===================== = End-of-Day report = =====================
Timeframe: Freitag 07-08-2026 18:00 − Montag 10-08-2026 18:00 Handler: Guenes Holler Co-Handler: n/a
===================== = News = =====================
∗∗∗ CISA: SonicWall SMA1000 flaws now exploited by ransomware gangs ∗∗∗ --------------------------------------------- CISA has confirmed that ransomware gangs have begun exploiting two recently patched SonicWall SMA1000 vulnerabilities, including a maximum-severity server-side request forgery (SSRF) flaw. --------------------------------------------- https://www.bleepingcomputer.com/news/security/cisa-sonicwall-sma1000-flaws-...
∗∗∗ AI-Generated Patches Fail Half the Time ∗∗∗ --------------------------------------------- A study of more than 6,000 patches found that even working patches can introduce new bugs, break something else, or are open to bypass. --------------------------------------------- https://www.darkreading.com/application-security/ai-generated-patches-fail-h...
∗∗∗ DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure ∗∗∗ --------------------------------------------- Microsoft Threat Intelligence examines DeadLock ransomware, an emerging financially motivated operation distinguished by its use of decentralized infrastructure to support victim communications, negotiations, and data leak operations alongside double extortion tactics used to pressure victims.The post DeadLock ransomware: Breaking down a Rust-based encryptor with decentralized recovery infrastructure appeared first on Microsoft Security Blog. --------------------------------------------- https://www.microsoft.com/en-us/security/blog/2026/08/10/deadlock-ransomware...
∗∗∗ Nearly 800 Malicious npm Packages Deliver Cross-Platform RAT and Infostealer ∗∗∗ --------------------------------------------- A cluster of nearly 800 malicious packages has been published to the npm registry as part of a new campaign designed to deliver cross-platform malware targeting Windows, Mac, and Linux systems. --------------------------------------------- https://thehackernews.com/2026/08/nearly-800-malicious-npm-packages.html
∗∗∗ New CSS Attacks Can Break Webmail Defenses to Steal Passwords and Tokens ∗∗∗ --------------------------------------------- New research shows content inside an email can escape its message boundary and interfere with the webmail interface. --------------------------------------------- https://thehackernews.com/2026/08/new-css-attacks-can-break-webmail.html
∗∗∗ Cyber vulnerability sweep picks up Royal Navy drones sending data to China ∗∗∗ --------------------------------------------- No, no nasties to see here, guv... --------------------------------------------- https://www.theregister.com/edge-and-iot/2026/08/10/cyber-vulnerability-swee...
∗∗∗ Sensitive Info Goes Into ‘No Reply’ Emails Constantly. This Guy Sees It All ∗∗∗ --------------------------------------------- Two security researchers bought cheap domains—including noreply.net and deleteduser.com—and set up email listening services. Hundreds of companies are sending them corporate secrets. --------------------------------------------- https://www.wired.com/story/sensitive-info-goes-into-no-reply-emails-constan...
∗∗∗ Russian military hackers pose as recruiters to target Ukrainian IT workers ∗∗∗ --------------------------------------------- Ukraine’s computer emergency response team, CERT-UA, said Saturday that the campaign has been running since at least May and is linked to Sandworm, the notorious hacking unit associated with Russia’s GRU military intelligence agency. --------------------------------------------- https://therecord.media/russian-military-hackers-pose-as-recruiters-ukraine-...
∗∗∗ Jeans-Hersteller Levi Strauss & Co. erleidet Datenpanne ∗∗∗ --------------------------------------------- Levi Strauss, als Anbieter von Jeans bekannt, hat die Woche einen Datenschutzvorfall erlitten. Mitarbeiter wurden über Social Media ausgetrickst. Dem Angreifer gelang dann wohl der Zugriff auf drei Rechner von Mitarbeitern. --------------------------------------------- https://borncity.com/blog/2026/08/08/jeans-hersteller-levi-strauss-co-erleid...
∗∗∗ SANS Institute rät Sicherheitsteams, offene Türen für KI-Agenten zu schließen ∗∗∗ --------------------------------------------- Die Sicherheitsvorfälle bei Anthropic, Open AI und Meta, sowie bei Bytedance, bei denen AI-Modelle oder Agenten aus ihrer Testumgebung ausbrachen und Angriff im Internet durchführten, hat die Branche aufgeschreckt. Das SANS Institute gibt Sicherheitsteams den Tipp: Offene Türen für KI-Agenten zu schließen. --------------------------------------------- https://borncity.com/blog/2026/08/09/sans-institute-raet-sicherheitsteams-of...
∗∗∗ Investigating a Multi-Stage PowerShell Loader ∗∗∗ --------------------------------------------- During recent threat hunting, I identified suspicious PowerShell content being served directly from an IP address and a domain: hxxp://203[.]188[.]171[.]166/hxxps://dorenzaa[.]com/ Both locations returned PowerShell rather than a conventional user-facing webpage. The PowerShell was responsible for retrieving a ZIP archive from Vercel-hosted infrastructure, extracting it locally, and executing an executable from the extracted content. --------------------------------------------- https://malwr-analysis.com/2026/08/08/investigating-a-multi-stage-powershell...
∗∗∗ IT threat evolution in Q2 2026. Non-mobile statistics ∗∗∗ --------------------------------------------- The report presents key trends and statistics on malware that targeted personal computers running Windows and macOS, as well as internet of things (IoT) devices, during Q2 2026. --------------------------------------------- https://securelist.com/malware-report-q2-2026-pc-iot-statistics/120960/
∗∗∗ IT threat evolution in Q2 2026. Mobile statistics ∗∗∗ --------------------------------------------- This report contains mobile threat statistics for Q2 2026, along with noteworthy discoveries and quarterly trends: the Anatsa banker and a transition to droppers. --------------------------------------------- https://securelist.com/malware-report-q2-2026-mobile-statistics/120948/
===================== = Vulnerabilities = =====================
∗∗∗ Jetzt patchen! Admin-Attacken auf Metabase beobachtet ∗∗∗ --------------------------------------------- Angreifer nutzen zurzeit eine kritische Sicherheitslücke in der Business-Intelligence-Plattform Metabase aus. Admins müssen jetzt handeln. --------------------------------------------- https://heise.de/-11404526
∗∗∗ Schadcode-Attacken auf Progress LoadMaster im Gange ∗∗∗ --------------------------------------------- Derzeit haben Angreifer Progress LoadMaster auf dem Schirm und attackieren aktiv Systeme. Sicherheitspatches sind verfügbar. --------------------------------------------- https://heise.de/-11404612
∗∗∗ LWN Security updates for Monday ∗∗∗ --------------------------------------------- https://lwn.net/Articles/1088057/
∗∗∗ Security updates 1.6.18 and 1.7.3 released ∗∗∗ --------------------------------------------- https://roundcube.net/news/2026/08/09/security-updates-1.6.18-and-1.7.3