<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Security on Crypto Biber</title><link>https://blog.klapprechner.org/en/tags/security/</link><description>Recent content in Security on Crypto Biber</description><generator>Hugo -- gohugo.io</generator><language>en-US</language><lastBuildDate>Tue, 21 Jul 2026 05:15:00 +0200</lastBuildDate><atom:link href="https://blog.klapprechner.org/en/tags/security/index.xml" rel="self" type="application/rss+xml"/><item><title>SharePoint under attack: critical flaw exploited days after Patch Tuesday</title><link>https://blog.klapprechner.org/en/posts/sharepoint-luecke-aktiv-ausgenutzt/</link><pubDate>Tue, 21 Jul 2026 05:15:00 +0200</pubDate><guid>https://blog.klapprechner.org/en/posts/sharepoint-luecke-aktiv-ausgenutzt/</guid><description>A critical deserialization bug in on-prem SharePoint (CVSS 9.8) came under attack right after Microsoft&amp;rsquo;s record Patch Tuesday. Stolen machine keys keep intruders in even after patching.</description></item><item><title>7-Zip flaw lets booby-trapped XZ archives run code — update to 26.02</title><link>https://blog.klapprechner.org/en/posts/7-zip-codeschmuggel-luecke/</link><pubDate>Tue, 21 Jul 2026 05:10:00 +0200</pubDate><guid>https://blog.klapprechner.org/en/posts/7-zip-codeschmuggel-luecke/</guid><description>A heap overflow in the XZ decoder (CVE-2026-14266) affects 7-Zip 21.07 through 26.01. Version 26.02 fixes it — but only if you install it yourself.</description></item><item><title>Allbridge paused after $1.65 million flash-loan attack</title><link>https://blog.klapprechner.org/en/posts/allbridge-flash-loan-exploit/</link><pubDate>Tue, 21 Jul 2026 05:05:00 +0200</pubDate><guid>https://blog.klapprechner.org/en/posts/allbridge-flash-loan-exploit/</guid><description>An attacker used a $1.12M flash loan to drain about $1.65M from Allbridge&amp;rsquo;s Solana pools. The bridge is paused and liquidity providers are told to withdraw.</description></item><item><title>Chrome emergency update: flaw already exploited in the wild</title><link>https://blog.klapprechner.org/en/posts/chrome-notfallupdate/</link><pubDate>Mon, 20 Jul 2026 09:30:00 +0200</pubDate><guid>https://blog.klapprechner.org/en/posts/chrome-notfallupdate/</guid><description>Google has shipped an out-of-band security update for Chrome. At least one of the patched flaws is already being used in attacks — don&amp;rsquo;t put this one off.</description></item><item><title>NIS2 and KRITIS: who actually falls under the new EU security rules</title><link>https://blog.klapprechner.org/en/posts/nis2-kritis/</link><pubDate>Sun, 19 Jul 2026 10:00:00 +0200</pubDate><guid>https://blog.klapprechner.org/en/posts/nis2-kritis/</guid><description>The EU&amp;rsquo;s cybersecurity rules cover far more organisations than many expect — from hospitals to emergency services. A look at who is affected by NIS2 and KRITIS.</description></item><item><title>ZachXBT slams hardware wallets — how much of it is fair?</title><link>https://blog.klapprechner.org/en/posts/zachxbt-hardware-wallets/</link><pubDate>Fri, 17 Jul 2026 11:30:00 +0200</pubDate><guid>https://blog.klapprechner.org/en/posts/zachxbt-hardware-wallets/</guid><description>The well-known onchain investigator calls hardware wallets unreliable and suggests a stripped-down iPhone used only for signing. A look at his arguments.</description></item></channel></rss>