===================== = End-of-Day report = =====================
Timeframe: Montag 27-07-2026 18:00 − Dienstag 28-07-2026 18:00 Handler: Alexander Riepl Co-Handler: n/a
===================== = News = =====================
∗∗∗ Apple sued over fake App Store crypto wallet app stealing $1.8M in Bitcoin ∗∗∗ --------------------------------------------- Apple is being sued by three people who claim approximately $1.8 million in Bitcoin was stolen after downloading and using a fraudulent Sparrow Wallet application from the App Store. --------------------------------------------- https://www.bleepingcomputer.com/news/apple/apple-sued-over-fake-app-store-c...
∗∗∗ New Dysphoria DDoS botnet spreads to 200k devices worldwide ∗∗∗ --------------------------------------------- A botnet called Dysphoria has compromised around 200,000 devices across the world and is using them for distributed denial of service (DDoS) attacks and traffic relay operations. --------------------------------------------- https://www.bleepingcomputer.com/news/security/new-dysphoria-ddos-botnet-spr...
∗∗∗ New Certighost PoC exploit lets attackers hijack Windows domains ∗∗∗ --------------------------------------------- A proof-of-concept exploit for "Certighost," a Windows Active Directory Certificate Services vulnerability, has been released that can allow authenticated attackers to potentially compromise a Windows domain. --------------------------------------------- https://www.bleepingcomputer.com/news/security/new-certighost-poc-exploit-le...
∗∗∗ Hackers target US firms in FastJson RCE zero-day attacks ∗∗∗ --------------------------------------------- Hackers are actively exploiting a vulnerability in the FastJson open-source Java library, allowing remote code execution without user interaction or elevated privileges. --------------------------------------------- https://www.bleepingcomputer.com/news/security/hackers-target-us-firms-in-fa...
∗∗∗ Data breach at medical billing firm MCBS affects 1.26 million people ∗∗∗ --------------------------------------------- Healthcare billing company Medical Computer Business Services (MCBS) has disclosed that a 2025 network breach exposed the sensitive information of more than 1.2 million people. --------------------------------------------- https://www.bleepingcomputer.com/news/security/data-breach-at-medical-billin...
∗∗∗ Nach OpenAI-Hack: US-Abgeordnete wollen Kill Switch für KI ∗∗∗ --------------------------------------------- Der eigenständige Hackerangriff von OpenAIs KI hat Nachwirkungen: Abgeordnete fordern mehr Kontrolle - und einen Kill Switch. --------------------------------------------- https://www.golem.de/news/nach-openai-hack-us-abgeordnete-wollen-kill-switch...
∗∗∗ Persönliche Daten geleakt: Unzählige Claude-Chats bei Google aufgetaucht ∗∗∗ --------------------------------------------- Claude-Nutzer können Links zu ihren Chats mit anderen Personen teilen. Die Unterhaltungen wurden bis vor kurzem aber auch bei Google gelistet. --------------------------------------------- https://www.golem.de/news/persoenliche-daten-geleakt-unzaehlige-claude-chats...
∗∗∗ NVIDIA Forms 37-Member Open Secure AI Alliance and Open-Sources NOOA Framework ∗∗∗ --------------------------------------------- NVIDIA and 36 other organizations have formed the Open Secure AI Alliance to develop and share open technologies, techniques, and tools for securing software and artificial intelligence (AI) agents.The 37-member group spans cloud, security, enterprise software, and AI companies, including Microsoft, Cisco, Cloudflare, CrowdStrike, Hugging Face, IBM, Palo Alto Networks, Red Hat, .. --------------------------------------------- https://thehackernews.com/2026/07/nvidia-forms-37-member-open-secure-ai.html
∗∗∗ AI-found bugs arent proving any easier to exploit despite the hype ∗∗∗ --------------------------------------------- VulnCheck says fewer than 2% of AI-assisted vulnerability discoveries have been weaponized, casting doubt on claims frontier models are handing attackers a major advantage --------------------------------------------- https://www.theregister.com/security/2026/07/28/ai-found-bugs-arent-proving-...
∗∗∗ Angriffe auf FortiOS und Arista VeloCloud beobachtet ∗∗∗ --------------------------------------------- Die IT-Sicherheitsbehörde CISA meldet Angriffe auf Sicherheitslücken in Fortinet FortiOS sowie Arista VeloCloud. --------------------------------------------- https://www.heise.de/news/Angriffe-auf-FortiOS-und-Arista-VeloCloud-beobacht...
∗∗∗ Neobank Revolut: Angeblich 75 Millionen Datensätze im Untergrund angeboten ∗∗∗ --------------------------------------------- Ein Krimineller bietet im digitalen Untergrund eine Datenbank mit 75 Millionen Einträgen an, die von der Neobank Revolut stammen sollen. --------------------------------------------- https://www.heise.de/news/Neobank-Revolut-Angeblich-75-Millionen-Datensaetze...
∗∗∗ Lücke: Claude Cowork entkommt macOS-Sandbox ∗∗∗ --------------------------------------------- Die Nutzung von KI-Agenten direkt auf dem Rechner kann Gefahren mit sich bringen. Das zeigt eine soeben entdecktes Sicherheitsloch in Claude Cowork für den Mac. --------------------------------------------- https://www.heise.de/news/Luecke-Claude-Cowork-entkommt-macOS-Sandbox-113794...
∗∗∗ IR Trends Q2 2026: Phishing and weaponized remote management tools drive attack chains ∗∗∗ --------------------------------------------- Talos IRs Q2 report highlights a significant surge in phishing-based initial access and the weaponization of legitimate remote management tools. Learn how to sharpen your defenses. --------------------------------------------- https://blog.talosintelligence.com/ir-trends-q2-2026/
∗∗∗ Zahlreiche Sicherheitslücken gefixt: Schnell auf iOS 26.6 und Co. aktualisieren ∗∗∗ --------------------------------------------- Apple hat nun seine Sicherheitshinweise zu den neuen Betriebssystemen publiziert. Es gibt erneut enorm viele Fixes – vermutlich auch dank KI. --------------------------------------------- https://heise.de/-11379576
∗∗∗ Verschiedene Attacken auf Progress LoadMaster möglich ∗∗∗ --------------------------------------------- Die Load-Balancing- und Cluster-Managementlösung LoadMaster ist verwundbar. Die Entwickler haben nun Sicherheitslücken geschlossen. --------------------------------------------- https://heise.de/-11380070