===================== = End-of-Day report = =====================
Timeframe: Donnerstag 16-07-2026 18:00 − Freitag 17-07-2026 18:00 Handler: Guenes Holler Co-Handler: Michael Schlagenhaufer
===================== = News = =====================
∗∗∗ Kurz nach Microsoft-Patchday: Kritische Sharepoint-Lücke wird aktiv ausgenutzt ∗∗∗ --------------------------------------------- Bei der besagten Sicherheitslücke handelt es sich um CVE-2026-58644. Laut Beschreibung kann ein Angreifer damit aus der Ferne Schadcode einschleusen und zur Ausführung bringen. Ursache ist eine mögliche Deserialisierung nicht-vertrauenswürdiger Daten in Microsoft Sharepoint. Den Angaben zufolge muss ein Angreifer für eine erfolgreiche Ausnutzung mindestens als Site Owner authentifiziert sein. --------------------------------------------- https://www.golem.de/news/kurz-nach-microsoft-patchday-kritische-sharepoint-...
∗∗∗ Claude Chrome extension flaw lets malicious extensions trigger AI actions ∗∗∗ --------------------------------------------- A flaw in Anthropics Claude for Chrome browser extension could allow a malicious extension to trigger predefined AI actions by simulating user clicks, potentially allowing it to abuse Claudes access to connected services such as Gmail, Google Docs, Google Calendar, and Salesforce. --------------------------------------------- https://www.bleepingcomputer.com/news/security/claude-chrome-extension-flaw-...
∗∗∗ New ClickLock macOS malware traps users into revealing login password ∗∗∗ --------------------------------------------- A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. --------------------------------------------- https://www.bleepingcomputer.com/news/security/new-clicklock-macos-malware-t...
∗∗∗ Ernst & Young discloses data breach after support system hack ∗∗∗ --------------------------------------------- Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. --------------------------------------------- https://www.bleepingcomputer.com/news/security/ernst-and-young-discloses-dat...
∗∗∗ 1M+ Emails Use Hidden Text to Dupe AI Security Filters ∗∗∗ --------------------------------------------- Artificial intelligence and LLMs can be surprisingly ineffective against text salting, allowing phishing emails to slide right into your inbox. --------------------------------------------- https://www.darkreading.com/threat-intelligence/1m-emails-hidden-text-dupe-a...
∗∗∗ Fake Coding Tests Deliver OtterCookie-Aligned Malware Hidden in SVG Flag Images ∗∗∗ --------------------------------------------- North Korean threat actors linked to the Contagious Interview campaign have been observed employing steganography in SVG image files to conceal malicious payloads as part of a campaign using fake job postings and coding challenges. --------------------------------------------- https://thehackernews.com/2026/07/north-korea-linked-hackers-hide.html
∗∗∗ Windows Server 2022: Mainstream-Support endet in 90 Tagen ∗∗∗ --------------------------------------------- Windows Server 2022 fällt in 90 Tagen aus dem Mainstream-Support. Erweiterte Sicherheitsupdates gibt es bis 2031 – und danach ESU. --------------------------------------------- https://www.heise.de/news/Windows-Server-2022-Mainstream-Support-endet-in-90...
∗∗∗ AI, Automation and Attacks: Unpacking the Unit 42 2026 Global Incident Response Report ∗∗∗ --------------------------------------------- The report spotlights four defining trends shaping the threat landscape. We’ll take a closer look at Trend 1: AI Has Become a Force Multiplier for Attackers. --------------------------------------------- https://unit42.paloaltonetworks.com/ai-incident-response-report/
===================== = Vulnerabilities = =====================
∗∗∗ Google Chrome: Ungeplantes Sicherheitsupdate Nummer zwei in dieser Woche ∗∗∗ --------------------------------------------- Google aktualisiert Chrome eigentlich jeden Mittwoch. Diese Woche folgt ein zweites Update, das mehrere kritische Lücken schließt. [..] Drei davon gelten als „kritisch“, es handelt sich um nicht näher erläuterte Use-after-free-Schwachstellen in den Komponenten CameraCapture (CVE-2026-15899), GPU (CVE-2026-15900) sowie Network (CVE-2026-15901). --------------------------------------------- https://heise.de/-11368362
∗∗∗ Critical Notepad++ Bugs Could Lead to Code Execution, Patch Available ∗∗∗ --------------------------------------------- The latest Notepad++ vulnerabilities addressed in version 8.9.7 include several high-impact security flaws that could expose Windows systems to arbitrary code execution, file overwrite attacks, memory corruption, and authentication bypass. Among the most critical issues is a PowerShell command injection vulnerability in the installer, alongside fixes for CVE-2026-52886, CVE-2026-54758, and CVE-2026-57233. --------------------------------------------- https://thecyberexpress.com/notepad-vulnerabilities-v897/
∗∗∗ VU#885548: Denial-of-service vulnerability in HTTP/2 servers via stalled flow-control conditions ∗∗∗ --------------------------------------------- https://kb.cert.org/vuls/id/885548
∗∗∗ LWN: Security updates for Friday ∗∗∗ --------------------------------------------- https://lwn.net/Articles/1083388/