=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 20-08-2026 18:00 − Freitag 21-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Hundreds of leaked AWS keys give full control over corporate accounts ∗∗∗
---------------------------------------------
More than 9,300 Amazon Web Services (AWS) access keys publicly exposed between August 2022 and August 2026 are still active and valid. ---------------------------------------------
https://www.bleepingcomputer.com/news/security/hundreds-of-leaked-aws-keys-…
∗∗∗ Slowakei: Russische Backdoor in Verkehrskameras entdeckt ∗∗∗
---------------------------------------------
Die Slowakei wollte im Rahmen eines Sanierungspakets 279 neue Verkehrskameras beschaffen. Erste Geräte kamen unerwartet aus Russland - inklusive Backdoor.
---------------------------------------------
https://www.golem.de/news/slowakei-russische-backdoor-in-verkehrskameras-en…
∗∗∗ N-able Passportal: Zahlreiche Unternehmen durch kritisches Passwort-Leck gefährdet ∗∗∗
---------------------------------------------
Ein Forscher hat bei N-able Passportal eine kritische Lücke entdeckt. Angreifer hätten damit leicht Zugangsdaten aus Passwort-Tresoren abgreifen können.
---------------------------------------------
https://www.golem.de/news/n-able-passportal-jede-website-konnte-passwort-tr…
∗∗∗ GitLab CVE-2026-19478 Comes Under Active Exploitation Within Days of Disclosure ∗∗∗
---------------------------------------------
A newly disclosed security flaw in GitLab has come under active exploitation within days of public disclosure, according to watchTowr.The vulnerability in question is CVE-2026-19478 (CVSS score: 9.4), a case of code injection that allows an unauthenticated ..
---------------------------------------------
https://thehackernews.com/2026/08/gitlab-cve-2026-19478-comes-under.html
∗∗∗ Researcher tricks Apple’s Find My into sharing location data with Linux ∗∗∗
---------------------------------------------
Clever protocol wrangling gets iBiz-only people tracking working on a non-iGadget
---------------------------------------------
https://www.theregister.com/security/2026/08/20/researcher-tricks-apples-fi…
∗∗∗ Cisco bug severity warning reads like Olympic gymnastics scores: 10, 10, 9.9, 9.6, and 7.5. ∗∗∗
---------------------------------------------
Secure Workload Software has five nasty flaws and even SaaS users have updates to install
---------------------------------------------
https://www.theregister.com/security/2026/08/21/cisco-bug-severity-warning-…
∗∗∗ ClaudeFix: Shared Claude Chats Meet ClickFix ∗∗∗
---------------------------------------------
ClickFix is a widely employed attack technique, first seen in 2024, where a victim is instructed to paste-and-run instructions on their system to “fix” a problem or install software. The seemingly benign instructions are, in fact, malicious and lead to the deployment of malware onto the victim’s system. Zscaler Threat Hunting has analyzed ..
---------------------------------------------
https://www.zscaler.com/blogs/security-research/claudefix-shared-claude-cha…
∗∗∗ Zimbra: Warnung vor Angriffen auf Befehlsschmuggel-Lücke ∗∗∗
---------------------------------------------
Das polnische CERT warnt vor Angriffen auf eine Befehlsschmuggel-Lücke in der Zimbra Collaboration Suite. Ein Update ist verfügbar.
---------------------------------------------
https://www.heise.de/news/Zimbra-Warnung-vor-Angriffen-auf-Befehlsschmuggel…
∗∗∗ Atlassian schließt mehr als 160 Sicherheitslücken in Confluence & Co. ∗∗∗
---------------------------------------------
Angreifer können unter anderem an kritischen Schadcode-Schwachstellen in Softwareprodukten von Atlassian ansetzen.
---------------------------------------------
https://www.heise.de/news/Atlassian-schliesst-mehr-als-160-Sicherheitslueck…
∗∗∗ Dell ObjectScale: Höhere Nutzerrechte erschleichbar ∗∗∗
---------------------------------------------
Sicherheitsupdates schließen mehrere Lücken in Dells Object-Storage-Plattform ObjectScale.
---------------------------------------------
https://www.heise.de/news/Dell-ObjectScale-Hoehere-Nutzerrechte-erschleichb…
∗∗∗ Lücke in WordPress-Plug-in Elementor Pro: 6 Millionen Webseiten gefährdet ∗∗∗
---------------------------------------------
Eine kritische Sicherheitslücke im WordPress-Plug-in Elementor Pro ermöglicht die komplette Übernahme von WordPress.
---------------------------------------------
https://www.heise.de/news/Luecke-in-WordPress-Plug-in-Elementor-Pro-6-Milli…
∗∗∗ Cyberangriff in Berlin: Behörden weiterhin offline ∗∗∗
---------------------------------------------
Zwei Senatsverwaltungen sind nach einem Cyberangriff vom Landesnetz isoliert. Das hat auch Auswirkungen auf die Auszahlung von Wohngeld.
---------------------------------------------
https://heise.de/-11421320
∗∗∗ Defeating AI-Assisted Reverse Engineering (or at Least Trying To) ∗∗∗
---------------------------------------------
At the beginning of 2026, a customer told us something along the lines of: obfuscation is finished, LLM-assisted reverse engineering breaks it. They had a walkthrough to back it up, produced by their own tooling, in which a model took one of their obfuscated libraries apart and recovered its hidden strings.They were not right, but not entirely wrong either.So we spent a ..
---------------------------------------------
http://blog.quarkslab.com/defeating-ai-assisted-reverse-engineering-or-at-l…
∗∗∗ I accidentally logged hundreds of thousands of phone calls to military bases ∗∗∗
---------------------------------------------
How an expired nameserver let me take over e164.arpa zones for multiple territories, and why I probably should have checked my logs sooner.
---------------------------------------------
https://lina.sh/blog/hijacking-e164-arpa
∗∗∗ Rust Supply Chain Attack on arrayref: Significant Overlap with DPRK Campaigns ∗∗∗
---------------------------------------------
Malicious versions of the arrayref Rust crate (and others) executed a backdoor at compile time. The campaigns infrastructure overlaps with recent DPRK supply chain attacks, including Mastra and axios.
---------------------------------------------
https://www.wiz.io/blog/rust-supply-chain-attack-on-arrayref-significant-ov…
∗∗∗ If Apple says your iPhone was targeted by mercenary spyware, treat it like an incident ∗∗∗
---------------------------------------------
Apples Threat Notifications signal mercenary spyware targeting; learn verification steps, response actions, and layered mobile security defenses for high-risk users.
---------------------------------------------
https://www.jamf.com/blog/apple-threat-notification-mercenary-spyware-respo…
=====================
= Vulnerabilities =
=====================
∗∗∗ [20260803] - Core - Inconsistent ACL checks for mutating webservice endpoints ∗∗∗
---------------------------------------------
https://developer.joomla.org/security-centre/1070-20260803-core-inconsisten…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 19-08-2026 18:00 − Donnerstag 20-08-2026 18:00
Handler: Guenes Holler
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Grok exfiltrates user data when malicious instructions are encrypted ∗∗∗
---------------------------------------------
Cryptographic Context Injection is only the latest way to break an LLM safety guardrail.
---------------------------------------------
https://arstechnica.com/security/2026/08/grok-exfiltrates-user-data-when-ma…
∗∗∗ US warns of AI-powered attacks on Siemens PLCs in critical infrastructure ∗∗∗
---------------------------------------------
U.S. cybersecurity agencies warn that threat actors are using AI-generated scripts to exploit Siemens S7 Series programmable logic controllers (PLCs) in U.S. critical infrastructure.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/us-warns-of-ai-powered-attac…
∗∗∗ Rogue ransomware affiliate poses as data recovery firm to steal payments ∗∗∗
---------------------------------------------
A suspected ransomware affiliate is posing as a ransomware recovery service called "Ransom Busters," contacting the victims before the attacks become public and claiming to be able to provide decryption keys and delete stolen data for a fee.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/rogue-ransomware-affiliate-r…
∗∗∗ New Manic Android malware can exfiltrate data through nearby devices ∗∗∗
---------------------------------------------
A new Android malware named Manic targeting users in multiple European countries has a fallback data exfiltration mechanism that uses nearby infected devices.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-manic-android-malware-ca…
∗∗∗ Critical Elementor Pro bug exposes WordPress sites to RCE attacks ∗∗∗
---------------------------------------------
A critical vulnerability in the Elementor Pro WordPress plugin could allow attackers to upload executable files for remote code execution on the server.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/critical-elementor-pro-bug-e…
∗∗∗ Kritische Sicherheitslücke: Hacker attackieren Gitlab-Instanzen ∗∗∗
---------------------------------------------
Angreifer können durch eine Sicherheitslücke auf Gitlab-Instanzen verheerende Schäden anrichten. Forscher warnen bereits vor laufenden Angriffen.
---------------------------------------------
https://www.golem.de/news/kritische-sicherheitsluecke-hacker-attackieren-gi…
∗∗∗ Cloudflare Workers Spectre Attack Leaks JWT From Co-Located Worker at 12 Bits/Second ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of a remote Spectre attack against Cloudflare Workers that leaked a JSON Web Token (JWT) from a co-located Worker in the production environment at up to 12 bits per second, 360 times the rate of an earlier attack demonstrated in 2021.The end-to-end experiment used an attacker Worker and a victim Worker controlled ..
---------------------------------------------
https://thehackernews.com/2026/08/cloudflare-workers-spectre-attack-leaks.h…
∗∗∗ 40 Malicious Firefox Extensions Pose as Web3 Products to Steal Wallet Secrets ∗∗∗
---------------------------------------------
A set of 40 Mozilla Firefox extensions has been found to engage in cryptocurrency wallet theft by masquerading as OKX, Rabby Wallet, TronLink, and other Web3 products.According to the Socket Threat Research team, the extensions are part of a ..
---------------------------------------------
https://thehackernews.com/2026/08/40-malicious-firefox-extensions-pose-as.h…
∗∗∗ CDN Tsunami Attack Abuses HTTP/3 Translation for Up to 350x DoS Amplification ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed two denial-of-service (DoS) attacks that exploit how major content delivery networks (CDNs) convert client-facing HTTP/3 traffic into HTTP/1.1 requests to the websites they front, amplifying a ..
---------------------------------------------
https://thehackernews.com/2026/08/cdn-tsunami-attack-abuses-http3.html
∗∗∗ Attackers Exploit Zimbra SNMP Flaw for Unauthenticated Remote Code Execution ∗∗∗
---------------------------------------------
A now-patched security flaw impacting Zimbra Collaboration (ZCS) has come under active exploitation in the wild, according to the Polish Computer Emergency Response Team (CERT Polska).The vulnerability in question is ..
---------------------------------------------
https://thehackernews.com/2026/08/attackers-exploit-zimbra-snmp-flaw-for.ht…
∗∗∗ Microsoft untersucht Spieleprobleme nach August-Patchday ∗∗∗
---------------------------------------------
Nach der Installation der Windows-Updates vom August-Patchday erhält Microsoft vermehrt Meldungen zu Problemen mit einigen Spielen.
---------------------------------------------
https://www.heise.de/news/Microsoft-untersucht-Spieleprobleme-nach-August-P…
∗∗∗ Citrix stopft kritische Anmeldungsumgehung in Netscaler ADC und Gateway ∗∗∗
---------------------------------------------
In Netscaler ADC und Gateway von Citrix können Angreifer mehrere Lücken missbrauchen. Sie können etwa unbefugt Zugriff erlangen.
---------------------------------------------
https://www.heise.de/news/Citrix-stopft-kritische-Anmeldungsumgehung-in-Net…
∗∗∗ Sicherheitslücke in Microsoft 365 Copilot: KI verrät eigene Schutzmechanismen ∗∗∗
---------------------------------------------
Sicherheitsforscher haben Microsofts KI-Assistenten dazu gebracht, seine eigenen Schutzmechanismen offenzulegen.
---------------------------------------------
https://www.heise.de/news/Sicherheitsluecke-in-Microsoft-365-Copilot-KI-ver…
∗∗∗ GivEnergy enters administration, batteries expose home networks ∗∗∗
---------------------------------------------
In late 2024, we found multiple vulnerabilities in GivEnergy home battery systems that could allow attackers to access customers’ home networks, disrupt battery operation, and potentially violate UK product security regulations. While GivEnergy updated installer guidance for newer deployments, older installations may still be exposed, with no clear remediation plan communicated to customers. Even before the latest news, this was ..
---------------------------------------------
https://www.pentestpartners.com/security-blog/givenergy-enters-administrati…
∗∗∗ A1-Phishing: Gefälschte E-Mails im Umlauf ∗∗∗
---------------------------------------------
Mit rund 7 Millionen Kund ist A1 einer der größten Anbieter für Handy, Festnetz und Internet in Österreich. Diese Bekanntheit nutzen Kriminelle aktuell aus und verschicken täuschend echte Phishing-Mails im Namen von A1. Das Ziel: Persönliche Daten und Kontoinformationen.
---------------------------------------------
https://www.watchlist-internet.at/news/a1-phishing-gefaelschte-e-mails-im-u…
∗∗∗ UAT-10147: Chinese-speaking adversary integrates agentic AI into post-compromise operations ∗∗∗
---------------------------------------------
Cisco Talos discovered a Chinese-speaking cybercrime group, tracked as UAT-10147, that targets a wide range of vulnerable web servers. This is an overview of the campaign, examining the countries affected, potential impact of BadIIS infections, the attack chain, and post-compromise tactics.
---------------------------------------------
https://blog.talosintelligence.com/uat-10147-chinese-speaking-adversary-int…
∗∗∗ Gefälschte Seite, falsche Software – trotz korrekt aussehender Links ∗∗∗
---------------------------------------------
Eine Kampagne mit gefälschten Webseiten zeigt korrekt erscheinende Links an, schiebt Opfern jedoch unerwünschte Software unter.
---------------------------------------------
https://heise.de/-11420547
∗∗∗ Supply chain attack on arrayref ∗∗∗
---------------------------------------------
On 2026-08-20 at 7:15 UTC we got a report that the proc-macro1 crate was malicious.
---------------------------------------------
https://blog.rust-lang.org/2026/08/20/supply-chain-attack-on-arrayref/
=====================
= Vulnerabilities =
=====================
∗∗∗ Link content parser - Critical - Unsupported - SA-CONTRIB-2026-101 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-101
∗∗∗ Gammu SMS Daemon - Critical - Unsupported - SA-CONTRIB-2026-100 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-100
∗∗∗ Cisco Advance Notification for Publication of August 19, 2026, Security Advisories ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 18-08-2026 18:00 − Mittwoch 19-08-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Slowakei: Russische Backdoor in Verkehrskameras entdeckt ∗∗∗
---------------------------------------------
Die Slowakei hat im Rahmen eines Sanierungspakets 279 neue
Verkehrskameras gekauft. Die Geräte kamen unerwartet aus Russland -
inklusive Backdoor.
---------------------------------------------
https://www.golem.de/news
/slowakei-russische-backdoor-in-verkehrskameras-entdeckt-2608-212088
.html
∗∗∗ Phishing-Welle im Namen des Finanzministeriums nutzt
Familienbeihilfe als Köder ∗∗∗
---------------------------------------------
Datenmissbrauch, unrechtmäßige Umleitungen und ausbleibende
Auszahlungen der Familienbeihilfe – mit diesem Bedrohungsbild gehen
Kriminelle momentan auf Beutezug. Sie geben sich in einer E-Mail als
Finanzministerium aus und wollen so an die Onlinebanking-Logindaten
ihrer Opfer gelangen.
---------------------------------------------
https://www.watchlist-internet.at/news
/phishing-finanzministeriums-familienbeihilfe/
∗∗∗ Warnung vor Angriffen auf Microsoft IKE, SharePoint, VMware vCenter
und macOS ∗∗∗
---------------------------------------------
Die IT-Sicherheitsbehörde CISA warnt aktuell vor Angriffen auf
Microsoft IKE, SharePoint, VMware vCenter und macOS.
---------------------------------------------
https://heise.de/-11418783
∗∗∗ CISA: Medusa ransomware hit over 500 critical infrastructure orgs
∗∗∗
---------------------------------------------
The Cybersecurity and Infrastructure Security Agency (CISA) said
Tuesday that the Medusa ransomware gang has breached more than 500
critical infrastructure organizations in the United States since June
2021.
---------------------------------------------
https://www.bleepingcomputer.com/news/security
/cisa-medusa-ransomware-hit-over-500-critical-infrastructure-orgs/
∗∗∗ Password spraying attacks surge 155x as hackers exploit MFA gaps
∗∗∗
---------------------------------------------
Huntress has observed a 155x increase in password spraying attacks in
the first half of 2026. Brute force is old news, but the spin driving
that spike is new.
---------------------------------------------
https://www.bleepingcomputer.com/news/security
/password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps/
∗∗∗ Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and
Secrets ∗∗∗
---------------------------------------------
Two critical vulnerabilities impacting MLflow, an open-source
artificial intelligence (AI) platform, and FUXA, an open-source,
web-based SCADA / HMI software built for operational technology (OT)
and industrial automation, are witnessing malicious scanning and
exploitation efforts.
---------------------------------------------
https://thehackernews.com/2026/08
/attackers-exploit-mlflow-ssrf-flaw-to.html
∗∗∗ Microsoft Links 30+ Rotating Domains to MacSync Stealer
Infrastructure ∗∗∗
---------------------------------------------
Microsoft Defender Experts have linked more than 30 web domains to
MacSync Stealer, a macOS-focused information stealer, after correlating
recurring endpoint and network behaviors across changing
infrastructure, tracing the malware from payload retrieval through data
collection, staging, and exfiltration.
---------------------------------------------
https://thehackernews.com/2026/08
/microsoft-links-30-rotating-domains-to.html
∗∗∗ Clop-Linked Windchill Web Shell Decrypts Credentials and Maps
Engineering Data ∗∗∗
---------------------------------------------
A JavaServer Pages (JSP) web shell deployed following the exploitation
of a critical security flaw in PTC Windchill and FlexPLM servers is
specifically designed for the enterprise Product Lifecycle Management
(PLM) software, according to new findings from ReliaQuest.
---------------------------------------------
https://thehackernews.com/2026/08/clop-linked-windchill-web-shell.html
∗∗∗ Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks,
Auth Bypasses, and P2P ∗∗∗
---------------------------------------------
Cybersecurity researchers at Hunt.io have disclosed details of a
campaign that they say compromised more than 14,530 Dahua devices
between June 17 and July 22, 2026, using credential attacks, two
authentication-bypass flaws, and a peer-to-peer (P2P) relay technique.
---------------------------------------------
https://thehackernews.com/2026/08
/hackers-compromised-14500-dahua-devices.html
=====================
= Vulnerabilities =
=====================
∗∗∗ Oracle-Patchday: Updates für weniger als tausend Schwachstellen ∗∗∗
---------------------------------------------
Oracle fixt zum „Critical Security Patch Update“ knapp 1000 Lücken –
weniger als zum letzten regulären „CPU“ genannten Patchday.
---------------------------------------------
https://heise.de/-11418883
∗∗∗ LWN Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1089501/
∗∗∗ Security Vulnerabilities fixed in Thunderbird 153.1 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-80/
∗∗∗ Security Vulnerabilities fixed in Thunderbird 140.14 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/
∗∗∗ Security Vulnerabilities fixed in Thunderbird 154 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-78/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 17-08-2026 18:00 − Dienstag 18-08-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Hacker claims 3.6 million Azure account records stolen from major companies ∗∗∗
---------------------------------------------
A threat actor is selling employee databases allegedly stolen from the Microsoft Azure infrastructure of multiple Fortune 500 companies after gaining access using compromised credentials.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hacker-claims-36-million-azu…
∗∗∗ Whatsapp, Signal und Threema: Angreifer können Gruppenchats unbemerkt manipulieren ∗∗∗
---------------------------------------------
Bei Whatsapp, Signal, iMessage und Threema kann ein Gruppenmitglied anderen Teilnehmern unterschiedliche Inhalte zeigen. Die Verschlüsselung muss dafür nicht gebrochen werden.
---------------------------------------------
https://www.golem.de/news/whatsapp-signal-und-threema-angreifer-koennen-gru…
∗∗∗ 16 Typosquatted RubyGems Packages Steal Browser Credentials and Crypto Wallets ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a new typosquatting campaign targeting RubyGems users with a Windows-based information stealer.
---------------------------------------------
https://thehackernews.com/2026/08/16-typosquatted-rubygems-packages-steal.h…
∗∗∗ TWINLOOT Abuses SharePoint and Teams to Steal Credentials and Move Across Networks ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of a previously undocumented Python implant framework dubbed TWINLOOT.
---------------------------------------------
https://thehackernews.com/2026/08/twinloot-abuses-sharepoint-and-teams-to.h…
∗∗∗ CISA gives feds 3 days to fix actively exploited Ray RCE bug ∗∗∗
---------------------------------------------
Phishing, malvertising attacks could target devs to gain access to private corporate networks.
---------------------------------------------
https://www.theregister.com/security/2026/08/18/cisa-gives-feds-3-days-to-f…
∗∗∗ „Sie haben eine neue Nachricht“: Phishing-Falle im Namen der easybank ∗∗∗
---------------------------------------------
Über eine angeblich notwendige „Vervollständigung der Kontodaten“ wollen Kriminelle an die Onlinebanking-Logininformationen ihrer Opfer gelangen. Sie geben sich dabei als Vertreter der „easybank“ aus und setzen auf eine Phishing-Falle, die typischer nicht sein könnte.
---------------------------------------------
https://www.watchlist-internet.at/news/phishing-falle-easybank/
∗∗∗ Microsoft starts removing WMIC tool used by cybercriminals ∗∗∗
---------------------------------------------
Microsoft announced that it removed the Windows Management Instrumentation Command-line (WMIC) tool from Windows 11 24H2 and 25H2, as well as from Windows 11 beta builds released this week.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-removes-wmic-lolb…
∗∗∗ Mobile Klimaanlage: Midea PortaSplit lässt sich von jedermann fernsteuern ∗∗∗
---------------------------------------------
Per Bluetooth können Nachbarn die mobile Klimaanlage fernbedienen oder abschalten, Midea sieht keine Sicherheitslücke darin.
---------------------------------------------
https://heise.de/-11417163
=====================
= Vulnerabilities =
=====================
∗∗∗ Keine Anmeldung nötig: Gitlab-Lücke lässt Angreifer Softwareprojekte löschen ∗∗∗
---------------------------------------------
Aufgrund einer kritischen Sicherheitslücke können Angreifer ohne Anmeldung Gitlab-Projekte manipulieren oder löschen. Admins sollten zügig handeln.
---------------------------------------------
https://www.golem.de/news/keine-anmeldung-noetig-gitlab-luecke-laesst-angre…
∗∗∗ Webmailer Roundcube: Updates stopfen zahlreiche Sicherheitslecks ∗∗∗
---------------------------------------------
Das Webmail-System Roundcube hat mit aktualisierter Software mehrere Sicherheitslücken geschlossen. Die teils hochriskanten Schwachstellen ermöglichen Angreifern etwa das Einschmuggeln von Schadcode. Die Updates stehen bereits seit rund zwei Wochen bereit, nun wurden die Schwachstelleneinträge der darin geschlossenen Lecks nachgeschoben.
---------------------------------------------
https://www.heise.de/news/Webmailer-Roundcube-Updates-stopfen-zahlreiche-Si…
∗∗∗ Redis: Sicherheitsupdates gegen Schadcode-Lücken ∗∗∗
---------------------------------------------
In der In-Memory-Datenbank Redis wurden mehrere Schwachstellen ausgemacht, die etwa Einschleusen von Schadcode erlauben. Es hagelt Updates.
---------------------------------------------
https://www.heise.de/news/Redis-Sicherheitsupdates-gegen-Schadcode-Luecken-…
∗∗∗ WordPress-Plug-in Forminator Forms: Kritische Lücke erlaubt Codeschmuggel ∗∗∗
---------------------------------------------
Das WordPress-Plug-in Forminator Forms enthält eine kritische Schadcode-Lücke. Zudem sind Royal Elementor Addons löchrig.
---------------------------------------------
https://heise.de/-11416793
∗∗∗ Weitere Sicherheitsupdates: iOS 26.6.1, macOS 26.6.2 und mehr veröffentlicht ∗∗∗
---------------------------------------------
Kleine Aktualisierung, viele Lücken: Gut 30 Sicherheitslöcher hat Apple in insgesamt sechs Betriebssystemen gestopft. KI dürfte geholfen haben.
---------------------------------------------
https://heise.de/-11416727
∗∗∗ LWN Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1089338/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 14-08-2026 18:00 − Montag 17-08-2026 18:00
Handler: Guenes Holler
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Cyberangriff auf die Arbeiterkammer Oberösterreich ∗∗∗
---------------------------------------------
Die Angreifer erlangten Zugriff auf Daten der Landes-Kammer.
---------------------------------------------
https://www.derstandard.at/story/3000000335811/cyberangriff-auf-die-arbeite…
∗∗∗ Schadcode im Anmarsch: SAP-Systeme werden über kritische Lücke attackiert ∗∗∗
---------------------------------------------
Angreifer können SAP-Commerce-Cloud-Instanzen über eine kritische Sicherheitslücke kompromittieren. Entsprechende Attacken laufen bereits.
---------------------------------------------
https://www.golem.de/news/schadcode-im-anmarsch-sap-systeme-werden-ueber-kr…
∗∗∗ Cyberattacke auf Berliner Verwaltung, Ermittlungen laufen ∗∗∗
---------------------------------------------
Die Senatskanzlei berichtet von einem Angriff auf Teile der Verwaltung in der Hauptstadt. Ein Krisenstab ist eingerichtet. Viele Fragen sind offen.
---------------------------------------------
https://heise.de/-11416539
∗∗∗ Microsoft confirms GitHub is down worldwide ∗∗∗
---------------------------------------------
GitHub is down for some users as a widespread outage is causing errors across the website, API, Actions, Pull Requests, and several other services.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-confirms-github-i…
∗∗∗ Windows-Ablaufdaten: Microsoft-Erinnerung an Server 2022 und Windows 11 24H2 ∗∗∗
---------------------------------------------
In 60 Tagen endet der (Mainstream-)Support für Windows Server 2022, Windows 11 24H2 und Windows 10 LTSB 2016, mahnt Microsoft.
---------------------------------------------
https://www.heise.de/news/Windows-Ablaufdaten-Microsoft-Erinnerung-an-Serve…
∗∗∗ PBS station fears losing 50TB of data after being ghosted by cloud storage provider ∗∗∗
---------------------------------------------
“We don’t have access to the data on the hardware/servers,” Iron Mountain told Ars.
---------------------------------------------
https://arstechnica.com/information-technology/2026/08/pbs-station-fears-lo…
∗∗∗ SafePal data breach impacts 39,798 customers, stolen info for sale ∗∗∗
---------------------------------------------
Cryptocurrency hardware wallet provider SafePal is warning of a data breach affecting about 39,798 customers after a flaw was exploited to steal customer order information, and a threat actor is now claiming to be selling the stolen data.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/safepal-data-breach-impacts-…
∗∗∗ Microsoft working on Defender patch for ShieldBreak zero-day ∗∗∗
---------------------------------------------
On Friday, Microsoft confirmed it has begun working on a security patch for a Defender zero-day vulnerability named "ShieldBreak."
---------------------------------------------
https://www.bleepingcomputer.com/news/security/microsoft-working-on-defende…
∗∗∗ Philips and GE investigating Clop ransomware data theft claims ∗∗∗
---------------------------------------------
Tech giants General Electric (GE) and Philips have also confirmed they're investigating claims that the Clop ransomware gang breached their systems and stole data.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/philips-and-ge-investigating…
∗∗∗ Certighost and the Privilege Hiding in Your Certificate Authority ∗∗∗
---------------------------------------------
Every mature Active Directory environment has a component that quietly holds more power than the people running it usually admit: the Certification Authority (CA). The thing your entire estate has agreed to believe.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/certighost-and-the-privilege…
∗∗∗ Sicherheit: KIT-Forscher identifizieren Personen via WLAN ∗∗∗
---------------------------------------------
Ein Forschungsteam des KIT nutzt unverschlüsselte WLAN-Signale zur Personenerkennung. Ein handelsüblicher Router reicht dafür aus.
---------------------------------------------
https://www.golem.de/news/sicherheit-kit-forscher-identifizieren-personen-v…
∗∗∗ Evooo1Bot Linux Botnet Exploits Known Flaws to Turn Edge Devices Into SOCKS5 Proxies ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a previously undocumented Linux botnet family dubbed Evooo1Bot that derives its core functionality from the Mirai botnet source code and is equipped to turn internet-facing devices into SOCKS proxies.
---------------------------------------------
https://thehackernews.com/2026/08/evooo1bot-linux-botnet-exploits-known.html
∗∗∗ Unisoc VoLTE Video Call Exploit Chain Can Give Attackers Full Android Kernel Access ∗∗∗
---------------------------------------------
Security researchers at SSD Secure Disclosure have published a two-stage exploit chain that achieves full Android kernel access on devices running Unisoc modem firmware through a VoLTE video call, with no fix from the chipset maker.
---------------------------------------------
https://thehackernews.com/2026/08/unisoc-volte-video-call-exploit-chain.html
∗∗∗ Microsoft blames AI for delayed Exchange update, can’t say when it will arrive ∗∗∗
---------------------------------------------
Dealing with machine-made bug backlog makes it hard to find a moment to deliver promised subscription service.
---------------------------------------------
https://www.theregister.com/software/2026/08/17/microsoft-blames-ai-for-del…
∗∗∗ Lücke in Online-Banking: BKA deckt Millionenschäden auf ∗∗∗
---------------------------------------------
Eine Gruppe Krimineller soll Bankkunden um Millionen betrogen haben. Ermittler aus Deutschland und Brasilien nahmen nach Durchsuchungen Verdächtige fest.
---------------------------------------------
https://www.heise.de/news/Luecke-in-Online-Banking-BKA-deckt-Millionenschae…
∗∗∗ Frankreich untersucht Diebstahl von Steuerdaten von 678.000 Betroffenen ∗∗∗
---------------------------------------------
Französische Staatsanwälte untersuchen einen „beispiellosen“ Cyberangriff, bei dem Steuerdaten von 678.000 Nutzern entwendet wurden.
---------------------------------------------
https://www.heise.de/news/Frankreich-untersucht-Diebstahl-von-Steuerdaten-v…
∗∗∗ Dubiose Werbung und Abofallen bei Shops für Nahrungsergänzungsmittel ∗∗∗
---------------------------------------------
Große Gesundheitsversprechen und günstige Angebote machen Nahrungsergänzungsmittel im Internet attraktiv. Doch hinter solchen Angeboten können fragwürdige Versprechen und undurchsichtige Abo-Modelle stecken. Der Fall alimora.shop zeigt, wo Kund:innen besonders genau hinsehen sollten.
---------------------------------------------
https://www.watchlist-internet.at/news/nahrungsergaenzungsmittel-online-kau…
∗∗∗ „Download more RAM“: Windows-Sicherheit durch RAM-EEPROM geknackt ∗∗∗
---------------------------------------------
IT-Forscher zeigen Angriff „Download more RAM“ auf Windows-Sicherheitsmechanismen, der auf Manipulation des RAM-EEPROMs basiert.
---------------------------------------------
https://www.heise.de/news/Download-more-RAM-Windows-Sicherheit-durch-RAM-EE…
=====================
= Vulnerabilities =
=====================
∗∗∗ Schadcode-Sicherheitslücken bedrohen PostgreSQL ∗∗∗
---------------------------------------------
In aktuellen Versionen haben die PostgreSQL-Entwickler mehrere Sicherheitslücken geschlossen. Für einen Versionsstrang läuft bald der Support aus.
---------------------------------------------
https://www.heise.de/news/Schadcode-Sicherheitsluecken-bedrohen-PostgreSQL-…
∗∗∗ Zahlreiche Crash-Lücken in Wireshark geschlossen ∗∗∗
---------------------------------------------
In der aktuellen Wireshark-Version haben sich die Entwickler um mehrere Sicherheitslücken gekümmert.
---------------------------------------------
https://heise.de/-11415516
∗∗∗ App-Baukasten AppYourself: Update stopft Sicherheitslücke ∗∗∗
---------------------------------------------
Mit AppYourself können auch Nicht-Programmierer Business-Apps erstellen. Ein Update schließt eine Sicherheitslücke in der Software.
---------------------------------------------
https://heise.de/-11416102
∗∗∗ Cisco Advance Notification for Publication of August 19, 2026, Security Advisories ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1089205/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 13-08-2026 18:00 − Freitag 14-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ Microsoft patches LegacyHive Windows zero-day vulnerability ∗∗∗
---------------------------------------------
Microsoft has released security patches to address a Windows zero-day vulnerability known as "LegacyHive," disclosed after the July 2026 Patch Tuesday.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-legacyhiv…
∗∗∗ Akira hackers disable EDR with Safe Mode, steal data but fail to encrypt ∗∗∗
---------------------------------------------
An Akira ransomware affiliate disabled the endpoint detection and response (EDR) solution on a compromised system by restarting the machine into Safe Mode with Networking.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/akira-hackers-disable-edr-wi…
∗∗∗ Ukraine shuts down 94 fraudulent call centers, seize millions in cash ∗∗∗
---------------------------------------------
Authorities in Ukraine shut down 94 fraudulent call centers across the country that lured people into investment scams or tried to obtain access to bank accounts.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/ukraine-shuts-down-94-fraudu…
∗∗∗ Shell investigates potential incident after Clop data theft claims ∗∗∗
---------------------------------------------
Oil giant Shell has confirmed it is investigating a potential security incident after the Clop ransomware gang claimed it stole 89GB of data.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/shell-investigates-potential…
∗∗∗ Security: Der Phish stinkt vom Kopf her ∗∗∗
---------------------------------------------
Anti-Phishing-Kampagnen sollen die IT-Laien in einer Firma fit gegen Angriffe machen. Das ist aber komplett der falsche Ansatz. Ein IMHO von R. Zehl
---------------------------------------------
https://www.golem.de/news/security-der-phish-stinkt-vom-kopf-her-2608-21187…
∗∗∗ APT group HoneyMyte upgrades CoolClient: the backdoor gets a kernel-level Windows rootkit ∗∗∗
---------------------------------------------
Our experts discovered a new CoolClient backdoor variant with a kernel-mode rootkit driver that hides malicious processes, files, and network connections from security tools and threat analysts.
---------------------------------------------
https://securelist.com/honeymyte-coolclient-driver-rootkit/121028/
∗∗∗ Digitale Kaperbriefe: US-Regierung erlaubt Unternehmen offensive Cyberangriffe ∗∗∗
---------------------------------------------
Im Kampf gegen transnationale kriminelle Akteure will die US-Regierung verstärkt auf die Privatwirtschaft setzen. Unternehmen sollen selbst angreifen dürfen.
---------------------------------------------
https://www.heise.de/news/Digitale-Kaperbriefe-US-Regierung-erlaubt-Unterne…
∗∗∗ Studie zum Umgang mit Passkeys: Nutzer wissen zu wenig Bescheid ∗∗∗
---------------------------------------------
Passkeys sollen Passwörter ablösen, sie gelten als viel sicherer. In der Praxis fehlt vielen Nutzern noch Wissen, haben US-Forscher herausgefunden.
---------------------------------------------
https://www.heise.de/news/Studie-zum-Umgang-mit-Passkeys-Teilweise-gefaehrl…
∗∗∗ Vermehrt Betrugsversuche auf Buchungsplattformen (booking.com, ..) ∗∗∗
---------------------------------------------
Momentan erreichen uns vermehrt Meldungen über Betrugsversuche in Bezug auf Reisebuchungen über Plattformen wie beispielsweise booking.com. Eine der häufigsten Methoden der Kriminellen ist der Missbrauch echter Buchungsdaten. Dabei erhalten Personen nach einer tatsächlichen Buchung über eine Reiseplattform eine Nachricht per E-Mail, SMS ..
---------------------------------------------
https://www.cert.at/de/aktuelles/2026/8/vermehrt-betrugsversuche-auf-buchun…
∗∗∗ New Mirai variant adds stealth capabilities to notorious botnet code ∗∗∗
---------------------------------------------
Beyond Mirai’s usual functions, the new code features include encrypted communications with command-and-control servers and a “sniffer” that looks for default access credentials.
---------------------------------------------
https://therecord.media/new-mirai-variant-adds-stealth-to-botnet-code
∗∗∗ You’re Back In The Room (Citrix NetScaler Pre-Auth RCE CVE-2026-8452(?)) ∗∗∗
---------------------------------------------
Suddenly, you’re in a room. You look around - oh, you’re surrounded by other new starters at your new job. Yes, it’s Monday, and you’re being onboarded.You know the drill - it’s the typical ..
---------------------------------------------
https://labs.watchtowr.com/youre-back-in-the-room-citrix-netscaler-pre-auth…
∗∗∗ Seitenkanal erlaubt Zugriff auf RAM des AMD-Sicherheitscontrollers PSP ∗∗∗
---------------------------------------------
Bei alten AMD-Prozessoren lässt sich die in Hardware verankerte RAM-Adressverwaltung manipulieren, um auf vermeintlich geschützte Bereiche zuzugreifen.
---------------------------------------------
https://heise.de/-11414481
∗∗∗ How to Investigate GitHub PAT Compromise: Lessons From a Multi-Organization Campaign ∗∗∗
---------------------------------------------
A practical playbook for investigating GitHub token compromise, drawn from Wiz CIRTs response to a coordinated multi-organization campaign.
---------------------------------------------
https://www.wiz.io/blog/investigating-github-pat-compromise
∗∗∗ Closing the Blind Spot: Securing Personal Repositories in the Software Supply Chain ∗∗∗
---------------------------------------------
Personal repositories are where corporate secrets quietly escape. Wiz correlates them to your developers, validates the real risk, and drives the fix.
---------------------------------------------
https://www.wiz.io/blog/securing-personal-repositories
=====================
= Vulnerabilities =
=====================
∗∗∗ External Authentication - Moderately critical - Access bypass - SA-CONTRIB-2026-098 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-098
∗∗∗ [R1] Security Center Version 6.9.0 Fixes Multiple Vulnerabilities ∗∗∗
---------------------------------------------
https://www.tenable.com/security/tns-2026-22
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 12-08-2026 18:00 − Donnerstag 13-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Neue Phishing-Welle trifft zahlreiche Hotels: Gäste sollten wachsam sein ∗∗∗
---------------------------------------------
Mitten in der Ferienzeit häufen sich erfolgreiche Angriffe auf IT-Dienstleister der Hotelbranche. Gäste erhalten derzeit vermehrt täuschend echt wirkende Phishing-Nachrichten, die sie zu Zahlungen oder zur Preisgabe von Kreditkartendaten drängen. Einer der aktuellen Fälle betrifft den österreichischen IT-Dienstleister Seekda. Nach einem Phishing-Angriff informiert Seekda erste Betroffene über ungewöhnliche Zugriffsmuster auf seine Systeme. Das Ausmaß des Sicherheitsvorfalls dürfte groß sein.
---------------------------------------------
https://www.heise.de/news/Phishing-Wellen-Cyberangriffe-auf-IT-Dienstleiste…
∗∗∗ Hundreds of fake Chrome VPN extensions route traffic through a proxy ∗∗∗
---------------------------------------------
More than 737 browser extensions published on the Chrome Web Store impersonated well-known VPN and proxy services while routing users traffic through SOCKS5 proxies operated by a single provider.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hundreds-of-fake-chrome-vpn-…
∗∗∗ Android malware combo takes out loans and relays victims credit cards ∗∗∗
---------------------------------------------
A new Android NFC relay malware called WindRelay is being used alongside the SpyNote remote administration tool (RAT) to steal live card data and send it to attackers in real time. [..] When receiving a call from your bank and asked to take urgent action, it is advisable to terminate the call, dial the number listed on the organization's official website, and ask to connect with the same support agent.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/android-malware-combo-takes-…
∗∗∗ "City-Forum" data-theft attacks target Salesforce, ServiceNow portals ∗∗∗
---------------------------------------------
An ongoing data theft campaign uses custom tools to steal data exposed to anonymous users through Salesforce Experience Cloud and ServiceNow customer portals. [..] Reco says all of the attacks originate from the IP address 158.220.87.79, hosted by German VPS provider Contabo, and almost always use the default Go-http-client/1.1 user agent when downloading data. This IP address is associated with the city-forum.com domain, which has resolved to the server since at least March 2025, indicating that the infrastructure has remained in place for more than a year.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/city-forum-data-theft-attack…
∗∗∗ Cisco Advance Notification for Publication of August 19, 2026, Security Advisories ∗∗∗
---------------------------------------------
On August 19, 2026, the Cisco Product Security Incident Response Team (PSIRT) will publish advisories to disclose security vulnerability information along with fixed software releases for the following Cisco products: BroadWorks, Industrial Ethernet 1000 Series Switches, Packaged Contact Center Enterprise and Unified Contact Center Enterprise, RoomOS, Secure Firewall Adaptive Security Appliance, Secure Firewall Management Center, Secure Firewall Threat Defense Center, Secure Workload, Unified Intelligence Center
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Verschlüsselter KI-„Denkprozess“ gehackt: Schwache Modelle verraten Geheimnisse ∗∗∗
---------------------------------------------
Über eine Sicherheitslücke lassen sich Abwägungsprotokolle von KI-Top-Systemen wie GPT-5 im Klartext auslesen – mithilfe kleinerer Modelle desselben Anbieters.
---------------------------------------------
https://www.heise.de/hintergrund/Verschluesselter-KI-Denkprozess-gehackt-Sc…
∗∗∗ How BitLocker PINs help protect your data and devices ∗∗∗
---------------------------------------------
The NCSC provides guidance on how to securely configure Microsoft Windows. This includes setting up BitLocker, which encrypts your device to protect the data and the operating system from tampering. Our guidance recommends that BitLocker be configured to require a PIN before decrypting your device.
---------------------------------------------
https://www.ncsc.gov.uk/blogs/how-bitlocker-pins-help-protect-your-data-and…
∗∗∗ WhatsApp-Benutzernamen: Vor- und Nachteile im Überblick ∗∗∗
---------------------------------------------
Wie schützt ein WhatsApp-Benutzername vor Betrug – und welche Daten gibt man preis? Verbraucherschützer bewerten den Status quo beim Meta-Messenger.
---------------------------------------------
https://heise.de/-11412273
=====================
= Vulnerabilities =
=====================
∗∗∗ Fortinet FortiManager FGFM Authentication Weakening via CLI Configuration ∗∗∗
---------------------------------------------
An Authentication Bypass Using an Alternate Path or Channel [CWE-288] vulnerability in FortiManager and FortiManager Cloud may allow a remote unauthenticated attacker to impersonate any FortiGate managed by the FortiManager with a specific CLI option set via crafted FGFM requests if the attacker has a valid certificate. CVE-2026-70468
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-160
∗∗∗ GitLab Patch Release: 19.2.2, 19.1.4, 19.0.6 ∗∗∗
---------------------------------------------
These versions contain important bug and security fixes, and we strongly recommend that all self-managed GitLab installations be upgraded to one of these versions immediately.
---------------------------------------------
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-2-releas…
∗∗∗ Palo Alto Networks Security Advisories 12.08.2026 ∗∗∗
---------------------------------------------
https://security.paloaltonetworks.com/
∗∗∗ LWN: Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1088715/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 11-08-2026 18:00 − Mittwoch 12-08-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Attackers Exploit VMware vCenter Vulnerability to Gain Persistent Remote Access ∗∗∗
---------------------------------------------
Threat actors have begun to actively exploit a recently patched critical security flaw in Broadcom VMware vCenter, according to new findings from QUIRSO.
---------------------------------------------
https://thehackernews.com/2026/08/attackers-exploit-vmware-vcenter.html
∗∗∗ Malicious LiteLLM Releases Tied to Trivy Hack May Have Exposed 2,100+ Organizations ∗∗∗
---------------------------------------------
Two malicious LiteLLM releases sat on PyPI for about 40 minutes in March carrying credential-stealing code capable of harvesting cloud keys, SSH keys, Kubernetes tokens, database passwords, and other secrets from systems that installed them. Threat intelligence firm CloudSEK now says a dataset it obtained, built from roughly 434,000 files the attackers captured, maps potential exposure to more than 2,500 organizations.
---------------------------------------------
https://thehackernews.com/2026/08/malicious-litellm-releases-tied-to.html
∗∗∗ Brandenburg: Cyberangriff legt IT-System der Gedenkstätten lahm ∗∗∗
---------------------------------------------
Die Stiftung Brandenburgische Gedenkstätten wurde Opfer eines Ransomware-Angriffs. IT-Systeme sind derzeit außer Betrieb, ein Datenabfluss wird vermutet.
---------------------------------------------
https://www.heise.de/news/Brandenburg-Cyberangriff-legt-IT-System-der-Geden…
∗∗∗ Threema: DDoS-Angriffe sorgen für Ausfälle bei Messenger ∗∗∗
---------------------------------------------
Nach einem Angriff auf einen Dienstleister von Threema war der Messenger am Dienstag stundenlang nicht nutzbar. Am Mittwoch dauern die Attacken an.
---------------------------------------------
https://www.heise.de/news/Stoerungen-bei-Threema-DDoS-Angriffe-sorgen-fuer-…
∗∗∗ Deadbugz: Currently Active MCP Supply-Chain Campaign ∗∗∗
---------------------------------------------
Pillar Security Researchers identified an active campaign to distribute a malicious Model Context Protocol (MCP) server through public GitHub pull requests. The server calls itself productivity-suite and initially looks harmless: it offers text formatting and summarization. After a connected client makes three tool calls, however, it changes the instructions it returns to the AI agent. The new metadata directs the agent to seek sensitive information, including SSH keys, AWS credentials, shell history, and Kubernetes configuration, and to conceal the activity from the user.
---------------------------------------------
https://www.pillar.security/blog/deadbugz-currently-active-mcp-supply-chain…
=====================
= Vulnerabilities =
=====================
∗∗∗ Nordkoreas Hacker schlagen zu: Angriffe auf Windows-Nutzer in Europa beobachtet ∗∗∗
---------------------------------------------
Die Hackergruppe Lazarus greift Windows-Nutzer über eine Treiberlücke an. Microsoft hat sie zusammen mit über 400 weiteren Sicherheitslücken gepatcht.
---------------------------------------------
https://www.golem.de/news/auch-in-europa-nordkoreanische-hacker-attackieren…
∗∗∗ Kein Klick nötig: Lücke ermöglicht heimliche Schadcode-Attacken über Zoom-Meetings ∗∗∗
---------------------------------------------
Eine Sicherheitslücke in Zoom lässt Angreifer anderen Meeting-Teilnehmern unbemerkt Schadcode unterschieben. Nutzer sollten zügig updaten.
---------------------------------------------
https://www.golem.de/news/kein-klick-noetig-luecke-ermoeglicht-heimliche-sc…
∗∗∗ Zero-Day-Lücke im Defender: Chaotic Eclipse leakt neuen Windows-Exploit ∗∗∗
---------------------------------------------
Ein neuer Exploit namens Shieldbreak umgeht einen früheren Patch für den Microsoft Defender. Angreifer erhalten damit unter Windows Systemrechte.
---------------------------------------------
https://www.golem.de/news/zero-day-luecke-im-defender-chaotic-eclipse-leakt…
∗∗∗ Böse Screen-Sharing-Lücke in macOS: Exploit aus Apples Patch gebaut ∗∗∗
---------------------------------------------
Wer Apples praktische Bildschirm-teilen-Funktion auf dem Mac nutzt, muss sein Betriebssystem aktualisieren. Ein Exploit ließ sich schnell entwickeln.
---------------------------------------------
https://www.heise.de/news/Boese-Screen-Sharing-Luecke-in-macOS-Exploit-aus-…
∗∗∗ Patchday Adobe: Schadcode-Schlupflöcher bedrohen Campaign Classic und ColdFusion ∗∗∗
---------------------------------------------
Wichtige Sicherheitsupdates schließen mehrere Schwachstellen an Adobe-Anwendungen.
---------------------------------------------
https://www.heise.de/news/Patchday-Adobe-Schadcode-Schlupfloecher-bedrohen-…
∗∗∗ Der Security-Ko-Prozessor in vielen CPUs ist unsicher ∗∗∗
---------------------------------------------
Das Trusted Platform Module ist das wichtigste Glied in der Vertrauenskette von PCs. Ausgerechnet dieses TPM ist angreifbar.
---------------------------------------------
https://www.heise.de/news/Der-Security-Ko-Prozessor-in-vielen-CPUs-ist-unsi…
∗∗∗ Cisco warnt vor Attacken auf Secure Firewall Adaptive Security Appliance ∗∗∗
---------------------------------------------
Derzeit lassen Angreifer Cisco Secure Firewall Adaptive Security Appliance nach Attacken abstürzen. Ein Sicherheitspatch ist verfügbar.
---------------------------------------------
https://heise.de/-11411427
∗∗∗ Microsoft August 2026 Patch Tuesday fixes 400 flaws, 3 zero-days ∗∗∗
---------------------------------------------
Today is Microsoft's August 2026 Patch Tuesday, and with it comes security updates for a massive 400 flaws, including one actively exploited and two publicly disclosed zero-day vulnerabilities.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-august-2026-patch…
∗∗∗ ZDI-26-532: SonicWall Email Security updateNetIf Command Injection Local Privilege Escalation Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-26-532/
∗∗∗ ZDI-26-531: SonicWall GMS Virtual Appliance interface Command Injection Local Privilege Escalation Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-26-531/
∗∗∗ ZDI-26-530: SonicWall Email Security snmp Command Injection Local Privilege Escalation Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-26-530/
∗∗∗ ZDI-26-527: Wazuh Cluster DAPI Protocol Deserialization of Untrusted Data Remote Code Execution Vulnerability ∗∗∗
---------------------------------------------
http://www.zerodayinitiative.com/advisories/ZDI-26-527/
∗∗∗ PSIRT FortiGuard Labs Heap overflow in kernel driver due to missing size validation ∗∗∗
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-156
∗∗∗ PSIRT FortiGuard Labs Broken access control in the RADIUS type admin group ∗∗∗
---------------------------------------------
https://fortiguard.fortinet.com/psirt/FG-IR-26-158
∗∗∗ LWN Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1088476/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 10-08-2026 18:00 − Dienstag 11-08-2026 18:00
Handler: Alexander Riepl
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ New Pass-ta-key attack reveals all the things we didnt know about passkeys ∗∗∗
---------------------------------------------
Why passkey apps treat Windows differently than other operating systems.
---------------------------------------------
https://arstechnica.com/security/2026/08/heres-why-the-new-pass-ta-key-atta…
∗∗∗ Hackers breached a small Polish energy plant via private APN last year ∗∗∗
---------------------------------------------
Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-breached-a-small-pol…
∗∗∗ CISA: Microsoft SharePoint flaw now exploited in ransomware attacks ∗∗∗
---------------------------------------------
CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-fl…
∗∗∗ Mozilla updates GPG signing key for Firefox releases after exposure ∗∗∗
---------------------------------------------
Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-…
∗∗∗ Nach KI-Hacks: Chinesisches KI-Modell trickst Forscher bei Tests aus ∗∗∗
---------------------------------------------
Das KI-Modell Kimi K3 hat bei Tests eine gesicherte Umgebung verlassen und sich die gesuchten Lösungen einfach bei Github beschafft.
---------------------------------------------
https://www.golem.de/news/nach-ki-hacks-chinesisches-ki-modell-trickst-fors…
∗∗∗ Kein Klick nötig: Plug-and-Pwn-Angriff kapert Windows-Systeme per USB ∗∗∗
---------------------------------------------
Windows lädt beim Anschließen neuer USB-Geräte oft Software nach. Angreifer können dadurch Systemrechte erlangen - manchmal sogar aus der Ferne.
---------------------------------------------
https://www.golem.de/news/kein-klick-noetig-plug-and-pwn-angriff-kapert-win…
∗∗∗ BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins ∗∗∗
---------------------------------------------
Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platforms plugins team to temporarily disable their downloads."Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said.
---------------------------------------------
https://thehackernews.com/2026/08/bdthemes-supply-chain-attack-poisons.html
∗∗∗ Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers ∗∗∗
---------------------------------------------
Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording.The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California drivers license and a New York bank account.The
---------------------------------------------
https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html
∗∗∗ Abyssos: Technical Analysis of a New Modular RAT ∗∗∗
---------------------------------------------
In late June 2026, Zscaler ThreatLabz identified a new malware family that we track as Abyssos. Abyssos is a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. Abyssos is in active development with multiple version numbers and different obfuscation passes that are designed to improve evasion from security ..
---------------------------------------------
https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-…
∗∗∗ Lahmer x86-Befehl hebelt triviale Schutzfunktion aus ∗∗∗
---------------------------------------------
Der mächtige System Management Mode (SMM) von x86-Prozessoren ist ein bevorzugtes Ziel von Angriffen. Ein Trick hebelt eine SMM-Schutzfunktion aus.
---------------------------------------------
https://www.heise.de/news/Lahmer-x86-Befehl-hebelt-triviale-Schutzfunktion-…
∗∗∗ Patchday: SAP Commerce Cloud komplett kompromittierbar ∗∗∗
---------------------------------------------
SAP schließt in seinem Softwareproduktportfolio mehrere unter anderem kritische Sicherheitslücken.
---------------------------------------------
https://www.heise.de/news/Patchday-SAP-Commerce-Cloud-komplett-kompromittie…
∗∗∗ Sexual predators targeting online accounts for intimate images, FBI warns ∗∗∗
---------------------------------------------
The FBI is warning that criminals are breaking into social media to steal and distribute non-consensual intimate images and videos.
---------------------------------------------
https://www.malwarebytes.com/blog/news/2026/08/sexual-predators-targeting-o…
∗∗∗ The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications ∗∗∗
---------------------------------------------
Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution.
---------------------------------------------
https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/
∗∗∗ Poland uncovers second heat plant cyberattack that went hidden for months ∗∗∗
---------------------------------------------
The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January.
---------------------------------------------
https://therecord.media/poland-uncovers-critical-infrastructure-attack-hidd…
∗∗∗ LexisNexis deaktiviert nach "verdächtigen Server-Aktivitäten" drei Dienste ∗∗∗
---------------------------------------------
Aktuell ist unklar, was genau passiert ist. Aber seit vorigen Mittwoch, den 5. August 2026, scheint bei LexisNexis etwas passiert zu seine. Der Anbieter hat nach "verdächtigen Server-Aktivitäten" gleich drei Dienste deaktiviert und Verbindungen zu Drittanbietern getrennt. Es laufen Untersuchungen ..
---------------------------------------------
https://borncity.com/blog/2026/08/10/lexisnexis-deaktiviert-nach-verdaechti…
∗∗∗ Steam-Hardware: Käufer müssen nach Cyberangriff mit Betrugsmails rechnen ∗∗∗
---------------------------------------------
Bei Valves Logistikpartner CEVA sind Namen und Adressen europäischer Steam-Hardware-Käufer abgeflossen. Valve warnt vor falschen Nachrichten.
---------------------------------------------
https://heise.de/-11409514
∗∗∗ Google Phishing Kit: When Phishing Becomes a Real-Time Remote Browser ∗∗∗
---------------------------------------------
Most of the phishing pages are mere static clones of the login form, whereas sophisticated phishing kits implement adversary-in-the-middle techniques that perform authentication in real-time. In particular, the design being analyzed below fits into the Browser-in-the-Middle (BitM) scheme where the victim-facing page becomes the client for the browser session running at the backend of the phishing operation.The captured network traffic and the extracted client-side artifacts ..
---------------------------------------------
https://www.joesecurity.org/blog/2909557602925734728
∗∗∗ Inside the Metabase SQLi: Exploited in the Wild ∗∗∗
---------------------------------------------
Reverse engineering Metabase CVE-2026-72898 with AI to accelerate defense.
---------------------------------------------
https://www.wiz.io/blog/inside-the-metabase-sqli-exploited-in-the-wild
=====================
= Vulnerabilities =
=====================
∗∗∗ TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool ∗∗∗
---------------------------------------------
It has been discovered that TYPO3 CMS is susceptible to broken access control.
---------------------------------------------
https://news.typo3.com/security/advisory/typo3-core-sa-2026-021
∗∗∗ Security updates for Tuesday ∗∗∗
---------------------------------------------
Security updates have been issued by AlmaLinux (gpsd), Debian (caddy, libyaml-syck-perl, nss, and wordpress), Fedora (chezmoi, chromium, emacs, kernel, knot, libcupsfilters, mingw-gstreamer1-plugins-good, mingw-libidn, mingw-python-pip, nghttp2, p11-kit, python-webob, suricata, and xen), Mageia (bind, openslide, php8.4, and php8.5), Oracle (gpsd-minimal, kernel, libarchive, libpng12, nodejs-nodemon, php:8.3, ruby:3.3, and ruby:4.0), SUSE (agama-web-ui, bind, bouncycastle, dhcpcd, ffmpeg, ..
---------------------------------------------
https://lwn.net/Articles/1088226/
∗∗∗ August 2026 Security Update ∗∗∗
---------------------------------------------
https://www.ivanti.com/blog/august-2026-security-update
∗∗∗ SAP Security Patch Day August 2026 | RedRays ∗∗∗
---------------------------------------------
https://redrays.io/blog/sap-security-patch-day-august-2026/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 07-08-2026 18:00 − Montag 10-08-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs ∗∗∗
---------------------------------------------
CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws…
∗∗∗ AI-Generated Patches Fail Half the Time ∗∗∗
---------------------------------------------
A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass.
---------------------------------------------
https://www.darkreading.com/application-security/ai-generated-patches-fail-…
∗∗∗ DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure ∗∗∗
---------------------------------------------
Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims.The post DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure appeared first on Microsoft Security Blog.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomwar…
∗∗∗ Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer ∗∗∗
---------------------------------------------
A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems.
---------------------------------------------
https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html
∗∗∗ New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens ∗∗∗
---------------------------------------------
New research shows content inside an email can escape its message boundary and interfere with the webmail interface.
---------------------------------------------
https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html
∗∗∗ Cyber vulnerability sweep picks up Royal Navy drones sending data to China ∗∗∗
---------------------------------------------
No, no nasties to see here, guv...
---------------------------------------------
https://www.theregister.com/edge-and-iot/2026/08/10/cyber-vulnerability-swe…
∗∗∗ Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All ∗∗∗
---------------------------------------------
Two security researchers bought cheap domains—including noreply.net and deleteduser.com—and set up email listening services. Hundreds of companies are sending them corporate secrets.
---------------------------------------------
https://www.wired.com/story/sensitive-info-goes-into-no-reply-emails-consta…
∗∗∗ Russian military hackers pose as recruiters to target Ukrainian IT workers ∗∗∗
---------------------------------------------
Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency.
---------------------------------------------
https://therecord.media/russian-military-hackers-pose-as-recruiters-ukraine…
∗∗∗ Jeans-Hersteller Levi Strauss & Co. erleidet Datenpanne ∗∗∗
---------------------------------------------
Levi Strauss, als Anbieter von Jeans bekannt, hat die Woche einen Datenschutzvorfall erlitten. Mitarbeiter wurden über Social Media ausgetrickst. Dem Angreifer gelang dann wohl der Zugriff auf drei Rechner von Mitarbeitern.
---------------------------------------------
https://borncity.com/blog/2026/08/08/jeans-hersteller-levi-strauss-co-erlei…
∗∗∗ SANS Institute rät Sicherheitsteams, offene Türen für KI-Agenten zu schließen ∗∗∗
---------------------------------------------
Die Sicherheitsvorfälle bei Anthropic, Open AI und Meta, sowie bei Bytedance, bei denen AI-Modelle oder Agenten aus ihrer Testumgebung ausbrachen und Angriff im Internet durchführten, hat die Branche aufgeschreckt. Das SANS Institute gibt Sicherheitsteams den Tipp: Offene Türen für KI-Agenten zu schließen.
---------------------------------------------
https://borncity.com/blog/2026/08/09/sans-institute-raet-sicherheitsteams-o…
∗∗∗ Investigating a Multi-Stage PowerShell Loader ∗∗∗
---------------------------------------------
During recent threat hunting, I identified suspicious PowerShell content being served directly from an IP address and a domain: hxxp://203[.]188[.]171[.]166/hxxps://dorenzaa[.]com/ Both locations returned PowerShell rather than a conventional user-facing webpage. The PowerShell was responsible for retrieving a ZIP archive from Vercel-hosted infrastructure, extracting it locally, and executing an executable from the extracted content.
---------------------------------------------
https://malwr-analysis.com/2026/08/08/investigating-a-multi-stage-powershel…
∗∗∗ IT threat evolution in Q2 2026. Non-mobile statistics ∗∗∗
---------------------------------------------
The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026.
---------------------------------------------
https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/
∗∗∗ IT threat evolution in Q2 2026. Mobile statistics ∗∗∗
---------------------------------------------
This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers.
---------------------------------------------
https://securelist.com/malware-report-q2-2026-mobile-statistics/120948/
=====================
= Vulnerabilities =
=====================
∗∗∗ Jetzt patchen! Admin-Attacken auf Metabase beobachtet ∗∗∗
---------------------------------------------
Angreifer nutzen zurzeit eine kritische Sicherheitslücke in der Business-Intelligence-Plattform Metabase aus. Admins müssen jetzt handeln.
---------------------------------------------
https://heise.de/-11404526
∗∗∗ Schadcode-Attacken auf Progress LoadMaster im Gange ∗∗∗
---------------------------------------------
Derzeit haben Angreifer Progress LoadMaster auf dem Schirm und attackieren aktiv Systeme. Sicherheitspatches sind verfügbar.
---------------------------------------------
https://heise.de/-11404612
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1088057/
∗∗∗ Security updates 1.6.18 and 1.7.3 released ∗∗∗
---------------------------------------------
https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/