=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 30-07-2026 18:00 − Freitag 31-07-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Claude uploaded malware to PyPI in Anthropics botched test ∗∗∗
---------------------------------------------
One of Anthropics Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/claude-uploaded-malware-to-p…
∗∗∗ Microsoft: Forscher finden Masterkey für Vollzugriff auf Azure-Datenbanken ∗∗∗
---------------------------------------------
Mit dem Key hätten Angreifer alle Datenbanken bei Microsofts Datenbankdienst Azure Cosmos DB auslesen und manipulieren können - auch die von Microsoft.
---------------------------------------------
https://www.golem.de/news/microsoft-forscher-finden-masterkey-fuer-vollzugr…
∗∗∗ Anthropic and OpenAI are competing to see whose agents can go rogue harder ∗∗∗
---------------------------------------------
Whoever wins, we lose
---------------------------------------------
https://www.theregister.com/security/2026/07/31/anthropic-and-openai-are-co…
∗∗∗ „CosmosEscape“ ermöglichte Übernahme aller Microsoft-Azure-Datenbanken ∗∗∗
---------------------------------------------
Eine Verkettung von Sicherheitslücken ermöglichte vollen Zugang zu allen Azure-Cosmos-DB-Datenbanken.
---------------------------------------------
https://www.heise.de/news/CosmosEscape-ermoeglichte-Uebernahme-aller-Micros…
∗∗∗ If you’re going to vibe code it, why not vibe pen test it? ∗∗∗
---------------------------------------------
TL;DR Why I built PenAI PenAI started as a project at a hackathon organised by Encode Club. It’s an AI agent that could work through Hack The Box-style lab machines on its own. Upload a VPN file, give it a target IP, pick a scope, set stealth mode and iteration limits, hit run, and let ..
---------------------------------------------
https://www.pentestpartners.com/security-blog/if-youre-going-to-vibe-code-i…
∗∗∗ The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version ∗∗∗
---------------------------------------------
Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic.
---------------------------------------------
https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/
∗∗∗ Firefox JIT-Schwachstelle gefährdete Tor-Nutzer unter Android ∗∗∗
---------------------------------------------
Im Firefox-Browser (151.0.1) gab es eine JIT-Schwachstelle (CVE-2026-10702), die einen Ausbruch aus dem Render des Browsers durch Code ermöglichte. Der Besuch einer bösartigen Webseite reichte aus, um beispielswiese den Tor-Browser, der den Firefox nutzt, zu kompromittieren. Ausnutzbar war das ..
---------------------------------------------
https://borncity.com/blog/2026/07/31/firefox-jit-schwachstelle-gefaehrdete-…
∗∗∗ Russische Akteure greifen über Outlook-Web-Access-Lücke an ∗∗∗
---------------------------------------------
Eine Sicherheitslücke in OWA ermöglicht durch Anzeigen von Mails das Ausführen von JavaScript-Code. Russische Akteure nutzen das aus.
---------------------------------------------
https://heise.de/-11387751
∗∗∗ SolarWinds Web Help Desk: Update bessert umgehbare Authentifizierung aus ∗∗∗
---------------------------------------------
SolarWinds schließt Sicherheitslücken in Web Help Desk. Eine gilt als kritisch und ermöglicht Angreifern, die Authentifizierung zu umgehen.
---------------------------------------------
https://heise.de/-11388191
∗∗∗ Unpatchbarer Fehler in Apple A12 & A13: Forensik- verklagt Security-Firma ∗∗∗
---------------------------------------------
Bis hin zum iPhone 11 stecken in Apple-Silicon-Chips nicht behebbare Lücken. Nun ist ein Streit darüber ausgebrochen, ob diese weitergegeben werden durfte.
---------------------------------------------
https://heise.de/-11379656
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 29-07-2026 18:00 − Donnerstag 30-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ HelloNet campaign: new malicious modules launched through the ViPNet update system ∗∗∗
---------------------------------------------
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
---------------------------------------------
https://securelist.com/tr/hellonet-vipnet/120700/
∗∗∗ Toy Ghouls’ new toy: the GenieLocker ransomware ∗∗∗
---------------------------------------------
The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector, and attributed to the Toy Ghouls group by open-source intelligence (link in Russian).
---------------------------------------------
https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/12…
∗∗∗ Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th) ∗∗∗
---------------------------------------------
Most of what an internet-facing SSH honeypot records is noise. Endless password guessing, and bots that log in, immediately pull down a payload, and move on. On 27 June 2026 my honeypot caught something quieter, and to me more interesting. A bot logged in as root, ran a careful survey of the machine's hardware, and then disconnected without downloading or running anything at all. No malware, no persistence, no second stage.
---------------------------------------------
https://isc.sans.edu/diary/rss/33198
∗∗∗ Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads ∗∗∗
---------------------------------------------
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads.
---------------------------------------------
https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
∗∗∗ Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts ∗∗∗
---------------------------------------------
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors.
---------------------------------------------
https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
∗∗∗ Verschlüsselt, aber falsch: Gruppenchats anfällig für manipulierte Inhalte ∗∗∗
---------------------------------------------
Alle Mitglieder eines Gruppenchats sollten dieselben Inhalte sehen. Die üblichen Chat-Dienste stellen das nicht sicher. Das ist riskant.
---------------------------------------------
https://www.heise.de/news/Verschluesselt-aber-falsch-Gruppenchats-anfaellig…
∗∗∗ Vermeintliche Zollgebühren der Post sind fake! ∗∗∗
---------------------------------------------
Eine offene Paketgebühr, ein Link zur Zahlung und eine täuschend echt aussehende Nachricht der Österreichischen Post. Mit dieser Masche versuchen Kriminelle derzeit, an Bankdaten zu gelangen.
---------------------------------------------
https://www.watchlist-internet.at/news/phishing-oesterreichischen-post-zoll/
∗∗∗ Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks ∗∗∗
---------------------------------------------
Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact.
---------------------------------------------
https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/
∗∗∗ Adform compromised to serve crypto stealer via supply chain attack ∗∗∗
---------------------------------------------
Adform are an advertising company used by around 14k companies, owning around a 30% share of the demand-side category.
---------------------------------------------
https://doublepulsar.com/adform-compromised-to-serve-crypto-stealer-via-sup…
∗∗∗ CISA Guide Helps Federal Agencies Securely and Effectively Use Open Source Software ∗∗∗
---------------------------------------------
Tailored Guidance to Use and Understand OSS Solutions, Contribute to and Produce Projects, and Evaluate AI Models.
---------------------------------------------
https://www.cisa.gov/news-events/news/cisa-guide-helps-federal-agencies-sec…
=====================
= Vulnerabilities =
=====================
∗∗∗ Angreifer missbrauchen Backdoor in Ciscos Firewall-Verwaltungssoftware ∗∗∗
---------------------------------------------
Angreifer missbrauchen fest einprogrammierte Zugangsdaten in Ciscos Firewall-Verwaltungssoftware. Updates sollen dagegen helfen.
---------------------------------------------
https://www.heise.de/news/Angreifer-missbrauchen-Backdoor-in-Ciscos-Firewal…
∗∗∗ Chrome-Update stopft weitere 370 Sicherheitslecks ∗∗∗
---------------------------------------------
Google hat wieder ein massives Sicherheitsupdate für Chrome veröffentlicht. Sieben der geschlossenen Lücken gelten als kritisch.
---------------------------------------------
https://heise.de/-11384153
∗∗∗ Cisco Secure Firewall Management Center Software Static Credential Vulnerability ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Progress: LoadMaster Critical Security Bulletin – July 2026 – (CVE-2026-59686, CVE-2026-59687, CVE-2026-59688, CVE-2026-59689, CVE-2026-59690) ∗∗∗
---------------------------------------------
https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulle…
∗∗∗ GitLab Patch Release: 19.2.1, 19.1.3, 19.0.5 ∗∗∗
---------------------------------------------
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-releas…
∗∗∗ Drupal Security Advisories 2026-July-29 ∗∗∗
---------------------------------------------
https://www.drupal.org/security
∗∗∗ Publish DFIR-IRIS advisories ∗∗∗
---------------------------------------------
https://github.com/sbaresearch/advisories/commit/0e542378f16ec1052b5ad032b4…
∗∗∗ LWN Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1086225/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 28-07-2026 18:00 − Mittwoch 29-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ vBulletin fixes critical pre-auth RCE flaw with public exploit ∗∗∗
---------------------------------------------
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [..] SSD Secure Disclosure has also published a technical analysis for CVE-2026-61511, explaining that the sanitization restrictions can be bypassed using the so-called “phpfuck” technique. [..] CVE-2026-61511 was reported to vBulletin on June 25, 2026, and version 6.2.2, which addressed the flaw, was released on July 1.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/vbulletin-fixes-critical-pre…
∗∗∗ Passwort-Hashes auslesbar: 20 Jahre alte BMC-Lücke gefährdet über 24.000 Server ∗∗∗
---------------------------------------------
Sicherheitsforscher von Lava haben 24.650 über das Internet erreichbare und für die Verwaltung von Serversystemen genutzte Baseboard Management Controller (BMC) ausfindig gemacht, die aufgrund einer zwei Jahrzehnte alten Sicherheitslücke Passwort-Hashes leaken. [..] Die Sicherheitslücke ist zwar, wie schon die CVE-ID erahnen lässt, erst 2013 öffentlich bekannt geworden, nach Angaben der Forscher war sie aber schon von Beginn an in IPMI 2.0 enthalten – und damit seit 2004. Trotz dieses Alters sind noch heute 36.872 Server-BMCs über IPMI erreichbar und davon 24.650 anfällig für CVE-2013-4786, wie Lava auf einem eigenen Dashboard zeigt.
---------------------------------------------
https://www.golem.de/news/passwort-hashes-auslesbar-20-jahre-alte-bmc-lueck…
∗∗∗ CubePilot drone software dev hit by DNS hijacking to intercept traffic ∗∗∗
---------------------------------------------
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cubepilot-drone-software-dev…
∗∗∗ Nationale Sicherheit: FCC verbietet Importe chinesischer Roboter ∗∗∗
---------------------------------------------
Die US-Fernmeldebehörde FCC verbietet die Zulassung neuer chinesischer Roboter und Wechselrichter wegen angeblicher Sicherheitsrisiken.
---------------------------------------------
https://www.golem.de/news/nationale-sicherheit-fcc-verbietet-importe-chines…
∗∗∗ Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass ∗∗∗
---------------------------------------------
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
---------------------------------------------
https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.h…
∗∗∗ JFrogs 0-days let OpenAIs models hack Hugging Face ∗∗∗
---------------------------------------------
We now know how OpenAI's models broke out of their cages to attack Hugging Face. The rogue models found zero-day vulnerabilities in JFrog’s universal binary repository manager Artifactory around the time they escaped, according to JFrog CTO Yoav Landman. While Landman wouldn't confirm that these flaws were the zero-days that OpenAI’s models found and exploited, ultimately allowing them to breach the massive model mart, OpenAI later admitted the connection.
---------------------------------------------
https://www.theregister.com/security/2026/07/28/jfrogs-0-days-let-openais-m…
∗∗∗ Some notes about Anthropic’s new results ∗∗∗
---------------------------------------------
Yesterday Anthropic published two new cryptanalysis results, both outputs of Claude Mythos, their (still) unreleased advanced model. The first of these results attacks a signature scheme called HAWK, while the second is an improved attack against reduced-round AES. Anthropic also released a blog post describing the research process that produced these results.
---------------------------------------------
https://blog.cryptographyengineering.com/2026/07/29/some-notes-about-anthro…
∗∗∗ Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon ∗∗∗
---------------------------------------------
Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure, allowing phishing campaigns to bypass many of the warning signs employees have been trained to recognize. Starting on June 25th through the second week of July, we identified more than 200 phishing emails targeting users across approximately 120 organizations, spanning a wide range of industries and countries worldwide. Victims were then prompted to grant permissions to an attacker-controlled application, allowing the campaign to abuse Microsoft’s trusted authentication flow while concealing its malicious intent.
---------------------------------------------
https://blog.checkpoint.com/email-security/attackers-are-turning-microsofts…
∗∗∗ Fake-PayPal-Mails: Rückerstattung und Abbuchung als Köder ∗∗∗
---------------------------------------------
Kriminelle verschicken derzeit gefälschte PayPal-Nachrichten, um an Zugangsdaten und Bankdaten zu gelangen. Eine Mail lockt mit einer Rückzahlung von 95,66 Euro, die andere warnt vor einer Abbuchung von 909,00 Euro.
---------------------------------------------
https://www.watchlist-internet.at/news/fake-paypal-mails-rueckerstattung-un…
∗∗∗ GitHub Blog: Disrupting supply chain attacks on npm and GitHub Actions ∗∗∗
---------------------------------------------
Explore the changes weve shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact.
---------------------------------------------
https://github.blog/security/supply-chain-security/disrupting-supply-chain-…
=====================
= Vulnerabilities =
=====================
∗∗∗ Gitea: Remote Code Execution via diffpatch Git Hook Installation ∗∗∗
---------------------------------------------
Gitea's diffpatch endpoint can be abused to install and execute a Git hook from repository-controlled content. An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user. With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository. CVE-2026-60004
---------------------------------------------
https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m
∗∗∗ Broadcom: VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) ∗∗∗
---------------------------------------------
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. [..] VMware vCenter contains a directory traversal vulnerability in the Syslog server. [..] VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter.
---------------------------------------------
https://support.broadcom.com/web/ecx/support-content-notification/-/externa…
∗∗∗ Jetbrains: Critical Security Issue Affecting TeamCity On-Premises (CVE-2026-63077) – Update to 2025.11.7 or 2026.1.3 Now ∗∗∗
---------------------------------------------
A critical security vulnerability has been identified in TeamCity On-Premises and assigned the Common Vulnerabilities and Exposures (CVE) identifier CVE-2026-63077. If exploited, this vulnerability may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands.
---------------------------------------------
https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/
∗∗∗ OpenWrt: Updates schließen teils kritische Sicherheitslücken ∗∗∗
---------------------------------------------
Das OpenWrt-Projekt hat aktualisierte Fassungen veröffentlicht, die teils als kritisches Risiko eingestufte Sicherheitslücken stopfen. [..] Mit einem einzigen UDP-Paket können Angreifer aus dem Netz ohne vorherige Anmeldung den Pufferüberlauf ausnutzen.
---------------------------------------------
https://heise.de/-11381496
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1086031/
∗∗∗ Node.js: Wednesday, July 29, 2026 Security Releases ∗∗∗
---------------------------------------------
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 27-07-2026 18:00 − Dienstag 28-07-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin ∗∗∗
---------------------------------------------
Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store.
---------------------------------------------
https://www.bleepingcomputer.com/news/apple/apple-sued-over-fake-app-store-…
∗∗∗ New Dysphoria DDoS botnet spreads to 200k devices worldwide ∗∗∗
---------------------------------------------
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-sp…
∗∗∗ New Certighost PoC exploit lets attackers hijack Windows domains ∗∗∗
---------------------------------------------
A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-certighost-poc-exploit-l…
∗∗∗ Hackers target US firms in FastJson RCE zero-day attacks ∗∗∗
---------------------------------------------
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-f…
∗∗∗ Data breach at medical billing firm MCBS affects 1.26 million people ∗∗∗
---------------------------------------------
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/data-breach-at-medical-billi…
∗∗∗ Nach OpenAI-Hack: US-Abgeordnete wollen Kill Switch für KI ∗∗∗
---------------------------------------------
Der eigenständige Hackerangriff von OpenAIs KI hat Nachwirkungen: Abgeordnete fordern mehr Kontrolle - und einen Kill Switch.
---------------------------------------------
https://www.golem.de/news/nach-openai-hack-us-abgeordnete-wollen-kill-switc…
∗∗∗ Persönliche Daten geleakt: Unzählige Claude-Chats bei Google aufgetaucht ∗∗∗
---------------------------------------------
Claude-Nutzer können Links zu ihren Chats mit anderen Personen teilen. Die Unterhaltungen wurden bis vor kurzem aber auch bei Google gelistet.
---------------------------------------------
https://www.golem.de/news/persoenliche-daten-geleakt-unzaehlige-claude-chat…
∗∗∗ NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework ∗∗∗
---------------------------------------------
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents.The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, ..
---------------------------------------------
https://thehackernews.com/2026/07/nvidia-forms-37-member-open-secure-ai.html
∗∗∗ AI-found bugs arent proving any easier to exploit despite the hype ∗∗∗
---------------------------------------------
VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage
---------------------------------------------
https://www.theregister.com/security/2026/07/28/ai-found-bugs-arent-proving…
∗∗∗ Angriffe auf FortiOS und Arista VeloCloud beobachtet ∗∗∗
---------------------------------------------
Die IT-Sicherheitsbehörde CISA meldet Angriffe auf Sicherheitslücken in Fortinet FortiOS sowie Arista VeloCloud.
---------------------------------------------
https://www.heise.de/news/Angriffe-auf-FortiOS-und-Arista-VeloCloud-beobach…
∗∗∗ Neobank Revolut: Angeblich 75 Millionen Datensätze im Untergrund angeboten ∗∗∗
---------------------------------------------
Ein Krimineller bietet im digitalen Untergrund eine Datenbank mit 75 Millionen Einträgen an, die von der Neobank Revolut stammen sollen.
---------------------------------------------
https://www.heise.de/news/Neobank-Revolut-Angeblich-75-Millionen-Datensaetz…
∗∗∗ Lücke: Claude Cowork entkommt macOS-Sandbox ∗∗∗
---------------------------------------------
Die Nutzung von KI-Agenten direkt auf dem Rechner kann Gefahren mit sich bringen. Das zeigt eine soeben entdecktes Sicherheitsloch in Claude Cowork für den Mac.
---------------------------------------------
https://www.heise.de/news/Luecke-Claude-Cowork-entkommt-macOS-Sandbox-11379…
∗∗∗ IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains ∗∗∗
---------------------------------------------
Talos IRs Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.
---------------------------------------------
https://blog.talosintelligence.com/ir-trends-q2-2026/
∗∗∗ Zahlreiche Sicherheitslücken gefixt: Schnell auf iOS 26.6 und Co. aktualisieren ∗∗∗
---------------------------------------------
Apple hat nun seine Sicherheitshinweise zu den neuen Betriebssystemen publiziert. Es gibt erneut enorm viele Fixes – vermutlich auch dank KI.
---------------------------------------------
https://heise.de/-11379576
∗∗∗ Verschiedene Attacken auf Progress LoadMaster möglich ∗∗∗
---------------------------------------------
Die Load-Balancing- und Cluster-Managementlösung LoadMaster ist verwundbar. Die Entwickler haben nun Sicherheitslücken geschlossen.
---------------------------------------------
https://heise.de/-11380070
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 24-07-2026 18:00 − Montag 27-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ SourTrade: Malvertising-Malware im Browser kompiliert ∗∗∗
---------------------------------------------
IT-Forscher haben eine mittels Malvertising verteilte Malware entdeckt. Die wird erst im Browser zusammengebaut.
---------------------------------------------
https://www.heise.de/news/SourTrade-Malvertising-Malware-im-Browser-kompili…
∗∗∗ How the Gentlemen Ransomware Group Built a Multi-Region Attack Machine in H1 2026 ∗∗∗
---------------------------------------------
Ransomware’s biggest story in the first half of 2026 was not only about established names maintaining dominance. A newer player, The Gentlemen ransomware group, emerged as one of the most geographically active operators, expanding its reach across Europe, Asia-Pacific, the Middle East & Africa, and the Americas.
---------------------------------------------
https://thecyberexpress.com/the-gentlemen-ransomware-group/
∗∗∗ ShinyHunters data leaks fuel $2,000 sextortion email scam ∗∗∗
---------------------------------------------
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel…
∗∗∗ Landes-Geheimdienstchef Kramer: OpenAI-Hackerangriff war "kein Skynet-Szenario" ∗∗∗
---------------------------------------------
Nach dem Hackerangriff auf Hugging Face mahnt der Thüringer Verfassungsschutz zur Besonnenheit. Er forderte aber ein KI-Frühwarnsystem für die Sicherheitsbehörden.
---------------------------------------------
https://www.golem.de/news/landes-geheimdienstchef-kramer-openai-hackerangri…
∗∗∗ Alle Daten gelöscht: US-Bürger wegen Nutzung einer GrapheneOS-Funktion angeklagt ∗∗∗
---------------------------------------------
Ein Mann wurde bei der Einreise in die USA durchsucht. Er trickste die Grenzpolizei mit einem Duress-Passwort aus – und muss sich dafür nun vor Gericht verantworten.
---------------------------------------------
https://www.golem.de/news/alle-daten-geloescht-us-buerger-wegen-nutzung-ein…
∗∗∗ Zugangsdaten im Visier: Hacker beim Datenklau über Hotel-WLANs erwischt ∗∗∗
---------------------------------------------
Eine russische Hackergruppe kapert wohl WLAN-Ausrüstung in Einrichtungen, um systematisch Microsoft-Zugangsdaten abzugreifen.
---------------------------------------------
https://www.golem.de/news/zugangsdaten-im-visier-hacker-beim-datenklau-uebe…
∗∗∗ Datenpanne in Gebets-App: Sicherheitslücke in "Gottes Tech-Stack" aufgedeckt ∗∗∗
---------------------------------------------
Eine Forscherin hat die offizielle Gebets-App des Papstes untersucht. "Gottes Tech-Stack" erwies sich als angreifbar und leakte Nutzerdaten.
---------------------------------------------
https://www.golem.de/news/700-000-nutzer-betroffen-suendhaftes-datenleck-be…
∗∗∗ BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery ∗∗∗
---------------------------------------------
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware.
---------------------------------------------
https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html
∗∗∗ DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts ∗∗∗
---------------------------------------------
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis.
---------------------------------------------
https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.ht…
∗∗∗ Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools.
---------------------------------------------
https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html
∗∗∗ Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update ∗∗∗
---------------------------------------------
One bug disabled the security service on restart, another blocked installation on hardened RHEL systems
---------------------------------------------
https://www.theregister.com/patches/2026/07/27/microsoft-defender-for-endpo…
∗∗∗ Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor ∗∗∗
---------------------------------------------
Zscaler ThreatLabz has been tracking attacks from a threat actor that is likely an initial access broker for ransomware attacks since January 2026. The threat actor targets organizations by leveraging vishing techniques through Microsoft Teams and deploying a variety of tools including a Go-based backdoor that we named GoGRPC. ThreatLabz has identified at least four variants of GoGPRC that we named Lep, Giver, Pet, and Kind. In some instances, the threat actor has deployed additional malware tools that include a backdoor that we named BlindDoor, a Go-based reverse SOCKS proxy we named RevSocket, a Python-based reverse SOCKS proxy we named PyGRPC, and two other tools we named S3Siphon and RSOX.
---------------------------------------------
https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vi…
∗∗∗ Geburtstagsgeschenk von Rituals? Vorsicht vor dieser Abofalle! ∗∗∗
---------------------------------------------
Viele bekannte Marken überraschen ihre Kund:innen zum Geburtstag mit kleinen Geschenken. Genau dieses Vertrauen machen sich Kriminelle zunutze: Sie verschicken gefälschte E-Mails im Namen von Rituals und locken mit einem Geschenkset. In Wahrheit landen die Opfer in einer teuren Abofalle.
---------------------------------------------
https://www.watchlist-internet.at/news/geburtstagsgeschenk-von-rituals-vors…
∗∗∗ Tenant-Übernahme möglich und drei kritische Sicherheitslücke in MS-Infrastruktur ∗∗∗
---------------------------------------------
Jeffrey Schwartz berichtet von der BlackHat 2026 in den USA, und einem speziellen Thema: Die Standard-Einstellung in Azure Automation ermöglichte eine mandantenübergreifende Identitätsübernahme. Dann gab es drei kritische Sicherheitslücken in der Infrastruktur von Microsoft (u.a. bei Bing Images), die die Ausführung von Remote-Code (RCE) ermöglichen. Kleine Nachschau zu diesen Sachverhalten.
---------------------------------------------
https://borncity.com/blog/2026/07/27/tenant-uebernahme-moeglich-und-drei-kr…
∗∗∗ Fake Corepack Site Distributes Infostealer and Proxyware to Developers ∗∗∗
---------------------------------------------
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
---------------------------------------------
https://socket.dev/blog/fake-corepack-site-distributes-infostealer-and-prox…
∗∗∗ Project ORBITAL ∗∗∗
---------------------------------------------
The modern cyber threat landscape has seen a fundamental shift in how threat actors manage and deploy their infrastructure. Advanced persistent threats (APTs) have almost completely moved away from static command-and-control (C2) servers, opting instead to build complex, multi-layered botnets known as Operational Relay Box (ORB) networks. Project ORBITAL (which stands for Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) was established as a centralised intelligence matrix to track, analyse, and ultimately help defenders disrupt this highly evasive infrastructure.
---------------------------------------------
https://blog.bushidotoken.net/2026/07/project-orbital.html
∗∗∗ Two Old Oj Flaws Chained to Trigger GitLab Remote Code Execution ∗∗∗
---------------------------------------------
A newly disclosed GitLab vulnerability has revealed how two long-standing memory-safety flaws in the widely used Ruby JSON parsing library, Oj, can be combined to achieve remote code execution on default GitLab installations.
---------------------------------------------
https://thecyberexpress.com/gitlab-vulnerability-oj-parser-rce/
=====================
= Vulnerabilities =
=====================
∗∗∗ Angreifer können MongoDB abstürzen lassen und Daten manipulieren ∗∗∗
---------------------------------------------
Die MongoDB-Entwickler haben in aktuellen Versionen zahlreiche Sicherheitslücken geschlossen. Bislang gibt es keine Hinweise auf laufende Attacken.
---------------------------------------------
https://heise.de/-11378494
∗∗∗ Sicherheitsupdate: Dateitransferlösung MOVEit ist verwundbar ∗∗∗
---------------------------------------------
Admins, die in Unternehmen für den Dateitransfer MOVEit nutzen, sollten die Software zeitnah auf den aktuellen Stand bringen. Geschieht das nicht, kann im schlimmsten Fall Schadcode auf PCs gelangen. Die Entwickler haben in einer neuen Version mehrere Schwachstellen geschlossen.
---------------------------------------------
https://heise.de/-11379295
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1085554/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 23-07-2026 18:00 − Freitag 24-07-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Vermehrt Phishing-Mails von legitimen E-Mail-Adressen aus Österreich ∗∗∗
---------------------------------------------
Im Moment beobachten wir vermehrt erfolgreiches Phishing, das von kompromittierten E-Mail-Konten österreichischer Unternehmen ausgeht.
Die Phishing-Mails zielen darauf ab, Microsoft-365-Zugangsdaten zu stehlen, das Konto zu übernehmen und weitere Phishing-Mails zu versenden. Die Phishing-Mails werden an die im Adressbuch gespeicherten Kontakte versendet. Da Empfänger und Sender sich kennen, erscheint dem Empfänger der Absender legitim, was die Chance auf eine weitere Kompromittierung erhöht. Dadurch hat diese Kampagne das Potenzial für eine besonders effektive Ausbreitung. Betroffen sind im Moment eher KMUs in der Baubranche (Bau, Metallbau, Holzbau, Werkzeug, Kabeltechnik).
---------------------------------------------
https://www.cert.at/de/aktuelles/2026/7/vermehrt-phishing-mails-von-legitim…
∗∗∗ Russische Angreifer missbrauchen Zero-Click-Lücke in Zimbra ∗∗∗
---------------------------------------------
In der Kollaborationssoftware Zimbra, die etwa Mail und Kalender und weitere Funktionen vereint, finden sich regelmäßig Sicherheitslücken, die die Entwickler mit Updates schließen. Admins installieren die offenbar weiterhin sehr zögerlich, denn internationale (IT-)Sicherheitsbehörden warnen nun gemeinsam vor Angriffen von russischen Akteuren, die mindestens seit Juli 2025 unter anderem eine Zero-Click-Lücke in Zimbra missbrauchen. Ziel der Angriffe sind demnach westliche Regierungen, kommerzielle sowie Bildungseinrichtungen, der Energiesektor, Strafverfolger, Medien, Nichtregierungsorganisationen und der Technologiesektor.
---------------------------------------------
https://www.heise.de/news/Russische-Angreifer-missbrauchen-Zero-Click-Lueck…
∗∗∗ New Dolphin X malware uses AI to rank high-value targets ∗∗∗
---------------------------------------------
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-dolphin-x-malware-uses-a…
∗∗∗ Hackers abuse Notepad++ plugins to stealthily install malware ∗∗∗
---------------------------------------------
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-p…
∗∗∗ Europol flags 4,340 URLs for removal in The Com crackdown ∗∗∗
---------------------------------------------
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic violent extremist groups.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/europol-flags-4-340-urls-for…
∗∗∗ Golden Chickens Resurfaces With Four New Malware Families and Modular Implants ∗∗∗
---------------------------------------------
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.
---------------------------------------------
https://thehackernews.com/2026/07/golden-chickens-resurfaces-with-four.html
∗∗∗ ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization.
---------------------------------------------
https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html
∗∗∗ Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller ∗∗∗
---------------------------------------------
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine.
---------------------------------------------
https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.ht…
=====================
= Vulnerabilities =
=====================
∗∗∗ Sicherheitsupdate n8n: Accountübernahme und Sandboxausbruch möglich ∗∗∗
---------------------------------------------
16 Sicherheitslücken gefährden IT-Umgebungen, in denen n8n zur Workflow-Automatisierung läuft. Der Großteil der Schwachstellen ist mit dem Bedrohungsgrad „hoch“ eingestuft. Angreifer können im schlimmsten Fall die volle Kontrolle über Systeme erlangen. Mittlerweile haben die Entwickler reparierte Versionen zum Download gestellt.
---------------------------------------------
https://heise.de/-11377037
∗∗∗ NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats ∗∗∗
---------------------------------------------
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version before 4.14.0 is affected. NodeBB has fixed them all, and administrators should be on 4.14.2.
---------------------------------------------
https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html
∗∗∗ LWN Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1084860/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 22-07-2026 18:00 − Donnerstag 23-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Microsoft SharePoint: Angriffe auf weitere Sicherheitslücke ∗∗∗
---------------------------------------------
Am Microsoft-Patchday im Juli waren bereits Angriffe auf eine SharePoint-Schwachstelle bekannt. Die hatte jedoch lediglich den Schweregrad „mittel“. Jetzt warnen IT-Sicherheitsfirmen und -Behörden vor beobachteten Attacken auf eine kritische SharePoint-Lücke, für die ebenfalls ein Softwareflicken seit dem Patchday bereitsteht. Zudem wurden Angriffe auf Check Point SmartConsole beobachtet.
---------------------------------------------
https://www.heise.de/news/Microsoft-SharePoint-Angriffe-auf-weitere-Sicherh…
∗∗∗ China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks ∗∗∗
---------------------------------------------
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.
---------------------------------------------
https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html
∗∗∗ Linux kernel team publishes 432 CVEs in two days ∗∗∗
---------------------------------------------
If you're responsible for Linux security, someone just dumped a pile of work onto your desk: 432 Linux kernel CVEs were published across Sunday and Monday this week. Linux watchers at nixCraft pointed out the volume on Monday morning, and it didn’t take long for seasoned sysadmins to start expressing concerns.
---------------------------------------------
https://www.theregister.com/security/2026/07/22/linux-kernel-team-publishes…
∗∗∗ 8000 PCs über Steam infiziert: Cyberkriminelle verteilen Malware via Fake-Games ∗∗∗
---------------------------------------------
Cyberkriminelle haben Steam genutzt, um zahlreiche PCs mit Malware zu infizieren. Die Schadsoftware war in Spielen versteckt und wurde gezielt beworben.
---------------------------------------------
https://www.heise.de/news/8-000-PCs-ueber-Steam-infiziert-Cyberkriminelle-v…
∗∗∗ Chaos ransomwares msaRAT: Living off the browser to build a covert C2 channel ∗∗∗
---------------------------------------------
Chaos is a ransomware-as-a-service (RaaS) group whose activity was first confirmed in February 2025. Although the number of listings on their data leak site remains relatively low, the group consistently targets large organizations and employs double extortion tactics. For initial access, they rely on spam emails and voice-based social engineering, commonly known as vishing. Once inside a network, their traditional post-compromise methodology involves abusing remote monitoring and management (RMM) tools to establish persistent access, while leveraging legitimate file-sharing software to exfiltrate data.
---------------------------------------------
https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-b…
∗∗∗ New TrickBot Variant Spotted Using DNS to Control Infected Windows PCs ∗∗∗
---------------------------------------------
Fortinet has found a new TrickBot variant hiding commands in DNS traffic and using scheduled tasks and added modules to maintain access on infected Windows PCs.
---------------------------------------------
https://hackread.com/new-trickbot-variant-dns-control-infected-windows-pcs/
∗∗∗ Dark Elevator: Windows Install Service Local Privilege Escalation (CVE-2026-50343) ∗∗∗
---------------------------------------------
Today we walk through Dark Elevator, a LPE in Windows 11. We reported it to Microsoft on May 20, 2026, and it is now fixed as CVE-2026-50343.
---------------------------------------------
https://blog.calif.io/p/dark-elevator-windows-install-service
∗∗∗ RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) ∗∗∗
---------------------------------------------
Qualys Threat Research Unit (TRU) identified CVE-2026-64600, a race condition in the Linux kernel’s XFS filesystem copy-on-write path. An attacker with an ordinary local account can exploit this race condition to overwrite protected files on disk and gain host root privileges on affected systems, including deployments running SELinux in Enforcing mode.
---------------------------------------------
https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs…
∗∗∗ Silent Replacement of Trusted macOS App Executables ∗∗∗
---------------------------------------------
A vulnerability in macOS allows an attacker to silently replace the main executable of any application downloaded from the web without requiring elevated privileges. As a result, trusted applications can be made to execute attacker-controlled code without triggering security warnings when relaunched. Apple assessed the reported behaviour as not requiring a security fix.
---------------------------------------------
https://mysk.blog/2026/07/23/macos-overwrite-app-executables/
∗∗∗ Next chapter: Restructuring GitHub’s bug bounty program ∗∗∗
---------------------------------------------
GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team.
---------------------------------------------
https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-…
∗∗∗ The CISO Guide to Endpoint Control and Prevention (ECP): The Next Architecture for Endpoint Security ∗∗∗
---------------------------------------------
New category market definition and buyer framework for securing users, agents, identities, and data at the endpoint. A five zone framework for securing AI-centric software at the endpoint.
---------------------------------------------
https://softwareanalyst.substack.com/p/the-ciso-guide-to-endpoint-control
∗∗∗ New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs ∗∗∗
---------------------------------------------
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.
---------------------------------------------
https://socket.dev/blog/slopsquatting-targets-across-frontier-llms?utm_medi…
=====================
= Vulnerabilities =
=====================
∗∗∗ VU#847406: Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability ∗∗∗
---------------------------------------------
Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placing malicious files, such as DLLs, in that directory. To mitigate this vulnerability, install Duplicati in the default C:\Program Files\ directory or update to the latest fixed version.
---------------------------------------------
https://kb.cert.org/vuls/id/847406
∗∗∗ Atlassian: Schadcode-Lücken bedrohen Bamboo und Bitbucket ∗∗∗
---------------------------------------------
Nutzen Angreifer erfolgreich Sicherheitslücken in Atlassian Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira, Jira Service Management oder Sourcetree für macOS/Windows aus, können sie PCs im schlimmsten Fall vollständig kompromittieren. Sicherheitsupdates stehen zum Download bereit.
---------------------------------------------
https://www.heise.de/news/Atlassian-Schadcode-Luecken-bedrohen-Bamboo-und-B…
∗∗∗ Drupal Security Advisories 2026-July-22 ∗∗∗
---------------------------------------------
https://www.drupal.org/security
∗∗∗ Ricoh MFP and Printer Products: Vulnerability in SSH Function ∗∗∗
---------------------------------------------
https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2026-0…
∗∗∗ LWN Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1084401/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 21-07-2026 18:00 − Mittwoch 22-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Critical SharePoint RCE flaw exploited to steal machine keys ∗∗∗
---------------------------------------------
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. [..] While applying the latest SharePoint security updates removes the vulnerability, watchTowr advises defenders to also rotate credentials on any asset that may have been exposed.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw…
∗∗∗ OpenAI hackt beliebtes KI-Portal, macht daraus PR-Stunt ∗∗∗
---------------------------------------------
Die neuesten Modelle seien bei einem Sicherheitstest eigenständig „ausgebrochen“ und hätten Hugging Face attackiert. [..] Der US-Konzern OpenAI hat nun die Verantwortung dafür übernommen.
---------------------------------------------
https://futurezone.at/digital-life/openai-hugging-face-hack-pr-stunt/403177…
∗∗∗ Cyberangriff: Nextcloud-Nutzer wurden auf verdächtige Cloudbox umgeleitet ∗∗∗
---------------------------------------------
Die offizielle Website von Nextcloud ist nach verdächtigen Umleitungen der Besucher temporär vom Netz genommen worden. Ursache war ein Cyberangriff. [..] Da die Nextcloud-Website auf Wordpress basiert, ist denkbar, dass der Angriff unter Ausnutzung zweier kürzlich bekannt gewordener Sicherheitslücken in dem CMS ausgeführt wurde.
---------------------------------------------
https://www.golem.de/news/cyberangriff-nextcloud-nutzer-wurden-auf-verdaech…
∗∗∗ Windows: Global Device ID führt zu gerichtswirksamer Identifikation ∗∗∗
---------------------------------------------
Microsoft nutzt in Windows eine Global Device ID (GDID). Die macht Windows-Installationen eindeutig erkennbar, sie übersteht Neustarts und Windows-Updates und lässt sich nicht entfernen. [..] Auf GitHub hat sich ein User mit dem Handle „SmtimesIWndr“ die Mühe gemacht und Informationen zur Windows GDID zusammengesammelt. Es handelt sich demnach um einen Bestandteil der Windows-Telemetrie, der wird zusammen mit anderen Informationen an Microsofts Server gesendet. [..] Der Global Device Identifier lässt sich also nicht einfach loswerden.
---------------------------------------------
https://heise.de/-11373417
∗∗∗ PyPI: Releases now reject new files after 14 days ∗∗∗
---------------------------------------------
The Python Package Index (PyPI) now rejects new files being uploaded to releases that are older than 14 days. This restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised.
---------------------------------------------
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-…
∗∗∗ LG to Ban Residential Proxies from Smart TV Apps ∗∗∗
---------------------------------------------
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn ones television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LGs webOS store allow unknown third-parties to route their Internet traffic through a users TV.
---------------------------------------------
https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smar…
∗∗∗ Klimabonus-Phishing ist zurück: Klicken Sie nicht auf diesen Mail-Link! ∗∗∗
---------------------------------------------
Die Kriminellen lassen nicht locker: Aktuell wieder in einer neuen Variante betreffend den Klimabonus im Umlauf. Eine betrügerische E-Mail verspricht Empfänger:innen 290 Euro.
---------------------------------------------
https://www.watchlist-internet.at/news/klimabonus-phishing-mail/
∗∗∗ Adobe Chrome extension flaw let sites access private WhatsApp chats ∗∗∗
---------------------------------------------
Exploiting them requires only that the target running the Adobe Acrobat extension be lured to a web page under the threat actor's control. [..] The issue has been fixed in 26.5.2.3 and delivered automatically to users.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-…
∗∗∗ AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code ∗∗∗
---------------------------------------------
Hidden text on a web page was enough to make Kiro, AWSs agentic coding IDE, rewrite its own configuration file and run an attackers code on a developers machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution.
---------------------------------------------
https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html
=====================
= Vulnerabilities =
=====================
∗∗∗ Serv-U: Datentransfersoftware Serv-U hat 15 kritische Sicherheitslücken ∗∗∗
---------------------------------------------
SolarWinds stopft mit dem Update auf Serv-U 2026.3 insgesamt 15 kritische Sicherheitslücken sowie eine mittleren Schweregrads. Die Auswirkungen reichen von der Rechteausweitung über Informationslecks hin zur Ausführung von eingeschleustem Schadcode aus dem Netz.
---------------------------------------------
https://heise.de/-11373098
∗∗∗ Ubuntu: Root-Lücke in snapd gefährdet unzählige Linux-Systeme ∗∗∗
---------------------------------------------
Angreifer können damit ihre Rechte ausweiten und Root-Zugriff erlangen. Laut Blogbeitrag der Forscher gelingt das bei anfälligen Ubuntu-Versionen bereits in der Standardkonfiguration. Patches sind verfügbar und sollten zeitnah installiert werden. [..] Die Ursache liegt in snap-confine, einer Komponente, die für den Aufbau der Ausführungsumgebung von Snap-Paketen zuständig ist. CVE-2026-8933
---------------------------------------------
https://www.golem.de/news/ubuntu-root-luecke-in-snapd-gefaehrdet-unzaehlige…
∗∗∗ Oracle Critical Patch Update Advisory - July 2026 ∗∗∗
---------------------------------------------
This Critical Patch Update contains 1449 new security patches across the product families listed below.
---------------------------------------------
https://www.oracle.com/security-alerts/cpujul2026.html
∗∗∗ Check Point: Security Advisory – Action Required – July 2026 Security Update ∗∗∗
---------------------------------------------
As part of Check Point’s Frontier AI Readiness Program, we are releasing a jumbo hotfix with security and hardening fixes for our firewall and management products. [..] This only affects a very specific configuration — when Management is exposed directly to the internet without IP restrictions. We’ve already notified the affected customers.
---------------------------------------------
https://blog.checkpoint.com/security/security-advisory-action-required-acti…
∗∗∗ Plane: VU#762226: Plane contains multi-tenant authorization bypass vulnerability ∗∗∗
---------------------------------------------
https://kb.cert.org/vuls/id/762226
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1084210/
∗∗∗ QNAP: Kritische Schwachstellen in QNAP NAS File Station 5 ∗∗∗
---------------------------------------------
https://www.syss.de/pentest-blog/kritische-schwachstellen-in-qnap-nas-file-…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 20-07-2026 18:00 − Dienstag 21-07-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ JadePuffer agentic attacks now target AI model data with ransomware ∗∗∗
---------------------------------------------
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-n…
∗∗∗ Attackers Combo Up Evasion Tactics for BEC Phishing ∗∗∗
---------------------------------------------
Researchers at Fortinet since late March have observed the campaign, dubbed "The TFF Trap," which uses a combination of fileless techniques and Lua-based loaders with low detection rates to deploy various malware families, including Agent Tesla, Remcos, XWorm, and Best Private Logger, according to a report published last week. The name comes from attackers' use of a TrueType Font (.ttf) file to hide the AutoIT/Lua loader used to deliver malware.
---------------------------------------------
https://www.darkreading.com/endpoint-security/attackers-combo-evasion-tacti…
∗∗∗ LG Monitors Silently Install Adware-Like App On Windows PCs ∗∗∗
---------------------------------------------
VideoCardz reports that connecting certain LG monitors to Windows PCs can trigger Windows Update to automatically install the LG Monitor App Installer, which runs at startup and repeatedly displays McAfee trial promotions. From the report: Gamers Nexus reproduced the behavior with an LG UltraGear 34GX900A-B after receiving reports from monitor owners. Windows Update first installed LG extension and software component packages.
---------------------------------------------
https://hardware.slashdot.org/story/26/07/20/1736218/lg-monitors-silently-i…
∗∗∗ Malicious cloud customers can bring down the power grid ∗∗∗
---------------------------------------------
The attack, dubbed Bit2Watt, imagines an adversary masquerading as a legitimate cloud tenant to launch GPU workloads that have the potential to damage datacenters and supporting electrical systems. It's intended to demonstrate the need to extend cybersecurity defenses to datacenter workload scheduling.
---------------------------------------------
https://www.theregister.com/ai-and-ml/2026/07/20/malicious-cloud-customers-…
∗∗∗ AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware ∗∗∗
---------------------------------------------
Inside the 7,600-repository FakeGit operation that brought SmartLoader into the AI capability supply chain, using GitHub repositories, public AI registries, and agent-readable instructions to create a new enterprise attack surface.
---------------------------------------------
https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-serv…
∗∗∗ What happens if you visit a WordPress site hacked through wp2shell? ∗∗∗
---------------------------------------------
WordPress has patched a serious core vulnerability chain known as wp2shell, and site owners are understandably focused on updating their own sites. But there’s another question worth asking: what happens to ordinary visitors when they land on a compromised site?
---------------------------------------------
https://www.malwarebytes.com/blog/bugs/2026/07/what-happens-if-you-visit-a-…
∗∗∗ Monday, July 27, 2026 Security Releases ∗∗∗
---------------------------------------------
The Node.js project will release new versions of the 26.x, 24.x, 22.x releases lines on or shortly after, Monday, July 27, 2026 in order to address: The highest severity issue fixed in this release is HIGH.
---------------------------------------------
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases
∗∗∗ Rumänien: Cyberkrimineller löscht die gesamte Grundbuchdatenbank des Landes ∗∗∗
---------------------------------------------
Ein Angreifer löscht die gesamte rumänische Grundbuchdatenbank, nachdem eine Erpressung scheiterte, und bringt damit den Immobilienmarkt zum Stillstand.
---------------------------------------------
https://heise.de/-11371451
∗∗∗ Passkeys in der Praxis – Teil 1: Die Architektur von Passkeys ∗∗∗
---------------------------------------------
So funktionieren Passkeys: Der erste Teil der Praxis-Serie für Entwickler zeigt im Detail die Architektur, die auf FIDO2 und WebAuthn aufbaut.
---------------------------------------------
https://heise.de/-11364345
∗∗∗ Suno-Datenleck: Have I Been Pwned ergänzt 55 Millionen Konten ∗∗∗
---------------------------------------------
Das Have-I-Been-Pwned-Projekt hat mehr als 55 Millionen Konten aus dem Suno-Datenleck zur Datenhalde hinzugefügt.
---------------------------------------------
https://heise.de/-11371843
=====================
= Vulnerabilities =
=====================
∗∗∗ Zimbra: Patch Release Update: Zimbra 10.1.20 ∗∗∗
---------------------------------------------
This release contains fixes for multiple critical security issues including a permanent fix for the critical SNMP vulnerability disclosed in our recent security advisory. The release also includes bug fixes in licensing and mail filtering.
---------------------------------------------
https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/
∗∗∗ Sicherheitspatch Grafana: Angreifer können sensible Daten abgreifen ∗∗∗
---------------------------------------------
Wie aus einer Warnmeldung von GrafanaLabs hervorgeht, ist die Lücke (CVE-2026-28381) als „kritisch“ eingestuft. Dem Beitrag zufolge sind Grafana-Installationen mit aktivem Snowflake-Datasource-Connector von der Schwachstelle betroffen.
---------------------------------------------
https://heise.de/-11371859
∗∗∗ LWN: Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1083948/
∗∗∗ Mozilla Foundation Security Advisories July 21, 2026 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/
∗∗∗ Tenable: [R1] Stand-alone Security Patch Available for Tenable Security Center Versions 6.6.0, 6.7.2 and 6.8.0: SC202607.1 ∗∗∗
---------------------------------------------
https://www.tenable.com/security/tns-2026-19
∗∗∗ Zyxel security advisory for post-authentication command injection vulnerability in certain DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders ∗∗∗
---------------------------------------------
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 17-07-2026 18:00 − Montag 20-07-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Microsoft warns of surge in ACR Stealer attacks on customers ∗∗∗
---------------------------------------------
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-…
∗∗∗ Cyberangriff: Bafin verhängt 240.000 Euro-Strafe gegen Teamviewer ∗∗∗
---------------------------------------------
Weil Teamviewer einen Angriff durch russische Hacker nicht sofort an die Börse meldete, greift die Finanzaufsicht Bafin nun durch.
---------------------------------------------
https://www.golem.de/news/cyberangriff-bafin-verhaengt-240-000-euro-strafe-…
∗∗∗ Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine ∗∗∗
---------------------------------------------
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops.
---------------------------------------------
https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html
∗∗∗ Critical ServiceNow code execution flaw now exploited in attacks ∗∗∗
---------------------------------------------
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/critical-servicenow-code-exe…
∗∗∗ New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens ∗∗∗
---------------------------------------------
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys.
---------------------------------------------
https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
∗∗∗ Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT ∗∗∗
---------------------------------------------
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack.
---------------------------------------------
https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html
∗∗∗ SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
---------------------------------------------
https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html
∗∗∗ HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 ∗∗∗
---------------------------------------------
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.
---------------------------------------------
https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.h…
∗∗∗ IPFire: Knot Resolver ersetzt Unbound ∗∗∗
---------------------------------------------
IPFire Core Update 203 ersetzt Unbound durch Knot Resolver, bringt DNS-Firewall, DoT und 6-GHz-WLAN.
---------------------------------------------
https://www.heise.de/news/IPFire-Knot-Resolver-ersetzt-Unbound-11371136.html
∗∗∗ 7 Sandbox Escape Vulnerabilities Across 4 Coding Agent Vendors ∗∗∗
---------------------------------------------
Over several months, Pillar Research found and reproduced sandbox escapes and boundary bypasses across Cursor, Codex, Gemini CLI, and Antigravity. In almost every case, the agent did not need to break the sandbox directly. It only had to write something that a trusted component outside the sandbox would later run, load, scan, or treat as safe. In aggregate, these vulnerabilities show that AI coding agents change the endpoint threat model, and that most sandbox designs have not caught up.
---------------------------------------------
https://www.pillar.security/blog/the-week-of-sandbox-escapes
∗∗∗ Abbott Laboratories probes two cyber incidents amid extortion claims ∗∗∗
---------------------------------------------
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-t…
=====================
= Vulnerabilities =
=====================
∗∗∗ Kritische Sicherheitslücken in WordPress - Updates verfügbar ∗∗∗
---------------------------------------------
In WordPress existieren zwei Sicherheitslücken. Eine SQL-Injection-Schwachstelle im Parameter „author__not_in“ von „WP_Query“ betrifft WordPress ab Version 6.8. Ab WordPress 6.9 lässt sich diese laut Advisory in Kombination mit einer Schwachstelle in der REST-API (Batch-Route-Confusion) zur Ausführung von beliebigem Code (Remote Code Execution) ausnutzen. Laut Searchlight Cyber ist diese Angriffskette ohne vorherige Authentifizierung und ohne weitere Voraussetzungen in einer Standardinstallation ohne Plugins nutzbar.
---------------------------------------------
https://www.cert.at/de/warnungen/2026/7/kritische-sicherheitslucken-in-word…
∗∗∗ Update now: 7-Zip fixes RCE flaw exploitable with malicious archives ∗∗∗
---------------------------------------------
7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. The vulnerability, disclosed by Lunbun researcher Landon Peng, exists in 7-Zip's processing of XZ-compressed data. According to an advisory from the Zero Day Initiative published this week, a specially crafted XZ data can trigger a heap-based buffer overflow, potentially allowing attackers to execute arbitrary code as the user.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/update-now-7-zip-fixes-rce-f…
∗∗∗ Angriff mit nur 11 Bytes: OpenSSL-Bug lässt Speicher von Servern volllaufen ∗∗∗
---------------------------------------------
Durch eine Sicherheitslücke in OpenSSL können Angreifer mit 11-Byte-Paketen den RAM anfälliger Server stark auslasten und Ausfälle herbeiführen.
---------------------------------------------
https://www.golem.de/news/angriff-mit-nur-11-bytes-openssl-bug-laesst-speic…
∗∗∗ Cyberangriff auf Hugging Face: KI erkennt KI-Angriff auf KI-Plattform ∗∗∗
---------------------------------------------
Hugging Face hat einen von KI-Agenten ausgeführten Cyberangriff per KI entdeckt. Der Zugriff gelang durch Sicherheitslücken in der KI-Plattform.
---------------------------------------------
https://www.golem.de/news/cyberangriff-auf-hugging-face-ki-erkennt-ki-angri…
∗∗∗ Kritische Sicherheitslücke: Schadcode kann auf Nginx-Server schlüpfen ∗∗∗
---------------------------------------------
Angreifer können Nginx Open Source und Nginx Plus attackieren. Sicherheitsupdates sind verfügbar.
---------------------------------------------
https://www.heise.de/news/Kritische-Sicherheitsluecke-Schadcode-kann-auf-Ng…
∗∗∗ Microsoft verteilt außerplanmäßiges Windows-Update ∗∗∗
---------------------------------------------
Microsoft verteilt ein ungeplantes Windows-Update. Es soll Probleme beheben, die insbesondere bei Dell-Computern aufgetreten sind.
---------------------------------------------
https://www.heise.de/news/Windows-Update-ausser-der-Reihe-korrigiert-Perfor…
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1083708/
∗∗∗ Langflow 1.3.0 Remote Code Execution ∗∗∗
---------------------------------------------
https://cxsecurity.com/issue/WLB-2026070007
∗∗∗ K000162343: Multiple Oracle Java SE vulnerabilities ∗∗∗
---------------------------------------------
https://my.f5.com/manage/s/article/K000162343
∗∗∗ Case closed: DIVD-2025-00003 - Multiple vulnerabilities in Mennekes Smart / Premium Charging stations ∗∗∗
---------------------------------------------
https://csirt.divd.nl/cases/DIVD-2025-00003/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/