=====================
= End-of-Day report =
=====================
Timeframe: Freitag 24-07-2026 18:00 − Montag 27-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ SourTrade: Malvertising-Malware im Browser kompiliert ∗∗∗
---------------------------------------------
IT-Forscher haben eine mittels Malvertising verteilte Malware entdeckt. Die wird erst im Browser zusammengebaut.
---------------------------------------------
https://www.heise.de/news/SourTrade-Malvertising-Malware-im-Browser-kompili…
∗∗∗ How the Gentlemen Ransomware Group Built a Multi-Region Attack Machine in H1 2026 ∗∗∗
---------------------------------------------
Ransomware’s biggest story in the first half of 2026 was not only about established names maintaining dominance. A newer player, The Gentlemen ransomware group, emerged as one of the most geographically active operators, expanding its reach across Europe, Asia-Pacific, the Middle East & Africa, and the Americas.
---------------------------------------------
https://thecyberexpress.com/the-gentlemen-ransomware-group/
∗∗∗ ShinyHunters data leaks fuel $2,000 sextortion email scam ∗∗∗
---------------------------------------------
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel…
∗∗∗ Landes-Geheimdienstchef Kramer: OpenAI-Hackerangriff war "kein Skynet-Szenario" ∗∗∗
---------------------------------------------
Nach dem Hackerangriff auf Hugging Face mahnt der Thüringer Verfassungsschutz zur Besonnenheit. Er forderte aber ein KI-Frühwarnsystem für die Sicherheitsbehörden.
---------------------------------------------
https://www.golem.de/news/landes-geheimdienstchef-kramer-openai-hackerangri…
∗∗∗ Alle Daten gelöscht: US-Bürger wegen Nutzung einer GrapheneOS-Funktion angeklagt ∗∗∗
---------------------------------------------
Ein Mann wurde bei der Einreise in die USA durchsucht. Er trickste die Grenzpolizei mit einem Duress-Passwort aus – und muss sich dafür nun vor Gericht verantworten.
---------------------------------------------
https://www.golem.de/news/alle-daten-geloescht-us-buerger-wegen-nutzung-ein…
∗∗∗ Zugangsdaten im Visier: Hacker beim Datenklau über Hotel-WLANs erwischt ∗∗∗
---------------------------------------------
Eine russische Hackergruppe kapert wohl WLAN-Ausrüstung in Einrichtungen, um systematisch Microsoft-Zugangsdaten abzugreifen.
---------------------------------------------
https://www.golem.de/news/zugangsdaten-im-visier-hacker-beim-datenklau-uebe…
∗∗∗ Datenpanne in Gebets-App: Sicherheitslücke in "Gottes Tech-Stack" aufgedeckt ∗∗∗
---------------------------------------------
Eine Forscherin hat die offizielle Gebets-App des Papstes untersucht. "Gottes Tech-Stack" erwies sich als angreifbar und leakte Nutzerdaten.
---------------------------------------------
https://www.golem.de/news/700-000-nutzer-betroffen-suendhaftes-datenleck-be…
∗∗∗ BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery ∗∗∗
---------------------------------------------
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware.
---------------------------------------------
https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html
∗∗∗ DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts ∗∗∗
---------------------------------------------
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis.
---------------------------------------------
https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.ht…
∗∗∗ Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools.
---------------------------------------------
https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html
∗∗∗ Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update ∗∗∗
---------------------------------------------
One bug disabled the security service on restart, another blocked installation on hardened RHEL systems
---------------------------------------------
https://www.theregister.com/patches/2026/07/27/microsoft-defender-for-endpo…
∗∗∗ Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor ∗∗∗
---------------------------------------------
Zscaler ThreatLabz has been tracking attacks from a threat actor that is likely an initial access broker for ransomware attacks since January 2026. The threat actor targets organizations by leveraging vishing techniques through Microsoft Teams and deploying a variety of tools including a Go-based backdoor that we named GoGRPC. ThreatLabz has identified at least four variants of GoGPRC that we named Lep, Giver, Pet, and Kind. In some instances, the threat actor has deployed additional malware tools that include a backdoor that we named BlindDoor, a Go-based reverse SOCKS proxy we named RevSocket, a Python-based reverse SOCKS proxy we named PyGRPC, and two other tools we named S3Siphon and RSOX.
---------------------------------------------
https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vi…
∗∗∗ Geburtstagsgeschenk von Rituals? Vorsicht vor dieser Abofalle! ∗∗∗
---------------------------------------------
Viele bekannte Marken überraschen ihre Kund:innen zum Geburtstag mit kleinen Geschenken. Genau dieses Vertrauen machen sich Kriminelle zunutze: Sie verschicken gefälschte E-Mails im Namen von Rituals und locken mit einem Geschenkset. In Wahrheit landen die Opfer in einer teuren Abofalle.
---------------------------------------------
https://www.watchlist-internet.at/news/geburtstagsgeschenk-von-rituals-vors…
∗∗∗ Tenant-Übernahme möglich und drei kritische Sicherheitslücke in MS-Infrastruktur ∗∗∗
---------------------------------------------
Jeffrey Schwartz berichtet von der BlackHat 2026 in den USA, und einem speziellen Thema: Die Standard-Einstellung in Azure Automation ermöglichte eine mandantenübergreifende Identitätsübernahme. Dann gab es drei kritische Sicherheitslücken in der Infrastruktur von Microsoft (u.a. bei Bing Images), die die Ausführung von Remote-Code (RCE) ermöglichen. Kleine Nachschau zu diesen Sachverhalten.
---------------------------------------------
https://borncity.com/blog/2026/07/27/tenant-uebernahme-moeglich-und-drei-kr…
∗∗∗ Fake Corepack Site Distributes Infostealer and Proxyware to Developers ∗∗∗
---------------------------------------------
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
---------------------------------------------
https://socket.dev/blog/fake-corepack-site-distributes-infostealer-and-prox…
∗∗∗ Project ORBITAL ∗∗∗
---------------------------------------------
The modern cyber threat landscape has seen a fundamental shift in how threat actors manage and deploy their infrastructure. Advanced persistent threats (APTs) have almost completely moved away from static command-and-control (C2) servers, opting instead to build complex, multi-layered botnets known as Operational Relay Box (ORB) networks. Project ORBITAL (which stands for Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) was established as a centralised intelligence matrix to track, analyse, and ultimately help defenders disrupt this highly evasive infrastructure.
---------------------------------------------
https://blog.bushidotoken.net/2026/07/project-orbital.html
∗∗∗ Two Old Oj Flaws Chained to Trigger GitLab Remote Code Execution ∗∗∗
---------------------------------------------
A newly disclosed GitLab vulnerability has revealed how two long-standing memory-safety flaws in the widely used Ruby JSON parsing library, Oj, can be combined to achieve remote code execution on default GitLab installations.
---------------------------------------------
https://thecyberexpress.com/gitlab-vulnerability-oj-parser-rce/
=====================
= Vulnerabilities =
=====================
∗∗∗ Angreifer können MongoDB abstürzen lassen und Daten manipulieren ∗∗∗
---------------------------------------------
Die MongoDB-Entwickler haben in aktuellen Versionen zahlreiche Sicherheitslücken geschlossen. Bislang gibt es keine Hinweise auf laufende Attacken.
---------------------------------------------
https://heise.de/-11378494
∗∗∗ Sicherheitsupdate: Dateitransferlösung MOVEit ist verwundbar ∗∗∗
---------------------------------------------
Admins, die in Unternehmen für den Dateitransfer MOVEit nutzen, sollten die Software zeitnah auf den aktuellen Stand bringen. Geschieht das nicht, kann im schlimmsten Fall Schadcode auf PCs gelangen. Die Entwickler haben in einer neuen Version mehrere Schwachstellen geschlossen.
---------------------------------------------
https://heise.de/-11379295
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1085554/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 23-07-2026 18:00 − Freitag 24-07-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Vermehrt Phishing-Mails von legitimen E-Mail-Adressen aus Österreich ∗∗∗
---------------------------------------------
Im Moment beobachten wir vermehrt erfolgreiches Phishing, das von kompromittierten E-Mail-Konten österreichischer Unternehmen ausgeht.
Die Phishing-Mails zielen darauf ab, Microsoft-365-Zugangsdaten zu stehlen, das Konto zu übernehmen und weitere Phishing-Mails zu versenden. Die Phishing-Mails werden an die im Adressbuch gespeicherten Kontakte versendet. Da Empfänger und Sender sich kennen, erscheint dem Empfänger der Absender legitim, was die Chance auf eine weitere Kompromittierung erhöht. Dadurch hat diese Kampagne das Potenzial für eine besonders effektive Ausbreitung. Betroffen sind im Moment eher KMUs in der Baubranche (Bau, Metallbau, Holzbau, Werkzeug, Kabeltechnik).
---------------------------------------------
https://www.cert.at/de/aktuelles/2026/7/vermehrt-phishing-mails-von-legitim…
∗∗∗ Russische Angreifer missbrauchen Zero-Click-Lücke in Zimbra ∗∗∗
---------------------------------------------
In der Kollaborationssoftware Zimbra, die etwa Mail und Kalender und weitere Funktionen vereint, finden sich regelmäßig Sicherheitslücken, die die Entwickler mit Updates schließen. Admins installieren die offenbar weiterhin sehr zögerlich, denn internationale (IT-)Sicherheitsbehörden warnen nun gemeinsam vor Angriffen von russischen Akteuren, die mindestens seit Juli 2025 unter anderem eine Zero-Click-Lücke in Zimbra missbrauchen. Ziel der Angriffe sind demnach westliche Regierungen, kommerzielle sowie Bildungseinrichtungen, der Energiesektor, Strafverfolger, Medien, Nichtregierungsorganisationen und der Technologiesektor.
---------------------------------------------
https://www.heise.de/news/Russische-Angreifer-missbrauchen-Zero-Click-Lueck…
∗∗∗ New Dolphin X malware uses AI to rank high-value targets ∗∗∗
---------------------------------------------
A new Dolphin X remote access trojan claims to use an AI-powered profiling feature to score and rank infected users, helping cybercriminals identify which victims should be targeted first.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-dolphin-x-malware-uses-a…
∗∗∗ Hackers abuse Notepad++ plugins to stealthily install malware ∗∗∗
---------------------------------------------
Ukraine's CERT has uncovered attacks distributing an archive containing the legitimate Notepad++ application and a malicious utility called LunchPoke disguised as a plugin to establish persistence.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-abuse-notepad-plus-p…
∗∗∗ Europol flags 4,340 URLs for removal in The Com crackdown ∗∗∗
---------------------------------------------
Europol has flagged 4,340 URLs for removal during a multi-week operation targeting online content linked to "The Com," a loosely organized network of nihilistic violent extremist groups.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/europol-flags-4-340-urls-for…
∗∗∗ Golden Chickens Resurfaces With Four New Malware Families and Modular Implants ∗∗∗
---------------------------------------------
The threat actors behind the Golden Chickens malware-as-a-service (MaaS) ecosystem have resurfaced with four new malware families, indicating that the operators are showing no signs of stopping despite extensive public disclosures into their inner workings.
---------------------------------------------
https://thehackernews.com/2026/07/golden-chickens-resurfaces-with-four.html
∗∗∗ ChatGPT AgentForger Flaw Could Deploy Rogue Workspace Agents via a Phishing Link ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed a critical vulnerability in OpenAI's ChatGPT Workspace Agents that could have allowed a single phishing link to stealthily build, authorize, and deploy an autonomous artificial intelligence (AI) agent inside a victim's organization.
---------------------------------------------
https://thehackernews.com/2026/07/chatgpt-agentforger-flaw-could-deploy.html
∗∗∗ Certighost Exploit Lets Low-Privileged Active Directory Users Impersonate a Domain Controller ∗∗∗
---------------------------------------------
Researchers H0j3n and Aniq Fakhrul published a working exploit on July 24 that lets a low-privileged Active Directory user obtain a certificate for a Domain Controller and authenticate as that machine.
---------------------------------------------
https://thehackernews.com/2026/07/certighost-exploit-lets-low-privileged.ht…
=====================
= Vulnerabilities =
=====================
∗∗∗ Sicherheitsupdate n8n: Accountübernahme und Sandboxausbruch möglich ∗∗∗
---------------------------------------------
16 Sicherheitslücken gefährden IT-Umgebungen, in denen n8n zur Workflow-Automatisierung läuft. Der Großteil der Schwachstellen ist mit dem Bedrohungsgrad „hoch“ eingestuft. Angreifer können im schlimmsten Fall die volle Kontrolle über Systeme erlangen. Mittlerweile haben die Entwickler reparierte Versionen zum Download gestellt.
---------------------------------------------
https://heise.de/-11377037
∗∗∗ NodeBB Patches Eight AI-Found Flaws Exposing Admin Access and Private Chats ∗∗∗
---------------------------------------------
Eight security flaws in NodeBB went public on Wednesday, along with the code to exploit them. Aikido Security rates all eight as high severity and says its AI pentest agents found them in a six-hour review of the forum software's source code. Every version before 4.14.0 is affected. NodeBB has fixed them all, and administrators should be on 4.14.2.
---------------------------------------------
https://thehackernews.com/2026/07/nodebb-patches-eight-ai-found-flaws.html
∗∗∗ LWN Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1084860/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 22-07-2026 18:00 − Donnerstag 23-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Microsoft SharePoint: Angriffe auf weitere Sicherheitslücke ∗∗∗
---------------------------------------------
Am Microsoft-Patchday im Juli waren bereits Angriffe auf eine SharePoint-Schwachstelle bekannt. Die hatte jedoch lediglich den Schweregrad „mittel“. Jetzt warnen IT-Sicherheitsfirmen und -Behörden vor beobachteten Attacken auf eine kritische SharePoint-Lücke, für die ebenfalls ein Softwareflicken seit dem Patchday bereitsteht. Zudem wurden Angriffe auf Check Point SmartConsole beobachtet.
---------------------------------------------
https://www.heise.de/news/Microsoft-SharePoint-Angriffe-auf-weitere-Sicherh…
∗∗∗ China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks ∗∗∗
---------------------------------------------
An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader.
---------------------------------------------
https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html
∗∗∗ Linux kernel team publishes 432 CVEs in two days ∗∗∗
---------------------------------------------
If you're responsible for Linux security, someone just dumped a pile of work onto your desk: 432 Linux kernel CVEs were published across Sunday and Monday this week. Linux watchers at nixCraft pointed out the volume on Monday morning, and it didn’t take long for seasoned sysadmins to start expressing concerns.
---------------------------------------------
https://www.theregister.com/security/2026/07/22/linux-kernel-team-publishes…
∗∗∗ 8000 PCs über Steam infiziert: Cyberkriminelle verteilen Malware via Fake-Games ∗∗∗
---------------------------------------------
Cyberkriminelle haben Steam genutzt, um zahlreiche PCs mit Malware zu infizieren. Die Schadsoftware war in Spielen versteckt und wurde gezielt beworben.
---------------------------------------------
https://www.heise.de/news/8-000-PCs-ueber-Steam-infiziert-Cyberkriminelle-v…
∗∗∗ Chaos ransomwares msaRAT: Living off the browser to build a covert C2 channel ∗∗∗
---------------------------------------------
Chaos is a ransomware-as-a-service (RaaS) group whose activity was first confirmed in February 2025. Although the number of listings on their data leak site remains relatively low, the group consistently targets large organizations and employs double extortion tactics. For initial access, they rely on spam emails and voice-based social engineering, commonly known as vishing. Once inside a network, their traditional post-compromise methodology involves abusing remote monitoring and management (RMM) tools to establish persistent access, while leveraging legitimate file-sharing software to exfiltrate data.
---------------------------------------------
https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-b…
∗∗∗ New TrickBot Variant Spotted Using DNS to Control Infected Windows PCs ∗∗∗
---------------------------------------------
Fortinet has found a new TrickBot variant hiding commands in DNS traffic and using scheduled tasks and added modules to maintain access on infected Windows PCs.
---------------------------------------------
https://hackread.com/new-trickbot-variant-dns-control-infected-windows-pcs/
∗∗∗ Dark Elevator: Windows Install Service Local Privilege Escalation (CVE-2026-50343) ∗∗∗
---------------------------------------------
Today we walk through Dark Elevator, a LPE in Windows 11. We reported it to Microsoft on May 20, 2026, and it is now fixed as CVE-2026-50343.
---------------------------------------------
https://blog.calif.io/p/dark-elevator-windows-install-service
∗∗∗ RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) ∗∗∗
---------------------------------------------
Qualys Threat Research Unit (TRU) identified CVE-2026-64600, a race condition in the Linux kernel’s XFS filesystem copy-on-write path. An attacker with an ordinary local account can exploit this race condition to overwrite protected files on disk and gain host root privileges on affected systems, including deployments running SELinux in Enforcing mode.
---------------------------------------------
https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs…
∗∗∗ Silent Replacement of Trusted macOS App Executables ∗∗∗
---------------------------------------------
A vulnerability in macOS allows an attacker to silently replace the main executable of any application downloaded from the web without requiring elevated privileges. As a result, trusted applications can be made to execute attacker-controlled code without triggering security warnings when relaunched. Apple assessed the reported behaviour as not requiring a security fix.
---------------------------------------------
https://mysk.blog/2026/07/23/macos-overwrite-app-executables/
∗∗∗ Next chapter: Restructuring GitHub’s bug bounty program ∗∗∗
---------------------------------------------
GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team.
---------------------------------------------
https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-…
∗∗∗ The CISO Guide to Endpoint Control and Prevention (ECP): The Next Architecture for Endpoint Security ∗∗∗
---------------------------------------------
New category market definition and buyer framework for securing users, agents, identities, and data at the endpoint. A five zone framework for securing AI-centric software at the endpoint.
---------------------------------------------
https://softwareanalyst.substack.com/p/the-ciso-guide-to-endpoint-control
∗∗∗ New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs ∗∗∗
---------------------------------------------
Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm.
---------------------------------------------
https://socket.dev/blog/slopsquatting-targets-across-frontier-llms?utm_medi…
=====================
= Vulnerabilities =
=====================
∗∗∗ VU#847406: Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability ∗∗∗
---------------------------------------------
Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placing malicious files, such as DLLs, in that directory. To mitigate this vulnerability, install Duplicati in the default C:\Program Files\ directory or update to the latest fixed version.
---------------------------------------------
https://kb.cert.org/vuls/id/847406
∗∗∗ Atlassian: Schadcode-Lücken bedrohen Bamboo und Bitbucket ∗∗∗
---------------------------------------------
Nutzen Angreifer erfolgreich Sicherheitslücken in Atlassian Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira, Jira Service Management oder Sourcetree für macOS/Windows aus, können sie PCs im schlimmsten Fall vollständig kompromittieren. Sicherheitsupdates stehen zum Download bereit.
---------------------------------------------
https://www.heise.de/news/Atlassian-Schadcode-Luecken-bedrohen-Bamboo-und-B…
∗∗∗ Drupal Security Advisories 2026-July-22 ∗∗∗
---------------------------------------------
https://www.drupal.org/security
∗∗∗ Ricoh MFP and Printer Products: Vulnerability in SSH Function ∗∗∗
---------------------------------------------
https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2026-0…
∗∗∗ LWN Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1084401/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 21-07-2026 18:00 − Mittwoch 22-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Critical SharePoint RCE flaw exploited to steal machine keys ∗∗∗
---------------------------------------------
Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. [..] While applying the latest SharePoint security updates removes the vulnerability, watchTowr advises defenders to also rotate credentials on any asset that may have been exposed.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw…
∗∗∗ OpenAI hackt beliebtes KI-Portal, macht daraus PR-Stunt ∗∗∗
---------------------------------------------
Die neuesten Modelle seien bei einem Sicherheitstest eigenständig „ausgebrochen“ und hätten Hugging Face attackiert. [..] Der US-Konzern OpenAI hat nun die Verantwortung dafür übernommen.
---------------------------------------------
https://futurezone.at/digital-life/openai-hugging-face-hack-pr-stunt/403177…
∗∗∗ Cyberangriff: Nextcloud-Nutzer wurden auf verdächtige Cloudbox umgeleitet ∗∗∗
---------------------------------------------
Die offizielle Website von Nextcloud ist nach verdächtigen Umleitungen der Besucher temporär vom Netz genommen worden. Ursache war ein Cyberangriff. [..] Da die Nextcloud-Website auf Wordpress basiert, ist denkbar, dass der Angriff unter Ausnutzung zweier kürzlich bekannt gewordener Sicherheitslücken in dem CMS ausgeführt wurde.
---------------------------------------------
https://www.golem.de/news/cyberangriff-nextcloud-nutzer-wurden-auf-verdaech…
∗∗∗ Windows: Global Device ID führt zu gerichtswirksamer Identifikation ∗∗∗
---------------------------------------------
Microsoft nutzt in Windows eine Global Device ID (GDID). Die macht Windows-Installationen eindeutig erkennbar, sie übersteht Neustarts und Windows-Updates und lässt sich nicht entfernen. [..] Auf GitHub hat sich ein User mit dem Handle „SmtimesIWndr“ die Mühe gemacht und Informationen zur Windows GDID zusammengesammelt. Es handelt sich demnach um einen Bestandteil der Windows-Telemetrie, der wird zusammen mit anderen Informationen an Microsofts Server gesendet. [..] Der Global Device Identifier lässt sich also nicht einfach loswerden.
---------------------------------------------
https://heise.de/-11373417
∗∗∗ PyPI: Releases now reject new files after 14 days ∗∗∗
---------------------------------------------
The Python Package Index (PyPI) now rejects new files being uploaded to releases that are older than 14 days. This restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised.
---------------------------------------------
https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-…
∗∗∗ LG to Ban Residential Proxies from Smart TV Apps ∗∗∗
---------------------------------------------
The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn ones television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LGs webOS store allow unknown third-parties to route their Internet traffic through a users TV.
---------------------------------------------
https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smar…
∗∗∗ Klimabonus-Phishing ist zurück: Klicken Sie nicht auf diesen Mail-Link! ∗∗∗
---------------------------------------------
Die Kriminellen lassen nicht locker: Aktuell wieder in einer neuen Variante betreffend den Klimabonus im Umlauf. Eine betrügerische E-Mail verspricht Empfänger:innen 290 Euro.
---------------------------------------------
https://www.watchlist-internet.at/news/klimabonus-phishing-mail/
∗∗∗ Adobe Chrome extension flaw let sites access private WhatsApp chats ∗∗∗
---------------------------------------------
Exploiting them requires only that the target running the Adobe Acrobat extension be lured to a web page under the threat actor's control. [..] The issue has been fixed in 26.5.2.3 and delivered automatically to users.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-…
∗∗∗ AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code ∗∗∗
---------------------------------------------
Hidden text on a web page was enough to make Kiro, AWSs agentic coding IDE, rewrite its own configuration file and run an attackers code on a developers machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution.
---------------------------------------------
https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html
=====================
= Vulnerabilities =
=====================
∗∗∗ Serv-U: Datentransfersoftware Serv-U hat 15 kritische Sicherheitslücken ∗∗∗
---------------------------------------------
SolarWinds stopft mit dem Update auf Serv-U 2026.3 insgesamt 15 kritische Sicherheitslücken sowie eine mittleren Schweregrads. Die Auswirkungen reichen von der Rechteausweitung über Informationslecks hin zur Ausführung von eingeschleustem Schadcode aus dem Netz.
---------------------------------------------
https://heise.de/-11373098
∗∗∗ Ubuntu: Root-Lücke in snapd gefährdet unzählige Linux-Systeme ∗∗∗
---------------------------------------------
Angreifer können damit ihre Rechte ausweiten und Root-Zugriff erlangen. Laut Blogbeitrag der Forscher gelingt das bei anfälligen Ubuntu-Versionen bereits in der Standardkonfiguration. Patches sind verfügbar und sollten zeitnah installiert werden. [..] Die Ursache liegt in snap-confine, einer Komponente, die für den Aufbau der Ausführungsumgebung von Snap-Paketen zuständig ist. CVE-2026-8933
---------------------------------------------
https://www.golem.de/news/ubuntu-root-luecke-in-snapd-gefaehrdet-unzaehlige…
∗∗∗ Oracle Critical Patch Update Advisory - July 2026 ∗∗∗
---------------------------------------------
This Critical Patch Update contains 1449 new security patches across the product families listed below.
---------------------------------------------
https://www.oracle.com/security-alerts/cpujul2026.html
∗∗∗ Check Point: Security Advisory – Action Required – July 2026 Security Update ∗∗∗
---------------------------------------------
As part of Check Point’s Frontier AI Readiness Program, we are releasing a jumbo hotfix with security and hardening fixes for our firewall and management products. [..] This only affects a very specific configuration — when Management is exposed directly to the internet without IP restrictions. We’ve already notified the affected customers.
---------------------------------------------
https://blog.checkpoint.com/security/security-advisory-action-required-acti…
∗∗∗ Plane: VU#762226: Plane contains multi-tenant authorization bypass vulnerability ∗∗∗
---------------------------------------------
https://kb.cert.org/vuls/id/762226
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1084210/
∗∗∗ QNAP: Kritische Schwachstellen in QNAP NAS File Station 5 ∗∗∗
---------------------------------------------
https://www.syss.de/pentest-blog/kritische-schwachstellen-in-qnap-nas-file-…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 20-07-2026 18:00 − Dienstag 21-07-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ JadePuffer agentic attacks now target AI model data with ransomware ∗∗∗
---------------------------------------------
The JadePuffer autonomous AI agent has upgraded with custom malware called EncForge that focuses on encrypting AI assets, such as training datasets, vector databases, and model checkpoints.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/jadepuffer-agentic-attacks-n…
∗∗∗ Attackers Combo Up Evasion Tactics for BEC Phishing ∗∗∗
---------------------------------------------
Researchers at Fortinet since late March have observed the campaign, dubbed "The TFF Trap," which uses a combination of fileless techniques and Lua-based loaders with low detection rates to deploy various malware families, including Agent Tesla, Remcos, XWorm, and Best Private Logger, according to a report published last week. The name comes from attackers' use of a TrueType Font (.ttf) file to hide the AutoIT/Lua loader used to deliver malware.
---------------------------------------------
https://www.darkreading.com/endpoint-security/attackers-combo-evasion-tacti…
∗∗∗ LG Monitors Silently Install Adware-Like App On Windows PCs ∗∗∗
---------------------------------------------
VideoCardz reports that connecting certain LG monitors to Windows PCs can trigger Windows Update to automatically install the LG Monitor App Installer, which runs at startup and repeatedly displays McAfee trial promotions. From the report: Gamers Nexus reproduced the behavior with an LG UltraGear 34GX900A-B after receiving reports from monitor owners. Windows Update first installed LG extension and software component packages.
---------------------------------------------
https://hardware.slashdot.org/story/26/07/20/1736218/lg-monitors-silently-i…
∗∗∗ Malicious cloud customers can bring down the power grid ∗∗∗
---------------------------------------------
The attack, dubbed Bit2Watt, imagines an adversary masquerading as a legitimate cloud tenant to launch GPU workloads that have the potential to damage datacenters and supporting electrical systems. It's intended to demonstrate the need to extend cybersecurity defenses to datacenter workload scheduling.
---------------------------------------------
https://www.theregister.com/ai-and-ml/2026/07/20/malicious-cloud-customers-…
∗∗∗ AgentBaiting: How 800+ Fake AI Skills and MCP Servers Delivered Malware ∗∗∗
---------------------------------------------
Inside the 7,600-repository FakeGit operation that brought SmartLoader into the AI capability supply chain, using GitHub repositories, public AI registries, and agent-readable instructions to create a new enterprise attack surface.
---------------------------------------------
https://www.island.io/blog/agentbaiting-how-800-fake-ai-skills-and-mcp-serv…
∗∗∗ What happens if you visit a WordPress site hacked through wp2shell? ∗∗∗
---------------------------------------------
WordPress has patched a serious core vulnerability chain known as wp2shell, and site owners are understandably focused on updating their own sites. But there’s another question worth asking: what happens to ordinary visitors when they land on a compromised site?
---------------------------------------------
https://www.malwarebytes.com/blog/bugs/2026/07/what-happens-if-you-visit-a-…
∗∗∗ Monday, July 27, 2026 Security Releases ∗∗∗
---------------------------------------------
The Node.js project will release new versions of the 26.x, 24.x, 22.x releases lines on or shortly after, Monday, July 27, 2026 in order to address: The highest severity issue fixed in this release is HIGH.
---------------------------------------------
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases
∗∗∗ Rumänien: Cyberkrimineller löscht die gesamte Grundbuchdatenbank des Landes ∗∗∗
---------------------------------------------
Ein Angreifer löscht die gesamte rumänische Grundbuchdatenbank, nachdem eine Erpressung scheiterte, und bringt damit den Immobilienmarkt zum Stillstand.
---------------------------------------------
https://heise.de/-11371451
∗∗∗ Passkeys in der Praxis – Teil 1: Die Architektur von Passkeys ∗∗∗
---------------------------------------------
So funktionieren Passkeys: Der erste Teil der Praxis-Serie für Entwickler zeigt im Detail die Architektur, die auf FIDO2 und WebAuthn aufbaut.
---------------------------------------------
https://heise.de/-11364345
∗∗∗ Suno-Datenleck: Have I Been Pwned ergänzt 55 Millionen Konten ∗∗∗
---------------------------------------------
Das Have-I-Been-Pwned-Projekt hat mehr als 55 Millionen Konten aus dem Suno-Datenleck zur Datenhalde hinzugefügt.
---------------------------------------------
https://heise.de/-11371843
=====================
= Vulnerabilities =
=====================
∗∗∗ Zimbra: Patch Release Update: Zimbra 10.1.20 ∗∗∗
---------------------------------------------
This release contains fixes for multiple critical security issues including a permanent fix for the critical SNMP vulnerability disclosed in our recent security advisory. The release also includes bug fixes in licensing and mail filtering.
---------------------------------------------
https://blog.zimbra.com/2026/07/patch-release-update-zimbra-10-1-20/
∗∗∗ Sicherheitspatch Grafana: Angreifer können sensible Daten abgreifen ∗∗∗
---------------------------------------------
Wie aus einer Warnmeldung von GrafanaLabs hervorgeht, ist die Lücke (CVE-2026-28381) als „kritisch“ eingestuft. Dem Beitrag zufolge sind Grafana-Installationen mit aktivem Snowflake-Datasource-Connector von der Schwachstelle betroffen.
---------------------------------------------
https://heise.de/-11371859
∗∗∗ LWN: Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1083948/
∗∗∗ Mozilla Foundation Security Advisories July 21, 2026 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/
∗∗∗ Tenable: [R1] Stand-alone Security Patch Available for Tenable Security Center Versions 6.6.0, 6.7.2 and 6.8.0: SC202607.1 ∗∗∗
---------------------------------------------
https://www.tenable.com/security/tns-2026-19
∗∗∗ Zyxel security advisory for post-authentication command injection vulnerability in certain DSL/Ethernet CPE, Fiber ONTs, and Wireless Extenders ∗∗∗
---------------------------------------------
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 17-07-2026 18:00 − Montag 20-07-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Microsoft warns of surge in ACR Stealer attacks on customers ∗∗∗
---------------------------------------------
Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/microsoft-warns-of-surge-in-…
∗∗∗ Cyberangriff: Bafin verhängt 240.000 Euro-Strafe gegen Teamviewer ∗∗∗
---------------------------------------------
Weil Teamviewer einen Angriff durch russische Hacker nicht sofort an die Börse meldete, greift die Finanzaufsicht Bafin nun durch.
---------------------------------------------
https://www.golem.de/news/cyberangriff-bafin-verhaengt-240-000-euro-strafe-…
∗∗∗ Russian Intelligence Hacks IP Cameras to Spy on Military Logistics Across NATO States and Ukraine ∗∗∗
---------------------------------------------
At least one Russian intelligence service is systematically hijacking internet-connected security cameras across Europe and Ukraine, using the feeds to watch military transport routes, weapons shipments bound for Kyiv, and the locations of Ukrainian troops.
---------------------------------------------
https://thehackernews.com/2026/07/russian-intelligence-hacks-ip-cameras.html
∗∗∗ Critical ServiceNow code execution flaw now exploited in attacks ∗∗∗
---------------------------------------------
Attackers have begun exploiting a critical vulnerability (CVE-2026-6875) in the ServiceNow AI Platform, according to threat intelligence company Defused.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/critical-servicenow-code-exe…
∗∗∗ New NadMesh Botnet Hunts Exposed AI Services for Cloud Keys and Kubernetes Tokens ∗∗∗
---------------------------------------------
A Go botnet called NadMesh turned up in early July hunting exposed AI services, and the operator's own dashboard claims 3,811 unique AWS keys.
---------------------------------------------
https://thehackernews.com/2026/07/new-nadmesh-botnet-hunts-exposed-ai.html
∗∗∗ Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT ∗∗∗
---------------------------------------------
Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack.
---------------------------------------------
https://thehackernews.com/2026/07/seven-malicious-vite-npm-packages-use.html
∗∗∗ SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads.
---------------------------------------------
https://thehackernews.com/2026/07/sleepergem-uses-three-malicious.html
∗∗∗ HollowGraph Malware Hides C2 and Stolen Files in Microsoft 365 Events Dated 2050 ∗∗∗
---------------------------------------------
A newly discovered espionage implant has been using a hijacked Microsoft 365 calendar as its command channel, planting operator instructions and smuggling out stolen files as attachments on calendar events dated to the year 2050.
---------------------------------------------
https://thehackernews.com/2026/07/hollowgraph-malware-hides-c2-and-stolen.h…
∗∗∗ IPFire: Knot Resolver ersetzt Unbound ∗∗∗
---------------------------------------------
IPFire Core Update 203 ersetzt Unbound durch Knot Resolver, bringt DNS-Firewall, DoT und 6-GHz-WLAN.
---------------------------------------------
https://www.heise.de/news/IPFire-Knot-Resolver-ersetzt-Unbound-11371136.html
∗∗∗ 7 Sandbox Escape Vulnerabilities Across 4 Coding Agent Vendors ∗∗∗
---------------------------------------------
Over several months, Pillar Research found and reproduced sandbox escapes and boundary bypasses across Cursor, Codex, Gemini CLI, and Antigravity. In almost every case, the agent did not need to break the sandbox directly. It only had to write something that a trusted component outside the sandbox would later run, load, scan, or treat as safe. In aggregate, these vulnerabilities show that AI coding agents change the endpoint threat model, and that most sandbox designs have not caught up.
---------------------------------------------
https://www.pillar.security/blog/the-week-of-sandbox-escapes
∗∗∗ Abbott Laboratories probes two cyber incidents amid extortion claims ∗∗∗
---------------------------------------------
Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that attackers breached its LabCentral portal and stole company data.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/abbott-laboratories-probes-t…
=====================
= Vulnerabilities =
=====================
∗∗∗ Kritische Sicherheitslücken in WordPress - Updates verfügbar ∗∗∗
---------------------------------------------
In WordPress existieren zwei Sicherheitslücken. Eine SQL-Injection-Schwachstelle im Parameter „author__not_in“ von „WP_Query“ betrifft WordPress ab Version 6.8. Ab WordPress 6.9 lässt sich diese laut Advisory in Kombination mit einer Schwachstelle in der REST-API (Batch-Route-Confusion) zur Ausführung von beliebigem Code (Remote Code Execution) ausnutzen. Laut Searchlight Cyber ist diese Angriffskette ohne vorherige Authentifizierung und ohne weitere Voraussetzungen in einer Standardinstallation ohne Plugins nutzbar.
---------------------------------------------
https://www.cert.at/de/warnungen/2026/7/kritische-sicherheitslucken-in-word…
∗∗∗ Update now: 7-Zip fixes RCE flaw exploitable with malicious archives ∗∗∗
---------------------------------------------
7-Zip version 26.02 was released on June 25 to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. The vulnerability, disclosed by Lunbun researcher Landon Peng, exists in 7-Zip's processing of XZ-compressed data. According to an advisory from the Zero Day Initiative published this week, a specially crafted XZ data can trigger a heap-based buffer overflow, potentially allowing attackers to execute arbitrary code as the user.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/update-now-7-zip-fixes-rce-f…
∗∗∗ Angriff mit nur 11 Bytes: OpenSSL-Bug lässt Speicher von Servern volllaufen ∗∗∗
---------------------------------------------
Durch eine Sicherheitslücke in OpenSSL können Angreifer mit 11-Byte-Paketen den RAM anfälliger Server stark auslasten und Ausfälle herbeiführen.
---------------------------------------------
https://www.golem.de/news/angriff-mit-nur-11-bytes-openssl-bug-laesst-speic…
∗∗∗ Cyberangriff auf Hugging Face: KI erkennt KI-Angriff auf KI-Plattform ∗∗∗
---------------------------------------------
Hugging Face hat einen von KI-Agenten ausgeführten Cyberangriff per KI entdeckt. Der Zugriff gelang durch Sicherheitslücken in der KI-Plattform.
---------------------------------------------
https://www.golem.de/news/cyberangriff-auf-hugging-face-ki-erkennt-ki-angri…
∗∗∗ Kritische Sicherheitslücke: Schadcode kann auf Nginx-Server schlüpfen ∗∗∗
---------------------------------------------
Angreifer können Nginx Open Source und Nginx Plus attackieren. Sicherheitsupdates sind verfügbar.
---------------------------------------------
https://www.heise.de/news/Kritische-Sicherheitsluecke-Schadcode-kann-auf-Ng…
∗∗∗ Microsoft verteilt außerplanmäßiges Windows-Update ∗∗∗
---------------------------------------------
Microsoft verteilt ein ungeplantes Windows-Update. Es soll Probleme beheben, die insbesondere bei Dell-Computern aufgetreten sind.
---------------------------------------------
https://www.heise.de/news/Windows-Update-ausser-der-Reihe-korrigiert-Perfor…
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1083708/
∗∗∗ Langflow 1.3.0 Remote Code Execution ∗∗∗
---------------------------------------------
https://cxsecurity.com/issue/WLB-2026070007
∗∗∗ K000162343: Multiple Oracle Java SE vulnerabilities ∗∗∗
---------------------------------------------
https://my.f5.com/manage/s/article/K000162343
∗∗∗ Case closed: DIVD-2025-00003 - Multiple vulnerabilities in Mennekes Smart / Premium Charging stations ∗∗∗
---------------------------------------------
https://csirt.divd.nl/cases/DIVD-2025-00003/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 16-07-2026 18:00 − Freitag 17-07-2026 18:00
Handler: Guenes Holler
Co-Handler: Michael Schlagenhaufer
=====================
= News =
=====================
∗∗∗ Kurz nach Microsoft-Patchday: Kritische Sharepoint-Lücke wird aktiv ausgenutzt ∗∗∗
---------------------------------------------
Bei der besagten Sicherheitslücke handelt es sich um CVE-2026-58644. Laut Beschreibung kann ein Angreifer damit aus der Ferne Schadcode einschleusen und zur Ausführung bringen. Ursache ist eine mögliche Deserialisierung nicht-vertrauenswürdiger Daten in Microsoft Sharepoint. Den Angaben zufolge muss ein Angreifer für eine erfolgreiche Ausnutzung mindestens als Site Owner authentifiziert sein.
---------------------------------------------
https://www.golem.de/news/kurz-nach-microsoft-patchday-kritische-sharepoint…
∗∗∗ Claude Chrome extension flaw lets malicious extensions trigger AI actions ∗∗∗
---------------------------------------------
A flaw in Anthropics Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claudes access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/claude-chrome-extension-flaw…
∗∗∗ New ClickLock macOS malware traps users into revealing login password ∗∗∗
---------------------------------------------
A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-clicklock-macos-malware-…
∗∗∗ Ernst & Young discloses data breach after support system hack ∗∗∗
---------------------------------------------
Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-da…
∗∗∗ 1M+ Emails Use Hidden Text to Dupe AI Security Filters ∗∗∗
---------------------------------------------
Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox.
---------------------------------------------
https://www.darkreading.com/threat-intelligence/1m-emails-hidden-text-dupe-…
∗∗∗ Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images ∗∗∗
---------------------------------------------
North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges.
---------------------------------------------
https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html
∗∗∗ Windows Server 2022: Mainstream-Support endet in 90 Tagen ∗∗∗
---------------------------------------------
Windows Server 2022 fällt in 90 Tagen aus dem Mainstream-Support. Erweiterte Sicherheitsupdates gibt es bis 2031 – und danach ESU.
---------------------------------------------
https://www.heise.de/news/Windows-Server-2022-Mainstream-Support-endet-in-9…
∗∗∗ AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report ∗∗∗
---------------------------------------------
The report spotlights four defining trends shaping the threat landscape. We’ll take a closer look at Trend 1: AI Has Become a Force Multiplier for Attackers.
---------------------------------------------
https://unit42.paloaltonetworks.com/ai-incident-response-report/
=====================
= Vulnerabilities =
=====================
∗∗∗ Google Chrome: Ungeplantes Sicherheitsupdate Nummer zwei in dieser Woche ∗∗∗
---------------------------------------------
Google aktualisiert Chrome eigentlich jeden Mittwoch. Diese Woche folgt ein zweites Update, das mehrere kritische Lücken schließt. [..] Drei davon gelten als „kritisch“, es handelt sich um nicht näher erläuterte Use-after-free-Schwachstellen in den Komponenten CameraCapture (CVE-2026-15899), GPU (CVE-2026-15900) sowie Network (CVE-2026-15901).
---------------------------------------------
https://heise.de/-11368362
∗∗∗ Critical Notepad++ Bugs Could Lead to Code Execution, Patch Available ∗∗∗
---------------------------------------------
The latest Notepad++ vulnerabilities addressed in version 8.9.7 include several high-impact security flaws that could expose Windows systems to arbitrary code execution, file overwrite attacks, memory corruption, and authentication bypass. Among the most critical issues is a PowerShell command injection vulnerability in the installer, alongside fixes for CVE-2026-52886, CVE-2026-54758, and CVE-2026-57233.
---------------------------------------------
https://thecyberexpress.com/notepad-vulnerabilities-v897/
∗∗∗ VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions ∗∗∗
---------------------------------------------
https://kb.cert.org/vuls/id/885548
∗∗∗ LWN: Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1083388/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 15-07-2026 18:00 − Donnerstag 16-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Have I Been Pwned: 821.100 Datensätze von Messgerätehersteller Fluke ergänzt ∗∗∗
---------------------------------------------
Das Have-I-Been-Pwned-Projekt hat 821.100 Kontodaten des Messgeräteherstellers Fluke zur Datenhalde hinzugefügt.
---------------------------------------------
https://heise.de/-11367041
∗∗∗ GoSerpent: a persistent threat evolves with sophisticated data collection and exfiltration ∗∗∗
---------------------------------------------
Two-phase attacks with the GoSerpent backdoor, Stowaway RAT, ThumbcacheService and other tools aim to steal data from government entities in Southeast Asia.
---------------------------------------------
https://securelist.com/goserpent-backdoor-in-southeast-asia/120687/
∗∗∗ Unpatched Shark Vacuum Flaw Could Let Attackers Control Other Vacuums Region-Wide ∗∗∗
---------------------------------------------
Pull the certificate off the flash of a Shark RV2320EDUS robot vacuum, and you can run root commands on other people's Shark vacuums across the same AWS region: watch the camera, drive the robot, read the map of the house, and take the Wi-Fi password in plaintext.
---------------------------------------------
https://thehackernews.com/2026/07/unpatched-shark-vacuum-flaw-could-let.html
∗∗∗ New TELEPUZ Malware Spreads via ClickFix to Steal Data and Run Commands ∗∗∗
---------------------------------------------
Cybersecurity researchers have called attention to a new modular malware called TELEPUZ that's been spreading via websites infected with ClickFix lures since late April 2026.
---------------------------------------------
https://thehackernews.com/2026/07/new-telepuz-malware-spreads-via.html
∗∗∗ Booking-Betrug per WhatsApp: Gefälschte Nachricht fordert Datenbestätigung ∗∗∗
---------------------------------------------
Der Urlaub ist gebucht, die Vorfreude groß, und dann meldet sich plötzlich der Vermieter über WhatsApp: Die Reservierung müsse noch einmal bestätigt werden, sonst drohe die Stornierung. Klingt nach Routine, ist aber eine Falle. Dahinter stecken Kriminelle, die sich Zugang zu echten Buchungsdaten verschafft haben.
---------------------------------------------
https://www.watchlist-internet.at/news/booking-betrug-per-whatsapp/
∗∗∗ UAT-11795 deploys novel Starland RAT and bespoke WLDR C2 implant in financially motivated campaign ∗∗∗
---------------------------------------------
Cisco Talos is disclosing UAT-11795, a sophisticated, Russian-speaking, financially motivated adversary that has been conducting a malicious campaign targeting users in the U.S. and Europe since at least June 2025.
---------------------------------------------
https://blog.talosintelligence.com/uat-11795-deploys-novel-starland-rat-and…
=====================
= Vulnerabilities =
=====================
∗∗∗ Webkonferenztool Zoom: Kontoübernahme aus dem Netz möglich ∗∗∗
---------------------------------------------
Zoom hat mehrere Sicherheitslücken in der Webkonferenzsoftware geschlossen. Sie ermöglichen etwa Kontoübernahme aus dem Netz.
---------------------------------------------
https://www.heise.de/news/Webkonferenztool-Zoom-Kontouebernahme-aus-dem-Net…
∗∗∗ Cisco RoomOS Security Hardening Release: July 2026 ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Cisco Identity Services Engine Path Traversal Vulnerability ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Splunk Security Advisories 2026-07-15 (1x Critical) ∗∗∗
---------------------------------------------
https://advisory.splunk.com//advisories
∗∗∗ Drupal Security advisories 2026-July-15 ∗∗∗
---------------------------------------------
https://www.drupal.org/security
∗∗∗ LWN Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1083201/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 14-07-2026 18:00 − Mittwoch 15-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ CISA sounds alarm over trio of exploited SharePoint flaws ∗∗∗
---------------------------------------------
Three bugs are under active attack, and two more critical holes could add to the pain. [..] Additionally, CISA appears concerned by CVE-2026-45659 (8.8) – a remote code execution (RCE) flaw made public in June and confirmed as being actively used in attacks last week after Microsoft said exploitation was "less likely."
---------------------------------------------
https://www.theregister.com/security/2026/07/15/cisa-sounds-alarm-over-trio…
∗∗∗ Researcher Drops New Windows Zero-Day PoC Hours After Microsoft Patch Tuesday ∗∗∗
---------------------------------------------
Security researcher Chaotic Eclipse (aka Nightmare-Eclipse) has released a new proof-of-concept (PoC) exploit called LegacyHive. It has been described as a Windows User Profile Service arbitrary hive load elevation of privileges vulnerability. [..] What makes it notable is that it's functional on all supported desktop and server versions of Windows, including those running the latest July 2026 Patch Tuesday update. [..] Microsoft told The Hacker News that it's investigating the new report.
---------------------------------------------
https://thehackernews.com/2026/07/researcher-drops-new-windows-zero-day.html
∗∗∗ US charges alleged operators of Russian bulletproof hosting service ∗∗∗
---------------------------------------------
U.S. federal prosecutors have unsealed charges against three Russian nationals, accusing them of providing bulletproof hosting (BPH) services to ransomware gangs that caused over $62 million in damages to victims worldwide. [..] The two BPH services, Media Land and ML.Cloud, also provided customers with infrastructure in multiple countries outside Russia, including China, Finland, the Netherlands, as well as the United States.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/us-charges-alleged-russian-b…
∗∗∗ LabubaRAT Masquerades as NVIDIA Software to Control Windows Hosts ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a previously undocumented Rust-based remote access trojan (RAT) codenamed LabubaRAT that masquerades as NVIDIA software to blend into target environments. [..] The starting point of the attack chain is an executable named "nvidia-sysruntime.exe," which impersonates NVIDIA's container runtime toolkit.
---------------------------------------------
https://thehackernews.com/2026/07/labubarat-masquerades-as-nvidia.html
∗∗∗ Cursor Flaw Lets Malicious Cloned Repositories Trigger Windows Code Execution ∗∗∗
---------------------------------------------
Open a repository in Cursor on Windows and, if a file named git.exe is sitting in the project root, Cursor runs it. No click, no approval dialog, no warning that anything in the folder is about to execute. [..] We asked Cursor to name any release that fixes it, and Mindgard, which version it last tested. This story will be updated with any response. [..] Mindgard is not the first firm to find this, and not the first to get Cursor's answer on it.
---------------------------------------------
https://thehackernews.com/2026/07/cursor-flaw-lets-malicious-cloned.html
∗∗∗ Spotify: "Ihr Zugang läuft ab" ∗∗∗
---------------------------------------------
Eine gefälschte Mail von Spotify sorgt gerade für Verunsicherung. Die Abbuchung sei fehlgeschlagen, heißt es darin. Das Premium-Abo drohe zu verfallen. Ignorieren Sie die Mail und klicken Sie nicht auf den Link!
---------------------------------------------
https://www.watchlist-internet.at/news/spotify-laeuft-ab/
∗∗∗ TuxBot v3: Inside an IoT Botnet Framework With LLM-Assisted Development ∗∗∗
---------------------------------------------
TuxBot is a modular IoT botnet framework derived from various known IoT botnet codebases. Based on our analysis of the samples, TuxBot includes features borrowed from the known botnet AISURU and the publicly unknown Wuhan botnet lineages.
---------------------------------------------
https://unit42.paloaltonetworks.com/tuxbot-v3-evolution-iot-botnet/
∗∗∗ Six Minutes to Compromise: How ‘Patriot Bait’ Actor Used AI to Build and Deploy a C&C Botnet ∗∗∗
---------------------------------------------
This report walks through the interaction between the threat actor and the AI agent and explains how this methodology is trivially portable to other threat actors, how the threat landscape has changed with AI, and provide detection guidance for defenders.
---------------------------------------------
https://www.trendmicro.com/en_us/research/26/g/actor-behind-patriot-bait-us…
∗∗∗ Ungeschützte Wechselrichter: Hoymiles verspricht Update ∗∗∗
---------------------------------------------
In der vergangenen Woche hat der Chaos Computer Club (CCC) auf eine Sicherheitslücke in Wechselrichtern von Hoymiles hingewiesen, durch die die Geräte aus hunderten Metern Entfernung manipuliert, abgeschaltet oder sogar zerstört werden können. Jetzt hat der Hersteller reagiert und verspricht ein Firmware-Update, das derartige Angriffe verhindern soll.
---------------------------------------------
https://heise.de/-11365046
∗∗∗ Fake-GitHub-Repositorys: Infostealer statt Security- oder Developer-Tools ∗∗∗
---------------------------------------------
Gut 290 GitHub-Repositorys, die angeblich von Securityanbietern, Toolherstellern und weiteren Firmen sind, verteilen Schadcode zum Abgreifen von Daten.
---------------------------------------------
https://heise.de/-11365096
=====================
= Vulnerabilities =
=====================
∗∗∗ VMSA-2026-0005: VMware Avi Load Balancer addresses multiple vulnerabilities (CVE-2026-47865, CVE-2026-47866, CVE-2026-47867, CVE-2026-47868, CVE-2026-47869, CVE-2026-47870, CVE-2026-47871) ∗∗∗
---------------------------------------------
VMware Avi Load Balancer contains an authentication bypass vulnerability. Broadcom has evaluated the severity of the issue to be in the Critical severity range with a maximum CVSSv3 base score of 9.8. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism.
---------------------------------------------
https://support.broadcom.com/web/ecx/support-content-notification/-/externa…
∗∗∗ Microsoft-Patchday: Neuer Rekord mit 622 gefixten Schwachstellen ∗∗∗
---------------------------------------------
Rund 60 der Sicherheitslücken stuft Microsoft als „kritisches“ Sicherheitsrisiko ein. [..] An fünfter Stelle findet sich bereits der SharePoint-Server mit 17 neuen CVE-Schwachstelleneinträgen, den es nun härter erwischt hat. [..] Angreifer missbrauchen bereits eine fehlende Authentifizierung zur Ausweitung ihrer Rechte in SharePoint.
---------------------------------------------
https://www.heise.de/news/Microsoft-Patchday-Neuer-Rekord-mit-622-gefixten-…
∗∗∗ Exchange Server: Sicherheitsupdates 14. Juli 2026 ∗∗∗
---------------------------------------------
Durch die Installation des Updates vom 14. Juli 2026 werden bereits angewendete Abhilfemaßnahmen für CVE-2026-42897 (siehe z.B. Microsofts Beitrag Addressing Exchange Server May 2026 vulnerability CVE-2026-42897) nicht automatisch entfernt. Daher sollten Administratoren nach der Installation des Juli 2026-SU die nachfolgenden Hinweise beachten.
---------------------------------------------
https://borncity.com/blog/2026/07/15/exchange-server-sicherheitsupdates-14-…
∗∗∗ Adobe: Security updates available for Adobe ColdFusion | APSB26-82 ∗∗∗
---------------------------------------------
https://helpx.adobe.com/in/security/products/coldfusion/apsb26-82.html
∗∗∗ Adobe: Security update available for Adobe Commerce | APSB26-73 ∗∗∗
---------------------------------------------
https://helpx.adobe.com/in/security/products/magento/apsb26-73.html
∗∗∗ Adobe: Security updates available for Adobe Experience Manager | APSB26-74 ∗∗∗
---------------------------------------------
https://helpx.adobe.com/in/security/products/experience-manager/apsb26-74.h…
∗∗∗ Google: Chrome Stable Channel Update for Desktop ∗∗∗
---------------------------------------------
https://chromereleases.googleblog.com/2026/07/stable-channel-update-for-des…
∗∗∗ Mozilla: Security Vulnerabilities fixed in Firefox 152.0.6 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-67/
∗∗∗ TYPO3-CORE-SA-2026-020: Unrestricted File Upload in Form Framework ∗∗∗
---------------------------------------------
https://news.typo3.com/security/advisory/typo3-core-sa-2026-020
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1083044/
∗∗∗ WebKitGTK and WPE WebKit Security Advisory WSA-2026-0004 ∗∗∗
---------------------------------------------
https://webkitgtk.org/security/WSA-2026-0004.html
∗∗∗ [R1] Tenable Agent Versions 11.2.1 and 11.1.4 Fix a Path Traversal Vulnerability ∗∗∗
---------------------------------------------
https://www.tenable.com/security/tns-2026-18
∗∗∗ Veeam Software Appliance/Veeam Infrastructure Appliance — Updater Component Vulnerability ∗∗∗
---------------------------------------------
https://www.veeam.com/kb4879
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 13-07-2026 18:00 − Dienstag 14-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Cyber-Angriff: Außenministerium bestellt Russlands Botschafter ein ∗∗∗
---------------------------------------------
2020 wurde eine Cyber-Attacke auf das österreichische Außenministerium verübt - Meinl-Reisinger: "Cyberangriffe sind inakzeptabel"
---------------------------------------------
https://www.derstandard.at/story/3000000331482/cyber-angriff-aussenminister…
∗∗∗ New phishing kits target Microsoft 365 accounts, evade MFA ∗∗∗
---------------------------------------------
Two new phishing kits, Jalisco and OmegaLord, have been discovered in attacks targeting Microsoft 365 accounts, using techniques that defeat multi-factor authentication (MFA).
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-phishing-kits-target-mic…
∗∗∗ LastPass, Bitwarden users targeted with fake security alerts ∗∗∗
---------------------------------------------
LastPass is warning users about an ongoing phishing campaign that is using fake security notices to direct them to fraudulent websites.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/lastpass-bitwarden-users-tar…
∗∗∗ Next.js strukturiert Sicherheitsmeldungen neu ∗∗∗
---------------------------------------------
Next.js will Sicherheitsmeldungen künftig strukturiert und planbar monatlich veröffentlichen. Kritische Warnungen kommen nach wie vor ad hoc.
---------------------------------------------
https://www.heise.de/news/Next-js-strukturiert-Sicherheitsmeldungen-neu-113…
∗∗∗ Microsoft SharePoint 2016/2019 ab 14. Juli 2026 EOL ∗∗∗
---------------------------------------------
IT-Spezialisten und Administratoren haben den heutigen Juli 2026-Patchday sicherlich im Kalender. Blog-Leser Markus S. hat mich gestern daran erinnert, dass Microsofts SharePoint 2016-Server am heutigen 14. Juli 2026 letztmalig Sicherheitsupdates erhält. Denn SharePoint 2016 erreicht heute sein "End of Life" und bekommt auch keinen Support mehr. Aber auch SharePoint 2019 erreicht sein EOL zum Juli 2026-Patchday.
---------------------------------------------
https://borncity.com/blog/2026/07/14/microsoft-sharepoint-2016-ab-14-juli-2…
∗∗∗ Compromised AsyncAPI packages on npm deliver malware ∗∗∗
---------------------------------------------
A commit to the AsyncAPI generator GitHub repository injected obfuscated JavaScript into four npm packages with a combined weekly download volume of over 3 million. Heres what we know and how to check if youre affected.
---------------------------------------------
https://securitylabs.datadoghq.com/articles/compromised-asyncapi-npm-packag…
∗∗∗ Microsoft macht Passkeys zum Standard in Entra ID ∗∗∗
---------------------------------------------
Microsoft führt Passkeys als Standard-Anmeldemethode in Entra ID ein. SMS- und Sprachanrufe laufen schrittweise aus.
---------------------------------------------
https://www.heise.de/news/Microsoft-macht-Passkeys-zum-Standard-in-Entra-ID…
=====================
= Vulnerabilities =
=====================
∗∗∗ Alte Cisco-Lücke attackiert: Leitfaden zum Schutz ∗∗∗
---------------------------------------------
Die US-IT-Sicherheitsbehörde CISA warnt vor Angriffen auf eine 18 Jahre alte Cisco-Lücke. Ein Leitfaden soll helfen, Router abzusichern.
---------------------------------------------
https://www.heise.de/news/Alte-Cisco-Luecke-attackiert-Leitfaden-zum-Schutz…
∗∗∗ SAP-Patchday: Teils kritische Sicherheitslücken in mehreren Produkten gefixt ∗∗∗
---------------------------------------------
Im Juli verarzten die Programmierer von SAP 16 teils kritische Sicherheitslücken in mehreren Produkten.
---------------------------------------------
https://www.heise.de/news/SAP-Patchday-Teils-kritische-Sicherheitsluecken-i…
∗∗∗ M5Burner: Flash-Tool für M5Stack-Geräte potenziell gefährlich ∗∗∗
---------------------------------------------
Das offizielle Flash-Tool für M5Stack-Geräte weist gravierende Sicherheitsmängel auf. Ein Leser hat die Probleme analysiert und sicheren Ersatz entwickelt.
---------------------------------------------
https://heise.de/-11364555
∗∗∗ 11 Old Microsoft-Signed Linux UEFI Shims Could Let Attackers Bypass Secure Boot ∗∗∗
---------------------------------------------
Cybersecurity researchers have discovered 11 old, Microsoft-signed, Unified Extensible Firmware Interface (UEFI) applications that could be abused to bypass Secure Boot on most systems using the modern firmware standard.
---------------------------------------------
https://thehackernews.com/2026/07/11-old-microsoft-signed-linux-uefi.html
∗∗∗ RabbitMQ Vulnerability Exposes OAuth Secrets to Attackers ∗∗∗
---------------------------------------------
A newly disclosed RabbitMQ vulnerability, tracked as CVE-2026-5721, has raised concerns among enterprise users after researchers revealed that the flaw could allow unauthenticated attackers to retrieve a broker’s confidential OAuth client secret. The successful exploitation could enable attackers to impersonate the broker, obtain administrator-level access, and potentially take control of the messaging infrastructure.
---------------------------------------------
https://thecyberexpress.com/cve-2026-5721-rabbitmq-vulnerability/
∗∗∗ LWN Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1082832/
∗∗∗ PSIRT Out of bounds read in GUI ∗∗∗
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-146
∗∗∗ PSIRT Unauthenticated VNC access exposed on all interfaces ∗∗∗
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-145
∗∗∗ Ivanti July 2026 Security Update ∗∗∗
---------------------------------------------
https://www.ivanti.com/blog/july-2026-security-update
∗∗∗ XSA-498 ∗∗∗
---------------------------------------------
https://xenbits.xen.org/xsa/advisory-498.html
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/