IT-Sicherheits-Digest (2026-09-11)

IT‑Sicherheits‑Digest (2026-09-11) Aktuelle Security‑News heise security Vierter Hacking-Vorfall: Weiteres Anthropic-Modell bricht aus Testumgebung aus (2026-09-10 13:46 UTC) Kurz: Nachdem Anthropic schon Ende Juli drei Hacking-Angriffe meldete, ist nach Analyse der Daten jetzt noch ein vierter bei Claude Opus 4.6 hinzugekommen. Quelle: Link Kritische Schadcode-Lücken bedrohen Ivanti Neurons for ITSM (2026-09-10 13:15 UTC) Kurz: Angreifer können Ivanti Endpoint Manager Mobile, Neurons for ITSM und Sentry attackieren. Sicherheitsupdates sind verfügbar. Quelle: Link Sicherheitslücken in ePA-Clients: „Die Implementierungen hatten blinde Flecken“ (2026-09-10 12:53 UTC) Kurz: Sicherheitsforscher sorgten für Fixes kritischer Lücken in ePA-Clients und der Telematikinfrastruktur. Dr. Simon Weber erklärt die Details im Interview. Quelle: Link BleepingComputer Trezor: 347,000 users targeted in phishing attacks after Brevo breach (2026-09-11 07:55 UTC) Kurz: Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. […] Quelle: Link Conti ransomware gang member sentenced to 4 years in prison (2026-09-11 06:48 UTC) Kurz: A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. […] Quelle: Link New Android malware encrypts files, steals data, and harasses victims (2026-09-10 21:40 UTC) Kurz: A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. […] Quelle: Link The Hacker News Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors (2026-09-11 07:31 UTC) Kurz: Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw th… Quelle: Link China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor (2026-09-11 07:14 UTC) Kurz: A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims’ computers, security company Gen Digital said in research publ… Quelle: Link PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws (2026-09-11 06:46 UTC) Kurz: PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development comp… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches CVE-2026-73784 — CVSS 8.8 (HIGH) Kurz: A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user. Quelle: Link CVE-2026-73785 — CVSS 7.5 (HIGH) Kurz: A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS). Quelle: Link CVE-2026-15889 — CVSS 6.4 (MEDIUM) Kurz: The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Content in all versions up to, and including, 3.0.14 due to insufficient input sanitization and output escaping. This… Quelle: Link VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

September 11, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-09-10)

IT‑Sicherheits‑Digest (2026-09-10) Aktuelle Security‑News heise security Jetzt patchen! Angreifer kompromittieren Cisco-Firewalls als Root (2026-09-10 07:52 UTC) Kurz: Angreifer attackieren derzeit Cisco Secure Firewall Management Center. Sicherheitsupdates sind seit März 2026 verfügbar. Quelle: Link OpenAI-Agenten haben auf mehr als 10 weiteren Websites unerlaubt kommuniziert (2026-09-10 03:04 UTC) Kurz: Sicherheitsforscher haben Spuren ausgebrochener KI-Agenten von OpenAI auf zusätzlichen Webseiten entdeckt. Zumeist haben sie sich auf Wiki-Seiten ausgetauscht. Quelle: Link Anstieg von Verbrauch an KI-Tokens – was einige Claude-Nutzer berichten (2026-09-09 13:38 UTC) Kurz: Einige Claude-User schauen derzeit geschockt auf ihren Token-Verbrauch. Obwohl sie die KI-Tools teilweise tagelang nicht nutzen, steigt der Verbrauch weiter. Quelle: Link BleepingComputer Trezor warns users of email provider breach, phishing attacks (2026-09-10 06:56 UTC) Kurz: Trezor warned customers on Wednesday that threat actors who breached its third-party email provider are targeting them in phishing attacks. […] Quelle: Link Cisco confirms CVE-2026-20079 Secure FMC flaw exploited in attacks (2026-09-09 21:40 UTC) Kurz: Cisco has confirmed that a maximum-severity authentication bypass vulnerability tracked as CVE-2026-20079 in its Secure Firewall Management Center (FMC) software is being actively exploited in attacks. […] Quelle: Link AdaptHealth confirms 4.1 million people exposed in July cyberattack (2026-09-09 21:30 UTC) Kurz: Healthcare company AdaptHealth has confirmed that data of 4.1 million people was exposed in a cyberattack discovered in July that was attributed to the ShinyHunters threat group. […] Quelle: Link The Hacker News U.S. Disrupts Xinbi Guarantee Scam Marketplace, Freezes $52.8 Million in Crypto (2026-09-09 18:26 UTC) Kurz: The U.S. Department of Justice (DoJ) on Wednesday announced coordinated actions aimed at an illicit online marketplace called Xinbi Guarantee that offered scam services, including seizing Telegram channels used to run the service, confiscat… Quelle: Link Four Spy Groups Used the Same Chrome and Windows Exploit Kit Within a Week (2026-09-09 16:34 UTC) Kurz: Multiple espionage-motivated threat activity clusters have been found deploying a previously undocumented exploit kit called BlueMoon that chains together multiple vulnerabilities in Microsoft Windows and Google Chrome. The first in-the-wil… Quelle: Link Infostealer Logs Expose Replayable AI Tokens That Can Bypass MFA (2026-09-09 14:23 UTC) Kurz: Cybercriminals are hijacking artificial intelligence (AI) user accounts via information stealer logs to create “stolen keys” that grant illicit access to tools from model providers like Google, Anthropic, and others. Information stealers li… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

September 10, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-09-09)

IT‑Sicherheits‑Digest (2026-09-09) Aktuelle Security‑News heise security Schweiz baut Alternative zu Microsoft 365 auf (2026-09-08 13:26 UTC) Kurz: Die Schweizer Bundeskanzlei startet ein Programm für eine souveräne Arbeitsplatzsoftware. Rund 3000 Beschäftigte sollen sie nutzen. Quelle: Link „WeWorm“: Zero-Click-Wurm hätte alle Konten von WeChat übernehmen können (2026-09-08 12:27 UTC) Kurz: Eine KI hat eine Schwachstelle in WeChat gefunden, über die man in kürzester Zeit eine Milliarde Konten hätte übernehmen können. Sie ist bereits geschlossen. Quelle: Link BleepingComputer New Microsoft Defender ‘ShieldCrash’ zero-day grants SYSTEM access (2026-09-09 07:30 UTC) Kurz: An anonymous security researcher known as Nightmare Eclipse has released a new Microsoft Defender zero-day exploit named “ShieldCrash” right after Microsoft rolled out its September 2026 Patch Tuesday security updates. […] Quelle: Link Google warns of new Chrome zero-day bug exploited in attacks (2026-09-09 06:25 UTC) Kurz: Google has patched 230 vulnerabilities on Tuesday, including another actively exploited Chrome zero-day bug, the seventh such vulnerability patched since the start of the year. […] Quelle: Link Microsoft adds age-awareness APIs that can tell if users are children, teens, or adults (2026-09-09 01:16 UTC) Kurz: Microsoft is adding new age-awareness APIs to Windows 11 that will allow apps to determine whether someone is a child, teenager, or adult without exposing their exact date of birth. […] Quelle: Link The Hacker News Microsoft Patches Record 974 Flaws, Including Two Exploited Windows Zero-Days (2026-09-09 04:41 UTC) Kurz: Microsoft on Tuesday broke Patch Tuesday records by addressing an earth-shattering 974 vulnerabilities spanning its software portfolio, including two flaws that it said have been actively exploited in the wild. These include 723 flaws in Wi… Quelle: Link N-able N-central Pre-Auth RCE Flaw Exploited in the Wild (2026-09-09 04:27 UTC) Kurz: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a maximum-severity security flaw impacting N-able N-central to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executive Branch … Quelle: Link Slim Spider Steals Crypto Custody Secrets From Brazilian Financial Institution (2026-09-08 16:20 UTC) Kurz: A previously undocumented financially motivated threat actor has been linked to attacks targeting Brazilian financial institutions since at least March 2026. Cybersecurity company CrowdStrike is tracking the Brazil-based activity cluster un… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) CVE-2026-26084 — CVSS 9.9 (CRITICAL) Kurz: A improper access control vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.5, FortiSandbox 4.4.0 through 4.4.8, FortiSandbox Cloud 5.0.4 through 5.0.5, FortiSandbox PaaS 5.0.4 through 5.0.5 may allow attacker to … Quelle: Link CVE-2026-84393 — CVSS 8.1 (HIGH) Kurz: A improper validation of certificate with host mismatch vulnerability in Fortinet FortiOS 7.6.1 through 7.6.6, FortiProxy 7.6.2 through 7.6.6 may allow attacker to information disclosure via Quelle: Link CVE-2026-84387 — CVSS 7.2 (HIGH) Kurz: A improper neutralization of special elements used in a command (‘command injection’) vulnerability in Fortinet FortiSandbox 5.2.0, FortiSandbox 5.0.0 through 5.0.6, FortiSandbox 4.4.0 through 4.4.9 may allow attacker to… Quelle: Link CVE-2026-84385 — CVSS 5.4 (MEDIUM) Kurz: A improper access control vulnerability in Fortinet FortiSOAR PaaS 7.6.0 through 7.6.6, FortiSOAR PaaS 7.5.0 through 7.5.3, FortiSOAR PaaS 7.4 all versions, FortiSOAR PaaS 7.3 all versions, FortiSOAR on-premise 7.6.0 thr… Quelle: Link CVE-2026-84386 — CVSS 5.1 (MEDIUM) Kurz: A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via Quelle: Link CVE-2026-22575 — CVSS 4.9 (MEDIUM) Kurz: An improper access control vulnerability in Fortinet FortiManager 7.6.0 through 7.6.4, FortiManager 7.4.0 through 7.4.10, FortiManager 7.2 all versions, FortiManager Cloud 7.6.2 through 7.6.4, FortiManager Cloud 7.4.1 th… Quelle: Link Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

September 9, 2026 · 4 min · Betty

IT-Sicherheits-Digest (2026-09-08)

IT‑Sicherheits‑Digest (2026-09-08) Aktuelle Security‑News heise security Ein Start-up entfernt Verweigerung aus KI-Modellen und verdient daran (2026-09-08 05:54 UTC) Kurz: Das Start-up Abliteration AI entfernt Verweigerungsmechanismen aus KI-Modellen. Das hilft Security-Teams, schafft aber auch neue Missbrauchsrisiken. Quelle: Link Sicherheitsvorfall bei Liquid Network: 320 Millionen US-Dollar in Bitcoin weg (2026-09-07 19:24 UTC) Kurz: „Angebliche White-Hat-Hacker“ haben mutmaßlich rund 4.000 der 4.200 Bitcoins abgezogen, die in der Liquid-Federation-Wallet des Unternehmens verwahrt waren. Quelle: Link NetBSD 9.5 schließt Sicherheitslücken – und beendet Support (2026-09-07 15:45 UTC) Kurz: Zum Abschied von NetBSD 9.x gibt es noch einmal einige Sicherheits- und Stabilitätskorrekturen. Ein Umstieg auf NetBSD 10 oder 11 wird ausdrücklich empfohlen. Quelle: Link BleepingComputer 220 million traveler records exposed in Vietnam-linked APIS leak (2026-09-08 07:35 UTC) Kurz: Exclusive: An exposed Advance Passenger Information System (APIS) database held 220 million passenger and crew records containing names, passport numbers, dates of birth, nationalities, and flight details spanning 2017 to 2026. Researchers … Quelle: Link Magento StyleSmuggler zero-day exploited to deploy Linux backdoor (2026-09-07 16:50 UTC) Kurz: A zero-day vulnerability dubbed “StyleSmuggler” affecting all versions of Magento and Adobe Commerce is being exploited in attacks to deploy a backdoor. […] Quelle: Link BigBear Microsoft 365 phishing service bypassed MFA at 258 organizations (2026-09-07 15:39 UTC) Kurz: A phishing-as-a-service framework called BigBear 2.0 has been used to bypass multi-factor authentication at 258 organizations and steal more than 5,000 Microsoft 365 credentials. […] Quelle: Link The Hacker News PEEP Turns Chrome and Edge Into Post-Compromise Backdoors for Host Command Execution (2026-09-07 18:12 UTC) Kurz: Cybersecurity researchers have disclosed details of a complex Chromium-based post-exploitation toolkit called PEEP that masquerades as a bookmarks extension for the web browser. “Requiring prior administrative or code execution access, its … Quelle: Link Fake IT Calls Target Executives in Microsoft 365 Data Theft and Extortion Attacks (2026-09-07 15:51 UTC) Kurz: Threat hunters have disclosed details of a widespread data theft and extortion threat cluster that’s targeting Microsoft 365 and other software-as-a-service (SaaS) offerings through information technology (IT) help desk vishing, adversary-i… Quelle: Link ⚡ Weekly Recap: Chrome 0-Day, Router Hijacks, Coder Supply Chain Attack and More (2026-09-07 14:36 UTC) Kurz: Turning off email images should at least stop the pictures. This week, attackers had a workaround: a scannable QR code built out of text. It still appears, even with images blocked. A small detail, but an annoying one if that was a precauti… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

September 8, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-09-07)

IT‑Sicherheits‑Digest (2026-09-07) Aktuelle Security‑News heise security Unheimliches Schwarmverhalten: OpenAI-Agenten kollaborieren auf deutschem Wiki (2026-09-06 16:47 UTC) Kurz: Tausende KI-Agenten brechen laut einer neuen Analyse aus ihren Testumgebungen aus, teilen Antworten und tauschen Wege zum Umgehen von Sicherheitsbarrieren aus. Quelle: Link Cyberattacke auf Berlin könnte größere Folgen haben als bisher gedacht (2026-09-06 15:52 UTC) Kurz: Rund 1,44 Millionen Dateien der Berliner Verwaltung stehen seit Freitag im Darknet. Das Ausmaß könnte viel weitreichender sein als angenommen. Quelle: Link BleepingComputer N-able patches max severity N-central flaw amid ongoing attacks (2026-09-07 06:17 UTC) Kurz: N-able has released an emergency hotfix for a maximum-severity remote code execution (RCE) flaw affecting its N-central remote monitoring and management (RMM) platform. […] Quelle: Link ChatGPT Astra is now rolling out to $20 Plus subscription (2026-09-07 01:15 UTC) Kurz: OpenAI is now rolling out ChatGPT Astra, its most powerful model to date, to those with a $20 Plus subscription, but there’s no word on when free users will get access.. […] Quelle: Link Attackers conceal phishing lures using invisible Unicode characters (2026-09-06 14:23 UTC) Kurz: Threat actors have adopted the ASCII smuggling technique in phishing campaigns, using invisible Unicode characters to evade email security filters. […] Quelle: Link The Hacker News Attackers Hijack MikroTik Routers Through Internet-Exposed SSH Without Authentication (2026-09-06 09:32 UTC) Kurz: Attackers are exploiting MikroTik routers with their Secure Shell (SSH) remote-access service, which is reachable from the internet, to gain full administrative control without authentication, according to CERT Polska’s attack warning, publ… Quelle: Link Four REVSTEALER-Linked Modules Disable Windows Update and Defender to Run a Crypto Miner (2026-09-06 08:34 UTC) Kurz: Elastic Security Labs has documented four previously unreported programs associated with REVSTEALER, an emerging Windows information stealer, that remain on an infected machine after the stealer deletes itself. One of them switches off Wind… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

September 7, 2026 · 2 min · Betty

IT-Sicherheits-Digest (2026-09-06)

IT‑Sicherheits‑Digest (2026-09-06) Aktuelle Security‑News heise security Draht statt Sprengstoff: Angriffe auf Umspannwerke und Grenzen der Netzredundanz (2026-09-05 14:41 UTC) Kurz: Sabotage an Umspannwerken zeigt, wie leicht Gigawatt vom Netz gehen, warum Schutztechnik Blackouts verhinderte – und wo der Kritis-Schutz hinterherhinkt. Quelle: Link BleepingComputer Over 5,400 hacked sites serve ClickFix payloads stored on the blockchain (2026-09-05 14:29 UTC) Kurz: A massive cybercriminal operation is leveraging thousands of compromised small-business websites to deliver ClickFix payloads stored in smart contracts on the BNB Smart Chain (BSC). […] Quelle: Link OpenAI admits it didn’t disclose rogue AI wiki hijacking incident (2026-09-05 11:11 UTC) Kurz: OpenAI admits it did not disclose an incident where autonomous AI agents hijacked a German wiki, created 18,000 posts, shared answers, and bypassed restrictions, saying it treated the activity as model “misalignment” rather than a security … Quelle: Link The Hacker News Unpatched Magento and Adobe Commerce Zero-Day Exploited to Backdoor Online Stores (2026-09-05 20:14 UTC) Kurz: Attackers are exploiting a new unpatched vulnerability in Magento Open Source and Adobe Commerce that lets them run malicious code on an online store’s server without logging in, Dutch e-commerce security company Sansec said in an advisory … Quelle: Link Attackers Breached JetBrains Cadence via Unpatched TeamCity, Extracting AWS Credentials (2026-09-05 16:52 UTC) Kurz: JetBrains is urging Cadence users to revoke and rotate all credentials following a security incident last month in which unidentified threat actors exploited a recently disclosed critical vulnerability in TeamCity to breach its own environm… Quelle: Link Critical VMware Workstation and Fusion Flaw Lets VM Admins Execute Host Code (2026-09-05 16:05 UTC) Kurz: Broadcom has released security updates for two security flaws impacting VMware Workstation and Fusion, including one critical bug that could result in arbitrary code execution under certain conditions. The vulnerability, tracked as CVE-2026… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

September 6, 2026 · 2 min · Betty

IT-Sicherheits-Digest (2026-09-05)

IT‑Sicherheits‑Digest (2026-09-05) Aktuelle Security‑News heise security WTF: Die KI-Hersteller werden beim Datensammeln immer skrupelloser (2026-09-05 07:03 UTC) Kurz: LLMs brauchen große Mengen an originären Daten für das Training. Um an diese zu gelangen, kennen die KI-Hersteller keine Grenzen. Quelle: Link Berliner Senat zahlt nicht - sensible Daten jetzt im Darknet (2026-09-04 15:37 UTC) Kurz: Nach Ablauf eines Ultimatums hat die Hackergruppe Rhysida mehrere Terabyte an Daten aus dem Berliner Landesnetz im Darknet veröffentlicht. Quelle: Link EU-Verteidigungspläne: Experten warnen vor digitaler Souveränität um jeden Preis (2026-09-04 14:48 UTC) Kurz: Verteidigungsbeamte und Rüstungskonzerne warnen vor dem EU-Gesetz CADA. Sie befürchten, dass der zu schnelle Ausschluss von US-Technik die Sicherheit gefährdet. Quelle: Link BleepingComputer IDScan sued over alleged data breach affecting 153 million drivers (2026-09-04 16:56 UTC) Kurz: Multiple lawsuits have been filed against identity verification company IDScan after hackers allegedly breached the service and offered to sell more than 153 million driver’s licenses. […] Quelle: Link Critical Citrix NetScaler auth bypass now leveraged in attacks (2026-09-04 15:25 UTC) Kurz: Attackers have begun targeting a critical-severity Citrix NetScaler auth bypass flaw (CVE-2026-19490) in the wild, according to vulnerability intelligence company Previdian. […] Quelle: Link Microsoft says some users can’t open the Teams desktop client (2026-09-04 14:30 UTC) Kurz: Microsoft is working to resolve a known issue that causes delays or blocks some users from opening the Microsoft Teams desktop client on Windows systems. […] Quelle: Link The Hacker News Attackers Exploit PaperCut Flaws to Steal Credentials From Schools and Universities (2026-09-05 07:31 UTC) Kurz: Threat actors are exploiting the newly disclosed PaperCut flaws to facilitate credential theft in attacks targeting the education sector in the U.S. and Europe. The Arctic Wolf Adversary Research Team said it observed attackers exploiting C… Quelle: Link Phishing Campaign Sends Millions of Emails Using Invisible Unicode to Evade Filters (2026-09-04 15:57 UTC) Kurz: Microsoft is alerting of a “high-volume phishing campaign” that’s using invisible Unicode tag characters to bypass email filters. “Instead of using these characters to hide instructions from people while exposing them to AI models, the atta… Quelle: Link PostgreSQL Fixes 12-Year-Old Logical Decoding Flaw Enabling Replication-Role Code Execution (2026-09-04 15:20 UTC) Kurz: PostgreSQL has released updates to address a security flaw that allows an account with the REPLICATION attribute to run arbitrary code as the operating-system user running the database server. The flaw, tracked as CVE-2026-6471 (CVSS score:… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

September 5, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-09-04)

IT‑Sicherheits‑Digest (2026-09-04) Aktuelle Security‑News heise security Jetzt patchen! Es laufen derzeit Schadcode-Attacken auf Chrome (2026-09-04 06:48 UTC) Kurz: Google hat mehrere Sicherheitslücken im Webbrowser Chrome geschlossen. Eine Schwachstelle nutzen Angreifer bereits aus. Quelle: Link Auslegungssache 167: Datenschutz mit System (2026-09-04 04:10 UTC) Kurz: Wie Unternehmen Datenschutz praxistauglich organisieren, erklärt Beraterin Regina Mühlich im c’t-Datenschutz-Podcast. Quelle: Link Kehrtwende bei Cybersicherheit: Bund gibt Plan für BSI-Grundgesetzänderung auf (2026-09-03 16:58 UTC) Kurz: Trotz der verschärften Bedrohungslage und verstärkter IT-Angriffe verzichtet die Bundesregierung überraschend auf eine Verfassungsänderung zur Stärkung des BSI. Quelle: Link BleepingComputer French hospital fined €500,000 after breach exposes data of 727,000 (2026-09-03 22:01 UTC) Kurz: France’s data protection authority (CNIL) has fined Hôpital privé de la Loire €500,000 ($580,000) for failing to adequately protect patients’ and their relatives’ data. […] Quelle: Link Coder’s registry infrastructure compromised to push malicious modules (2026-09-03 20:04 UTC) Kurz: Attackers compromised Coder’s Cloudflare infrastructure and added unauthorized registry servers that delivered malicious Terraform modules containing credential-stealing code. […] Quelle: Link HPE patches critical ArubaOS-CX remote code execution flaw (2026-09-03 18:28 UTC) Kurz: Hewlett Packard Enterprise (HPE) has patched a critical vulnerability in the ArubaOS-CX network operating system that could lead to remote code execution. […] Quelle: Link The Hacker News ThreatsDay: CEO Phishing Kits, 5K Dropbox Account Hacks, OAuth Traps + 17 More Stories (2026-09-03 18:02 UTC) Kurz: The worst part is how normal these attacks look. A call from IT. A shared file. A trusted app. A simple request to click “Allow.” Why break in when someone might open the door? That idea runs through this edition. Attackers use real tools, … Quelle: Link Critical Cisco Nexus 9000 Flaw Lets Unauthenticated Remote Attackers Run Code as Root (2026-09-03 15:52 UTC) Kurz: Cisco has released patches to address a critical security flaw affecting 10 Silicon One-based Nexus 9000 switches that could allow an unauthenticated, remote attacker to execute code as root, alongside an IOS XR hardening release bundling 7… Quelle: Link BraZetsu Malware Turns Compromised Windows Hosts Into Criminal Marketplace Inventory (2026-09-03 15:26 UTC) Kurz: Cybersecurity researchers have disclosed details of a sophisticated Python-based Windows malware framework called BraZetsu that fuels an underground marketplace commercializing access to compromised hosts. “Unlike the standard infostealer m… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

September 4, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-09-03)

IT‑Sicherheits‑Digest (2026-09-03) Aktuelle Security‑News heise security WhatsApp-Sicherheitslücke: Zugriff auf Fotos bei gesperrtem Android-Handy (2026-09-03 07:18 UTC) Kurz: Eine Sicherheitslücke in WhatsApp für Android ermöglicht es, bei einem eingehenden Videoanruf auf private Fotos zuzugreifen, ohne das Gerät zu entsperren. Quelle: Link ServiceNow AI Platform: Angreifer können aus Sandbox ausbrechen (2026-09-02 13:17 UTC) Kurz: Die Software zum Automatisieren und Optimieren von Geschäftsprozessen ServiceNow AI Platform ist verwundbar. Quelle: Link Für Unternehmen: Zero Data Retention-Option für Fable (2026-09-02 12:54 UTC) Kurz: Anthropic bietet Firmenkunden mit Enterprise Frontier Safeguards wieder Zero Data Retention – die Missbrauchskontrolle müssen sie aber selbst übernehmen. Quelle: Link BleepingComputer Hackers exploit Sangoma Switchvox flaw to deploy reverse shells (2026-09-02 21:00 UTC) Kurz: Attackers are actively exploiting CVE-2026-9586, an unauthenticated SQL injection vulnerability in the Sangoma Switchvox VoIP platform that can lead to remote code execution. […] Quelle: Link WordPress backup plugin flaw exposes millions of sites to takeover attacks (2026-09-02 19:28 UTC) Kurz: An SQL injection vulnerability in the All-in-One WP Migration and Backup plugin for WordPress could allow unauthenticated attackers to execute remote code and take control of affected websites. […] Quelle: Link Hackers exploit critical JFrog Artifactory flaw to forge admin tokens (2026-09-02 15:47 UTC) Kurz: A critical authentication bypass vulnerability (CVE-2026-82329) in JFrog Artifactory is being exploited in attacks to create tokens that provide administrative access. […] Quelle: Link The Hacker News Researcher Releases FalconFlank PoC Showing Privilege Escalation in CrowdStrike Falcon (2026-09-03 06:26 UTC) Kurz: The security researcher known as Chaotic Eclipse (aka INFINITE NIGHTMARE, MSNightmare, and Nightmare-Eclipse) has dropped a new zero-day dubbed FalconFlank, a privilege escalation flaw impacting Crowdstrike Falcon. “FalconFlank is a 0day pr… Quelle: Link CISA Adds Seven Exploited Flaws as Attackers Deploy Reverse Shells and Crypto Miners (2026-09-03 05:19 UTC) Kurz: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added seven security flaws to its Known Exploited Vulnerabilities (KEV) catalog after they landed in attackers’ crosshairs. The vulnerabilities are as follows - C… Quelle: Link Google, Anthropic, and OpenAI Unveil Cyber AI Models, Safeguards, and Access Programs (2026-09-02 18:27 UTC) Kurz: Google on Wednesday announced Gemini 3.8 Flash Cyber, which it described as its most capable cybersecurity model, and has made it available to a set of trusted defenders via a new initiative called the Fairwind Program. “The Fairwind Progra… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

September 3, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-09-02)

IT‑Sicherheits‑Digest (2026-09-02) Aktuelle Security‑News heise security Jetzt patchen! Angreifer attackieren Langflow-Instanzen mit Schadcode (2026-09-02 07:21 UTC) Kurz: Angreifer nutzen derzeit eine kritische Sicherheitslücke im KI-Tool Langflow aus. Ein Sicherheitspatch ist schon länger verfügbar. Quelle: Link „Passwort“ Folge 65: Wasserzeichen, Schlüsselprüfungen und langsame Logs (2026-09-02 07:00 UTC) Kurz: Der Podcast beleuchtet Wasserzeichen für KI, Schutzmaßnahmen gegen KI, Messengersicherheit ohne KI – und mal wieder ein Thema aus der Web-P…KI. Quelle: Link KI-Agenten führen git-Schadcode beim Starten automatisch aus (2026-09-02 05:23 UTC) Kurz: Agenten von Claude, Qwen, Grok usw. starten in manipulierten Repositories automatisch Schadcode – ohne Zutun des Anwenders, aber mit dessen vollen Rechten. Quelle: Link BleepingComputer SonicWall warns of actively exploited SMA1000 zero-day flaws (2026-09-02 06:39 UTC) Kurz: SonicWall warned customers that threat actors are chaining two new SMA1000 zero-day vulnerabilities in remote code execution attacks. […] Quelle: Link Hackers abuse Faronics Deploy admin tool to install ScreenConnect (2026-09-01 20:53 UTC) Kurz: Phishing actors are abusing the legitimate Faronics Deploy endpoint-management platform to gain remote administrative control over victim computers and install the ScreenConnect remote support software. […] Quelle: Link Aesto Health says data breach affects over 9.5 million patients (2026-09-01 19:28 UTC) Kurz: Aesto LLC, operating as Aesto Health, disclosed that a data breach discovered recently affects more than 9.5 million individuals. […] Quelle: Link The Hacker News Researchers Use Claude to Port Pre-Auth RCE Exploit From One PLC Model to Another (2026-09-02 07:47 UTC) Kurz: Forescout Research - Vedere Labs said it used Anthropic’s Claude to port a working pre-authentication remote code execution (RCE) exploit from one WAGO programmable logic controller (PLC) to another, executing attacker-supplied ARM shellcod… Quelle: Link Attackers Exploit Critical Switchvox Flaw to Deploy Reverse Shells Without Credentials (2026-09-02 07:08 UTC) Kurz: Threat actors are exploiting a severe security vulnerability in Sangoma Switchvox, an enterprise VoIP platform, that could allow unauthenticated remote code execution. The vulnerability in question is CVE-2026-9586 (CVSS score: 9.3), a crit… Quelle: Link Authorities Turn Sality’s P2P Network Against Itself, Cutting Off New Malware Payloads (2026-09-02 06:56 UTC) Kurz: The U.S. Department of Justice (DoJ) on Tuesday announced the takedown of a long-standing peer-to-peer (P2P) botnet known as Sality as part of a coordinated law enforcement operation. The effort was undertaken on August 31, 2026, by authori… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches CVE-2026-19766 — CVSS 9.6 (CRITICAL) Kurz: An authentication bypass vulnerability exists in the underlying operating system of HPE Networking Fabric Composer. Successful exploitation could allow an unauthenticated adjacent attacker to execute arbitrary code as a … Quelle: Link CVE-2026-73700 — CVSS 9.0 (CRITICAL) Kurz: A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an authenticated low privilege operator user to conduct a stored cross-site scripting (XSS) attack against an administra… Quelle: Link CVE-2026-73701 — CVSS 9.0 (CRITICAL) Kurz: An unauthenticated remote code execution vulnerability exists in the underlying operating system of HPE Networking Fabric Composer and could be exploited if certain preconditions outside of the attacker’s control are met… Quelle: Link CVE-2026-73702 — CVSS 8.8 (HIGH) Kurz: A privilege escalation vulnerability exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an admi… Quelle: Link CVE-2026-73703 — CVSS 8.8 (HIGH) Kurz: A vulnerability in the web-based management interface of HPE Networking Fabric Composer could allow an unauthenticated adjacent attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interfa… Quelle: Link CVE-2026-73704 — CVSS 8.8 (HIGH) Kurz: A command sanitization bypass exists in the API of HPE Networking Fabric Composer. Successful exploitation could allow an authenticated low privilege operator user to escalate their permissions to those of an administrat… Quelle: Link VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

September 2, 2026 · 4 min · Betty