=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 06-08-2026 18:00 − Freitag 07-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Malware Can Abuse Windows Hello for Business Keys for Persistent Entra ID Access ∗∗∗
---------------------------------------------
Security researcher Malcolm Stagg has disclosed a new attack class called NatJack that manipulates network address translation (NAT) connection state to hijack active TCP sessions, spoof DNS responses, disclose victim IP addresses and mapped ports, and exhaust NAT tables. [..] The disclosure does not identify the exact Windows builds or Windows Hello for Business deployment models tested. [..] The new work removes that requirement by treating the Windows Hello for Business key as a FIDO2 passkey through WebAuthn. Mollema found that the five-minute Entra ID challenge is not bound to a session, user, or tenant. An attacker can therefore request it on another host and have the compromised endpoint produce the signed assertion.
---------------------------------------------
https://thehackernews.com/2026/08/malware-can-abuse-windows-hello-for.html
∗∗∗ Durch Metabase-0day: Datenleck bei Laptophersteller Framework ∗∗∗
---------------------------------------------
Der Laptophersteller Framework hat ein Datenleck erlitten und warnt seine Kunden vor abgeflossenen Informationen. Kontakt- und Lieferdaten privater und gewerblicher Kunden kamen abhanden – Zahlungs- und Bestellinformationen nach Frameworks Angaben jedoch nicht. Offenbar nutzten Angreifer eine Zero-Day-Lücke in Metabase aus; der Datenbankhersteller hat Updates veröffentlicht und seine Cloud-Instanzen abgedichtet.
---------------------------------------------
https://www.heise.de/news/Durch-Metabase-0day-Datenleck-bei-Laptopherstelle…
∗∗∗ ChainDrop: Inside a Self-Propagating npm Worm ∗∗∗
---------------------------------------------
A self-propagating npm worm nicknamed ChainDrop infected over 400 packages that are collectively downloaded hundreds of millions of times each week. This includes malicious versions of widely used packages such as keyv and cacheable-request. Unit 42 has unique observations of this attack.
---------------------------------------------
https://unit42.paloaltonetworks.com/chaindrop-npm-worm-analysis/
∗∗∗ N-able N-central: 2. Hotfix vom 6. August 2026 ∗∗∗
---------------------------------------------
Ein Patch gegen die Schwachstelle (CVE-2026-18576) wirkte nicht. Die RMM-Lösung wird bereits angegriffen. Der Hotfix 1 von Anfang August 2026 scheint nicht auszureichen, vor wenigen Stunden wird ein Hotfix 2 nachgeschoben.
---------------------------------------------
https://borncity.com/blog/2026/08/07/n-able-n-central-2-hotfix-vom-6-august…
∗∗∗ "deGDID" entfernt GDID in Windows und blockt Neuanlage ∗∗∗
---------------------------------------------
Microsoft vergibt in Windows eine eindeutige GDID genannte Kennung, über die Nutzer identifiziert werden können. Der VPN-Anbieter Windscribe hat nun ein Skript entwickelt, um das versteckte GDID-Tracking von Microsoft unter Windows zu blockieren.
---------------------------------------------
https://borncity.com/blog/2026/08/07/degdid-entfernt-gdid-in-windows-und-bl…
∗∗∗ Unternehmen fürchten US-Kill-Switch für kritische IT-Dienste ∗∗∗
---------------------------------------------
74 Prozent der Unternehmen befürchten, dass US-Anbieter auf Druck der US-Regierung wichtige Dienste sperren könnten.
---------------------------------------------
https://heise.de/-11403600
=====================
= Vulnerabilities =
=====================
∗∗∗ Screen Sharing: Gefährliche MacOS-Lücke lässt Angreifer Apple-Systeme kapern ∗∗∗
---------------------------------------------
Die besagte Sicherheitslücke ist als CVE-2026-65400 registriert und verfügt mit einem CVSS-Wert von 7,1 über einen hohen Schweregrad. "Ein Angreifer im Netzwerk könnte sich möglicherweise ohne gültige Anmeldedaten bei der Bildschirmfreigabe authentifizieren", heißt es in der Beschreibung. [..] Die gepatchten MacOS-Versionen tragen die Versionsnummern 26.6.1 (Tahoe), 15.7.9 (Sequoia) und 14.8.9 (Sonoma).
---------------------------------------------
https://www.golem.de/news/screen-sharing-gefaehrliche-macos-luecke-laesst-a…
∗∗∗ New Zapscape KVM Flaw Could Let Privileged L1 Guest Code Escape to Linux Hosts ∗∗∗
---------------------------------------------
Zapscape, a new Linux kernel vulnerability, could allow an attacker with kernel privileges inside an L1 guest virtual machine (VM) to escape KVM isolation and execute code on the host. The risk applies when nested virtualization is exposed to untrusted guests. The flaw is tracked as CVE-2026-64561 and affects KVM/x86's shadow memory management unit (MMU), which manages shadow page tables used for nested guest memory translation. [..] As of August 6, 2026, Debian's tracker listed bullseye, bookworm, and trixie kernel packages, including their security repositories, as vulnerable.
---------------------------------------------
https://thehackernews.com/2026/08/new-zapscape-kvm-flaw-could-let.html
∗∗∗ SCTPhantom: An 18-Year-Old SCTP ASCONF Transport Use-After-Free ∗∗∗
---------------------------------------------
SCTPhantom is a Linux kernel use-after-free in SCTP Dynamic Address Reconfiguration. An ordered ASCONF sequence can remove a transport and then reuse its stale pointer, leaving the association with dangling path references. Corvus AI developed the initial finding into a reproducible vulnerability and demonstrated local privilege escalation and container-to-host escape on the tested systems. The issue is tracked as CVE-2026-64564 and fixed upstream by 9b2854f86f0b.
---------------------------------------------
https://matrix.tencent.com/en/2026/08/06/sctphantom-CVE-2026-64564
∗∗∗ WordPress 7.0.3 release ∗∗∗
---------------------------------------------
WordPress 7.0.3 is now available WordPress 7.0.3 is now available which features several security fixes. Because this is a security release, it is recommended that you update your sites immediately. [..] Pre-auth reflected cross-site scripting (XSS) on the login screen with potential to lead to PHP code execution reported by the team at pwn.ai.
---------------------------------------------
https://wordpress.org/news/2026/08/wordpress-7-0-3-release/
∗∗∗ LWN: Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1087742/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 05-08-2026 18:00 − Donnerstag 06-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Alexander Riepl
=====================
= News =
=====================
∗∗∗ COLDCARD security audit phishing attack installs remote access tool ∗∗∗
---------------------------------------------
A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/coldcard-security-audit-phis…
∗∗∗ Schweiz: Bundesamt für Informatik und Telekommunikation über Sharepoint gehackt ∗∗∗
---------------------------------------------
Ein Cyberangriff hat das Schweizer BIT getroffen. Angreifer sind über Microsoft Sharepoint eingedrungen und haben Hunderte Nutzerkonten kompromittiert.
---------------------------------------------
https://www.golem.de/news/schweiz-bundesamt-fuer-informatik-und-telekommuni…
∗∗∗ "Wiederkehrendes Muster": OpenSSL-Entwickler wettert gegen KI-Hacks ∗∗∗
---------------------------------------------
Seit einigen Tagen hacken sich vermehrt KI-Modelle von OpenAI, Anthropic und Meta durchs Netz. Das Problem liegt laut OpenSSL-Entwickler Hudson aber nicht bei der KI.
---------------------------------------------
https://www.golem.de/news/wiederkehrendes-muster-openssl-entwickler-wettert…
∗∗∗ Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports ∗∗∗
---------------------------------------------
Two security flaws in Paperclip could let attackers execute commands on a network server or a developers computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and ..
---------------------------------------------
https://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.html
∗∗∗ Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures ∗∗∗
---------------------------------------------
A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.The server-side ..
---------------------------------------------
https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html
∗∗∗ Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink.According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available ..
---------------------------------------------
https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.ht…
∗∗∗ Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed a security issue with Apples iCloud Private Relay tool that can expose a users real IP address.Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users privacy by routing ..
---------------------------------------------
https://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.html
∗∗∗ Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities ∗∗∗
---------------------------------------------
Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network.Its August 3 scan counted 4,407 exposed Rockwell ..
---------------------------------------------
https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.ht…
∗∗∗ ClaudeFix: Shared Claude Chats Meet ClickFix ∗∗∗
---------------------------------------------
ClickFix is a widely employed attack technique, first seen in 2024, where a victim is instructed to paste-and-run instructions on their system to “fix” a problem or install software. The seemingly benign instructions are, in fact, malicious and lead to the deployment of malware onto the victim’s system. Zscaler Threat Hunting has identified ..
---------------------------------------------
https://www.zscaler.com/blogs/security-research/claudefix-shared-claude-cha…
∗∗∗ Fehlende Kontaktmöglichkeit: Deutschland verschläft Sicherheit per security.txt ∗∗∗
---------------------------------------------
Nur 1,8 Prozent der deutschen Webseiten bieten eine standardisierte security.txt an. Das BSI warnt vor den Risiken und verweist auf kommende Meldepflichten.
---------------------------------------------
https://www.heise.de/news/Fehlende-Kontaktmoeglichkeit-Deutschland-verschla…
∗∗∗ Scammers target OnlyFans users with deepfakes ∗∗∗
---------------------------------------------
Criminals are impersonating OnlyFans creators using AI tools in order to scam followers.
---------------------------------------------
https://www.malwarebytes.com/blog/news/2026/08/scammers-target-onlyfans-use…
∗∗∗ Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits ∗∗∗
---------------------------------------------
Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didnt exist.
---------------------------------------------
https://www.bitdefender.com/en-us/blog/hotforsecurity/apple-bug-bounty-ai-m…
∗∗∗ Token Jacking: Cybercriminals Could Be Stealing Your AI Resources ∗∗∗
---------------------------------------------
Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys.
---------------------------------------------
https://unit42.paloaltonetworks.com/ai-token-jacking/
∗∗∗ OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries ∗∗∗
---------------------------------------------
Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025.
---------------------------------------------
https://hackread.com/octlurk-silklurk-backdoors-target-6-countries/
∗∗∗ Sicherheitspatches: Angreifer können Schadcode auf n8n-Servern ausführen ∗∗∗
---------------------------------------------
Die n8n-Entwicklwer haben in aktuellen Versionen insgesamt 18 Sicherheitslücken geschlossen.
---------------------------------------------
https://heise.de/-11400494
∗∗∗ Fake Zoom installer uses .NET downloader to deliver Overlord RAT on macOS ∗∗∗
---------------------------------------------
Jamf Threat Labs uncovers a macOS campaign using a fake Zoom installer to deploy Overlord RAT. Built with .NET, this cross-platform technique simultaneously targets Windows, joining Go- and Rust-based cross-platform malware.
---------------------------------------------
https://www.jamf.com/blog/fake-zoom-installer-delivers-overlord-rat-macos/
=====================
= Vulnerabilities =
=====================
∗∗∗ Cisco IOS XE Software Security Hardening Release: August 2026 ∗∗∗
---------------------------------------------
As part of Ciscos ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not ..
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Veeam: Vulnerabilities Resolved in Veeam ONE 13.1 ∗∗∗
---------------------------------------------
Veeam has released 6 new security advisories for Veeam ONE (1x critical, 4x high, 1x medium)
---------------------------------------------
https://www.veeam.com/kb4892
∗∗∗ Security updates for Thursday ∗∗∗
---------------------------------------------
Security updates have been issued by Debian (7zip, kernel, libde265, and p7zip), Mageia (tomcat), Oracle (fence-agents, frr10, kernel, ldns, libgcrypt, mingw-glib2, nodejs24, osbuild-composer, p11-kit, php8.4, sg3_utils, and thunderbird), Red Hat (libXfont2), and SUSE (containerd, evince, libXfont2, nginx, openssl-3, pcp, php7, php8, python-Django, python-httplib2, python-nltk, rrdtool, vifm, and wireshark).
---------------------------------------------
https://lwn.net/Articles/1087489/
∗∗∗ Entity Browser - Moderately critical - Cross site scripting - SA-CONTRIB-2026-094 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-094
∗∗∗ Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093 ∗∗∗
---------------------------------------------
https://www.drupal.org/sa-contrib-2026-093
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 04-08-2026 18:00 − Mittwoch 05-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Shaid Hulu: Neue Angriffe kompromittieren Hunderte npm-Pakete (4.8.2026) ∗∗∗
---------------------------------------------
Es gibt wohl eine neue Shaid Hulu-Angriffskampagne auf npm-Pakete. Nach dem Hack eines Entwicklerkontos sind wohl schon über 800 npm-Pakete mit Millionen Downloads kompromittiert. [..] Auslöser war die Kompromittierung des GitHub-Kontos des Betreuers von "keyv", einer Bibliothek mit rund 127 Millionen wöchentlichen npm-Downloads.
---------------------------------------------
https://borncity.com/blog/2026/08/05/shaid-hulu-neue-angriffe-kompromittier…
∗∗∗ Weitere KI-Attacke: Modell schleust Schwachstelle ein und manipuliert Menschen ∗∗∗
---------------------------------------------
Die Serie von Enthüllungen über alarmierende Hacker-Fähigkeiten führender KI-Modelle reißt nicht ab. Jetzt ertappten britische Sicherheitsforscher eine Künstliche Intelligenz in einem Testlauf beim Versuch, in Eigeninitiative eine Schwachstelle in öffentlich zugängliche Software einzuschleusen. Um damit durchzukommen, versuchte das KI-Modell der Entwicklerfirma Anthropic den Experten zufolge sogar, per E-Mail einen zuständigen Menschen zu manipulieren.
---------------------------------------------
https://heise.de/-11399219
∗∗∗ Cyberangriff auf Ungarn: Hacker stürzt Finanzverwaltung ins IT-Chaos ∗∗∗
---------------------------------------------
Ein Angreifer hat IT-Systeme der Finanzverwaltung Ungarns infiltriert. Den Zugriff erhielt er wohl über eine seit 2017 bekannte Lücke in Oracle Weblogic.
---------------------------------------------
https://www.golem.de/news/cyberangriff-auf-ungarn-hacker-stuerzt-finanzverw…
∗∗∗ Die Doppel-Überweisung: Wie Kriminelle mit einer Masche zweifach abkassieren wollen ∗∗∗
---------------------------------------------
Mit einem Fake-Shop und einem gestohlenen Impressum werden Opfer in eine Falle gelockt, die doppelt zuschnappen soll. Nach erfolgter Bezahlung via Überweisung, erhalten Betroffene eine E-Mail, in der von „Problemen mit dem Banksystem“ die Rede ist. Man solle die alte Überweisung stornieren und den Betrag auf ein anderes Konto transferieren.
---------------------------------------------
https://www.watchlist-internet.at/news/die-doppel-ueberweisung/
∗∗∗ II: Nachtrag zum Defender-Fehlalarm: Rückmeldung von Synology und Microsoft ∗∗∗
---------------------------------------------
Der Microsoft Defender hält oder hielt Synology-Backups auf verschiedenen Servern für einen Trojaner. Dadurch laufen die Sicherungen nicht mehr durch. Zum echten Problem für Administratoren wird das Ganze, weil die Defender-Option "Zulassen" für den in Quarantäne geschobenen Prozess die ganze Erkennungsregel abschaltet.
---------------------------------------------
https://borncity.com/blog/2026/08/04/ii-nachtrag-zum-defender-fehlalarm-rue…
∗∗∗ Attackers Don’t Need Your Devices Anymore They Just Need Your Identity. ∗∗∗
---------------------------------------------
Your EDR watches every endpoint. But modern attackers have learned to move between identities instead of devices. The good news is that the telemetry for every step of this movement exists across your hunting tables. The trick is knowing which table holds which evidence and how to correlate across them.
---------------------------------------------
https://detect.fyi/attackers-dont-need-your-devices-anymore-they-just-need-…
=====================
= Vulnerabilities =
=====================
∗∗∗ Critical Gitea Flaw Let Unauthenticated Attackers Read Server Files via Org-Mode Markup ∗∗∗
---------------------------------------------
An unauthenticated attacker can read any file the service account can access on Gitea, the self-hosted Git platform, in versions 1.22.1 through 1.27.0. No login, no repository write access. A public repository and crafted Org-mode markup are enough. The flaw is fixed in Gitea 1.27.1. The file-read flaw is tracked as CVE-2026-59774, rated Critical with a CVSS score of 9.8, and received its formal advisory on August 2. Gitea 1.27.1 also patches CVE-2026-60004, a separate remote code execution bug covered in a prior THN report.
---------------------------------------------
https://thehackernews.com/2026/08/critical-gitea-flaw-let-unauthenticated.h…
∗∗∗ Sicherheitsupdates: TP-Links Netzwerk-Ökosystem Omada ist kompromittierbar ∗∗∗
---------------------------------------------
Im Zuge der Black-Hat-2026-Konferenz haben Sicherheitsforscher von Forescout Informationen zu mehreren Sicherheitslücken in Omada veröffentlicht, die konkret ZTP betreffen. Ihnen zufolge können sich Angreifer unter anderem über hartkodierte kryptografische Schlüssel (CVE-2025-15627 „mittel“) und ein hartkodiertes Zertifikat (CVE-2025-15628 „hoch“) Zugriff verschaffen, Schadcode ausführen (CVE-2025-7850 „kritisch“) und sich einen Root-Shell-Zugriff einrichten (CVE-2025-7851 „hoch“). Die Forscher führen aus, dass Angreifer Schwachstellen miteinander kombinieren können, um sich weitreichenden Netzwerkzugriff zu verschaffen.
---------------------------------------------
https://www.heise.de/news/Sicherheitsupdates-TP-Links-Netzwerk-Oekosystem-O…
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1087318/
∗∗∗ Veeam: Vulnerabilities Resolved in Veeam Service Provider Console 9.3 ∗∗∗
---------------------------------------------
https://www.veeam.com/kb4893
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 03-08-2026 18:00 − Dienstag 04-08-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Phishing-Mails der ÖGK jetzt auch im Dialekt ∗∗∗
---------------------------------------------
Manche Betrugsmaschen halten sich hartnäckig über Jahre. Dazu zählen Phishing-Mails im Namen der Österreichischen Gesundheitskasse (ÖGK). Nun setzen die Kriminellen auch auf Dialekt.
---------------------------------------------
https://www.watchlist-internet.at/news/phishing-mails-der-oegk/
∗∗∗ NuGet-Sicherheit: Microsoft verkürzt Gültigkeit von API-Keys auf 30 Tage ∗∗∗
---------------------------------------------
Eine kürzere Gültigkeit von API-Keys zur Paketveröffentlichung soll die Sicherheit von NuGet stärken. Sie betrifft sowohl bestehende als auch neue Keys.
---------------------------------------------
https://heise.de/-11396124
∗∗∗ INC Ransomware Emerges as Dominant Actor Exploiting SonicWall SMA 1000 Flaws ∗∗∗
---------------------------------------------
The INC Ransomware operation has emerged as the "dominant threat actor" exploiting the recently disclosed security flaws in SonicWall Secure Mobile Access (SMA) 1000 series VPN appliances.
---------------------------------------------
https://thehackernews.com/2026/08/inc-ransomware-emerges-as-dominant.html
∗∗∗ Chinese Threat Actor Uses Leaked DarkSword Kit to Deploy GHOSTBLADE on iOS ∗∗∗
---------------------------------------------
An unknown Chinese-speaking threat actor has been observed running a campaign targeting Apple iOS devices by leveraging a publicly leaked version of the DarkSword exploit kit.
---------------------------------------------
https://thehackernews.com/2026/08/chinese-threat-actor-uses-leaked.html
∗∗∗ DOUBLECUP Uses ClickFix and Cached PNGs to Deliver CountLoader and DeviceManager RAT ∗∗∗
---------------------------------------------
A new Russian loader-as-a-service (LaaS) codenamed DOUBLECUP has been using ClickFix lures as a way to stage malware-laced PNG images in victims' browser cache and ultimately deliver CountLoader and a previously undocumented remote access trojan called DeviceManager.
---------------------------------------------
https://thehackernews.com/2026/08/doublecup-uses-clickfix-and-cached-pngs.h…
∗∗∗ Fake Adobe and Zoom Updates Install ScreenConnect for Persistent Remote Access ∗∗∗
---------------------------------------------
Cybersecurity researchers have disclosed details of an active, multi-wave campaign that employs social engineering lures themed around Adobe and Zoom software updates, business document reviews, and system maintenance utilities to stealthily deploy Remote Monitoring and Management (RMM) programs like ConnectWise ScreenConnect.
---------------------------------------------
https://thehackernews.com/2026/08/fake-adobe-and-zoom-updates-install.html
∗∗∗ AI slop pollutes the CVE pipeline with fake vulns ∗∗∗
---------------------------------------------
With NIST still buried under its backlog, expect AI-generated bogus reports to continue.
---------------------------------------------
https://www.theregister.com/security/2026/08/03/ai-slop-pollutes-the-cve-pi…
∗∗∗ Wenn die IT ausfällt: Krisensimulation für Krankenhäuser ∗∗∗
---------------------------------------------
Wie Krankenhäuser bei IT-Ausfällen reagieren, testet Nico Brüggemann vom Fraunhofer SIT. Er erklärt, warum Abläufe oft nur auf dem Papier funktionieren.
---------------------------------------------
https://www.heise.de/hintergrund/Wenn-die-IT-ausfaellt-Krisensimulation-fue…
∗∗∗ Almost Half of Malware Samples Communicate Direct to IP ∗∗∗
---------------------------------------------
Malware samples often bypass DNS entirely, communicating directly to IP addresses instead. Our analysis of 4 million dynamic analysis reports indicates that almost half (45.32%) of malware samples with any command-and-control (C2) activity made at least one direct-to-IP (D2IP) address connection. Measured as a fraction of all C2 connection attempts, D2IP traffic accounts for 23.17% of the total.
---------------------------------------------
https://unit42.paloaltonetworks.com/malware-bypass-dns-direct-to-ip/
∗∗∗ EU-Cybersecurity-Pflichten für Hersteller & Betriebe – Hands-on ∗∗∗
---------------------------------------------
Auf Hersteller und Unternehmen in Europa kommen in den nächsten Wochen und Monaten (z.B. ab 11.09.2026) einige Cybersecurity-Pflichten zu, die EU-weit geregelt sind. NIS-2, Cyber Resilience Act und Maschinenverordnung. Mir hat der Betreiber einer entsprechenden Infoseite einige Informationen zukommen lassen. Ich nutze die Gelegenheit, einen kuren Überblick über die Sachlage zu geben.
---------------------------------------------
https://borncity.com/blog/2026/08/04/eu-cybersecurity-pflichten-fuer-herste…
∗∗∗ Popular npm Packages in the keyv and Cacheable Namespaces Compromised in Active Supply Chain Attack ∗∗∗
---------------------------------------------
Socket’s Threat Research Team is tracking an active supply chain compromise affecting the widely used keyv and cacheable npm packages. On August 4, 2026, at least ten packages beginning with the keyv and cacheable namespaces and spreading to packages owned by other maintainers, were published with a malicious preinstall hook (setup.mjs) that downloads a standalone Bun runtime, executes an obfuscated second stage, harvests cloud and CI credentials, and republishes trojanized versions of other packages the stolen npm token can reach. The affected packages collectively account for tens of millions of weekly downloads. New packages are appearing in real time, and Socket team will keep on updating the list.
---------------------------------------------
https://socket.dev/blog/popular-npm-packages-in-the-keyv-and-cacheable-name…
=====================
= Vulnerabilities =
=====================
∗∗∗ New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root ∗∗∗
---------------------------------------------
cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database's root context, crossing the privilege boundary between a cPanel account and the server's administrative database identity. It shipped in a targeted security release that closes two other routes past account boundaries.
---------------------------------------------
https://thehackernews.com/2026/08/new-cpanel-critical-flaw-could-let.html
∗∗∗ Jetzt patchen! Angreifer attackieren N-able N-central ∗∗∗
---------------------------------------------
N-ables Endpoint-Managementlösung N-central ist verwundbar und Angreifer attackieren bereits Instanzen. Admins sollten zügig handeln.
---------------------------------------------
https://www.heise.de/news/Jetzt-patchen-Angreifer-attackieren-N-able-N-cent…
∗∗∗ Check Point: Angreifer können Security-Management-Server übernehmen ∗∗∗
---------------------------------------------
Aufgrund einer Sicherheitslücke können Angreifer die IT-Sicherheitslösung Security Management von Check Point attackieren. Hotfixes stehen zum Download.
---------------------------------------------
https://heise.de/-11398187
∗∗∗ Broadcom Fixes Multiple Critical VMware Vulnerabilities ∗∗∗
---------------------------------------------
Broadcom’s latest security advisory resolves five vulnerabilities affecting core VMware products. The most severe vulnerabilities carry a CVSS score of 9.8, allowing attackers to bypass authentication or execute arbitrary code on vulnerable systems. Because vCenter Server acts as the centralized management platform for VMware environments, successful exploitation could provide attackers with extensive control over virtual infrastructure. There are currently no confirmed reports of widespread exploitation, but the technical impact warrants immediate remediation.
---------------------------------------------
https://thecyberthrone.in/2026/08/03/broadcom-fixes-multiple-critical-vmwar…
∗∗∗ LWN Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1087068/
∗∗∗ Security Vulnerabilities fixed in Firefox for Android 153.0.3 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-73/
∗∗∗ [R1] Sensor Proxy Version 1.4.2 Fixes One Vulnerability ∗∗∗
---------------------------------------------
https://www.tenable.com/security/tns-2026-21
∗∗∗ Zyxel security advisory for path traversal vulnerability in the configuration file execution CLI command of ZLD firewalls ∗∗∗
---------------------------------------------
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-…
∗∗∗ Zyxel security advisory for command injection and improper authentication vulnerabilities in certain APs, FWA7, and Security Routers ∗∗∗
---------------------------------------------
https://www.zyxel.com/global/en/support/security-advisories/zyxel-security-…
∗∗∗ List of Security Fixes and Improvements in Veeam ONE ∗∗∗
---------------------------------------------
https://www.veeam.com/kb4858
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 31-07-2026 18:00 − Montag 03-08-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Arch Linux disables AUR package adoption to stop malware flood ∗∗∗
---------------------------------------------
The Arch Linux project has temporarily disabled adoption of Arch User Repository (AUR) packages after a surge in malicious takeovers of existing packages.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/arch-linux-disables-aur-pack…
∗∗∗ Inside the Underground Business of BTMOB RAT ∗∗∗
---------------------------------------------
BTMOB has been covered by several cybersecurity publications, primarily through technical analyses of the malware and its capabilities, but much less has been reported about the ecosystem that has developed around it.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/inside-the-underground-busin…
∗∗∗ ExfilSquad hackers leak info of over 100,000 UK police officers, staff ∗∗∗
---------------------------------------------
A cyberattack on the U.K.'s Police National Legal Database (PNLD) has compromised contact data of more than 100,000 police officers and other criminal justice professionals.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/exfilsquad-hackers-leak-info…
∗∗∗ Coldcard-Wallets: Massenhafte Bitcoin-Diebstähle erschüttern die Kryptobranche ∗∗∗
---------------------------------------------
Bitcoins im Wert von mehr als 70 Millionen Euro haben zuletzt unverhofft die Besitzer gewechselt. Grund ist eine Schwachstelle in Hardware-Wallets von Coinkite.
---------------------------------------------
https://www.golem.de/news/coldcard-wallets-massenhafte-bitcoin-diebstaehle-…
∗∗∗ Phishing Campaigns Targeting AI Solutions Providers, (Sat, Aug 1st) ∗∗∗
---------------------------------------------
Most phishing campaigns rely on the fact that the victim is afraid to loose "something": money, access to information, ... Many brands have been impersonated by campaigns but I spotted some phishing emails that focus on AI services like ChatGPT.
---------------------------------------------
https://isc.sans.edu/diary/rss/33206
∗∗∗ N-able Says Attackers Take Over N-central Servers After Initial Fix Proves Incomplete ∗∗∗
---------------------------------------------
N-able said attackers exploited an authentication bypass in N-central to gain remote administrative access and reach the customer systems managed through those servers.
---------------------------------------------
https://thehackernews.com/2026/08/n-able-says-attackers-take-over-n.html
∗∗∗ The OpenAI and Anthropic AI Hacking Sprees Are a Messy New Legal Frontier ∗∗∗
---------------------------------------------
Both major AI labs’ models broke containment, escaped onto the internet, and hacked other companies. If a human had done that, the law would likely be against them. But a bot?
---------------------------------------------
https://www.wired.com/story/openai-anthropic-ai-hacking-sprees-illegal/
∗∗∗ The Risk of Fine-Tuned Open-Weight Models ∗∗∗
---------------------------------------------
In the last weeks I was wondering how to continue offensive security and malware development over the next months or even years with the help of AI.
---------------------------------------------
https://www.msecops.de/blog/posts/backdoored-llms/
∗∗∗ Auswärtiges Amt warnt vor IT-Fachkräften aus Nordkorea ∗∗∗
---------------------------------------------
IT-Fachkräfte aus Nordkorea unterwandern zunehmend westliche Unternehmen. Jetzt gibt es eine internationale Warnung davor.
---------------------------------------------
https://www.heise.de/news/Auswaertiges-Amt-warnt-vor-IT-Fachkraeften-aus-No…
∗∗∗ Cyberangriff auf Liechtenstein – 31.000 Datensätze betroffen ∗∗∗
---------------------------------------------
Die Regierung Liechtensteins meldet einen Angriff auf ein Personenverzeichnis. Was steckt hinter dem Zugriff auf 31.000 Datensätze?
---------------------------------------------
https://www.heise.de/news/Cyberangriff-auf-Liechtenstein-31-000-Datensaetze…
∗∗∗ Apple: Limit für Bug-Meldungen pro Person ∗∗∗
---------------------------------------------
Apple reagiert auf die Flut von KI-generierten Sicherheitsmeldungen und begrenzt die Einreichungen pro Person.
---------------------------------------------
https://www.heise.de/news/Apple-Limit-fuer-Bug-Meldungen-pro-Person-1139537…
∗∗∗ Traumjob von zuhause? Achtung Geldwäschefalle! ∗∗∗
---------------------------------------------
Kriminelle geben sich als Personaler:innen aus, um ahnungslose Menschen für Geldwäsche zu missbrauchen. Die Opfer wissen dabei oft von nichts. Wir zeigen, wie Sie den Betrug erkennen.
---------------------------------------------
https://www.watchlist-internet.at/news/traumjob-von-zuhause-geldwaesche/
∗∗∗ Pass the Passkey: A Novel Attack Surface in Passwordless Authentication ∗∗∗
---------------------------------------------
This article analyzes new attack classes against passwordless authentication, focusing on Google’s synced passkey ecosystem and the Cloud Authenticator used by desktop clients. The attacks demonstrate how malware on a compromised endpoint can misuse onboarding, recovery and device trust workflows to take over passkey-protected accounts. We show how an attacker can authenticate without user interaction, bypass user verification requirements and extract all synced passkey private keys.
---------------------------------------------
https://unit42.paloaltonetworks.com/passwordless-authentication-security-ri…
∗∗∗ The Hidden CCS2 Attack Surface on EV Chargers ∗∗∗
---------------------------------------------
An EV charger's charging port is a network port. We found SSH and Telnet services exposed on XCharge C6 chargers with default root:root credentials. A threat actor with a malicious EV can gain immediate full control access on the charger and perform energy theft or potentially cause physical damage.
---------------------------------------------
https://www.saiflow.com/blog/the-hidden-ccs2-attack-surface-on-ev-chargers
∗∗∗ Guide to Bypassing Hotel Wi-Fi Captive Portals (With Permission) ∗∗∗
---------------------------------------------
Have you ever been curious about how easy it is to bypass that pesky captive portal? This article guides you through 3 different methods.
---------------------------------------------
https://projectblack.io/blog/bypassing-hotel-wi-fi-captive-portals/
=====================
= Vulnerabilities =
=====================
∗∗∗ Thermo Fisher Patches Flaw That Could Make DNA File Tampering Nearly Undetectable ∗∗∗
---------------------------------------------
Thermo Fisher Scientific has patched a flaw in select Applied Biosystems human identification software that could allow data files to be altered before analysis software loads them.
---------------------------------------------
https://thehackernews.com/2026/08/thermo-fisher-patches-flaw-that-could.html
∗∗∗ Adobe Campaign Classic Schwachstelle CVE-2026-48449 (CVSS 3.x 10.0) gepatcht ∗∗∗
---------------------------------------------
Adobe musste die Tage die Schwachstelle CVE-2026-48449 in seinem Produkt Adobe Campaign Classic patchen. Es handelt sich um eine Authorisierungsschwachstelle, die das umgehen einer Anmeldung ermöglicht. Die Schwachstelle wurde mit einem CVSS 3.x von 10.0, also dem höchstmöglichen Wert, als kritisch eingestuft.
---------------------------------------------
https://borncity.com/blog/2026/08/03/adobe-campaign-classic-schwachstelle-c…
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1086897/
∗∗∗ Synology-SA-26:12 Synology Assistant ∗∗∗
---------------------------------------------
https://www.synology.com/en-global/support/security/Synology_SA_26_12
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 30-07-2026 18:00 − Freitag 31-07-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Claude uploaded malware to PyPI in Anthropics botched test ∗∗∗
---------------------------------------------
One of Anthropics Claude models built and uploaded a malicious Python package to PyPI during a botched security evaluation, where it ran on 15 real systems and stole credentials from a security vendor. It was one of three incidents affecting real companies.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/claude-uploaded-malware-to-p…
∗∗∗ Microsoft: Forscher finden Masterkey für Vollzugriff auf Azure-Datenbanken ∗∗∗
---------------------------------------------
Mit dem Key hätten Angreifer alle Datenbanken bei Microsofts Datenbankdienst Azure Cosmos DB auslesen und manipulieren können - auch die von Microsoft.
---------------------------------------------
https://www.golem.de/news/microsoft-forscher-finden-masterkey-fuer-vollzugr…
∗∗∗ Anthropic and OpenAI are competing to see whose agents can go rogue harder ∗∗∗
---------------------------------------------
Whoever wins, we lose
---------------------------------------------
https://www.theregister.com/security/2026/07/31/anthropic-and-openai-are-co…
∗∗∗ „CosmosEscape“ ermöglichte Übernahme aller Microsoft-Azure-Datenbanken ∗∗∗
---------------------------------------------
Eine Verkettung von Sicherheitslücken ermöglichte vollen Zugang zu allen Azure-Cosmos-DB-Datenbanken.
---------------------------------------------
https://www.heise.de/news/CosmosEscape-ermoeglichte-Uebernahme-aller-Micros…
∗∗∗ If you’re going to vibe code it, why not vibe pen test it? ∗∗∗
---------------------------------------------
TL;DR Why I built PenAI PenAI started as a project at a hackathon organised by Encode Club. It’s an AI agent that could work through Hack The Box-style lab machines on its own. Upload a VPN file, give it a target IP, pick a scope, set stealth mode and iteration limits, hit run, and let ..
---------------------------------------------
https://www.pentestpartners.com/security-blog/if-youre-going-to-vibe-code-i…
∗∗∗ The Xcode Assassin Returns: A Deep Dive Into the Latest XCSSET Version ∗∗∗
---------------------------------------------
Analysis of XCSSET v40 reveals a macOS malware targeting developers via Xcode. Unit 42 used advanced pattern matching and AI to decode its logic.
---------------------------------------------
https://unit42.paloaltonetworks.com/xcsset-v40-malware-analysis/
∗∗∗ Firefox JIT-Schwachstelle gefährdete Tor-Nutzer unter Android ∗∗∗
---------------------------------------------
Im Firefox-Browser (151.0.1) gab es eine JIT-Schwachstelle (CVE-2026-10702), die einen Ausbruch aus dem Render des Browsers durch Code ermöglichte. Der Besuch einer bösartigen Webseite reichte aus, um beispielswiese den Tor-Browser, der den Firefox nutzt, zu kompromittieren. Ausnutzbar war das ..
---------------------------------------------
https://borncity.com/blog/2026/07/31/firefox-jit-schwachstelle-gefaehrdete-…
∗∗∗ Russische Akteure greifen über Outlook-Web-Access-Lücke an ∗∗∗
---------------------------------------------
Eine Sicherheitslücke in OWA ermöglicht durch Anzeigen von Mails das Ausführen von JavaScript-Code. Russische Akteure nutzen das aus.
---------------------------------------------
https://heise.de/-11387751
∗∗∗ SolarWinds Web Help Desk: Update bessert umgehbare Authentifizierung aus ∗∗∗
---------------------------------------------
SolarWinds schließt Sicherheitslücken in Web Help Desk. Eine gilt als kritisch und ermöglicht Angreifern, die Authentifizierung zu umgehen.
---------------------------------------------
https://heise.de/-11388191
∗∗∗ Unpatchbarer Fehler in Apple A12 & A13: Forensik- verklagt Security-Firma ∗∗∗
---------------------------------------------
Bis hin zum iPhone 11 stecken in Apple-Silicon-Chips nicht behebbare Lücken. Nun ist ein Streit darüber ausgebrochen, ob diese weitergegeben werden durfte.
---------------------------------------------
https://heise.de/-11379656
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 29-07-2026 18:00 − Donnerstag 30-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ HelloNet campaign: new malicious modules launched through the ViPNet update system ∗∗∗
---------------------------------------------
We identified targeted infection attempts against large Russian organizations using the ViPNet update system (a software suite for creating secure networks).
---------------------------------------------
https://securelist.com/tr/hellonet-vipnet/120700/
∗∗∗ Toy Ghouls’ new toy: the GenieLocker ransomware ∗∗∗
---------------------------------------------
The new GenieLocker ransomware family has been active since March 2026. It has been used in attacks against organizations in the Russian Federation, primarily in the manufacturing sector, and attributed to the Toy Ghouls group by open-source intelligence (link in Russian).
---------------------------------------------
https://securelist.com/genielocker-ransomware-for-windows-linux-and-esxi/12…
∗∗∗ Reconnaissance First: An SSH Bot That Sizes Up Your Hardware Before Deploying a Miner [Guest Diary], (Thu, Jul 30th) ∗∗∗
---------------------------------------------
Most of what an internet-facing SSH honeypot records is noise. Endless password guessing, and bots that log in, immediately pull down a payload, and move on. On 27 June 2026 my honeypot caught something quieter, and to me more interesting. A bot logged in as root, ran a careful survey of the machine's hardware, and then disconnected without downloading or running anything at all. No malware, no persistence, no second stage.
---------------------------------------------
https://isc.sans.edu/diary/rss/33198
∗∗∗ Critical Rails Flaw Could Let Unauthenticated Attackers Read Server Files via Image Uploads ∗∗∗
---------------------------------------------
Ruby on Rails has released fixes for a critical Active Storage vulnerability that could let unauthenticated attackers read arbitrary files from application servers through crafted image uploads.
---------------------------------------------
https://thehackernews.com/2026/07/critical-rails-flaw-could-let.html
∗∗∗ Hackers Exploit AnySign4PC via Hacked Korean Sites to Install Backdoors Without Prompts ∗∗∗
---------------------------------------------
South Korean authorities and four security firms have disclosed a state-sponsored campaign that compromised trusted domestic websites. The attackers used those sites to exploit locally installed financial-security software and infect targeted visitors with SIGNBT or COPPERHEDGE backdoors.
---------------------------------------------
https://thehackernews.com/2026/07/hackers-exploit-anysign4pc-via-hacked.html
∗∗∗ Verschlüsselt, aber falsch: Gruppenchats anfällig für manipulierte Inhalte ∗∗∗
---------------------------------------------
Alle Mitglieder eines Gruppenchats sollten dieselben Inhalte sehen. Die üblichen Chat-Dienste stellen das nicht sicher. Das ist riskant.
---------------------------------------------
https://www.heise.de/news/Verschluesselt-aber-falsch-Gruppenchats-anfaellig…
∗∗∗ Vermeintliche Zollgebühren der Post sind fake! ∗∗∗
---------------------------------------------
Eine offene Paketgebühr, ein Link zur Zahlung und eine täuschend echt aussehende Nachricht der Österreichischen Post. Mit dieser Masche versuchen Kriminelle derzeit, an Bankdaten zu gelangen.
---------------------------------------------
https://www.watchlist-internet.at/news/phishing-oesterreichischen-post-zoll/
∗∗∗ Chinese-Speaking Threat Actor Harnesses AI Models for Autonomous Cyberattacks ∗∗∗
---------------------------------------------
Unit 42 identified an AI-enabled autonomous hacking campaign carried out by a Chinese-speaking threat actor. They targeted infrastructure using seven vulnerabilities, combining autonomous AI-driven enumeration with manual exploitation that achieved confirmed impact.
---------------------------------------------
https://unit42.paloaltonetworks.com/autonomous-ai-cyber-attack-campaign/
∗∗∗ Adform compromised to serve crypto stealer via supply chain attack ∗∗∗
---------------------------------------------
Adform are an advertising company used by around 14k companies, owning around a 30% share of the demand-side category.
---------------------------------------------
https://doublepulsar.com/adform-compromised-to-serve-crypto-stealer-via-sup…
∗∗∗ CISA Guide Helps Federal Agencies Securely and Effectively Use Open Source Software ∗∗∗
---------------------------------------------
Tailored Guidance to Use and Understand OSS Solutions, Contribute to and Produce Projects, and Evaluate AI Models.
---------------------------------------------
https://www.cisa.gov/news-events/news/cisa-guide-helps-federal-agencies-sec…
=====================
= Vulnerabilities =
=====================
∗∗∗ Angreifer missbrauchen Backdoor in Ciscos Firewall-Verwaltungssoftware ∗∗∗
---------------------------------------------
Angreifer missbrauchen fest einprogrammierte Zugangsdaten in Ciscos Firewall-Verwaltungssoftware. Updates sollen dagegen helfen.
---------------------------------------------
https://www.heise.de/news/Angreifer-missbrauchen-Backdoor-in-Ciscos-Firewal…
∗∗∗ Chrome-Update stopft weitere 370 Sicherheitslecks ∗∗∗
---------------------------------------------
Google hat wieder ein massives Sicherheitsupdate für Chrome veröffentlicht. Sieben der geschlossenen Lücken gelten als kritisch.
---------------------------------------------
https://heise.de/-11384153
∗∗∗ Cisco Secure Firewall Management Center Software Static Credential Vulnerability ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Progress: LoadMaster Critical Security Bulletin – July 2026 – (CVE-2026-59686, CVE-2026-59687, CVE-2026-59688, CVE-2026-59689, CVE-2026-59690) ∗∗∗
---------------------------------------------
https://community.progress.com/s/article/LoadMaster-Critical-Security-Bulle…
∗∗∗ GitLab Patch Release: 19.2.1, 19.1.3, 19.0.5 ∗∗∗
---------------------------------------------
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-2-1-releas…
∗∗∗ Drupal Security Advisories 2026-July-29 ∗∗∗
---------------------------------------------
https://www.drupal.org/security
∗∗∗ Publish DFIR-IRIS advisories ∗∗∗
---------------------------------------------
https://github.com/sbaresearch/advisories/commit/0e542378f16ec1052b5ad032b4…
∗∗∗ LWN Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1086225/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 28-07-2026 18:00 − Mittwoch 29-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ vBulletin fixes critical pre-auth RCE flaw with public exploit ∗∗∗
---------------------------------------------
A critical vulnerability in the vBulletin forum software allows unauthenticated attackers to execute arbitrary PHP code through template rendering. [..] SSD Secure Disclosure has also published a technical analysis for CVE-2026-61511, explaining that the sanitization restrictions can be bypassed using the so-called “phpfuck” technique. [..] CVE-2026-61511 was reported to vBulletin on June 25, 2026, and version 6.2.2, which addressed the flaw, was released on July 1.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/vbulletin-fixes-critical-pre…
∗∗∗ Passwort-Hashes auslesbar: 20 Jahre alte BMC-Lücke gefährdet über 24.000 Server ∗∗∗
---------------------------------------------
Sicherheitsforscher von Lava haben 24.650 über das Internet erreichbare und für die Verwaltung von Serversystemen genutzte Baseboard Management Controller (BMC) ausfindig gemacht, die aufgrund einer zwei Jahrzehnte alten Sicherheitslücke Passwort-Hashes leaken. [..] Die Sicherheitslücke ist zwar, wie schon die CVE-ID erahnen lässt, erst 2013 öffentlich bekannt geworden, nach Angaben der Forscher war sie aber schon von Beginn an in IPMI 2.0 enthalten – und damit seit 2004. Trotz dieses Alters sind noch heute 36.872 Server-BMCs über IPMI erreichbar und davon 24.650 anfällig für CVE-2013-4786, wie Lava auf einem eigenen Dashboard zeigt.
---------------------------------------------
https://www.golem.de/news/passwort-hashes-auslesbar-20-jahre-alte-bmc-lueck…
∗∗∗ CubePilot drone software dev hit by DNS hijacking to intercept traffic ∗∗∗
---------------------------------------------
CubePilot, an Australian firm that designs flight controllers for drones (UAVs), announced a severe operational disruption caused by a DNS hijacking attack.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cubepilot-drone-software-dev…
∗∗∗ Nationale Sicherheit: FCC verbietet Importe chinesischer Roboter ∗∗∗
---------------------------------------------
Die US-Fernmeldebehörde FCC verbietet die Zulassung neuer chinesischer Roboter und Wechselrichter wegen angeblicher Sicherheitsrisiken.
---------------------------------------------
https://www.golem.de/news/nationale-sicherheit-fcc-verbietet-importe-chines…
∗∗∗ Public PoC Released for Exploited Check Point SmartConsole Authentication Bypass ∗∗∗
---------------------------------------------
Cybersecurity researchers have shared additional technical details about a recently patched critical security flaw impacting Check Point Security Management Server and Multi-Domain Security Management Server (MDS) that has come under active exploitation in the wild. The vulnerability, tracked as CVE-2026-16232 (CVSS score: 9.3), is an authentication bypass in the SmartConsole login process that allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges.
---------------------------------------------
https://thehackernews.com/2026/07/rapid7-releases-poc-for-exploited-check.h…
∗∗∗ JFrogs 0-days let OpenAIs models hack Hugging Face ∗∗∗
---------------------------------------------
We now know how OpenAI's models broke out of their cages to attack Hugging Face. The rogue models found zero-day vulnerabilities in JFrog’s universal binary repository manager Artifactory around the time they escaped, according to JFrog CTO Yoav Landman. While Landman wouldn't confirm that these flaws were the zero-days that OpenAI’s models found and exploited, ultimately allowing them to breach the massive model mart, OpenAI later admitted the connection.
---------------------------------------------
https://www.theregister.com/security/2026/07/28/jfrogs-0-days-let-openais-m…
∗∗∗ Some notes about Anthropic’s new results ∗∗∗
---------------------------------------------
Yesterday Anthropic published two new cryptanalysis results, both outputs of Claude Mythos, their (still) unreleased advanced model. The first of these results attacks a signature scheme called HAWK, while the second is an improved attack against reduced-round AES. Anthropic also released a blog post describing the research process that produced these results.
---------------------------------------------
https://blog.cryptographyengineering.com/2026/07/29/some-notes-about-anthro…
∗∗∗ Attackers Are Turning Microsoft’s Trusted Login System Into Their Latest Phishing Weapon ∗∗∗
---------------------------------------------
Attackers are increasingly abandoning fake Microsoft login pages in favor of abusing Microsoft’s legitimate authentication infrastructure, allowing phishing campaigns to bypass many of the warning signs employees have been trained to recognize. Starting on June 25th through the second week of July, we identified more than 200 phishing emails targeting users across approximately 120 organizations, spanning a wide range of industries and countries worldwide. Victims were then prompted to grant permissions to an attacker-controlled application, allowing the campaign to abuse Microsoft’s trusted authentication flow while concealing its malicious intent.
---------------------------------------------
https://blog.checkpoint.com/email-security/attackers-are-turning-microsofts…
∗∗∗ Fake-PayPal-Mails: Rückerstattung und Abbuchung als Köder ∗∗∗
---------------------------------------------
Kriminelle verschicken derzeit gefälschte PayPal-Nachrichten, um an Zugangsdaten und Bankdaten zu gelangen. Eine Mail lockt mit einer Rückzahlung von 95,66 Euro, die andere warnt vor einer Abbuchung von 909,00 Euro.
---------------------------------------------
https://www.watchlist-internet.at/news/fake-paypal-mails-rueckerstattung-un…
∗∗∗ GitHub Blog: Disrupting supply chain attacks on npm and GitHub Actions ∗∗∗
---------------------------------------------
Explore the changes weve shipped across npm and GitHub Actions over the past few months to disrupt supply chain attack techniques and limit their impact.
---------------------------------------------
https://github.blog/security/supply-chain-security/disrupting-supply-chain-…
=====================
= Vulnerabilities =
=====================
∗∗∗ Gitea: Remote Code Execution via diffpatch Git Hook Installation ∗∗∗
---------------------------------------------
Gitea's diffpatch endpoint can be abused to install and execute a Git hook from repository-controlled content. An attacker with ordinary write access to a repository can execute arbitrary shell commands as the Gitea OS user. With default open registration, an unauthenticated visitor can obtain the required write access by registering an account and creating a repository. CVE-2026-60004
---------------------------------------------
https://github.com/go-gitea/gitea/security/advisories/GHSA-rcr6-4jqh-j84m
∗∗∗ Broadcom: VMSA-2026-0006: VMware ESX, vCenter, Workstation, and Fusion updates address multiple vulnerabilities (CVE-2026-59309, CVE-2026-59310, CVE-2026-47876, CVE-2026-41703, CVE-2026-41709) ∗∗∗
---------------------------------------------
VMware vCenter contains an authentication bypass vulnerability in the VMware Directory Service. [..] VMware vCenter contains a directory traversal vulnerability in the Syslog server. [..] VMware ESX contains an out-of-bounds write vulnerability in the VMXNET3 virtual network adapter.
---------------------------------------------
https://support.broadcom.com/web/ecx/support-content-notification/-/externa…
∗∗∗ Jetbrains: Critical Security Issue Affecting TeamCity On-Premises (CVE-2026-63077) – Update to 2025.11.7 or 2026.1.3 Now ∗∗∗
---------------------------------------------
A critical security vulnerability has been identified in TeamCity On-Premises and assigned the Common Vulnerabilities and Exposures (CVE) identifier CVE-2026-63077. If exploited, this vulnerability may allow an unauthenticated attacker with HTTP(S) access to a TeamCity server to bypass authentication checks and execute arbitrary operating system commands.
---------------------------------------------
https://blog.jetbrains.com/teamcity/2026/07/cve-2026-63077/
∗∗∗ OpenWrt: Updates schließen teils kritische Sicherheitslücken ∗∗∗
---------------------------------------------
Das OpenWrt-Projekt hat aktualisierte Fassungen veröffentlicht, die teils als kritisches Risiko eingestufte Sicherheitslücken stopfen. [..] Mit einem einzigen UDP-Paket können Angreifer aus dem Netz ohne vorherige Anmeldung den Pufferüberlauf ausnutzen.
---------------------------------------------
https://heise.de/-11381496
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1086031/
∗∗∗ Node.js: Wednesday, July 29, 2026 Security Releases ∗∗∗
---------------------------------------------
https://nodejs.org/en/blog/vulnerability/july-2026-security-releases
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 27-07-2026 18:00 − Dienstag 28-07-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin ∗∗∗
---------------------------------------------
Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store.
---------------------------------------------
https://www.bleepingcomputer.com/news/apple/apple-sued-over-fake-app-store-…
∗∗∗ New Dysphoria DDoS botnet spreads to 200k devices worldwide ∗∗∗
---------------------------------------------
A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-sp…
∗∗∗ New Certighost PoC exploit lets attackers hijack Windows domains ∗∗∗
---------------------------------------------
A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-certighost-poc-exploit-l…
∗∗∗ Hackers target US firms in FastJson RCE zero-day attacks ∗∗∗
---------------------------------------------
Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-f…
∗∗∗ Data breach at medical billing firm MCBS affects 1.26 million people ∗∗∗
---------------------------------------------
Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/data-breach-at-medical-billi…
∗∗∗ Nach OpenAI-Hack: US-Abgeordnete wollen Kill Switch für KI ∗∗∗
---------------------------------------------
Der eigenständige Hackerangriff von OpenAIs KI hat Nachwirkungen: Abgeordnete fordern mehr Kontrolle - und einen Kill Switch.
---------------------------------------------
https://www.golem.de/news/nach-openai-hack-us-abgeordnete-wollen-kill-switc…
∗∗∗ Persönliche Daten geleakt: Unzählige Claude-Chats bei Google aufgetaucht ∗∗∗
---------------------------------------------
Claude-Nutzer können Links zu ihren Chats mit anderen Personen teilen. Die Unterhaltungen wurden bis vor kurzem aber auch bei Google gelistet.
---------------------------------------------
https://www.golem.de/news/persoenliche-daten-geleakt-unzaehlige-claude-chat…
∗∗∗ NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework ∗∗∗
---------------------------------------------
NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents.The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, ..
---------------------------------------------
https://thehackernews.com/2026/07/nvidia-forms-37-member-open-secure-ai.html
∗∗∗ AI-found bugs arent proving any easier to exploit despite the hype ∗∗∗
---------------------------------------------
VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage
---------------------------------------------
https://www.theregister.com/security/2026/07/28/ai-found-bugs-arent-proving…
∗∗∗ Angriffe auf FortiOS und Arista VeloCloud beobachtet ∗∗∗
---------------------------------------------
Die IT-Sicherheitsbehörde CISA meldet Angriffe auf Sicherheitslücken in Fortinet FortiOS sowie Arista VeloCloud.
---------------------------------------------
https://www.heise.de/news/Angriffe-auf-FortiOS-und-Arista-VeloCloud-beobach…
∗∗∗ Neobank Revolut: Angeblich 75 Millionen Datensätze im Untergrund angeboten ∗∗∗
---------------------------------------------
Ein Krimineller bietet im digitalen Untergrund eine Datenbank mit 75 Millionen Einträgen an, die von der Neobank Revolut stammen sollen.
---------------------------------------------
https://www.heise.de/news/Neobank-Revolut-Angeblich-75-Millionen-Datensaetz…
∗∗∗ Lücke: Claude Cowork entkommt macOS-Sandbox ∗∗∗
---------------------------------------------
Die Nutzung von KI-Agenten direkt auf dem Rechner kann Gefahren mit sich bringen. Das zeigt eine soeben entdecktes Sicherheitsloch in Claude Cowork für den Mac.
---------------------------------------------
https://www.heise.de/news/Luecke-Claude-Cowork-entkommt-macOS-Sandbox-11379…
∗∗∗ IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains ∗∗∗
---------------------------------------------
Talos IRs Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses.
---------------------------------------------
https://blog.talosintelligence.com/ir-trends-q2-2026/
∗∗∗ Zahlreiche Sicherheitslücken gefixt: Schnell auf iOS 26.6 und Co. aktualisieren ∗∗∗
---------------------------------------------
Apple hat nun seine Sicherheitshinweise zu den neuen Betriebssystemen publiziert. Es gibt erneut enorm viele Fixes – vermutlich auch dank KI.
---------------------------------------------
https://heise.de/-11379576
∗∗∗ Verschiedene Attacken auf Progress LoadMaster möglich ∗∗∗
---------------------------------------------
Die Load-Balancing- und Cluster-Managementlösung LoadMaster ist verwundbar. Die Entwickler haben nun Sicherheitslücken geschlossen.
---------------------------------------------
https://heise.de/-11380070
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 24-07-2026 18:00 − Montag 27-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ SourTrade: Malvertising-Malware im Browser kompiliert ∗∗∗
---------------------------------------------
IT-Forscher haben eine mittels Malvertising verteilte Malware entdeckt. Die wird erst im Browser zusammengebaut.
---------------------------------------------
https://www.heise.de/news/SourTrade-Malvertising-Malware-im-Browser-kompili…
∗∗∗ How the Gentlemen Ransomware Group Built a Multi-Region Attack Machine in H1 2026 ∗∗∗
---------------------------------------------
Ransomware’s biggest story in the first half of 2026 was not only about established names maintaining dominance. A newer player, The Gentlemen ransomware group, emerged as one of the most geographically active operators, expanding its reach across Europe, Asia-Pacific, the Middle East & Africa, and the Americas.
---------------------------------------------
https://thecyberexpress.com/the-gentlemen-ransomware-group/
∗∗∗ ShinyHunters data leaks fuel $2,000 sextortion email scam ∗∗∗
---------------------------------------------
Threat actors are using email addresses exposed in data breaches leaked by the ShinyHunters extortion group to send sextortion emails demanding $2,000 in Bitcoin.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/shinyhunters-data-leaks-fuel…
∗∗∗ Landes-Geheimdienstchef Kramer: OpenAI-Hackerangriff war "kein Skynet-Szenario" ∗∗∗
---------------------------------------------
Nach dem Hackerangriff auf Hugging Face mahnt der Thüringer Verfassungsschutz zur Besonnenheit. Er forderte aber ein KI-Frühwarnsystem für die Sicherheitsbehörden.
---------------------------------------------
https://www.golem.de/news/landes-geheimdienstchef-kramer-openai-hackerangri…
∗∗∗ Alle Daten gelöscht: US-Bürger wegen Nutzung einer GrapheneOS-Funktion angeklagt ∗∗∗
---------------------------------------------
Ein Mann wurde bei der Einreise in die USA durchsucht. Er trickste die Grenzpolizei mit einem Duress-Passwort aus – und muss sich dafür nun vor Gericht verantworten.
---------------------------------------------
https://www.golem.de/news/alle-daten-geloescht-us-buerger-wegen-nutzung-ein…
∗∗∗ Zugangsdaten im Visier: Hacker beim Datenklau über Hotel-WLANs erwischt ∗∗∗
---------------------------------------------
Eine russische Hackergruppe kapert wohl WLAN-Ausrüstung in Einrichtungen, um systematisch Microsoft-Zugangsdaten abzugreifen.
---------------------------------------------
https://www.golem.de/news/zugangsdaten-im-visier-hacker-beim-datenklau-uebe…
∗∗∗ Datenpanne in Gebets-App: Sicherheitslücke in "Gottes Tech-Stack" aufgedeckt ∗∗∗
---------------------------------------------
Eine Forscherin hat die offizielle Gebets-App des Papstes untersucht. "Gottes Tech-Stack" erwies sich als angreifbar und leakte Nutzerdaten.
---------------------------------------------
https://www.golem.de/news/700-000-nutzer-betroffen-suendhaftes-datenleck-be…
∗∗∗ BlueNoroff Zoom Phishing Kit Profiles Crypto Wallets Before Malware Delivery ∗∗∗
---------------------------------------------
The North Korean threat actors behind the ClickFix-style campaigns that employ typosquatted Zoom and Microsoft Teams domains have been found to operate an active phishing kit to impersonate the videoconferencing platforms in social engineering campaigns designed to deliver malware.
---------------------------------------------
https://thehackernews.com/2026/07/bluenoroff-zoom-phishing-kit-profiles.html
∗∗∗ DevMan RaaS Portal Centralizes Payload Builds, Victim Management, and Affiliate Payouts ∗∗∗
---------------------------------------------
The operators of the DevMan ransomware-as-a-service (RaaS) scheme are maintaining a dedicated web platform that offers affiliates the ability to build payloads, oversee earnings, and manage various aspects related to victims. Swiss cybersecurity company PRODAFT is tracking the centrally administered RaaS operation under the name Funky Mantis.
---------------------------------------------
https://thehackernews.com/2026/07/devman-raas-portal-centralizes-payload.ht…
∗∗∗ Operation BlueDash Deploys Level RMM and ScreenConnect via Fake Teams Update ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a Microsoft Teams-themed phishing campaign that employs "secure document" lures to deliver legitimate remote monitoring and management (RMM) tools.
---------------------------------------------
https://thehackernews.com/2026/07/operation-bluedash-deploys-level-rmm.html
∗∗∗ Microsoft Defender for Endpoint leaves some Linux boxes defenseless after update ∗∗∗
---------------------------------------------
One bug disabled the security service on restart, another blocked installation on hardened RHEL systems
---------------------------------------------
https://www.theregister.com/patches/2026/07/27/microsoft-defender-for-endpo…
∗∗∗ Helpdesk Hijackers: Teams Vishing, Quick Assist, and GoGRPC Backdoor ∗∗∗
---------------------------------------------
Zscaler ThreatLabz has been tracking attacks from a threat actor that is likely an initial access broker for ransomware attacks since January 2026. The threat actor targets organizations by leveraging vishing techniques through Microsoft Teams and deploying a variety of tools including a Go-based backdoor that we named GoGRPC. ThreatLabz has identified at least four variants of GoGPRC that we named Lep, Giver, Pet, and Kind. In some instances, the threat actor has deployed additional malware tools that include a backdoor that we named BlindDoor, a Go-based reverse SOCKS proxy we named RevSocket, a Python-based reverse SOCKS proxy we named PyGRPC, and two other tools we named S3Siphon and RSOX.
---------------------------------------------
https://www.zscaler.com/blogs/security-research/helpdesk-hijackers-teams-vi…
∗∗∗ Geburtstagsgeschenk von Rituals? Vorsicht vor dieser Abofalle! ∗∗∗
---------------------------------------------
Viele bekannte Marken überraschen ihre Kund:innen zum Geburtstag mit kleinen Geschenken. Genau dieses Vertrauen machen sich Kriminelle zunutze: Sie verschicken gefälschte E-Mails im Namen von Rituals und locken mit einem Geschenkset. In Wahrheit landen die Opfer in einer teuren Abofalle.
---------------------------------------------
https://www.watchlist-internet.at/news/geburtstagsgeschenk-von-rituals-vors…
∗∗∗ Tenant-Übernahme möglich und drei kritische Sicherheitslücke in MS-Infrastruktur ∗∗∗
---------------------------------------------
Jeffrey Schwartz berichtet von der BlackHat 2026 in den USA, und einem speziellen Thema: Die Standard-Einstellung in Azure Automation ermöglichte eine mandantenübergreifende Identitätsübernahme. Dann gab es drei kritische Sicherheitslücken in der Infrastruktur von Microsoft (u.a. bei Bing Images), die die Ausführung von Remote-Code (RCE) ermöglichen. Kleine Nachschau zu diesen Sachverhalten.
---------------------------------------------
https://borncity.com/blog/2026/07/27/tenant-uebernahme-moeglich-und-drei-kr…
∗∗∗ Fake Corepack Site Distributes Infostealer and Proxyware to Developers ∗∗∗
---------------------------------------------
A fake corepack.org site is impersonating the Node.js tool and delivers an infostealer and proxyware to developers who download it.
---------------------------------------------
https://socket.dev/blog/fake-corepack-site-distributes-infostealer-and-prox…
∗∗∗ Project ORBITAL ∗∗∗
---------------------------------------------
The modern cyber threat landscape has seen a fundamental shift in how threat actors manage and deploy their infrastructure. Advanced persistent threats (APTs) have almost completely moved away from static command-and-control (C2) servers, opting instead to build complex, multi-layered botnets known as Operational Relay Box (ORB) networks. Project ORBITAL (which stands for Operational Relay Box Intelligence, Tracking, & Analysis Lexicon) was established as a centralised intelligence matrix to track, analyse, and ultimately help defenders disrupt this highly evasive infrastructure.
---------------------------------------------
https://blog.bushidotoken.net/2026/07/project-orbital.html
∗∗∗ Two Old Oj Flaws Chained to Trigger GitLab Remote Code Execution ∗∗∗
---------------------------------------------
A newly disclosed GitLab vulnerability has revealed how two long-standing memory-safety flaws in the widely used Ruby JSON parsing library, Oj, can be combined to achieve remote code execution on default GitLab installations.
---------------------------------------------
https://thecyberexpress.com/gitlab-vulnerability-oj-parser-rce/
=====================
= Vulnerabilities =
=====================
∗∗∗ Angreifer können MongoDB abstürzen lassen und Daten manipulieren ∗∗∗
---------------------------------------------
Die MongoDB-Entwickler haben in aktuellen Versionen zahlreiche Sicherheitslücken geschlossen. Bislang gibt es keine Hinweise auf laufende Attacken.
---------------------------------------------
https://heise.de/-11378494
∗∗∗ Sicherheitsupdate: Dateitransferlösung MOVEit ist verwundbar ∗∗∗
---------------------------------------------
Admins, die in Unternehmen für den Dateitransfer MOVEit nutzen, sollten die Software zeitnah auf den aktuellen Stand bringen. Geschieht das nicht, kann im schlimmsten Fall Schadcode auf PCs gelangen. Die Entwickler haben in einer neuen Version mehrere Schwachstellen geschlossen.
---------------------------------------------
https://heise.de/-11379295
∗∗∗ LWN Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1085554/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/