===================== = End-of-Day report = =====================
Timeframe: Mittwoch 05-08-2026 18:00 − Donnerstag 06-08-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: Alexander Riepl
===================== = News = =====================
∗∗∗ COLDCARD security audit phishing attack installs remote access tool ∗∗∗ --------------------------------------------- A phishing campaign is exploiting fears surrounding the recently disclosed COLDCARD wallet vulnerability and suspected $88.6 million Bitcoin theft to trick users into installing ScreenConnect remote access software. --------------------------------------------- https://www.bleepingcomputer.com/news/security/coldcard-security-audit-phish...
∗∗∗ Schweiz: Bundesamt für Informatik und Telekommunikation über Sharepoint gehackt ∗∗∗ --------------------------------------------- Ein Cyberangriff hat das Schweizer BIT getroffen. Angreifer sind über Microsoft Sharepoint eingedrungen und haben Hunderte Nutzerkonten kompromittiert. --------------------------------------------- https://www.golem.de/news/schweiz-bundesamt-fuer-informatik-und-telekommunik...
∗∗∗ "Wiederkehrendes Muster": OpenSSL-Entwickler wettert gegen KI-Hacks ∗∗∗ --------------------------------------------- Seit einigen Tagen hacken sich vermehrt KI-Modelle von OpenAI, Anthropic und Meta durchs Netz. Das Problem liegt laut OpenSSL-Entwickler Hudson aber nicht bei der KI. --------------------------------------------- https://www.golem.de/news/wiederkehrendes-muster-openssl-entwickler-wettert-...
∗∗∗ Paperclip AI Flaws Let Attackers Run Host Commands via Malicious Agent Imports ∗∗∗ --------------------------------------------- Two security flaws in Paperclip could let attackers execute commands on a network server or a developers computer. Paperclip is an open-source control plane for teams of artificial intelligence (AI) agents, and both paths rely on importing a malicious agent and .. --------------------------------------------- https://thehackernews.com/2026/08/paperclip-ai-flaws-let-attackers-run.html
∗∗∗ Over 250 ClickFix Domains Use Browser Fingerprinting to Hide macOS Malware Lures ∗∗∗ --------------------------------------------- A macOS ClickFix operation spanning more than 250 front-end domains now fingerprints visitors before deciding whether to show them a malware lure, a change Microsoft Threat Intelligence tracked on infrastructure it had been watching for weeks.The server-side .. --------------------------------------------- https://thehackernews.com/2026/08/over-250-clickfix-domains-use-browser.html
∗∗∗ Chinese-Made Zbtlink Routers Ship With Backdoor That Opens Unauthenticated Root Shells ∗∗∗ --------------------------------------------- Cybersecurity researchers have disclosed details of a "factory-shipped backdoor" implanted in at least 20 Chinese router models from Zbtlink.According to a new report from VulnCheck, the implant appears in all 21 firmware images currently available .. --------------------------------------------- https://thehackernews.com/2026/08/chinese-made-zbtlink-routers-ship-with.htm...
∗∗∗ Apple iCloud Private Relay Can Expose Real IPs Through WebKit Proxy Bypasses ∗∗∗ --------------------------------------------- Cybersecurity researchers have disclosed a security issue with Apples iCloud Private Relay tool that can expose a users real IP address.Introduced with iOS 15, iCloud Private Relay employs a dual-hop architecture to ensure users privacy by routing .. --------------------------------------------- https://thehackernews.com/2026/08/webkit-proxy-bypasses-can-expose-real.html
∗∗∗ Over 4,400 Rockwell PLCs Exposed Online, 22 Found in Water Attack Cities ∗∗∗ --------------------------------------------- Forescout found 22 internet-facing Rockwell Automation programmable logic controllers (PLCs) in cities hit by recent cyberattacks on US water utilities. Nineteen used the same mobile carrier network.Its August 3 scan counted 4,407 exposed Rockwell .. --------------------------------------------- https://thehackernews.com/2026/08/over-4400-rockwell-plcs-exposed-online.htm...
∗∗∗ ClaudeFix: Shared Claude Chats Meet ClickFix ∗∗∗ --------------------------------------------- ClickFix is a widely employed attack technique, first seen in 2024, where a victim is instructed to paste-and-run instructions on their system to “fix” a problem or install software. The seemingly benign instructions are, in fact, malicious and lead to the deployment of malware onto the victim’s system. Zscaler Threat Hunting has identified .. --------------------------------------------- https://www.zscaler.com/blogs/security-research/claudefix-shared-claude-chat...
∗∗∗ Fehlende Kontaktmöglichkeit: Deutschland verschläft Sicherheit per security.txt ∗∗∗ --------------------------------------------- Nur 1,8 Prozent der deutschen Webseiten bieten eine standardisierte security.txt an. Das BSI warnt vor den Risiken und verweist auf kommende Meldepflichten. --------------------------------------------- https://www.heise.de/news/Fehlende-Kontaktmoeglichkeit-Deutschland-verschlae...
∗∗∗ Scammers target OnlyFans users with deepfakes ∗∗∗ --------------------------------------------- Criminals are impersonating OnlyFans creators using AI tools in order to scam followers. --------------------------------------------- https://www.malwarebytes.com/blog/news/2026/08/scammers-target-onlyfans-user...
∗∗∗ Apple’s bug bounty program is drowning in so much AI slop, it is in danger of missing serious exploits ∗∗∗ --------------------------------------------- Apple has imposed strict new submission limits on its bug bounty portal after finding itself overwhelmed by low-quality, AI generated vulnerability reports - many of which were found to be describing security flaws that simply didnt exist. --------------------------------------------- https://www.bitdefender.com/en-us/blog/hotforsecurity/apple-bug-bounty-ai-mi...
∗∗∗ Token Jacking: Cybercriminals Could Be Stealing Your AI Resources ∗∗∗ --------------------------------------------- Discover how attackers hijack AI tokens to fuel gray market transfer stations by stealing developer API keys. --------------------------------------------- https://unit42.paloaltonetworks.com/ai-token-jacking/
∗∗∗ OctLurk and SilkLurk Windows Backdoors Target Governments in 6 Countries ∗∗∗ --------------------------------------------- Kaspersky links OctLurk and SilkLurk to cyberespionage attacks stealing passwords, emails and files from government systems in six countries since January 2025. --------------------------------------------- https://hackread.com/octlurk-silklurk-backdoors-target-6-countries/
∗∗∗ Sicherheitspatches: Angreifer können Schadcode auf n8n-Servern ausführen ∗∗∗ --------------------------------------------- Die n8n-Entwicklwer haben in aktuellen Versionen insgesamt 18 Sicherheitslücken geschlossen. --------------------------------------------- https://heise.de/-11400494
∗∗∗ Fake Zoom installer uses .NET downloader to deliver Overlord RAT on macOS ∗∗∗ --------------------------------------------- Jamf Threat Labs uncovers a macOS campaign using a fake Zoom installer to deploy Overlord RAT. Built with .NET, this cross-platform technique simultaneously targets Windows, joining Go- and Rust-based cross-platform malware. --------------------------------------------- https://www.jamf.com/blog/fake-zoom-installer-delivers-overlord-rat-macos/
===================== = Vulnerabilities = =====================
∗∗∗ Cisco IOS XE Software Security Hardening Release: August 2026 ∗∗∗ --------------------------------------------- As part of Ciscos ongoing commitment to proactive security and product quality, the Cisco IOS XE Software engineering team has conducted a comprehensive internal security review. This review resulted in software hardening releases that address multiple internally discovered vulnerabilities. These vulnerabilities were found during internal testing and are not .. --------------------------------------------- https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisor...
∗∗∗ Veeam: Vulnerabilities Resolved in Veeam ONE 13.1 ∗∗∗ --------------------------------------------- Veeam has released 6 new security advisories for Veeam ONE (1x critical, 4x high, 1x medium) --------------------------------------------- https://www.veeam.com/kb4892
∗∗∗ Security updates for Thursday ∗∗∗ --------------------------------------------- Security updates have been issued by Debian (7zip, kernel, libde265, and p7zip), Mageia (tomcat), Oracle (fence-agents, frr10, kernel, ldns, libgcrypt, mingw-glib2, nodejs24, osbuild-composer, p11-kit, php8.4, sg3_utils, and thunderbird), Red Hat (libXfont2), and SUSE (containerd, evince, libXfont2, nginx, openssl-3, pcp, php7, php8, python-Django, python-httplib2, python-nltk, rrdtool, vifm, and wireshark). --------------------------------------------- https://lwn.net/Articles/1087489/
∗∗∗ Entity Browser - Moderately critical - Cross site scripting - SA-CONTRIB-2026-094 ∗∗∗ --------------------------------------------- https://www.drupal.org/sa-contrib-2026-094
∗∗∗ Edit in-place field - Moderately critical - Access bypass - SA-CONTRIB-2026-093 ∗∗∗ --------------------------------------------- https://www.drupal.org/sa-contrib-2026-093