=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 09-07-2026 18:00 − Freitag 10-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Unpatched XRING Flaw in XQUIC Lets Remote Clients Crash HTTP/3 Servers ∗∗∗
---------------------------------------------
A single wrong variable on one line in XQUIC, Alibabas QUIC and HTTP/3 library, lets any remote client crash the server with a short burst of completely legal traffic. There is no patch. FoxIO researcher Sébastien Féry disclosed the flaw on July 8 and nicknamed it XRING. He says it needs no login and no malformed packets: about 260 bytes of ordinary QPACK traffic takes the server process down. [..] FoxIO demonstrated a crash, not code execution, and reported no exploitation in the wild. [..] XRING is the latest in a string of remote crashes in HTTP/2 and HTTP/3 stacks.
---------------------------------------------
https://thehackernews.com/2026/07/unpatched-xring-flaw-in-xquic-lets.html
∗∗∗ Exposed Hacker Server Reveals WP-SHELLSTORM Backdooring Thousands of WordPress Sites ∗∗∗
---------------------------------------------
A cybercrime crew left one of its own servers wide open on the internet for three weeks, and it exposed the operations inner workings: the hacking tools, the activity logs, and target lists naming more than 1.4 million websites. Far fewer were actually broken into, but the exposed files showed researchers how a mass site-hacking operation runs from the inside.
---------------------------------------------
https://thehackernews.com/2026/07/exposed-hacker-server-reveals-wp.html
∗∗∗ Software developers are the target. New trojan attacks supply chains and inflicts multifaceted damage on infected PCs ∗∗∗
---------------------------------------------
A new trojan engaging in supply chain attacks has recently come under the scrutiny of our antivirus laboratory. The malware primarily targets C++ and C# project files. This malicious sample is particularly dangerous as its payload incorporates multiple damaging features, allowing it to steal data, access clipboard content, operate as a backdoor, engage in rogue mining and also infect other files. [..] It mainly spreads over the Internet via infected executable files and Python scripts. The infection process is quite complex, so let’s examine the entire sequence phase by phase.
---------------------------------------------
https://news.drweb.com/show/?i=15276&lng=en&c=9
∗∗∗ "Comment stuffing" in an HTML phishing attachment as a mechanism for evading AI-based detection?, (Fri, Jul 10th) ∗∗∗
---------------------------------------------
Anyone who deals with phishing messages caught by basic security filters knows that most phishing samples tend to blend into one another, since only a small set of techniques and approaches keeps reappearing in them. That is precisely why it is worth pausing on the occasional message that does something a little out of the ordinary.
---------------------------------------------
https://isc.sans.edu/diary/rss/33144
∗∗∗ npm 12 Disables Install Scripts by Default to Reduce Supply Chain Risk ∗∗∗
---------------------------------------------
GitHub has officially announced the release of npm version 12 with install scripts disabled by default, along with deprecating granular access tokens (GATs) designed to bypass two-factor authentication (2FA).
---------------------------------------------
https://thehackernews.com/2026/07/npm-12-disables-install-scripts-by.html
∗∗∗ Microsoft warns customers AI will mean busier Patch Tuesdays ∗∗∗
---------------------------------------------
More patches mean more reasons to buy Redmond’s auto-patching tools
---------------------------------------------
https://www.theregister.com/security/2026/07/10/microsoft-warns-customers-a…
∗∗∗ GigaWiper: Anatomy of a destructive backdoor assembled from multiple malware ∗∗∗
---------------------------------------------
In October 2025, Microsoft Threat Intelligence identified destructive wiping activity and uncovered a sophisticated Go programming language (Golang)-based backdoor we now track as GigaWiper, a versatile implant that combines robust command-and-control (C2) capabilities with multiple destructive payloads, including disk wiping, fake ransomware, and system-level sabotage. [..] In this blog, we provide a code-level analysis of GigaWiper’s architecture.
---------------------------------------------
https://www.microsoft.com/en-us/security/blog/2026/07/09/gigawiper-anatomy-…
∗∗∗ Flying with the Flipper Zero ∗∗∗
---------------------------------------------
Why is the world so alarmed about taking the Flipper on board planes? Is it just poorly educated armchair cyber commentators of the ‘don’t use open Wi-Fi / USB juicejacking’ style of fearmongering, or is there something to it? [..] Flippers are not a threat to the safety of a flight.
---------------------------------------------
https://www.pentestpartners.com/security-blog/flying-with-the-flipper-zero/
∗∗∗ Organized Cybercrime Merging with Other Crime ∗∗∗
---------------------------------------------
In a recent report, the FBI warns that Silent Ransom Group has also begun recruiting gig workers in the victims’ area under the guise of hiring helpdesk personnel. Gig workers are people who earn money through short-term, flexible jobs rather than a traditional permanent role. They are usually paid per task, project or assignment.
---------------------------------------------
https://www.truesec.com/hub/blog/organized-cybercrime-merging-with-other-cr…
∗∗∗ Wiz in the Verizon DBIR: How AI Acceleration and Cloud Sprawl Impact Modern Defense ∗∗∗
---------------------------------------------
Verizons latest DBIR highlights how attackers are exploiting familiar weaknesses at increasing speed and scale. [..] The lesson from this year's DBIR is that familiar weaknesses remain highly effective when combined with cloud scale, interconnected trust relationships, and increasingly rapid exploitation cycles.
---------------------------------------------
https://www.wiz.io/blog/verizon-dbir-2026-ai-cloud-security
=====================
= Vulnerabilities =
=====================
∗∗∗ GitLab Patch Release: 19.1.2, 19.0.4, 18.11.7 ∗∗∗
---------------------------------------------
https://docs.gitlab.com/releases/patches/patch-release-gitlab-19-1-2-releas…
∗∗∗ LWN: Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1082272/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 08-07-2026 18:00 − Donnerstag 09-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Microsoft patches RoguePlanet Defender zero-day vulnerability ∗∗∗
---------------------------------------------
Microsoft has released a security patch to address a Defender zero-day vulnerability known as "RoguePlanet," disclosed after the June 2026 Patch Tuesday. The flaw (tracked as CVE-2026-50656) was disclosed by a security researcher using the "Nightmare Eclipse" handle as part of an ongoing dispute with Microsoft over the company's bug bounty and vulnerability disclosure practices.
---------------------------------------------
https://www.bleepingcomputer.com/news/microsoft/microsoft-patches-rogueplan…
∗∗∗ Schwachstelle in Coding-Agenten: Zugriff auf beliebige Dateien über Symlinks ∗∗∗
---------------------------------------------
In sechs großen Coding-Agenten findet sich eine Sicherheitslücke: Über ein Repository mit Schadcode können Angreifer die KI-Modelle dazu bewegen, auf beliebige Dateien zuzugreifen – auch außerhalb einer Sandbox. [..] Betroffen sind Amazon Q Developer, Anthropics Claude Code, Augment, Cursor, Google Antigravity und Windsurf. Für die meisten Tools existiert inzwischen ein Update, das die Schwachstelle behebt, aber für Augment und Windsurf existieren noch keine Patches.
---------------------------------------------
https://heise.de/-11358849
∗∗∗ IonStack part II: GhostLock, a stack-UAF that has existed in ALL Linux distributions for 15 years ∗∗∗
---------------------------------------------
GhostLock (CVE-2026-43499) is a Linux kernel vulnerability found by VEGA that exists in every major distribution since 2011. Triggering the bug does not require any special kernel config or privilege. By turning it into a 97% stable privilege escalation and container escape, Google has rewarded us $92,337 in kernelCTF. This writeup covers the technical details of the exploit.
---------------------------------------------
https://nebusec.ai/research/ionstack-part-2/
∗∗∗ Entra passkey enrollment vishing targets Microsoft 365 users ∗∗∗
---------------------------------------------
A threat actor has been targeting organizations across multiple sectors with voice-based fake security requests that ask Microsoft 365 users to enroll a new Entra passkey.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/entra-passkey-enrollment-vis…
∗∗∗ New Forg365 phishing platform uses AI to target Microsoft 365 accounts ∗∗∗
---------------------------------------------
A new phishing-as-a-service (PhaaS) operation called Forg365 focuses on stealing Microsoft 365 accounts by combining adversary-in-the-middle (AiTM) and device code methods with AI-assisted lure generation.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-forg365-phishing-platfor…
∗∗∗ Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real Victims ∗∗∗
---------------------------------------------
Residential proxies are one of the hottest topics in cybersecurity today. Turns out, they are often not in residences, and they facilitate a wide range of criminal activity. In the simplest terms, a little piece of software in a TV, digital picture frame, or your phone might enable a company to sell access to your device’s bandwidth to their own customers. [..] Our discovery started with a single campaign: In early 2026, the actor, who we track as Lurking Lizard, fooled users into downloading a fake version of the 7-Zip archive utility.
---------------------------------------------
Fake Installers, Fake Reviews, Fake Services – Real Proxies, Real Victims
∗∗∗ GodDamn Ransomware Uses PoisonX Driver to Disable Endpoint Defenses ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a new ransomware family called GodDamn that employs the PoisonX kernel driver to neutralize security software as part of its defense evasion strategy. According to a new report published by the Threat Hunter Team from Symantec, the ransomware was first publicly spotted in the wild on May 21, 2026. It's assessed to be a rebrand of the Beast ransomware, which, in turn, was an enhanced version of Monster, a Delphi-based ransomware that surfaced in March 2022.
---------------------------------------------
https://thehackernews.com/2026/07/goddamn-ransomware-uses-poisonx-driver.ht…
∗∗∗ GitHub Copilot: Sorry Dave, I cant do that harmful thing - unless you ask me in code ∗∗∗
---------------------------------------------
t's the latest example of AI safety guardrails being bypassed. GitHub Copilot refuses harmful prompts almost always if asked in chat - like, "how to fool a breathalyzer test" or "smuggle bulk cash out of the US" - but then will write them in code 100 percent of the time if the prompt is broken into smaller steps and distributed across multiple stages of a software development workflow.
---------------------------------------------
https://www.theregister.com/security/2026/07/08/github-copilot-sorry-dave-i…
∗∗∗ Eintrag wider Willen: Wenn Unternehmen ungefragt auf dubiosen Portalen landen ∗∗∗
---------------------------------------------
Taucht das eigene Unternehmen plötzlich auf unbekannten Portalen auf, ist die Überraschung groß. Unangenehm wird es dann, wenn sich das Profil ohne Registrierung nicht löschen lässt und sich die Plattformbetreiber regelmäßig mit aufdringlichen Spam-Mails melden. Und wie war das nochmal mit dem Urheberrecht? Das Problem, dargestellt am Beispiel evepla.com.
---------------------------------------------
https://www.watchlist-internet.at/news/eintrag-wider-willen-dubiose-portale/
=====================
= Vulnerabilities =
=====================
∗∗∗ n8n: CERT-Bund veröffentlicht Warnmeldung zu kürzlich beseitigten Schwachstellen ∗∗∗
---------------------------------------------
Kritisch ist keine der jüngst gefixten Lücken in der Automatisierungslösung n8n. Dennoch betont eine Warnmeldung des BSI die hohe Update-Relevanz.
---------------------------------------------
https://heise.de/-11359656
∗∗∗ Drupal Security Advisories 2026-July-08 ∗∗∗
---------------------------------------------
https://www.drupal.org/security
∗∗∗ LWN: Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1082030/
∗∗∗ Paloalto: PAN-SA-2026-0010 Chromium: Monthly Vulnerability Update (July 2026) (Severity: HIGH) ∗∗∗
---------------------------------------------
https://security.paloaltonetworks.com/PAN-SA-2026-0010
∗∗∗ Paloalto: PAN-SA-2026-0010 Chromium and Prisma Browser: Monthly Vulnerability Update (July 2026) (Severity: HIGH) ∗∗∗
---------------------------------------------
https://security.paloaltonetworks.com/PAN-SA-2026-0010
∗∗∗ Chrome-Browser & ChromeOS LTS : Updates schließen teils kritische Lücken ∗∗∗
---------------------------------------------
https://heise.de/-11359376
∗∗∗ Wireshark 4.6.7 Fixes 12 Security Issues Across SSH, IEEE 802.11, Catapult DCT2000 and Other Protocols ∗∗∗
---------------------------------------------
https://thecyberexpress.com/wireshark-4-6-7/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 07-07-2026 18:00 − Mittwoch 08-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Accenture confirms breach after hacker offers stolen data for sale ∗∗∗
---------------------------------------------
IT services giant Accenture has confirmed it suffered a security breach after a threat actor claimed to have stolen 35 GB of source code and other data from the company. [..] According to the threat actor, the data includes source code, RSA keys, SSH keys, Azure PAT (personal access tokens), Azure Storage access keys, and configuration files.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/accenture-confirms-breach-af…
∗∗∗ GitHub AI agent leaks private repos when asked nicely ∗∗∗
---------------------------------------------
Malicious prompters could easily trick GitHub agents into pulling data from private repositories and then leaking the information as a public comment for anyone to access, according to Noma Labs researchers who named the vulnerability GitLost. The issue exists in GitHub’s Agentic Workflows, which allow an AI agent powered by Claude or GitHub Copilot to autonomously execute tasks in GitHub Actions.
---------------------------------------------
https://www.theregister.com/security/2026/07/07/github-ai-agent-leaks-priva…
∗∗∗ „Ihr Paket liegt im Logistikzentrum!“ – Über eine Zollgebühr in die Phishing-Falle ∗∗∗
---------------------------------------------
Zwei Sätze, eine Aufforderung, eine Frist. Mehr braucht es nicht – und die Phishing-Falle ist fertig. Eine zurzeit besonders häufig gemeldete Masche nutzt den Paketdienstleister DPD als Tarnung. Da sich entsprechende Hinweise im Posteingang der Redaktion stapeln, ist es an der Zeit, die Masche erneut unter die Lupe zu nehmen.
---------------------------------------------
https://www.watchlist-internet.at/news/dpd-paket-im-logistikzentrum/
∗∗∗ Vidar Stealer Unmasked: Code Signing Abuse, Go Loaders and File Inflation ∗∗∗
---------------------------------------------
In April 2026, Unit 42 researchers identified a financially motivated campaign delivering Vidar stealer and the XMRig cryptocurrency miner to consumer and small- and medium-sized business victims worldwide. [..] We assess the operator of the campaign to be a Vidar stealer malware-as-a-service (MaaS) affiliate involved in operations targeting victims in the U.S. and European Union. This article provides a technical analysis of the campaign.
---------------------------------------------
https://unit42.paloaltonetworks.com/vidar-stealer-xmrig-miner-campaign-anal…
∗∗∗ Offene Datenbank: Nextcloud GmbH behebt potenzielles Datenleck ∗∗∗
---------------------------------------------
Daten des Unternehmens hinter der populären Kollaborationslösung standen wegen einer Fehlkonfiguration offen im Netz. Die Software ist nicht betroffen.
---------------------------------------------
https://heise.de/-11358275
=====================
= Vulnerabilities =
=====================
∗∗∗ Joomla Security Advisories (Fixed Date: 2026-07-07) ∗∗∗
---------------------------------------------
Joomla has released 12 new security advisories.
---------------------------------------------
https://developer.joomla.org/security-centre/
∗∗∗ Foxit-Entwickler schließen Schwachstellen in PDF Reader und Editor ∗∗∗
---------------------------------------------
Nicht kritisch, aber zahlreich: Aktuelle Sicherheitsupdates dichten Foxits PDF Reader und Editor gegen eine lange Lückenliste ab.
---------------------------------------------
https://www.heise.de/news/Foxit-Entwickler-schliessen-Schwachstellen-in-PDF…
∗∗∗ ILIAS: Wichtige Aktualisierungen für Lernplattform beseitigen Schwachstellen ∗∗∗
---------------------------------------------
Für die von Hochschulen, Kliniken und anderen öffentlichen Institutionen genutzte offene Lernplattform ILIAS stehen Aktualisierungen bereit. Die neuen Versionen 9.21, 10.9 und 11.2 schließen Sicherheitslücken, von denen alle früheren Ausgaben betroffen waren. Von drei Lücken geht ein hohes, von den übrigen ein mittleres Sicherheitsrisiko aus.
---------------------------------------------
https://heise.de/-11357739
∗∗∗ Juniper: 2026-07 Security Bulletin: Junos OS Evolved: A port which has been inadvertently exposed can be reached by an attacker (CVE-2026-57028) ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos…
∗∗∗ Juniper: 2026-07 Security Bulletin: Junos OS: MX Series with SPC3, SRX Series: Processing of a specifically malformed SIP invite causes a flowd crash (CVE-2026-57026) ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos…
∗∗∗ Juniper: 2026-07 Security Bulletin: Junos OS: MX Series with SPC3, SRX Series: A specifically malformed TCP packet causes a flowd crash (CVE-2026-57023) ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos…
∗∗∗ Juniper: 2026-07 Security Bulletin: Junos OS and Junos OS Evolved: Receipt of a specific SNMPv3 request results in memory leak and eventual snmpd crash (CVE-2026-33799) ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos…
∗∗∗ Juniper: 2026-07 Security Bulletin: Junos OS and Junos OS Evolved: Configuration of a specific SSH option results in mgd crash (CVE-2026-21901) ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos…
∗∗∗ Juniper: 2026-07 Security Bulletin: cRPD: Multiple vulnerabilities resolved in cRPD 26.2R1 ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-cRPD-…
∗∗∗ Juniper: 2026-07 Security Bulletin: Junos Space: Multiple vulnerabilities resolved in 26.1R1 Patch V1 Release ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos…
∗∗∗ Juniper: 2026-07 Security Bulletin: Network Director: Multiple vulnerabilities resolved in 7.1R3 release ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Netwo…
∗∗∗ Juniper: 2026-07 Security Bulletin: Junos OS Evolved: URL handling vulnerability in libfetch results in heap buffer overflow (CVE-2020-7450) ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-Junos…
∗∗∗ Juniper: 2026-07 Security Bulletin: CTPView: Multiple vulnerabilities resolved in 9.3R2-3 Release ∗∗∗
---------------------------------------------
https://supportportal.juniper.net/s/article/2026-07-Security-Bulletin-CTPVi…
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1081798/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 06-07-2026 18:00 − Dienstag 07-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Angreifer können Balkonkraftwerke aus der Ferne abschalten ∗∗∗
---------------------------------------------
Geräte des chinesischen Herstellers Hoymiles lassen sich durch eine Sicherheitslücke fernsteuern.
---------------------------------------------
https://futurezone.at/digital-life/balkonkraftwerk-sicherheitsluecke-hoymil…
∗∗∗ Air-Gapped-Systeme: Malware leitet Daten über Monitorkabel aus ∗∗∗
---------------------------------------------
Air Gapping schützt vor einer unerwünschten Datenausleitung. Ein neuartiger Angriff umgeht diesen Schutz über das Monitor-Kabel - und das ziemlich performant.
---------------------------------------------
https://www.golem.de/news/air-gapped-systeme-malware-leitet-daten-ueber-mon…
∗∗∗ Geheimdienstbericht in Kanada: Cyberoperationen im Ausland ∗∗∗
---------------------------------------------
Kanadas Nachrichtendienst führt Cyberangriffe gegen Drogenhändler, Extremisten und Cyberkriminelle durch. Ungewöhnlich ist das öffentliche Bekenntnis.
---------------------------------------------
https://www.heise.de/news/Geheimdienstbericht-in-Kanada-Cyberoperationen-im…
∗∗∗ OpenSSH bringt erstmals hybride Post-Quantum-Signaturen ∗∗∗
---------------------------------------------
OpenSSH 10.4 behebt mehrere Sicherheitslücken in SSH, SCP und SFTP. Zudem gibt es Protokollverschärfungen und experimentelle Post-Quantum-Signaturen.
---------------------------------------------
https://www.heise.de/news/OpenSSH-bringt-erstmals-hybride-Post-Quantum-Sign…
∗∗∗ Woodruff: You shouldnt trust trusted publishing ∗∗∗
---------------------------------------------
Trusted Publishing is a mechanism for establishing trust between an external machine identity (like a CI/CD workflow) and one or more projects on a package index/registry. The "trust" in "Trusted Publishing" refers to that trust relationship, and not to anything else. It is not, and cannot be, a signal for package trust or quality. You cannot use it to determine whether a package is safe or "good," and PyPI consciously stymies attempts to misuse it for that purpose by not rendering it as a "green checkmark" or anything else of the sort. Or as another framing: Trusted Publishing is just a form of authentication. It doesn't tell you anything other than that an upload was authenticated, which all uploads to PyPI are.
---------------------------------------------
https://lwn.net/Articles/1081690/
∗∗∗ Scattered Spider-Mitglied Peter Stokes durch Windows GUID identifiziert und überführt ∗∗∗
---------------------------------------------
Vor einiger Zeit wurde Peter Stokes als mutmaßliches Mitglied der Cybergang Scattered Spider in Finnland verhaftet und ist inzwischen in die USA ausgeliefert worden. Aus Gerichtsdokumenten geht nun hervor, dass die von Windows vergebene eindeutige GDID, per Telemetrie – samt weiteren Daten – an Microsoft übertragen, Stokes bei seinen Aktivitäten, die er bestmöglich verschleierte, verraten und zu seiner Identifizierung geführt hat.
---------------------------------------------
https://borncity.com/blog/2026/07/06/scattered-spider-mitglied-peter-stokes…
∗∗∗ Joomla Helix3-Lücke: Hacked by Antonkill ∗∗∗
---------------------------------------------
Kurzer Hinweis für Leute, die eine Joomla-Instanz betreiben oder eine solche Installation in ihrem Umfeld kennen. Eine Schwachstelle im Helix3-Framework von JoomShaper wird durch ein Botnetz ausgenutzt, um Joomla-Instanzen zu infizieren. Dort taucht dann die Meldung "Hacked by AntonKill" oder auch "Hacked by trenggalek6etar" auf.
---------------------------------------------
https://borncity.com/blog/2026/07/07/joomla-helix3-luecke-hacked-by-antonki…
∗∗∗ Reducing Microsoft Sentinel Costs Without Compromising Detection – Part 2: The Firewall Quest ∗∗∗
---------------------------------------------
Continuing our journey through Sentinel ingestion cost reduction, this part focuses on one of the most expensive log sources: firewalls, and more specifically, network traffic events.
---------------------------------------------
https://blog.nviso.eu/2026/07/07/reducing-microsoft-sentinel-costs-without-…
∗∗∗ UAT-7810 continues building ORB networks using new malware ∗∗∗
---------------------------------------------
Talos assesses with high confidence that UAT-7810 is a China-nexus threat actor based on the infrastructure that it provides to secondary China-nexus APTs such as UAT-5918. Open-source reporting has also illustrated overlapping tooling between UAT-5918 and UAT-7810. However, at this time, Talos considers UAT-5918 and UAT-7810 separate APT actors tasked with their own set of objectives and targets.
---------------------------------------------
https://blog.talosintelligence.com/uat-7810/
∗∗∗ Software vom BSI und Fraunhofer: Wie KI ihre eigenen Deepfakes entlarvt ∗∗∗
---------------------------------------------
Forschende vom Fraunhofer-Institut und Bundesamt für Sicherheit haben ein neues Verfahren entwickelt, um Deepfakes zu erkennen. Doch es bietet noch mehr.
---------------------------------------------
https://heise.de/-11355899
∗∗∗ Sicherheitsalbtraum Wechselrichter: Hoymiles lässt Nachbarschaften verstummen ∗∗∗
---------------------------------------------
Schwere Funkschwachstellen bei Hunderttausenden PV-Anlagen erlauben laut Forschern das Abschalten im Vorbeifahren und sogar die physische Zerstörung der Geräte.
---------------------------------------------
https://heise.de/-11357067
∗∗∗ Entra Agent ID: Protect, detect, respond ∗∗∗
---------------------------------------------
This post continues and concludes our series on Agent ID, by outlining steps that an administrator or security team can take to secure blueprints and agent identities created in their local Entra ID tenant.
---------------------------------------------
https://securitylabs.datadoghq.com/articles/agent-id-protect-detect-respond/
∗∗∗ KYC : Bypass age verification using generative video models ∗∗∗
---------------------------------------------
Historically reserved for the banking sector, the KYC (Know Your Customer) process is now making its way into many online services, driven by increasingly strict legislation on anonymity and age verification. To comply, platforms deploy significant measures aimed at guaranteeing the "proof of life" of the user behind their webcam or smartphone. However, the meteoric rise of generative video AI models completely reshuffles the deck, offering attackers formidable and accessible tools to fool these systems. The French PVID framework aims to counter this new threat.
---------------------------------------------
https://www.synacktiv.com/en/publications/kyc-bypass-age-verification-using…
∗∗∗ Phishing poses as big-brand job interview to steal Google accounts ∗∗∗
---------------------------------------------
A phishing campaign is impersonating more than 30 well-known brands, including Adobe, Netflix, Coca-Cola, and OpenAI, in fake job interviews to steal Google account credentials from marketing professionals.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/phishing-poses-as-big-brand-…
=====================
= Vulnerabilities =
=====================
∗∗∗ BeyondTrust warns of critical flaws in remote access software ∗∗∗
---------------------------------------------
BeyondTrust warned customers to patch two critical security flaws in its Remote Support (RS) and Privileged Remote Access (PRA) software that could allow attackers to bypass authentication.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/beyondtrust-warns-of-critica…
∗∗∗ Tenda firmware (multiple versions) contains hidden authentication backdoor ∗∗∗
---------------------------------------------
Several versions of Tenda firmware contain an undocumented authentication backdoor that grants administrative access to the devices' web management interfaces. An attacker can expoit this vulnerability, tracked as CVE-2026-11405, to bypass the password verification process and obtain full administrative control without valid credentials.
---------------------------------------------
https://kb.cert.org/vuls/id/213560
∗∗∗ Samsung-Sicherheitsupdate: Juli-Patches für Galaxy-Geräte ∗∗∗
---------------------------------------------
Samsung hat sein Security-Bulletin für Juli 2026 veröffentlicht und verteilt wichtige Sicherheitspatches vor allem für die Topmodelle der Galaxy-Reihe.
---------------------------------------------
https://www.heise.de/news/Samsung-Sicherheitsupdate-Juli-Patches-fuer-Galax…
∗∗∗ Zimbra Collaboration Suite: Kritische Lücke macht Classic Web Client angreifbar ∗∗∗
---------------------------------------------
Die Zimbra-Entwickler haben im Zuge eines Patch Release Updates auf Version 10.1.19 der Zimbra Collaboration Suite (ZCS) auf ein mögliches Sicherheitsrisiko aufmerksam gemacht. Laut Patch Release Notes kann die zugrundeliegende Schwachstelle ausschließlich über die Komponente Classic Web Client missbraucht werden, wird in diesem Kontext allerdings als „kritisch“ bezeichnet.
---------------------------------------------
https://www.heise.de/news/Zimbra-Collaboration-Suite-Kritische-Luecke-macht…
∗∗∗ Cloudsysteme gefährdet: 16 Jahre alte KVM-Lücke ermöglicht VM-Ausbruch unter Linux ∗∗∗
---------------------------------------------
Eine seit 2010 bestehende Lücke im KVM-Code des Linux-Kernels gefährdet unter anderem Cloudsysteme. Angreifer können damit VM-Hosts kapern.
---------------------------------------------
https://www.golem.de/news/cloudsysteme-gefaehrdet-16-jahre-alte-kvm-luecke-…
∗∗∗ LWN Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1081644/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 03-07-2026 18:00 − Montag 06-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Sicherheitswarnungen: Node.js will KI-Flut mit KI bekämpfen ∗∗∗
---------------------------------------------
In der Node.js-Community ist eine Diskussion darüber entstanden, wie sie weiter mit der Vielzahl an LLM-generierten Sicherheitsmeldungen verfahren soll.
---------------------------------------------
https://www.heise.de/news/Sicherheitswarnungen-Node-js-will-KI-Flut-mit-KI-…
∗∗∗ WhatsApp-Benutzernamen wecken Befürchtungen an möglichem Identitätsdiebstahl ∗∗∗
---------------------------------------------
Betrüger könnten WhatsApp-Benutzernamen bekannter Personen zu kriminellen Zwecken missbrauchen, warnen Sicherheitsexperten. Reservierungen sind bereits möglich.
---------------------------------------------
https://heise.de/-11354304
∗∗∗ When checking the URL isn’t enough: a Device Code Phishing attack via a Microsoft website ∗∗∗
---------------------------------------------
The OAuth 2.0 Device Authorization Grant specification was designed to streamline authentication for Smart TVs, IoT devices, and printers. Today, threat actors are weaponizing it.
---------------------------------------------
https://securelist.com/microsoft-device-code-phishing-attack/120350/
∗∗∗ SkillCloak Lets Malicious AI Agent Skills Evade Static Scanners with Self-Extracting Packing ∗∗∗
---------------------------------------------
Scanners meant to catch malicious add-on "skills" for AI coding agents can be fooled by a few simple changes that leave the malware working, according to a new study from researchers at the Hong Kong University of Science and Technology. Their strongest trick slipped past every scanner tested more than 90% of the time, and the same team built a runtime checker that catches most of the disguised skills the scanners miss.
---------------------------------------------
https://thehackernews.com/2026/07/new-skillcloak-technique-lets-malicious.h…
∗∗∗ Opera GX Flaw Let Malicious Sites Auto-Install Mods to Steal Data From Visited Pages ∗∗∗
---------------------------------------------
Researchers found a flaw in Opera GX, the gaming-focused version of the Opera browser, that let a malicious website silently install a browser add-on and use it to lift specific data from the pages a victim visits.In a proof of concept, they reconstructed a signed-in users full Gmail address from a single visit, with no click. [..] The fix shipped in Opera GX version 130.0.5847.89, so anyone on a current build is already covered; you can confirm yours at opera://about. There is no CVE.
---------------------------------------------
https://thehackernews.com/2026/07/opera-gx-flaw-let-malicious-sites-auto.ht…
∗∗∗ PDF-Abo-Falle: Wenn aus 99 Cent ein teures Abo wird ∗∗∗
---------------------------------------------
Wer eine PDF-Datei schnell online bearbeiten möchte, stößt auf zahlreiche Dienste, die kostenlos oder besonders günstig wirken. Nach der Bearbeitung wird häufig lediglich ein kleiner Betrag von 99 Cent für den Download verlangt. Was viele nicht bemerken: Im Hintergrund wird oft ein teures Abo abgeschlossen.
---------------------------------------------
https://www.watchlist-internet.at/news/pdf-abo-falle/
∗∗∗ AI Used in Ransomware Attack ∗∗∗
---------------------------------------------
Using AI to automate part or all of the attack chain is also more of an evolution than a revolution in ransomware. [..] Nevertheless, the attack shows how the use of AI can lead to faster, if still unsophisticated, attacks that give victims less time to react.
---------------------------------------------
https://www.truesec.com/hub/blog/ai-used-in-ransomware-attack
=====================
= Vulnerabilities =
=====================
∗∗∗ OPNsense-Update beseitigt kritische Rootlücke und weitere Sicherheitsrisiken ∗∗∗
---------------------------------------------
Die kürzlich erschienenen Versionen 26.1.11 und 26.4.1(p1) von OPNsense, einer quelloffenen Firewall- und Routing-Plattform auf FreeBSD-Basis, bringen Sicherheitsfixes mit. Unter den geschlossenen Lücken befindet sich auch eine kritische: CVE-2026-57155 (CVSS-Score 9.9 von 10.0) hätte unter bestimmten Voraussetzungen zur Rechteausweitung und letztlich zur kompletten Firewall-Übernahme missbraucht werden können.
---------------------------------------------
https://www.heise.de/news/OPNsense-Update-beseitigt-kritische-Rootluecke-un…
∗∗∗ HestiaCP Admin Takeover & RCE ∗∗∗
---------------------------------------------
A low privileged user in HestiaCP can exploit a Broken Authorisation flaw to takeover Admin accounts. [..] A patch can be found here. This currently needs to be applied manually until HestiaCP decide to create a release. CVE-2026-12196
---------------------------------------------
https://projectblack.io/blog/hestiacp-admin-takeover-rce/
∗∗∗ Dell: DSA-2026-278: Security Update for Dell PowerProtect Data Domain Multiple Vulnerabilities ∗∗∗
---------------------------------------------
https://www.dell.com/support/kbdoc/de-de/000481268/dsa-2026-278-security-up…
∗∗∗ Coolify: Authenticated RCE via SHELL_SAFE_COMMAND_PATTERN regression → host root ∗∗∗
---------------------------------------------
https://github.com/coollabsio/coolify/security/advisories/GHSA-chg4-63hm-xv…
∗∗∗ LWN: Security updates for Monday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1081495/
∗∗∗ Roundcube: Security updates 1.6.17 and 1.7.2 released ∗∗∗
---------------------------------------------
https://roundcube.net/news/2026/07/05/security-updates-1.6.17-and-1.7.2
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Donnerstag 02-07-2026 18:00 − Freitag 03-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Google Disrupts NetNut Residential Proxy Network Spanning 2 Million Home Devices ∗∗∗
---------------------------------------------
Google has significantly degraded NetNut, one of the biggest networks that turns home devices into rented relays for other people's traffic.
---------------------------------------------
https://thehackernews.com/2026/07/google-disrupts-netnut-residential.html
∗∗∗ Ransomware Groups Turn to Citrix Bleed 2, BYOVD, and Supply Chain Credentials ∗∗∗
---------------------------------------------
Threat actors associated with the Anubis ransomware operation have been observed exploiting the Citrix Bleed 2 (CVE-2025-5777) vulnerability to obtain initial access.
---------------------------------------------
https://thehackernews.com/2026/07/ransomware-groups-turn-to-citrix-bleed.ht…
∗∗∗ Armored Likho Targets Government Agencies, Power Sector with BusySnake Stealer ∗∗∗
---------------------------------------------
A previously undocumented threat actor known as Armored Likho has been attributed to cyber attacks targeting government agencies and the electric power sector across Russia, Brazil, and Kazakhstan.
---------------------------------------------
https://thehackernews.com/2026/07/armored-likho-targets-government.html
∗∗∗ Indirect Prompt Injection in Web Content Targets AI Agents ∗∗∗
---------------------------------------------
AI agents are increasingly changing how users interact with web content, making the content itself a growing attack surface for threat actors. Just as a human user can be socially engineered through phishing, AI agents are also susceptible to similar attacks. Indirect prompt injection (IPI) is an example of these types of attacks that embed malicious instructions in the content retrieved by an AI agent (websites, documents, email, etc.) to influence the agent’s reasoning during task execution. Zscaler ThreatLabz has observed malicious websites that impersonate legitimate services and use IPI to manipulate AI-driven workflows.
---------------------------------------------
https://www.zscaler.com/blogs/security-research/indirect-prompt-injection-w…
∗∗∗ Fake Google and Cloudflare verification pages spread multiple malware families ∗∗∗
---------------------------------------------
ClickFix attacks, which trick people into running malicious commands themselves, continue to evolve. This latest campaign uses fake Google and Cloudflare verification pages to convince victims to infect their own devices.
---------------------------------------------
https://www.malwarebytes.com/blog/threat-intel/2026/07/fake-google-and-clou…
∗∗∗ The Gentlemen ransomware: what you need to know ∗∗∗
---------------------------------------------
Despite the impeccably polite name, there is nothing polite or refined about this particular gang of cybercriminals. In little more than a year, The Gentlemen has gone from relative obscurity to becoming one of the most active ransomware operations on the planet. First surfacing in mid-2025, The Gentlemen is a ransomware-as-a-service (RaaS) operation that appears to have splintered away from the notorious Qilin ransomware group.
---------------------------------------------
https://www.fortra.com/blog/gentlemen-ransomware-what-you-need-know
∗∗∗ It’s 37oC, And All We Can Think About Is ColdFusion (Adobe ColdFusion Security Bulletin APSB26-68 CVE Bonanza) ∗∗∗
---------------------------------------------
We’re back, melting - we’ve tried shouting, screaming, and throwing things at the Sun, and it is just not working.
---------------------------------------------
https://labs.watchtowr.com/its-37oc-and-all-we-can-think-about-is-coldfusio…
∗∗∗ Mitglied im Sonderausschuss zu Pegasus: EU-Abgeordneter mit Spyware attackiert ∗∗∗
---------------------------------------------
Vor Jahren hat das Europaparlament Angriffe mit der Pegasus-Spyware in der EU untersucht. Ein stellvertretendes Ausschussmitglied wurde da selbst angegriffen.
---------------------------------------------
https://heise.de/-11352514
∗∗∗ How GitHub used secret scanning to reach inbox zero ∗∗∗
---------------------------------------------
GitHub had 20,000+ secret scanning alerts across 15,000 repositories. Here’s how we separated signal from noise, built remediation workflows, and reached inbox zero in nine months.
---------------------------------------------
https://github.blog/security/application-security/how-github-used-secret-sc…
=====================
= Vulnerabilities =
=====================
∗∗∗ Behörde warnt: Microsoft-Sharepoint-Server werden attackiert ∗∗∗
---------------------------------------------
Angreifer nutzen eine gefährliche Sicherheitslücke in Microsoft Sharepoint aus, um Schadcode einzuschleusen. Admins sollten handeln.
---------------------------------------------
https://www.golem.de/news/behoerde-warnt-microsoft-sharepoint-server-werden…
∗∗∗ Jetzt updaten: Kritische Lücken in Ubiquiti UniFi erlauben Remote-Angriffe ∗∗∗
---------------------------------------------
Mehrere Produkte aus Ubiquitis UniFi-Ökosystem sind von teils kritischen Lücken betroffen. Admins sollten die abgesicherten Versionen zügig einspielen.
---------------------------------------------
https://www.heise.de/news/Jetzt-updaten-Kritische-Luecken-in-Ubiquiti-UniFi…
∗∗∗ Angriff per USB-Stick: KI findet gefährliche Lücke in populärem FatFs-Treiber ∗∗∗
---------------------------------------------
Das bloße Anschließen eines USB-Sticks reicht aus, um auf vielen Embedded- und IoT-Geräten Schadcode einzuschleusen. Einen Patch gibt es bisher nicht. (Sicherheitslücke, Speichermedien)
---------------------------------------------
https://www.golem.de/news/angriff-per-usb-stick-ki-findet-gefaehrliche-luec…
∗∗∗ LWN Security updates for Friday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1081187/
∗∗∗ NCSC-2026-0219 [1.00] [M/H] Kwetsbaarheden verholpen in GitHub Enterprise Server ∗∗∗
---------------------------------------------
https://advisories.ncsc.nl/advisory?id=NCSC-2026-0219
∗∗∗ NCSC-2026-0220 [1.00] [M/H] Kwetsbaarheden verholpen in Rancher door Rancher Labs ∗∗∗
---------------------------------------------
https://advisories.ncsc.nl/advisory?id=NCSC-2026-0220
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Mittwoch 01-07-2026 18:00 − Donnerstag 02-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ Cisco finally confirms attackers exploiting Unified CM flaw ∗∗∗
---------------------------------------------
Cisco confirmed that attackers are now exploiting a Unified Communications Manager (Unified CM) vulnerability patched in early June.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cisco-finally-confirms-attac…
∗∗∗ 6 security settings every GitHub maintainer should enable this week ∗∗∗
---------------------------------------------
These six free settings will not make your project unhackable. Nothing will. What they will do is close the easy doors. Turn these on, and your project will be meaningfully harder to attack than it was before.
---------------------------------------------
https://github.blog/security/6-security-settings-every-github-maintainer-sh…
∗∗∗ Ransomware im Anmarsch: Hacker greifen mit fieser Interpol-Masche an ∗∗∗
---------------------------------------------
Angreifer geben sich bei Unternehmen als Personal von Interpol aus und ködern mit angeblichen Beweismitteln. Doch stattdessen gibt es Ransomware.
---------------------------------------------
https://www.golem.de/news/ransomware-im-anmarsch-hacker-greifen-mit-fieser-…
∗∗∗ Falsche Rechnungen und Chatpartner bei ZumDaten, MichVerlieben & Co. ∗∗∗
---------------------------------------------
Eine Rechnung über mehrere hundert Euro von einer Datingplattform, bei der Sie nie ein Konto angelegt haben? Genau das berichten derzeit zahlreiche Betroffene. Doch nicht nur Menschen, die sich nie angemeldet haben, geraten ins Visier: Auch Registrierte können durch fragwürdige Praktiken viel Geld verlieren. Was hinter den Maschen von michverlieben.com, zumdaten.com und Co. steckt – und wie Sie sich dagegen wehren können.
---------------------------------------------
https://www.watchlist-internet.at/news/falsche-zahlungsaufforderungen-von-d…
∗∗∗ New ChocoPoC malware targets researchers via trojanized PoC exploits ∗∗∗
---------------------------------------------
Multiple weaponized proof-of-concept (PoC) exploits on GitHub were found delivering a Python-based remote access trojan (RAT) named ChocoPoC that can execute commands and steal sensitive data in a campaign believed to target cybersecurity researchers.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-chocopoc-malware-targets…
∗∗∗ Medtronic notifies customers impacted by ShinyHunters data breach ∗∗∗
---------------------------------------------
Healthcare device firm Medtronic is notifying affected customers about a data breach that exposed their personal data to an unauthorized third party.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/medtronic-notifies-customers…
∗∗∗ Opera rolls out Paste Protect feature to fight ClickFix attacks ∗∗∗
---------------------------------------------
Opera has introduced Paste Protect, a security feature designed to block ClickFix-style attacks that trick users into executing malicious commands through social engineering.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/opera-rolls-out-paste-protec…
∗∗∗ VEIL#DROP Malware Chain Uses Blogger Platform to Deliver PureLogs Stealer ∗∗∗
---------------------------------------------
Cybersecurity researchers have flagged a new multi-stage malware delivery attack chain that uses social engineering and Blogger pages to deliver an information stealer called PureLogs.
---------------------------------------------
https://thehackernews.com/2026/07/veildrop-malware-chain-uses-blogger.html
∗∗∗ Unpatched Argo CD Repo-Server Flaw Could Let Attackers Take Over Kubernetes Clusters ∗∗∗
---------------------------------------------
Argo CD, a widely used tool for deploying software to Kubernetes, has an unpatched flaw in its repo-server component that lets an unauthenticated attacker run code, provided they can reach the component's internal network port. Synacktiv, which found the bug, says it can lead to a full cluster takeover. There is no fix and no CVE. The firm says it reported the flaw to Argo CD's maintainers in January 2025; roughly eighteen months later, it remains unpatched, so it published the details to warn users.
---------------------------------------------
https://thehackernews.com/2026/07/unpatched-argo-cd-repo-server-flaw.html
∗∗∗ FortiBleed Credential Theft Linked to INC and Lynx Ransomware Operations ∗∗∗
---------------------------------------------
The recently discovered financially-motivated FortiBleed campaign has been attributed to INC and Lynx ransomware operations, indicating that the verified, stolen credentials were intended for follow-on intrusions.
---------------------------------------------
https://thehackernews.com/2026/07/fortibleed-credential-theft-linked-to.html
∗∗∗ Fehler in „E-Mail-Adresse verbergen“ von Apple weiter ohne Fix ∗∗∗
---------------------------------------------
„Hide my E-Mail“ oder „E-Mail-Adresse verbergen“ soll eigentlich User vor Spam und Co. schützen. Es gibt aber eine Lücke. Die Entdecker warten weiter auf Apple.
---------------------------------------------
https://heise.de/-11351055
∗∗∗ PamStealer: a Rust-based macOS infostealer that validates credentials through PAM ∗∗∗
---------------------------------------------
Jamf Threat Labs investigates PamStealer, a macOS infostealer disguised as the legitimate Maccy clipboard manager that uses a two-stage attack chain to silently harvest data and clipboard contents while evading detection.
---------------------------------------------
https://www.jamf.com/blog/pamstealer-macos-infostealer-applescript-rust/
=====================
= Vulnerabilities =
=====================
∗∗∗ WinRAR flaw could allow attackers to take control of your computer ∗∗∗
---------------------------------------------
A new WinRAR update fixes a serious security flaw, but without automatic updates many users could miss the patch.
---------------------------------------------
https://www.malwarebytes.com/blog/news/2026/07/winrar-flaw-could-allow-atta…
∗∗∗ Schwachstellen in Synology MailPlus Server lassen Angreifer passieren ∗∗∗
---------------------------------------------
Netzwerkspeicher von Synology mit MailPlus Server sind attackierbar. Ein Sicherheitspatch schafft Abhilfe.
---------------------------------------------
https://heise.de/-11351331
∗∗∗ ClamAV Vulnerabilities Affecting Cisco Products: July 2026 ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Cisco Catalyst Center Arbitrary File Read Vulnerability ∗∗∗
---------------------------------------------
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdviso…
∗∗∗ Drupal Security Advisories 2026-July-01 ∗∗∗
---------------------------------------------
https://www.drupal.org/security
∗∗∗ SVD-2026-0701: Third-Party Package Updates in Python for Scientific Computing - July 2026 ∗∗∗
---------------------------------------------
https://advisory.splunk.com//advisories/SVD-2026-0701
∗∗∗ LWN Security updates for Thursday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1080956/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Dienstag 30-06-2026 18:00 − Mittwoch 01-07-2026 18:00
Handler: Michael Schlagenhaufer
Co-Handler: Guenes Holler
=====================
= News =
=====================
∗∗∗ CitrixBleed To Infinity And Beyond (Citrix NetScaler Pre-Auth Memory Overread CVE-2026-8451) ∗∗∗
---------------------------------------------
For those that don’t start violently wretching when the phrase “Citrix NetScaler” is uttered, we have another word to whisper: “CitrixBleed”. As many know, the term CitrixBleed now refers to not a single vulnerability, but an entire class of Memory Disclosure-esque vulnerabilities in Citrix NetScaler devices, many of which have played roles in breaches and incidents in recent memory. [..] We’ve given up counting the numbers, and so we’ve decided to call this vulnerability “CitrixBleed To Infinity And Beyond”.
---------------------------------------------
https://labs.watchtowr.com/citrixbleed-to-infinity-and-beyond-citrix-netsca…
∗∗∗ Over 900 Oracle E-Business instances exposed to ongoing attacks ∗∗∗
---------------------------------------------
Over 900 Oracle E-Business Suite (EBS) instances have been found exposed online amid ongoing attacks exploiting a critical security flaw.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/over-900-oracle-e-business-i…
∗∗∗ The SOC Files: ScreenConnect masked as freeware. An inside look at a large-scale campaign ∗∗∗
---------------------------------------------
Kaspersky experts have uncovered a malicious network infrastructure for delivering AsyncRAT. The Trojan is dropped via compromised ScreenConnect software. In this post, we break down the infection chain and analyze the C2 infrastructure.
---------------------------------------------
https://securelist.com/tr/the-soc-files-screenconnect-campaign-with-asyncra…
∗∗∗ Microsoft Warns Poisoned MCP Tool Descriptions Can Make AI Agents Leak Data ∗∗∗
---------------------------------------------
New Microsoft research shows how attackers can hijack AI agents that act on a users behalf, using nothing more than a poisoned tool description to make the agent quietly hand over company data to an outsider.The trick is that the agent never breaks a rule. Every step looks routine, so in a default setup no alarm may fire.
---------------------------------------------
https://thehackernews.com/2026/06/microsoft-warns-poisoned-mcp-tool.html
∗∗∗ RustDuck Botnet Rebuilds in Rust to Hijack Routers and Servers for DDoS ∗∗∗
---------------------------------------------
A new two-stage malware family called RustDuck is hijacking home routers, IP cameras, Android boxes, and poorly secured servers, then stitching them into a network built to knock websites and online services offline. [..] RustDuck does not lean on a single clever trick. It sprays a mix of old, well-known weaknesses and hopes one sticks. The first is the oldest in the book: devices left on the internet with weak or default passwords on their remote-login services (Telnet and SSH). Guess the password, walk in.
---------------------------------------------
https://thehackernews.com/2026/06/rustduck-botnet-rebuilds-in-rust-to.html
∗∗∗ Phantom Squatting: AI-Hallucinated Domains as a Software Supply Chain Vector ∗∗∗
---------------------------------------------
Unit 42 researchers found that large language models (LLMs) consistently hallucinate web domains for legitimate brands. Adversaries are actively weaponizing this vector by registering these nonexistent domains to intercept traffic generated by AI systems. We call this phenomenon phantom squatting, and it poses a significant risk to the software supply chain.
---------------------------------------------
https://unit42.paloaltonetworks.com/phantom-squatting-hallucinated-web-doma…
∗∗∗ ARToken: Inside an EvilTokens affiliate panel targeting Microsoft 365 ∗∗∗
---------------------------------------------
Cisco Talos identified a fully-featured phishing-as-a-service (PhaaS) operator panel, branded "ARToken," that shares infrastructure, API contracts, and operational patterns with the EvilTokens platform documented by Sekoia and Microsoft in early 2026.
---------------------------------------------
https://blog.talosintelligence.com/artoken-inside-an-eviltokens-affiliate-p…
∗∗∗ Browser-Only Ransomware: From LLM Hallucinations to a Practical Attack Technique ∗∗∗
---------------------------------------------
In this research, DeepSeek connected unrealistic browser-malware concepts with a real browser capability, turning an AI-generated malware hallucination into a plausible browser-native ransomware technique. Although the generated sample was incomplete, it exposed a practical abuse path based on the File System Access API and access to photo directories.
---------------------------------------------
https://research.checkpoint.com/2026/browser-only-ransomware-from-llm-hallu…
=====================
= Vulnerabilities =
=====================
∗∗∗ Adobe patches seven max severity ColdFusion, Campaign flaws ∗∗∗
---------------------------------------------
Adobe has released security patches for seven maximum-severity vulnerabilities in the ColdFusion web app development platform and the Campaign Classic marketing automation platform.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/adobe-patches-seven-max-seve…
∗∗∗ Riesiges Update: 382 Sicherheitslücken in Google Chrome entdeckt ∗∗∗
---------------------------------------------
Die neueste Chrome-Version schließt fast 400 teils kritische Sicherheitslücken. Auch für Edge, Vivaldi und Brave dürften entsprechende Updates folgen.
---------------------------------------------
https://www.golem.de/news/riesiges-update-382-sicherheitsluecken-in-google-…
∗∗∗ Citrix Patches Six NetScaler Flaws Allowing File Read and Denial-of-Service ∗∗∗
---------------------------------------------
Citrix on Tuesday released security updates to address multiple flaws in NetScaler ADC (formerly Citrix ADC) and NetScaler Gateway (formerly Citrix Gateway) that could be exploited by an attacker to facilitate arbitrary file reads or trigger a denial-of-service (DoS) condition. CVE-2026-8451 (CVSS score: 8.8) - An insufficient input validation vulnerability leading to memory overread when NetScaler ADC or NetScaler Gateway is configured as a SAML IDP.
---------------------------------------------
https://thehackernews.com/2026/07/citrix-patches-six-netscaler-flaws.html
∗∗∗ Root-Sicherheitslücken in alternativer Router-Firmware OpenWRT geschlossen ∗∗∗
---------------------------------------------
Die OpenWRT-Entwickler haben in einer aktuellen Version unter anderem mehrere kritische Sicherheitslücken geschlossen. [..] Am gefährlichsten gilt eine „kritische“ Lücke mit einem CVSSS Score 9.9 von 10 in LuCI. Eine CVE-Nummer wurde offensichtlich bislang nicht vergeben. Voraussetzung für eine Attacke ist, dass der VPN-Dienst Tailscale installiert ist.
---------------------------------------------
https://www.heise.de/news/Root-Sicherheitsluecken-in-alternativer-Router-Fi…
∗∗∗ HCL BigFix: PC-Fernverwaltung: Man-in-the-Middle-Attacken auf HCL BigFix möglich ∗∗∗
---------------------------------------------
https://www.heise.de/news/PC-Fernverwaltung-Man-in-the-Middle-Attacken-auf-…
∗∗∗ LWN: Security updates for Wednesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1080689/
∗∗∗ mozilla: Security Vulnerabilities fixed in Thunderbird 140.12.1 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-64/
∗∗∗ mozilla: Security Vulnerabilities fixed in Thunderbird 152.0.1 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-63/
∗∗∗ Genucenter: Publish SBA-ADV-20260424-01: Genucenter Disclosure of SNMP Credentials ∗∗∗
---------------------------------------------
https://github.com/sbaresearch/advisories/commit/d78bf80a4103af68e8c17ba027…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Montag 29-06-2026 18:00 − Dienstag 30-06-2026 18:00
Handler: Guenes Holler
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Parkstrafe per SMS? Kriminelle haben es auf Kreditkartendaten abgesehen! ∗∗∗
---------------------------------------------
Alles beginnt mit einer SMS-Nachricht zu einer angeblich offenen Parkstrafe. Am Ende hat das Opfer den Kriminellen sein Auto-Kennzeichen und die Kreditkartendaten übermittelt. Eine Phishing-Falle, die klassischer nicht sein könnte. Und so funktioniert sie.
---------------------------------------------
https://www.watchlist-internet.at/news/parkstrafe-per-sms-kreditkartendaten/
∗∗∗ Sicherheitslücken ohne Ende: Flut an KI-Bug-Reports überfordert Github ∗∗∗
---------------------------------------------
Github kommt bei der Bearbeitung von Sicherheitsmeldungen nicht mehr hinterher. Es gibt wohl einen Rückstau von mehreren Wochen.
---------------------------------------------
https://www.golem.de/news/sicherheitsluecken-ohne-ende-flut-an-ki-bug-repor…
∗∗∗ Fernwartung SimpleHelp: Schwachstelle wird angegriffen ∗∗∗
---------------------------------------------
In der Fernwartungssoftware SimpleHelp klafft eine Sicherheitslücke, die die Höchstwertung beim Risiko erreicht. Sie wurde Mitte des Monats bekannt. Jetzt haben IT-Sicherheitsexperten Cyberangriffe auf das Sicherheitsleck beobachtet.
---------------------------------------------
https://heise.de/-11348620
∗∗∗ CISA: Windows BlueHammer flaw now exploited by ransomware gangs ∗∗∗
---------------------------------------------
CISA confirmed on Monday that ransomware gangs have begun exploiting a high-severity Microsoft Defender privilege escalation vulnerability that has previously been abused in zero-day attacks.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cisa-windows-bluehammer-flaw…
∗∗∗ Malicious Perplexity Chrome Extension Intercepted Searches and Address Bar Input ∗∗∗
---------------------------------------------
Microsoft has found a malicious Chrome extension that posed as the AI search engine Perplexity and quietly logged what people searched for. It routed every query and every character typed into the address bar through an attacker-controlled server before redirecting users to real results.
---------------------------------------------
https://thehackernews.com/2026/06/malicious-perplexity-chrome-extension.html
∗∗∗ Daktronics: Straßenschilder durch Controller-Lücken manipulierbar ∗∗∗
---------------------------------------------
Durch Sicherheitslücken in Daktronics-Controllern können Angreifer LED-Anzeigetafeln kompromittieren – unter anderem solche am Straßenrand.
---------------------------------------------
https://www.golem.de/news/daktronics-strassenschilder-durch-controller-luec…
∗∗∗ Enterprise Tech In, Shell Out (Progress Kemp LoadMaster Uninitialized Heap to Pre-Auth RCE CVE-2026-8037) ∗∗∗
---------------------------------------------
This time, we're looking at Progress Kemp LoadMaster, a load balancer that sits at the edge of a lot of enterprise networks. Edge appliances have a habit of becoming the way in rather than the thing keeping people out, and CVE-2026-8037 keeps that streak alive: a pre-authentication Remote Code Execution vulnerability accessible to anyone who can access the API. So, in probably a predictable turn of events, we're back doing what we do best.
---------------------------------------------
https://labs.watchtowr.com/enterprise-tech-in-shell-out-progress-kemp-loadm…
∗∗∗ Bot-Schutz: Googles reCaptcha mit Handgesten fällt auf Fotos rein ∗∗∗
---------------------------------------------
Google hat vergangene Woche angekündigt, den reCaptcha-Bot-Schutz mit Handgesten auszustatten. Das lässt sich mit Fotos aushebeln.
---------------------------------------------
https://heise.de/-11348830
∗∗∗ Longinus: 2 Boundaries in One Bug, Piercing Chrome’s Renderer and V8 Sandbox with a Single Vulnerability, CVE-2026-6307 ∗∗∗
---------------------------------------------
To understand the bug, we first need a high-level overview of TurboFan, how it inlines JS-to-Wasm calls, and how its deoptimization metadata decides what kind of value should be reconstructed after a lazy deopt. Furthermore, we need to understand how V8 heap sandbox works and why this single vulnerability allows attackers to do two things at once: 1) gain arbitrary read/write primitives in the sandbox, and 2) escape the sandbox to write outside of it.
---------------------------------------------
https://nebusec.ai/research/v8-cve-2026-6307-writeup/
∗∗∗ Unprivileged root via a use-after-free in DRM GEM change_handle (CVE-2026-46215) ∗∗∗
---------------------------------------------
A use-after-free in the DRM GEM core ioctl DRM_IOCTL_GEM_CHANGE_HANDLE lets any local user with access to a render node escalate to root. drm_gem_change_handle_ioctl() moves a GEM object from one handle to another, but it never adjusts the object’s handle_count. For a short window the object has two IDR entries while its handle count still reads 1, and a concurrent DRM_IOCTL_GEM_CLOSE on the old handle drives that count to 0 and frees the object while the new handle is still pointing at it. The dangling handle is the use-after-free.
---------------------------------------------
https://cyberstan.co.uk/drm-lpe-linux/
∗∗∗ Chrome and Firefox Extensions Posing as Free VPNs Add Clipboard Stealers via Malicious Updates ∗∗∗
---------------------------------------------
Malicious Chrome and Firefox extensions posed as free VPNs while stealing clipboard data through later extension updates.
---------------------------------------------
https://socket.dev/blog/chrome-and-firefox-extensions-free-vpns-add-clipboa…
=====================
= Vulnerabilities =
=====================
∗∗∗ iOS 26.5.2, iPadOS 26.5.2 und macOS 26.5.2: Wichtige Sicherheitsfixes wegen KI ∗∗∗
---------------------------------------------
Apple hat am Montagabend insgesamt drei Betriebssysteme aktualisiert sowie seinen Browser Safari für macOS 15 (Sequoia) und 14 (Sonoma) auf einen neuen Stand gebracht. Systeme und Browser enthalten keine bekannten Neuerungen, dafür stopfen sie diverse Sicherheitslöcher, die Apple laut eigenen Angaben auch aufgrund der neuen Gefahren durch KI flotter liefert.
---------------------------------------------
https://www.heise.de/news/iOS-26-5-2-iPadOS-26-5-2-und-macOS-26-5-2-Wichtig…
∗∗∗ ipv6_frag_escape: Linux LPE - Reliable Jail/Container Escape ∗∗∗
---------------------------------------------
A reliable unprivileged container / jail escape proof of concept for CentOS / RHEL 10.It rides a now fixed IPv6 fragmentation bug in __ip6_append_data() (closed upstream by 38becddc, no CVE), an in-slab linear overflow into the skb_shared_info at the tail of a packet's own head object. This README documents the exploitation chain only. It does not cover the trigger.
---------------------------------------------
https://github.com/sgkdev/ipv6_frag_escape
∗∗∗ LWN Security updates for Tuesday ∗∗∗
---------------------------------------------
https://lwn.net/Articles/1080439/
∗∗∗ DGM3103SCT vulnerable to OS command injection ∗∗∗
---------------------------------------------
https://jvn.jp/en/jp/JVN28979424/
∗∗∗ Security Vulnerabilities fixed in Firefox 152.0.4 ∗∗∗
---------------------------------------------
https://www.mozilla.org/en-US/security/advisories/mfsa2026-62/
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/
=====================
= End-of-Day report =
=====================
Timeframe: Freitag 26-06-2026 18:00 − Montag 29-06-2026 18:00
Handler: Alexander Riepl
Co-Handler: n/a
=====================
= News =
=====================
∗∗∗ Cybersecurity firms targeted by fraudulent OpenAI organization invites ∗∗∗
---------------------------------------------
Threat actors are creating OpenAI tenants that impersonate legitimate companies and inviting employees to join them, in what appears to be a ploy to trick targets into submitting sensitive company information in chats and projects.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/cybersecurity-firms-targeted…
∗∗∗ Polymarket customers lose $3 million in supply-chain attack ∗∗∗
---------------------------------------------
Polymarket says it will fully reimburse customers who lost an estimated $3 million after hackers injected a malicious script into the platforms frontend following a breach at a third-party vendor.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/polymarket-customers-lose-3-…
∗∗∗ Hackers now exploit critical Oracle E-Business flaw in attacks ∗∗∗
---------------------------------------------
Attackers have begun exploiting a critical vulnerability (CVE-2026-46817) in the Oracle E-Business Suite (EBS) financial application, according to threat intelligence company Defused.
---------------------------------------------
https://www.bleepingcomputer.com/news/security/new-oracle-e-business-suite-…
∗∗∗ Root-Zugriff möglich: Exploits für gefährliche Lücke im Linux-Kernel geleakt ∗∗∗
---------------------------------------------
Admins sollten zügig ihre Linux-Systeme absichern. Auf Github sind Exploits für eine Root-Lücke in Debian, Ubuntu und RHEL aufgetaucht.
---------------------------------------------
https://www.golem.de/news/root-zugriff-moeglich-exploits-fuer-gefaehrliche-…
∗∗∗ The Gentlemen are knocking: сustom backdoors and evolving tactics ∗∗∗
---------------------------------------------
Kaspersky researchers analyze incidents related to The Gentlemen RaaS group, disclose their tools and TTPs, and find a new ransomware variant.
---------------------------------------------
https://securelist.com/the-gentlemen-raas/120447/
∗∗∗ Microsoft Adds Another Year To Windows 10 Extended Update Program ∗∗∗
---------------------------------------------
Microsoft has quietly extended free Windows 10 security updates for consumers by another year, pushing the Extended Security Updates (ESU) programs end date from October 12, 2026, to October 12, 2027. "The ESU support page was updated with that date, and Microsofts blog post on the program has a new editors note confirming the change," reports Ars Technica. From the report: The prevalence of Windows across so many devices and form factors has given Microsoft a ..
---------------------------------------------
https://tech.slashdot.org/story/26/06/26/0029235/microsoft-adds-another-yea…
∗∗∗ New SharkLoader Malware Deploys Cobalt Strike in StrikeShark Cyberattacks ∗∗∗
---------------------------------------------
A newly discovered cyber attack campaign has been observed delivering a previously undocumented malware family called SharkLoader that acts as a loader for deploying Cobalt Strike Beacon on compromised hosts.Kaspersky, which is tracking the activity under the moniker StrikeShark, said the campaign has targeted a diplomatic organization in Indonesia, government organizations in Taiwan, ..
---------------------------------------------
https://thehackernews.com/2026/06/new-sharkloader-malware-deploys-cobalt.ht…
∗∗∗ Microsoft keeps Windows Server 2022 hotpatching alive into 2027 ∗∗∗
---------------------------------------------
In the Azure Edition, of course
---------------------------------------------
https://www.theregister.com/security/2026/06/29/microsoft-keeps-windows-ser…
∗∗∗ Critical Unauthenticated Remote Code Execution in Splunk Enterprise (CVE-2026-20253) ∗∗∗
---------------------------------------------
Splunk disclosed a critical unauthenticated remote code execution (RCE) vulnerability in Splunk Enterprise tracked as CVE-2026-20253 on June 10, 2026. The vulnerability has a CVSS score of 9.8 and stems from missing authentication on a PostgreSQL sidecar service recovery endpoint that can be reached through the Splunk Web interface, which proxies requests to the internal PostgreSQL sidecar service without enforcing authentication. A successful attacker can create or truncate ..
---------------------------------------------
https://www.zscaler.com/blogs/security-research/critical-unauthenticated-re…
∗∗∗ Taiwan: Cybersicherheitsbehörde warnt vor Überwachung durch billige eSIMs ∗∗∗
---------------------------------------------
Günstig für den Urlaub erworbene eSIMs könnten Datenverkehr durch China leiten, warnt Taiwans Digitalministerium. Dabei könnten Daten abgegriffen werden.
---------------------------------------------
https://www.heise.de/news/Taiwanische-Cybersicherheitsbehoerde-warnt-vor-Ue…
∗∗∗ FBI-Warnung: Russischer Geheimdienst sieht es auf Messenger-Backup-Keys ab ∗∗∗
---------------------------------------------
Russische Angreifer geben sich inzwischen als Messenger-Support aus, der Zugriff auf die Backup-Wiederherstellungsschlüssel braucht.
---------------------------------------------
https://www.heise.de/news/FBI-Warnung-Russischer-Geheimdienst-sieht-es-auf-…
∗∗∗ Cyberangriffe auf Hotel- und Gastgewerbe: Täter nisten sich ein ∗∗∗
---------------------------------------------
Microsoft Threat Intelligence beobachtet eine mehrstufige Angriffswelle auf das Hotel- und Gastgewerbe in Asien und Europa.
---------------------------------------------
https://www.heise.de/news/Cyberangriffe-auf-Hotel-und-Gastgewerbe-Taeter-ni…
∗∗∗ Kritische libssh2-Lücke: Proof-of-Concept-Exploit veröffentlicht ∗∗∗
---------------------------------------------
Vergangene Woche wurde eine Sicherheitslücke in libssh2 bekannt. Jetzt ist Exploit-Code aufgetaucht, der sie missbrauchen kann.
---------------------------------------------
https://www.heise.de/news/Kritische-libssh2-Luecke-Proof-of-Concept-Exploit…
∗∗∗ Hacking-Fähigkeiten von Chinas KI Z.ai angeblich so gut wie die von Claude ∗∗∗
---------------------------------------------
Zhipu AIs offenes Modell GLM-5.2 erreicht laut Sicherheitsexperten die Fähigkeiten von Anthropics Mythos bei der Bug-Erkennung.
---------------------------------------------
https://www.heise.de/news/Hacking-Faehigkeiten-von-Chinas-KI-Z-ai-angeblich…
∗∗∗ Harnessing Harnesses - Climbing the LLM Hills ∗∗∗
---------------------------------------------
Trying to coerce useful work out of LLMs without the harness is like supervising a room full of drunk toddlers, each convinced theyre helping, none of them checking with each other and falling over the next.
---------------------------------------------
https://blog.zsec.uk/harnessing-harnesses/
∗∗∗ From Perimeter to Proof: The New Architecture of Email Security ∗∗∗
---------------------------------------------
How identity, investigation, browser security, and AI are reshaping the future of email defense.
---------------------------------------------
https://softwareanalyst.substack.com/p/from-perimeter-to-proof-the-new-arch…
∗∗∗ Miasma Mini Shai-Hulud Hits ImmobiliareLabs npm Packages ∗∗∗
---------------------------------------------
Latest wave affects legitimate @immobiliarelabs Backstage packages, with malicious npm releases published across GitLab and LDAP authentication plugin families on June 26, 2026.Socket Threat Research is tracking a fresh compromise in the ongoing Miasma Mini Shai-Hulud supply chain campaign. The latest activity affects legitimate npm packages published under the @immobiliarelabs scope, including Backstage plugins used for GitLab integration and LDAP authentication ..
---------------------------------------------
https://socket.dev/blog/miasma-mini-shai-hulud-hits-immobiliarelabs-npm-pac…
--
CERT.at Daily mailing list
Listinfo: https://lists.cert.at/mailman3/postorius/lists/daily.lists.cert.at/