team</author></item><item><title>InSEKurity of the Week (CW28/2026): Linux KVM Guest-to-Host VM Escape -- Januscape (CVE-2026-53359)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw28-2026-linux-kvm/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw28-2026-linux-kvm/</guid><description>Eine 16 Jahre alte Use-after-Free-Luecke in der KVM-Shadow-MMU laesst einen Root-Nutzer in einer Gast-VM auf den Host ausbrechen -- auf Intel und AMD, ausgenutzt als Zero-Day in Googles kvmCTF</description><pubDate>Tue, 14 Jul 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Linux</category><category>KVM</category><category>VM Escape</category><category>Use-After-Free</category><category>Virtualization</category><author>sekurity-team</author></item><item><title>InSEKurity of the Week (CW27/2026): Microsoft SharePoint Server Deserialization RCE (CVE-2026-45659)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw27-2026-microsoft-sharepoint-rce/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw27-2026-microsoft-sharepoint-rce/</guid><description>Eine Deserialisierungsluecke in Microsoft SharePoint Server erlaubt einem authentifizierten Benutzer mit niedrigen Rechten das Ausfuehren von Code auf dem Server -- jetzt im CISA-KEV-Katalog unter bestaetigter aktiver Ausnutzung</description><pubDate>Tue, 07 Jul 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Microsoft</category><category>SharePoint</category><category>Deserialization</category><category>RCE</category><category>CISA KEV</category><author>sekurity-team</author></item><item><title>InSEKurity of the Week (CW26/2026): Fortinet FortiSandbox Unauthenticated OS Command Injection (CVE-2026-25089)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw26-2026-fortisandbox/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw26-2026-fortisandbox/</guid><description>Eine kritische OS-Command-Injection in der FortiSandbox-Web-GUI erlaubt nicht authentifizierten Angreifern, ueber praeparierte HTTP-Requests beliebige Systembefehle auszufuehren -- ein Fuss in der Tuer genau jener Appliance, die Malware analysieren soll</description><pubDate>Tue, 30 Jun 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Fortinet</category><category>FortiSandbox</category><category>RCE</category><category>OS Command Injection</category><category>Unauthenticated</category><author>sekurity-team</author></item><item><title>InSEKurity of the Week (CW25/2026): Splunk Enterprise Unauthenticated RCE ueber PostgreSQL-Sidecar (CVE-2026-20253)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw25-2026-splunk-enterprise/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw25-2026-splunk-enterprise/</guid><description>Eine Missing-Authentication-Luecke im PostgreSQL-Sidecar-Dienst von Splunk Enterprise erlaubt unauthentifizierten Angreifern das Erstellen und Ueberschreiben beliebiger Dateien -- verkettet zu Remote Code Execution, aktiv ausgenutzt und die erste Splunk-Luecke ueberhaupt im CISA-KEV-Katalog</description><pubDate>Tue, 23 Jun 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Splunk</category><category>Splunk Enterprise</category><category>RCE</category><category>Missing Authentication</category><category>PostgreSQL</category><category>CISA KEV</category><author>sekurity-team</author></item><item><title>InSEKurity of the Week (CW24/2026): Check Point Remote Access VPN IKEv1 Authentication Bypass (CVE-2026-50751)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw24-2026-check-point-vpn-ikev1/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw24-2026-check-point-vpn-ikev1/</guid><description>Ein Logikfehler im veralteten IKEv1-VPN des Check Point Security Gateway erlaubt unauthentifizierten Angreifern, eine Remote-Access-VPN-Sitzung ohne gueltiges Passwort aufzubauen -- als Zero-Day von einem Qilin-Ransomware-Affiliate ausgenutzt und im CISA-KEV-Katalog gelistet</description><pubDate>Tue, 16 Jun 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Check Point</category><category>Security Gateway</category><category>VPN</category><category>IKEv1</category><category>Authentication Bypass</category><category>Ransomware</category><author>sekurity-team</author></item><item><title>InSEKurity of the Week (CW23/2026): Cisco Unified CM WebDialer Unauthentifizierte SSRF-zu-Root (CVE-2026-20230)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw23-2026-cisco-unified-cm-webdialer/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw23-2026-cisco-unified-cm-webdialer/</guid><description>Unauthentifizierte SSRF im WebDialer-Dienst von Cisco Unified Communications Manager erlaubt entfernten Angreifern, Dateien auf das zugrunde liegende OS zu schreiben und auf root zu eskalieren -- oeffentlicher Exploit-Code ist bereits verfuegbar</description><pubDate>Tue, 09 Jun 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Cisco</category><category>Unified Communications Manager</category><category>WebDialer</category><category>SSRF</category><category>Privilege Escalation</category><author>sekurity-team</author></item><item><title>InSEKurity of the Week (CW22/2026): Windows Netlogon Pre-Auth RCE auf Domain Controllern (CVE-2026-41089)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw22-2026-windows-netlogon-rce/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw22-2026-windows-netlogon-rce/</guid><description>Kritischer Stack-basierter Buffer Overflow in Windows Netlogon erlaubt unauthentifizierten Angreifern SYSTEM-Code auf jedem Windows-Domain-Controller ueber das Netzwerk -- jetzt aktiv ausgenutzt</description><pubDate>Tue, 02 Jun 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Microsoft</category><category>Windows</category><category>Netlogon</category><category>Active Directory</category><category>Domain Controller</category><category>RCE</category><category>Buffer Overflow</category><author>sekurity-team</author></item><item><title>BitLocker umgangen – warum ein gepatchtes Windows 11 nicht reicht</title><link>https://blog.sekurity.de/de/blog/bitlocker-bypass-winre/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/bitlocker-bypass-winre/</guid><description>BitUnlocker und YellowKey zeigen, dass BitLocker-Bypasses nicht die Kryptografie brechen — sie nutzen die Vertrauenskette rund um WinRE, TPM und Secure Boot aus.</description><pubDate>Fri, 29 May 2026 00:00:00 GMT</pubDate><category>general</category><category>BitLocker</category><category>Windows</category><category>WinRE</category><category>BitUnlocker</category><category>YellowKey</category><category>CVE-2026-45585</category><author>alexander-sturz</author></item><item><title>adPEAS v2 Episode 9: Tips &amp; Tricks - Die versteckten Werkzeuge in adPEAS</title><link>https://blog.sekurity.de/de/blog/adpeas-v2-tips-tricks/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/adpeas-v2-tips-tricks/</guid><description>Versteckte Produktivitäts-Booster in adPEAS v2: Show-Object, KnownSPN-Discovery, gefährliche ACL-Analyse, EPA-Testing, Account-Activity-Filter, Zertifikatsanalyse und mehr.</description><pubDate>Wed, 27 May 2026 00:00:00 GMT</pubDate><category>adPEAS</category><category>adPEAS</category><category>Active Directory</category><category>PowerShell</category><category>Penetration Testing</category><category>Tips</category><category>Security Tools</category><author>alexander-sturz</author></item><item><title>InSEKurity der Woche (KW21/2026): Drupal Core Anonyme SQL Injection (CVE-2026-9082)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw21-2026-drupal-core-sql-injection/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw21-2026-drupal-core-sql-injection/</guid><description>Eine unauthentifizierte SQL Injection im PostgreSQL EntityQuery-Handler von Drupal Core -- anonyme Angreifer verwandeln JSON-Objekt-Schluessel und JSON:API-Filterparameter in rohe SQL-Fragmente. Von Drupal mit 23/25 &apos;Highly Critical&apos; bewertet, CISA KEV, 15.000+ Exploit-Versuche in 48 Stunden</description><pubDate>Tue, 26 May 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Drupal</category><category>SQL Injection</category><category>PostgreSQL</category><category>JSON:API</category><category>CMS</category><category>CISA KEV</category><category>Web Security</category><author>sekurity-team</author></item><item><title>adPEAS v2 Episode 8: PAC Deep-Dive &amp; Ticket Forging — Was im Ticket steckt</title><link>https://blog.sekurity.de/de/blog/adpeas-v2-pac-tickets/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/adpeas-v2-pac-tickets/</guid><description>Deep Dive in die PAC-Struktur, NDR-Serialisierung, PAC-Checksums und wie adPEAS v2 Golden, Silver und Diamond Tickets Schritt für Schritt fälscht.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><category>adPEAS</category><category>adPEAS</category><category>Kerberos</category><category>PAC</category><category>Golden Ticket</category><category>Silver Ticket</category><category>Diamond Ticket</category><author>alexander-sturz</author></item><item><title>SEKurity 2.0: Unsere neue Website ist live</title><link>https://blog.sekurity.de/de/blog/website-2-0-relaunch/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/website-2-0-relaunch/</guid><description>Wir haben sekurity.de von Grund auf neu gebaut - eine neue UX/UI auf einem modernen Technologie-Stack, mit viel Zeit und noch mehr Liebe zum Detail.</description><pubDate>Wed, 20 May 2026 00:00:00 GMT</pubDate><category>company</category><category>Company News</category><category>Website</category><category>Web Development</category><category>UX/UI</category><category>Performance</category><author>sekurity-team</author></item><item><title>InSEKurity of the Week (CW20/2026): NGINX Rift -- 18 Jahre alter Heap-Overflow im Rewrite-Modul, unauthentifizierter DoS &amp; moegliche RCE (CVE-2026-42945)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw20-2026-nginx-rift/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw20-2026-nginx-rift/</guid><description>Ein Groessen-Mismatch im NGINX-Rewrite-Modul erlaubt einem entfernten, unauthentifizierten Angreifer einen Heap-Overflow mit einer einzigen praeparierten HTTP-Anfrage -- zuverlaessige Worker-Abstuerze fuer alle, moegliche RCE wenn ASLR aus ist. CVSS 4.0 9.2, oeffentlicher PoC, seit 2026-05-16 aktiv ausgenutzt, ca. 5,7 Mio. exponierte Server</description><pubDate>Tue, 19 May 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>F5</category><category>NGINX</category><category>Web Server</category><category>Heap Buffer Overflow</category><category>Rewrite Module</category><category>DoS</category><category>RCE</category><author>sekurity-team</author></item><item><title>adPEAS v2 Episode 7: Kerberos Internals - Was wirklich auf dem Draht passiert</title><link>https://blog.sekurity.de/de/blog/adpeas-v2-kerberos/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/adpeas-v2-kerberos/</guid><description>Deep Dive in die Kerberos-Protokoll-Internals wie sie adPEAS v2 implementiert: ASN.1-Encoding, Key Derivation, Verschlüsselungsalgorithmen, Nachrichtenstrukturen und warum Angriffe wie Kerberoasting funktionieren.</description><pubDate>Wed, 13 May 2026 00:00:00 GMT</pubDate><category>adPEAS</category><category>adPEAS</category><category>Kerberos</category><category>ASN.1</category><category>Cryptography</category><category>Active Directory</category><category>Security Research</category><author>alexander-sturz</author></item><item><title>InSEKurity der Woche (KW19/2026): Palo Alto PAN-OS User-ID Portal unauthentisierte Root-RCE (CVE-2026-0300)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw19-2026-paloalto-panos-userid-portal/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw19-2026-paloalto-panos-userid-portal/</guid><description>Ein Buffer Overflow im PAN-OS User-ID Authentication Portal erlaubt nicht-authentisierten Angreifern eine Root-Shell auf PA-Series- und VM-Series-Firewalls -- CVSS 9.3, CISA KEV, aktive Ausnutzung durch einen mutmasslich staatlich gesteuerten Cluster (CL-STA-1132)</description><pubDate>Tue, 12 May 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Palo Alto</category><category>PAN-OS</category><category>Firewall</category><category>Buffer Overflow</category><category>Captive Portal</category><category>User-ID</category><category>RCE</category><category>CISA KEV</category><author>sekurity-team</author></item><item><title>adPEAS v2 Episode 6: Offensive Operations - AD manipulieren mit adPEAS</title><link>https://blog.sekurity.de/de/blog/adpeas-v2-offensive-ops/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/adpeas-v2-offensive-ops/</guid><description>Praxis-Guide für die offensiven Funktionen von adPEAS v2: Privilege Escalation, Persistence, Lateral Movement, GPO Abuse, ADCS-Exploitation und Kerberos Ticket Forging.</description><pubDate>Wed, 06 May 2026 00:00:00 GMT</pubDate><category>adPEAS</category><category>adPEAS</category><category>Active Directory</category><category>Privilege Escalation</category><category>Kerberos</category><category>Golden Ticket</category><category>Red Team</category><author>alexander-sturz</author></item><item><title>InSEKurity der Woche (KW18/2026): Linux Kernel &quot;Copy Fail&quot; Privilege Escalation (CVE-2026-31431)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw18-2026-linux-kernel-copyfail/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw18-2026-linux-kernel-copyfail/</guid><description>Ein neun Jahre alter Logikfehler im Linux-Kernel-Modul algif_aead erlaubt jedem lokalen Benutzer einen kontrollierten 4-Byte-Schreibzugriff in den Page Cache jeder lesbaren Datei -- Root, Container-Escape, kein Race Condition, oeffentlicher PoC</description><pubDate>Tue, 05 May 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Linux</category><category>Kernel</category><category>Privilege Escalation</category><category>AF_ALG</category><category>algif_aead</category><category>Container Escape</category><category>CopyFail</category><category>CISA KEV</category><author>sekurity-team</author></item><item><title>adPEAS v2 Episode 5: Output &amp; Reports - Vom Scan zum Bericht</title><link>https://blog.sekurity.de/de/blog/adpeas-v2-output-reports/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/adpeas-v2-output-reports/</guid><description>Wie adPEAS v2 Scan-Ergebnisse in verwertbare Ausgabe verwandelt: farbcodierte Console, interaktive HTML-Reports, inkrementelles Scannen, Offline-Konvertierung und Report-Diff.</description><pubDate>Wed, 29 Apr 2026 00:00:00 GMT</pubDate><category>adPEAS</category><category>adPEAS</category><category>Active Directory</category><category>Reporting</category><category>HTML Report</category><category>Penetration Testing</category><category>Security Tools</category><author>alexander-sturz</author></item><item><title>InSEKurity der Woche (KW17/2026): Windows TCP/IP IPv6 + IPsec RCE (CVE-2026-33827)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw17-2026-windows-tcpip-rce/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw17-2026-windows-tcpip-rce/</guid><description>Kritische Pre-Auth-Race-Condition im Windows-TCP/IP-Stack erlaubt Remote-Codeausfuehrung ueber IPv6 gegen jeden Host mit aktiviertem IPsec -- wormable, ohne Anmeldedaten, ohne Benutzerinteraktion</description><pubDate>Tue, 28 Apr 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Microsoft</category><category>Windows</category><category>TCPIP</category><category>IPv6</category><category>IPsec</category><category>RCE</category><category>Race Condition</category><category>Wormable</category><author>sekurity-team</author></item><item><title>adPEAS v2 Episode 4: Security Checks - Alle Module im Überblick</title><link>https://blog.sekurity.de/de/blog/adpeas-v2-security-checks/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/adpeas-v2-security-checks/</guid><description>Kompletter Überblick über die adPEAS v2 Security-Check-Module: Domain, Accounts, Delegation, Rights, Creds, ADCS, Computer, GPO und Application Checks für Active Directory.</description><pubDate>Wed, 22 Apr 2026 00:00:00 GMT</pubDate><category>adPEAS</category><category>adPEAS</category><category>Active Directory</category><category>Security Checks</category><category>ADCS</category><category>Kerberoasting</category><category>Penetration Testing</category><author>alexander-sturz</author></item><item><title>InSEKurity der Woche (KW16/2026): Windows IKE Extensions RCE (CVE-2026-33824)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw16-2026-windows-ike-rce/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw16-2026-windows-ike-rce/</guid><description>Kritischer Pre-Auth Double-Free in den Windows IKE Service Extensions (IKEEXT.dll) erlaubt entfernten Angreifern Code-Ausfuehrung als SYSTEM ueber UDP/500 und UDP/4500 -- wurmfaehig, oeffentlicher PoC bereits online</description><pubDate>Tue, 21 Apr 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Microsoft</category><category>Windows</category><category>IKE</category><category>IKEv2</category><category>IPsec</category><category>RCE</category><category>Double Free</category><category>Wormable</category><author>sekurity-team</author></item><item><title>adPEAS v2 Episode 3: Authentication Deep-Dive - Von Passwort bis Zertifikat</title><link>https://blog.sekurity.de/de/blog/adpeas-v2-authentication/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/adpeas-v2-authentication/</guid><description>Deep Dive in die adPEAS v2 Authentifizierung: Kerberos-Internals, Pass-the-Hash, Pass-the-Key, PKINIT mit Zertifikaten, Shadow Credentials und Pass-the-Cert via Schannel.</description><pubDate>Wed, 15 Apr 2026 00:00:00 GMT</pubDate><category>adPEAS</category><category>adPEAS</category><category>Active Directory</category><category>Kerberos</category><category>Pass-the-Hash</category><category>PKINIT</category><category>Penetration Testing</category><author>alexander-sturz</author></item><item><title>InSEKurity der Woche (KW15/2026): Cisco IMC Authentication Bypass (CVE-2026-20093)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw15-2026-cisco-imc/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw15-2026-cisco-imc/</guid><description>Kritische Pre-Auth-Schwachstelle im Cisco Integrated Management Controller erlaubt es entfernten Angreifern, beliebige Admin-Passwoerter zurueckzusetzen und die komplette Out-of-Band-Kontrolle ueber UCS-Server zu uebernehmen</description><pubDate>Tue, 14 Apr 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Cisco</category><category>IMC</category><category>UCS</category><category>Authentication Bypass</category><category>Pre-Auth</category><author>sekurity-team</author></item><item><title>adPEAS v2 Episode 2: Unter der Haube - Anatomie eines Scans</title><link>https://blog.sekurity.de/de/blog/adpeas-v2-anatomy-of-a-scan/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/adpeas-v2-anatomy-of-a-scan/</guid><description>Was passiert, wenn adPEAS ein Active Directory scannt? Von Authentifizierung und LDAP-Abfragen bis hin zu kontextabhängigen Severity-Bewertungen und Caching — ein Blick unter die Haube.</description><pubDate>Wed, 08 Apr 2026 00:00:00 GMT</pubDate><category>adPEAS</category><category>adPEAS</category><category>Active Directory</category><category>PowerShell</category><category>LDAP</category><category>Kerberos</category><category>Penetration Testing</category><author>alexander-sturz</author></item><item><title>InSEKurity of the Week (CW14/2026): FortiClient EMS Unauthenticated Remote Code Execution (CVE-2026-35616)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw14-2026-forticlient-ems/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw14-2026-forticlient-ems/</guid><description>Kritische Improper Access Control-Schwachstelle in Fortinet FortiClient EMS als Zero-Day aktiv ausgenutzt - Unauthentifizierter API-Bypass ermoeglicht Remote Code Execution</description><pubDate>Tue, 07 Apr 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Fortinet</category><category>FortiClient EMS</category><category>Remote Code Execution</category><category>Zero-Day</category><author>sekurity-team</author></item><item><title>adPEAS v2 Blog-Serie: Active Directory Sicherheitsanalyse mit adPEAS</title><link>https://blog.sekurity.de/de/blog/adpeas-v2-introduction/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/adpeas-v2-introduction/</guid><description>Einführung in adPEAS v2 — eine komplette Neuentwicklung des PowerShell-basierten Active Directory Analyse-Tools mit nativem Kerberos-Support, null Abhängigkeiten und über 40 Security-Checks.</description><pubDate>Wed, 01 Apr 2026 00:00:00 GMT</pubDate><category>adPEAS</category><category>adPEAS</category><category>Active Directory</category><category>PowerShell</category><category>Kerberos</category><category>Penetration Testing</category><category>Security Tools</category><author>alexander-sturz</author></item><item><title>InSEKurity of the Week (CW13/2026): Cisco Catalyst SD-WAN Manager Authentication Bypass (CVE-2026-20129)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw13-2026-cisco-sdwan-manager/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw13-2026-cisco-sdwan-manager/</guid><description>Kritische Authentication Bypass-Schwachstelle in Cisco Catalyst SD-WAN Manager wird aktiv ausgenutzt - Unauthentifizierter Zugriff mit Netadmin-Rechten möglich</description><pubDate>Mon, 30 Mar 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Cisco</category><category>SD-WAN</category><category>Authentication Bypass</category><category>Zero-Day</category><author>sekurity-team</author></item><item><title>InSEKurity of the Week (CW07/2026): Windows Shell SmartScreen Bypass Zero-Day (CVE-2026-21510)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw07-2026-windows-smartscreen/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw07-2026-windows-smartscreen/</guid><description>Kritische Zero-Day-Schwachstelle in Windows Shell ermöglicht Angreifern das Umgehen von SmartScreen- und Mark-of-the-Web-Schutzmaßnahmen durch einen einzigen böswilligen Klick</description><pubDate>Fri, 13 Feb 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Windows</category><category>SmartScreen</category><category>Zero-Day</category><category>Protection Bypass</category><category>Mark of the Web</category><author>sekurity-team</author></item><item><title>InSEKurity of the Week (CW06/2026): OpenClaw AI Agent 1-Click RCE (CVE-2026-25253)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw06-2026-openclaw/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw06-2026-openclaw/</guid><description>Kritische Schwachstelle in OpenClaw AI Agent ermöglicht Remote Code Execution mit nur einem Klick - Authentication Token Exfiltration durch manipulierte URLs</description><pubDate>Tue, 03 Feb 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>AI Agent</category><category>RCE</category><category>OpenClaw</category><category>1-Click</category><category>Token Exfiltration</category><author>sekurity-team</author></item><item><title>InSEKurity of the Week (CW04/2026): Cisco Unified Communications Manager Zero-Day (CVE-2026-20045)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw04-2026-cisco-unified-cm/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw04-2026-cisco-unified-cm/</guid><description>Kritische Zero-Day-Schwachstelle in Cisco Unified Communications Manager und Webex wird aktiv ausgenutzt - Root-Zugriff durch Code Injection möglich</description><pubDate>Tue, 27 Jan 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Cisco</category><category>Zero-Day</category><category>Code Injection</category><category>RCE</category><category>Webex</category><author>sekurity-team</author></item><item><title>InSEKurity of the Week (CW03/2026): Node.js node-tar Path Traversal (CVE-2026-23745)</title><link>https://blog.sekurity.de/de/blog/insekurity-week-cw03-2026-node-tar/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/insekurity-week-cw03-2026-node-tar/</guid><description>Kritische Path-Traversal-Schwachstelle in node-tar ermöglicht das Überschreiben beliebiger Dateien durch manipulierte Hardlinks und Symlinks in TAR-Archiven</description><pubDate>Tue, 20 Jan 2026 00:00:00 GMT</pubDate><category>cve-bug-bounty</category><category>InSEKurity</category><category>CVE</category><category>Node.js</category><category>Path Traversal</category><category>Supply Chain Security</category><category>npm</category><author>sekurity-team</author></item><item><title>Willkommen im SEKurity Blog</title><link>https://blog.sekurity.de/de/blog/welcome-to-sekurity-blog/</link><guid isPermaLink="true">https://blog.sekurity.de/de/blog/welcome-to-sekurity-blog/</guid><description>Wir stellen unsere neue Blog-Plattform für Security Research, Vulnerability Disclosures, Unternehmensnews und Einblicke in die offensive Cybersecurity vor.</description><pubDate>Wed, 14 Jan 2026 00:00:00 GMT</pubDate><category>company</category><category>Unternehmensnews</category><category>Security Research</category><category>Vulnerability Disclosure</category><author>sekurity-team</author></item></channel></rss>