IT-Sicherheits-Digest (2026-09-11)
IT‑Sicherheits‑Digest (2026-09-11) Aktuelle Security‑News heise security Vierter Hacking-Vorfall: Weiteres Anthropic-Modell bricht aus Testumgebung aus (2026-09-10 13:46 UTC) Kurz: Nachdem Anthropic schon Ende Juli drei Hacking-Angriffe meldete, ist nach Analyse der Daten jetzt noch ein vierter bei Claude Opus 4.6 hinzugekommen. Quelle: Link Kritische Schadcode-Lücken bedrohen Ivanti Neurons for ITSM (2026-09-10 13:15 UTC) Kurz: Angreifer können Ivanti Endpoint Manager Mobile, Neurons for ITSM und Sentry attackieren. Sicherheitsupdates sind verfügbar. Quelle: Link Sicherheitslücken in ePA-Clients: „Die Implementierungen hatten blinde Flecken“ (2026-09-10 12:53 UTC) Kurz: Sicherheitsforscher sorgten für Fixes kritischer Lücken in ePA-Clients und der Telematikinfrastruktur. Dr. Simon Weber erklärt die Details im Interview. Quelle: Link BleepingComputer Trezor: 347,000 users targeted in phishing attacks after Brevo breach (2026-09-11 07:55 UTC) Kurz: Trezor has revealed that phishing attacks against its customers earlier this week targeted 347,000 email addresses and affected 2,500 users who clicked an embedded malicious link. […] Quelle: Link Conti ransomware gang member sentenced to 4 years in prison (2026-09-11 06:48 UTC) Kurz: A Ukrainian national has been sentenced to four years in prison for his role in Conti ransomware attacks between 2021 and 2022. […] Quelle: Link New Android malware encrypts files, steals data, and harasses victims (2026-09-10 21:40 UTC) Kurz: A new Android malware strain called Mantax Otax combines ransomware and spyware capabilities to encrypt files, steal sensitive data, and spam and harass victims. […] Quelle: Link The Hacker News Attackers Chain JFrog Artifactory Flaws to Gain Admin Control and Plant Backdoors (2026-09-11 07:31 UTC) Kurz: Attackers have chained two flaws in JFrog Artifactory, the repository that software build pipelines pull from, to take administrator control of self-hosted servers and plant backdoors, cloud security company Wiz said in a report. Wiz saw th… Quelle: Link China-Linked UNC3569 Exploited Sogou Input Method Flaw to Deploy GRAYRABBIT Backdoor (2026-09-11 07:14 UTC) Kurz: A China-linked hacking group exploited a flaw in Sogou Input Method, one of the most widely used tools for typing Chinese characters on Windows, to install a backdoor on victims’ computers, security company Gen Digital said in research publ… Quelle: Link PaperCut Replaces Emergency Patches With Fixes for Two Actively Exploited Flaws (2026-09-11 06:46 UTC) Kurz: PaperCut on Thursday released a new security maintenance release that replaces all previously published emergency patches that were pushed to address two security flaws that have come under active exploitation. The software development comp… Quelle: Link Neue CVEs (letzte 24h, NVD‑Abgleich) Fortinet FortiGate (7.4.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Atlassian (Jira/Confluence) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. HPE/Aruba Switches CVE-2026-73784 — CVSS 8.8 (HIGH) Kurz: A potential security vulnerability in HPE IceWall products could be exploited to tamper SAML response, allowing an attacker to impersonate another user. Quelle: Link CVE-2026-73785 — CVSS 7.5 (HIGH) Kurz: A potential security vulnerability in HPE IceWall Federation Agent and Proxy could allow a remote unauthenticated attacker to cause a denial of service (DoS). Quelle: Link CVE-2026-15889 — CVSS 6.4 (MEDIUM) Kurz: The Aruba HiSpeed Cache plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the Post Content in all versions up to, and including, 3.0.14 due to insufficient input sanitization and output escaping. This… Quelle: Link VMware ESXi/vCenter (7.x) Keine neuen Treffer in den erfolgreich abgefragten NVD‑Daten der letzten 24h. Hinweis CVE‑Treffer sind ein Frühwarn‑Check (NVD) und müssen für eure exakten Versionen/Deployments gegengeprüft werden (Vendor Advisory/Patches). News-Auswahl: nur frische Meldungen aus den letzten 36 Stunden; Dubletten aus dem Vortags-Digest werden ausgeblendet.