=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 13-08-2026 18:00 − Freitag 14-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Microsoft patches LegacyHive Windows zero-day vulnerability ∗∗∗
---------------------------------------------
Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-legacyhiv…
∗∗∗ Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt ∗∗∗
---------------------------------------------
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-wi…
∗∗∗ Ukraine shuts down 94 fraudulent call centers, seize millions in cash ∗∗∗
---------------------------------------------
Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/ukraine-shuts-down-94-fraudu…
∗∗∗ Shell investigates potential incident after Clop data theft claims ∗∗∗
---------------------------------------------
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/shell-investigates-potential…
∗∗∗ Security: Der Phish stinkt vom Kopf her ∗∗∗
---------------------------------------------
Anti-Phishing-Kampagnen sollen die IT-Laien in einer Firma fit gegen Angriffe machen. Das ist aber komplett der falsche Ansatz. Ein IMHO von R. Zehl
---------------------------------------------
https://www.golem.de/news/security-der-phish-stinkt-vom-kopf-her-2608-21187…
∗∗∗ APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit ∗∗∗
---------------------------------------------
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
---------------------------------------------
https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
∗∗∗ Digitale Kaperbriefe: US-Regierung erlaubt Unternehmen offensive Cyberangriffe ∗∗∗
---------------------------------------------
Im Kampf gegen transnationale kriminelle Akteure will die US-Regierung verstärkt auf die Privatwirtschaft setzen. Unternehmen sollen selbst angreifen dürfen.
---------------------------------------------
https://www.heise.de/news/Digitale-Kaperbriefe-US-Regierung-erlaubt-Unterne…
∗∗∗ Studie zum Umgang mit Passkeys: Nutzer wissen zu wenig Bescheid ∗∗∗
---------------------------------------------
Passkeys sollen Passwörter ablösen, sie gelten als viel sicherer. In der Praxis fehlt vielen Nutzern noch Wissen, haben US-Forscher herausgefunden.
---------------------------------------------
https://www.heise.de/news/Studie-zum-Umgang-mit-Passkeys-Teilweise-gefaehrl…
∗∗∗ Vermehrt Betrugsversuche auf Buchungsplattformen (booking.com, ..) ∗∗∗
---------------------------------------------
Momentan erreichen uns vermehrt Meldungen über Betrugsversuche in Bezug auf Reisebuchungen über Plattformen wie beispielsweise booking.com. Eine der häufigsten Methoden der Kriminellen ist der Missbrauch echter Buchungsdaten. Dabei erhalten Personen nach einer tatsächlichen Buchung über eine Reiseplattform eine Nachricht per E-Mail, SMS ..
---------------------------------------------
https://www.cert.at/de/aktuelles/2026/8/vermehrt-betrugsversuche-auf-buchun…
∗∗∗ New Mirai variant adds stealth capabilities to notorious botnet code ∗∗∗
---------------------------------------------
Beyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials.
---------------------------------------------
https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code
∗∗∗ You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) ∗∗∗
---------------------------------------------
Suddenly, you’re in a room. You look around - oh, you’re surrounded by other new starters at your new job. Yes, it’s Monday, and you’re being onboarded.You know the drill - it’s the typical ..
---------------------------------------------
https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth…
∗∗∗ Seitenkanal erlaubt Zugriff auf RAM des AMD-Sicherheitscontrollers PSP ∗∗∗
---------------------------------------------
Bei alten AMD-Prozessoren lässt sich die in Hardware verankerte RAM-Adressverwaltung manipulieren, um auf vermeintlich geschützte Bereiche zuzugreifen.
---------------------------------------------
https://heise.de/-11414481
∗∗∗ How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign ∗∗∗
---------------------------------------------
A practical playbook for investigating GitHub token compromise, drawn from Wiz CIRTs response to a coordinated multi-organization campaign.
---------------------------------------------
https://www.wiz.io/blog/investigating-github-pat-compromise
∗∗∗ Closing the Blind Spot: Securing Personal Repositories in the Software Supply Chain ∗∗∗
---------------------------------------------
Personal repositories are where corporate secrets quietly escape. Wiz correlates them to your developers, validates the real risk, and drives the fix.
---------------------------------------------
https://www.wiz.io/blog/securing-personal-repositories
=====================
= Vulnerabilities =
=====================
∗∗∗ External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-098
∗∗∗ [R1] Security Center Version 6.9.0 Fixes Multiple Vulnerabilities ∗∗∗
---------------------------------------------
https://www.tenable.com/security/tns-2026-22
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 12-08-2026 18:00 − Donnerstag 13-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Neue Phishing-Welle trifft zahlreiche Hotels: Gäste sollten wachsam sein ∗∗∗
---------------------------------------------
Mitten in der Ferienzeit häufen sich erfolgreiche Angriffe auf IT-Dienstleister der Hotelbranche. Gäste erhalten derzeit vermehrt täuschend echt wirkende Phishing-Nachrichten, die sie zu Zahlungen oder zur Preisgabe von Kreditkartendaten drängen. Einer der aktuellen Fälle betrifft den österreichischen IT-Dienstleister Seekda. Nach einem Phishing-Angriff informiert Seekda erste Betroffene über ungewöhnliche Zugriffsmuster auf seine Systeme. Das Ausmaß des Sicherheitsvorfalls dürfte groß sein.
---------------------------------------------
https://www.heise.de/news/Phishing-Wellen-Cyberangriffe-auf-IT-Dienstleiste…
∗∗∗ Hundreds of fake Chrome VPN extensions route traffic through a proxy ∗∗∗
---------------------------------------------
More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users traffic through SOCKS5 proxies operated by a single provider.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hundreds-of-fake-chrome-vpn-…
∗∗∗ Android malware combo takes out loans and relays victims credit cards ∗∗∗
---------------------------------------------
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [..] When receiving a call from your bank and asked to take urgent action, it is advisable to terminate the call, dial the number listed on the organization's official website, and ask to connect with the same support agent.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/android-malware-combo-takes-…
∗∗∗ "City-Forum" data-theft attacks target Salesforce, ServiceNow portals ∗∗∗
---------------------------------------------
An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [..] Reco says all of the attacks originate from the IP address 158.220.87.79, hosted by German VPS provider Contabo, and almost always use the default Go-http-client/1.1 user agent when downloading data. This IP address is associated with the city-forum.com domain, which has resolved to the server since at least March 2025, indicating that the infrastructure has remained in place for more than a year.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/city-forum-data-theft-attack…
∗∗∗ Cisco Advance Notification for Publication of August 19, 2026, Security Advisories ∗∗∗
---------------------------------------------
On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: BroadWorks, Industrial Ethernet 1000 Series Switches, Packaged Contact Center Enterprise and Unified Contact Center Enterprise, RoomOS, Secure Firewall Adaptive Security Appliance, Secure Firewall Management Center, Secure Firewall Threat Defense Center, Secure Workload, Unified Intelligence Center
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Verschlüsselter KI-„Denkprozess“ gehackt: Schwache Modelle verraten Geheimnisse ∗∗∗
---------------------------------------------
Über eine Sicherheitslücke lassen sich Abwägungsprotokolle von KI-Top-Systemen wie GPT-5 im Klartext auslesen – mithilfe kleinerer Modelle desselben Anbieters.
---------------------------------------------
https://www.heise.de/hintergrund/Verschluesselter-KI-Denkprozess-gehackt-Sc…
∗∗∗ How BitLocker PINs help protect your data and devices ∗∗∗
---------------------------------------------
The NCSC provides guidance on how to securely configure Microsoft Windows. This includes setting up BitLocker, which encrypts your device to protect the data and the operating system from tampering. Our guidance recommends that BitLocker be configured to require a PIN before decrypting your device.
---------------------------------------------
https://www.ncsc.gov.uk/blogs/how-bitlocker-pins-help-protect-your-data-and…
∗∗∗ WhatsApp-Benutzernamen: Vor- und Nachteile im Überblick ∗∗∗
---------------------------------------------
Wie schützt ein WhatsApp-Benutzername vor Betrug – und welche Daten gibt man preis? Verbraucherschützer bewerten den Status quo beim Meta-Messenger.
---------------------------------------------
https://heise.de/-11412273
=====================
= Vulnerabilities =
=====================
∗∗∗ Fortinet FortiManager FGFM Authentication Weakening via CLI Configuration ∗∗∗
---------------------------------------------
An Authentication Bypass Using an Alternate Path or Channel [CWE-288] vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to impersonate any FortiGate managed by the FortiManager with a specific CLI option set via crafted FGFM requests if the attacker has a valid certificate. CVE-2026-70468
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-160
∗∗∗ GitLab Patch Release: 19.2.2, 19.1.4, 19.0.6 ∗∗∗
---------------------------------------------
These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately.
---------------------------------------------
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-releas…
∗∗∗ Palo Alto Networks Security Advisories 12.08.2026 ∗∗∗
---------------------------------------------
https://security.paloaltonetworks.com/
∗∗∗ LWN: Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1088715/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 11-08-2026 18:00 − Mittwoch 12-08-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access ∗∗∗
---------------------------------------------
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO.
---------------------------------------------
https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html
∗∗∗ Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations ∗∗∗
---------------------------------------------
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more than 2,500 organizations.
---------------------------------------------
https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html
∗∗∗ Brandenburg: Cyberangriff legt IT-System der Gedenkstätten lahm ∗∗∗
---------------------------------------------
Die Stiftung Brandenburgische Gedenkstätten wurde Opfer eines Ransomware-Angriffs. IT-Systeme sind derzeit außer Betrieb, ein Datenabfluss wird vermutet.
---------------------------------------------
https://www.heise.de/news/Brandenburg-Cyberangriff-legt-IT-System-der-Geden…
∗∗∗ Threema: DDoS-Angriffe sorgen für Ausfälle bei Messenger ∗∗∗
---------------------------------------------
Nach einem Angriff auf einen Dienstleister von Threema war der Messenger am Dienstag stundenlang nicht nutzbar. Am Mittwoch dauern die Attacken an.
---------------------------------------------
https://www.heise.de/news/Stoerungen-bei-Threema-DDoS-Angriffe-sorgen-fuer-…
∗∗∗ Deadbugz: Currently Active MCP Supply-Chain Campaign ∗∗∗
---------------------------------------------
Pillar Security Researchers identified an active campaign to distribute a malicious Model Context Protocol (MCP) server through public GitHub pull requests. The server calls itself productivity-suite and initially looks harmless: it offers text formatting and summarization. After a connected client makes three tool calls, however, it changes the instructions it returns to the AI agent. The new metadata directs the agent to seek sensitive information, including SSH keys, AWS credentials, shell history, and Kubernetes configuration, and to conceal the activity from the user.
---------------------------------------------
https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain…
=====================
= Vulnerabilities =
=====================
∗∗∗ Nordkoreas Hacker schlagen zu: Angriffe auf Windows-Nutzer in Europa beobachtet ∗∗∗
---------------------------------------------
Die Hackergruppe Lazarus greift Windows-Nutzer über eine Treiberlücke an. Microsoft hat sie zusammen mit über 400 weiteren Sicherheitslücken gepatcht.
---------------------------------------------
https://www.golem.de/news/auch-in-europa-nordkoreanische-hacker-attackieren…
∗∗∗ Kein Klick nötig: Lücke ermöglicht heimliche Schadcode-Attacken über Zoom-Meetings ∗∗∗
---------------------------------------------
Eine Sicherheitslücke in Zoom lässt Angreifer anderen Meeting-Teilnehmern unbemerkt Schadcode unterschieben. Nutzer sollten zügig updaten.
---------------------------------------------
https://www.golem.de/news/kein-klick-noetig-luecke-ermoeglicht-heimliche-sc…
∗∗∗ Zero-Day-Lücke im Defender: Chaotic Eclipse leakt neuen Windows-Exploit ∗∗∗
---------------------------------------------
Ein neuer Exploit namens Shieldbreak umgeht einen früheren Patch für den Microsoft Defender. Angreifer erhalten damit unter Windows Systemrechte.
---------------------------------------------
https://www.golem.de/news/zero-day-luecke-im-defender-chaotic-eclipse-leakt…
∗∗∗ Böse Screen-Sharing-Lücke in macOS: Exploit aus Apples Patch gebaut ∗∗∗
---------------------------------------------
Wer Apples praktische Bildschirm-teilen-Funktion auf dem Mac nutzt, muss sein Betriebssystem aktualisieren. Ein Exploit ließ sich schnell entwickeln.
---------------------------------------------
https://www.heise.de/news/Boese-Screen-Sharing-Luecke-in-macOS-Exploit-aus-…
∗∗∗ Patchday Adobe: Schadcode-Schlupflöcher bedrohen Campaign Classic und ColdFusion ∗∗∗
---------------------------------------------
Wichtige Sicherheitsupdates schließen mehrere Schwachstellen an Adobe-Anwendungen.
---------------------------------------------
https://www.heise.de/news/Patchday-Adobe-Schadcode-Schlupfloecher-bedrohen-…
∗∗∗ Der Security-Ko-Prozessor in vielen CPUs ist unsicher ∗∗∗
---------------------------------------------
Das Trusted Platform Module ist das wichtigste Glied in der Vertrauenskette von PCs. Ausgerechnet dieses TPM ist angreifbar.
---------------------------------------------
https://www.heise.de/news/Der-Security-Ko-Prozessor-in-vielen-CPUs-ist-unsi…
∗∗∗ Cisco warnt vor Attacken auf Secure Firewall Adaptive Security Appliance ∗∗∗
---------------------------------------------
Derzeit lassen Angreifer Cisco Secure Firewall Adaptive Security Appliance nach Attacken abstürzen. Ein Sicherheitspatch ist verfügbar.
---------------------------------------------
https://heise.de/-11411427
∗∗∗ Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days ∗∗∗
---------------------------------------------
Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch…
∗∗∗ ZDI-26-532: SonicWall Email Security updateNetIf Command Injection Local Privilege Escalation Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-26-532/
∗∗∗ ZDI-26-531: SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-26-531/
∗∗∗ ZDI-26-530: SonicWall Email Security snmp Command Injection Local Privilege Escalation Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-26-530/
∗∗∗ ZDI-26-527: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-26-527/
∗∗∗ PSIRT FortiGuard Labs Heap overflow in kernel driver due to missing size validation ∗∗∗
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-156
∗∗∗ PSIRT FortiGuard Labs Broken access control in the RADIUS type admin group ∗∗∗
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-158
∗∗∗ LWN Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1088476/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 10-08-2026 18:00 − Dienstag 11-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ New Pass-ta-key attack reveals all the things we didnt know about passkeys ∗∗∗
---------------------------------------------
Why passkey apps treat Windows differently than other operating systems.
---------------------------------------------
https://arstechnica.com/security/2026/08/heres-why-the-new-pass-ta-key-atta…
∗∗∗ Hackers breached a small Polish energy plant via private APN last year ∗∗∗
---------------------------------------------
Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-breached-a-small-pol…
∗∗∗ CISA: Microsoft SharePoint flaw now exploited in ransomware attacks ∗∗∗
---------------------------------------------
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-fl…
∗∗∗ Mozilla updates GPG signing key for Firefox releases after exposure ∗∗∗
---------------------------------------------
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-…
∗∗∗ Nach KI-Hacks: Chinesisches KI-Modell trickst Forscher bei Tests aus ∗∗∗
---------------------------------------------
Das KI-Modell Kimi K3 hat bei Tests eine gesicherte Umgebung verlassen und sich die gesuchten Lösungen einfach bei Github beschafft.
---------------------------------------------
https://www.golem.de/news/nach-ki-hacks-chinesisches-ki-modell-trickst-fors…
∗∗∗ Kein Klick nötig: Plug-and-Pwn-Angriff kapert Windows-Systeme per USB ∗∗∗
---------------------------------------------
Windows lädt beim Anschließen neuer USB-Geräte oft Software nach. Angreifer können dadurch Systemrechte erlangen - manchmal sogar aus der Ferne.
---------------------------------------------
https://www.golem.de/news/kein-klick-noetig-plug-and-pwn-angriff-kapert-win…
∗∗∗ BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins ∗∗∗
---------------------------------------------
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platforms plugins team to temporarily disable their downloads."Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.
---------------------------------------------
https://thehackernews.com/2026/08/bdthemes-supply-chain-attack-poisons.html
∗∗∗ Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers ∗∗∗
---------------------------------------------
Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording.The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California drivers license and a New York bank account.The
---------------------------------------------
https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html
∗∗∗ Abyssos: Technical Analysis of a New Modular RAT ∗∗∗
---------------------------------------------
In late June 2026, Zscaler ThreatLabz identified a new malware family that we track as Abyssos. Abyssos is a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. Abyssos is in active development with multiple version numbers and different obfuscation passes that are designed to improve evasion from security ..
---------------------------------------------
https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-…
∗∗∗ Lahmer x86-Befehl hebelt triviale Schutzfunktion aus ∗∗∗
---------------------------------------------
Der mächtige System Management Mode (SMM) von x86-Prozessoren ist ein bevorzugtes Ziel von Angriffen. Ein Trick hebelt eine SMM-Schutzfunktion aus.
---------------------------------------------
https://www.heise.de/news/Lahmer-x86-Befehl-hebelt-triviale-Schutzfunktion-…
∗∗∗ Patchday: SAP Commerce Cloud komplett kompromittierbar ∗∗∗
---------------------------------------------
SAP schließt in seinem Softwareproduktportfolio mehrere unter anderem kritische Sicherheitslücken.
---------------------------------------------
https://www.heise.de/news/Patchday-SAP-Commerce-Cloud-komplett-kompromittie…
∗∗∗ Sexual predators targeting online accounts for intimate images, FBI warns ∗∗∗
---------------------------------------------
The FBI is warning that criminals are breaking into social media to steal and distribute non-consensual intimate images and videos.
---------------------------------------------
https://www.malwarebytes.com/blog/news/2026/08/sexual-predators-targeting-o…
∗∗∗ The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications ∗∗∗
---------------------------------------------
Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution.
---------------------------------------------
https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/
∗∗∗ Poland uncovers second heat plant cyberattack that went hidden for months ∗∗∗
---------------------------------------------
The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.
---------------------------------------------
https://therecord.media/poland-uncovers-critical-infrastructure-attack-hidd…
∗∗∗ LexisNexis deaktiviert nach "verdächtigen Server-Aktivitäten" drei Dienste ∗∗∗
---------------------------------------------
Aktuell ist unklar, was genau passiert ist. Aber seit vorigen Mittwoch, den 5. August 2026, scheint bei LexisNexis etwas passiert zu seine. Der Anbieter hat nach "verdächtigen Server-Aktivitäten" gleich drei Dienste deaktiviert und Verbindungen zu Drittanbietern getrennt. Es laufen Untersuchungen ..
---------------------------------------------
https://borncity.com/blog/2026/08/10/lexisnexis-deaktiviert-nach-verdaechti…
∗∗∗ Steam-Hardware: Käufer müssen nach Cyberangriff mit Betrugsmails rechnen ∗∗∗
---------------------------------------------
Bei Valves Logistikpartner CEVA sind Namen und Adressen europäischer Steam-Hardware-Käufer abgeflossen. Valve warnt vor falschen Nachrichten.
---------------------------------------------
https://heise.de/-11409514
∗∗∗ Google Phishing Kit: When Phishing Becomes a Real-Time Remote Browser ∗∗∗
---------------------------------------------
Most of the phishing pages are mere static clones of the login form, whereas sophisticated phishing kits implement adversary-in-the-middle techniques that perform authentication in real-time. In particular, the design being analyzed below fits into the Browser-in-the-Middle (BitM) scheme where the victim-facing page becomes the client for the browser session running at the backend of the phishing operation.The captured network traffic and the extracted client-side artifacts ..
---------------------------------------------
https://www.joesecurity.org/blog/2909557602925734728
∗∗∗ Inside the Metabase SQLi: Exploited in the Wild ∗∗∗
---------------------------------------------
Reverse engineering Metabase CVE-2026-72898 with AI to accelerate defense.
---------------------------------------------
https://www.wiz.io/blog/inside-the-metabase-sqli-exploited-in-the-wild
=====================
= Vulnerabilities =
=====================
∗∗∗ TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool ∗∗∗
---------------------------------------------
It has been discovered that TYPO3 CMS is susceptible to broken access control.
---------------------------------------------
https://news.typo3.com/security/advisory/typo3-core-sa-2026-021
∗∗∗ Security updates for Tuesday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (gpsd), Debian (caddy, libyaml-syck-perl, nss, and wordpress), Fedora (chezmoi, chromium, emacs, kernel, knot, libcupsfilters, mingw-gstreamer1-plugins-good, mingw-libidn, mingw-python-pip, nghttp2, p11-kit, python-webob, suricata, and xen), Mageia (bind, openslide, php8.4, and php8.5), Oracle (gpsd-minimal, kernel, libarchive, libpng12, nodejs-nodemon, php:8.3, ruby:3.3, and ruby:4.0), SUSE (agama-web-ui, bind, bouncycastle, dhcpcd, ffmpeg, ..
---------------------------------------------
https://lwn.net/Articles/1088226/
∗∗∗ August 2026 Security Update ∗∗∗
---------------------------------------------
https://www.ivanti.com/blog/august-2026-security-update
∗∗∗ SAP Security Patch Day August 2026 | RedRays ∗∗∗
---------------------------------------------
https://redrays.io/blog/sap-security-patch-day-august-2026/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 07-08-2026 18:00 − Montag 10-08-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs ∗∗∗
---------------------------------------------
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws…
∗∗∗ AI-Generated Patches Fail Half the Time ∗∗∗
---------------------------------------------
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.
---------------------------------------------
https://www.darkreading.com/application-security/ai-generated-patches-fail-…
∗∗∗ DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure ∗∗∗
---------------------------------------------
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims.The post DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure appeared first on Microsoft Security Blog.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomwar…
∗∗∗ Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer ∗∗∗
---------------------------------------------
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.
---------------------------------------------
https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html
∗∗∗ New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens ∗∗∗
---------------------------------------------
New research shows content inside an email can escape its message boundary and interfere with the webmail interface.
---------------------------------------------
https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html
∗∗∗ Cyber vulnerability sweep picks up Royal Navy drones sending data to China ∗∗∗
---------------------------------------------
No, no nasties to see here, guv...
---------------------------------------------
https://www.theregister.com/edge-and-iot/2026/08/10/cyber-vulnerability-swe…
∗∗∗ Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All ∗∗∗
---------------------------------------------
Two security researchers bought cheap domains—including noreply.net and deleteduser.com—and set up email listening services. Hundreds of companies are sending them corporate secrets.
---------------------------------------------
https://www.wired.com/story/sensitive-info-goes-into-no-reply-emails-consta…
∗∗∗ Russian military hackers pose as recruiters to target Ukrainian IT workers ∗∗∗
---------------------------------------------
Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency.
---------------------------------------------
https://therecord.media/russian-military-hackers-pose-as-recruiters-ukraine…
∗∗∗ Jeans-Hersteller Levi Strauss & Co. erleidet Datenpanne ∗∗∗
---------------------------------------------
Levi Strauss, als Anbieter von Jeans bekannt, hat die Woche einen Datenschutzvorfall erlitten. Mitarbeiter wurden über Social Media ausgetrickst. Dem Angreifer gelang dann wohl der Zugriff auf drei Rechner von Mitarbeitern.
---------------------------------------------
https://borncity.com/blog/2026/08/08/jeans-hersteller-levi-strauss-co-erlei…
∗∗∗ SANS Institute rät Sicherheitsteams, offene Türen für KI-Agenten zu schließen ∗∗∗
---------------------------------------------
Die Sicherheitsvorfälle bei Anthropic, Open AI und Meta, sowie bei Bytedance, bei denen AI-Modelle oder Agenten aus ihrer Testumgebung ausbrachen und Angriff im Internet durchführten, hat die Branche aufgeschreckt. Das SANS Institute gibt Sicherheitsteams den Tipp: Offene Türen für KI-Agenten zu schließen.
---------------------------------------------
https://borncity.com/blog/2026/08/09/sans-institute-raet-sicherheitsteams-o…
∗∗∗ Investigating a Multi-Stage PowerShell Loader ∗∗∗
---------------------------------------------
During recent threat hunting, I identified suspicious PowerShell content being served directly from an IP address and a domain: hxxp://203[.]188[.]171[.]166/hxxps://dorenzaa[.]com/ Both locations returned PowerShell rather than a conventional user-facing webpage. The PowerShell was responsible for retrieving a ZIP archive from Vercel-hosted infrastructure, extracting it locally, and executing an executable from the extracted content.
---------------------------------------------
https://malwr-analysis.com/2026/08/08/investigating-a-multi-stage-powershel…
∗∗∗ IT threat evolution in Q2 2026. Non-mobile statistics ∗∗∗
---------------------------------------------
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.
---------------------------------------------
https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/
∗∗∗ IT threat evolution in Q2 2026. Mobile statistics ∗∗∗
---------------------------------------------
This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.
---------------------------------------------
https://securelist.com/malware-report-q2-2026-mobile-statistics/120948/
=====================
= Vulnerabilities =
=====================
∗∗∗ Jetzt patchen! Admin-Attacken auf Metabase beobachtet ∗∗∗
---------------------------------------------
Angreifer nutzen zurzeit eine kritische Sicherheitslücke in der Business-Intelligence-Plattform Metabase aus. Admins müssen jetzt handeln.
---------------------------------------------
https://heise.de/-11404526
∗∗∗ Schadcode-Attacken auf Progress LoadMaster im Gange ∗∗∗
---------------------------------------------
Derzeit haben Angreifer Progress LoadMaster auf dem Schirm und attackieren aktiv Systeme. Sicherheitspatches sind verfügbar.
---------------------------------------------
https://heise.de/-11404612
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1088057/
∗∗∗ Security updates 1.6.18 and 1.7.3 released ∗∗∗
---------------------------------------------
https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 06-08-2026 18:00 − Freitag 07-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access ∗∗∗
---------------------------------------------
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables. [..] The disclosure does not identify the exact Windows builds or Windows Hello for Business deployment models tested. [..] The new work removes that requirement by treating the Windows Hello for Business key as a FIDO2 passkey through WebAuthn. Mollema found that the five-minute Entra ID challenge is not bound to a session, user, or tenant. An attacker can therefore request it on another host and have the compromised endpoint produce the signed assertion.
---------------------------------------------
https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html
∗∗∗ Durch Metabase-0day: Datenleck bei Laptophersteller Framework ∗∗∗
---------------------------------------------
Der Laptophersteller Framework hat ein Datenleck erlitten und warnt seine Kunden vor abgeflossenen Informationen. Kontakt- und Lieferdaten privater und gewerblicher Kunden kamen abhanden – Zahlungs- und Bestellinformationen nach Frameworks Angaben jedoch nicht. Offenbar nutzten Angreifer eine Zero-Day-Lücke in Metabase aus; der Datenbankhersteller hat Updates veröffentlicht und seine Cloud-Instanzen abgedichtet.
---------------------------------------------
https://www.heise.de/news/Durch-Metabase-0day-Datenleck-bei-Laptopherstelle…
∗∗∗ ChainDrop: Inside a Self-Propagating npm Worm ∗∗∗
---------------------------------------------
A self-propagating npm worm nicknamed ChainDrop infected over 400 packages that are collectively downloaded hundreds of millions of times each week. This includes malicious versions of widely used packages such as keyv and cacheable-request. Unit 42 has unique observations of this attack.
---------------------------------------------
https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/
∗∗∗ N-able N-central: 2. Hotfix vom 6. August 2026 ∗∗∗
---------------------------------------------
Ein Patch gegen die Schwachstelle (CVE-2026-18576) wirkte nicht. Die RMM-Lösung wird bereits angegriffen. Der Hotfix 1 von Anfang August 2026 scheint nicht auszureichen, vor wenigen Stunden wird ein Hotfix 2 nachgeschoben.
---------------------------------------------
https://borncity.com/blog/2026/08/07/n-able-n-central-2-hotfix-vom-6-august…
∗∗∗ "deGDID" entfernt GDID in Windows und blockt Neuanlage ∗∗∗
---------------------------------------------
Microsoft vergibt in Windows eine eindeutige GDID genannte Kennung, über die Nutzer identifiziert werden können. Der VPN-Anbieter Windscribe hat nun ein Skript entwickelt, um das versteckte GDID-Tracking von Microsoft unter Windows zu blockieren.
---------------------------------------------
https://borncity.com/blog/2026/08/07/degdid-entfernt-gdid-in-windows-und-bl…
∗∗∗ Unternehmen fürchten US-Kill-Switch für kritische IT-Dienste ∗∗∗
---------------------------------------------
74 Prozent der Unternehmen befürchten, dass US-Anbieter auf Druck der US-Regierung wichtige Dienste sperren könnten.
---------------------------------------------
https://heise.de/-11403600
=====================
= Vulnerabilities =
=====================
∗∗∗ Screen Sharing: Gefährliche MacOS-Lücke lässt Angreifer Apple-Systeme kapern ∗∗∗
---------------------------------------------
Die besagte Sicherheitslücke ist als CVE-2026-65400 registriert und verfügt mit einem CVSS-Wert von 7,1 über einen hohen Schweregrad. "Ein Angreifer im Netzwerk könnte sich möglicherweise ohne gültige Anmeldedaten bei der Bildschirmfreigabe authentifizieren", heißt es in der Beschreibung. [..] Die gepatchten MacOS-Versionen tragen die Versionsnummern 26.6.1 (Tahoe), 15.7.9 (Sequoia) und 14.8.9 (Sonoma).
---------------------------------------------
https://www.golem.de/news/screen-sharing-gefaehrliche-macos-luecke-laesst-a…
∗∗∗ New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts ∗∗∗
---------------------------------------------
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page tables used for nested guest memory translation. [..] As of August 6, 2026, Debian's tracker listed bullseye, bookworm, and trixie kernel packages, including their security repositories, as vulnerable.
---------------------------------------------
https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html
∗∗∗ SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free ∗∗∗
---------------------------------------------
SCTPhantom is a Linux kernel use-after-free in SCTP Dynamic Address Reconfiguration. An ordered ASCONF sequence can remove a transport and then reuse its stale pointer, leaving the association with dangling path references. Corvus AI developed the initial finding into a reproducible vulnerability and demonstrated local privilege escalation and container-to-host escape on the tested systems. The issue is tracked as CVE-2026-64564 and fixed upstream by 9b2854f86f0b.
---------------------------------------------
https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564
∗∗∗ WordPress 7.0.3 release ∗∗∗
---------------------------------------------
WordPress 7.0.3 is now available WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. [..] Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai.
---------------------------------------------
https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
∗∗∗ LWN: Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1087742/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 05-08-2026 18:00 − Donnerstag 06-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ COLDCARD security audit phishing attack installs remote access tool ∗∗∗
---------------------------------------------
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/coldcard-security-audit-phis…
∗∗∗ Schweiz: Bundesamt für Informatik und Telekommunikation über Sharepoint gehackt ∗∗∗
---------------------------------------------
Ein Cyberangriff hat das Schweizer BIT getroffen. Angreifer sind über Microsoft Sharepoint eingedrungen und haben Hunderte Nutzerkonten kompromittiert.
---------------------------------------------
https://www.golem.de/news/schweiz-bundesamt-fuer-informatik-und-telekommuni…
∗∗∗ "Wiederkehrendes Muster": OpenSSL-Entwickler wettert gegen KI-Hacks ∗∗∗
---------------------------------------------
Seit einigen Tagen hacken sich vermehrt KI-Modelle von OpenAI, Anthropic und Meta durchs Netz. Das Problem liegt laut OpenSSL-Entwickler Hudson aber nicht bei der KI.
---------------------------------------------
https://www.golem.de/news/wiederkehrendes-muster-openssl-entwickler-wettert…
∗∗∗ Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports ∗∗∗
---------------------------------------------
Two security flaws in Paperclip could let attackers execute commands on a network server or a developers computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and ..
---------------------------------------------
https://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.html
∗∗∗ Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures ∗∗∗
---------------------------------------------
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.The server-side ..
---------------------------------------------
https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html
∗∗∗ Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink.According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available ..
---------------------------------------------
https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.ht…
∗∗∗ Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed a security issue with Apples iCloud Private Relay tool that can expose a users real IP address.Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users privacy by routing ..
---------------------------------------------
https://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.html
∗∗∗ Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities ∗∗∗
---------------------------------------------
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network.Its August 3 scan counted 4,407 exposed Rockwell ..
---------------------------------------------
https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.ht…
∗∗∗ ClaudeFix: Shared Claude Chats Meet ClickFix ∗∗∗
---------------------------------------------
ClickFix is a widely employed attack technique, first seen in 2024, where a victim is instructed to paste-and-run instructions on their system to “fix” a problem or install software. The seemingly benign instructions are, in fact, malicious and lead to the deployment of malware onto the victim’s system. Zscaler Threat Hunting has identified ..
---------------------------------------------
https://www.zscaler.com/blogs/security-research/claudefix-shared-claude-cha…
∗∗∗ Fehlende Kontaktmöglichkeit: Deutschland verschläft Sicherheit per security.txt ∗∗∗
---------------------------------------------
Nur 1,8 Prozent der deutschen Webseiten bieten eine standardisierte security.txt an. Das BSI warnt vor den Risiken und verweist auf kommende Meldepflichten.
---------------------------------------------
https://www.heise.de/news/Fehlende-Kontaktmoeglichkeit-Deutschland-verschla…
∗∗∗ Scammers target OnlyFans users with deepfakes ∗∗∗
---------------------------------------------
Criminals are impersonating OnlyFans creators using AI tools in order to scam followers.
---------------------------------------------
https://www.malwarebytes.com/blog/news/2026/08/scammers-target-onlyfans-use…
∗∗∗ Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits ∗∗∗
---------------------------------------------
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didnt exist.
---------------------------------------------
https://www.bitdefender.com/en-us/blog/hotforsecurity/apple-bug-bounty-ai-m…
∗∗∗ Token Jacking: Cybercriminals Could Be Stealing Your AI Resources ∗∗∗
---------------------------------------------
Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys.
---------------------------------------------
https://unit42.paloaltonetworks.com/ai-token-jacking/
∗∗∗ OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries ∗∗∗
---------------------------------------------
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025.
---------------------------------------------
https://hackread.com/octlurk-silklurk-backdoors-target-6-countries/
∗∗∗ Sicherheitspatches: Angreifer können Schadcode auf n8n-Servern ausführen ∗∗∗
---------------------------------------------
Die n8n-Entwicklwer haben in aktuellen Versionen insgesamt 18 Sicherheitslücken geschlossen.
---------------------------------------------
https://heise.de/-11400494
∗∗∗ Fake Zoom installer uses .NET downloader to deliver Overlord RAT on macOS ∗∗∗
---------------------------------------------
Jamf Threat Labs uncovers a macOS campaign using a fake Zoom installer to deploy Overlord RAT. Built with .NET, this cross-platform technique simultaneously targets Windows, joining Go- and Rust-based cross-platform malware.
---------------------------------------------
https://www.jamf.com/blog/fake-zoom-installer-delivers-overlord-rat-macos/
=====================
= Vulnerabilities =
=====================
∗∗∗ Cisco IOS XE Software Security Hardening Release: August 2026 ∗∗∗
---------------------------------------------
As part of Ciscos ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not ..
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Veeam: Vulnerabilities Resolved in Veeam ONE 13.1 ∗∗∗
---------------------------------------------
Veeam has released 6 new security advisories for Veeam ONE (1x critical, 4x high, 1x medium)
---------------------------------------------
https://www.veeam.com/kb4892
∗∗∗ Security updates for Thursday ∗∗∗
---------------------------------------------
Security updates have been issued by Debian (7zip, kernel, libde265, and p7zip), Mageia (tomcat), Oracle (fence-agents, frr10, kernel, ldns, libgcrypt, mingw-glib2, nodejs24, osbuild-composer, p11-kit, php8.4, sg3_utils, and thunderbird), Red Hat (libXfont2), and SUSE (containerd, evince, libXfont2, nginx, openssl-3, pcp, php7, php8, python-Django, python-httplib2, python-nltk, rrdtool, vifm, and wireshark).
---------------------------------------------
https://lwn.net/Articles/1087489/
∗∗∗ Entity Browser - Moderately critical - Cross site scripting - SA-CONTRIB-2026-094 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-094
∗∗∗ Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-093
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 04-08-2026 18:00 − Mittwoch 05-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Shaid Hulu: Neue Angriffe kompromittieren Hunderte npm-Pakete (4.8.2026) ∗∗∗
---------------------------------------------
Es gibt wohl eine neue Shaid Hulu-Angriffskampagne auf npm-Pakete. Nach dem Hack eines Entwicklerkontos sind wohl schon über 800 npm-Pakete mit Millionen Downloads kompromittiert. [..] Auslöser war die Kompromittierung des GitHub-Kontos des Betreuers von "keyv", einer Bibliothek mit rund 127 Millionen wöchentlichen npm-Downloads.
---------------------------------------------
https://borncity.com/blog/2026/08/05/shaid-hulu-neue-angriffe-kompromittier…
∗∗∗ Weitere KI-Attacke: Modell schleust Schwachstelle ein und manipuliert Menschen ∗∗∗
---------------------------------------------
Die Serie von Enthüllungen über alarmierende Hacker-Fähigkeiten führender KI-Modelle reißt nicht ab. Jetzt ertappten britische Sicherheitsforscher eine Künstliche Intelligenz in einem Testlauf beim Versuch, in Eigeninitiative eine Schwachstelle in öffentlich zugängliche Software einzuschleusen. Um damit durchzukommen, versuchte das KI-Modell der Entwicklerfirma Anthropic den Experten zufolge sogar, per E-Mail einen zuständigen Menschen zu manipulieren.
---------------------------------------------
https://heise.de/-11399219
∗∗∗ Cyberangriff auf Ungarn: Hacker stürzt Finanzverwaltung ins IT-Chaos ∗∗∗
---------------------------------------------
Ein Angreifer hat IT-Systeme der Finanzverwaltung Ungarns infiltriert. Den Zugriff erhielt er wohl über eine seit 2017 bekannte Lücke in Oracle Weblogic.
---------------------------------------------
https://www.golem.de/news/cyberangriff-auf-ungarn-hacker-stuerzt-finanzverw…
∗∗∗ Die Doppel-Überweisung: Wie Kriminelle mit einer Masche zweifach abkassieren wollen ∗∗∗
---------------------------------------------
Mit einem Fake-Shop und einem gestohlenen Impressum werden Opfer in eine Falle gelockt, die doppelt zuschnappen soll. Nach erfolgter Bezahlung via Überweisung, erhalten Betroffene eine E-Mail, in der von „Problemen mit dem Banksystem“ die Rede ist. Man solle die alte Überweisung stornieren und den Betrag auf ein anderes Konto transferieren.
---------------------------------------------
https://www.watchlist-internet.at/news/die-doppel-ueberweisung/
∗∗∗ II: Nachtrag zum Defender-Fehlalarm: Rückmeldung von Synology und Microsoft ∗∗∗
---------------------------------------------
Der Microsoft Defender hält oder hielt Synology-Backups auf verschiedenen Servern für einen Trojaner. Dadurch laufen die Sicherungen nicht mehr durch. Zum echten Problem für Administratoren wird das Ganze, weil die Defender-Option "Zulassen" für den in Quarantäne geschobenen Prozess die ganze Erkennungsregel abschaltet.
---------------------------------------------
https://borncity.com/blog/2026/08/04/ii-nachtrag-zum-defender-fehlalarm-rue…
∗∗∗ Attackers Don’t Need Your Devices Anymore They Just Need Your Identity. ∗∗∗
---------------------------------------------
Your EDR watches every endpoint. But modern attackers have learned to move between identities instead of devices. The good news is that the telemetry for every step of this movement exists across your hunting tables. The trick is knowing which table holds which evidence and how to correlate across them.
---------------------------------------------
https://detect.fyi/attackers-dont-need-your-devices-anymore-they-just-need-…
=====================
= Vulnerabilities =
=====================
∗∗∗ Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup ∗∗∗
---------------------------------------------
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1. The file-read flaw is tracked as CVE-2026-59774, rated Critical with a CVSS score of 9.8, and received its formal advisory on August 2. Gitea 1.27.1 also patches CVE-2026-60004, a separate remote code execution bug covered in a prior THN report.
---------------------------------------------
https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.h…
∗∗∗ Sicherheitsupdates: TP-Links Netzwerk-Ökosystem Omada ist kompromittierbar ∗∗∗
---------------------------------------------
Im Zuge der Black-Hat-2026-Konferenz haben Sicherheitsforscher von Forescout Informationen zu mehreren Sicherheitslücken in Omada veröffentlicht, die konkret ZTP betreffen. Ihnen zufolge können sich Angreifer unter anderem über hartkodierte kryptografische Schlüssel (CVE-2025-15627 „mittel“) und ein hartkodiertes Zertifikat (CVE-2025-15628 „hoch“) Zugriff verschaffen, Schadcode ausführen (CVE-2025-7850 „kritisch“) und sich einen Root-Shell-Zugriff einrichten (CVE-2025-7851 „hoch“). Die Forscher führen aus, dass Angreifer Schwachstellen miteinander kombinieren können, um sich weitreichenden Netzwerkzugriff zu verschaffen.
---------------------------------------------
https://www.heise.de/news/Sicherheitsupdates-TP-Links-Netzwerk-Oekosystem-O…
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1087318/
∗∗∗ Veeam: Vulnerabilities Resolved in Veeam Service Provider Console 9.3 ∗∗∗
---------------------------------------------
https://www.veeam.com/kb4893
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 03-08-2026 18:00 − Dienstag 04-08-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Phishing-Mails der ÖGK jetzt auch im Dialekt ∗∗∗
---------------------------------------------
Manche Betrugsmaschen halten sich hartnäckig über Jahre. Dazu zählen Phishing-Mails im Namen der Österreichischen Gesundheitskasse (ÖGK). Nun setzen die Kriminellen auch auf Dialekt.
---------------------------------------------
https://www.watchlist-internet.at/news/phishing-mails-der-oegk/
∗∗∗ NuGet-Sicherheit: Microsoft verkürzt Gültigkeit von API-Keys auf 30 Tage ∗∗∗
---------------------------------------------
Eine kürzere Gültigkeit von API-Keys zur Paketveröffentlichung soll die Sicherheit von NuGet stärken. Sie betrifft sowohl bestehende als auch neue Keys.
---------------------------------------------
https://heise.de/-11396124
∗∗∗ INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws ∗∗∗
---------------------------------------------
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances.
---------------------------------------------
https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
∗∗∗ Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS ∗∗∗
---------------------------------------------
An unknown Chinese-speaking threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.
---------------------------------------------
https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html
∗∗∗ DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT ∗∗∗
---------------------------------------------
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.
---------------------------------------------
https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.h…
∗∗∗ Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect.
---------------------------------------------
https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html
∗∗∗ AI slop pollutes the CVE pipeline with fake vulns ∗∗∗
---------------------------------------------
With NIST still buried under its backlog, expect AI-generated bogus reports to continue.
---------------------------------------------
https://www.theregister.com/security/2026/08/03/ai-slop-pollutes-the-cve-pi…
∗∗∗ Wenn die IT ausfällt: Krisensimulation für Krankenhäuser ∗∗∗
---------------------------------------------
Wie Krankenhäuser bei IT-Ausfällen reagieren, testet Nico Brüggemann vom Fraunhofer SIT. Er erklärt, warum Abläufe oft nur auf dem Papier funktionieren.
---------------------------------------------
https://www.heise.de/hintergrund/Wenn-die-IT-ausfaellt-Krisensimulation-fue…
∗∗∗ Almost Half of Malware Samples Communicate Direct to IP ∗∗∗
---------------------------------------------
Malware samples often bypass DNS entirely, communicating directly to IP addresses instead. Our analysis of 4 million dynamic analysis reports indicates that almost half (45.32%) of malware samples with any command-and-control (C2) activity made at least one direct-to-IP (D2IP) address connection. Measured as a fraction of all C2 connection attempts, D2IP traffic accounts for 23.17% of the total.
---------------------------------------------
https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/
∗∗∗ EU-Cybersecurity-Pflichten für Hersteller & Betriebe – Hands-on ∗∗∗
---------------------------------------------
Auf Hersteller und Unternehmen in Europa kommen in den nächsten Wochen und Monaten (z.B. ab 11.09.2026) einige Cybersecurity-Pflichten zu, die EU-weit geregelt sind. NIS-2, Cyber Resilience Act und Maschinenverordnung. Mir hat der Betreiber einer entsprechenden Infoseite einige Informationen zukommen lassen. Ich nutze die Gelegenheit, einen kuren Überblick über die Sachlage zu geben.
---------------------------------------------
https://borncity.com/blog/2026/08/04/eu-cybersecurity-pflichten-fuer-herste…
∗∗∗ Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack ∗∗∗
---------------------------------------------
Socket’s Threat Research Team is tracking an active supply chain compromise affecting the widely used keyv and cacheable npm packages. On August 4, 2026, at least ten packages beginning with the keyv and cacheable namespaces and spreading to packages owned by other maintainers, were published with a malicious preinstall hook (setup.mjs) that downloads a standalone Bun runtime, executes an obfuscated second stage, harvests cloud and CI credentials, and republishes trojanized versions of other packages the stolen npm token can reach. The affected packages collectively account for tens of millions of weekly downloads. New packages are appearing in real time, and Socket team will keep on updating the list.
---------------------------------------------
https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-name…
=====================
= Vulnerabilities =
=====================
∗∗∗ New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root ∗∗∗
---------------------------------------------
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries.
---------------------------------------------
https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html
∗∗∗ Jetzt patchen! Angreifer attackieren N-able N-central ∗∗∗
---------------------------------------------
N-ables Endpoint-Managementlösung N-central ist verwundbar und Angreifer attackieren bereits Instanzen. Admins sollten zügig handeln.
---------------------------------------------
https://www.heise.de/news/Jetzt-patchen-Angreifer-attackieren-N-able-N-cent…
∗∗∗ Check Point: Angreifer können Security-Management-Server übernehmen ∗∗∗
---------------------------------------------
Aufgrund einer Sicherheitslücke können Angreifer die IT-Sicherheitslösung Security Management von Check Point attackieren. Hotfixes stehen zum Download.
---------------------------------------------
https://heise.de/-11398187
∗∗∗ Broadcom Fixes Multiple Critical VMware Vulnerabilities ∗∗∗
---------------------------------------------
Broadcom’s latest security advisory resolves five vulnerabilities affecting core VMware products. The most severe vulnerabilities carry a CVSS score of 9.8, allowing attackers to bypass authentication or execute arbitrary code on vulnerable systems. Because vCenter Server acts as the centralized management platform for VMware environments, successful exploitation could provide attackers with extensive control over virtual infrastructure. There are currently no confirmed reports of widespread exploitation, but the technical impact warrants immediate remediation.
---------------------------------------------
https://thecyberthrone.in/2026/08/03/broadcom-fixes-multiple-critical-vmwar…
∗∗∗ LWN Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1087068/
∗∗∗ Security Vulnerabilities fixed in Firefox for Android 153.0.3 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-73/
∗∗∗ [R1] Sensor Proxy Version 1.4.2 Fixes One Vulnerability ∗∗∗
---------------------------------------------
https://www.tenable.com/security/tns-2026-21
∗∗∗ Zyxel security advisory for path traversal vulnerability in the configuration file execution CLI command of ZLD firewalls ∗∗∗
---------------------------------------------
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-…
∗∗∗ Zyxel security advisory for command injection and improper authentication vulnerabilities in certain APs, FWA7, and Security Routers ∗∗∗
---------------------------------------------
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-…
∗∗∗ List of Security Fixes and Improvements in Veeam ONE ∗∗∗
---------------------------------------------
https://www.veeam.com/kb4858
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 31-07-2026 18:00 − Montag 03-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Arch Linux disables AUR package adoption to stop malware flood ∗∗∗
---------------------------------------------
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/arch-linux-disables-aur-pack…
∗∗∗ Inside the Underground Business of BTMOB RAT ∗∗∗
---------------------------------------------
BTMOB has been covered by several cybersecurity publications, primarily through technical analyses of the malware and its capabilities, but much less has been reported about the ecosystem that has developed around it.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/inside-the-underground-busin…
∗∗∗ ExfilSquad hackers leak info of over 100,000 UK police officers, staff ∗∗∗
---------------------------------------------
A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info…
∗∗∗ Coldcard-Wallets: Massenhafte Bitcoin-Diebstähle erschüttern die Kryptobranche ∗∗∗
---------------------------------------------
Bitcoins im Wert von mehr als 70 Millionen Euro haben zuletzt unverhofft die Besitzer gewechselt. Grund ist eine Schwachstelle in Hardware-Wallets von Coinkite.
---------------------------------------------
https://www.golem.de/news/coldcard-wallets-massenhafte-bitcoin-diebstaehle-…
∗∗∗ Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st) ∗∗∗
---------------------------------------------
Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.
---------------------------------------------
https://isc.sans.edu/diary/rss/33206
∗∗∗ N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete ∗∗∗
---------------------------------------------
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.
---------------------------------------------
https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html
∗∗∗ The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier ∗∗∗
---------------------------------------------
Both major AI labs’ models broke containment, escaped onto the internet, and hacked other companies. If a human had done that, the law would likely be against them. But a bot?
---------------------------------------------
https://www.wired.com/story/openai-anthropic-ai-hacking-sprees-illegal/
∗∗∗ The Risk of Fine-Tuned Open-Weight Models ∗∗∗
---------------------------------------------
In the last weeks I was wondering how to continue offensive security and malware development over the next months or even years with the help of AI.
---------------------------------------------
https://www.msecops.de/blog/posts/backdoored-llms/
∗∗∗ Auswärtiges Amt warnt vor IT-Fachkräften aus Nordkorea ∗∗∗
---------------------------------------------
IT-Fachkräfte aus Nordkorea unterwandern zunehmend westliche Unternehmen. Jetzt gibt es eine internationale Warnung davor.
---------------------------------------------
https://www.heise.de/news/Auswaertiges-Amt-warnt-vor-IT-Fachkraeften-aus-No…
∗∗∗ Cyberangriff auf Liechtenstein – 31.000 Datensätze betroffen ∗∗∗
---------------------------------------------
Die Regierung Liechtensteins meldet einen Angriff auf ein Personenverzeichnis. Was steckt hinter dem Zugriff auf 31.000 Datensätze?
---------------------------------------------
https://www.heise.de/news/Cyberangriff-auf-Liechtenstein-31-000-Datensaetze…
∗∗∗ Apple: Limit für Bug-Meldungen pro Person ∗∗∗
---------------------------------------------
Apple reagiert auf die Flut von KI-generierten Sicherheitsmeldungen und begrenzt die Einreichungen pro Person.
---------------------------------------------
https://www.heise.de/news/Apple-Limit-fuer-Bug-Meldungen-pro-Person-1139537…
∗∗∗ Traumjob von zuhause? Achtung Geldwäschefalle! ∗∗∗
---------------------------------------------
Kriminelle geben sich als Personaler:innen aus, um ahnungslose Menschen für Geldwäsche zu missbrauchen. Die Opfer wissen dabei oft von nichts. Wir zeigen, wie Sie den Betrug erkennen.
---------------------------------------------
https://www.watchlist-internet.at/news/traumjob-von-zuhause-geldwaesche/
∗∗∗ Pass the Passkey: A Novel Attack Surface in Passwordless Authentication ∗∗∗
---------------------------------------------
This article analyzes new attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The attacks demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts. We show how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.
---------------------------------------------
https://unit42.paloaltonetworks.com/passwordless-authentication-security-ri…
∗∗∗ The Hidden CCS2 Attack Surface on EV Chargers ∗∗∗
---------------------------------------------
An EV charger's charging port is a network port. We found SSH and Telnet services exposed on XCharge C6 chargers with default root:root credentials. A threat actor with a malicious EV can gain immediate full control access on the charger and perform energy theft or potentially cause physical damage.
---------------------------------------------
https://www.saiflow.com/blog/the-hidden-ccs2-attack-surface-on-ev-chargers
∗∗∗ Guide to Bypassing Hotel Wi-Fi Captive Portals (With Permission) ∗∗∗
---------------------------------------------
Have you ever been curious about how easy it is to bypass that pesky captive portal? This article guides you through 3 different methods.
---------------------------------------------
https://projectblack.io/blog/bypassing-hotel-wi-fi-captive-portals/
=====================
= Vulnerabilities =
=====================
∗∗∗ Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable ∗∗∗
---------------------------------------------
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them.
---------------------------------------------
https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html
∗∗∗ Adobe Campaign Classic Schwachstelle CVE-2026-48449 (CVSS 3.x 10.0) gepatcht ∗∗∗
---------------------------------------------
Adobe musste die Tage die Schwachstelle CVE-2026-48449 in seinem Produkt Adobe Campaign Classic patchen. Es handelt sich um eine Authorisierungsschwachstelle, die das umgehen einer Anmeldung ermöglicht. Die Schwachstelle wurde mit einem CVSS 3.x von 10.0, also dem höchstmöglichen Wert, als kritisch eingestuft.
---------------------------------------------
https://borncity.com/blog/2026/08/03/adobe-campaign-classic-schwachstelle-c…
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1086897/
∗∗∗ Synology-SA-26:12 Synology Assistant ∗∗∗
---------------------------------------------
https://www.synology.com/en-global/support/security/Synology_SA_26_12
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/