IT-Sicherheits-Digest (2026-07-23)

IT‑Sicherheits‑Digest (2026-07-23) Aktuelle Security‑News heise security Microsoft SharePoint: Angriffe auf weitere Sicherheitslücke (2026-07-23 07:13 UTC) Kurz: Weitere Sicherheitslücken in SharePoint stehen unter Beschuss. Auch Check Point SmartConsole wird derzeit attackiert. Quelle: Link Cyberattacken auf Landesverwaltung nehmen weiter zu (2026-07-23 04:45 UTC) Kurz: Cyberangriffe nehmen in Sachsen-Anhalt deutlich zu: Im ersten Halbjahr meldet die Landesverwaltung mehr als doppelt so viele Vorfälle wie zuvor. Quelle: Link Online-Trading-Betrug: Opfer investieren über eine Million (2026-07-23 04:19 UTC) Kurz: 24 Menschen aus ganz Deutschland sollen Geld in vermeintliche Online-Trading-Plattformen investiert haben. Doch Gewinne wurden nie ausgezahlt. Quelle: Link BleepingComputer Upbound says hack caused $13 million in fraudulent Acima leases (2026-07-22 21:43 UTC) Kurz: The Upbound Group fintech company disclosed that threat actors who stole data from its systems leveraged it to create $13 million in Acima leases. […] Quelle: Link South Korea discloses data breach impacting diplomats worldwide (2026-07-22 20:06 UTC) Kurz: South Korea disclosed that hackers breached the National Diplomatic Academy’s online education system for ten months and stole personal information belonging to current and former employees of the Ministry of Foreign Affairs (MFA), includin… Quelle: Link Swiss rail giant Stadler rejects $12.3M ransom demand after cyberattack (2026-07-22 16:59 UTC) Kurz: Swiss rail vehicle manufacturer Stadler Rail says the Everest ransomware gang demanded about $12.3 million after breaching a data exchange platform shared with one of its suppliers. […] Quelle: Link The Hacker News GitHub Cuts Public Bug Bounty Payouts, Moves Top Rewards to VIP Tier (2026-07-22 18:37 UTC) Kurz: Beginning July 27, 2026, GitHub will cut public bug bounty payouts by at least half at every severity level. Critical findings will drop from $20,000-$30,000+ to a fixed $10,000, while its permanent invite-only VIP tier will pay $30,000 or … Quelle: Link Ubuntu snap-confine Flaw Could Give Local Users Root on Default Desktop Installs (2026-07-22 18:07 UTC) Kurz: Cybersecurity researchers have disclosed details of a new local privilege escalation (LPE) vulnerability in snap-confine that an unprivileged user can trigger to obtain root access and gain complete control of a target environment. The high… Quelle: Link Adobe Acrobat Extension Flaw Let Malicious Sites Read WhatsApp Web Data (2026-07-22 15:01 UTC) Kurz: Cybersecurity researchers have disclosed details of a now-patched vulnerability chain in the Adobe Acrobat Chrome extension that has over 314 million users, which, if exploited, could facilitate a silent hijack of a user’s WhatsApp data. Th… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

July 23, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-07-22)

IT‑Sicherheits‑Digest (2026-07-22) Aktuelle Security‑News heise security Backupsoftware Veeam: Updater ermöglicht Rechteausweitung (2026-07-22 07:37 UTC) Kurz: IT-Sicherheitsforscher haben in der Update-Komponente von Veeam eine Sicherheitslücke entdeckt, die das Ausweiten der Rechte ermöglicht. Quelle: Link „Passwort“ Folge 62: IETF-Grabenkämpfe, Umbrella-CVEs, Riksha-Hacking und mehr (2026-07-22 07:00 UTC) Kurz: Eine Podcastfolge fast ohne PKI, aber mit gehörig Drama (bei der IETF), Kopfschütteln (über Cisco) und gefährlichen Sicherheitslücken (im In- und Ausland). Quelle: Link Oracle Critical Patch Update: 1449 Softwareflicken im Juli (2026-07-22 06:30 UTC) Kurz: Zum vierteljährlichen Oracle CPU liefert der Hersteller 1449 Sicherheitsupdates aus – ein neuer Rekordwert. Admins sollten handeln. Quelle: Link BleepingComputer Chick-fil-A discloses data breach after credential stuffing attacks (2026-07-22 06:40 UTC) Kurz: American fast food restaurant chain Chick-fil-A is notifying customers of a data breach after their accounts were hacked in a wave of recent credential stuffing attacks. […] Quelle: Link OpenAI says its AI models hacked Hugging Face during testing (2026-07-22 05:19 UTC) Kurz: OpenAI says its AI models, including GPT‑5.6 Sol and a pre-release model, hacked into the Hugging Face artificial intelligence repository while being tested in a sandboxed testing environment. […] Quelle: Link Police dismantle Kratos phishing platform, arrest developer (2026-07-21 23:07 UTC) Kurz: Authorities in Germany and the U.S. dismantled the central infrastructure of Kratos, a phishing-as-a-service (PhaaS) platform with global reach, and its developer was arrested in Indonesia. […] Quelle: Link The Hacker News Police Dismantle Kratos Phishing Kit Built to Steal Microsoft 365 Sessions and Bypass MFA (2026-07-22 06:38 UTC) Kurz: German and US law enforcement have taken down the core infrastructure of Kratos, described by German investigators as one of the world’s most widely used criminal phishing kits, and Indonesian authorities arrested the man they say developed… Quelle: Link Trojanized Newtonsoft.Json Fork Hides Game-Rigging Code in a Working Library (2026-07-22 06:00 UTC) Kurz: Cybersecurity researchers have discovered a NuGet typosquat that’s unlike the typical information-stealing malware distributed via package registries: usual info-stealers: it’s designed to rig live game results on Digitain. The package, nam… Quelle: Link Microsoft Azure DevOps MCP Flaw Lets Hidden PR Comments Hijack AI Review Agents (2026-07-22 04:57 UTC) Kurz: A single invisible comment in an Azure DevOps pull request can turn a reviewer’s own AI coding agent against them, driving it into projects the attacker has no rights to reach and quietly leaking what it finds. The flaw is in Microsoft’s of… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) CVE-2026-21575 — CVSS 7.1 (HIGH) Kurz: This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.11 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.1, al… Quelle: Link CVE-2026-21577 — CVSS n/a Kurz: This High severity DoS (Denial of Service) vulnerability was introduced in versions 9.0.1, 9.1.0, 9.2.0, 9.3.1, 9.4.0, 9.5.1, 10.0.2, 10.1.0 and 10.2.0 of Confluence Data Center. This DoS (Denial of Service) vulnerabilit… Quelle: Link CVE-2026-21579 — CVSS n/a Kurz: This High severity Information Disclosure vulnerability was introduced in versions 7.17.0, 7.19.0, 8.5.0, 8.9.0, 9.0.1, 9.1.0, 9.2.0, 10.0.2, 10.1.0, and 10.2.0 of Confluence Data Center. This Information Disclosure vuln… Quelle: Link HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

July 22, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-07-21)

IT‑Sicherheits‑Digest (2026-07-21) Aktuelle Security‑News heise security Coca Cola: Molkereisparte fairlife stellt Produktion nach Cyberangriff ein (2026-07-21 07:08 UTC) Kurz: Der Molkereiprodukte-Zweig fairlife von Coca Cola muss nach einem Ransomware-Vorfall temporär die Produktion einstellen. Quelle: Link Rumänien: Cyberkrimineller löscht die gesamte Grundbuchdatenbank des Landes (2026-07-21 03:15 UTC) Kurz: Ein Angreifer löscht die gesamte rumänische Grundbuchdatenbank, nachdem eine Erpressung scheiterte, und bringt damit den Immobilienmarkt zum Stillstand. Quelle: Link Hunderttausende Opfer: Schlag gegen Phishing-Service (2026-07-20 16:42 UTC) Kurz: Ermittler aus Deutschland und den USA haben die Infrastruktur des Phishing-Services Kratos zerschlagen. Der Dienst ermöglichte monatlich tausende Angriffe. Quelle: Link BleepingComputer Estée Lauder discloses data breach via Oracle E-Business flaw (2026-07-20 22:39 UTC) Kurz: Cosmetics giant Estée Lauder is notifying customers of a data breach after hackers exploited a flaw in Oracle E-Business Suite that the company used for human resources (HR) operations. […] Quelle: Link SonicWall SMA1000 flaws exploited as zero-days to push custom malware (2026-07-20 22:23 UTC) Kurz: Two recently disclosed SonicWall SMA1000 vulnerabilities were exploited in zero-day attacks for weeks, allowing threat actors to install custom malware on vulnerable VPN appliances. […] Quelle: Link Hackers steal $23.7 million in crypto from Ostium in off-chain attack (2026-07-20 22:22 UTC) Kurz: The Ostium trading platform announced that an attacker stole $23.75 million from its liquidity provider vault last week, after compromising off-chain infrastructure used to feed prices into the protocol. […] Quelle: Link The Hacker News New ENCFORGE Ransomware Targets AI Model Files in Langflow RCE Attack (2026-07-21 07:34 UTC) Kurz: Researchers at Sysdig have linked a second attack on the same Langflow server to JADEPUFFER, the AI-agent-driven operator it first documented earlier this month. The same operator has now been spotted deploying ENCFORGE, a new compiled Go r… Quelle: Link Critical ServiceNow AI Platform Flaw Exploited for Unauthenticated Code Execution (2026-07-21 06:29 UTC) Kurz: Threat actors are now exploiting a recently disclosed critical security flaw impacting ServiceNow AI Platform, according to Defused Cyber. In a post shared on X, the threat intelligence firm said it’s observing in-the-wild exploitation of C… Quelle: Link FakeGit Campaign Uses 7,600 GitHub Repositories to Spread SmartLoader Malware (2026-07-20 18:23 UTC) Kurz: Cybersecurity researchers have discovered nearly 7,600 malicious GitHub repositories, out of which more than 800 pose as artificial intelligence (AI) skills or Model Context Protocol (MCP) servers to deliver a malware family known as SmartL… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

July 21, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-07-20)

IT‑Sicherheits‑Digest (2026-07-20) Aktuelle Security‑News heise security Kritische Sicherheitslücke: Schadcode kann auf Nginx-Server schlüpfen (2026-07-20 07:03 UTC) Kurz: Angreifer können Nginx Open Source und Nginx Plus attackieren. Sicherheitsupdates sind verfügbar. Quelle: Link Shark-Saugroboter: Sicherheitslücke ermöglicht Übernahme aus dem Netz (2026-07-20 06:39 UTC) Kurz: Ein IT-Sicherheitsforscher hat eine Schwachstelle in Shark-Saugrobotern entdeckt, die die Übernahme aus dem Internet ermöglicht. Quelle: Link Googles cleverer KI-Schachzug – oder: wer kontrolliert zukünftig den KI-Markt? (2026-07-19 16:00 UTC) Kurz: Macht das Modell den entscheidenden Unterschied? Google zumindest scheint eher auf den richtigen Rahmen zu setzen als das eigene Top-Modell. Eine Analyse. Quelle: Link BleepingComputer Hackers abuse ViPNet software to target Russian govt agencies (2026-07-19 14:23 UTC) Kurz: An advanced threat actor is abusing the update mechanism for the ViPNet private networking product suite to target Russian organizations, including government agencies. […] Quelle: Link The Hacker News World’s Largest AI Model Repository Hugging Face Breached by Autonomous AI Agent (2026-07-20 05:27 UTC) Kurz: In an ironic twist, open-source artificial intelligence (AI) platform Hugging Face revealed that it was the victim of a hack perpetrated by an autonomous AI agent system. The company said it detected and responded to the incident targeting … Quelle: Link SleeperGem Uses Three Malicious RubyGems Packages to Target Developer Machines (2026-07-20 05:15 UTC) Kurz: Cybersecurity researchers have flagged a new software supply chain attack codenamed SleeperGem targeting the Ruby ecosystem after three malicious gems were published to RubyGems with the end goal of serving additional payloads. The rogue ge… Quelle: Link Critical NGINX Vulnerability Can Crash Workers and May Allow Remote Code Execution (2026-07-19 20:42 UTC) Kurz: F5 has shipped fixes for a critical nginx flaw that lets a remote, unauthenticated attacker trigger a heap buffer overflow in the worker process with crafted HTTP requests. CVE-2026-42533 was patched on July 15 in nginx 1.30.4 (stable) and … Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

July 20, 2026 · 2 min · Betty

IT-Sicherheits-Digest (2026-07-19)

IT‑Sicherheits‑Digest (2026-07-19) Aktuelle Security‑News heise security Keine neuen, nicht bereits gestern gelisteten Meldungen im 36h-Fenster. BleepingComputer Update now: 7-Zip fixes RCE flaw exploitable with malicious archives (2026-07-18 19:32 UTC) Kurz: 7-Zip version 26.02 was released to fix a remote code execution vulnerability that could allow attackers to execute malicious code by convincing users to open specially crafted compressed files. […] Quelle: Link WordPress Core “wp2shell” RCE flaws get public exploits, patch now (2026-07-18 17:22 UTC) Kurz: Public exploits have been released for the critical “wp2shell” remote code execution vulnerabilities affecting WordPress Core, making it imperative that administrators patch their sites immediately. […] Quelle: Link Microsoft warns of surge in ACR Stealer attacks on customers (2026-07-18 14:17 UTC) Kurz: Microsoft has observed a surge in attacks using the ACR Stealer malware to steal browser-stored passwords, authentication tokens, and sensitive documents from its enterprise customers. […] Quelle: Link The Hacker News Keine neuen, nicht bereits gestern gelisteten Meldungen im 36h-Fenster. Lageeinschätzung Heute sind nur wenige frische, nicht doppelte Meldungen im 36h-Fenster aufgelaufen. Das ist typisch nach Wochenenden/Feiertagen oder wenn Feeds erst später am Vormittag aktualisieren. Ausgeblendet: 81 ältere oder bereits gestern verwendete Feed-Einträge. Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) CVE-2026-47865 — CVSS 9.8 (CRITICAL) Kurz: VMware Avi Load Balancer contains an authentication bypass vulnerability. A malicious user with network access may be able to access the Avi Control plane by bypassing the authentication mechanism. Affected versions: 31.… Quelle: Link CVE-2026-47867 — CVSS 8.7 (HIGH) Kurz: VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious user with network access may be able to access the Avi Control plane and execute code remotely. Affected versions: 32.1.1 (fixed in 32.… Quelle: Link CVE-2026-47869 — CVSS 8.7 (HIGH) Kurz: VMware Avi Load Balancer contains a remote code execution vulnerability. A malicious authenticated user with network access may be able to inject and execute code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 throu… Quelle: Link CVE-2026-47866 — CVSS 8.3 (HIGH) Kurz: VMware Avi Load Balancer contains an authorization bypass vulnerability. A malicious actor on the network can access a limited subset of the Avi Control Plane without proper authorization. Affected versions: 32.1.1 (fixe… Quelle: Link CVE-2026-47868 — CVSS 7.8 (HIGH) Kurz: VMware Avi Load Balancer contains a local privilege escalation vulnerability. A malicious user with local access may be able to escalate their privileges to run code as root. Affected versions: 32.1.1 (fixed in 32.1.2) 3… Quelle: Link CVE-2026-47870 — CVSS 7.1 (HIGH) Kurz: VMware Avi Load Balancer contains a privilege escalation vulnerability. A malicious authenticated user with network access may be able to execute remote code. Affected versions: 32.1.1 (fixed in 32.1.2) 31.1.1 through 31… Quelle: Link Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

July 19, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-07-18)

IT‑Sicherheits‑Digest (2026-07-18) Aktuelle Security‑News heise security „wp2shell“: Kritische WordPress-Lücke erlaubt Codeeinschleusung über API (2026-07-18 05:19 UTC) Kurz: Durch Verkettung einer SQL-Injection- und einer API-Lücke können Angreifer Code einschleusen. WordPress hat ein Update veröffentlicht, die Finder einen Hotfix. Quelle: Link VMware Avi Load Balancer: Kritische Lücke erlaubt Umgehung von Anmeldung (2026-07-17 10:11 UTC) Kurz: VMware warnt vor zum Teil kritischen Lücken im Avi Load Balancer. Angreifer können Authentifizierung und Autorisierung umgehen. Quelle: Link Windows Server 2022: Mainstream-Support endet in 90 Tagen (2026-07-17 08:21 UTC) Kurz: Windows Server 2022 fällt in 90 Tagen aus dem Mainstream-Support. Erweiterte Sicherheitsupdates gibt es bis 2031 – und danach ESU. Quelle: Link BleepingComputer Abbott probes two cyber incidents amid extortion claims (2026-07-17 20:45 UTC) Kurz: Abbott Laboratories is investigating two separate cybersecurity incidents after confirming unauthorized access to internal legacy Exact Sciences systems in its Cancer Diagnostics business, while also investigating a separate claim that atta… Quelle: Link HollowByte DDoS flaw bloats OpenSSL server memory with 11-byte payload (2026-07-17 17:56 UTC) Kurz: A vulnerability dubbed HollowByte allows unauthenticated attackers to trigger a denial-of-service (DoS) condition on OpenSSL servers with a malicious payload of just 11 bytes. […] Quelle: Link Ernst & Young discloses data breach after support system hack (2026-07-17 14:55 UTC) Kurz: Ernst & Young is notifying customers of a data breach caused by the compromise of a third-party support ticket system used by its IT personnel. […] Quelle: Link The Hacker News New wp2shell WordPress Core Flaw Lets Unauthenticated Attackers Run Code (2026-07-17 21:20 UTC) Kurz: Updated July 18, 2026: the two flaws now carry CVE IDs, the full mechanism has been published, a persistent-object-cache condition has surfaced, and a working proof-of-concept is public. The story below reflects all of it. An anonymous HTTP… Quelle: Link OpenSSL HollowByte Flaw Could Freeze Server Memory with 11-Byte TLS Requests (2026-07-17 20:20 UTC) Kurz: Eleven bytes will make an unpatched OpenSSL server set aside up to 131 KB of memory for a message that never arrives. On the glibc systems Okta tested, that memory is gone until the process restarts. OpenSSL shipped the HollowByte fix in Ju… Quelle: Link Seven Malicious Vite npm Packages Use Blockchain C2 to Deliver a RAT (2026-07-17 18:54 UTC) Kurz: Cybersecurity researchers have discovered a cluster of seven malicious npm packages targeting the Vite frontend tooling ecosystem as part of a software supply chain attack. The malicious package campaign, codenamed ViteVenom by Checkmarx, m… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

July 18, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-07-17)

IT‑Sicherheits‑Digest (2026-07-17) Aktuelle Security‑News heise security Apple-Tool nachgemacht: So geht die neue macOS-Malware CrashStealer vor (2026-07-17 07:30 UTC) Kurz: Momentan kursiert ein neuer Mac-Datenschädling, der Zugangsdaten und Kryptowährungen klauen kann. Er tarnt sich als Apple-Software. Quelle: Link Google Chrome: Außerplanmäßiges zweites Update in der Woche (2026-07-17 06:27 UTC) Kurz: Google aktualisiert Chrome eigentlich jeden Mittwoch. Diese Woche folgt ein zweites Update, das mehrere kritische Lücken schließt. Quelle: Link 7-Zip: Update stopft Codeschmuggel-Lücke (2026-07-17 06:07 UTC) Kurz: Das Packprogramm 7-Zip patzt bei der Verarbeitung präparierter xz-Daten. Das kann zum Ausführen eingeschmuggelten Codes führen. Quelle: Link BleepingComputer CISA urges immediate action on actively exploited Fortinet flaws (2026-07-17 07:03 UTC) Kurz: CISA on Thursday ordered government agencies to prioritize patching two actively exploited vulnerabilities in the Fortinet FortiSandbox threat detection platform. […] Quelle: Link New ClickLock macOS malware traps users into revealing login password (2026-07-16 21:52 UTC) Kurz: A new macOS information-stealing malware dubbed ClickLock terminates all visible processes to force users into entering their system login password. […] Quelle: Link Coca-Cola says Fairlife ransomware attack halts US dairy production (2026-07-16 21:09 UTC) Kurz: The Coca-Cola Company disclosed today that a ransomware attack impacting its Fairlife dairy subsidiary has disrupted operations, temporarily suspending production of Fairlife products across the United States. […] Quelle: Link The Hacker News CISA Adds Exploited SharePoint RCE Zero-Day CVE-2026-58644 to KEV (2026-07-17 06:42 UTC) Kurz: The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Thursday added a newly patched security flaw impacting Microsoft SharePoint Server to its Known Exploited Vulnerabilities (KEV) catalog, requiring Federal Civilian Executiv… Quelle: Link Two Scattered Spider Hackers Get 5.5 Years Each for £29 Million TfL Hack (2026-07-16 17:09 UTC) Kurz: Owen Flowers, 18, and Thalha Jubair, 20, were each sentenced to five and a half years at Woolwich Crown Court on Thursday, 16 July 2026, for the 2024 hack of Transport for London. The attack left 148 TfL systems inoperable and forced all 27… Quelle: Link ThreatsDay: Game Cheat Spyware, 24-Hour Ransomware, Chrome Sync Stalking + 12 More Stories (2026-07-16 15:41 UTC) Kurz: A lot of this week’s trouble starts with something that looks close enough. A familiar repo. A useful installer. A harmless sync setting. Then the handoff goes bad, the box starts talking to someone else, and the damage moves faster than th… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

July 17, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-07-16)

IT‑Sicherheits‑Digest (2026-07-16) Aktuelle Security‑News heise security Webkonferenztool Zoom: Kontoübernahme aus dem Netz möglich (2026-07-16 07:38 UTC) Kurz: Zoom hat mehrere Sicherheitslücken in der Webkonferenzsoftware geschlossen. Sie ermöglichen etwa Kontoübernahme aus dem Netz. Quelle: Link Windows-Update: Wegen Problemen auf einigen Dell-Computern ausgesetzt (2026-07-16 05:46 UTC) Kurz: Die Windows-Updates machen auf einigen Dell-Computern Probleme. Microsoft installiert sie daher nicht auf betroffene Systeme. Quelle: Link BSI seziert Windows Hello: Wo Microsofts Anmeldung an Grenzen stößt (2026-07-15 13:30 UTC) Kurz: Das BSI hat Windows Hello for Business analysiert und Schwächen bei der biometrischen Anmeldung aufgedeckt – besonders ohne Enhanced Sign-in Security. Quelle: Link BleepingComputer Dutch police bust investment fraud ring stealing over €100 million (2026-07-15 21:55 UTC) Kurz: The Dutch Police announced the arrest of multiple individuals suspected of being part of an international investment fraud scheme estimated to have tens of thousands of victims. […] Quelle: Link Zoom warns of critical account takeover vulnerability (2026-07-15 20:16 UTC) Kurz: Zoom is warning of a critical vulnerability in its desktop client and software development kit for Windows that could be exploited by an unauthenticated party to hijack accounts. […] Quelle: Link Google Gemini CLI abused as a hacking agent, malware botnet operator (2026-07-15 18:33 UTC) Kurz: A Russian-speaking threat actor known as “bandcampro” used Google’s open-source Gemini CLI AI tool as a hacking agent and to operate a small-scale botnet. […] Quelle: Link The Hacker News TuxBot v3 Evolution Shows Signs of LLM-Assisted IoT Botnet Development (2026-07-15 18:43 UTC) Kurz: Cybersecurity researchers have disclosed details of a previously unreported Internet-of-Things (IoT) botnet framework dubbed TuxBot v3 Evolution that shows signs of being developed with assistance from a large language model (LLM), albeit w… Quelle: Link OkoBot Malware Framework Injects Seed Phrase Phishing Into Ledger and Trezor Apps (2026-07-15 15:30 UTC) Kurz: A malware framework called OkoBot has been running on Windows machines since April 2025, and one of its modules is built to con hardware wallet owners out of their recovery phrase. On an infected PC, the request comes from inside the wallet… Quelle: Link Firefox, Chrome, Adobe, and VMware Updates Fix Multiple Critical Security Flaws (2026-07-15 13:18 UTC) Kurz: Mozilla has released updates to address two critical flaws in Firefox for which it warned that exploit code has been published. The vulnerabilities are listed below - CVE-2026-15718, an invalid pointer in the JavaScript: WebAssembly compone… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) CVE-2026-59838 — CVSS 5.9 (MEDIUM) Kurz: A improper neutralization of script-related html tags in a web page (basic xss) vulnerability in Fortinet FortiSIEM 7.4.0, FortiSIEM 7.3.0 through 7.3.4, FortiSIEM 7.2.0 through 7.2.6, FortiSIEM 7.1 all versions, FortiSI… Quelle: Link Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

July 16, 2026 · 3 min · Betty

IT-Sicherheits-Digest (2026-07-15)

IT‑Sicherheits‑Digest (2026-07-15) Aktuelle Security‑News heise security Ungeschützte Wechselrichter: Hoymiles verspricht Update (2026-07-15 06:26 UTC) Kurz: Angreifer können durch Sicherheitslücken in Hoymiles-Wechselrichtern die Geräte aus der Ferne lahmlegen. Ein Update soll das ändern. Quelle: Link Software-Update Ursache von IT-Problemen der Berliner Justiz (2026-07-15 04:46 UTC) Kurz: Technische Probleme haben die Berliner Gerichte lahmgelegt. Ein fehlerhaftes Software-Update sorgte für einen Totalausfall, der nun schrittweise behoben wird. Quelle: Link Microsoft macht Passkeys zum Standard in Entra ID (2026-07-14 15:35 UTC) Kurz: Microsoft führt Passkeys als Standard-Anmeldemethode in Entra ID ein. SMS- und Sprachanrufe laufen schrittweise aus. Quelle: Link BleepingComputer US charges alleged operators of Russian bulletproof hosting service (2026-07-15 07:45 UTC) Kurz: U.S. federal prosecutors have unsealed charges against three Russian nationals, accusing them of providing bulletproof hosting (BPH) services to ransomware gangs that caused over $62 million in damages to victims worldwide. […] Quelle: Link SonicWall warns of SMA1000 flaws exploited in zero-day attacks, patch now (2026-07-14 21:23 UTC) Kurz: SonicWall warns that threat actors have been exploiting two SMA1000 vulnerabilities, tracked as CVE-2026-15409 and CVE-2026-15410, in zero-day attacks and urges customers to install the newly released security updates. […] Quelle: Link Spanish Police take down €140 million cyber fraud ring, arrest four (2026-07-14 20:23 UTC) Kurz: The Spanish Police dismantled a cybercrime and money-laundering organization that made €140 million ($160 million) from investment fraud and business email compromise (BEC) attacks. […] Quelle: Link The Hacker News Two SonicWall SMA 1000 Zero-Days Exploited, One Could Enable Admin Commands (2026-07-15 05:30 UTC) Kurz: SonicWall has warned of active exploitation of two zero-day vulnerabilities impacting Secure Mobile Access (SMA) 1000 series appliances, one of which could be exploited to achieve arbitrary command execution. The vulnerabilities are listed … Quelle: Link Microsoft Patches Record 622 Flaws, Including Two Zero-Days Under Active Attack (2026-07-14 20:25 UTC) Kurz: Microsoft shipped its largest Patch Tuesday on record today, and two of the fixes close holes that attackers are already exploiting. The release covers 622 of Microsoft’s own CVEs by its Security Update Guide count, more than triple June’s … Quelle: Link SAP Patches CVSS 9.9 NetWeaver ABAP Flaw That Could Expose or Modify Data (2026-07-14 18:17 UTC) Kurz: SAP has rolled out updates to address multiple vulnerabilities as part of its July 2026 security updates, including a critical flaw in SAP NetWeaver Application Server ABAP. The vulnerability in question is CVE-2026-44747 (CVSS score: 9.9),… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) CVE-2026-59835 — CVSS 8.6 (HIGH) Kurz: A exposure of resource to wrong sphere vulnerability in Fortinet FortiSandbox 5.0.0 through 5.0.2, FortiSandbox 4.4.3 through 4.4.8 may allow an unauthenticated attacker to access the VNC server of VMs performing scannin… Quelle: Link CVE-2025-53379 — CVSS 7.5 (HIGH) Kurz: A out-of-bounds read vulnerability in Fortinet FortiAuthenticator 6.6.0 through 6.6.2, FortiAuthenticator 6.5 all versions may allow a remote unauthenticated attacker to retrieve sensitive information via a specially cra… Quelle: Link CVE-2026-59837 — CVSS 6.6 (MEDIUM) Kurz: A stack-based buffer overflow vulnerability in Fortinet FortiOS 7.4.0 through 7.4.1, FortiOS 7.2 all versions, FortiPAM 1.8.0 through 1.8.2, FortiPAM 1.7 all versions, FortiPAM 1.6 all versions, FortiPAM 1.5 all versions… Quelle: Link CVE-2026-23573 — CVSS 6.1 (MEDIUM) Kurz: An Improper Neutralization of Input During Web Page Generation (‘Cross-site Scripting’) vulnerability [CWE-79] vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4 all versions, FortiOS 7.2 all versions, Fo… Quelle: Link CVE-2026-59839 — CVSS 5.5 (MEDIUM) Kurz: A improper limitation of a pathname to a restricted directory (‘path traversal’) vulnerability in Fortinet FortiOS 7.6.0 through 7.6.6, FortiOS 7.4.0 through 7.4.9, FortiOS 7.2 all versions, FortiOS 7.0 all versions, For… Quelle: Link CVE-2025-43892 — CVSS 4.3 (MEDIUM) Kurz: A buffer over-read vulnerability in Fortinet FortiOS 7.6.0 through 7.6.2, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2 all versions may allow an authenticated remote attacker to return a portion of device memory in the redir… Quelle: Link Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

July 15, 2026 · 4 min · Betty

IT-Sicherheits-Digest (2026-07-14)

IT‑Sicherheits‑Digest (2026-07-14) Aktuelle Security‑News heise security Telegram-Messenger: Kurzdomain t.me womöglich wegen US-Sanktionen gesperrt (2026-07-14 07:31 UTC) Kurz: Die Domain wurde von der Vergabestelle des Landes Montenegro blockiert - womöglich stecken US-Sanktionen gegen einen VPN-Anbieter dahinter. Quelle: Link Betrügerischer Ransomware-Verhandler muss 70 Monate ins Gefängnis (2026-07-14 07:29 UTC) Kurz: Das Urteil ist gefallen: Für 70 Monate wandert ein betrügerischer Ransomware-Verhandler aus Florida hinter Gitter. Quelle: Link Alte Cisco-Lücke attackiert: Leitfaden zum Schutz (2026-07-14 05:38 UTC) Kurz: Die US-IT-Sicherheitsbehörde CISA warnt vor Angriffen auf eine 18 Jahre alte Cisco-Lücke. Ein Leitfaden soll helfen, Router abzusichern. Quelle: Link BleepingComputer Japan’s largest taxi operator shuts systems after cyberattack (2026-07-13 20:18 UTC) Kurz: Japan’s largest taxi operator, Nihon Kotsu, announced that its systems were compromised in a cyberattack, forcing the company to shut down part of its infrastructure. […] Quelle: Link Hackers backdoor Jscrambler npm package with infostealer malware (2026-07-13 19:44 UTC) Kurz: The Jscrambler client-side web security company disclosed that a threat actor published a malicious version of its npm package that has been downloaded almost 1,500 times. […] Quelle: Link New CrashStealer malware poses as Apple crash reporting tool (2026-07-13 19:04 UTC) Kurz: A new macOS information-stealing malware called CrashStealer pretends to be Apple’s crash-reporting tool to steal credentials, keychain data, and crypto wallets. […] Quelle: Link The Hacker News Microsoft Maps Year-Long ShinyHunters-Linked Salesforce Data Theft Across Three Paths (2026-07-14 06:19 UTC) Kurz: Attackers whose methods line up with the data-extortion group ShinyHunters have spent the past year walking into corporate Salesforce environments without exploiting a single flaw in the platform. The way in has been the trust the organizat… Quelle: Link CrashStealer macOS Malware Uses Notarized Dropper to Pass Gatekeeper Checks (2026-07-13 17:36 UTC) Kurz: Cybersecurity researchers have flagged a new macOS information stealer called CrashStealer that’s capable of harvesting sensitive data from compromised systems. Unlike other information stealers that are built on AppleScript droppers or Obj… Quelle: Link Google and Microsoft Pull ModHeader With 1.6 Million Installs After Dormant Collector Found (2026-07-13 17:17 UTC) Kurz: Google and Microsoft have pulled ModHeader, a popular header-editing extension with roughly 1.6 million installs across Chrome and Edge, after researchers found a hidden browsing-history collector built into its official store version. The … Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.

July 14, 2026 · 3 min · Betty