===================== = End-of-Day report = =====================
Timeframe: Dienstag 18-08-2026 18:00 − Mittwoch 19-08-2026 18:00 Handler: Guenes Holler Co-Handler: n/a
===================== = News = =====================
∗∗∗ Slowakei: Russische Backdoor in Verkehrskameras entdeckt ∗∗∗ --------------------------------------------- Die Slowakei hat im Rahmen eines Sanierungspakets 279 neue Verkehrskameras gekauft. Die Geräte kamen unerwartet aus Russland - inklusive Backdoor. --------------------------------------------- https://www.golem.de/news /slowakei-russische-backdoor-in-verkehrskameras-entdeckt-2608-212088 .html
∗∗∗ Phishing-Welle im Namen des Finanzministeriums nutzt Familienbeihilfe als Köder ∗∗∗ --------------------------------------------- Datenmissbrauch, unrechtmäßige Umleitungen und ausbleibende Auszahlungen der Familienbeihilfe – mit diesem Bedrohungsbild gehen Kriminelle momentan auf Beutezug. Sie geben sich in einer E-Mail als Finanzministerium aus und wollen so an die Onlinebanking-Logindaten ihrer Opfer gelangen. --------------------------------------------- https://www.watchlist-internet.at/news /phishing-finanzministeriums-familienbeihilfe/
∗∗∗ Warnung vor Angriffen auf Microsoft IKE, SharePoint, VMware vCenter und macOS ∗∗∗ --------------------------------------------- Die IT-Sicherheitsbehörde CISA warnt aktuell vor Angriffen auf Microsoft IKE, SharePoint, VMware vCenter und macOS. --------------------------------------------- https://heise.de/-11418783
∗∗∗ CISA: Medusa ransomware hit over 500 critical infrastructure orgs ∗∗∗ --------------------------------------------- The Cybersecurity and Infrastructure Security Agency (CISA) said Tuesday that the Medusa ransomware gang has breached more than 500 critical infrastructure organizations in the United States since June 2021. --------------------------------------------- https://www.bleepingcomputer.com/news/security /cisa-medusa-ransomware-hit-over-500-critical-infrastructure-orgs/
∗∗∗ Password spraying attacks surge 155x as hackers exploit MFA gaps ∗∗∗ --------------------------------------------- Huntress has observed a 155x increase in password spraying attacks in the first half of 2026. Brute force is old news, but the spin driving that spike is new. --------------------------------------------- https://www.bleepingcomputer.com/news/security /password-spraying-attacks-surge-155x-as-hackers-exploit-mfa-gaps/
∗∗∗ Attackers Exploit MLflow SSRF Flaw to Steal Cloud Credentials and Secrets ∗∗∗ --------------------------------------------- Two critical vulnerabilities impacting MLflow, an open-source artificial intelligence (AI) platform, and FUXA, an open-source, web-based SCADA / HMI software built for operational technology (OT) and industrial automation, are witnessing malicious scanning and exploitation efforts. --------------------------------------------- https://thehackernews.com/2026/08 /attackers-exploit-mlflow-ssrf-flaw-to.html
∗∗∗ Microsoft Links 30+ Rotating Domains to MacSync Stealer Infrastructure ∗∗∗ --------------------------------------------- Microsoft Defender Experts have linked more than 30 web domains to MacSync Stealer, a macOS-focused information stealer, after correlating recurring endpoint and network behaviors across changing infrastructure, tracing the malware from payload retrieval through data collection, staging, and exfiltration. --------------------------------------------- https://thehackernews.com/2026/08 /microsoft-links-30-rotating-domains-to.html
∗∗∗ Clop-Linked Windchill Web Shell Decrypts Credentials and Maps Engineering Data ∗∗∗ --------------------------------------------- A JavaServer Pages (JSP) web shell deployed following the exploitation of a critical security flaw in PTC Windchill and FlexPLM servers is specifically designed for the enterprise Product Lifecycle Management (PLM) software, according to new findings from ReliaQuest. --------------------------------------------- https://thehackernews.com/2026/08/clop-linked-windchill-web-shell.html
∗∗∗ Hackers Compromised 14,500+ Dahua Devices Using Credential Attacks, Auth Bypasses, and P2P ∗∗∗ --------------------------------------------- Cybersecurity researchers at Hunt.io have disclosed details of a campaign that they say compromised more than 14,530 Dahua devices between June 17 and July 22, 2026, using credential attacks, two authentication-bypass flaws, and a peer-to-peer (P2P) relay technique. --------------------------------------------- https://thehackernews.com/2026/08 /hackers-compromised-14500-dahua-devices.html
===================== = Vulnerabilities = =====================
∗∗∗ Oracle-Patchday: Updates für weniger als tausend Schwachstellen ∗∗∗ --------------------------------------------- Oracle fixt zum „Critical Security Patch Update“ knapp 1000 Lücken – weniger als zum letzten regulären „CPU“ genannten Patchday. --------------------------------------------- https://heise.de/-11418883
∗∗∗ LWN Security updates for Wednesday ∗∗∗ --------------------------------------------- https://lwn.net/Articles/1089501/
∗∗∗ Security Vulnerabilities fixed in Thunderbird 153.1 ∗∗∗ --------------------------------------------- https://www.mozilla.org/en-US/security/advisories/mfsa2026-80/
∗∗∗ Security Vulnerabilities fixed in Thunderbird 140.14 ∗∗∗ --------------------------------------------- https://www.mozilla.org/en-US/security/advisories/mfsa2026-79/
∗∗∗ Security Vulnerabilities fixed in Thunderbird 154 ∗∗∗ --------------------------------------------- https://www.mozilla.org/en-US/security/advisories/mfsa2026-78/