Normale Ansicht

Received yesterday — 08. September 2026
Received before yesterday

Stinknormales WLAN kann Menschen in Räumen orten – sogar ohne Smartphone

02. September 2026 um 05:45

Der Beitrag Stinknormales WLAN kann Menschen in Räumen orten – sogar ohne Smartphone erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.

WLAN Überwachung Menschen orten Funkwellen identifizieren

Jeder Router kann zum Überwachungsgerät werden. In einer Studie zeigen Wissenschaftler des KIT, wie sich Menschen allein über das WLAN-Signal identifizieren lassen. Kameras oder elektronische Geräte sind dafür nicht nötig. Die Hintergründe. 

Wissenschaftler des Karlsruher Instituts für Technologie (KIT) haben eine Möglichkeit entdeckt, Personen allein anhand von WLAN-Signalen zu erkennen. Bedeutet: Wer beispielsweise an einem Café mit WLAN vorbeiläuft, kann ganz einfach identifiziert werden.

Personen müssen für eine derartige Identifikation kein Smartphone oder Tablet bei sich tragen. Wie das KIT in der entsprechenden Pressemitteilung schreibt, reiche es aus, dass WLAN-Geräte in der Nähe miteinander kommunizieren.

Keine besondere Hardware notwendig

Möglich ist das aufgrund von sogenanntem Beamforming. Die Technik gibt es seit WiFi 5. Statt das Funksignal gleichmäßig in alle Richtungen abzustrahlen, bündelt der Router es gezielt in Richtung der verbundenen Geräte. Das verbessert Reichweite und Tempo. Allerdings liegt genau da das Problem.

Denn damit der Router weiß, wohin er senden muss, melden sich Geräte regelmäßig zurück und liefern Informationen darüber ab, wie das Signal bei ihnen ankommt. Diese Rückmeldungen heißen „Beamforming Feedback Information“, kurz BFI. Laut KIT werden diese Infos unverschlüsselt übertragen und sind damit auch für Dritte lesbar.

Anders als bei Angriffen mit LIDAR-Sensoren oder bisherigen WLAN-basierten Methoden, die Channel State Information (CSI) nutzen – also Messdaten darüber, wie sich ein Funksignal durch Wände, Möbel oder Personen verändert –, benötigen Angreifende keine Spezialhardware. Die Methode funktioniert mit handelsüblichen WLAN-Geräten.

WLAN-Router als „stille Beobachter“

Per BFI entstehen Bilder aus verschiedenen Blickwinkeln, die zur Identifikation der Personen dienen können. Dieser Prozess dauert nur wenige Sekunden, sobald das dahinterstehende Machine-Learning-Modell trainiert ist. Das WLAN wird auf diese Weise zum erheblichen Risiko für die Privatsphäre.

„Wir beobachten die Ausbreitung der Radiowellen und können so ein Bild der Umgebung und von Personen erzeugen”, erklärt Cybersicherheitsexperte Thorsten Strufe vom KASTEL, dem Institut für Informationssicherheit und Verlässlichkeit des KIT.

Das funktioniert ähnlich wie bei einer normalen Kamera, nur dass diese Lichtwellen statt Radiowellen in ein Bild umwandelt. Es ist deshalb auch unerheblich, ob jemand ein WLAN-Gerät bei sich hat oder nicht.

Jeder WLAN-Router ein potenzielles Überwachungsgerät

Mit ihrer Forschung wollen die Wissenschaftler vor Risiken für die Privatsphäre warnen. Denn: „Die Technik macht aus jedem Router ein potenzielles Überwachungsgerät“, so Julian Todt vom KASTEL. Auch das Abschalten des WLANs schützt nicht. Es reicht schon aus, wenn andere Geräte in der Umgebung aktiv sind.

Wer regelmäßig an einem Café mit WLAN vorbeigeht, könnte dort unbemerkt identifiziert und später wiedererkannt werden – etwa von staatlichen Stellen oder Unternehmen.

Zwar gebe es für Geheimdienste oder Cyberkriminelle einfachere Methoden, Menschen zu beobachten. So beispielsweise durch den Zugriff auf Überwachungskameras oder Video-Türklingeln.

Allerdings könnten die allgegenwärtigen Drahtlosnetzwerke zu einer nahezu flächendeckenden Überwachungsinfrastruktur werden. Immerhin gibt es WLAN heutzutage in fast allen Wohnungen, Büros, Restaurants und öffentlichen Räumen.

Für Privatpersonen geht das Risiko über die reine Wiedererkennung hinaus. Die Forschung zu BFI-Sensing hat sich inzwischen weiterentwickelt: Eine Arbeit in den IEEE Transactions on Mobile Computing zeigt, dass sich damit auch Tastatureingaben mehrerer Personen rekonstruieren lassen.

Fast 100 Prozent: So identifiziert WLAN Menschen

Um ihre Hypothese zu testen, ermittelten die Wissenschaftler die Identitäten einer Gruppe von Testpersonen. Von insgesamt 197 Teilnehmern konnte das Forschungsteam Personen mit 99,5 Prozent Genauigkeit erkennen. Persönliche Merkmale wie die Gangart oder ein bestimmter Blickwinkel waren dabei irrelevant.

Die Forscher des KIT befürchten, dass die Technik besonders in autoritären Staaten zur Gefahr für Grundrechte und Privatsphäre werden könnte. Dort ließe sie sich beispielsweise zur Überwachung von Protestierenden einsetzen. In ihrem wissenschaftlichen Artikel fordern die Wissenschaftler deshalb Schutzmaßnahmen.

Sie richten sich beispielsweise an den WLAN-Standard IEEE 802.11bf, der WLAN-Sensing offiziell regelt. Er wurde bereits am 26. September 2025 veröffentlicht und ist eine Erweiterung des bestehenden WLAN-Standards. Ob die vom KIT geforderten Maßnahmen darin enthalten sind, geht aus öffentlichen Angaben allerdings nicht hervor.

Weitere Angriffe, kaum Schutz

Wie ernst das Problem ist, zeigen auch andere Forschungsarbeiten. So stellte ein Forschungsteam auf dem Sicherheitssymposium NDSS 2025 einen verwandten Angriff namens LeakyBeam vor. Er wertete ebenfalls unverschlüsselte BFI-Pakete aus.

Neben den Warnungen gibt es auch Lösungsvorschläge: Die NDSS-Autoren schlagen beispielsweise vor, entweder die BFI-Daten zu verschleiern. Das würde nur minimale Hardwareänderungen erfordern. Eine andere Option wäre, die Pakete per WPA3 zu verschlüsseln. Diese Variante wäre wirksamer, würde allerdings Firmware-Updates auf allen WLAN-Geräten weltweit nötig machen.

Nutzern bleibt damit wenig Handlungsspielraum. Das eigene WLAN abzuschalten hilft nicht, weil fremde Geräte in der Umgebung genügen, um Personen zu identifizieren.

Auch der Verzicht auf Smartphone oder Laptop bringt nichts, da für die Identifikation kein eigenes Gerät nötig ist. Wirksamer Schutz müsste also im Standard selbst verankert sein oder von den Herstellern per Update nachgereicht werden.

Auch interessant: 

Der Beitrag Stinknormales WLAN kann Menschen in Räumen orten – sogar ohne Smartphone erschien zuerst auf BASIC thinking. Folge uns auch auf Google News und Flipboard oder abonniere unseren Newsletter UPDATE.

Russian hacker faces up to 20 years in prison, following extradition and indictment over US phishing campaign that allegedly infected 80,000 PCs — hacker stole victims' data via remote access

02. September 2026 um 16:22

A federal grand jury in California has indicted Russian citizen Searzhudin Tamirlanovich Aktulaev for allegedly conducting phishing attacks that stole data from over 80,000 computers between June 2016 and November 2017, using TVRAT and DarkVNC remote-control malware. Detailed in a Department of Justice press release on September 1st, the indictment — filed in June 2021 and released September 2026 — lists charges of “Conspiracy, Transmission of a Program, Information, Code, and Command to Cause Damage to a Protected Computer, and Aggravated Identity Theft, among other offenses.”

Aktulaev was extradited to the U.S. in August 2026, five years after his arrest in Cyprus in May 2021. He made his first appearance in federal court in San Francisco — after which he was remanded to federal custody — and is scheduled to appear in district court on October 5, 2026. The arrest was made after an FBI investigation, and the case is being prosecuted by the National Security, Cyber, and Special Prosecutions Section.

According to the indictment, Aktulaev “conspired to exploit the online message platform of a well-known freelance employment technology company, located in the Northern District of California, to spread malware to approximately 80,000 freelancers”. He sent messages containing malicious Microsoft Excel attachments, using approximately 255 fake user accounts. Once opened, the attachments prompted users to run a macro that then downloaded malware from the Internet, mirroring a hack earlier this year in which an unofficial 7-zip.com website served malware-laden downloads for over a week.

The attack used TVRAT (TeamViewer Remote Access Trojan) and DarkVNC malware, both of which grant the attacker remote control of the infected system. TVRAT exploits TeamViewer, while DarkVNC exploits VNC Viewer, popular remote administration tools. The malware stole and uploaded data from the victims' computers to a command-and-control server, from which Aktulaev and his co-conspirators extracted the stolen data to “commit fraud and other criminal activities”.

The indictment says thousands of computers infected by the TVRAT malware were “calling back” to a command-and-control domain hosted in the United States, which was paid for using virtual currency. Roughly half of the victims were in the United States, many of whom were Northern District of California residents, according to the indictment.

“A database found on the command-and-control domain revealed thousands of victims. Additionally, a shared document on the email account used in the criminal activities contained information to include e-commerce login credentials, as well as personally identifiable information (“PII”) for hundreds of victims,” the press release said.

If convicted, Aktulaev could spend up to 20 years behind bars and pay a $250,000 fine or twice the total illicit gains for the conspiracy to commit wire fraud charge alone. The other charges carry terms ranging from two to twenty years in prison, in addition to fines. Meanwhile, the FBI is currently investigating another hack in which 153 million US and Canadian drivers’ licenses were leaked on a Russian cybercrime forum.

FBI investigating 153 million US and Canadian driver’s licenses leaked on Russian cybercrime forum, including that of US SecDef Pete Hegseth — data is suspected to have come from an ID-authentication service provider

More than 153 million US and Canadian driver’s licenses, as well as other identity documents, have reportedly become available for purchase on the dark web for a limited time. According to cybersecurity journalist Brian Krebs, the service was called Nexus, and although it’s no longer available at the time of writing, it claimed to have possessed 153 million driver’s licenses, 10 million ID cards, 1.9 million travel documents, 1.3 million international driver’s licenses, 579k medical cards, 429k common access cards, 91k residence cards, 77k employment authorization records, and 5 million other documents, allegedly sourced from an ID-authentication service based in Louisiana.

The service was advertised on the Russian cybercrime forum Exploit, where whoever was promoting it posted the driver’s license of Krebs as a free sample, which caught the journalist’s attention. He was also able to see a preview of U.S. Secretary of Defense Pete Hegseth’s information on the database — a concerning breach of security for someone with such a sensitive position in the government. After further investigation, they concluded that the service seemed to have possessed legitimate data, especially after searching for the data of several of his friends and family members with their consent. One thing that all the people he found in the database had in common was that they all used Hertz to rent a vehicle.

Krebs also talked with security and privacy researcher Zach Edwards, who said that their information was also found on Nexus. Edwards said that they did not rent a car recently but used their ID at a Planet13 marijuana dispensary. The time stamps found on the scanned images of the driver’s licenses and other identity documents coincide with the time that the victims used their IDs at the said companies, confirming that they were the sources of the leaks. However, Planet13 and Hertz do not do their own authentication; instead, they contract a service provider for the service. Now, it turns out that both Planet13 and Hertz used the company for identity verification and ID-authentication — IDScan.

Based on the evidence gathered by Krebs, it seems that the leak is centered around the company. He has already contacted the company about the issue, and they said they were investigating the matter. “At this point I’m not able to share any additional information, but the updates you have provided have been welcome, and helpful to our team’s investigation,” Jillian Kossman, a marketing and operations leader at idscan.net, told the journalist. The FBI has also started looking into the leak, with its New Orleans field office opening an official investigation into the breach.

The massive amount of data that was briefly available on the dark web is certainly concerning. A similar data breach hit Discord after its third-party service provider was hit and resulted in the exposure of 70,000 government IDs. Incidents like these have got privacy experts concerned with the push for online age verification requirements, which is why the EFF is asking the California governor to veto the law requiring this.

Aside from privacy-invasive checks and stepping on First Amendment rights, the leakage of sensitive data like this could increase incidents of stolen identity and more. Driver’s licenses are often widely accepted for opening credit lines and bank accounts, with both photographic, UV, and IR scans available on many of the leaked licenses. Aside from that, it could also potentially compromise the privacy and security of vulnerable people, like those fleeing domestic violence and those who are under the witness protection program.

Claude-KI im Visier: Malware stiehlt Sitzungen und leert Konten

01. September 2026 um 14:34
Anthropic, Claude, Claude AI Das KI-Unternehmen Anthropic sperrt derzeit zahlreiche Nutzerkonten seines Textgenerators Claude wegen massiver Cyberangriffe. Kriminelle nutzen gestohlene Sitzungs-Cookies, um teure Nutzungskontingente auf Kosten der Opfer zu verbrauchen. (Weiter lesen)

BlindLock hides your password manager and secure vault in a PNG image — also offers secure notes, 2FA, and a crypto address book, with optional hardware security keys

01. September 2026 um 13:45

A new local‑only password manager, notes app, and secure vault that hides your secrets in an ordinary-looking .PNG image file is now available. BlindLock does all this and more with an option to bind to your hardware using TPM2.0, Secure Enclave, or StrongBox. No cloud storage or central vault account is required, and the dev is selling lifetime licenses at $49 (for now). There is an interactive online demo, with nothing uploaded or downloaded, as well as a downloadable full 7-day demo available.

BlindLock’s solo developer David Domingo indicates that one of the main drivers behind his efforts to create this application was the theft of customer vault backups from LastPass in late 2022. What happened to LastPass could have also happened to 1Password, Dashlane, even Proton Pass, reckons Domingo. “When your vault sits on someone else's server, you inherit every risk that server carries: employee access, infrastructure vulnerabilities, government subpoenas, supply chain attacks, and the simple mathematical reality that a server holding tens of millions of vaults is a far more attractive target than your laptop,” says the BlindLock dev on his blog.

BlindLock

(Image credit: BlindLock)

So, three independent layers of security apply to your BlindLock vault. It is invisible in its ordinary-looking PNG carrier, not just encrypted. BlindLock doesn’t run a central vault database, so there is nothing for attackers to steal from BlindLock servers and crack later. Your resting vault file uses 256-bit authenticated encryption and already includes NIST post-quantum components. It is also bound to your device. “The vault opens only when three things match: the carrier file, your master password and your authorized device,” asserts the BlindLock app page. “A copied file alone is not enough to gain access.”

BlindLock’s feature set is pretty broad for a new offering. Fully encrypted inside your chosen .PNG holiday snap or cat photo is a password manager, Markdown-supporting secure notes, a built-in 2FA authenticator, and an encrypted file vault (for any type of file), and there is support for an optional fourth-factor security key like a YubiKey or Google Titan, etc.

Accessing your BlindLock data requires three things at once: the carrier file, your master password, and the authorized device - the vault key is sealed to that device's security chip, which is TPM 2.0, Secure Enclave, or StrongBox depending on the platform. You can avoid overly bloating your central .PNG file by squirreling larger files separately in their own encrypted containers. BlindLock employs a hidden volumes system not unlike VeraCrypt for these containers. Domingo admits these are “not magically unfindable,” but are Argon2id-hardened, 256-bit authentication-encrypted and stored inconspicuously. For device loss or migration, users must create an encrypted BlindLock backup and keep its recovery phrase separately.

BlindLock

Online demo screenshot (Image credit: BlindLock)

As per the intro, BlindLock is being introduced as a one-time $49 purchase. This perpetual pricing plan only applies to the first 1,000 licenses. There will be three waves: “the first 100 at $49, the next 350 at $89, and the final 550 at $109. After that, BlindLock is subscription-only,” says Domingo. The independent dev wants to lay a solid financial foundation, so development of BlindLock can continue.

This article is merely sharing the news about BlindLock and shouldn't be taken as a recommendation. Please check out the online and downloadable demos and judge whether it works for you and offers the features you want for the price.

Security researchers find surveillance implants in Chinese-made routers sold worldwide — three different backdoor-like implants hidden in firmware

28. August 2026 um 16:13

Security researchers have found three different backdoor-like implants hidden in firmware for routers manufactured by Shenzhen Zhibotong Electronics, better known as ZBT. The hardware is sold around the world under a bewildering array of brands, meaning you may not even realize you're using a ZBT router. The research, published by security firm VulnCheck, began with a Zbtlink AX3000 router. Researchers found that its firmware contained an implant that they dubbed ENDLESSDOORS, as it automatically phones home to a command-and-control server and can execute arbitrary commands as root.

ENDLESSDOORS is essentially a remote-control system embedded directly into the router's firmware. It starts automatically at boot and disguises itself as a normal Linux kernel process called kworker. The router periodically connects to a hard-coded server and announces itself. There's no meaningful authentication or encryption involved. Commands received from the server are passed directly to a shell running as root, and the implant can also establish an interactive root shell.

VulnCheck demonstrated the problem by impersonating the command server and taking control of its own test router. In other words, this isn't merely a theoretical vulnerability; if an attacker can hijack the connection to the implant's command server, they can obtain complete control of the router. The researchers found ENDLESSDOORS embedded in firmware for 20 ZBT models, including the Z8102AX, WG3526, WE826-T3-DSIM, and several other cellular routers. The same hardware is also sold under other names because ZBT manufactures routers for OEM and ODM customers. VulnCheck assigned the issue CVE-2026-66747, with a CVSS score of 9.3, but that wasn't the end of the investigation.

A photograph of the Deep Orange 4G/LTE Router, which is a rebranded ZBT device.

The label on the Deep Orange 4G/LTE Router that VulnCheck purchased from a US Amazon seller clearly marks its as a rebranded ZBT device. (Image credit: VulnCheck)

VulnCheck subsequently bought an $88 Deep Orange cellular router from a US seller on Amazon and discovered that it was actually a white-labeled ZBT-WE826-T2. Its 2019 firmware was too old to contain ENDLESSDOORS, but instead, it contained two other implants that the firm designated DARKLANTERN and SPEAKINGSTONE.

DARKLANTERN is the particularly straightforward one. Operating as the infosrvd service, it opens a listener on the WAN via UDP port 9992 and accepts commands directly from the Internet without authentication. An attacker only needs to send a fixed 19-byte info probe to force the router to reveal identifying information like its model, firmware version, MAC address, and uptime.

Researchers found that the backdoor's meager security mechanisms could be trivially bypassed: its command payload checksum relies on a static, hardcoded salt ("mqonu.com"), and its internal MAC address filter can be entirely circumvented simply by submitting a MAC field of all zeroes. This allows any remote attacker to easily forge a packet and execute arbitrary commands as root. VulnCheck scanned the Internet and found 203 exposed DARKLANTERN instances in 22 countries, spread across 16 router models.

A diagram showing the surveillance architecture of the DARKLANTERN and SPEAKINGSTONE malware.

This diagram shows the surveillance architecture of the DARKLANTERN and SPEAKINGSTONE vulnerabilities. (Image credit: Vulncheck)

Meanwhile, SPEAKINGSTONE works differently and is even more concerning. Rather than waiting for an attacker to connect to a listening port, it runs as the yunmgrd service and periodically beacons outbound to ZBT's command-and-control infrastructure over UDP port 10000. That makes it useful even when the router sits securely behind NAT or a firewall, as it relies on a custom format dubbed "zbtProtocol" to push full device fingerprints directly to the remote server. SPEAKINGSTONE is also considerably more capable than simply providing a remote shell. According to VulnCheck, its command protocol allows remote operators to execute arbitrary commands, steal WAN PPPoE credentials, rewrite a DNS hijack list, and establish a reverse SSH tunnel.

The researchers also discovered a backup command server domain embedded in the malware that nobody had registered, so naturally, they registered it themselves. VulnCheck set up a server capable of speaking SPEAKINGSTONE's protocol at the newly registered "www.findmyipaddr.com" and watched the infected routers start calling home.

By August 21st, 392 unique devices had connected to the sinkhole. Fully 390 of those 392 were located in China, with the vast majority using China Mobile's network. Most of those devices were the same router model running the same firmware, suggesting a large-scale carrier deployment rather than random consumer infections. VulnCheck describes this particular deployment as "domestic Chinese surveillance technology."

An infographic showing the global scan results of the DARKLANTERN backdoor, with the majority of infections found in the US.

(Image credit: VulnCheck)

Now, that doesn't mean every ZBT router is a Chinese surveillance device. VulnCheck found ZBT hardware being sold under numerous independent brands worldwide, including Lippert Components, Wave WiFi, OneX in Australia, MoFI Network in Canada, Digineo in Germany, and more. Vulncheck explicitly notes that some of the firmware they examined did not contain the implants. The problem is that ZBT's OEM business makes the hardware's origin surprisingly difficult to identify. The same underlying platforms have appeared under brands including WiFlyer, Deep Orange, Cioswi, CroSkylink and KuWFi, among others.

So the really unsettling part isn't that VulnCheck found three vulnerabilities in an obscure router. It's that these aren't conventional vulnerabilities where someone accidentally forgot to bounds-check a buffer. These are pieces of software deliberately included in the router firmware that provide remote access to the device. We would normally call this malware, but ZBT has described ENDLESSDOORS as an after-sales technical-support mechanism.

VulnCheck's counterargument is pretty compelling; the firm says that whatever its intended purpose, the mechanisms don't securely authenticate the party controlling them. An attacker who can hijack the communications can potentially exercise the same privileges, and because ZBT hardware is frequently sold under other brands, simply not buying something with “ZBT” printed on the box isn't necessarily enough.

If you own one of the affected devices, of which you can find a list at VulnCheck's blog entries for the vulnerabilities (ENDLESSDOORS and the other two), the only real solution is to simply replace it, because the security holes were installed at the factory; it's not as if installing a different firmware version is going to restore trust. Even if your device isn't listed, for anyone running a cheap cellular router, travel router, RV router, or other piece of networking hardware from an obscure OEM, you need to keep in mind that the brand on the plastic probably isn't the company that wrote the firmware, and the fellow who wrote the firmware may not share your values with regard to freedom or privacy.

US Justice Department seizes domains it says Chinese state-sponsored hackers used to infiltrate systems at NASA, Senate, Federal Reserve, and more — FBI moves forward with domain seizures

26. August 2026 um 17:49

The U.S. Department of Justice and FBI revealed in a statement Wednesday that it had seized domains related to platforms that it claims were operated by China state-sponsored hackers. The press release says the Federal Reserve, Department of Energy, Department of Justice, Department of Health and Human Services, NIH, NASA, and U.S. Senate all experienced "computer intrusion activity."

The Justice Department says a state-sponsored group known as QTFY is responsible for the intrusion, which the U.S. government claims came to be through two pieces of malware: QTRouter and QScan. The release says the People's Republic of China (PRC) Ministry of State Security was among QTFY's paying customers.

According to the U.S. government, QScan "scans and automatically infects thousands of [IoT] devices worldwide." Those devices are then added to the QTRouter network. It's a botnet, but the Justice Department also calls it an "obfuscation layer" to mask the origin of malicious traffic. QTFY's system has been used to compromise U.S. critical infrastructure since 2018, according to the affidavit.

The group is said to be employed by the Nanjing Xinjiuwei Network Technology Company, which we were unable to find any information on.

As part of the action, the Justice Department seized three domains: qtproxy.xyz, qt-proxy.org, and qt-team.com. Those domains now show the seizure notice you can see below.

U.S. domain seizure notice.

(Image credit: Tom's Hardware)

The investigation into the group began as early as 2019, when the FBI looked into a system intrusion at NASA related to the CVE-2019-11510, which was subsequently patched. The FBI traced the activity back to two Gmail accounts and a phone number with a +86 country code (the code for the PRC).

The group allegedly rented infrastructure from commercial platforms, leading to a series of abuse complaints to the emails by hosting provider Hostwinds. The FBI says the group obtained the three domains it seized between 2022 and 2024, registering them with domain registrar Namecheap and paying through PayPal.

Although the PRC routinely denies hacking activities in the U.S., Chinese officials reportedly acknowledged that the government was behind a series of attacks on U.S. infrastructure late last year. In 2024, 30-year-old wiretap systems deployed by the U.S. government in telecom and internet providers were reportedly compromised by Chinese attackers.

AliExpress allegedly uses your browser's audio system to fingerprint your PC — hidden code runs even when no sound is playing

Chinese multinational tech giant Alibaba has been accused of tracking web users after a developer discovered its global online marketplace running hidden audio processes that could be used for sophisticated audio fingerprinting. While investigating an issue with his wireless headphones, Matt Callaghan found that opening an AliExpress webpage in Firefox or Chrome interfered with the multipoint Bluetooth audio feature.

As Callaghan explains in his blog post, “Normally the PC takes priority playing audio, with my phone being able to play audio when nothing is playing on the PC. Usually I listen to music on my phone but with notifications or YouTube playing through the PC.” However, shortly after loading the AliExpress homepage, audio from his phone would stop playing, despite no media playing on his PC. Closing the AliExpress tab immediately fixed the issue, while muting the tab, browser, or Windows did not seem to resolve it.

Their investigation began by inspecting various conventional media elements; however, he did not find any unusual activity. He also zeroed in on the fact that the problem would not begin immediately, but rather after the webpage had been sitting idle for a few seconds. He then moved on to inspect the Web Audio API to wrap the AudioContext constructor so that it would record whenever a page created an audio-processing context. They additionally wrapped AudioNode.prototype.connect() to see whether anything was connected to the context's audio destination.

Eventually, Callaghan found that the page was loading two suspicious scripts named collina.js and fireyejs.js, which appeared to be part of Alibaba's browser security and anti-abuse tooling. With some help from AI during his research, he found that the scripts built a Web Audio graph using a sawtooth oscillator to generate a waveform. An analyzer then measured the results after they passed through the browser's audio implementation, while another script read the resulting frequency data. The scripts also set the volume gain to zero, meaning there was no audible sound or noise, even though the browser continued actively processing the Web Audio graph.

Unlike autoplaying videos, there is no media element playing, which is why the browser's tab mute control does not help. However, the webpage continues performing live audio processing, keeping the Bluetooth audio path active and preventing multipoint Bluetooth headphones from switching between devices. Further investigation also uncovered code collecting information related to screen dimensions, device memory, browser plugins, WebGL rendering, supported audio and video formats, browser performance, mouse events, and more. The scripts also appear to serialize and encrypt the collected data before sending it to Alibaba's telemetry services using fetch() or sendBeacon() functions.

Following the discovery, Firefox said on X that its browser includes built-in protections against fingerprinting. The company pointed to a blog post explaining that Firefox 118, released in September 2023, introduced additional protections against Web Audio-based fingerprinting. Brave also claims to block audio fingerprinting by default. According to the browser maker, it does this by injecting randomized data into the browser's audio output, making the fingerprint appear different to websites and resetting the data between sessions.

Für Europa: Fraunhofer und SAP wollen US-Cloud-Anbieter austricksen

13. August 2026 um 19:50

Der Beitrag Für Europa: Fraunhofer und SAP wollen US-Cloud-Anbieter austricksen erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.

Cloud-Edge-computing USA Europa Clouds Unabhängigkeit Souveränität

Europäische Unternehmen hängen bei der digitalen Infrastruktur stark von US-Konzernen ab. Eine neue Open-Source-Architektur hinter Cloud Edge Computing soll nun die Wende einleiten und die Datenverarbeitung direkt vor Ort ermöglichen. Damit könnte eine unabhängige und nachhaltige digitale Infrastruktur in greifbare Nähe rücken. 

Ein Blick auf die Internetinfrastruktur offenbart ein klares Bild: Wir in Europa zeigen eine deutliche Abhängigkeit von US-Konzernen, wie Amazon, Google oder Microsoft. Allein diese Anbieter verwalten etwa 70 Prozent der europäischen Infrastruktur. Im Resultat ist aber nicht immer ganz klar, wohin die Daten europäischer Bürger und Firmen fließen.

Eine Lösung des Problems könnten dezentrale Netzwerke sein. Derzeit entwickeln das Fraunhofer-Institut für Software- und Systemtechnik ISST und für Angewandte und Integrierte Sicherheit AISEC sowie SAP im Rahmen der EU-Initiative IPCEI-CIS eine Architektur (ApeiroRA), die zentrale Rechenzentren mit genau diesen dezentralen Netzwerken vereinen soll. Das könnte dann so aussehen, dass die Verarbeitung von Informationen innerhalb der Rechenzentren in sogenannten Cloud Edges erfolgt.

Was ist Cloud Edge Computing?

Bei Cloud Edges handelt es sich um dezentrale Rechenknoten, die Cloud-Dienste physisch näher an ihre Nutzer bringen. Denn das ermöglicht die Datenverarbeitung vor Ort und reduziert Latenzzeiten teils drastisch. In den Cloud Edges erfolgt die Analyse von Informationen in Echtzeit, während die Cloud weiterhin als zentraler Speicher dient.

Und hier besteht in Europa großes Potenzial. Denn solche Cloud Edges könnten etwa direkt im Turmfuß eines Windrads oder auf einem beliebigen lokalen industriellen Betriebshof entstehen. Heinrich Pettenpohl, Abteilungsleiter für IT Service Providers am Fraunhofer ISST, fasst zusammen:

Im globalen Markt für Public-Cloud-Dienste hat Europa den Anschluss verloren. Im Bereich von Cloud Edge Computing ist das nicht der Fall. Daher verfolgt die EU-Kommission die Strategie, dezentrale, kleinere Rechenzentren, sogenannte Cloud Edges, zu fördern, sodass europäische Unternehmen direkten Zugriff haben und ihre Daten dort ablegen können.

Das Projekt hat auch die Nachhaltigkeit im Blick. Denn digitale Arbeitslasten sollen laut Angaben dynamisch an diejenigen Standorte verlagert werden, an denen im jeweiligen Moment ausreichend Ökostrom zur Verfügung steht.

Offene Standards für europäische Unternehmen

Für Unternehmen und Behörden bringen die offenen Schnittstellen weitere Vorteile. In sich isolierte Insellösungen sollen dann nämlich der Vergangenheit angehören. Denn der neue Ansatz soll erstmals eine besonders hohe Flexibilität und Interoperabilität bieten. Eine strikte Bindung an nur einen Anbieter findet dann nicht mehr statt.

Die Fraunhofer-Institute beschreiben auch konkrete Zukunftsszenarien. Intelligente Systeme könnten etwa zur Optimierung des eigenen Ressourcenverbrauchs digitale Zwillinge simulieren. Durch die Auswahl der besten Simulation ließe sich im Resultat dann die optimale IT-Konfiguration finden. Eine autonome Fehleranalyse und KI-gestützte Betriebsführung sollen Administrationsaufwände deutlich reduzieren.

Für die unabhängige Weiterentwicklung übergaben die Projektpartner ihre zentralen Ergebnisse an die NeoNephos Foundation. Diese ist Teil der Linux Foundation Europe und soll bald die komplexe Architektur schrittweise in konkrete Lösungen und Piloten überführen. Dabei sind höchste Sicherheitsstandards unverzichtbar, um die Informationen vor unbefugten Zugriffen zu schützen. Im besten Fall entsteht also eine übertragbare Lösung, die Europa mehr Unabhängigkeit, Transparenz und eine langfristige Wettbewerbsfähigkeit ermöglicht.

Auch interessant:

Der Beitrag Für Europa: Fraunhofer und SAP wollen US-Cloud-Anbieter austricksen erschien zuerst auf BASIC thinking. Folge uns auch auf Google News und Flipboard oder abonniere unseren Newsletter UPDATE.

SoSafe Virtual Academy 2026: Digitale Resilienz beginnt beim Menschen

06. August 2026 um 09:30

Der Beitrag SoSafe Virtual Academy 2026: Digitale Resilienz beginnt beim Menschen erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.

SoSafe Virtual Academy 2026

Wenn Angreifer KI nutzen, um Täuschungen zu perfektionieren, reicht „mehr Technologie“ allein nicht mehr aus. Entscheidend ist, wie Organisationen entscheiden, reagieren und wie konsequent sie menschliche Risiken steuern. Genau hier setzt die kostenfreie SoSafe Virtual Academy 2026 an: ein kompaktes Online-Event für alle, die Cyber-Resilienz strategisch denken.

Die zweite Jahreshälfte 2026 startet für viele Security-Teams mit einem paradoxen Mix: Im Kalender ist Luft, in der Bedrohungslage nicht. Phishing, Social Engineering und KI-gestützte Angriffe machen keine Sommerpause. Gleichzeitig steigt der Druck von außen: durch Compliance-Anforderungen wie NIS2, durch steigende Erwartungen an Incident Response und durch die Frage, wie Security im Board wirklich Priorität bekommt.

Die SoSafe Virtual Academy 2026 bringt diese Themen auf den Punkt, als fokussiertes, virtuelles Sommer-Forum für digitale Resilienz und adaptive Abwehr. Das Event findet am 18. August 2026 von 09:05 bis 12:00 Uhr statt und ist kostenfrei zugänglich. Zielgruppe sind CISOs, IT- und Security-Verantwortliche, Führungskräfte sowie Akteure aus dem öffentlichen Sektor.

Warum Human Risk Management zur Sicherheitsstrategie gehört

In vielen Organisationen wird Cybersecurity noch immer zu stark als Technologieprojekt betrachtet: Tools einführen, Policies schreiben, Systeme härten. Das bleibt wichtig, aber es löst nicht das Kernproblem, das Angreifer seit Jahren ausnutzen: Menschen treffen Entscheidungen unter Zeitdruck, lassen sich durch glaubwürdige Geschichten täuschen oder umgehen Prozesse, wenn sie als Bremsklotz erlebt werden.

Human Risk Management zielt darauf, dieses Risiko nicht nur mit Awareness-Schulungen „abzudecken“, sondern es messbar zu machen, zu priorisieren und in die Sicherheitssteuerung zu integrieren. Genau diese Perspektive – Verhalten, Kultur, Führung und Entscheidungsfähigkeit – ist ein roter Faden der Academy. Und sie passt zu einer Realität, die viele CISOs kennen: Selbst die beste technische Verteidigung verliert an Wirkung, wenn Meldewege unklar sind, die Belegschaft nicht mitzieht oder Krisenprozesse nur auf Papier existieren.

Kostenfrei zur SoSafe Virtual Academy anmelden

Die Agenda der SoSafe Virtual Academy 2026

SoSafe setzt bei der Virtual Academy auf ein Format, das der Realität von Security-Verantwortlichen entgegenkommt: kompakt, thematisch fokussiert und mit Raum für konkrete Takeaways. Neben einer Eröffnungs-Keynote und Recaps gibt es parallele Deep-Dive Sessions sowie interaktive Workshops & Masterclasses. Dadurch lässt sich der Vormittag wie ein kuratierter Strategie-Sprint nutzen, statt wie eine Konferenz, die vor allem „Input“ produziert.

Ein Blick in die Programmpunkte zeigt, wie breit das Spektrum ist und wie konsequent die Academy den Faktor Mensch mit Governance und operativer Resilienz verbindet:

  • Incident Response & Krisenmanagement: Warum Vorbereitung lange vor der Krise beginnt, inklusive mentaler Resilienz unter Entscheidungsdruck.
  • Security Leadership: Wie CISOs Security-Themen im Board platzieren und Entscheidungsräume sichern.
  • Public Sector Best Practice: Wie Behörden verpflichtende Awareness-Schulungen mit hoher Abschlussquote umsetzen, ohne Eskalationsprozesse.
  • NIS2 & Human Risk Management: Wie sich regulatorische Anforderungen mit einer ganzheitlichen, menschenzentrierten Sicherheitsstrategie verbinden lassen.
  • Mentale Widerstandskraft: Praktische Übungen für Stressregulation und Fokus als Teil digitaler Resilienz.

NIS2: Compliance ist kein Projektplan, sondern Betriebsmodus

NIS2 hat den Ton in vielen Organisationen verändert: Cybersecurity wird zur Managementaufgabe mit Nachweispflichten, Meldewegen und überprüfbaren Maßnahmen. Die Herausforderung liegt dabei nicht nur in technischen Kontrollen, sondern in der Fähigkeit, Risikomanagement, Verantwortlichkeiten und Schulungs- bzw. Enablement-Maßnahmen dauerhaft in den Betrieb zu überführen.

Genau deshalb ist die Klammer aus NIS2, Cyber-Resilienz und Human Risk Management so praxisrelevant. Wer NIS2 rein über Dokumentation und Tooling betrachtet, läuft Gefahr, am Ende zwar formale Anforderungen abzuhaken, aber im Ernstfall trotzdem in eine Entscheidungs- und Kommunikationskrise zu rutschen. Ein ganzheitlicher Ansatz verbindet dagegen Governance, Kultur und konkrete Verhaltensänderung und damit die Fähigkeit, schneller zu erkennen, zu melden und zu reagieren.

Diese Speaker sind dabei: Von CISO-Praxis bis Adversarial AI

Für Tiefe sorgt eine Speaker-Liste, die sowohl Strategie als auch operative Erfahrung abdeckt: Dr. Niklas Hellemann (CEO und Co-Founder, SoSafe), Dr. Daniel Lemmer (ex-CISO ZF Group), Andrew Rose (CISO, Board Advisor), Daniel Holzinger, Jörg Scheiblhofer (CISO, ORF), Niels Hoffmann, Lawrence Pritchard, Joschka Havenith sowie Anitra Eggler als Closing-Keynote.

Inhaltlich spannend ist auch die Verbindung aus Security und Verhaltensperspektive: Mit Rollen wie Director Human Risk Management oder Adversarial AI Research wird deutlich, dass moderne Cyberabwehr nicht nur in SIEM-Dashboards entschieden wird, sondern auch in Kommunikation, Lernpsychologie, Stressmanagement und Führung.

Was Teilnehmende konkret mitnehmen können

Konferenzen werden dann wertvoll, wenn sich daraus Entscheidungen ableiten lassen. Die Virtual Academy adressiert deshalb sehr konkrete „Pain Points“, die sich in fast jeder Organisation finden lassen, unabhängig von Branche oder Reifegrad:

  • Incident Response als Organisationsfähigkeit: Wer in der Krise improvisiert, verliert Zeit. Wer vorher Rollen, Meldewege und Entscheidungsroutinen trainiert, gewinnt Handlungsfähigkeit.
  • Board-Kommunikation: Security muss als Risiko- und Entscheidungsfrage verstanden werden, nicht als Technikdetail.
  • Akzeptanz statt Zwang: Hohe Beteiligung an Pflichtmaßnahmen entsteht nicht durch Druck, sondern durch gute Formate, Relevanz und klare Nutzensignale.
  • NIS2 umsetzbar machen: Anforderungen lassen sich besser erfüllen, wenn menschliche Risiken als Teil des Risikomanagements gemessen und gesteuert werden.

Praktisch: Laut SoSafe erhalten Teilnehmende nach Abschluss der Sessions ein Teilnahmezertifikat und außerdem On-Demand-Zugriff auf die Inhalte. Das hilft, wenn sich nicht jede Session live abdecken lässt oder wenn Inhalte intern weitergegeben werden sollen.

Warum der Zeitpunkt ideal ist: Sommer-Freiraum als Resilienz-Hebel

Ein unterschätzter Vorteil des Termins: Viele Organisationen haben im August mehr Luft für strategische Themen, die im operativen Dauerfeuer untergehen. Genau dafür ist das Format gebaut, als konzentrierter Vormittag mit Pausen, Recaps und parallelen Streams.

Wer 2026 Cyber-Resilienz ernst nimmt, braucht neben Technologie vor allem eine belastbare Sicherheitskultur: klare Entscheidungswege, trainierte Prozesse, eine Belegschaft, die meldet statt verschweigt, und Führungskräfte, die Security als Teil von Business Continuity verstehen. Die SoSafe Virtual Academy bündelt diese Perspektiven in einem Format, das sich leicht in den Arbeitsalltag integrieren lässt.

Jetzt kostenfrei teilnehmen

Der Beitrag SoSafe Virtual Academy 2026: Digitale Resilienz beginnt beim Menschen erschien zuerst auf BASIC thinking. Folge uns auch auf Google News und Flipboard oder abonniere unseren Newsletter UPDATE.

Hacker-Hype: Nur 1,3 Prozent der von KI entlarvten Schwachstellen ausgenutzt

04. August 2026 um 20:55

Der Beitrag Hacker-Hype: Nur 1,3 Prozent der von KI entlarvten Schwachstellen ausgenutzt erschien zuerst beim Online-Magazin BASIC thinking. Über unseren Newsletter UPDATE startest du jeden Morgen bestens informiert in den Tag.

KI Hacker Angriff OpenAI Anthropic ChatGPT Claude Gefahr

Erst OpenAI, dann Anthropic: Innerhalb weniger Wochen räumten die beiden KI-Unternehmen ein, dass ihre Modelle eigenständig in fremde Systeme eingedrungen sind. Die Aufregung war groß. Das Thema in den Medien präsent. Eine aktuelle Auswertung zeigt aber: In der Praxis hat sich die Bedrohungslage bislang kaum verändert.

Haben wir die Kontrolle über Künstliche Intelligenz verloren? Im Juli 2026 räumte OpenAI einen „beispiellosen Cybervorfall“ ein: Bei einem Test brachen KI-Modelle aus ihrer abgeschotteten Testumgebung aus, verschafften sich selbstständig Zugang zum Internet und drangen in die Systeme der Plattform Hugging Face ein.

Wenige Tage später legte der Konkurrent Anthropic nach. Bei der Überprüfung von rund 141.000 Testläufen stellte das Unternehmen fest, dass auch einige Claude-Modelle in die Systeme von drei Unternehmen eingedrungen waren. Weder die Betroffenen noch Anthropic selbst hatten das bemerkt.

KI als Hacker: Was sagen die Zahlen?

So beunruhigend die Vorfälle auch klingen, ganz so nah scheint das Ende noch nicht zu sein: Die US-Sicherheitsfirma VulnCheck hat für ihren State-of-Exploitation-Report 2026 ausgewertet, wie viele der von KI entdeckten Schwachstellen tatsächlich für Angriffe genutzt wurden.

Grundlage sind zwei Datensätze: die Anthropic zugeschriebenen Sicherheitsmeldungen sowie die Daten der Berkeley Vulnerability Research Initiative.

Das Ergebnis: Von 1.061 Schwachstellen, die auf KI-gestützte Entdeckung zurückgehen, wurden nur 14 nachweislich ausgenutzt. Das entspricht 1,3 Prozent und liegt damit ungefähr auf dem Niveau aller anderen Schwachstellen im ersten Halbjahr 2026.

Grundsätzlich bedeutet das, dass die von KI gefundenen Lücken nach aktueller Datenlage nicht gefährlicher sind als solche, die Menschen mit klassischen Methoden aufspüren.

Außerdem wurden im ersten Halbjahr 2026 innerhalb von 31 Tagen nach Veröffentlichung rund 200 Schwachstellen angegriffen. In den Vorjahren waren es 196 und 194, also etwa gleich viele.

Gleichzeitig stieg die Zahl der insgesamt veröffentlichten Schwachstellen um 45 Prozent. Das Verhältnis von tatsächlich ausgenutzten zu gemeldeten Lücken sank entsprechend von 2,7 Prozent Ende 2023 auf 1,4 Prozent.

Sind Anthropics Zahlen überbewertet?

Besonders deutlich wird die Lücke zwischen Ankündigung und Nachweis bei Anthropic selbst. Das Unternehmen hatte im April mit Project Glasswing gewarnt, KI-gestützte Schwachstellensuche könne Angreifern helfen, Systeme zu übernehmen oder Daten zu stehlen.

Zuvor hatte bereits das Anthropic-Modell Mythos die Debatte angeheizt, weil es laut Tagesschau über Jahrzehnte unentdeckt gebliebene Sicherheitslücken in viel genutzten Programmen und Onlinediensten fand.

Im Mai 2026 veröffentlichte Anthropic ein öffentliches Verzeichnis dazu und sprach von 23.019 gefundenen Auffälligkeiten. VulnCheck-Analyst Patrick Garrity hat nachgerechnet: Das Verzeichnis ist seit dem Start bei 1.611 Einträgen stehen geblieben, 126 der Funde mündeten in offiziell veröffentlichte Schwachstellen.

Nur eine davon wurde bislang nachweislich für einen Angriff genutzt. Mehr als 150 Funde haben ihre eigene Offenlegungsfrist inzwischen überschritten, ohne dass Anthropic sie veröffentlicht hätte.

Hackerangriff durch KI: Das reale Risiko

Eine Entwarnung ist das allerdings nicht. VulnCheck weist auf zwei Entwicklungen hin, die unabhängig vom KI-Hype relevant sind.

  • Erstens landen Schwachstellen schneller auf der Liste der nachweislich ausgenutzten Lücken. Die Zeitspanne von der Veröffentlichung bis zum ersten dokumentierten Angriff sank im Median von 120 Tagen im Jahr 2025 auf 80 Tage. Der Anteil der Lücken, die schon am Tag der Veröffentlichung oder davor angegriffen wurden, ging dagegen leicht zurück, von 28,93 auf 23,43 Prozent.
  • Zweitens werden KI-Produkte selbst zum Ziel. VulnCheck registrierte 28 Schwachstellen in KI-Systemen, bei zehn davon gab es tatsächliche Angriffe. Bei der Open-Source-Plattform LangFlow etwa verschafften sich Angreifer Zugang, sammelten Zugangsdaten ein, installierten Kryptominer und versuchten, sich weiter im Netzwerk auszubreiten. Dennoch hält sich auch hier die Überraschung in Grenzen, denn KI-Systeme bekommen zunehmend Zugriff auf sensible Unternehmensdaten und wichtige Infrastruktur.

Zwischen Panik und Verharmlosung

Bleibt die Frage, wie ernst die Lage nun wirklich ist. Die Vorfälle bei OpenAI und Anthropic sind keine Kleinigkeit. Sie zeigen ein Steuerungsproblem bei autonomen KI-Agenten. Dass ein Modell einen Angriff fortsetzt, obwohl es das echte Ziel erkannt hat, ist ein ernstzunehmendes Sicherheitsproblem.

Gleichzeitig lohnt sich der Blick darauf, von wem die Warnungen stammen. Sowohl OpenAI als auch Anthropic stehen im Wettbewerb um Investoren und Aufmerksamkeit.

Der ChatGPT-Entwickler steuert zudem auf einen Börsengang zu. Eine Warnung vor der eigenen, angeblich gefährlich mächtigen Technologie ist immer auch eine Demonstration der eigenen Leistungsfähigkeit.

Hacker-Hype: KI nützt Verteidigern mehr als Angreifern

VulnCheck kommt zu einem entsprechenden Schluss. Die bisherigen Daten, einschließlich Anthropics eigenem, ins Stocken geratenem Offenlegungsverzeichnis, deuteten darauf hin, dass KI-gestützte Schwachstellensuche und die Fähigkeiten der Frontier-Modelle „im Verhältnis zu den heute verfügbaren Belegen überbewertet“ worden seien.

Vorerst dürfte der breite Zugang zu leistungsfähigen KI-Modellen sogar eher den Verteidigern nutzen als den Angreifern, weil sich mehr Lücken finden und schließen lassen, bevor jemand sie ausnutzt.

Eine Entwarnung ist das trotzdem nicht. Die Auswirkungen seien bislang moderat, aber real, schreibt VulnCheck. Statt allein auf den Hype zu reagieren, solle man die weitere Entwicklung genau beobachten.

Für Unternehmen bedeutet das: Die wichtigsten Angriffsziele bleiben dieselben wie zuvor. Content-Management-Systeme machten im ersten Halbjahr ein Drittel aller nachgewiesenen Angriffe aus, vor allem über WordPress-Plugins.

Auch interessant:

Der Beitrag Hacker-Hype: Nur 1,3 Prozent der von KI entlarvten Schwachstellen ausgenutzt erschien zuerst auf BASIC thinking. Folge uns auch auf Google News und Flipboard oder abonniere unseren Newsletter UPDATE.

❌