=====================
= End-of-Day report =
=====================
Timeframe: Montag 20-07-2026 18:00 − Dienstag 21-07-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ JadePuffer agentic attacks now target AI model data with ransomware ∗∗∗
---------------------------------------------
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-n…
∗∗∗ Attackers Combo Up Evasion Tactics for BEC Phishing ∗∗∗
---------------------------------------------
Researchers at Fortinet since late March have observed the campaign, dubbed "The TFF Trap," which uses a combination of fileless techniques and Lua-based loaders with low detection rates to deploy various malware families, including Agent Tesla, Remcos, XWorm, and Best Private Logger, according to a report published last week. The name comes from attackers' use of a TrueType Font (.ttf) file to hide the AutoIT/Lua loader used to deliver malware.
---------------------------------------------
https://www.darkreading.com/endpoint-security/attackers-combo-evasion-tacti…
∗∗∗ LG Monitors Silently Install Adware-Like App On Windows PCs ∗∗∗
---------------------------------------------
VideoCardz reports that connecting certain LG monitors to Windows PCs can trigger Windows Update to automatically install the LG Monitor App Installer, which runs at startup and repeatedly displays McAfee trial promotions. From the report: Gamers Nexus reproduced the behavior with an LG UltraGear 34GX900A-B after receiving reports from monitor owners. Windows Update first installed LG extension and software component packages.
---------------------------------------------
https://hardware.slashdot.org/story/26/07/20/1736218/lg-monitors-silently-i…
∗∗∗ Malicious cloud customers can bring down the power grid ∗∗∗
---------------------------------------------
The attack, dubbed Bit2Watt, imagines an adversary masquerading as a legitimate cloud tenant to launch GPU workloads that have the potential to damage datacenters and supporting electrical systems. It's intended to demonstrate the need to extend cybersecurity defenses to datacenter workload scheduling.
---------------------------------------------
https://www.theregister.com/ai-and-ml/2026/07/20/malicious-cloud-customers-…
∗∗∗ AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware ∗∗∗
---------------------------------------------
Inside the 7,600-repository FakeGit operation that brought SmartLoader into the AI capability supply chain, using GitHub repositories, public AI registries, and agent-readable instructions to create a new enterprise attack surface.
---------------------------------------------
https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-serv…
∗∗∗ What happens if you visit a WordPress site hacked through wp2shell? ∗∗∗
---------------------------------------------
WordPress has patched a serious core vulnerability chain known as wp2shell, and site owners are understandably focused on updating their own sites. But there’s another question worth asking: what happens to ordinary visitors when they land on a compromised site?
---------------------------------------------
https://www.malwarebytes.com/blog/bugs/2026/07/what-happens-if-you-visit-a-…
∗∗∗ Monday, July 27, 2026 Security Releases ∗∗∗
---------------------------------------------
The Node.js project will release new versions of the 26.x, 24.x, 22.x releases lines on or shortly after, Monday, July 27, 2026 in order to address: The highest severity issue fixed in this release is HIGH.
---------------------------------------------
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases
∗∗∗ Rumänien: Cyberkrimineller löscht die gesamte Grundbuchdatenbank des Landes ∗∗∗
---------------------------------------------
Ein Angreifer löscht die gesamte rumänische Grundbuchdatenbank, nachdem eine Erpressung scheiterte, und bringt damit den Immobilienmarkt zum Stillstand.
---------------------------------------------
https://heise.de/-11371451
∗∗∗ Passkeys in der Praxis – Teil 1: Die Architektur von Passkeys ∗∗∗
---------------------------------------------
So funktionieren Passkeys: Der erste Teil der Praxis-Serie für Entwickler zeigt im Detail die Architektur, die auf FIDO2 und WebAuthn aufbaut.
---------------------------------------------
https://heise.de/-11364345
∗∗∗ Suno-Datenleck: Have I Been Pwned ergänzt 55 Millionen Konten ∗∗∗
---------------------------------------------
Das Have-I-Been-Pwned-Projekt hat mehr als 55 Millionen Konten aus dem Suno-Datenleck zur Datenhalde hinzugefügt.
---------------------------------------------
https://heise.de/-11371843
=====================
= Vulnerabilities =
=====================
∗∗∗ Zimbra: Patch Release Update: Zimbra 10.1.20 ∗∗∗
---------------------------------------------
This release contains fixes for multiple critical security issues including a permanent fix for the critical SNMP vulnerability disclosed in our recent security advisory. The release also includes bug fixes in licensing and mail filtering.
---------------------------------------------
https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/
∗∗∗ Sicherheitspatch Grafana: Angreifer können sensible Daten abgreifen ∗∗∗
---------------------------------------------
Wie aus einer Warnmeldung von GrafanaLabs hervorgeht, ist die Lücke (CVE-2026-28381) als „kritisch“ eingestuft. Dem Beitrag zufolge sind Grafana-Installationen mit aktivem Snowflake-Datasource-Connector von der Schwachstelle betroffen.
---------------------------------------------
https://heise.de/-11371859
∗∗∗ LWN: Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1083948/
∗∗∗ Mozilla Foundation Security Advisories July 21, 2026 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/
∗∗∗ Tenable: [R1] Stand-alone Security Patch Available for Tenable Security Center Versions 6.6.0, 6.7.2 and 6.8.0: SC202607.1 ∗∗∗
---------------------------------------------
https://www.tenable.com/security/tns-2026-19
∗∗∗ Zyxel security advisory for post-authentication command injection vulnerability in certain DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders ∗∗∗
---------------------------------------------
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 17-07-2026 18:00 − Montag 20-07-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Microsoft warns of surge in ACR Stealer attacks on customers ∗∗∗
---------------------------------------------
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-…
∗∗∗ Cyberangriff: Bafin verhängt 240.000 Euro-Strafe gegen Teamviewer ∗∗∗
---------------------------------------------
Weil Teamviewer einen Angriff durch russische Hacker nicht sofort an die Börse meldete, greift die Finanzaufsicht Bafin nun durch.
---------------------------------------------
https://www.golem.de/news/cyberangriff-bafin-verhaengt-240-000-euro-strafe-…
∗∗∗ Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine ∗∗∗
---------------------------------------------
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops.
---------------------------------------------
https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html
∗∗∗ Critical ServiceNow code execution flaw now exploited in attacks ∗∗∗
---------------------------------------------
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/critical-servicenow-code-exe…
∗∗∗ New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens ∗∗∗
---------------------------------------------
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys.
---------------------------------------------
https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
∗∗∗ Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT ∗∗∗
---------------------------------------------
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack.
---------------------------------------------
https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html
∗∗∗ SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
---------------------------------------------
https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html
∗∗∗ HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 ∗∗∗
---------------------------------------------
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.
---------------------------------------------
https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.h…
∗∗∗ IPFire: Knot Resolver ersetzt Unbound ∗∗∗
---------------------------------------------
IPFire Core Update 203 ersetzt Unbound durch Knot Resolver, bringt DNS-Firewall, DoT und 6-GHz-WLAN.
---------------------------------------------
https://www.heise.de/news/IPFire-Knot-Resolver-ersetzt-Unbound-11371136.html
∗∗∗ 7 Sandbox Escape Vulnerabilities Across 4 Coding Agent Vendors ∗∗∗
---------------------------------------------
Over several months, Pillar Research found and reproduced sandbox escapes and boundary bypasses across Cursor, Codex, Gemini CLI, and Antigravity. In almost every case, the agent did not need to break the sandbox directly. It only had to write something that a trusted component outside the sandbox would later run, load, scan, or treat as safe. In aggregate, these vulnerabilities show that AI coding agents change the endpoint threat model, and that most sandbox designs have not caught up.
---------------------------------------------
https://www.pillar.security/blog/the-week-of-sandbox-escapes
∗∗∗ Abbott Laboratories probes two cyber incidents amid extortion claims ∗∗∗
---------------------------------------------
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-t…
=====================
= Vulnerabilities =
=====================
∗∗∗ Kritische Sicherheitslücken in WordPress - Updates verfügbar ∗∗∗
---------------------------------------------
In WordPress existieren zwei Sicherheitslücken. Eine SQL-Injection-Schwachstelle im Parameter „author__not_in“ von „WP_Query“ betrifft WordPress ab Version 6.8. Ab WordPress 6.9 lässt sich diese laut Advisory in Kombination mit einer Schwachstelle in der REST-API (Batch-Route-Confusion) zur Ausführung von beliebigem Code (Remote Code Execution) ausnutzen. Laut Searchlight Cyber ist diese Angriffskette ohne vorherige Authentifizierung und ohne weitere Voraussetzungen in einer Standardinstallation ohne Plugins nutzbar.
---------------------------------------------
https://www.cert.at/de/warnungen/2026/7/kritische-sicherheitslucken-in-word…
∗∗∗ Update now: 7-Zip fixes RCE flaw exploitable with malicious archives ∗∗∗
---------------------------------------------
7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. The vulnerability, disclosed by Lunbun researcher Landon Peng, exists in 7-Zip's processing of XZ-compressed data. According to an advisory from the Zero Day Initiative published this week, a specially crafted XZ data can trigger a heap-based buffer overflow, potentially allowing attackers to execute arbitrary code as the user.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/update-now-7-zip-fixes-rce-f…
∗∗∗ Angriff mit nur 11 Bytes: OpenSSL-Bug lässt Speicher von Servern volllaufen ∗∗∗
---------------------------------------------
Durch eine Sicherheitslücke in OpenSSL können Angreifer mit 11-Byte-Paketen den RAM anfälliger Server stark auslasten und Ausfälle herbeiführen.
---------------------------------------------
https://www.golem.de/news/angriff-mit-nur-11-bytes-openssl-bug-laesst-speic…
∗∗∗ Cyberangriff auf Hugging Face: KI erkennt KI-Angriff auf KI-Plattform ∗∗∗
---------------------------------------------
Hugging Face hat einen von KI-Agenten ausgeführten Cyberangriff per KI entdeckt. Der Zugriff gelang durch Sicherheitslücken in der KI-Plattform.
---------------------------------------------
https://www.golem.de/news/cyberangriff-auf-hugging-face-ki-erkennt-ki-angri…
∗∗∗ Kritische Sicherheitslücke: Schadcode kann auf Nginx-Server schlüpfen ∗∗∗
---------------------------------------------
Angreifer können Nginx Open Source und Nginx Plus attackieren. Sicherheitsupdates sind verfügbar.
---------------------------------------------
https://www.heise.de/news/Kritische-Sicherheitsluecke-Schadcode-kann-auf-Ng…
∗∗∗ Microsoft verteilt außerplanmäßiges Windows-Update ∗∗∗
---------------------------------------------
Microsoft verteilt ein ungeplantes Windows-Update. Es soll Probleme beheben, die insbesondere bei Dell-Computern aufgetreten sind.
---------------------------------------------
https://www.heise.de/news/Windows-Update-ausser-der-Reihe-korrigiert-Perfor…
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1083708/
∗∗∗ Langflow 1.3.0 Remote Code Execution ∗∗∗
---------------------------------------------
https://cxsecurity.com/issue/WLB-2026070007
∗∗∗ K000162343: Multiple Oracle Java SE vulnerabilities ∗∗∗
---------------------------------------------
https://my.f5.com/manage/s/article/K000162343
∗∗∗ Case closed: DIVD-2025-00003 - Multiple vulnerabilities in Mennekes Smart / Premium Charging stations ∗∗∗
---------------------------------------------
https://csirt.divd.nl/cases/DIVD-2025-00003/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 16-07-2026 18:00 − Freitag 17-07-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Kurz nach Microsoft-Patchday: Kritische Sharepoint-Lücke wird aktiv ausgenutzt ∗∗∗
---------------------------------------------
Bei der besagten Sicherheitslücke handelt es sich um CVE-2026-58644. Laut Beschreibung kann ein Angreifer damit aus der Ferne Schadcode einschleusen und zur Ausführung bringen. Ursache ist eine mögliche Deserialisierung nicht-vertrauenswürdiger Daten in Microsoft Sharepoint. Den Angaben zufolge muss ein Angreifer für eine erfolgreiche Ausnutzung mindestens als Site Owner authentifiziert sein.
---------------------------------------------
https://www.golem.de/news/kurz-nach-microsoft-patchday-kritische-sharepoint…
∗∗∗ Claude Chrome extension flaw lets malicious extensions trigger AI actions ∗∗∗
---------------------------------------------
A flaw in Anthropics Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claudes access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/claude-chrome-extension-flaw…
∗∗∗ New ClickLock macOS malware traps users into revealing login password ∗∗∗
---------------------------------------------
A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-clicklock-macos-malware-…
∗∗∗ Ernst & Young discloses data breach after support system hack ∗∗∗
---------------------------------------------
Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-da…
∗∗∗ 1M+ Emails Use Hidden Text to Dupe AI Security Filters ∗∗∗
---------------------------------------------
Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox.
---------------------------------------------
https://www.darkreading.com/threat-intelligence/1m-emails-hidden-text-dupe-…
∗∗∗ Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images ∗∗∗
---------------------------------------------
North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges.
---------------------------------------------
https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html
∗∗∗ Windows Server 2022: Mainstream-Support endet in 90 Tagen ∗∗∗
---------------------------------------------
Windows Server 2022 fällt in 90 Tagen aus dem Mainstream-Support. Erweiterte Sicherheitsupdates gibt es bis 2031 – und danach ESU.
---------------------------------------------
https://www.heise.de/news/Windows-Server-2022-Mainstream-Support-endet-in-9…
∗∗∗ AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report ∗∗∗
---------------------------------------------
The report spotlights four defining trends shaping the threat landscape. We’ll take a closer look at Trend 1: AI Has Become a Force Multiplier for Attackers.
---------------------------------------------
https://unit42.paloaltonetworks.com/ai-incident-response-report/
=====================
= Vulnerabilities =
=====================
∗∗∗ Google Chrome: Ungeplantes Sicherheitsupdate Nummer zwei in dieser Woche ∗∗∗
---------------------------------------------
Google aktualisiert Chrome eigentlich jeden Mittwoch. Diese Woche folgt ein zweites Update, das mehrere kritische Lücken schließt. [..] Drei davon gelten als „kritisch“, es handelt sich um nicht näher erläuterte Use-after-free-Schwachstellen in den Komponenten CameraCapture (CVE-2026-15899), GPU (CVE-2026-15900) sowie Network (CVE-2026-15901).
---------------------------------------------
https://heise.de/-11368362
∗∗∗ Critical Notepad++ Bugs Could Lead to Code Execution, Patch Available ∗∗∗
---------------------------------------------
The latest Notepad++ vulnerabilities addressed in version 8.9.7 include several high-impact security flaws that could expose Windows systems to arbitrary code execution, file overwrite attacks, memory corruption, and authentication bypass. Among the most critical issues is a PowerShell command injection vulnerability in the installer, alongside fixes for CVE-2026-52886, CVE-2026-54758, and CVE-2026-57233.
---------------------------------------------
https://thecyberexpress.com/notepad-vulnerabilities-v897/
∗∗∗ VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions ∗∗∗
---------------------------------------------
https://kb.cert.org/vuls/id/885548
∗∗∗ LWN: Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1083388/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 15-07-2026 18:00 − Donnerstag 16-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Have I Been Pwned: 821.100 Datensätze von Messgerätehersteller Fluke ergänzt ∗∗∗
---------------------------------------------
Das Have-I-Been-Pwned-Projekt hat 821.100 Kontodaten des Messgeräteherstellers Fluke zur Datenhalde hinzugefügt.
---------------------------------------------
https://heise.de/-11367041
∗∗∗ GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration ∗∗∗
---------------------------------------------
Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.
---------------------------------------------
https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/
∗∗∗ Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide ∗∗∗
---------------------------------------------
Pull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people's Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaintext.
---------------------------------------------
https://thehackernews.com/2026/07/unpatched-shark-vacuum-flaw-could-let.html
∗∗∗ New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands ∗∗∗
---------------------------------------------
Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that's been spreading via websites infected with ClickFix lures since late April 2026.
---------------------------------------------
https://thehackernews.com/2026/07/new-telepuz-malware-spreads-via.html
∗∗∗ Booking-Betrug per WhatsApp: Gefälschte Nachricht fordert Datenbestätigung ∗∗∗
---------------------------------------------
Der Urlaub ist gebucht, die Vorfreude groß, und dann meldet sich plötzlich der Vermieter über WhatsApp: Die Reservierung müsse noch einmal bestätigt werden, sonst drohe die Stornierung. Klingt nach Routine, ist aber eine Falle. Dahinter stecken Kriminelle, die sich Zugang zu echten Buchungsdaten verschafft haben.
---------------------------------------------
https://www.watchlist-internet.at/news/booking-betrug-per-whatsapp/
∗∗∗ UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign ∗∗∗
---------------------------------------------
Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.
---------------------------------------------
https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and…
=====================
= Vulnerabilities =
=====================
∗∗∗ Webkonferenztool Zoom: Kontoübernahme aus dem Netz möglich ∗∗∗
---------------------------------------------
Zoom hat mehrere Sicherheitslücken in der Webkonferenzsoftware geschlossen. Sie ermöglichen etwa Kontoübernahme aus dem Netz.
---------------------------------------------
https://www.heise.de/news/Webkonferenztool-Zoom-Kontouebernahme-aus-dem-Net…
∗∗∗ Cisco RoomOS Security Hardening Release: July 2026 ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Cisco Identity Services Engine Path Traversal Vulnerability ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Splunk Security Advisories 2026-07-15 (1x Critical) ∗∗∗
---------------------------------------------
https://advisory.splunk.com//advisories
∗∗∗ Drupal Security advisories 2026-July-15 ∗∗∗
---------------------------------------------
https://www.drupal.org/security
∗∗∗ LWN Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1083201/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 14-07-2026 18:00 − Mittwoch 15-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ CISA sounds alarm over trio of exploited SharePoint flaws ∗∗∗
---------------------------------------------
Three bugs are under active attack, and two more critical holes could add to the pain. [..] Additionally, CISA appears concerned by CVE-2026-45659 (8.8) – a remote code execution (RCE) flaw made public in June and confirmed as being actively used in attacks last week after Microsoft said exploitation was "less likely."
---------------------------------------------
https://www.theregister.com/security/2026/07/15/cisa-sounds-alarm-over-trio…
∗∗∗ Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday ∗∗∗
---------------------------------------------
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. [..] What makes it notable is that it's functional on all supported desktop and server versions of Windows, including those running the latest July 2026 Patch Tuesday update. [..] Microsoft told The Hacker News that it's investigating the new report.
---------------------------------------------
https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html
∗∗∗ US charges alleged operators of Russian bulletproof hosting service ∗∗∗
---------------------------------------------
U.S. federal prosecutors have unsealed charges against three Russian nationals, accusing them of providing bulletproof hosting (BPH) services to ransomware gangs that caused over $62 million in damages to victims worldwide. [..] The two BPH services, Media Land and ML.Cloud, also provided customers with infrastructure in multiple countries outside Russia, including China, Finland, the Netherlands, as well as the United States.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/us-charges-alleged-russian-b…
∗∗∗ LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. [..] The starting point of the attack chain is an executable named "nvidia-sysruntime.exe," which impersonates NVIDIA's container runtime toolkit.
---------------------------------------------
https://thehackernews.com/2026/07/labubarat-masquerades-as-nvidia.html
∗∗∗ Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution ∗∗∗
---------------------------------------------
Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. [..] We asked Cursor to name any release that fixes it, and Mindgard, which version it last tested. This story will be updated with any response. [..] Mindgard is not the first firm to find this, and not the first to get Cursor's answer on it.
---------------------------------------------
https://thehackernews.com/2026/07/cursor-flaw-lets-malicious-cloned.html
∗∗∗ Spotify: "Ihr Zugang läuft ab" ∗∗∗
---------------------------------------------
Eine gefälschte Mail von Spotify sorgt gerade für Verunsicherung. Die Abbuchung sei fehlgeschlagen, heißt es darin. Das Premium-Abo drohe zu verfallen. Ignorieren Sie die Mail und klicken Sie nicht auf den Link!
---------------------------------------------
https://www.watchlist-internet.at/news/spotify-laeuft-ab/
∗∗∗ TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development ∗∗∗
---------------------------------------------
TuxBot is a modular IoT botnet framework derived from various known IoT botnet codebases. Based on our analysis of the samples, TuxBot includes features borrowed from the known botnet AISURU and the publicly unknown Wuhan botnet lineages.
---------------------------------------------
https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/
∗∗∗ Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet ∗∗∗
---------------------------------------------
This report walks through the interaction between the threat actor and the AI agent and explains how this methodology is trivially portable to other threat actors, how the threat landscape has changed with AI, and provide detection guidance for defenders.
---------------------------------------------
https://www.trendmicro.com/en_us/research/26/g/actor-behind-patriot-bait-us…
∗∗∗ Ungeschützte Wechselrichter: Hoymiles verspricht Update ∗∗∗
---------------------------------------------
In der vergangenen Woche hat der Chaos Computer Club (CCC) auf eine Sicherheitslücke in Wechselrichtern von Hoymiles hingewiesen, durch die die Geräte aus hunderten Metern Entfernung manipuliert, abgeschaltet oder sogar zerstört werden können. Jetzt hat der Hersteller reagiert und verspricht ein Firmware-Update, das derartige Angriffe verhindern soll.
---------------------------------------------
https://heise.de/-11365046
∗∗∗ Fake-GitHub-Repositorys: Infostealer statt Security- oder Developer-Tools ∗∗∗
---------------------------------------------
Gut 290 GitHub-Repositorys, die angeblich von Securityanbietern, Toolherstellern und weiteren Firmen sind, verteilen Schadcode zum Abgreifen von Daten.
---------------------------------------------
https://heise.de/-11365096
=====================
= Vulnerabilities =
=====================
∗∗∗ VMSA-2026-0005: VMware Avi Load Balancer addresses multiple vulnerabilities (CVE-2026-47865, CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, CVE-2026-47871) ∗∗∗
---------------------------------------------
VMware Avi Load Balancer contains an authentication bypass vulnerability. Broadcom has evaluated the severity of the issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism.
---------------------------------------------
https://support.broadcom.com/web/ecx/support-content-notification/-/externa…
∗∗∗ Microsoft-Patchday: Neuer Rekord mit 622 gefixten Schwachstellen ∗∗∗
---------------------------------------------
Rund 60 der Sicherheitslücken stuft Microsoft als „kritisches“ Sicherheitsrisiko ein. [..] An fünfter Stelle findet sich bereits der SharePoint-Server mit 17 neuen CVE-Schwachstelleneinträgen, den es nun härter erwischt hat. [..] Angreifer missbrauchen bereits eine fehlende Authentifizierung zur Ausweitung ihrer Rechte in SharePoint.
---------------------------------------------
https://www.heise.de/news/Microsoft-Patchday-Neuer-Rekord-mit-622-gefixten-…
∗∗∗ Exchange Server: Sicherheitsupdates 14. Juli 2026 ∗∗∗
---------------------------------------------
Durch die Installation des Updates vom 14. Juli 2026 werden bereits angewendete Abhilfemaßnahmen für CVE-2026-42897 (siehe z.B. Microsofts Beitrag Addressing Exchange Server May 2026 vulnerability CVE-2026-42897) nicht automatisch entfernt. Daher sollten Administratoren nach der Installation des Juli 2026-SU die nachfolgenden Hinweise beachten.
---------------------------------------------
https://borncity.com/blog/2026/07/15/exchange-server-sicherheitsupdates-14-…
∗∗∗ Adobe: Security updates available for Adobe ColdFusion | APSB26-82 ∗∗∗
---------------------------------------------
https://helpx.adobe.com/in/security/products/coldfusion/apsb26-82.html
∗∗∗ Adobe: Security update available for Adobe Commerce | APSB26-73 ∗∗∗
---------------------------------------------
https://helpx.adobe.com/in/security/products/magento/apsb26-73.html
∗∗∗ Adobe: Security updates available for Adobe Experience Manager | APSB26-74 ∗∗∗
---------------------------------------------
https://helpx.adobe.com/in/security/products/experience-manager/apsb26-74.h…
∗∗∗ Google: Chrome Stable Channel Update for Desktop ∗∗∗
---------------------------------------------
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-des…
∗∗∗ Mozilla: Security Vulnerabilities fixed in Firefox 152.0.6 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/
∗∗∗ TYPO3-CORE-SA-2026-020: Unrestricted File Upload in Form Framework ∗∗∗
---------------------------------------------
https://news.typo3.com/security/advisory/typo3-core-sa-2026-020
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1083044/
∗∗∗ WebKitGTK and WPE WebKit Security Advisory WSA-2026-0004 ∗∗∗
---------------------------------------------
https://webkitgtk.org/security/WSA-2026-0004.html
∗∗∗ [R1] Tenable Agent Versions 11.2.1 and 11.1.4 Fix a Path Traversal Vulnerability ∗∗∗
---------------------------------------------
https://www.tenable.com/security/tns-2026-18
∗∗∗ Veeam Software Appliance/Veeam Infrastructure Appliance — Updater Component Vulnerability ∗∗∗
---------------------------------------------
https://www.veeam.com/kb4879
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 13-07-2026 18:00 − Dienstag 14-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Cyber-Angriff: Außenministerium bestellt Russlands Botschafter ein ∗∗∗
---------------------------------------------
2020 wurde eine Cyber-Attacke auf das österreichische Außenministerium verübt - Meinl-Reisinger: "Cyberangriffe sind inakzeptabel"
---------------------------------------------
https://www.derstandard.at/story/3000000331482/cyber-angriff-aussenminister…
∗∗∗ New phishing kits target Microsoft 365 accounts, evade MFA ∗∗∗
---------------------------------------------
Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA).
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-phishing-kits-target-mic…
∗∗∗ LastPass, Bitwarden users targeted with fake security alerts ∗∗∗
---------------------------------------------
LastPass is warning users about an ongoing phishing campaign that is using fake security notices to direct them to fraudulent websites.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/lastpass-bitwarden-users-tar…
∗∗∗ Next.js strukturiert Sicherheitsmeldungen neu ∗∗∗
---------------------------------------------
Next.js will Sicherheitsmeldungen künftig strukturiert und planbar monatlich veröffentlichen. Kritische Warnungen kommen nach wie vor ad hoc.
---------------------------------------------
https://www.heise.de/news/Next-js-strukturiert-Sicherheitsmeldungen-neu-113…
∗∗∗ Microsoft SharePoint 2016/2019 ab 14. Juli 2026 EOL ∗∗∗
---------------------------------------------
IT-Spezialisten und Administratoren haben den heutigen Juli 2026-Patchday sicherlich im Kalender. Blog-Leser Markus S. hat mich gestern daran erinnert, dass Microsofts SharePoint 2016-Server am heutigen 14. Juli 2026 letztmalig Sicherheitsupdates erhält. Denn SharePoint 2016 erreicht heute sein "End of Life" und bekommt auch keinen Support mehr. Aber auch SharePoint 2019 erreicht sein EOL zum Juli 2026-Patchday.
---------------------------------------------
https://borncity.com/blog/2026/07/14/microsoft-sharepoint-2016-ab-14-juli-2…
∗∗∗ Compromised AsyncAPI packages on npm deliver malware ∗∗∗
---------------------------------------------
A commit to the AsyncAPI generator GitHub repository injected obfuscated JavaScript into four npm packages with a combined weekly download volume of over 3 million. Heres what we know and how to check if youre affected.
---------------------------------------------
https://securitylabs.datadoghq.com/articles/compromised-asyncapi-npm-packag…
∗∗∗ Microsoft macht Passkeys zum Standard in Entra ID ∗∗∗
---------------------------------------------
Microsoft führt Passkeys als Standard-Anmeldemethode in Entra ID ein. SMS- und Sprachanrufe laufen schrittweise aus.
---------------------------------------------
https://www.heise.de/news/Microsoft-macht-Passkeys-zum-Standard-in-Entra-ID…
=====================
= Vulnerabilities =
=====================
∗∗∗ Alte Cisco-Lücke attackiert: Leitfaden zum Schutz ∗∗∗
---------------------------------------------
Die US-IT-Sicherheitsbehörde CISA warnt vor Angriffen auf eine 18 Jahre alte Cisco-Lücke. Ein Leitfaden soll helfen, Router abzusichern.
---------------------------------------------
https://www.heise.de/news/Alte-Cisco-Luecke-attackiert-Leitfaden-zum-Schutz…
∗∗∗ SAP-Patchday: Teils kritische Sicherheitslücken in mehreren Produkten gefixt ∗∗∗
---------------------------------------------
Im Juli verarzten die Programmierer von SAP 16 teils kritische Sicherheitslücken in mehreren Produkten.
---------------------------------------------
https://www.heise.de/news/SAP-Patchday-Teils-kritische-Sicherheitsluecken-i…
∗∗∗ M5Burner: Flash-Tool für M5Stack-Geräte potenziell gefährlich ∗∗∗
---------------------------------------------
Das offizielle Flash-Tool für M5Stack-Geräte weist gravierende Sicherheitsmängel auf. Ein Leser hat die Probleme analysiert und sicheren Ersatz entwickelt.
---------------------------------------------
https://heise.de/-11364555
∗∗∗ 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot ∗∗∗
---------------------------------------------
Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard.
---------------------------------------------
https://thehackernews.com/2026/07/11-old-microsoft-signed-linux-uefi.html
∗∗∗ RabbitMQ Vulnerability Exposes OAuth Secrets to Attackers ∗∗∗
---------------------------------------------
A newly disclosed RabbitMQ vulnerability, tracked as CVE-2026-5721, has raised concerns among enterprise users after researchers revealed that the flaw could allow unauthenticated attackers to retrieve a broker’s confidential OAuth client secret. The successful exploitation could enable attackers to impersonate the broker, obtain administrator-level access, and potentially take control of the messaging infrastructure.
---------------------------------------------
https://thecyberexpress.com/cve-2026-5721-rabbitmq-vulnerability/
∗∗∗ LWN Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1082832/
∗∗∗ PSIRT Out of bounds read in GUI ∗∗∗
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-146
∗∗∗ PSIRT Unauthenticated VNC access exposed on all interfaces ∗∗∗
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-145
∗∗∗ Ivanti July 2026 Security Update ∗∗∗
---------------------------------------------
https://www.ivanti.com/blog/july-2026-security-update
∗∗∗ XSA-498 ∗∗∗
---------------------------------------------
https://xenbits.xen.org/xsa/advisory-498.html
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 10-07-2026 18:00 − Montag 13-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Progress warnt Admins: ShareFile deaktivieren ∗∗∗
---------------------------------------------
Ein Betroffener hat einen Screenshot der E-Mail von Progress auf Reddit geteilt. Das Unternehmen schreibt dort, dass es Grund zur Annahme hat, dass eine glaubwürdige Sicherheitsbedrohung von außerhalb besteht. Betroffen sind Progress ShareFile Storage Zone Controller. Es gebe keine Hinweise auf unbefugte Zugriffe auf ShareFile-Konten oder Daten.
---------------------------------------------
https://www.heise.de/news/Progress-warnt-Admins-ShareFile-deaktivieren-1136…
∗∗∗ Bootloader angreifbar: Sicherheitslücken in U-Boot gefährden unzählige Systeme ∗∗∗
---------------------------------------------
U-Boot unterstützt verschiedene CPU-Architekturen wie x86, Arm, Mips, Risc-V und PowerPC und kommt unter anderem auf smarten Kameras, Routern und bei Embedded Systemen zum Einsatz. [..] ngreifer können anfällige Systeme damit zum Absturz bringen und im schlimmsten Fall sogar Schadcode einschleusen, der vor dem Start des Betriebssystems ausgeführt wird. Patches sind zwar verfügbar, müssen aber von Herstellern weitergereicht werden.
---------------------------------------------
https://www.golem.de/news/bootloader-angreifbar-sicherheitsluecken-in-u-boo…
∗∗∗ EU sanktioniert Russland wegen schwerer Cyberangriffe und Sabotage ∗∗∗
---------------------------------------------
Der Europäische Rat wirft Moskau ein koordiniertes digitales System aus Geheimdiensten und Kriminellen vor. [..] Im Mittelpunkt der Vorwürfe steht das sogenannte 16. Zentrum des russischen Inlandsgeheimdienstes FSB. Diese Einheit soll laut dem Rat zahlreiche bekannte Cybergruppen wie Turla steuern.
---------------------------------------------
https://www.heise.de/news/EU-sanktioniert-Russland-wegen-schwerer-Cyberangr…
∗∗∗ Ghostcommit hides prompt injection in images to fool AI agents, steal secrets ∗∗∗
---------------------------------------------
A PNG hiding a prompt injection could steal your repos secrets, researchers demonstrate. The technique, dubbed Ghostcommit, slipped past AI code reviewers CodeRabbit and Bugbot, which never open image files at all, then convinced a coding agent to read a repos .env and write every secret into the code as a list of numbers.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/ghostcommit-hides-prompt-inj…
∗∗∗ Someone Is Scanning for Your MCP Servers and AI Assistant Credentials, (Mon, Jul 13th) ∗∗∗
---------------------------------------------
omeone is systematically looking for Model Context Protocol servers, AI assistant configuration files, and locally exposed LLM endpoints. On a server that runs none of those things.
---------------------------------------------
https://isc.sans.edu/diary/rss/33150
∗∗∗ Misconfigured Server Reveals Three Evilginx Phishing Operations Targeting Microsoft 365 ∗∗∗
---------------------------------------------
An attacker running a live Microsoft 365 phishing operation left a Python web server listening on a public port with directory listing switched on. The command that did it: python3 -m http.server 8080, was still sitting in the readable .bash_history.
---------------------------------------------
https://thehackernews.com/2026/07/misconfigured-server-reveals-three.html
∗∗∗ New MemGhost Attack Plants Persistent False Memories in AI Agents Through One Email ∗∗∗
---------------------------------------------
Give an AI assistant a memory and access to your inbox, and you hand an attacker a way to rewrite what it thinks it knows about you. A single email can trick that agent into saving a false "fact" about the user, hide the change, and quietly steer its answers in later sessions.When it works, the person reads an ordinary-looking reply and never learns their assistant was tampered with.
---------------------------------------------
https://thehackernews.com/2026/07/new-memghost-attack-plants-persistent.html
∗∗∗ jscrambler npm Package Compromised in Supply Chain Attack ∗∗∗
---------------------------------------------
A compromised release of the popular jscrambler npm package introduced hidden native binaries that execute automatically during npm install, exposing users to a supply chain attack before any application code runs.The malicious 8.14.0 release, published on July 11, adds an undocumented preinstall hook that invokes dist/setup.js.
---------------------------------------------
https://socket.dev/blog/jscrambler-supply-chain-attack
∗∗∗ CrashStealer: C++ macOS infostealer posing as crash reporter ∗∗∗
---------------------------------------------
Jamf Threat Labs discovers and investigates CrashStealer, a C++ macOS infostealer that impersonates Apples crash-reporting framework to harvest browser credentials, cryptocurrency wallets and keychain data, encrypting stolen files with AES-GCM before exfiltrating them to a remote command-and-control server.
---------------------------------------------
https://www.jamf.com/blog/crashstealer-macos-infostealer-analysis/
=====================
= Vulnerabilities =
=====================
∗∗∗ Werbeblocker Pi-hole: Update stopft hochriskante Sicherheitslücken ∗∗∗
---------------------------------------------
Von den insgesamt sechs Schwachstellen gelten vier als hohes Risiko, eine als mittleres und eine als niedriges. User, die als „pihole“-User Code ausführen dürfen, können durch Ersetzen von „/etc/pihole/logrotate“ an root-Rechte gelangen (CVE-2026-50130, CVSS 8.8, Risiko „hoch“).
---------------------------------------------
https://heise.de/-11362432
∗∗∗ VU#564823: GNU Wget enables SSRF via unvalidated FTP PASV IPs ∗∗∗
---------------------------------------------
https://kb.cert.org/vuls/id/564823
∗∗∗ LWN: Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1082642/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 09-07-2026 18:00 − Freitag 10-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers ∗∗∗
---------------------------------------------
A single wrong variable on one line in XQUIC, Alibabas QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. He says it needs no login and no malformed packets: about 260 bytes of ordinary QPACK traffic takes the server process down. [..] FoxIO demonstrated a crash, not code execution, and reported no exploitation in the wild. [..] XRING is the latest in a string of remote crashes in HTTP/2 and HTTP/3 stacks.
---------------------------------------------
https://thehackernews.com/2026/07/unpatched-xring-flaw-in-xquic-lets.html
∗∗∗ Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites ∗∗∗
---------------------------------------------
A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operations inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million websites. Far fewer were actually broken into, but the exposed files showed researchers how a mass site-hacking operation runs from the inside.
---------------------------------------------
https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html
∗∗∗ Software developers are the target. New trojan attacks supply chains and inflicts multifaceted damage on infected PCs ∗∗∗
---------------------------------------------
A new trojan engaging in supply chain attacks has recently come under the scrutiny of our antivirus laboratory. The malware primarily targets C++ and C# project files. This malicious sample is particularly dangerous as its payload incorporates multiple damaging features, allowing it to steal data, access clipboard content, operate as a backdoor, engage in rogue mining and also infect other files. [..] It mainly spreads over the Internet via infected executable files and Python scripts. The infection process is quite complex, so let’s examine the entire sequence phase by phase.
---------------------------------------------
https://news.drweb.com/show/?i=15276&lng=en&c=9
∗∗∗ "Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th) ∗∗∗
---------------------------------------------
Anyone who deals with phishing messages caught by basic security filters knows that most phishing samples tend to blend into one another, since only a small set of techniques and approaches keeps reappearing in them. That is precisely why it is worth pausing on the occasional message that does something a little out of the ordinary.
---------------------------------------------
https://isc.sans.edu/diary/rss/33144
∗∗∗ npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk ∗∗∗
---------------------------------------------
GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA).
---------------------------------------------
https://thehackernews.com/2026/07/npm-12-disables-install-scripts-by.html
∗∗∗ Microsoft warns customers AI will mean busier Patch Tuesdays ∗∗∗
---------------------------------------------
More patches mean more reasons to buy Redmond’s auto-patching tools
---------------------------------------------
https://www.theregister.com/security/2026/07/10/microsoft-warns-customers-a…
∗∗∗ GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware ∗∗∗
---------------------------------------------
In October 2025, Microsoft Threat Intelligence identified destructive wiping activity and uncovered a sophisticated Go programming language (Golang)-based backdoor we now track as GigaWiper, a versatile implant that combines robust command-and-control (C2) capabilities with multiple destructive payloads, including disk wiping, fake ransomware, and system-level sabotage. [..] In this blog, we provide a code-level analysis of GigaWiper’s architecture.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-…
∗∗∗ Flying with the Flipper Zero ∗∗∗
---------------------------------------------
Why is the world so alarmed about taking the Flipper on board planes? Is it just poorly educated armchair cyber commentators of the ‘don’t use open Wi-Fi / USB juicejacking’ style of fearmongering, or is there something to it? [..] Flippers are not a threat to the safety of a flight.
---------------------------------------------
https://www.pentestpartners.com/security-blog/flying-with-the-flipper-zero/
∗∗∗ Organized Cybercrime Merging with Other Crime ∗∗∗
---------------------------------------------
In a recent report, the FBI warns that Silent Ransom Group has also begun recruiting gig workers in the victims’ area under the guise of hiring helpdesk personnel. Gig workers are people who earn money through short-term, flexible jobs rather than a traditional permanent role. They are usually paid per task, project or assignment.
---------------------------------------------
https://www.truesec.com/hub/blog/organized-cybercrime-merging-with-other-cr…
∗∗∗ Wiz in the Verizon DBIR: How AI Acceleration and Cloud Sprawl Impact Modern Defense ∗∗∗
---------------------------------------------
Verizons latest DBIR highlights how attackers are exploiting familiar weaknesses at increasing speed and scale. [..] The lesson from this year's DBIR is that familiar weaknesses remain highly effective when combined with cloud scale, interconnected trust relationships, and increasingly rapid exploitation cycles.
---------------------------------------------
https://www.wiz.io/blog/verizon-dbir-2026-ai-cloud-security
=====================
= Vulnerabilities =
=====================
∗∗∗ GitLab Patch Release: 19.1.2, 19.0.4, 18.11.7 ∗∗∗
---------------------------------------------
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-releas…
∗∗∗ LWN: Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1082272/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 08-07-2026 18:00 − Donnerstag 09-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Microsoft patches RoguePlanet Defender zero-day vulnerability ∗∗∗
---------------------------------------------
Microsoft has released a security patch to address a Defender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday. The flaw (tracked as CVE-2026-50656) was disclosed by a security researcher using the "Nightmare Eclipse" handle as part of an ongoing dispute with Microsoft over the company's bug bounty and vulnerability disclosure practices.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplan…
∗∗∗ Schwachstelle in Coding-Agenten: Zugriff auf beliebige Dateien über Symlinks ∗∗∗
---------------------------------------------
In sechs großen Coding-Agenten findet sich eine Sicherheitslücke: Über ein Repository mit Schadcode können Angreifer die KI-Modelle dazu bewegen, auf beliebige Dateien zuzugreifen – auch außerhalb einer Sandbox. [..] Betroffen sind Amazon Q Developer, Anthropics Claude Code, Augment, Cursor, Google Antigravity und Windsurf. Für die meisten Tools existiert inzwischen ein Update, das die Schwachstelle behebt, aber für Augment und Windsurf existieren noch keine Patches.
---------------------------------------------
https://heise.de/-11358849
∗∗∗ IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years ∗∗∗
---------------------------------------------
GhostLock (CVE-2026-43499) is a Linux kernel vulnerability found by VEGA that exists in every major distribution since 2011. Triggering the bug does not require any special kernel config or privilege. By turning it into a 97% stable privilege escalation and container escape, Google has rewarded us $92,337 in kernelCTF. This writeup covers the technical details of the exploit.
---------------------------------------------
https://nebusec.ai/research/ionstack-part-2/
∗∗∗ Entra passkey enrollment vishing targets Microsoft 365 users ∗∗∗
---------------------------------------------
A threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Entra passkey.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vis…
∗∗∗ New Forg365 phishing platform uses AI to target Microsoft 365 accounts ∗∗∗
---------------------------------------------
A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-forg365-phishing-platfor…
∗∗∗ Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real Victims ∗∗∗
---------------------------------------------
Residential proxies are one of the hottest topics in cybersecurity today. Turns out, they are often not in residences, and they facilitate a wide range of criminal activity. In the simplest terms, a little piece of software in a TV, digital picture frame, or your phone might enable a company to sell access to your device’s bandwidth to their own customers. [..] Our discovery started with a single campaign: In early 2026, the actor, who we track as Lurking Lizard, fooled users into downloading a fake version of the 7-Zip archive utility.
---------------------------------------------
Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real Victims
∗∗∗ GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy. According to a new report published by the Threat Hunter Team from Symantec, the ransomware was first publicly spotted in the wild on May 21, 2026. It's assessed to be a rebrand of the Beast ransomware, which, in turn, was an enhanced version of Monster, a Delphi-based ransomware that surfaced in March 2022.
---------------------------------------------
https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.ht…
∗∗∗ GitHub Copilot: Sorry Dave, I cant do that harmful thing - unless you ask me in code ∗∗∗
---------------------------------------------
t's the latest example of AI safety guardrails being bypassed. GitHub Copilot refuses harmful prompts almost always if asked in chat - like, "how to fool a breathalyzer test" or "smuggle bulk cash out of the US" - but then will write them in code 100 percent of the time if the prompt is broken into smaller steps and distributed across multiple stages of a software development workflow.
---------------------------------------------
https://www.theregister.com/security/2026/07/08/github-copilot-sorry-dave-i…
∗∗∗ Eintrag wider Willen: Wenn Unternehmen ungefragt auf dubiosen Portalen landen ∗∗∗
---------------------------------------------
Taucht das eigene Unternehmen plötzlich auf unbekannten Portalen auf, ist die Überraschung groß. Unangenehm wird es dann, wenn sich das Profil ohne Registrierung nicht löschen lässt und sich die Plattformbetreiber regelmäßig mit aufdringlichen Spam-Mails melden. Und wie war das nochmal mit dem Urheberrecht? Das Problem, dargestellt am Beispiel evepla.com.
---------------------------------------------
https://www.watchlist-internet.at/news/eintrag-wider-willen-dubiose-portale/
=====================
= Vulnerabilities =
=====================
∗∗∗ n8n: CERT-Bund veröffentlicht Warnmeldung zu kürzlich beseitigten Schwachstellen ∗∗∗
---------------------------------------------
Kritisch ist keine der jüngst gefixten Lücken in der Automatisierungslösung n8n. Dennoch betont eine Warnmeldung des BSI die hohe Update-Relevanz.
---------------------------------------------
https://heise.de/-11359656
∗∗∗ Drupal Security Advisories 2026-July-08 ∗∗∗
---------------------------------------------
https://www.drupal.org/security
∗∗∗ LWN: Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1082030/
∗∗∗ Paloalto: PAN-SA-2026-0010 Chromium: Monthly Vulnerability Update (July 2026) (Severity: HIGH) ∗∗∗
---------------------------------------------
https://security.paloaltonetworks.com/PAN-SA-2026-0010
∗∗∗ Paloalto: PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026) (Severity: HIGH) ∗∗∗
---------------------------------------------
https://security.paloaltonetworks.com/PAN-SA-2026-0010
∗∗∗ Chrome-Browser & ChromeOS LTS : Updates schließen teils kritische Lücken ∗∗∗
---------------------------------------------
https://heise.de/-11359376
∗∗∗ Wireshark 4.6.7 Fixes 12 Security Issues Across SSH, IEEE 802.11, Catapult DCT2000 and Other Protocols ∗∗∗
---------------------------------------------
https://thecyberexpress.com/wireshark-4-6-7/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 07-07-2026 18:00 − Mittwoch 08-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Accenture confirms breach after hacker offers stolen data for sale ∗∗∗
---------------------------------------------
IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. [..] According to the threat actor, the data includes source code, RSA keys, SSH keys, Azure PAT (personal access tokens), Azure Storage access keys, and configuration files.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-af…
∗∗∗ GitHub AI agent leaks private repos when asked nicely ∗∗∗
---------------------------------------------
Malicious prompters could easily trick GitHub agents into pulling data from private repositories and then leaking the information as a public comment for anyone to access, according to Noma Labs researchers who named the vulnerability GitLost. The issue exists in GitHub’s Agentic Workflows, which allow an AI agent powered by Claude or GitHub Copilot to autonomously execute tasks in GitHub Actions.
---------------------------------------------
https://www.theregister.com/security/2026/07/07/github-ai-agent-leaks-priva…
∗∗∗ „Ihr Paket liegt im Logistikzentrum!“ – Über eine Zollgebühr in die Phishing-Falle ∗∗∗
---------------------------------------------
Zwei Sätze, eine Aufforderung, eine Frist. Mehr braucht es nicht – und die Phishing-Falle ist fertig. Eine zurzeit besonders häufig gemeldete Masche nutzt den Paketdienstleister DPD als Tarnung. Da sich entsprechende Hinweise im Posteingang der Redaktion stapeln, ist es an der Zeit, die Masche erneut unter die Lupe zu nehmen.
---------------------------------------------
https://www.watchlist-internet.at/news/dpd-paket-im-logistikzentrum/
∗∗∗ Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation ∗∗∗
---------------------------------------------
In April 2026, Unit 42 researchers identified a financially motivated campaign delivering Vidar stealer and the XMRig cryptocurrency miner to consumer and small- and medium-sized business victims worldwide. [..] We assess the operator of the campaign to be a Vidar stealer malware-as-a-service (MaaS) affiliate involved in operations targeting victims in the U.S. and European Union. This article provides a technical analysis of the campaign.
---------------------------------------------
https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-anal…
∗∗∗ Offene Datenbank: Nextcloud GmbH behebt potenzielles Datenleck ∗∗∗
---------------------------------------------
Daten des Unternehmens hinter der populären Kollaborationslösung standen wegen einer Fehlkonfiguration offen im Netz. Die Software ist nicht betroffen.
---------------------------------------------
https://heise.de/-11358275
=====================
= Vulnerabilities =
=====================
∗∗∗ Joomla Security Advisories (Fixed Date: 2026-07-07) ∗∗∗
---------------------------------------------
Joomla has released 12 new security advisories.
---------------------------------------------
https://developer.joomla.org/security-centre/
∗∗∗ Foxit-Entwickler schließen Schwachstellen in PDF Reader und Editor ∗∗∗
---------------------------------------------
Nicht kritisch, aber zahlreich: Aktuelle Sicherheitsupdates dichten Foxits PDF Reader und Editor gegen eine lange Lückenliste ab.
---------------------------------------------
https://www.heise.de/news/Foxit-Entwickler-schliessen-Schwachstellen-in-PDF…
∗∗∗ ILIAS: Wichtige Aktualisierungen für Lernplattform beseitigen Schwachstellen ∗∗∗
---------------------------------------------
Für die von Hochschulen, Kliniken und anderen öffentlichen Institutionen genutzte offene Lernplattform ILIAS stehen Aktualisierungen bereit. Die neuen Versionen 9.21, 10.9 und 11.2 schließen Sicherheitslücken, von denen alle früheren Ausgaben betroffen waren. Von drei Lücken geht ein hohes, von den übrigen ein mittleres Sicherheitsrisiko aus.
---------------------------------------------
https://heise.de/-11357739
∗∗∗ Juniper: 2026-07 Security Bulletin: Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attacker (CVE-2026-57028) ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos…
∗∗∗ Juniper: 2026-07 Security Bulletin: Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash (CVE-2026-57026) ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos…
∗∗∗ Juniper: 2026-07 Security Bulletin: Junos OS: MX Series with SPC3, SRX Series: A specifically malformed TCP packet causes a flowd crash (CVE-2026-57023) ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos…
∗∗∗ Juniper: 2026-07 Security Bulletin: Junos OS and Junos OS Evolved: Receipt of a specific SNMPv3 request results in memory leak and eventual snmpd crash (CVE-2026-33799) ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos…
∗∗∗ Juniper: 2026-07 Security Bulletin: Junos OS and Junos OS Evolved: Configuration of a specific SSH option results in mgd crash (CVE-2026-21901) ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos…
∗∗∗ Juniper: 2026-07 Security Bulletin: cRPD: Multiple vulnerabilities resolved in cRPD 26.2R1 ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-cRPD-…
∗∗∗ Juniper: 2026-07 Security Bulletin: Junos Space: Multiple vulnerabilities resolved in 26.1R1 Patch V1 Release ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos…
∗∗∗ Juniper: 2026-07 Security Bulletin: Network Director: Multiple vulnerabilities resolved in 7.1R3 release ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Netwo…
∗∗∗ Juniper: 2026-07 Security Bulletin: Junos OS Evolved: URL handling vulnerability in libfetch results in heap buffer overflow (CVE-2020-7450) ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos…
∗∗∗ Juniper: 2026-07 Security Bulletin: CTPView: Multiple vulnerabilities resolved in 9.3R2-3 Release ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-CTPVi…
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1081798/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/