Threats Affecting Austria
View all threats affecting or targeting Austria. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Affecting Austria
Click on any threat for detailed analysis and mitigation recommendations
New TrickMo Variant: Device Take Over malware targeting Banking, Fintech, Wallet & Auth apps 0 A new variant of the TrickMo Android banking trojan was identified between January and February 2026, representing a substantial platform redesign rather than new capabilities. The malware has migrated its command-and-control infrastructure entirely onto The Open Network (TON) using .adnl endpoints, moving away from conventional internet infrastructure. Active campaigns have targeted banking and wallet users in France, Italy, and Austria. Once accessibility permissions are granted, operators gain real-time device control including credential phishing, keylogging, screen recording, SMS interception, and bidirectional remote control. New features include network reconnaissance capabilities and SSH tunnelling that transform infected devices into programmable network pivots and SOCKS5 proxy exit nodes, enabling operators to bypass IP-based fraud detection systems while accessing victim networks. Join the discussion | AlienVault OTX General | 05/11/2026, 09:07:43 UTC Added: 05/11/2026, 09:51:23 UTC |
European Commission Reports Cyber Intrusion and Data Theft 0 The ShinyHunters hacker group claimed to have stolen over 350GB of information from European Commission cloud systems. The post European Commission Reports Cyber Intrusion and Data Theft appeared first on SecurityWeek . Join the discussion | SecurityWeek | 03/30/2026, 11:29:45 UTC Added: 03/30/2026, 11:38:17 UTC |
CVE-2025-67260: n/aCVE-2025-67260 0 The Terrapack software, from ASTER TEC / ASTER S.p.A., with the indicated components and versions has a file upload vulnerability that may allow attackers to execute arbitrary code. Vulnerable components include Terrapack TkWebCoreNG:: 1.0.20200914, Terrapack TKServerCGI 2.5.4.150, and Terrapack TpkWebGIS Client 1.0.0. Join the discussion | CVE Database V5 | 03/20/2026, 00:00:00 UTC Added: 03/20/2026, 15:54:21 UTC |
CVE-2026-3511: CWE-611 Improper Restriction of XML External Entity Reference in Slovensko.Digital AutogramCVE-2026-3511 0 Improper Restriction of XML External Entity Reference vulnerability in XMLUtils.java in Slovensko.Digital Autogram allows remote unauthenticated attacker to conduct SSRF (Server Side Request Forgery) attacks and obtain unauthorized access to local files on filesystems running the vulnerable application. Successful exploitation requires the victim to visit a specially crafted website that sends request containing a specially crafted XML document to /sign endpoint of the local HTTP server run by the application. Join the discussion | CVE Database V5 | 03/19/2026, 11:25:44 UTC Added: 03/19/2026, 13:54:25 UTC |
CVE-2026-30695: n/aCVE-2026-30695 0 CVE-2026-30695 is a medium severity Cross-Site Scripting (XSS) vulnerability affecting the web-based configuration interface of Zucchetti Axess access control devices, including models XA4, X3/X3BIO, X4, X7, and XIO/i-door/i-door+. The vulnerability arises from improper sanitization of user input in the dirBrowse parameter of the /file_manager.cgi endpoint. Exploitation requires user interaction but no authentication, allowing an attacker to inject malicious scripts that can compromise confidentiality and integrity. There are no known exploits in the wild and no patches currently available. The vulnerability impacts the confidentiality and integrity of the device management interface but does not affect availability. Organizations using these access control devices should be aware of the risk of session hijacking, credential theft, or unauthorized actions via injected scripts. Mitigation involves restricting access to the management interface, implementing web application firewalls with XSS protections, and monitoring for suspicious activity. Countries with significant deployments of Zucchetti Axess devices, particularly in Europe and Italy, are most at risk. This vulnerability requires prompt attention to prevent potential targeted attacks on physical access control systems. Join the discussion | CVE Database V5 | 03/18/2026, 00:00:00 UTC Added: 03/18/2026, 17:13:23 UTC |
CVE-2026-4208: CWE-639 in TYPO3 Extension "E-Mail MFA Provider"CVE-2026-4208 0 The extension fails to properly reset the generated MFA code after successful authentication. This leads to a possible MFA bypass for future login attempts by providing an empty string as MFA code to the extensions MFA provider. Join the discussion | CVE Database V5 | 03/17/2026, 08:34:52 UTC Added: 03/17/2026, 08:58:21 UTC |
CVE-2026-32100: CWE-200: Exposure of Sensitive Information to an Unauthorized Actor in swag platform-securityCVE-2026-32100 0 CVE-2026-32100 is a medium severity vulnerability in the Shopware open commerce platform's swag platform-security component. The /api/_info/config API endpoint exposes sensitive information about active security fixes without requiring authentication. This information disclosure could aid attackers in identifying unpatched vulnerabilities. The issue affects versions prior to 2.0.16, 3.0.12, and 4.0.7 and has a CVSS score of 5. Join the discussion | CVE Database V5 | 03/12/2026, 18:10:58 UTC Added: 03/12/2026, 18:15:36 UTC |
CVE-2025-66956: n/aCVE-2025-66956 0 Insecure Access Control in Contact Plan, E-Mail, SMS and Fax components in Asseco SEE Live 2.0 allows remote attackers to access and execute attachments via a computable URL. Join the discussion | CVE Database V5 | 03/11/2026, 00:00:00 UTC Added: 03/11/2026, 20:29:54 UTC |
CVE-2026-31889: CWE-290: Authentication Bypass by Spoofing in shopware coreCVE-2026-31889 0 CVE-2026-31889 is a high-severity authentication bypass vulnerability in Shopware core affecting versions prior to 6.6.10.15 and 6.7.8.1. It arises from the legacy app registration flow where HMAC-based authentication does not sufficiently bind a shop installation to its original domain. Attackers who possess the app-side secret can abuse the re-registration process to update the shop URL without proving control over the original domain. This allows targeted hijacking of app communication, redirecting traffic to attacker-controlled domains and potentially stealing API credentials. Join the discussion | CVE Database V5 | 03/11/2026, 18:56:23 UTC Added: 03/11/2026, 19:29:48 UTC |
CVE-2026-31888: CWE-204: Observable Response Discrepancy in shopware coreCVE-2026-31888 0 CVE-2026-31888 is a medium-severity vulnerability in Shopware core versions prior to 6.7.8.1 and 6.6.10.15. It arises from an observable response discrepancy in the Store API login endpoint, which returns different error codes and messages depending on whether an email address is registered or not. This behavior allows unauthenticated attackers to enumerate valid customer accounts by probing email addresses. The storefront login controller does not exhibit this flaw, indicating inconsistent error handling between components. Join the discussion | CVE Database V5 | 03/11/2026, 18:53:03 UTC Added: 03/11/2026, 18:59:52 UTC |
Showing 1 to 10 of 2659 results