Printcart (WordPress): File Deletion via CVE-2026-9725
CVE-2026-9725 (CVSS 9.1) in the WordPress plugin Printcart allows unauthenticated deletion of arbitrary files. Update to version 2.5.3.
Novalnet for WooCommerce: Critical Vulnerability (CVE-2026-57677)
CVE-2026-57677 (CVSS 9.8) in the Novalnet plugin for WooCommerce allows unauthenticated store takeover. Update to version 12.10.4.
DokuWiki: Controversial Account Vulnerability (CVE-2026-37106)
CVE-2026-37106 (DokuWiki): Not RCE, but a controversial account creation issue—only when self-registration is enabled (default: disabled). Assessment & Protection.
Cyberdome Germany: National Cyber Defense in the Context of the NIS2 Directive
The Federal Ministry of the Interior is promoting Cyberdome Deutschland as the national response to the NIS2 requirements. An analysis of its objectives and implications.
CVE-2026-11645: Chrome Zero-Day and the Growing Threat of Phishing
INTERPOL reports a rise in cybercrime. At the same time, a Chrome zero-day vulnerability (CVE-2026-11645, CVSS 8.8) that is actively being exploited has come to light. Analysis and protective measures.
NIS2 Registration: BSI Sets Extension Deadline of July 31, 2026
The statutory deadline for NIS2 registration with the BSI expired on March 6, 2026. The BSI has granted an extension until July 31, 2026. Take action now.
CVE-2026-25470: Critical Vulnerability in the WordPress Plugin ACPT (CVSS 10.0)
Analysis of the critical remote code execution vulnerability CVE-2026-25470 (CVSS 10.0) in the WordPress plugin ACPT. Versions up to 2.0.47 are affected. Immediate action is required.
CVE-2026-49109: Critical vulnerability in WordPress plugin for Salesforce
Critical vulnerability CVE-2026-49109 (CVSS 9.8) in the WordPress plugin cf7-salesforce allows PHP object injection. All versions are <= 1.4.3.
Preliminary Scan Without Supplier Consent: Evaluate Suppliers Faster
LocateRisk VRM now allows for a preliminary scan without supplier consent—enabling a quick initial assessment of the external IT security landscape.
CVE-2026-29116: Denial-of-service vulnerability in Dahua products (CVSS 8.7)
Analysis of the critical vulnerability CVE-2026-29116 (CVSS 8.7) in Dahua products. An unauthenticated attack could result in a denial of service. Recommended actions.
CVE-2025-12686: Critical vulnerability in Synology BeeStation (CVSS 9.8)
Analysis of the critical vulnerability CVE-2025-12686 (CVSS 9.8) in Synology BeeStation, which allows unauthenticated remote code execution. Details and measures.
Eliminate shadow IT with LocateRisk MCP & AI | EASM
The identification of unknown infrastructure is a core task in External Attack Surface Management (EASM). LocateRisk provides a specialized interface based on the Model Context Protocol (MCP) for this purpose. LocateRisk is currently the only provider to enable direct machine-to-machine communication, which makes complex detection paths of IT systems immediately analyzable for artificial intelligence.
Cyberattack on Foxconn: A stress test for vendor risk management of global supply chains
What happened? Facts and allegations According to reports, there were IT disruptions from May 1, 2026, primarily affecting the plant in Mount Pleasant, Wisconsin - an important center for the production of AI servers. On May 11, Foxconn appeared on the Nitrogen Group's leak site. The attackers threatened to release over 11 million [...]
BSI C3A: Cloud sovereignty & operational independence
The BSI has presented a list of criteria that defines when a cloud service is considered sovereign. The focus is on data control options, transparency of the service provider and the ability to comply with regulatory requirements.



