===================== = End-of-Day report = =====================
Timeframe: Mittwoch 22-07-2026 18:00 − Donnerstag 23-07-2026 18:00 Handler: Michael Schlagenhaufer Co-Handler: Guenes Holler
===================== = News = =====================
∗∗∗ Microsoft SharePoint: Angriffe auf weitere Sicherheitslücke ∗∗∗ --------------------------------------------- Am Microsoft-Patchday im Juli waren bereits Angriffe auf eine SharePoint-Schwachstelle bekannt. Die hatte jedoch lediglich den Schweregrad „mittel“. Jetzt warnen IT-Sicherheitsfirmen und -Behörden vor beobachteten Attacken auf eine kritische SharePoint-Lücke, für die ebenfalls ein Softwareflicken seit dem Patchday bereitsteht. Zudem wurden Angriffe auf Check Point SmartConsole beobachtet. --------------------------------------------- https://www.heise.de/news/Microsoft-SharePoint-Angriffe-auf-weitere-Sicherhe...
∗∗∗ China-Nexus JadeProx Uses New TriBack Loader in Government and Healthcare Attacks ∗∗∗ --------------------------------------------- An exposed Alibaba Cloud server has revealed a China-nexus operation that Group-IB tracks as JadeProx. The cluster has targeted government, healthcare, and education organizations across Asia and Latin America with a previously undocumented Windows loader called TriBack Loader. --------------------------------------------- https://thehackernews.com/2026/07/china-nexus-jadeprox-uses-new-triback.html
∗∗∗ Linux kernel team publishes 432 CVEs in two days ∗∗∗ --------------------------------------------- If you're responsible for Linux security, someone just dumped a pile of work onto your desk: 432 Linux kernel CVEs were published across Sunday and Monday this week. Linux watchers at nixCraft pointed out the volume on Monday morning, and it didn’t take long for seasoned sysadmins to start expressing concerns. --------------------------------------------- https://www.theregister.com/security/2026/07/22/linux-kernel-team-publishes-...
∗∗∗ 8000 PCs über Steam infiziert: Cyberkriminelle verteilen Malware via Fake-Games ∗∗∗ --------------------------------------------- Cyberkriminelle haben Steam genutzt, um zahlreiche PCs mit Malware zu infizieren. Die Schadsoftware war in Spielen versteckt und wurde gezielt beworben. --------------------------------------------- https://www.heise.de/news/8-000-PCs-ueber-Steam-infiziert-Cyberkriminelle-ve...
∗∗∗ Chaos ransomwares msaRAT: Living off the browser to build a covert C2 channel ∗∗∗ --------------------------------------------- Chaos is a ransomware-as-a-service (RaaS) group whose activity was first confirmed in February 2025. Although the number of listings on their data leak site remains relatively low, the group consistently targets large organizations and employs double extortion tactics. For initial access, they rely on spam emails and voice-based social engineering, commonly known as vishing. Once inside a network, their traditional post-compromise methodology involves abusing remote monitoring and management (RMM) tools to establish persistent access, while leveraging legitimate file-sharing software to exfiltrate data. --------------------------------------------- https://blog.talosintelligence.com/chaos-msarat-living-off-the-browser-to-bu...
∗∗∗ New TrickBot Variant Spotted Using DNS to Control Infected Windows PCs ∗∗∗ --------------------------------------------- Fortinet has found a new TrickBot variant hiding commands in DNS traffic and using scheduled tasks and added modules to maintain access on infected Windows PCs. --------------------------------------------- https://hackread.com/new-trickbot-variant-dns-control-infected-windows-pcs/
∗∗∗ Dark Elevator: Windows Install Service Local Privilege Escalation (CVE-2026-50343) ∗∗∗ --------------------------------------------- Today we walk through Dark Elevator, a LPE in Windows 11. We reported it to Microsoft on May 20, 2026, and it is now fixed as CVE-2026-50343. --------------------------------------------- https://blog.calif.io/p/dark-elevator-windows-install-service
∗∗∗ RefluXFS: A Linux Kernel Local Privilege Escalation to Root in XFS (CVE-2026-64600) ∗∗∗ --------------------------------------------- Qualys Threat Research Unit (TRU) identified CVE-2026-64600, a race condition in the Linux kernel’s XFS filesystem copy-on-write path. An attacker with an ordinary local account can exploit this race condition to overwrite protected files on disk and gain host root privileges on affected systems, including deployments running SELinux in Enforcing mode. --------------------------------------------- https://blog.qualys.com/vulnerabilities-threat-research/2026/07/22/refluxfs-...
∗∗∗ Silent Replacement of Trusted macOS App Executables ∗∗∗ --------------------------------------------- A vulnerability in macOS allows an attacker to silently replace the main executable of any application downloaded from the web without requiring elevated privileges. As a result, trusted applications can be made to execute attacker-controlled code without triggering security warnings when relaunched. Apple assessed the reported behaviour as not requiring a security fix. --------------------------------------------- https://mysk.blog/2026/07/23/macos-overwrite-app-executables/
∗∗∗ Next chapter: Restructuring GitHub’s bug bounty program ∗∗∗ --------------------------------------------- GitHub is making some significant changes to its bug bounty program, shifting its focus to give researchers a better experience working with the GitHub team. --------------------------------------------- https://github.blog/security/next-chapter-restructuring-githubs-bug-bounty-p...
∗∗∗ The CISO Guide to Endpoint Control and Prevention (ECP): The Next Architecture for Endpoint Security ∗∗∗ --------------------------------------------- New category market definition and buyer framework for securing users, agents, identities, and data at the endpoint. A five zone framework for securing AI-centric software at the endpoint. --------------------------------------------- https://softwareanalyst.substack.com/p/the-ciso-guide-to-endpoint-control
∗∗∗ New Study Identifies 53 Slopsquatting Targets Across 5 Frontier LLMs ∗∗∗ --------------------------------------------- Five frontier LLMs generated the same nonexistent package names, leaving 53 available for potential slopsquatting across PyPI and npm. --------------------------------------------- https://socket.dev/blog/slopsquatting-targets-across-frontier-llms?utm_mediu...
===================== = Vulnerabilities = =====================
∗∗∗ VU#847406: Duplicati backup software v2.3.0.1 is vulnerable to an incorrect permission assignment vulnerability ∗∗∗ --------------------------------------------- Duplicati v2.3.0.1 is vulnerable to arbitrary code execution when installed outside the default C:\Program Files\Duplicati 2\ directory. An attacker with local user privileges who can write files to the Duplicati installation directory can execute arbitrary code by placing malicious files, such as DLLs, in that directory. To mitigate this vulnerability, install Duplicati in the default C:\Program Files\ directory or update to the latest fixed version. --------------------------------------------- https://kb.cert.org/vuls/id/847406
∗∗∗ Atlassian: Schadcode-Lücken bedrohen Bamboo und Bitbucket ∗∗∗ --------------------------------------------- Nutzen Angreifer erfolgreich Sicherheitslücken in Atlassian Bamboo, Bitbucket, Confluence, Crowd, Fisheye/Crucible, Jira, Jira Service Management oder Sourcetree für macOS/Windows aus, können sie PCs im schlimmsten Fall vollständig kompromittieren. Sicherheitsupdates stehen zum Download bereit. --------------------------------------------- https://www.heise.de/news/Atlassian-Schadcode-Luecken-bedrohen-Bamboo-und-Bi...
∗∗∗ Drupal Security Advisories 2026-July-22 ∗∗∗ --------------------------------------------- https://www.drupal.org/security
∗∗∗ Ricoh MFP and Printer Products: Vulnerability in SSH Function ∗∗∗ --------------------------------------------- https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2026-00...
∗∗∗ LWN Security updates for Thursday ∗∗∗ --------------------------------------------- https://lwn.net/Articles/1084401/