Security

You can find more information about the service in our documentation portal.

Vulnerabilities in Cisco Secure Endpont - Update necessary

Warning
Fri 07/03/2026 12:54 PM - Fri 07/31/2026 12:54 PM

Cisco warns about several vulnerabilities in ClamAV, which is used, among other things, in Cisco Secure Endpoint.

An update to the versions
Secure Endpoint Connector for Linux 1.29.0
Secure Endpoint Connector for Mac 1.27.2
Secure Endpoint Connector for Windows 8.6.2

or higher is urgently required.

03.07.2026 12:58

Currently high level of phishing attempts (e.g. "Incoming & Outgoing Server Blocked", "Aktualisierung Ihres Profils im Universitätsverzeichnis")

Warning
Thu 07/02/2026 04:00 PM - Sat 07/11/2026 12:00 AM

We are currently observing a high number of reported phishing emails. The current top reported subjects are these:

  • Incoming & Outgoing Server Blocked Thu, July 2, 2026
  • Aktualisierung Ihres Profils im Universitätsverzeichnis

However, it is very likely that additional subjects will be observed. If necessary we will update this list with further information.

Please check received emails for typical phishing signs, such as:

  • suspicious sender
  • links to external URLs
  • artificial urgency
02.07.2026 16:54

Phishing Email: "AW: Sie haben am 7. April 2026 eine neue Nachricht von ..."

Warning
Tue 04/07/2026 01:45 PM - Fri 05/08/2026 09:05 AM

We are currently observing a wave of phishing emails with the subject "AW: Sie haben am 7. April 2026 eine neue Nachricht von ...".

Please do not click on the link and do not enter any login credentials.

Emails are being sent from already compromised RWTH email accounts, primarily to members of RWTH.

07.04.2026 14:03

DDoS against RWTH

Notice
Tue 03/10/2026 02:15 PM - Thu 03/12/2026 04:27 PM

A DDoS attack that, in its initial phase, saturated both lines to the DFN, leading to impairments in external connectivity.

10.03.2026 16:27

Scam Email: Piano Donation

Notice
Tue 01/06/2026 12:00 PM - Wed 01/21/2026 12:00 PM

Yesterday (06.01.2026) a high number of emails about a free piano were sent to RWTH Aachen email accounts.

This is most likely a scam attempt using old pictures. Please consider the possible risks before engaging with the supposed donor, especially if you are asked to transfer any money to cover e.g. delivery fees.

The different email subjects were as follows:

"KOSTENLOSE SPENDE EINES YAMAHA-FLUGELS.!!!"
"BABY PIANO SPENDE AN EIN LIEBEVOLLES ZUHAUSE.!!!"
"GROSSZÜGIGE KLAVIERSPENDE!!!"
"WOHLTATIGE SPENDE EINES YAMAHA-FLUGELS.!!!"

07.01.2026 13:36

Phishing Email: "Alert: Important Message for ... (E-Mail Adresse)"

Warning
Mon 11/17/2025 01:00 PM - Thu 11/20/2025 02:58 PM

A phishing email with the above subject line points to a convincing fake of mail.rwth-aachen.de.

Please do not click, we are monitoring this.

17.11.2025 15:01

Phishing Email: "Aktion erforderlich ..."

Warning
Tue 11/11/2025 10:31 PM - Sun 11/16/2025 01:30 PM

Last night, a phishing email was sent out with today's or yesterday's date in the subject line.

Please do not enter any login information via the link in this email.

The pattern is always the same:

a) it creates pressure to do something IMMEDIATELY.
b) the sender is fake.

These are typical characteristics of a phishing email.

12.11.2025 13:31
Updates

A new phishing email has just arrived, subject: "Aktion erforderlich" (date of today)

13.11.2025 16:32

DNS RPZ

Notice
Mon 07/07/2025 12:45 PM - Tue 07/08/2025 01:45 PM

Some records have been added to the local RWTH response policy zone with "passthru" policy - so just logging but not blocking DNS requestst to known bad domains.

07.07.2025 12:30

Routing über neue XWiN-Router

Maintenance
Tue 06/10/2025 09:00 PM - Tue 06/10/2025 10:13 PM

During this period, the routing of the previous XWiN routers (Nexus 7700) will be switched to the new XWiN routers (Catalyst 9600). These routers are essential for RWTH's network connection. This changeover also requires the migration of the DFN connection, which is switched redundantly to Frankfurt and Hannover, and the RWTH firewall to the new systems.
There will be complete or partial outages of the external connection during the maintenance window. All RWTH services (e.g. VPN, email, RWTHonline, RWTHmoodle) will not be available during this period. The accessibility of services within the RWTH network will be temporarily unavailable due to limited DNS functionality.

07.05.2025 12:47
Updates

Der Uplink nach Frankfurt wurde erfolgreich auf das neue System geschwenkt.

10.06.2025 21:07

Umbau des Uplinks nach Hannover beginnt.

10.06.2025 21:36

Uplink nach Hannover auf das neue System umgezogen.

10.06.2025 21:45

BGP v4/v6 nach Frankfurt und Hannover sind nun über die neue Routern funktional.

10.06.2025 21:57

Es stehen noch ein paar kleinere Nacharbeiten an.

10.06.2025 22:03

Wartung ist abgeschlossen. Der Datenverkehr läuft nun vollständig über die neuen Router!

10.06.2025 22:12

Problematik mit der Anbindung zur Physik identifiziert, Lösung erfolgt morgen früh.

10.06.2025 23:50

DFN Timestamp Service Temporarily Unavailable

Partial Outage
Wed 02/12/2025 03:45 PM - Wed 02/12/2025 10:00 PM

The DFN timestamp service is temporarily unavailable at the moment. As a result, the digital signature cannot be used as usual.
We are already working on a solution to the problem.

12.02.2025 15:53
Updates

DFN Zeitstempeldienst funktioniert wieder

19.02.2025 13:13

Phishing Warning

Notice
Wed 12/18/2024 10:45 AM - Fri 01/24/2025 01:29 PM

We are currently observing a new wave of phishing attacks. This time, the focus is on CEO Fraud:
https:
polizei.nrw/en/article/ceo-fraud-high-risk-of-fraud-for-companies
Usually the name of the correct supervisor is shown as the sender name. The actual sender email address, however, is most often very generic (e.g. office12345@gmail.com or similar). It is therefore strongly recommended to check the actual sender email address.
We advise caution. If you receive one of those emails, please do not reply and never send any gift cards or money. Report the email (as an attachment) to servicedesk@itc.rwth-aachen.de and also to spam@access.ironport.com in Cc.
You can find more information about e-mail phishing here:
https:
help.itc.rwth-aachen.de/en/service/1jefzdccuvuch/article/44343c9765a44f1cad23f0c4cd75f856/#Phishing-Mails

18.12.2024 11:15

Erneuerung der Vulnerability-Management-Lösungen

Notice
Thu 01/02/2025 11:15 AM - Thu 01/09/2025 12:15 PM

As part of a modernization of the vulnerability management solutions used, the license of the old appliance has expired as planned. The reports displayed on [0] therefore do not reflect the current status quo. Information about a new portal, which displays the data of the new scanner, will soon be provided via the usual channels (e.g. e-mail distribution list for the admin round).
[0]
https:
noc-portal.itc.rwth-aachen.de/sec-scan-report/scan_results

02.01.2025 11:23