=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 26-08-2026 18:00 − Donnerstag 27-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ New GPUThor attack defeats NVIDIA ECC protection for root access ∗∗∗
---------------------------------------------
A newly disclosed Rowhammer attack called GPUThor can bypass error-correcting code (ECC) protections on NVIDIA GPUs, enabling denial-of-service (DoS) and root-level privilege escalation.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-gputhor-attack-defeats-n…
∗∗∗ ATF confirms “major incident” after recent Qilin breach claims ∗∗∗
---------------------------------------------
ATF, the regulatory agency that enforces federal laws governing firearms and explosives in the United States, has confirmed that one of its systems was compromised after breach claims made by the Qilin ransomware gang.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/atf-confirms-major-incident-…
∗∗∗ Carhartt data breach exposes information of 12.9 million accounts ∗∗∗
---------------------------------------------
The ShinyHunters extortion group has published sensitive data from nearly 13 million accounts stolen from clothing retailer giant Carhartt earlier this month, according to data breach notification service Have I Been Pwned.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/carhartt-data-breach-exposes…
∗∗∗ Sicherheitslücke beim Mobilfunk: Angreifer konnten per Anruf Gerätedaten ausspähen ∗∗∗
---------------------------------------------
Reporter haben eine Sicherheitslücke in den Mobilfunknetzen mehrerer Provider entdeckt. Angreifer konnten ohne Nutzerinteraktion Gerätedaten abgreifen.
---------------------------------------------
https://www.golem.de/news/sicherheitsluecke-beim-mobilfunk-angreifer-haben-…
∗∗∗ Threat landscape for industrial automation systems. Q2 2026 ∗∗∗
---------------------------------------------
The report contains statistics on industrial threats for Q2 2026, including ransomware, miners, spyware and other threats that were detected and blocked on industrial control systems.
---------------------------------------------
https://securelist.com/industrial-threat-report-q2-2026/121159/
∗∗∗ When AI infrastructure becomes the target: Securing gateways and control points ∗∗∗
---------------------------------------------
Microsoft Threat Intelligence examines attacks on exposed AI workloads, including LiteLLM gateway exploitation, credential harvesting, persistence, and cryptomining activity.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/08/26/when-ai-infrastruc…
∗∗∗ What We Still Don’t Know About OpenAI’s Hugging Face Hack ∗∗∗
---------------------------------------------
The AI giant acknowledges that it could have done far more to prevent its AI agents from going rogue. But it still fails to explain why it didnt see this fiasco coming.
---------------------------------------------
https://www.wired.com/story/openais-hugging-face-hack-debrief-raises-more-q…
∗∗∗ Berliner Landesnetz: Sensible Daten bei Cyberangriff womöglich doch betroffen ∗∗∗
---------------------------------------------
Eine Cyberattacke traf vor knapp zwei Wochen zwei Berliner Senatsverwaltungen. Bislang hieß es, es seien nur frei verfügbare Geodaten abgeflossen.
---------------------------------------------
https://www.heise.de/news/Sensible-Daten-bei-Cyberangriff-womoeglich-doch-b…
∗∗∗ Angreifer können an rund 550 Lücken in Dell PowerProtect Cyber Recovery ansetzen ∗∗∗
---------------------------------------------
Dells IT-Sicherheitslösung PowerProtect Cyber Recovery bietet viele Angriffspunkte. Admins sollten ihre Instanzen zeitnah über Updates absichern.
---------------------------------------------
https://www.heise.de/news/Sicherheitspatches-Rund-550-Luecken-gefaehrden-De…
∗∗∗ Hugging-Face-Angriff: OpenAI-Abschlussbericht liefert neue Erkenntnisse ∗∗∗
---------------------------------------------
OpenAIs Bericht zum Hugging-Face-Vorfall zeigt, dass riskante Verhaltensmuster schon beim Training auftraten und Warnsignale nicht ausreichend eskaliert wurden.
---------------------------------------------
https://www.heise.de/news/OpenAI-Abschlussbericht-Rund-700-Agenten-griffen-…
∗∗∗ Two Alleged ‘TeamPCP’ Hackers Arrested in Australia ∗∗∗
---------------------------------------------
Authorities in Australia have arrested two men believed to be members of TeamPCP, a prolific cybercrime and data extortion group blamed for perpetrating the longest running spree of software supply chain attacks ever. In a statement released today, the Australian Federal Police (AFP) said two unnamed suspects from Western Australia, aged 21 and 23, were arrested in connection with a "sophisticated cybercrime syndicate that allegedly created malicious open-source software to rob thousands ..
---------------------------------------------
https://krebsonsecurity.com/2026/08/two-alleged-teampcp-hackers-arrested-in…
∗∗∗ Microsoft Exchange: Exploit-Code veröffentlicht (CVE-2026-62911) ∗∗∗
---------------------------------------------
Wie Heise berichtet, wurde auf Github Exploit-Code für eine Sicherheitslücke in Microsoft Exchange veröffentlicht. Microsoft hat im Rahmen seines regulären Patchzykluses Fixes für diese Sicherheitslücke veröffentlicht, betroffen sind demnach die Versionen Microsoft Exchange Server 2019, 2016 und die Subscription Edition RTM. Für die Version 2016 stellt Microsoft die Fixes nur über sein Extended-Security-Updates-Programm zur Verfügung. Wir teilen ..
---------------------------------------------
https://www.cert.at/de/aktuelles/2026/8/microsoft-exchange-exploit-code-ver…
∗∗∗ CISA Urges SharePoint Hardening After New Exploitations ∗∗∗
---------------------------------------------
Update August 26, 2026:CISA has updated this Alert to clarify guidance on avoiding the direct exposure of SharePoint Servers to the internet.Update August 18, 2026:CISA has updated this Alert to reflect the addition of CVE-2026-55040 to its Known Exploited Vulnerabilities (KEV) Catalog on August 18, 2026. Update July 28, 2026:CISA has updated this Alert to include CVE-2026-50522 and its addition to the KEV Catalog on July 22, 2026.Update July 16, 2026: CISA has updated this Alert to reflect the ..
---------------------------------------------
https://www.cisa.gov/news-events/alerts/2026/07/14/cisa-urges-sharepoint-ha…
∗∗∗ Medical device firm Boston Scientific says cyberattack has disrupted shipment processes ∗∗∗
---------------------------------------------
The company released a statement and filed documents with the Securities and Exchange Commission (SEC) saying a cybersecurity incident was discovered on Tuesday.
---------------------------------------------
https://therecord.media/boston-scientific-cyberattack-disrupts-shipment-pro…
∗∗∗ Disruptive cyber activity highlights risk from internet-exposed systems and edge devices ∗∗∗
---------------------------------------------
Targeting of operational technology reinforces the need for organisations to understand what is exposed to the internet, address avoidable vulnerabilities, and build long-term cyber resilience.
---------------------------------------------
https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from…
∗∗∗ Brief independent investigation of agents’ behavior, reasoning and collaboration in the OpenAI / Hugging Face hacking incident ∗∗∗
---------------------------------------------
Two METR staff members (Hjalmar Wijk and Ajeya Cotra) and a Redwood Research staff member contracting with METR (Ryan Greenblatt) worked on premises at OpenAI over a total of six days1 to attempt to form an independent understanding of model behavior observed during the recent incident in which OpenAI agents coordinated a multi-day hack of Hugging Face on a shared unsanctioned “message board.”
---------------------------------------------
https://metr.org/blog/2026-08-26-openai-hugging-face-incident-investigation/
∗∗∗ Detecting multi-stage attacks on AWS: A guide to cross-service signal correlation ∗∗∗
---------------------------------------------
A single alert from one security service tells you something happened. Read that signal alongside activity from other services and your own business context, and you will know whether what happened is part of a multi-stage attack. Consider a short sequence. An identity calls GetCallerIdentity from a source address it hasn’t previously used. Within minutes, […]
---------------------------------------------
https://aws.amazon.com/blogs/security/detecting-multi-stage-attacks-on-aws-…
=====================
= Vulnerabilities =
=====================
∗∗∗ CAPTCHA Protected Page - Moderately critical - Cookie Forgery - SA-CONTRIB-2026-105 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-105
∗∗∗ Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-111 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-111
∗∗∗ Disable Login Page - Moderately critical - Access bypass - SA-CONTRIB-2026-110 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-110
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 25-08-2026 18:00 − Mittwoch 26-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Hackers abuse npm mirrors to host phishing redirect pages ∗∗∗
---------------------------------------------
Threat actors are abusing npm and its mirrors to host malicious HTML pages that impersonate Cloudflare CAPTCHAs to redirect visitors to attacker-controlled websites.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-abuse-npm-mirrors-to…
∗∗∗ Ubiquiti patches three max severity security vulnerabilities ∗∗∗
---------------------------------------------
Ubiquiti has released security patches for three new maximum-severity vulnerabilities that threat actors can exploit remotely without privileges.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/ubiquiti-patches-three-max-s…
∗∗∗ Jetzt updaten: 327 Sicherheitslücken in Google Chrome gepatcht ∗∗∗
---------------------------------------------
Unzählige Chrome-Nutzer sind über mehr als 300 Sicherheitslücken Angreifbar. Das jüngste Update schützt davor und sollte zügig installiert werden.
---------------------------------------------
https://www.golem.de/news/jetzt-updaten-327-sicherheitsluecken-in-google-ch…
∗∗∗ Viele Softwareprojekte gefährdet: Hacker schleusen Schadcode auf Gitea-Instanzen ∗∗∗
---------------------------------------------
Eine kritische Sicherheitslücke ermöglicht Schadcode-Attacken auf Gitea-Instanzen. Angreifer nutzen das bereits. Admins sollten zügig patchen.
---------------------------------------------
https://www.golem.de/news/viele-softwareprojekte-gefaehrdet-hacker-schleuse…
∗∗∗ Exploits and vulnerabilities in Q2 2026 ∗∗∗
---------------------------------------------
This report covers statistics on vulnerabilities, exploits, and C2 frameworks in Q2 2026. For the first time ever, we aggregate data on vulnerabilities in open-source AI agents and AI frameworks.
---------------------------------------------
https://securelist.com/vulnerabilities-and-exploits-in-q2-2026/121091/
∗∗∗ The patch window is collapsing: Why security needs a new control plane ∗∗∗
---------------------------------------------
Organizations need protection that operates in the gap between discovery and remediation.
---------------------------------------------
https://azure.microsoft.com/en-us/blog/the-patch-window-is-collapsing-why-s…
∗∗∗ Boston Scientific discloses global disruption in ongoing cyberattack ∗∗∗
---------------------------------------------
No timeline to restore IT systems as probe remains ongoing
---------------------------------------------
https://www.theregister.com/security/2026/08/26/boston-scientific-discloses…
∗∗∗ WordPress-Plug-in TranslatePress ermöglicht Übernahme bei 400.000 Installationen ∗∗∗
---------------------------------------------
Eine Lücke im Plug-in TranslatePress für WordPress gefährdet 400.000 Instanzen. Angriffe laufen derweil auf miniOrange SAML.
---------------------------------------------
https://www.heise.de/news/WordPress-Plug-in-TranslatePress-ermoeglicht-Uebe…
∗∗∗ Spyware-Masche gegen Indeed-Nutzer – infizierte Vorstellungsgespräch-Apps ∗∗∗
---------------------------------------------
IT-Forscher beobachten eine globale Malware-Kampagne, bei der die Drahtzieher es auf Nutzer der Indeed-Plattform abgesehen haben.
---------------------------------------------
https://www.heise.de/news/Spyware-Masche-gegen-Indeed-Nutzer-infizierte-Vor…
∗∗∗ Kritische Schadcode-Lücken in Adobe-Anwendungen geschlossen ∗∗∗
---------------------------------------------
Angreifer können mehrere Sicherheitslücken unter anderem in Adobe Campaign Classic, Illustrator und Substance 3D Designer ausnutzen.
---------------------------------------------
https://www.heise.de/news/Kritische-Schadcode-Luecken-in-Adobe-Anwendungen-…
∗∗∗ Verfassungsschutz sieht kein Zero-Day-Problem durch mehr Befugnisse ∗∗∗
---------------------------------------------
Unternehmen sind stark von Cyberangriffen betroffen, so eine Bitkom-Studie. Verfassungsschutzpräsident Selen warnt vor dem Unterschätzen von Abhängigkeiten.
---------------------------------------------
https://www.heise.de/news/Verfassungsschutz-sieht-kein-Zero-Day-Problem-dur…
∗∗∗ Zwei Fallen in einer: Wie Kriminelle ihre Opfer mit Fake-Jobs und Krypto-Investmentbetrug ausnehmen ∗∗∗
---------------------------------------------
Eine Betrugsfalle allein kann bereits großen finanziellen Schaden anrichten. Werden zwei Maschen kombiniert, steigert dies die Gefahr nochmals deutlich. Ein vorliegender Fall zeigt, wie Kriminelle ein bereits schwer getroffenes Opfer weiter ausnehmen. Sie erfinden dabei das Rad keineswegs neu, sondern setzen schlicht und einfach sowohl auf Job- als auch auf Krypto-Investmentbetrug.
---------------------------------------------
https://www.watchlist-internet.at/news/zwei-fallen-in-einer/
∗∗∗ Häufung von Betrugsversuchen durch Business Email Compromise (BEC) ∗∗∗
---------------------------------------------
In den letzten Wochen erreichen uns vermehrt Berichte über Versuche, österreichische Organisationen und Unternehmen mittels Business E-Mail Compromise (BEC) zu schädigen. Bei dieser Betrugsform geben sich Kriminelle als vertrauenswürdige Person aus (wie beispielsweise als Geschäftsführung, bekannter Lieferant, Kolleg:in aus der Personalabteilung, ...), um ..
---------------------------------------------
https://www.cert.at/de/aktuelles/2026/8/vermehrt-betrugsversuche-durch-busi…
∗∗∗ UK government seeks powers to secretly block risky tech suppliers ∗∗∗
---------------------------------------------
The British government is seeking new powers to ban certain technology vendors from supplying companies working in the country’s critical sectors — and to potentially do so in secret.
---------------------------------------------
https://therecord.media/uk-technology-national-security
∗∗∗ From Mayhem to Atlantis: how AI is changing capture the flag and what this means for cybersecurity ∗∗∗
---------------------------------------------
Ten years after DARPAs first all-machine hacking tournament, AI agents are solving live CTF challenges, competing with human teams and pushing cybersecurity toward an AI-versus-AI future. Read on to discover how this future can affect your cybersecurity.
---------------------------------------------
https://www.jamf.com/blog/from-mayhem-to-atlantis-ai-is-changing/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 24-08-2026 18:00 − Dienstag 25-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Police arrests dozens of suspects in global cybercrime crackdown ∗∗∗
---------------------------------------------
Law enforcement agencies from 22 countries helped identify 263 suspects and arrested 58 individuals linked to cybercrime networks coordinated by African crime groups.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/police-arrests-dozens-of-sus…
∗∗∗ Hackers breached over 270 Zimbra servers in ongoing attacks ∗∗∗
---------------------------------------------
Threat actors have already compromised over 270 Zimbra instances in remote code execution attacks targeting a high-severity Zimbra Collaboration Suite (ZCS) vulnerability.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-breached-over-270-zi…
∗∗∗ Third-Party Script Security: How Tags, Pixels, and Embeds Can Put Websites at Risk ∗∗∗
---------------------------------------------
Third-party scripts are common on websites. They help with analytics, ads, live chat, social media, video, payments, and many other features. While not all are risky, every external tag, pixel, widget, or embed adds to your website’s vulnerability. These tools can read page content, collect visitor data, change what users see, and connect ..
---------------------------------------------
https://blog.sucuri.net/2026/08/third-party-script-security-how-tags-pixels…
∗∗∗ Attackers Target miniOrange SAML Flaws That Can Grant WordPress Admin Access ∗∗∗
---------------------------------------------
Bad actors are attempting to exploit two severe unauthenticated authentication bypasses in the Xecurify miniOrange SAML 2.0 Single Sign On plugin that make it possible for an attacker to sign in as any WordPress user, including ..
---------------------------------------------
https://thehackernews.com/2026/08/attackers-target-miniorange-saml-flaws.ht…
∗∗∗ Mirage2FA Surge Hits 4,500 US and EU Companies, Abusing Microsoft 365 Login Flows ∗∗∗
---------------------------------------------
Thousands of companies have been affected by the Mirage2FA campaign from 2024 to 2026. The commercial phishing-as-a-service toolkit targets Microsoft 365 accounts by abusing legitimate login flows and bypassing two-factor ..
---------------------------------------------
https://thehackernews.com/2026/08/mirage2fa-surge-hits-4500-us-and-eu.html
∗∗∗ E4del and PINHOLE RATs Turn FTP Banners Into Dead Drops for Malware Commands ∗∗∗
---------------------------------------------
Cybersecurity researchers are calling attention to a new campaign that employs FTP banners as dead drop resolvers (DDRs) to deliver two previously unreported remote access trojans (RATs) tracked as E4del and PINHOLE.While threat actors are ..
---------------------------------------------
https://thehackernews.com/2026/08/e4del-and-pinhole-rats-turn-ftp-banners.h…
∗∗∗ A Malicious Webpage Could Poison Your Local AI Model Behind NVIDIA NemoClaw ∗∗∗
---------------------------------------------
Oasis Security has disclosed a weakness in NVIDIA NemoClaw that could let an attacker-controlled webpage take unauthenticated control of the local Ollama instance serving an AI agent and plant hidden instructions inside the model itself.The findings were ..
---------------------------------------------
https://thehackernews.com/2026/08/a-malicious-webpage-could-poison-your.html
∗∗∗ You dont want this Sleepwalker backdoor on your Windows machine ∗∗∗
---------------------------------------------
Its own command language, 23 instructions - signs point to well-resourced operation rather than an opportunistic one
---------------------------------------------
https://www.theregister.com/security/2026/08/24/you-dont-want-this-sleepwal…
∗∗∗ Crooks push Mac malware through fake OpenAI Codex ads ∗∗∗
---------------------------------------------
Sponsored search results lead developers straight into a ClickFix malware trap
---------------------------------------------
https://www.theregister.com/security/2026/08/25/crooks-push-mac-malware-thr…
∗∗∗ CISA slaps its tightest three-day patching deadline on perfect-10 Oracle flaw ∗∗∗
---------------------------------------------
Disclosed in January and honeypots buzzed soon after, CISA says it’s finally time for the USG to plug the gap
---------------------------------------------
https://www.theregister.com/security/2026/08/25/cisa-slaps-its-tightest-thr…
∗∗∗ Kriminalisierung: Informatiker verlangen Freipass für IT-Sicherheitsforscher ∗∗∗
---------------------------------------------
Die Gesellschaft für Informatik fordert die Bundesregierung auf, ethische Hacker endlich wirksam vor Strafverfolgung zu schützen.
---------------------------------------------
https://www.heise.de/news/Kriminalisierung-Informatiker-verlangen-Freipass-…
∗∗∗ Angreifer nehmen Oracle Weblogic und HTTP-Server ins Visier ∗∗∗
---------------------------------------------
Angreifer missbrauchen eine Sicherheitslücke in Oracle HTTP-Server und Weblogic Server, die komplette Kompromittierung ermöglicht.
---------------------------------------------
https://www.heise.de/news/Attacken-auf-Oracle-Weblogic-und-HTTP-Server-beob…
∗∗∗ Zugriffsverwaltung Keycloak: Kontoübernahme durch Passwort-Rücksetzfunktion ∗∗∗
---------------------------------------------
In dem Identitäts- und Zugriffssteuerungssystem Keycloak können Angreifer einen Fehler beim Passwort-Rücksetzen missbrauchen, um Konten zu übernehmen.
---------------------------------------------
https://www.heise.de/news/Zugriffsverwaltung-Keycloak-Kontouebernahme-durch…
∗∗∗ WhatsApp führt mehrere Passkeys ein und ersetzt PINs ∗∗∗
---------------------------------------------
WhatsApp verbessert die Kontosicherheit durch die Unterstützung mehrerer Passkeys, stärkere Passwörter und Kontextinformationen bei unbekannten Anrufen.
---------------------------------------------
https://www.heise.de/news/WhatsApp-Mehr-Passkeys-und-verbesserte-Sicherheit…
∗∗∗ Phishing-Versuch greift Login-Daten für Onlinebroker ab ∗∗∗
---------------------------------------------
Eine SMS-Nachricht, ein Login-Portal – und fertig ist die Phishing-Falle. Kriminelle versenden aktuell im Namen des Onlinebrokers „flatex“ Warnungen vor dem Ablaufen der für Überweisungen benötigten iTAN-Card. Über die Fake-Anmeldeseite wollen sie an Benutzername und Passwort ihrer Opfer gelangen.
---------------------------------------------
https://www.watchlist-internet.at/news/phishing-login-daten-onlinebroker/
∗∗∗ The State of AI-Enabled Malware August 2026: From Brand Abuse to Agentic Execution ∗∗∗
---------------------------------------------
To assess the impact of AI-enabled malware, we collected and analyzed over 400 malware samples that integrate AI in some capacity, from brand impersonation and large language model (LLM)-generated code to agentic execution loops. Our central finding was that the AI malware space is currently overwhelmingly composed of ..
---------------------------------------------
https://unit42.paloaltonetworks.com/ai-enabled-malware-analysis/
∗∗∗ Large DDoS attack knocks Norwegian public services offline ∗∗∗
---------------------------------------------
The Norwegian Digitalisation Agency said it was working with its IT partner to stabilize systems affected by a distributed denial-of-service attack, with some services gradually coming back online.
---------------------------------------------
https://therecord.media/norway-cyberattack-ddos-government
∗∗∗ A Tale of Two SOCs: Insights From Two Red Team Assessments ∗∗∗
---------------------------------------------
The Cybersecurity and Infrastructure Security Agency (CISA) conducted simultaneous red team assessments at two organizations and observed different defensive outcomes. In both environments, the red team achieved full domain compromise and accessed sensitive business systems (SBSs) and cloud resources. Organization A failed to detect or contain the activity, but ..
---------------------------------------------
https://www.cisa.gov/news-events/cybersecurity-advisories/aa26-237a
∗∗∗ ToxNetV2: An AI-Assisted Botnet Controller ∗∗∗
---------------------------------------------
ToxNetV2 is an AArch64 Linux peer-to-peer botnet that integrates an LLM into the operational workflow of its controller. As uncovered in the Joe Reverser analysis, the controller collects host and botnet telemetry, sends that context to NVIDIA NIM, parses selected model responses into structured actions, and queues those actions for operator approval. The resulting ..
---------------------------------------------
https://www.joesecurity.org/blog/6764463444623599134
∗∗∗ Open VSX Unblocks Extension IDs Used in Malware Campaign ∗∗∗
---------------------------------------------
Over a five-day period from August 16 through August 20, the registry unblocked AlDuncanson.react-hooks-snippets, magne-sjaastad.opm-flow-editor-support, and rumbledb.jsoniq-vscode. All three IDs had been used by impostors in the 77-extension evil-twin campaign documented by Manifold Security earlier this month. Legitimate versions of the OPM and RumbleDB ..
---------------------------------------------
https://socket.dev/blog/open-vsx-unblocks-malicious-extension-ids
=====================
= Vulnerabilities =
=====================
∗∗∗ TYPO3-EXT-SA-2026-025: Multiple Vulnerabilities in extension "Apache Solr for TYPO3 - Enterprise Search" (solr) ∗∗∗
---------------------------------------------
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-025
∗∗∗ TYPO3-EXT-SA-2026-023: Multiple vulnerabilities in extension "Event management and registration" (sf_event_mgt) ∗∗∗
---------------------------------------------
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-023
∗∗∗ TYPO3-EXT-SA-2026-021: Broken Access Control in extension "Forum" (pforum) ∗∗∗
---------------------------------------------
https://news.typo3.com/security/advisory/typo3-ext-sa-2026-021
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 21-08-2026 18:00 − Montag 24-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ How an Emerging Industrial Protocol Family Could Put OT at Risk ∗∗∗
---------------------------------------------
New research shows how attacks against some unprotected TSN protocols could allow attackers to disrupt or manipulate physical processes.
---------------------------------------------
https://www.darkreading.com/ics-ot-security/how-emerging-industrial-protoco…
∗∗∗ Nach Hackerangriff: Berliner Senat überrascht über Größe des IT-Systems ∗∗∗
---------------------------------------------
Nach einem Hackerangriff sind zwei Berliner Verwaltungen wieder am Netz. Es gibt jedoch weiter Verdachtsmomente für eine Infiltration.
---------------------------------------------
https://www.golem.de/news/nach-hackerangriff-berliner-senat-ueberrascht-ueb…
∗∗∗ Missbrauch von Passkeys: Phishing-Toolkit soll Passwort-Reset umgehen können ∗∗∗
---------------------------------------------
Ein ab 10.000 US-Dollar gehandeltes Phishing-Toolkit soll Angreifern über Passkeys einen dauerhaften Zugriff etwa auf gekaperte Google-Konten verleihen.
---------------------------------------------
https://www.golem.de/news/missbrauch-von-passkeys-phishing-toolkit-soll-pas…
∗∗∗ Security vets rally around $4 paper password books for sale in Australia ∗∗∗
---------------------------------------------
Once shunned by the IT crowd, pen-and-paper password vaults are getting the love they deserve in 2026
---------------------------------------------
https://www.theregister.com/security/2026/08/24/security-vets-rally-around-…
∗∗∗ AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a devs headphones ∗∗∗
---------------------------------------------
Sawtooth waves you cant hear still mess with your Bluetooth. Firefox and Brave say theyve got you covered
---------------------------------------------
https://www.theregister.com/security/2026/08/24/aliexpress-accused-of-finge…
∗∗∗ The curious case of the effortful fraud ∗∗∗
---------------------------------------------
How what looked like a generic phishing site seemingly turned out to be a put-some-effort-into it, targeted fraud.
---------------------------------------------
https://bytesandborscht.com/the-curious-case-of-the-effortful-fraud/
∗∗∗ Britische Regierung bestätigt Cyberattacke auf Kraftwerk ∗∗∗
---------------------------------------------
Für vier Tage haben Angreifer in Großbritannien ein Kraftwerk abgeschaltet. Die Behörden warnen und besänftigten zugleich.
---------------------------------------------
https://www.heise.de/news/Britische-Regierung-bestaetigt-Cyberattacke-auf-K…
∗∗∗ Microsoft stopft zahlreiche Cloud-Schwachstellen ∗∗∗
---------------------------------------------
Microsoft dokumentiert 18 teils kritische Sicherheitslücken in Cloud-Produkten, die die Entwickler geschlossen haben.
---------------------------------------------
https://www.heise.de/news/Microsoft-stopft-zahlreiche-Cloud-Schwachstellen-…
∗∗∗ „GTA 6“-ISO: Vermeintliche Leak-Abbilddatei voller Malware ∗∗∗
---------------------------------------------
Bösartige Akteure bieten das vermeintlich geleakte ISO von „GTA 6“ im Netz an. Die 113 GByte enthalten aufgepumpte Virendaten.
---------------------------------------------
https://www.heise.de/news/GTA-6-ISO-Vermeintliche-Leak-Abbilddatei-voller-M…
∗∗∗ Notepad++ v8.9.8 stopft 14 Sicherheitslücken ∗∗∗
---------------------------------------------
Am Sonntag hat Don Ho Version 8.9.8 des beliebten Editors Notepad++ herausgegeben. Sie schließt etwa Codeschmuggellücken.
---------------------------------------------
https://www.heise.de/news/Notepad-v8-9-8-stopft-14-Sicherheitsluecken-11423…
∗∗∗ And then the men with guns tell you to do it anyway ∗∗∗
---------------------------------------------
Perhaps you can think of a way to design an alerting system which cannot be abused - but I can't.
---------------------------------------------
https://shkspr.mobi/blog/2026/08/and-then-the-men-with-guns-tell-you-to-do-…
∗∗∗ Everything I own, owned ∗∗∗
---------------------------------------------
Over the past couple weeks I’ve been doing agent-driven reverse engineering of peripherals that happen to be within arm’s reach. From those devices, I’ve come away with a full plaintext command shell inside my microphone, a webcam whose activity LED I can switch off while it records, and a key light that hands out memory writes to anyone on the WiFi.
---------------------------------------------
https://schlarp.com/posts/everything-i-own-owned/
∗∗∗ Building certgrep.sh: a free certificate transparency search engine ∗∗∗
---------------------------------------------
Certificate transparency is one of the best public datasets in security. Every certificate issued by a publicly trusted certificate authority lands in an append-only, cryptographically verifiable log, usually before the certificate is ever used. For anyone hunting malicious infrastructure, that makes certificate transparency (CT) one of the earliest ..
---------------------------------------------
https://haveibeensquatted.com/blog/building-certgrep
=====================
= Vulnerabilities =
=====================
The Fabrik Fiasco: Announced, Restricted, Relabelled
---------------------------------------------
https://mysites.guru/blog/fabrik-unauthenticated-rce-calc-element/
Fabrik 4.7.2 for Joomla: A Long List of Security Fixes
---------------------------------------------
https://mysites.guru/blog/fabrik-4-7-2-security-release/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 20-08-2026 18:00 − Freitag 21-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Hundreds of leaked AWS keys give full control over corporate accounts ∗∗∗
---------------------------------------------
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. ---------------------------------------------
https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-…
∗∗∗ Slowakei: Russische Backdoor in Verkehrskameras entdeckt ∗∗∗
---------------------------------------------
Die Slowakei wollte im Rahmen eines Sanierungspakets 279 neue Verkehrskameras beschaffen. Erste Geräte kamen unerwartet aus Russland - inklusive Backdoor.
---------------------------------------------
https://www.golem.de/news/slowakei-russische-backdoor-in-verkehrskameras-en…
∗∗∗ N-able Passportal: Zahlreiche Unternehmen durch kritisches Passwort-Leck gefährdet ∗∗∗
---------------------------------------------
Ein Forscher hat bei N-able Passportal eine kritische Lücke entdeckt. Angreifer hätten damit leicht Zugangsdaten aus Passwort-Tresoren abgreifen können.
---------------------------------------------
https://www.golem.de/news/n-able-passportal-jede-website-konnte-passwort-tr…
∗∗∗ GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure ∗∗∗
---------------------------------------------
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr.The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated ..
---------------------------------------------
https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html
∗∗∗ Researcher tricks Apple’s Find My into sharing location data with Linux ∗∗∗
---------------------------------------------
Clever protocol wrangling gets iBiz-only people tracking working on a non-iGadget
---------------------------------------------
https://www.theregister.com/security/2026/08/20/researcher-tricks-apples-fi…
∗∗∗ Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5. ∗∗∗
---------------------------------------------
Secure Workload Software has five nasty flaws and even SaaS users have updates to install
---------------------------------------------
https://www.theregister.com/security/2026/08/21/cisco-bug-severity-warning-…
∗∗∗ ClaudeFix: Shared Claude Chats Meet ClickFix ∗∗∗
---------------------------------------------
ClickFix is a widely employed attack technique, first seen in 2024, where a victim is instructed to paste-and-run instructions on their system to “fix” a problem or install software. The seemingly benign instructions are, in fact, malicious and lead to the deployment of malware onto the victim’s system. Zscaler Threat Hunting has analyzed ..
---------------------------------------------
https://www.zscaler.com/blogs/security-research/claudefix-shared-claude-cha…
∗∗∗ Zimbra: Warnung vor Angriffen auf Befehlsschmuggel-Lücke ∗∗∗
---------------------------------------------
Das polnische CERT warnt vor Angriffen auf eine Befehlsschmuggel-Lücke in der Zimbra Collaboration Suite. Ein Update ist verfügbar.
---------------------------------------------
https://www.heise.de/news/Zimbra-Warnung-vor-Angriffen-auf-Befehlsschmuggel…
∗∗∗ Atlassian schließt mehr als 160 Sicherheitslücken in Confluence & Co. ∗∗∗
---------------------------------------------
Angreifer können unter anderem an kritischen Schadcode-Schwachstellen in Softwareprodukten von Atlassian ansetzen.
---------------------------------------------
https://www.heise.de/news/Atlassian-schliesst-mehr-als-160-Sicherheitslueck…
∗∗∗ Dell ObjectScale: Höhere Nutzerrechte erschleichbar ∗∗∗
---------------------------------------------
Sicherheitsupdates schließen mehrere Lücken in Dells Object-Storage-Plattform ObjectScale.
---------------------------------------------
https://www.heise.de/news/Dell-ObjectScale-Hoehere-Nutzerrechte-erschleichb…
∗∗∗ Lücke in WordPress-Plug-in Elementor Pro: 6 Millionen Webseiten gefährdet ∗∗∗
---------------------------------------------
Eine kritische Sicherheitslücke im WordPress-Plug-in Elementor Pro ermöglicht die komplette Übernahme von WordPress.
---------------------------------------------
https://www.heise.de/news/Luecke-in-WordPress-Plug-in-Elementor-Pro-6-Milli…
∗∗∗ Cyberangriff in Berlin: Behörden weiterhin offline ∗∗∗
---------------------------------------------
Zwei Senatsverwaltungen sind nach einem Cyberangriff vom Landesnetz isoliert. Das hat auch Auswirkungen auf die Auszahlung von Wohngeld.
---------------------------------------------
https://heise.de/-11421320
∗∗∗ Defeating AI-Assisted Reverse Engineering (or at Least Trying To) ∗∗∗
---------------------------------------------
At the beginning of 2026, a customer told us something along the lines of: obfuscation is finished, LLM-assisted reverse engineering breaks it. They had a walkthrough to back it up, produced by their own tooling, in which a model took one of their obfuscated libraries apart and recovered its hidden strings.They were not right, but not entirely wrong either.So we spent a ..
---------------------------------------------
http://blog.quarkslab.com/defeating-ai-assisted-reverse-engineering-or-at-l…
∗∗∗ I accidentally logged hundreds of thousands of phone calls to military bases ∗∗∗
---------------------------------------------
How an expired nameserver let me take over e164.arpa zones for multiple territories, and why I probably should have checked my logs sooner.
---------------------------------------------
https://lina.sh/blog/hijacking-e164-arpa
∗∗∗ Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns ∗∗∗
---------------------------------------------
Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaigns infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios.
---------------------------------------------
https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-ov…
∗∗∗ If Apple says your iPhone was targeted by mercenary spyware, treat it like an incident ∗∗∗
---------------------------------------------
Apples Threat Notifications signal mercenary spyware targeting; learn verification steps, response actions, and layered mobile security defenses for high-risk users.
---------------------------------------------
https://www.jamf.com/blog/apple-threat-notification-mercenary-spyware-respo…
=====================
= Vulnerabilities =
=====================
∗∗∗ [20260803] - Core - Inconsistent ACL checks for mutating webservice endpoints ∗∗∗
---------------------------------------------
https://developer.joomla.org/security-centre/1070-20260803-core-inconsisten…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 19-08-2026 18:00 − Donnerstag 20-08-2026 18:00
Handler: Guenes Holler
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Grok exfiltrates user data when malicious instructions are encrypted ∗∗∗
---------------------------------------------
Cryptographic Context Injection is only the latest way to break an LLM safety guardrail.
---------------------------------------------
https://arstechnica.com/security/2026/08/grok-exfiltrates-user-data-when-ma…
∗∗∗ US warns of AI-powered attacks on Siemens PLCs in critical infrastructure ∗∗∗
---------------------------------------------
U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attac…
∗∗∗ Rogue ransomware affiliate poses as data recovery firm to steal payments ∗∗∗
---------------------------------------------
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-r…
∗∗∗ New Manic Android malware can exfiltrate data through nearby devices ∗∗∗
---------------------------------------------
A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-manic-android-malware-ca…
∗∗∗ Critical Elementor Pro bug exposes WordPress sites to RCE attacks ∗∗∗
---------------------------------------------
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-e…
∗∗∗ Kritische Sicherheitslücke: Hacker attackieren Gitlab-Instanzen ∗∗∗
---------------------------------------------
Angreifer können durch eine Sicherheitslücke auf Gitlab-Instanzen verheerende Schäden anrichten. Forscher warnen bereits vor laufenden Angriffen.
---------------------------------------------
https://www.golem.de/news/kritische-sicherheitsluecke-hacker-attackieren-gi…
∗∗∗ Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021.The end-to-end experiment used an attacker Worker and a victim Worker controlled ..
---------------------------------------------
https://thehackernews.com/2026/08/cloudflare-workers-spectre-attack-leaks.h…
∗∗∗ 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets ∗∗∗
---------------------------------------------
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products.According to the Socket Threat Research team, the extensions are part of a ..
---------------------------------------------
https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.h…
∗∗∗ CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a ..
---------------------------------------------
https://thehackernews.com/2026/08/cdn-tsunami-attack-abuses-http3.html
∗∗∗ Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution ∗∗∗
---------------------------------------------
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska).The vulnerability in question is ..
---------------------------------------------
https://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.ht…
∗∗∗ Microsoft untersucht Spieleprobleme nach August-Patchday ∗∗∗
---------------------------------------------
Nach der Installation der Windows-Updates vom August-Patchday erhält Microsoft vermehrt Meldungen zu Problemen mit einigen Spielen.
---------------------------------------------
https://www.heise.de/news/Microsoft-untersucht-Spieleprobleme-nach-August-P…
∗∗∗ Citrix stopft kritische Anmeldungsumgehung in Netscaler ADC und Gateway ∗∗∗
---------------------------------------------
In Netscaler ADC und Gateway von Citrix können Angreifer mehrere Lücken missbrauchen. Sie können etwa unbefugt Zugriff erlangen.
---------------------------------------------
https://www.heise.de/news/Citrix-stopft-kritische-Anmeldungsumgehung-in-Net…
∗∗∗ Sicherheitslücke in Microsoft 365 Copilot: KI verrät eigene Schutzmechanismen ∗∗∗
---------------------------------------------
Sicherheitsforscher haben Microsofts KI-Assistenten dazu gebracht, seine eigenen Schutzmechanismen offenzulegen.
---------------------------------------------
https://www.heise.de/news/Sicherheitsluecke-in-Microsoft-365-Copilot-KI-ver…
∗∗∗ GivEnergy enters administration, batteries expose home networks ∗∗∗
---------------------------------------------
In late 2024, we found multiple vulnerabilities in GivEnergy home battery systems that could allow attackers to access customers’ home networks, disrupt battery operation, and potentially violate UK product security regulations. While GivEnergy updated installer guidance for newer deployments, older installations may still be exposed, with no clear remediation plan communicated to customers. Even before the latest news, this was ..
---------------------------------------------
https://www.pentestpartners.com/security-blog/givenergy-enters-administrati…
∗∗∗ A1-Phishing: Gefälschte E-Mails im Umlauf ∗∗∗
---------------------------------------------
Mit rund 7 Millionen Kund ist A1 einer der größten Anbieter für Handy, Festnetz und Internet in Österreich. Diese Bekanntheit nutzen Kriminelle aktuell aus und verschicken täuschend echte Phishing-Mails im Namen von A1. Das Ziel: Persönliche Daten und Kontoinformationen.
---------------------------------------------
https://www.watchlist-internet.at/news/a1-phishing-gefaelschte-e-mails-im-u…
∗∗∗ UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations ∗∗∗
---------------------------------------------
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.
---------------------------------------------
https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-int…
∗∗∗ Gefälschte Seite, falsche Software – trotz korrekt aussehender Links ∗∗∗
---------------------------------------------
Eine Kampagne mit gefälschten Webseiten zeigt korrekt erscheinende Links an, schiebt Opfern jedoch unerwünschte Software unter.
---------------------------------------------
https://heise.de/-11420547
∗∗∗ Supply chain attack on arrayref ∗∗∗
---------------------------------------------
On 2026-08-20 at 7:15 UTC we got a report that the proc-macro1 crate was malicious.
---------------------------------------------
https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
=====================
= Vulnerabilities =
=====================
∗∗∗ Link content parser - Critical - Unsupported - SA-CONTRIB-2026-101 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-101
∗∗∗ Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-100
∗∗∗ Cisco Advance Notification for Publication of August 19, 2026, Security Advisories ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 18-08-2026 18:00 − Mittwoch 19-08-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Slowakei: Russische Backdoor in Verkehrskameras entdeckt ∗∗∗
---------------------------------------------
Die Slowakei hat im Rahmen eines Sanierungspakets 279 neue
Verkehrskameras gekauft. Die Geräte kamen unerwartet aus Russland -
inklusive Backdoor.
---------------------------------------------
https://www.golem.de/news
/slowakei-russische-backdoor-in-verkehrskameras-entdeckt-2608-212088
.html
∗∗∗ Phishing-Welle im Namen des Finanzministeriums nutzt
Familienbeihilfe als Köder ∗∗∗
---------------------------------------------
Datenmissbrauch, unrechtmäßige Umleitungen und ausbleibende
Auszahlungen der Familienbeihilfe – mit diesem Bedrohungsbild gehen
Kriminelle momentan auf Beutezug. Sie geben sich in einer E-Mail als
Finanzministerium aus und wollen so an die Onlinebanking-Logindaten
ihrer Opfer gelangen.
---------------------------------------------
https://www.watchlist-internet.at/news
/phishing-finanzministeriums-familienbeihilfe/
∗∗∗ Warnung vor Angriffen auf Microsoft IKE, SharePoint, VMware vCenter
und macOS ∗∗∗
---------------------------------------------
Die IT-Sicherheitsbehörde CISA warnt aktuell vor Angriffen auf
Microsoft IKE, SharePoint, VMware vCenter und macOS.
---------------------------------------------
https://heise.de/-11418783
∗∗∗ CISA: Medusa ransomware hit over 500 critical infrastructure orgs
∗∗∗
---------------------------------------------
The Cybersecurity and Infrastructure Security Agency (CISA) said
Tuesday that the Medusa ransomware gang has breached more than 500
critical infrastructure organizations in the United States since June
2021.
---------------------------------------------
https://www.bleepingcomputer.com/news/security
/cisa-medusa-ransomware-hit-over-500-critical-infrastructure-orgs/
∗∗∗ Password spraying attacks surge 155x as hackers exploit MFA gaps
∗∗∗
---------------------------------------------
Huntress has observed a 155x increase in password spraying attacks in
the first half of 2026. Brute force is old news, but the spin driving
that spike is new.
---------------------------------------------
https://www.bleepingcomputer.com/news/security
/password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps/
∗∗∗ Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and
Secrets ∗∗∗
---------------------------------------------
Two critical vulnerabilities impacting MLflow, an open-source
artificial intelligence (AI) platform, and FUXA, an open-source,
web-based SCADA / HMI software built for operational technology (OT)
and industrial automation, are witnessing malicious scanning and
exploitation efforts.
---------------------------------------------
https://thehackernews.com/2026/08
/attackers-exploit-mlflow-ssrf-flaw-to.html
∗∗∗ Microsoft Links 30+ Rotating Domains to MacSync Stealer
Infrastructure ∗∗∗
---------------------------------------------
Microsoft Defender Experts have linked more than 30 web domains to
MacSync Stealer, a macOS-focused information stealer, after correlating
recurring endpoint and network behaviors across changing
infrastructure, tracing the malware from payload retrieval through data
collection, staging, and exfiltration.
---------------------------------------------
https://thehackernews.com/2026/08
/microsoft-links-30-rotating-domains-to.html
∗∗∗ Clop-Linked Windchill Web Shell Decrypts Credentials and Maps
Engineering Data ∗∗∗
---------------------------------------------
A JavaServer Pages (JSP) web shell deployed following the exploitation
of a critical security flaw in PTC Windchill and FlexPLM servers is
specifically designed for the enterprise Product Lifecycle Management
(PLM) software, according to new findings from ReliaQuest.
---------------------------------------------
https://thehackernews.com/2026/08/clop-linked-windchill-web-shell.html
∗∗∗ Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks,
Auth Bypasses, and P2P ∗∗∗
---------------------------------------------
Cybersecurity researchers at Hunt.io have disclosed details of a
campaign that they say compromised more than 14,530 Dahua devices
between June 17 and July 22, 2026, using credential attacks, two
authentication-bypass flaws, and a peer-to-peer (P2P) relay technique.
---------------------------------------------
https://thehackernews.com/2026/08
/hackers-compromised-14500-dahua-devices.html
=====================
= Vulnerabilities =
=====================
∗∗∗ Oracle-Patchday: Updates für weniger als tausend Schwachstellen ∗∗∗
---------------------------------------------
Oracle fixt zum „Critical Security Patch Update“ knapp 1000 Lücken –
weniger als zum letzten regulären „CPU“ genannten Patchday.
---------------------------------------------
https://heise.de/-11418883
∗∗∗ LWN Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1089501/
∗∗∗ Security Vulnerabilities fixed in Thunderbird 153.1 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-80/
∗∗∗ Security Vulnerabilities fixed in Thunderbird 140.14 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/
∗∗∗ Security Vulnerabilities fixed in Thunderbird 154 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-78/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 17-08-2026 18:00 − Dienstag 18-08-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Hacker claims 3.6 million Azure account records stolen from major companies ∗∗∗
---------------------------------------------
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azu…
∗∗∗ Whatsapp, Signal und Threema: Angreifer können Gruppenchats unbemerkt manipulieren ∗∗∗
---------------------------------------------
Bei Whatsapp, Signal, iMessage und Threema kann ein Gruppenmitglied anderen Teilnehmern unterschiedliche Inhalte zeigen. Die Verschlüsselung muss dafür nicht gebrochen werden.
---------------------------------------------
https://www.golem.de/news/whatsapp-signal-und-threema-angreifer-koennen-gru…
∗∗∗ 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer.
---------------------------------------------
https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.h…
∗∗∗ TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT.
---------------------------------------------
https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.h…
∗∗∗ CISA gives feds 3 days to fix actively exploited Ray RCE bug ∗∗∗
---------------------------------------------
Phishing, malvertising attacks could target devs to gain access to private corporate networks.
---------------------------------------------
https://www.theregister.com/security/2026/08/18/cisa-gives-feds-3-days-to-f…
∗∗∗ „Sie haben eine neue Nachricht“: Phishing-Falle im Namen der easybank ∗∗∗
---------------------------------------------
Über eine angeblich notwendige „Vervollständigung der Kontodaten“ wollen Kriminelle an die Onlinebanking-Logininformationen ihrer Opfer gelangen. Sie geben sich dabei als Vertreter der „easybank“ aus und setzen auf eine Phishing-Falle, die typischer nicht sein könnte.
---------------------------------------------
https://www.watchlist-internet.at/news/phishing-falle-easybank/
∗∗∗ Microsoft starts removing WMIC tool used by cybercriminals ∗∗∗
---------------------------------------------
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolb…
∗∗∗ Mobile Klimaanlage: Midea PortaSplit lässt sich von jedermann fernsteuern ∗∗∗
---------------------------------------------
Per Bluetooth können Nachbarn die mobile Klimaanlage fernbedienen oder abschalten, Midea sieht keine Sicherheitslücke darin.
---------------------------------------------
https://heise.de/-11417163
=====================
= Vulnerabilities =
=====================
∗∗∗ Keine Anmeldung nötig: Gitlab-Lücke lässt Angreifer Softwareprojekte löschen ∗∗∗
---------------------------------------------
Aufgrund einer kritischen Sicherheitslücke können Angreifer ohne Anmeldung Gitlab-Projekte manipulieren oder löschen. Admins sollten zügig handeln.
---------------------------------------------
https://www.golem.de/news/keine-anmeldung-noetig-gitlab-luecke-laesst-angre…
∗∗∗ Webmailer Roundcube: Updates stopfen zahlreiche Sicherheitslecks ∗∗∗
---------------------------------------------
Das Webmail-System Roundcube hat mit aktualisierter Software mehrere Sicherheitslücken geschlossen. Die teils hochriskanten Schwachstellen ermöglichen Angreifern etwa das Einschmuggeln von Schadcode. Die Updates stehen bereits seit rund zwei Wochen bereit, nun wurden die Schwachstelleneinträge der darin geschlossenen Lecks nachgeschoben.
---------------------------------------------
https://www.heise.de/news/Webmailer-Roundcube-Updates-stopfen-zahlreiche-Si…
∗∗∗ Redis: Sicherheitsupdates gegen Schadcode-Lücken ∗∗∗
---------------------------------------------
In der In-Memory-Datenbank Redis wurden mehrere Schwachstellen ausgemacht, die etwa Einschleusen von Schadcode erlauben. Es hagelt Updates.
---------------------------------------------
https://www.heise.de/news/Redis-Sicherheitsupdates-gegen-Schadcode-Luecken-…
∗∗∗ WordPress-Plug-in Forminator Forms: Kritische Lücke erlaubt Codeschmuggel ∗∗∗
---------------------------------------------
Das WordPress-Plug-in Forminator Forms enthält eine kritische Schadcode-Lücke. Zudem sind Royal Elementor Addons löchrig.
---------------------------------------------
https://heise.de/-11416793
∗∗∗ Weitere Sicherheitsupdates: iOS 26.6.1, macOS 26.6.2 und mehr veröffentlicht ∗∗∗
---------------------------------------------
Kleine Aktualisierung, viele Lücken: Gut 30 Sicherheitslöcher hat Apple in insgesamt sechs Betriebssystemen gestopft. KI dürfte geholfen haben.
---------------------------------------------
https://heise.de/-11416727
∗∗∗ LWN Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1089338/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 14-08-2026 18:00 − Montag 17-08-2026 18:00
Handler: Guenes Holler
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Cyberangriff auf die Arbeiterkammer Oberösterreich ∗∗∗
---------------------------------------------
Die Angreifer erlangten Zugriff auf Daten der Landes-Kammer.
---------------------------------------------
https://www.derstandard.at/story/3000000335811/cyberangriff-auf-die-arbeite…
∗∗∗ Schadcode im Anmarsch: SAP-Systeme werden über kritische Lücke attackiert ∗∗∗
---------------------------------------------
Angreifer können SAP-Commerce-Cloud-Instanzen über eine kritische Sicherheitslücke kompromittieren. Entsprechende Attacken laufen bereits.
---------------------------------------------
https://www.golem.de/news/schadcode-im-anmarsch-sap-systeme-werden-ueber-kr…
∗∗∗ Cyberattacke auf Berliner Verwaltung, Ermittlungen laufen ∗∗∗
---------------------------------------------
Die Senatskanzlei berichtet von einem Angriff auf Teile der Verwaltung in der Hauptstadt. Ein Krisenstab ist eingerichtet. Viele Fragen sind offen.
---------------------------------------------
https://heise.de/-11416539
∗∗∗ Microsoft confirms GitHub is down worldwide ∗∗∗
---------------------------------------------
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-github-i…
∗∗∗ Windows-Ablaufdaten: Microsoft-Erinnerung an Server 2022 und Windows 11 24H2 ∗∗∗
---------------------------------------------
In 60 Tagen endet der (Mainstream-)Support für Windows Server 2022, Windows 11 24H2 und Windows 10 LTSB 2016, mahnt Microsoft.
---------------------------------------------
https://www.heise.de/news/Windows-Ablaufdaten-Microsoft-Erinnerung-an-Serve…
∗∗∗ PBS station fears losing 50TB of data after being ghosted by cloud storage provider ∗∗∗
---------------------------------------------
“We don’t have access to the data on the hardware/servers,” Iron Mountain told Ars.
---------------------------------------------
https://arstechnica.com/information-technology/2026/08/pbs-station-fears-lo…
∗∗∗ SafePal data breach impacts 39,798 customers, stolen info for sale ∗∗∗
---------------------------------------------
Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-…
∗∗∗ Microsoft working on Defender patch for ShieldBreak zero-day ∗∗∗
---------------------------------------------
On Friday, Microsoft confirmed it has begun working on a security patch for a Defender zero-day vulnerability named "ShieldBreak."
---------------------------------------------
https://www.bleepingcomputer.com/news/security/microsoft-working-on-defende…
∗∗∗ Philips and GE investigating Clop ransomware data theft claims ∗∗∗
---------------------------------------------
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating…
∗∗∗ Certighost and the Privilege Hiding in Your Certificate Authority ∗∗∗
---------------------------------------------
Every mature Active Directory environment has a component that quietly holds more power than the people running it usually admit: the Certification Authority (CA). The thing your entire estate has agreed to believe.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/certighost-and-the-privilege…
∗∗∗ Sicherheit: KIT-Forscher identifizieren Personen via WLAN ∗∗∗
---------------------------------------------
Ein Forschungsteam des KIT nutzt unverschlüsselte WLAN-Signale zur Personenerkennung. Ein handelsüblicher Router reicht dafür aus.
---------------------------------------------
https://www.golem.de/news/sicherheit-kit-forscher-identifizieren-personen-v…
∗∗∗ Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies.
---------------------------------------------
https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html
∗∗∗ Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access ∗∗∗
---------------------------------------------
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker.
---------------------------------------------
https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html
∗∗∗ Microsoft blames AI for delayed Exchange update, can’t say when it will arrive ∗∗∗
---------------------------------------------
Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service.
---------------------------------------------
https://www.theregister.com/software/2026/08/17/microsoft-blames-ai-for-del…
∗∗∗ Lücke in Online-Banking: BKA deckt Millionenschäden auf ∗∗∗
---------------------------------------------
Eine Gruppe Krimineller soll Bankkunden um Millionen betrogen haben. Ermittler aus Deutschland und Brasilien nahmen nach Durchsuchungen Verdächtige fest.
---------------------------------------------
https://www.heise.de/news/Luecke-in-Online-Banking-BKA-deckt-Millionenschae…
∗∗∗ Frankreich untersucht Diebstahl von Steuerdaten von 678.000 Betroffenen ∗∗∗
---------------------------------------------
Französische Staatsanwälte untersuchen einen „beispiellosen“ Cyberangriff, bei dem Steuerdaten von 678.000 Nutzern entwendet wurden.
---------------------------------------------
https://www.heise.de/news/Frankreich-untersucht-Diebstahl-von-Steuerdaten-v…
∗∗∗ Dubiose Werbung und Abofallen bei Shops für Nahrungsergänzungsmittel ∗∗∗
---------------------------------------------
Große Gesundheitsversprechen und günstige Angebote machen Nahrungsergänzungsmittel im Internet attraktiv. Doch hinter solchen Angeboten können fragwürdige Versprechen und undurchsichtige Abo-Modelle stecken. Der Fall alimora.shop zeigt, wo Kund:innen besonders genau hinsehen sollten.
---------------------------------------------
https://www.watchlist-internet.at/news/nahrungsergaenzungsmittel-online-kau…
∗∗∗ „Download more RAM“: Windows-Sicherheit durch RAM-EEPROM geknackt ∗∗∗
---------------------------------------------
IT-Forscher zeigen Angriff „Download more RAM“ auf Windows-Sicherheitsmechanismen, der auf Manipulation des RAM-EEPROMs basiert.
---------------------------------------------
https://www.heise.de/news/Download-more-RAM-Windows-Sicherheit-durch-RAM-EE…
=====================
= Vulnerabilities =
=====================
∗∗∗ Schadcode-Sicherheitslücken bedrohen PostgreSQL ∗∗∗
---------------------------------------------
In aktuellen Versionen haben die PostgreSQL-Entwickler mehrere Sicherheitslücken geschlossen. Für einen Versionsstrang läuft bald der Support aus.
---------------------------------------------
https://www.heise.de/news/Schadcode-Sicherheitsluecken-bedrohen-PostgreSQL-…
∗∗∗ Zahlreiche Crash-Lücken in Wireshark geschlossen ∗∗∗
---------------------------------------------
In der aktuellen Wireshark-Version haben sich die Entwickler um mehrere Sicherheitslücken gekümmert.
---------------------------------------------
https://heise.de/-11415516
∗∗∗ App-Baukasten AppYourself: Update stopft Sicherheitslücke ∗∗∗
---------------------------------------------
Mit AppYourself können auch Nicht-Programmierer Business-Apps erstellen. Ein Update schließt eine Sicherheitslücke in der Software.
---------------------------------------------
https://heise.de/-11416102
∗∗∗ Cisco Advance Notification for Publication of August 19, 2026, Security Advisories ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1089205/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 13-08-2026 18:00 − Freitag 14-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Microsoft patches LegacyHive Windows zero-day vulnerability ∗∗∗
---------------------------------------------
Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-legacyhiv…
∗∗∗ Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt ∗∗∗
---------------------------------------------
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-wi…
∗∗∗ Ukraine shuts down 94 fraudulent call centers, seize millions in cash ∗∗∗
---------------------------------------------
Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/ukraine-shuts-down-94-fraudu…
∗∗∗ Shell investigates potential incident after Clop data theft claims ∗∗∗
---------------------------------------------
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/shell-investigates-potential…
∗∗∗ Security: Der Phish stinkt vom Kopf her ∗∗∗
---------------------------------------------
Anti-Phishing-Kampagnen sollen die IT-Laien in einer Firma fit gegen Angriffe machen. Das ist aber komplett der falsche Ansatz. Ein IMHO von R. Zehl
---------------------------------------------
https://www.golem.de/news/security-der-phish-stinkt-vom-kopf-her-2608-21187…
∗∗∗ APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit ∗∗∗
---------------------------------------------
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
---------------------------------------------
https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
∗∗∗ Digitale Kaperbriefe: US-Regierung erlaubt Unternehmen offensive Cyberangriffe ∗∗∗
---------------------------------------------
Im Kampf gegen transnationale kriminelle Akteure will die US-Regierung verstärkt auf die Privatwirtschaft setzen. Unternehmen sollen selbst angreifen dürfen.
---------------------------------------------
https://www.heise.de/news/Digitale-Kaperbriefe-US-Regierung-erlaubt-Unterne…
∗∗∗ Studie zum Umgang mit Passkeys: Nutzer wissen zu wenig Bescheid ∗∗∗
---------------------------------------------
Passkeys sollen Passwörter ablösen, sie gelten als viel sicherer. In der Praxis fehlt vielen Nutzern noch Wissen, haben US-Forscher herausgefunden.
---------------------------------------------
https://www.heise.de/news/Studie-zum-Umgang-mit-Passkeys-Teilweise-gefaehrl…
∗∗∗ Vermehrt Betrugsversuche auf Buchungsplattformen (booking.com, ..) ∗∗∗
---------------------------------------------
Momentan erreichen uns vermehrt Meldungen über Betrugsversuche in Bezug auf Reisebuchungen über Plattformen wie beispielsweise booking.com. Eine der häufigsten Methoden der Kriminellen ist der Missbrauch echter Buchungsdaten. Dabei erhalten Personen nach einer tatsächlichen Buchung über eine Reiseplattform eine Nachricht per E-Mail, SMS ..
---------------------------------------------
https://www.cert.at/de/aktuelles/2026/8/vermehrt-betrugsversuche-auf-buchun…
∗∗∗ New Mirai variant adds stealth capabilities to notorious botnet code ∗∗∗
---------------------------------------------
Beyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials.
---------------------------------------------
https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code
∗∗∗ You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) ∗∗∗
---------------------------------------------
Suddenly, you’re in a room. You look around - oh, you’re surrounded by other new starters at your new job. Yes, it’s Monday, and you’re being onboarded.You know the drill - it’s the typical ..
---------------------------------------------
https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth…
∗∗∗ Seitenkanal erlaubt Zugriff auf RAM des AMD-Sicherheitscontrollers PSP ∗∗∗
---------------------------------------------
Bei alten AMD-Prozessoren lässt sich die in Hardware verankerte RAM-Adressverwaltung manipulieren, um auf vermeintlich geschützte Bereiche zuzugreifen.
---------------------------------------------
https://heise.de/-11414481
∗∗∗ How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign ∗∗∗
---------------------------------------------
A practical playbook for investigating GitHub token compromise, drawn from Wiz CIRTs response to a coordinated multi-organization campaign.
---------------------------------------------
https://www.wiz.io/blog/investigating-github-pat-compromise
∗∗∗ Closing the Blind Spot: Securing Personal Repositories in the Software Supply Chain ∗∗∗
---------------------------------------------
Personal repositories are where corporate secrets quietly escape. Wiz correlates them to your developers, validates the real risk, and drives the fix.
---------------------------------------------
https://www.wiz.io/blog/securing-personal-repositories
=====================
= Vulnerabilities =
=====================
∗∗∗ External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-098
∗∗∗ [R1] Security Center Version 6.9.0 Fixes Multiple Vulnerabilities ∗∗∗
---------------------------------------------
https://www.tenable.com/security/tns-2026-22
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/