Security
You can find more information about the service in our documentation portal.
Vulnerabilities in Cisco Secure Endpont - Update necessary
Cisco warns about several vulnerabilities in ClamAV, which is used, among other things, in Cisco Secure Endpoint.
An update to the versions
Secure Endpoint Connector for Linux 1.29.0
Secure Endpoint Connector for Mac 1.27.2
Secure Endpoint Connector for Windows 8.6.2
or higher is urgently required.
Currently high level of phishing attempts (e.g. "Incoming & Outgoing Server Blocked", "Aktualisierung Ihres Profils im Universitätsverzeichnis")
We are currently observing a high number of reported phishing emails. The current top reported subjects are these:
- Incoming & Outgoing Server Blocked Thu, July 2, 2026
- Aktualisierung Ihres Profils im Universitätsverzeichnis
However, it is very likely that additional subjects will be observed. If necessary we will update this list with further information.
Please check received emails for typical phishing signs, such as:
- suspicious sender
- links to external URLs
- artificial urgency
Phishing Email: "AW: Sie haben am 7. April 2026 eine neue Nachricht von ..."
We are currently observing a wave of phishing emails with the subject "AW: Sie haben am 7. April 2026 eine neue Nachricht von ...".
Please do not click on the link and do not enter any login credentials.
Emails are being sent from already compromised RWTH email accounts, primarily to members of RWTH.
DDoS against RWTH
A DDoS attack that, in its initial phase, saturated both lines to the DFN, leading to impairments in external connectivity.
Scam Email: Piano Donation
Yesterday (06.01.2026) a high number of emails about a free piano were sent to RWTH Aachen email accounts.
This is most likely a scam attempt using old pictures. Please consider the possible risks before engaging with the supposed donor, especially if you are asked to transfer any money to cover e.g. delivery fees.
The different email subjects were as follows:
"KOSTENLOSE SPENDE EINES YAMAHA-FLUGELS.!!!"
"BABY PIANO SPENDE AN EIN LIEBEVOLLES ZUHAUSE.!!!"
"GROSSZÜGIGE KLAVIERSPENDE!!!"
"WOHLTATIGE SPENDE EINES YAMAHA-FLUGELS.!!!"
Phishing Email: "Alert: Important Message for ... (E-Mail Adresse)"
A phishing email with the above subject line points to a convincing fake of mail.rwth-aachen.de.
Please do not click, we are monitoring this.
Phishing Email: "Aktion erforderlich ..."
Last night, a phishing email was sent out with today's or yesterday's date in the subject line.
Please do not enter any login information via the link in this email.
The pattern is always the same:
a) it creates pressure to do something IMMEDIATELY.
b) the sender is fake.
These are typical characteristics of a phishing email.
A new phishing email has just arrived, subject: "Aktion erforderlich" (date of today)
DNS RPZ
Some records have been added to the local RWTH response policy zone with "passthru" policy - so just logging but not blocking DNS requestst to known bad domains.
Routing über neue XWiN-Router
During this period, the routing of the previous XWiN routers (Nexus 7700) will be switched to the new XWiN routers (Catalyst 9600). These routers are essential for RWTH's network connection. This changeover also requires the migration of the DFN connection, which is switched redundantly to Frankfurt and Hannover, and the RWTH firewall to the new systems.
There will be complete or partial outages of the external connection during the maintenance window. All RWTH services (e.g. VPN, email, RWTHonline, RWTHmoodle) will not be available during this period. The accessibility of services within the RWTH network will be temporarily unavailable due to limited DNS functionality.
Der Uplink nach Frankfurt wurde erfolgreich auf das neue System geschwenkt.
Umbau des Uplinks nach Hannover beginnt.
Uplink nach Hannover auf das neue System umgezogen.
BGP v4/v6 nach Frankfurt und Hannover sind nun über die neue Routern funktional.
Es stehen noch ein paar kleinere Nacharbeiten an.
Wartung ist abgeschlossen. Der Datenverkehr läuft nun vollständig über die neuen Router!
Problematik mit der Anbindung zur Physik identifiziert, Lösung erfolgt morgen früh.
DFN Timestamp Service Temporarily Unavailable
The DFN timestamp service is temporarily unavailable at the moment. As a result, the digital signature cannot be used as usual.
We are already working on a solution to the problem.
DFN Zeitstempeldienst funktioniert wieder
Phishing Warning
We are currently observing a new wave of phishing attacks. This time, the focus is on CEO Fraud:
https:
polizei.nrw/en/article/ceo-fraud-high-risk-of-fraud-for-companies
Usually the name of the correct supervisor is shown as the sender name. The actual sender email address, however, is most often very generic (e.g. office12345@gmail.com or similar). It is therefore strongly recommended to check the actual sender email address.
We advise caution. If you receive one of those emails, please do not reply and never send any gift cards or money. Report the email (as an attachment) to servicedesk@itc.rwth-aachen.de and also to spam@access.ironport.com in Cc.
You can find more information about e-mail phishing here:
https:
help.itc.rwth-aachen.de/en/service/1jefzdccuvuch/article/44343c9765a44f1cad23f0c4cd75f856/#Phishing-Mails
Erneuerung der Vulnerability-Management-Lösungen
As part of a modernization of the vulnerability management solutions used, the license of the old appliance has expired as planned. The reports displayed on [0] therefore do not reflect the current status quo. Information about a new portal, which displays the data of the new scanner, will soon be provided via the usual channels (e.g. e-mail distribution list for the admin round).
[0]
https:
noc-portal.itc.rwth-aachen.de/sec-scan-report/scan_results