===================== = End-of-Day report = =====================
Timeframe: Montag 10-08-2026 18:00 − Dienstag 11-08-2026 18:00 Handler: Alexander Riepl Co-Handler: Guenes Holler
===================== = News = =====================
∗∗∗ New Pass-ta-key attack reveals all the things we didnt know about passkeys ∗∗∗ --------------------------------------------- Why passkey apps treat Windows differently than other operating systems. --------------------------------------------- https://arstechnica.com/security/2026/08/heres-why-the-new-pass-ta-key-attac...
∗∗∗ Hackers breached a small Polish energy plant via private APN last year ∗∗∗ --------------------------------------------- Hackers breached a heat-and-power plant facility in Poland, which supplies heat to about 50,000 residents, using a private APN (Access Point Name) to access an OT (Operational Technology) network. --------------------------------------------- https://www.bleepingcomputer.com/news/security/hackers-breached-a-small-poli...
∗∗∗ CISA: Microsoft SharePoint flaw now exploited in ransomware attacks ∗∗∗ --------------------------------------------- CISA confirmed today that ransomware gangs have begun abusing a high-severity Microsoft SharePoint remote code execution vulnerability, which has been flagged as actively exploited since early July. --------------------------------------------- https://www.bleepingcomputer.com/news/security/cisa-microsoft-sharepoint-fla...
∗∗∗ Mozilla updates GPG signing key for Firefox releases after exposure ∗∗∗ --------------------------------------------- Mozilla announced today that it updated the GPG key used to sign Firefox and Thunderbird releases after it was accidentally exposed on GitHub. --------------------------------------------- https://www.bleepingcomputer.com/news/security/mozilla-updates-gpg-key-for-s...
∗∗∗ Nach KI-Hacks: Chinesisches KI-Modell trickst Forscher bei Tests aus ∗∗∗ --------------------------------------------- Das KI-Modell Kimi K3 hat bei Tests eine gesicherte Umgebung verlassen und sich die gesuchten Lösungen einfach bei Github beschafft. --------------------------------------------- https://www.golem.de/news/nach-ki-hacks-chinesisches-ki-modell-trickst-forsc...
∗∗∗ Kein Klick nötig: Plug-and-Pwn-Angriff kapert Windows-Systeme per USB ∗∗∗ --------------------------------------------- Windows lädt beim Anschließen neuer USB-Geräte oft Software nach. Angreifer können dadurch Systemrechte erlangen - manchmal sogar aus der Ferne. --------------------------------------------- https://www.golem.de/news/kein-klick-noetig-plug-and-pwn-angriff-kapert-wind...
∗∗∗ BdThemes Supply Chain Attack Poisons JSON to Create Rogue WordPress Admins ∗∗∗ --------------------------------------------- Cybersecurity researchers have warned of a supply chain compromise impacting WordPress plugin vendor BdThemes, prompting the content management systems (CMS) platforms plugins team to temporarily disable their downloads."Unlike traditional software supply chain attacks, zero source code files were modified within the official WordPress.org repository," Wordfence researcher Paolo Tresso said. --------------------------------------------- https://thehackernews.com/2026/08/bdthemes-supply-chain-attack-poisons.html
∗∗∗ Researchers Built a Fake Crypto Startup and Hired Three Suspected North Korean IT Workers ∗∗∗ --------------------------------------------- Security researchers invented a cryptocurrency startup, advertised developer jobs, and hired three people they believe were North Korean operatives. Every virtual machine the company issued was recording.The onboarding paperwork is the part hiring teams can use. The first hire claimed to live in Pasadena, Texas, then sent a California drivers license and a New York bank account.The --------------------------------------------- https://thehackernews.com/2026/08/researchers-built-fake-crypto-startup.html
∗∗∗ Abyssos: Technical Analysis of a New Modular RAT ∗∗∗ --------------------------------------------- In late June 2026, Zscaler ThreatLabz identified a new malware family that we track as Abyssos. Abyssos is a new modular remote administration tool (RAT) written in C++ that supports a variety of features including credential theft, file exfiltration, and remote access via VNC. Abyssos is in active development with multiple version numbers and different obfuscation passes that are designed to improve evasion from security .. --------------------------------------------- https://www.zscaler.com/blogs/security-research/abyssos-technical-analysis-n...
∗∗∗ Lahmer x86-Befehl hebelt triviale Schutzfunktion aus ∗∗∗ --------------------------------------------- Der mächtige System Management Mode (SMM) von x86-Prozessoren ist ein bevorzugtes Ziel von Angriffen. Ein Trick hebelt eine SMM-Schutzfunktion aus. --------------------------------------------- https://www.heise.de/news/Lahmer-x86-Befehl-hebelt-triviale-Schutzfunktion-a...
∗∗∗ Patchday: SAP Commerce Cloud komplett kompromittierbar ∗∗∗ --------------------------------------------- SAP schließt in seinem Softwareproduktportfolio mehrere unter anderem kritische Sicherheitslücken. --------------------------------------------- https://www.heise.de/news/Patchday-SAP-Commerce-Cloud-komplett-kompromittier...
∗∗∗ Sexual predators targeting online accounts for intimate images, FBI warns ∗∗∗ --------------------------------------------- The FBI is warning that criminals are breaking into social media to steal and distribute non-consensual intimate images and videos. --------------------------------------------- https://www.malwarebytes.com/blog/news/2026/08/sexual-predators-targeting-on...
∗∗∗ The Permanent Threat: Analyzing Aeternum’s Blockchain-Based C2 Operations and Communications ∗∗∗ --------------------------------------------- Analysis of the Aeternum botnet loader, a threat leveraging Polygon blockchain smart contracts for decentralized C2 infrastructure and payload execution. --------------------------------------------- https://unit42.paloaltonetworks.com/aeternum-blockchain-c2-analysis/
∗∗∗ Poland uncovers second heat plant cyberattack that went hidden for months ∗∗∗ --------------------------------------------- The incident occurred on the same day as coordinated cyberattacks struck more than 30 other renewable energy installations and a larger heat plant, as Poland publicly disclosed in January. --------------------------------------------- https://therecord.media/poland-uncovers-critical-infrastructure-attack-hidde...
∗∗∗ LexisNexis deaktiviert nach "verdächtigen Server-Aktivitäten" drei Dienste ∗∗∗ --------------------------------------------- Aktuell ist unklar, was genau passiert ist. Aber seit vorigen Mittwoch, den 5. August 2026, scheint bei LexisNexis etwas passiert zu seine. Der Anbieter hat nach "verdächtigen Server-Aktivitäten" gleich drei Dienste deaktiviert und Verbindungen zu Drittanbietern getrennt. Es laufen Untersuchungen .. --------------------------------------------- https://borncity.com/blog/2026/08/10/lexisnexis-deaktiviert-nach-verdaechtig...
∗∗∗ Steam-Hardware: Käufer müssen nach Cyberangriff mit Betrugsmails rechnen ∗∗∗ --------------------------------------------- Bei Valves Logistikpartner CEVA sind Namen und Adressen europäischer Steam-Hardware-Käufer abgeflossen. Valve warnt vor falschen Nachrichten. --------------------------------------------- https://heise.de/-11409514
∗∗∗ Google Phishing Kit: When Phishing Becomes a Real-Time Remote Browser ∗∗∗ --------------------------------------------- Most of the phishing pages are mere static clones of the login form, whereas sophisticated phishing kits implement adversary-in-the-middle techniques that perform authentication in real-time. In particular, the design being analyzed below fits into the Browser-in-the-Middle (BitM) scheme where the victim-facing page becomes the client for the browser session running at the backend of the phishing operation.The captured network traffic and the extracted client-side artifacts .. --------------------------------------------- https://www.joesecurity.org/blog/2909557602925734728
∗∗∗ Inside the Metabase SQLi: Exploited in the Wild ∗∗∗ --------------------------------------------- Reverse engineering Metabase CVE-2026-72898 with AI to accelerate defense. --------------------------------------------- https://www.wiz.io/blog/inside-the-metabase-sqli-exploited-in-the-wild
===================== = Vulnerabilities = =====================
∗∗∗ TYPO3-CORE-SA-2026-021: Broken Access Control in Backend and Install Tool ∗∗∗ --------------------------------------------- It has been discovered that TYPO3 CMS is susceptible to broken access control. --------------------------------------------- https://news.typo3.com/security/advisory/typo3-core-sa-2026-021
∗∗∗ Security updates for Tuesday ∗∗∗ --------------------------------------------- Security updates have been issued by AlmaLinux (gpsd), Debian (caddy, libyaml-syck-perl, nss, and wordpress), Fedora (chezmoi, chromium, emacs, kernel, knot, libcupsfilters, mingw-gstreamer1-plugins-good, mingw-libidn, mingw-python-pip, nghttp2, p11-kit, python-webob, suricata, and xen), Mageia (bind, openslide, php8.4, and php8.5), Oracle (gpsd-minimal, kernel, libarchive, libpng12, nodejs-nodemon, php:8.3, ruby:3.3, and ruby:4.0), SUSE (agama-web-ui, bind, bouncycastle, dhcpcd, ffmpeg, .. --------------------------------------------- https://lwn.net/Articles/1088226/
∗∗∗ August 2026 Security Update ∗∗∗ --------------------------------------------- https://www.ivanti.com/blog/august-2026-security-update
∗∗∗ SAP Security Patch Day August 2026 | RedRays ∗∗∗ --------------------------------------------- https://redrays.io/blog/sap-security-patch-day-august-2026/