===================== = End-of-Day report = =====================
Timeframe: Donnerstag 27-08-2026 18:00 − Freitag 28-08-2026 18:00 Handler: Alexander Riepl Co-Handler: n/a
===================== = News = =====================
∗∗∗ PaperCut warns of NG, MF flaw exploited in zero-day attacks ∗∗∗ --------------------------------------------- PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. --------------------------------------------- https://www.bleepingcomputer.com/news/security/papercut-warns-of-ng-mf-flaw-...
∗∗∗ Over 8,300 Gitea servers vulnerable to code execution attacks ∗∗∗ --------------------------------------------- Over 8,300 Internet-exposed Gitea instances are still unpatched against a critical security flaw exploited in ongoing remote code execution attacks, according to cybersecurity watchdog Shadowserver. --------------------------------------------- https://www.bleepingcomputer.com/news/security/over-8-300-gitea-servers-vuln...
∗∗∗ Patch-Defizit in Deutschland: Exploit gefährdet 85 Prozent aller Exchange-Server ∗∗∗ --------------------------------------------- Auf Github ist ein Exploit für eine gefährliche Exchange-Lücke aufgetaucht. Einen Patch gibt es zwar, doch den haben in Deutschland nur wenige installiert. --------------------------------------------- https://www.golem.de/news/patch-defizit-in-deutschland-exploit-gefaehrdet-85... change-server-2608-212397.html
∗∗∗ APT28-Linked HOOKEDGE Backdoor Targets European Government and Diplomatic Organizations ∗∗∗ --------------------------------------------- Cybersecurity researchers have flagged a fresh set of campaigns targeting government and diplomatic organizations in Romania, Spain, and Türkiye between late September 2025 and early April 2026.These campaigns, per Recorded Future Insikt Group, .. --------------------------------------------- https://thehackernews.com/2026/08/apt28-linked-hookedge-backdoor-targets.htm...
∗∗∗ Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server ∗∗∗ --------------------------------------------- cPanel has released patches for a security flaw affecting domain parking and addon domain functionality in cPanel and WebHost Manager (WHM), which could allow code execution as the root user.The vulnerability, assigned the CVE identifier CVE-2026-65643, .. --------------------------------------------- https://thehackernews.com/2026/08/critical-cpanel-flaw-could-let-one.html
∗∗∗ Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL ∗∗∗ --------------------------------------------- ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, in certain circumstances, by an unauthenticated attacker.The company said it deployed a .. --------------------------------------------- https://thehackernews.com/2026/08/three-cvss-100-servicenow-flaws-could.html
∗∗∗ 19 Chrome and Edge Extensions Found With Wallet-Stealing and Crypto-Draining Code ∗∗∗ --------------------------------------------- Cybersecurity researchers have discovered a cluster of 18 Google Chrome and one Microsoft Edge extensions that were published over the last six months and harbored wallet secret stealing and cryptocurrency draining capabilities.The extensions, per .. --------------------------------------------- https://thehackernews.com/2026/08/19-chrome-and-edge-extensions-found.html
∗∗∗ AI girlfriend review sites secrets were exposed to the world for three weeks ∗∗∗ --------------------------------------------- Even testing and staging sites need protection from prying eyes. --------------------------------------------- https://www.theregister.com/security/2026/08/27/ai-girlfriend-review-sites-s...
∗∗∗ CRPx0 hacking service for dummies claims victim count more than quintupled ∗∗∗ --------------------------------------------- Its built to be operated by a human with no technical background. --------------------------------------------- https://www.theregister.com/cyber-crime/2026/08/27/crpx0-hacking-service-for...
∗∗∗ TeamViewer schließt hochriskante Lücken in Clients ∗∗∗ --------------------------------------------- Die TeamViewer-Clients können Angreifern das Ausführen von Schadcode ermöglichen. Updates stopfen die hochriskanten Sicherheitslücken. --------------------------------------------- https://www.heise.de/news/TeamViewer-stopft-Codeschmuggel-Leck-11432840.html
∗∗∗ Google macht Android 17 sicherer: ECH-Unterstützung und 2G-Abschaltung ∗∗∗ --------------------------------------------- Mit Android 17 führt Google neue Netzwerksicherheitsfunktionen ein. Diese sollen Verbindungen absichern und die Privatsphäre im heimischen WLAN schützen. --------------------------------------------- https://www.heise.de/news/2G-Abschaltung-und-ECH-Support-Android-17-erhoeht-...
∗∗∗ „Begrenztes Zeitfenster“: Mehr als 100 Unternehmen warnen vor KI-Cyberangriffen ∗∗∗ --------------------------------------------- Führende KI-Labore sowie mehr als 100 Organisationen warnen in einem offenen Brief vor einer baldigen Zunahme KI-gestützter Cyberangriffe. --------------------------------------------- https://www.heise.de/news/Begrenztes-Zeitfenster-Mehr-als-100-Unternehmen-wa...
∗∗∗ Zwei kritische Lücken in Next.js – Remote-Code-Ausführung unter Windows ∗∗∗ --------------------------------------------- Die zwei kritischen von Vercel gemeldeten Lücken im JavaScript-Framework Next.js ermöglichen es Angreifern, Code auszuführen. --------------------------------------------- https://www.heise.de/news/Zwei-kritische-Luecken-in-Next-js-Remote-Code-Ausf...
∗∗∗ (OEM-)China-Router von ZBT mit Backdoors ∗∗∗ --------------------------------------------- IT-Forscher haben Router vom OEM-Hersteller ZBT untersucht, die weltweit von Anbietern verkauft werden. Darin fanden sie Backdoors. --------------------------------------------- https://www.heise.de/news/OEM-China-Router-von-ZBT-mit-Backdoors-11433072.ht...
∗∗∗ Disruptive cyber activity highlights risk from internet-exposed systems and edge devices ∗∗∗ --------------------------------------------- Targeting of operational technology reinforces the need for organisations to understand what is exposed to the internet, address avoidable vulnerabilities, and build long-term cyber resilience. --------------------------------------------- https://www.ncsc.gov.uk/news/disruptive-cyber-activity-highlights-risk-from-...
∗∗∗ Threat Actors Are Posing as OpenAI, Anthropic and DeepSeek to Target Credentials and Secrets ∗∗∗ --------------------------------------------- GreyNoise is observing automated scanners posing as the web crawlers of OpenAI, Anthropic, DeepSeek, and Fortune 500 companies, using forged user agents while requesting the files where misconfigured web servers frequently leak secrets and credentials. --------------------------------------------- https://www.greynoise.io/blog/threat-actors-posing-as-ai-crawlers
∗∗∗ Inside 90 days of attacks on AI infrastructure ∗∗∗ --------------------------------------------- Wiz honeypots uncover active campaigns targeting LiteLLM, MCP servers, and AI frameworks through RCE, blind prompt injection, and memory credential theft. --------------------------------------------- https://www.wiz.io/blog/ai-infrastructure-honeypot