===================== = End-of-Day report = =====================
Timeframe: Freitag 21-08-2026 18:00 − Montag 24-08-2026 18:00 Handler: Alexander Riepl Co-Handler: n/a
===================== = News = =====================
∗∗∗ How an Emerging Industrial Protocol Family Could Put OT at Risk ∗∗∗ --------------------------------------------- New research shows how attacks against some unprotected TSN protocols could allow attackers to disrupt or manipulate physical processes. --------------------------------------------- https://www.darkreading.com/ics-ot-security/how-emerging-industrial-protocol...
∗∗∗ Nach Hackerangriff: Berliner Senat überrascht über Größe des IT-Systems ∗∗∗ --------------------------------------------- Nach einem Hackerangriff sind zwei Berliner Verwaltungen wieder am Netz. Es gibt jedoch weiter Verdachtsmomente für eine Infiltration. --------------------------------------------- https://www.golem.de/news/nach-hackerangriff-berliner-senat-ueberrascht-uebe...
∗∗∗ Missbrauch von Passkeys: Phishing-Toolkit soll Passwort-Reset umgehen können ∗∗∗ --------------------------------------------- Ein ab 10.000 US-Dollar gehandeltes Phishing-Toolkit soll Angreifern über Passkeys einen dauerhaften Zugriff etwa auf gekaperte Google-Konten verleihen. --------------------------------------------- https://www.golem.de/news/missbrauch-von-passkeys-phishing-toolkit-soll-pass...
∗∗∗ Security vets rally around $4 paper password books for sale in Australia ∗∗∗ --------------------------------------------- Once shunned by the IT crowd, pen-and-paper password vaults are getting the love they deserve in 2026 --------------------------------------------- https://www.theregister.com/security/2026/08/24/security-vets-rally-around-4...
∗∗∗ AliExpress accused of fingerprinting shoppers with silent audio trick that also muted a devs headphones ∗∗∗ --------------------------------------------- Sawtooth waves you cant hear still mess with your Bluetooth. Firefox and Brave say theyve got you covered --------------------------------------------- https://www.theregister.com/security/2026/08/24/aliexpress-accused-of-finger...
∗∗∗ The curious case of the effortful fraud ∗∗∗ --------------------------------------------- How what looked like a generic phishing site seemingly turned out to be a put-some-effort-into it, targeted fraud. --------------------------------------------- https://bytesandborscht.com/the-curious-case-of-the-effortful-fraud/
∗∗∗ Britische Regierung bestätigt Cyberattacke auf Kraftwerk ∗∗∗ --------------------------------------------- Für vier Tage haben Angreifer in Großbritannien ein Kraftwerk abgeschaltet. Die Behörden warnen und besänftigten zugleich. --------------------------------------------- https://www.heise.de/news/Britische-Regierung-bestaetigt-Cyberattacke-auf-Kr...
∗∗∗ Microsoft stopft zahlreiche Cloud-Schwachstellen ∗∗∗ --------------------------------------------- Microsoft dokumentiert 18 teils kritische Sicherheitslücken in Cloud-Produkten, die die Entwickler geschlossen haben. --------------------------------------------- https://www.heise.de/news/Microsoft-stopft-zahlreiche-Cloud-Schwachstellen-1...
∗∗∗ „GTA 6“-ISO: Vermeintliche Leak-Abbilddatei voller Malware ∗∗∗ --------------------------------------------- Bösartige Akteure bieten das vermeintlich geleakte ISO von „GTA 6“ im Netz an. Die 113 GByte enthalten aufgepumpte Virendaten. --------------------------------------------- https://www.heise.de/news/GTA-6-ISO-Vermeintliche-Leak-Abbilddatei-voller-Ma...
∗∗∗ Notepad++ v8.9.8 stopft 14 Sicherheitslücken ∗∗∗ --------------------------------------------- Am Sonntag hat Don Ho Version 8.9.8 des beliebten Editors Notepad++ herausgegeben. Sie schließt etwa Codeschmuggellücken. --------------------------------------------- https://www.heise.de/news/Notepad-v8-9-8-stopft-14-Sicherheitsluecken-114238...
∗∗∗ And then the men with guns tell you to do it anyway ∗∗∗ --------------------------------------------- Perhaps you can think of a way to design an alerting system which cannot be abused - but I can't. --------------------------------------------- https://shkspr.mobi/blog/2026/08/and-then-the-men-with-guns-tell-you-to-do-i...
∗∗∗ Everything I own, owned ∗∗∗ --------------------------------------------- Over the past couple weeks I’ve been doing agent-driven reverse engineering of peripherals that happen to be within arm’s reach. From those devices, I’ve come away with a full plaintext command shell inside my microphone, a webcam whose activity LED I can switch off while it records, and a key light that hands out memory writes to anyone on the WiFi. --------------------------------------------- https://schlarp.com/posts/everything-i-own-owned/
∗∗∗ Building certgrep.sh: a free certificate transparency search engine ∗∗∗ --------------------------------------------- Certificate transparency is one of the best public datasets in security. Every certificate issued by a publicly trusted certificate authority lands in an append-only, cryptographically verifiable log, usually before the certificate is ever used. For anyone hunting malicious infrastructure, that makes certificate transparency (CT) one of the earliest .. --------------------------------------------- https://haveibeensquatted.com/blog/building-certgrep
===================== = Vulnerabilities = =====================
The Fabrik Fiasco: Announced, Restricted, Relabelled --------------------------------------------- https://mysites.guru/blog/fabrik-unauthenticated-rce-calc-element/
Fabrik 4.7.2 for Joomla: A Long List of Security Fixes --------------------------------------------- https://mysites.guru/blog/fabrik-4-7-2-security-release/