===================== = End-of-Day report = =====================
Timeframe: Dienstag 21-07-2026 18:00 − Mittwoch 22-07-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: n/a
===================== = News = =====================
∗∗∗ Critical SharePoint RCE flaw exploited to steal machine keys ∗∗∗ --------------------------------------------- Hackers are actively exploiting the critical CVE-2026-50522 vulnerability in Microsoft SharePoint to steal machine keys and maintain access even after affected servers are patched. [..] While applying the latest SharePoint security updates removes the vulnerability, watchTowr advises defenders to also rotate credentials on any asset that may have been exposed. --------------------------------------------- https://www.bleepingcomputer.com/news/security/critical-sharepoint-rce-flaw-...
∗∗∗ OpenAI hackt beliebtes KI-Portal, macht daraus PR-Stunt ∗∗∗ --------------------------------------------- Die neuesten Modelle seien bei einem Sicherheitstest eigenständig „ausgebrochen“ und hätten Hugging Face attackiert. [..] Der US-Konzern OpenAI hat nun die Verantwortung dafür übernommen. --------------------------------------------- https://futurezone.at/digital-life/openai-hugging-face-hack-pr-stunt/4031775...
∗∗∗ Cyberangriff: Nextcloud-Nutzer wurden auf verdächtige Cloudbox umgeleitet ∗∗∗ --------------------------------------------- Die offizielle Website von Nextcloud ist nach verdächtigen Umleitungen der Besucher temporär vom Netz genommen worden. Ursache war ein Cyberangriff. [..] Da die Nextcloud-Website auf Wordpress basiert, ist denkbar, dass der Angriff unter Ausnutzung zweier kürzlich bekannt gewordener Sicherheitslücken in dem CMS ausgeführt wurde. --------------------------------------------- https://www.golem.de/news/cyberangriff-nextcloud-nutzer-wurden-auf-verdaecht...
∗∗∗ Windows: Global Device ID führt zu gerichtswirksamer Identifikation ∗∗∗ --------------------------------------------- Microsoft nutzt in Windows eine Global Device ID (GDID). Die macht Windows-Installationen eindeutig erkennbar, sie übersteht Neustarts und Windows-Updates und lässt sich nicht entfernen. [..] Auf GitHub hat sich ein User mit dem Handle „SmtimesIWndr“ die Mühe gemacht und Informationen zur Windows GDID zusammengesammelt. Es handelt sich demnach um einen Bestandteil der Windows-Telemetrie, der wird zusammen mit anderen Informationen an Microsofts Server gesendet. [..] Der Global Device Identifier lässt sich also nicht einfach loswerden. --------------------------------------------- https://heise.de/-11373417
∗∗∗ PyPI: Releases now reject new files after 14 days ∗∗∗ --------------------------------------------- The Python Package Index (PyPI) now rejects new files being uploaded to releases that are older than 14 days. This restriction was put in place to prevent old and long-stable releases from being poisoned in case publishing tokens or workflows of PyPI projects were compromised. --------------------------------------------- https://blog.pypi.org/posts/2026-07-22-releases-now-reject-new-files-after-1...
∗∗∗ LG to Ban Residential Proxies from Smart TV Apps ∗∗∗ --------------------------------------------- The home appliance giant LG Electronics USA said this week it plans to suspend any apps built for its smart TVs that turn ones television into an always-on residential proxy node. The move comes less than a month after researchers found that more than 42 percent of games and other apps available for download on LGs webOS store allow unknown third-parties to route their Internet traffic through a users TV. --------------------------------------------- https://krebsonsecurity.com/2026/07/lg-to-ban-residential-proxies-from-smart...
∗∗∗ Klimabonus-Phishing ist zurück: Klicken Sie nicht auf diesen Mail-Link! ∗∗∗ --------------------------------------------- Die Kriminellen lassen nicht locker: Aktuell wieder in einer neuen Variante betreffend den Klimabonus im Umlauf. Eine betrügerische E-Mail verspricht Empfänger:innen 290 Euro. --------------------------------------------- https://www.watchlist-internet.at/news/klimabonus-phishing-mail/
∗∗∗ Adobe Chrome extension flaw let sites access private WhatsApp chats ∗∗∗ --------------------------------------------- Exploiting them requires only that the target running the Adobe Acrobat extension be lured to a web page under the threat actor's control. [..] The issue has been fixed in 26.5.2.3 and delivered automatically to users. --------------------------------------------- https://www.bleepingcomputer.com/news/security/adobe-chrome-extension-flaw-l...
∗∗∗ AWS Kiro Flaw Let a Poisoned Web Page Rewrite Its Config and Run Code ∗∗∗ --------------------------------------------- Hidden text on a web page was enough to make Kiro, AWSs agentic coding IDE, rewrite its own configuration file and run an attackers code on a developers machine, with no approval step able to stop it. Intezer, in research with Kodem Security, found that a request as ordinary as asking Kiro to summarize a page could end in remote code execution. --------------------------------------------- https://thehackernews.com/2026/07/aws-kiro-flaw-let-poisoned-web-page.html
===================== = Vulnerabilities = =====================
∗∗∗ Serv-U: Datentransfersoftware Serv-U hat 15 kritische Sicherheitslücken ∗∗∗ --------------------------------------------- SolarWinds stopft mit dem Update auf Serv-U 2026.3 insgesamt 15 kritische Sicherheitslücken sowie eine mittleren Schweregrads. Die Auswirkungen reichen von der Rechteausweitung über Informationslecks hin zur Ausführung von eingeschleustem Schadcode aus dem Netz. --------------------------------------------- https://heise.de/-11373098
∗∗∗ Ubuntu: Root-Lücke in snapd gefährdet unzählige Linux-Systeme ∗∗∗ --------------------------------------------- Angreifer können damit ihre Rechte ausweiten und Root-Zugriff erlangen. Laut Blogbeitrag der Forscher gelingt das bei anfälligen Ubuntu-Versionen bereits in der Standardkonfiguration. Patches sind verfügbar und sollten zeitnah installiert werden. [..] Die Ursache liegt in snap-confine, einer Komponente, die für den Aufbau der Ausführungsumgebung von Snap-Paketen zuständig ist. CVE-2026-8933 --------------------------------------------- https://www.golem.de/news/ubuntu-root-luecke-in-snapd-gefaehrdet-unzaehlige-...
∗∗∗ Oracle Critical Patch Update Advisory - July 2026 ∗∗∗ --------------------------------------------- This Critical Patch Update contains 1449 new security patches across the product families listed below. --------------------------------------------- https://www.oracle.com/security-alerts/cpujul2026.html
∗∗∗ Check Point: Security Advisory – Action Required – July 2026 Security Update ∗∗∗ --------------------------------------------- As part of Check Point’s Frontier AI Readiness Program, we are releasing a jumbo hotfix with security and hardening fixes for our firewall and management products. [..] This only affects a very specific configuration — when Management is exposed directly to the internet without IP restrictions. We’ve already notified the affected customers. --------------------------------------------- https://blog.checkpoint.com/security/security-advisory-action-required-activ...
∗∗∗ Plane: VU#762226: Plane contains multi-tenant authorization bypass vulnerability ∗∗∗ --------------------------------------------- https://kb.cert.org/vuls/id/762226
∗∗∗ LWN: Security updates for Wednesday ∗∗∗ --------------------------------------------- https://lwn.net/Articles/1084210/
∗∗∗ QNAP: Kritische Schwachstellen in QNAP NAS File Station 5 ∗∗∗ --------------------------------------------- https://www.syss.de/pentest-blog/kritische-schwachstellen-in-qnap-nas-file-s...